Voilà la suite.
SDFix: Version 1.129
Run by ALeX on 19/01/2008 at 22:33
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
No Trojan Files Found
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-19 22:45:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1006
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"="%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe:*:Enabled:SPLINTER CELL PANDORA"
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"="%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe:*:Enabled:PANDORA"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\APPS\\Inventime\\my.exe"="C:\\APPS\\Inventime\\my.exe:*:Enabled:INVENTIME"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\Sierra On-Line\\SIGSPat.exe"="C:\\Program Files\\Sierra On-Line\\SIGSPat.exe:*:Enabled:SIGSPat"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Disabled:Internet Explorer"
"C:\\Program Files\\i-Media\\ims.exe"="C:\\Program Files\\i-Media\\ims.exe:*:Disabled:i-Minitel Serveur"
"C:\\WINDOWS\\system32\\rtcshare.exe"="C:\\WINDOWS\\system32\\rtcshare.exe:*:Disabled:Partage de l'application RTC"
"C:\\Program Files\\AOL 9.0\\aol.exe"="C:\\Program Files\\AOL 9.0\\aol.exe:*:Disabled:AOL"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Disabled:eMule"
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"="C:\\Program Files\\Windows Media Player\\wmplayer.exe:*:Enabled:Lecteur Windows Media"
"C:\\Program Files\\CheckFlow\\FlowProtector\\5.0.0.2\\FlowService.exe"="C:\\Program Files\\CheckFlow\\FlowProtector\\5.0.0.2\\FlowService.exe:*:Enabled:FlowProtector 2006"
"C:\\Program Files\\CheckFlow\\FlowProtector\\5.0.0.2\\Fp2006.exe"="C:\\Program Files\\CheckFlow\\FlowProtector\\5.0.0.2\\Fp2006.exe:*:Enabled:FlowProtector2006"
"C:\\Program Files\\CheckFlow\\FlowProtector\\5.0.0.2\\FlowBrowser.exe"="C:\\Program Files\\CheckFlow\\FlowProtector\\5.0.0.2\\FlowBrowser.exe:*:Enabled:FlowBrowser.exe"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\CheckFlow\\FlowProtector\\5.0.0.1\\FlowService.exe"="C:\\Program Files\\CheckFlow\\FlowProtector\\5.0.0.1\\FlowService.exe:*:Enabled:FlowProtector2006"
"C:\\Program Files\\CheckFlow\\FlowProtector\\5.0.0.1\\Fp2006.exe"="C:\\Program Files\\CheckFlow\\FlowProtector\\5.0.0.1\\Fp2006.exe:*:Enabled:FlowProtector2006"
"C:\\Program Files\\CheckFlow\\FlowProtector\\5.0.0.1\\FlowBrowser.exe"="C:\\Program Files\\CheckFlow\\FlowProtector\\5.0.0.1\\FlowBrowser.exe:*:Enabled:FlowBrowser.exe"
"C:\\Program Files\\Biromsoft\\WebCam\\BWebCam.exe"="C:\\Program Files\\Biromsoft\\WebCam\\BWebCam.exe:*:Disabled:BWebCam"
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\age2_x1.icd"="C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\age2_x1.icd:*:Enabled:Age of Empires II Expansion"
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"="C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe:*:Enabled:BlueSoleil"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Disabled:Skype"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\Sprite Software\\Sprite Backup\\SpriteService.exe"="C:\\Program Files\\Sprite Software\\Sprite Backup\\SpriteService.exe:*:Enabled:Sprite Backup PC Service"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
Remaining Files:
---------------
Files with Hidden Attributes:
Mon 7 Mar 2005 215 A.SHR --- "C:\BOOT.BAK"
Fri 12 Mar 2004 54,384 A..H. --- "C:\Program Files\AOL 9.0\aolphx.exe"
Fri 12 Mar 2004 156,784 A..H. --- "C:\Program Files\AOL 9.0\aoltray.exe"
Fri 12 Mar 2004 31,344 A..H. --- "C:\Program Files\AOL 9.0\RBM.exe"
Tue 12 Dec 2006 47,104 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL0074.tmp"
Sat 6 Jan 2007 25,088 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL0177.tmp"
Sat 6 Jan 2007 25,088 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL0285.tmp"
Tue 12 Dec 2006 44,032 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL0433.tmp"
Tue 12 Dec 2006 45,568 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL0624.tmp"
Sat 6 Jan 2007 25,088 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL0867.tmp"
Tue 12 Dec 2006 43,008 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL0917.tmp"
Sat 6 Jan 2007 25,088 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL0987.tmp"
Sat 6 Jan 2007 25,088 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL1091.tmp"
Sat 6 Jan 2007 28,672 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL1094.tmp"
Sat 6 Jan 2007 25,600 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL1179.tmp"
Tue 12 Dec 2006 45,568 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL1279.tmp"
Sat 6 Jan 2007 28,672 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL1371.tmp"
Sat 6 Jan 2007 25,600 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL1500.tmp"
Tue 12 Dec 2006 43,008 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL1616.tmp"
Tue 12 Dec 2006 45,056 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL1657.tmp"
Sat 6 Jan 2007 25,600 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL2028.tmp"
Sat 6 Jan 2007 24,064 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL2986.tmp"
Tue 12 Dec 2006 44,032 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL3246.tmp"
Sat 6 Jan 2007 24,576 ...H. --- "C:\Documents and Settings\ALeX\Bureau\~WRL4034.tmp"
Fri 29 Apr 2005 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 29 Apr 2005 401 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv16.bak"
Thu 25 May 2006 312,832 ...H. --- "C:\Documents and Settings\Jo\Bureau\~WRL0805.tmp"
Thu 25 May 2006 318,464 ...H. --- "C:\Documents and Settings\Jo\Bureau\~WRL2586.tmp"
Thu 25 May 2006 324,096 ...H. --- "C:\Documents and Settings\Jo\Bureau\~WRL3857.tmp"
Thu 21 Apr 2005 367 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti4.tmp"
Thu 31 May 2007 1,121,792 A.SH. --- "C:\Documents and Settings\ALeX\Bureau\London\SIV2.tmp"
Sun 7 Jan 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Fri 29 Dec 2006 0 A..H. --- "C:\Program Files\CheckFlow\FlowProtector\Administrateur.ADMINISTRATEUR.001\BIT293.tmp"
Tue 10 Jan 2006 0 A..H. --- "C:\Program Files\CheckFlow\FlowProtector\Jo\BIT5.tmp"
Fri 12 Mar 2004 106,496 A..H. --- "C:\Program Files\Fichiers communs\aolshare\shell\fr\shellext.dll"
Finished!