Voila le rapport de sdfix:
[b]SDFix: Version 1.219 /b
Run by acer on 28/08/2008 at 14:31
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services /b:
[b]Name /b:
aspimgr
[b]Path /b:
C:\WINDOWS\system32\aspimgr.exe
aspimgr - Deleted
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files /b:
Trojan Files Found:
C:\WINDOWS\db32.txt - Deleted
C:\WINDOWS\ws386.ini - Deleted
Removing Temp Files
[b]ADS Check /b:
[b]Final Check /b:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-28 14:38:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:d598eee3
"s2"=dword:d7f675d8
"h0"=dword:00000002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:33,79,3e,e4,f3,f0,5d,ee,b4,94,86,c0,ca,e5,fc,3e,a1,f4,6e,d2,ae,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000001
"khjeh"=hex:37,f9,02,11,9b,42,d7,dc,4c,8d,68,00,32,f7,8f,68,f8,8d,bb,da,a1,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,36,20,cc,4b,9e,48,18,b8,2a,f5,38,69,e6,f5,9b,44,38,..
"khjeh"=hex:f6,b9,ca,32,41,fa,48,81,bd,bb,80,4a,0d,4e,7d,70,42,ae,9f,5a,41,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:69,ae,a4,c4,49,fc,b9,e4,51,82,d9,56,e2,a2,6d,a5,19,48,ae,be,46,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:33,79,3e,e4,f3,f0,5d,ee,b4,94,86,c0,ca,e5,fc,3e,a1,f4,6e,d2,ae,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000001
"khjeh"=hex:37,f9,02,11,9b,42,d7,dc,4c,8d,68,00,32,f7,8f,68,f8,8d,bb,da,a1,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,36,20,cc,4b,9e,48,18,b8,2a,f5,38,69,e6,f5,9b,44,38,..
"khjeh"=hex:f6,b9,ca,32,41,fa,48,81,bd,bb,80,4a,0d,4e,7d,70,42,ae,9f,5a,41,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:69,ae,a4,c4,49,fc,b9,e4,51,82,d9,56,e2,a2,6d,a5,19,48,ae,be,46,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:33,79,3e,e4,f3,f0,5d,ee,b4,94,86,c0,ca,e5,fc,3e,a1,f4,6e,d2,ae,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000001
"khjeh"=hex:fd,f5,fe,c1,97,7c,a9,2d,77,ee,71,83,79,66,39,05,3d,a8,3f,b2,e0,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,36,20,cc,4b,9e,48,18,b8,2a,f5,38,69,e6,f5,9b,44,38,..
"khjeh"=hex:f6,b9,ca,32,41,fa,48,81,bd,bb,80,4a,0d,4e,7d,70,42,ae,9f,5a,41,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:5a,fb,b8,b7,35,34,a6,6c,18,e6,26,f3,4d,e5,15,8b,cd,f0,cd,9b,80,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:000000aa
"TracesSuccessful"=dword:00000078
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services /b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\PokerOffice\\bin\\javaw.exe"="C:\\Program Files\\PokerOffice\\bin\\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[b]Remaining Files /b:
File Backups: - C:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes /b:
Tue 3 May 2005 1,024 A..HR --- "C:\WINDOWS\system32\NTIBUN4.dll"
Tue 3 May 2005 1,024 ...HR --- "C:\WINDOWS\system32\NTICDMK7.dll"
Tue 3 May 2005 1,024 ...HR --- "C:\WINDOWS\system32\NTIFCD3.dll"
Tue 3 May 2005 1,024 A..HR --- "C:\WINDOWS\system32\NTIMP3.dll"
Tue 3 May 2005 1,024 A..HR --- "C:\WINDOWS\system32\NTIMPEG2.dll"
Mon 9 Jan 2006 30,720 A..H. --- "C:\Documents and Settings\acer\Mes documents\~WRL0002.tmp"
Thu 1 Dec 2005 27,136 A..H. --- "C:\Documents and Settings\acer\Mes documents\~WRL0004.tmp"
Mon 9 Jan 2006 31,744 A..H. --- "C:\Documents and Settings\acer\Mes documents\~WRL0005.tmp"
Mon 9 Jan 2006 35,328 A..H. --- "C:\Documents and Settings\acer\Mes documents\~WRL0919.tmp"
Mon 9 Jan 2006 36,864 A..H. --- "C:\Documents and Settings\acer\Mes documents\~WRL1326.tmp"
Mon 9 Jan 2006 47,104 A..H. --- "C:\Documents and Settings\acer\Mes documents\~WRL2172.tmp"
Mon 9 Jan 2006 46,592 A..H. --- "C:\Documents and Settings\acer\Mes documents\~WRL2372.tmp"
Mon 9 Jan 2006 39,936 A..H. --- "C:\Documents and Settings\acer\Mes documents\~WRL3646.tmp"
Mon 9 Jan 2006 28,672 A..H. --- "C:\Documents and Settings\acer\Mes documents\~WRL3922.tmp"
Mon 9 Jan 2006 46,080 A..H. --- "C:\Documents and Settings\acer\Mes documents\~WRL4082.tmp"
Sat 1 Oct 2005 29,184 A..H. --- "C:\Documents and Settings\acer\Application Data\Microsoft\ModŠles\~WRL3961.tmp"
Sat 1 Oct 2005 6,838 A..H. --- "C:\Documents and Settings\acer\Application Data\Microsoft\Office\Shortcut Bar\Off2.tmp"
Tue 3 Aug 2004 25,088 A..H. --- "C:\Documents and Settings\acer\Bureau\a graver\SCOLAIRE ENFANT\940_fiches_a_imprimer_de_jeux_pour_enfants\graphisme\mathematiques\~WRL0003.tmp"
Mon 2 Aug 2004 43,008 A..H. --- "C:\Documents and Settings\acer\Bureau\a graver\SCOLAIRE ENFANT\940_fiches_a_imprimer_de_jeux_pour_enfants\graphisme\mathematiques\~WRL0354.tmp"
Tue 3 Aug 2004 56,832 A..H. --- "C:\Documents and Settings\acer\Bureau\a graver\SCOLAIRE ENFANT\940_fiches_a_imprimer_de_jeux_pour_enfants\graphisme\mathematiques\~WRL0356.tmp"
Tue 3 Aug 2004 26,624 A..H. --- "C:\Documents and Settings\acer\Bureau\a graver\SCOLAIRE ENFANT\940_fiches_a_imprimer_de_jeux_pour_enfants\graphisme\mathematiques\~WRL0397.tmp"
Tue 3 Aug 2004 127,488 A..H. --- "C:\Documents and Settings\acer\Bureau\a graver\SCOLAIRE ENFANT\940_fiches_a_imprimer_de_jeux_pour_enfants\graphisme\mathematiques\~WRL0450.tmp"
Mon 2 Aug 2004 20,992 A..H. --- "C:\Documents and Settings\acer\Bureau\a graver\SCOLAIRE ENFANT\940_fiches_a_imprimer_de_jeux_pour_enfants\graphisme\mathematiques\~WRL0663.tmp"
Mon 2 Aug 2004 77,312 A..H. --- "C:\Documents and Settings\acer\Bureau\a graver\SCOLAIRE ENFANT\940_fiches_a_imprimer_de_jeux_pour_enfants\graphisme\mathematiques\~WRL0944.tmp"
Tue 3 Aug 2004 90,624 A..H. --- "C:\Documents and Settings\acer\Bureau\a graver\SCOLAIRE ENFANT\940_fiches_a_imprimer_de_jeux_pour_enfants\graphisme\mathematiques\~WRL1876.tmp"
Tue 3 Aug 2004 164,352 A..H. --- "C:\Documents and Settings\acer\Bureau\a graver\SCOLAIRE ENFANT\940_fiches_a_imprimer_de_jeux_pour_enfants\graphisme\mathematiques\~WRL2053.tmp"
Mon 2 Aug 2004 25,088 A..H. --- "C:\Documents and Settings\acer\Bureau\a graver\SCOLAIRE ENFANT\940_fiches_a_imprimer_de_jeux_pour_enfants\graphisme\mathematiques\~WRL2667.tmp"
Mon 2 Aug 2004 190,464 A..H. --- "C:\Documents and Settings\acer\Bureau\a graver\SCOLAIRE ENFANT\940_fiches_a_imprimer_de_jeux_pour_enfants\graphisme\mathematiques\~WRL3345.tmp"
[b]Finished!/b
je suis un peu comme le patient qui attend l 'avis du médecin..........angoissééééééééééééééééééé