Voila le rapport sdfix:
[b]SDFix: Version 1.240 /b
Run by ns 3 on 17/03/2009 at 21:43
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services /b:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files /b:
Trojan Files Found:
C:\WINDOWS\system32\kazaabackupfiles\shServ.exe - Deleted
Folder C:\WINDOWS\system32\kazaabackupfiles - Removed
Removing Temp Files
[b]ADS Check /b:
[b]Final Check /b:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-17 21:49:28
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000000
"ujdew"=hex:a8,b1,fe,91,4f,07,eb,ff,cd,54,6f,fd,63,8f,41,5b,c6,b1,9d,84,27,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000000
"ujdew"=hex:a8,b1,fe,91,4f,07,eb,ff,cd,54,6f,fd,63,8f,41,5b,c6,b1,9d,84,27,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services /b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[b]Remaining Files /b:
File Backups: - C:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes /b:
Sun 15 Mar 2009 48,690 ..SHR --- "C:\WINDOWS\fxsteller.exe"
Tue 17 Mar 2009 94,290 ...H. --- "C:\WINDOWS\system32\fubbmuoe.exe"
Tue 17 Mar 2009 94,290 ...H. --- "C:\WINDOWS\system32\fzqzsyur.exe"
Tue 17 Mar 2009 94,290 ...H. --- "C:\WINDOWS\system32\iiueddab.exe"
Tue 17 Mar 2009 94,290 ...H. --- "C:\WINDOWS\system32\jcpebsnq.exe"
Tue 17 Mar 2009 94,290 ...H. --- "C:\WINDOWS\system32\kutxcwuy.exe"
Tue 17 Mar 2009 94,290 ...H. --- "C:\WINDOWS\system32\lkyentnd.exe"
Tue 17 Mar 2009 94,290 ...H. --- "C:\WINDOWS\system32\neoqmkll.exe"
Tue 17 Mar 2009 94,290 ...H. --- "C:\WINDOWS\system32\oworoaxk.exe"
Tue 17 Mar 2009 94,290 ...H. --- "C:\WINDOWS\system32\qnukignu.exe"
Tue 17 Mar 2009 94,290 ...H. --- "C:\WINDOWS\system32\rzlmxzpg.exe"
Tue 17 Mar 2009 94,290 ...H. --- "C:\WINDOWS\system32\ssdpuuus.exe"
Tue 17 Mar 2009 94,290 ...H. --- "C:\WINDOWS\system32\tsflaass.exe"
Tue 17 Mar 2009 94,290 ...H. --- "C:\WINDOWS\system32\tzvsixed.exe"
Tue 17 Mar 2009 94,290 ...H. --- "C:\WINDOWS\system32\vtnkleiz.exe"
Tue 17 Mar 2009 94,290 ...H. --- "C:\WINDOWS\system32\xnbapmcl.exe"
Tue 17 Mar 2009 94,290 ...H. --- "C:\WINDOWS\system32\zexnloeu.exe"
Sat 28 Feb 2009 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
[b]Finished!/b