Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Analyse rapport Combofix


Messages recommandés

Posté(e)

j'ai enregistré gmer sur mon bureau

 

oui mon antivirus fonctionne normalement

 

j'ai un virus? qu'en pense tu?

Posté(e)

C'est possible, mais si, par exemple, on a installé et utilisé ComboFix puis désinstallé/réinstallé, cela peut fausser tous les rapports suivants.

 

Si tu as bien utilisé Gmer comme recommandé, il ne montre rien de très spécial mais on va faire une vérif ou deux.

 

"N'est pas une application Win32 valide" est parfois le signe d'un Bagle présent ou de TDSS, mais je ne les vois ni dans le rapport ComboFix ni dans Gmer.

 

Télécharge load_tdsskiller de Loup Blanc sur ton Bureau en cliquant sur ce lien :

 

http://fradesch.perso.cegetel.net/transf/Load_tdsskiller.exe

 

Cet outil est conçu pour automatiser différentes tâches proposées par TDSSKiller, un fix de Kaspersky.

  • Lance load_tdsskiller en double-cliquant dessus : l'outil va se connecter au Net pour télécharger une copie à jour de TDSSKiller, puis va lancer le scan
  • A la fin du scan, appuie sur une touche pour continuer, comme l'indique le message dans la fenêtre noire d'invite de commande
  • Le rapport s'affichera automatiquement : copie-colle son contenu dans ta prochaine réponse (le fichier est également présent ici : C:\tdsskiller\report.txt)
  • Fais redémarrer ton PC

 

NB: Pendant la procédure, si TDSSKiller fait apparaître ce message:

Hidden service detected: H8SRTd.sys

Type "delete" (without quotes) to delete it: 14:30:08:000 0256

, tape delete et valide.

 

@++

Posté(e)

Mince :P

 

Tu as vu la fenêtre noire je suppose. (pas très longtemps).

 

Regarde toujours par le poste de travail/double clic sur C pour voir si tu trouves le rapport:

 

C:\tdsskiller\report.txt)

 

AVG est la version gratuite? Serais-tu d'accord pour en mettre un autre plus performant et aussi gratuit?

Posté(e)

j'ai été dans C:/tdsskiller mais il n'y a pas de dossier report

 

oui je serais ok pour un antivirus plus performant et gratuit

 

est-ce normal le message d'erreur win32...?

de plus mon ordinateur est très lent

Posté(e)

Je viens de tester l'outil, il m'ouvre un texte vide aussi mais j'ai trouvé le rapport sur le C.

 

As-tu redémarré le pc après l'utilisation de TDSSKiller? Il faut le faire. Tu verras s'il y a ou non un rapport.

 

Ok pour l'antivirus, je te dis ça après.

 

@++

Posté(e)

Ca m'ennuie de ne pas voir ce rapport.

 

Désolé pour ce contretemps mais je vais te faire recommencer avec le téléchargement direct de l'outil que j'ai téléchargé moi-même chez Kaspersky et que j'ai hébergé.

 

Il est ultra important que tu l'enregistres sur ton bureau et nulle-part ailleurs.

 

Télécharge-le ici: http://senduit.com/573c50

 

Va dans Démarrer/exécuter (ou touches Windows et R) et copie/colle le contenu du cadre (sans le mot code) ci-dessous:

 

"%userprofile%\bureau\TDSSKiller.exe" -l TDSSlog.txt -v

 

A la fin de l'exécution, appuie sur une touche comme demandé pour fermer la fenêtre.

Un fichier TDSSlog.txt va apparaitre sur ton bureau.

Ouvre le et poste l'intégralité de son contenu dans ta prochaine réponse.

 

NB: si l'outil demande un reboot, accepter en tapant Y (yes). ;-

 

@++

Posté(e)

[voila le rapport

 

19:39:08:171 1512 TDSS rootkit removing tool 2.2.2 Jan 13 2010 08:42:25

19:39:08:171 1512 ================================================================================

19:39:08:171 1512 SystemInfo:

 

19:39:08:171 1512 OS Version: 5.1.2600 ServicePack: 2.0

19:39:08:171 1512 Product type: Workstation

19:39:08:171 1512 ComputerName: MARIE

19:39:08:171 1512 UserName: HP_Propriétaire

19:39:08:171 1512 Windows directory: C:\WINDOWS

19:39:08:171 1512 Processor architecture: Intel x86

19:39:08:171 1512 Number of processors: 1

19:39:08:171 1512 Page size: 0x1000

19:39:08:171 1512 Boot type: Normal boot

19:39:08:171 1512 ================================================================================

19:39:08:171 1512 UnloadDriverW: NtUnloadDriver error 2

19:39:08:171 1512 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2

19:39:08:187 1512 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000

19:39:08:234 1512 UtilityInit: KLMD drop and load success

19:39:08:234 1512 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201000)

19:39:08:234 1512 UtilityInit: KLMD open success

19:39:08:234 1512 UtilityInit: Initialize success

19:39:08:234 1512

19:39:08:234 1512 Scanning Services ...

19:39:08:234 1512 CreateRegParser: Registry parser init started

19:39:08:234 1512 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127

19:39:08:234 1512 CreateRegParser: DisableWow64Redirection error

19:39:08:234 1512 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system

19:39:08:234 1512 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043

19:39:08:234 1512 wfopen_ex: MyNtCreateFileW error 32 (C0000043)

19:39:08:234 1512 wfopen_ex: Trying to KLMD file open

19:39:08:234 1512 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system

19:39:08:234 1512 wfopen_ex: File opened ok (Flags 2)

19:39:08:234 1512 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: 9C4938

19:39:08:234 1512 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software

19:39:08:250 1512 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043

19:39:08:250 1512 wfopen_ex: MyNtCreateFileW error 32 (C0000043)

19:39:08:250 1512 wfopen_ex: Trying to KLMD file open

19:39:08:250 1512 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software

19:39:08:250 1512 wfopen_ex: File opened ok (Flags 2)

19:39:08:250 1512 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: 9C49E0

19:39:08:250 1512 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127

19:39:08:250 1512 CreateRegParser: EnableWow64Redirection error

19:39:08:250 1512 CreateRegParser: RegParser init completed

19:39:08:562 1512 GetAdvancedServicesInfo: Raw services enum returned 305 services

19:39:08:562 1512 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system

19:39:08:562 1512 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software

19:39:08:562 1512

19:39:08:562 1512 Scanning Kernel memory ...

19:39:08:562 1512 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk

19:39:08:562 1512 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 86532A08

19:39:08:562 1512 DetectCureTDL3: KLMD_GetDeviceObjectList returned 13 DevObjects

19:39:08:562 1512

19:39:08:562 1512 DetectCureTDL3: DEVICE_OBJECT: 85E43868

19:39:08:562 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 85E43868

19:39:08:562 1512 KLMD_ReadMem: Trying to ReadMemory 0x85E43868[0x38]

19:39:08:562 1512 DetectCureTDL3: DRIVER_OBJECT: 86532A08

19:39:08:562 1512 KLMD_ReadMem: Trying to ReadMemory 0x86532A08[0xA8]

19:39:08:562 1512 KLMD_ReadMem: Trying to ReadMemory 0xE1023930[0x18]

19:39:08:562 1512 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

19:39:08:562 1512 DetectCureTDL3: IrpHandler (0) addr: F7676C30

19:39:08:562 1512 DetectCureTDL3: IrpHandler (1) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (2) addr: F7676C30

19:39:08:562 1512 DetectCureTDL3: IrpHandler (3) addr: F7670D9B

19:39:08:562 1512 DetectCureTDL3: IrpHandler (4) addr: F7670D9B

19:39:08:562 1512 DetectCureTDL3: IrpHandler (5) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (6) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (7) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (:P addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (9) addr: F7671366

19:39:08:562 1512 DetectCureTDL3: IrpHandler (10) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (11) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (12) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (13) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (14) addr: F767144D

19:39:08:562 1512 DetectCureTDL3: IrpHandler (15) addr: F7674FC3

19:39:08:562 1512 DetectCureTDL3: IrpHandler (16) addr: F7671366

19:39:08:562 1512 DetectCureTDL3: IrpHandler (17) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (18) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (19) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (20) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (21) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (22) addr: F7672EF3

19:39:08:562 1512 DetectCureTDL3: IrpHandler (23) addr: F7677A24

19:39:08:562 1512 DetectCureTDL3: IrpHandler (24) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (25) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (26) addr: 804F320E

19:39:08:562 1512 TDL3_FileDetect: Processing driver: Disk

19:39:08:562 1512 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys

19:39:08:562 1512 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys

19:39:08:562 1512 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean

19:39:08:562 1512

19:39:08:562 1512 DetectCureTDL3: DEVICE_OBJECT: 85E85C68

19:39:08:562 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 85E85C68

19:39:08:562 1512 KLMD_ReadMem: Trying to ReadMemory 0x85E85C68[0x38]

19:39:08:562 1512 DetectCureTDL3: DRIVER_OBJECT: 86532A08

19:39:08:562 1512 KLMD_ReadMem: Trying to ReadMemory 0x86532A08[0xA8]

19:39:08:562 1512 KLMD_ReadMem: Trying to ReadMemory 0xE1023930[0x18]

19:39:08:562 1512 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

19:39:08:562 1512 DetectCureTDL3: IrpHandler (0) addr: F7676C30

19:39:08:562 1512 DetectCureTDL3: IrpHandler (1) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (2) addr: F7676C30

19:39:08:562 1512 DetectCureTDL3: IrpHandler (3) addr: F7670D9B

19:39:08:562 1512 DetectCureTDL3: IrpHandler (4) addr: F7670D9B

19:39:08:562 1512 DetectCureTDL3: IrpHandler (5) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (6) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (7) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (:P addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (9) addr: F7671366

19:39:08:562 1512 DetectCureTDL3: IrpHandler (10) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (11) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (12) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (13) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (14) addr: F767144D

19:39:08:562 1512 DetectCureTDL3: IrpHandler (15) addr: F7674FC3

19:39:08:562 1512 DetectCureTDL3: IrpHandler (16) addr: F7671366

19:39:08:562 1512 DetectCureTDL3: IrpHandler (17) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (18) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (19) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (20) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (21) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (22) addr: F7672EF3

19:39:08:562 1512 DetectCureTDL3: IrpHandler (23) addr: F7677A24

19:39:08:562 1512 DetectCureTDL3: IrpHandler (24) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (25) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (26) addr: 804F320E

19:39:08:562 1512 TDL3_FileDetect: Processing driver: Disk

19:39:08:562 1512 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys

19:39:08:562 1512 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys

19:39:08:562 1512 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean

19:39:08:562 1512

19:39:08:562 1512 DetectCureTDL3: DEVICE_OBJECT: 85E581E8

19:39:08:562 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 85E581E8

19:39:08:562 1512 KLMD_ReadMem: Trying to ReadMemory 0x85E581E8[0x38]

19:39:08:562 1512 DetectCureTDL3: DRIVER_OBJECT: 86532A08

19:39:08:562 1512 KLMD_ReadMem: Trying to ReadMemory 0x86532A08[0xA8]

19:39:08:562 1512 KLMD_ReadMem: Trying to ReadMemory 0xE1023930[0x18]

19:39:08:562 1512 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

19:39:08:562 1512 DetectCureTDL3: IrpHandler (0) addr: F7676C30

19:39:08:562 1512 DetectCureTDL3: IrpHandler (1) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (2) addr: F7676C30

19:39:08:562 1512 DetectCureTDL3: IrpHandler (3) addr: F7670D9B

19:39:08:562 1512 DetectCureTDL3: IrpHandler (4) addr: F7670D9B

19:39:08:562 1512 DetectCureTDL3: IrpHandler (5) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (6) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (7) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (:P addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (9) addr: F7671366

19:39:08:562 1512 DetectCureTDL3: IrpHandler (10) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (11) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (12) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (13) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (14) addr: F767144D

19:39:08:562 1512 DetectCureTDL3: IrpHandler (15) addr: F7674FC3

19:39:08:562 1512 DetectCureTDL3: IrpHandler (16) addr: F7671366

19:39:08:562 1512 DetectCureTDL3: IrpHandler (17) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (18) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (19) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (20) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (21) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (22) addr: F7672EF3

19:39:08:562 1512 DetectCureTDL3: IrpHandler (23) addr: F7677A24

19:39:08:562 1512 DetectCureTDL3: IrpHandler (24) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (25) addr: 804F320E

19:39:08:562 1512 DetectCureTDL3: IrpHandler (26) addr: 804F320E

19:39:08:562 1512 TDL3_FileDetect: Processing driver: Disk

19:39:08:562 1512 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys

19:39:08:562 1512 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys

19:39:08:578 1512 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean

19:39:08:578 1512

19:39:08:578 1512 DetectCureTDL3: DEVICE_OBJECT: 85E585B0

19:39:08:578 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 85E585B0

19:39:08:578 1512 KLMD_ReadMem: Trying to ReadMemory 0x85E585B0[0x38]

19:39:08:578 1512 DetectCureTDL3: DRIVER_OBJECT: 86532A08

19:39:08:578 1512 KLMD_ReadMem: Trying to ReadMemory 0x86532A08[0xA8]

19:39:08:578 1512 KLMD_ReadMem: Trying to ReadMemory 0xE1023930[0x18]

19:39:08:578 1512 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

19:39:08:578 1512 DetectCureTDL3: IrpHandler (0) addr: F7676C30

19:39:08:578 1512 DetectCureTDL3: IrpHandler (1) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (2) addr: F7676C30

19:39:08:578 1512 DetectCureTDL3: IrpHandler (3) addr: F7670D9B

19:39:08:578 1512 DetectCureTDL3: IrpHandler (4) addr: F7670D9B

19:39:08:578 1512 DetectCureTDL3: IrpHandler (5) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (6) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (7) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (:P addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (9) addr: F7671366

19:39:08:578 1512 DetectCureTDL3: IrpHandler (10) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (11) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (12) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (13) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (14) addr: F767144D

19:39:08:578 1512 DetectCureTDL3: IrpHandler (15) addr: F7674FC3

19:39:08:578 1512 DetectCureTDL3: IrpHandler (16) addr: F7671366

19:39:08:578 1512 DetectCureTDL3: IrpHandler (17) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (18) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (19) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (20) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (21) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (22) addr: F7672EF3

19:39:08:578 1512 DetectCureTDL3: IrpHandler (23) addr: F7677A24

19:39:08:578 1512 DetectCureTDL3: IrpHandler (24) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (25) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (26) addr: 804F320E

19:39:08:578 1512 TDL3_FileDetect: Processing driver: Disk

19:39:08:578 1512 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys

19:39:08:578 1512 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys

19:39:08:578 1512 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean

19:39:08:578 1512

19:39:08:578 1512 DetectCureTDL3: DEVICE_OBJECT: 86297268

19:39:08:578 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86297268

19:39:08:578 1512 KLMD_ReadMem: Trying to ReadMemory 0x86297268[0x38]

19:39:08:578 1512 DetectCureTDL3: DRIVER_OBJECT: 86532A08

19:39:08:578 1512 KLMD_ReadMem: Trying to ReadMemory 0x86532A08[0xA8]

19:39:08:578 1512 KLMD_ReadMem: Trying to ReadMemory 0xE1023930[0x18]

19:39:08:578 1512 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

19:39:08:578 1512 DetectCureTDL3: IrpHandler (0) addr: F7676C30

19:39:08:578 1512 DetectCureTDL3: IrpHandler (1) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (2) addr: F7676C30

19:39:08:578 1512 DetectCureTDL3: IrpHandler (3) addr: F7670D9B

19:39:08:578 1512 DetectCureTDL3: IrpHandler (4) addr: F7670D9B

19:39:08:578 1512 DetectCureTDL3: IrpHandler (5) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (6) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (7) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (:) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (9) addr: F7671366

19:39:08:578 1512 DetectCureTDL3: IrpHandler (10) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (11) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (12) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (13) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (14) addr: F767144D

19:39:08:578 1512 DetectCureTDL3: IrpHandler (15) addr: F7674FC3

19:39:08:578 1512 DetectCureTDL3: IrpHandler (16) addr: F7671366

19:39:08:578 1512 DetectCureTDL3: IrpHandler (17) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (18) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (19) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (20) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (21) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (22) addr: F7672EF3

19:39:08:578 1512 DetectCureTDL3: IrpHandler (23) addr: F7677A24

19:39:08:578 1512 DetectCureTDL3: IrpHandler (24) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (25) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (26) addr: 804F320E

19:39:08:578 1512 TDL3_FileDetect: Processing driver: Disk

19:39:08:578 1512 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys

19:39:08:578 1512 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys

19:39:08:578 1512 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean

19:39:08:578 1512

19:39:08:578 1512 DetectCureTDL3: DEVICE_OBJECT: 85E6C8F8

19:39:08:578 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 85E6C8F8

19:39:08:578 1512 DetectCureTDL3: DEVICE_OBJECT: 85E3CC10

19:39:08:578 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 85E3CC10

19:39:08:578 1512 KLMD_ReadMem: Trying to ReadMemory 0x85E3CC10[0x38]

19:39:08:578 1512 DetectCureTDL3: DRIVER_OBJECT: 85E41C08

19:39:08:578 1512 KLMD_ReadMem: Trying to ReadMemory 0x85E41C08[0xA8]

19:39:08:578 1512 KLMD_ReadMem: Trying to ReadMemory 0xE1610860[0x1E]

19:39:08:578 1512 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR

19:39:08:578 1512 DetectCureTDL3: IrpHandler (0) addr: F78ED218

19:39:08:578 1512 DetectCureTDL3: IrpHandler (1) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (2) addr: F78ED218

19:39:08:578 1512 DetectCureTDL3: IrpHandler (3) addr: F78ED23C

19:39:08:578 1512 DetectCureTDL3: IrpHandler (4) addr: F78ED23C

19:39:08:578 1512 DetectCureTDL3: IrpHandler (5) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (6) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (7) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (;) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (9) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (10) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (11) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (12) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (13) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (14) addr: F78ED180

19:39:08:578 1512 DetectCureTDL3: IrpHandler (15) addr: F78E89E6

19:39:08:578 1512 DetectCureTDL3: IrpHandler (16) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (17) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (18) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (19) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (20) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (21) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (22) addr: F78EC5F0

19:39:08:578 1512 DetectCureTDL3: IrpHandler (23) addr: F78EAA6E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (24) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (25) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (26) addr: 804F320E

19:39:08:578 1512 KLMD_ReadMem: Trying to ReadMemory 0xF78E9F26[0x400]

19:39:08:578 1512 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0

19:39:08:578 1512 TDL3_FileDetect: Processing driver: USBSTOR

19:39:08:578 1512 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

19:39:08:578 1512 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

19:39:08:578 1512 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean

19:39:08:578 1512

19:39:08:578 1512 DetectCureTDL3: DEVICE_OBJECT: 862B2030

19:39:08:578 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 862B2030

19:39:08:578 1512 DetectCureTDL3: DEVICE_OBJECT: 85E49EA0

19:39:08:578 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 85E49EA0

19:39:08:578 1512 KLMD_ReadMem: Trying to ReadMemory 0x85E49EA0[0x38]

19:39:08:578 1512 DetectCureTDL3: DRIVER_OBJECT: 85E41C08

19:39:08:578 1512 KLMD_ReadMem: Trying to ReadMemory 0x85E41C08[0xA8]

19:39:08:578 1512 KLMD_ReadMem: Trying to ReadMemory 0xE1610860[0x1E]

19:39:08:578 1512 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR

19:39:08:578 1512 DetectCureTDL3: IrpHandler (0) addr: F78ED218

19:39:08:578 1512 DetectCureTDL3: IrpHandler (1) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (2) addr: F78ED218

19:39:08:578 1512 DetectCureTDL3: IrpHandler (3) addr: F78ED23C

19:39:08:578 1512 DetectCureTDL3: IrpHandler (4) addr: F78ED23C

19:39:08:578 1512 DetectCureTDL3: IrpHandler (5) addr: 804F320E

19:39:08:578 1512 DetectCureTDL3: IrpHandler (6) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (7) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (;) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (9) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (10) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (11) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (12) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (13) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (14) addr: F78ED180

19:39:08:593 1512 DetectCureTDL3: IrpHandler (15) addr: F78E89E6

19:39:08:593 1512 DetectCureTDL3: IrpHandler (16) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (17) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (18) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (19) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (20) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (21) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (22) addr: F78EC5F0

19:39:08:593 1512 DetectCureTDL3: IrpHandler (23) addr: F78EAA6E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (24) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (25) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (26) addr: 804F320E

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0xF78E9F26[0x400]

19:39:08:593 1512 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0

19:39:08:593 1512 TDL3_FileDetect: Processing driver: USBSTOR

19:39:08:593 1512 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

19:39:08:593 1512 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

19:39:08:593 1512 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean

19:39:08:593 1512

19:39:08:593 1512 DetectCureTDL3: DEVICE_OBJECT: 86261828

19:39:08:593 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86261828

19:39:08:593 1512 DetectCureTDL3: DEVICE_OBJECT: 85E3C720

19:39:08:593 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 85E3C720

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0x85E3C720[0x38]

19:39:08:593 1512 DetectCureTDL3: DRIVER_OBJECT: 85E41C08

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0x85E41C08[0xA8]

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0xE1610860[0x1E]

19:39:08:593 1512 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR

19:39:08:593 1512 DetectCureTDL3: IrpHandler (0) addr: F78ED218

19:39:08:593 1512 DetectCureTDL3: IrpHandler (1) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (2) addr: F78ED218

19:39:08:593 1512 DetectCureTDL3: IrpHandler (3) addr: F78ED23C

19:39:08:593 1512 DetectCureTDL3: IrpHandler (4) addr: F78ED23C

19:39:08:593 1512 DetectCureTDL3: IrpHandler (5) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (6) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (7) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (:) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (9) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (10) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (11) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (12) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (13) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (14) addr: F78ED180

19:39:08:593 1512 DetectCureTDL3: IrpHandler (15) addr: F78E89E6

19:39:08:593 1512 DetectCureTDL3: IrpHandler (16) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (17) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (18) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (19) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (20) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (21) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (22) addr: F78EC5F0

19:39:08:593 1512 DetectCureTDL3: IrpHandler (23) addr: F78EAA6E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (24) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (25) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (26) addr: 804F320E

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0xF78E9F26[0x400]

19:39:08:593 1512 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0

19:39:08:593 1512 TDL3_FileDetect: Processing driver: USBSTOR

19:39:08:593 1512 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

19:39:08:593 1512 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

19:39:08:593 1512 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean

19:39:08:593 1512

19:39:08:593 1512 DetectCureTDL3: DEVICE_OBJECT: 86299AB8

19:39:08:593 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86299AB8

19:39:08:593 1512 DetectCureTDL3: DEVICE_OBJECT: 85E498E0

19:39:08:593 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 85E498E0

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0x85E498E0[0x38]

19:39:08:593 1512 DetectCureTDL3: DRIVER_OBJECT: 85E41C08

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0x85E41C08[0xA8]

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0xE1610860[0x1E]

19:39:08:593 1512 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR

19:39:08:593 1512 DetectCureTDL3: IrpHandler (0) addr: F78ED218

19:39:08:593 1512 DetectCureTDL3: IrpHandler (1) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (2) addr: F78ED218

19:39:08:593 1512 DetectCureTDL3: IrpHandler (3) addr: F78ED23C

19:39:08:593 1512 DetectCureTDL3: IrpHandler (4) addr: F78ED23C

19:39:08:593 1512 DetectCureTDL3: IrpHandler (5) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (6) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (7) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (:D addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (9) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (10) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (11) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (12) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (13) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (14) addr: F78ED180

19:39:08:593 1512 DetectCureTDL3: IrpHandler (15) addr: F78E89E6

19:39:08:593 1512 DetectCureTDL3: IrpHandler (16) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (17) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (18) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (19) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (20) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (21) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (22) addr: F78EC5F0

19:39:08:593 1512 DetectCureTDL3: IrpHandler (23) addr: F78EAA6E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (24) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (25) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (26) addr: 804F320E

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0xF78E9F26[0x400]

19:39:08:593 1512 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0

19:39:08:593 1512 TDL3_FileDetect: Processing driver: USBSTOR

19:39:08:593 1512 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

19:39:08:593 1512 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

19:39:08:593 1512 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean

19:39:08:593 1512

19:39:08:593 1512 DetectCureTDL3: DEVICE_OBJECT: 85E72AB8

19:39:08:593 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 85E72AB8

19:39:08:593 1512 DetectCureTDL3: DEVICE_OBJECT: 8628F210

19:39:08:593 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8628F210

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0x8628F210[0x38]

19:39:08:593 1512 DetectCureTDL3: DRIVER_OBJECT: 85E41C08

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0x85E41C08[0xA8]

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0xE1610860[0x1E]

19:39:08:593 1512 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR

19:39:08:593 1512 DetectCureTDL3: IrpHandler (0) addr: F78ED218

19:39:08:593 1512 DetectCureTDL3: IrpHandler (1) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (2) addr: F78ED218

19:39:08:593 1512 DetectCureTDL3: IrpHandler (3) addr: F78ED23C

19:39:08:593 1512 DetectCureTDL3: IrpHandler (4) addr: F78ED23C

19:39:08:593 1512 DetectCureTDL3: IrpHandler (5) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (6) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (7) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (:lol: addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (9) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (10) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (11) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (12) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (13) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (14) addr: F78ED180

19:39:08:593 1512 DetectCureTDL3: IrpHandler (15) addr: F78E89E6

19:39:08:593 1512 DetectCureTDL3: IrpHandler (16) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (17) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (18) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (19) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (20) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (21) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (22) addr: F78EC5F0

19:39:08:593 1512 DetectCureTDL3: IrpHandler (23) addr: F78EAA6E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (24) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (25) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (26) addr: 804F320E

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0xF78E9F26[0x400]

19:39:08:593 1512 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0

19:39:08:593 1512 TDL3_FileDetect: Processing driver: USBSTOR

19:39:08:593 1512 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

19:39:08:593 1512 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

19:39:08:593 1512 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean

19:39:08:593 1512

19:39:08:593 1512 DetectCureTDL3: DEVICE_OBJECT: 8652D030

19:39:08:593 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8652D030

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0x8652D030[0x38]

19:39:08:593 1512 DetectCureTDL3: DRIVER_OBJECT: 86532A08

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0x86532A08[0xA8]

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0xE1023930[0x18]

19:39:08:593 1512 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

19:39:08:593 1512 DetectCureTDL3: IrpHandler (0) addr: F7676C30

19:39:08:593 1512 DetectCureTDL3: IrpHandler (1) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (2) addr: F7676C30

19:39:08:593 1512 DetectCureTDL3: IrpHandler (3) addr: F7670D9B

19:39:08:593 1512 DetectCureTDL3: IrpHandler (4) addr: F7670D9B

19:39:08:593 1512 DetectCureTDL3: IrpHandler (5) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (6) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (7) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (:mhh: addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (9) addr: F7671366

19:39:08:593 1512 DetectCureTDL3: IrpHandler (10) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (11) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (12) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (13) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (14) addr: F767144D

19:39:08:593 1512 DetectCureTDL3: IrpHandler (15) addr: F7674FC3

19:39:08:593 1512 DetectCureTDL3: IrpHandler (16) addr: F7671366

19:39:08:593 1512 DetectCureTDL3: IrpHandler (17) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (18) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (19) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (20) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (21) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (22) addr: F7672EF3

19:39:08:593 1512 DetectCureTDL3: IrpHandler (23) addr: F7677A24

19:39:08:593 1512 DetectCureTDL3: IrpHandler (24) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (25) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (26) addr: 804F320E

19:39:08:593 1512 TDL3_FileDetect: Processing driver: Disk

19:39:08:593 1512 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys

19:39:08:593 1512 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys

19:39:08:593 1512 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean

19:39:08:593 1512

19:39:08:593 1512 DetectCureTDL3: DEVICE_OBJECT: 86535C68

19:39:08:593 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86535C68

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0x86535C68[0x38]

19:39:08:593 1512 DetectCureTDL3: DRIVER_OBJECT: 86532A08

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0x86532A08[0xA8]

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0xE1023930[0x18]

19:39:08:593 1512 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk

19:39:08:593 1512 DetectCureTDL3: IrpHandler (0) addr: F7676C30

19:39:08:593 1512 DetectCureTDL3: IrpHandler (1) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (2) addr: F7676C30

19:39:08:593 1512 DetectCureTDL3: IrpHandler (3) addr: F7670D9B

19:39:08:593 1512 DetectCureTDL3: IrpHandler (4) addr: F7670D9B

19:39:08:593 1512 DetectCureTDL3: IrpHandler (5) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (6) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (7) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (:D addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (9) addr: F7671366

19:39:08:593 1512 DetectCureTDL3: IrpHandler (10) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (11) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (12) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (13) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (14) addr: F767144D

19:39:08:593 1512 DetectCureTDL3: IrpHandler (15) addr: F7674FC3

19:39:08:593 1512 DetectCureTDL3: IrpHandler (16) addr: F7671366

19:39:08:593 1512 DetectCureTDL3: IrpHandler (17) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (18) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (19) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (20) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (21) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (22) addr: F7672EF3

19:39:08:593 1512 DetectCureTDL3: IrpHandler (23) addr: F7677A24

19:39:08:593 1512 DetectCureTDL3: IrpHandler (24) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (25) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (26) addr: 804F320E

19:39:08:593 1512 TDL3_FileDetect: Processing driver: Disk

19:39:08:593 1512 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys

19:39:08:593 1512 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys

19:39:08:593 1512 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean

19:39:08:593 1512

19:39:08:593 1512 DetectCureTDL3: DEVICE_OBJECT: 86568AB8

19:39:08:593 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86568AB8

19:39:08:593 1512 DetectCureTDL3: DEVICE_OBJECT: 86569B00

19:39:08:593 1512 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86569B00

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0x86569B00[0x38]

19:39:08:593 1512 DetectCureTDL3: DRIVER_OBJECT: 86545B60

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0x86545B60[0xA8]

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0xE1022C08[0x1A]

19:39:08:593 1512 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi

19:39:08:593 1512 DetectCureTDL3: IrpHandler (0) addr: F74A2572

19:39:08:593 1512 DetectCureTDL3: IrpHandler (1) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (2) addr: F74A2572

19:39:08:593 1512 DetectCureTDL3: IrpHandler (3) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (4) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (5) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (6) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (7) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (:D addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (9) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (10) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (11) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (12) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (13) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (14) addr: F74A2592

19:39:08:593 1512 DetectCureTDL3: IrpHandler (15) addr: F749E7B4

19:39:08:593 1512 DetectCureTDL3: IrpHandler (16) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (17) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (18) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (19) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (20) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (21) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (22) addr: F74A25BC

19:39:08:593 1512 DetectCureTDL3: IrpHandler (23) addr: F74A9164

19:39:08:593 1512 DetectCureTDL3: IrpHandler (24) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (25) addr: 804F320E

19:39:08:593 1512 DetectCureTDL3: IrpHandler (26) addr: 804F320E

19:39:08:593 1512 KLMD_ReadMem: Trying to ReadMemory 0xF749F7C6[0x400]

19:39:08:609 1512 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0

19:39:08:609 1512 TDL3_FileDetect: Processing driver: atapi

19:39:08:609 1512 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys

19:39:08:609 1512 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys

19:39:08:609 1512 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Clean

19:39:08:609 1512

19:39:08:609 1512 Completed

19:39:08:609 1512

19:39:08:609 1512 Results:

19:39:08:609 1512 Memory objects infected / cured / cured on reboot: 0 / 0 / 0

19:39:08:609 1512 Registry objects infected / cured / cured on reboot: 0 / 0 / 0

19:39:08:609 1512 File objects infected / cured / cured on reboot: 0 / 0 / 0

19:39:08:609 1512

19:39:08:609 1512 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000

19:39:08:609 1512 UtilityDeinit: KLMD(ARK) unloaded successfully

Posté(e)

Parfait il n'y a pas le rootkit TDSS.

 

On va changer ton antivirus et tu feras une analyse complète.

 

Télécharge d'abord l'exécutable d'Antivir puis déconnecte toi du net. (important).

 

http://dlce.antivir.com/package/wks_avira/...personal_fr.exe

 

Désinstalle AVG par ajouter/supprimer des programmes.

 

Je te donne la procédure; tu te reconnectes au net pour faire les mises à jour d'Antivir.

 

Antivir est un antivirus gratuit, efficace et léger, maintenant en français, dont les mises à jour sont quotidiennes et les nouvelles menaces sont rapidement intégrées dans sa base virale. (D'où la meilleure protection).

 

 

 

PS: Quand un fichier infecté est détecté par Antivir, une fenêtre semblable à celle-ci s'ouvre:

 

Avira-Francais-037.jpg

 

Antivir te demande ce qu'il doit faire du fichier infecté.

Choisis Déplacer en quarantaine puis clique sur OK.

 

Tu peux automatiser ce type d'action en cochant une case), comme ci dessous :

 

img-221315ynxxt.jpg

Cela permet de ne pas rester à la surveiller.:P

 

Mets-le à jour puis lance une analyse complète.

Poste le rapport obtenu stp.

 

@ + tard :P

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...