cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

ComboFix 15-07-10.01 - Chocco 10/07/2015 12:51:46.2.2 - x64
Microsoft Windows 7 Édition Intégrale 6.1.7601.1.1252.33.1036.18.3235.1478 [GMT 2:00]
Lancé depuis: c:\users\Chocco\Desktop\ComboFix.exe
Commutateurs utilisés :: c:\users\Chocco\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Une copie infectée de c:\windows\system32\Services.exe a été trouvée et désinfectée
Copie restaurée à partir de - c:\windows\erdnt\cache64\services.exe
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2015-06-10 au 2015-07-10 ))))))))))))))))))))))))))))))))))))
.
.
2015-07-10 11:09 . 2015-06-23 23:22 12221144 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A97745FD-84E2-41F9-9E8D-9E27BFF0B431}\mpengine.dll
2015-07-10 11:05 . 2015-07-10 11:22 -------- d-----w- c:\users\Chocco\AppData\Local\temp
2015-07-10 11:05 . 2015-07-10 11:05 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2015-07-10 11:05 . 2015-07-10 11:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-07-08 12:05 . 2015-07-08 12:05 -------- d-----w- c:\program files (x86)\HD Tune
2015-07-07 00:30 . 2015-07-07 00:32 -------- d-----w- C:\FRST
2015-07-04 18:54 . 2015-07-04 18:54 -------- d-----w- c:\users\Chocco\AppData\Roaming\Dofus-3
2015-07-04 16:44 . 2015-07-04 16:44 -------- d-----w- c:\program files (x86)\ZHPFix
2015-07-04 14:59 . 2015-07-04 16:47 -------- d-----w- c:\users\Chocco\AppData\Roaming\ZHP
2015-06-11 17:16 . 2015-06-11 17:16 -------- d-----w- c:\windows\SysWow64\NV
2015-06-11 17:16 . 2015-06-11 17:16 -------- d-----w- c:\windows\system32\NV
2015-06-11 16:53 . 2015-06-03 21:04 1320304 ----a-w- c:\windows\SysWow64\nvspcap.dll
2015-06-11 16:53 . 2015-06-03 21:04 1316000 ----a-w- c:\windows\SysWow64\nvspbridge.dll
2015-06-11 16:53 . 2015-06-03 21:04 1756424 ----a-w- c:\windows\system32\nvspbridge64.dll
2015-06-11 16:53 . 2015-06-03 21:04 1571696 ----a-w- c:\windows\system32\nvspcap64.dll
2015-06-11 16:47 . 2015-05-19 03:29 46768 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2015-06-11 16:47 . 2015-05-19 03:14 61616 ----a-w- c:\windows\system32\nvaudcap64v.dll
2015-06-11 16:47 . 2015-05-19 03:14 57520 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2015-06-10 13:00 . 2015-06-10 13:00 -------- d-----w- c:\users\Chocco\AppData\Local\Secunia PSI
2015-06-10 12:57 . 2015-06-10 12:57 -------- d-----w- c:\program files (x86)\Secunia
2015-06-10 12:32 . 2015-05-25 17:08 3206144 ----a-w- c:\windows\system32\win32k.sys
2015-06-10 12:31 . 2015-05-22 18:18 700416 ----a-w- c:\windows\system32\generaltel.dll
2015-06-10 12:31 . 2015-05-22 18:18 757248 ----a-w- c:\windows\system32\invagent.dll
2015-06-10 12:31 . 2015-05-22 18:18 423424 ----a-w- c:\windows\system32\devinv.dll
2015-06-10 12:31 . 2015-05-22 18:18 1021440 ----a-w- c:\windows\system32\appraiser.dll
2015-06-10 12:31 . 2015-05-22 18:18 45568 ----a-w- c:\windows\system32\acmigration.dll
2015-06-10 12:31 . 2015-05-22 18:18 227328 ----a-w- c:\windows\system32\aepdu.dll
2015-06-10 12:31 . 2015-05-22 18:13 1119232 ----a-w- c:\windows\system32\aeinv.dll
2015-06-10 12:31 . 2015-05-21 13:19 193536 ----a-w- c:\windows\system32\aepic.dll
2015-06-10 12:29 . 2015-04-24 18:17 633856 ----a-w- c:\windows\system32\comctl32.dll
2015-06-10 12:29 . 2015-04-24 17:56 530432 ----a-w- c:\windows\SysWow64\comctl32.dll
2015-06-10 12:29 . 2015-04-11 03:19 69888 ----a-w- c:\windows\system32\drivers\stream.sys
2015-06-10 12:26 . 2015-06-10 12:26 -------- d-----w- c:\program files (x86)\Common Files\Java
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-06-26 19:46 . 2013-12-22 12:25 442264 ----a-w- c:\windows\system32\drivers\aswsp.sys
2015-06-23 11:30 . 2010-11-21 03:27 300704 ------w- c:\windows\system32\MpSigStub.exe
2015-06-15 12:26 . 2014-08-02 00:40 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-06-11 02:23 . 2013-12-25 18:14 140135120 ----a-w- c:\windows\system32\MRT.exe
2015-06-10 12:24 . 2015-03-13 15:30 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2015-06-04 20:21 . 2015-06-04 20:21 513640 ----a-w- c:\windows\system32\igfxsrvc.exe
2015-06-04 20:21 . 2015-06-04 20:21 173672 ----a-w- c:\windows\system32\igfxtray.exe
2015-06-04 20:21 . 2015-06-04 20:21 444008 ----a-w- c:\windows\system32\igfxpers.exe
2015-06-04 20:21 . 2015-06-04 20:21 401512 ----a-w- c:\windows\system32\hkcmd.exe
2015-06-04 20:21 . 2015-06-04 20:21 256616 ----a-w- c:\windows\system32\igfxext.exe
2015-06-04 20:21 . 2015-06-04 20:21 187496 ----a-w- c:\windows\system32\difx64.exe
2015-06-04 20:21 . 2015-06-04 20:21 5906536 ----a-w- c:\windows\system32\GfxUI.exe
2015-06-04 20:21 . 2015-06-04 20:21 280680 ----a-w- c:\windows\SysWow64\IntelCpHeciSvc.exe
2015-06-04 20:20 . 2015-06-04 20:20 116224 ----a-w- c:\windows\system32\igfxCoIn_v4229.dll
2015-05-28 07:04 . 2013-12-22 12:05 175880 ----a-w- c:\windows\system32\nvinitx.dll
2015-05-28 07:04 . 2013-12-22 12:05 175880 ----a-w- c:\windows\system32\nvinitx(358).dll
2015-05-28 07:04 . 2013-12-22 12:05 154256 ----a-w- c:\windows\SysWow64\nvinit.dll
2015-05-28 07:04 . 2013-12-22 12:05 154256 ----a-w- c:\windows\SysWow64\nvinit(359).dll
2015-05-28 04:15 . 2013-12-22 12:06 937288 ----a-w- c:\windows\system32\nvvsvc.exe
2015-05-28 04:15 . 2013-12-22 12:06 75080 ----a-w- c:\windows\system32\nv3dappshextr.dll
2015-05-28 04:15 . 2013-12-22 12:06 62608 ----a-w- c:\windows\system32\nvshext.dll
2015-05-28 04:15 . 2013-12-22 12:06 385168 ----a-w- c:\windows\system32\nvmctray.dll
2015-05-28 04:15 . 2013-12-22 12:06 3491984 ----a-w- c:\windows\system32\nvsvc64.dll
2015-05-28 04:15 . 2013-12-22 12:06 2558608 ----a-w- c:\windows\system32\nvsvcr.dll
2015-05-28 04:15 . 2013-12-22 12:06 1059472 ----a-w- c:\windows\system32\nv3dappshext.dll
2015-05-28 04:15 . 2013-12-22 12:06 6872904 ----a-w- c:\windows\system32\nvcpl.dll
2015-05-27 10:48 . 2013-12-22 12:06 4408727 ----a-w- c:\windows\system32\nvcoproc.bin
2015-05-26 19:02 . 2015-05-26 19:02 5375448 ----a-w- c:\windows\system32\drivers\igdkmd64.sys
2015-05-26 19:00 . 2015-05-26 19:00 940360 ----a-w- c:\windows\SysWow64\igfxcmrt32.dll
2015-05-26 19:00 . 2015-05-26 19:00 530968 ----a-w- c:\windows\system32\iglhsip64.dll
2015-05-26 19:00 . 2015-05-26 19:00 525800 ----a-w- c:\windows\SysWow64\iglhsip32.dll
2015-05-26 19:00 . 2015-05-26 19:00 31984 ----a-w- c:\windows\system32\igfxexps.dll
2015-05-26 19:00 . 2015-05-26 19:00 220432 ----a-w- c:\windows\system32\iglhcp64.dll
2015-05-26 19:00 . 2015-05-26 19:00 184352 ----a-w- c:\windows\SysWow64\iglhcp32.dll
2015-05-26 19:00 . 2015-05-26 19:00 12937864 ----a-w- c:\windows\system32\igd10umd64.dll
2015-05-26 19:00 . 2015-05-26 19:00 12694808 ----a-w- c:\windows\system32\igdumd64.dll
2015-05-26 19:00 . 2015-05-26 19:00 11245520 ----a-w- c:\windows\SysWow64\igd10umd32.dll
2015-05-26 19:00 . 2015-05-26 19:00 11117808 ----a-w- c:\windows\SysWow64\igdumd32.dll
2015-05-26 19:00 . 2015-05-26 19:00 1049576 ----a-w- c:\windows\system32\igfxcmrt64.dll
2015-05-26 18:57 . 2015-05-26 18:57 3581440 ----a-w- c:\windows\system32\igdbcl64.dll
2015-05-26 18:57 . 2015-05-26 18:57 29591040 ----a-w- c:\windows\system32\igdrcl64.dll
2015-05-26 18:57 . 2015-05-26 18:57 241664 ----a-w- c:\windows\system32\IntelOpenCL64.dll
2015-05-26 18:56 . 2015-05-26 18:56 29573120 ----a-w- c:\windows\SysWow64\igdrcl32.dll
2015-05-26 18:56 . 2015-05-26 18:56 2898944 ----a-w- c:\windows\SysWow64\igdbcl32.dll
2015-05-26 18:56 . 2015-05-26 18:56 195584 ----a-w- c:\windows\SysWow64\IntelOpenCL32.dll
2015-05-26 18:55 . 2015-05-26 18:55 27468800 ----a-w- c:\windows\system32\igdfcl64.dll
2015-05-26 18:53 . 2015-05-26 18:53 21848576 ----a-w- c:\windows\SysWow64\igdfcl32.dll
2015-05-26 18:53 . 2015-05-26 18:53 101376 ----a-w- c:\windows\system32\igdde64.dll
2015-05-26 18:53 . 2015-05-26 18:53 81408 ----a-w- c:\windows\SysWow64\igdde32.dll
2015-05-26 18:52 . 2015-05-26 18:52 9007616 ----a-w- c:\windows\system32\igfxress.dll
2015-05-26 18:52 . 2015-05-26 18:52 64000 ----a-w- c:\windows\system32\igfxsrvc.dll
2015-05-26 18:52 . 2015-05-26 18:52 439808 ----a-w- c:\windows\system32\igfxrfra.lrc
2015-05-26 18:52 . 2015-05-26 18:52 439296 ----a-w- c:\windows\system32\igfxrrus.lrc
2015-05-26 18:52 . 2015-05-26 18:52 439296 ----a-w- c:\windows\system32\igfxrrom.lrc
2015-05-26 18:52 . 2015-05-26 18:52 438784 ----a-w- c:\windows\system32\igfxrsky.lrc
2015-05-26 18:52 . 2015-05-26 18:52 438784 ----a-w- c:\windows\system32\igfxrptg.lrc
2015-05-26 18:52 . 2015-05-26 18:52 438784 ----a-w- c:\windows\system32\igfxrplk.lrc
2015-05-26 18:52 . 2015-05-26 18:52 438784 ----a-w- c:\windows\system32\igfxrnld.lrc
2015-05-26 18:52 . 2015-05-26 18:52 438784 ----a-w- c:\windows\system32\igfxrita.lrc
2015-05-26 18:52 . 2015-05-26 18:52 438784 ----a-w- c:\windows\system32\igfxrhrv.lrc
2015-05-26 18:52 . 2015-05-26 18:52 438272 ----a-w- c:\windows\system32\igfxrhun.lrc
2015-05-26 18:52 . 2015-05-26 18:52 437760 ----a-w- c:\windows\system32\igfxrtrk.lrc
2015-05-26 18:52 . 2015-05-26 18:52 437760 ----a-w- c:\windows\system32\igfxrsve.lrc
2015-05-26 18:52 . 2015-05-26 18:52 437760 ----a-w- c:\windows\system32\igfxrslv.lrc
2015-05-26 18:52 . 2015-05-26 18:52 437760 ----a-w- c:\windows\system32\igfxrptb.lrc
2015-05-26 18:52 . 2015-05-26 18:52 437760 ----a-w- c:\windows\system32\igfxrnor.lrc
2015-05-26 18:52 . 2015-05-26 18:52 437248 ----a-w- c:\windows\system32\igfxrtha.lrc
2015-05-26 18:52 . 2015-05-26 18:52 435712 ----a-w- c:\windows\system32\igfxrheb.lrc
2015-05-26 18:52 . 2015-05-26 18:52 432128 ----a-w- c:\windows\system32\igfxrjpn.lrc
2015-05-26 18:52 . 2015-05-26 18:52 431104 ----a-w- c:\windows\system32\igfxrkor.lrc
2015-05-26 18:52 . 2015-05-26 18:52 9728 ----a-w- c:\windows\system32\IGFXDEVLib.dll
2015-05-26 18:52 . 2015-05-26 18:52 442880 ----a-w- c:\windows\system32\igfxdev.dll
2015-05-26 18:52 . 2015-05-26 18:52 440320 ----a-w- c:\windows\system32\igfxrell.lrc
2015-05-26 18:52 . 2015-05-26 18:52 439808 ----a-w- c:\windows\system32\igfxresn.lrc
2015-05-26 18:52 . 2015-05-26 18:52 438784 ----a-w- c:\windows\system32\igfxrdeu.lrc
2015-05-26 18:52 . 2015-05-26 18:52 438272 ----a-w- c:\windows\system32\igfxrfin.lrc
2015-05-26 18:52 . 2015-05-26 18:52 438272 ----a-w- c:\windows\system32\igfxrcsy.lrc
2015-05-26 18:52 . 2015-05-26 18:52 437248 ----a-w- c:\windows\system32\igfxrdan.lrc
2015-05-26 18:52 . 2015-05-26 18:52 435712 ----a-w- c:\windows\system32\igfxrara.lrc
2015-05-26 18:52 . 2015-05-26 18:52 429056 ----a-w- c:\windows\system32\igfxrcht.lrc
2015-05-26 18:52 . 2015-05-26 18:52 428544 ----a-w- c:\windows\system32\igfxrchs.lrc
2015-05-26 18:52 . 2015-05-26 18:52 410112 ----a-w- c:\windows\system32\igfxTMM.dll
2015-05-26 18:52 . 2015-05-26 18:52 384512 ----a-w- c:\windows\system32\igfxpph.dll
2015-05-26 18:52 . 2015-05-26 18:52 286208 ----a-w- c:\windows\system32\igfxrenu.lrc
2015-05-26 18:52 . 2015-05-26 18:52 175104 ----a-w- c:\windows\system32\gfxSrvc.dll
2015-05-26 18:52 . 2015-05-26 18:52 142336 ----a-w- c:\windows\system32\igfxdo.dll
2015-05-26 18:52 . 2015-05-26 18:52 126976 ----a-w- c:\windows\system32\igfxcpl.cpl
2015-05-26 18:52 . 2015-05-26 18:52 110592 ----a-w- c:\windows\system32\hccutils.dll
2015-05-26 18:52 . 2015-05-26 18:52 8620032 ----a-w- c:\windows\SysWow64\ig7icd32.dll
2015-05-26 18:52 . 2015-05-26 18:52 330752 ----a-w- c:\windows\SysWow64\igfxdv32.dll
2015-05-26 18:52 . 2015-05-26 18:52 25088 ----a-w- c:\windows\SysWow64\igfxexps32.dll
2015-05-26 18:52 . 2015-05-26 18:52 11643392 ----a-w- c:\windows\system32\ig7icd64.dll
2015-05-26 18:50 . 2015-05-26 18:50 56832 ----a-w- c:\windows\system32\Intel_OpenCL_ICD64.dll
2015-05-26 18:50 . 2015-05-26 18:50 56320 ----a-w- c:\windows\SysWow64\Intel_OpenCL_ICD32.dll
2015-05-26 18:50 . 2015-05-26 18:50 598384 ----a-w- c:\windows\system32\igvpkrng700.bin
2015-05-26 18:50 . 2015-05-26 18:50 575488 ----a-w- c:\windows\system32\igfx11cmrt64.dll
2015-05-26 18:50 . 2015-05-26 18:50 542720 ----a-w- c:\windows\SysWow64\igfx11cmrt32.dll
2015-05-26 18:50 . 2015-05-26 18:50 3511296 ----a-w- c:\windows\system32\igfxcmjit64.dll
2015-05-26 18:50 . 2015-05-26 18:50 3121152 ----a-w- c:\windows\SysWow64\igfxcmjit32.dll
2015-05-26 18:50 . 2015-05-26 18:50 754652 ----a-w- c:\windows\system32\igcodeckrng700.bin
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[-] 2013-12-26 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
[-] 2013-12-26 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-05-11 5515496]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-disabled]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 VBoxAswDrv;VBoxAsw Support Driver;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [x]
R3 AMPPALP;Protocole Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x]
R3 AvastVBoxSvc;AvastVBox COM Service;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 ma-config_amd64;ma-config_amd64;c:\program files\ma-config.com\Drivers\ma-config_amd64.sys;c:\program files\ma-config.com\Drivers\ma-config_amd64.sys [x]
R3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\DRIVERS\mcvidrv.sys;c:\windows\SYSNATIVE\DRIVERS\mcvidrv.sys [x]
R3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv_x64.sys;c:\windows\SYSNATIVE\drivers\mcaudrv_x64.sys [x]
R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys;c:\windows\SYSNATIVE\DRIVERS\MijXfilt.sys [x]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys;c:\windows\SYSNATIVE\DRIVERS\netaapl64.sys [x]
R3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf_amd64.sys;c:\windows\SYSNATIVE\DRIVERS\psi_mf_amd64.sys [x]
R3 PVUSB;CESG502 64bit USB Driver;c:\windows\system32\DRIVERS\CESG64.sys;c:\windows\SYSNATIVE\DRIVERS\CESG64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 rzendpt;rzendpt;c:\windows\system32\DRIVERS\rzendpt.sys;c:\windows\SYSNATIVE\DRIVERS\rzendpt.sys [x]
R3 rzmpos;rzmpos;c:\windows\system32\DRIVERS\rzmpos.sys;c:\windows\SYSNATIVE\DRIVERS\rzmpos.sys [x]
R3 rzudd;Razer Keyboard Driver;c:\windows\system32\DRIVERS\rzudd.sys;c:\windows\SYSNATIVE\DRIVERS\rzudd.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x]
R4 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x]
R4 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x]
R4 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
R4 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [x]
R4 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
R4 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
R4 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service;c:\windows\system32\igfxCUIService.exe;c:\windows\SYSNATIVE\igfxCUIService.exe [x]
R4 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
R4 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
R4 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
R4 KMSServerService;KMS Server Service;c:\windows\KMSServerService\KMS Server Service.exe ;c:\windows\KMSServerService\KMS Server Service.exe [x]
R4 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
R4 MaConfigAgent;Ma-Config Agent;c:\program files\ma-config.com\MaConfigAgent.exe;c:\program files\ma-config.com\MaConfigAgent.exe [x]
R4 Micro Star SCM;Micro Star SCM;c:\windows\SysWOW64\MSIService.exe;c:\windows\SysWOW64\MSIService.exe [x]
R4 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
R4 Qualcomm Atheros Killer Service;Qualcomm Atheros Killer Service;c:\program files\Qualcomm Atheros\Killer Network Manager\BFNService.exe;c:\program files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [x]
R4 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe;c:\program files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [x]
R4 RealPlayer Cloud Service;RealPlayer Cloud Service;c:\program files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe;c:\program files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe [x]
R4 RealPlayerUpdateSvc;RealPlayer Update Service;c:\program files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe;c:\program files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [x]
R4 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe;c:\program files (x86)\Secunia\PSI\PSIA.exe [x]
R4 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe;c:\program files (x86)\Secunia\PSI\sua.exe [x]
R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x]
S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x]
S0 iusb3hcs;Pilote de commutateur de contrôleur d'hôte Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 BfLwf;Qualcomm Atheros Bandwidth Control;c:\windows\system32\DRIVERS\bflwfx64.sys;c:\windows\SYSNATIVE\DRIVERS\bflwfx64.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys;c:\windows\SYSNATIVE\DRIVERS\idmwfp.sys [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S3 AMPPAL;Carte réseau virtuelle Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x]
S3 IntcDAud;Son Intel(R) pour écrans;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 iusb3hub;Pilote de concentrateur Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Pilote du contrôleur d'hôte extensible Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 L1C;NDIS Miniport Driver for the Killer e2200 PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\e22w7x64.sys;c:\windows\SYSNATIVE\DRIVERS\e22w7x64.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfswin7.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfswin7.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaywin7.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaywin7.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirwin7.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirwin7.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvolwin7.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvolwin7.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-06-09 14:21 986440 ----a-w- c:\program files (x86)\Google\Chrome\Application\43.0.2357.124\Installer\chrmstp.exe
.
Contenu du dossier 'Tâches planifiées'
.
2015-06-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-29 13:08]
.
2015-06-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-22 12:18]
.
2015-06-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-22 12:18]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-04-23 11:49 722400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2014-04-21 10:02 25112 ----a-w- c:\program files (x86)\Internet Download Manager\IDMShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2015-06-03 2754704]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2015-06-03 1571696]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll c:\windows\System32\nvinitx.dll
.
------- Examen supplémentaire -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Tout télécharger avec Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlall.htm
IE: Télécharger avec Free Download Manager - file://c:\program files (x86)\Free Download Manager\dllink.htm
IE: Télécharger avec IDM - c:\program files (x86)\Internet Download Manager\IEExt.htm
IE: Télécharger la sélection avec Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlselected.htm
IE: Télécharger la vidéo avec Free Download Manager - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm
IE: Télécharger tous les liens avec Internet Download Manager - c:\program files (x86)\Internet Download Manager\IEGetAll.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Chocco\AppData\Roaming\Mozilla\Firefox\Profiles\uchy69fr.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/?pc=SK2M&ocid=SK2MDHP&osmkt=fr-fr
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M&q=
.
- - - - ORPHELINS SUPPRIMES - - - -
.
Wow6432Node-HKLM-Run- - (no file)
MSConfigStartUp-Sidebar - %ProgramFiles(x86)%\Windows Sidebar\Sidebar.exe
AddRemove-{0721FCF8-0D1B-AE68-068F-63DAFC13AD1B} - c:\progra~3\INSTAL~1\{90F06~1\Setup.exe
AddRemove-{92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB3023224 - c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\v4.5.51209\setup.exe
AddRemove-{92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB3035490 - c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\v4.5.51209\setup.exe
AddRemove-{92FB6C44-E685-45AD-9B20-CADF4CABA132}.KB3037581 - c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\v4.5.51209\setup.exe
.
.
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_188_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_188_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
.
**************************************************************************
.
Heure de fin: 2015-07-10 13:27:21 - La machine a redémarré
ComboFix-quarantined-files.txt 2015-07-10 11:27
ComboFix2.txt 2015-07-09 16:35
.
Avant-CF: 283 809 161 216 octets libres
Après-CF: 283 992 059 904 octets libres
.
- - End Of File - - 22EE6DE9D8156EFC202D7537CBB7FC41
A36C5E4F47E84449FF07ED3517B43A31

Publicité


Signaler le contenu de ce document

Publicité