Merci pour ta réponse, voici ci-dessous le rapport cleannavi.txt
Clean Navipromo version 3.5.0 commencé le 05/03/2008 à 8:58:55,09
Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 04.03.2008 à 17h00 par IL-MAFIOSO
Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.11
Système de fichiers : NTFS
Mode suppression par méthode manuelle
Nom du fichier saisi : bvynbfrm
*** Recherche, création sauvegardes et suppression ***
* Suppression dans C:\WINDOWS\system32 *
C:\WINDOWS\prefetch\bvynbfrm*.pf trouvé !
Copie C:\WINDOWS\prefetch\bvynbfrm*.pf réalisée avec succès !
C:\WINDOWS\prefetch\bvynbfrm*.pf supprimé !
* Suppression dans "C:\Documents and Settings\Christine\locals~1\applic~1" *
bvynbfrm.exe trouvé !
Copie bvynbfrm.exe réalisée avec succès !
bvynbfrm.exe supprimé !
bvynbfrm.dat trouvé !
Copie bvynbfrm.dat réalisée avec succès !
bvynbfrm.dat supprimé !
bvynbfrm_nav.dat trouvé !
Copie bvynbfrm_nav.dat réalisée avec succès !
bvynbfrm_nav.dat supprimé !
bvynbfrm_navps.dat trouvé !
Copie bvynbfrm_navps.dat réalisée avec succès !
bvynbfrm_navps.dat supprimé !
*** Suppression dossiers dans C:\WINDOWS ***
*** Suppression dossiers dans C:\Program Files ***
*** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***
*** Suppression dossiers dans "C:\Documents and Settings\Christine\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\Christine\locals~1\applic~1" ***
*** Suppression dossiers dans "C:\Documents and Settings\Christine\menudm~1\progra~1" ***
*** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***
...\InternetGameBox ...suppression...
...\InternetGameBox supprimé !
*** Suppression fichiers ***
C:\DOCUME~1\ALLUSE~1\Bureau\InternetGameBox.lnk supprimé !
C:\WINDOWS\system32\nvs2.inf supprimé !
*** Suppression fichiers temporaires ***
Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\Christine\locals~1\Temp effectué !
*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Suppression avec sauvegardes nouveaux fichiers Instant Access :
2)Recherche, création sauvegardes et suppression Heuristique :
* Dans C:\WINDOWS\system32 *
* Dans "C:\Documents and Settings\Christine\locals~1\applic~1" *
*** Sauvegarde du Registre vers dossier Backupnavi ***
sauvegarde du Registre réalisée avec succès !
*** Nettoyage Registre ***
Nettoyage Registre Ok
*** Certificats ***
Certificat Egroup supprimé !
Certificat Electronic-Group supprimé !
Certificat OOO-Favorit supprimé !
*** Nettoyage terminé le 05/03/2008 à 9:03:18,54 ***
Sur le bureau de mon ordinateur, il y a un icone catcme.log voici ce qu'il y a d'inscrit dans le bloc note :
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-05 10:51:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword
7eac169
"s2"=dword:8b9901f1
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:e6,93,c8,6b,87,e9,de,88,3f,03,5a,2c,f2,b3,71,c7,db,ed,42,aa,18,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,77,68,e9,7b,2c,62,cc,d2,cb,e1,70,a2,e9,43,4d,c4,69,..
"khjeh"=hex:41,5d,7a,bd,f5,b9,3d,fa,6b,9b,d5,de,00,a0,bf,54,15,dc,c3,57,58,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:6c,ae,b3,de,00,37,47,1f,a7,2f,0b,b6,17,17,1c,ff,e8,a8,60,16,be,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:64,62,02,00,18,51,33,00,18,e9,48,b5,d8,ff,ff,ff,76,6b,0a,00,40,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:0c,29,4d,11,10,37,14,2c,0e,b6,a1,59,44,7b,f0,d0,3f,19,85,dd,c0,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:e6,93,c8,6b,87,e9,de,88,3f,03,5a,2c,f2,b3,71,c7,db,ed,42,aa,18,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,77,68,e9,7b,2c,62,cc,d2,cb,e1,70,a2,e9,43,4d,c4,69,..
"khjeh"=hex:41,5d,7a,bd,f5,b9,3d,fa,6b,9b,d5,de,00,a0,bf,54,15,dc,c3,57,58,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:6c,ae,b3,de,00,37,47,1f,a7,2f,0b,b6,17,17,1c,ff,e8,a8,60,16,be,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:64,62,02,00,90,b8,20,00,a0,ee,20,00,e0,ff,ff,ff,76,6b,08,00,a8,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:0c,29,4d,11,10,37,14,2c,0e,b6,a1,59,44,7b,f0,d0,3f,19,85,dd,c0,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 19
Voici également le contenu du fichier Report.txt :
SDFix: Version 1.153
Run by Christine on 05/03/2008 at 10:28
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\services.exe - Deleted
C:\WINDOWS\system32\autorun.ini - Deleted
C:\WINDOWS\system32\real.txt - Deleted
Folder C:\Program Files\RichVideoCodec - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-05 10:51:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword
7eac169
"s2"=dword:8b9901f1
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:e6,93,c8,6b,87,e9,de,88,3f,03,5a,2c,f2,b3,71,c7,db,ed,42,aa,18,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,77,68,e9,7b,2c,62,cc,d2,cb,e1,70,a2,e9,43,4d,c4,69,..
"khjeh"=hex:41,5d,7a,bd,f5,b9,3d,fa,6b,9b,d5,de,00,a0,bf,54,15,dc,c3,57,58,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:6c,ae,b3,de,00,37,47,1f,a7,2f,0b,b6,17,17,1c,ff,e8,a8,60,16,be,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:64,62,02,00,18,51,33,00,18,e9,48,b5,d8,ff,ff,ff,76,6b,0a,00,40,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:0c,29,4d,11,10,37,14,2c,0e,b6,a1,59,44,7b,f0,d0,3f,19,85,dd,c0,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:e6,93,c8,6b,87,e9,de,88,3f,03,5a,2c,f2,b3,71,c7,db,ed,42,aa,18,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,77,68,e9,7b,2c,62,cc,d2,cb,e1,70,a2,e9,43,4d,c4,69,..
"khjeh"=hex:41,5d,7a,bd,f5,b9,3d,fa,6b,9b,d5,de,00,a0,bf,54,15,dc,c3,57,58,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:6c,ae,b3,de,00,37,47,1f,a7,2f,0b,b6,17,17,1c,ff,e8,a8,60,16,be,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:64,62,02,00,90,b8,20,00,a0,ee,20,00,e0,ff,ff,ff,76,6b,08,00,a8,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:0c,29,4d,11,10,37,14,2c,0e,b6,a1,59,44,7b,f0,d0,3f,19,85,dd,c0,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 19
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\FarStone\\VirtualDrive\\MGR.exe"="C:\\Program Files\\FarStone\\VirtualDrive\\MGR.exe:*
isabled:VirtualDrive MGR"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Hamachi\\hamachi.exe"="C:\\Program Files\\Hamachi\\hamachi.exe:*:Enabled:Hamachi Client"
"D:\\Program Files\\Steam\\SteamApps\\masteranakin02\\counter-strike\\hl.exe"="D:\\Program Files\\Steam\\SteamApps\\masteranakin02\\counter-strike\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\Program Files\\Steam\\SteamApps\\masteranakin02\\counter-strike source\\hl2.exe"="D:\\Program Files\\Steam\\SteamApps\\masteranakin02\\counter-strike source\\hl2.exe:*:Enabled:hl2"
"C:\\Documents and Settings\\Christine\\Mes documents\\ragnarok\\wow.exe"="C:\\Documents and Settings\\Christine\\Mes documents\\ragnarok\\wow.exe:*:Enabled:Blizzard Downloader"
"C:\\games\\RedFaction\\rf.exe"="C:\\games\\RedFaction\\rf.exe:*
isabled:Red Faction"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"C:\\Program Files\\Joost\\xulrunner\\tvprunner.exe"="C:\\Program Files\\Joost\\xulrunner\\tvprunner.exe:*:Enabled:tvprunner"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"D:\\Program Files\\Warcraft III\\Warcraft III.exe"="D:\\Program Files\\Warcraft III\\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. Take a deep breath "
"C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\services.exe"="C:\\DOCUME~1\\CHRIST~1\\LOCALS~1\\Temp\\services.exe:*:Enabled:Flash Media"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Sun 1 Apr 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 14 Nov 2007 27,136 ...H. --- "C:\Documents and Settings\Christine\Mes documents\~WRL0002.tmp"
Sun 25 Mar 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Wed 18 Jul 2007 1,060,864 A.SH. --- "C:\Documents and Settings\Christine\Mes documents\Noel 2007\100KM028\SIV31.tmp"
Finished!
En ce qui concerne la capture d'écran, j'arrive a la faire et à la mettre sur word mais je n'arrive pas à te l'envoyer.
Merci encore