- ven. 14 déc. 2012 20:59
#37131
ComboFix 12-12-14.01 - Sébastien 14/12/2012 20:44:28.1.4 - x64
Microsoft Windows 7 Professionnel 6.1.7601.1.1252.33.1036.18.8108.6218 [GMT 1:00]
Lancé depuis: c:\users\SÚbastien\Desktop\ComboFix.exe
AV: Protection antivirus et antispyware McAfee *Disabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
FW: Pare-feu McAfee *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}
SP: Protection antivirus et antispyware McAfee *Disabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2012-11-14 au 2012-12-14 ))))))))))))))))))))))))))))))))))))
.
.
2012-12-13 09:49 . 2012-12-13 09:49 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2012-12-13 08:51 . 2012-10-04 17:38 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-12-12 22:29 . 2012-12-12 22:29 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-12-12 22:29 . 2012-12-12 22:29 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-12-12 22:29 . 2012-12-12 22:29 -------- d-----w- c:\program files (x86)\Java
2012-12-12 21:25 . 2012-12-12 21:25 -------- d-----w- c:\program files\CPUID
2012-12-12 20:44 . 2012-12-12 20:44 -------- d-----w- c:\program files (x86)\FinalWire
2012-12-12 16:57 . 2012-12-13 23:29 -------- d-----w- C:\ZHP
2012-12-12 16:57 . 2012-12-13 23:29 -------- d-----w- c:\program files (x86)\ZHPDiag
2012-12-11 11:39 . 2012-12-11 11:39 -------- d-----w- c:\program files\Microsoft Sync Framework
2012-12-11 11:20 . 2012-12-11 11:20 -------- d-----w- c:\program files\Common Files\DESIGNER
2012-12-11 11:07 . 2003-04-18 18:06 8192 ----a-w- c:\windows\SysWow64\srvany.exe
2012-12-11 08:43 . 2012-12-11 08:43 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-12-11 08:43 . 2012-12-11 08:43 -------- d-----w- c:\program files\iTunes
2012-12-11 08:43 . 2012-12-11 08:43 -------- d-----w- c:\program files (x86)\iTunes
2012-12-11 08:43 . 2012-12-11 08:43 -------- d-----w- c:\program files\iPod
2012-12-10 21:17 . 2007-09-07 16:33 135168 ----a-w- c:\windows\SysWow64\EEBAPI.dll
2012-12-10 21:17 . 2007-03-28 17:26 65536 ----a-w- c:\windows\SysWow64\EEBUtil.dll
2012-12-10 20:58 . 2012-12-10 20:58 -------- d-----w- c:\program files (x86)\EpsonNet
2012-12-10 20:57 . 2007-06-21 23:10 501912 ----a-w- c:\windows\SysWow64\PICSDK2.dll
2012-12-10 20:57 . 2006-10-30 23:10 71840 ----a-w- c:\windows\SysWow64\EPPicMgr.dll
2012-12-10 20:57 . 2006-10-30 23:10 120992 ----a-w- c:\windows\SysWow64\EpPicPrt.dll
2012-12-10 20:57 . 2006-10-19 23:10 80024 ----a-w- c:\windows\SysWow64\PICSDK.dll
2012-12-10 20:57 . 2006-10-19 23:10 108704 ----a-w- c:\windows\SysWow64\PICEntry.dll
2012-12-10 20:56 . 2009-04-30 23:00 17408 ----a-w- c:\windows\system32\esxcdev.dll
2012-12-10 20:56 . 2009-04-30 23:00 128392 ----a-w- c:\windows\system32\esdevapp.exe
2012-12-10 20:56 . 2008-11-16 23:00 459776 ----a-w- c:\windows\system32\esxwiaud.dll
2012-12-09 23:39 . 2012-12-09 23:39 9888912 ----a-w- c:\windows\SysWow64\RtsPStorIcon.dll
2012-12-09 23:39 . 2012-12-09 23:39 340112 ----a-w- c:\windows\system32\drivers\RtsPStor.sys
2012-12-03 15:56 . 2012-12-12 22:29 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-12-03 14:54 . 2009-08-19 22:50 24416 ----a-r- c:\windows\system32\AdobePDFUI.dll
2012-12-03 14:52 . 2012-12-03 19:45 -------- d-----w- C:\_AcroTemp
2012-11-30 10:33 . 2012-06-01 07:36 756319 ----a-w- c:\windows\Five Guiding Principles.scr
2012-11-30 10:33 . 2012-11-30 10:33 -------- d-----w- c:\windows\Five Guiding Principles Uninstaller
2012-11-19 11:54 . 2012-08-21 21:01 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2012-11-19 11:16 . 2012-11-19 11:16 -------- d-----w- c:\program files (x86)\Common Files\Intel Corporation
2012-11-19 11:16 . 2012-11-19 11:16 -------- d-----w- c:\program files (x86)\Intel Corporation
2012-11-19 08:37 . 2012-11-19 08:37 -------- d-----w- c:\windows\system32\SPReview
2012-11-19 08:37 . 2012-11-19 08:37 -------- d-----w- c:\windows\system32\EventProviders
2012-11-18 19:36 . 2010-11-20 13:27 444416 ----a-w- c:\windows\system32\winhttp.dll
2012-11-18 19:35 . 2010-11-20 13:44 133632 ----a-w- c:\windows\system32\NAPHLPR.DLL
2012-11-18 19:34 . 2010-11-20 13:26 399872 ----a-w- c:\windows\system32\dpx.dll
2012-11-18 19:34 . 2010-11-20 12:21 189952 ----a-w- c:\windows\SysWow64\wdscore.dll
2012-11-18 19:34 . 2010-11-20 12:21 189952 ----a-w- c:\windows\SysWow64\sqmapi.dll
2012-11-18 19:34 . 2010-11-20 12:21 363008 ----a-w- c:\windows\SysWow64\wbemcomn.dll
2012-11-18 19:34 . 2010-11-20 12:21 189952 ----a-w- c:\program files (x86)\Windows Portable Devices\sqmapi.dll
2012-11-18 19:34 . 2010-11-20 12:19 606208 ----a-w- c:\windows\SysWow64\wbem\fastprox.dll
2012-11-18 19:33 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2012-11-18 19:33 . 2010-11-20 13:27 244736 ----a-w- c:\program files\Windows Portable Devices\sqmapi.dll
2012-11-18 19:33 . 2010-11-20 13:27 244736 ----a-w- c:\windows\system32\sqmapi.dll
2012-11-17 22:39 . 2012-11-17 22:39 -------- d-----w- c:\program files (x86)\VideoLAN
2012-11-17 19:38 . 2012-08-21 12:01 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-11-17 19:24 . 2012-11-17 19:38 -------- dc----w- c:\windows\system32\DRVSTORE
2012-11-17 19:24 . 2012-08-21 12:01 125872 ----a-w- c:\windows\system32\GEARAspi64.dll
2012-11-17 19:24 . 2012-08-21 12:01 106928 ----a-w- c:\windows\SysWow64\GEARAspi.dll
2012-11-17 19:24 . 2012-11-17 19:37 -------- d-----w- c:\programdata\Apple Computer
2012-11-17 19:24 . 2012-11-17 19:24 -------- d-----w- c:\programdata\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2012-11-17 19:24 . 2012-11-17 19:24 -------- d-----w- c:\program files (x86)\Apple Software Update
2012-11-17 19:23 . 2012-11-17 19:41 -------- d-----w- c:\program files\Common Files\Apple
2012-11-17 19:23 . 2012-11-19 11:46 -------- d-----w- c:\program files\Bonjour
2012-11-17 19:23 . 2012-11-17 19:23 -------- d-----w- c:\program files (x86)\Bonjour
2012-11-17 19:23 . 2012-12-11 08:43 -------- d-----w- c:\program files (x86)\Common Files\Apple
2012-11-17 19:23 . 2012-11-17 19:23 -------- d-----w- c:\programdata\Apple
2012-11-17 18:48 . 2012-11-17 19:20 -------- d-----w- c:\programdata\WindSolutions
2012-11-17 13:58 . 2011-03-25 03:29 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2012-11-17 13:58 . 2011-03-25 03:29 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2012-11-17 13:58 . 2011-03-25 03:29 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2012-11-17 13:58 . 2011-03-25 03:29 98816 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-11-17 13:58 . 2011-03-25 03:29 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2012-11-17 13:58 . 2011-03-25 03:29 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2012-11-17 13:58 . 2011-03-25 03:28 7936 ----a-w- c:\windows\system32\drivers\usbd.sys
2012-11-17 13:58 . 2012-07-06 20:07 552960 ----a-w- c:\windows\system32\drivers\bthport.sys
2012-11-17 13:58 . 2011-04-28 03:54 80384 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2012-11-17 13:58 . 2010-11-20 13:24 229376 ----a-w- c:\windows\system32\fsquirt.exe
2012-11-17 13:57 . 2011-03-11 06:33 2565632 ----a-w- c:\windows\system32\esent.dll
2012-11-17 13:57 . 2011-03-11 05:33 1699328 ----a-w- c:\windows\SysWow64\esent.dll
2012-11-17 13:57 . 2011-03-11 06:41 166272 ----a-w- c:\windows\system32\drivers\nvstor.sys
2012-11-17 13:57 . 2011-03-11 06:41 189824 ----a-w- c:\windows\system32\drivers\storport.sys
2012-11-17 13:57 . 2011-03-11 06:41 148352 ----a-w- c:\windows\system32\drivers\nvraid.sys
2012-11-17 13:57 . 2011-03-11 06:41 107904 ----a-w- c:\windows\system32\drivers\amdsata.sys
2012-11-17 13:57 . 2011-03-11 06:41 410496 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2012-11-17 13:57 . 2011-03-11 06:41 27008 ----a-w- c:\windows\system32\drivers\amdxata.sys
2012-11-17 13:57 . 2011-03-11 06:30 96768 ----a-w- c:\windows\system32\fsutil.exe
2012-11-17 13:57 . 2011-03-11 04:37 91648 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS
2012-11-17 13:57 . 2011-03-11 05:31 74240 ----a-w- c:\windows\SysWow64\fsutil.exe
2012-11-17 13:42 . 2012-11-17 13:42 -------- d-----w- c:\program files (x86)\XnView
2012-11-17 13:36 . 2012-12-10 21:05 -------- d-----w- c:\program files (x86)\epson
2012-11-17 13:35 . 2008-11-12 02:00 118784 ----a-w- c:\windows\system32\E_ILMFIE.DLL
2012-11-17 13:35 . 2008-11-12 02:00 81920 ----a-w- c:\windows\system32\E_IBCBFIE.DLL
2012-11-17 13:35 . 2007-04-10 00:06 10752 ----a-w- c:\windows\system32\E_GCINST.DLL
2012-11-17 13:35 . 2012-12-10 20:56 -------- d-----w- c:\programdata\EPSON
2012-11-16 16:19 . 2012-11-16 16:19 -------- d-----w- c:\programdata\Malwarebytes
2012-11-16 16:19 . 2012-11-19 11:47 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-11-16 16:19 . 2012-09-29 18:54 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-16 15:46 . 2012-11-16 15:46 -------- d-----w- c:\windows\SysWow64\Wat
2012-11-16 15:46 . 2012-11-16 15:46 -------- d-----w- c:\windows\system32\Wat
2012-11-16 15:46 . 2011-02-19 12:05 1139200 ----a-w- c:\windows\system32\FntCache.dll
2012-11-16 15:46 . 2011-02-19 12:04 902656 ----a-w- c:\windows\system32\d2d1.dll
2012-11-16 15:46 . 2011-02-19 06:30 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2012-11-16 15:42 . 2012-11-16 15:42 -------- d-----w- c:\program files\Realtek
2012-11-16 15:42 . 2012-12-09 23:58 -------- d-----w- c:\windows\SysWow64\RTCOM
2012-11-16 15:39 . 2009-07-14 01:41 101376 ----a-w- c:\windows\system32\Spool\prtprocs\x64\HPZPPWN7.DLL
2012-11-16 15:14 . 2012-11-16 15:14 331264 ----a-w- c:\windows\system32\drivers\IntcDAud.sys
2012-11-16 15:14 . 2012-11-16 15:14 14848 ----a-w- c:\windows\system32\IntcDAuC.dll
2012-11-16 15:14 . 2012-11-16 15:14 29184 ----a-w- c:\windows\system32\drivers\stm_tpm.sys
2012-11-16 15:14 . 2012-11-16 15:14 114742 ----a-w- c:\windows\system32\tpmddl.dll
2012-11-16 15:13 . 2012-11-16 15:13 43832 ----a-w- c:\windows\system32\drivers\Smb_driver_Intel.sys
2012-11-16 15:13 . 2012-11-16 15:13 74344 ----a-w- c:\windows\system32\RtNicProp64.dll
2012-11-16 15:13 . 2012-11-16 15:13 726160 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2012-11-16 15:12 . 2012-11-16 15:12 11499008 ----a-w- c:\windows\system32\drivers\Netwsw00.sys
2012-11-16 15:12 . 2012-11-16 15:12 885520 ----a-w- c:\windows\system32\Netwcw00.dll
2012-11-16 15:12 . 2012-11-16 15:12 3381008 ----a-w- c:\windows\system32\Netwrw00.dll
2012-11-16 15:12 . 2012-11-16 15:12 19264 ----a-w- c:\windows\system32\drivers\iusb3hcs.sys
2012-11-16 15:12 . 2012-11-16 15:12 647736 ----a-w- c:\windows\system32\drivers\iaStorA.sys
2012-11-16 15:12 . 2012-11-16 15:12 18832 ----a-w- c:\windows\system32\drivers\pmkbdfltr.sys
2012-11-16 14:41 . 2012-11-16 14:41 -------- d-----w- c:\windows\SysWow64\wbem\en-US
2012-11-16 14:41 . 2012-11-16 14:41 -------- d-----w- c:\windows\system32\wbem\en-US
2012-11-16 14:01 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-11-16 14:01 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-11-16 14:01 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2012-11-16 13:53 . 2012-11-16 13:53 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2012-11-16 13:44 . 2012-12-13 10:59 67413224 ----a-w- c:\windows\system32\MRT.exe
2012-11-16 13:44 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-11-16 13:44 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-11-16 13:44 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-10 13:54 . 2012-11-16 08:56 60304 ----a-w- c:\users\Sébastien\g2mdlhlpx.exe
2012-12-10 13:54 . 2012-11-16 08:56 60304 ----a-w- c:\users\Sébastien\g2mdlhlpx.exe
2012-11-19 08:41 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-11-19 08:41 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-11-15 23:28 . 2010-06-24 10:33 19696 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-11-15 22:58 . 2012-11-15 22:58 2560 ----a-w- c:\windows\SysWow64\drivers\fr-FR\qwavedrv.sys.mui
2012-11-15 22:58 . 2012-11-15 22:58 29696 ----a-w- c:\windows\SysWow64\drivers\fr-FR\bfe.dll.mui
2012-11-15 22:58 . 2012-11-15 22:58 15872 ----a-w- c:\windows\SysWow64\drivers\fr-FR\pacer.sys.mui
2012-11-15 22:58 . 2012-11-15 22:58 6144 ----a-w- c:\windows\SysWow64\drivers\fr-FR\ndiscap.sys.mui
2012-11-15 22:58 . 2012-11-15 22:58 2560 ----a-w- c:\windows\SysWow64\drivers\fr-FR\scfilter.sys.mui
2012-11-15 22:58 . 2012-11-15 22:58 49152 ----a-w- c:\windows\SysWow64\drivers\fr-FR\tcpip.sys.mui
2012-10-31 14:10 . 2012-10-31 14:10 829264 ----a-w- c:\windows\system32\msvcr100.dll
2012-10-31 14:10 . 2012-10-31 14:10 773968 ----a-w- c:\windows\SysWow64\msvcr100.dll
2012-10-31 14:10 . 2012-10-31 14:10 421200 ----a-w- c:\windows\SysWow64\msvcp100.dll
2012-10-31 14:10 . 2012-10-31 14:10 158536 ----a-w- c:\windows\system32\atl100.dll
2012-10-31 14:10 . 2012-10-31 14:10 138056 ----a-w- c:\windows\SysWow64\atl100.dll
2012-10-16 08:38 . 2012-11-28 11:51 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38 . 2012-11-28 11:51 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39 . 2012-11-28 11:51 561664 ----a-w- c:\windows\apppatch\AcLayers.dll
2012-10-04 16:40 . 2012-12-13 08:52 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-11-15 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-09-12 1535112]
"ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2010-11-17 673168]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2012-07-31 41944]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2012-07-30 640480]
"VAIO Boot Manager"="c:\program files (x86)\Sony\VAIO Boot Manager\StartUpProcessDelayTool.exe" [2010-12-08 734608]
"Powersuite Monitor"="c:\program files (x86)\Uniblue\Powersuite\powersuite_monitor.exe" [2012-09-13 323936]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"EEventManager"="c:\progra~2\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-04-07 673616]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-11-28 151952]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]
.
c:\users\Sébastien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
BUFFALO NAS Navigator2.lnk - c:\program files (x86)\BUFFALO\NASNAVI\NasNavi.exe [2012-9-24 1925211]
NAS Scheduler.lnk - c:\program files (x86)\BUFFALO\NASNAVI\nassche.exe [2009-5-15 206128]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-7-29 1132320]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-05 13336]
R2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-12-07 2429544]
R2 KMService;KMService;c:\windows\system32\srvany.exe [x]
R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2012-08-31 201304]
R2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe [2011-01-29 259192]
R2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-05 2656280]
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2010-11-03 344616]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-11-03 39464]
R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys [2009-06-10 281088]
R3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys [2012-04-20 196440]
R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2010-08-30 220528]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-07-17 106112]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-11-02 340240]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 Partner Service;Partner Service;c:\programdata\Partner\Partner.exe [2012-11-15 332272]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [2012-12-09 340112]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736]
R3 VCService;VCService;c:\program files\Sony\VAIO Care\VCService.exe [2011-02-14 44736]
R3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update Common\VUAgent.exe [2012-01-13 1256040]
R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2012-11-16 1255736]
R3 WSDScan;Prise en charge de la numérisation WSD via UMB;c:\windows\system32\DRIVERS\WSDScan.sys [2009-07-14 25088]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys [2012-11-16 647736]
S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys [2012-11-16 28216]
S0 iusb3hcs;Pilote de commutateur de contrôleur d'hôte Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys [2012-11-16 19264]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-07-17 335784]
S0 stmtpm;STM TPM Service;c:\windows\system32\DRIVERS\stm_tpm.sys [2012-11-16 29184]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-12-21 204288]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-29 399432]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-29 676936]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-08-31 201304]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-08-31 201304]
S2 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2012-08-31 201304]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-07-17 218320]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-07-17 177144]
S2 NasPmService;NAS PM Service;c:\program files (x86)\BUFFALO\NASNAVI\nassvc.exe [2012-03-29 251760]
S2 QDLService2kSony;Qualcomm Gobi 2000 Download Service (Sony);c:\program files (x86)\QUALCOMM\QDLService2k\QDLService2kSony.exe [2010-10-21 332096]
S2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
S2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [2010-12-06 584080]
S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe [2010-12-09 923024]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-07-17 69672]
S3 IntcDAud;Son Intel(R) pour écrans;c:\windows\system32\DRIVERS\IntcDAud.sys [2012-11-16 331264]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [2012-05-25 12312832]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-29 25928]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-07-17 513456]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-11-01 80384]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-11-01 180736]
S3 pmkbdfltr;PenMount Keyboard Device Filter Driver;c:\windows\system32\DRIVERS\pmkbdfltr.sys [2012-11-16 18832]
S3 qcfiltersny2k;Qualcomm Gobi 2000 USB Composite Device Filter 9225;c:\windows\system32\DRIVERS\qcfiltersny2k.sys [2010-10-21 6400]
S3 qcombussny;Gobi 2000 USB Composite Device Driver(05C6-9225);c:\windows\system32\DRIVERS\qcombussny.sys [2010-10-21 137800]
S3 qcusbnetsny2k;Gobi 2000 USB-NDIS miniport(05C6-9225);c:\windows\system32\DRIVERS\qcusbnetsny2k.sys [2010-10-21 443392]
S3 qcusbserSny2k;Gobi 2000 USB Device for Legacy Serial Communication(05C6-9225);c:\windows\system32\DRIVERS\qcusbserSny2k.sys [2010-10-21 230784]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-11-16 726160]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys [2010-04-26 12032]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys [2012-11-16 43832]
S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [2010-12-01 42392]
.
.
--- Autres Services/Pilotes en mémoire ---
.
*NewlyCreated* - WS2IFSL
*Deregistered* - mfeavfk01
.
Contenu du dossier 'Tâches planifiées'
.
2012-12-13 c:\windows\Tasks\Epson Printer Software Downloader.job
- c:\program files (x86)\EPSON\EPAPDL\E_SAPDL2.EXE [2009-05-26 10:43]
.
2012-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-15 23:18]
.
2012-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-15 23:18]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-05-25 167744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-05-25 417088]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-11-16 12503184]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2012-11-16 1833576]
.
------- Examen supplémentaire -------
.
uStart Page = aboutblank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride =
IE: Ajouter la cible du lien à un fichier PDF existant - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Ajouter à un fichier PDF existant - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir au format Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien au format Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Exporter vers Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
IE: Turbo Internet: Bookmark this page
IE: Turbo Internet: Download this link
TCP: DhcpNameServer = 192.168.0.254
.
- - - - ORPHELINS SUPPRIMES - - - -
.
Wow6432Node-HKLM-Run- - (no file)
SafeBoot-58715776.sys
HKLM-Run-Apoint - c:\program files (x86)\Apoint\Apoint.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SampleCollector]
"ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=5000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=c:\programdata\Sony Corporation\VAIO Care\inteldata\""
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing\WinZip]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Autres processus actifs ------------------------
.
c:\program files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\SysWOW64\rundll32.exe
c:\program files (x86)\Sony\VAIO Event Service\VESMgr.exe
c:\program files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
c:\program files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
c:\windows\SysWOW64\DllHost.exe
c:\windows\SysWOW64\DllHost.exe
.
**************************************************************************
.
Heure de fin: 2012-12-14 20:50:08 - La machine a redémarré
ComboFix-quarantined-files.txt 2012-12-14 19:50
.
Avant-CF: 37 398 642 688 octets libres
Après-CF: 37 224 214 528 octets libres
.
- - End Of File - - DDF5C3BA316F28FD49FB7492A5CE503A