voici le rapport combofix:
ComboFix 09-09-14.02 - ordinateur 16/09/2009 14:11.1.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.33.1036.18.958.305 [GMT 2:00]
Lancé depuis: c:\users\ordinateur\Desktop\antitibs.exe
AV: AntiVirus Firewall 7.03 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: AntiVirus Firewall 7.03 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
SP: AntiVirus Firewall 7.03 *disabled* (Updated) {0651C4B0-1D7E-4682-B965-2E9523C483A5}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3256058986-3725062286-1355632027-500
c:\$recycle.bin\S-1-5-21-3727031232-2403248329-2125757128-500
c:\program files\Mozilla Firefox\plc4.dll
c:\programdata\Microsoft\Network\Downloader\qmgr0.dat
c:\programdata\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Installer\761212.msi
----- BITS: Il y a peut-être des sites infectés -----
hxxp://download.yimg.com
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-08-16 au 2009-09-16 ))))))))))))))))))))))))))))))))))))
.
2009-09-16 12:22 . 2009-09-16 12:22 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-16 11:36 . 2009-09-16 11:55 -------- d-----w- C:\ToolBar SD
2009-09-15 22:17 . 2009-09-16 00:49 -------- d-----w- C:\GenProc
2009-09-15 22:09 . 2009-09-15 22:09 -------- d-----w- c:\program files\Common Files\Sonic Shared
2009-09-09 17:36 . 2009-09-09 17:36 -------- d-----w- c:\users\ordinateur\AppData\Roaming\Keynote Systems
2009-09-09 09:03 . 2009-07-11 19:32 297984 ----a-w- c:\windows\system32\wlansec.dll
2009-09-09 09:03 . 2009-07-11 19:26 123904 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-09 09:03 . 2009-07-11 19:32 502272 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-09 09:03 . 2009-07-11 19:32 290816 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-09 09:03 . 2009-07-11 19:32 67584 ----a-w- c:\windows\system32\wlanhlp.dll
2009-09-09 09:03 . 2009-07-11 19:32 47104 ----a-w- c:\windows\system32\wlanapi.dll
2009-09-09 09:03 . 2009-08-14 14:24 813568 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-09 09:03 . 2009-08-14 17:16 213592 ----a-w- c:\windows\system32\drivers\netio.sys
2009-09-09 09:03 . 2009-08-14 16:40 103936 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-09 09:03 . 2009-08-14 16:42 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2009-09-09 09:02 . 2009-08-14 14:25 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-09 09:02 . 2009-08-14 14:25 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-09 09:02 . 2009-08-14 14:23 22016 ----a-w- c:\windows\system32\netiougc.exe
2009-09-09 09:02 . 2009-08-14 14:25 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-09 09:02 . 2009-08-14 14:25 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-09 09:02 . 2009-08-14 14:25 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-09 09:02 . 2009-08-14 14:25 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-09 09:02 . 2009-08-14 14:25 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-09 09:02 . 2009-08-14 16:40 15360 ----a-w- c:\windows\system32\netevent.dll
2009-09-09 09:00 . 2009-06-10 12:07 2855424 ----a-w- c:\windows\system32\mf.dll
2009-09-09 09:00 . 2009-06-10 12:07 98816 ----a-w- c:\windows\system32\mfps.dll
2009-09-09 09:00 . 2009-06-10 10:14 52736 ----a-w- c:\windows\system32\rrinstaller.exe
2009-09-09 09:00 . 2009-06-10 10:15 24576 ----a-w- c:\windows\system32\mfpmp.exe
2009-09-09 09:00 . 2009-06-10 08:50 2048 ----a-w- c:\windows\system32\mferror.dll
2009-09-02 19:13 . 2009-08-29 03:41 1686528 ----a-w- c:\windows\system32\gameux.dll
2009-09-02 19:13 . 2009-08-29 03:40 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-02 19:13 . 2009-08-28 23:31 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-31 12:39 . 2009-08-31 12:39 -------- d-----w- c:\users\ordinateur\AppData\Roaming\Roxio
2009-08-31 10:30 . 2009-08-31 10:33 -------- d-----w- c:\users\ordinateur\AppData\Roaming\HpUpdate
2009-08-31 10:29 . 2009-08-31 10:29 -------- d-----w- c:\windows\Hewlett-Packard
2009-08-26 22:59 . 2009-06-22 08:44 2048 ----a-w- c:\windows\system32\tzres.dll
2009-08-25 09:03 . 2009-08-25 09:03 -------- d-----w- C:\fb7b6d59a7b1bf85a3aa9689
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-16 12:21 . 2009-05-10 11:59 -------- d-----w- c:\users\ordinateur\AppData\Roaming\DNA
2009-09-16 12:09 . 2009-09-16 12:09 6736 ----a-w- c:\windows\system32\drivers\PROCEXP90.SYS
2009-09-16 11:21 . 2009-03-19 17:03 28314 ----a-w- c:\programdata\nvModes.dat
2009-09-16 11:21 . 2009-05-10 11:59 -------- d-----w- c:\program files\DNA
2009-09-16 11:19 . 2009-08-07 16:21 12 ----a-w- c:\windows\bthservsdp.dat
2009-09-16 08:40 . 2009-05-16 22:10 -------- d-----w- c:\programdata\Yahoo! Companion
2009-09-16 08:37 . 2009-03-05 13:11 92488 ----a-w- c:\users\ordinateur\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-15 22:09 . 2009-02-25 11:57 -------- d-----w- c:\programdata\Roxio
2009-09-14 09:23 . 2009-05-10 12:00 -------- d-----w- c:\users\ordinateur\AppData\Roaming\BitTorrent
2009-09-10 09:48 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-04 12:14 . 2009-02-25 13:08 -------- d-----w- c:\program files\Java
2009-08-31 10:31 . 2009-02-25 12:20 -------- d-----w- c:\program files\HP
2009-08-14 10:50 . 2006-11-02 15:48 697522 ----a-w- c:\windows\system32\perfh00C.dat
2009-08-14 10:50 . 2006-11-02 15:48 120556 ----a-w- c:\windows\system32\perfc00C.dat
2009-08-06 13:11 . 2009-08-06 13:07 -------- d-----w- c:\users\ordinateur\AppData\Roaming\ESTsoft
2009-08-06 13:11 . 2009-08-06 13:11 -------- d-----w- c:\programdata\Estsoft
2009-08-06 13:08 . 2009-08-06 13:07 -------- d-----w- c:\program files\ESTsoft
2009-08-01 11:11 . 2009-08-01 11:11 -------- d-----w- c:\users\ordinateur\AppData\Roaming\GTek
2009-08-01 11:09 . 2009-02-25 11:29 -------- d-----w- c:\program files\Hewlett-Packard
2009-08-01 10:58 . 2009-02-25 16:14 -------- d-----w- c:\users\ordinateur\AppData\Roaming\Hewlett-Packard
2009-07-25 03:23 . 2009-05-16 20:20 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-18 21:11 . 2009-07-18 21:11 -------- d-----w- c:\users\ordinateur\AppData\Roaming\Canneverbe_Limited
2009-07-18 21:09 . 2009-07-18 21:09 -------- d-----w- c:\program files\CDBurnerXP
2009-07-18 20:21 . 2009-07-02 16:09 -------- d-----w- c:\users\ordinateur\AppData\Roaming\dvdcss
2009-07-18 12:17 . 2009-07-29 09:22 827392 ----a-w- c:\windows\system32\wininet.dll
2009-07-18 12:10 . 2009-07-29 09:22 56320 ----a-w- c:\windows\system32\iesetup.dll
2009-07-18 12:10 . 2009-07-29 09:22 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-07-18 12:07 . 2009-07-29 09:22 72704 ----a-w- c:\windows\system32\admparse.dll
2009-07-18 10:00 . 2009-07-29 09:22 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-18 08:34 . 2009-07-29 09:22 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-07-17 14:52 . 2009-08-12 09:49 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-14 13:02 . 2009-08-12 09:49 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 13:01 . 2009-08-12 09:48 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-14 13:00 . 2009-08-12 09:48 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-14 11:11 . 2009-08-12 09:48 8147968 ----a-w- c:\windows\system32\wmploc.DLL
2009-09-09 17:37 . 2009-09-09 17:37 115552 ----a-w- c:\program files\mozilla firefox\components\FFConnectorLauncher.dll
2009-09-09 17:37 . 2009-09-09 17:37 239968 ----a-w- c:\program files\mozilla firefox\components\FFSource.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-03-05 1232896]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 484904]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-05-10 321344]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2009-02-25 1006264]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 827392]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-04-23 176128]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 159744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 317128]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-04 13556256]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-04 92704]
"F-Secure Manager"="c:\program files\Orange\AntivirusFirewall\Common\FSM32.EXE" [2008-04-23 182936]
"F-Secure TNB"="c:\program files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" [2008-04-23 744032]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"lxbkbmgr.exe"="c:\program files\Lexmark X1100 Series\lxbkbmgr.exe" [2008-02-28 74408]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-07 44128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"FilterAdministratorToken"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{60732EE7-860B-496D-9915-0D7A317A7055}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{A26BBC00-80DF-425C-AF52-5F28A0ADFEBC}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{30A8FFC0-8660-42D3-B83D-3E25BD361154}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{8BF6C23A-1CB5-494A-B06C-5D74D3CDAAC4}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{65C91274-814B-4072-B6A9-490EC7A1C00F}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{57AFDFF0-1ED1-4BD1-B002-4FC8486E35AB}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{4038BFE4-5A81-47A5-88B5-E4C9FB8B5FE0}"= UDP:c:\windows\System32\lxbkcoms.exe:Lexmark Communications System
"{B59793A6-D059-45AF-AF8A-3B841B8FF552}"= TCP:c:\windows\System32\lxbkcoms.exe:Lexmark Communications System
"{F9CB680B-9643-409F-9312-A5AECA0E8FFD}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxbkpswx.exe:Printer Status Window
"{3426DB8F-721A-45F0-AFA4-59AC26A85EAF}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxbkpswx.exe:Printer Status Window
"{5B87D4CE-5353-4F71-9993-F121763BB6BE}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{F933B9A2-04F0-4649-997A-2851E44A40C9}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 F-Secure HIPS;F-Secure HIPS;c:\program files\Orange\AntivirusFirewall\HIPS\fshs.sys [10/05/2009 12:59 41184]
R1 FSES;F-Secure Email Scanning Driver;c:\windows\System32\drivers\fses.sys [10/05/2009 13:00 34752]
R1 FSFW;F-Secure Firewall Driver;c:\windows\System32\drivers\fsdfw.sys [10/05/2009 13:00 60064]
R1 fsvista;F-Secure Vista Support Driver;c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsvista.sys [10/05/2009 12:58 12896]
R2 lxbk_device;lxbk_device;c:\windows\system32\lxbkcoms.exe -service --> c:\windows\system32\lxbkcoms.exe -service [?]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsgk.sys [10/05/2009 12:58 77824]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Orange\AntivirusFirewall\Anti-Virus\win2k\fsfilter.sys [10/05/2009 12:58 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Orange\AntivirusFirewall\Anti-Virus\win2k\fsrec.sys [10/05/2009 12:58 25184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contenu du dossier 'Tâches planifiées'
2009-09-16 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\Orange\ANTIVI~1\ANTI-V~1\fsav.exe [2009-05-10 16:11]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=73&bd=Pavilion&pf=laptop
mWindow Title =
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
LSP: c:\program files\Orange\AntivirusFirewall\FSPS\program\FSLSP.DLL
FF - ProfilePath - c:\users\ordinateur\AppData\Roaming\Mozilla\Firefox\Profiles\c7en7ds7.default\
FF - component: c:\program files\Mozilla Firefox\components\FFConnectorLauncher.dll
FF - component: c:\program files\Mozilla Firefox\components\FFSource.dll
FF - plugin: c:\users\ordinateur\Program Files\DNA\plugins\npbtdna.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHELINS SUPPRIMES - - - -
AddRemove-Ask Toolbar_is1 - c:\program files\AskBarDis\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-16 14:23
Windows 6.0.6000 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(704)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'lsass.exe'(620)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'csrss.exe'(516)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'csrss.exe'(576)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
.
Heure de fin: 2009-09-16 14:26
ComboFix-quarantined-files.txt 2009-09-16 12:26
Avant-CF: 22 646 984 704 octets libres
Après-CF: 22 803 066 880 octets libres
237 --- E O F --- 2009-09-15 09:04
Vu le nom, c'est un Rootkit