Voila l'autre Rapport!
[b]SDFix: Version 1.240
/b
Run by cunnigganh on 21/03/2009 at 21:20
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services
/b:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files
/b:
No Trojan Files Found
Removing Temp Files
[b]ADS Check
/b:
[b]Final Check
/b:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-21 21:50:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:d2,35,ce,53,08,0f,e6,80,c4,89,e8,61,f2,f7,34,41,ea,a0,32,9e,5e,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000001
"khjeh"=hex:b4,8b,c9,cb,27,42,cf,82,1e,f7,52,b6,54,ca,e1,61,80,58,a3,02,8f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,46,70,fa,ce,df,7a,54,f4,e2,e3,8d,2c,16,59,35,bc,28,..
"khjeh"=hex:21,44,15,21,68,77,cc,c5,d8,a0,8c,d9,89,c9,52,a6,5f,b6,54,ca,0d,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:00,57,ba,44,b0,da,c3,65,e6,28,31,f9,df,94,79,d2,1a,b7,a5,e1,38,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:7f,b6,32,cb,86,d5,a9,06,39,0f,a5,5d,16,67,0e,f0,bc,db,50,a3,ba,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:edcdbdcd
"s2"=dword:12fe12ed
"h0"=dword:00000002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:d2,35,ce,53,08,0f,e6,80,c4,89,e8,61,f2,f7,34,41,ea,a0,32,9e,5e,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:83,ba,27,c1,f3,fe,31,64,1f,88,db,12,1b,39,e7,73,86,93,4a,0d,e1,..
"p0"="C:\Program Files\DAEMON Tools Lite\"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:f7,28,d0,20,48,ff,c9,4a,ca,14,38,ce,c4,ec,01,cb,47,92,4d,1f,4a,..
"a0"=hex:20,01,00,00,38,62,24,26,b8,99,63,7d,78,a2,e1,2c,7c,a9,3f,3a,1e,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:5e,a9,4b,11,ca,ea,ed,ab,23,76,98,ad,bc,50,2b,8e,5b,77,78,b1,01,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:5e,a9,4b,11,ca,ea,ed,ab,23,76,98,ad,bc,50,2b,8e,5b,77,78,b1,01,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:d2,35,ce,53,08,0f,e6,80,c4,89,e8,61,f2,f7,34,41,ea,a0,32,9e,5e,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000001
"khjeh"=hex:ff,1e,e1,64,17,cc,96,01,d3,83,ed,a4,7a,51,7d,c1,ff,3e,d9,f6,d6,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,46,70,fa,ce,df,7a,54,f4,e2,e3,8d,2c,16,59,35,bc,28,..
"khjeh"=hex:21,44,15,21,68,77,cc,c5,d8,a0,8c,d9,89,c9,52,a6,5f,b6,54,ca,0d,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:00,57,ba,44,b0,da,c3,65,e6,28,31,f9,df,94,79,d2,1a,b7,a5,e1,38,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:7f,b6,32,cb,86,d5,a9,06,39,0f,a5,5d,16,67,0e,f0,bc,db,50,a3,ba,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:d2,35,ce,53,08,0f,e6,80,c4,89,e8,61,f2,f7,34,41,ea,a0,32,9e,5e,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:83,ba,27,c1,f3,fe,31,64,1f,88,db,12,1b,39,e7,73,86,93,4a,0d,e1,..
"p0"="C:\Program Files\DAEMON Tools Lite\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:f7,28,d0,20,48,ff,c9,4a,ca,14,38,ce,c4,ec,01,cb,47,92,4d,1f,4a,..
"a0"=hex:20,01,00,00,38,62,24,26,b8,99,63,7d,78,a2,e1,2c,7c,a9,3f,3a,1e,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:5e,a9,4b,11,ca,ea,ed,ab,23,76,98,ad,bc,50,2b,8e,5b,77,78,b1,01,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:5e,a9,4b,11,ca,ea,ed,ab,23,76,98,ad,bc,50,2b,8e,5b,77,78,b1,01,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000298
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services
/b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Disabled:eMule"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"="C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main"
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"="C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD"
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"="C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater"
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"="C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server"
"C:\\Program Files\\Warcraft III\\Frozen Throne.exe"="C:\\Program Files\\Warcraft III\\Frozen Throne.exe:*:Enabled:Warcraft III - The Frozen Throne"
"C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"="C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe:*:Disabled:Football Manager 2008"
"C:\\WINDOWS\\explorer.exe"="C:\\WINDOWS\\explorer.exe:*:Enabled:Explorer"
"C:\\WINDOWS\\system32\\winlogon.exe"="C:\\WINDOWS\\system32\\winlogon.exe:*:Enabled:winlogon"
"C:\\WINDOWS\\system32\\logonui.exe"="C:\\WINDOWS\\system32\\logonui.exe:*:Enabled:LogonUI"
"C:\\Program Files\\Corel\\Corel GuideMenu\\GuideMenu.exe"="C:\\Program Files\\Corel\\Corel GuideMenu\\GuideMenu.exe:*:Enabled:GuideMenu"
"C:\\Program Files\\Steam\\SteamApps\\cmg5dr\\counter-strike source\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\cmg5dr\\counter-strike source\\hl2.exe:*:Enabled:hl2"
"C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:RUNDLL32"
"C:\\WINDOWS\\system32\\imapi.exe"="C:\\WINDOWS\\system32\\imapi.exe:*:Enabled:imapi"
"C:\\WINDOWS\\system32\\spoolsv.exe"="C:\\WINDOWS\\system32\\spoolsv.exe:*:Enabled:spoolsv"
"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe"="C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe:*:Enabled:avgas"
"C:\\WINDOWS\\system32\\lsass.exe"="C:\\WINDOWS\\system32\\lsass.exe:*:Enabled:lsass"
"C:\\Documents and Settings\\cunnigganh\\Local Settings\\Temp\\Rar$EX00.703\\EMPIRES2.ICD"="C:\\Documents and Settings\\cunnigganh\\Local Settings\\Temp\\Rar$EX00.703\\EMPIRES2.ICD:*:Enabled:Age of Empires II"
"C:\\Documents and Settings\\cunnigganh\\Local Settings\\Temp\\Rar$EX00.703\\age2_x1\\AGE2_X1.ICD"="C:\\Documents and Settings\\cunnigganh\\Local Settings\\Temp\\Rar$EX00.703\\age2_x1\\AGE2_X1.ICD:*:Enabled:Age of Empires II Expansion"
"C:\\Program Files\\GameSpy Arcade\\Aphex.exe"="C:\\Program Files\\GameSpy Arcade\\Aphex.exe:*:Enabled:GameSpy Arcade"
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\age2_x1.exe"="C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"C:\\WINDOWS\\system32\\dplaysvr.exe"="C:\\WINDOWS\\system32\\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\\WINDOWS\\system32\\services.exe"="C:\\WINDOWS\\system32\\services.exe:*:Enabled:services"
"C:\\WINDOWS\\system32\\userinit.exe"="C:\\WINDOWS\\system32\\userinit.exe:*:Enabled:userinit"
"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\guard.exe"="C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\guard.exe:*:Enabled:guard"
"C:\\Program Files\\Steam\\SteamApps\\common\\astropop deluxe\\WinAP.exe"="C:\\Program Files\\Steam\\SteamApps\\common\\astropop deluxe\\WinAP.exe:*:Enabled:AstroPop Deluxe Demo"
"C:\\Program Files\\Steam\\SteamApps\\common\\peggle extreme\\PeggleExtreme.exe"="C:\\Program Files\\Steam\\SteamApps\\common\\peggle extreme\\PeggleExtreme.exe:*:Enabled:Peggle Extreme"
"C:\\Documents and Settings\\cunnigganh\\Local Settings\\Temp\\Blizzard Launcher Temporary - 0360bb18\\Launcher.exe"="C:\\Documents and Settings\\cunnigganh\\Local Settings\\Temp\\Blizzard Launcher Temporary - 0360bb18\\Launcher.exe:*:Enabled:Blizzard Launcher"
"C:\\Program Files\\World of Warcraft\\Repair.exe"="C:\\Program Files\\World of Warcraft\\Repair.exe:*:Enabled:Blizzard Repair Utility"
"C:\\Program Files\\World of Warcraft\\Launcher.exe"="C:\\Program Files\\World of Warcraft\\Launcher.exe:*:Enabled:Blizzard Launcher"
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[b]Remaining Files
/b:
[b]Files with Hidden Attributes
/b:
Tue 17 Mar 2009 111,435 ..SHR --- "C:\luk1ylq.com"
Tue 27 Jan 2009 8 ..SHR --- "C:\WINDOWS\system32\12E7A7BBA9.sys"
Thu 29 Jan 2009 2,157 ..SH. --- "C:\WINDOWS\system32\dobazusi.exe"
Wed 28 Jan 2009 3,140 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Fri 23 Jan 2009 134,258 A.SH. --- "C:\WINDOWS\system32\kimapuge.dll"
--- 78,848 A.SH. --- "C:\WINDOWS\system32\mufezuwi.dll"
Fri 23 Jan 2009 134,258 A.SH. --- "C:\WINDOWS\system32\urbapm.dll"
Sat 12 May 2007 9 A..H. --- "C:\WINDOWS\system32\wxmmin.dll"
--- 44,032 A.SH. --- "C:\WINDOWS\system32\yigiwopa.dll"
Sun 19 Mar 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sun 21 Dec 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Mon 29 Sep 2008 1,301 ...HR --- "C:\Documents and Settings\cunnigganh\Application Data\SecuROM\UserData\securom_v7_01.bak"
Sun 19 Mar 2006 4,348 A..H. --- "C:\Documents and Settings\cunnigganh\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
Sun 20 Aug 2006 20 A..H. --- "C:\Documents and Settings\cunnigganh\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
Sat 5 Aug 2006 400 A.SH. --- "C:\Documents and Settings\cunnigganh\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
Sun 19 Mar 2006 4,348 ...H. --- "C:\Documents and Settings\vivamone\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
Wed 12 Jul 2006 20 A..H. --- "C:\Documents and Settings\vivamone\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
Sat 4 Mar 2006 312 A.SH. --- "C:\Documents and Settings\vivamone\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
[b]Finished!
/b