Hi,
I posted a log last Sunday on a french site but did not get any answer since.
So here is the Combo Fix Log.
ComboFix 08-09-22.05 - Propri‚taire 2008-09-24 0:11:07.2 - NTFSx86
Lancé depuis: C:\Documents and Settings\Propri‚taire\Bureau\ComboFix.exe
Commutateurs utilisés :: C:\Documents and Settings\Propri‚taire\Bureau\CFScript.txt
* Un nouveau point de restauration a été créé
FILE ::
C:\WINDOWS\system32\imquqgiy.ini
C:\WINDOWS\system32\qhmbvvui.ini
C:\WINDOWS\system32\RCdJRqss.ini
C:\WINDOWS\system32\RCdJRqss.ini2
C:\WINDOWS\system32\sjpxmopc.ini
C:\WINDOWS\system32\yfjulxgf.ini
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DOCUME~1\ALLUSE~1\APPLIC~1\flag ace stupid data
C:\Program Files\BoontyGames
C:\Program Files\BoontyGames\Components\bureau.url
C:\Program Files\BoontyGames\Components\Joystick.ico
C:\Program Files\BoontyGames\Components\start.url
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\BALLOFF1.BMP
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\BALLOFF2.BMP
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\BALLOFF3.BMP
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\BALLON1.BMP
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\BALLON2.BMP
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\BALLON3.BMP
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\BOMBOFF1.BMP
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\BOMBOFF2.BMP
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\BOMBOFF3.BMP
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\BOMBON1.BMP
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\BOMBON2.BMP
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\BOMBON3.BMP
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\circularoff1.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\circularoff2.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\circularoff3.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\circularon1.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\circularon2.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\circularon3.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\CURSOR1.BMP
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\CURSOR2.BMP
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\figureoff1.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\figureoff2.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\figureoff3.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\figureon1.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\figureon2.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\figureon3.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\stat2line1.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\stat2line2.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\stat2line3.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\stat2linefull1.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\stat2linefull2.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\stat2linefull3.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\statline1.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\statline2.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\statline3.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\statlinefull1.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\statlinefull2.bmp
C:\Program Files\BoontyGames\Tetris4000\BITMAPS\statlinefull3.bmp
C:\Program Files\BoontyGames\Tetris4000\config.dat
C:\Program Files\BoontyGames\Tetris4000\CONV.BAT
C:\Program Files\BoontyGames\Tetris4000\FONTS\font1.bmp
C:\Program Files\BoontyGames\Tetris4000\FONTS\Font1.jpg
C:\Program Files\BoontyGames\Tetris4000\FONTS\font2.bmp
C:\Program Files\BoontyGames\Tetris4000\FONTS\Font2.jpg
C:\Program Files\BoontyGames\Tetris4000\FONTS\font3.bmp
C:\Program Files\BoontyGames\Tetris4000\FONTS\Font3.jpg
C:\Program Files\BoontyGames\Tetris4000\FONTS\font4.bmp
C:\Program Files\BoontyGames\Tetris4000\FONTS\Font4.jpg
C:\Program Files\BoontyGames\Tetris4000\FONTS\font5.bmp
C:\Program Files\BoontyGames\Tetris4000\FONTS\Font5.jpg
C:\Program Files\BoontyGames\Tetris4000\GLOBAL.DAT
C:\Program Files\BoontyGames\Tetris4000\History.txt
C:\Program Files\BoontyGames\Tetris4000\ICON.ICO
C:\Program Files\BoontyGames\Tetris4000\ICONS\ICON.ICO
C:\Program Files\BoontyGames\Tetris4000\ICONS\SETUP.ICO
C:\Program Files\BoontyGames\Tetris4000\license.txt
C:\Program Files\BoontyGames\Tetris4000\LOCAL.DAT
C:\Program Files\BoontyGames\Tetris4000\LOGO.BMP
C:\Program Files\BoontyGames\Tetris4000\mail\ICON.ICO
C:\Program Files\BoontyGames\Tetris4000\mail\icon1.ico
C:\Program Files\BoontyGames\Tetris4000\mail\icon10.ico
C:\Program Files\BoontyGames\Tetris4000\mail\icon2.ico
C:\Program Files\BoontyGames\Tetris4000\mail\icon3.ico
C:\Program Files\BoontyGames\Tetris4000\mail\icon4.ico
C:\Program Files\BoontyGames\Tetris4000\mail\icon5.ico
C:\Program Files\BoontyGames\Tetris4000\mail\icon6.ico
C:\Program Files\BoontyGames\Tetris4000\mail\icon7.ico
C:\Program Files\BoontyGames\Tetris4000\mail\icon8.ico
C:\Program Files\BoontyGames\Tetris4000\mail\icon9.ico
C:\Program Files\BoontyGames\Tetris4000\mail\main.ico
C:\Program Files\BoontyGames\Tetris4000\mail\text1.txt
C:\Program Files\BoontyGames\Tetris4000\mail\text10.txt
C:\Program Files\BoontyGames\Tetris4000\mail\text2.txt
C:\Program Files\BoontyGames\Tetris4000\mail\text3.txt
C:\Program Files\BoontyGames\Tetris4000\mail\text4.txt
C:\Program Files\BoontyGames\Tetris4000\mail\text5.txt
C:\Program Files\BoontyGames\Tetris4000\mail\text6.txt
C:\Program Files\BoontyGames\Tetris4000\mail\text7.txt
C:\Program Files\BoontyGames\Tetris4000\mail\text8.txt
C:\Program Files\BoontyGames\Tetris4000\mail\text9.txt
C:\Program Files\BoontyGames\Tetris4000\mailsetup.ini
C:\Program Files\BoontyGames\Tetris4000\MAIN.CFG
C:\Program Files\BoontyGames\Tetris4000\MODELS\BOMB.X
C:\Program Files\BoontyGames\Tetris4000\MODELS\bounce.x
C:\Program Files\BoontyGames\Tetris4000\MODELS\BOX1.X
C:\Program Files\BoontyGames\Tetris4000\MODELS\BOX2.X
C:\Program Files\BoontyGames\Tetris4000\MODELS\BOX3.X
C:\Program Files\BoontyGames\Tetris4000\MODELS\CIRCULAR.X
C:\Program Files\BoontyGames\Tetris4000\MODELS\FITIL.X
C:\Program Files\BoontyGames\Tetris4000\MODELS\FRAME.X
C:\Program Files\BoontyGames\Tetris4000\MUSIC\MUSIC1.MID
C:\Program Files\BoontyGames\Tetris4000\MUSIC\MUSIC10.MID
C:\Program Files\BoontyGames\Tetris4000\MUSIC\MUSIC11.MID
C:\Program Files\BoontyGames\Tetris4000\MUSIC\MUSIC2.MID
C:\Program Files\BoontyGames\Tetris4000\MUSIC\MUSIC3.MID
C:\Program Files\BoontyGames\Tetris4000\MUSIC\MUSIC4.MID
C:\Program Files\BoontyGames\Tetris4000\MUSIC\MUSIC5.MID
C:\Program Files\BoontyGames\Tetris4000\MUSIC\MUSIC6.MID
C:\Program Files\BoontyGames\Tetris4000\MUSIC\MUSIC7.MID
C:\Program Files\BoontyGames\Tetris4000\MUSIC\MUSIC8.MID
C:\Program Files\BoontyGames\Tetris4000\MUSIC\MUSIC9.MID
C:\Program Files\BoontyGames\Tetris4000\other.ini
C:\Program Files\BoontyGames\Tetris4000\PLAYLIST.CFG
C:\Program Files\BoontyGames\Tetris4000\SETUP.EXE
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\bombexplode.wav
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\bombprepare.wav
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\bounce1.WAV
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\bounce2.WAV
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\bounce3.WAV
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\Boxhit.wav
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\DisplayBox.WAV
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\DROP.WAV
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\earthstrike.wav
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\exbounce.WAV
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\Explode.WAV
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\GAMEOVER.WAV
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\menuclick.wav
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\menuscroll.wav
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\menuupdown.wav
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\nextlevel.WAV
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\PREPARE.WAV
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\TIMER.WAV
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\VOICE1.WAV
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\VOICE2.WAV
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\VOICE3.WAV
C:\Program Files\BoontyGames\Tetris4000\SOUNDS\VOICE4.WAV
C:\Program Files\BoontyGames\Tetris4000\Tell.exe
C:\Program Files\BoontyGames\Tetris4000\Tetris4000.exe
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\bkgnd.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\BKGND.JPG
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\bkgnd2.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\BKGND2.JPG
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\bkgnd3.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\BKGND3.JPG
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\bkgnd4.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\BKGND4.JPG
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\bkgnd5.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\BKGND5.JPG
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\bkgnd6.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\BKGND6.JPG
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\bounce.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\CONV.EXE
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\dynamics1.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\FF0.BMP
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\FF1.BMP
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\FF2.BMP
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\FF3.BMP
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\FF4.BMP
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\FF5.BMP
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\FF6.BMP
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\FF7.BMP
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\FF8.BMP
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\FF9.BMP
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\FrameBack.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\intro.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\intro.JPG
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\LINE.BMP
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\loadingline.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\loadingline1.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\loadingline2.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\LONGLINE.BMP
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\MenuBkgnd.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\MenuLight.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\nag1.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\NAG1.JPG
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\nag2.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\NAG2.JPG
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\nag3.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\NAG3.JPG
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\nag4.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\NAG4.JPG
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\scrollbar.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\SCROLLER.BMP
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\t11.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\T11.JPG
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\t12.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\T12.JPG
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\t13.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\T13.JPG
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\t14.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\T14.JPG
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\t15.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\T15.JPG
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\TEXTURE2.BMP
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\Thumbs.db
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\title.bmp
C:\Program Files\BoontyGames\Tetris4000\TEXTURES\TITLE.JPG
C:\Program Files\BoontyGames\Tetris4000\unins000.dat
C:\Program Files\BoontyGames\Tetris4000\unins000.exe
C:\Program Files\BoontyGames\Tetris4000\uninstal.exe
C:\Program Files\BoontyGames\Tetris4000\uninstal.ini
C:\Program Files\BoontyGames\Tetris4000\Updater.exe
C:\Program Files\BoontyGames\Tetris4000\Version.dat
C:\Program Files\BoontyGames\Tetris4000\website.url
C:\WINDOWS\system32\imquqgiy.ini
C:\WINDOWS\system32\qhmbvvui.ini
C:\WINDOWS\system32\RCdJRqss.ini
C:\WINDOWS\system32\RCdJRqss.ini2
C:\WINDOWS\system32\sjpxmopc.ini
C:\WINDOWS\system32\yfjulxgf.ini
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-08-23 au 2008-09-23 ))))))))))))))))))))))))))))))))))))
.
2008-09-23 23:02 . 2008-09-23 23:04 <REP> d-------- C:\WINDOWS\LastGood
2008-09-23 21:38 . 2008-09-23 21:51 <REP> d-------- C:\Lop SD
2008-09-21 19:03 . 2008-09-21 19:03 <REP> d-------- C:\Program Files\Trend Micro
2008-09-21 14:28 . 2008-09-21 14:28 3,748 --a------ C:\WINDOWS\system32\tmp.reg
2008-09-21 14:24 . 2008-09-21 17:31 <REP> d-------- C:\Program Files\Navilog1
2008-09-21 14:24 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-09-21 14:24 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-09-21 14:24 . 2008-09-08 23:38 88,576 --a------ C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-09-21 14:24 . 2008-09-02 16:51 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-09-21 14:24 . 2008-09-19 12:26 82,944 --a------ C:\WINDOWS\system32\o4Patch.exe
2008-09-21 14:24 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-09-21 14:24 . 2008-09-19 12:26 82,944 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-09-21 14:24 . 2008-08-18 12:19 82,432 --a------ C:\WINDOWS\system32\404Fix.exe
2008-09-21 14:24 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-09-21 14:24 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-09-21 13:43 . 2008-09-21 13:43 <REP> d-------- C:\VundoFix Backups
2008-09-21 11:17 . 2008-09-21 11:17 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-21 11:17 . <REP> C:\Documents and Settings\Propriétaire\Application Data\Malwarebytes
2008-09-21 11:17 . <REP> C:\Documents and Settings\Propriétaire\Application Data\Malwarebytes
2008-09-21 11:17 . 2008-09-21 11:17 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-21 11:17 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-21 11:17 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-21 02:37 . 2008-09-21 02:37 850 --a------ C:\WINDOWS\system32\ProductTweaks.xml
2008-09-21 02:37 . 2008-09-21 02:37 385 --a------ C:\WINDOWS\system32\user_gensett.xml
2008-09-21 02:24 . 2008-09-21 02:24 <REP> d-------- C:\WINDOWS\system32\logs
2008-09-21 02:24 . <REP> C:\Documents and Settings\Propriétaire\Application Data\BitDefender
2008-09-21 02:24 . <REP> C:\Documents and Settings\Propriétaire\Application Data\BitDefender
2008-09-21 02:23 . 2008-09-21 02:23 <REP> d-------- C:\Program Files\BitDefender
2008-09-21 02:23 . 2008-09-21 02:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
2008-09-21 02:17 . 2008-09-21 02:23 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
2008-09-21 02:14 . <REP> C:\Documents and Settings\Propriétaire\Application Data\Flock
2008-09-21 02:14 . <REP> C:\Documents and Settings\Propriétaire\Application Data\Flock
2008-09-21 02:13 . 2008-09-21 02:18 <REP> d-------- C:\Program Files\Flock
2008-09-20 16:25 . 2008-09-20 19:44 <REP> d-------- C:\Program Files\a-squared Free
2008-09-20 16:21 . 2008-09-20 16:21 <REP> d-------- C:\Program Files\AxBx
2008-09-20 00:49 . 2008-09-20 00:49 <REP> d-------- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2008-09-15 09:29 . 2000-07-15 05:00 101,888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL
2008-09-15 09:29 . 2001-03-28 22:02 89,088 --a------ C:\WINDOWS\system32\ProgressBar4.ocx
2008-09-15 09:29 . 1999-01-26 19:36 11,012 --a------ C:\WINDOWS\system32\threadapi.tlb
2008-09-15 09:28 . <REP> C:\Documents and Settings\Propriétaire\Application Data\Simply Super Software
2008-09-15 09:28 . <REP> C:\Documents and Settings\Propriétaire\Application Data\Simply Super Software
2008-09-15 09:26 . 2003-11-19 15:59 512,688 --a------ C:\WINDOWS\system32\XceedCry.dll
2008-09-15 09:26 . 2004-05-11 11:56 423,784 --a------ C:\WINDOWS\system32\XceedBkp.dll
2008-09-15 09:26 . 2004-02-05 22:53 389,120 --a------ C:\WINDOWS\system32\ACTSKN43.OCX
2008-09-15 09:26 . 2004-01-09 12:54 188,416 --a------ C:\WINDOWS\system32\actsplash.ocx
2008-09-14 23:25 . 2003-01-02 14:38 <REP> d-a------ C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\WINDOWS
2008-09-14 23:25 . 2003-01-02 13:38 <REP> d-a------ C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Voisinage r‚seau
2008-09-14 23:25 . 2003-01-02 13:38 <REP> d-a------ C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Voisinage d'impression
2008-09-14 23:25 . 2008-09-14 23:25 <REP> d---s---- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\UserData
2008-09-14 23:25 . 2008-09-14 23:25 <REP> d-a------ C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\ModŠles
2008-09-14 23:25 . 2008-09-20 16:25 <REP> d-a------ C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Mes documents
2008-09-14 23:25 . 2007-03-04 06:16 <REP> d-a------ C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Menu D‚marrer
2008-09-14 23:25 . 2007-03-04 06:16 <REP> d-a------ C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Favoris
2008-09-14 23:25 . 2008-09-20 16:24 <REP> d-a------ C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Bureau
2008-09-14 23:25 . 2003-09-19 16:35 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\VERITAS
2008-09-14 23:25 . 2006-12-13 00:59 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\TransRender
2008-09-14 23:25 . 2006-12-13 23:43 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\Temporary
2008-09-14 23:25 . 2006-05-06 22:34 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\TaoUSign
2008-09-14 23:25 . 2003-01-01 18:42 <REP> d-a------ C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\Symantec
2008-09-14 23:25 . 2004-05-10 23:01 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\SpamPal
2008-09-14 23:25 . 2003-01-02 14:36 <REP> d-a------ C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\Sonic
2008-09-14 23:25 . 2003-12-09 23:10 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\ScanSoft
2008-09-14 23:25 . 2006-12-13 00:56 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\Samsung
2008-09-14 23:25 . 2003-01-02 14:44 <REP> d-a------ C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\SampleView
2008-09-14 23:25 . 2006-01-03 10:18 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\PC Tools
2008-09-14 23:25 . 2004-03-18 22:01 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\Nikon
2008-09-14 23:25 . 2006-02-04 20:17 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\MSNInstaller
2008-09-14 23:25 . 2006-01-15 17:32 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\MSN6
2008-09-14 23:25 . 2005-02-26 11:49 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\Microsoft Web Folders
2008-09-14 23:25 . 2004-01-14 00:12 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\Leadertech
2008-09-14 23:25 . 2006-12-30 19:01 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\Lavasoft
2008-09-14 23:25 . 2006-01-07 01:56 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\Jetico Personal Firewall
2008-09-14 23:25 . 2003-10-20 09:19 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\InterVideo
2008-09-14 23:25 . 2003-01-02 14:37 <REP> d-a------ C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\InterTrust
2008-09-14 23:25 . 2007-01-07 19:54 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\ESTsoft
2008-09-14 23:25 . 2003-09-23 15:06 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\Copernic
2008-09-14 23:25 . 2006-12-13 23:55 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\ConvertTemp
2008-09-14 23:25 . 2003-12-09 23:07 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\Canon
2008-09-14 23:25 . 2006-01-06 10:02 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\AVG7
2008-09-14 23:25 . 2006-07-12 21:54 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\ArcSoft
2008-09-14 23:25 . 2008-09-04 00:28 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\Apple Computer
2008-09-14 23:25 . 2006-01-06 00:31 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\Ahead
2008-09-14 23:25 . 2006-06-29 07:17 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\AdobeUM
2008-09-14 23:25 . 2006-08-17 21:34 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\Application Data\AdobeAUM
2008-09-14 23:25 . 2006-01-14 20:21 24,192 --a------ C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\usbsermptxp.sys
2008-09-14 23:25 . 2006-01-14 20:21 22,768 --a------ C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ\usbsermpt.sys
2008-09-14 23:24 . 2008-09-19 22:55 <REP> d-------- C:\Documents and Settings\Administrateur.NOM-K5WGBUATAIQ
2008-09-14 22:39 . <REP> C:\Documents and Settings\Propriétaire\Application Data\TmpRecentIcons
2008-09-14 22:39 . <REP> C:\Documents and Settings\Propriétaire\Application Data\TmpRecentIcons
2008-09-14 22:39 . 2008-09-12 22:03 151,552 --a------ C:\WINDOWS\eeqb.exe
2008-09-10 22:38 . <REP> C:\Documents and Settings\Propriétaire\Application Data\CopyTrans
2008-09-10 22:38 . <REP> C:\Documents and Settings\Propriétaire\Application Data\CopyTrans
2008-09-10 22:36 . 2008-09-10 22:36 <REP> d-------- C:\Program Files\WindSolutions
2008-09-10 22:36 . <REP> C:\Documents and Settings\Propriétaire\Application Data\CopyTransControlCenter
2008-09-10 22:36 . <REP> C:\Documents and Settings\Propriétaire\Application Data\CopyTransControlCenter
2008-09-10 22:36 . 2008-09-10 22:37 <REP> d-------- C:\Documents and Settings\All Users\Application Data\CopyTransControlCenter
2008-09-09 23:43 . 2008-09-09 23:43 <REP> d-------- C:\Program Files\NCH Swift Sound
2008-09-09 23:19 . 2008-09-09 23:19 <REP> d-------- C:\Program Files\Xi
2008-09-09 23:00 . <REP> C:\Documents and Settings\Propriétaire\Application Data\streamripper
2008-09-09 23:00 . <REP> C:\Documents and Settings\Propriétaire\Application Data\streamripper
2008-09-09 22:49 . 2008-09-09 23:05 <REP> d-------- C:\Program Files\Streamripper
2008-09-04 01:05 . 2008-09-04 01:05 <REP> d-------- C:\Program Files\iPod
2008-09-04 01:04 . 2008-09-04 01:05 <REP> d-------- C:\Program Files\iTunes
2008-09-04 01:04 . 2008-09-04 01:04 <REP> d-------- C:\Program Files\Bonjour
2008-09-04 01:00 . 2008-09-04 01:00 <REP> d-------- C:\Program Files\Apple Software Update
2008-09-04 01:00 . 2008-07-22 20:32 32,000 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
2008-09-04 00:59 . 2008-09-04 00:59 <REP> d-------- C:\Program Files\Fichiers communs\Apple
2008-09-04 00:59 . 2008-09-04 00:59 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-09-04 00:49 . 2008-09-04 00:49 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-04 00:49 . 2008-09-04 00:49 1,409 --a------ C:\WINDOWS\QTFont.for
2008-09-04 00:46 . 2008-09-06 18:54 <REP> d-------- C:\Program Files\QuickTime
2008-09-04 00:15 . 2008-09-23 23:00 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-01 17:37 . 2008-09-01 17:37 <REP> d-------- C:\Program Files\Iomega
2008-08-27 23:16 . 2008-08-27 23:16 <REP> d-------- C:\WINDOWS\system32\fr
2008-08-27 23:16 . 2008-08-27 23:16 <REP> d-------- C:\WINDOWS\l2schemas
2008-08-27 22:38 . 2008-08-27 22:38 <REP> d-------- C:\Program Files\Windows Installer Clean Up
2008-08-27 22:37 . 2008-08-27 22:37 <REP> d-------- C:\Program Files\MSECACHE
2008-08-26 01:38 . 2008-04-14 04:33 1,306,624 --------- C:\WINDOWS\system32\msxml6.dll
2008-08-26 01:37 . 2008-04-14 04:31 290,816 -----c--- C:\WINDOWS\system32\dllcache\l3codeca.acm
2008-08-26 01:36 . 2008-04-14 04:33 651,264 --------- C:\WINDOWS\system32\dot3ui.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-23 20:58 --------- d---a-w C:\Program Files\Fichiers communs\Symantec Shared
2008-09-20 17:44 --------- d-----w C:\Program Files\StreamCast
2008-09-20 07:20 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\RegClean
2008-09-20 07:20 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\RegClean
2008-09-19 22:49 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-19 22:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-14 20:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-09-10 23:18 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Apple Computer
2008-09-10 23:18 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Apple Computer
2008-09-06 17:26 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Mozilla
2008-09-06 17:26 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Mozilla
2008-09-03 22:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-03 22:28 --------- d-----w C:\Documents and Settings\Philippe\Application Data\Apple Computer
2008-08-29 09:35 97,928 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-27 21:58 --------- d-----w C:\Program Files\MSN Messenger
2008-08-27 20:38 --------- d---a-w C:\Documents and Settings\Propriétaire\Application Data\Microsoft
2008-08-27 20:38 --------- d---a-w C:\Documents and Settings\Propriétaire\Application Data\Microsoft
2008-08-19 07:19 --------- d---a-w C:\Program Files\Easy Internet signup
2008-08-18 21:17 --------- d-----w C:\Program Files\RegCleaner
2008-08-18 20:27 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Samsung
2008-08-18 20:27 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Samsung
2008-08-18 20:26 --------- d-----w C:\Program Files\Samsung
2008-08-14 16:54 102,208 ----a-w C:\WINDOWS\system32\drivers\bdfndisf.sys
2008-08-12 16:40 228,672 ----a-w C:\WINDOWS\system32\drivers\bdfsfltr.sys
2008-08-12 16:40 108,864 ----a-w C:\WINDOWS\system32\drivers\bdfm.sys
2008-07-28 21:09 --------- d-----w C:\Program Files\BitLord
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-04 06:32 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-06-24 16:44 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:28 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2007-03-11 18:23 262,144 ----a-w C:\Documents and Settings\PropriÚtaire\NTUSER.DAT
2007-03-11 18:23 262,144 ----a-w C:\Documents and Settings\PropriÚtaire\NTUSER.DAT
2006-01-14 18:21 24,192 ----a-w C:\WINDOWS\system32\config\systemprofile\usbsermptxp.sys
2006-01-14 18:21 24,192 ----a-w C:\Documents and Settings\Propriétaire\usbsermptxp.sys
2006-01-14 18:21 24,192 ----a-w C:\Documents and Settings\Philippe\usbsermptxp.sys
2006-01-14 18:21 24,192 ----a-w C:\Documents and Settings\Default User\usbsermptxp.sys
2006-01-14 18:21 22,768 ----a-w C:\WINDOWS\system32\config\systemprofile\usbsermpt.sys
2006-01-14 18:21 22,768 ----a-w C:\Documents and Settings\Propriétaire\usbsermpt.sys
2006-01-14 18:21 22,768 ----a-w C:\Documents and Settings\Philippe\usbsermpt.sys
2006-01-14 18:21 22,768 ----a-w C:\Documents and Settings\Default User\usbsermpt.sys
2006-01-12 23:03 29,968 ----a-w C:\Documents and Settings\Propriétaire\Application Data\GDIPFONTCACHEV1.DAT
2006-01-12 23:03 29,968 ----a-w C:\Documents and Settings\Propriétaire\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((( snapshot@2008-09-23_23.15.13.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-07-30 17:19:32 325,976 ----a-w C:\WINDOWS\LastGood\system32\wucltui.dll
+ 2007-07-30 17:18:40 33,624 ----a-w C:\WINDOWS\LastGood\system32\wups.dll
+ 2007-07-30 17:19:12 43,352 ----a-w C:\WINDOWS\LastGood\system32\wups2.dll
+ 2007-07-30 17:19:46 203,096 ----a-w C:\WINDOWS\LastGood\system32\wuweb.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"RegistryMechanic"="C:\Program Files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]
"NVIEW"="nview.dll" [2003-03-04 C:\WINDOWS\system32\nview.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-03-04 4595712]
"StorageGuard"="C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-12 114688]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-02-28 315392]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-08-01 81920]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"AppleSyncNotifier"="C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"NAV CfgWiz"="c:\PROGRA~1\NORTON~1\Cfgwiz.exe" [2002-11-26 496784]
"ccRegVfy"="c:\Program Files\Fichiers communs\Symantec Shared\ccRegVfy.exe" [2002-11-20 59056]
"ccApp"="c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2002-11-20 54960]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-29 1235736]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-12 61440]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe" [2008-09-21 716800]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe" [2008-08-10 69632]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-05 C:\WINDOWS\system32\Ati2mdxx.exe]
"nwiz"="nwiz.exe" [2003-03-04 C:\WINDOWS\system32\nwiz.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-04 C:\WINDOWS\ALCXMNTR.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll jnwlox.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
--a------ 1998-05-08 00:04 52736 c:\WINDOWS\system\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-05-16 22:13 185896 C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIEW]
--a------ 2003-03-04 02:44 831557 C:\WINDOWS\system32\nview.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\BitLord\\BitLord.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Tâches planifiées'
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-24 00:28:02
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
**************************************************************************
.
Heure de fin: 2008-09-24 0:38:20
ComboFix-quarantined-files.txt 2008-09-23 22:36:33
ComboFix2.txt 2008-09-23 21:18:24
Avant-CF: 22ÿ257ÿ725ÿ440 octets libres
Après-CF: 22,236,336,128 octets libres
473 --- E O F --- 2008-09-11 21:13:58
I scanned wuapi.dll and wuapi.dll.mui as I could not find the wuapi.dll.wusetup. Both files seems to be clean as only Fortinet found them suspicious.
Sorry could not manage to find the clipboard and paste it.
Thanks.