Infection Zero Access

Peu tu m'aider j'ai donc le même souci que Kaaze
Link: https://forums.commentcamarche.net/forum/affich-25399711-cheval-de-troie-services-exe#p25818994

Je te poste aussi 3 photo de fenêtre d'application qui s'ouvre toute les 5 minutes ..

Déjà avec MalwareBytes sa me dit sa toute les 2 min :
http://nsm05.casimages.com/img/2012/08/12/12081203094814694810202354.jpg

Ensuite sa , sa ces ouvert 2 fois en moins d'une heure :
http://nsm05.casimages.com/img/2012/08/12/12081203055514694810202324.jpg

Cette chose c'est un rapport du logiciel MB :
http://nsm05.casimages.com/img/2012/08/12/12081203031914694810202316.jpg

Et cette photo c'est ce que m'indique AVG un peu comme Kaaze :
http://nsm05.casimages.com/img/2012/08/12/12081203031914694810202316.jpg

Voila j'ai lut tes réponse et pas tous compris . donc je t'appelle pour que tu m'aide quand ton temps est disponible . Je suis souvent même toujours devant le PC . Merci A toi .

57 réponses

Résumé de la discussion

Des symptômes décrits incluent des fenêtres d'application qui s'ouvrent toutes les cinq minutes et des alertes répétées par MalwareBytes et AVG, suggérant une infection par cheval de Troie. Plusieurs propositions tournent autour de l’analyse avec des outils anti-malware et des vérifications complémentaires, notamment les rapports suspects, le redémarrage en mode sans échec et Combofix ou Defogger. Des réponses évoquent une infection potentiellement plus complexe, comme un rootkit TDSS, et certains échanges portent sur les risques de sessions temporaires et la nécessité de sauvegardes et d’un diagnostic approfondi. Une nuance utile précise que certains symptômes peuvent persister après un nettoyage et qu’il faut surveiller les processus et les services système, ainsi que refaire des analyses périodiques pour confirmer la suppression.

Bobot (l’IA à votre service)
  1. non tous est nikel . je peu donc supprimer tous les logiciels ? Combofix et defogger ? et autres truk qui sont mis sur mon bureaux ?

    Ha comment te remercier ... sérieux je stresser trop ce matin , j'aime pas savoir que mon petit pc est malade :D !

    Bin merci infiniment et bon courage pour tous les autres souci que tu va réglée .
    GL mec !
    0
    1. Malwarebytes Anti-Malware (Essai) 1.62.0.1300
      www.malwarebytes.org

      Version de la base de données: v2012.08.12.05

      Windows 7 Service Pack 1 x64 NTFS
      Internet Explorer 8.0.7601.17514
      Slayerz :: SLAYERZ-PC [administrateur]

      Protection: Désactivé

      13/08/2012 00:05:33
      mbam-log-2012-08-13 (00-42-08).txt

      Type d'examen: Examen complet (C:\|D:\|F:\|)
      Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
      Options d'examen désactivées: P2P
      Elément(s) analysé(s): 354530
      Temps écoulé: 36 minute(s), 14 seconde(s)

      Processus mémoire détecté(s): 0
      (Aucun élément nuisible détecté)

      Module(s) mémoire détecté(s): 0
      (Aucun élément nuisible détecté)

      Clé(s) du Registre détectée(s): 0
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre détectée(s): 0
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre détecté(s): 0
      (Aucun élément nuisible détecté)

      Dossier(s) détecté(s): 0
      (Aucun élément nuisible détecté)

      Fichier(s) détecté(s): 1
      C:\Users\Slayerz\Desktop\winlogon.exe (Heuristics.Reserved.Word.Exploit) -> Aucune action effectuée.

      (fin)
      0
      1. Okey thx , a toute et merci pour ces heures a m'aider a supporter mais incompréhension en plus de mes énormes fautes d'orthographe . Pourtant je suis bien français -_- a toute .
        0
        1. lol
          0
      2. coupe aux ciseaux !! :D

        non ferme juste les fenetres ouvertes connectées ^^
        0
        1. oui mais je suis honnête . certain on des soucis de ce style et ne font pas part de ces chose la . après il s'étonne bref , excuse moi quand tu dit :Déconnecte toi et ferme toutes applications en cours !

          Je me déconnecte d'internet ? ou je coup carrément la connections de mon pc a la box ?
          0
          1. pas bien !!!

            fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

            ▶ Télécharge ici :

            Malwarebytes

            ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

            relance malwarebytes en suivant scrupuleusement ces consignes :

            ! Déconnecte toi et ferme toutes applications en cours !

            ▶ Lance Malwarebyte's .

            Fais un examen dit "Complet" .

            ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
            ▶ à la fin tu cliques sur "résultat" .
            ▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

            ▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

            ▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

            0
            1. oui c'est un plug-in pour sony vegas pro 11 ( logiciel de montage vidéo ) Pour être honnête c'est du télécharger , avec keygen ou je sais pu si c'est un patch . logiciel beaucoup trop cher .
              0
              1. ca te dit quelque chose ca ?

                c:\program files (x86)\Magic Bullet Looks Vegas
                0
                1. ComboFix 12-08-10.02 - Slayerz 12/08/2012 23:40:17.3.4 - x64
                  Microsoft Windows 7 Édition Familiale Premium 6.1.7601.1.1252.33.1036.18.16381.14424 [GMT 2:00]
                  Lancé depuis: c:\users\Slayerz\Desktop\Frenchkiss.exe
                  Commutateurs utilisés :: c:\users\Slayerz\Desktop\CFScript.txt
                  AV: AVG Internet Security 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
                  FW: AVG Firewall *Disabled* {621CC794-9486-F902-D092-0484E8EA828B}
                  SP: AVG Internet Security 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
                  SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                  .
                  FILE ::
                  "c:\program files (x86)\loleusetup.exe"
                  .
                  .
                  (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  c:\program files (x86)\loleusetup.exe
                  c:\users\Slayerz\AppData\Roaming\OpenCandy
                  c:\users\Slayerz\AppData\Roaming\OpenCandy\832D5B32883C46A49F21C10CB3F27118\2785.ico
                  c:\users\Slayerz\AppData\Roaming\OpenCandy\832D5B32883C46A49F21C10CB3F27118\EBB77268-338F-4C6A-8590-AD88FED26F4A
                  c:\users\Slayerz\AppData\Roaming\OpenCandy\832D5B32883C46A49F21C10CB3F27118\OCBrowserHelper_1.0.3.85.dll
                  c:\users\Slayerz\AppData\Roaming\OpenCandy\DAF0D51A0CA247DEAB2F92A5C355AC8F\2785.ico
                  c:\users\Slayerz\AppData\Roaming\OpenCandy\DAF0D51A0CA247DEAB2F92A5C355AC8F\EBB77268-338F-4C6A-8590-AD88FED26F4A
                  c:\users\Slayerz\AppData\Roaming\OpenCandy\DAF0D51A0CA247DEAB2F92A5C355AC8F\OCBrowserHelper_1.0.3.85.dll
                  .
                  .
                  ((((((((((((((((((((((((((((( Fichiers créés du 2012-07-12 au 2012-08-12 ))))))))))))))))))))))))))))))))))))
                  .
                  .
                  2020-10-01 02:00 . 2012-08-12 18:51 -------- d-----w- c:\users\Slayerz\AppData\Local\ElevatedDiagnostics
                  2012-08-12 21:44 . 2012-08-12 21:44 -------- d-----w- c:\users\Default\AppData\Local\temp
                  2012-08-12 21:33 . 2012-08-12 21:33 -------- d-----w- c:\users\Slayerz\AppData\Roaming\AVG2012
                  2012-08-12 21:32 . 2012-08-12 21:33 -------- d-----w- c:\programdata\AVG Secure Search
                  2012-08-12 21:32 . 2012-08-12 21:32 -------- d-----w- c:\program files (x86)\Common Files\AVG Secure Search
                  2012-08-12 21:32 . 2012-08-12 21:33 -------- d-----w- c:\program files (x86)\AVG Secure Search
                  2012-08-12 21:31 . 2012-08-12 21:35 -------- d-----w- c:\programdata\AVG2012
                  2012-08-12 20:17 . 2012-08-12 20:24 -------- dc----w- C:\Pre_Scan
                  2012-08-12 20:16 . 2012-08-12 21:32 -------- d-----w- c:\windows\SysWow64\drivers\AVG
                  2012-08-12 18:19 . 2012-08-12 18:30 -------- d-----w- c:\programdata\SecTaskMan
                  2012-08-12 13:46 . 2012-08-12 14:35 -------- d-----w- c:\users\TEMP
                  2012-08-12 13:12 . 2012-08-12 19:08 -------- d-----w- c:\program files (x86)\MALWAREBYTES ANTI-MALWARE
                  2012-08-12 12:09 . 2012-08-12 12:09 -------- d-----w- c:\users\Slayerz\AppData\Roaming\Malwarebytes
                  2012-08-12 12:09 . 2012-08-12 13:06 -------- d-----w- c:\programdata\Malwarebytes
                  2012-08-12 11:50 . 2012-08-12 12:08 -------- d-----w- c:\users\Slayerz\AppData\Local\LooksBuilder
                  2012-08-12 11:42 . 2012-08-12 14:33 -------- d-----w- c:\program files (x86)\Magic Bullet Looks Vegas
                  2012-08-12 11:42 . 2012-08-12 11:42 -------- d-----w- c:\program files (x86)\Red Giant Link
                  2012-08-12 00:35 . 2012-08-12 00:35 -------- d-----w- c:\program files (x86)\Common Files\OFX
                  2012-08-12 00:35 . 2012-08-12 14:32 -------- d-----w- c:\program files\Sony
                  2012-08-12 00:15 . 2012-08-12 00:15 -------- d-----w- c:\program files (x86)\LooksBuilder
                  2012-08-11 17:28 . 2012-08-12 14:32 -------- d-----w- c:\users\Slayerz\AppData\Local\Dxtory Software
                  2012-08-11 17:28 . 2012-08-12 14:32 -------- d-----w- c:\program files (x86)\Dxtory Software
                  2012-08-11 17:28 . 2011-05-23 21:29 3673600 ----a-w- c:\windows\system32\DxtoryCodec64.dll
                  2012-08-11 17:28 . 2011-05-23 21:23 3166720 ---ha-w- c:\windows\SysWow64\DxtoryCodec.dll
                  2012-08-09 08:54 . 2012-08-09 08:54 -------- d-----w- c:\program files\WinPcap
                  2012-08-09 08:54 . 2012-08-09 09:10 -------- d-----w- c:\program files\VDownloader
                  2012-08-03 19:52 . 2012-08-03 19:52 -------- d-----w- c:\program files\Realmware
                  2012-07-29 12:25 . 2012-07-29 12:25 -------- d-----w- c:\users\Slayerz\AppData\Local\mediAvatar
                  2012-07-29 12:24 . 2012-07-29 12:27 -------- d-----w- c:\users\Slayerz\AppData\Roaming\mediAvatar
                  2012-07-29 12:08 . 2012-07-29 12:08 -------- d-----w- c:\users\Slayerz\AppData\Roaming\GrabPro
                  2012-07-29 11:52 . 2012-07-29 11:52 -------- d-----w- c:\users\Slayerz\AppData\Roaming\ProgSense
                  2012-07-29 11:51 . 2012-08-12 14:32 -------- d-----w- c:\users\Slayerz\AppData\Roaming\Orbit
                  2012-07-25 14:56 . 2012-08-12 14:32 -------- d-----w- c:\program files (x86)\Origin Games
                  2012-07-25 14:56 . 2012-08-09 09:49 -------- d-----w- c:\users\Slayerz\AppData\Local\Origin
                  2012-07-25 14:56 . 2012-08-09 09:49 -------- d-----w- c:\programdata\Origin
                  2012-07-25 14:55 . 2012-08-12 14:32 -------- d-----w- c:\program files (x86)\Origin
                  2012-07-25 14:53 . 2012-08-12 14:32 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
                  2012-07-22 12:17 . 2012-07-22 12:17 -------- d-----w- c:\programdata\ATI
                  2012-07-22 12:17 . 2012-08-12 14:32 -------- d-----w- c:\program files (x86)\AMD APP
                  2012-07-21 16:09 . 2012-07-21 16:09 -------- d-----w- c:\program files (x86)\SPCA1628
                  2012-07-20 18:22 . 2012-07-20 18:22 -------- d-----w- c:\program files (x86)\LOLReplay
                  .
                  .
                  .
                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2012-08-11 22:06 . 2012-02-04 17:37 283304 ---ha-w- c:\windows\SysWow64\PnkBstrB.exe
                  2012-08-11 22:06 . 2012-01-08 18:23 283304 ---ha-w- c:\windows\SysWow64\PnkBstrB.xtr
                  2012-08-11 22:06 . 2012-01-08 18:21 280904 ---ha-w- c:\windows\SysWow64\PnkBstrB.ex0
                  2012-08-03 16:43 . 2012-04-03 10:17 426184 ---ha-w- c:\windows\SysWow64\FlashPlayerApp.exe
                  2012-08-03 16:43 . 2012-01-08 05:50 70344 ---ha-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
                  2012-07-26 17:03 . 2012-02-04 17:37 76888 ---ha-w- c:\windows\SysWow64\PnkBstrA.exe
                  2012-07-11 13:36 . 2012-01-13 13:14 59701280 ----a-w- c:\windows\system32\MRT.exe
                  2012-06-12 03:08 . 2012-07-11 13:38 3148800 ----a-w- c:\windows\system32\win32k.sys
                  2012-06-11 18:59 . 2012-06-11 18:59 10248192 ----a-w- c:\windows\system32\drivers\atikmdag.sys
                  2012-06-11 18:35 . 2012-06-11 18:35 70144 ----a-w- c:\windows\system32\coinst_8.98.dll
                  2012-06-11 18:29 . 2012-06-11 18:29 24826368 ----a-w- c:\windows\system32\atio6axx.dll
                  2012-06-11 18:00 . 2012-06-11 18:00 20467712 ---ha-w- c:\windows\SysWow64\atioglxx.dll
                  2012-06-11 17:25 . 2012-06-11 17:25 163840 ----a-w- c:\windows\system32\atiapfxx.exe
                  2012-06-11 17:24 . 2011-11-10 03:16 924160 ---ha-w- c:\windows\SysWow64\aticfx32.dll
                  2012-06-11 17:23 . 2012-06-11 17:23 1090560 ----a-w- c:\windows\system32\aticfx64.dll
                  2012-06-11 17:20 . 2012-06-11 17:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
                  2012-06-11 17:19 . 2012-06-11 17:19 532992 ----a-w- c:\windows\system32\atieclxx.exe
                  2012-06-11 17:19 . 2012-06-11 17:19 239616 ----a-w- c:\windows\system32\atiesrxx.exe
                  2012-06-11 17:17 . 2012-06-11 17:17 120320 ----a-w- c:\windows\system32\atitmm64.dll
                  2012-06-11 17:17 . 2012-06-11 17:17 21504 ----a-w- c:\windows\system32\atimuixx.dll
                  2012-06-11 17:17 . 2012-06-11 17:17 59392 ----a-w- c:\windows\system32\atiedu64.dll
                  2012-06-11 17:17 . 2012-06-11 17:17 43520 ---ha-w- c:\windows\SysWow64\ati2edxx.dll
                  2012-06-11 17:16 . 2012-06-11 17:16 6301696 ---ha-w- c:\windows\SysWow64\atidxx32.dll
                  2012-06-11 17:01 . 2012-06-11 17:01 6914560 ----a-w- c:\windows\system32\atidxx64.dll
                  2012-06-11 16:51 . 2012-06-11 16:51 4246528 ----a-w- c:\windows\system32\atiumd6a.dll
                  2012-06-11 16:45 . 2012-06-11 16:45 51200 ----a-w- c:\windows\system32\aticalrt64.dll
                  2012-06-11 16:45 . 2012-06-11 16:45 46080 ---ha-w- c:\windows\SysWow64\aticalrt.dll
                  2012-06-11 16:45 . 2012-04-06 01:34 5480448 ---ha-w- c:\windows\SysWow64\atiumdag.dll
                  2012-06-11 16:45 . 2012-06-11 16:45 44544 ----a-w- c:\windows\system32\aticalcl64.dll
                  2012-06-11 16:45 . 2012-06-11 16:45 44032 ---ha-w- c:\windows\SysWow64\aticalcl.dll
                  2012-06-11 16:45 . 2012-06-11 16:45 15703040 ----a-w- c:\windows\system32\aticaldd64.dll
                  2012-06-11 16:43 . 2012-04-06 01:22 4729344 ---ha-w- c:\windows\SysWow64\atiumdva.dll
                  2012-06-11 16:40 . 2012-06-11 16:40 13277696 ---ha-w- c:\windows\SysWow64\aticaldd.dll
                  2012-06-11 16:36 . 2012-06-11 16:36 6605824 ----a-w- c:\windows\system32\atiumd64.dll
                  2012-06-11 16:27 . 2012-06-11 16:27 539136 ----a-w- c:\windows\system32\atiadlxx.dll
                  2012-06-11 16:26 . 2012-06-11 16:26 368640 ---ha-w- c:\windows\SysWow64\atiadlxy.dll
                  2012-06-11 16:26 . 2012-06-11 16:26 17920 ----a-w- c:\windows\system32\atig6pxx.dll
                  2012-06-11 16:26 . 2012-06-11 16:26 14848 ---ha-w- c:\windows\SysWow64\atiglpxx.dll
                  2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\system32\atiglpxx.dll
                  2012-06-11 16:26 . 2012-06-11 16:26 41984 ----a-w- c:\windows\system32\atig6txx.dll
                  2012-06-11 16:26 . 2012-06-11 16:26 33280 ---ha-w- c:\windows\SysWow64\atigktxx.dll
                  2012-06-11 16:26 . 2012-06-11 16:26 367616 ----a-w- c:\windows\system32\drivers\atikmpag.sys
                  2012-06-11 16:25 . 2011-11-10 02:11 54784 ----a-w- c:\windows\system32\atiuxp64.dll
                  2012-06-11 16:25 . 2012-06-11 16:25 42496 ---ha-w- c:\windows\SysWow64\atiuxpag.dll
                  2012-06-11 16:25 . 2012-04-06 01:09 45056 ----a-w- c:\windows\system32\atiu9p64.dll
                  2012-06-11 16:24 . 2012-04-06 01:09 32768 ---ha-w- c:\windows\SysWow64\atiu9pag.dll
                  2012-06-11 16:24 . 2012-06-11 16:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
                  2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\atimpc64.dll
                  2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\amdpcom64.dll
                  2012-06-11 16:23 . 2012-06-11 16:23 56832 ---ha-w- c:\windows\SysWow64\atimpc32.dll
                  2012-06-11 16:23 . 2012-06-11 16:23 56832 ---ha-w- c:\windows\SysWow64\amdpcom32.dll
                  2012-06-11 11:50 . 2012-06-11 11:50 187392 ----a-w- c:\windows\system32\clinfo.exe
                  2012-06-11 11:50 . 2012-06-11 11:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll
                  2012-06-11 11:50 . 2012-06-11 11:50 65024 ---ha-w- c:\windows\SysWow64\OpenVideo.dll
                  2012-06-11 11:50 . 2012-06-11 11:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll
                  2012-06-11 11:50 . 2012-06-11 11:50 56320 ---ha-w- c:\windows\SysWow64\OVDecode.dll
                  2012-06-11 11:50 . 2012-06-11 11:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll
                  2012-06-11 11:49 . 2012-06-11 11:49 13008896 ---ha-w- c:\windows\SysWow64\amdocl.dll
                  2012-06-09 05:43 . 2012-07-11 12:14 14172672 ----a-w- c:\windows\system32\shell32.dll
                  2012-06-07 17:29 . 2012-06-07 17:29 5632 ----a-w- c:\windows\system32\bbchlp.dll
                  2012-06-07 17:29 . 2012-06-07 17:29 4608 ----a-w- c:\windows\system32\drivers\bbcap.sys
                  2012-06-07 17:29 . 2012-06-07 17:29 37376 ----a-w- c:\windows\system32\bbcap.dll
                  2012-06-06 06:06 . 2012-07-11 12:14 2004480 ----a-w- c:\windows\system32\msxml6.dll
                  2012-06-06 06:06 . 2012-07-11 12:14 1881600 ----a-w- c:\windows\system32\msxml3.dll
                  2012-06-06 06:02 . 2012-07-11 12:14 1133568 ----a-w- c:\windows\system32\cdosys.dll
                  2012-06-06 05:05 . 2012-07-11 12:14 1390080 ----a-w- c:\windows\SysWow64\msxml6.dll
                  2012-06-06 05:05 . 2012-07-11 12:14 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll
                  2012-06-06 05:03 . 2012-07-11 12:14 805376 ----a-w- c:\windows\SysWow64\cdosys.dll
                  2012-06-02 22:19 . 2012-06-21 00:32 38424 ----a-w- c:\windows\system32\wups.dll
                  2012-06-02 22:19 . 2012-06-21 00:32 2428952 ----a-w- c:\windows\system32\wuaueng.dll
                  2012-06-02 22:19 . 2012-06-21 00:32 57880 ----a-w- c:\windows\system32\wuauclt.exe
                  2012-06-02 22:19 . 2012-06-21 00:32 44056 ----a-w- c:\windows\system32\wups2.dll
                  2012-06-02 22:19 . 2012-06-21 00:32 701976 ----a-w- c:\windows\system32\wuapi.dll
                  2012-06-02 22:15 . 2012-06-21 00:32 2622464 ----a-w- c:\windows\system32\wucltux.dll
                  2012-06-02 22:15 . 2012-06-21 00:32 99840 ----a-w- c:\windows\system32\wudriver.dll
                  2012-06-02 13:19 . 2012-06-21 00:32 186752 ----a-w- c:\windows\system32\wuwebv.dll
                  2012-06-02 13:15 . 2012-06-21 00:32 36864 ----a-w- c:\windows\system32\wuapp.exe
                  2012-06-02 05:50 . 2012-07-11 12:14 458704 ----a-w- c:\windows\system32\drivers\cng.sys
                  2012-06-02 05:48 . 2012-07-11 12:14 151920 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
                  2012-06-02 05:48 . 2012-07-11 12:14 95600 ----a-w- c:\windows\system32\drivers\ksecdd.sys
                  2012-06-02 05:45 . 2012-07-11 12:14 340992 ----a-w- c:\windows\system32\schannel.dll
                  2012-06-02 05:44 . 2012-07-11 12:14 307200 ----a-w- c:\windows\system32\ncrypt.dll
                  2012-06-02 04:40 . 2012-07-11 12:14 22016 ----a-w- c:\windows\SysWow64\secur32.dll
                  2012-06-02 04:40 . 2012-07-11 12:14 225280 ----a-w- c:\windows\SysWow64\schannel.dll
                  2012-06-02 04:39 . 2012-07-11 12:14 219136 ----a-w- c:\windows\SysWow64\ncrypt.dll
                  2012-06-02 04:34 . 2012-07-11 12:14 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
                  2012-05-17 22:50 . 2012-05-17 22:50 71680 ----a-w- c:\windows\system32\frapsv64.dll
                  2012-05-17 22:50 . 2012-05-17 22:50 65536 ---ha-w- c:\windows\SysWow64\frapsvid.dll
                  2012-05-15 04:01 . 2012-06-13 23:25 1188864 ----a-w- c:\windows\system32\wininet.dll
                  2012-05-15 03:59 . 2012-06-13 23:25 64512 ----a-w- c:\windows\system32\jsproxy.dll
                  2012-05-15 03:03 . 2012-06-13 23:25 981504 ----a-w- c:\windows\SysWow64\wininet.dll
                  .
                  .
                  ((((((((((((((((((((((((((((( SnapShot@2012-08-12_20.47.42 )))))))))))))))))))))))))))))))))))))))))
                  .
                  + 2012-01-10 10:52 . 2012-08-12 21:19 47658 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
                  + 2009-07-14 05:10 . 2012-08-12 21:19 38584 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
                  + 2012-01-08 04:16 . 2012-08-12 21:19 26468 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3996339946-498750113-113193782-1000_UserData.bin
                  - 2009-07-14 05:30 . 2012-07-22 12:17 86016 c:\windows\system32\DriverStore\infpub.dat
                  + 2009-07-14 05:30 . 2012-08-12 21:31 86016 c:\windows\system32\DriverStore\infpub.dat
                  - 2011-05-23 00:03 . 2011-05-23 00:03 48992 c:\windows\system32\DriverStore\FileRepository\avgfwfd6.inf_amd64_neutral_ae1e76d52507ef34\avgfwd6a.sys
                  + 2011-05-22 23:03 . 2011-05-22 23:03 48992 c:\windows\system32\DriverStore\FileRepository\avgfwfd6.inf_amd64_neutral_ae1e76d52507ef34\avgfwd6a.sys
                  + 2011-09-13 04:30 . 2011-09-13 04:30 37456 c:\windows\system32\drivers\avgrkx64.sys
                  + 2011-08-08 04:08 . 2011-08-08 04:08 46672 c:\windows\system32\drivers\avgmfx64.sys
                  + 2011-07-10 23:14 . 2011-07-10 23:14 29776 c:\windows\system32\drivers\AVGIDSFilter.sys
                  + 2011-07-10 23:14 . 2011-07-10 23:14 26704 c:\windows\system32\drivers\AVGIDSEH.sys
                  + 2011-05-22 23:03 . 2011-05-22 23:03 48992 c:\windows\system32\drivers\avgfwd6a.sys
                  + 2012-01-08 04:06 . 2012-08-12 21:45 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                  - 2012-01-08 04:06 . 2012-08-12 20:47 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                  + 2012-01-08 04:06 . 2012-08-12 21:45 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                  - 2012-01-08 04:06 . 2012-08-12 20:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                  + 2009-07-14 04:54 . 2012-08-12 21:45 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                  - 2009-07-14 04:54 . 2012-08-12 20:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                  - 2012-01-08 05:04 . 2012-08-12 20:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                  + 2012-01-08 05:04 . 2012-08-12 21:46 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                  - 2012-01-08 05:04 . 2012-08-12 20:48 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                  + 2012-01-08 05:04 . 2012-08-12 21:46 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                  + 2012-01-08 05:04 . 2012-08-12 21:46 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                  - 2012-01-08 05:04 . 2012-08-12 20:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                  + 2012-01-08 04:19 . 2012-08-12 21:46 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                  - 2012-01-08 04:19 . 2012-08-12 20:48 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                  + 2012-01-08 04:19 . 2012-08-12 21:46 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                  - 2012-01-08 04:19 . 2012-08-12 20:48 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                  - 2012-08-12 20:47 . 2012-08-12 20:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
                  + 2012-08-12 21:45 . 2012-08-12 21:45 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
                  + 2012-08-12 21:45 . 2012-08-12 21:45 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
                  - 2012-08-12 20:47 . 2012-08-12 20:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
                  + 2009-07-14 05:30 . 2012-08-12 21:31 143360 c:\windows\system32\DriverStore\infstrng.dat
                  - 2009-07-14 05:30 . 2012-07-22 12:17 143360 c:\windows\system32\DriverStore\infstrng.dat
                  - 2009-07-14 05:30 . 2012-07-22 12:15 143360 c:\windows\system32\DriverStore\infstor.dat
                  + 2009-07-14 05:30 . 2012-08-12 21:31 143360 c:\windows\system32\DriverStore\infstor.dat
                  + 2011-07-10 23:14 . 2011-07-10 23:14 375376 c:\windows\system32\drivers\avgtdia.sys
                  + 2011-10-07 04:23 . 2011-10-07 04:23 283728 c:\windows\system32\drivers\avgldx64.sys
                  + 2011-07-10 23:14 . 2011-07-10 23:14 120400 c:\windows\system32\drivers\AVGIDSDriver.sys
                  + 2009-07-14 05:01 . 2012-08-12 21:44 306396 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
                  - 2009-07-14 05:01 . 2012-08-12 20:45 306396 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
                  + 2012-08-12 21:26 . 2012-08-12 21:26 7629312 c:\windows\Installer\ce354.msi
                  + 2012-08-12 21:31 . 2012-08-12 21:31 2871808 c:\windows\Installer\ce34f.msi
                  + 2012-01-09 23:41 . 2012-08-12 21:44 10234924 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3996339946-498750113-113193782-1000-12288.dat
                  .
                  ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                  REGEDIT4
                  .
                  [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
                  2012-08-12 21:32 1811296 ----a-w- c:\program files (x86)\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll
                  .
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
                  "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll" [2012-08-12 1811296]
                  .
                  [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
                  [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
                  [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
                  .
                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "Dxtory Update Checker 2.0"="c:\program files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe" [2010-10-17 93696]
                  "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
                  .
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
                  "AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]
                  "vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2012-08-12 939872]
                  .
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                  "ConsentPromptBehaviorAdmin"= 0 (0x0)
                  "ConsentPromptBehaviorUser"= 3 (0x3)
                  "EnableLUA"= 0 (0x0)
                  "EnableUIADesktopToggle"= 0 (0x0)
                  "PromptOnSecureDesktop"= 0 (0x0)
                  .
                  [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
                  "aux2"=wdmaud.drv
                  .
                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
                  BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart
                  .
                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                  Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
                  .
                  [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
                  "LWS"=c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
                  .
                  R2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-03-05 53888]
                  R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
                  R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-07 160944]
                  R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-03 250056]
                  R3 ALSysIO;ALSysIO;c:\users\Slayerz\AppData\Local\Temp\ALSysIO64.sys [x]
                  R3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;c:\windows\system32\drivers\Apowersoft_AudioDevice.sys [2010-12-24 29288]
                  R3 Bulk1628;SPCA1628 Still Camera Service;c:\windows\system32\Drivers\Bulk1628.sys [x]
                  R3 ca1628UVCav;ca1628UVCav Driver Service;c:\windows\system32\Drivers\ca1628UVCav.sys [x]
                  R3 driverhardwarev2x64;driverhardwarev2x64;c:\program files\ma-config.com\Drivers\driverhardwarev2x64.sys [2011-07-21 16640]
                  R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [2012-01-18 351136]
                  R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\x64\maconfservice.exe [2012-07-04 427672]
                  R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-18 113120]
                  R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2011-08-01 45416]
                  R3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.0);c:\windows\system32\DRIVERS\RtTeam60.sys [2010-12-14 58472]
                  R3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.2);c:\windows\system32\DRIVERS\RtVlan60.sys [2010-12-14 24064]
                  R3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.0);c:\windows\system32\DRIVERS\RtTeam60.sys [2010-12-14 58472]
                  R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
                  R3 VLAN;Realtek Virtual Miniport Driver for VLAN (NDIS 6.2);c:\windows\system32\DRIVERS\RtVLAN60.sys [2010-12-14 24064]
                  R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-09 1255736]
                  S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-10 26704]
                  S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2011-09-13 37456]
                  S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [2011-05-22 48992]
                  S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2011-10-07 283728]
                  S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2011-08-08 46672]
                  S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2011-07-10 375376]
                  S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-02-18 283200]
                  S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
                  S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616]
                  S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-06-11 361984]
                  S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-03-05 53888]
                  S2 avgfws;Pare-feu AVG;c:\program files (x86)\AVG\AVG2012\avgfws.exe [2011-11-23 2391832]
                  S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
                  S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]
                  S2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\DRIVERS\RtNdPt60.sys [2010-12-14 27136]
                  S2 vToolbarUpdater;vToolbarUpdater;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe [2012-08-12 909152]
                  S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
                  S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192]
                  S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616]
                  S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
                  S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-10 120400]
                  S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-10 29776]
                  S3 bbcap;bb_capture_driver;c:\windows\system32\DRIVERS\bbcap.sys [2012-06-07 4608]
                  S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [2011-08-25 57088]
                  S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [2011-08-25 80384]
                  S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-09-29 646248]
                  .
                  .
                  Contenu du dossier 'Tâches planifiées'
                  .
                  2012-08-12 c:\windows\Tasks\Adobe Flash Player Updater.job
                  - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 16:43]
                  .
                  .
                  --------- X64 Entries -----------
                  .
                  .
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-10-17 13307496]
                  "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
                  "Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2010-11-03 1580368]
                  .
                  ------- Examen supplémentaire -------
                  .
                  uLocal Page = c:\windows\System32\blank.htm
                  uStart Page = hxxp://www.google.com/
                  mLocal Page = c:\windows\System32\blank.htm
                  uSearchAssistant = hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=FR&userid=7be687c5-e150-4759-b6e9-1e5789eb2c32&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
                  TCP: DhcpNameServer = 192.168.1.254
                  Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll
                  FF - ProfilePath - c:\users\Slayerz\AppData\Roaming\Mozilla\Firefox\Profiles\4lpyt9g0.default\
                  FF - prefs.js: browser.startup.homepage - google
                  FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B5df57259-4f97-46b4-960e-27b24bf564c7%7D&mid=179485536fc347d18e6081ac0fb55bd6-edec6e9b9801a805de0ef0a1f22d2e9456f9e99e&ds=AVG&v=10.0.0.7&lang=fr&pr=pr&d=2012-08-12%2023%3A32%3A58&sap=ku&q=
                  FF - user.js: extensions.incredibar_i.newTab - false
                  FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6PQvmh65hf&loc=IB_TB&i=26&search=
                  FF - user.js: extensions.incredibar_i.id - 96d3c1f100000000000050e54951b225
                  FF - user.js: extensions.incredibar_i.instlDay - 15454
                  FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14
                  FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14
                  FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1413:07
                  FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
                  FF - user.js: extensions.incredibar_i.prdct - incredibar
                  FF - user.js: extensions.incredibar_i.aflt - orgnl
                  FF - user.js: extensions.incredibar_i.smplGrp - none
                  FF - user.js: extensions.incredibar_i.tlbrId - base
                  FF - user.js: extensions.incredibar_i.instlRef -
                  FF - user.js: extensions.incredibar_i.dfltLng -
                  FF - user.js: extensions.incredibar_i.excTlbr - false
                  FF - user.js: extensions.incredibar_i.ms_url_id -
                  FF - user.js: extensions.incredibar_i.upn2 - 6PQvmh65hf
                  FF - user.js: extensions.incredibar_i.upn2n - 92542769836807201
                  FF - user.js: extensions.incredibar_i.productid - 26
                  FF - user.js: extensions.incredibar_i.installerproductid - 26
                  FF - user.js: extensions.incredibar_i.did - 10650
                  FF - user.js: extensions.incredibar_i.ppd - 42%5F4
                  .
                  - - - - ORPHELINS SUPPRIMES - - - -
                  .
                  Toolbar-{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - (no file)
                  WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
                  .
                  .
                  .
                  --------------------- CLES DE REGISTRE BLOQUEES ---------------------
                  .
                  [HKEY_USERS\S-1-5-21-3996339946-498750113-113193782-1000\Software\SecuROM\License information*]
                  "datasecu"=hex:ef,ca,16,da,c2,1b,64,78,33,ac,61,89,21,dd,60,c6,57,bd,6e,95,1f,
                  59,f1,ac,92,ad,c0,c8,2f,35,9e,d4,f8,4d,c7,df,74,fc,a1,67,81,b2,b9,3c,4a,09,\
                  "rkeysecu"=hex:c8,93,fc,d5,be,96,86,c3,92,7f,d9,dd,47,99,26,62
                  .
                  ------------------------ Autres processus actifs ------------------------
                  .
                  c:\windows\SysWOW64\PnkBstrA.exe
                  .
                  **************************************************************************
                  .
                  Heure de fin: 2012-08-12 23:50:32 - La machine a redémarré
                  ComboFix-quarantined-files.txt 2012-08-12 21:50
                  ComboFix2.txt 2012-08-12 21:14
                  ComboFix3.txt 2012-08-12 20:52
                  .
                  Avant-CF: 151 697 674 240 octets libres
                  Après-CF: 151 678 418 944 octets libres
                  .
                  - - End Of File - - 9A22BD9EDA1587EAE98231A21E2D6615
                  0

                  1. __________________________________________________
                    =>/!\Le script qui suit a été écrit spécialement cet ordinateur/!\ <=
                    =>il est fort déconseillé de le transposer sur un autre ordinateur !<=
                    ----------------------------------------------------------------------------


                    Toujours avec toutes les protections désactivées, fais ceci :

                    ▶ Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
                    ▶ Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :

                    ----------------------------------------------------------
                    KillAll::

                    ClearJavaCache::

                    File::
                    c:\program files (x86)\loleusetup.exe

                    Folder::
                    c:\users\TEMP
                    c:\users\Slayerz\AppData\Roaming\OpenCandy

                    RegLock::
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
                    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]


                    ------------------------------------------------------------------

                    ▶ Enregistre ce fichier sur ton Bureau (et pas ailleurs !) sous le nom CFScript.txt
                    ▶ Quitte le Bloc Notes

                    ▶ Fais un glisser/déposer de ce fichier CFScript sur le fichier combofix comme sur cette : illustration

                    ▶ Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
                    ▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
                    ▶ Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt

                    0
                    1. Dis moi que c'est bon stp :) . j'aimerais savoir , comment avec un rapport on peu voir ce qui infecter ?

                      Combofix ma supprimer 4 fichier tous a l'heure mais c'était avent que je le renomme .
                      0
                      1. ComboFix 12-08-10.02 - Slayerz 12/08/2012 23:05:46.2.4 - x64
                        Microsoft Windows 7 Édition Familiale Premium 6.1.7601.1.1252.33.1036.18.16381.14660 [GMT 2:00]
                        Lancé depuis: c:\users\Slayerz\Desktop\Frenchkiss.exe
                        SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                        .
                        .
                        ((((((((((((((((((((((((((((( Fichiers créés du 2012-07-12 au 2012-08-12 ))))))))))))))))))))))))))))))))))))
                        .
                        .
                        2020-10-01 02:00 . 2012-08-12 18:51 -------- d-----w- c:\users\Slayerz\AppData\Local\ElevatedDiagnostics
                        2012-08-12 21:08 . 2012-08-12 21:08 -------- d-----w- c:\users\Default\AppData\Local\temp
                        2012-08-12 20:17 . 2012-08-12 20:24 -------- dc----w- C:\Pre_Scan
                        2012-08-12 20:16 . 2012-08-12 20:16 -------- d-----w- c:\windows\SysWow64\drivers\AVG
                        2012-08-12 18:19 . 2012-08-12 18:30 -------- d-----w- c:\programdata\SecTaskMan
                        2012-08-12 13:46 . 2012-08-12 14:35 -------- d-----w- c:\users\TEMP
                        2012-08-12 13:12 . 2012-08-12 19:08 -------- d-----w- c:\program files (x86)\MALWAREBYTES ANTI-MALWARE
                        2012-08-12 12:09 . 2012-08-12 12:09 -------- d-----w- c:\users\Slayerz\AppData\Roaming\Malwarebytes
                        2012-08-12 12:09 . 2012-08-12 13:06 -------- d-----w- c:\programdata\Malwarebytes
                        2012-08-12 11:50 . 2012-08-12 12:08 -------- d-----w- c:\users\Slayerz\AppData\Local\LooksBuilder
                        2012-08-12 11:42 . 2012-08-12 14:33 -------- d-----w- c:\program files (x86)\Magic Bullet Looks Vegas
                        2012-08-12 11:42 . 2012-08-12 11:42 -------- d-----w- c:\program files (x86)\Red Giant Link
                        2012-08-12 00:35 . 2012-08-12 00:35 -------- d-----w- c:\program files (x86)\Common Files\OFX
                        2012-08-12 00:35 . 2012-08-12 14:32 -------- d-----w- c:\program files\Sony
                        2012-08-12 00:15 . 2012-08-12 00:15 -------- d-----w- c:\program files (x86)\LooksBuilder
                        2012-08-11 17:28 . 2012-08-12 14:32 -------- d-----w- c:\users\Slayerz\AppData\Local\Dxtory Software
                        2012-08-11 17:28 . 2012-08-12 14:32 -------- d-----w- c:\program files (x86)\Dxtory Software
                        2012-08-11 17:28 . 2011-05-23 21:29 3673600 ----a-w- c:\windows\system32\DxtoryCodec64.dll
                        2012-08-11 17:28 . 2011-05-23 21:23 3166720 ---ha-w- c:\windows\SysWow64\DxtoryCodec.dll
                        2012-08-09 08:54 . 2012-08-09 08:54 -------- d-----w- c:\program files\WinPcap
                        2012-08-09 08:54 . 2012-08-09 09:10 -------- d-----w- c:\program files\VDownloader
                        2012-08-03 19:52 . 2012-08-03 19:52 -------- d-----w- c:\program files\Realmware
                        2012-07-29 12:25 . 2012-07-29 12:25 -------- d-----w- c:\users\Slayerz\AppData\Local\mediAvatar
                        2012-07-29 12:24 . 2012-07-29 12:27 -------- d-----w- c:\users\Slayerz\AppData\Roaming\mediAvatar
                        2012-07-29 12:08 . 2012-07-29 12:08 -------- d-----w- c:\users\Slayerz\AppData\Roaming\GrabPro
                        2012-07-29 11:52 . 2012-07-29 11:52 -------- d-----w- c:\users\Slayerz\AppData\Roaming\ProgSense
                        2012-07-29 11:52 . 2012-08-12 14:32 -------- d-----w- c:\users\Slayerz\AppData\Roaming\OpenCandy
                        2012-07-29 11:51 . 2012-08-12 14:32 -------- d-----w- c:\users\Slayerz\AppData\Roaming\Orbit
                        2012-07-25 14:56 . 2012-08-12 14:32 -------- d-----w- c:\program files (x86)\Origin Games
                        2012-07-25 14:56 . 2012-08-09 09:49 -------- d-----w- c:\users\Slayerz\AppData\Local\Origin
                        2012-07-25 14:56 . 2012-08-09 09:49 -------- d-----w- c:\programdata\Origin
                        2012-07-25 14:55 . 2012-08-12 14:32 -------- d-----w- c:\program files (x86)\Origin
                        2012-07-25 14:53 . 2012-08-12 14:32 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
                        2012-07-22 12:17 . 2012-07-22 12:17 -------- d-----w- c:\programdata\ATI
                        2012-07-22 12:17 . 2012-08-12 14:32 -------- d-----w- c:\program files (x86)\AMD APP
                        2012-07-21 16:09 . 2012-07-21 16:09 -------- d-----w- c:\program files (x86)\SPCA1628
                        2012-07-20 18:22 . 2012-07-20 18:22 -------- d-----w- c:\program files (x86)\LOLReplay
                        .
                        .
                        .
                        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        2012-08-11 22:06 . 2012-02-04 17:37 283304 ---ha-w- c:\windows\SysWow64\PnkBstrB.exe
                        2012-08-11 22:06 . 2012-01-08 18:23 283304 ---ha-w- c:\windows\SysWow64\PnkBstrB.xtr
                        2012-08-11 22:06 . 2012-01-08 18:21 280904 ---ha-w- c:\windows\SysWow64\PnkBstrB.ex0
                        2012-08-03 16:43 . 2012-04-03 10:17 426184 ---ha-w- c:\windows\SysWow64\FlashPlayerApp.exe
                        2012-08-03 16:43 . 2012-01-08 05:50 70344 ---ha-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
                        2012-07-26 17:03 . 2012-02-04 17:37 76888 ---ha-w- c:\windows\SysWow64\PnkBstrA.exe
                        2012-07-11 13:36 . 2012-01-13 13:14 59701280 ----a-w- c:\windows\system32\MRT.exe
                        2012-06-12 03:08 . 2012-07-11 13:38 3148800 ----a-w- c:\windows\system32\win32k.sys
                        2012-06-11 18:59 . 2012-06-11 18:59 10248192 ----a-w- c:\windows\system32\drivers\atikmdag.sys
                        2012-06-11 18:35 . 2012-06-11 18:35 70144 ----a-w- c:\windows\system32\coinst_8.98.dll
                        2012-06-11 18:29 . 2012-06-11 18:29 24826368 ----a-w- c:\windows\system32\atio6axx.dll
                        2012-06-11 18:00 . 2012-06-11 18:00 20467712 ---ha-w- c:\windows\SysWow64\atioglxx.dll
                        2012-06-11 17:25 . 2012-06-11 17:25 163840 ----a-w- c:\windows\system32\atiapfxx.exe
                        2012-06-11 17:24 . 2011-11-10 03:16 924160 ---ha-w- c:\windows\SysWow64\aticfx32.dll
                        2012-06-11 17:23 . 2012-06-11 17:23 1090560 ----a-w- c:\windows\system32\aticfx64.dll
                        2012-06-11 17:20 . 2012-06-11 17:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
                        2012-06-11 17:19 . 2012-06-11 17:19 532992 ----a-w- c:\windows\system32\atieclxx.exe
                        2012-06-11 17:19 . 2012-06-11 17:19 239616 ----a-w- c:\windows\system32\atiesrxx.exe
                        2012-06-11 17:17 . 2012-06-11 17:17 120320 ----a-w- c:\windows\system32\atitmm64.dll
                        2012-06-11 17:17 . 2012-06-11 17:17 21504 ----a-w- c:\windows\system32\atimuixx.dll
                        2012-06-11 17:17 . 2012-06-11 17:17 59392 ----a-w- c:\windows\system32\atiedu64.dll
                        2012-06-11 17:17 . 2012-06-11 17:17 43520 ---ha-w- c:\windows\SysWow64\ati2edxx.dll
                        2012-06-11 17:16 . 2012-06-11 17:16 6301696 ---ha-w- c:\windows\SysWow64\atidxx32.dll
                        2012-06-11 17:01 . 2012-06-11 17:01 6914560 ----a-w- c:\windows\system32\atidxx64.dll
                        2012-06-11 16:51 . 2012-06-11 16:51 4246528 ----a-w- c:\windows\system32\atiumd6a.dll
                        2012-06-11 16:45 . 2012-06-11 16:45 51200 ----a-w- c:\windows\system32\aticalrt64.dll
                        2012-06-11 16:45 . 2012-06-11 16:45 46080 ---ha-w- c:\windows\SysWow64\aticalrt.dll
                        2012-06-11 16:45 . 2012-04-06 01:34 5480448 ---ha-w- c:\windows\SysWow64\atiumdag.dll
                        2012-06-11 16:45 . 2012-06-11 16:45 44544 ----a-w- c:\windows\system32\aticalcl64.dll
                        2012-06-11 16:45 . 2012-06-11 16:45 44032 ---ha-w- c:\windows\SysWow64\aticalcl.dll
                        2012-06-11 16:45 . 2012-06-11 16:45 15703040 ----a-w- c:\windows\system32\aticaldd64.dll
                        2012-06-11 16:43 . 2012-04-06 01:22 4729344 ---ha-w- c:\windows\SysWow64\atiumdva.dll
                        2012-06-11 16:40 . 2012-06-11 16:40 13277696 ---ha-w- c:\windows\SysWow64\aticaldd.dll
                        2012-06-11 16:36 . 2012-06-11 16:36 6605824 ----a-w- c:\windows\system32\atiumd64.dll
                        2012-06-11 16:27 . 2012-06-11 16:27 539136 ----a-w- c:\windows\system32\atiadlxx.dll
                        2012-06-11 16:26 . 2012-06-11 16:26 368640 ---ha-w- c:\windows\SysWow64\atiadlxy.dll
                        2012-06-11 16:26 . 2012-06-11 16:26 17920 ----a-w- c:\windows\system32\atig6pxx.dll
                        2012-06-11 16:26 . 2012-06-11 16:26 14848 ---ha-w- c:\windows\SysWow64\atiglpxx.dll
                        2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\system32\atiglpxx.dll
                        2012-06-11 16:26 . 2012-06-11 16:26 41984 ----a-w- c:\windows\system32\atig6txx.dll
                        2012-06-11 16:26 . 2012-06-11 16:26 33280 ---ha-w- c:\windows\SysWow64\atigktxx.dll
                        2012-06-11 16:26 . 2012-06-11 16:26 367616 ----a-w- c:\windows\system32\drivers\atikmpag.sys
                        2012-06-11 16:25 . 2011-11-10 02:11 54784 ----a-w- c:\windows\system32\atiuxp64.dll
                        2012-06-11 16:25 . 2012-06-11 16:25 42496 ---ha-w- c:\windows\SysWow64\atiuxpag.dll
                        2012-06-11 16:25 . 2012-04-06 01:09 45056 ----a-w- c:\windows\system32\atiu9p64.dll
                        2012-06-11 16:24 . 2012-04-06 01:09 32768 ---ha-w- c:\windows\SysWow64\atiu9pag.dll
                        2012-06-11 16:24 . 2012-06-11 16:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
                        2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\atimpc64.dll
                        2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\amdpcom64.dll
                        2012-06-11 16:23 . 2012-06-11 16:23 56832 ---ha-w- c:\windows\SysWow64\atimpc32.dll
                        2012-06-11 16:23 . 2012-06-11 16:23 56832 ---ha-w- c:\windows\SysWow64\amdpcom32.dll
                        2012-06-11 11:50 . 2012-06-11 11:50 187392 ----a-w- c:\windows\system32\clinfo.exe
                        2012-06-11 11:50 . 2012-06-11 11:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll
                        2012-06-11 11:50 . 2012-06-11 11:50 65024 ---ha-w- c:\windows\SysWow64\OpenVideo.dll
                        2012-06-11 11:50 . 2012-06-11 11:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll
                        2012-06-11 11:50 . 2012-06-11 11:50 56320 ---ha-w- c:\windows\SysWow64\OVDecode.dll
                        2012-06-11 11:50 . 2012-06-11 11:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll
                        2012-06-11 11:49 . 2012-06-11 11:49 13008896 ---ha-w- c:\windows\SysWow64\amdocl.dll
                        2012-06-09 05:43 . 2012-07-11 12:14 14172672 ----a-w- c:\windows\system32\shell32.dll
                        2012-06-07 17:29 . 2012-06-07 17:29 5632 ----a-w- c:\windows\system32\bbchlp.dll
                        2012-06-07 17:29 . 2012-06-07 17:29 4608 ----a-w- c:\windows\system32\drivers\bbcap.sys
                        2012-06-07 17:29 . 2012-06-07 17:29 37376 ----a-w- c:\windows\system32\bbcap.dll
                        2012-06-06 06:06 . 2012-07-11 12:14 2004480 ----a-w- c:\windows\system32\msxml6.dll
                        2012-06-06 06:06 . 2012-07-11 12:14 1881600 ----a-w- c:\windows\system32\msxml3.dll
                        2012-06-06 06:02 . 2012-07-11 12:14 1133568 ----a-w- c:\windows\system32\cdosys.dll
                        2012-06-06 05:05 . 2012-07-11 12:14 1390080 ----a-w- c:\windows\SysWow64\msxml6.dll
                        2012-06-06 05:05 . 2012-07-11 12:14 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll
                        2012-06-06 05:03 . 2012-07-11 12:14 805376 ----a-w- c:\windows\SysWow64\cdosys.dll
                        2012-06-02 22:19 . 2012-06-21 00:32 38424 ----a-w- c:\windows\system32\wups.dll
                        2012-06-02 22:19 . 2012-06-21 00:32 2428952 ----a-w- c:\windows\system32\wuaueng.dll
                        2012-06-02 22:19 . 2012-06-21 00:32 57880 ----a-w- c:\windows\system32\wuauclt.exe
                        2012-06-02 22:19 . 2012-06-21 00:32 44056 ----a-w- c:\windows\system32\wups2.dll
                        2012-06-02 22:19 . 2012-06-21 00:32 701976 ----a-w- c:\windows\system32\wuapi.dll
                        2012-06-02 22:15 . 2012-06-21 00:32 2622464 ----a-w- c:\windows\system32\wucltux.dll
                        2012-06-02 22:15 . 2012-06-21 00:32 99840 ----a-w- c:\windows\system32\wudriver.dll
                        2012-06-02 13:19 . 2012-06-21 00:32 186752 ----a-w- c:\windows\system32\wuwebv.dll
                        2012-06-02 13:15 . 2012-06-21 00:32 36864 ----a-w- c:\windows\system32\wuapp.exe
                        2012-06-02 05:50 . 2012-07-11 12:14 458704 ----a-w- c:\windows\system32\drivers\cng.sys
                        2012-06-02 05:48 . 2012-07-11 12:14 151920 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
                        2012-06-02 05:48 . 2012-07-11 12:14 95600 ----a-w- c:\windows\system32\drivers\ksecdd.sys
                        2012-06-02 05:45 . 2012-07-11 12:14 340992 ----a-w- c:\windows\system32\schannel.dll
                        2012-06-02 05:44 . 2012-07-11 12:14 307200 ----a-w- c:\windows\system32\ncrypt.dll
                        2012-06-02 04:40 . 2012-07-11 12:14 22016 ----a-w- c:\windows\SysWow64\secur32.dll
                        2012-06-02 04:40 . 2012-07-11 12:14 225280 ----a-w- c:\windows\SysWow64\schannel.dll
                        2012-06-02 04:39 . 2012-07-11 12:14 219136 ----a-w- c:\windows\SysWow64\ncrypt.dll
                        2012-06-02 04:34 . 2012-07-11 12:14 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
                        2012-05-24 10:50 . 2012-05-24 10:18 814143398 ----a-w- c:\program files (x86)\loleusetup.exe
                        2012-05-17 22:50 . 2012-05-17 22:50 71680 ----a-w- c:\windows\system32\frapsv64.dll
                        2012-05-17 22:50 . 2012-05-17 22:50 65536 ---ha-w- c:\windows\SysWow64\frapsvid.dll
                        2012-05-15 04:01 . 2012-06-13 23:25 1188864 ----a-w- c:\windows\system32\wininet.dll
                        2012-05-15 03:59 . 2012-06-13 23:25 64512 ----a-w- c:\windows\system32\jsproxy.dll
                        2012-05-15 03:03 . 2012-06-13 23:25 981504 ----a-w- c:\windows\SysWow64\wininet.dll
                        .
                        .
                        ((((((((((((((((((((((((((((( SnapShot@2012-08-12_20.47.42 )))))))))))))))))))))))))))))))))))))))))
                        .
                        + 2009-07-14 05:10 . 2012-08-12 20:49 38520 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
                        + 2012-01-08 04:16 . 2012-08-12 20:49 26306 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3996339946-498750113-113193782-1000_UserData.bin
                        - 2012-01-08 04:06 . 2012-08-12 20:47 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                        + 2012-01-08 04:06 . 2012-08-12 21:10 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                        + 2012-01-08 04:06 . 2012-08-12 21:10 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                        - 2012-01-08 04:06 . 2012-08-12 20:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                        + 2009-07-14 04:54 . 2012-08-12 21:10 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                        - 2009-07-14 04:54 . 2012-08-12 20:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                        + 2012-01-08 05:04 . 2012-08-12 21:11 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                        - 2012-01-08 05:04 . 2012-08-12 20:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                        + 2012-01-08 05:04 . 2012-08-12 21:11 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                        - 2012-01-08 05:04 . 2012-08-12 20:48 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                        - 2012-01-08 05:04 . 2012-08-12 20:48 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                        + 2012-01-08 05:04 . 2012-08-12 21:11 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                        - 2012-01-08 04:19 . 2012-08-12 20:48 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                        + 2012-01-08 04:19 . 2012-08-12 21:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                        - 2012-01-08 04:19 . 2012-08-12 20:48 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                        + 2012-01-08 04:19 . 2012-08-12 21:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                        - 2012-08-12 20:47 . 2012-08-12 20:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
                        + 2012-08-12 21:10 . 2012-08-12 21:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
                        + 2012-08-12 21:10 . 2012-08-12 21:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
                        - 2012-08-12 20:47 . 2012-08-12 20:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
                        - 2009-07-14 05:01 . 2012-08-12 20:45 306396 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
                        + 2009-07-14 05:01 . 2012-08-12 21:08 306396 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
                        + 2012-01-09 23:41 . 2012-08-12 21:08 10029176 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3996339946-498750113-113193782-1000-12288.dat
                        - 2012-01-09 23:41 . 2012-08-12 20:45 10029176 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3996339946-498750113-113193782-1000-12288.dat
                        .
                        ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        .
                        *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                        REGEDIT4
                        .
                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "Dxtory Update Checker 2.0"="c:\program files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe" [2010-10-17 93696]
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                        "ConsentPromptBehaviorAdmin"= 0 (0x0)
                        "ConsentPromptBehaviorUser"= 3 (0x3)
                        "EnableLUA"= 0 (0x0)
                        "EnableUIADesktopToggle"= 0 (0x0)
                        "PromptOnSecureDesktop"= 0 (0x0)
                        .
                        [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
                        "aux2"=wdmaud.drv
                        .
                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                        Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
                        .
                        [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
                        "LWS"=c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
                        .
                        R2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-03-05 53888]
                        R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
                        R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-07 160944]
                        R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-03 250056]
                        R3 ALSysIO;ALSysIO;c:\users\Slayerz\AppData\Local\Temp\ALSysIO64.sys [x]
                        R3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;c:\windows\system32\drivers\Apowersoft_AudioDevice.sys [2010-12-24 29288]
                        R3 Bulk1628;SPCA1628 Still Camera Service;c:\windows\system32\Drivers\Bulk1628.sys [x]
                        R3 ca1628UVCav;ca1628UVCav Driver Service;c:\windows\system32\Drivers\ca1628UVCav.sys [x]
                        R3 driverhardwarev2x64;driverhardwarev2x64;c:\program files\ma-config.com\Drivers\driverhardwarev2x64.sys [2011-07-21 16640]
                        R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [2012-01-18 351136]
                        R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\x64\maconfservice.exe [2012-07-04 427672]
                        R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-18 113120]
                        R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2011-08-01 45416]
                        R3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.0);c:\windows\system32\DRIVERS\RtTeam60.sys [2010-12-14 58472]
                        R3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.2);c:\windows\system32\DRIVERS\RtVlan60.sys [2010-12-14 24064]
                        R3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.0);c:\windows\system32\DRIVERS\RtTeam60.sys [2010-12-14 58472]
                        R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
                        R3 VLAN;Realtek Virtual Miniport Driver for VLAN (NDIS 6.2);c:\windows\system32\DRIVERS\RtVLAN60.sys [2010-12-14 24064]
                        R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-09 1255736]
                        S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-02-18 283200]
                        S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
                        S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616]
                        S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-06-11 361984]
                        S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-03-05 53888]
                        S2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\DRIVERS\RtNdPt60.sys [2010-12-14 27136]
                        S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
                        S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192]
                        S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616]
                        S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
                        S3 bbcap;bb_capture_driver;c:\windows\system32\DRIVERS\bbcap.sys [2012-06-07 4608]
                        S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [2011-08-25 57088]
                        S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [2011-08-25 80384]
                        S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-09-29 646248]
                        .
                        .
                        Contenu du dossier 'Tâches planifiées'
                        .
                        2012-08-12 c:\windows\Tasks\Adobe Flash Player Updater.job
                        - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 16:43]
                        .
                        .
                        --------- X64 Entries -----------
                        .
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-10-17 13307496]
                        "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
                        "Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2010-11-03 1580368]
                        .
                        ------- Examen supplémentaire -------
                        .
                        uLocal Page = c:\windows\System32\blank.htm
                        uStart Page = hxxp://www.google.com/
                        mLocal Page = c:\windows\System32\blank.htm
                        uSearchAssistant = hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=FR&userid=7be687c5-e150-4759-b6e9-1e5789eb2c32&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
                        TCP: DhcpNameServer = 192.168.1.254
                        FF - ProfilePath - c:\users\Slayerz\AppData\Roaming\Mozilla\Firefox\Profiles\4lpyt9g0.default\
                        FF - prefs.js: browser.startup.homepage - google
                        FF - user.js: extensions.incredibar_i.newTab - false
                        FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6PQvmh65hf&loc=IB_TB&i=26&search=
                        FF - user.js: extensions.incredibar_i.id - 96d3c1f100000000000050e54951b225
                        FF - user.js: extensions.incredibar_i.instlDay - 15454
                        FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14
                        FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14
                        FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1413:07
                        FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
                        FF - user.js: extensions.incredibar_i.prdct - incredibar
                        FF - user.js: extensions.incredibar_i.aflt - orgnl
                        FF - user.js: extensions.incredibar_i.smplGrp - none
                        FF - user.js: extensions.incredibar_i.tlbrId - base
                        FF - user.js: extensions.incredibar_i.instlRef -
                        FF - user.js: extensions.incredibar_i.dfltLng -
                        FF - user.js: extensions.incredibar_i.excTlbr - false
                        FF - user.js: extensions.incredibar_i.ms_url_id -
                        FF - user.js: extensions.incredibar_i.upn2 - 6PQvmh65hf
                        FF - user.js: extensions.incredibar_i.upn2n - 92542769836807201
                        FF - user.js: extensions.incredibar_i.productid - 26
                        FF - user.js: extensions.incredibar_i.installerproductid - 26
                        FF - user.js: extensions.incredibar_i.did - 10650
                        FF - user.js: extensions.incredibar_i.ppd - 42%5F4
                        .
                        - - - - ORPHELINS SUPPRIMES - - - -
                        .
                        Toolbar-{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - (no file)
                        WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
                        .
                        .
                        .
                        --------------------- CLES DE REGISTRE BLOQUEES ---------------------
                        .
                        [HKEY_USERS\S-1-5-21-3996339946-498750113-113193782-1000\Software\SecuROM\License information*]
                        "datasecu"=hex:ef,ca,16,da,c2,1b,64,78,33,ac,61,89,21,dd,60,c6,57,bd,6e,95,1f,
                        59,f1,ac,92,ad,c0,c8,2f,35,9e,d4,f8,4d,c7,df,74,fc,a1,67,81,b2,b9,3c,4a,09,\
                        "rkeysecu"=hex:c8,93,fc,d5,be,96,86,c3,92,7f,d9,dd,47,99,26,62
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
                        @Denied: (A 2) (Everyone)
                        @="FlashBroker"
                        "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_270_ActiveX.exe,-101"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
                        "Enabled"=dword:00000001
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
                        @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_270_ActiveX.exe"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
                        @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
                        @Denied: (A 2) (Everyone)
                        @="Shockwave Flash Object"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
                        @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx"
                        "ThreadingModel"="Apartment"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
                        @="0"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
                        @="ShockwaveFlash.ShockwaveFlash.11"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                        @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx, 1"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
                        @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
                        @="1.0"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                        @="ShockwaveFlash.ShockwaveFlash"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
                        @Denied: (A 2) (Everyone)
                        @="Macromedia Flash Factory Object"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
                        @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx"
                        "ThreadingModel"="Apartment"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
                        @="FlashFactory.FlashFactory.1"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                        @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx, 1"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
                        @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
                        @="1.0"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                        @="FlashFactory.FlashFactory"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
                        @Denied: (A 2) (Everyone)
                        @="IFlashBroker4"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
                        @="{00020424-0000-0000-C000-000000000046}"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
                        @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                        "Version"="1.0"
                        .
                        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
                        @Denied: (Full) (Everyone)
                        .
                        ------------------------ Autres processus actifs ------------------------
                        .
                        c:\windows\SysWOW64\PnkBstrA.exe
                        .
                        **************************************************************************
                        .
                        Heure de fin: 2012-08-12 23:14:47 - La machine a redémarré
                        ComboFix-quarantined-files.txt 2012-08-12 21:14
                        ComboFix2.txt 2012-08-12 20:52
                        .
                        Avant-CF: 152 423 837 696 octets libres
                        Après-CF: 152 408 064 000 octets libres
                        .
                        - - End Of File - - 50C99641CFAB09CDCA38F3918E12BEC2
                        0
                        1. c'est a dire c'est que quand j'ai lu sa j'ai pas comprit . Mais je renome quoi ? je renome le logiciel qui est sur le bureau ? j'écris quoi ?
                          0
                          1. c'est ecrit
                            0
                        2. tu ne lis pas ce que j'ecris...
                          0
                          1. ComboFix 12-08-10.02 - Slayerz 12/08/2012 22:41:42.1.4 - x64
                            Microsoft Windows 7 Édition Familiale Premium 6.1.7601.1.1252.33.1036.18.16381.14666 [GMT 2:00]
                            Lancé depuis: c:\users\Slayerz\Desktop\ComboFix.exe
                            SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                            .
                            .
                            (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                            .
                            .
                            c:\users\Public\sdelevURL.tmp
                            c:\windows\SysWow64\Packet.dll
                            c:\windows\SysWow64\pthreadVC.dll
                            c:\windows\SysWow64\wpcap.dll
                            .
                            .
                            ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                            .
                            .
                            -------\Legacy_NPF
                            -------\Service_npf
                            .
                            .
                            ((((((((((((((((((((((((((((( Fichiers créés du 2012-07-12 au 2012-08-12 ))))))))))))))))))))))))))))))))))))
                            .
                            .
                            2020-10-01 02:00 . 2012-08-12 18:51 -------- d-----w- c:\users\Slayerz\AppData\Local\ElevatedDiagnostics
                            2012-08-12 20:17 . 2012-08-12 20:24 -------- dc----w- C:\Pre_Scan
                            2012-08-12 20:16 . 2012-08-12 20:16 -------- d-----w- c:\windows\SysWow64\drivers\AVG
                            2012-08-12 18:19 . 2012-08-12 18:30 -------- d-----w- c:\programdata\SecTaskMan
                            2012-08-12 13:46 . 2012-08-12 14:35 -------- d-----w- c:\users\TEMP
                            2012-08-12 13:12 . 2012-08-12 19:08 -------- d-----w- c:\program files (x86)\MALWAREBYTES ANTI-MALWARE
                            2012-08-12 12:09 . 2012-08-12 12:09 -------- d-----w- c:\users\Slayerz\AppData\Roaming\Malwarebytes
                            2012-08-12 12:09 . 2012-08-12 13:06 -------- d-----w- c:\programdata\Malwarebytes
                            2012-08-12 11:50 . 2012-08-12 12:08 -------- d-----w- c:\users\Slayerz\AppData\Local\LooksBuilder
                            2012-08-12 11:42 . 2012-08-12 14:33 -------- d-----w- c:\program files (x86)\Magic Bullet Looks Vegas
                            2012-08-12 11:42 . 2012-08-12 11:42 -------- d-----w- c:\program files (x86)\Red Giant Link
                            2012-08-12 00:35 . 2012-08-12 00:35 -------- d-----w- c:\program files (x86)\Common Files\OFX
                            2012-08-12 00:35 . 2012-08-12 14:32 -------- d-----w- c:\program files\Sony
                            2012-08-12 00:15 . 2012-08-12 00:15 -------- d-----w- c:\program files (x86)\LooksBuilder
                            2012-08-11 17:28 . 2012-08-12 14:32 -------- d-----w- c:\users\Slayerz\AppData\Local\Dxtory Software
                            2012-08-11 17:28 . 2012-08-12 14:32 -------- d-----w- c:\program files (x86)\Dxtory Software
                            2012-08-11 17:28 . 2011-05-23 21:29 3673600 ----a-w- c:\windows\system32\DxtoryCodec64.dll
                            2012-08-11 17:28 . 2011-05-23 21:23 3166720 ---ha-w- c:\windows\SysWow64\DxtoryCodec.dll
                            2012-08-09 08:54 . 2012-08-09 08:54 -------- d-----w- c:\program files\WinPcap
                            2012-08-09 08:54 . 2012-08-09 09:10 -------- d-----w- c:\program files\VDownloader
                            2012-08-03 19:52 . 2012-08-03 19:52 -------- d-----w- c:\program files\Realmware
                            2012-07-29 12:25 . 2012-07-29 12:25 -------- d-----w- c:\users\Slayerz\AppData\Local\mediAvatar
                            2012-07-29 12:24 . 2012-07-29 12:27 -------- d-----w- c:\users\Slayerz\AppData\Roaming\mediAvatar
                            2012-07-29 12:08 . 2012-07-29 12:08 -------- d-----w- c:\users\Slayerz\AppData\Roaming\GrabPro
                            2012-07-29 11:52 . 2012-07-29 11:52 -------- d-----w- c:\users\Slayerz\AppData\Roaming\ProgSense
                            2012-07-29 11:52 . 2012-08-12 14:32 -------- d-----w- c:\users\Slayerz\AppData\Roaming\OpenCandy
                            2012-07-29 11:51 . 2012-08-12 14:32 -------- d-----w- c:\users\Slayerz\AppData\Roaming\Orbit
                            2012-07-25 14:56 . 2012-08-12 14:32 -------- d-----w- c:\program files (x86)\Origin Games
                            2012-07-25 14:56 . 2012-08-09 09:49 -------- d-----w- c:\users\Slayerz\AppData\Local\Origin
                            2012-07-25 14:56 . 2012-08-09 09:49 -------- d-----w- c:\programdata\Origin
                            2012-07-25 14:55 . 2012-08-12 14:32 -------- d-----w- c:\program files (x86)\Origin
                            2012-07-25 14:53 . 2012-08-12 14:32 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
                            2012-07-22 12:17 . 2012-07-22 12:17 -------- d-----w- c:\programdata\ATI
                            2012-07-22 12:17 . 2012-08-12 14:32 -------- d-----w- c:\program files (x86)\AMD APP
                            2012-07-21 16:09 . 2012-07-21 16:09 -------- d-----w- c:\program files (x86)\SPCA1628
                            2012-07-20 18:22 . 2012-07-20 18:22 -------- d-----w- c:\program files (x86)\LOLReplay
                            .
                            .
                            .
                            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                            .
                            2012-08-11 22:06 . 2012-02-04 17:37 283304 ---ha-w- c:\windows\SysWow64\PnkBstrB.exe
                            2012-08-11 22:06 . 2012-01-08 18:23 283304 ---ha-w- c:\windows\SysWow64\PnkBstrB.xtr
                            2012-08-11 22:06 . 2012-01-08 18:21 280904 ---ha-w- c:\windows\SysWow64\PnkBstrB.ex0
                            2012-08-03 16:43 . 2012-04-03 10:17 426184 ---ha-w- c:\windows\SysWow64\FlashPlayerApp.exe
                            2012-08-03 16:43 . 2012-01-08 05:50 70344 ---ha-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
                            2012-07-26 17:03 . 2012-02-04 17:37 76888 ---ha-w- c:\windows\SysWow64\PnkBstrA.exe
                            2012-07-11 13:36 . 2012-01-13 13:14 59701280 ----a-w- c:\windows\system32\MRT.exe
                            2012-06-12 03:08 . 2012-07-11 13:38 3148800 ----a-w- c:\windows\system32\win32k.sys
                            2012-06-11 18:59 . 2012-06-11 18:59 10248192 ----a-w- c:\windows\system32\drivers\atikmdag.sys
                            2012-06-11 18:35 . 2012-06-11 18:35 70144 ----a-w- c:\windows\system32\coinst_8.98.dll
                            2012-06-11 18:29 . 2012-06-11 18:29 24826368 ----a-w- c:\windows\system32\atio6axx.dll
                            2012-06-11 18:00 . 2012-06-11 18:00 20467712 ---ha-w- c:\windows\SysWow64\atioglxx.dll
                            2012-06-11 17:25 . 2012-06-11 17:25 163840 ----a-w- c:\windows\system32\atiapfxx.exe
                            2012-06-11 17:24 . 2011-11-10 03:16 924160 ---ha-w- c:\windows\SysWow64\aticfx32.dll
                            2012-06-11 17:23 . 2012-06-11 17:23 1090560 ----a-w- c:\windows\system32\aticfx64.dll
                            2012-06-11 17:20 . 2012-06-11 17:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
                            2012-06-11 17:19 . 2012-06-11 17:19 532992 ----a-w- c:\windows\system32\atieclxx.exe
                            2012-06-11 17:19 . 2012-06-11 17:19 239616 ----a-w- c:\windows\system32\atiesrxx.exe
                            2012-06-11 17:17 . 2012-06-11 17:17 120320 ----a-w- c:\windows\system32\atitmm64.dll
                            2012-06-11 17:17 . 2012-06-11 17:17 21504 ----a-w- c:\windows\system32\atimuixx.dll
                            2012-06-11 17:17 . 2012-06-11 17:17 59392 ----a-w- c:\windows\system32\atiedu64.dll
                            2012-06-11 17:17 . 2012-06-11 17:17 43520 ---ha-w- c:\windows\SysWow64\ati2edxx.dll
                            2012-06-11 17:16 . 2012-06-11 17:16 6301696 ---ha-w- c:\windows\SysWow64\atidxx32.dll
                            2012-06-11 17:01 . 2012-06-11 17:01 6914560 ----a-w- c:\windows\system32\atidxx64.dll
                            2012-06-11 16:51 . 2012-06-11 16:51 4246528 ----a-w- c:\windows\system32\atiumd6a.dll
                            2012-06-11 16:45 . 2012-06-11 16:45 51200 ----a-w- c:\windows\system32\aticalrt64.dll
                            2012-06-11 16:45 . 2012-06-11 16:45 46080 ---ha-w- c:\windows\SysWow64\aticalrt.dll
                            2012-06-11 16:45 . 2012-04-06 01:34 5480448 ---ha-w- c:\windows\SysWow64\atiumdag.dll
                            2012-06-11 16:45 . 2012-06-11 16:45 44544 ----a-w- c:\windows\system32\aticalcl64.dll
                            2012-06-11 16:45 . 2012-06-11 16:45 44032 ---ha-w- c:\windows\SysWow64\aticalcl.dll
                            2012-06-11 16:45 . 2012-06-11 16:45 15703040 ----a-w- c:\windows\system32\aticaldd64.dll
                            2012-06-11 16:43 . 2012-04-06 01:22 4729344 ---ha-w- c:\windows\SysWow64\atiumdva.dll
                            2012-06-11 16:40 . 2012-06-11 16:40 13277696 ---ha-w- c:\windows\SysWow64\aticaldd.dll
                            2012-06-11 16:36 . 2012-06-11 16:36 6605824 ----a-w- c:\windows\system32\atiumd64.dll
                            2012-06-11 16:27 . 2012-06-11 16:27 539136 ----a-w- c:\windows\system32\atiadlxx.dll
                            2012-06-11 16:26 . 2012-06-11 16:26 368640 ---ha-w- c:\windows\SysWow64\atiadlxy.dll
                            2012-06-11 16:26 . 2012-06-11 16:26 17920 ----a-w- c:\windows\system32\atig6pxx.dll
                            2012-06-11 16:26 . 2012-06-11 16:26 14848 ---ha-w- c:\windows\SysWow64\atiglpxx.dll
                            2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\system32\atiglpxx.dll
                            2012-06-11 16:26 . 2012-06-11 16:26 41984 ----a-w- c:\windows\system32\atig6txx.dll
                            2012-06-11 16:26 . 2012-06-11 16:26 33280 ---ha-w- c:\windows\SysWow64\atigktxx.dll
                            2012-06-11 16:26 . 2012-06-11 16:26 367616 ----a-w- c:\windows\system32\drivers\atikmpag.sys
                            2012-06-11 16:25 . 2011-11-10 02:11 54784 ----a-w- c:\windows\system32\atiuxp64.dll
                            2012-06-11 16:25 . 2012-06-11 16:25 42496 ---ha-w- c:\windows\SysWow64\atiuxpag.dll
                            2012-06-11 16:25 . 2012-04-06 01:09 45056 ----a-w- c:\windows\system32\atiu9p64.dll
                            2012-06-11 16:24 . 2012-04-06 01:09 32768 ---ha-w- c:\windows\SysWow64\atiu9pag.dll
                            2012-06-11 16:24 . 2012-06-11 16:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
                            2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\atimpc64.dll
                            2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\amdpcom64.dll
                            2012-06-11 16:23 . 2012-06-11 16:23 56832 ---ha-w- c:\windows\SysWow64\atimpc32.dll
                            2012-06-11 16:23 . 2012-06-11 16:23 56832 ---ha-w- c:\windows\SysWow64\amdpcom32.dll
                            2012-06-11 11:50 . 2012-06-11 11:50 187392 ----a-w- c:\windows\system32\clinfo.exe
                            2012-06-11 11:50 . 2012-06-11 11:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll
                            2012-06-11 11:50 . 2012-06-11 11:50 65024 ---ha-w- c:\windows\SysWow64\OpenVideo.dll
                            2012-06-11 11:50 . 2012-06-11 11:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll
                            2012-06-11 11:50 . 2012-06-11 11:50 56320 ---ha-w- c:\windows\SysWow64\OVDecode.dll
                            2012-06-11 11:50 . 2012-06-11 11:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll
                            2012-06-11 11:49 . 2012-06-11 11:49 13008896 ---ha-w- c:\windows\SysWow64\amdocl.dll
                            2012-06-09 05:43 . 2012-07-11 12:14 14172672 ----a-w- c:\windows\system32\shell32.dll
                            2012-06-07 17:29 . 2012-06-07 17:29 5632 ----a-w- c:\windows\system32\bbchlp.dll
                            2012-06-07 17:29 . 2012-06-07 17:29 4608 ----a-w- c:\windows\system32\drivers\bbcap.sys
                            2012-06-07 17:29 . 2012-06-07 17:29 37376 ----a-w- c:\windows\system32\bbcap.dll
                            2012-06-06 06:06 . 2012-07-11 12:14 2004480 ----a-w- c:\windows\system32\msxml6.dll
                            2012-06-06 06:06 . 2012-07-11 12:14 1881600 ----a-w- c:\windows\system32\msxml3.dll
                            2012-06-06 06:02 . 2012-07-11 12:14 1133568 ----a-w- c:\windows\system32\cdosys.dll
                            2012-06-06 05:05 . 2012-07-11 12:14 1390080 ----a-w- c:\windows\SysWow64\msxml6.dll
                            2012-06-06 05:05 . 2012-07-11 12:14 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll
                            2012-06-06 05:03 . 2012-07-11 12:14 805376 ----a-w- c:\windows\SysWow64\cdosys.dll
                            2012-06-02 22:19 . 2012-06-21 00:32 38424 ----a-w- c:\windows\system32\wups.dll
                            2012-06-02 22:19 . 2012-06-21 00:32 2428952 ----a-w- c:\windows\system32\wuaueng.dll
                            2012-06-02 22:19 . 2012-06-21 00:32 57880 ----a-w- c:\windows\system32\wuauclt.exe
                            2012-06-02 22:19 . 2012-06-21 00:32 44056 ----a-w- c:\windows\system32\wups2.dll
                            2012-06-02 22:19 . 2012-06-21 00:32 701976 ----a-w- c:\windows\system32\wuapi.dll
                            2012-06-02 22:15 . 2012-06-21 00:32 2622464 ----a-w- c:\windows\system32\wucltux.dll
                            2012-06-02 22:15 . 2012-06-21 00:32 99840 ----a-w- c:\windows\system32\wudriver.dll
                            2012-06-02 13:19 . 2012-06-21 00:32 186752 ----a-w- c:\windows\system32\wuwebv.dll
                            2012-06-02 13:15 . 2012-06-21 00:32 36864 ----a-w- c:\windows\system32\wuapp.exe
                            2012-06-02 05:50 . 2012-07-11 12:14 458704 ----a-w- c:\windows\system32\drivers\cng.sys
                            2012-06-02 05:48 . 2012-07-11 12:14 151920 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
                            2012-06-02 05:48 . 2012-07-11 12:14 95600 ----a-w- c:\windows\system32\drivers\ksecdd.sys
                            2012-06-02 05:45 . 2012-07-11 12:14 340992 ----a-w- c:\windows\system32\schannel.dll
                            2012-06-02 05:44 . 2012-07-11 12:14 307200 ----a-w- c:\windows\system32\ncrypt.dll
                            2012-06-02 04:40 . 2012-07-11 12:14 22016 ----a-w- c:\windows\SysWow64\secur32.dll
                            2012-06-02 04:40 . 2012-07-11 12:14 225280 ----a-w- c:\windows\SysWow64\schannel.dll
                            2012-06-02 04:39 . 2012-07-11 12:14 219136 ----a-w- c:\windows\SysWow64\ncrypt.dll
                            2012-06-02 04:34 . 2012-07-11 12:14 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
                            2012-05-24 10:50 . 2012-05-24 10:18 814143398 ----a-w- c:\program files (x86)\loleusetup.exe
                            2012-05-17 22:50 . 2012-05-17 22:50 71680 ----a-w- c:\windows\system32\frapsv64.dll
                            2012-05-17 22:50 . 2012-05-17 22:50 65536 ---ha-w- c:\windows\SysWow64\frapsvid.dll
                            2012-05-15 04:01 . 2012-06-13 23:25 1188864 ----a-w- c:\windows\system32\wininet.dll
                            2012-05-15 03:59 . 2012-06-13 23:25 64512 ----a-w- c:\windows\system32\jsproxy.dll
                            2012-05-15 03:03 . 2012-06-13 23:25 981504 ----a-w- c:\windows\SysWow64\wininet.dll
                            .
                            .
                            ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                            .
                            .
                            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                            REGEDIT4
                            .
                            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            "Dxtory Update Checker 2.0"="c:\program files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe" [2010-10-17 93696]
                            .
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                            "ConsentPromptBehaviorAdmin"= 0 (0x0)
                            "ConsentPromptBehaviorUser"= 3 (0x3)
                            "EnableLUA"= 0 (0x0)
                            "EnableUIADesktopToggle"= 0 (0x0)
                            "PromptOnSecureDesktop"= 0 (0x0)
                            .
                            [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
                            "aux2"=wdmaud.drv
                            .
                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                            Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
                            .
                            [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
                            "LWS"=c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
                            .
                            R2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-03-05 53888]
                            R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
                            R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-07 160944]
                            R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-03 250056]
                            R3 ALSysIO;ALSysIO;c:\users\Slayerz\AppData\Local\Temp\ALSysIO64.sys [x]
                            R3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;c:\windows\system32\drivers\Apowersoft_AudioDevice.sys [2010-12-24 29288]
                            R3 Bulk1628;SPCA1628 Still Camera Service;c:\windows\system32\Drivers\Bulk1628.sys [x]
                            R3 ca1628UVCav;ca1628UVCav Driver Service;c:\windows\system32\Drivers\ca1628UVCav.sys [x]
                            R3 driverhardwarev2x64;driverhardwarev2x64;c:\program files\ma-config.com\Drivers\driverhardwarev2x64.sys [2011-07-21 16640]
                            R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [2012-01-18 351136]
                            R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\x64\maconfservice.exe [2012-07-04 427672]
                            R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-18 113120]
                            R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2011-08-01 45416]
                            R3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.0);c:\windows\system32\DRIVERS\RtTeam60.sys [2010-12-14 58472]
                            R3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.2);c:\windows\system32\DRIVERS\RtVlan60.sys [2010-12-14 24064]
                            R3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.0);c:\windows\system32\DRIVERS\RtTeam60.sys [2010-12-14 58472]
                            R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
                            R3 VLAN;Realtek Virtual Miniport Driver for VLAN (NDIS 6.2);c:\windows\system32\DRIVERS\RtVLAN60.sys [2010-12-14 24064]
                            R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-09 1255736]
                            S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-02-18 283200]
                            S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
                            S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616]
                            S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-06-11 361984]
                            S2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-03-05 53888]
                            S2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\DRIVERS\RtNdPt60.sys [2010-12-14 27136]
                            S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
                            S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192]
                            S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616]
                            S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]
                            S3 bbcap;bb_capture_driver;c:\windows\system32\DRIVERS\bbcap.sys [2012-06-07 4608]
                            S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [2011-08-25 57088]
                            S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [2011-08-25 80384]
                            S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-09-29 646248]
                            .
                            .
                            --- Autres Services/Pilotes en mémoire ---
                            .
                            *NewlyCreated* - WS2IFSL
                            .
                            Contenu du dossier 'Tâches planifiées'
                            .
                            2012-08-12 c:\windows\Tasks\Adobe Flash Player Updater.job
                            - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 16:43]
                            .
                            .
                            --------- X64 Entries -----------
                            .
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-10-17 13307496]
                            "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
                            "Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2010-11-03 1580368]
                            "combofix"="c:\combofix\CF29533.3XE" [2010-11-20 345088]
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                            "LoadAppInit_DLLs"=0x0
                            .
                            ------- Examen supplémentaire -------
                            .
                            uLocal Page = c:\windows\System32\blank.htm
                            uStart Page = hxxp://www.google.com/
                            mLocal Page = c:\windows\System32\blank.htm
                            uSearchAssistant = hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=FR&userid=7be687c5-e150-4759-b6e9-1e5789eb2c32&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
                            TCP: DhcpNameServer = 192.168.1.254
                            FF - ProfilePath - c:\users\Slayerz\AppData\Roaming\Mozilla\Firefox\Profiles\4lpyt9g0.default\
                            FF - prefs.js: browser.startup.homepage - google
                            FF - user.js: extensions.incredibar_i.newTab - false
                            FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6PQvmh65hf&loc=IB_TB&i=26&search=
                            FF - user.js: extensions.incredibar_i.id - 96d3c1f100000000000050e54951b225
                            FF - user.js: extensions.incredibar_i.instlDay - 15454
                            FF - user.js: extensions.incredibar_i.vrsn - 1.5.11.14
                            FF - user.js: extensions.incredibar_i.vrsni - 1.5.11.14
                            FF - user.js: extensions.incredibar_i.vrsnTs - 1.5.11.1413:07
                            FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
                            FF - user.js: extensions.incredibar_i.prdct - incredibar
                            FF - user.js: extensions.incredibar_i.aflt - orgnl
                            FF - user.js: extensions.incredibar_i.smplGrp - none
                            FF - user.js: extensions.incredibar_i.tlbrId - base
                            FF - user.js: extensions.incredibar_i.instlRef -
                            FF - user.js: extensions.incredibar_i.dfltLng -
                            FF - user.js: extensions.incredibar_i.excTlbr - false
                            FF - user.js: extensions.incredibar_i.ms_url_id -
                            FF - user.js: extensions.incredibar_i.upn2 - 6PQvmh65hf
                            FF - user.js: extensions.incredibar_i.upn2n - 92542769836807201
                            FF - user.js: extensions.incredibar_i.productid - 26
                            FF - user.js: extensions.incredibar_i.installerproductid - 26
                            FF - user.js: extensions.incredibar_i.did - 10650
                            FF - user.js: extensions.incredibar_i.ppd - 42%5F4
                            .
                            - - - - ORPHELINS SUPPRIMES - - - -
                            .
                            Toolbar-{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - (no file)
                            WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
                            WebBrowser-{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E} - (no file)
                            AddRemove-PluginPac - c:\program files (x86)\Sonic Foundry\Vegas 3.0\Video Plug-Ins\PluginPac\uninst.exe
                            AddRemove-{259C0ABB-A3B2-4D70-008F-BF7EE491B70B} - f:\nfs carbon (x86)\EAUninstall.exe
                            .
                            .
                            .
                            --------------------- CLES DE REGISTRE BLOQUEES ---------------------
                            .
                            [HKEY_USERS\S-1-5-21-3996339946-498750113-113193782-1000\Software\SecuROM\License information*]
                            "datasecu"=hex:ef,ca,16,da,c2,1b,64,78,33,ac,61,89,21,dd,60,c6,57,bd,6e,95,1f,
                            59,f1,ac,92,ad,c0,c8,2f,35,9e,d4,f8,4d,c7,df,74,fc,a1,67,81,b2,b9,3c,4a,09,\
                            "rkeysecu"=hex:c8,93,fc,d5,be,96,86,c3,92,7f,d9,dd,47,99,26,62
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
                            @Denied: (A 2) (Everyone)
                            @="FlashBroker"
                            "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_270_ActiveX.exe,-101"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
                            "Enabled"=dword:00000001
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
                            @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_270_ActiveX.exe"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
                            @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
                            @Denied: (A 2) (Everyone)
                            @="Shockwave Flash Object"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
                            @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx"
                            "ThreadingModel"="Apartment"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
                            @="0"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
                            @="ShockwaveFlash.ShockwaveFlash.11"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                            @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx, 1"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
                            @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
                            @="1.0"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                            @="ShockwaveFlash.ShockwaveFlash"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
                            @Denied: (A 2) (Everyone)
                            @="Macromedia Flash Factory Object"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
                            @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx"
                            "ThreadingModel"="Apartment"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
                            @="FlashFactory.FlashFactory.1"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                            @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx, 1"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
                            @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
                            @="1.0"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                            @="FlashFactory.FlashFactory"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
                            @Denied: (A 2) (Everyone)
                            @="IFlashBroker4"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
                            @="{00020424-0000-0000-C000-000000000046}"
                            .
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
                            @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                            "Version"="1.0"
                            .
                            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
                            @Denied: (Full) (Everyone)
                            .
                            ------------------------ Autres processus actifs ------------------------
                            .
                            c:\windows\SysWOW64\PnkBstrA.exe
                            .
                            **************************************************************************
                            .
                            Heure de fin: 2012-08-12 22:52:36 - La machine a redémarré
                            ComboFix-quarantined-files.txt 2012-08-12 20:52
                            .
                            Avant-CF: 152 279 318 528 octets libres
                            Après-CF: 152 414 732 288 octets libres
                            .
                            - - End Of File - - B2CFA1E9AC89ECB74E5A2A714C34DD2D
                            0
                            • 1
                            • 2
                            • 3