Virus alert

omarjustin -  
jacques.gache Messages postés 34829 Statut Contributeur sécurité -
Bonjour,

voila mon rapport aidez moi sp

[b]SDFix: Version 1.238 [/b]
Run by Proprietario on 30/10/2008 at 22:47

Microsoft Windows XP [Versione 5.1.2600]
Running From: C:\SDFix

[b]Checking Services [/b]:

Restoring Default Security Values
Restoring Default Hosts File
Restoring Windows Product ID To Remove Fake Virus Alert
Restoring Time Format To Remove Fake Virus Alert
Restoring Default Start Menu

Rebooting

[b]Checking Files [/b]:

Trojan Files Found:

C:\Documents and Settings\Proprietario\Preferiti\Malware Defender.url - Deleted
C:\Documents and Settings\Proprietario\Desktop\Malware Defender.url - Deleted
C:\Documents and Settings\Proprietario\Preferiti\Protect Your Privacy.url - Deleted
C:\Documents and Settings\Proprietario\Desktop\Protect Your Privacy.url - Deleted
C:\Documents and Settings\Proprietario\Preferiti\System Error Fixer.url - Deleted
C:\Documents and Settings\Proprietario\Desktop\System Error Fixer.url - Deleted

Removing Temp Files

[b]ADS Check [/b]:

[b]Final Check [/b]:

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-30 22:53:27
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

[b]Remaining Services [/b]:

Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Programmi\\eMule\\emule.exe"="C:\\Programmi\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Programmi\\FreeCall.com\\FreeCall\\FreeCall.exe"="C:\\Programmi\\FreeCall.com\\FreeCall\\FreeCall.exe:*:Enabled:FreeCall"
"C:\\Programmi\\Skype\\Phone\\Skype.exe"="C:\\Programmi\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. Take a deep breath "
"C:\\Programmi\\Windows Live\\Messenger\\MsnMsgr.Exe"="C:\\Programmi\\Windows Live\\Messenger\\MsnMsgr.Exe:*:Enabled:Windows Live Messenger"
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"="C:\\Programmi\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Programmi\\LimeWire\\LimeWire.exe"="C:\\Programmi\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Programmi\\Windows Live\\Messenger\\MsnMsgr.Exe"="C:\\Programmi\\Windows Live\\Messenger\\MsnMsgr.Exe:*:Enabled:Windows Live Messenger"
"C:\\Programmi\\Windows Live\\Messenger\\livecall.exe"="C:\\Programmi\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[b]Remaining Files [/b]:

File Backups: - C:\SDFix\backups\backups.zip

[b]Files with Hidden Attributes [/b]:

Thu 7 Oct 2004 1,024 ...HR --- "C:\WINDOWS\system32\NTICDMK32.dll"
Thu 7 Oct 2004 1,024 ...HR --- "C:\WINDOWS\system32\NTIMPEG2.dll"
Thu 7 Oct 2004 1,024 ...HR --- "C:\WINDOWS\system32\ntiembed.dll"
Mon 4 Jun 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"

[b]Finished![/b]
A voir également:

1 réponse

jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 618
 
bonjour, ne sois pas trop surpris d'être infecté car en étant un mordu de téléchargement sur le P2P source d'infection garantie car avec 2 logiciels "emule et limewire " en même temps tu dois y aller dur dur
0