ComboFix 14-01-21.02 - Ghislaine 21/01/2014 15:40:58.1.2 - x64 Microsoft Windows 7 Professionnel 6.1.7601.1.1252.33.1036.18.3071.1877 [GMT 1:00] Lancé depuis: d:\download.01.2014\Downloads\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B} SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Autres suppressions )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Public\AlexaNSISPlugin.3352.dll . . ((((((((((((((((((((((((((((( Fichiers créés du 2013-12-21 au 2014-01-21 )))))))))))))))))))))))))))))))))))) . . 2014-01-21 14:46 . 2014-01-21 14:46 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2014-01-21 14:46 . 2014-01-21 14:46 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-01-21 11:09 . 2014-01-21 12:31 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{74737DD1-1FC0-4169-AC96-4600F4FEB75D}\offreg.dll 2014-01-21 11:03 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{74737DD1-1FC0-4169-AC96-4600F4FEB75D}\mpengine.dll 2014-01-19 03:25 . 2014-01-19 03:25 -------- d-----w- c:\users\Ghislaine\.android 2014-01-19 02:24 . 2014-01-19 02:24 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2014-01-19 01:49 . 2014-01-19 01:49 -------- d-----w- c:\program files (x86)\VS Revo Group 2014-01-17 13:30 . 2014-01-19 02:04 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\com.adobe.dmp.contentviewer 2014-01-16 23:25 . 2014-01-16 23:25 -------- d-----w- c:\users\Ghislaine\AppData\Local\Citrix 2014-01-16 22:51 . 2014-01-16 22:51 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\GoforFiles 2014-01-16 17:00 . 2014-01-17 02:28 -------- d-----w- c:\program files\Common Files\Adobe 2014-01-16 16:59 . 2014-01-17 02:43 -------- d-----w- c:\program files\Adobe 2014-01-16 03:16 . 2014-01-16 03:16 -------- d-----w- c:\users\Ghislaine\AppData\Local\Amazon 2014-01-16 01:50 . 2014-01-16 01:50 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\pdfforge 2014-01-16 01:50 . 2012-05-05 09:54 662288 ----a-w- c:\windows\SysWow64\MSCOMCT2.OCX 2014-01-16 01:50 . 2012-05-05 09:54 137000 ----a-w- c:\windows\SysWow64\MSMAPI32.OCX 2014-01-16 01:50 . 1998-07-13 00:08 119568 ----a-w- c:\windows\SysWow64\VB6FR.DLL 2014-01-16 01:50 . 1998-07-13 00:08 141312 ----a-w- c:\windows\SysWow64\MSCMCFR.DLL 2014-01-16 01:50 . 2012-05-05 09:54 23552 ----a-w- c:\windows\SysWow64\MSMPIDE.DLL 2014-01-16 01:50 . 1998-07-13 00:08 59904 ----a-w- c:\windows\SysWow64\MSCC2FR.DLL 2014-01-15 15:13 . 2014-01-15 15:13 -------- d-----w- c:\program files (x86)\PDF Architect 2014-01-15 13:57 . 2013-11-27 01:41 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys 2014-01-15 13:57 . 2013-11-27 01:41 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2014-01-15 13:57 . 2013-11-27 01:41 53248 ----a-w- c:\windows\system32\drivers\usbehci.sys 2014-01-15 13:57 . 2013-11-27 01:41 325120 ----a-w- c:\windows\system32\drivers\usbport.sys 2014-01-15 13:57 . 2013-11-27 01:41 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys 2014-01-15 13:57 . 2013-11-27 01:41 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys 2014-01-15 13:57 . 2013-11-27 01:41 7808 ----a-w- c:\windows\system32\drivers\usbd.sys 2014-01-15 13:56 . 2013-11-26 10:32 3156480 ----a-w- c:\windows\system32\win32k.sys 2014-01-15 13:56 . 2013-11-26 11:40 376768 ----a-w- c:\windows\system32\drivers\netio.sys 2014-01-15 02:01 . 2014-01-15 02:01 -------- d-----w- c:\windows\CheckSur 2014-01-14 03:21 . 2014-01-14 03:26 1352 ----a-w- c:\windows\system32\ASOROSet.bin 2014-01-14 03:11 . 2014-01-15 17:34 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\Systweak 2014-01-14 03:11 . 2013-02-28 15:27 20312 ----a-w- c:\windows\system32\roboot64.exe 2014-01-14 01:47 . 2014-01-14 01:47 -------- d-----w- c:\programdata\Logitech 2014-01-14 01:46 . 2014-01-14 01:46 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\Leadertech 2014-01-14 01:46 . 2014-01-14 01:46 53248 ----a-r- c:\users\Ghislaine\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe 2014-01-14 01:46 . 2014-01-14 01:46 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd 2014-01-14 01:46 . 2014-01-18 20:34 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys 2014-01-14 01:46 . 2014-01-14 01:47 -------- d-----w- c:\programdata\Logishrd 2014-01-14 01:46 . 2014-01-14 01:46 -------- d-----w- c:\program files\Logitech 2014-01-14 01:44 . 2014-01-14 01:46 -------- d-----w- c:\program files\Common Files\LogiShrd 2014-01-14 01:44 . 2014-01-14 01:46 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\Logitech 2014-01-14 01:44 . 2014-01-14 01:44 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\Logishrd 2014-01-06 22:56 . 2014-01-06 23:00 -------- d-----w- C:\AdwCleaner 2014-01-05 03:26 . 2013-04-09 13:13 110264 ----a-w- c:\windows\system32\pdfcmon.dll 2014-01-04 23:35 . 2014-01-19 00:07 512 ----a-w- C:\PhysicalDisk0_MBR.bin 2014-01-04 23:25 . 2014-01-19 16:52 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\ZHP 2014-01-04 23:25 . 2014-01-19 00:03 -------- d-----w- c:\program files (x86)\ZHPDiag 2014-01-02 17:09 . 2014-01-02 17:09 -------- d-----w- C:\$WINDOWS.~BT 2014-01-02 16:29 . 2014-01-02 17:30 -------- d-----w- c:\users\Ghislaine\AppData\Local\Diagnostics 2013-12-30 21:22 . 2014-01-19 01:10 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\uTorrent 2013-12-30 18:32 . 2013-12-30 18:33 79672 ----a-w- c:\windows\system32\drivers\aswstm.sys . . . (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M )))))))))))))))))))))))))))))))))))))))))))))))) . 2014-01-15 14:51 . 2013-12-10 12:50 86054176 ----a-w- c:\windows\system32\MRT.exe 2014-01-14 12:20 . 2013-12-05 11:29 247808 ----a-w- c:\windows\SysWow64\schannel.dll 2013-12-30 18:32 . 2013-12-03 14:11 207904 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2013-12-30 18:32 . 2013-12-03 14:11 422216 ----a-w- c:\windows\system32\drivers\aswsp.sys 2013-12-30 18:32 . 2013-12-03 14:11 1034464 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2013-12-30 18:32 . 2013-12-03 14:11 78648 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-12-30 18:32 . 2013-12-03 14:11 334136 ----a-w- c:\windows\system32\aswBoot.exe 2013-12-30 18:32 . 2013-12-03 14:11 43152 ----a-w- c:\windows\avastSS.scr 2013-12-18 05:13 . 2013-12-03 13:59 270496 ------w- c:\windows\system32\MpSigStub.exe 2013-12-07 01:46 . 2013-12-07 01:46 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-12-07 01:46 . 2013-12-07 01:46 194048 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-12-07 01:46 . 2013-12-07 01:46 942592 ----a-w- c:\windows\system32\jsIntl.dll 2013-12-07 01:46 . 2013-12-07 01:46 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll 2013-12-07 01:46 . 2013-12-07 01:46 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2013-12-07 01:46 . 2013-12-07 01:46 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-12-07 01:46 . 2013-12-07 01:46 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2013-12-07 01:46 . 2013-12-07 01:46 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll 2013-12-07 01:46 . 2013-12-07 01:46 62464 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-12-07 01:46 . 2013-12-07 01:46 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2013-12-07 01:46 . 2013-12-07 01:46 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2013-12-07 01:46 . 2013-12-07 01:46 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2013-12-07 01:46 . 2013-12-07 01:46 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-12-07 01:46 . 2013-12-07 01:46 454656 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-12-07 01:46 . 2013-12-07 01:46 36352 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-12-07 01:46 . 2013-12-07 01:46 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2013-12-07 01:46 . 2013-12-07 01:46 337408 ----a-w- c:\windows\SysWow64\html.iec 2013-12-07 01:46 . 2013-12-07 01:46 247808 ----a-w- c:\windows\system32\msls31.dll 2013-12-07 01:46 . 2013-12-07 01:46 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-12-07 01:46 . 2013-12-07 01:46 235008 ----a-w- c:\windows\system32\elshyph.dll 2013-12-07 01:46 . 2013-12-07 01:46 182272 ----a-w- c:\windows\SysWow64\msls31.dll 2013-12-07 01:46 . 2013-12-07 01:46 151552 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-12-07 01:46 . 2013-12-07 01:46 139264 ----a-w- c:\windows\SysWow64\wextract.exe 2013-12-07 01:46 . 2013-12-07 01:46 13312 ----a-w- c:\windows\SysWow64\mshta.exe 2013-12-07 01:46 . 2013-12-07 01:46 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-12-07 01:46 . 2013-12-07 01:46 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-12-07 01:46 . 2013-12-07 01:46 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-12-07 01:46 . 2013-12-07 01:46 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-12-07 01:46 . 2013-12-07 01:46 84992 ----a-w- c:\windows\system32\mshtmled.dll 2013-12-07 01:46 . 2013-12-07 01:46 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2013-12-07 01:46 . 2013-12-07 01:46 81408 ----a-w- c:\windows\system32\icardie.dll 2013-12-07 01:46 . 2013-12-07 01:46 774144 ----a-w- c:\windows\system32\jscript.dll 2013-12-07 01:46 . 2013-12-07 01:46 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-12-07 01:46 . 2013-12-07 01:46 626176 ----a-w- c:\windows\system32\msfeeds.dll 2013-12-07 01:46 . 2013-12-07 01:46 62464 ----a-w- c:\windows\system32\pngfilt.dll 2013-12-07 01:46 . 2013-12-07 01:46 616104 ----a-w- c:\windows\system32\ieapfltr.dat 2013-12-07 01:46 . 2013-12-07 01:46 548352 ----a-w- c:\windows\system32\vbscript.dll 2013-12-07 01:46 . 2013-12-07 01:46 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-12-07 01:46 . 2013-12-07 01:46 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-12-07 01:46 . 2013-12-07 01:46 48128 ----a-w- c:\windows\system32\imgutil.dll 2013-12-07 01:46 . 2013-12-07 01:46 453120 ----a-w- c:\windows\system32\dxtmsft.dll 2013-12-07 01:46 . 2013-12-07 01:46 413696 ----a-w- c:\windows\system32\html.iec 2013-12-07 01:46 . 2013-12-07 01:46 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2013-12-07 01:46 . 2013-12-07 01:46 30208 ----a-w- c:\windows\system32\licmgr10.dll 2013-12-07 01:46 . 2013-12-07 01:46 296960 ----a-w- c:\windows\system32\dxtrans.dll 2013-12-07 01:46 . 2013-12-07 01:46 263376 ----a-w- c:\windows\system32\iedkcs32.dll 2013-12-07 01:46 . 2013-12-07 01:46 243200 ----a-w- c:\windows\system32\webcheck.dll 2013-12-07 01:46 . 2013-12-07 01:46 235520 ----a-w- c:\windows\system32\url.dll 2013-12-07 01:46 . 2013-12-07 01:46 195584 ----a-w- c:\windows\system32\msrating.dll 2013-12-07 01:46 . 2013-12-07 01:46 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-12-07 01:46 . 2013-12-07 01:46 147968 ----a-w- c:\windows\system32\occache.dll 2013-12-07 01:46 . 2013-12-07 01:46 143872 ----a-w- c:\windows\system32\wextract.exe 2013-12-07 01:46 . 2013-12-07 01:46 13824 ----a-w- c:\windows\system32\mshta.exe 2013-12-07 01:46 . 2013-12-07 01:46 135680 ----a-w- c:\windows\system32\iepeers.dll 2013-12-07 01:46 . 2013-12-07 01:46 13312 ----a-w- c:\windows\system32\msfeedssync.exe 2013-12-07 01:46 . 2013-12-07 01:46 131072 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-12-07 01:46 . 2013-12-07 01:46 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-12-07 01:46 . 2013-12-07 01:46 105984 ----a-w- c:\windows\system32\iesysprep.dll 2013-12-07 01:46 . 2013-12-07 01:46 101376 ----a-w- c:\windows\system32\inseng.dll 2013-12-06 00:11 . 2013-12-06 00:11 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-12-06 00:11 . 2013-12-06 00:11 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-12-06 00:11 . 2013-12-06 00:11 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll 2013-12-06 00:11 . 2013-12-06 00:11 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-12-06 00:11 . 2013-12-06 00:11 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-12-06 00:11 . 2013-12-06 00:11 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-12-06 00:11 . 2013-12-06 00:11 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-12-06 00:11 . 2013-12-06 00:11 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2013-12-06 00:11 . 2013-12-06 00:11 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-12-06 00:11 . 2013-12-06 00:11 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-12-06 00:11 . 2013-12-06 00:11 3928064 ----a-w- c:\windows\system32\d2d1.dll 2013-12-06 00:11 . 2013-12-06 00:11 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2013-12-06 00:11 . 2013-12-06 00:11 363008 ----a-w- c:\windows\system32\dxgi.dll 2013-12-06 00:11 . 2013-12-06 00:11 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-12-06 00:11 . 2013-12-06 00:11 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-12-06 00:11 . 2013-12-06 00:11 333312 ----a-w- c:\windows\system32\d3d10_1core.dll 2013-12-06 00:11 . 2013-12-06 00:11 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 2013-12-06 00:11 . 2013-12-06 00:11 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-12-06 00:11 . 2013-12-06 00:11 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-12-06 00:11 . 2013-12-06 00:11 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-12-06 00:11 . 2013-12-06 00:11 296960 ----a-w- c:\windows\system32\d3d10core.dll 2013-12-06 00:11 . 2013-12-06 00:11 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2013-12-06 00:11 . 2013-12-06 00:11 2565120 ----a-w- c:\windows\system32\d3d10warp.dll 2013-12-06 00:11 . 2013-12-06 00:11 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-12-06 00:11 . 2013-12-06 00:11 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-12-06 00:11 . 2013-12-06 00:11 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll 2013-12-06 00:11 . 2013-12-06 00:11 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll 2013-12-06 00:11 . 2013-12-06 00:11 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2013-12-06 00:11 . 2013-12-06 00:11 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll 2013-12-06 00:11 . 2013-12-06 00:11 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll 2013-12-06 00:11 . 2013-12-06 00:11 1682432 ----a-w- c:\windows\system32\XpsPrint.dll 2013-12-06 00:11 . 2013-12-06 00:11 1643520 ----a-w- c:\windows\system32\DWrite.dll . . ((((((((((((((((((((((((((((((((( Points de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "GoogleChromeAutoLaunch_B8338D669EAEB1927541E881AD52569B"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2014-01-11 866584] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-12-30 3764024] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] "Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2013-12-19 2239376] . c:\users\Ghislaine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Logitech . Enregistrement du produit.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe /remind /language=FRA /_WFM="." [2009-11-16 517384] OneNote 2010 - Capture d’écran et lancement.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE /tsr [2010-3-29 227712] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] R2 PDF Architect Service;PDF Architect Service;c:\program files (x86)\PDF Architect\ConversionService.exe;c:\program files (x86)\PDF Architect\ConversionService.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 ma-config_amd64;ma-config_amd64;c:\program files\ma-config.com\Drivers\ma-config_amd64.sys;c:\program files\ma-config.com\Drivers\ma-config_amd64.sys [x] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S0 aswRvrt;avast! Revert; [x] S0 aswVmm;avast! VM Monitor; [x] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 MaConfigAgent;Ma-Config Agent;c:\program files\ma-config.com\MaConfigAgent.exe;c:\program files\ma-config.com\MaConfigAgent.exe [x] S2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files (x86)\PDF Architect\HelperService.exe;c:\program files (x86)\PDF Architect\HelperService.exe [x] S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys;c:\windows\SYSNATIVE\DRIVERS\LEqdUsb.Sys [x] S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys;c:\windows\SYSNATIVE\DRIVERS\LHidEqd.Sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-01-19 01:30 1211672 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.76\Installer\chrmstp.exe . Contenu du dossier 'Tâches planifiées' . 2014-01-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-03 14:11] . 2014-01-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-03 14:11] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1] @="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}" [HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}] 2013-12-13 11:20 3359600 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2] @="{853B7E05-C47D-4985-909A-D0DC5C6D7303}" [HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}] 2013-12-13 11:20 3359600 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3] @="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}" [HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}] 2013-12-13 11:20 3359600 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-12-30 18:32 287280 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1832760] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2013-07-31 3091224] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-12-10 472984] . ------- Examen supplémentaire ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm IE: &Envoyer à OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: E&xporter vers Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.0.1 . - - - - ORPHELINS SUPPRIMES - - - - . Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file) . . . --------------------- CLES DE REGISTRE BLOQUEES --------------------- . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Heure de fin: 2014-01-21 15:49:19 ComboFix-quarantined-files.txt 2014-01-21 14:49 . Avant-CF: 35 945 615 360 octets libres Après-CF: 35 808 350 208 octets libres . - - End Of File - - A610148A21DD7BC4E197091C4DE13FBF A36C5E4F47E84449FF07ED3517B43A31