ComboFix 13-02-02.05 - Calimero 03/02/2013 4:31.1.8 - x64 NETWORK
Microsoft Windows 7 Édition Familiale Premium 6.1.7601.1.1252.32.1036.18.6068.5052 [GMT 1:00]
Lancé depuis: c:\users\Calimero\Desktop\ComboFix.exe
AV: BitDefender Antivirus *Enabled/Updated* {982ADE23-275B-0766-37C5-DE01A484098E}
FW: BitDefender Firewall *Enabled* {A0115F06-6D34-063E-1C9A-77345A574EF5}
SP: BitDefender Antispyware *Enabled/Updated* {234B3FC7-0161-08E8-0D75-E573DF034333}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Un nouveau point de restauration a été créé
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\esupport\eDriver\Software\ASUS\MultiFrame\XP32_Vista32_Vista64_Win7_32_Win7_64_1.0.0021\Desktop_.ini
c:\programdata\FullRemove.exe
c:\programdata\Roaming
c:\users\Calimero\AppData\Local\assembly\tmp
c:\users\Calimero\AppData\Local\uninst.tmp
c:\windows\msxml4-KB2758694-enu.LOG
c:\windows\SysWow64\tmp3C98.tmp
c:\windows\SysWow64\tmp3CE7.tmp
c:\windows\SysWow64\tmp539B.tmp
c:\windows\SysWow64\tmp53AC.tmp
c:\windows\SysWow64\tmpAF42.tmp
c:\windows\SysWow64\tmpAF43.tmp
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2013-01-03 au 2013-02-03 ))))))))))))))))))))))))))))))))))))
.
.
2013-02-03 00:02 . 2013-02-03 00:02 -------- d-----w- c:\program files (x86)\ESET
2013-02-02 23:22 . 2013-02-02 23:22 -------- d-----w- c:\users\Calimero\AppData\Roaming\Malwarebytes
2013-02-02 23:22 . 2013-02-02 23:22 -------- d-----w- c:\programdata\Malwarebytes
2013-02-02 23:22 . 2012-12-14 15:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-02-02 23:22 . 2013-02-02 23:22 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-02-02 22:12 . 2013-02-02 23:32 -------- d-----w- c:\users\Calimero\AppData\Roaming\Puaquh
2013-02-02 22:12 . 2013-02-02 22:14 -------- d-----w- c:\users\Calimero\AppData\Roaming\Odtoy
2013-02-02 22:12 . 2013-02-02 22:13 -------- d-----w- c:\users\Calimero\AppData\Roaming\tor
2013-02-01 21:06 . 2013-02-01 21:06 -------- d-----w- c:\users\Calimero\AppData\Local\GameMaker8.1
2013-02-01 21:06 . 2013-02-01 21:06 -------- d-----w- c:\users\Calimero\AppData\Local\YoYo_Games_Ltd
2013-02-01 21:05 . 2013-02-01 21:06 -------- d-----w- c:\users\Calimero\AppData\Roaming\GameMaker
2013-02-01 20:02 . 2013-02-01 20:02 -------- d-----w- c:\users\Calimero\AppData\Local\PreEmptive Solutions
2013-02-01 17:51 . 2013-02-01 17:51 -------- d-----w- c:\users\Calimero\AppData\Local\CrashDumps
2013-01-28 18:44 . 2013-01-12 02:30 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-01-26 21:08 . 2013-01-27 11:59 -------- d-----w- c:\users\Calimero\AppData\Roaming\Elephant Games
2013-01-26 21:08 . 2013-01-27 11:59 -------- d-----w- c:\programdata\Elephant Games
2013-01-24 20:59 . 2012-10-17 03:31 741480 ------w- c:\windows\system32\HPDiscoPMa211.dll
2013-01-24 20:59 . 2013-01-24 20:59 -------- d-----w- c:\program files\HP
2013-01-13 20:49 . 2013-01-13 20:49 -------- d-----w- c:\users\Calimero\AppData\Roaming\digipen
2013-01-13 20:49 . 2013-01-13 20:49 -------- d-----w- c:\users\Calimero\AppData\Local\digipen
2013-01-13 14:13 . 2013-01-13 14:13 -------- d-----w- c:\users\Calimero\AppData\Local\DigitalVolcano
2013-01-13 13:42 . 2013-01-13 13:42 -------- d-----w- c:\program files (x86)\Duplicate Cleaner
2013-01-12 13:40 . 2013-01-12 13:40 -------- d-----w- c:\users\Calimero\AppData\Local\Zoner
2013-01-12 13:40 . 2013-01-12 13:40 -------- d-----w- c:\users\Calimero\AppData\Roaming\Zoner
2013-01-12 13:37 . 2013-01-12 13:37 -------- d-----w- c:\programdata\Zoner
2013-01-12 13:37 . 2013-01-12 13:37 -------- d-----w- c:\program files\Zoner
2013-01-10 21:03 . 2013-01-19 17:12 -------- d-----w- c:\program files (x86)\Alawar
2013-01-09 05:47 . 2012-11-30 05:41 424448 ----a-w- c:\windows\system32\KernelBase.dll
2013-01-09 05:45 . 2012-11-23 03:13 68608 ----a-w- c:\windows\system32\taskhost.exe
2013-01-09 05:45 . 2012-11-23 03:26 3149824 ----a-w- c:\windows\system32\win32k.sys
2013-01-07 21:20 . 2013-01-07 21:20 -------- d-----w- c:\users\Calimero\AppData\Roaming\SolEol
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-03 00:04 . 2011-01-15 14:54 45056 ----a-w- c:\windows\system32\acovcnt.exe
2013-01-10 19:21 . 2012-04-24 15:50 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-01-10 19:21 . 2011-06-14 20:00 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-09 06:02 . 2011-01-15 21:47 67599240 ----a-w- c:\windows\system32\MRT.exe
2012-12-19 21:08 . 2012-09-02 11:11 859072 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-12-19 21:08 . 2011-10-25 19:57 779704 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-12-16 17:11 . 2012-12-21 22:17 46080 ----a-w- c:\windows\system32\atmlib.dll
2012-12-16 14:45 . 2012-12-21 22:17 367616 ----a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-21 22:17 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2012-12-16 14:13 . 2012-12-21 22:17 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2012-12-01 14:21 . 2012-12-01 12:22 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-12-01 14:21 . 2012-12-01 12:22 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-12-01 12:24 . 2012-12-01 12:22 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-12-01 12:22 . 2012-12-01 12:22 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-11-30 04:45 . 2013-01-09 05:47 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2012-11-14 07:06 . 2012-12-13 05:27 17811968 ----a-w- c:\windows\system32\mshtml.dll
2012-11-14 06:32 . 2012-12-13 05:27 10925568 ----a-w- c:\windows\system32\ieframe.dll
2012-11-14 06:11 . 2012-12-13 05:27 2312704 ----a-w- c:\windows\system32\jscript9.dll
2012-11-14 06:04 . 2012-12-13 05:27 1346048 ----a-w- c:\windows\system32\urlmon.dll
2012-11-14 06:04 . 2012-12-13 05:27 1392128 ----a-w- c:\windows\system32\wininet.dll
2012-11-14 06:02 . 2012-12-13 05:27 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2012-11-14 06:02 . 2012-12-13 05:27 237056 ----a-w- c:\windows\system32\url.dll
2012-11-14 05:59 . 2012-12-13 05:27 85504 ----a-w- c:\windows\system32\jsproxy.dll
2012-11-14 05:58 . 2012-12-13 05:27 816640 ----a-w- c:\windows\system32\jscript.dll
2012-11-14 05:57 . 2012-12-13 05:27 599040 ----a-w- c:\windows\system32\vbscript.dll
2012-11-14 05:57 . 2012-12-13 05:27 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-11-14 05:55 . 2012-12-13 05:27 2144768 ----a-w- c:\windows\system32\iertutil.dll
2012-11-14 05:55 . 2012-12-13 05:27 729088 ----a-w- c:\windows\system32\msfeeds.dll
2012-11-14 05:53 . 2012-12-13 05:27 96768 ----a-w- c:\windows\system32\mshtmled.dll
2012-11-14 05:52 . 2012-12-13 05:27 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-11-14 05:46 . 2012-12-13 05:27 248320 ----a-w- c:\windows\system32\ieui.dll
2012-11-14 02:09 . 2012-12-13 05:27 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
2012-11-14 01:58 . 2012-12-13 05:27 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2012-11-14 01:57 . 2012-12-13 05:27 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2012-11-14 01:49 . 2012-12-13 05:27 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2012-11-14 01:48 . 2012-12-13 05:27 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-11-14 01:44 . 2012-12-13 05:27 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2012-11-09 05:45 . 2012-12-13 01:12 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-09 04:42 . 2012-12-13 01:12 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-11-08 10:29 . 2012-11-08 10:29 1402312 ----a-w- c:\windows\SysWow64\msxml4.dll
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zoner Photo Studio Autoupdate"="c:\program files\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE" [2012-12-04 773728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ASUS VIBE"="c:\program files (x86)\ASUS\ASUS VIBE\ASUS VIBE.exe" [2010-03-02 102400]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-12-19 41208]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-23 1601536]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160]
"AdobeCS4ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Trend Micro RUBotted V2.0 Beta"="c:\program files (x86)\Trend Micro\RUBotted\RUBottedGUI.exe" [2010-12-17 1103184]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-12-14 512360]
"Z1"="c:\users\Calimero\Desktop\mbar-1.01.0.1017\mbar\mbar.exe" [2013-01-18 1358408]
.
c:\users\Calimero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Alertes de surveillance de l'encre - HP Deskjet 3070 B611 series.lnk - c:\windows\system32\RunDll32.exe [2009-7-14 45568]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
R1 bdfwfpf;bdfwfpf;c:\program files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys [2011-12-02 89680]
R2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [2010-06-22 379520]
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2010\bdvedisk.sys [2010-01-19 103944]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 fsproflt;FSPro Filter Service;c:\windows\SysWOW64\fsproflt.exe [2009-03-09 73392]
R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
R2 MSMQSVC;Message Queuing Service;c:\windows\system32\mqsv32.exe [x]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 47632]
R2 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe [2012-03-28 3288400]
R2 RUBotSrv;Trend Micro RUBotted Service;c:\program files (x86)\Trend Micro\RUBotted\RUBotSrv.exe [2010-12-17 439632]
R2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-04-16 13832]
R2 TurboBoost;Intel(R) Turbo Boost Technology Monitor;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-04-16 134928]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2314240]
R3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [2009-10-19 278224]
R3 BDFM;BDFM;c:\windows\system32\DRIVERS\bdfm.sys [2010-01-29 163936]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2009-12-14 53800]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-11-04 79360]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-01-31 1038088]
R3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys [2010-07-28 29720]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176]
R3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [x]
R3 PSSDK42;PSSDK42;c:\windows\system32\Drivers\pssdk42.sys [2011-06-18 53312]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [2010-07-26 318056]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-09-28 53760]
R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2011-01-18 68440]
R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2011-01-15 1255736]
S0 FSProFilter;FSPro File Filter;c:\windows\System32\Drivers\FSPFltd.sys [2008-06-06 55440]
S0 oodrvled;oodrvled;c:\windows\system32\DRIVERS\oodrvled.sys [2011-03-02 30800]
S1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\windows\system32\DRIVERS\BdfNdisf6.sys [2011-12-02 88144]
S3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver;c:\windows\system32\DRIVERS\FLxHCIc.sys [2010-09-24 229376]
S3 FLxHCIh;Fresco Logic xHCI (USB3) Hub Device Driver;c:\windows\system32\DRIVERS\FLxHCIh.sys [2010-09-24 69120]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-04-21 76912]
.
.
Contenu du dossier 'Tâches planifiées'
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"THXCfg64"="c:\windows\system32\THXCfg64.dll" [2009-10-15 17920]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184]
"BitDefender Antiphishing Helper 32"="c:\program files\BitDefender\BitDefender 2010\Antispam32\IEShow.exe" [2009-10-19 71152]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2010\IEShow.exe" [2009-10-19 76296]
"BDAgent"="c:\program files\BitDefender\BitDefender 2010\bdagent.exe" [2012-11-02 1704568]
"OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2012-03-28 3998032]
.
------- Examen supplémentaire -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.be/
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Calimero\AppData\Roaming\Mozilla\Firefox\Profiles\7bcnnfzp.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.type - 0
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHELINS SUPPRIMES - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-RunOnce-Malwarebytes Anti-Malware (cleanup) - c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll
Toolbar-Locked - (no file)
HKLM-Run-ASUS WebStorage - c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-Setwallpaper - c:\programdata\SetWallpaper.cmd
AddRemove-Ootake_is1 - d:\games\Emuls\Ootake\unins000.exe
AddRemove-Uplay - c:\program files (x86)\Ubisoft\Ubisoft Game Launcher\Uninstall.exe
AddRemove-{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88} - c:\program files (x86)\InstallShield Installation Information\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}\setup.exe
.
.
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_USERS\S-1-5-21-3955869695-4156559446-3699184568-1002\Software\SecuROM\License information*]
"datasecu"=hex:0e,06,4d,74,33,13,96,83,da,f1,50,1c,dc,33,d6,92,8b,42,52,69,94,
e4,8e,77,6c,e9,70,9b,f8,a7,04,59,7e,01,68,07,f9,39,b0,d9,b7,79,e8,23,39,b7,\
"rkeysecu"=hex:12,40,19,d4,7b,f1,83,63,b1,ec,fb,fe,15,5c,10,cb
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11g_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11g_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODLED04.00.00.01PRO"="E1224628CBB33A7F3882D6CAB871D9DFEA1B66BCE34E276E0CCDFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A9C6AECB7A5D14075D575E7D6A3B98085D575E7D6A3B980819A297E7EE2EF7AE8624D30A399E2BCFB4AF24A6F93F143EB93EE2E5A482905C87483B03C022695966D3FEDEB161A43B7FD77E68030EF29F73E9FACECF5F1F5F8BC1A407B49997F7EE88261E4E8784496EF548E15145F02061479ACFA8D77C960DF938DEAA92A5BD9FDE1110D8541E19BCFCC957380E33ED163CAB4AA91840DE966AA328E6E0BC551D894C317F60CAC346731142EB63622E48455C5431A205065A255337112B08DAB14D272ED19667528F7370CE8898AC76D1719F36034DE852294D7D9237EB36DFC903B6ECC6B8D3C13C2BF9DC8CD04451B3E4A970C7410FF97D9C97F149F07C69F519D285B5D77485965C8A825905DEBE8FD5F6B00A7D1D2B725EDBC61BDE91EF6B109740DEDBB2828D5EBB07B68135B12C0FC35F3AD23F8347724C32662C31E082FB6520E003FB14329AF1E6CCE80611F4701394A9E6A398E0CEA88AC5239A9D38086057C3DA3F07BA1050D3AC2E91B878EDAA9D1134FB72C67AF95BB9E0137A2E706FCB6FC8729D01D0BFB0471C1FF5EA0E95FD0B07FE0CA4110CE2A7DBDFC1A987419B31838D8D8282EE17734DF70D21ECA1691904E8564AC46D14D8574EAE12B043153A178D82E1DF4E536B3268349638604A1C1E77342CD77093F6F02E7374E72C3C21E17398643892664D12C2176B35A7BC5C20EC7FE1242CBD1495D23404B772485E1BC2E3F36BB5831C05DDD4E039921406A89082A895FC21A588138B1243D124CF4784681FF1F3143DF59200DF317F5528A82C7E5D2B027E82DF4A059ABECBEF3743C5211855CFB4FB27BD20709A10B835E48F27067B9D4EE688D9A1B873A47FB8BF977B33B38D3686ADC2AF440B2AAD85F90D24CAACF6B974BE25D62E4063D9DE3F0E5AEA3FB51C6F70061E2DA7F8D4D4D2FA9276FB7921AE96928EDF94D3BB161AC113DEBE9520AD2F714E21AC6904C1B23380F93A54157EF60FA5D6F68812317C50EF4F0CC0AD99F7F196BCE9AD44CF2F177367CA7ADCAF9A096B3E7FD282E365D72F211688E674317A443EC1BC53653185E279A52373730F75A6E8DC4DE449A80082E0DD891EDD13001308AC5122D0F7E8BB0AD8CA065DB94A8FCBCED2C25DEEEF10BA7A9D5D5EAA7CB8A1B367D73F14285D99822E79E54E05D37E2C03DD8232D471001669605E586DDA35F843CC44EBB51B4B585261E9D9A49240DCC2A8FC455EB5A8EFCF19AED0D316922D690F57B981BE6821FC8A2A3AAC64EEDEBAC977C8425E4D59F9AA801DB6762D18A55ED3898282DB3BBAF2CAA1A4CE11C3569E7F3638E12CB7D5EDE91A"
"OODEFRAG15.00.00.01PROFESSIONAL"="236EE06FA09AE09B0FA0644328B651E4244E55B9544617B1F405C951E07DDB30710552F254FD8E90143B83C1969C9B5BE1CEDAFBD32FF55432B6ECE4AE72EBF84DE9E8C848FB567E5B93E307153B8CED9AE580B27B8DAAC8736A5741D160B1BF4FF5BDC61863E777C71CD44919CB96E2A1BDE7973F2411A599A31EBFD9330B8C83257D0913EA45943467B504CEEB8382BAA44727C8995302F6086E000DB9A9E86A9766EE392845F16C30FBF8951DEC18220C68237377F2FED1E3FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A9C6AECB7A5D14075D575E7D6A3B98085D575E7D6A3B9808F42F1B801C5E3A566EA8644BF70FEAC723B09438B45D53ECFAA0E2DCE2122690F7DC73D2211EAC828FB1C184267D953BE3C6CE131336107A3B16AAC8A1573A8A5780471A9A90D98693E81BB7A1DCEC3854E51933443383FD4AFC73B2EED4ECCA7FF1AC2E1C19352A3AA60645E2DEF061AD892624487B5894F690296EEE43B685F34E71CD0EA2A4DBDC094975B6BF937D396F5AD2EEB7AF7D215171B5985E859547759318AB17012C6371E1F03F3D3E775899CE93DE191D1D3C0220A235E5B8F5A40C461584681AD3CB0402C76F98C8DDFB4ED11E91D0A97A4F294137631DA7C7C8F9722DFC8B30AAAA2A0C6B92950564AC97650E54155042F91292D6184C19D0056AB2AD4C78FAAEA49119B2C201B3E184C33E63CAA101C3E9CB86CB183ECBF83E4FD6C67EACA203F32BF557F0260D513565C50068B52073E32AC44000C36FCEEDDA6210F1A8C7EB672CA3F7E358BCD07F529AAB781206E841442746BCAEA98121070C025DEF7955618DD597B26BE0243C248D13187EFDDF6D74BB5090D814E6F98F41F9460C404BD70C761C4CB90C31563AA3443A4649B8E8DAC5B9151CBAF62D739F3A898A940054A920CF6EA246044D3597B222B61AF7C659BBBBB3D89ECF84F67BE5567964CAF52CA461AF068A4A337CD5B66CA21AC3329847F82AF336B1DBA35C08B0F01323709A87E2F749C658313A808B0561E4696402C8758CD2698026C47D0EEF8575A90843824C85D65FA4805A6DCFAECD89D72FC6D019C0E29447E76ACFC94158D59D96378175E71DAA49F1922407FDC58D24F5D7A6B0829289323A69F4EEA20773670C4CA49E040C7306685665195E2CE806B2ED44EB5F560E11C9D9C41968367E8EE99A41691399F8BC5A6120510C6785576F84D9DFBBA55AD9D9174C433B109D434780DFDCA141EE7555B0FADE9AE2459A4ED948844DFB9B25BDC049D095C0EB564D1E3CE111FD7BDAF5074F556E8CFBF203F027B69E58F2AFDFBC3086C878F4BDB9D8C7C89454BA3B70E92A2C40D772A755113F360EBFF4DA3DB2A80DF66C3E13E05926C3B5473A0A0D254E3EA0BA"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Heure de fin: 2013-02-03 04:51:38
ComboFix-quarantined-files.txt 2013-02-03 03:51
.
Avant-CF: 48.643.473.408 octets libres
Après-CF: 51.274.227.712 octets libres
.
- - End Of File - - 09C573BC64F4B19BB0F9B3A994560A1B
Microsoft Windows 7 Édition Familiale Premium 6.1.7601.1.1252.32.1036.18.6068.5052 [GMT 1:00]
Lancé depuis: c:\users\Calimero\Desktop\ComboFix.exe
AV: BitDefender Antivirus *Enabled/Updated* {982ADE23-275B-0766-37C5-DE01A484098E}
FW: BitDefender Firewall *Enabled* {A0115F06-6D34-063E-1C9A-77345A574EF5}
SP: BitDefender Antispyware *Enabled/Updated* {234B3FC7-0161-08E8-0D75-E573DF034333}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Un nouveau point de restauration a été créé
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\esupport\eDriver\Software\ASUS\MultiFrame\XP32_Vista32_Vista64_Win7_32_Win7_64_1.0.0021\Desktop_.ini
c:\programdata\FullRemove.exe
c:\programdata\Roaming
c:\users\Calimero\AppData\Local\assembly\tmp
c:\users\Calimero\AppData\Local\uninst.tmp
c:\windows\msxml4-KB2758694-enu.LOG
c:\windows\SysWow64\tmp3C98.tmp
c:\windows\SysWow64\tmp3CE7.tmp
c:\windows\SysWow64\tmp539B.tmp
c:\windows\SysWow64\tmp53AC.tmp
c:\windows\SysWow64\tmpAF42.tmp
c:\windows\SysWow64\tmpAF43.tmp
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2013-01-03 au 2013-02-03 ))))))))))))))))))))))))))))))))))))
.
.
2013-02-03 00:02 . 2013-02-03 00:02 -------- d-----w- c:\program files (x86)\ESET
2013-02-02 23:22 . 2013-02-02 23:22 -------- d-----w- c:\users\Calimero\AppData\Roaming\Malwarebytes
2013-02-02 23:22 . 2013-02-02 23:22 -------- d-----w- c:\programdata\Malwarebytes
2013-02-02 23:22 . 2012-12-14 15:49 24176 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-02-02 23:22 . 2013-02-02 23:22 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-02-02 22:12 . 2013-02-02 23:32 -------- d-----w- c:\users\Calimero\AppData\Roaming\Puaquh
2013-02-02 22:12 . 2013-02-02 22:14 -------- d-----w- c:\users\Calimero\AppData\Roaming\Odtoy
2013-02-02 22:12 . 2013-02-02 22:13 -------- d-----w- c:\users\Calimero\AppData\Roaming\tor
2013-02-01 21:06 . 2013-02-01 21:06 -------- d-----w- c:\users\Calimero\AppData\Local\GameMaker8.1
2013-02-01 21:06 . 2013-02-01 21:06 -------- d-----w- c:\users\Calimero\AppData\Local\YoYo_Games_Ltd
2013-02-01 21:05 . 2013-02-01 21:06 -------- d-----w- c:\users\Calimero\AppData\Roaming\GameMaker
2013-02-01 20:02 . 2013-02-01 20:02 -------- d-----w- c:\users\Calimero\AppData\Local\PreEmptive Solutions
2013-02-01 17:51 . 2013-02-01 17:51 -------- d-----w- c:\users\Calimero\AppData\Local\CrashDumps
2013-01-28 18:44 . 2013-01-12 02:30 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-01-26 21:08 . 2013-01-27 11:59 -------- d-----w- c:\users\Calimero\AppData\Roaming\Elephant Games
2013-01-26 21:08 . 2013-01-27 11:59 -------- d-----w- c:\programdata\Elephant Games
2013-01-24 20:59 . 2012-10-17 03:31 741480 ------w- c:\windows\system32\HPDiscoPMa211.dll
2013-01-24 20:59 . 2013-01-24 20:59 -------- d-----w- c:\program files\HP
2013-01-13 20:49 . 2013-01-13 20:49 -------- d-----w- c:\users\Calimero\AppData\Roaming\digipen
2013-01-13 20:49 . 2013-01-13 20:49 -------- d-----w- c:\users\Calimero\AppData\Local\digipen
2013-01-13 14:13 . 2013-01-13 14:13 -------- d-----w- c:\users\Calimero\AppData\Local\DigitalVolcano
2013-01-13 13:42 . 2013-01-13 13:42 -------- d-----w- c:\program files (x86)\Duplicate Cleaner
2013-01-12 13:40 . 2013-01-12 13:40 -------- d-----w- c:\users\Calimero\AppData\Local\Zoner
2013-01-12 13:40 . 2013-01-12 13:40 -------- d-----w- c:\users\Calimero\AppData\Roaming\Zoner
2013-01-12 13:37 . 2013-01-12 13:37 -------- d-----w- c:\programdata\Zoner
2013-01-12 13:37 . 2013-01-12 13:37 -------- d-----w- c:\program files\Zoner
2013-01-10 21:03 . 2013-01-19 17:12 -------- d-----w- c:\program files (x86)\Alawar
2013-01-09 05:47 . 2012-11-30 05:41 424448 ----a-w- c:\windows\system32\KernelBase.dll
2013-01-09 05:45 . 2012-11-23 03:13 68608 ----a-w- c:\windows\system32\taskhost.exe
2013-01-09 05:45 . 2012-11-23 03:26 3149824 ----a-w- c:\windows\system32\win32k.sys
2013-01-07 21:20 . 2013-01-07 21:20 -------- d-----w- c:\users\Calimero\AppData\Roaming\SolEol
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-03 00:04 . 2011-01-15 14:54 45056 ----a-w- c:\windows\system32\acovcnt.exe
2013-01-10 19:21 . 2012-04-24 15:50 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-01-10 19:21 . 2011-06-14 20:00 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-09 06:02 . 2011-01-15 21:47 67599240 ----a-w- c:\windows\system32\MRT.exe
2012-12-19 21:08 . 2012-09-02 11:11 859072 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-12-19 21:08 . 2011-10-25 19:57 779704 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-12-16 17:11 . 2012-12-21 22:17 46080 ----a-w- c:\windows\system32\atmlib.dll
2012-12-16 14:45 . 2012-12-21 22:17 367616 ----a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-21 22:17 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2012-12-16 14:13 . 2012-12-21 22:17 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2012-12-01 14:21 . 2012-12-01 12:22 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-12-01 14:21 . 2012-12-01 12:22 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-12-01 12:24 . 2012-12-01 12:22 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-12-01 12:22 . 2012-12-01 12:22 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-11-30 04:45 . 2013-01-09 05:47 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2012-11-14 07:06 . 2012-12-13 05:27 17811968 ----a-w- c:\windows\system32\mshtml.dll
2012-11-14 06:32 . 2012-12-13 05:27 10925568 ----a-w- c:\windows\system32\ieframe.dll
2012-11-14 06:11 . 2012-12-13 05:27 2312704 ----a-w- c:\windows\system32\jscript9.dll
2012-11-14 06:04 . 2012-12-13 05:27 1346048 ----a-w- c:\windows\system32\urlmon.dll
2012-11-14 06:04 . 2012-12-13 05:27 1392128 ----a-w- c:\windows\system32\wininet.dll
2012-11-14 06:02 . 2012-12-13 05:27 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2012-11-14 06:02 . 2012-12-13 05:27 237056 ----a-w- c:\windows\system32\url.dll
2012-11-14 05:59 . 2012-12-13 05:27 85504 ----a-w- c:\windows\system32\jsproxy.dll
2012-11-14 05:58 . 2012-12-13 05:27 816640 ----a-w- c:\windows\system32\jscript.dll
2012-11-14 05:57 . 2012-12-13 05:27 599040 ----a-w- c:\windows\system32\vbscript.dll
2012-11-14 05:57 . 2012-12-13 05:27 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-11-14 05:55 . 2012-12-13 05:27 2144768 ----a-w- c:\windows\system32\iertutil.dll
2012-11-14 05:55 . 2012-12-13 05:27 729088 ----a-w- c:\windows\system32\msfeeds.dll
2012-11-14 05:53 . 2012-12-13 05:27 96768 ----a-w- c:\windows\system32\mshtmled.dll
2012-11-14 05:52 . 2012-12-13 05:27 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-11-14 05:46 . 2012-12-13 05:27 248320 ----a-w- c:\windows\system32\ieui.dll
2012-11-14 02:09 . 2012-12-13 05:27 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
2012-11-14 01:58 . 2012-12-13 05:27 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2012-11-14 01:57 . 2012-12-13 05:27 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2012-11-14 01:49 . 2012-12-13 05:27 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2012-11-14 01:48 . 2012-12-13 05:27 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-11-14 01:44 . 2012-12-13 05:27 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2012-11-09 05:45 . 2012-12-13 01:12 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-09 04:42 . 2012-12-13 01:12 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-11-08 10:29 . 2012-11-08 10:29 1402312 ----a-w- c:\windows\SysWow64\msxml4.dll
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zoner Photo Studio Autoupdate"="c:\program files\ZONER\PHOTO STUDIO 15\Program32\ZPSTRAY.EXE" [2012-12-04 773728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ASUS VIBE"="c:\program files (x86)\ASUS\ASUS VIBE\ASUS VIBE.exe" [2010-03-02 102400]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-12-19 41208]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-23 1601536]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160]
"AdobeCS4ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Trend Micro RUBotted V2.0 Beta"="c:\program files (x86)\Trend Micro\RUBotted\RUBottedGUI.exe" [2010-12-17 1103184]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-12-14 512360]
"Z1"="c:\users\Calimero\Desktop\mbar-1.01.0.1017\mbar\mbar.exe" [2013-01-18 1358408]
.
c:\users\Calimero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Alertes de surveillance de l'encre - HP Deskjet 3070 B611 series.lnk - c:\windows\system32\RunDll32.exe [2009-7-14 45568]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
R1 bdfwfpf;bdfwfpf;c:\program files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys [2011-12-02 89680]
R2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [2010-06-22 379520]
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2010\bdvedisk.sys [2010-01-19 103944]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 fsproflt;FSPro Filter Service;c:\windows\SysWOW64\fsproflt.exe [2009-03-09 73392]
R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
R2 MSMQSVC;Message Queuing Service;c:\windows\system32\mqsv32.exe [x]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 47632]
R2 OODefragAgent;O&O Defrag;c:\program files\OO Software\Defrag\oodag.exe [2012-03-28 3288400]
R2 RUBotSrv;Trend Micro RUBotted Service;c:\program files (x86)\Trend Micro\RUBotted\RUBotSrv.exe [2010-12-17 439632]
R2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-04-16 13832]
R2 TurboBoost;Intel(R) Turbo Boost Technology Monitor;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-04-16 134928]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2314240]
R3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [2009-10-19 278224]
R3 BDFM;BDFM;c:\windows\system32\DRIVERS\bdfm.sys [2010-01-29 163936]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2009-12-14 53800]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-11-04 79360]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-01-31 1038088]
R3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys [2010-07-28 29720]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176]
R3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys [x]
R3 PSSDK42;PSSDK42;c:\windows\system32\Drivers\pssdk42.sys [2011-06-18 53312]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [2010-07-26 318056]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-09-28 53760]
R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2011-01-18 68440]
R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2011-01-15 1255736]
S0 FSProFilter;FSPro File Filter;c:\windows\System32\Drivers\FSPFltd.sys [2008-06-06 55440]
S0 oodrvled;oodrvled;c:\windows\system32\DRIVERS\oodrvled.sys [2011-03-02 30800]
S1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\windows\system32\DRIVERS\BdfNdisf6.sys [2011-12-02 88144]
S3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver;c:\windows\system32\DRIVERS\FLxHCIc.sys [2010-09-24 229376]
S3 FLxHCIh;Fresco Logic xHCI (USB3) Hub Device Driver;c:\windows\system32\DRIVERS\FLxHCIh.sys [2010-09-24 69120]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2010-04-21 76912]
.
.
Contenu du dossier 'Tâches planifiées'
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"THXCfg64"="c:\windows\system32\THXCfg64.dll" [2009-10-15 17920]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184]
"BitDefender Antiphishing Helper 32"="c:\program files\BitDefender\BitDefender 2010\Antispam32\IEShow.exe" [2009-10-19 71152]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2010\IEShow.exe" [2009-10-19 76296]
"BDAgent"="c:\program files\BitDefender\BitDefender 2010\bdagent.exe" [2012-11-02 1704568]
"OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2012-03-28 3998032]
.
------- Examen supplémentaire -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.be/
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Calimero\AppData\Roaming\Mozilla\Firefox\Profiles\7bcnnfzp.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.type - 0
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHELINS SUPPRIMES - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-RunOnce-Malwarebytes Anti-Malware (cleanup) - c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll
Toolbar-Locked - (no file)
HKLM-Run-ASUS WebStorage - c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-Setwallpaper - c:\programdata\SetWallpaper.cmd
AddRemove-Ootake_is1 - d:\games\Emuls\Ootake\unins000.exe
AddRemove-Uplay - c:\program files (x86)\Ubisoft\Ubisoft Game Launcher\Uninstall.exe
AddRemove-{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88} - c:\program files (x86)\InstallShield Installation Information\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}\setup.exe
.
.
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_USERS\S-1-5-21-3955869695-4156559446-3699184568-1002\Software\SecuROM\License information*]
"datasecu"=hex:0e,06,4d,74,33,13,96,83,da,f1,50,1c,dc,33,d6,92,8b,42,52,69,94,
e4,8e,77,6c,e9,70,9b,f8,a7,04,59,7e,01,68,07,f9,39,b0,d9,b7,79,e8,23,39,b7,\
"rkeysecu"=hex:12,40,19,d4,7b,f1,83,63,b1,ec,fb,fe,15,5c,10,cb
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11g_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11g_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODLED04.00.00.01PRO"="E1224628CBB33A7F3882D6CAB871D9DFEA1B66BCE34E276E0CCDFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A9C6AECB7A5D14075D575E7D6A3B98085D575E7D6A3B980819A297E7EE2EF7AE8624D30A399E2BCFB4AF24A6F93F143EB93EE2E5A482905C87483B03C022695966D3FEDEB161A43B7FD77E68030EF29F73E9FACECF5F1F5F8BC1A407B49997F7EE88261E4E8784496EF548E15145F02061479ACFA8D77C960DF938DEAA92A5BD9FDE1110D8541E19BCFCC957380E33ED163CAB4AA91840DE966AA328E6E0BC551D894C317F60CAC346731142EB63622E48455C5431A205065A255337112B08DAB14D272ED19667528F7370CE8898AC76D1719F36034DE852294D7D9237EB36DFC903B6ECC6B8D3C13C2BF9DC8CD04451B3E4A970C7410FF97D9C97F149F07C69F519D285B5D77485965C8A825905DEBE8FD5F6B00A7D1D2B725EDBC61BDE91EF6B109740DEDBB2828D5EBB07B68135B12C0FC35F3AD23F8347724C32662C31E082FB6520E003FB14329AF1E6CCE80611F4701394A9E6A398E0CEA88AC5239A9D38086057C3DA3F07BA1050D3AC2E91B878EDAA9D1134FB72C67AF95BB9E0137A2E706FCB6FC8729D01D0BFB0471C1FF5EA0E95FD0B07FE0CA4110CE2A7DBDFC1A987419B31838D8D8282EE17734DF70D21ECA1691904E8564AC46D14D8574EAE12B043153A178D82E1DF4E536B3268349638604A1C1E77342CD77093F6F02E7374E72C3C21E17398643892664D12C2176B35A7BC5C20EC7FE1242CBD1495D23404B772485E1BC2E3F36BB5831C05DDD4E039921406A89082A895FC21A588138B1243D124CF4784681FF1F3143DF59200DF317F5528A82C7E5D2B027E82DF4A059ABECBEF3743C5211855CFB4FB27BD20709A10B835E48F27067B9D4EE688D9A1B873A47FB8BF977B33B38D3686ADC2AF440B2AAD85F90D24CAACF6B974BE25D62E4063D9DE3F0E5AEA3FB51C6F70061E2DA7F8D4D4D2FA9276FB7921AE96928EDF94D3BB161AC113DEBE9520AD2F714E21AC6904C1B23380F93A54157EF60FA5D6F68812317C50EF4F0CC0AD99F7F196BCE9AD44CF2F177367CA7ADCAF9A096B3E7FD282E365D72F211688E674317A443EC1BC53653185E279A52373730F75A6E8DC4DE449A80082E0DD891EDD13001308AC5122D0F7E8BB0AD8CA065DB94A8FCBCED2C25DEEEF10BA7A9D5D5EAA7CB8A1B367D73F14285D99822E79E54E05D37E2C03DD8232D471001669605E586DDA35F843CC44EBB51B4B585261E9D9A49240DCC2A8FC455EB5A8EFCF19AED0D316922D690F57B981BE6821FC8A2A3AAC64EEDEBAC977C8425E4D59F9AA801DB6762D18A55ED3898282DB3BBAF2CAA1A4CE11C3569E7F3638E12CB7D5EDE91A"
"OODEFRAG15.00.00.01PROFESSIONAL"="236EE06FA09AE09B0FA0644328B651E4244E55B9544617B1F405C951E07DDB30710552F254FD8E90143B83C1969C9B5BE1CEDAFBD32FF55432B6ECE4AE72EBF84DE9E8C848FB567E5B93E307153B8CED9AE580B27B8DAAC8736A5741D160B1BF4FF5BDC61863E777C71CD44919CB96E2A1BDE7973F2411A599A31EBFD9330B8C83257D0913EA45943467B504CEEB8382BAA44727C8995302F6086E000DB9A9E86A9766EE392845F16C30FBF8951DEC18220C68237377F2FED1E3FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A9C6AECB7A5D14075D575E7D6A3B98085D575E7D6A3B9808F42F1B801C5E3A566EA8644BF70FEAC723B09438B45D53ECFAA0E2DCE2122690F7DC73D2211EAC828FB1C184267D953BE3C6CE131336107A3B16AAC8A1573A8A5780471A9A90D98693E81BB7A1DCEC3854E51933443383FD4AFC73B2EED4ECCA7FF1AC2E1C19352A3AA60645E2DEF061AD892624487B5894F690296EEE43B685F34E71CD0EA2A4DBDC094975B6BF937D396F5AD2EEB7AF7D215171B5985E859547759318AB17012C6371E1F03F3D3E775899CE93DE191D1D3C0220A235E5B8F5A40C461584681AD3CB0402C76F98C8DDFB4ED11E91D0A97A4F294137631DA7C7C8F9722DFC8B30AAAA2A0C6B92950564AC97650E54155042F91292D6184C19D0056AB2AD4C78FAAEA49119B2C201B3E184C33E63CAA101C3E9CB86CB183ECBF83E4FD6C67EACA203F32BF557F0260D513565C50068B52073E32AC44000C36FCEEDDA6210F1A8C7EB672CA3F7E358BCD07F529AAB781206E841442746BCAEA98121070C025DEF7955618DD597B26BE0243C248D13187EFDDF6D74BB5090D814E6F98F41F9460C404BD70C761C4CB90C31563AA3443A4649B8E8DAC5B9151CBAF62D739F3A898A940054A920CF6EA246044D3597B222B61AF7C659BBBBB3D89ECF84F67BE5567964CAF52CA461AF068A4A337CD5B66CA21AC3329847F82AF336B1DBA35C08B0F01323709A87E2F749C658313A808B0561E4696402C8758CD2698026C47D0EEF8575A90843824C85D65FA4805A6DCFAECD89D72FC6D019C0E29447E76ACFC94158D59D96378175E71DAA49F1922407FDC58D24F5D7A6B0829289323A69F4EEA20773670C4CA49E040C7306685665195E2CE806B2ED44EB5F560E11C9D9C41968367E8EE99A41691399F8BC5A6120510C6785576F84D9DFBBA55AD9D9174C433B109D434780DFDCA141EE7555B0FADE9AE2459A4ED948844DFB9B25BDC049D095C0EB564D1E3CE111FD7BDAF5074F556E8CFBF203F027B69E58F2AFDFBC3086C878F4BDB9D8C7C89454BA3B70E92A2C40D772A755113F360EBFF4DA3DB2A80DF66C3E13E05926C3B5473A0A0D254E3EA0BA"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Heure de fin: 2013-02-03 04:51:38
ComboFix-quarantined-files.txt 2013-02-03 03:51
.
Avant-CF: 48.643.473.408 octets libres
Après-CF: 51.274.227.712 octets libres
.
- - End Of File - - 09C573BC64F4B19BB0F9B3A994560A1B