Et voici le 2ème rapport :
[b]SDFix: Version 1.240 /b
Run by Isabelle on 31/03/2009 at 10:46
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services /b:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files /b:
No Trojan Files Found
Removing Temp Files
[b]ADS Check /b:
[b]Final Check /b:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-31 11:03:39
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ovfsthxfonkobjpxotrvdebwdtkgpewklqqsyb]
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=str(2):"\systemroot\system32\drivers\ovfsthgrhayesdsmfbhmuijicpocslxnmqwqky.sys"
"inst"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ovfsthxfonkobjpxotrvdebwdtkgpewklqqsyb\main]
"ver"="icv230309"
"cid"="02"
"bid"="1013082430-725345543-879983540-2146883605"
"aid"="303369"
"sid"="16"
"feed"=hex:22,64,78,36,3c,2e,3b,29,39,3b,3b,3a,04,4f,01,0c,09,65
"cmddelay"=dword:00003841
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ovfsthxfonkobjpxotrvdebwdtkgpewklqqsyb\modules]
"ovfsth.dll"="\systemroot\system32\ovfsthjcaqumwaqipmoamgidemrcymfxrcjlgy.dll"
"ovfsth.sys"="\systemroot\system32\drivers\ovfsthgrhayesdsmfbhmuijicpocslxnmqwqky.sys"
"ovfsthlog.dat"="\systemroot\system32\ovfstheercupogmaqqtuhntosdsvosefacanum.dat"
"ovfsthwi.dll"="\systemroot\system32\ovfsthschtmqeceqiqdtkrabpruiychhtwjaak.dll"
"ovfsthff.dll"="\systemroot\system32\ovfsthjohhgushqsncbeftcrtmtjrueebbiynq.dll"
"ovfsth.dat"="\systemroot\system32\ovfsthbumiyqpjvhmuaiptnscgbcvopbxcwcnw.dat"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\ovfsthxfonkobjpxotrvdebwdtkgpewklqqsyb]
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=str(2):"\systemroot\system32\drivers\ovfsthgrhayesdsmfbhmuijicpocslxnmqwqky.sys"
"inst"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\ovfsthxfonkobjpxotrvdebwdtkgpewklqqsyb\main]
"ver"="icv230309"
"cid"="02"
"bid"="1013082430-725345543-879983540-2146883605"
"aid"="303369"
"sid"="16"
"feed"=hex:22,64,78,36,3c,2e,3b,29,39,3b,3b,3a,04,4f,01,0c,09,65
"cmddelay"=dword:00003841
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\ovfsthxfonkobjpxotrvdebwdtkgpewklqqsyb\modules]
"ovfsth.dll"="\systemroot\system32\ovfsthjcaqumwaqipmoamgidemrcymfxrcjlgy.dll"
"ovfsth.sys"="\systemroot\system32\drivers\ovfsthgrhayesdsmfbhmuijicpocslxnmqwqky.sys"
"ovfsthlog.dat"="\systemroot\system32\ovfstheercupogmaqqtuhntosdsvosefacanum.dat"
"ovfsthwi.dll"="\systemroot\system32\ovfsthschtmqeceqiqdtkrabpruiychhtwjaak.dll"
"ovfsthff.dll"="\systemroot\system32\ovfsthjohhgushqsncbeftcrtmtjrueebbiynq.dll"
"ovfsth.dat"="\systemroot\system32\ovfsthbumiyqpjvhmuaiptnscgbcvopbxcwcnw.dat"
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update]
"OfflineDetectionPending"=dword:00000001
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services /b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\WINDOWS\\system32\\mshta.exe"="C:\\WINDOWS\\system32\\mshta.exe:*:Enabled:Microsoft (R) HTML Application host"
"C:\\Documents and Settings\\Isabelle\\Mes documents\\WLinstaller.exe"="C:\\Documents and Settings\\Isabelle\\Mes documents\\WLinstaller.exe:*:Enabled:WLinstaller"
"C:\\Documents and Settings\\Isabelle\\Bureau\\MsgPlusLive-470.exe"="C:\\Documents and Settings\\Isabelle\\Bureau\\MsgPlusLive-470.exe:*:Enabled:MsgPlusLive-470"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:LocalSubNet:Enabled:eMule"
"C:\\WINDOWS\\system32\\jmvklc.exe"="C:\\WINDOWS\\system32\\jmvklc.exe:*:Disabled:gDGTEvDF"
"C:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"="C:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe:*:Enabled:mbam"
"C:\\WINDOWS\\system32\\frmwrk32.exe"="C:\\WINDOWS\\system32\\frmwrk32.exe:*:Enabled:frmwrk32"
"C:\\WINDOWS\\system32\\lsass.exe"="C:\\WINDOWS\\system32\\lsass.exe:*:Enabled:lsass"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[b]Remaining Files /b:
[b]Files with Hidden Attributes /b:
Mon 7 Jul 2008 1,429,840 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 7 Jul 2008 4,891,472 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 7 Jul 2008 2,156,368 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Tue 24 Mar 2009 23,475 ..SH. --- "C:\WINDOWS\system32\vidajadu.dll"
Tue 24 Mar 2009 23,475 ..SH. --- "C:\WINDOWS\system32\zotemiso.dll"
Thu 18 Dec 2008 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 7 Mar 2001 311,296 ...HR --- "C:\WINDOWS\system32\Tools\AC2K.exe"
Wed 21 Feb 2001 310,784 ...HR --- "C:\WINDOWS\system32\Tools\AC98.exe"
Wed 21 Feb 2001 311,296 ...HR --- "C:\WINDOWS\system32\Tools\ACL98.exe"
Wed 21 Feb 2001 311,808 ...HR --- "C:\WINDOWS\system32\Tools\ACLME.exe"
Fri 27 Apr 2001 327,168 ...HR --- "C:\WINDOWS\system32\Tools\All.exe"
Fri 24 Nov 2000 316,416 ...HR --- "C:\WINDOWS\system32\Tools\AutoClick.exe"
Tue 16 Oct 2001 363,008 ...HR --- "C:\WINDOWS\system32\Tools\Change.exe"
Thu 11 Apr 2002 547,840 ...HR --- "C:\WINDOWS\system32\Tools\CheckPath.exe"
Fri 31 Aug 2001 381,440 ...HR --- "C:\WINDOWS\system32\Tools\Counter.exe"
Mon 21 Jan 2002 360,960 ...HR --- "C:\WINDOWS\system32\Tools\DelDv.exe"
Tue 20 Mar 2001 532,480 ...HR --- "C:\WINDOWS\system32\Tools\DeleteFiles.exe"
Mon 21 Jan 2002 360,960 ...HR --- "C:\WINDOWS\system32\Tools\DelT2.exe"
Mon 21 Jan 2002 360,960 ...HR --- "C:\WINDOWS\system32\Tools\DelT2Dv.exe"
Wed 6 Mar 2002 360,960 ...HR --- "C:\WINDOWS\system32\Tools\DelTools.exe"
Mon 11 Mar 2002 361,472 ...HR --- "C:\WINDOWS\system32\Tools\LostRun.exe"
Tue 3 Apr 2001 296,960 ...HR --- "C:\WINDOWS\system32\Tools\RegClean.exe"
Fri 8 Mar 2002 369,152 ...HR --- "C:\WINDOWS\system32\Tools\Regexe.exe"
Fri 8 Mar 2002 382,464 ...HR --- "C:\WINDOWS\system32\Tools\Restart.exe"
Fri 8 Mar 2002 374,784 ...HR --- "C:\WINDOWS\system32\Tools\RunAP.exe"
Fri 8 Mar 2002 360,960 ...HR --- "C:\WINDOWS\system32\Tools\RunRegexe.exe"
Fri 2 Nov 2001 379,392 ...HR --- "C:\WINDOWS\system32\Tools\SDW98ME.exe"
Fri 9 Mar 2001 312,832 ...HR --- "C:\WINDOWS\system32\Tools\SoundDrv.exe"
Fri 5 Dec 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
[b]Finished!/b