Voila le rapport final
[b]SDFix: Version 1.236 /b
Run by rekik on 19/10/2008 at 19:39
Microsoft Windows XP [version 5.1.2600]
Running From: H:\SDFix
[b]Checking Services /b:
Restoring Default Security Values
Restoring Default Hosts File
Resetting AppInit_DLLs value
Rebooting
[b]Infected beep.sys Found!/b
beep.sys File Locations:
"H:\WINDOWS2\system32\dllcache\beep.sys" 28160 17/10/2008 21:36
Infected File Listed Below:
H:\WINDOWS2\system32\dllcache\beep.sys
File copied to Backups Folder
Attempting to replace beep.sys with original version
Original beep.sys Restored
"H:\WINDOWS2\system32\dllcache\beep.sys" 4224 07/08/2008 16:27
"H:\WINDOWS2\system32\drivers\beep.sys" 4224 07/08/2008 16:27
[b]Checking Files /b:
Trojan Files Found:
H:\DOCUME~1\REKIK\COOKIES\MYXALUXI.DB - Deleted
H:\DOCUME~1\REKIK\COOKIES\ISYS.DL - Deleted
H:\DOCUME~1\REKIK\COOKIES\UNOP._SY - Deleted
H:\DOCUME~1\REKIK\COOKIES\REZYSYTO.SCR - Deleted
H:\Program Files\XP_Antispyware\AVEngn.dll - Deleted
H:\Program Files\XP_Antispyware\htmlayout.dll - Deleted
H:\Program Files\XP_Antispyware\pthreadVC2.dll - Deleted
H:\Program Files\XP_Antispyware\Uninstall.exe - Deleted
H:\Program Files\XP_Antispyware\wscui.cpl - Deleted
H:\Program Files\XP_Antispyware\XP_Antispyware.cfg - Deleted
H:\Program Files\XP_Antispyware\data\daily.cvd - Deleted
H:\Program Files\XP_Antispyware\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest - Deleted
H:\Program Files\XP_Antispyware\Microsoft.VC80.CRT\msvcm80.dll - Deleted
H:\Program Files\XP_Antispyware\Microsoft.VC80.CRT\msvcp80.dll - Deleted
H:\Program Files\XP_Antispyware\Microsoft.VC80.CRT\msvcr80.dll - Deleted
H:\Documents and Settings\All Users.WINDOWS2\Documents\kanynup.db - Deleted
H:\Program Files\Fichiers communs\afuvonet.bin - Deleted
H:\Program Files\Fichiers communs\egolon.vbs - Deleted
H:\Documents and Settings\rekik\Application Data\afomeqosi.bin - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries1.cab2 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries1.cab3 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries1.cab4 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries1.cab5 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries1.cab6 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries1.cab7 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries1.cab8 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries1.cab9 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries2.cab3 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries2.cab4 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries2.cab5 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries2.cab6 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries2.cab7 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries2.cab8 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries2.cab9 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries3.cab4 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries3.cab5 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries3.cab6 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries3.cab7 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries3.cab8 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\Binaries3.cab9 - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\TDSS13b6.tmp - Deleted
H:\DOCUME~1\rekik\LOCALS~1\Temp\TDSS1471.tmp - Deleted
H:\WINDOWS2\system32\wini10801.exe - Deleted
H:\Documents and Settings\rekik\Application Data\Microsoft\Internet Explorer\Quick Launch\XP_AntiSpyware.lnk - Deleted
H:\Documents and Settings\rekik\Bureau\XP_AntiSpyware.lnk - Deleted
H:\WINDOWS2\brastk.exe - Deleted
H:\WINDOWS2\karna.dat - Deleted
H:\WINDOWS2\system32\_scui.cpl - Deleted
H:\WINDOWS2\system32\delself.bat - Deleted
Folder H:\Program Files\XP_Antispyware - Removed
Removing Temp Files
[b]ADS Check /b:
[b]Final Check /b:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-19 19:55:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:0000015a
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services /b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"H:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="H:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"H:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="H:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"H:\\Program Files\\ma-config.com\\maconfservice.exe"="H:\\Program Files\\ma-config.com\\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
"H:\\Program Files\\Bonjour\\mDNSResponder.exe"="H:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"H:\\Program Files\\iTunes\\iTunes.exe"="H:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"H:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="H:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"H:\\Program Files\\SopCast\\SopCast.exe"="H:\\Program Files\\SopCast\\SopCast.exe:*:Enabled:SopCast Main Application"
"H:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"="H:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare"
"H:\\Program Files\\SopCast\\adv\\SopAdver.exe"="H:\\Program Files\\SopCast\\adv\\SopAdver.exe:*:Enabled:SopCast Adver"
"H:\\WINDOWS2\\system32\\muzapp.exe"="H:\\WINDOWS2\\system32\\muzapp.exe:*:Enabled:MUZ AOD APP player"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"H:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="H:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"H:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="H:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files /b:
File Backups: - H:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes /b:
Fri 8 Sep 2006 218 ..SH. --- "H:\BOOT.BAK"
Wed 21 May 2008 616,448 A.SH. --- "H:\WINDOWS\Temp\6rm46sxi.TMP"
Fri 2 Feb 2007 797,248,032 A.SH. --- "H:\WINDOWS\Temp\8uc1k9q9.TMP"
Sat 25 Nov 2006 616,448 A.SH. --- "H:\WINDOWS\Temp\90waduz4.TMP"
Fri 2 Feb 2007 827,207,808 A.SH. --- "H:\WINDOWS\Temp\g09z78hl.TMP"
Wed 13 Sep 2006 4,348 A.SH. --- "H:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 1 Mar 2007 22,528 ...H. --- "H:\Documents and Settings\All Users\Documents\Divers\~WRL0002.tmp"
Sun 4 Mar 2007 22,528 ...H. --- "H:\Documents and Settings\All Users\Documents\Divers\~WRL0004.tmp"
Wed 28 Feb 2007 24,064 ...H. --- "H:\Documents and Settings\Compaq_Propri‚taire\Mes documents\Mes fichiers re‡us\~WRL2745.tmp"
Wed 7 May 2008 0 A..H. --- "H:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\BIT7.tmp"
Mon 9 Jun 2008 0 A..H. --- "H:\WINDOWS\SoftwareDistribution\Download\326d1a08fc685e3efad9e9a5b059ebfb\BIT55E.tmp"
Mon 9 Jun 2008 0 A..H. --- "H:\WINDOWS\SoftwareDistribution\Download\8b3179d71e82d8085d960408b16ae5bf\BIT55F.tmp"
Tue 12 Dec 2006 19,456 ...H. --- "H:\Documents and Settings\Compaq_Propri‚taire\Application Data\Microsoft\Word\~WRL0004.tmp"
Wed 28 Feb 2007 23,552 ...H. --- "H:\Documents and Settings\Compaq_Propri‚taire\Application Data\Microsoft\Word\~WRL0005.tmp"
Wed 28 Feb 2007 27,136 ...H. --- "H:\Documents and Settings\Compaq_Propri‚taire\Application Data\Microsoft\Word\~WRL0258.tmp"
Wed 28 Feb 2007 25,600 ...H. --- "H:\Documents and Settings\Compaq_Propri‚taire\Application Data\Microsoft\Word\~WRL0966.tmp"
Wed 28 Feb 2007 25,088 ...H. --- "H:\Documents and Settings\Compaq_Propri‚taire\Application Data\Microsoft\Word\~WRL1062.tmp"
Wed 28 Feb 2007 25,088 ...H. --- "H:\Documents and Settings\Compaq_Propri‚taire\Application Data\Microsoft\Word\~WRL2392.tmp"
Wed 28 Feb 2007 24,576 ...H. --- "H:\Documents and Settings\Compaq_Propri‚taire\Application Data\Microsoft\Word\~WRL2415.tmp"
Wed 28 Feb 2007 24,064 ...H. --- "H:\Documents and Settings\Compaq_Propri‚taire\Application Data\Microsoft\Word\~WRL3126.tmp"
Wed 13 Sep 2006 4,348 ...H. --- "H:\Documents and Settings\Compaq_Propri‚taire\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
Fri 1 Dec 2006 20 A..H. --- "H:\Documents and Settings\Compaq_Propri‚taire\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
Tue 12 Sep 2006 312 A.SH. --- "H:\Documents and Settings\Compaq_Propri‚taire\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
Wed 15 Oct 2008 19,456 ...H. --- "H:\Documents and Settings\rekik\Application Data\Microsoft\Word\~WRL0003.tmp"
Wed 15 Oct 2008 19,456 ...H. --- "H:\Documents and Settings\rekik\Application Data\Microsoft\Word\~WRL0454.tmp"
Wed 15 Oct 2008 19,456 ...H. --- "H:\Documents and Settings\rekik\Application Data\Microsoft\Word\~WRL2392.tmp"
Wed 15 Oct 2008 19,968 ...H. --- "H:\Documents and Settings\rekik\Application Data\Microsoft\Word\~WRL3494.tmp"
[b]Finished!/b
ca a l'air d'etre bon ?