ComboFix 11-01-31.01 - niko 01/02/2011 0:43.1.1 - x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.511.288 [GMT 1:00]
Lancé depuis: c:\documents and settings\niko\Mes documents\Téléchargements\niko.exe
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-12-28 au 2011-01-31 ))))))))))))))))))))))))))))))))))))
.
2011-01-31 18:30 . 2011-01-31 18:30 -------- d-sh--w- c:\documents and settings\niko\IECompatCache
2011-01-31 18:15 . 2011-01-31 18:15 16856 ----a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2011-01-31 18:15 . 2011-01-31 18:15 719832 ----a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2011-01-31 18:08 . 2011-01-31 18:08 -------- d-sh--w- c:\documents and settings\niko\PrivacIE
2011-01-31 17:31 . 2011-01-31 17:44 -------- d-----w- c:\winnt\system32\NtmsData
2011-01-31 17:22 . 2011-01-31 17:22 -------- d-----w- c:\documents and settings\niko\Application Data\Avira
2011-01-31 17:12 . 2010-12-06 07:48 135096 ----a-w- c:\winnt\system32\drivers\avipbb.sys
2011-01-31 17:12 . 2010-06-17 13:28 45416 ----a-w- c:\winnt\system32\drivers\avgntdd.sys
2011-01-31 17:12 . 2010-06-17 13:28 22360 ----a-w- c:\winnt\system32\drivers\avgntmgr.sys
2011-01-31 17:12 . 2011-01-31 17:12 -------- d-----w- c:\program files\Avira
2011-01-31 17:12 . 2011-01-31 17:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2011-01-31 17:01 . 2011-01-31 17:01 -------- d-----w- c:\documents and settings\niko\Local Settings\Application Data\Temp
2011-01-31 16:52 . 2011-01-31 16:53 -------- d-----w- c:\program files\Fichiers communs\Adobe
2011-01-31 16:44 . 2011-01-31 16:44 -------- d-sh--w- c:\documents and settings\niko\IETldCache
2011-01-31 15:44 . 2011-01-31 15:44 -------- d--h--w- c:\winnt\msdownld.tmp
2011-01-31 15:43 . 2009-01-07 17:21 26144 ----a-w- c:\winnt\system32\spupdsvc.exe
2011-01-31 15:42 . 2011-01-31 15:44 -------- dc-h--w- c:\winnt\ie8
2011-01-31 15:42 . 2011-01-31 15:43 -------- d-----w- c:\winnt\system32\fr-FR
2011-01-31 14:41 . 2011-01-31 14:40 73728 ----a-w- c:\winnt\system32\javacpl.cpl
2011-01-31 14:41 . 2011-01-31 14:40 472808 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-01-31 14:41 . 2011-01-31 14:40 472808 ----a-w- c:\winnt\system32\deployJava1.dll
2011-01-31 11:58 . 2011-01-31 11:58 -------- d-----w- c:\winnt\system32\wbem\Repository
2011-01-17 16:28 . 2011-01-31 22:45 -------- d-----w- c:\program files\JDownloader
2011-01-15 11:17 . 2011-01-15 11:17 -------- d-----w- c:\documents and settings\niko\Local Settings\Application Data\Ahead
2011-01-15 11:16 . 2011-01-15 11:16 -------- d-----w- c:\documents and settings\niko\Application Data\Nero
2011-01-15 11:11 . 2011-01-15 11:15 -------- d-----w- c:\program files\Fichiers communs\Nero
2011-01-15 11:11 . 2011-01-15 11:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2011-01-15 11:11 . 2011-01-15 11:11 -------- d-----w- c:\program files\Nero
2011-01-15 11:09 . 2005-01-28 14:22 827392 ----a-w- c:\program files\Windows Media Player\wmsetsdk.exe
2011-01-15 11:09 . 2004-08-11 00:45 47616 ----a-w- c:\program files\Windows Media Player\msoobci.dll
2011-01-14 23:03 . 2001-03-27 15:38 11212 ----a-w- c:\winnt\system32\drivers\ElbyCDIO.sys
2011-01-14 23:03 . 2011-01-14 23:03 -------- d-----w- c:\program files\Elaborate Bytes
2011-01-08 19:43 . 2011-01-08 19:43 -------- d-----w- c:\documents and settings\niko\Local Settings\Application Data\Identities
2011-01-07 19:11 . 2011-01-07 19:11 -------- d-----w- c:\program files\Audacity
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-20 17:09 . 2010-12-23 21:11 38224 ----a-w- c:\winnt\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2010-12-23 21:11 20952 ----a-w- c:\winnt\system32\drivers\mbam.sys
2010-12-11 08:00 . 2010-12-23 21:32 108032 ----a-w- c:\winnt\system32\ff_vfw.dll
2010-12-07 18:40 . 2010-12-23 21:32 183808 ----a-w- c:\winnt\system32\xvidvfw.dll
2010-12-07 18:22 . 2010-12-23 21:32 810496 ----a-w- c:\winnt\system32\xvidcore.dll
2010-12-06 07:48 . 2010-12-23 20:44 61960 ----a-w- c:\winnt\system32\drivers\avgntflt.sys
2010-11-03 19:08 . 2010-12-23 21:32 237568 ----a-w- c:\winnt\system32\yv12vfw.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Fichiers communs\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-12-06 281768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\winnt\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [31/01/2011 18:12 135336]
.
.
------- Examen supplémentaire -------
.
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\niko\Application Data\Mozilla\Firefox\Profiles\zzk4tq86.default\
FF - prefs.js: browser.startup.homepage - hxxp://fr.msn.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-02-01 00:48
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2011-02-01 00:51:03
ComboFix-quarantined-files.txt 2011-01-31 23:51
Avant-CF: 5 348 818 944 octets libres
Après-CF: 5 345 652 736 octets libres
- - End Of File - - 0D6E17D3F7D5040F60BAB001ADC12CA2