cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

ComboFix 14-01-21.02 - Ghislaine 21/01/2014 15:40:58.1.2 - x64
Microsoft Windows 7 Professionnel 6.1.7601.1.1252.33.1036.18.3071.1877 [GMT 1:00]
Lanc� depuis: d:\download.01.2014\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Public\AlexaNSISPlugin.3352.dll
.
.
((((((((((((((((((((((((((((( Fichiers cr��s du 2013-12-21 au 2014-01-21 ))))))))))))))))))))))))))))))))))))
.
.
2014-01-21 14:46 . 2014-01-21 14:46 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-01-21 14:46 . 2014-01-21 14:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-01-21 11:09 . 2014-01-21 12:31 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{74737DD1-1FC0-4169-AC96-4600F4FEB75D}\offreg.dll
2014-01-21 11:03 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{74737DD1-1FC0-4169-AC96-4600F4FEB75D}\mpengine.dll
2014-01-19 03:25 . 2014-01-19 03:25 -------- d-----w- c:\users\Ghislaine\.android
2014-01-19 02:24 . 2014-01-19 02:24 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-01-19 01:49 . 2014-01-19 01:49 -------- d-----w- c:\program files (x86)\VS Revo Group
2014-01-17 13:30 . 2014-01-19 02:04 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\com.adobe.dmp.contentviewer
2014-01-16 23:25 . 2014-01-16 23:25 -------- d-----w- c:\users\Ghislaine\AppData\Local\Citrix
2014-01-16 22:51 . 2014-01-16 22:51 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\GoforFiles
2014-01-16 17:00 . 2014-01-17 02:28 -------- d-----w- c:\program files\Common Files\Adobe
2014-01-16 16:59 . 2014-01-17 02:43 -------- d-----w- c:\program files\Adobe
2014-01-16 03:16 . 2014-01-16 03:16 -------- d-----w- c:\users\Ghislaine\AppData\Local\Amazon
2014-01-16 01:50 . 2014-01-16 01:50 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\pdfforge
2014-01-16 01:50 . 2012-05-05 09:54 662288 ----a-w- c:\windows\SysWow64\MSCOMCT2.OCX
2014-01-16 01:50 . 2012-05-05 09:54 137000 ----a-w- c:\windows\SysWow64\MSMAPI32.OCX
2014-01-16 01:50 . 1998-07-13 00:08 119568 ----a-w- c:\windows\SysWow64\VB6FR.DLL
2014-01-16 01:50 . 1998-07-13 00:08 141312 ----a-w- c:\windows\SysWow64\MSCMCFR.DLL
2014-01-16 01:50 . 2012-05-05 09:54 23552 ----a-w- c:\windows\SysWow64\MSMPIDE.DLL
2014-01-16 01:50 . 1998-07-13 00:08 59904 ----a-w- c:\windows\SysWow64\MSCC2FR.DLL
2014-01-15 15:13 . 2014-01-15 15:13 -------- d-----w- c:\program files (x86)\PDF Architect
2014-01-15 13:57 . 2013-11-27 01:41 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2014-01-15 13:57 . 2013-11-27 01:41 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2014-01-15 13:57 . 2013-11-27 01:41 53248 ----a-w- c:\windows\system32\drivers\usbehci.sys
2014-01-15 13:57 . 2013-11-27 01:41 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2014-01-15 13:57 . 2013-11-27 01:41 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2014-01-15 13:57 . 2013-11-27 01:41 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2014-01-15 13:57 . 2013-11-27 01:41 7808 ----a-w- c:\windows\system32\drivers\usbd.sys
2014-01-15 13:56 . 2013-11-26 10:32 3156480 ----a-w- c:\windows\system32\win32k.sys
2014-01-15 13:56 . 2013-11-26 11:40 376768 ----a-w- c:\windows\system32\drivers\netio.sys
2014-01-15 02:01 . 2014-01-15 02:01 -------- d-----w- c:\windows\CheckSur
2014-01-14 03:21 . 2014-01-14 03:26 1352 ----a-w- c:\windows\system32\ASOROSet.bin
2014-01-14 03:11 . 2014-01-15 17:34 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\Systweak
2014-01-14 03:11 . 2013-02-28 15:27 20312 ----a-w- c:\windows\system32\roboot64.exe
2014-01-14 01:47 . 2014-01-14 01:47 -------- d-----w- c:\programdata\Logitech
2014-01-14 01:46 . 2014-01-14 01:46 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\Leadertech
2014-01-14 01:46 . 2014-01-14 01:46 53248 ----a-r- c:\users\Ghislaine\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2014-01-14 01:46 . 2014-01-14 01:46 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd
2014-01-14 01:46 . 2014-01-18 20:34 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2014-01-14 01:46 . 2014-01-14 01:47 -------- d-----w- c:\programdata\Logishrd
2014-01-14 01:46 . 2014-01-14 01:46 -------- d-----w- c:\program files\Logitech
2014-01-14 01:44 . 2014-01-14 01:46 -------- d-----w- c:\program files\Common Files\LogiShrd
2014-01-14 01:44 . 2014-01-14 01:46 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\Logitech
2014-01-14 01:44 . 2014-01-14 01:44 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\Logishrd
2014-01-06 22:56 . 2014-01-06 23:00 -------- d-----w- C:\AdwCleaner
2014-01-05 03:26 . 2013-04-09 13:13 110264 ----a-w- c:\windows\system32\pdfcmon.dll
2014-01-04 23:35 . 2014-01-19 00:07 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2014-01-04 23:25 . 2014-01-19 16:52 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\ZHP
2014-01-04 23:25 . 2014-01-19 00:03 -------- d-----w- c:\program files (x86)\ZHPDiag
2014-01-02 17:09 . 2014-01-02 17:09 -------- d-----w- C:\$WINDOWS.~BT
2014-01-02 16:29 . 2014-01-02 17:30 -------- d-----w- c:\users\Ghislaine\AppData\Local\Diagnostics
2013-12-30 21:22 . 2014-01-19 01:10 -------- d-----w- c:\users\Ghislaine\AppData\Roaming\uTorrent
2013-12-30 18:32 . 2013-12-30 18:33 79672 ----a-w- c:\windows\system32\drivers\aswstm.sys
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-15 14:51 . 2013-12-10 12:50 86054176 ----a-w- c:\windows\system32\MRT.exe
2014-01-14 12:20 . 2013-12-05 11:29 247808 ----a-w- c:\windows\SysWow64\schannel.dll
2013-12-30 18:32 . 2013-12-03 14:11 207904 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-12-30 18:32 . 2013-12-03 14:11 422216 ----a-w- c:\windows\system32\drivers\aswsp.sys
2013-12-30 18:32 . 2013-12-03 14:11 1034464 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-12-30 18:32 . 2013-12-03 14:11 78648 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-12-30 18:32 . 2013-12-03 14:11 334136 ----a-w- c:\windows\system32\aswBoot.exe
2013-12-30 18:32 . 2013-12-03 14:11 43152 ----a-w- c:\windows\avastSS.scr
2013-12-18 05:13 . 2013-12-03 13:59 270496 ------w- c:\windows\system32\MpSigStub.exe
2013-12-07 01:46 . 2013-12-07 01:46 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-12-07 01:46 . 2013-12-07 01:46 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-12-07 01:46 . 2013-12-07 01:46 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-12-07 01:46 . 2013-12-07 01:46 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-12-07 01:46 . 2013-12-07 01:46 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-12-07 01:46 . 2013-12-07 01:46 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-12-07 01:46 . 2013-12-07 01:46 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-12-07 01:46 . 2013-12-07 01:46 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-12-07 01:46 . 2013-12-07 01:46 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-12-07 01:46 . 2013-12-07 01:46 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-12-07 01:46 . 2013-12-07 01:46 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-12-07 01:46 . 2013-12-07 01:46 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2013-12-07 01:46 . 2013-12-07 01:46 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-12-07 01:46 . 2013-12-07 01:46 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-12-07 01:46 . 2013-12-07 01:46 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-12-07 01:46 . 2013-12-07 01:46 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-12-07 01:46 . 2013-12-07 01:46 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-12-07 01:46 . 2013-12-07 01:46 247808 ----a-w- c:\windows\system32\msls31.dll
2013-12-07 01:46 . 2013-12-07 01:46 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-12-07 01:46 . 2013-12-07 01:46 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-12-07 01:46 . 2013-12-07 01:46 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-12-07 01:46 . 2013-12-07 01:46 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-12-07 01:46 . 2013-12-07 01:46 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-12-07 01:46 . 2013-12-07 01:46 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-12-07 01:46 . 2013-12-07 01:46 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-12-07 01:46 . 2013-12-07 01:46 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-12-07 01:46 . 2013-12-07 01:46 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-12-07 01:46 . 2013-12-07 01:46 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-12-07 01:46 . 2013-12-07 01:46 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-12-07 01:46 . 2013-12-07 01:46 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-12-07 01:46 . 2013-12-07 01:46 81408 ----a-w- c:\windows\system32\icardie.dll
2013-12-07 01:46 . 2013-12-07 01:46 774144 ----a-w- c:\windows\system32\jscript.dll
2013-12-07 01:46 . 2013-12-07 01:46 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-12-07 01:46 . 2013-12-07 01:46 626176 ----a-w- c:\windows\system32\msfeeds.dll
2013-12-07 01:46 . 2013-12-07 01:46 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-12-07 01:46 . 2013-12-07 01:46 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-12-07 01:46 . 2013-12-07 01:46 548352 ----a-w- c:\windows\system32\vbscript.dll
2013-12-07 01:46 . 2013-12-07 01:46 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-12-07 01:46 . 2013-12-07 01:46 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-12-07 01:46 . 2013-12-07 01:46 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-12-07 01:46 . 2013-12-07 01:46 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-12-07 01:46 . 2013-12-07 01:46 413696 ----a-w- c:\windows\system32\html.iec
2013-12-07 01:46 . 2013-12-07 01:46 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-12-07 01:46 . 2013-12-07 01:46 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-12-07 01:46 . 2013-12-07 01:46 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-12-07 01:46 . 2013-12-07 01:46 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-12-07 01:46 . 2013-12-07 01:46 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-12-07 01:46 . 2013-12-07 01:46 235520 ----a-w- c:\windows\system32\url.dll
2013-12-07 01:46 . 2013-12-07 01:46 195584 ----a-w- c:\windows\system32\msrating.dll
2013-12-07 01:46 . 2013-12-07 01:46 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-12-07 01:46 . 2013-12-07 01:46 147968 ----a-w- c:\windows\system32\occache.dll
2013-12-07 01:46 . 2013-12-07 01:46 143872 ----a-w- c:\windows\system32\wextract.exe
2013-12-07 01:46 . 2013-12-07 01:46 13824 ----a-w- c:\windows\system32\mshta.exe
2013-12-07 01:46 . 2013-12-07 01:46 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-12-07 01:46 . 2013-12-07 01:46 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-12-07 01:46 . 2013-12-07 01:46 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-12-07 01:46 . 2013-12-07 01:46 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-12-07 01:46 . 2013-12-07 01:46 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-12-07 01:46 . 2013-12-07 01:46 101376 ----a-w- c:\windows\system32\inseng.dll
2013-12-06 00:11 . 2013-12-06 00:11 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-12-06 00:11 . 2013-12-06 00:11 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-12-06 00:11 . 2013-12-06 00:11 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2013-12-06 00:11 . 2013-12-06 00:11 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-12-06 00:11 . 2013-12-06 00:11 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-12-06 00:11 . 2013-12-06 00:11 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-12-06 00:11 . 2013-12-06 00:11 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-12-06 00:11 . 2013-12-06 00:11 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2013-12-06 00:11 . 2013-12-06 00:11 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-12-06 00:11 . 2013-12-06 00:11 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-12-06 00:11 . 2013-12-06 00:11 3928064 ----a-w- c:\windows\system32\d2d1.dll
2013-12-06 00:11 . 2013-12-06 00:11 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2013-12-06 00:11 . 2013-12-06 00:11 363008 ----a-w- c:\windows\system32\dxgi.dll
2013-12-06 00:11 . 2013-12-06 00:11 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-12-06 00:11 . 2013-12-06 00:11 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-12-06 00:11 . 2013-12-06 00:11 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2013-12-06 00:11 . 2013-12-06 00:11 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-12-06 00:11 . 2013-12-06 00:11 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-12-06 00:11 . 2013-12-06 00:11 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-12-06 00:11 . 2013-12-06 00:11 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-12-06 00:11 . 2013-12-06 00:11 296960 ----a-w- c:\windows\system32\d3d10core.dll
2013-12-06 00:11 . 2013-12-06 00:11 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll
2013-12-06 00:11 . 2013-12-06 00:11 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2013-12-06 00:11 . 2013-12-06 00:11 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-12-06 00:11 . 2013-12-06 00:11 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-12-06 00:11 . 2013-12-06 00:11 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2013-12-06 00:11 . 2013-12-06 00:11 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2013-12-06 00:11 . 2013-12-06 00:11 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll
2013-12-06 00:11 . 2013-12-06 00:11 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll
2013-12-06 00:11 . 2013-12-06 00:11 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll
2013-12-06 00:11 . 2013-12-06 00:11 1682432 ----a-w- c:\windows\system32\XpsPrint.dll
2013-12-06 00:11 . 2013-12-06 00:11 1643520 ----a-w- c:\windows\system32\DWrite.dll
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les �l�ments vides & les �l�ments initiaux l�gitimes ne sont pas list�s
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GoogleChromeAutoLaunch_B8338D669EAEB1927541E881AD52569B"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2014-01-11 866584]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-12-30 3764024]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2013-12-19 2239376]
.
c:\users\Ghislaine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech . Enregistrement du produit.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe /remind /language=FRA /_WFM="." [2009-11-16 517384]
OneNote 2010 - Capture d��cran et lancement.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE /tsr [2010-3-29 227712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R2 PDF Architect Service;PDF Architect Service;c:\program files (x86)\PDF Architect\ConversionService.exe;c:\program files (x86)\PDF Architect\ConversionService.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 ma-config_amd64;ma-config_amd64;c:\program files\ma-config.com\Drivers\ma-config_amd64.sys;c:\program files\ma-config.com\Drivers\ma-config_amd64.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 MaConfigAgent;Ma-Config Agent;c:\program files\ma-config.com\MaConfigAgent.exe;c:\program files\ma-config.com\MaConfigAgent.exe [x]
S2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files (x86)\PDF Architect\HelperService.exe;c:\program files (x86)\PDF Architect\HelperService.exe [x]
S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys;c:\windows\SYSNATIVE\DRIVERS\LEqdUsb.Sys [x]
S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys;c:\windows\SYSNATIVE\DRIVERS\LHidEqd.Sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-01-19 01:30 1211672 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.76\Installer\chrmstp.exe
.
Contenu du dossier 'T�ches planifi�es'
.
2014-01-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-03 14:11]
.
2014-01-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-03 14:11]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2013-12-13 11:20 3359600 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2013-12-13 11:20 3359600 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2013-12-13 11:20 3359600 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-12-30 18:32 287280 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1832760]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2013-07-31 3091224]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-12-10 472984]
.
------- Examen suppl�mentaire -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: &Envoyer � OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: E&xporter vers Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
.
- - - - ORPHELINS SUPPRIMES - - - -
.
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)
.
.
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Heure de fin: 2014-01-21 15:49:19
ComboFix-quarantined-files.txt 2014-01-21 14:49
.
Avant-CF: 35�945�615�360 octets libres
Apr�s-CF: 35�808�350�208 octets libres
.
- - End Of File - - A610148A21DD7BC4E197091C4DE13FBF
A36C5E4F47E84449FF07ED3517B43A31

Publicité


Signaler le contenu de ce document

Publicité