Problème avec wininit.exe

Bonjour,

Je viens de faire une rapide recherche et je pense que je suis infecté par bamital via le fichier wininit.exe, j'aurais besoin d'aide car mes connaissance en informatique sont limitées.

Merci d'avance à mon sauveur ^^

52 réponses

Résumé de la discussion

Suspicion d'infection par bamital via wininit.exe sur Windows 7 avec Firefox 3.6.2, nécessitant des conseils techniques pour identifier et supprimer le malware et comprendre les traces laissées. Plusieurs éléments de réponse efficaces ont été avancés, notamment un rapport VirusTotal indiquant une suspicion et une analyse Malwarebytes qui a détecté plusieurs éléments infectés et les a mis en quarantaine et supprimés. Le rapport de détection détaillait six éléments infectés, dont des composants adware et des trojans, et ces éléments ont été mis en quarantaine puis supprimés grâce à l'analyse complète. Des éléments supplémentaires indiquent l'utilisation éventuelle d'un outil comme Combofix et des messages d'erreur relatifs à wininit.exe, apportant une nuance sur l'évolution du diagnostic global.

Bobot (l’IA à votre service)
  1. Je vous mets le lien du rapport obtenu avec virustotal

    http://www.virustotal.com/file-scan/report.html?id=f6b4d18fa0d3c4958711ac0d476c21a6fdf2897f989a0ad290b43f463dd8b5b0-1315347722
    0
    1. salut quels sont les symptomes en fait ?
      0
      1. Salut,

        Un message d'erreur me disant que wininit.exe a cessé de fonctionner, des plantages de mon navigateur, des message me disant que mes pilotes graphique ont un problème et des écran noirs.
        J'ai pas en tête exactement les textes des messages mais je l'ai écrirais lorsqu'ils réapparaitront. ;-)
        Les symptomes sont apparuent lorsque j'ai lancé un scan minutieux avec avast!
        0
        1. ▶ Télécharge Reload_TDSSKiller

          ▶ Lance le

          choisis : lancer le nettoyage

          l'outil va automatiquement télécharger la derniere version puis

          TDSSKiller va s'ouvrir , clique sur "Start Scan"

          Si TDSS.tdl2 est détecté l''option delete sera cochée par défaut.
          Si TDSS.tdl3 est détecté assure toi que Cure est bien cochée.
          Si TDSS.tdl4(\HardDisk0\MBR) est détecté assure toi que Cure est bien cochée.
          Si Suspicious file est indiqué, laisse l''option cochée sur Skip
          Si Rootkit.Win32.ZAccess.* est détecté règle sur "cure" en haut , et "delete" en bas

          une fois qu'il a terminé , redemarre s'il te le demande pour finir de nettoyer

          sinon , ferme tdssKiller et le rapport s'affichera sur le bureau

          ▶ Copie/Colle son contenu dans ta prochaine réponse.
          0
          1. Bonjour,

            Merci pour ton aide et voilà le rapport:


            -------------------------------------------------------------------------------

            2011/09/07 09:40:55.0485 1840 TDSS rootkit removing tool 2.5.19.0 Sep 6 2011 19:23:56
            2011/09/07 09:40:55.0594 1840 ================================================================================
            2011/09/07 09:40:55.0594 1840 SystemInfo:
            2011/09/07 09:40:55.0594 1840
            2011/09/07 09:40:55.0594 1840 OS Version: 6.1.7601 ServicePack: 1.0
            2011/09/07 09:40:55.0594 1840 Product type: Workstation
            2011/09/07 09:40:55.0594 1840 ComputerName: CARLOS-PC
            2011/09/07 09:40:55.0594 1840 UserName: Carlos
            2011/09/07 09:40:55.0594 1840 Windows directory: C:\Windows
            2011/09/07 09:40:55.0594 1840 System windows directory: C:\Windows
            2011/09/07 09:40:55.0594 1840 Running under WOW64
            2011/09/07 09:40:55.0594 1840 Processor architecture: Intel x64
            2011/09/07 09:40:55.0594 1840 Number of processors: 2
            2011/09/07 09:40:55.0594 1840 Page size: 0x1000
            2011/09/07 09:40:55.0594 1840 Boot type: Normal boot
            2011/09/07 09:40:55.0594 1840 ================================================================================
            2011/09/07 09:40:56.0684 1840 Initialize success
            2011/09/07 09:40:59.0908 5704 ================================================================================
            2011/09/07 09:40:59.0908 5704 Scan started
            2011/09/07 09:40:59.0908 5704 Mode: Manual;
            2011/09/07 09:40:59.0908 5704 ================================================================================
            2011/09/07 09:41:01.0749 5704 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
            2011/09/07 09:41:01.0827 5704 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
            2011/09/07 09:41:01.0954 5704 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
            2011/09/07 09:41:02.0054 5704 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
            2011/09/07 09:41:02.0114 5704 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
            2011/09/07 09:41:02.0164 5704 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
            2011/09/07 09:41:02.0344 5704 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
            2011/09/07 09:41:02.0414 5704 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
            2011/09/07 09:41:02.0524 5704 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
            2011/09/07 09:41:02.0564 5704 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
            2011/09/07 09:41:02.0624 5704 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
            2011/09/07 09:41:02.0654 5704 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
            2011/09/07 09:41:02.0734 5704 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
            2011/09/07 09:41:02.0804 5704 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
            2011/09/07 09:41:02.0864 5704 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
            2011/09/07 09:41:03.0054 5704 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
            2011/09/07 09:41:03.0214 5704 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
            2011/09/07 09:41:03.0244 5704 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
            2011/09/07 09:41:03.0344 5704 AsDsm (88fbc8bebfd38566235eaa5e4dbc4e05) C:\Windows\system32\drivers\AsDsm.sys
            2011/09/07 09:41:03.0414 5704 ASMMAP64 (2db34edd17d3a8da7105a19c95a3dd68) C:\Program Files\ATKGFNEX\ASMMAP64.sys
            2011/09/07 09:41:03.0594 5704 aswFsBlk (1f4c94c932a7082cdbec61cc56a16e0c) C:\Windows\system32\drivers\aswFsBlk.sys
            2011/09/07 09:41:03.0714 5704 aswFW (b4dde5ea73e2d95a7832c6daedfce97b) C:\Windows\system32\drivers\aswFW.sys
            2011/09/07 09:41:03.0754 5704 aswMonFlt (51507b345c9074c5449d2cacbe21b824) C:\Windows\system32\drivers\aswMonFlt.sys
            2011/09/07 09:41:03.0844 5704 aswNdis (44b635cb67240d492cdd8870649dfc21) C:\Windows\system32\DRIVERS\aswNdis.sys
            2011/09/07 09:41:03.0924 5704 aswRdr (9cf7b963c7ebb77338f85f6a21e78bda) C:\Windows\system32\drivers\aswRdr.sys
            2011/09/07 09:41:04.0024 5704 aswSnx (28a9f9bf5eb1332f9199504035ff1f8a) C:\Windows\system32\drivers\aswSnx.sys
            2011/09/07 09:41:04.0084 5704 aswSP (fde2ae82f0ed9eb1b4cf5ec2051caaaf) C:\Windows\system32\drivers\aswSP.sys
            2011/09/07 09:41:04.0114 5704 aswTdi (797d64231064046e81c6c53a79f6e7f7) C:\Windows\system32\drivers\aswTdi.sys
            2011/09/07 09:41:04.0194 5704 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
            2011/09/07 09:41:04.0284 5704 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
            2011/09/07 09:41:04.0364 5704 athr (0acc06fcf46f64ed4f11e57ee461c1f4) C:\Windows\system32\DRIVERS\athrx.sys
            2011/09/07 09:41:04.0554 5704 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
            2011/09/07 09:41:04.0604 5704 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
            2011/09/07 09:41:04.0654 5704 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
            2011/09/07 09:41:04.0754 5704 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
            2011/09/07 09:41:04.0864 5704 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
            2011/09/07 09:41:04.0904 5704 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
            2011/09/07 09:41:04.0934 5704 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
            2011/09/07 09:41:04.0994 5704 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
            2011/09/07 09:41:05.0044 5704 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
            2011/09/07 09:41:05.0124 5704 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
            2011/09/07 09:41:05.0164 5704 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
            2011/09/07 09:41:05.0194 5704 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
            2011/09/07 09:41:05.0254 5704 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
            2011/09/07 09:41:05.0344 5704 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
            2011/09/07 09:41:05.0454 5704 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
            2011/09/07 09:41:05.0504 5704 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
            2011/09/07 09:41:05.0664 5704 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
            2011/09/07 09:41:05.0734 5704 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
            2011/09/07 09:41:05.0814 5704 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys
            2011/09/07 09:41:05.0934 5704 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
            2011/09/07 09:41:06.0004 5704 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
            2011/09/07 09:41:06.0114 5704 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
            2011/09/07 09:41:06.0274 5704 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
            2011/09/07 09:41:06.0354 5704 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
            2011/09/07 09:41:06.0404 5704 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
            2011/09/07 09:41:06.0554 5704 driverhardwarev2x64 (b28c853770c995552b9f5760d8245f44) C:\Program Files\ma-config.com\Drivers\driverhardwarev2x64.sys
            2011/09/07 09:41:06.0644 5704 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
            2011/09/07 09:41:06.0734 5704 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
            2011/09/07 09:41:06.0874 5704 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
            2011/09/07 09:41:07.0044 5704 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
            2011/09/07 09:41:07.0094 5704 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
            2011/09/07 09:41:07.0204 5704 ETD (1299d1ea00b7a4bf69c5869dca31e0f6) C:\Windows\system32\DRIVERS\ETD.sys
            2011/09/07 09:41:07.0254 5704 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
            2011/09/07 09:41:07.0294 5704 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
            2011/09/07 09:41:07.0344 5704 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
            2011/09/07 09:41:07.0414 5704 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
            2011/09/07 09:41:07.0444 5704 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
            2011/09/07 09:41:07.0574 5704 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
            2011/09/07 09:41:07.0654 5704 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
            2011/09/07 09:41:07.0724 5704 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
            2011/09/07 09:41:07.0764 5704 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
            2011/09/07 09:41:07.0864 5704 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
            2011/09/07 09:41:07.0914 5704 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
            2011/09/07 09:41:08.0004 5704 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
            2011/09/07 09:41:08.0194 5704 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
            2011/09/07 09:41:08.0304 5704 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
            2011/09/07 09:41:08.0384 5704 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
            2011/09/07 09:41:08.0424 5704 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
            2011/09/07 09:41:08.0464 5704 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
            2011/09/07 09:41:08.0494 5704 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
            2011/09/07 09:41:08.0664 5704 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\drivers\hidusb.sys
            2011/09/07 09:41:08.0774 5704 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
            2011/09/07 09:41:08.0864 5704 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
            2011/09/07 09:41:08.0924 5704 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
            2011/09/07 09:41:09.0034 5704 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
            2011/09/07 09:41:09.0144 5704 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
            2011/09/07 09:41:09.0204 5704 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
            2011/09/07 09:41:09.0414 5704 IntcAzAudAddService (718a4008ee5da174400396b27509ef82) C:\Windows\system32\drivers\RTKVHD64.sys
            2011/09/07 09:41:09.0494 5704 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
            2011/09/07 09:41:09.0594 5704 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
            2011/09/07 09:41:09.0684 5704 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
            2011/09/07 09:41:09.0764 5704 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
            2011/09/07 09:41:09.0814 5704 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
            2011/09/07 09:41:09.0944 5704 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
            2011/09/07 09:41:10.0014 5704 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
            2011/09/07 09:41:10.0064 5704 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
            2011/09/07 09:41:10.0164 5704 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
            2011/09/07 09:41:10.0234 5704 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
            2011/09/07 09:41:10.0324 5704 kbfiltr (e63ef8c3271d014f14e2469ce75fecb4) C:\Windows\system32\DRIVERS\kbfiltr.sys
            2011/09/07 09:41:10.0414 5704 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys
            2011/09/07 09:41:10.0504 5704 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys
            2011/09/07 09:41:10.0584 5704 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
            2011/09/07 09:41:10.0804 5704 LHidFilt (1074c77a47835e03c15bf92452f9a750) C:\Windows\system32\DRIVERS\LHidFilt.Sys
            2011/09/07 09:41:10.0874 5704 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
            2011/09/07 09:41:10.0974 5704 LMouFilt (96999c364c649e2866a268f7420a304a) C:\Windows\system32\DRIVERS\LMouFilt.Sys
            2011/09/07 09:41:11.0114 5704 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
            2011/09/07 09:41:11.0154 5704 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
            2011/09/07 09:41:11.0204 5704 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
            2011/09/07 09:41:11.0314 5704 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
            2011/09/07 09:41:11.0404 5704 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
            2011/09/07 09:41:11.0534 5704 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
            2011/09/07 09:41:11.0594 5704 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
            2011/09/07 09:41:11.0664 5704 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
            2011/09/07 09:41:11.0764 5704 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
            2011/09/07 09:41:11.0834 5704 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
            2011/09/07 09:41:11.0914 5704 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
            2011/09/07 09:41:11.0984 5704 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
            2011/09/07 09:41:12.0044 5704 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
            2011/09/07 09:41:12.0094 5704 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
            2011/09/07 09:41:12.0174 5704 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
            2011/09/07 09:41:12.0234 5704 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
            2011/09/07 09:41:12.0294 5704 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
            2011/09/07 09:41:12.0334 5704 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
            2011/09/07 09:41:12.0394 5704 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
            2011/09/07 09:41:12.0454 5704 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
            2011/09/07 09:41:12.0534 5704 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
            2011/09/07 09:41:12.0604 5704 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
            2011/09/07 09:41:12.0664 5704 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
            2011/09/07 09:41:12.0794 5704 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
            2011/09/07 09:41:12.0844 5704 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
            2011/09/07 09:41:12.0874 5704 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
            2011/09/07 09:41:12.0954 5704 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
            2011/09/07 09:41:13.0054 5704 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
            2011/09/07 09:41:13.0184 5704 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
            2011/09/07 09:41:13.0254 5704 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
            2011/09/07 09:41:13.0334 5704 MTsensor (032d35c996f21d19a205a7c8f0b76f3c) C:\Windows\system32\DRIVERS\ATK64AMD.sys
            2011/09/07 09:41:13.0414 5704 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
            2011/09/07 09:41:13.0494 5704 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
            2011/09/07 09:41:13.0624 5704 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
            2011/09/07 09:41:13.0724 5704 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
            2011/09/07 09:41:13.0814 5704 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
            2011/09/07 09:41:13.0884 5704 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
            2011/09/07 09:41:13.0964 5704 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
            2011/09/07 09:41:14.0024 5704 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
            2011/09/07 09:41:14.0214 5704 Netaapl (307bc83250fc8e3b2878d81e7d760299) C:\Windows\system32\DRIVERS\netaapl64.sys
            2011/09/07 09:41:14.0264 5704 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
            2011/09/07 09:41:14.0324 5704 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
            2011/09/07 09:41:14.0474 5704 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
            2011/09/07 09:41:14.0514 5704 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
            2011/09/07 09:41:14.0564 5704 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
            2011/09/07 09:41:14.0674 5704 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
            2011/09/07 09:41:14.0734 5704 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
            2011/09/07 09:41:14.0804 5704 NVHDA (960e39a54e525df58cb29193147dffa1) C:\Windows\system32\drivers\nvhda64v.sys
            2011/09/07 09:41:15.0154 5704 nvlddmkm (cc1efea1f0ab17e59bd4b5baff3e5cb0) C:\Windows\system32\DRIVERS\nvlddmkm.sys
            2011/09/07 09:41:15.0364 5704 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
            2011/09/07 09:41:15.0464 5704 nvsmu (61a59fb62864eb3f32d24985a505ce03) C:\Windows\system32\DRIVERS\nvsmu.sys
            2011/09/07 09:41:15.0524 5704 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
            2011/09/07 09:41:15.0574 5704 nvstor64 (71b6ecd3c56fbf12fb1968da3953b703) C:\Windows\system32\DRIVERS\nvstor64.sys
            2011/09/07 09:41:15.0694 5704 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
            2011/09/07 09:41:15.0764 5704 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
            2011/09/07 09:41:15.0854 5704 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
            2011/09/07 09:41:15.0924 5704 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
            2011/09/07 09:41:15.0994 5704 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
            2011/09/07 09:41:16.0064 5704 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
            2011/09/07 09:41:16.0114 5704 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
            2011/09/07 09:41:16.0144 5704 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
            2011/09/07 09:41:16.0194 5704 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
            2011/09/07 09:41:16.0464 5704 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
            2011/09/07 09:41:16.0514 5704 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
            2011/09/07 09:41:16.0714 5704 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
            2011/09/07 09:41:16.0804 5704 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
            2011/09/07 09:41:16.0854 5704 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
            2011/09/07 09:41:16.0904 5704 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
            2011/09/07 09:41:16.0944 5704 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
            2011/09/07 09:41:17.0024 5704 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
            2011/09/07 09:41:17.0114 5704 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
            2011/09/07 09:41:17.0224 5704 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
            2011/09/07 09:41:17.0254 5704 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
            2011/09/07 09:41:17.0334 5704 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
            2011/09/07 09:41:17.0384 5704 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
            2011/09/07 09:41:17.0414 5704 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
            2011/09/07 09:41:17.0485 5704 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
            2011/09/07 09:41:17.0532 5704 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
            2011/09/07 09:41:17.0594 5704 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
            2011/09/07 09:41:17.0672 5704 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
            2011/09/07 09:41:17.0828 5704 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
            2011/09/07 09:41:17.0890 5704 RTL8167 (b49dc435ae3695bac5623dd94b05732d) C:\Windows\system32\DRIVERS\Rt64win7.sys
            2011/09/07 09:41:17.0953 5704 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
            2011/09/07 09:41:18.0109 5704 SCDEmu (07237c66e05da6778e9f3cb67fa00736) C:\Windows\system32\drivers\SCDEmu.sys
            2011/09/07 09:41:18.0171 5704 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
            2011/09/07 09:41:18.0327 5704 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
            2011/09/07 09:41:18.0405 5704 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
            2011/09/07 09:41:18.0452 5704 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
            2011/09/07 09:41:18.0514 5704 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
            2011/09/07 09:41:18.0608 5704 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
            2011/09/07 09:41:18.0655 5704 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
            2011/09/07 09:41:18.0686 5704 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
            2011/09/07 09:41:18.0748 5704 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
            2011/09/07 09:41:18.0858 5704 SiSGbeLH (1bc348cf6baa90ec8e533ef6e6a69933) C:\Windows\system32\DRIVERS\SiSG664.sys
            2011/09/07 09:41:18.0904 5704 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
            2011/09/07 09:41:18.0967 5704 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
            2011/09/07 09:41:19.0029 5704 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
            2011/09/07 09:41:19.0223 5704 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
            2011/09/07 09:41:19.0413 5704 sptd (602884696850c86434530790b110e8eb) C:\Windows\system32\Drivers\sptd.sys
            2011/09/07 09:41:19.0413 5704 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 602884696850c86434530790b110e8eb
            2011/09/07 09:41:19.0433 5704 sptd - detected LockedFile.Multi.Generic (1)
            2011/09/07 09:41:19.0493 5704 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
            2011/09/07 09:41:19.0563 5704 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
            2011/09/07 09:41:19.0613 5704 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
            2011/09/07 09:41:19.0783 5704 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
            2011/09/07 09:41:19.0853 5704 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
            2011/09/07 09:41:20.0003 5704 Tcpip (f0e98c00a09fdf791525829a1d14240f) C:\Windows\system32\drivers\tcpip.sys
            2011/09/07 09:41:20.0523 5704 TCPIP6 (f0e98c00a09fdf791525829a1d14240f) C:\Windows\system32\DRIVERS\tcpip.sys
            2011/09/07 09:41:20.0923 5704 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
            2011/09/07 09:41:21.0373 5704 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
            2011/09/07 09:41:21.0673 5704 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
            2011/09/07 09:41:21.0873 5704 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
            2011/09/07 09:41:22.0013 5704 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
            2011/09/07 09:41:22.0433 5704 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
            2011/09/07 09:41:22.0843 5704 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
            2011/09/07 09:41:23.0263 5704 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
            2011/09/07 09:41:23.0663 5704 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
            2011/09/07 09:41:24.0073 5704 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
            2011/09/07 09:41:24.0423 5704 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
            2011/09/07 09:41:24.0733 5704 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
            2011/09/07 09:41:24.0983 5704 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
            2011/09/07 09:41:25.0473 5704 USBAAPL64 (54d4b48d443e7228bf64cf7cdc3118ac) C:\Windows\system32\Drivers\usbaapl64.sys
            2011/09/07 09:41:25.0793 5704 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
            2011/09/07 09:41:26.0053 5704 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
            2011/09/07 09:41:26.0133 5704 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
            2011/09/07 09:41:26.0183 5704 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
            2011/09/07 09:41:26.0213 5704 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\DRIVERS\usbohci.sys
            2011/09/07 09:41:26.0333 5704 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
            2011/09/07 09:41:26.0393 5704 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
            2011/09/07 09:41:26.0463 5704 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
            2011/09/07 09:41:26.0513 5704 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
            2011/09/07 09:41:26.0643 5704 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\system32\Drivers\usbvideo.sys
            2011/09/07 09:41:26.0743 5704 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
            2011/09/07 09:41:26.0803 5704 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
            2011/09/07 09:41:26.0843 5704 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
            2011/09/07 09:41:26.0913 5704 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
            2011/09/07 09:41:26.0983 5704 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
            2011/09/07 09:41:27.0063 5704 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
            2011/09/07 09:41:27.0133 5704 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
            2011/09/07 09:41:27.0213 5704 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
            2011/09/07 09:41:27.0263 5704 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
            2011/09/07 09:41:27.0313 5704 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
            2011/09/07 09:41:27.0353 5704 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
            2011/09/07 09:41:27.0413 5704 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
            2011/09/07 09:41:27.0543 5704 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
            2011/09/07 09:41:27.0573 5704 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
            2011/09/07 09:41:27.0753 5704 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
            2011/09/07 09:41:27.0803 5704 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
            2011/09/07 09:41:27.0983 5704 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
            2011/09/07 09:41:28.0043 5704 WimFltr (52ded146e4797e6ccf94799e8e22bb2a) C:\Windows\system32\DRIVERS\wimfltr.sys
            2011/09/07 09:41:28.0083 5704 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
            2011/09/07 09:41:28.0303 5704 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
            2011/09/07 09:41:28.0473 5704 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
            2011/09/07 09:41:28.0643 5704 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
            2011/09/07 09:41:28.0743 5704 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
            2011/09/07 09:41:28.0823 5704 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
            2011/09/07 09:41:28.0933 5704 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
            2011/09/07 09:41:28.0983 5704 Boot (0x1200) (f88a58317dfbea2a116f89c2a8ffc964) \Device\Harddisk0\DR0\Partition0
            2011/09/07 09:41:29.0033 5704 Boot (0x1200) (fec08a70594905e5a3a8e3d9e9f55914) \Device\Harddisk0\DR0\Partition1
            2011/09/07 09:41:29.0043 5704 ================================================================================
            2011/09/07 09:41:29.0043 5704 Scan finished
            2011/09/07 09:41:29.0043 5704 ================================================================================
            2011/09/07 09:41:29.0073 4980 Detected object count: 1
            2011/09/07 09:41:29.0073 4980 Actual detected object count: 1
            2011/09/07 09:41:31.0013 4980 LockedFile.Multi.Generic(sptd) - User select action: Skip
            2011/09/07 09:41:35.0243 2316 Deinitialize success
            0
            1. Sinon j'ai fais une capture d'écran du message d'erreur

              http://img69.imageshack.us/img69/699/wininiitexecapturemessa.png

              J'essaie de faire une capture du message d'erreur du pilote graphique dès que je le chope et je le mettrais ici, si ça peut aider à résoudre le problème.
              0
              1. ah y'a 2 "i" collés à wininit donc c'est pas celui d'origine

                Télécharge ici :OTL

                enregistre le sur ton Bureau.

                si tu as XP => double clique
                si tu as Vista ou windows 7 => clic droit "executer en tant que...."


                sur OTL.exe pour le lancer.

                => Clique ici pour voir la Configuration

                ▶Clic sur Analyse.

                A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

                Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

                ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

                Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

                ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

                ▶ Clique sur Ouvrir.

                ▶ Clique sur "Cliquez ici pour déposer le fichier".

                juste au niveau du bouton , en fin de chargement du fichier , Un lien de cette forme apparaitra :

                http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

                ▶ Copie ce lien dans ta réponse.

                ▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
                0
                1. Re-salut,

                  Oui désolé pour "l'ortographe" de wininiit j'ai pas fais bien attention.

                  Voilà le premier lien pour le fichier OTL:

                  http://www.cijoint.fr/cjlink.php?file=cj201109/cij24biV4E.txt

                  Et voilà le deuxième pour le fichier Extras:

                  http://www.cijoint.fr/cjlink.php?file=cj201109/cij2cIpWPp.txt

                  J'espère avoir tout fait correctement
                  0
                  1. Ah!! j'ai réussi à choper une capture d'écran du message d'erreur sur mon pilote graphique, c'est le message en bas à droite au moment ou je faisais la manip' que tu m'as indiquée.

                    http://img847.imageshack.us/img847/2414/messageplantagepiloteda.png
                    0
                    1. Télécharge et enregistre ADWcleaner sur ton bureau :

                      ADWCleaner (Merci à Xplode)

                      Lance le,

                      clique sur suppression et poste son rapport.

                      ======================================

                      ▶ Télécharge ici : USBFIX sur ton bureau

                      branche tous tes periphériques sans les ouvrir

                      /!\ Désactive provisoirement et seulement le temps de l'utilisation d'USBFIX, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

                      si tu as XP => double clique
                      si tu as Vista ou windows 7 => clic droit "executer en tant que...."


                      sur l'icône Usbfix située sur ton Bureau.
                      Sur la page, clique sur le bouton :

                      ▶ choisi l option Suppression

                      ▶ UsbFix scannera ton pc , laisse travailler l outil.

                      ▶ Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

                      ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                      ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                      0
                      1. Voici le rapport de AdwCleaner:

                        # AdwCleaner v1.304 - Rapport créé le 07/09/2011 à 18:07:50
                        # Mis à jour le 05/09/11 à 14h30 par Xplode
                        # Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
                        # Nom d'utilisateur : Carlos - CARLOS-PC (Administrateur)
                        # Exécuté depuis : C:\Users\Carlos\Desktop\Downloads\adwcleaner.exe
                        # Option [Suppression]

                        ***** [KillNav] *****

                        # chrome.exe [PID:4992] -> Tué
                        # firefox.exe [PID:2848] -> Tué

                        ***** [Processus] *****

                        ***** [Services] *****

                        ***** [Fichiers / Dossiers] *****

                        ***** [Registre] *****

                        ***** [Registre (64 bits)] *****

                        ***** [Navigateurs] *****

                        -\\ Internet Explorer v8.0.7601.17514

                        [OK] Le registre ne contient aucune entrée illégitime.

                        -\\ Mozilla Firefox v3.6.2pre (fr)

                        Profil : p7ifvncg.default
                        Fichier : C:\Users\Carlos\AppData\Roaming\Mozilla\Firefox\Profiles\p7ifvncg.default\prefs.js

                        [OK] Le fichier ne contient aucune entrée illégitime.

                        -\\ Google Chrome v [Impossible d'obtenir la version]

                        Fichier : C:\Users\Carlos\AppData\Local\Google\Chrome\User Data\Default\Preferences

                        [OK] Le fichier ne contient aucune entrée illégitime.

                        *************************

                        AdwCleaner[S1].txt - [1168 octets] - [07/09/2011 18:07:50]

                        ########## EOF - C:\AdwCleaner[S1].txt - [1296 octets] ##########

                        Je passe à la manip' avec USBFIX à tout de suite...
                        0
                        1. ############################## | UsbFix 7.058 | [Suppression]

                          Utilisateur: Carlos (Administrateur) # CARLOS-PC [ASUSTeK Computer Inc. K61IC]
                          Mis à jour le 24/08/2011 par El Desaparecido
                          Lancé à 18:17:16 | 07/09/2011
                          Site Web: http://www.teamxscript.org
                          Submit your sample: http://www.teamxscript.org/Upload.php

                          CPU: Intel(R) Core(TM)2 Duo CPU T5900 @ 2.20GHz
                          CPU 2: Intel(R) Core(TM)2 Duo CPU T5900 @ 2.20GHz
                          Microsoft Windows 7 Édition Familiale Premium (6.1.7601 64-Bit) # Service Pack 1
                          Internet Explorer 8.0.7601.17514

                          Pare-feu Windows: Activé
                          RAM -> 4095 Mo
                          C:\ (%systemdrive%) -> Disque fixe # 233 Go (71 Go libre(s) - 31%) [OS] # NTFS
                          D:\ -> Disque fixe # 218 Go (91 Go libre(s) - 42%) [DATA] # NTFS
                          E:\ -> CD-ROM
                          F:\ -> CD-ROM
                          G:\ -> CD-ROM

                          ################## | Éléments infectieux |

                          Supprimé! C:\Users\Carlos\AppData\Local\Temp\MSN.abc
                          Supprimé! C:\Users\Carlos\AppData\Local\Temp\XxX.xXx
                          Supprimé! C:\Users\Carlos\AppData\Local\Temp\xxxyyyzzz.dat
                          Supprimé! C:\$RECYCLE.BIN\S-1-5-20
                          Supprimé! C:\$RECYCLE.BIN\S-1-5-21-2612661552-4213280396-732593824-1001
                          Supprimé! D:\$RECYCLE.BIN\S-1-5-21-2612661552-4213280396-732593824-1001
                          Supprimé! D:\$RECYCLE.BIN\S-1-5-21-2612661552-4213280396-732593824-500

                          ################## | Registre |

                          Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|HKCU
                          Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Run|HKLM

                          ################## | Mountpoints2 |

                          Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{e502131a-f30c-11de-8b46-90e6ba745c7c}

                          ################## | Listing |

                          [07/09/2011 - 18:21:46 | SHD ] C:\$Recycle.Bin
                          [15/06/2009 - 13:11:59 | N | 54] C:\AdobeReader.log
                          [07/09/2011 - 18:08:06 | N | 1297] C:\AdwCleaner[S1].txt
                          [05/12/2009 - 13:32:22 | D ] C:\asus.dat
                          [15/07/2011 - 21:44:53 | D ] C:\Boot
                          [20/11/2010 - 14:40:07 | RASH | 383786] C:\bootmgr
                          [29/07/2009 - 08:03:37 | N | 8192] C:\BOOTSECT.BAK
                          [03/09/2011 - 03:03:15 | D ] C:\Config.Msi
                          [14/10/2009 - 07:02:27 | N | 12801] C:\devlist.txt
                          [14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings
                          [14/10/2009 - 07:02:27 | N | 9] C:\Finish.log
                          [26/03/2010 - 21:47:50 | D ] C:\gPotato.eu
                          [07/09/2011 - 00:05:13 | ASH | 3220647936] C:\hiberfil.sys
                          [14/09/2009 - 09:56:55 | N | 18] C:\K61IC_K70IC_WIN7.10
                          [11/09/2009 - 15:10:53 | N | 1048576] C:\K70IC.BIN
                          [14/10/2009 - 06:15:18 | RHD ] C:\MSOCache
                          [02/07/2009 - 09:17:15 | N | 37] C:\Nero.Log
                          [02/09/2011 - 16:01:58 | D ] C:\NVIDIA
                          [12/06/2009 - 03:32:00 | N | 57] C:\OFFICE2007_L.TXT
                          [07/09/2011 - 00:05:18 | ASH | 4294201344] C:\pagefile.sys
                          [13/10/2009 - 18:17:57 | N | 146] C:\Pass.txt
                          [01/09/2009 - 04:54:37 | N | 3750] C:\Patch.LOG
                          [14/07/2009 - 05:20:08 | D ] C:\PerfLogs
                          [07/09/2011 - 00:04:26 | D ] C:\perlb
                          [02/09/2011 - 16:19:53 | D ] C:\Program Files
                          [27/08/2011 - 19:46:17 | D ] C:\Program Files (x86)
                          [07/09/2011 - 00:04:24 | HD ] C:\ProgramData
                          [05/12/2009 - 13:18:12 | SHD ] C:\Recovery
                          [14/09/2009 - 09:56:55 | N | 14] C:\RECOVERY.DAT
                          [14/10/2009 - 06:48:13 | N | 3240] C:\RHDSetup.log
                          [14/10/2009 - 06:52:53 | N | 90] C:\setup.log
                          [14/05/2006 - 10:22:24 | N | 5] C:\store.log
                          [14/10/2009 - 06:38:33 | N | 170] C:\SumHidd.txt
                          [14/10/2009 - 06:37:16 | N | 98] C:\SumOS.txt
                          [06/09/2011 - 22:31:21 | N | 271] C:\sv.bat
                          [06/09/2011 - 22:31:21 | N | 373760] C:\svchoost.exe
                          [07/09/2011 - 03:01:10 | SHD ] C:\System Volume Information
                          [07/09/2011 - 18:21:46 | D ] C:\UsbFix
                          [07/09/2011 - 18:16:24 | A | 3522] C:\UsbFix.txt
                          [15/05/2011 - 00:31:19 | D ] C:\Users
                          [07/09/2009 - 13:59:54 | N | 25] C:\v811.txt
                          [09/01/2011 - 14:40:25 | D ] C:\Warhammer Online - Age of Reckoning
                          [07/09/2011 - 00:40:14 | D ] C:\Windows
                          [07/09/2011 - 18:21:46 | SHDC ] D:\$RECYCLE.BIN
                          [06/09/2011 - 20:04:29 | DC ] D:\Downloads
                          [07/11/2007 - 08:00:40 | C | 17734] D:\eula.1028.txt
                          [07/11/2007 - 08:00:40 | C | 17734] D:\eula.1031.txt
                          [07/11/2007 - 08:00:40 | C | 10134] D:\eula.1033.txt
                          [07/11/2007 - 08:00:40 | C | 17734] D:\eula.1036.txt
                          [07/11/2007 - 08:00:40 | C | 17734] D:\eula.1040.txt
                          [07/11/2007 - 08:00:40 | C | 118] D:\eula.1041.txt
                          [07/11/2007 - 08:00:40 | C | 17734] D:\eula.1042.txt
                          [07/11/2007 - 08:00:40 | C | 17734] D:\eula.2052.txt
                          [07/11/2007 - 08:00:40 | C | 17734] D:\eula.3082.txt
                          [07/11/2007 - 08:00:40 | C | 1110] D:\globdata.ini
                          [07/11/2007 - 08:03:18 | C | 562688] D:\install.exe
                          [07/11/2007 - 08:00:40 | C | 843] D:\install.ini
                          [07/11/2007 - 08:03:18 | C | 76304] D:\install.res.1028.dll
                          [07/11/2007 - 08:03:18 | C | 96272] D:\install.res.1031.dll
                          [07/11/2007 - 08:03:18 | C | 91152] D:\install.res.1033.dll
                          [07/11/2007 - 08:03:18 | C | 97296] D:\install.res.1036.dll
                          [07/11/2007 - 08:03:18 | C | 95248] D:\install.res.1040.dll
                          [07/11/2007 - 08:03:18 | C | 81424] D:\install.res.1041.dll
                          [07/11/2007 - 08:03:18 | C | 79888] D:\install.res.1042.dll
                          [07/11/2007 - 08:03:18 | C | 75792] D:\install.res.2052.dll
                          [07/11/2007 - 08:03:18 | C | 96272] D:\install.res.3082.dll
                          [26/03/2010 - 18:01:59 | DC ] D:\MIGWEL
                          [26/02/2010 - 16:47:50 | DC ] D:\Program Files (x86)
                          [14/10/2009 - 06:04:51 | SHDC ] D:\System Volume Information
                          [17/01/2010 - 22:00:53 | DC ] D:\the ultimate warhammer 40k painting guides
                          [07/11/2007 - 08:00:40 | C | 5686] D:\vcredist.bmp
                          [07/11/2007 - 08:09:22 | C | 1442522] D:\VC_RED.cab
                          [07/11/2007 - 08:12:28 | C | 232960] D:\VC_RED.MSI
                          [01/01/1995 - 02:00:00 | R | 44] E:\Track01.cda
                          [01/01/1995 - 02:00:00 | R | 44] E:\Track02.cda
                          [01/01/1995 - 02:00:00 | R | 44] E:\Track03.cda
                          [01/01/1995 - 02:00:00 | R | 44] E:\Track04.cda
                          [01/01/1995 - 02:00:00 | R | 44] E:\Track05.cda
                          [01/01/1995 - 02:00:00 | R | 44] E:\Track06.cda
                          [01/01/1995 - 02:00:00 | R | 44] E:\Track07.cda
                          [01/01/1995 - 02:00:00 | R | 44] E:\Track08.cda
                          [01/01/1995 - 02:00:00 | R | 44] E:\Track09.cda
                          [01/01/1995 - 02:00:00 | R | 44] E:\Track10.cda

                          ################## | Vaccin |

                          C:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)
                          D:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)

                          ################## | Upload |

                          Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_CARLOS-PC.zip
                          http://www.teamxscript.org/Upload.php
                          Merci de votre contribution.

                          ################## | E.O.F |
                          0
                          1. Je viens de redémarrer et toujours le message d'erreur du pilote graphique et des écran noirs
                            0
                            1. desactive ton antivirus
                              desactive Windows defender si présent
                              desactive ton pare-feu

                              Ferme toutes tes appilications en cours

                              telecharge et enregistre ceci sur ton bureau :

                              Pre_Scan

                              si le lien ne fonctionne pas :

                              http://www.archive-host.com

                              s'il n'est pas sur ton bureau coupe-le de ton dossier telechargements et colle-le sur ton bureau

                              Avertissement: Il y aura une extinction du bureau pendant le scan --> pas de panique.

                              une fois telechargé lance-le , laisse faire le scan jusqu'à l'apparition de "Pre_scan.txt" sur le bureau.

                              si 'outil est bloqué par l'infection utilise cette version : Version .pif

                              si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"

                              si l'outil semble ne pas avoir fonctionné renomme-le winlogon , ou change son extension en .com ou .scr

                              Il se peut qu'une multitude de fenêtres noires clignotent , laisse-le travailler

                              Poste Pre_Scan_la_date_et_l'heure.txt qui apparaitra sur le bureau en fin de scan

                              ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

                              clique sur ce lien : http://www.cijoint.fr/

                              ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

                              ▶ Clique sur Ouvrir.

                              ▶ Clique sur "Cliquez ici pour déposer le fichier".

                              Un lien de cette forme :

                              http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

                              est ajouté dans la page.

                              ▶ Copie ce lien dans ta réponse.

                              si ton bureau ne reapparait pas => ctrl+alt+supp , gestionnaire des taches => onglet fichier => nouvelle tache puis tape explorer
                              0
                              1. Voilà le rapport de prescan

                                http://www.cijoint.fr/cjlink.php?file=cj201109/cij7LUitn8.txt

                                Au passage j'ai encore eu le message d'erreur de wininiit.exe
                                0
                                1. Fais analyser le(s) fichier(s) suivants sur Virustotal :

                                  Virus Total

                                  clique sur "Parcourir" et trouve puis selectionne ce(s) fichier(s) :

                                  C:\perlb\svhost.exe

                                  * Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
                                  * Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
                                  * Lorsque l'analyse est terminée colle le lien de(s)( la) page(s) dans ta prochaine réponse.
                                  0
                                  1. Voila le résultat:

                                    http://www.virustotal.com/file-scan/report.html?id=a08ccdfcb6d94a73a6c8ab39d7381d71c19fe80aa1ba66697f9c727cb2926568-1315421488
                                    0
                                    1. ......c'est à toi ce truc-là ?
                                      0
                                      1. ok je connaissais pas...

                                        et vu le resultat de virus total....

                                        =====================

                                        je regarde ton log
                                        0
                                        • 1
                                        • 2
                                        • 3