Le log final sdfix
comment je peux verifier qu'il ne reste rien?
en relancant tout depuis le depart?
Merci pour ton(votre) aide precieuse!
je vais faire la meme chose sur mon portable...
[b]SDFix: Version 1.181 /b
Run by Carpenter on 09/05/2008 at 19:33
Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\CARPEN~1\Bureau\SDFix
[b]Checking Services /b:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
[b]Checking Files /b:
Trojan Files Found:
C:\smp.bat - Deleted
Removing Temp Files
[b]ADS Check /b:
[b]Final Check /b:
catchme 0.3.1359.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-09 19:40:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
IPC error: 2 Le fichier spécifié est introuvable.
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:6be05fad
"s2"=dword:06aa690d
"h0"=dword:00000002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"p0"="C:\Program Files\DAEMON Tools Pro\"
"h0"=dword:00000001
"hdf12"=hex:bd,2f,2a,e4,7c,ec,f8,7b,0b,59,6a,86,15,df,16,55,c5,f9,87,ad,9c,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
"a0"=hex:20,01,00,00,9f,41,e2,15,de,25,99,ae,73,83,3c,b7,21,d5,b7,56,c1,..
"hdf12"=hex:20,cb,07,6a,8e,33,78,11,d1,dc,3d,70,ca,50,e4,25,d2,0c,ae,50,6b,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
"hdf12"=hex:57,43,22,60,c0,a6,d1,85,da,90,31,82,48,60,68,b1,d1,85,9d,2f,7a,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002]
"a0"=hex:20,01,00,00,6f,94,e3,15,14,c6,59,23,83,69,c5,85,10,aa,3f,10,f2,..
"hdf12"=hex:85,4f,b6,6f,4f,f0,56,e3,b9,39,13,aa,70,ff,0c,89,6a,6c,df,18,0a,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0]
"hdf12"=hex:80,e1,ce,4c,cf,25,36,ea,68,b6,9c,93,04,1f,75,48,55,52,e8,37,44,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq1]
"hdf12"=hex:b8,90,50,19,82,72,f0,a5,7c,58,37,3e,e1,b8,54,0f,32,99,a7,91,a0,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:6f,81,6d,94,df,c0,93,d1,65,fb,0e,1f,f5,ea,c0,77,78,db,8a,9b,41,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"p0"="C:\Program Files\DAEMON Tools Pro\"
"h0"=dword:00000001
"hdf12"=hex:bd,2f,2a,e4,7c,ec,f8,7b,0b,59,6a,86,15,df,16,55,c5,f9,87,ad,9c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
"a0"=hex:20,01,00,00,9f,41,e2,15,de,25,99,ae,73,83,3c,b7,21,d5,b7,56,c1,..
"hdf12"=hex:20,cb,07,6a,8e,33,78,11,d1,dc,3d,70,ca,50,e4,25,d2,0c,ae,50,6b,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
"hdf12"=hex:57,43,22,60,c0,a6,d1,85,da,90,31,82,48,60,68,b1,d1,85,9d,2f,7a,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002]
"a0"=hex:20,01,00,00,6f,94,e3,15,14,c6,59,23,83,69,c5,85,10,aa,3f,10,f2,..
"hdf12"=hex:85,4f,b6,6f,4f,f0,56,e3,b9,39,13,aa,70,ff,0c,89,6a,6c,df,18,0a,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0]
"hdf12"=hex:80,e1,ce,4c,cf,25,36,ea,68,b6,9c,93,04,1f,75,48,55,52,e8,37,44,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq1]
"hdf12"=hex:b8,90,50,19,82,72,f0,a5,7c,58,37,3e,e1,b8,54,0f,32,99,a7,91,a0,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:6f,81,6d,94,df,c0,93,d1,65,fb,0e,1f,f5,ea,c0,77,78,db,8a,9b,41,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services /b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Kerio\\Personal Firewall 4\\kpf4gui.exe"="C:\\Program Files\\Kerio\\Personal Firewall 4\\kpf4gui.exe:*:Enabled:Kerio Personal Firewall 4 - GUI"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Documents and Settings\\Carpenter\\Bureau\\utorrent.exe"="C:\\Documents and Settings\\Carpenter\\Bureau\\utorrent.exe:*:Enabled:æTorrent"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"E:\\Neverwinter\\nwn2main.exe"="E:\\Neverwinter\\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main"
"E:\\Neverwinter\\nwn2main_amdxp.exe"="E:\\Neverwinter\\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD"
"E:\\Neverwinter\\nwupdate.exe"="E:\\Neverwinter\\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater"
"E:\\Neverwinter\\nwn2server.exe"="E:\\Neverwinter\\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"E:\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\XR_3DA.exe"="E:\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\XR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)"
"E:\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\dedicated\\XR_3DA.exe"="E:\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\dedicated\\XR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"E:\\stalk\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\XR_3DA.exe"="E:\\stalk\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\XR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)"
"E:\\stalk\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\dedicated\\XR_3DA.exe"="E:\\stalk\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\dedicated\\XR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)"
"F:\\Jeux\\lost\\Lost Via Domus\\Yeti_Final_Win32.exe"="F:\\Jeux\\lost\\Lost Via Domus\\Yeti_Final_Win32.exe:*:Enabled:Lost Via Domus Game"
"F:\\Jeux\\lost\\Lost Via Domus\\gu.exe"="F:\\Jeux\\lost\\Lost Via Domus\\gu.exe:*:Enabled:Lost Via Domus Updater"
"F:\\Jeux\\lost\\Lost Via Domus\\detection\\Launcher.exe"="F:\\Jeux\\lost\\Lost Via Domus\\detection\\Launcher.exe:*:Enabled:Lost Via Domus Requirements Tool"
"F:\\Jeux\\HGL\\Launcher.exe"="F:\\Jeux\\HGL\\Launcher.exe:*:Enabled:Hellgate : London"
"C:\\Documents and Settings\\Carpenter\\Bureau\\utorrent-1.8-beta-9704.upx.exe"="C:\\Documents and Settings\\Carpenter\\Bureau\\utorrent-1.8-beta-9704.upx.exe:*:Enabled:æTorrent"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files /b:
File Backups: - C:\DOCUME~1\CARPEN~1\Bureau\SDFix\backups\backups.zip
[b]Files with Hidden Attributes /b:
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Fri 27 Feb 2004 233,472 A..H. --- "C:\Program Files\Image-Line\FL Studio 7\REX Shared Library.dll"
Sun 8 Apr 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Thu 3 Apr 2008 10,051 ...HR --- "C:\Documents and Settings\Carpenter\Application Data\SecuROM\UserData\securom_v7_01.bak"
Tue 12 Jun 2007 290,816 ...H. --- "C:\Documents and Settings\Carpenter\Mes documents\Geoffroy\altedia\~WRL0002.tmp"