ComboFix 09-07-29.04 - pour les jeux 31/07/2009 16:55.1.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.595 [GMT 2:00]
Running from: c:\documents and settings\pour les jeux\Bureau\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\pour les jeux\Application Data\Google\cqvgl19623160.exe
c:\documents and settings\pour les jeux\Application Data\Google\Shell32.dll
c:\windows\system32\drivers\svchost.exe
.
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-31 )))))))))))))))))))))))))))))))
.
2009-07-31 14:16 . 2009-07-13 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-31 14:16 . 2009-07-31 14:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-31 14:16 . 2009-07-31 14:16 -------- dc----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-31 14:16 . 2009-07-13 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-31 14:11 . 2009-07-31 14:21 -------- dc----w- C:\ToolBar SD
2009-07-31 13:13 . 2009-07-31 13:13 -------- d-----w- c:\program files\Trend Micro
2009-07-31 12:47 . 2009-07-31 12:47 -------- dc----w- c:\documents and settings\pour les jeux\Application Data\Malwarebytes
2009-07-31 12:07 . 2009-07-31 12:07 4956408 -c--a-w- c:\documents and settings\pour les jeux\Application Data\pdinstall.exe
2009-07-31 11:56 . 2009-07-31 11:56 422 -c--a-w- c:\documents and settings\pour les jeux\Application Data\DivX\mario.exe
2009-07-31 11:56 . 2009-07-31 11:56 16141 -c--a-w- c:\documents and settings\pour les jeux\Application Data\Help\flamiks32.exe
2009-07-31 11:56 . 2009-07-31 11:56 145131 -c--a-w- c:\documents and settings\pour les jeux\Application Data\dvdcss\pingo.dll
2009-07-31 11:56 . 2009-07-31 11:56 13221 -c--a-w- c:\documents and settings\pour les jeux\Application Data\DAEMON Tools Lite\xl12.exe
2009-07-31 11:56 . 2009-07-31 11:56 11232 -c--a-w- c:\documents and settings\pour les jeux\Application Data\Adobe\norigami.dll
2009-07-30 11:59 . 2009-07-30 11:59 -------- d-----w- c:\windows\Eurobarre
2009-07-29 11:45 . 2009-07-29 11:54 -------- d-----w- c:\program files\GUILD WARS
2009-07-28 23:16 . 2009-07-03 16:57 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-28 23:16 . 2009-07-03 16:57 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-07-28 14:26 . 2009-07-28 14:26 -------- dc----w- C:\CrashReport
2009-07-27 20:55 . 2009-07-30 23:51 -------- dc----w- c:\documents and settings\pour les jeux\Local Settings\Application Data\VirtuaTennis2009
2009-07-27 11:11 . 2009-07-27 11:11 -------- d-----w- c:\program files\NVIDIA Corporation
2009-07-27 11:11 . 2009-07-27 11:11 -------- dc----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2009-07-27 10:52 . 2009-07-27 10:52 -------- d-----w- c:\program files\Electronic Arts
2009-07-25 17:31 . 2009-07-25 17:37 -------- d-----w- c:\program files\BitComet
2009-07-25 17:24 . 2009-07-25 17:24 -------- d-----w- c:\program files\uTorrent
2009-07-23 17:55 . 2009-07-23 17:57 -------- dc----w- c:\documents and settings\pour les jeux\Application Data\TigerPlayer
2009-07-23 17:53 . 2009-07-23 17:53 -------- dc----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-07-23 17:51 . 2009-07-23 17:55 -------- d-----w- c:\program files\MpcStar
2009-07-22 15:04 . 2009-07-27 21:18 -------- dc----w- c:\documents and settings\pour les jeux\Local Settings\Application Data\Adobe
2009-07-21 20:04 . 2009-07-21 20:04 -------- dc----w- c:\documents and settings\pour les jeux\Local Settings\Application Data\Help
2009-07-21 10:42 . 2009-07-21 10:42 -------- dc----w- c:\documents and settings\pour les jeux\Application Data\TuneUp Software
2009-07-20 21:14 . 2009-07-20 21:14 -------- dcsh--w- c:\documents and settings\pour les jeux\IECompatCache
2009-07-18 15:32 . 2009-07-18 15:32 -------- dc----w- c:\documents and settings\pour les jeux\Local Settings\Application Data\Mozilla
2009-07-18 11:07 . 2009-07-29 14:25 -------- dc----w- c:\documents and settings\pour les jeux\Application Data\dvdcss
2009-07-16 21:20 . 2009-07-16 21:20 -------- dc----w- c:\documents and settings\pour les jeux\Application Data\vlc
2009-07-16 21:19 . 2009-07-16 21:19 -------- dc----w- c:\documents and settings\pour les jeux\Application Data\DivX
2009-07-16 19:04 . 2009-07-16 19:04 -------- dc-h--r- c:\documents and settings\pour les jeux\Application Data\SecuROM
2009-07-16 11:23 . 2009-07-31 15:02 -------- dc----w- c:\documents and settings\pour les jeux\Tracing
2009-07-15 20:09 . 2009-07-15 20:09 48120 -c--a-w- c:\documents and settings\pour les jeux\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-15 19:50 . 2009-07-15 19:50 -------- dc----w- c:\documents and settings\pour les jeux\Local Settings\Application Data\Electronic Arts
2009-07-15 19:34 . 2009-07-15 19:35 -------- dc----w- c:\documents and settings\pour les jeux\Application Data\DAEMON Tools Lite
2009-07-14 11:34 . 2009-07-14 11:34 86016 ----a-w- c:\windows\system32\nvmctray.dll
2009-07-14 11:29 . 2009-07-14 11:29 -------- dcsh--w- c:\documents and settings\pour les jeux\PrivacIE
2009-07-14 10:06 . 2009-07-14 10:06 -------- d-----w- c:\program files\Firaxis Games
2009-07-13 08:50 . 2009-07-13 08:50 -------- dc----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-07-12 18:46 . 2009-07-13 13:39 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Application Data\dvdcss
2009-07-12 14:26 . 2009-07-12 14:26 -------- d-----w- c:\program files\Fichiers communs\DirectX
2009-07-12 13:57 . 2009-07-12 13:57 -------- dc----w- C:\AeriaGames
2009-07-12 01:06 . 2009-07-12 01:06 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-07-11 18:39 . 2009-07-11 18:39 -------- d-----w- c:\program files\psx emulation cheater
2009-07-11 18:26 . 2008-04-14 12:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-07-11 18:14 . 2009-07-11 18:14 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Application Data\fltk.org
2009-07-11 10:49 . 2009-07-11 10:58 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Application Data\Mount&Blade
2009-07-11 10:39 . 2009-07-11 10:56 -------- d-----w- c:\program files\Mount&Blade
2009-07-11 09:37 . 2009-07-11 09:37 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Local Settings\Application Data\Electronic Arts
2009-07-11 09:35 . 2009-07-11 09:36 -------- d--h--w- c:\windows\msdownld.tmp
2009-07-11 00:46 . 2008-10-16 12:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-07-11 00:46 . 2008-10-16 12:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-07-10 11:30 . 2009-07-17 00:09 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Tracing
2009-07-10 11:28 . 2009-07-24 17:45 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-10 11:27 . 2009-07-10 11:27 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-07-10 11:27 . 2009-02-06 16:08 55152 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-07-10 11:26 . 2009-07-10 11:26 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-07-10 11:25 . 2009-07-10 11:25 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-07-10 11:24 . 2009-07-10 11:28 -------- d-----w- c:\program files\Microsoft
2009-07-10 11:24 . 2009-07-10 11:24 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-07-10 11:23 . 2009-07-10 11:27 -------- d-----w- c:\program files\Windows Live
2009-07-10 11:18 . 2009-07-10 11:18 -------- d-----w- c:\program files\Fichiers communs\Windows Live
2009-07-10 11:00 . 2009-07-10 11:07 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Local Settings\Application Data\Google
2009-07-10 11:00 . 2009-07-10 12:26 -------- d-----w- c:\program files\Google
2009-07-10 11:00 . 2009-07-10 11:00 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
2009-07-10 10:44 . 2009-07-10 10:43 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-10 10:43 . 2009-07-10 10:43 -------- d-----w- c:\program files\Java
2009-07-10 10:32 . 2009-07-10 10:32 0 ----a-w- c:\windows\nsreg.dat
2009-07-10 10:32 . 2009-07-10 10:32 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Local Settings\Application Data\Mozilla
2009-07-10 10:09 . 2009-07-10 10:09 -------- d-----w- c:\program files\AGEIA Technologies
2009-07-10 10:09 . 2009-07-10 10:09 -------- d-----w- c:\windows\system32\AGEIA
2009-07-10 10:08 . 2009-07-22 14:22 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2009-07-09 14:43 . 2009-07-09 14:43 96 ---ha-w- c:\windows\system32\HsInfo.dat
2009-07-09 10:11 . 2009-07-09 10:11 -------- d-----r- c:\documents and settings\LocalService\Mes documents
2009-07-09 10:11 . 2009-07-09 10:11 -------- d-----r- c:\documents and settings\LocalService\Favoris
2009-07-09 10:11 . 2009-07-09 10:11 -------- d-----w- c:\documents and settings\LocalService\Menu Démarrer
2009-07-09 10:11 . 2009-07-09 10:11 -------- d-----w- c:\documents and settings\LocalService\Bureau
2009-07-09 10:10 . 2009-07-09 10:10 -------- d-----w- c:\program files\Winletmin
2009-07-09 10:02 . 2009-07-09 10:02 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Local Settings\Application Data\Adobe
2009-07-09 01:42 . 2009-07-10 13:04 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Application Data\Hamachi
2009-07-09 01:42 . 2009-07-09 01:42 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
2009-07-09 01:42 . 2009-07-09 01:42 -------- d-----w- c:\program files\Hamachi
2009-07-09 01:19 . 2009-07-09 01:19 -------- d-sh--w- c:\windows\ftpcache
2009-07-09 00:13 . 2009-07-11 23:05 -------- d-----w- c:\program files\Postal2STP
2009-07-08 23:53 . 2009-07-09 00:01 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Local Settings\Application Data\The Witcher
2009-07-08 21:53 . 2009-07-08 21:53 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Application Data\vlc
2009-07-08 21:15 . 2009-07-08 22:23 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Application Data\Xfire
2009-07-08 21:15 . 2009-07-08 22:23 -------- d-s---w- c:\program files\Xfire
2009-07-08 18:02 . 2009-07-08 18:02 -------- d-----w- c:\program files\THQ
2009-07-08 17:23 . 2009-07-08 17:23 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Local Settings\Application Data\Gas Powered Games
2009-07-08 17:20 . 2009-07-10 11:29 48120 -c--a-w- c:\documents and settings\jeux.BUREAU1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-08 17:10 . 2009-07-08 17:10 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Application Data\Stardock
2009-07-08 17:09 . 2009-07-08 17:09 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{EA77F737-0FEA-4800-BD99-D6AF1051C7A9}
2009-07-08 17:09 . 2009-03-12 19:49 2601464 -c--a-w- c:\documents and settings\All Users\Application Data\{EA77F737-0FEA-4800-BD99-D6AF1051C7A9}\Impulse_setup.exe
2009-07-08 17:09 . 2009-07-08 17:09 -------- dc----w- c:\documents and settings\All Users\Application Data\Stardock
2009-07-08 17:09 . 2009-07-08 17:09 -------- d-----w- c:\program files\Stardock
2009-07-08 17:06 . 2009-07-08 17:06 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Local Settings\Application Data\Stardock
2009-07-08 13:56 . 2009-07-08 13:56 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Local Settings\Application Data\Oblivion
2009-07-07 20:27 . 2009-07-07 20:27 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-07-07 17:31 . 2009-07-27 15:54 -------- d-----w- c:\program files\Nobilis
2009-07-07 16:56 . 2009-07-09 08:38 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Local Settings\Application Data\VirtuaTennis2009
2009-07-07 16:47 . 2009-03-09 13:27 453456 ----a-w- c:\windows\system32\d3dx10_41.dll
2009-07-07 16:47 . 2009-03-09 13:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2009-07-07 16:47 . 2009-03-09 13:27 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll
2009-07-07 16:47 . 2009-03-16 12:18 69448 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-07-07 16:47 . 2009-03-16 12:18 517448 ----a-w- c:\windows\system32\XAudio2_4.dll
2009-07-07 16:47 . 2009-03-16 12:18 235352 ----a-w- c:\windows\system32\xactengine3_4.dll
2009-07-07 16:47 . 2009-03-16 12:18 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
2009-07-07 15:57 . 2009-07-07 15:57 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Application Data\DAEMON Tools Pro
2009-07-07 15:55 . 2009-07-07 15:55 126064 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-07-07 15:55 . 2009-07-07 15:55 -------- d-----w- c:\program files\MSBuild
2009-07-07 15:55 . 2009-07-07 15:55 -------- d-----w- c:\windows\system32\XPSViewer
2009-07-07 15:55 . 2009-07-07 15:55 -------- d-----w- c:\program files\Reference Assemblies
2009-07-07 15:38 . 2009-07-31 14:24 -------- d-----w- c:\program files\SEGA
2009-07-07 09:45 . 2009-07-07 15:37 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Application Data\DAEMON Tools Lite
2009-07-07 09:43 . 2009-07-17 01:51 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Application Data\uTorrent
2009-07-07 09:39 . 2009-07-09 22:41 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Contacts
2009-07-07 09:33 . 2009-07-07 09:33 -------- dcsh--w- c:\documents and settings\jeux.BUREAU1\PrivacIE
2009-07-07 09:31 . 2009-07-07 09:31 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Local Settings\Application Data\Symantec
2009-07-07 08:54 . 2009-07-14 11:06 279712 ----a-w- c:\windows\system32\drivers\atksgt.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-31 15:02 . 2009-06-28 00:08 -------- d-----w- c:\program files\Symantec AntiVirus
2009-07-31 11:56 . 2009-07-14 11:34 -------- dc----w- c:\documents and settings\pour les jeux\Application Data\uTorrent
2009-07-30 09:32 . 2009-06-27 15:16 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-14 18:54 . 2009-06-27 17:14 485920 ----a-w- c:\windows\system32\nvudisp.exe
2009-07-14 18:54 . 2009-06-10 16:33 868352 ----a-w- c:\windows\system32\nvapi.dll
2009-07-14 18:54 . 2009-06-10 16:33 7741664 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-07-14 18:54 . 2009-06-10 16:33 5842816 ----a-w- c:\windows\system32\nv4_disp.dll
2009-07-14 18:54 . 2009-06-10 16:33 2189856 ----a-w- c:\windows\system32\nvcuvid.dll
2009-07-14 18:54 . 2009-06-10 16:33 2002944 ----a-w- c:\windows\system32\nvcuda.dll
2009-07-14 18:54 . 2009-06-10 16:33 1706528 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-07-14 18:54 . 2009-06-10 16:33 1597690 ----a-w- c:\windows\system32\nvdata.bin
2009-07-14 18:54 . 2009-06-10 16:33 151552 ----a-w- c:\windows\system32\nvcodins.dll
2009-07-14 18:54 . 2009-06-10 16:33 151552 ----a-w- c:\windows\system32\nvcod.dll
2009-07-14 18:54 . 2009-06-10 16:33 10457088 ----a-w- c:\windows\system32\nvoglnt.dll
2009-07-14 11:34 . 2009-07-14 11:34 8085504 ----a-w- c:\windows\system32\nvdispsr.dll
2009-07-14 11:34 . 2009-07-14 11:34 4923392 ----a-w- c:\windows\system32\nvdisps.dll
2009-07-14 11:34 . 2009-07-14 11:34 4640768 ----a-w- c:\windows\system32\nvgamesr.dll
2009-07-14 11:34 . 2009-07-14 11:34 458752 ----a-w- c:\windows\system32\nvmccssr.dll
2009-07-14 11:34 . 2009-07-14 11:34 3547136 ----a-w- c:\windows\system32\nvgames.dll
2009-07-14 11:34 . 2009-07-14 11:34 2854912 ----a-w- c:\windows\system32\nvmoblsr.dll
2009-07-14 11:34 . 2009-07-14 11:34 188416 ----a-w- c:\windows\system32\nvmccss.dll
2009-07-14 11:34 . 2009-07-14 11:34 168004 ----a-w- c:\windows\system32\nvsvc32.exe
2009-07-14 11:34 . 2009-07-14 11:34 143360 ----a-w- c:\windows\system32\nvcolor.exe
2009-07-14 11:34 . 2009-07-14 11:34 13877248 ----a-w- c:\windows\system32\nvcpl.dll
2009-07-14 11:34 . 2009-07-14 11:34 1286144 ----a-w- c:\windows\system32\nvmobls.dll
2009-07-14 11:34 . 2009-07-14 11:34 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-07-10 22:34 . 2009-06-27 17:33 -------- d-----w- c:\program files\DivX
2009-07-10 11:01 . 2009-07-10 11:01 -------- dc----w- c:\documents and settings\jeux.BUREAU1\Application Data\DivX
2009-07-07 15:56 . 2008-04-14 12:00 81040 ----a-w- c:\windows\system32\perfc00C.dat
2009-07-07 15:56 . 2008-04-14 12:00 501312 ----a-w- c:\windows\system32\perfh00C.dat
2009-07-04 23:11 . 2009-06-27 15:16 -------- d-----w- c:\program files\Fichiers communs\InstallShield
2009-07-03 16:57 . 2008-04-14 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-01 14:41 . 2009-06-30 15:51 -------- d-----w- c:\program files\Game Optimizer Pro
2009-07-01 13:41 . 2009-07-01 13:41 -------- dc----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-07-01 08:34 . 2009-07-01 08:34 -------- d-----w- c:\program files\Microsoft WSE
2009-07-01 08:14 . 2009-07-01 08:14 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-07-01 08:10 . 2009-07-01 08:10 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-06-30 17:28 . 2009-06-30 17:28 -------- d-----w- c:\program files\Bethesda Softworks
2009-06-30 15:51 . 2009-06-30 15:51 -------- d-----w- c:\program files\RAM Defrag
2009-06-30 08:58 . 2009-06-30 08:58 -------- d-----w- c:\program files\Fichiers communs\Futuremark Shared
2009-06-29 12:13 . 2009-06-29 10:24 -------- d-----w- c:\program files\Neuf
2009-06-29 10:59 . 2009-06-29 10:59 -------- d-----w- c:\program files\CCleaner
2009-06-29 10:35 . 2009-06-29 10:35 -------- d-----w- c:\program files\OpenAL
2009-06-29 10:35 . 2009-06-29 10:35 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-06-29 10:35 . 2009-06-29 10:35 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2009-06-29 10:17 . 2009-06-29 10:17 -------- d-----w- c:\program files\VideoLAN
2009-06-29 08:48 . 2009-06-28 22:43 -------- d-----w- c:\program files\SystemRequirementsLab
2009-06-28 23:11 . 2009-06-28 23:11 -------- d-----w- c:\program files\Fichiers communs\i4j_jres
2009-06-28 15:14 . 2009-06-27 15:05 76507 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-28 09:46 . 2009-06-28 09:46 -------- d-----w- c:\program files\MSXML 4.0
2009-06-28 00:47 . 2009-06-28 00:46 -------- d-----w- c:\program files\CyberLink
2009-06-28 00:42 . 2009-06-28 00:42 -------- d-----w- c:\program files\Fichiers communs\LightScribe
2009-06-28 00:42 . 2009-06-28 00:42 -------- d-----w- c:\program files\Fichiers communs\Nero
2009-06-28 00:40 . 2009-06-28 00:39 -------- d-----w- c:\program files\Ahead
2009-06-28 00:39 . 2009-06-28 00:39 -------- d-----w- c:\program files\Fichiers communs\Ahead
2009-06-28 00:29 . 2009-06-28 00:29 -------- d-----w- c:\program files\Microsoft.NET
2009-06-28 00:22 . 2009-06-28 00:20 -------- d-----w- c:\program files\Microsoft Works
2009-06-28 00:14 . 2009-06-28 00:08 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2009-06-28 00:08 . 2009-06-28 00:08 -------- d-----w- c:\program files\Symantec
2009-06-28 00:08 . 2009-06-28 00:08 -------- dc----w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-27 17:32 . 2009-06-27 17:32 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-06-27 17:08 . 2009-06-27 17:08 -------- d-----w- c:\program files\ma-config.com
2009-06-27 15:16 . 2009-06-27 15:16 -------- d-----w- c:\program files\Analog Devices
2009-06-27 15:06 . 2009-06-27 15:06 -------- d-----w- c:\program files\microsoft frontpage
2009-06-27 15:05 . 2009-06-27 15:05 -------- d-----w- c:\program files\Services en ligne
2009-06-27 15:04 . 2009-06-27 15:04 21892 ----a-w- c:\windows\system32\emptyregdb.dat
2009-06-21 06:46 . 2009-06-27 17:14 485920 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-06-16 14:40 . 2008-04-14 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:40 . 2008-04-14 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:10 . 2008-04-14 12:00 1297408 ----a-w- c:\windows\system32\quartz.dll
2009-05-07 15:33 . 2008-04-14 12:00 348672 ----a-w- c:\windows\system32\localspl.dll
2009-07-15 22:31 . 2009-07-24 17:57 137208 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2005-04-18 48752]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2005-05-09 85088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-10 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-14 13877248]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-07-14 86016]
c:\documents and settings\jeux.BUREAU1\Menu D‚marrer\Programmes\D‚marrage\
Xfire.lnk - c:\program files\Xfire\Xfire.exe [2006-2-15 3631752]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMAX"="c:\program files\Analog Devices\SoundMAX\Smax4.exe" /tray
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"20541:TCP"= 20541:TCP:BitComet 20541 TCP
"20541:UDP"= 20541:UDP:BitComet 20541 UDP
"18192:TCP"= 18192:TCP:BitComet 18192 TCP
"18192:UDP"= 18192:UDP:BitComet 18192 UDP
"8318:TCP"= 8318:TCP:BitComet 8318 TCP
"8318:UDP"= 8318:UDP:BitComet 8318 UDP
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [10/07/2009 13:27 55152]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [05/07/2009 15:22 604416]
R3 EraserUtilDrv10910;EraserUtilDrv10910;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilDrv10910.sys [24/07/2009 20:00 101936]
S2 WinSvc;Gestionnaire de mise à jour Winsudate;c:\program files\Winsudate\gibsvc.exe --> c:\program files\Winsudate\gibsvc.exe [?]
S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 18:08 533360]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [29/05/2009 17:13 234864]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\20.tmp --> c:\windows\system32\20.tmp [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [09/05/2005 10:46 127584]
S3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;c:\windows\system32\drivers\WlanBZXP.sys [28/06/2009 18:27 402432]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-31 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:42]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)
ShellIconOverlayIdentifiers-{B9CE503D-03F8-4161-A8A6-C912ADFCF2D4} - (no file)
HKLM-Run-realteks - c:\documents and settings\pour les jeux\Application Data\Google\cqvgl19623160.exe
.
------- Supplementary Scan -------
.
mWindow Title =
uInternet Connection Wizard,ShellNext = "c:\program files\Outlook Express\msimn.exe" //mailurl:mailto:pissavy@jeuxvideo.com
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
FF - ProfilePath - c:\documents and settings\pour les jeux\Application Data\Mozilla\Firefox\Profiles\vsdb5bnv.default\
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "
https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-31 17:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\20.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1715567821-573735546-682003330-1009\Software\SecuROM\License information*]
"datasecu"=hex:9f,2e,17,02,d4,d2,17,79,13,83,1c,4b,7f,82,11,04,84,aa,6a,91,f4,
08,b6,e0,2f,c8,18,6e,42,63,da,48,e4,e7,3c,3b,2c,ab,49,f5,14,f4,72,be,21,44,\
"rkeysecu"=hex:ca,4e,0e,58,8e,a0,7b,25,24,1d,86,c3,51,c6,36,eb
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3964)
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Fichiers communs\Symantec Shared\ccSetMgr.exe
c:\program files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\rundll32.exe
c:\program files\Symantec AntiVirus\DoScan.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Completion time: 2009-07-31 17:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-31 15:05
Pre-Run: 38 023 966 720 octets libres
Post-Run: 38 074 142 720 octets libres
398 --- E O F --- 2009-07-29 01:01