Voici le dernier rapport avec sdfix, c'est bon maintenant?
[b]SDFix: Version 1.240 /b
Run by Administrateur on 17/05/2009 at 23:51
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services /b:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files /b:
Trojan Files Found:
C:\WINDOWS\system32\118.tmp - Deleted
Removing Temp Files
[b]ADS Check /b:
[b]Final Check /b:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-18 00:14:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:3e,bd,b3,38,97,02,13,fd,b1,f4,3d,d6,88,98,54,5c,15,b5,be,65,ac,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:3e,bd,b3,38,97,02,13,fd,b1,f4,3d,d6,88,98,54,5c,15,b5,be,65,ac,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:3e,bd,b3,38,97,02,13,fd,b1,f4,3d,d6,88,98,54,5c,15,b5,be,65,ac,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:3e,bd,b3,38,97,02,13,fd,b1,f4,3d,d6,88,98,54,5c,15,b5,be,65,ac,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services /b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\p2pnetworks\\p2pnetworks.exe"="C:\\Program Files\\p2pnetworks\\p2pnetworks.exe:*:Enabled:P2PNetworks"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Lecteur CANALPLAY\\CanalPlayer.exe"="C:\\Program Files\\Lecteur CANALPLAY\\CanalPlayer.exe:*:Enabled:Lecteur CANALPLAY"
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"="C:\\Program Files\\Winamp Remote\\bin\\Orb.exe:*:Enabled:Orb"
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe:*:Enabled:OrbTray"
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\eMule\\eMule.exe"="C:\\Program Files\\eMule\\eMule.exe:*:Enabled:eMule Plus"
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"="C:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe:*:Enabled:avast! Antivirus"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\River Past\\Audio Converter Pro\\AudioConverter.exe"="C:\\Program Files\\River Past\\Audio Converter Pro\\AudioConverter.exe:*:Enabled:River Past Audio Converter Pro"
"C:\\Documents and Settings\\Ludwig Collin\\Local Settings\\Temp\\Blizzard Launcher Temporary - 1ada5038\\Launcher.exe"="C:\\Documents and Settings\\Ludwig Collin\\Local Settings\\Temp\\Blizzard Launcher Temporary - 1ada5038\\Launcher.exe:*:Enabled:Blizzard Launcher"
"C:\\Documents and Settings\\Ludwig Collin\\Local Settings\\Temp\\Blizzard Launcher Temporary - 895384a8\\Launcher.exe"="C:\\Documents and Settings\\Ludwig Collin\\Local Settings\\Temp\\Blizzard Launcher Temporary - 895384a8\\Launcher.exe:*:Enabled:Blizzard Launcher"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Ex‚cuter une DLL en tant qu'application"
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\World of Warcraft\\Launcher.exe"="C:\\Program Files\\World of Warcraft\\Launcher.exe:*:Enabled:Blizzard Launcher"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[b]Remaining Files /b:
File Backups: - C:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes /b:
Fri 12 Oct 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 3 Jan 2006 2,658,304 ...H. --- "C:\Documents and Settings\Juliette Ledru\Mes documents\~WRL1787.tmp"
Tue 3 Jan 2006 3,575,808 ...H. --- "C:\Documents and Settings\Juliette Ledru\Mes documents\~WRL3332.tmp"
Tue 3 Jan 2006 2,659,328 ...H. --- "C:\Documents and Settings\Juliette Ledru\Mes documents\~WRL3460.tmp"
Tue 3 Jan 2006 2,658,816 ...H. --- "C:\Documents and Settings\Juliette Ledru\Mes documents\~WRL3526.tmp"
Thu 28 Feb 2008 27,648 ...H. --- "C:\Documents and Settings\Ludwig Collin\Mes documents\~WRL0260.tmp"
Fri 28 Sep 2007 46,080 ...H. --- "C:\Documents and Settings\Ludwig Collin\Mes documents\~WRL0362.tmp"
Thu 28 Feb 2008 30,208 ...H. --- "C:\Documents and Settings\Ludwig Collin\Mes documents\~WRL1287.tmp"
Thu 28 Feb 2008 27,648 ...H. --- "C:\Documents and Settings\Ludwig Collin\Mes documents\~WRL2230.tmp"
Tue 7 Feb 2006 299,008 A..H. --- "C:\Program Files\Canon\MP Navigator 3.0\Maint.exe"
Mon 25 Apr 2005 61,440 A..H. --- "C:\Program Files\Canon\MP Navigator 3.0\uinstrsc.dll"
Thu 1 Nov 2007 593 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti208.tmp"
Mon 5 Nov 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Thu 14 May 2009 50,970 ...H. --- "C:\Documents and Settings\Ludwig Collin\Mes documents\eFax Messenger 4.2\J2GPlus.exe-BarState"
Mon 29 Jan 2007 22,016 ...H. --- "C:\Documents and Settings\Juliette Ledru\Application Data\Microsoft\Word\~WRL0003.tmp"
Sat 10 Dec 2005 52,736 ...H. --- "C:\Documents and Settings\Juliette Ledru\Application Data\Microsoft\Word\~WRL0005.tmp"
Mon 29 Jan 2007 21,504 ...H. --- "C:\Documents and Settings\Juliette Ledru\Application Data\Microsoft\Word\~WRL0006.tmp"
Tue 3 Jan 2006 2,658,816 ...H. --- "C:\Documents and Settings\Juliette Ledru\Application Data\Microsoft\Word\~WRL1345.tmp"
Tue 7 Aug 2007 36,864 ...H. --- "C:\Documents and Settings\Juliette Ledru\Application Data\Microsoft\Word\~WRL1449.tmp"
Fri 3 Aug 2007 102,912 ...H. --- "C:\Documents and Settings\Ludwig Collin\Application Data\Microsoft\Word\~WRL0138.tmp"
Fri 3 Aug 2007 78,848 ...H. --- "C:\Documents and Settings\Ludwig Collin\Application Data\Microsoft\Word\~WRL2854.tmp"
Fri 3 Aug 2007 102,912 ...H. --- "C:\Documents and Settings\Ludwig Collin\Application Data\Microsoft\Word\~WRL3932.tmp"
[b]Finished!/b