ComboFix 17-10-17.01 - kamaz 10/11/2017 18:46:01.1.4 - x64 Microsoft Windows 7 Édition Intégrale 6.1.7601.1.1252.33.1036.18.10192.8533 [GMT 1:00] Lancé depuis: c:\users\kamaz\Desktop\Patrice.exe AV: Avast Antivirus *Disabled/Updated* {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} SP: Avast Antivirus *Disabled/Updated* {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Autres suppressions )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\_@8A54.tmp C:\_@8BCB.tmp c:\windows\msdownld.tmp c:\windows\SysWow64\SET262D.tmp c:\windows\SysWow64\SET4BCC.tmp c:\windows\SysWow64\SET65B9.tmp c:\windows\wininit.ini . . ((((((((((((((((((((((((((((( Fichiers créés du 2017-10-10 au 2017-11-10 )))))))))))))))))))))))))))))))))))) . . 2017-11-10 17:52 . 2017-11-10 17:52 -------- d-----w- c:\users\Default\AppData\Local\temp 2017-11-10 13:19 . 2017-11-10 13:19 -------- d-----w- c:\programdata\SWCUTemp 2017-11-10 12:40 . 2017-11-10 12:39 183584 ----a-w- c:\windows\system32\drivers\aswArPot.sys 2017-11-10 12:40 . 2017-11-10 12:39 365168 ----a-w- c:\windows\system32\aswBoot.exe 2017-11-09 19:17 . 2017-11-10 12:58 -------- d-----w- C:\FRST 2017-11-09 14:44 . 2017-11-09 14:44 -------- d-----w- c:\users\kamaz\AppData\Roaming\FastStone 2017-11-09 14:44 . 2017-11-09 14:44 -------- d-----w- c:\users\kamaz\AppData\Local\FastStone 2017-11-09 14:44 . 2017-11-09 14:44 -------- d-----w- c:\program files (x86)\FastStone Capture 2017-11-08 21:41 . 2017-11-08 21:41 -------- d-----w- c:\users\kamaz\AppData\Roaming\Bandicam Company 2017-11-08 19:00 . 2017-11-08 19:00 -------- d-----w- c:\users\LogMeInRemoteUser 2017-11-08 18:39 . 2017-11-10 12:52 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2017-11-06 15:13 . 2017-11-06 15:18 -------- d-----w- c:\users\kamaz\AppData\Roaming\ZHP 2017-11-06 15:13 . 2017-11-06 15:18 -------- d-----w- c:\users\kamaz\AppData\Local\ZHP 2017-11-04 03:31 . 2017-10-27 16:06 136312 ----a-w- c:\windows\SysWow64\nvStreaming.exe 2017-11-04 03:23 . 2017-10-11 01:05 50624 ----a-w- c:\windows\system32\drivers\nvvad64v.sys 2017-11-03 16:16 . 2017-11-03 16:16 -------- d-----w- c:\program files\iPod 2017-11-03 16:15 . 2017-11-03 16:16 -------- d-----w- c:\program files\iTunes 2017-11-03 16:02 . 2017-11-03 16:02 -------- d-----w- c:\program files (x86)\Common Files\Java 2017-11-03 16:00 . 2017-11-03 16:11 19 ----a-w- C:\SysMon.exe.bin 2017-11-03 15:59 . 2017-11-03 15:59 -------- d-----w- c:\windows\Azart 2017-11-03 15:58 . 2017-11-03 15:58 -------- d-----w- c:\users\kamaz\AppData\Roaming\Easeware 2017-11-03 15:58 . 2017-11-03 16:16 -------- d-----w- c:\programdata\dadhService 2017-11-03 15:43 . 2017-11-03 15:43 -------- d-----w- C:\$AV_ASW 2017-11-03 12:02 . 2017-11-10 13:04 -------- d-----r- c:\users\kamaz\iCloudDrive 2017-11-03 12:01 . 2017-11-03 12:02 -------- d-----w- c:\users\kamaz\AppData\Local\Apple Inc 2017-10-16 22:15 . 2017-11-03 16:01 -------- d-----w- c:\users\kamaz\AppData\Local\JDownloader v2.0 2017-10-16 22:15 . 2017-10-16 22:16 -------- d-----w- c:\users\kamaz\AppData\Local\{C6A4F0F8-E20C-9C40-8F94-B9A8ABFC4530} 2017-10-16 20:10 . 2017-10-16 20:10 -------- d-----w- c:\users\kamaz\AppData\Local\TangoGameworks 2017-10-15 04:11 . 2017-10-15 04:11 -------- d-----w- c:\users\kamaz\dwhelper 2017-10-15 03:58 . 2017-10-20 18:00 -------- d-----w- c:\users\kamaz\Jeux Pc 2017-10-13 00:18 . 2017-11-03 16:26 18896 ----a-w- c:\program files (x86)\Mozilla Firefox\qipcap64.dll 2017-10-12 00:32 . 2017-10-12 00:32 126925120 -c--a-w- c:\windows\system32\MRT-KB890830.exe . . . (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M )))))))))))))))))))))))))))))))))))))))))))))))) . 2017-11-10 12:39 . 2015-01-03 13:55 203976 ----a-w- c:\windows\system32\drivers\aswStm.sys 2017-11-10 12:39 . 2015-01-03 13:55 364464 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2017-11-10 12:39 . 2015-01-03 13:55 455384 ----a-w- c:\windows\system32\drivers\aswSP.sys 2017-11-10 12:39 . 2015-01-03 13:55 84416 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2017-11-10 12:39 . 2015-01-03 13:55 148288 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2017-11-10 12:39 . 2015-01-03 13:55 47008 ----a-w- c:\windows\system32\drivers\aswHwid.sys 2017-11-10 12:39 . 2015-01-03 13:55 110376 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2017-11-10 12:39 . 2015-01-03 13:55 1026232 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2017-11-10 12:39 . 2017-03-06 09:41 57728 ----a-w- c:\windows\system32\drivers\aswbuniva.sys 2017-11-10 12:39 . 2017-03-06 09:41 343288 ----a-w- c:\windows\system32\drivers\aswbloga.sys 2017-11-10 12:39 . 2017-03-06 09:41 198968 ----a-w- c:\windows\system32\drivers\aswbidsha.sys 2017-11-10 12:39 . 2017-03-06 09:41 321032 ----a-w- c:\windows\system32\drivers\aswbidsdrivera.sys 2017-11-08 19:02 . 2017-09-07 18:51 114688 ----a-w- c:\windows\system32\LMIRfsClientNP.dll 2017-11-08 19:02 . 2017-09-07 18:51 109024 ----a-w- c:\windows\system32\LMIinit.dll 2017-11-04 02:26 . 2015-01-01 13:42 803328 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2017-11-04 02:26 . 2015-01-01 13:42 144896 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2017-11-03 16:02 . 2015-01-27 20:35 97856 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2017-10-27 17:46 . 2017-05-17 13:44 18207248 ----a-w- c:\windows\system32\nvd3dumx.dll 2017-10-27 17:46 . 2017-03-21 13:20 19012232 ----a-w- c:\windows\SysWow64\nvwgf2um.dll 2017-10-27 17:46 . 2017-03-21 13:20 15027984 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2017-10-27 17:46 . 2016-11-21 13:43 492048 ----a-w- c:\windows\system32\nvumdshimx.dll 2017-10-27 17:46 . 2015-09-30 12:18 3799032 ----a-w- c:\windows\SysWow64\nvapi.dll 2017-10-27 17:46 . 2015-01-26 15:03 1615472 ----a-w- c:\windows\system32\nvhdagenco6420103.dll 2017-10-27 17:46 . 2015-01-01 13:28 21744632 ----a-w- c:\windows\system32\nvwgf2umx.dll 2017-10-27 17:46 . 2015-01-01 13:28 4284496 ----a-w- c:\windows\system32\nvapi64.dll 2017-10-27 16:36 . 2016-11-21 14:02 1951 ----a-w- c:\windows\NvContainerRecovery.bat 2017-10-27 16:12 . 2015-01-01 13:29 5960824 ----a-w- c:\windows\system32\nvcpl.dll 2017-10-27 16:12 . 2015-01-01 13:29 2587768 ----a-w- c:\windows\system32\nvsvc64.dll 2017-10-27 16:12 . 2016-04-12 14:47 81856 ----a-w- c:\windows\system32\nv3dappshextr.dll 2017-10-27 16:12 . 2016-04-12 14:47 607168 ----a-w- c:\windows\system32\nv3dappshext.dll 2017-10-27 16:12 . 2015-01-01 13:29 449656 ----a-w- c:\windows\system32\nvmctray.dll 2017-10-27 16:12 . 2015-01-01 13:29 1766520 ----a-w- c:\windows\system32\nvsvcr.dll 2017-10-27 16:12 . 2015-01-01 13:29 123000 ----a-w- c:\windows\system32\nvshext.dll 2017-10-25 10:33 . 2015-01-01 13:29 7802921 ----a-w- c:\windows\system32\nvcoproc.bin 2017-10-12 00:32 . 2015-01-03 19:03 126925120 -c--a-w- c:\windows\system32\MRT.exe 2017-10-11 01:05 . 2017-03-14 13:52 1796032 ----a-w- c:\windows\system32\nvspcap64.dll 2017-10-11 01:05 . 2017-03-14 13:52 1577920 ----a-w- c:\windows\SysWow64\nvspcap.dll 2017-10-11 01:05 . 2017-03-14 13:52 918976 ----a-w- c:\windows\system32\NvRtmpStreamer64.dll 2017-10-11 01:05 . 2017-05-17 14:12 186304 ----a-w- c:\windows\system32\nvaudcap64v.dll 2017-10-11 01:05 . 2017-05-17 14:12 152512 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll 2017-10-10 23:26 . 2017-05-17 14:13 1951 ----a-w- c:\windows\NvTelemetryContainerRecovery.bat 2017-09-19 07:23 . 2017-03-14 13:52 1755072 ----a-w- c:\windows\system32\nvspbridge64.dll 2017-09-19 07:23 . 2017-03-14 13:52 1317312 ----a-w- c:\windows\SysWow64\nvspbridge.dll 2017-09-13 23:20 . 2017-09-13 23:20 798008 ----a-w- c:\windows\SysWow64\vulkan-1-1-0-61-0.dll 2017-09-13 23:20 . 2016-04-12 14:48 798008 ----a-w- c:\windows\SysWow64\vulkan-1.dll 2017-09-13 23:20 . 2017-09-13 23:20 490296 ----a-w- c:\windows\SysWow64\vulkaninfo-1-1-0-61-0.exe 2017-09-13 23:20 . 2016-04-12 14:48 490296 ----a-w- c:\windows\SysWow64\vulkaninfo.exe 2017-09-13 23:19 . 2017-09-13 23:19 927544 ----a-w- c:\windows\system32\vulkan-1-1-0-61-0.dll 2017-09-13 23:19 . 2016-04-12 14:48 927544 ----a-w- c:\windows\system32\vulkan-1.dll 2017-09-13 23:19 . 2017-09-13 23:19 591160 ----a-w- c:\windows\system32\vulkaninfo-1-1-0-61-0.exe 2017-09-13 23:19 . 2016-04-12 14:48 591160 ----a-w- c:\windows\system32\vulkaninfo.exe 2017-09-13 15:33 . 2017-10-11 02:53 631176 ----a-w- c:\windows\system32\winresume.efi 2017-09-13 15:32 . 2017-10-11 02:53 706792 ----a-w- c:\windows\system32\winload.efi 2017-09-13 15:32 . 2017-10-11 02:53 5547752 ----a-w- c:\windows\system32\ntoskrnl.exe 2017-09-13 15:32 . 2017-10-11 02:53 95464 ----a-w- c:\windows\system32\drivers\ksecdd.sys 2017-09-13 15:32 . 2017-10-11 02:53 154856 ----a-w- c:\windows\system32\drivers\ksecpkg.sys 2017-09-13 15:31 . 2017-10-11 02:53 1732864 ----a-w- c:\windows\system32\ntdll.dll 2017-09-13 15:28 . 2017-10-11 02:53 448512 ----a-w- c:\windows\system32\wlansec.dll 2017-09-13 15:28 . 2017-10-11 02:53 414208 ----a-w- c:\windows\system32\wlanmsm.dll 2017-09-13 15:28 . 2017-10-11 02:53 118784 ----a-w- c:\windows\system32\wlanhlp.dll 2017-09-13 15:28 . 2017-10-11 02:53 886272 ----a-w- c:\windows\system32\wlansvc.dll 2017-09-13 15:28 . 2017-10-11 02:53 113664 ----a-w- c:\windows\system32\wlanapi.dll 2017-09-13 15:28 . 2017-10-11 02:53 362496 ----a-w- c:\windows\system32\wow64win.dll 2017-09-13 15:28 . 2017-10-11 02:53 243712 ----a-w- c:\windows\system32\wow64.dll 2017-09-13 15:28 . 2017-10-11 02:53 215552 ----a-w- c:\windows\system32\winsrv.dll 2017-09-13 15:28 . 2017-10-11 02:53 13312 ----a-w- c:\windows\system32\wow64cpu.dll 2017-09-13 15:28 . 2017-10-11 02:53 86528 ----a-w- c:\windows\system32\TSpkg.dll 2017-09-13 15:28 . 2017-10-11 02:53 210432 ----a-w- c:\windows\system32\wdigest.dll 2017-09-13 15:28 . 2017-10-11 02:53 503808 ----a-w- c:\windows\system32\srcore.dll 2017-09-13 15:28 . 2017-10-11 02:53 135680 ----a-w- c:\windows\system32\sspicli.dll 2017-09-13 15:28 . 2017-10-11 02:53 50176 ----a-w- c:\windows\system32\srclient.dll 2017-09-13 15:28 . 2017-10-11 02:53 28672 ----a-w- c:\windows\system32\sspisrv.dll 2017-09-13 15:28 . 2017-10-11 02:53 63488 ----a-w- c:\windows\system32\setbcdlocale.dll 2017-09-13 15:28 . 2017-10-11 02:53 345600 ----a-w- c:\windows\system32\schannel.dll 2017-09-13 15:28 . 2017-10-11 02:53 1212928 ----a-w- c:\windows\system32\rpcrt4.dll 2017-09-13 15:28 . 2017-10-11 02:53 190464 ----a-w- c:\windows\system32\rpchttp.dll 2017-09-13 15:28 . 2017-10-11 02:53 28160 ----a-w- c:\windows\system32\secur32.dll 2017-09-13 15:28 . 2017-10-11 02:53 16384 ----a-w- c:\windows\system32\ntvdm64.dll 2017-09-13 15:28 . 2017-10-11 02:53 312320 ----a-w- c:\windows\system32\ncrypt.dll 2017-09-13 15:28 . 2017-10-11 02:53 1068544 ----a-w- c:\windows\system32\msctf.dll 2017-09-13 15:28 . 2017-10-11 02:53 316928 ----a-w- c:\windows\system32\msv1_0.dll 2017-09-13 15:28 . 2017-10-11 02:52 146432 ----a-w- c:\windows\system32\msaudite.dll 2017-09-13 15:28 . 2017-10-11 02:52 60416 ----a-w- c:\windows\system32\msobjs.dll 2017-09-13 15:27 . 2017-10-11 02:53 731648 ----a-w- c:\windows\system32\kerberos.dll 2017-09-13 15:27 . 2017-10-11 02:53 1460736 ----a-w- c:\windows\system32\lsasrv.dll 2017-09-13 15:27 . 2017-10-11 02:53 1163264 ----a-w- c:\windows\system32\kernel32.dll 2017-09-13 15:27 . 2017-10-11 02:53 419840 ----a-w- c:\windows\system32\KernelBase.dll 2017-09-13 15:27 . 2017-10-11 02:53 44032 ----a-w- c:\windows\system32\csrsrv.dll 2017-09-13 15:27 . 2017-10-11 02:53 43520 ----a-w- c:\windows\system32\cryptbase.dll 2017-09-13 15:27 . 2017-10-11 02:53 22016 ----a-w- c:\windows\system32\credssp.dll 2017-09-13 15:27 . 2017-10-11 02:53 463872 ----a-w- c:\windows\system32\certcli.dll 2017-09-13 15:27 . 2017-10-11 02:53 880640 ----a-w- c:\windows\system32\advapi32.dll 2017-09-13 15:27 . 2017-10-11 02:53 123904 ----a-w- c:\windows\system32\bcrypt.dll 2017-09-13 15:27 . 2017-10-11 02:53 59904 ----a-w- c:\windows\system32\appidapi.dll 2017-09-13 15:27 . 2017-10-11 02:53 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2017-09-13 15:27 . 2017-10-11 02:53 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2017-09-13 15:27 . 2017-10-11 02:53 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2017-09-13 15:27 . 2017-10-11 02:53 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2017-09-13 15:27 . 2017-10-11 02:53 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2017-09-13 15:27 . 2017-10-11 02:53 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll . . ((((((((((((((((((((((((((((((((( Points de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "iCloudServices"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" [2017-10-19 67384] "DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2011-03-17 842048] "iCloudDrive"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe" [2017-10-19 110392] "iCloudPhotos"="c:\program files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe" [2017-10-19 356664] "ApplePhotoStreams"="c:\program files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2017-10-19 67896] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2015-03-23 296216] "MSIRegister"="c:\msi\MSIRegister\MSIRegister.exe" [2017-07-11 1262544] "Fast Boot"="c:\program files (x86)\MSI\Fast Boot\StartFastBoot.exe" [2015-04-22 759120] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2017-09-05 587288] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) "SoftwareSASGeneration"= 1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 aswbIDSAgent;aswbIDSAgent;c:\program files\AVAST Software\Avast\x64\aswidsagenta.exe;c:\program files\AVAST Software\Avast\x64\aswidsagenta.exe [x] R3 aswHwid;aswHwid;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x] R3 Ke2200;NDIS Miniport Driver for Killer e2201/e2202 PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\e22w7x64.sys;c:\windows\SYSNATIVE\DRIVERS\e22w7x64.sys [x] R3 MSIClock_CC;MSIClock_CC;c:\program files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe;c:\program files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe [x] R3 NTIOLib_1_0_3;NTIOLib_1_0_3;c:\program files (x86)\MSI\Super Charger\NTIOLib_X64.sys;c:\program files (x86)\MSI\Super Charger\NTIOLib_X64.sys [x] R3 NTIOLib_1_0_C;NTIOLib_1_0_C;d:\ntiolib_x64.sys;d:\NTIOLib_X64.sys [x] R3 NTIOLib_MB;NTIOLib_MB;c:\program files (x86)\MSI\MSI Gaming APP\Lib\NTIOLib_X64.sys;c:\program files (x86)\MSI\MSI Gaming APP\Lib\NTIOLib_X64.sys [x] R3 NTIOLib_MSIClock_CC;NTIOLib_MSIClock_CC;c:\program files (x86)\MSI\Command Center\ClockGen\NTIOLib_X64.sys;c:\program files (x86)\MSI\Command Center\ClockGen\NTIOLib_X64.sys [x] R3 NTIOLib_MSICOMM_CC;NTIOLib_MSICOMM_CC;c:\program files (x86)\MSI\Command Center\NTIOLib_X64.sys;c:\program files (x86)\MSI\Command Center\NTIOLib_X64.sys [x] R3 NTIOLib_MSICPU_CC;NTIOLib_MSICPU_CC;c:\program files (x86)\MSI\Command Center\CPU\NTIOLib_X64.sys;c:\program files (x86)\MSI\Command Center\CPU\NTIOLib_X64.sys [x] R3 NTIOLib_MSIDDR_CC;NTIOLib_MSIDDR_CC;c:\program files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys;c:\program files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys [x] R3 NTIOLib_MSIFrequency_CC;NTIOLib_MSIFrequency_CC;c:\program files (x86)\MSI\Command Center\ClockGen\CPU_Frequency\NTIOLib_X64.sys;c:\program files (x86)\MSI\Command Center\ClockGen\CPU_Frequency\NTIOLib_X64.sys [x] R3 NTIOLib_MSIRatio_CC;NTIOLib_MSIRatio_CC;c:\program files (x86)\MSI\Command Center\CPU\CPU_Ratio\NTIOLib_X64.sys;c:\program files (x86)\MSI\Command Center\CPU\CPU_Ratio\NTIOLib_X64.sys [x] R3 NTIOLib_MSISMB_CC;NTIOLib_MSISMB_CC;c:\program files (x86)\MSI\Command Center\SMBus\NTIOLib_X64.sys;c:\program files (x86)\MSI\Command Center\SMBus\NTIOLib_X64.sys [x] R3 NTIOLib_MSISuperIO_CC;NTIOLib_MSISuperIO_CC;c:\program files (x86)\MSI\Command Center\SuperIO\NTIOLib_X64.sys;c:\program files (x86)\MSI\Command Center\SuperIO\NTIOLib_X64.sys [x] R3 NvContainerNetworkService;NVIDIA NetworkService Container;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe [x] R3 NvStreamKms;NVIDIA KMS;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S0 aswbidsh;aswbidsh;c:\windows\system32\drivers\aswbidsha.sys;c:\windows\SYSNATIVE\drivers\aswbidsha.sys [x] S0 aswblog;aswblog;c:\windows\system32\drivers\aswbloga.sys;c:\windows\SYSNATIVE\drivers\aswbloga.sys [x] S0 aswbuniv;aswbuniv;c:\windows\system32\drivers\aswbuniva.sys;c:\windows\SYSNATIVE\drivers\aswbuniva.sys [x] S0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys;c:\windows\SYSNATIVE\drivers\aswRvrt.sys [x] S0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys;c:\windows\SYSNATIVE\drivers\aswVmm.sys [x] S0 iusb3hcs;Pilote de commutateur de contrôleur d'hôte Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x] S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x] S1 aswArPot;aswArPot;c:\windows\system32\drivers\aswArPot.sys;c:\windows\SYSNATIVE\drivers\aswArPot.sys [x] S1 aswbidsdriver;aswbidsdriver;c:\windows\system32\drivers\aswbidsdrivera.sys;c:\windows\SYSNATIVE\drivers\aswbidsdrivera.sys [x] S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x] S1 BfLwf;Killer Bandwidth Control;c:\windows\system32\DRIVERS\bflwfx64.sys;c:\windows\SYSNATIVE\DRIVERS\bflwfx64.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 GamingApp_Service;GamingApp_Service;c:\program files (x86)\MSI\Gaming APP\GamingApp_Service.exe;c:\program files (x86)\MSI\Gaming APP\GamingApp_Service.exe [x] S2 GamingHotkey_Service;GamingHotkey_Service;c:\program files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe;c:\program files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe [x] S2 iocbios2;iocbios2;c:\program files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys;c:\program files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [x] S2 ISCTAgent;Intel(R) Smart Connect Technology Agent;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe ;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [x] S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [x] S2 LMIInfo;LogMeIn Kernel Information Provider;c:\windows\system32\drivers\LMIInfo.sys;c:\windows\SYSNATIVE\drivers\LMIInfo.sys [x] S2 MSI_ActiveX_Service;MSI_ActiveX_Service;c:\program files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe;c:\program files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe [x] S2 MSI_ECOSERVICE;MSI_ECOSERVICE;c:\program files (x86)\MSI\ECO Center\ECO_Service.exe;c:\program files (x86)\MSI\ECO Center\ECO_Service.exe [x] S2 MSI_FastBoot;MSI Fast Boot Service;c:\program files (x86)\MSI\Fast Boot\FastBootService.exe;c:\program files (x86)\MSI\Fast Boot\FastBootService.exe [x] S2 MSI_LiveUpdate_Service;MSI Live Update Service;c:\program files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe;c:\program files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [x] S2 MSI_SuperCharger;MSI Super Charger Service;c:\program files (x86)\MSI\Super Charger\ChargeService.exe;c:\program files (x86)\MSI\Super Charger\ChargeService.exe [x] S2 MSIREGISTER_MR;MSIREGISTER_MR;c:\msi\MSIRegister\MSIRegisterService.exe;c:\msi\MSIRegister\MSIRegisterService.exe [x] S2 NvContainerLocalSystem;NVIDIA LocalSystem Container;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe;c:\program files\NVIDIA Corporation\NvContainer\nvcontainer.exe [x] S2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS;c:\program files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe;c:\program files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [x] S2 NvTelemetryContainer;NVIDIA Telemetry Container;c:\program files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe;c:\program files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [x] S2 SuperRAIDSvc;SuperRAIDSvc;c:\msi\Smart Utilities\SuperRAIDSvc.exe;c:\msi\Smart Utilities\SuperRAIDSvc.exe [x] S2 XTU3SERVICE;Intel(R) Extreme Tuning Utility Service;c:\program files (x86)\Intel\Extreme Tuning Utility\XtuService.exe;c:\program files (x86)\Intel\Extreme Tuning Utility\XtuService.exe [x] S3 AcpiCtlDrv;AcpiCtlDrv;c:\windows\system32\DRIVERS\AcpiCtlDrv.sys;c:\windows\SYSNATIVE\DRIVERS\AcpiCtlDrv.sys [x] S3 I2cHkBurn;I2cHkBurn;c:\windows\system32\drivers\I2cHkBurn.sys;c:\windows\SYSNATIVE\drivers\I2cHkBurn.sys [x] S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x] S3 ICCWDT;Intel(R) Watchdog Timer Driver (Intel(R) WDT);c:\windows\system32\DRIVERS\ICCWDT.sys;c:\windows\SYSNATIVE\DRIVERS\ICCWDT.sys [x] S3 ikbevent;Intel Upper keyboard Class Filter Driver;c:\windows\system32\DRIVERS\ikbevent.sys;c:\windows\SYSNATIVE\DRIVERS\ikbevent.sys [x] S3 imsevent;Intel Upper Mouse Class Filter Driver;c:\windows\system32\DRIVERS\imsevent.sys;c:\windows\SYSNATIVE\DRIVERS\imsevent.sys [x] S3 INETMON;INETMON;c:\windows\System32\Drivers\INETMON.sys;c:\windows\SYSNATIVE\Drivers\INETMON.sys [x] S3 ISCT;Intel(R) Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD.sys;c:\windows\SYSNATIVE\DRIVERS\ISCTD.sys [x] S3 iusb3hub;Pilote de concentrateur Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x] S3 iusb3xhc;Pilote du contrôleur d'hôte extensible Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x] S3 KillerEth;NDIS Miniport Driver for Killer PCI-E Gigabit Ethernet Controller;c:\windows\system32\DRIVERS\e2xw7x64.sys;c:\windows\SYSNATIVE\DRIVERS\e2xw7x64.sys [x] S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x] S3 NTIOLib_ECO;NTIOLib_ECO;c:\program files (x86)\MSI\ECO Center\NTIOLib_X64.sys;c:\program files (x86)\MSI\ECO Center\NTIOLib_X64.sys [x] S3 NTIOLib_FastBoot;NTIOLib_FastBoot;c:\program files (x86)\MSI\Fast Boot\NTIOLib_X64.sys;c:\program files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [x] S3 NTIOLib_MBAPI;NTIOLib_MBAPI;c:\program files (x86)\MSI\Gaming APP\Lib\NTIOLib_X64.sys;c:\program files (x86)\MSI\Gaming APP\Lib\NTIOLib_X64.sys [x] S3 NTIOLib_MSI_RAID;NTIOLib_MSI_RAID;c:\msi\Smart Utilities\NTIOLib_X64.sys;c:\msi\Smart Utilities\NTIOLib_X64.sys [x] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x] S3 nvvhci;NVVHCI Enumerator Service;c:\windows\system32\DRIVERS\nvvhci.sys;c:\windows\SYSNATIVE\DRIVERS\nvvhci.sys [x] . . --- Autres Services/Pilotes en mémoire --- . *NewlyCreated* - NTIOLIB_FASTBOOT . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveBlacklisted] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}] 2017-10-09 08:33 775064 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveSynced] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}] 2017-10-09 08:33 775064 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveSyncing] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}] 2017-10-09 08:33 775064 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00asw] @="{472083B0-C522-11CF-8763-00608CC02F24}" . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2017-11-10 12:39 1793296 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00asw] @="{472083B0-C522-11CF-8763-00608CC02F24}" . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2017-11-10 12:39 1793296 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2017-11-09 9228800] "MBCfg64"="c:\windows\system32\MBCfg64.dll" [2014-02-21 41088] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvLaunch.exe" [2017-11-10 253344] "VX3000"="c:\windows\vVX3000.exe" [2010-05-20 762736] "ISCT Tray"="c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe" [2014-08-25 5860656] "LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2016-12-27 423424] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2017-10-20 297784] . ------- Examen supplémentaire ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = https://www.google.co.th/ mDefault_Search_URL = hxxp://www.google.com mStart Page = https://www.bing.com/search?FORM=INCOH1&PC=IC05&PTAG=ICO-a516bf1a mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://www.google.com uInternet Settings,ProxyServer = localhost:8080 TCP: DhcpNameServer = 192.168.0.254 FF - ProfilePath - c:\users\kamaz\AppData\Roaming\Mozilla\Firefox\Profiles\938tijup.default-1500038935817\ FF - prefs.js: browser.search.selectedEngine - Search Provided by Bing FF - prefs.js: browser.startup.homepage - google.fr/ FF - prefs.js: keyword.URL - true . - - - - ORPHELINS SUPPRIMES - - - - . SafeBoot-MBAMService HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start . . . --------------------- CLES DE REGISTRE BLOQUEES --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Heure de fin: 2017-11-10 18:54:55 ComboFix-quarantined-files.txt 2017-11-10 17:54 . Avant-CF: 113 203 073 024 octets libres Après-CF: 113 154 682 880 octets libres . - - End Of File - - 589C59370987111E982893EE9A63AC5A A36C5E4F47E84449FF07ED3517B43A31