Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 12-07-11.03 - Gurvan 12/07/2012 12:45:15.1.4 - x64
- Microsoft Windows 7 Édition Familiale Premium 6.1.7601.1.1252.33.1036.18.8190.6374 [GMT 2:00]
- Lancé depuis: c:\users\Gurvan\Downloads\AntiBackdoor.exe
- AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
- SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
- SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- .
- .
- (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- c:\users\Gurvan\AppData\Local\Microsoft\Windows\Temporary Internet Files\{7E266E91-CCE1-4EB3-A620-2C6A6E303806}.xps
- c:\users\Gurvan\AppData\Local\Temp\svchost.exe
- c:\users\Gurvan\AppData\Roaming\3K30KTHSP8XHLVJava Update.exe
- c:\users\Gurvan\AppData\Roaming\app
- c:\users\Gurvan\AppData\Roaming\app\Jerakine_lang.dat
- c:\users\Gurvan\AppData\Roaming\app\Jerakine_lang_vesrion.dat
- c:\users\Gurvan\AppData\Roaming\DFH0086Java Update 5.exe
- c:\users\Gurvan\AppData\Roaming\dxsBAc7zjr.exe
- c:\users\Gurvan\AppData\Roaming\E6I39Java D.exe
- c:\users\Gurvan\AppData\Roaming\n4iaY.exe
- E:\Autorun.inf
- .
- .
- ((((((((((((((((((((((((((((( Fichiers créés du 2012-06-12 au 2012-07-12 ))))))))))))))))))))))))))))))))))))
- .
- .
- 2012-07-12 10:56 . 2012-07-12 10:56 -------- d-----w- c:\users\Default\AppData\Local\temp
- 2012-07-12 10:41 . 2012-05-31 04:04 9013136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0B824AB5-781D-4CB0-99D9-5395DB5EE0C2}\mpengine.dll
- 2012-07-12 00:53 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys
- 2012-07-12 00:24 . 2012-07-12 00:25 -------- d-----w- C:\rei
- 2012-07-12 00:24 . 2012-07-12 00:24 -------- d-----w- c:\program files\Reimage
- 2012-07-12 00:24 . 2012-07-12 00:24 -------- d-----w- c:\program files (x86)\ReImageCompanion
- 2012-07-11 23:52 . 2012-07-11 23:52 -------- d-----w- c:\programdata\RegCure
- 2012-07-11 23:52 . 2012-07-11 23:54 -------- d-----w- c:\program files (x86)\RegCure
- 2012-07-11 23:28 . 2012-07-11 23:28 -------- d-----w- C:\VundoFix Backups
- 2012-07-11 22:09 . 2012-07-11 22:09 -------- d-----w- c:\users\Gurvan\AppData\Roaming\SUPERAntiSpyware.com
- 2012-07-11 22:09 . 2012-07-11 22:09 -------- d-----w- c:\program files\SUPERAntiSpyware
- 2012-07-11 22:09 . 2012-07-11 22:09 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
- 2012-07-11 11:20 . 2012-06-06 06:06 2004480 ----a-w- c:\windows\system32\msxml6.dll
- 2012-07-11 11:20 . 2012-06-06 06:06 1881600 ----a-w- c:\windows\system32\msxml3.dll
- 2012-07-11 11:20 . 2012-06-06 05:05 1390080 ----a-w- c:\windows\SysWow64\msxml6.dll
- 2012-07-11 11:20 . 2012-06-06 05:05 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll
- 2012-07-11 11:20 . 2010-06-26 03:55 2048 ----a-w- c:\windows\system32\msxml3r.dll
- 2012-07-11 11:20 . 2010-06-26 03:24 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
- 2012-07-09 22:27 . 2012-07-09 22:27 -------- d-----w- C:\Ace of Spades
- 2012-07-07 11:31 . 2012-07-11 23:30 -------- d-----w- c:\users\Gurvan\riotsGamesLogs
- 2012-06-30 02:11 . 2012-06-30 02:12 -------- d-----w- c:\program files\ma-config.com
- 2012-06-30 02:11 . 2012-06-30 02:11 -------- d-----w- c:\programdata\ma-config.com
- 2012-06-29 17:50 . 2012-06-29 17:50 -------- d-----w- c:\users\Gurvan\AppData\Roaming\LolClient
- 2012-06-29 09:22 . 2012-06-29 09:22 -------- d-----w- c:\programdata\ATI
- 2012-06-29 09:22 . 2012-06-29 09:22 -------- d-----w- c:\program files (x86)\AMD APP
- 2012-06-28 10:28 . 2008-07-12 06:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll
- 2012-06-28 10:28 . 2008-07-12 06:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll
- 2012-06-28 10:28 . 2008-07-12 06:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll
- 2012-06-28 10:25 . 2012-06-28 10:25 -------- d-----w- C:\Riot Games
- 2012-06-28 07:57 . 2012-06-28 07:57 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
- 2012-06-27 23:51 . 2012-07-11 23:47 -------- d-----w- c:\users\Gurvan\AppData\Local\PMB Files
- 2012-06-27 23:51 . 2012-07-11 23:47 -------- d-----w- c:\programdata\PMB Files
- 2012-06-27 23:50 . 2012-06-27 23:50 -------- d-----w- c:\program files (x86)\Pando Networks
- 2012-06-27 09:43 . 2012-06-27 09:43 -------- d-----w- c:\users\Gurvan\AppData\Roaming\AnkamaCertificates
- 2012-06-26 22:31 . 2010-11-05 01:57 32072 ---h--w- c:\users\Gurvan\AppData\Roaming\Mozilla Firefox.exe
- 2012-06-26 09:54 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
- 2012-06-26 09:54 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
- 2012-06-26 09:54 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
- 2012-06-26 09:54 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
- 2012-06-26 09:53 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll
- 2012-06-26 09:53 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll
- 2012-06-26 09:53 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll
- 2012-06-26 09:53 . 2012-06-02 13:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
- 2012-06-26 09:53 . 2012-06-02 13:15 36864 ----a-w- c:\windows\system32\wuapp.exe
- 2012-06-25 22:05 . 2012-06-25 22:05 -------- d-----w- c:\users\Gurvan\AppData\Roaming\Dofus-3.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
- 2012-06-20 19:35 . 2012-06-20 19:35 -------- d-----w- c:\users\Gurvan\AppData\Roaming\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
- 2012-06-20 18:32 . 2012-06-20 18:32 -------- d-----w- c:\users\Gurvan\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
- 2012-06-20 18:32 . 2012-06-29 16:15 -------- d-----w- c:\users\Gurvan\AppData\Roaming\Dofus2
- 2012-06-20 18:32 . 2012-06-20 18:32 -------- d-----w- c:\users\Gurvan\AppData\Roaming\Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
- 2012-06-19 21:02 . 2012-07-12 00:48 -------- d-----w- c:\users\Gurvan\AppData\Roaming\.minecraft
- 2012-06-19 21:00 . 2012-06-20 15:50 -------- d-----w- c:\users\Gurvan\AppData\Roaming\.minecraft - Copie (2)
- 2012-06-18 12:38 . 2012-06-18 12:38 -------- d-----w- c:\users\Gurvan\AppData\Local\Macromedia
- 2012-06-16 09:24 . 2012-06-16 09:24 -------- d-----w- c:\program files\Microsoft Silverlight
- 2012-06-16 09:24 . 2012-06-16 09:24 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
- 2012-06-13 16:40 . 2012-04-26 05:41 77312 ----a-w- c:\windows\system32\rdpwsx.dll
- 2012-06-13 16:40 . 2012-04-26 05:41 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
- 2012-06-13 16:40 . 2012-04-26 05:34 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe
- 2012-06-13 16:40 . 2012-05-01 05:40 209920 ----a-w- c:\windows\system32\profsvc.dll
- 2012-06-13 16:40 . 2012-05-04 11:06 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
- 2012-06-13 16:40 . 2012-05-04 10:03 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
- 2012-06-13 16:40 . 2012-05-04 10:03 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
- 2012-06-13 16:40 . 2012-04-24 05:37 1462272 ----a-w- c:\windows\system32\crypt32.dll
- 2012-06-13 16:40 . 2012-04-24 05:37 184320 ----a-w- c:\windows\system32\cryptsvc.dll
- 2012-06-13 16:40 . 2012-04-24 05:37 140288 ----a-w- c:\windows\system32\cryptnet.dll
- 2012-06-13 16:40 . 2012-04-24 04:36 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
- 2012-06-13 16:40 . 2012-04-24 04:36 1158656 ----a-w- c:\windows\SysWow64\crypt32.dll
- 2012-06-13 16:40 . 2012-04-24 04:36 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
- 2012-06-13 16:39 . 2012-04-07 12:31 3216384 ----a-w- c:\windows\system32\msi.dll
- 2012-06-13 16:39 . 2012-04-07 11:26 2342400 ----a-w- c:\windows\SysWow64\msi.dll
- 2012-06-13 16:39 . 2012-04-28 03:55 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
- .
- .
- .
- (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2012-06-23 22:37 . 2012-05-28 08:33 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
- 2012-06-23 22:37 . 2011-12-29 10:41 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
- 2012-06-11 18:59 . 2012-06-11 18:59 10248192 ----a-w- c:\windows\system32\drivers\atikmdag.sys
- 2012-06-11 18:35 . 2012-06-11 18:35 70144 ----a-w- c:\windows\system32\coinst_8.98.dll
- 2012-06-11 18:29 . 2012-06-11 18:29 24826368 ----a-w- c:\windows\system32\atio6axx.dll
- 2012-06-11 18:00 . 2012-06-11 18:00 20467712 ----a-w- c:\windows\SysWow64\atioglxx.dll
- 2012-06-11 17:25 . 2012-06-11 17:25 163840 ----a-w- c:\windows\system32\atiapfxx.exe
- 2012-06-11 17:24 . 2011-09-08 17:34 924160 ----a-w- c:\windows\SysWow64\aticfx32.dll
- 2012-06-11 17:23 . 2011-09-08 17:32 1090560 ----a-w- c:\windows\system32\aticfx64.dll
- 2012-06-11 17:20 . 2012-06-11 17:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
- 2012-06-11 17:19 . 2012-06-11 17:19 532992 ----a-w- c:\windows\system32\atieclxx.exe
- 2012-06-11 17:19 . 2012-06-11 17:19 239616 ----a-w- c:\windows\system32\atiesrxx.exe
- 2012-06-11 17:17 . 2012-06-11 17:17 120320 ----a-w- c:\windows\system32\atitmm64.dll
- 2012-06-11 17:17 . 2012-06-11 17:17 21504 ----a-w- c:\windows\system32\atimuixx.dll
- 2012-06-11 17:17 . 2012-06-11 17:17 59392 ----a-w- c:\windows\system32\atiedu64.dll
- 2012-06-11 17:17 . 2012-06-11 17:17 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
- 2012-06-11 17:16 . 2012-06-11 17:16 6301696 ----a-w- c:\windows\SysWow64\atidxx32.dll
- 2012-06-11 17:01 . 2011-09-08 17:16 6914560 ----a-w- c:\windows\system32\atidxx64.dll
- 2012-06-11 16:51 . 2012-06-11 16:51 4246528 ----a-w- c:\windows\system32\atiumd6a.dll
- 2012-06-11 16:45 . 2012-06-11 16:45 51200 ----a-w- c:\windows\system32\aticalrt64.dll
- 2012-06-11 16:45 . 2012-06-11 16:45 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
- 2012-06-11 16:45 . 2011-09-08 17:05 5480448 ----a-w- c:\windows\SysWow64\atiumdag.dll
- 2012-06-11 16:45 . 2012-06-11 16:45 44544 ----a-w- c:\windows\system32\aticalcl64.dll
- 2012-06-11 16:45 . 2012-06-11 16:45 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
- 2012-06-11 16:45 . 2012-06-11 16:45 15703040 ----a-w- c:\windows\system32\aticaldd64.dll
- 2012-06-11 16:43 . 2011-09-08 17:08 4729344 ----a-w- c:\windows\SysWow64\atiumdva.dll
- 2012-06-11 16:40 . 2012-06-11 16:40 13277696 ----a-w- c:\windows\SysWow64\aticaldd.dll
- 2012-06-11 16:36 . 2012-06-11 16:36 6605824 ----a-w- c:\windows\system32\atiumd64.dll
- 2012-06-11 16:27 . 2012-06-11 16:27 539136 ----a-w- c:\windows\system32\atiadlxx.dll
- 2012-06-11 16:26 . 2012-06-11 16:26 368640 ----a-w- c:\windows\SysWow64\atiadlxy.dll
- 2012-06-11 16:26 . 2012-06-11 16:26 17920 ----a-w- c:\windows\system32\atig6pxx.dll
- 2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll
- 2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\system32\atiglpxx.dll
- 2012-06-11 16:26 . 2012-06-11 16:26 41984 ----a-w- c:\windows\system32\atig6txx.dll
- 2012-06-11 16:26 . 2012-06-11 16:26 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
- 2012-06-11 16:26 . 2012-06-11 16:26 367616 ----a-w- c:\windows\system32\drivers\atikmpag.sys
- 2012-06-11 16:25 . 2011-09-08 16:52 54784 ----a-w- c:\windows\system32\atiuxp64.dll
- 2012-06-11 16:25 . 2012-04-06 01:09 42496 ----a-w- c:\windows\SysWow64\atiuxpag.dll
- 2012-06-11 16:25 . 2012-06-11 16:25 45056 ----a-w- c:\windows\system32\atiu9p64.dll
- 2012-06-11 16:24 . 2011-09-08 16:51 32768 ----a-w- c:\windows\SysWow64\atiu9pag.dll
- 2012-06-11 16:24 . 2012-06-11 16:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
- 2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\atimpc64.dll
- 2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\amdpcom64.dll
- 2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll
- 2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll
- 2012-06-11 11:50 . 2012-06-11 11:50 187392 ----a-w- c:\windows\system32\clinfo.exe
- 2012-06-11 11:50 . 2012-06-11 11:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll
- 2012-06-11 11:50 . 2012-06-11 11:50 65024 ----a-w- c:\windows\SysWow64\OpenVideo.dll
- 2012-06-11 11:50 . 2012-06-11 11:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll
- 2012-06-11 11:50 . 2012-06-11 11:50 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll
- 2012-06-11 11:50 . 2012-06-11 11:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll
- 2012-06-11 11:49 . 2012-06-11 11:49 13008896 ----a-w- c:\windows\SysWow64\amdocl.dll
- 2012-05-31 20:51 . 2012-05-31 20:51 2306328 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
- 2012-05-31 20:51 . 2012-05-31 20:51 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
- 2012-05-31 20:51 . 2012-05-31 20:51 639312 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
- .
- .
- ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
- REGEDIT4
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
- @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
- 2012-02-14 22:58 94208 ----a-w- c:\users\Gurvan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
- @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
- 2012-02-14 22:58 94208 ----a-w- c:\users\Gurvan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
- @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
- 2012-02-14 22:58 94208 ----a-w- c:\users\Gurvan\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
- .
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Clownfish"="c:\program files (x86)\Clownfish\Clownfish.exe" [2012-06-21 1097464]
- "ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
- "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-07-09 5661056]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
- "AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
- "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-12-01 258512]
- "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
- "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
- "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-06-27 1996200]
- "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704]
- .
- c:\users\Gurvan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
- Dropbox.lnk - c:\users\Gurvan\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
- DUC 3.0.lnk - c:\program files (x86)\No-IP\DUC30.exe [2010-6-18 1423520]
- OneNote 2010 - Capture d’écran et lancement.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 245120]
- .
- c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
- EasySetPackage.lnk - c:\program files (x86)\LG Soft India\EasySetPackage\bin\EasySetPackage.exe [2011-12-29 159744]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
- "ConsentPromptBehaviorAdmin"= 0 (0x0)
- "ConsentPromptBehaviorUser"= 3 (0x3)
- "EnableLUA"= 0 (0x0)
- "EnableUIADesktopToggle"= 0 (0x0)
- "PromptOnSecureDesktop"= 0 (0x0)
- .
- [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
- Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
- @=""
- .
- [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
- "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
- "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
- "ISUSScheduler"="c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
- "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
- "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
- .
- R2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-03-05 53888]
- R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
- R2 gupdate;Service Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-30 116648]
- R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-14 160944]
- R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-23 250056]
- R3 cpuz134;cpuz134;c:\users\Gurvan\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x]
- R3 driverhardwarev2x64;driverhardwarev2x64;c:\program files\ma-config.com\Drivers\driverhardwarev2x64.sys [2011-07-21 16640]
- R3 gupdatem;Service Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-30 116648]
- R3 LGDDCDevice;LGDDCDevice;c:\windows\system32\LGI2CDriver.sys [x]
- R3 LGII2CDevice;LGII2CDevice;c:\windows\system32\LGPII2CDriver.sys [x]
- R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\x64\maconfservice.exe [2011-11-25 427640]
- R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
- R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
- R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
- R3 SilvrLnk;SilverLink (USB GraphLink) Cable;c:\windows\system32\DRIVERS\silvrlnk.sys [2009-09-10 129536]
- R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
- R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736]
- R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2011-12-29 1255736]
- S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [2011-04-15 79488]
- S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [2011-04-15 40064]
- S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-12-01 27760]
- S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-12-29 270912]
- S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
- S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
- S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
- S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672]
- S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
- S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616]
- S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-06-11 361984]
- S2 AntiVirSchedulerService;Avira Planificateur;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-12-01 86224]
- S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-03-05 53888]
- S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-06-27 2369960]
- S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
- S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-03-19 2666880]
- S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2011-11-30 2123584]
- S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
- S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192]
- S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616]
- S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
- S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 24904]
- S3 netr28ux;Pilote de carte réseau sans fil RT2870 USB pour Vista;c:\windows\system32\DRIVERS\netr28ux.sys [2009-06-10 867328]
- S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
- S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [2011-11-24 11856]
- S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2010-11-28 44672]
- S3 WSDPrintDevice;Prise en charge de l’impression WSD via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]
- .
- .
- --- Autres Services/Pilotes en mémoire ---
- .
- *NewlyCreated* - WS2IFSL
- .
- Contenu du dossier 'Tâches planifiées'
- .
- 2012-07-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-28 22:37]
- .
- 2012-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-30 19:53]
- .
- 2012-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-30 19:53]
- .
- 2012-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4232414852-395253565-4101861292-1000Core.job
- - c:\users\Gurvan\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-29 19:26]
- .
- 2012-07-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4232414852-395253565-4101861292-1000UA.job
- - c:\users\Gurvan\AppData\Local\Google\Update\GoogleUpdate.exe [2011-12-29 19:26]
- .
- 2012-07-12 c:\windows\Tasks\RegCure Program Check.job
- - c:\program files (x86)\RegCure\RegCure.exe [2010-05-19 23:20]
- .
- 2012-07-12 c:\windows\Tasks\RegCure.job
- - c:\program files (x86)\RegCure\RegCure.exe [2010-05-19 23:20]
- .
- 2012-07-12 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 3b95a0ab-237c-4274-bc92-cbb9089994c2.job
- - c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
- .
- 2012-07-12 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task ee355027-66da-4693-b1da-548b8baf2997.job
- - c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
- .
- .
- --------- X64 Entries -----------
- .
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
- @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
- 2012-02-14 22:58 97792 ----a-w- c:\users\Gurvan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
- @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
- 2012-02-14 22:58 97792 ----a-w- c:\users\Gurvan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
- @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
- 2012-02-14 22:58 97792 ----a-w- c:\users\Gurvan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
- @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
- [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
- 2012-02-14 22:58 97792 ----a-w- c:\users\Gurvan\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-06-24 7233640]
- "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
- "LoadAppInit_DLLs"=0x0
- .
- ------- Examen supplémentaire -------
- .
- uLocal Page = c:\windows\system32\blank.htm
- uStart Page = hxxp://google.fr/
- mLocal Page = c:\windows\SysWOW64\blank.htm
- uInternet Settings,ProxyOverride = *.local
- IE: &Envoyer à OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
- IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
- FF - ProfilePath - c:\users\Gurvan\AppData\Roaming\Mozilla\Firefox\Profiles\qe9nz0hn.default\
- FF - prefs.js: browser.startup.homepage - hxxps://mail.google.com/mail/?hl=fr&shva=1#inbox
- FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?affID=112555&tt=060612_7_&babsrc=KW_ss&mntrId=7c638ea60000000000000014d15bc5c7&q=
- FF - user.js: network.http.max-persistent-connections-per-server - 4
- FF - user.js: nglayout.initialpaint.delay - 600
- FF - user.js: content.notify.interval - 600000
- FF - user.js: content.max.tokenizing.time - 1800000
- FF - user.js: content.switch.threshold - 600000
- FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=112555&tt=060612_7_
- FF - user.js: extensions.BabylonToolbar_i.babExt -
- FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
- FF - user.js: extensions.BabylonToolbar_i.id - 7c638ea60000000000000014d15bc5c7
- FF - user.js: extensions.BabylonToolbar_i.hardId - 7c638ea60000000000000014d15bc5c7
- FF - user.js: extensions.BabylonToolbar_i.instlDay - 15502
- FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
- FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
- FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1720:17
- FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
- FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
- FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
- FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
- FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
- FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
- .
- - - - - ORPHELINS SUPPRIMES - - - -
- .
- Wow6432Node-HKLM-Run-Browser companion helper - c:\program files (x86)\BrowserCompanion\BCHelper.exe
- .
- .
- .
- --------------------- CLES DE REGISTRE BLOQUEES ---------------------
- .
- [HKEY_USERS\S-1-5-21-4232414852-395253565-4101861292-1000\Software\G*e*n*i*e*"!\FM Genie Scout 12]
- "GameDir"="c:\\Users\\Gurvan\\Documents\\Sports Interactive\\Football Manager 2012\\games"
- "ShortlistDir"="c:\\Users\\Gurvan\\Documents\\Sports Interactive\\Football Manager 2012\\shortlists"
- "FMPath"=""
- "ScreenshotsDir"="c:\\Users\\Gurvan\\Documents\\Sports Interactive\\Football Manager 2012"
- "SaveDir"="c:\\Users\\Gurvan\\Documents\\Sports Interactive\\Football Manager 2012\\"
- "HistoryDir"="c:\\FM Genie Scout 12\\History Points"
- "LangDB"="c:\\FM Genie Scout 12\\lang_db.dat"
- "LastSaveGame"="c:\\Users\\Gurvan\\Documents\\Sports Interactive\\Football Manager 2012\\games\\Olympique Lyonnais.fm"
- "Language"="French"
- "LoadLangDB"=dword:00000001
- "CompressHistoryPoints"=dword:00000000
- "HighlightedAttributes"=dword:00000000
- "MinCondition"=dword:00000050
- "GraphStep"=dword:00000000
- "SkinName"="Steklo Black"
- "LastUpdateCheck"=dword:00009fe7
- "VersionOf201"=dword:0000007b
- "HighQualityGUI"=dword:00000001
- "AutomaticallyUpdateCheck"=dword:00000001
- "AdvancedGeneration"=dword:00000000
- "TranslateStaffSkills"=dword:00000001
- "TranslatePlayerSkills"=dword:00000001
- "TranslatePositions"=dword:00000001
- "ShowHistory"=dword:00000001
- "ShowGuidNotification"=dword:00000000
- "ShowDonateNotification"=dword:00000000
- "Version"=dword:000000cc
- "UniqueID"="94-FC65-2983"
- "Currency"=dword:00000056
- "UseProxy"=dword:00000000
- "ProxyHost"=""
- "ProxyPort"=""
- "UseAuthentication"=dword:00000000
- "UserName"=""
- "UserPassword"=""
- "PlayerSearchFeatureNum"=dword:00000002
- "StaffSearchFeatureNum"=dword:00000000
- "ClubSearchFeatureNum"=dword:00000000
- "FilterByClubFeatureNum"=dword:00000000
- "CompareFeatureNum"=dword:00000000
- "ShortlistFeatureNum"=dword:00000000
- "ExportFeatureNum"=dword:00000000
- "HistoryFeatureNum"=dword:00000000
- "LanguageDBFeatureNum"=dword:00000002
- "HintsFeatureNum"=dword:00000001
- "GenieReportFeatureNum"=dword:00000000
- "TopFormationFeatureNum"=dword:00000000
- "ScreenshotFeatureNum"=dword:00000000
- "AdClicksNum"=dword:00000000
- "AdImpressionsNum"=dword:0000000d
- "GameLoadedCounter"=dword:00000002
- .
- [HKEY_USERS\S-1-5-21-4232414852-395253565-4101861292-1000\Software\SecuROM\License information*]
- "datasecu"=hex:b4,f4,0f,9c,e4,f4,3a,42,32,59,7c,6f,7b,8a,a0,c8,fe,b4,d9,70,2d,
- 1c,e7,6b,5f,65,a2,e4,a3,c3,47,2a,d5,00,d3,3e,e6,bb,d9,2e,14,90,7c,f8,cd,2c,\
- "rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
- .
- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
- @Denied: (Full) (Everyone)
- .
- ------------------------ Autres processus actifs ------------------------
- .
- c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
- c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
- c:\windows\SysWOW64\PnkBstrA.exe
- c:\windows\SysWOW64\DllHost.exe
- .
- **************************************************************************
- .
- Heure de fin: 2012-07-12 13:20:32 - La machine a redémarré
- ComboFix-quarantined-files.txt 2012-07-12 11:20
- .
- Avant-CF: 111 056 953 344 octets libres
- Après-CF: 110 764 589 056 octets libres
- .
- - - End Of File - - D2044CB1910B13BA4274C011E9630943
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement