[b]SDFix: Version 1.187 /b
Run by 1 A Les renoux on 02/06/2008 at 16:41
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services /b:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
[b]Checking Files /b:
No Trojan Files Found
Removing Temp Files
[b]ADS Check /b:
[b]Final Check /b:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-02 16:50:31
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:91e31109
"s2"=dword:8dae28cc
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:17,e1,25,a8,26,9e,e0,aa,d9,6a,8f,be,04,bc,3a,fd,58,21,bf,6e,8c,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,07,7a,61,93,5c,08,f8,c3,db,0d,cb,c8,99,f6,00,0b,d9,..
"khjeh"=hex:da,ff,04,60,74,7d,e8,d8,1c,70,0f,d8,93,68,73,fa,c9,c4,39,a4,23,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:bb,e4,96,38,85,ae,2c,55,0b,25,30,58,ce,63,e9,aa,b8,a7,ee,78,b5,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:17,e1,25,a8,26,9e,e0,aa,d9,6a,8f,be,04,bc,3a,fd,58,21,bf,6e,8c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,07,7a,61,93,5c,08,f8,c3,db,0d,cb,c8,99,f6,00,0b,d9,..
"khjeh"=hex:da,ff,04,60,74,7d,e8,d8,1c,70,0f,d8,93,68,73,fa,c9,c4,39,a4,23,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:bb,e4,96,38,85,ae,2c,55,0b,25,30,58,ce,63,e9,aa,b8,a7,ee,78,b5,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:17,e1,25,a8,26,9e,e0,aa,d9,6a,8f,be,04,bc,3a,fd,58,21,bf,6e,8c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,07,7a,61,93,5c,08,f8,c3,db,0d,cb,c8,99,f6,00,0b,d9,..
"khjeh"=hex:da,ff,04,60,74,7d,e8,d8,1c,70,0f,d8,93,68,73,fa,c9,c4,39,a4,23,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:bb,e4,96,38,85,ae,2c,55,0b,25,30,58,ce,63,e9,aa,b8,a7,ee,78,b5,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update]
"OfflineDetectionPending"=dword:00000001
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services /b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Documents and Settings\\Les renoux.RENOUX\\Mes documents\\microtorrent_torrent_1.7.5_anglais_18245.exe"="C:\\Documents and Settings\\Les renoux.RENOUX\\Mes documents\\microtorrent_torrent_1.7.5_anglais_18245.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Valve\\Steam\\SteamApps\\stornugl\\condition zero\\hl.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\stornugl\\condition zero\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\Microsoft Office\\Office10\\WINWORD.EXE"="C:\\Program Files\\Microsoft Office\\Office10\\WINWORD.EXE:*:Enabled:Microsoft Word"
"C:\\Program Files\\Valve\\Steam\\SteamApps\\stornugl\\counter-strike\\hl.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\stornugl\\counter-strike\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\Joost\\xulrunner\\tvprunner.exe"="C:\\Program Files\\Joost\\xulrunner\\tvprunner.exe:*:Enabled:tvprunner"
"C:\\Program Files\\Valve\\Steam\\SteamApps\\pitpit44\\condition zero\\hl.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\pitpit44\\condition zero\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Valve\\Steam\\Steam.exe"="C:\\Program Files\\Valve\\Steam\\Steam.exe:*:Enabled:Steam"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\adslTV\\adsltv.exe"="C:\\Program Files\\adslTV\\adsltv.exe:*:Enabled:adsltv"
"C:\\Program Files\\adslTV\\vlc.exe"="C:\\Program Files\\adslTV\\vlc.exe:*:Enabled:VLC media player"
"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP2b\\RpcAgentSrv.exe"="C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP2b\\RpcAgentSrv.exe:*:Enabled:SiSoftware Deployment Agent Service"
"C:\\Program Files\\Valve\\Steam\\SteamApps\\stornugl\\deathmatch classic\\hl.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\stornugl\\deathmatch classic\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP2b\\WNt500x86\\RpcSandraSrv.exe"="C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP2b\\WNt500x86\\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\parie sportif\\uTorrent.exe"="C:\\Program Files\\parie sportif\\uTorrent.exe:*:Enabled:æTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files /b:
[b]Files with Hidden Attributes /b:
Sat 29 Dec 2007 219,952 A..H. --- "C:\Program Files\parie sportif\uTorrent.exe"
Sat 24 May 2008 1,080 A..H. --- "C:\Program Files\Pronosoft\downloads.bak"
Sun 13 May 2007 5,308,416 A..H. --- "C:\Program Files\Pronosoft\emule.exe"
Mon 30 Apr 2007 72,220 A..H. --- "C:\Program Files\Pronosoft\eMule Light.tmpl"
Mon 3 Jul 2006 115,247 A..H. --- "C:\Program Files\Pronosoft\eMule.tmpl"
Wed 22 Mar 2006 270,336 A..H. --- "C:\Program Files\Pronosoft\LinkCreator.exe"
Fri 28 Dec 2007 74,329 A..H. --- "C:\Program Files\Pronosoft\Uninstall.exe"
Mon 16 Apr 2007 16 ...H. --- "C:\WINDOWS\system32\tgjshep.dll"
Mon 11 Feb 2008 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 28 Dec 2007 40 A..HR --- "C:\Program Files\Freedom Scientific\Activator\FSSHELL32.dll"
Sat 19 Apr 2008 29,755 A..H. --- "C:\Program Files\Pronosoft\config\clients.met.bak"
Sun 13 May 2007 81,920 A..H. --- "C:\Program Files\Pronosoft\lang\ar_AE.dll"
Sun 13 May 2007 106,496 A..H. --- "C:\Program Files\Pronosoft\lang\ba_BA.dll"
Sun 13 May 2007 102,400 A..H. --- "C:\Program Files\Pronosoft\lang\bg_BG.dll"
Sun 13 May 2007 106,496 A..H. --- "C:\Program Files\Pronosoft\lang\ca_ES.dll"
Sun 13 May 2007 98,304 A..H. --- "C:\Program Files\Pronosoft\lang\cz_CZ.dll"
Sun 13 May 2007 98,304 A..H. --- "C:\Program Files\Pronosoft\lang\da_DK.dll"
Sun 13 May 2007 106,496 A..H. --- "C:\Program Files\Pronosoft\lang\de_DE.dll"
Sun 13 May 2007 110,592 A..H. --- "C:\Program Files\Pronosoft\lang\el_GR.dll"
Sun 13 May 2007 102,400 A..H. --- "C:\Program Files\Pronosoft\lang\es_AS.dll"
Sun 13 May 2007 110,592 A..H. --- "C:\Program Files\Pronosoft\lang\es_ES_T.dll"
Sun 13 May 2007 94,208 A..H. --- "C:\Program Files\Pronosoft\lang\et_EE.dll"
Sun 13 May 2007 106,496 A..H. --- "C:\Program Files\Pronosoft\lang\fa_IR.dll"
Sun 13 May 2007 98,304 A..H. --- "C:\Program Files\Pronosoft\lang\fi_FI.dll"
Sun 13 May 2007 106,496 A..H. --- "C:\Program Files\Pronosoft\lang\fr_BR.dll"
Sun 13 May 2007 110,592 A..H. --- "C:\Program Files\Pronosoft\lang\fr_FR.dll"
Sun 13 May 2007 106,496 A..H. --- "C:\Program Files\Pronosoft\lang\gl_ES.dll"
Sun 13 May 2007 81,920 A..H. --- "C:\Program Files\Pronosoft\lang\he_IL.dll"
Sun 13 May 2007 102,400 A..H. --- "C:\Program Files\Pronosoft\lang\hu_HU.dll"
Sun 13 May 2007 110,592 A..H. --- "C:\Program Files\Pronosoft\lang\it_IT.dll"
Sun 13 May 2007 65,536 A..H. --- "C:\Program Files\Pronosoft\lang\jp_JP.dll"
Sun 13 May 2007 69,632 A..H. --- "C:\Program Files\Pronosoft\lang\ko_KR.dll"
Sun 13 May 2007 102,400 A..H. --- "C:\Program Files\Pronosoft\lang\lt_LT.dll"
Sun 13 May 2007 98,304 A..H. --- "C:\Program Files\Pronosoft\lang\lv_LV.dll"
Sun 13 May 2007 110,592 A..H. --- "C:\Program Files\Pronosoft\lang\mt_MT.dll"
Sun 13 May 2007 98,304 A..H. --- "C:\Program Files\Pronosoft\lang\nb_NO.dll"
Sun 13 May 2007 106,496 A..H. --- "C:\Program Files\Pronosoft\lang\nl_NL.dll"
Sun 13 May 2007 98,304 A..H. --- "C:\Program Files\Pronosoft\lang\nn_NO.dll"
Sun 13 May 2007 98,304 A..H. --- "C:\Program Files\Pronosoft\lang\pl_PL.dll"
Sun 13 May 2007 106,496 A..H. --- "C:\Program Files\Pronosoft\lang\pt_BR.dll"
Sun 13 May 2007 110,592 A..H. --- "C:\Program Files\Pronosoft\lang\pt_PT.dll"
Sun 13 May 2007 98,304 A..H. --- "C:\Program Files\Pronosoft\lang\ro_RO.dll"
Sun 13 May 2007 94,208 A..H. --- "C:\Program Files\Pronosoft\lang\ru_RU.dll"
Sun 13 May 2007 102,400 A..H. --- "C:\Program Files\Pronosoft\lang\sl_SI.dll"
Sun 13 May 2007 106,496 A..H. --- "C:\Program Files\Pronosoft\lang\sq_AL.dll"
Sun 13 May 2007 98,304 A..H. --- "C:\Program Files\Pronosoft\lang\sv_SE.dll"
Sun 13 May 2007 102,400 A..H. --- "C:\Program Files\Pronosoft\lang\tr_TR.dll"
Sun 13 May 2007 98,304 A..H. --- "C:\Program Files\Pronosoft\lang\ua_UA.dll"
Sun 13 May 2007 106,496 A..H. --- "C:\Program Files\Pronosoft\lang\va_ES.dll"
Sun 13 May 2007 98,304 A..H. --- "C:\Program Files\Pronosoft\lang\vi_VN.dll"
Sun 13 May 2007 49,152 A..H. --- "C:\Program Files\Pronosoft\lang\zh_CN.dll"
Sun 13 May 2007 49,152 A..H. --- "C:\Program Files\Pronosoft\lang\zh_TW.dll"
Sat 24 May 2008 236 A..H. --- "C:\Program Files\Pronosoft\Temp\004.part.met.bak"
Sat 24 May 2008 171 A..H. --- "C:\Program Files\Pronosoft\Temp\007.part.met.bak"
Fri 28 Dec 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Thu 27 Dec 2007 2,306,312 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\72925c57d6c1f26720ca873dbab691da\BIT19.tmp"
Thu 27 Dec 2007 108,493,392 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ed6b59489cf951b4c460967d2f642364\download\BIT2.tmp"
[b]Finished!/b