voilà le rapport:
SDFix: Version 1.79
Run by VINCENT - 23/04/2007 - 2:57:18,43
Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\VINCEN~1.VIR\Bureau\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
No Trojan Files Found...
Removing Temp Files
ADS Check:
Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.
Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servi
ces\SharedAccess\Parameters\FirewallPolicy\Standar
dProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste
m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program
Files\\BitTornado\\btdownloadgui.exe"="C:\\Program
Files\\BitTornado\\btdownloadgui.exe:*:Enabled:btd
ownloadgui"
"C:\\WINDOWS\\system32\\LEXPPS.EXE"="C:\\WINDOWS\\
system32\\LEXPPS.EXE:*:Disabled:LEXPPS.EXE"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\TribalWeb.net\\tribalweb.exe"="C:\\Program
Files\\TribalWeb.net\\tribalweb.exe:*:Enabled:Trib
alWeb.net : Réseau privé sur Internet"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servi
ces\SharedAccess\Parameters\FirewallPolicy\DomainP
rofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste
m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
Remaining Files:
---------------
Checking For Files with Hidden Attributes:
C:\Documents and Settings\VINCENT.VIRGINIE\Local Settings\Application
Data\Microsoft\Messenger\vincent.teriaaaaa@hotmail
.fr\Sharing Folders\riddersdu78@msn.com\Furry Bomb # 4\Thumbs.db
C:\Documents and Settings\VINCENT.VIRGINIE\Local Settings\Application
Data\Microsoft\Messenger\vincent.teriaaaaa@hotmail
.fr\Sharing Folders\riddersdu78@msn.com\Furrybomb\Thumbs.db
C:\Documents and Settings\VINCENT.VIRGINIE\Local Settings\Application
Data\Microsoft\Messenger\vincent.teriaaaaa@hotmail
.fr\Sharing Folders\riddersdu78@msn.com\Furrybomb 3\Thumbs.db
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Documents and
Settings\VINCENT.VIRGINIE\Bureau\Divers\Zelda\~WRL
0004.tmp
Finished
et j´ai supprimez les deux fichiers infectés qui se trouvé dans la liste 