Ca rassure de savoir que mon ordi est pourri! lol
voici le rapport SDFix
SDFix: Version 1.236 Run by Antoine Larkin on 16/10/2008 at 16:17
Microsoft Windows XP [version 5.1.2600]
Running From: C:\Documents and Settings\Antoine Larkin\Bureau\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\DOCUME~1\ANTOIN~1\COOKIES\HAQEWUJE.LIB - Deleted
C:\DOCUME~1\ANTOIN~1\COOKIES\DEZU.VBS - Deleted
C:\WINDOWS\mslagent\2_mslagent.dll - Deleted
C:\WINDOWS\mslagent\mslagent.exe - Deleted
C:\WINDOWS\mslagent\uninstall.exe - Deleted
C:\Program Files\akl\akl.dll - Deleted
C:\Program Files\akl\akl.exe - Deleted
C:\Program Files\akl\uninstall.exe - Deleted
C:\Program Files\akl\unsetup.exe - Deleted
C:\Program Files\Inet Delivery\inetdl.exe - Deleted
C:\Program Files\Inet Delivery\intdel.exe - Deleted
C:\Program Files\XP_Antispyware\AVEngn.dll - Deleted
C:\Program Files\XP_Antispyware\htmlayout.dll - Deleted
C:\Program Files\XP_Antispyware\Uninstall.exe - Deleted
C:\Documents and Settings\All Users\Documents\vinerifuk.dat - Deleted
C:\Documents and Settings\All Users\Documents\lujyxaqoq.dl - Deleted
C:\Documents and Settings\All Users\Documents\ovapakady.pif - Deleted
C:\Documents and Settings\All Users\Documents\urek.vbs - Deleted
C:\Program Files\Fichiers communs\igury.com - Deleted
C:\Program Files\Fichiers communs\codijeg.dat - Deleted
C:\Program Files\Fichiers communs\urek.dat - Deleted
C:\Program Files\Fichiers communs\degygidam.pif - Deleted
C:\Program Files\Fichiers communs\ufecyrir.pif - Deleted
C:\Program Files\Fichiers communs\odude.scr - Deleted
C:\Documents and Settings\Antoine Larkin\Application Data\ogilar.bin - Deleted
C:\Documents and Settings\Antoine Larkin\Application Data\ubidy.bin - Deleted
C:\Documents and Settings\Antoine Larkin\Application Data\xomefar.bin - Deleted
C:\Documents and Settings\Antoine Larkin\Application Data\okycirymo.pif - Deleted
C:\Documents and Settings\Antoine Larkin\Application Data\avaryr.vbs - Deleted
C:\WINDOWS\a.bat - Deleted
C:\WINDOWS\system32\wini104552663.exe - Deleted
C:\WINDOWS\zip1.tmp - Deleted
C:\WINDOWS\zip2.tmp - Deleted
C:\WINDOWS\zip3.tmp - Deleted
C:\WINDOWS\zipped.tmp - Deleted
C:\WINDOWS\a.bat - Deleted
C:\WINDOWS\base64.tmp - Deleted
C:\WINDOWS\bdn.com - Deleted
C:\WINDOWS\FVProtect.exe - Deleted
C:\WINDOWS\iTunesMusic.exe - Deleted
C:\WINDOWS\mssecu.exe - Deleted
C:\WINDOWS\system32\akttzn.exe - Deleted
C:\WINDOWS\system32\anticipator.dll - Deleted
C:\WINDOWS\system32\awtoolb.dll - Deleted
C:\WINDOWS\system32\bdn.com - Deleted
C:\WINDOWS\system32\brastk.exe - Deleted
C:\WINDOWS\system32\bsva-egihsg52.exe - Deleted
C:\WINDOWS\system32\dpcproxy.exe - Deleted
C:\WINDOWS\system32\drivers\svchost.exe - Deleted
C:\WINDOWS\system32\emesx.dll - Deleted
C:\WINDOWS\system32\h@tkeysh@@k.dll - Deleted
C:\WINDOWS\system32\hoproxy.dll - Deleted
C:\WINDOWS\system32\hxiwlgpm.dat - Deleted
C:\WINDOWS\system32\hxiwlgpm.exe - Deleted
C:\WINDOWS\system32\medup012.dll - Deleted
C:\WINDOWS\system32\medup020.dll - Deleted
C:\WINDOWS\system32\msgp.exe - Deleted
C:\WINDOWS\system32\msnbho.dll - Deleted
C:\WINDOWS\system32\mssecu.exe - Deleted
C:\WINDOWS\system32\msvchost.exe - Deleted
C:\WINDOWS\system32\mtr2.exe - Deleted
C:\WINDOWS\system32\mwin32.exe - Deleted
C:\WINDOWS\system32\netode.exe - Deleted
C:\WINDOWS\system32\newsd32.exe - Deleted
C:\WINDOWS\system32\ps1.exe - Deleted
C:\WINDOWS\system32\psof1.exe - Deleted
C:\WINDOWS\system32\psoft1.exe - Deleted
C:\WINDOWS\system32\regc64.dll - Deleted
C:\WINDOWS\system32\regm64.dll - Deleted
C:\WINDOWS\system32\Rundl1.exe - Deleted
C:\WINDOWS\system32\smp\msrc.exe - Deleted
C:\WINDOWS\system32\sncntr.exe - Deleted
C:\WINDOWS\system32\ssurf022.dll - Deleted
C:\WINDOWS\system32\ssvchost.com - Deleted
C:\WINDOWS\system32\ssvchost.exe - Deleted
C:\WINDOWS\system32\sysreq.exe - Deleted
C:\WINDOWS\system32\taack.dat - Deleted
C:\WINDOWS\system32\taack.exe - Deleted
C:\WINDOWS\system32\temp#01.exe - Deleted
C:\WINDOWS\system32\thun.dll - Deleted
C:\WINDOWS\system32\thun32.dll - Deleted
C:\WINDOWS\system32\VBIEWER.OCX - Deleted
C:\WINDOWS\system32\vbsys2.dll - Deleted
C:\WINDOWS\system32\vcatchpi.dll - Deleted
C:\WINDOWS\system32\winlogonpc.exe - Deleted
C:\WINDOWS\system32\winsystem.exe - Deleted
C:\WINDOWS\system32\WINWGPX.EXE - Deleted
C:\WINDOWS\userconfig9x.dll - Deleted
C:\WINDOWS\winsystem.exe - Deleted
Folder C:\Program Files\akl - Removed
Folder C:\Program Files\Inet Delivery - Removed
Folder C:\Program Files\XP_Antispyware - Removed
Folder C:\WINDOWS\mslagent - Removed
Folder C:\WINDOWS\system32\smp - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-16 16:31:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
Remaining Files :
File Backups: - C:\DOCUME~1\ANTOIN~1\Bureau\SDFix\backups\backups.zip
Files with Hidden Attributes :
Mon 10 Mar 2008 5,903,928 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Mon 2 Apr 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 28 Feb 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Mon 13 Oct 2008 299,008 ...H. --- "C:\Documents and Settings\Antoine Larkin\Mes documents\ESSEC\ThŠse pro\~WRL2139.tmp"
Sun 14 May 2006 23,552 A..H. --- "C:\Documents and Settings\Antoine Larkin\Mes documents\HEI\cours H4\chantier de merde!\~WRL1849.tmp"
Sat 11 Jun 2005 117,248 A..H. --- "C:\Documents and Settings\Antoine Larkin\Mes documents\HEI\cours H4\fuck la charpente!\charpente\~WRL1411.tmp"
Fri 3 Jun 2005 616,960 A..H. --- "C:\Documents and Settings\Antoine Larkin\Mes documents\HEI\cours H4\fuck la charpente!\charpente\~WRL1563.tmp"
Sat 11 Jun 2005 538,624 A..H. --- "C:\Documents and Settings\Antoine Larkin\Mes documents\HEI\cours H4\fuck la charpente!\charpente\~WRL3320.tmp"
Mon 14 Jun 2004 666,112 A..H. --- "C:\Documents and Settings\Antoine Larkin\Mes documents\HEI\cours H4\fuck la charpente!\charpente\rapport charpente 2004 lyon\~WRL3839.tmp"
Sun 14 May 2006 23,552 A..H. --- "C:\Documents and Settings\Antoine Larkin\Local Settings\Application Data\Microsoft\Messenger\antoine_larkin@hotmail.fr\Sharing Folders\largo_nico@hotmail.com\chantier de merde!\~WRL1849.tmp"
Sat 11 Jun 2005 117,248 A..H. --- "C:\Documents and Settings\Antoine Larkin\Local Settings\Application Data\Microsoft\Messenger\antoine_larkin@hotmail.fr\Sharing Folders\largo_nico@hotmail.com\fuck la charpente!\charpente\~WRL1411.tmp"
Fri 3 Jun 2005 616,960 A..H. --- "C:\Documents and Settings\Antoine Larkin\Local Settings\Application Data\Microsoft\Messenger\antoine_larkin@hotmail.fr\Sharing Folders\largo_nico@hotmail.com\fuck la charpente!\charpente\~WRL1563.tmp"
Sat 11 Jun 2005 538,624 A..H. --- "C:\Documents and Settings\Antoine Larkin\Local Settings\Application Data\Microsoft\Messenger\antoine_larkin@hotmail.fr\Sharing Folders\largo_nico@hotmail.com\fuck la charpente!\charpente\~WRL3320.tmp"
Mon 14 Jun 2004 666,112 A..H. --- "C:\Documents and Settings\Antoine Larkin\Local Settings\Application Data\Microsoft\Messenger\antoine_larkin@hotmail.fr\Sharing Folders\largo_nico@hotmail.com\fuck la charpente!\charpente\rapport charpente 2004 lyon\~WRL3839.tmp"
Finished!