Voici le rapport de Combofix :
ComboFix 09-08-09.04 - Fayna 10/08/2009 17:43.1.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.503.256 [GMT 1:00]
Running from: c:\documents and settings\Fayna\Bureau\CFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090810-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Fayna\Application Data\0200000051186e3d654C.manifest
c:\documents and settings\Fayna\Application Data\0200000051186e3d654O.manifest
c:\documents and settings\Fayna\Application Data\0200000051186e3d654P.manifest
c:\documents and settings\Fayna\Application Data\0200000051186e3d654S.manifest
c:\documents and settings\Maman\Application Data\0200000051186e3d654C.manifest
c:\documents and settings\Maman\Application Data\0200000051186e3d654O.manifest
c:\documents and settings\Maman\Application Data\0200000051186e3d654P.manifest
c:\documents and settings\Maman\Application Data\0200000051186e3d654S.manifest
c:\windows\Installer\1149d9.msi
c:\windows\Installer\168bc.msi
.
((((((((((((((((((((((((( Files Created from 2009-07-10 to 2009-08-10 )))))))))))))))))))))))))))))))
.
2009-08-10 15:34 . 2009-08-10 15:34 -------- d-----w- C:\Genproc
2009-08-10 11:21 . 2009-08-10 11:37 -------- d-----w- C:\ToolBar SD
2009-08-10 10:32 . 2009-08-10 11:44 -------- d-----w- c:\program files\ZHPDiag
2009-08-09 21:30 . 2009-08-09 21:30 3942047 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-03 18:52 . 2009-08-03 18:52 -------- d-----w- c:\program files\Fichiers communs\Remove64C
2009-08-03 18:52 . 2009-08-03 18:52 -------- d-----w- c:\program files\Fichiers communs\PAC207
2009-08-03 18:52 . 2009-08-03 18:52 -------- d-----w- c:\program files\Fichiers communs\RemoveC
2009-08-03 18:52 . 2009-08-03 18:52 -------- d-----w- c:\program files\PC Camer@
2009-08-02 11:44 . 2009-08-02 11:44 -------- d-----w- c:\windows\PixArt
2009-08-02 11:42 . 2009-08-03 18:52 -------- d-----w- c:\windows\PAC207
2009-07-23 16:59 . 2009-07-23 16:59 163 ----a-w- c:\windows\system32\MEX.REG
2009-07-23 14:55 . 2000-08-10 20:23 80880 ----a-w- c:\windows\unvise.exe
2009-07-23 14:54 . 2009-07-23 14:54 -------- d-----w- c:\program files\Macromedia
2009-07-15 21:23 . 2009-07-15 21:23 -------- d-----w- c:\documents and settings\Papa\Application Data\InterVideo
2009-07-15 21:19 . 2009-07-15 21:22 -------- d-----w- c:\documents and settings\Papa\Application Data\dvdcss
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-09 21:32 . 2009-05-28 17:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-09 20:03 . 2008-07-29 09:35 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-09 20:02 . 2008-09-09 00:40 -------- d-----w- c:\program files\MyHeritage
2009-08-09 16:43 . 2009-05-28 13:10 -------- d-----w- c:\program files\trend micro
2009-08-09 16:38 . 2009-03-22 17:44 -------- d-----w- c:\documents and settings\Fayna\Application Data\DMCache
2009-08-09 15:10 . 2008-09-07 21:14 -------- d-----w- c:\documents and settings\Fayna\Application Data\LimeWire
2009-08-09 15:07 . 2009-03-19 18:35 -------- d-----w- c:\documents and settings\Fayna\Application Data\uTorrent
2009-08-03 12:36 . 2009-05-28 17:38 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 12:36 . 2009-05-28 17:38 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-03 11:39 . 2009-05-30 22:20 -------- d-----w- c:\documents and settings\Ines\Application Data\DMCache
2009-08-03 11:27 . 2008-11-21 13:27 -------- d-----w- c:\documents and settings\Ines\Application Data\Skype
2009-08-03 10:18 . 2008-11-21 13:30 -------- d-----w- c:\documents and settings\Ines\Application Data\skypePM
2009-07-28 18:49 . 2008-07-29 09:15 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-07-23 17:04 . 2008-07-29 08:59 1152 --sha-w- C:\2v2jaw3o.sys
2009-07-11 19:13 . 2009-04-23 13:57 67944 ----a-w- c:\documents and settings\Ines\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-07 19:50 . 2009-07-07 19:50 -------- d-----w- c:\documents and settings\Ines\Application Data\Nokia Multimedia Player
2009-07-05 17:56 . 2009-05-30 22:20 -------- d-----w- c:\documents and settings\Ines\Application Data\IDM
2009-06-13 20:56 . 2008-10-24 11:03 67944 ----a-w- c:\documents and settings\Fayna\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-30 22:21 . 2009-05-30 22:21 116144 ----a-w- c:\documents and settings\Ines\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
2009-05-29 14:46 . 2009-05-29 14:46 152576 ----a-w- c:\documents and settings\Fayna\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-20 15:06 . 2004-08-05 12:00 72034 ----a-w- c:\windows\system32\perfc00C.dat
2009-05-20 15:06 . 2004-08-05 12:00 459218 ----a-w- c:\windows\system32\perfh00C.dat
2009-01-04 14:14 . 2009-01-04 14:10 4054016 ----a-w- c:\program files\FLV PlayerRCSetup.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-07-29 185896]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-20 729178]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-12-21 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-12-21 126976]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
"WatchDog"="c:\program files\InterVideo\DVD Check\DVDCheck.exe" [2004-12-08 184320]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-12-14 98304]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-08-24 88363]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DVD Check.lnk - c:\program files\InterVideo\DVD Check\DVDCheck.exe [2008-8-14 184320]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
Photo Express SE Calendar Checker.lnk - c:\program files\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe [2008-8-18 61440]
Watch.lnk - c:\program files\Mustek 1200 UB Plus\Driver\WATCH.exe [2008-10-15 364544]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Documents and Settings\\Ines\\Local Settings\\Application Data\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [29/07/2008 10:11 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [29/07/2008 10:11 20560]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [19/12/2008 18:19 55136]
R2 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 18:08 533360]
S3 PAC207;PC Camer@;c:\windows\system32\drivers\PFC027.SYS [20/11/2006 08:48 506112]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = about:blank
mWindow Title =
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
LSP: c:\windows\system32\idmmbc.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-10 17:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{65596034-b3a8-4fe5-875d-48242cdf171d}]
@Denied: (Full) (Everyone)
"Model"=dword:000000cb
"Therad"=dword:00000015
"MData"=hex(0):cb,9b,ad,ef,27,7d,29,69,f5,02,f0,76,aa,4a,f1,7c,d3,d9,67,7f,6a,
4b,7b,ad,04,7a,b1,b5,76,9b,27,47,dc,ec,cc,3f,48,1f,82,04,13,b1,15,3c,46,79,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):3d,23,13,93,b2,9c,bb,69,5b,1b,1c,90,98,08,7b,88,ef,ae,c9,01,7e,
1a,e4,b5,ff,e1,5f,d3,51,30,4a,83,9e,a7,23,e0,6c,70,d0,b3,00,00,00,00,00,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(916)
c:\windows\system32\idmmbc.dll
.
Completion time: 2009-08-10 18:01
ComboFix-quarantined-files.txt 2009-08-10 17:01
Pre-Run: 1 829 195 776 octets libres
Post-Run: 3 614 240 768 octets libres
160 --- E O F --- 2009-05-20 13:04
L'outil ne m'a pas demandé d'installer "la console de récupération" , est ce normal ? et il n'a pas détecté de Rootkit .
Est ce que je peux réactiver mes défenses même si "le console de récupération" n'est pas installée ?