Bon voilà, donc j'ai tout fait !!
Finished s'est affiché, et je colle donc ici, comme demandé, le report du dossier SDFix, que faire ensuite????? car s'est marqué "avec un nouveau log Hijackthis" mais je comprend pas ce que ça veut dire ?? !! ...... merci !
[b]SDFix: Version 1.154 /b
Run by MICHAEL on 09/03/2008 at 00:35
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services /b:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
[b]Checking Files /b:
Trojan Files Found:
C:\WINDOWS\mrofinu1423.exe - Deleted
C:\WINDOWS\mrofinu1423.exe.tmp - Deleted
C:\DOCUME~1\MICHAEL\LOCALS~1\Temp\services.exe - Deleted
Removing Temp Files
[b]ADS Check /b:
[b]Final Check /b:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-09 00:45:19
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services /b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\System32\\P2P Networking\\P2P Networking.exe"="C:\\WINDOWS\\System32\\P2P Networking\\P2P Networking.exe:*:Disabled:P2P Networking"
"C:\\WINDOWS\\explorer.exe"="C:\\WINDOWS\\explorer.exe:*:Disabled:Explorateur Windows"
"D:\\_nti40\\bin\\search.exe"="D:\\_nti40\\bin\\search.exe:*:Disabled:Verity Publisher"
"C:\\Program Files\\Wanadoo Messager\\Wanadoo Messager.exe"="C:\\Program Files\\Wanadoo Messager\\Wanadoo Messager.exe:*:Enabled:Application Messager"
"C:\\WINDOWS\\System32\\dpvsetup.exe"="C:\\WINDOWS\\System32\\dpvsetup.exe:*:Disabled:Microsoft DirectPlay Voice Test"
"C:\\WINDOWS\\System32\\lexpps.exe"="C:\\WINDOWS\\System32\\lexpps.exe:*:Enabled:LEXPPS.EXE"
"C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Documents and Settings\\MICHAEL\\Bureau\\eMule\\emule.exe"="C:\\Documents and Settings\\MICHAEL\\Bureau\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\Warez P2P Client\\warez.exe"="C:\\Program Files\\Warez P2P Client\\warez.exe:*:Disabled:Warez p2p client"
"C:\\Documents and Settings\\SEBASTIEN\\Bureau\\mes document\\X-Chat 2\\xchat.exe"="C:\\Documents and Settings\\SEBASTIEN\\Bureau\\mes document\\X-Chat 2\\xchat.exe:*:Disabled:X-Chat IRC Client"
@=""
"C:\\DOCUME~1\\MICHAEL\\LOCALS~1\\Temp\\services.exe"="C:\\DOCUME~1\\MICHAEL\\LOCALS~1\\Temp\\services.exe:*:Enabled:Flash Media"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files /b:
File Backups: - C:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes /b:
Fri 29 Oct 2004 48 ..SH. --- "C:\Documents and Settings\All Users\DRM\v2ks.sec.bak"
Fri 29 Oct 2004 400 ..SH. --- "C:\Documents and Settings\All Users\DRM\v2ks.bla.bak"
Sun 9 Nov 2003 401 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv13.bak"
Wed 9 Jul 2003 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 22 Oct 2004 22,528 ...H. --- "C:\Documents and Settings\RICHARD JL\Local Settings\Temp\~WRL0004.tmp"
Thu 8 Nov 2007 22,016 ...H. --- "C:\Documents and Settings\MICHAEL\Bureau\IUFM 2007 2008\~WRL1098.tmp"
Thu 8 Nov 2007 31,232 ...H. --- "C:\Documents and Settings\MICHAEL\Bureau\IUFM 2007 2008\~WRL1453.tmp"
Mon 19 Apr 2004 19,968 ...H. --- "C:\Documents and Settings\MARTINE\Local Settings\Temp\~WRL0004.tmp"
Mon 19 Apr 2004 20,480 ...H. --- "C:\Documents and Settings\MARTINE\Local Settings\Temp\~WRL3993.tmp"
Mon 19 Apr 2004 21,504 ...H. --- "C:\Documents and Settings\MARTINE\Local Settings\Temp\~WRL3187.tmp"
Sat 20 Oct 2007 401 A..H. --- "C:\Program Files\Wanadoo\richard.jeanluc\Ma Musique\Sauvegarde de la licence\drmv1lic.bak"
Wed 9 Jul 2003 4,348 ...H. --- "C:\Program Files\Wanadoo\richard.jeanluc\Ma Musique\Sauvegarde de la licence\drmv1key.bak"
Sat 20 Oct 2007 9,855 A.SH. --- "C:\Program Files\Wanadoo\richard.jeanluc\Ma Musique\Sauvegarde de la licence\drmv2key.bak"
[b]Finished!/b