>>la protection en temps réel de ton Antivirus et de tes Antispywares,
>>qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.
avira = rien à faire pour désactiver
¤¤¤¤¤¤¤¤¤¤ LAISSE-LE INSTALLER LA CONSOLE DE RECUPERATION S'IL TE LE DEMANDE ¤¤¤¤¤¤¤¤¤¤
rien demandé !!!
mais plus aucun accés au web avec n'importe quel navigateur
j'ai redémarré le pc et plusieurs tentatives avec firefox ...
apparement ça y est ;)
le rapport:
ComboFix 12-06-14.01 - bg 14/06/2012 20:46:09.2.2 - x86
Microsoft® Windows Vista(TM) Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.3066.1792 [GMT 2:00]
Lancé depuis: c:\users\bg\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Mozilla Maintenance Service
c:\program files\Mozilla Maintenance Service\maintenanceservice.exe
c:\program files\Mozilla Maintenance Service\Uninstall.exe
c:\program files\YooBooton\tbHElper.dll
c:\programdata\00DB1C16CF.sys
c:\programdata\3D3
c:\programdata\3D3\Frames\FBRU_AA-1.frame
c:\programdata\3D3\Frames\FBRU_AA-2.frame
c:\programdata\3D3\Frames\FBRU_AB-1.frame
c:\programdata\3D3\Frames\FBRU_AB-2.frame
c:\programdata\3D3\Frames\FBRU_AB-3.frame
c:\programdata\3D3\Frames\FBRU_AB-4.frame
c:\programdata\3D3\Frames\FBRU_AC-1.frame
c:\programdata\3D3\Frames\FBRU_AC-2.frame
c:\programdata\3D3\Frames\FBRU_AD-1.frame
c:\programdata\3D3\Frames\FBRU_AD-2.frame
c:\programdata\3D3\Frames\FCHI_AA1.frame
c:\programdata\3D3\Frames\FCIR_AA-1.frame
c:\programdata\3D3\Frames\FCIR_AA-2.frame
c:\programdata\3D3\Frames\FOVL_AA1.frame
c:\programdata\3D3\Frames\FOVL_AA2.frame
c:\programdata\3D3\Frames\FOVL_BB1.frame
c:\programdata\3D3\Frames\FPFR_WW1.frame
c:\programdata\3D3\Frames\FPHO_BB-1.frame
c:\programdata\3D3\Frames\FSEA_AA-1.frame
c:\programdata\3D3\Frames\FSLD_AA-1.frame
c:\programdata\3D3\Frames\FSLD_BB-1.frame
c:\programdata\3D3\Frames\FSTR_AA-1.frame
c:\programdata\3D3\Frames\FSTR_AA-2.frame
c:\programdata\3D3\mm.db
c:\programdata\F1236EEA56.sys
c:\users\bg\AppData\Roaming\1&1
c:\users\bg\AppData\Roaming\1&1\1&1 EasyLogin\EasyLogin.log
c:\users\bg\AppData\Roaming\FFSJ
c:\users\bg\AppData\Roaming\FFSJ\FFSJ.cfg
c:\windows\system32\hjgruivrpuxxbp.dat
c:\windows\system32\SET79A.tmp
c:\windows\system32\Temp
c:\windows\XSxS
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_hjgruiixymomfp
-------\Service_hjgruiixymomfp
-------\Service_MozillaMaintenance
-------\Service_MozillaMaintenance
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2012-05-14 au 2012-06-14 ))))))))))))))))))))))))))))))))))))
.
.
2012-06-14 19:10 . 2012-06-14 19:13 -------- d-----w- c:\users\bg\AppData\Local\temp
2012-06-14 19:10 . 2012-06-14 19:10 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-14 17:52 . 2012-06-14 17:52 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2012-06-14 13:40 . 2012-06-14 17:52 -------- d-----w- C:\ZHP
2012-06-14 13:40 . 2012-06-14 17:52 -------- d-----w- c:\program files\ZHPDiag
2012-06-13 19:50 . 2012-06-13 19:51 -------- d-----w- c:\users\bg\AppData\Roaming\pdfforge
2012-06-13 19:50 . 1998-06-23 23:00 137000 ----a-w- c:\windows\system32\MSMAPI32.OCX
2012-06-13 19:50 . 2012-05-14 07:17 79360 ----a-w- c:\windows\system32\pdfcmon.dll
2012-06-13 19:50 . 2012-06-13 19:51 -------- d-----w- c:\program files\PDFCreator
2012-06-13 19:50 . 1998-07-05 23:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2012-06-13 19:50 . 2012-06-13 19:50 -------- d-----w- c:\users\bg\AppData\Local\CRE
2012-06-13 19:50 . 2012-06-13 19:50 -------- d-----w- c:\program files\Conduit
2012-06-13 19:50 . 2012-06-13 19:54 -------- d-----w- c:\users\bg\AppData\Local\Conduit
2012-06-13 19:48 . 2012-06-13 19:58 -------- d-----w- c:\programdata\SweetIM
2012-06-13 19:48 . 2012-06-13 19:58 -------- d-----w- c:\program files\SweetIM
2012-06-13 19:48 . 2012-06-13 19:48 -------- d-----w- c:\programdata\Premium
2012-06-13 19:48 . 2012-06-13 19:48 -------- d-----w- c:\programdata\InstallMate
2012-06-13 13:36 . 2012-06-13 13:36 -------- d-----w- c:\users\bg\AppData\Roaming\Pencil
2012-06-13 13:36 . 2012-06-13 13:36 -------- d-----w- c:\users\bg\AppData\Local\Pencil
2012-06-13 07:37 . 2012-04-23 16:00 984064 ----a-w- c:\windows\system32\crypt32.dll
2012-06-13 07:37 . 2012-04-23 16:00 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-06-13 07:37 . 2012-04-23 16:00 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-06-13 07:36 . 2012-05-01 14:03 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-13 07:35 . 2012-05-15 19:51 2045440 ----a-w- c:\windows\system32\win32k.sys
2012-06-12 13:57 . 2012-06-12 13:57 -------- d-----w- c:\users\bg\AppData\Local\Macromedia
2012-06-11 16:00 . 2012-06-11 16:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-06-11 16:00 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-11 15:50 . 2012-06-11 15:50 -------- d-----w- c:\programdata\Kaspersky Lab
2012-06-11 15:50 . 2012-06-11 15:50 -------- d-----w- c:\program files\Kaspersky Lab
2012-06-11 15:48 . 2012-06-11 15:48 -------- d-----w- c:\program files\1&1
2012-06-08 12:46 . 2012-06-09 05:48 -------- d-----w- c:\program files\WinMerge
2012-06-06 14:36 . 2012-06-13 19:20 772592 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-06-06 14:16 . 2012-06-06 14:16 -------- d-----w- c:\program files\MySQL
2012-06-06 13:47 . 2012-06-06 13:47 -------- d-----w- c:\users\bg\paros
2012-06-05 18:08 . 2012-06-05 18:37 -------- d-----w- C:\tunisie
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-13 19:41 . 2012-03-30 12:20 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-13 19:41 . 2011-05-15 07:17 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-13 19:20 . 2010-04-26 10:38 687600 ----a-w- c:\windows\system32\deployJava1.dll
2012-05-08 16:40 . 2012-06-13 07:39 6737808 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5F00CE54-AF2D-4D2F-A86F-C31AE26E490F}\mpengine.dll
2012-04-03 08:16 . 2012-05-09 09:11 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-03 08:16 . 2012-05-09 09:11 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-30 12:39 . 2012-05-09 09:13 905600 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-03-20 23:28 . 2012-05-09 09:13 53120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2003-03-21 11:45 . 2009-07-08 12:11 250544 ----a-w- c:\program files\Common Files\keyhelp.ocx
2012-05-08 10:13 . 2011-05-24 16:32 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2006-05-03 09:06 163328 --sh--r- c:\windows\System32\flvDX.dll
2007-02-21 10:47 31232 --sh--r- c:\windows\System32\msfDX.dll
2008-03-16 12:30 216064 --sh--r- c:\windows\System32\nbDX.dll
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2012-06-04 14:12 1310040 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2012-06-04 1310040]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-10-31 21:02 94208 ----a-w- c:\users\bg\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-10-31 21:02 94208 ----a-w- c:\users\bg\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-10-31 21:02 94208 ----a-w- c:\users\bg\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-10-31 21:02 94208 ----a-w- c:\users\bg\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-08-04 14:45 40496 ----a-w- c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Sidebar"="c:\program files\windows sidebar\sidebar.exe" [2009-04-11 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-28 39408]
"SEO Soft"="c:\divers\SeoSoft\seosoft.exe" [2012-04-07 9688064]
"KSS"="c:\program files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe" [2012-04-25 202296]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-06-13 888720]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-24 6265376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-10 13605408]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2011-07-31 126976]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-02-15 258512]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2012-05-29 115032]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^StartUp^ProjectWhois.lnk]
backup=c:\windows\pss\ProjectWhois.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 06:58 611712 ----a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\crlregistrationf]
2003-02-18 13:16 327680 ----a-w- c:\program files\Adobe\Adobe Photoshop CS4\Plug-ins\KPT Collection\Register\Registration.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Quick Search Box]
2011-07-31 13:24 126976 ----a-w- c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-09-27 18:13 133104 ----atw- c:\users\bg\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LxrAutorun]
2006-11-09 08:00 24576 ----a-w- c:\users\bg\AppData\Local\Lexar Media\LxrAutorun.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-11-10 00:54 4240760 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2009-02-10 12:38 92704 ----a-w- c:\windows\System32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 10:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SEO Soft]
2012-04-07 16:12 9688064 ----a-w- c:\divers\SeoSoft\seosoft.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-17 09:07 252296 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
2010-07-04 19:51 17408 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-21 02:25 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\users\bg\AppData\Local\Google\Update\GoogleUpdate.exe" /c
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1064041974-2318268328-94334938-1000]
"EnableNotificationsRef"=dword:00000001
.
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Akamai REG_MULTI_SZ Akamai
.
Contenu du dossier 'Tâches planifiées'
.
2009-06-04 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-05-08 09:39]
.
2012-06-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 15:44]
.
2012-06-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 15:44]
.
2012-03-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1064041974-2318268328-94334938-1000Core1cd0a9ababe758d.job
- c:\users\bg\AppData\Local\Google\Update\GoogleUpdate.exe [2009-09-27 18:13]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://home.sweetim.com/?barid={D06FCABA-B590-11E1-B396-0015AFFC49D0}
mStart Page = hxxp://home.sweetim.com/?barid={D06FCABA-B590-11E1-B396-0015AFFC49D0}
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\bg\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\bg\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\bg\AppData\Roaming\Mozilla\Firefox\Profiles\mrkwrbzv.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
.
- - - - ORPHELINS SUPPRIMES - - - -
.
URLSearchHooks-{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
AddRemove-Mozilla Thunderbird (2.0.0.23) - f:\portablethunderbird\App\thunderbird\uninstall\helper.exe
AddRemove-MozillaMaintenanceService - c:\program files\Mozilla Maintenance Service\uninstall.exe
AddRemove-_{ADDBE07D-95B8-4789-9C76-187FFF9624B4} - c:\program files\Corel\CorelDRAW Essential Edition 3\Programs\MSILauncher {ADDBE07D-95B8-4789-9C76-187FFF9624B4}
.
.
.
**************************************************************************
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés:
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Akamai]
"ServiceDll"="C:/Program Files/Common Files/Akamai/rswin_3647.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Akamai]
"ServiceDll"="C:/Program Files/Common Files/Akamai/rswin_3647.dll"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_USERS\S-1-5-21-1064041974-2318268328-94334938-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{BAEF7A3B-A9CA-C0F2-BAC1-CDBD6BD52671}*]
"haffdklhinfbfkbl"=hex:6b,61,70,6c,65,69,70,69,66,6d,6d,6e,68,6d,6a,63,70,67,
65,62,69,6d,00,00
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:e0,23,7c,b3,03,cc,34,24,7b,d4,a3,ef,f2,a8,6f,6c,2c,db,ec,b6,12,
c2,9f,69,cb,e7,2c,f0,96,5b,60,e4,a8,3a,f0,5b,9c,a7,8d,a7,8c,d2,4a,15,48,8e,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\InprocServer32]
@DACL=(02 0000)
@="c:\\Program Files\\pdfforge Toolbar\\SearchSettings.dll"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:e0,23,7c,b3,03,cc,34,24,7b,d4,a3,ef,f2,a8,6f,6c,2c,db,ec,b6,12,
c2,9f,69,cb,e7,2c,f0,96,5b,60,e4,a8,3a,f0,5b,9c,a7,8d,a7,8c,d2,4a,15,48,8e,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'Explorer.exe'(5704)
c:\program files\SweetIM\Messenger\mgAdaptersProxy.dll
c:\users\bg\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
c:\users\bg\AppData\Roaming\Dropbox\bin\MSVCP71.dll
c:\program files\EgisTec\MyWinLocker 3\x86\psdprotect.dll
c:\program files\EgisTec\MyWinLocker 3\x86\sysenv.dll
c:\program files\EgisTec\MyWinLocker 3\x86\mwlUI.dll
c:\program files\EgisTec\MyWinLocker 3\x86\GDIExtendCtrl.dll
c:\program files\EgisTec\MyWinLocker 3\x86\mwlOP.dll
c:\program files\EgisTec\MyWinLocker 3\x86\CryptoAPI.dll
c:\program files\EgisTec\MyWinLocker 3\x86\ShowErrMsg.dll
c:\thumbsplus\cswshlex.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\program files\EgisTec\VITAKEY\CompPtcVUI.exe
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\ASTSRV.EXE
c:\windows\system32\LxrSII1s.exe
c:\program files\McAfee\SiteAdvisor\McSACore.exe
c:\program files\EgisTec\MyWinLocker 3\x86\MWLService.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\PSIService.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Photodex\ProShowGold\ScsiAccess.exe
c:\program files\TeamViewer\Version6\TeamViewer_Service.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\WUDFHost.exe
c:\progra~1\COMMON~1\X10\Common\x10nets.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Windows Media Player\wmplayer.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\ehome\ehsched.exe
c:\windows\ehome\ehRecvr.exe
c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
.
**************************************************************************
.
Heure de fin: 2012-06-14 21:22:40 - La machine a redémarré
ComboFix-quarantined-files.txt 2012-06-14 19:22
.
Avant-CF: 104 192 176 128 octets libres
Après-CF: 104 166 076 416 octets libres
.
- - End Of File - - A02E0DC81E079CA6ECB1ED5EB3A9A1E0