le rapport de sdfix:
SDFix: Version 1.171
Run by Administrateur on 14/04/2008 at 21:06
Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\ADMINI~1\Bureau\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS.EXE - Deleted
C:\WINDOWS.EXE - Deleted
C:\DOCUME~1\ADMINI~1\APPLIC~1\MICROS~1\WINDOWS\UABPQ.EXE - Deleted
C:\DOCUME~1\ADMINI~1\EIPDIU.EXE - Deleted
C:\DOCUME~1\ADMINI~1\JIMNUG.EXE - Deleted
C:\DOCUME~1\ADMINI~1\LRAHCL.EXE - Deleted
C:\DOCUME~1\ADMINI~1\MNBTCW.EXE - Deleted
C:\DOCUME~1\ADMINI~1\OYIAZP.EXE - Deleted
C:\DOCUME~1\ADMINI~1\RDMKIY.EXE - Deleted
C:\DOCUME~1\ADMINI~1\RRHTIH.EXE - Deleted
C:\DOCUME~1\ADMINI~1\SEJOWV.EXE - Deleted
C:\DOCUME~1\ADMINI~1\SGJXLS.EXE - Deleted
C:\DOCUME~1\ADMINI~1\APPLIC~1\WinTouch\WinTouch.exe - Deleted
C:\DOCUME~1\ADMINI~1\APPLIC~1\WinTouch\wintouch.MSNFix - Deleted
C:\DOCUME~1\ADMINI~1\APPLIC~1\WinTouch\WTUninstaller.MSNFix - Deleted
C:\Program Files\CPV\CPV8.dll - Deleted
C:\Program Files\JavaCore\JavaCore.MSNFix - Deleted
C:\Program Files\JavaCore\UnInstall.MSNFix - Deleted
C:\Program Files\nvcoi\mst.MSNFix - Deleted
C:\Program Files\nvcoi\nvcoi.MSNFix - Deleted
C:\Program Files\Temporary\InsiDERInst.MSNFix - Deleted
C:\Program Files\Fichiers communs\Yazzle1560OinAdmin.exe - Deleted
C:\Program Files\Fichiers communs\Yazzle1560OinUninstaller.MSNFix - Deleted
C:\WINDOWS.0\17PHolmes1423.exe - Deleted
C:\WINDOWS.0\b138.exe - Deleted
C:\WINDOWS.0\b152.exe - Deleted
C:\WINDOWS.0\b153.exe - Deleted
C:\WINDOWS.0\b155.exe - Deleted
C:\Documents and Settings\Administrateur\real.txt - Deleted
Folder C:\Documents and Settings\Administrateur\Application Data\WinTouch - Removed
Folder C:\Program Files\CPV - Removed
Folder C:\Program Files\JavaCore - Removed
Folder C:\Program Files\nvcoi - Removed
Folder C:\Program Files\Temporary - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1351.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-14 21:15:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:f1,a7,40,0c,4c,ce,df,d4,b8,e0,c3,bc,a9,0a,b2,b8,bb,04,ae,58,80,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:35,d9,82,77,b7,b6,14,0f,f5,c5,df,13,4f,25,d0,e4,61,1f,e3,a0,b7,..
"d0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:b7,b4,a3,32,55,e1,d7,ba,da,c8,51,19,42,1d,59,b0,a3,56,cf,c9,24,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:f1,a7,40,0c,4c,ce,df,d4,b8,e0,c3,bc,a9,0a,b2,b8,bb,04,ae,58,80,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:35,d9,82,77,b7,b6,14,0f,f5,c5,df,13,4f,25,d0,e4,61,1f,e3,a0,b7,..
"d0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:b7,b4,a3,32,55,e1,d7,ba,da,c8,51,19,42,1d,59,b0,a3,56,cf,c9,24,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Steam\\SteamApps\\fredo0013\\counter-strike source\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\fredo0013\\counter-strike source\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
Remaining Files :
File Backups: - C:\DOCUME~1\ADMINI~1\Bureau\SDFix\backups\backups.zip
Files with Hidden Attributes :
Fri 11 Apr 2008 230,400 ..SHR --- "C:\WINDOWS.0\??stem\w?nword.exe"
Wed 21 Nov 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users.WINDOWS.0\DRM\DRMv1.bak"
Sat 9 Jun 2007 70,656 ..SHR --- "C:\Program Files\Makayama Interactive\Easy WiFi Radar\Setup.exe"
Mon 14 Apr 2008 68,608 ..SHR --- "C:\Documents and Settings\Administrateur\Application Data\T?sks\javaw.exe"
Sun 25 Nov 2007 25,839,664 A..H. --- "C:\WINDOWS.0\SoftwareDistribution\Download\60ca6af11040112be1355236afadeb90\BIT70.tmp"
Thu 22 Nov 2007 0 A..H. --- "C:\WINDOWS.0\SoftwareDistribution\Download\cc102203f99c8c6ebf1523556f8411b6\BIT1.tmp"
Finished!