Re, et encore merci pour ta patience. Je vais poster les rapporte séparément
Rapport de "SDFix"
[b]SDFix: Version 1.240
/b
Run by TAF on 17/06/2009 at 18:01
Microsoft Windows XP [version 5.1.2600]
Running From: H:\SDFix
[b]Checking Services
/b:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files
/b:
No Trojan Files Found
Removing Temp Files
[b]ADS Check
/b:
[b]Final Check
/b:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-17 18:40:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="H:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:5f,0b,12,9f,53,41,c6,3d,bb,31,b3,56,e5,4a,51,de,42,5d,f4,a8,86,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,5b,b6,03,45,f0,29,40,13,1f,eb,c3,ef,3d,ae,19,27,4d,..
"khjeh"=hex:4a,fc,07,05,bf,ae,2f,70,d7,ba,86,6d,8c,38,a7,01,69,20,3d,af,07,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:c0,f4,ae,f6,fc,e0,bc,07,13,9a,b1,3f,4e,b3,2e,b0,26,33,3f,90,d2,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="H:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:5f,0b,12,9f,53,41,c6,3d,bb,31,b3,56,e5,4a,51,de,42,5d,f4,a8,86,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,5b,b6,03,45,f0,29,40,13,1f,eb,c3,ef,3d,ae,19,27,4d,..
"khjeh"=hex:4a,fc,07,05,bf,ae,2f,70,d7,ba,86,6d,8c,38,a7,01,69,20,3d,af,07,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:c0,f4,ae,f6,fc,e0,bc,07,13,9a,b1,3f,4e,b3,2e,b0,26,33,3f,90,d2,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="H:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:5f,0b,12,9f,53,41,c6,3d,bb,31,b3,56,e5,4a,51,de,42,5d,f4,a8,86,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,5b,b6,03,45,f0,29,40,13,1f,eb,c3,ef,3d,ae,19,27,4d,..
"khjeh"=hex:4a,fc,07,05,bf,ae,2f,70,d7,ba,86,6d,8c,38,a7,01,69,20,3d,af,07,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:c0,f4,ae,f6,fc,e0,bc,07,13,9a,b1,3f,4e,b3,2e,b0,26,33,3f,90,d2,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="H:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:5f,0b,12,9f,53,41,c6,3d,bb,31,b3,56,e5,4a,51,de,42,5d,f4,a8,86,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,5b,b6,03,45,f0,29,40,13,1f,eb,c3,ef,3d,ae,19,27,4d,..
"khjeh"=hex:4a,fc,07,05,bf,ae,2f,70,d7,ba,86,6d,8c,38,a7,01,69,20,3d,af,07,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:7b,4b,d5,1f,00,38,b8,90,1f,c9,47,ac,33,47,81,36,6f,18,ea,3d,f0,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="H:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:5f,0b,12,9f,53,41,c6,3d,bb,31,b3,56,e5,4a,51,de,42,5d,f4,a8,86,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,5b,b6,03,45,f0,29,40,13,1f,eb,c3,ef,3d,ae,19,27,4d,..
"khjeh"=hex:4a,fc,07,05,bf,ae,2f,70,d7,ba,86,6d,8c,38,a7,01,69,20,3d,af,07,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:c0,f4,ae,f6,fc,e0,bc,07,13,9a,b1,3f,4e,b3,2e,b0,26,33,3f,90,d2,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="H:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:5f,0b,12,9f,53,41,c6,3d,bb,31,b3,56,e5,4a,51,de,42,5d,f4,a8,86,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,5b,b6,03,45,f0,29,40,13,1f,eb,c3,ef,3d,ae,19,27,4d,..
"khjeh"=hex:4a,fc,07,05,bf,ae,2f,70,d7,ba,86,6d,8c,38,a7,01,69,20,3d,af,07,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:c0,f4,ae,f6,fc,e0,bc,07,13,9a,b1,3f,4e,b3,2e,b0,26,33,3f,90,d2,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="H:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:5f,0b,12,9f,53,41,c6,3d,bb,31,b3,56,e5,4a,51,de,42,5d,f4,a8,86,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,5b,b6,03,45,f0,29,40,13,1f,eb,c3,ef,3d,ae,19,27,4d,..
"khjeh"=hex:4a,fc,07,05,bf,ae,2f,70,d7,ba,86,6d,8c,38,a7,01,69,20,3d,af,07,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:c0,f4,ae,f6,fc,e0,bc,07,13,9a,b1,3f,4e,b3,2e,b0,26,33,3f,90,d2,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="H:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:5f,0b,12,9f,53,41,c6,3d,bb,31,b3,56,e5,4a,51,de,42,5d,f4,a8,86,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,5b,b6,03,45,f0,29,40,13,1f,eb,c3,ef,3d,ae,19,27,4d,..
"khjeh"=hex:4a,fc,07,05,bf,ae,2f,70,d7,ba,86,6d,8c,38,a7,01,69,20,3d,af,07,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:c0,f4,ae,f6,fc,e0,bc,07,13,9a,b1,3f,4e,b3,2e,b0,26,33,3f,90,d2,..
scanning hidden registry entries ...
scanning hidden files ...
H:\Documents and Settings\TAF\Local Settings\Application Data\Microsoft\Windows\GameExplorer\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}\PlayTasks\1\Les Sims™ 2 : Boit@Look.lnk 1087 bytes hidden from API
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1
[b]Remaining Services
/b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"H:\\Program Files\\Messenger\\msmsgs.exe"="H:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"H:\\Program Files\\uTorrent\\uTorrent.exe"="H:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"H:\\Program Files\\Hercules\\Classic Silver\\Station2.exe"="H:\\Program Files\\Hercules\\Classic Silver\\Station2.exe:*:Enabled:Hercules Webcam Station Evolution"
"H:\\Program Files\\FlashGet\\flashget.exe"="H:\\Program Files\\FlashGet\\flashget.exe:*:Enabled:Flashget"
"H:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2.exe"="H:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2.exe:*:Enabled:Ghost Recon Advanced Warfighter© 2"
"H:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="H:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"H:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="H:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"H:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="H:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"H:\\Program Files\\ma-config.com\\maconfservice.exe"="H:\\Program Files\\ma-config.com\\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
"H:\\Documents and Settings\\TAF\\Bureau\\CabalTemp\\ESTSetupLoader.exe"="H:\\Documents and Settings\\TAF\\Bureau\\CabalTemp\\ESTSetupLoader.exe:*:Enabled:EST! download engine"
"H:\\Program Files\\Games-Masters.com\\CABAL Online (Europe)\\launcher\\update\\ESTdnheadless.exe"="H:\\Program Files\\Games-Masters.com\\CABAL Online (Europe)\\launcher\\update\\ESTdnheadless.exe:*:Enabled:EST! download engine"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"H:\\Documents and Settings\\TAF\\Bureau\\Fotos.exe"="H:\\Documents and Settings\\TAF\\Bureau\\Fotos.exe:*:Enabled:Session Win32"
"H:\\Program Files\\Microsoft Studio Files\\lsass.exe"="H:\\Program Files\\Microsoft Studio Files\\lsass.exe:*:Enabled:Session Win32"
"H:\\Program Files\\skmw\\gwdwin.exe"="H:\\Program Files\\skmw\\gwdwin.exe:*:Enabled:Session Win32"
"H:\\Program Files\\skmw\\irc.exe"="H:\\Program Files\\skmw\\irc.exe:*:Enabled:WinIRC"
"H:\\Program Files\\dwimn\\mwstwn.exe"="H:\\Program Files\\dwimn\\mwstwn.exe:*:Enabled:Session Win32"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"H:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="H:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"H:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="H:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"H:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="H:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files
/b:
[b]Files with Hidden Attributes
/b:
Sat 25 Apr 2009 636,088 A.SH. --- H:\PROGRA~1\INTERN~1\IEXPLORE.EXE
Thu 19 Aug 2004 1,667,584 ..SH. --- H:\PROGRA~1\MESSEN~1\MSMSGS.EXE
Thu 19 Aug 2004 60,416 A.SH. --- H:\PROGRA~1\OUTLOO~1\MSIMN.EXE
Wed 22 Oct 2008 949,072 A.SHR --- H:\PROGRA~1\SPYBOT~1\ADVCHECK.DLL
Mon 15 Sep 2008 1,562,960 A.SHR --- H:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
Wed 22 Oct 2008 962,896 A.SHR --- H:\PROGRA~1\SPYBOT~1\TOOLS.DLL
Thu 12 Jun 2008 4,348 A.SH. --- H:\DOCUME~1\ALLUSE~1\DRM\DRMV1.BAK
[b]Finished!
/b