ComboFix 14-02-24.02 - Steeve 24/02/2014 18:13:12.1.2 - x64
Microsoft® Windows Vista™ Édition Intégrale 6.0.6002.2.1252.33.1036.18.2750.1121 [GMT 1:00]
Lancé depuis: c:\users\Steeve\Desktop\ComboFix.exe
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Steeve\AppData\Roaming\vso_ts_preview.xml
c:\windows\SysWow64\embedded
c:\windows\SysWow64\embedded\Licence.rtf
c:\windows\SysWow64\embedded\License.txt
c:\windows\SysWow64\embedded\uninstall.exe
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2014-01-24 au 2014-02-24 ))))))))))))))))))))))))))))))))))))
.
.
2014-02-24 17:48 . 2014-02-24 17:48 -------- d-----w- c:\users\UpdatusUser.PC-de-Steeve\AppData\Local\temp
2014-02-24 17:48 . 2014-02-24 17:48 -------- d-----w- c:\users\Administrateur\AppData\Local\temp
2014-02-20 16:33 . 2014-02-20 20:35 -------- d-----w- C:\Shortcut_Module
2014-02-14 07:57 . 2014-02-05 10:19 17849344 ----a-w- c:\windows\system32\mshtml.dll
2014-02-14 07:57 . 2014-02-05 10:02 10926080 ----a-w- c:\windows\system32\ieframe.dll
2014-02-13 20:03 . 2014-02-20 14:31 -------- d-----w- C:\Pre_Scan
2014-02-13 19:25 . 2013-12-05 04:48 1869824 ----a-w- c:\windows\system32\msxml3.dll
2014-02-13 19:25 . 2013-12-05 02:12 1248768 ----a-w- c:\windows\SysWow64\msxml3.dll
2014-02-13 17:51 . 2014-02-24 17:49 -------- d-----w- c:\users\Steeve\AppData\Local\CrashDumps
2014-02-10 19:28 . 2009-07-15 08:17 82992 ----a-w- c:\windows\system32\drivers\sbtis.sys
2014-02-10 19:27 . 2009-12-03 22:40 35000 ----a-w- c:\windows\system32\mxntdfg.exe
2014-02-10 19:27 . 2009-12-03 16:03 27432 ----a-w- c:\windows\system32\sbbd.exe
2014-02-10 19:19 . 2014-02-24 17:51 -------- d-----w- C:\_Backup
2014-02-10 19:18 . 2014-02-10 19:30 -------- d-----w- c:\users\Steeve\AppData\Roaming\Avanquest
2014-02-10 19:18 . 2014-02-10 19:28 -------- d-----w- c:\programdata\Avanquest
2014-02-10 19:17 . 2014-02-10 19:28 -------- d-----w- c:\program files (x86)\Common Files\AntiVirus
2014-02-10 19:17 . 2014-02-10 19:17 -------- d-----w- c:\program files (x86)\Avanquest
2014-02-10 19:15 . 2014-02-10 19:15 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2014-02-10 11:39 . 2014-02-11 18:49 -------- d-----w- c:\windows\system32\wbem\Logs
2014-02-10 11:39 . 2014-02-14 06:53 -------- d-----w- c:\windows\Debug
2014-02-10 11:04 . 2014-02-10 15:59 -------- d-----w- c:\users\Steeve\AppData\Roaming\System Speedup
2014-02-10 11:03 . 2014-02-10 11:04 -------- d-----w- c:\program files (x86)\System Speedup
2014-02-09 22:35 . 2014-02-09 22:35 -------- d-----w- c:\users\Administrateur\AppData\Roaming\AVAST Software
2014-02-09 21:51 . 2014-02-09 21:51 -------- d-----w- c:\users\Steeve\AppData\Roaming\AVAST Software
2014-02-09 20:46 . 2014-02-09 20:46 -------- d-----w- c:\program files\AVAST Software(1)
2014-02-09 18:27 . 2014-02-09 18:44 -------- d-----w- C:\FRST
2014-02-07 08:22 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{46685C1D-1193-4783-B32C-B8A5C19187B2}\mpengine.dll
2014-01-30 19:52 . 2014-01-30 19:52 -------- d-----w- c:\program files\iPod
2014-01-30 19:52 . 2014-01-30 19:53 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-30 19:52 . 2014-01-30 19:53 -------- d-----w- c:\program files\iTunes
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-17 06:59 . 2006-11-02 12:35 88567024 ----a-w- c:\windows\system32\mrt.exe
2014-02-05 17:00 . 2012-03-31 13:04 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-02-05 17:00 . 2011-05-15 12:02 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-02-05 08:50 . 2014-02-14 07:58 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2014-01-03 14:24 . 2013-08-24 20:38 65264 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2014-01-03 14:24 . 2013-08-24 20:38 1034464 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-01-03 14:24 . 2013-08-24 20:38 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-01-03 14:24 . 2013-08-24 20:38 207904 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-01-03 14:24 . 2013-08-24 20:38 422216 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-01-03 14:24 . 2013-08-24 20:38 78648 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-01-03 14:24 . 2013-08-21 15:43 334136 ----a-w- c:\windows\system32\aswBoot.exe
2014-01-03 14:24 . 2013-08-24 20:38 64752 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2014-01-03 14:24 . 2013-08-24 20:37 43152 ----a-w- c:\windows\avastSS.scr
2013-12-26 15:22 . 2013-12-26 15:23 109696 ----a-w- c:\windows\SysWow64\EasyHook64.dll
2013-12-18 05:13 . 2010-08-08 12:33 270496 ------w- c:\windows\system32\MpSigStub.exe
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"Windows Defender User Interface"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1584184]
"Windows Mail"="c:\program files\Windows Mail\WinMail.exe" [2008-01-21 400896]
"PrivatVPN"="c:\program files (x86)\PrivatVPN\PrivatVPN.exe" [2013-11-21 1055744]
"Spotify Web Helper"="c:\users\Steeve\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2014-01-13 1171968]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2012-02-23 59240]
"SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-01-03 3764024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"OpwareSE4"="c:\program files (x86)\ScanSoft\OmniPageSE4\OpwareSE4.exe"
"SSBkgdUpdate"="c:\program files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"NBKeyScan"="c:\program files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe"
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Themes
.
Contenu du dossier 'Tâches planifiées'
.
2014-02-24 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 17:00]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-01-03 14:24 287280 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 242192]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-14 1028384]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Examen supplémentaire -------
.
uLocal Page = c:\windows\SysWOW64\blank.htm
uStart Page = hxxp://
www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://
www.google.com/ie
TCP: DhcpNameServer = 192.168.0.254
FF - ProfilePath - c:\users\Steeve\AppData\Roaming\Mozilla\Firefox\Profiles\fcjwrg9w.default-1389549710114\
FF - prefs.js: browser.startup.homepage -
http://www.google.com
.
- - - - ORPHELINS SUPPRIMES - - - -
.
Toolbar-10 - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
SafeBoot-SRService
Toolbar-10 - (no file)
AddRemove-AVS Update Manager_is1 - c:\program files (x86)\AVS4YOU\AVSUpdateManager\unins000.exe
AddRemove-AVS4YOU Software Navigator_is1 - c:\program files (x86)\AVS4YOU\AVSSoftwareNavigator\unins000.exe
AddRemove-AVS4YOU Video Converter 7_is1 - c:\program files (x86)\AVS4YOU\AVSVideoConverter\unins000.exe
AddRemove-dBpowerAMP AAC Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpowerAMP AAC to Mp4 Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBPowerAMP AIFF codec r4 - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpowerAMP FAAC Mp4 Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpowerAMP FLAC Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpowerAMP Monkeys Audio Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpowerAMP mp3PRO Input Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpowerAMP Mp4 AAC Decode Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpowerAMP Musepack Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpowerAMP Music Converter - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpowerAMP Ogg Vorbis Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpowerAMP Real Audio Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBPowerAMP Real Audio Encoder R3 - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpowerAMP Winamp Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Windows Media Audio 10 Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpowerAMP WMA V9 Codec - c:\windows\system32\SpoonUninstall.exe
AddRemove-dMC mp3PRO (CLI) Encoder - c:\windows\system32\SpoonUninstall.exe
AddRemove-dMC Power Pack - c:\windows\system32\SpoonUninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_USERS\S-1-5-21-1720773443-3340476489-2937632913-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (S-1-5-21-1720773443-3340476489-2937632913-1000)
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-1720773443-3340476489-2937632913-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (S-1-5-21-1720773443-3340476489-2937632913-1000)
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-1720773443-3340476489-2937632913-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (S-1-5-21-1720773443-3340476489-2937632913-1000)
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-1720773443-3340476489-2937632913-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]
@Denied: (2) (S-1-5-21-1720773443-3340476489-2937632913-1000)
@Denied: (2) (LocalSystem)
"Progid"="IE.AssocFile.SVG"
.
[HKEY_USERS\S-1-5-21-1720773443-3340476489-2937632913-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (S-1-5-21-1720773443-3340476489-2937632913-1000)
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-1720773443-3340476489-2937632913-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (S-1-5-21-1720773443-3340476489-2937632913-1000)
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
[HKEY_USERS\S-1-5-21-1720773443-3340476489-2937632913-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-1720773443-3340476489-2937632913-1000_Classes\CLSID]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-1720773443-3340476489-2937632913-1000_Classes\CLSID\{70FB5B96-9A1E-4FA2-9975-91117B672879}]
@DACL=(02 0000)
@="VisualNews.VisualNewsGadget"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_44_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_44_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_44_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_44_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_44.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_44.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_44.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_44.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG14.00.00.01PROFESSIONAL"="FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B98089DB7CE019D40AA5C8EDD5E5BE2F6E667C038D530D6EB3452F6263ACFC7EC6084F2DF59AF063BE94F7D08E18765E8AA50EB4BDB11A26542C59554A2A5F3540DD37DE5181BEA4DDCC27D466DEC7568CA980F72733B6121967B99290B16810813E5D5C4111BCAC3A4A943616C601C5D52C824D723B3FDE5DF1899037CA405E100AFBB5CBD5FB40E9335D35E6C5F03EE72EE9B46A5655AAE50A58F9205C73AD027DAD1E11E8C5EB1BACD9D997A5AF7551E4F4A5DBB2DFD8ADBE6595C376B025A1EC5206033BB1D46F08CF140ACB5E9DE0E616A922ADD101BBC4F3B38A6ED5C93BE0111B485F66E78D24003D4994C6F6B3E4F192BBA3CDF17EE085B54EE2272A8275275119E4071883F6CEA30DB69BFEF6FF957C4B8835FC835EB42B0ACD08DD7B9B3FEFB8D096B4A584625FB944EB9F7A5F40BCE74E1A50D138D5F2381B29DF61DD147CD65BBC2A586B812B667315D1EA807FD0D45F7E9575331855313F7B56A3B0FC735BB34831973E2F633FA3ACE96842D5C1701DC8CAD82CE6BBD0CC30B30C00161B32BC05FB110177B987C06D724891438D7849B0D2BF092A9B4992CFAD4226F569F53A6A8960EDA2CE1992765A14C220810322F147C355D40DB6C3E827C14DA4EA2571FD6FE65E8F95C8721887A246E23D3EC8C6AE5A644912C3BF5C5DF91F1D439DCD20736D1B138ADFDEC7532ADC2490B9F99FBBB648EE272BE498A48D79B59368DE4F81DD0D520C937F7055CC9201970B3ADDD69CDB960CE369DBC97E971AE3F9AE71029A62DCD7C7324B4239BBA9A141C99446D09F597B6E0CE6A3E0DC08DCEB4E45461D9C042E3F6C525C38A7736D94D9D895900A87A7407AAC7444C0B103292D6F1E1B650E0F489259B8F4574B8F93F712B535EE95EA2EF752A46F506370AEF2E385CCACC72F4750181EB397F54006F3DCA95160500B2EA668C739A9B644E0B4E9B936A5F24FD0C09E1511D1E9CCB5E21AF6F5BFBFC68C9A7100D91E7E0C62611B3602D6005009F636F4D67060E1010AC42C22982D7DEE0D7746BF4BD561208403C2FEC5E0B3D88A67D81D32305D60D6812853A0276010B0B23FAA3A255217C1E9500489D8C4C23E20723E394C1F9634CCE4212952310254825B93ECE50BB4F5CC4E725134819CD1826FBDB2FE9A9A147CF96F30F8D2111882BBA2C31A0F9D6A4EE0EA7E95D606CB99EE742F98769DEBB8FB5EA73461DB3BE87A6976A00C96713E22FBD0050B6E6B25459E3B08792B07F2A65C279C4BF784A2FB76D510EED5C360E9B93E88882295F4E56D241BCCE37DBE3000D0FE31A4C84403D606E4E7B931306381F6B547E22913CF4E0D05A201110A0731F53601220B6779AE6FE285C702301FB1600"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\progra~2\AVANQU~1\Fix-It\mxtask.exe
c:\progra~2\AVANQU~1\Fix-It\mxtask2.exe
c:\program files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
c:\program files (x86)\REALTEK\RTL8187B Wireless LAN Utility\RtlService.exe
c:\program files (x86)\Common Files\AntiVirus\SBAMSvc.exe
c:\program files (x86)\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe
c:\program files\Logitech\SetPoint\x86\SetPoint32.exe
c:\windows\SysWOW64\WerFault.exe
c:\program files (x86)\REALTEK\RTL8187B Wireless LAN Utility\RtWlan.exe
.
**************************************************************************
.
Heure de fin: 2014-02-24 19:14:42 - La machine a redémarré
ComboFix-quarantined-files.txt 2014-02-24 18:14
.
Avant-CF: 18 770 903 040 octets libres
Après-CF: 18 393 513 984 octets libres
.
- - End Of File - - 308CC91F40E3316B4B8174548D8429AD
5C616939100B85E558DA92B899A0FC36