This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe hogging memory, and other Trojans

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello there, I'm on Windows XP, using Avira and Malwarebytes Anti-Malware. It started a few hours ago, Avira kept detecting 'HTML/Infected.WebPage.Gen' or 'TR/Gendal.KD.390280' every few minutes. I performed 2 quick scans with MWAW, deleting some Trojans in the process. Avira no longer detects trojans every 5 minutes, but now there's a highly suspisicous ping.exe process that is always running. It comes back after a while if I terminate it. I'd greatly appreciate any help to get rid of that thing! Here is HijackThis log: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 18:43:03, on 2011-11-06 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Program Files\Avira\AntiVir Desktop\avshadow.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe D:\Jeux\Steam\steam.exe C:\Program Files\DAEMON Tools Lite\DTLite.exe C:\Documents and Settings\Antoine\Application Data\Dropbox\bin\Dropbox.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\WINDOWS\system32\HPSIsvc.exe C:\WINDOWS\system32\lkads.exe C:\Program Files\National Instruments\MAX\nimxs.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\system32\lkcitdl.exe C:\WINDOWS\system32\lktsrv.exe C:\WINDOWS\system32\WTablet\TabUserW.exe C:\WINDOWS\system32\Tablet.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\wbem\wmiapsrv.exe C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe C:\WINDOWS\system32\taskmgr.exe c:\program files\avira\antivir desktop\avcenter.exe C:\WINDOWS\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Documents and Settings\Antoine\Mes documents\Téléchargements\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [Six Engine] "C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe" -r O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [NI Update Service] "C:\Program Files\National Instruments\Shared\Update Service\NIUpdateService.exe" -startupTask O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [Steam] "D:\Jeux\Steam\steam.exe" -silent O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun O4 - HKCU\..\Run: [NIRegistrationWizard] C:\Program Files\National Instruments\Shared\RegistrationWizard\Bin\RegistrationWizard.exe -autoDiscover 1 -displayIfNoneFound 0 -displayRegisterOptions 1 -sleepIfNoneFound 0 -locale 3084 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: Dropbox.lnk = C:\Documents and Settings\Antoine\Application Data\Dropbox\bin\Dropbox.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000 O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\program files\national instruments\shared\mdns responder\nimdnsnsp.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{3142997B-A9D1-4938-BF47-64968F5E532C}: NameServer = 192.168.0.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{3142997B-A9D1-4938-BF47-64968F5E532C}: NameServer = 192.168.0.1 O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: HP SI Service (HPSIService) - HP - C:\WINDOWS\system32\HPSIsvc.exe O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments Corporation - C:\WINDOWS\system32\lkads.exe O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments Corporation - C:\WINDOWS\system32\lktsrv.exe O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Fichiers communs\Steam\SteamService.exe O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe – End of file - 9471 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Having said that….Let's get going!! :thumbup:
———-
Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post the logs created by DDS and aswMBR. :)
Hi Jeff, thanks for your fast reply!

Here's an update on my situation :

While waiting for a reply, I scanned my computer with Hitman Pro. It deleted some corrupt files (and rendered my keyboard unusable, but I just fixed it in the registry)
Right now ping.exe doesn't show up anymore, and there are no trojan alerts for now.
I also forgot to mention that when browsing on google, I was sometimes redirected to unrelated pages. Right now it doesn't seem to happen any more.

For now on, I'll just follow your instructions :)

There we go, the logs:

dds.txt

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_29
Run by [removed] at 21:53:35 on 2011-11-06
Microsoft Windows XP Professionnel 5.1.2600.2.1252.2.1036.18.3071.2357 [GMT -5:00]
.
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\HPSIsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe
C:\WINDOWS\system32\lkads.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\Tablet.exe
D:\Jeux\Steam\steam.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Documents and Settings\Antoine\Application Data\Dropbox\bin\Dropbox.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Antoine\Mes documents\Téléchargements\dds.com
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\fichiers communs\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Programme d'aide de l'Assistant de connexion Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\fichiers communs\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Steam] "d:\jeux\steam\steam.exe" -silent
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [NIRegistrationWizard] c:\program files\national instruments\shared\registrationwizard\bin\RegistrationWizard.exe -autoDiscover 1 -displayIfNoneFound 0 -displayRegisterOptions 1 -sleepIfNoneFound 0 -locale 3084
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Six Engine] "c:\program files\asus\epu-4 engine\FourEngine.exe" -r
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Adobe ARM] "c:\program files\fichiers communs\adobe\arm\1.0\AdobeARM.exe"
mRun: [ContentTransferWMDetector.exe] c:\program files\sony\content transfer\ContentTransferWMDetector.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [NI Update Service] "c:\program files\national instruments\shared\update service\NIUpdateService.exe" -startupTask
mRun: [SunJavaUpdateSched] "c:\program files\fichiers communs\java\java update\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\antoine\menudm~1\progra~1\dmarra~1\dropbox.lnk - c:\documents and settings\antoine\application data\dropbox\bin\Dropbox.exe
IE: E&xporter; vers Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
LSP: mswsock.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: Interfaces\{3142997B-A9D1-4938-BF47-64968F5E532C} : NameServer = 192.168.0.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\antoine\application data\mozilla\firefox\profiles\8j8skgbm.default\
FF - plugin: c:\documents and settings\antoine\local settings\application data\e-academy inc\mozilla\firefox\plugins\npHostSdmLoader.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nplv2011win32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nplv90win32.dll
.
============= SERVICES / DRIVERS ===============
.
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-7-5 11608]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-7-24 218688]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\avira\antivir desktop\sched.exe [2011-7-5 136360]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-7-5 269480]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-7-5 66616]
R2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [2011-7-14 99896]
R3 mvusbews;USB EWS Device;c:\windows\system32\drivers\mvusbews.sys [2011-7-14 17408]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [2011-11-6 23624]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 NIApplicationWebServer;NI Application Web Server;c:\program files\national instruments\shared\ni webserver\ApplicationWebServer.exe [2011-5-27 50336]
S4 nimDNSResponder;National Instruments mDNS Responder Service;c:\program files\national instruments\shared\mdns responder\nimdnsResponder.exe [2011-6-1 194224]
S4 NINetworkDiscovery;NI Network Discovery;c:\program files\national instruments\shared\ni network discovery\niDiscSvc.exe [2011-6-10 121032]
.
=============== Created Last 30 ================
.
2011-11-07 02:07:03 221184 —-a-w- c:\windows\system32\wmpns.dll
2011-11-07 02:02:53 9728 ——w- c:\windows\system32\rwnh.dll
2011-11-07 02:02:53 10752 ——w- c:\windows\system32\smtpapi.dll
2011-11-07 02:02:29 19528 —-a-w- c:\windows\000001_.tmp
2011-11-07 00:58:16 23624 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-11-07 00:57:40 ——– d—–w- c:\documents and settings\all users\application data\Hitman Pro
2011-11-06 22:38:07 476904 —-a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2011-11-06 22:37:39 6642 —-a-w- c:\windows\system32\PerfStringBackup.TMP
2011-11-06 20:14:52 ——– d—–w- c:\windows\pss
2011-11-06 19:47:41 ——– d—–w- c:\documents and settings\antoine\application data\Malwarebytes
2011-11-06 19:47:25 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes
2011-11-06 19:47:21 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-06 19:47:21 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-11-06 18:31:07 ——– d—–w- c:\windows\system32\wbem\repository\FS
2011-11-06 18:31:07 ——– d—–w- c:\windows\system32\wbem\Repository
2011-10-25 19:07:52 ——– d—–w- c:\documents and settings\antoine\local settings\application data\Padus
2011-10-25 19:04:36 17408 —-a-w- C:\psapi.dll
2011-10-23 00:42:16 ——– d—–w- c:\program files\The Game Creators
2011-10-17 02:25:12 ——– d—–w- c:\program files\fichiers communs\DirectX
.
==================== Find3M ====================
.
2011-10-17 20:48:41 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-03 10:06:03 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-03 07:37:52 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-08-31 16:05:40 66616 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2011-08-14 21:08:58 98304 —-a-w- c:\windows\system32CmdLineExt.dll
.
============= FINISH: 21:54:02,67 ===============


attach.txt


.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professionnel
Boot Device: \Device\HarddiskVolume1
Install Date: 2011-07-05 21:52:48
System Uptime: 2011-11-06 21:40:03 (0 hours ago)
.
Motherboard: ASUSTeK Computer INC. | | P5QL PRO
Processor: Processeur Intel Pentium III Xeon | LGA775 | 2792/266mhz
Processor: Processeur Intel Pentium III Xeon | LGA775 | 2793/266mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 155 GiB total, 120,056 GiB free.
D: is FIXED (NTFS) - 310 GiB total, 109,328 GiB free.
E: is CDROM (CDFS)
F: is CDROM (CDFS)
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP120: 2011-11-06 13:36:09 - Point de vérification système
RP121: 2011-11-06 17:37:33 - Installé Java™ 6 Update 29
RP122: 2011-11-06 20:09:30 - Opération de restauration
RP123: 2011-11-06 20:13:01 - Opération de restauration
RP124: 2011-11-06 21:02:33 - Le Service Pack 2 pour Windows XP a été installé.
.
==== Installed Programs ======================
.
7-Zip 9.20
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Recommended Settings
Adobe Color JA Extra Settings
Adobe Color NA Extra Settings
Adobe Default Language CS3
Adobe Device Central CS3
Adobe ExtendScript Toolkit 2
Adobe Flash Player 10 ActiveX
Adobe Flash Player 11 Plugin
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Linguistics CS3
Adobe PDF Library Files
Adobe Photoshop CS3
Adobe Reader X (10.1.0) - Français
Adobe Setup
Adobe Shockwave Player 11.6
Adobe Stock Photos CS3
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
Alice: Madness Returns
Alien Breed 2: Assault
AMD APP SDK Runtime
Archiveur WinRAR
Assistant de connexion Windows Live
Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
ATI AVIVO Codecs
ATI Catalyst Control Center
ATI Catalyst Install Manager
ATI Problem Report Wizard
Avira AntiVir Personal - Free Antivirus
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization Chinese Standard
Catalyst Control Center Localization Chinese Traditional
Catalyst Control Center Localization Czech
Catalyst Control Center Localization Danish
Catalyst Control Center Localization Dutch
Catalyst Control Center Localization Finnish
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Japanese
Catalyst Control Center Localization Korean
Catalyst Control Center Localization Norwegian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Russian
Catalyst Control Center Localization Spanish
Catalyst Control Center Localization Swedish
Catalyst Control Center Localization Thai
Catalyst Control Center Localization Turkish
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Content Transfer
Correctif pour Windows XP (KB935448)
Correctif pour Windows XP (KB952287)
Correctif pour Windows XP (KB961118)
Correctif pour Windows XP (KB981793)
Correctif Windows XP - KB873339
Correctif Windows XP - KB885835
Correctif Windows XP - KB885836
Correctif Windows XP - KB886185
Correctif Windows XP - KB887472
Correctif Windows XP - KB888302
Correctif Windows XP - KB890859
DAEMON Tools Lite
Dark Basic Professional
DeliPlayer
Dropbox
EPU-4 Engine
Frets On Fire
GOM Player
Heroes of Newerth
High Definition Audio Driver Package - KB888111
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB954550-v5)
HP LaserJet Professional P1100-P1560-P1600 Series
Installation Windows Live
Java Auto Updater
Java™ 6 Update 29
League of Legends
Logiciels National Instruments
Malwarebytes' Anti-Malware version 1.51.2.1300
MATLAB Family of Products Release 14
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile FRA Language Pack
Microsoft .NET Framework 4 Extended
Microsoft .NET Framework 4 Extended FRA Language Pack
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Office Access MUI (French) 2007
Microsoft Office Excel MUI (French) 2007
Microsoft Office InfoPath MUI (French) 2007
Microsoft Office Outlook MUI (French) 2007
Microsoft Office PowerPoint MUI (French) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (Arabic) 2007
Microsoft Office Proof (Dutch) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (German) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (French) 2007
Microsoft Office Publisher MUI (French) 2007
Microsoft Office Shared MUI (French) 2007
Microsoft Office Word MUI (French) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (French) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft XNA Framework Redistributable 4.0
Mise à jour de sécurité pour Lecteur Windows Media (KB911564)
Mise à jour de sécurité pour Lecteur Windows Media (KB952069)
Mise à jour de sécurité pour Lecteur Windows Media (KB954155)
Mise à jour de sécurité pour Lecteur Windows Media (KB973540)
Mise à jour de sécurité pour Lecteur Windows Media (KB978695)
Mise à jour de sécurité pour Lecteur Windows Media (KB979402)
Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)
Mise à jour de sécurité pour Windows XP (KB2229593)
Mise à jour de sécurité pour Windows XP (KB890046)
Mise à jour de sécurité pour Windows XP (KB893756)
Mise à jour de sécurité pour Windows XP (KB896358)
Mise à jour de sécurité pour Windows XP (KB896423)
Mise à jour de sécurité pour Windows XP (KB899587)
Mise à jour de sécurité pour Windows XP (KB899591)
Mise à jour de sécurité pour Windows XP (KB900725)
Mise à jour de sécurité pour Windows XP (KB901017)
Mise à jour de sécurité pour Windows XP (KB901190)
Mise à jour de sécurité pour Windows XP (KB901214)
Mise à jour de sécurité pour Windows XP (KB902400)
Mise à jour de sécurité pour Windows XP (KB905414)
Mise à jour de sécurité pour Windows XP (KB905749)
Mise à jour de sécurité pour Windows XP (KB911562)
Mise à jour de sécurité pour Windows XP (KB911927)
Mise à jour de sécurité pour Windows XP (KB913580)
Mise à jour de sécurité pour Windows XP (KB914388)
Mise à jour de sécurité pour Windows XP (KB914389)
Mise à jour de sécurité pour Windows XP (KB918118)
Mise à jour de sécurité pour Windows XP (KB918439)
Mise à jour de sécurité pour Windows XP (KB920213)
Mise à jour de sécurité pour Windows XP (KB920670)
Mise à jour de sécurité pour Windows XP (KB920683)
Mise à jour de sécurité pour Windows XP (KB923191)
Mise à jour de sécurité pour Windows XP (KB923561)
Mise à jour de sécurité pour Windows XP (KB923789)
Mise à jour de sécurité pour Windows XP (KB923980)
Mise à jour de sécurité pour Windows XP (KB924270)
Mise à jour de sécurité pour Windows XP (KB924496)
Mise à jour de sécurité pour Windows XP (KB924667)
Mise à jour de sécurité pour Windows XP (KB925902)
Mise à jour de sécurité pour Windows XP (KB926255)
Mise à jour de sécurité pour Windows XP (KB926436)
Mise à jour de sécurité pour Windows XP (KB927779)
Mise à jour de sécurité pour Windows XP (KB927802)
Mise à jour de sécurité pour Windows XP (KB928255)
Mise à jour de sécurité pour Windows XP (KB928843)
Mise à jour de sécurité pour Windows XP (KB929123)
Mise à jour de sécurité pour Windows XP (KB930178)
Mise à jour de sécurité pour Windows XP (KB931261)
Mise à jour de sécurité pour Windows XP (KB932168)
Mise à jour de sécurité pour Windows XP (KB938127)
Mise à jour de sécurité pour Windows XP (KB941569)
Mise à jour de sécurité pour Windows XP (KB943055)
Mise à jour de sécurité pour Windows XP (KB943460)
Mise à jour de sécurité pour Windows XP (KB944338-v2)
Mise à jour de sécurité pour Windows XP (KB944653)
Mise à jour de sécurité pour Windows XP (KB945553)
Mise à jour de sécurité pour Windows XP (KB946026)
Mise à jour de sécurité pour Windows XP (KB946648)
Mise à jour de sécurité pour Windows XP (KB950749)
Mise à jour de sécurité pour Windows XP (KB950762)
Mise à jour de sécurité pour Windows XP (KB950974)
Mise à jour de sécurité pour Windows XP (KB951376-v2)
Mise à jour de sécurité pour Windows XP (KB951748)
Mise à jour de sécurité pour Windows XP (KB952004)
Mise à jour de sécurité pour Windows XP (KB952954)
Mise à jour de sécurité pour Windows XP (KB955069)
Mise à jour de sécurité pour Windows XP (KB956572)
Mise à jour de sécurité pour Windows XP (KB956802)
Mise à jour de sécurité pour Windows XP (KB956803)
Mise à jour de sécurité pour Windows XP (KB956844)
Mise à jour de sécurité pour Windows XP (KB958470)
Mise à jour de sécurité pour Windows XP (KB958644)
Mise à jour de sécurité pour Windows XP (KB958869)
Mise à jour de sécurité pour Windows XP (KB959426)
Mise à jour de sécurité pour Windows XP (KB960225)
Mise à jour de sécurité pour Windows XP (KB960803)
Mise à jour de sécurité pour Windows XP (KB960859)
Mise à jour de sécurité pour Windows XP (KB961501)
Mise à jour de sécurité pour Windows XP (KB969059)
Mise à jour de sécurité pour Windows XP (KB970238)
Mise à jour de sécurité pour Windows XP (KB970430)
Mise à jour de sécurité pour Windows XP (KB971032)
Mise à jour de sécurité pour Windows XP (KB971468)
Mise à jour de sécurité pour Windows XP (KB971657)
Mise à jour de sécurité pour Windows XP (KB971961)
Mise à jour de sécurité pour Windows XP (KB972270)
Mise à jour de sécurité pour Windows XP (KB973507)
Mise à jour de sécurité pour Windows XP (KB973869)
Mise à jour de sécurité pour Windows XP (KB973904)
Mise à jour de sécurité pour Windows XP (KB974112)
Mise à jour de sécurité pour Windows XP (KB974318)
Mise à jour de sécurité pour Windows XP (KB974392)
Mise à jour de sécurité pour Windows XP (KB974571)
Mise à jour de sécurité pour Windows XP (KB975025)
Mise à jour de sécurité pour Windows XP (KB975467)
Mise à jour de sécurité pour Windows XP (KB975560)
Mise à jour de sécurité pour Windows XP (KB975561)
Mise à jour de sécurité pour Windows XP (KB975562)
Mise à jour de sécurité pour Windows XP (KB975713)
Mise à jour de sécurité pour Windows XP (KB977816)
Mise à jour de sécurité pour Windows XP (KB977914)
Mise à jour de sécurité pour Windows XP (KB978037)
Mise à jour de sécurité pour Windows XP (KB978338)
Mise à jour de sécurité pour Windows XP (KB978542)
Mise à jour de sécurité pour Windows XP (KB978601)
Mise à jour de sécurité pour Windows XP (KB978706)
Mise à jour de sécurité pour Windows XP (KB979309)
Mise à jour de sécurité pour Windows XP (KB979482)
Mise à jour de sécurité pour Windows XP (KB979559)
Mise à jour de sécurité pour Windows XP (KB979683)
Mise à jour de sécurité pour Windows XP (KB980195)
Mise à jour de sécurité pour Windows XP (KB980218)
Mise à jour de sécurité pour Windows XP (KB980232)
Mise à jour de sécurité pour Windows XP (KB981350)
Mise à jour de sécurité pour Windows XP (KB982381)
Mise à jour pour Windows XP (KB894391)
Mise à jour pour Windows XP (KB898461)
Mise à jour pour Windows XP (KB900485)
Mise à jour pour Windows XP (KB908531)
Mise à jour pour Windows XP (KB910437)
Mise à jour pour Windows XP (KB911280)
Mise à jour pour Windows XP (KB916595)
Mise à jour pour Windows XP (KB920872)
Mise à jour pour Windows XP (KB922582)
Mise à jour pour Windows XP (KB925720)
Mise à jour pour Windows XP (KB927891)
Mise à jour pour Windows XP (KB930916)
Mise à jour pour Windows XP (KB936357)
Mise à jour pour Windows XP (KB938828)
Mise à jour pour Windows XP (KB955759)
Mise à jour pour Windows XP (KB961503)
Mise à jour pour Windows XP (KB967715)
Mise à jour pour Windows XP (KB968389)
Mise à jour pour Windows XP (KB971737)
Mise à jour pour Windows XP (KB973687)
Mise à jour pour Windows XP (KB973815)
Module linguistique Microsoft .NET Framework 4 Client Profile FRA
Module linguistique Microsoft .NET Framework 4 Extended FRA
Mozilla Firefox 7.0.1 (x86 fr)
MSVCRT
MSXML 6 Service Pack 2 (KB973686)
NI-DAQmx/LabVIEW shared documentation 1.9.5
NI-RPC 4.2.2f0
NI-RPC 4.2.2f0 for Phar Lap ETS
NI Assistant Framework
NI Assistant Framework LabVIEW 2011 Support
NI Assistant Framework LabVIEW Code Generator 2011
NI Authentication 2.0
NI CodeSignAPI
NI Curl 1.1
NI DataSocket 4.9
NI Distributed System Manager 2011
NI DN 2.0 SP1 installer
NI Error Reporting 2011
NI EulaDepot
NI Example Finder 11.0
NI GMP Windows 32-bit Installer 11.0.0
NI Help Assistant
NI Instrument IO Assistant for LabVIEW 2011 32-bit
NI LabVIEW 2009 SP1 Run-Time Engine Web Services
NI LabVIEW 2011
NI LabVIEW 2011 Deployable License
NI LabVIEW 2011 Deployment Framework
NI LabVIEW 2011 Help
NI LabVIEW 2011 Help File
NI LabVIEW 2011 License
NI LabVIEW 2011 Manuals
NI LabVIEW 2011 MeasAppChm File
NI LabVIEW 2011 Real-Time Error Dialog
NI LabVIEW 2011 Real-Time NBFifo
NI LabVIEW 2011 Run-Time Engine Non-English Support.
NI LabVIEW 2011 Search
NI LabVIEW 2011 Simulation
NI LabVIEW 2011 VIPM Helper
NI LabVIEW 2011 Web Server
NI LabVIEW Broker
NI LabVIEW C Interface
NI LabVIEW Compare Utility 11.0.0
NI LabVIEW MAX XML
NI LabVIEW Merge Utility 11.0.0
NI LabVIEW Real-Time NBFifo
NI LabVIEW Run-Time Engine 2009 SP1
NI LabVIEW Run-Time Engine 2011
NI LabVIEW Run-Time Engine Interop 2009
NI LabVIEW Run-Time Engine Interop 2011
NI LabVIEW Web Server for Run-Time Engine
NI LabVIEW Web Services Runtime
NI LabWindows/CVI 2010 Code Generator
NI LabWindows/CVI 2010 LabVIEW DLL Builder
NI LabWindows/CVI 9.0 Run-Time Engine
NI License Manager
NI Logos 5.3.0
NI Logos LabVIEW 2011 Support
NI Logos XT Support
NI Math Kernel Libraries
NI MAX Remote Configuration Installer 5.0
NI MDF Support
NI mDNS Responder 1.6.0
NI Measurement & Automation Explorer 5.0.0
NI Measurement Studio Recipe Processor
NI MetaSuite Installer
NI Microsoft Silverlight Wrapper
NI MXS 5.0.0
NI Network Discovery 5.0
NI OPC Support
NI Portable Configuration 5.0.0
NI Registration Wizard
NI Remote Provider for MAX 5.0.0
NI Remote PXI Provider for MAX 5.0.0
NI Search Shared
NI Software Provider for MAX 5.0.0
NI SSL LabVIEW 2011 Support
NI SSL Support
NI System API Client for WIF 5.0.0
NI System API Web-Servce 32-bit 5.0.0
NI System API Windows 32-bit 5.0.0
NI System Configuration Runtime 5.0.0
NI System State Publisher
NI System Web Server 2.0
NI System Web Server Base 2.0
NI TDM Excel Add-In 3.3
NI TDMS
NI Trace Engine
NI Uninstaller
NI Update Service 2.0
NI USI 1.9.0
NI Variable Engine 2.5.0
NI Variable Engine LabVIEW 2011 Support
NI VC2005MSMs x86
NI VC2008MSMs x86
NI Web Application Server 2.0
NI Web Interface Framework 2.0
NI Web Pipeline 2.0.1
NI Xalan Delay Load 1.10.1
NI Xerces Delay Load 2.7.3
NVIDIA PhysX v8.10.29
NWZ-E340 WALKMAN Guide
Outil de téléchargement Windows Live
PDF Settings
Pirates, Vikings, & Knights II
Plants vs. Zombies: Game of the Year
Python 2.6
Python 2.6 PyAudio
Python 2.6 pypitch-svn_rev7
Rayman Raving Rabbids
Real Alternative 1.8.0
Realtek High Definition Audio Driver
Reset NI Config 5.0.0
Secure Download Manager
Segoe UI
Skins
Skype Toolbars
Skype™ 5.3
Spiral Knights
Steam
swMSM
Tablette
Team Fortress 2
Terraria
The Games Factory
UE3Redist
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
WebFldrs XP
WIF Core Dependencies Windows 5.0.0
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Live Call
Windows Live Communications Platform
Windows Live Messenger
Windows Media Format 11 runtime
Windows XP Service Pack 2
WinUAE 2.3.2
.
==== Event Viewer Messages From Past Week ========
.
2011-11-06 21:41:29, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-06 21:07:19, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-06 20:47:32, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-06 20:32:42, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-06 20:13:21, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-06 19:53:32, error: Service Control Manager [7023] - Le service NLA (Network Location Awareness) s'est arrêté avec l'erreur : La procédure spécifiée est introuvable.
2011-11-05 18:31:08, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-05 17:29:32, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-04 23:50:03, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-04 22:48:59, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-03 21:51:22, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-03 20:48:21, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-03 19:48:20, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-03 18:46:52, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-02 23:48:33, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-02 22:47:29, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-02 21:46:24, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-02 20:45:22, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-02 19:43:16, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-02 18:43:14, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-02 10:33:20, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-02 01:07:38, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-02 00:06:34, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-01 23:05:32, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-01 22:04:27, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-01 19:01:16, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-01 18:00:14, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-01 16:59:08, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-01 15:58:06, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-01 13:55:59, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-01 11:53:51, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-01 10:52:46, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-11-01 09:50:28, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-10-31 21:44:51, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-10-31 20:42:34, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-10-31 08:50:13, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
2011-10-30 21:44:07, error: MRxSmb [8003] - Le maître explorateur a reçu une annonce de serveur de l'ordinateur ONE qui pense qu'il est le maître explorateur sur le domaine pour le transport NetBT_Tcpip_{3142997B-A9D1-4938-BF47. Le maître explorateur s'arrête ou une élection est provoquée.
.
==== End Of File ===========================




aswMBR.txt


aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-11-06 21:56:02
—————————–
21:56:02.593 OS Version: Windows 5.1.2600 Service Pack 2
21:56:02.593 Number of processors: 2 586 0x170A
21:56:02.593 ComputerName: ATLANTIS UserName: Antoine
21:56:04.968 Initialize success
21:58:08.218 AVAST engine defs: 11110602
22:03:00.937 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-7
22:03:00.937 Disk 0 Vendor: ST3500410AS CC34 Size: 476940MB BusType: 3
22:03:02.937 Disk 0 MBR read successfully
22:03:02.937 Disk 0 MBR scan
22:03:02.968 Disk 0 Windows XP default MBR code
22:03:02.968 Disk 0 scanning sectors +976752000
22:03:03.031 Disk 0 scanning C:\WINDOWS\system32\drivers
22:03:12.609 Service scanning
22:03:14.234 Modules scanning
22:03:16.265 Disk 0 trace - called modules:
22:03:16.265 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
22:03:16.265 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8addfab8]
22:03:16.265 3 CLASSPNP.SYS[ba0e905b] -> nt!IofCallDriver -> \Device\0000006b[0x8adb69e8]
22:03:16.265 5 ACPI.sys[b9f7e620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-7[0x8ade4d98]
22:03:19.125 AVAST engine scan C:\WINDOWS
22:03:31.609 AVAST engine scan C:\WINDOWS\system32
22:05:15.765 AVAST engine scan C:\WINDOWS\system32\drivers
22:05:31.078 AVAST engine scan C:\Documents and Settings\Antoine
22:07:24.671 File: C:\Documents and Settings\Antoine\Local Settings\Temp\dwme.exe **INFECTED** Win32:Cycbot-OB [Trj]
22:08:49.937 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Antoine\Bureau\MBR.dat"
22:08:49.968 The log file has been saved successfully to "C:\Documents and Settings\Antoine\Bureau\aswMBR.txt"




Looks like aswMBR found something.
Since things might have changed since my first post, I'll send you a new HijackThis log : Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 22:19:40, on 2011-11-06 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Program Files\Avira\AntiVir Desktop\avshadow.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\HPSIsvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe C:\WINDOWS\system32\lkads.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe C:\WINDOWS\system32\lktsrv.exe C:\Program Files\National Instruments\MAX\nimxs.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\system32\lkcitdl.exe C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\WTablet\TabUserW.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\Tablet.exe D:\Jeux\Steam\steam.exe C:\Program Files\DAEMON Tools Lite\DTLite.exe C:\Documents and Settings\Antoine\Application Data\Dropbox\bin\Dropbox.exe C:\WINDOWS\System32\wbem\wmiapsrv.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\Antoine\Mes documents\Téléchargements\aswMBR.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\Antoine\Mes documents\Téléchargements\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [Six Engine] "C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe" -r O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [NI Update Service] "C:\Program Files\National Instruments\Shared\Update Service\NIUpdateService.exe" -startupTask O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [Steam] "D:\Jeux\Steam\steam.exe" -silent O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun O4 - HKCU\..\Run: [NIRegistrationWizard] C:\Program Files\National Instruments\Shared\RegistrationWizard\Bin\RegistrationWizard.exe -autoDiscover 1 -displayIfNoneFound 0 -displayRegisterOptions 1 -sleepIfNoneFound 0 -locale 3084 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: Dropbox.lnk = C:\Documents and Settings\Antoine\Application Data\Dropbox\bin\Dropbox.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000 O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\program files\national instruments\shared\mdns responder\nimdnsnsp.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{3142997B-A9D1-4938-BF47-64968F5E532C}: NameServer = 192.168.0.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{3142997B-A9D1-4938-BF47-64968F5E532C}: NameServer = 192.168.0.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{3142997B-A9D1-4938-BF47-64968F5E532C}: NameServer = 192.168.0.1 O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: HP SI Service (HPSIService) - HP - C:\WINDOWS\system32\HPSIsvc.exe O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments Corporation - C:\WINDOWS\system32\lkads.exe O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments Corporation - C:\WINDOWS\system32\lktsrv.exe O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Fichiers communs\Steam\SteamService.exe O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe – End of file - 9628 bytes
Hi LobsterKing,

Thank you for the updated logs. :) You don't need to run HijackThis anymore though unless I ask you to do so. DDS is a more thorough scan that we can use.
———-

Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • If it needs to, DeFogger may ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.
———-

GMER

Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-
This scan was long, but finally, here it is. During the scan, Avira found some stuff in C:\System Volume Information, such as 'TR/Trash.Gen' and 'TR/Rootkit.Gen2'.

Attachments:

Hi LobsterKing,

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

What you have on your system is the ZeroAccess rootkit. This is a particularly nasty infection that we can attempt to fix, but as a warning we may not be able to fix this. It is one of the worst infections out there right now.

If you would like to format and reinstall your Operating System please let me know and I can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help. :)
———-

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
————

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
———-
Let's try to fix it. TdssKiller found nothing, Combofix recognized the ZeroAccess Toolkit.

TDSSKILLER

22:48:53.0687 5724 TDSS rootkit removing tool 2.6.16.0 Nov 7 2011 16:26:51
22:48:53.0984 5724 ============================================================
22:48:53.0984 5724 Current date / time: 2011/11/07 22:48:53.0984
22:48:53.0984 5724 SystemInfo:
22:48:53.0984 5724
22:48:53.0984 5724 OS Version: 5.1.2600 ServicePack: 2.0
22:48:53.0984 5724 Product type: Workstation
22:48:53.0984 5724 ComputerName: ATLANTIS
22:48:53.0984 5724 UserName: Antoine
22:48:53.0984 5724 Windows directory: C:\WINDOWS
22:48:53.0984 5724 System windows directory: C:\WINDOWS
22:48:53.0984 5724 Processor architecture: Intel x86
22:48:53.0984 5724 Number of processors: 2
22:48:53.0984 5724 Page size: 0x1000
22:48:53.0984 5724 Boot type: Normal boot
22:48:53.0984 5724 ============================================================
22:48:54.0812 5724 Initialize success
22:49:07.0093 6068 ============================================================
22:49:07.0093 6068 Scan started
22:49:07.0093 6068 Mode: Manual;
22:49:07.0093 6068 ============================================================
22:49:07.0906 6068 Abiosdsk - ok
22:49:07.0906 6068 abp480n5 - ok
22:49:07.0953 6068 ACPI (0bd94fbfc14ea3606cd6ca4c0255baa3) C:\WINDOWS\system32\DRIVERS\ACPI.sys
22:49:07.0953 6068 ACPI - ok
22:49:07.0968 6068 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\drivers\ACPIEC.sys
22:49:07.0968 6068 ACPIEC - ok
22:49:07.0984 6068 adpu160m - ok
22:49:08.0015 6068 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys
22:49:08.0015 6068 aec - ok
22:49:08.0046 6068 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
22:49:08.0062 6068 AFD - ok
22:49:08.0062 6068 Aha154x - ok
22:49:08.0078 6068 aic78u2 - ok
22:49:08.0078 6068 aic78xx - ok
22:49:08.0093 6068 AliIde - ok
22:49:08.0093 6068 amsint - ok
22:49:08.0109 6068 asc - ok
22:49:08.0109 6068 asc3350p - ok
22:49:08.0125 6068 asc3550 - ok
22:49:08.0156 6068 AsIO (2b4e66fac6503494a2c6f32bb6ab3826) C:\WINDOWS\system32\drivers\AsIO.sys
22:49:08.0156 6068 AsIO - ok
22:49:08.0171 6068 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
22:49:08.0171 6068 AsyncMac - ok
22:49:08.0203 6068 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
22:49:08.0203 6068 atapi - ok
22:49:08.0203 6068 Atdisk - ok
22:49:08.0343 6068 ati2mtag (23f1a61ae7553d086ef264c72afc4e6a) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
22:49:08.0375 6068 ati2mtag - ok
22:49:08.0406 6068 AtiHdmiService (41c8f0eda10da14378d304c20ba6e558) C:\WINDOWS\system32\drivers\AtiHdmi.sys
22:49:08.0421 6068 AtiHdmiService - ok
22:49:08.0437 6068 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
22:49:08.0453 6068 Atmarpc - ok
22:49:08.0468 6068 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
22:49:08.0468 6068 audstub - ok
22:49:08.0500 6068 avgio (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Program Files\Avira\AntiVir Desktop\avgio.sys
22:49:08.0500 6068 avgio - ok
22:49:08.0515 6068 avgntflt (1e4114685de1ffa9675e09c6a1fb3f4b) C:\WINDOWS\system32\DRIVERS\avgntflt.sys
22:49:08.0515 6068 avgntflt - ok
22:49:08.0546 6068 avipbb (0f78d3dae6dedd99ae54c9491c62adf2) C:\WINDOWS\system32\DRIVERS\avipbb.sys
22:49:08.0546 6068 avipbb - ok
22:49:08.0593 6068 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
22:49:08.0593 6068 Beep - ok
22:49:08.0625 6068 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
22:49:08.0625 6068 cbidf2k - ok
22:49:08.0625 6068 cd20xrnt - ok
22:49:08.0640 6068 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
22:49:08.0640 6068 Cdaudio - ok
22:49:08.0656 6068 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
22:49:08.0656 6068 Cdfs - ok
22:49:08.0687 6068 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
22:49:08.0687 6068 Cdrom - ok
22:49:08.0687 6068 Changer - ok
22:49:08.0703 6068 CmdIde - ok
22:49:08.0718 6068 Cpqarray - ok
22:49:08.0750 6068 cvintdrv (dbd89bc0dbe00dcd245be8f61dbee291) C:\WINDOWS\system32\drivers\cvintdrv.sys
22:49:08.0750 6068 cvintdrv - ok
22:49:08.0750 6068 dac2w2k - ok
22:49:08.0765 6068 dac960nt - ok
22:49:08.0781 6068 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
22:49:08.0781 6068 Disk - ok
22:49:08.0812 6068 dmboot (e2d3b7620310fe56685f9b15a6b404b3) C:\WINDOWS\system32\drivers\dmboot.sys
22:49:08.0828 6068 dmboot - ok
22:49:08.0828 6068 dmio (c77f5c20aa70197a69aa84baa9de43c8) C:\WINDOWS\system32\drivers\dmio.sys
22:49:08.0828 6068 dmio - ok
22:49:08.0843 6068 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
22:49:08.0843 6068 dmload - ok
22:49:08.0875 6068 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
22:49:08.0875 6068 DMusic - ok
22:49:08.0890 6068 dpti2o - ok
22:49:08.0906 6068 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
22:49:08.0906 6068 drmkaud - ok
22:49:08.0937 6068 dtsoftbus01 (555e54ac2f601a8821cef58961653991) C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys
22:49:08.0937 6068 dtsoftbus01 - ok
22:49:08.0953 6068 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
22:49:08.0968 6068 Fastfat - ok
22:49:08.0984 6068 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys
22:49:08.0984 6068 Fdc - ok
22:49:09.0000 6068 Fips (8b121ff880683607ab2aef0340721718) C:\WINDOWS\system32\drivers\Fips.sys
22:49:09.0000 6068 Fips - ok
22:49:09.0015 6068 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
22:49:09.0015 6068 Flpydisk - ok
22:49:09.0046 6068 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\drivers\fltmgr.sys
22:49:09.0046 6068 FltMgr - ok
22:49:09.0062 6068 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:49:09.0062 6068 Fs_Rec - ok
22:49:09.0062 6068 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
22:49:09.0078 6068 Ftdisk - ok
22:49:09.0078 6068 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
22:49:09.0078 6068 Gpc - ok
22:49:09.0093 6068 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
22:49:09.0109 6068 HDAudBus - ok
22:49:09.0140 6068 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
22:49:09.0140 6068 hidusb - ok
22:49:09.0156 6068 hitmanpro35 (72472b9ce5d02e443cff49a40355455d) C:\WINDOWS\system32\drivers\hitmanpro35.sys
22:49:09.0171 6068 hitmanpro35 - ok
22:49:09.0171 6068 hpn - ok
22:49:09.0203 6068 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys
22:49:09.0218 6068 HTTP - ok
22:49:09.0218 6068 i2omgmt - ok
22:49:09.0234 6068 i2omp - ok
22:49:09.0265 6068 i8042prt (d1efcbd693b5ba21314d06368c471070) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
22:49:09.0265 6068 i8042prt - ok
22:49:09.0296 6068 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
22:49:09.0296 6068 Imapi - ok
22:49:09.0296 6068 ini910u - ok
22:49:09.0625 6068 IntcAzAudAddService (6f336c2d18ba1e7ce8d0f31541c87a1d) C:\WINDOWS\system32\drivers\RtkHDAud.sys
22:49:09.0640 6068 IntcAzAudAddService - ok
22:49:09.0656 6068 IntelIde - ok
22:49:09.0687 6068 intelppm (dd5ad1e79ac26d3f8d8828ad4627f160) C:\WINDOWS\system32\DRIVERS\intelppm.sys
22:49:09.0687 6068 intelppm - ok
22:49:09.0703 6068 ip6fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys
22:49:09.0703 6068 ip6fw - ok
22:49:09.0734 6068 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:49:09.0734 6068 IpFilterDriver - ok
22:49:09.0734 6068 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
22:49:09.0734 6068 IpInIp - ok
22:49:09.0750 6068 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys
22:49:09.0765 6068 IpNat - ok
22:49:09.0765 6068 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
22:49:09.0765 6068 IPSec - ok
22:49:09.0796 6068 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
22:49:09.0796 6068 IRENUM - ok
22:49:09.0828 6068 isapnp (54632f1a7de61dc3615d756f2a90fa72) C:\WINDOWS\system32\DRIVERS\isapnp.sys
22:49:09.0828 6068 isapnp - ok
22:49:09.0843 6068 Kbdclass (e798705e8dc7fab596ef6bfdf167e007) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
22:49:09.0843 6068 Kbdclass - ok
22:49:09.0890 6068 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys
22:49:09.0890 6068 kmixer - ok
22:49:09.0921 6068 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys
22:49:09.0921 6068 KSecDD - ok
22:49:09.0937 6068 L1e (fa46f5d09edf93e0c71fe6500fe3f4ae) C:\WINDOWS\system32\DRIVERS\l1e51x86.sys
22:49:09.0937 6068 L1e - ok
22:49:09.0953 6068 lbrtfdc - ok
22:49:09.0984 6068 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
22:49:09.0984 6068 mnmdd - ok
22:49:10.0015 6068 Modem (5ac7e16f5b40a6da14b5f2b3ada4693e) C:\WINDOWS\system32\drivers\Modem.sys
22:49:10.0015 6068 Modem - ok
22:49:10.0046 6068 Mouclass (7d4f19411bd941e1d432a99e24230386) C:\WINDOWS\system32\DRIVERS\mouclass.sys
22:49:10.0046 6068 Mouclass - ok
22:49:10.0046 6068 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys
22:49:10.0062 6068 mouhid - ok
22:49:10.0062 6068 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
22:49:10.0078 6068 MountMgr - ok
22:49:10.0078 6068 mraid35x - ok
22:49:10.0109 6068 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
22:49:10.0109 6068 MRxDAV - ok
22:49:10.0125 6068 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
22:49:10.0125 6068 MRxSmb - ok
22:49:10.0171 6068 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
22:49:10.0171 6068 Msfs - ok
22:49:10.0203 6068 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
22:49:10.0203 6068 MSKSSRV - ok
22:49:10.0218 6068 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
22:49:10.0218 6068 MSPCLOCK - ok
22:49:10.0218 6068 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
22:49:10.0218 6068 MSPQM - ok
22:49:10.0250 6068 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
22:49:10.0250 6068 mssmbios - ok
22:49:10.0265 6068 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys
22:49:10.0265 6068 MTsensor - ok
22:49:10.0281 6068 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
22:49:10.0296 6068 Mup - ok
22:49:10.0312 6068 mvusbews (b9df137953a5280eddbd4a705ca093a2) C:\WINDOWS\system32\Drivers\mvusbews.sys
22:49:10.0328 6068 mvusbews - ok
22:49:10.0343 6068 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
22:49:10.0343 6068 NDIS - ok
22:49:10.0343 6068 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:49:10.0359 6068 NdisTapi - ok
22:49:10.0359 6068 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:49:10.0375 6068 Ndisuio - ok
22:49:10.0375 6068 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:49:10.0375 6068 NdisWan - ok
22:49:10.0390 6068 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
22:49:10.0390 6068 NDProxy - ok
22:49:10.0406 6068 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
22:49:10.0406 6068 NetBIOS - ok
22:49:10.0421 6068 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
22:49:10.0421 6068 NetBT - ok
22:49:10.0453 6068 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
22:49:10.0453 6068 Npfs - ok
22:49:10.0500 6068 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys
22:49:10.0500 6068 Ntfs - ok
22:49:10.0515 6068 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
22:49:10.0515 6068 Null - ok
22:49:10.0546 6068 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
22:49:10.0546 6068 NwlnkFlt - ok
22:49:10.0546 6068 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
22:49:10.0562 6068 NwlnkFwd - ok
22:49:10.0578 6068 Parport (318696359ac7df48d1e51974ec527dd2) C:\WINDOWS\system32\drivers\Parport.sys
22:49:10.0578 6068 Parport - ok
22:49:10.0593 6068 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
22:49:10.0593 6068 PartMgr - ok
22:49:10.0625 6068 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys
22:49:10.0625 6068 ParVdm - ok
22:49:10.0656 6068 PCI (7c5da5c1ed801ad8b0309d5514f0b75e) C:\WINDOWS\system32\DRIVERS\pci.sys
22:49:10.0656 6068 PCI - ok
22:49:10.0656 6068 PCIDump - ok
22:49:10.0671 6068 PCIIde (f4bfde7209c14a07aaa61e4d6ae69eac) C:\WINDOWS\system32\DRIVERS\pciide.sys
22:49:10.0671 6068 PCIIde - ok
22:49:10.0687 6068 Pcmcia (641da274e163617ea7a33506bc6da8e3) C:\WINDOWS\system32\drivers\Pcmcia.sys
22:49:10.0687 6068 Pcmcia - ok
22:49:10.0687 6068 PDCOMP - ok
22:49:10.0703 6068 PDFRAME - ok
22:49:10.0703 6068 PDRELI - ok
22:49:10.0718 6068 PDRFRAME - ok
22:49:10.0718 6068 perc2 - ok
22:49:10.0734 6068 perc2hib - ok
22:49:10.0765 6068 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
22:49:10.0765 6068 PptpMiniport - ok
22:49:10.0781 6068 Processor (f480712b761e538bc8e44ede60f3a3c3) C:\WINDOWS\system32\DRIVERS\processr.sys
22:49:10.0781 6068 Processor - ok
22:49:10.0781 6068 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
22:49:10.0796 6068 PSched - ok
22:49:10.0812 6068 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
22:49:10.0812 6068 Ptilink - ok
22:49:10.0828 6068 ql1080 - ok
22:49:10.0828 6068 Ql10wnt - ok
22:49:10.0828 6068 ql12160 - ok
22:49:10.0843 6068 ql1240 - ok
22:49:10.0843 6068 ql1280 - ok
22:49:10.0875 6068 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:49:10.0875 6068 RasAcd - ok
22:49:10.0875 6068 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
22:49:10.0890 6068 Rasl2tp - ok
22:49:10.0890 6068 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:49:10.0890 6068 RasPppoe - ok
22:49:10.0906 6068 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
22:49:10.0906 6068 Raspti - ok
22:49:10.0937 6068 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:49:10.0953 6068 Rdbss - ok
22:49:10.0953 6068 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
22:49:10.0953 6068 RDPCDD - ok
22:49:10.0968 6068 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
22:49:10.0968 6068 rdpdr - ok
22:49:11.0015 6068 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys
22:49:11.0015 6068 RDPWD - ok
22:49:11.0031 6068 redbook (2cc30b68dd62b73d444a41322cd7fc4c) C:\WINDOWS\system32\DRIVERS\redbook.sys
22:49:11.0031 6068 redbook - ok
22:49:11.0078 6068 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys
22:49:11.0078 6068 Secdrv - ok
22:49:11.0078 6068 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
22:49:11.0093 6068 serenum - ok
22:49:11.0109 6068 Serial (653201755ca96ab4aaa4131daf6da356) C:\WINDOWS\system32\DRIVERS\serial.sys
22:49:11.0109 6068 Serial - ok
22:49:11.0125 6068 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
22:49:11.0125 6068 Sfloppy - ok
22:49:11.0140 6068 Simbad - ok
22:49:11.0140 6068 Sparrow - ok
22:49:11.0187 6068 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys
22:49:11.0187 6068 splitter - ok
22:49:11.0203 6068 sr (b52181023b827acda36c1b76751ebffd) C:\WINDOWS\system32\DRIVERS\sr.sys
22:49:11.0203 6068 sr - ok
22:49:11.0234 6068 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys
22:49:11.0234 6068 Srv - ok
22:49:11.0265 6068 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
22:49:11.0265 6068 ssmdrv - ok
22:49:11.0281 6068 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
22:49:11.0281 6068 swenum - ok
22:49:11.0296 6068 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
22:49:11.0296 6068 swmidi - ok
22:49:11.0312 6068 symc810 - ok
22:49:11.0312 6068 symc8xx - ok
22:49:11.0328 6068 sym_hi - ok
22:49:11.0328 6068 sym_u3 - ok
22:49:11.0343 6068 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
22:49:11.0343 6068 sysaudio - ok
22:49:11.0375 6068 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys
22:49:11.0375 6068 Tcpip - ok
22:49:11.0406 6068 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
22:49:11.0406 6068 TDPIPE - ok
22:49:11.0406 6068 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
22:49:11.0406 6068 TDTCP - ok
22:49:11.0421 6068 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
22:49:11.0421 6068 TermDD - ok
22:49:11.0437 6068 TosIde - ok
22:49:11.0453 6068 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
22:49:11.0453 6068 Udfs - ok
22:49:11.0468 6068 ultra - ok
22:49:11.0484 6068 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys
22:49:11.0500 6068 Update - ok
22:49:11.0515 6068 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
22:49:11.0515 6068 usbccgp - ok
22:49:11.0562 6068 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
22:49:11.0562 6068 usbehci - ok
22:49:11.0562 6068 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
22:49:11.0578 6068 usbhub - ok
22:49:11.0578 6068 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
22:49:11.0593 6068 usbprint - ok
22:49:11.0609 6068 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
22:49:11.0625 6068 usbscan - ok
22:49:11.0656 6068 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
22:49:11.0656 6068 USBSTOR - ok
22:49:11.0687 6068 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
22:49:11.0687 6068 usbuhci - ok
22:49:11.0718 6068 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
22:49:11.0734 6068 VgaSave - ok
22:49:11.0734 6068 ViaIde - ok
22:49:11.0765 6068 VolSnap (313b1a0d5db26dfe1c34a6c13b2ce0a7) C:\WINDOWS\system32\drivers\VolSnap.sys
22:49:11.0765 6068 VolSnap - ok
22:49:11.0796 6068 wacommousefilter (427a8bc96f16c40df81c2d2f4edd32dd) C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys
22:49:11.0796 6068 wacommousefilter - ok
22:49:11.0812 6068 wacomvhid (73e6f16a1f187d71fb26af308551e54a) C:\WINDOWS\system32\DRIVERS\wacomvhid.sys
22:49:11.0812 6068 wacomvhid - ok
22:49:11.0843 6068 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:49:11.0859 6068 Wanarp - ok
22:49:11.0890 6068 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys
22:49:11.0906 6068 Wdf01000 - ok
22:49:11.0906 6068 WDICA - ok
22:49:11.0953 6068 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys
22:49:11.0953 6068 wdmaud - ok
22:49:12.0000 6068 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
22:49:12.0000 6068 WpdUsb - ok
22:49:12.0046 6068 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
22:49:12.0062 6068 WudfPf - ok
22:49:12.0062 6068 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
22:49:12.0062 6068 WudfRd - ok
22:49:12.0078 6068 MBR (0x1B8) (c99c3199cfaa4cbdcd91493f6d113a50) \Device\Harddisk0\DR0
22:49:12.0140 6068 \Device\Harddisk0\DR0 - ok
22:49:12.0140 6068 Boot (0x1200) (5fba20f0b397ae3b6b099fe929f63a13) \Device\Harddisk0\DR0\Partition0
22:49:12.0140 6068 \Device\Harddisk0\DR0\Partition0 - ok
22:49:12.0171 6068 Boot (0x1200) (8b127d03b7ed7e0c5d5b69e2e71b56fe) \Device\Harddisk0\DR0\Partition1
22:49:12.0171 6068 \Device\Harddisk0\DR0\Partition1 - ok
22:49:12.0171 6068 ============================================================
22:49:12.0171 6068 Scan finished
22:49:12.0171 6068 ============================================================
22:49:12.0171 3752 Detected object count: 0
22:49:12.0171 3752 Actual detected object count: 0
22:49:18.0500 2376 ============================================================
22:49:18.0500 2376 Scan started
22:49:18.0500 2376 Mode: Manual;
22:49:18.0500 2376 ============================================================
22:49:19.0156 2376 Abiosdsk - ok
22:49:19.0171 2376 abp480n5 - ok
22:49:19.0187 2376 ACPI (0bd94fbfc14ea3606cd6ca4c0255baa3) C:\WINDOWS\system32\DRIVERS\ACPI.sys
22:49:19.0187 2376 ACPI - ok
22:49:19.0218 2376 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\drivers\ACPIEC.sys
22:49:19.0218 2376 ACPIEC - ok
22:49:19.0234 2376 adpu160m - ok
22:49:19.0250 2376 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys
22:49:19.0250 2376 aec - ok
22:49:19.0265 2376 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
22:49:19.0265 2376 AFD - ok
22:49:19.0281 2376 Aha154x - ok
22:49:19.0281 2376 aic78u2 - ok
22:49:19.0296 2376 aic78xx - ok
22:49:19.0296 2376 AliIde - ok
22:49:19.0312 2376 amsint - ok
22:49:19.0328 2376 asc - ok
22:49:19.0328 2376 asc3350p - ok
22:49:19.0343 2376 asc3550 - ok
22:49:19.0390 2376 AsIO (2b4e66fac6503494a2c6f32bb6ab3826) C:\WINDOWS\system32\drivers\AsIO.sys
22:49:19.0390 2376 AsIO - ok
22:49:19.0421 2376 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
22:49:19.0421 2376 AsyncMac - ok
22:49:19.0453 2376 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
22:49:19.0453 2376 atapi - ok
22:49:19.0468 2376 Atdisk - ok
22:49:19.0593 2376 ati2mtag (23f1a61ae7553d086ef264c72afc4e6a) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
22:49:19.0640 2376 ati2mtag - ok
22:49:19.0671 2376 AtiHdmiService (41c8f0eda10da14378d304c20ba6e558) C:\WINDOWS\system32\drivers\AtiHdmi.sys
22:49:19.0671 2376 AtiHdmiService - ok
22:49:19.0703 2376 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
22:49:19.0703 2376 Atmarpc - ok
22:49:19.0734 2376 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
22:49:19.0734 2376 audstub - ok
22:49:19.0812 2376 avgio (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Program Files\Avira\AntiVir Desktop\avgio.sys
22:49:19.0812 2376 avgio - ok
22:49:19.0828 2376 avgntflt (1e4114685de1ffa9675e09c6a1fb3f4b) C:\WINDOWS\system32\DRIVERS\avgntflt.sys
22:49:19.0828 2376 avgntflt - ok
22:49:19.0843 2376 avipbb (0f78d3dae6dedd99ae54c9491c62adf2) C:\WINDOWS\system32\DRIVERS\avipbb.sys
22:49:19.0843 2376 avipbb - ok
22:49:19.0890 2376 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
22:49:19.0890 2376 Beep - ok
22:49:19.0921 2376 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
22:49:19.0921 2376 cbidf2k - ok
22:49:19.0921 2376 cd20xrnt - ok
22:49:19.0937 2376 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
22:49:19.0937 2376 Cdaudio - ok
22:49:19.0968 2376 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
22:49:19.0968 2376 Cdfs - ok
22:49:20.0000 2376 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
22:49:20.0000 2376 Cdrom - ok
22:49:20.0000 2376 Changer - ok
22:49:20.0015 2376 CmdIde - ok
22:49:20.0031 2376 Cpqarray - ok
22:49:20.0062 2376 cvintdrv (dbd89bc0dbe00dcd245be8f61dbee291) C:\WINDOWS\system32\drivers\cvintdrv.sys
22:49:20.0062 2376 cvintdrv - ok
22:49:20.0078 2376 dac2w2k - ok
22:49:20.0078 2376 dac960nt - ok
22:49:20.0140 2376 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
22:49:20.0140 2376 Disk - ok
22:49:20.0171 2376 dmboot (e2d3b7620310fe56685f9b15a6b404b3) C:\WINDOWS\system32\drivers\dmboot.sys
22:49:20.0187 2376 dmboot - ok
22:49:20.0187 2376 dmio (c77f5c20aa70197a69aa84baa9de43c8) C:\WINDOWS\system32\drivers\dmio.sys
22:49:20.0187 2376 dmio - ok
22:49:20.0203 2376 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
22:49:20.0203 2376 dmload - ok
22:49:20.0234 2376 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
22:49:20.0250 2376 DMusic - ok
22:49:20.0250 2376 dpti2o - ok
22:49:20.0281 2376 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
22:49:20.0281 2376 drmkaud - ok
22:49:20.0312 2376 dtsoftbus01 (555e54ac2f601a8821cef58961653991) C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys
22:49:20.0312 2376 dtsoftbus01 - ok
22:49:20.0328 2376 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
22:49:20.0328 2376 Fastfat - ok
22:49:20.0343 2376 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys
22:49:20.0343 2376 Fdc - ok
22:49:20.0359 2376 Fips (8b121ff880683607ab2aef0340721718) C:\WINDOWS\system32\drivers\Fips.sys
22:49:20.0375 2376 Fips - ok
22:49:20.0375 2376 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
22:49:20.0390 2376 Flpydisk - ok
22:49:20.0406 2376 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\drivers\fltmgr.sys
22:49:20.0406 2376 FltMgr - ok
22:49:20.0421 2376 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:49:20.0421 2376 Fs_Rec - ok
22:49:20.0421 2376 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
22:49:20.0437 2376 Ftdisk - ok
22:49:20.0437 2376 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
22:49:20.0437 2376 Gpc - ok
22:49:20.0468 2376 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
22:49:20.0468 2376 HDAudBus - ok
22:49:20.0515 2376 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
22:49:20.0515 2376 hidusb - ok
22:49:20.0531 2376 hitmanpro35 (72472b9ce5d02e443cff49a40355455d) C:\WINDOWS\system32\drivers\hitmanpro35.sys
22:49:20.0531 2376 hitmanpro35 - ok
22:49:20.0546 2376 hpn - ok
22:49:20.0578 2376 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys
22:49:20.0578 2376 HTTP - ok
22:49:20.0593 2376 i2omgmt - ok
22:49:20.0593 2376 i2omp - ok
22:49:20.0625 2376 i8042prt (d1efcbd693b5ba21314d06368c471070) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
22:49:20.0625 2376 i8042prt - ok
22:49:20.0640 2376 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
22:49:20.0640 2376 Imapi - ok
22:49:20.0656 2376 ini910u - ok
22:49:20.0750 2376 IntcAzAudAddService (6f336c2d18ba1e7ce8d0f31541c87a1d) C:\WINDOWS\system32\drivers\RtkHDAud.sys
22:49:20.0781 2376 IntcAzAudAddService - ok
22:49:20.0781 2376 IntelIde - ok
22:49:20.0812 2376 intelppm (dd5ad1e79ac26d3f8d8828ad4627f160) C:\WINDOWS\system32\DRIVERS\intelppm.sys
22:49:20.0812 2376 intelppm - ok
22:49:20.0828 2376 ip6fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys
22:49:20.0828 2376 ip6fw - ok
22:49:20.0843 2376 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:49:20.0843 2376 IpFilterDriver - ok
22:49:20.0859 2376 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
22:49:20.0859 2376 IpInIp - ok
22:49:20.0875 2376 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys
22:49:20.0875 2376 IpNat - ok
22:49:20.0890 2376 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
22:49:20.0890 2376 IPSec - ok
22:49:20.0890 2376 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
22:49:20.0890 2376 IRENUM - ok
22:49:20.0921 2376 isapnp (54632f1a7de61dc3615d756f2a90fa72) C:\WINDOWS\system32\DRIVERS\isapnp.sys
22:49:20.0921 2376 isapnp - ok
22:49:20.0937 2376 Kbdclass (e798705e8dc7fab596ef6bfdf167e007) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
22:49:20.0937 2376 Kbdclass - ok
22:49:20.0968 2376 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys
22:49:20.0968 2376 kmixer - ok
22:49:20.0984 2376 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys
22:49:20.0984 2376 KSecDD - ok
22:49:21.0015 2376 L1e (fa46f5d09edf93e0c71fe6500fe3f4ae) C:\WINDOWS\system32\DRIVERS\l1e51x86.sys
22:49:21.0015 2376 L1e - ok
22:49:21.0031 2376 lbrtfdc - ok
22:49:21.0078 2376 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
22:49:21.0078 2376 mnmdd - ok
22:49:21.0109 2376 Modem (5ac7e16f5b40a6da14b5f2b3ada4693e) C:\WINDOWS\system32\drivers\Modem.sys
22:49:21.0109 2376 Modem - ok
22:49:21.0125 2376 Mouclass (7d4f19411bd941e1d432a99e24230386) C:\WINDOWS\system32\DRIVERS\mouclass.sys
22:49:21.0125 2376 Mouclass - ok
22:49:21.0125 2376 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys
22:49:21.0125 2376 mouhid - ok
22:49:21.0140 2376 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
22:49:21.0140 2376 MountMgr - ok
22:49:21.0140 2376 mraid35x - ok
22:49:21.0171 2376 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
22:49:21.0171 2376 MRxDAV - ok
22:49:21.0187 2376 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
22:49:21.0187 2376 MRxSmb - ok
22:49:21.0203 2376 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
22:49:21.0203 2376 Msfs - ok
22:49:21.0250 2376 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
22:49:21.0250 2376 MSKSSRV - ok
22:49:21.0250 2376 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
22:49:21.0250 2376 MSPCLOCK - ok
22:49:21.0250 2376 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
22:49:21.0250 2376 MSPQM - ok
22:49:21.0281 2376 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
22:49:21.0281 2376 mssmbios - ok
22:49:21.0296 2376 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys
22:49:21.0296 2376 MTsensor - ok
22:49:21.0312 2376 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
22:49:21.0312 2376 Mup - ok
22:49:21.0328 2376 mvusbews (b9df137953a5280eddbd4a705ca093a2) C:\WINDOWS\system32\Drivers\mvusbews.sys
22:49:21.0328 2376 mvusbews - ok
22:49:21.0343 2376 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
22:49:21.0359 2376 NDIS - ok
22:49:21.0359 2376 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:49:21.0359 2376 NdisTapi - ok
22:49:21.0375 2376 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:49:21.0375 2376 Ndisuio - ok
22:49:21.0375 2376 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:49:21.0375 2376 NdisWan - ok
22:49:21.0390 2376 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
22:49:21.0390 2376 NDProxy - ok
22:49:21.0390 2376 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
22:49:21.0406 2376 NetBIOS - ok
22:49:21.0406 2376 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
22:49:21.0421 2376 NetBT - ok
22:49:21.0437 2376 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
22:49:21.0437 2376 Npfs - ok
22:49:21.0484 2376 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys
22:49:21.0484 2376 Ntfs - ok
22:49:21.0500 2376 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
22:49:21.0500 2376 Null - ok
22:49:21.0531 2376 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
22:49:21.0531 2376 NwlnkFlt - ok
22:49:21.0531 2376 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
22:49:21.0531 2376 NwlnkFwd - ok
22:49:21.0562 2376 Parport (318696359ac7df48d1e51974ec527dd2) C:\WINDOWS\system32\drivers\Parport.sys
22:49:21.0562 2376 Parport - ok
22:49:21.0562 2376 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
22:49:21.0562 2376 PartMgr - ok
22:49:21.0593 2376 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys
22:49:21.0593 2376 ParVdm - ok
22:49:21.0609 2376 PCI (7c5da5c1ed801ad8b0309d5514f0b75e) C:\WINDOWS\system32\DRIVERS\pci.sys
22:49:21.0609 2376 PCI - ok
22:49:21.0609 2376 PCIDump - ok
22:49:21.0625 2376 PCIIde (f4bfde7209c14a07aaa61e4d6ae69eac) C:\WINDOWS\system32\DRIVERS\pciide.sys
22:49:21.0625 2376 PCIIde - ok
22:49:21.0640 2376 Pcmcia (641da274e163617ea7a33506bc6da8e3) C:\WINDOWS\system32\drivers\Pcmcia.sys
22:49:21.0640 2376 Pcmcia - ok
22:49:21.0640 2376 PDCOMP - ok
22:49:21.0656 2376 PDFRAME - ok
22:49:21.0656 2376 PDRELI - ok
22:49:21.0656 2376 PDRFRAME - ok
22:49:21.0671 2376 perc2 - ok
22:49:21.0671 2376 perc2hib - ok
22:49:21.0734 2376 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
22:49:21.0734 2376 PptpMiniport - ok
22:49:21.0765 2376 Processor (f480712b761e538bc8e44ede60f3a3c3) C:\WINDOWS\system32\DRIVERS\processr.sys
22:49:21.0765 2376 Processor - ok
22:49:21.0781 2376 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
22:49:21.0781 2376 PSched - ok
22:49:21.0796 2376 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
22:49:21.0796 2376 Ptilink - ok
22:49:21.0796 2376 ql1080 - ok
22:49:21.0812 2376 Ql10wnt - ok
22:49:21.0812 2376 ql12160 - ok
22:49:21.0828 2376 ql1240 - ok
22:49:21.0828 2376 ql1280 - ok
22:49:21.0859 2376 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:49:21.0859 2376 RasAcd - ok
22:49:21.0875 2376 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
22:49:21.0875 2376 Rasl2tp - ok
22:49:21.0875 2376 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:49:21.0875 2376 RasPppoe - ok
22:49:21.0890 2376 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
22:49:21.0890 2376 Raspti - ok
22:49:21.0921 2376 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:49:21.0921 2376 Rdbss - ok
22:49:21.0937 2376 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
22:49:21.0937 2376 RDPCDD - ok
22:49:21.0953 2376 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
22:49:21.0953 2376 rdpdr - ok
22:49:21.0984 2376 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys
22:49:21.0984 2376 RDPWD - ok
22:49:22.0000 2376 redbook (2cc30b68dd62b73d444a41322cd7fc4c) C:\WINDOWS\system32\DRIVERS\redbook.sys
22:49:22.0000 2376 redbook - ok
22:49:22.0046 2376 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys
22:49:22.0046 2376 Secdrv - ok
22:49:22.0046 2376 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
22:49:22.0046 2376 serenum - ok
22:49:22.0078 2376 Serial (653201755ca96ab4aaa4131daf6da356) C:\WINDOWS\system32\DRIVERS\serial.sys
22:49:22.0078 2376 Serial - ok
22:49:22.0109 2376 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
22:49:22.0109 2376 Sfloppy - ok
22:49:22.0125 2376 Simbad - ok
22:49:22.0140 2376 Sparrow - ok
22:49:22.0171 2376 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys
22:49:22.0171 2376 splitter - ok
22:49:22.0187 2376 sr (b52181023b827acda36c1b76751ebffd) C:\WINDOWS\system32\DRIVERS\sr.sys
22:49:22.0187 2376 sr - ok
22:49:22.0218 2376 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys
22:49:22.0218 2376 Srv - ok
22:49:22.0250 2376 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
22:49:22.0250 2376 ssmdrv - ok
22:49:22.0265 2376 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
22:49:22.0265 2376 swenum - ok
22:49:22.0281 2376 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
22:49:22.0281 2376 swmidi - ok
22:49:22.0296 2376 symc810 - ok
22:49:22.0296 2376 symc8xx - ok
22:49:22.0312 2376 sym_hi - ok
22:49:22.0312 2376 sym_u3 - ok
22:49:22.0328 2376 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
22:49:22.0328 2376 sysaudio - ok
22:49:22.0359 2376 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys
22:49:22.0359 2376 Tcpip - ok
22:49:22.0375 2376 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
22:49:22.0375 2376 TDPIPE - ok
22:49:22.0390 2376 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
22:49:22.0390 2376 TDTCP - ok
22:49:22.0390 2376 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
22:49:22.0390 2376 TermDD - ok
22:49:22.0406 2376 TosIde - ok
22:49:22.0437 2376 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
22:49:22.0437 2376 Udfs - ok
22:49:22.0437 2376 ultra - ok
22:49:22.0453 2376 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys
22:49:22.0468 2376 Update - ok
22:49:22.0484 2376 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
22:49:22.0484 2376 usbccgp - ok
22:49:22.0515 2376 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
22:49:22.0515 2376 usbehci - ok
22:49:22.0531 2376 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
22:49:22.0531 2376 usbhub - ok
22:49:22.0546 2376 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
22:49:22.0546 2376 usbprint - ok
22:49:22.0578 2376 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
22:49:22.0578 2376 usbscan - ok
22:49:22.0609 2376 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
22:49:22.0609 2376 USBSTOR - ok
22:49:22.0656 2376 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
22:49:22.0656 2376 usbuhci - ok
22:49:22.0687 2376 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
22:49:22.0687 2376 VgaSave - ok
22:49:22.0703 2376 ViaIde - ok
22:49:22.0718 2376 VolSnap (313b1a0d5db26dfe1c34a6c13b2ce0a7) C:\WINDOWS\system32\drivers\VolSnap.sys
22:49:22.0718 2376 VolSnap - ok
22:49:22.0750 2376 wacommousefilter (427a8bc96f16c40df81c2d2f4edd32dd) C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys
22:49:22.0750 2376 wacommousefilter - ok
22:49:22.0765 2376 wacomvhid (73e6f16a1f187d71fb26af308551e54a) C:\WINDOWS\system32\DRIVERS\wacomvhid.sys
22:49:22.0765 2376 wacomvhid - ok
22:49:22.0765 2376 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:49:22.0765 2376 Wanarp - ok
22:49:22.0796 2376 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys
22:49:22.0812 2376 Wdf01000 - ok
22:49:22.0812 2376 WDICA - ok
22:49:22.0843 2376 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys
22:49:22.0843 2376 wdmaud - ok
22:49:22.0906 2376 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
22:49:22.0906 2376 WpdUsb - ok
22:49:22.0937 2376 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
22:49:22.0937 2376 WudfPf - ok
22:49:22.0953 2376 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
22:49:22.0953 2376 WudfRd - ok
22:49:22.0968 2376 MBR (0x1B8) (c99c3199cfaa4cbdcd91493f6d113a50) \Device\Harddisk0\DR0
22:49:23.0031 2376 \Device\Harddisk0\DR0 - ok
22:49:23.0031 2376 Boot (0x1200) (5fba20f0b397ae3b6b099fe929f63a13) \Device\Harddisk0\DR0\Partition0
22:49:23.0031 2376 \Device\Harddisk0\DR0\Partition0 - ok
22:49:23.0046 2376 Boot (0x1200) (8b127d03b7ed7e0c5d5b69e2e71b56fe) \Device\Harddisk0\DR0\Partition1
22:49:23.0062 2376 \Device\Harddisk0\DR0\Partition1 - ok
22:49:23.0062 2376 ============================================================
22:49:23.0062 2376 Scan finished
22:49:23.0062 2376 ============================================================
22:49:23.0062 5960 Detected object count: 0
22:49:23.0062 5960 Actual detected object count: 0
22:49:28.0234 1436 Deinitialize success


COMBOFIX

ComboFix 11-11-07.03 - Antoine 2011-11-07 22:58:20.1.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.2.1036.18.3071.2571 [GMT -5:00]
Lancé depuis: c:\documents and settings\Antoine\Bureau\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\$NtUninstallKB51661$
c:\windows\$NtUninstallKB51661$\1576047677\@
c:\windows\$NtUninstallKB51661$\1576047677\bckfg.tmp
c:\windows\$NtUninstallKB51661$\1576047677\cfg.ini
c:\windows\$NtUninstallKB51661$\1576047677\Desktop.ini
c:\windows\$NtUninstallKB51661$\1576047677\keywords
c:\windows\$NtUninstallKB51661$\1576047677\kwrd.dll
c:\windows\$NtUninstallKB51661$\1576047677\L\iseykmio
c:\windows\$NtUninstallKB51661$\1576047677\U\00000001.@
c:\windows\$NtUninstallKB51661$\1576047677\U\00000002.@
c:\windows\$NtUninstallKB51661$\1576047677\U\00000004.@
c:\windows\$NtUninstallKB51661$\1576047677\U\80000000.@
c:\windows\$NtUninstallKB51661$\1576047677\U\80000004.@
c:\windows\$NtUninstallKB51661$\1576047677\U\80000032.@
c:\windows\$NtUninstallKB51661$\229964038
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-10-08 au 2011-11-08 ))))))))))))))))))))))))))))))))))))
.
.
2011-11-07 02:02 . 2004-08-19 21:09 10752 ——w- c:\windows\system32\smtpapi.dll
2011-11-07 02:02 . 2004-08-19 21:09 9728 ——w- c:\windows\system32\rwnh.dll
2011-11-07 02:02 . 2004-07-17 16:40 19528 —-a-w- c:\windows\000001_.tmp
2011-11-07 00:58 . 2011-11-07 01:03 23624 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-11-07 00:57 . 2011-11-07 01:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Hitman Pro
2011-11-06 22:38 . 2011-11-06 22:38 ——– d—–w- c:\program files\Fichiers communs\Java
2011-11-06 22:38 . 2011-10-03 10:06 476904 —-a-w- c:\program files\Mozilla Firefox\Plugins\npdeployJava1.dll
2011-11-06 22:37 . 2011-11-06 22:37 6642 —-a-w- c:\windows\system32\PerfStringBackup.TMP
2011-11-06 19:47 . 2011-11-06 19:47 ——– d—–w- c:\documents and settings\Antoine\Application Data\Malwarebytes
2011-11-06 19:47 . 2011-11-06 19:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-06 19:47 . 2011-11-06 19:47 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-11-06 19:47 . 2011-08-31 22:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-06 18:51 . 2011-11-06 18:51 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2011-11-06 18:51 . 2011-11-06 18:51 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-11-06 18:51 . 2011-11-06 18:51 ——– d-s—w- c:\documents and settings\NetworkService\UserData
2011-11-06 18:31 . 2011-11-06 18:31 ——– d—–w- c:\windows\system32\wbem\Repository
2011-11-06 18:28 . 2011-11-06 18:29 ——– d-s—w- c:\documents and settings\Administrateur
2011-10-25 21:05 . 2011-10-25 21:05 ——– d—–w- c:\program files\7-Zip
2011-10-25 19:07 . 2011-10-25 19:07 ——– d—–w- c:\documents and settings\Antoine\Local Settings\Application Data\Padus
2011-10-25 19:04 . 2011-10-25 19:05 17408 —-a-w- C:\psapi.dll
2011-10-23 00:42 . 2011-10-23 00:42 ——– d—–w- c:\program files\The Game Creators
2011-10-17 02:25 . 2011-10-17 02:25 ——– d—–w- c:\program files\Fichiers communs\DirectX
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-17 20:48 . 2011-07-06 03:19 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-03 10:06 . 2011-07-31 02:09 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-03 07:37 . 2011-07-31 02:09 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-08-31 16:05 . 2011-07-06 02:28 66616 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2011-08-31 16:05 . 2011-07-06 02:28 138192 —-a-w- c:\windows\system32\drivers\avipbb.sys
2011-08-14 21:08 . 2011-08-14 21:08 98304 —-a-w- c:\windows\system32CmdLineExt.dll
2011-06-22 15:44 . 2011-06-22 15:44 158720 —-a-w- c:\program files\internet explorer\plugins\LV2011ActiveXControl.dll
2010-10-19 22:15 . 2010-10-19 22:15 158720 —-a-w- c:\program files\internet explorer\plugins\LV90ActiveXControl.dll
2011-10-02 03:49 . 2011-07-06 03:03 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Antoine\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Antoine\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Antoine\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Antoine\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
"Steam"="d:\jeux\Steam\steam.exe" [2011-08-07 1242448]
"NIRegistrationWizard"="c:\program files\National Instruments\Shared\RegistrationWizard\Bin\RegistrationWizard.exe" [2010-06-21 846520]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-09-30 16864768]
"Six Engine"="c:\program files\ASUS\EPU-4 Engine\FourEngine.exe" [2008-07-23 5625344]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-17 281768]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"ContentTransferWMDetector.exe"="c:\program files\Sony\Content Transfer\ContentTransferWMDetector.exe" [2009-11-19 583016]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"NI Update Service"="c:\program files\National Instruments\Shared\Update Service\NIUpdateService.exe" [2011-06-07 3002976]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
.
c:\documents and settings\Antoine\Menu Démarrer\Programmes\Démarrage\
Dropbox.lnk - c:\documents and settings\Antoine\Application Data\Dropbox\bin\Dropbox.exe [2011-9-1 24183152]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^NI Error Reporting.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\NI Error Reporting.lnk
backup=c:\windows\pss\NI Error Reporting.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NITaggerService"=2 (0x2)
"niSvcLoc"=2 (0x2)
"NINetworkDiscovery"=2 (0x2)
"nimDNSResponder"=2 (0x2)
"NILM License Manager"=3 (0x3)
"NIDomainService"=2 (0x2)
"NIApplicationWebServer"=2 (0x2)
"Bonjour Service"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Jeux\\Steam\\Steam.exe"=
"d:\\Jeux\\Riot Games\\League of Legends\\lol.launcher.exe"=
"d:\\Jeux\\Steam\\SteamApps\\common\\magicka trailer\\smp.exe"=
"d:\\Jeux\\Steam\\SteamApps\\common\\amd driver updater, xp, 32 bit\\Setup.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Jeux\\Heroes of Newerth\\hon.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Jeux\\Steam\\SteamApps\\common\\plants vs zombies\\PlantsVsZombies.exe"=
"d:\\Jeux\\Steam\\SteamApps\\common\\alien breed 2 assault\\Binaries\\AlienBreed2Assault.exe"=
"d:\\Jeux\\Steam\\SteamApps\\common\\spiral knights\\java_vm\\bin\\javaw.exe"=
"d:\\Jeux\\EA Games\\Alice Madness Returns\\Alice1\\bin\\alice.exe"=
"d:\\Jeux\\EA Games\\Alice Madness Returns\\Alice2\\Binaries\\Win32\\AliceMadnessReturns.exe"=
"c:\\Documents and Settings\\Antoine\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\National Instruments\\Shared\\NI WebServer\\ApplicationWebServer.exe"=
"c:\\Program Files\\National Instruments\\Shared\\NI WebServer\\SystemWebServer.exe"=
"c:\\Program Files\\National Instruments\\Shared\\mDNS Responder\\nimdnsResponder.exe"=
"d:\\Jeux\\Psygnosis\\Rollcage Stage II\\BIN\\Rollcage D3D.exe"=
"d:\\Jeux\\Steam\\SteamApps\\xtian111\\pirates, vikings, and knights ii\\hl2.exe"=
"d:\\Jeux\\MM8BDM-v1b\\skulltag.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8381:TCP"= 8381:TCP:League of Legends Launcher
"8381:UDP"= 8381:UDP:League of Legends Launcher
"8382:TCP"= 8382:TCP:League of Legends Launcher
"8382:UDP"= 8382:UDP:League of Legends Launcher
"8383:TCP"= 8383:TCP:League of Legends Launcher
"8383:UDP"= 8383:UDP:League of Legends Launcher
"8393:TCP"= 8393:TCP:League of Legends Lobby
"8393:UDP"= 8393:UDP:League of Legends Lobby
"8390:TCP"= 8390:TCP:League of Legends Game Client
"8390:UDP"= 8390:UDP:League of Legends Game Client
"6890:TCP"= 6890:TCP:League of Legends Launcher
"6890:UDP"= 6890:UDP:League of Legends Launcher
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-07-24 218688]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-07-05 136360]
R2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [2011-07-14 99896]
R3 mvusbews;USB EWS Device;c:\windows\system32\drivers\mvusbews.sys [2011-07-14 17408]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [2011-11-06 23624]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 NIApplicationWebServer;NI Application Web Server;c:\program files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [2011-05-27 50336]
S4 nimDNSResponder;National Instruments mDNS Responder Service;c:\program files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [2011-06-01 194224]
S4 NINetworkDiscovery;NI Network Discovery;c:\program files\National Instruments\Shared\NI Network Discovery\niDiscSvc.exe [2011-06-10 121032]
.
.
——- Examen supplémentaire ——-
.
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
TCP: Interfaces\{3142997B-A9D1-4938-BF47-64968F5E532C}: NameServer = 192.168.0.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Antoine\Application Data\Mozilla\Firefox\Profiles\8j8skgbm.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-07 23:08
Windows 5.1.2600 Service Pack 2 NTFS
.
Recherche de processus cachés …
.
Recherche d'éléments en démarrage automatique cachés …
.
Recherche de fichiers cachés …
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
——————— DLLs chargées dans les processus actifs ———————
.
- - - - - - - > 'winlogon.exe'(768)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(1320)
c:\documents and settings\Antoine\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\windows\System32\shdoclc.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Autres processus actifs ————————
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lkads.exe
c:\program files\National Instruments\MAX\nimxs.exe
c:\windows\RTHDCPL.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\Tablet.exe
c:\windows\system32\lkcitdl.exe
c:\windows\system32\lktsrv.exe
c:\windows\system32\WTablet\TabUserW.exe
c:\windows\system32\Tablet.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\windows\System32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Heure de fin: 2011-11-07 23:11:40 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-11-08 04:11
.
Avant-CF: 128 585 076 736 octets libres
Après-CF: 129 697 726 464 octets libres
.
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /NoExecute=OptIn
.
- - End Of File - - DB528C8AE1564F4B6D852E929B19B7BF
Hi LobsterKing,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "8381:TCP"=-
    "8381:UDP"=-
    "8382:TCP"=-
    "8382:UDP"=-
    "8383:TCP"=-
    "8383:UDP"=-
    "8393:TCP"=-
    "8393:UDP"=-
    "8390:TCP"=-
    "8390:UDP"=-
    "6890:TCP"=-
    "6890:UDP"=-
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Hi Jeff,

Combofix asked if he could update itself. I said yes.
It did not reboot this time, and didn't mention ZeroAccess like the first time.

Log ahead !

ComboFix 11-11-08.02 - Antoine 2011-11-08 14:35:19.2.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.2.1036.18.3071.2297 [GMT -5:00]
Lancé depuis: c:\documents and settings\Antoine\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Antoine\Bureau\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-10-08 au 2011-11-08 ))))))))))))))))))))))))))))))))))))
.
.
2011-11-07 02:02 . 2004-08-19 21:09 10752 ——w- c:\windows\system32\smtpapi.dll
2011-11-07 02:02 . 2004-08-19 21:09 9728 ——w- c:\windows\system32\rwnh.dll
2011-11-07 02:02 . 2004-07-17 16:40 19528 —-a-w- c:\windows\000001_.tmp
2011-11-07 00:58 . 2011-11-07 01:03 23624 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-11-07 00:57 . 2011-11-07 01:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Hitman Pro
2011-11-06 22:38 . 2011-11-06 22:38 ——– d—–w- c:\program files\Fichiers communs\Java
2011-11-06 22:38 . 2011-10-03 10:06 476904 —-a-w- c:\program files\Mozilla Firefox\Plugins\npdeployJava1.dll
2011-11-06 22:37 . 2011-11-06 22:37 6642 —-a-w- c:\windows\system32\PerfStringBackup.TMP
2011-11-06 19:47 . 2011-11-06 19:47 ——– d—–w- c:\documents and settings\Antoine\Application Data\Malwarebytes
2011-11-06 19:47 . 2011-11-06 19:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-06 19:47 . 2011-11-06 19:47 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-11-06 19:47 . 2011-08-31 22:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-06 18:51 . 2011-11-06 18:51 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2011-11-06 18:51 . 2011-11-06 18:51 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-11-06 18:51 . 2011-11-06 18:51 ——– d-s—w- c:\documents and settings\NetworkService\UserData
2011-11-06 18:31 . 2011-11-06 18:31 ——– d—–w- c:\windows\system32\wbem\Repository
2011-11-06 18:28 . 2011-11-06 18:29 ——– d-s—w- c:\documents and settings\Administrateur
2011-10-25 21:05 . 2011-10-25 21:05 ——– d—–w- c:\program files\7-Zip
2011-10-25 19:07 . 2011-10-25 19:07 ——– d—–w- c:\documents and settings\Antoine\Local Settings\Application Data\Padus
2011-10-25 19:04 . 2011-10-25 19:05 17408 —-a-w- C:\psapi.dll
2011-10-23 00:42 . 2011-10-23 00:42 ——– d—–w- c:\program files\The Game Creators
2011-10-17 02:25 . 2011-10-17 02:25 ——– d—–w- c:\program files\Fichiers communs\DirectX
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-17 20:48 . 2011-07-06 03:19 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-03 10:06 . 2011-07-31 02:09 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-03 07:37 . 2011-07-31 02:09 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-08-31 16:05 . 2011-07-06 02:28 66616 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2011-08-31 16:05 . 2011-07-06 02:28 138192 —-a-w- c:\windows\system32\drivers\avipbb.sys
2011-08-14 21:08 . 2011-08-14 21:08 98304 —-a-w- c:\windows\system32CmdLineExt.dll
2011-06-22 15:44 . 2011-06-22 15:44 158720 —-a-w- c:\program files\internet explorer\plugins\LV2011ActiveXControl.dll
2010-10-19 22:15 . 2010-10-19 22:15 158720 —-a-w- c:\program files\internet explorer\plugins\LV90ActiveXControl.dll
2011-10-02 03:49 . 2011-07-06 03:03 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-08_04.08.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-08 19:30 . 2011-11-08 19:30 16384 c:\windows\Temp\Perflib_Perfdata_54c.dat
+ 2002-08-30 12:00 . 2007-11-13 10:25 20480 c:\windows\system32\drivers\secdrv.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Antoine\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Antoine\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Antoine\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\Antoine\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
"Steam"="d:\jeux\Steam\steam.exe" [2011-08-07 1242448]
"NIRegistrationWizard"="c:\program files\National Instruments\Shared\RegistrationWizard\Bin\RegistrationWizard.exe" [2010-06-21 846520]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-09-30 16864768]
"Six Engine"="c:\program files\ASUS\EPU-4 Engine\FourEngine.exe" [2008-07-23 5625344]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-17 281768]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"ContentTransferWMDetector.exe"="c:\program files\Sony\Content Transfer\ContentTransferWMDetector.exe" [2009-11-19 583016]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"NI Update Service"="c:\program files\National Instruments\Shared\Update Service\NIUpdateService.exe" [2011-06-07 3002976]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
.
c:\documents and settings\Antoine\Menu Démarrer\Programmes\Démarrage\
Dropbox.lnk - c:\documents and settings\Antoine\Application Data\Dropbox\bin\Dropbox.exe [2011-9-1 24183152]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^NI Error Reporting.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\NI Error Reporting.lnk
backup=c:\windows\pss\NI Error Reporting.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NITaggerService"=2 (0x2)
"niSvcLoc"=2 (0x2)
"NINetworkDiscovery"=2 (0x2)
"nimDNSResponder"=2 (0x2)
"NILM License Manager"=3 (0x3)
"NIDomainService"=2 (0x2)
"NIApplicationWebServer"=2 (0x2)
"Bonjour Service"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Jeux\\Steam\\Steam.exe"=
"d:\\Jeux\\Riot Games\\League of Legends\\lol.launcher.exe"=
"d:\\Jeux\\Steam\\SteamApps\\common\\magicka trailer\\smp.exe"=
"d:\\Jeux\\Steam\\SteamApps\\common\\amd driver updater, xp, 32 bit\\Setup.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Jeux\\Heroes of Newerth\\hon.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Jeux\\Steam\\SteamApps\\common\\plants vs zombies\\PlantsVsZombies.exe"=
"d:\\Jeux\\Steam\\SteamApps\\common\\alien breed 2 assault\\Binaries\\AlienBreed2Assault.exe"=
"d:\\Jeux\\Steam\\SteamApps\\common\\spiral knights\\java_vm\\bin\\javaw.exe"=
"d:\\Jeux\\EA Games\\Alice Madness Returns\\Alice1\\bin\\alice.exe"=
"d:\\Jeux\\EA Games\\Alice Madness Returns\\Alice2\\Binaries\\Win32\\AliceMadnessReturns.exe"=
"c:\\Documents and Settings\\Antoine\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\National Instruments\\Shared\\NI WebServer\\ApplicationWebServer.exe"=
"c:\\Program Files\\National Instruments\\Shared\\NI WebServer\\SystemWebServer.exe"=
"c:\\Program Files\\National Instruments\\Shared\\mDNS Responder\\nimdnsResponder.exe"=
"d:\\Jeux\\Psygnosis\\Rollcage Stage II\\BIN\\Rollcage D3D.exe"=
"d:\\Jeux\\Steam\\SteamApps\\xtian111\\pirates, vikings, and knights ii\\hl2.exe"=
"d:\\Jeux\\MM8BDM-v1b\\skulltag.exe"=
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-07-24 218688]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-07-05 136360]
R2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [2011-07-14 99896]
R3 mvusbews;USB EWS Device;c:\windows\system32\drivers\mvusbews.sys [2011-07-14 17408]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [2011-11-06 23624]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 NIApplicationWebServer;NI Application Web Server;c:\program files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [2011-05-27 50336]
S4 nimDNSResponder;National Instruments mDNS Responder Service;c:\program files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe [2011-06-01 194224]
S4 NINetworkDiscovery;NI Network Discovery;c:\program files\National Instruments\Shared\NI Network Discovery\niDiscSvc.exe [2011-06-10 121032]
.
.
——- Examen supplémentaire ——-
.
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
TCP: Interfaces\{3142997B-A9D1-4938-BF47-64968F5E532C}: NameServer = 192.168.0.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Antoine\Application Data\Mozilla\Firefox\Profiles\8j8skgbm.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-08 14:40
Windows 5.1.2600 Service Pack 2 NTFS
.
Recherche de processus cachés …
.
Recherche d'éléments en démarrage automatique cachés …
.
Recherche de fichiers cachés …
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
——————— DLLs chargées dans les processus actifs ———————
.
- - - - - - - > 'winlogon.exe'(764)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(3664)
c:\documents and settings\Antoine\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\windows\System32\shdoclc.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Heure de fin: 2011-11-08 14:41:18
ComboFix-quarantined-files.txt 2011-11-08 19:41
ComboFix2.txt 2011-11-08 04:11
.
Avant-CF: 129 778 262 016 octets libres
Après-CF: 129 762 394 112 octets libres
.
- - End Of File - - 96A4FF0849DA612B8CD0D912CDB532A5
Hi LobsterKing,

Please run TDSSKiller once more and save the log that is created for your next reply.
———-

I see that you have Malwarebytes on your system. Please open Malwarebytes, update it and then run a Quick Scan. Save that log for your next reply.
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply please post the logs created by TDSSKiller, Malwarebytes and ESET online scanner. :)
Hey Jeff, here's what you asked for! :)
I'm sorry, my OS is French, I hope it does not hinder you too much when reading logs.


TDSSKiller

14:55:28.0765 3000 TDSS rootkit removing tool 2.6.16.0 Nov 7 2011 16:26:51
14:55:28.0859 3000 ============================================================
14:55:28.0859 3000 Current date / time: 2011/11/08 14:55:28.0859
14:55:28.0859 3000 SystemInfo:
14:55:28.0859 3000
14:55:28.0859 3000 OS Version: 5.1.2600 ServicePack: 2.0
14:55:28.0859 3000 Product type: Workstation
14:55:28.0859 3000 ComputerName: ATLANTIS
14:55:28.0859 3000 UserName: Antoine
14:55:28.0859 3000 Windows directory: C:\WINDOWS
14:55:28.0859 3000 System windows directory: C:\WINDOWS
14:55:28.0859 3000 Processor architecture: Intel x86
14:55:28.0859 3000 Number of processors: 2
14:55:28.0859 3000 Page size: 0x1000
14:55:28.0859 3000 Boot type: Normal boot
14:55:28.0859 3000 ============================================================
14:55:29.0828 3000 Initialize success
14:55:31.0109 2140 ============================================================
14:55:31.0109 2140 Scan started
14:55:31.0109 2140 Mode: Manual;
14:55:31.0109 2140 ============================================================
14:55:31.0890 2140 Abiosdsk - ok
14:55:31.0906 2140 abp480n5 - ok
14:55:31.0921 2140 ACPI (0bd94fbfc14ea3606cd6ca4c0255baa3) C:\WINDOWS\system32\DRIVERS\ACPI.sys
14:55:31.0921 2140 ACPI - ok
14:55:31.0953 2140 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\drivers\ACPIEC.sys
14:55:31.0953 2140 ACPIEC - ok
14:55:31.0968 2140 adpu160m - ok
14:55:32.0000 2140 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys
14:55:32.0000 2140 aec - ok
14:55:32.0031 2140 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
14:55:32.0031 2140 AFD - ok
14:55:32.0031 2140 Aha154x - ok
14:55:32.0046 2140 aic78u2 - ok
14:55:32.0046 2140 aic78xx - ok
14:55:32.0062 2140 AliIde - ok
14:55:32.0062 2140 amsint - ok
14:55:32.0078 2140 asc - ok
14:55:32.0078 2140 asc3350p - ok
14:55:32.0093 2140 asc3550 - ok
14:55:32.0125 2140 AsIO (2b4e66fac6503494a2c6f32bb6ab3826) C:\WINDOWS\system32\drivers\AsIO.sys
14:55:32.0140 2140 AsIO - ok
14:55:32.0171 2140 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
14:55:32.0187 2140 AsyncMac - ok
14:55:32.0203 2140 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
14:55:32.0218 2140 atapi - ok
14:55:32.0218 2140 Atdisk - ok
14:55:32.0343 2140 ati2mtag (23f1a61ae7553d086ef264c72afc4e6a) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
14:55:32.0390 2140 ati2mtag - ok
14:55:32.0421 2140 AtiHdmiService (41c8f0eda10da14378d304c20ba6e558) C:\WINDOWS\system32\drivers\AtiHdmi.sys
14:55:32.0421 2140 AtiHdmiService - ok
14:55:32.0437 2140 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
14:55:32.0437 2140 Atmarpc - ok
14:55:32.0468 2140 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
14:55:32.0468 2140 audstub - ok
14:55:32.0500 2140 avgio (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Program Files\Avira\AntiVir Desktop\avgio.sys
14:55:32.0500 2140 avgio - ok
14:55:32.0515 2140 avgntflt (1e4114685de1ffa9675e09c6a1fb3f4b) C:\WINDOWS\system32\DRIVERS\avgntflt.sys
14:55:32.0515 2140 avgntflt - ok
14:55:32.0546 2140 avipbb (0f78d3dae6dedd99ae54c9491c62adf2) C:\WINDOWS\system32\DRIVERS\avipbb.sys
14:55:32.0562 2140 avipbb - ok
14:55:32.0593 2140 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
14:55:32.0593 2140 Beep - ok
14:55:32.0656 2140 catchme - ok
14:55:32.0671 2140 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
14:55:32.0687 2140 cbidf2k - ok
14:55:32.0687 2140 cd20xrnt - ok
14:55:32.0703 2140 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
14:55:32.0703 2140 Cdaudio - ok
14:55:32.0734 2140 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
14:55:32.0734 2140 Cdfs - ok
14:55:32.0765 2140 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
14:55:32.0765 2140 Cdrom - ok
14:55:32.0765 2140 Changer - ok
14:55:32.0781 2140 CmdIde - ok
14:55:32.0796 2140 Cpqarray - ok
14:55:32.0828 2140 cvintdrv (dbd89bc0dbe00dcd245be8f61dbee291) C:\WINDOWS\system32\drivers\cvintdrv.sys
14:55:32.0828 2140 cvintdrv - ok
14:55:32.0828 2140 dac2w2k - ok
14:55:32.0843 2140 dac960nt - ok
14:55:32.0843 2140 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
14:55:32.0859 2140 Disk - ok
14:55:32.0875 2140 dmboot (e2d3b7620310fe56685f9b15a6b404b3) C:\WINDOWS\system32\drivers\dmboot.sys
14:55:32.0890 2140 dmboot - ok
14:55:32.0906 2140 dmio (c77f5c20aa70197a69aa84baa9de43c8) C:\WINDOWS\system32\drivers\dmio.sys
14:55:32.0906 2140 dmio - ok
14:55:32.0921 2140 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
14:55:32.0921 2140 dmload - ok
14:55:32.0953 2140 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
14:55:32.0968 2140 DMusic - ok
14:55:32.0968 2140 dpti2o - ok
14:55:33.0000 2140 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
14:55:33.0000 2140 drmkaud - ok
14:55:33.0031 2140 dtsoftbus01 (555e54ac2f601a8821cef58961653991) C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys
14:55:33.0031 2140 dtsoftbus01 - ok
14:55:33.0046 2140 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
14:55:33.0062 2140 Fastfat - ok
14:55:33.0062 2140 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys
14:55:33.0078 2140 Fdc - ok
14:55:33.0078 2140 Fips (8b121ff880683607ab2aef0340721718) C:\WINDOWS\system32\drivers\Fips.sys
14:55:33.0093 2140 Fips - ok
14:55:33.0109 2140 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
14:55:33.0109 2140 Flpydisk - ok
14:55:33.0140 2140 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\drivers\fltmgr.sys
14:55:33.0140 2140 FltMgr - ok
14:55:33.0156 2140 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
14:55:33.0156 2140 Fs_Rec - ok
14:55:33.0156 2140 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
14:55:33.0171 2140 Ftdisk - ok
14:55:33.0187 2140 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
14:55:33.0187 2140 Gpc - ok
14:55:33.0218 2140 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
14:55:33.0218 2140 HDAudBus - ok
14:55:33.0265 2140 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
14:55:33.0265 2140 hidusb - ok
14:55:33.0281 2140 hitmanpro35 (72472b9ce5d02e443cff49a40355455d) C:\WINDOWS\system32\drivers\hitmanpro35.sys
14:55:33.0296 2140 hitmanpro35 - ok
14:55:33.0296 2140 hpn - ok
14:55:33.0328 2140 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys
14:55:33.0328 2140 HTTP - ok
14:55:33.0343 2140 i2omgmt - ok
14:55:33.0359 2140 i2omp - ok
14:55:33.0390 2140 i8042prt (d1efcbd693b5ba21314d06368c471070) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
14:55:33.0390 2140 i8042prt - ok
14:55:33.0437 2140 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
14:55:33.0437 2140 Imapi - ok
14:55:33.0453 2140 ini910u - ok
14:55:33.0546 2140 IntcAzAudAddService (6f336c2d18ba1e7ce8d0f31541c87a1d) C:\WINDOWS\system32\drivers\RtkHDAud.sys
14:55:33.0562 2140 IntcAzAudAddService - ok
14:55:33.0578 2140 IntelIde - ok
14:55:33.0625 2140 intelppm (dd5ad1e79ac26d3f8d8828ad4627f160) C:\WINDOWS\system32\DRIVERS\intelppm.sys
14:55:33.0625 2140 intelppm - ok
14:55:33.0640 2140 ip6fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys
14:55:33.0640 2140 ip6fw - ok
14:55:33.0656 2140 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
14:55:33.0656 2140 IpFilterDriver - ok
14:55:33.0671 2140 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
14:55:33.0687 2140 IpInIp - ok
14:55:33.0703 2140 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys
14:55:33.0703 2140 IpNat - ok
14:55:33.0718 2140 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
14:55:33.0718 2140 IPSec - ok
14:55:33.0734 2140 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
14:55:33.0734 2140 IRENUM - ok
14:55:33.0781 2140 isapnp (54632f1a7de61dc3615d756f2a90fa72) C:\WINDOWS\system32\DRIVERS\isapnp.sys
14:55:33.0781 2140 isapnp - ok
14:55:33.0796 2140 Kbdclass (e798705e8dc7fab596ef6bfdf167e007) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
14:55:33.0796 2140 Kbdclass - ok
14:55:33.0828 2140 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys
14:55:33.0828 2140 kmixer - ok
14:55:33.0859 2140 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys
14:55:33.0859 2140 KSecDD - ok
14:55:33.0875 2140 L1e (fa46f5d09edf93e0c71fe6500fe3f4ae) C:\WINDOWS\system32\DRIVERS\l1e51x86.sys
14:55:33.0875 2140 L1e - ok
14:55:33.0875 2140 lbrtfdc - ok
14:55:33.0921 2140 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
14:55:33.0921 2140 mnmdd - ok
14:55:33.0953 2140 Modem (5ac7e16f5b40a6da14b5f2b3ada4693e) C:\WINDOWS\system32\drivers\Modem.sys
14:55:33.0953 2140 Modem - ok
14:55:33.0968 2140 Mouclass (7d4f19411bd941e1d432a99e24230386) C:\WINDOWS\system32\DRIVERS\mouclass.sys
14:55:33.0984 2140 Mouclass - ok
14:55:33.0984 2140 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys
14:55:34.0000 2140 mouhid - ok
14:55:34.0000 2140 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
14:55:34.0015 2140 MountMgr - ok
14:55:34.0015 2140 mraid35x - ok
14:55:34.0046 2140 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
14:55:34.0046 2140 MRxDAV - ok
14:55:34.0078 2140 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
14:55:34.0078 2140 MRxSmb - ok
14:55:34.0109 2140 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
14:55:34.0109 2140 Msfs - ok
14:55:34.0140 2140 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
14:55:34.0140 2140 MSKSSRV - ok
14:55:34.0156 2140 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
14:55:34.0156 2140 MSPCLOCK - ok
14:55:34.0156 2140 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
14:55:34.0171 2140 MSPQM - ok
14:55:34.0203 2140 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
14:55:34.0203 2140 mssmbios - ok
14:55:34.0203 2140 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys
14:55:34.0203 2140 MTsensor - ok
14:55:34.0234 2140 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
14:55:34.0250 2140 Mup - ok
14:55:34.0281 2140 mvusbews (b9df137953a5280eddbd4a705ca093a2) C:\WINDOWS\system32\Drivers\mvusbews.sys
14:55:34.0281 2140 mvusbews - ok
14:55:34.0296 2140 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
14:55:34.0296 2140 NDIS - ok
14:55:34.0312 2140 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
14:55:34.0312 2140 NdisTapi - ok
14:55:34.0328 2140 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
14:55:34.0328 2140 Ndisuio - ok
14:55:34.0328 2140 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
14:55:34.0343 2140 NdisWan - ok
14:55:34.0343 2140 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
14:55:34.0359 2140 NDProxy - ok
14:55:34.0359 2140 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
14:55:34.0359 2140 NetBIOS - ok
14:55:34.0375 2140 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
14:55:34.0390 2140 NetBT - ok
14:55:34.0421 2140 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
14:55:34.0421 2140 Npfs - ok
14:55:34.0468 2140 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys
14:55:34.0468 2140 Ntfs - ok
14:55:34.0484 2140 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
14:55:34.0484 2140 Null - ok
14:55:34.0515 2140 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
14:55:34.0515 2140 NwlnkFlt - ok
14:55:34.0515 2140 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
14:55:34.0515 2140 NwlnkFwd - ok
14:55:34.0546 2140 Parport (318696359ac7df48d1e51974ec527dd2) C:\WINDOWS\system32\drivers\Parport.sys
14:55:34.0546 2140 Parport - ok
14:55:34.0562 2140 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
14:55:34.0562 2140 PartMgr - ok
14:55:34.0578 2140 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys
14:55:34.0593 2140 ParVdm - ok
14:55:34.0609 2140 PCI (7c5da5c1ed801ad8b0309d5514f0b75e) C:\WINDOWS\system32\DRIVERS\pci.sys
14:55:34.0609 2140 PCI - ok
14:55:34.0609 2140 PCIDump - ok
14:55:34.0625 2140 PCIIde (f4bfde7209c14a07aaa61e4d6ae69eac) C:\WINDOWS\system32\DRIVERS\pciide.sys
14:55:34.0625 2140 PCIIde - ok
14:55:34.0640 2140 Pcmcia (641da274e163617ea7a33506bc6da8e3) C:\WINDOWS\system32\drivers\Pcmcia.sys
14:55:34.0640 2140 Pcmcia - ok
14:55:34.0656 2140 PDCOMP - ok
14:55:34.0656 2140 PDFRAME - ok
14:55:34.0656 2140 PDRELI - ok
14:55:34.0671 2140 PDRFRAME - ok
14:55:34.0671 2140 perc2 - ok
14:55:34.0687 2140 perc2hib - ok
14:55:34.0718 2140 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
14:55:34.0718 2140 PptpMiniport - ok
14:55:34.0734 2140 Processor (f480712b761e538bc8e44ede60f3a3c3) C:\WINDOWS\system32\DRIVERS\processr.sys
14:55:34.0734 2140 Processor - ok
14:55:34.0750 2140 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
14:55:34.0750 2140 PSched - ok
14:55:34.0765 2140 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
14:55:34.0765 2140 Ptilink - ok
14:55:34.0781 2140 ql1080 - ok
14:55:34.0781 2140 Ql10wnt - ok
14:55:34.0781 2140 ql12160 - ok
14:55:34.0796 2140 ql1240 - ok
14:55:34.0796 2140 ql1280 - ok
14:55:34.0812 2140 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
14:55:34.0812 2140 RasAcd - ok
14:55:34.0828 2140 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
14:55:34.0828 2140 Rasl2tp - ok
14:55:34.0843 2140 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
14:55:34.0843 2140 RasPppoe - ok
14:55:34.0859 2140 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
14:55:34.0859 2140 Raspti - ok
14:55:34.0890 2140 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys
14:55:34.0890 2140 Rdbss - ok
14:55:34.0890 2140 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
14:55:34.0906 2140 RDPCDD - ok
14:55:34.0921 2140 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
14:55:34.0921 2140 rdpdr - ok
14:55:34.0953 2140 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys
14:55:34.0968 2140 RDPWD - ok
14:55:34.0984 2140 redbook (2cc30b68dd62b73d444a41322cd7fc4c) C:\WINDOWS\system32\DRIVERS\redbook.sys
14:55:34.0984 2140 redbook - ok
14:55:35.0015 2140 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
14:55:35.0015 2140 Secdrv - ok
14:55:35.0031 2140 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
14:55:35.0031 2140 serenum - ok
14:55:35.0062 2140 Serial (653201755ca96ab4aaa4131daf6da356) C:\WINDOWS\system32\DRIVERS\serial.sys
14:55:35.0062 2140 Serial - ok
14:55:35.0078 2140 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
14:55:35.0078 2140 Sfloppy - ok
14:55:35.0093 2140 Simbad - ok
14:55:35.0109 2140 Sparrow - ok
14:55:35.0140 2140 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys
14:55:35.0140 2140 splitter - ok
14:55:35.0171 2140 sr (b52181023b827acda36c1b76751ebffd) C:\WINDOWS\system32\DRIVERS\sr.sys
14:55:35.0171 2140 sr - ok
14:55:35.0203 2140 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys
14:55:35.0218 2140 Srv - ok
14:55:35.0250 2140 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
14:55:35.0250 2140 ssmdrv - ok
14:55:35.0265 2140 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
14:55:35.0265 2140 swenum - ok
14:55:35.0296 2140 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
14:55:35.0296 2140 swmidi - ok
14:55:35.0312 2140 symc810 - ok
14:55:35.0328 2140 symc8xx - ok
14:55:35.0328 2140 sym_hi - ok
14:55:35.0343 2140 sym_u3 - ok
14:55:35.0359 2140 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
14:55:35.0359 2140 sysaudio - ok
14:55:35.0390 2140 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys
14:55:35.0406 2140 Tcpip - ok
14:55:35.0421 2140 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
14:55:35.0421 2140 TDPIPE - ok
14:55:35.0437 2140 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
14:55:35.0437 2140 TDTCP - ok
14:55:35.0453 2140 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
14:55:35.0468 2140 TermDD - ok
14:55:35.0468 2140 TosIde - ok
14:55:35.0484 2140 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
14:55:35.0500 2140 Udfs - ok
14:55:35.0500 2140 ultra - ok
14:55:35.0546 2140 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys
14:55:35.0546 2140 Update - ok
14:55:35.0578 2140 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
14:55:35.0578 2140 usbccgp - ok
14:55:35.0625 2140 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
14:55:35.0625 2140 usbehci - ok
14:55:35.0625 2140 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
14:55:35.0640 2140 usbhub - ok
14:55:35.0687 2140 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
14:55:35.0687 2140 usbprint - ok
14:55:35.0718 2140 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
14:55:35.0718 2140 usbscan - ok
14:55:35.0750 2140 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:55:35.0750 2140 USBSTOR - ok
14:55:35.0781 2140 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
14:55:35.0796 2140 usbuhci - ok
14:55:35.0828 2140 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
14:55:35.0828 2140 VgaSave - ok
14:55:35.0828 2140 ViaIde - ok
14:55:35.0859 2140 VolSnap (313b1a0d5db26dfe1c34a6c13b2ce0a7) C:\WINDOWS\system32\drivers\VolSnap.sys
14:55:35.0875 2140 VolSnap - ok
14:55:35.0921 2140 wacommousefilter (427a8bc96f16c40df81c2d2f4edd32dd) C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys
14:55:35.0921 2140 wacommousefilter - ok
14:55:35.0953 2140 wacomvhid (73e6f16a1f187d71fb26af308551e54a) C:\WINDOWS\system32\DRIVERS\wacomvhid.sys
14:55:35.0968 2140 wacomvhid - ok
14:55:35.0968 2140 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
14:55:35.0968 2140 Wanarp - ok
14:55:36.0015 2140 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys
14:55:36.0015 2140 Wdf01000 - ok
14:55:36.0031 2140 WDICA - ok
14:55:36.0062 2140 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys
14:55:36.0078 2140 wdmaud - ok
14:55:36.0125 2140 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
14:55:36.0125 2140 WpdUsb - ok
14:55:36.0171 2140 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
14:55:36.0187 2140 WudfPf - ok
14:55:36.0187 2140 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
14:55:36.0187 2140 WudfRd - ok
14:55:36.0218 2140 MBR (0x1B8) (c99c3199cfaa4cbdcd91493f6d113a50) \Device\Harddisk0\DR0
14:55:36.0281 2140 \Device\Harddisk0\DR0 - ok
14:55:36.0281 2140 Boot (0x1200) (5fba20f0b397ae3b6b099fe929f63a13) \Device\Harddisk0\DR0\Partition0
14:55:36.0281 2140 \Device\Harddisk0\DR0\Partition0 - ok
14:55:36.0296 2140 Boot (0x1200) (8b127d03b7ed7e0c5d5b69e2e71b56fe) \Device\Harddisk0\DR0\Partition1
14:55:36.0296 2140 \Device\Harddisk0\DR0\Partition1 - ok
14:55:36.0296 2140 ============================================================
14:55:36.0296 2140 Scan finished
14:55:36.0296 2140 ============================================================
14:55:36.0312 1932 Detected object count: 0
14:55:36.0312 1932 Actual detected object count: 0
15:03:30.0078 2996 Deinitialize success



MalwareBytes

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Version de la base de données: 8098

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

2011-11-08 14:59:44
mbam-log-2011-11-08 (14-59-44).txt

Type d'examen: Examen rapide
Elément(s) analysé(s): 175817
Temps écoulé: 2 minute(s), 53 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)



ESET Threats found:

C:\System Volume Information\_restore{FF4A8485-274D-4665-AD43-2320E3548B40}\RP120\A0023183.sys a variant of Win32/Rootkit.Kryptik.EX trojan
C:\System Volume Information\_restore{FF4A8485-274D-4665-AD43-2320E3548B40}\RP120\A0023204.sys a variant of Win32/Rootkit.Kryptik.EX trojan
C:\System Volume Information\_restore{FF4A8485-274D-4665-AD43-2320E3548B40}\RP121\A0023325.sys a variant of Win32/Rootkit.Kryptik.EX trojan
Hey Jeff, I'd like to thank you again and say that I really appreciate your help. Seems fine so far. There were no virus alerts in the last hours and I don't see any suspiscious proccesses. I guess I should turn off Windows' system restore to clean System Volume Information. ESET only found threats in there, and last time Avira detected something, it was there too. And I don't think I want to restore the system to a previously infected state. :huh: EDIT : I didn't experience any weird webpage redirections today. I didn't browse around a lot, though.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI