peged
Inscrit le: 16 Sep 2005 Messages: 44
|
Posté le: Sam Fév 09, 2008 3:21 pm Sujet du message: |
|
|
Bien, tout d'abord un grand merci pour ta réponse rapide et précise
Tout n'est pas encore réglé chez moi il semble, j'ai eu beaucoup de mal à faire ce que tu me demandais tant la machine est désormais lente et même s'il y a un petit mieux tout n'est pas encore résolu (toujours cette immense lenteur sur système).
Autre chose, il m'est impossible sous ma session principale d'ouvrir le poste de travail
En attendant voici le rapport
SDFix: Version 1.139
Run by Administrateur on 09/02/2008 at 14:09
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\windows\b138.exe - Deleted
C:\windows\b149.exe - Deleted
C:\windows\mrofinu1188.exe - Deleted
C:\windows\mrofinu1188.exe.tmp - Deleted
C:\windows\Fonts\Setup.exe - Deleted
C:\windows\Fonts\svchost.exe - Deleted
C:\windows\wr.txt - Deleted
Folder C:\Program Files\InetGet2 - Removed
Folder C:\Program Files\WinPop - Removed
Folder C:\windows\Fonts\- - Removed
Removing Temp Files...
ADS Check:
Final Check:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-09 14:28:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:209e1105
"s2"=dword:ac9ed807
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:24,aa,ad,0d,88,fe,d1,69,b3,0b,84,cf,32,f6,1f,9c,37,af,01,8b,b7,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:90,a9,80,76,af,b0,49,19,30,c2,4e,53,ad,a5,16,c4,f3,62,3c,e8,55,..
"a0"=hex:20,01,00,00,22,09,83,d1,db,fb,e9,4b,36,d4,23,26,82,a4,5a,5e,94,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:e0,d8,20,50,10,dd,68,8f,65,62,48,93,2a,f6,31,f3,ad,53,06,0e,c6,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:e0,d8,20,50,10,dd,68,8f,65,62,48,93,2a,f6,31,f3,ad,53,06,0e,c6,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:24,aa,ad,0d,88,fe,d1,69,b3,0b,84,cf,32,f6,1f,9c,37,af,01,8b,b7,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:90,a9,80,76,af,b0,49,19,30,c2,4e,53,ad,a5,16,c4,f3,62,3c,e8,55,..
"a0"=hex:20,01,00,00,22,09,83,d1,db,fb,e9,4b,36,d4,23,26,82,a4,5a,5e,94,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:e0,d8,20,50,10,dd,68,8f,65,62,48,93,2a,f6,31,f3,ad,53,06,0e,c6,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:e0,d8,20,50,10,dd,68,8f,65,62,48,93,2a,f6,31,f3,ad,53,06,0e,c6,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"="C:\\Program Files\\IncrediMail\\bin\\IMApp.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\ICQ\\Icq.exe"="C:\\Program Files\\ICQ\\Icq.exe:*:Enabled:ICQ"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Infogrames\\Grand Prix 4\\GP4.exe"="C:\\Program Files\\Infogrames\\Grand Prix 4\\GP4.exe:*:Enabled:GP4"
"C:\\Program Files\\Microsoft Office\\Office10\\FRONTPG.EXE"="C:\\Program Files\\Microsoft Office\\Office10\\FRONTPG.EXE:*:Enabled:Microsoft FrontPage"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Ex‚cuter une DLL en tant qu'application"
"C:\\TYPSoft FTP Server\\ftpserv.exe"="C:\\TYPSoft FTP Server\\ftpserv.exe:*:Enabled:TYPSoft FTP Server"
"C:\\Program Files\\Ratajik Software\\StationRipper\\StationRipperConsole.exe"="C:\\Program Files\\Ratajik Software\\StationRipper\\StationRipperConsole.exe:*:Enabled:StationRipperConsole"
"C:\\Eddy\\jeux\\Pacific Warriors\\Pacific Warriors\\Pacific Warriors.exe"="C:\\Eddy\\jeux\\Pacific Warriors\\Pacific Warriors\\Pacific Warriors.exe:*:Enabled:Pacific Warriors"
"C:\\Eddy\\jeux\\Fur Fighters\\Fur Fighters\\furfighters.exe"="C:\\Eddy\\jeux\\Fur Fighters\\Fur Fighters\\furfighters.exe:*:Enabled:DirectPlay Sample Application: StagedConnect"
"C:\\Eddy\\jeux\\Heavy Metal - FAKK2 FR\\Heavy Metal - FAKK2 FR\\fakk2.exe"="C:\\Eddy\\jeux\\Heavy Metal - FAKK2 FR\\Heavy Metal - FAKK2 FR\\fakk2.exe:*:Enabled:Heavy Metal : Fakk 2"
"C:\\Program Files\\Inventel\\Gateway\\RGWRepair.exe"="C:\\Program Files\\Inventel\\Gateway\\RGWRepair.exe:*:Enabled:RGWRepair"
"C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Atari\\Test Drive Unlimited\\TestDriveUnlimited.exe"="C:\\Program Files\\Atari\\Test Drive Unlimited\\TestDriveUnlimited.exe:*:Enabled:Test Drive Unlimited"
"C:\\Program Files\\Ma‹do Production\\IziSpot 4\\IziSpot.exe"="C:\\Program Files\\Ma‹do Production\\IziSpot 4\\IziSpot.exe:*:Enabled:IziSpot"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Sat 9 Feb 2008 33,464 ..SH. --- "C:\WINDOWS\system32\zynvejmy.dllbox"
Mon 26 Jun 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 25 Jun 2007 444 ...HR --- "C:\Documents and Settings\PETITJEAN\Application Data\SecuROM\UserData\securom_v7_01.bak"
Thu 7 Dec 2006 3,096,576 A..H. --- "C:\Documents and Settings\PETITJEAN\Application Data\U3\temp\Launchpad Removal.exe"
Finished!
Bon courage et merci  |
|