Voilà les rapports manquants :
[b]SDFix: Version 1.220 /b
Run by Propri‚taire on 31/08/2008 at 11:21
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services /b:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files /b:
No Trojan Files Found
Removing Temp Files
[b]ADS Check /b:
[b]Final Check /b:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-31 11:47:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:6cc1aafb
"s2"=dword:730b1adc
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000000
"hdf12"=hex:b6,d8,62,c1,7c,7c,67,2c,76,90,c3,b3,17,bf,75,aa,a6,a4,17,b0,07,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Vax347s\Config\jdgg40]
"ujdew"=hex:20,02,00,00,82,ee,7e,12,ba,ec,9f,4b,26,c9,2e,d4,eb,a0,57,89,1c,..
"ljej40"=hex:33,c7,11,f3,89,94,38,a0,19,ec,40,fd,8e,a0,1a,68,5e,8a,e3,6f,5d,..
"ljej41"=hex:c2,c7,11,f3,f1,94,38,a0,18,ec,41,fd,8f,a0,1a,68,5e,8a,e3,6f,5d,..
"ljej42"=hex:c2,c7,11,f3,f1,94,38,a0,18,ec,41,fd,8f,a0,1a,68,5e,8a,e3,6f,5d,..
"ljej43"=hex:c2,c7,11,f3,f1,94,38,a0,18,ec,41,fd,8f,a0,1a,68,5e,8a,e3,6f,5d,..
"ljej44"=hex:c2,c7,11,f3,f1,94,38,a0,18,ec,41,fd,8f,a0,1a,68,5e,8a,e3,6f,5d,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Vax347s\Config\jdgg41]
"ujdew"=hex:20,02,00,00,82,ee,7e,12,d0,b1,dc,c6,26,c9,2e,d4,eb,a0,57,89,1c,..
"ljej40"=hex:33,c7,11,f3,89,94,38,a0,19,ec,40,fd,8e,a0,1a,68,5e,8a,e3,6f,63,..
"ljej41"=hex:c2,c7,11,f3,f1,94,38,a0,18,ec,41,fd,8f,a0,1a,68,5e,8a,e3,6f,5d,..
"ljej42"=hex:c2,c7,11,f3,f1,94,38,a0,18,ec,41,fd,8f,a0,1a,68,5e,8a,e3,6f,5d,..
"ljej43"=hex:c2,c7,11,f3,f1,94,38,a0,18,ec,41,fd,8f,a0,1a,68,5e,8a,e3,6f,5d,..
"ljej44"=hex:c2,c7,11,f3,f1,94,38,a0,18,ec,41,fd,8f,a0,1a,68,5e,8a,e3,6f,5d,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000000
"hdf12"=hex:b6,d8,62,c1,7c,7c,67,2c,76,90,c3,b3,17,bf,75,aa,a6,a4,17,b0,07,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System]
"OODEFRAG08.00.00.01WORKSTATION"="85F58880A853B1F5E96E93C74B06FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A2D97226D213B5558EDD5E5BE2F6E6675D575E7D6A3B9808E70C8F0DA201EFFB99DAEF72091168E05B5695C44072E259594335B8ADF58D9CBBD0EAA560AD507DDDD7D49E3C0A16165EBB09A7EBF3E7FB7DD2D36E2504D283435EC91EBB442099029DA4398A81E1AA1FDBF88BA12D439931A732245153BC42EE81E46AF99A0291E3B06FB73355CEB006956A063EA67F350F9AE9314BB47B6B23A98AC310E9E82AD63B5753AA48B73C756AF473D2CA7A55A0282732E2DB1197B9ED1CA42D4F1C2C200B92881A01C7683F03C2F0A5EA6504676FA9059A60D4E17F848E4E2D4DB7E3F913E999DE09805129289460AFB7C6D05836C64DA740EF6A35CCEBC5A548ABA212693E8A08CFB69AEFCA3C689FCA764E5961E5F1F5DA635511C64F515D8ABB3C8BC57FA55A2713E8C2FCA073D61F24924700831EA3F300C83A16EBFDCF40FE897B0935774F46916442F53EAE6993D0B773BEAF4102366D71CE06861CAD7BE2676BB1F8D0924683BD088EA40CA2EBD2DE20748F0F9A2CA57E5F81783F59B22536DA69F9C706A58E249DC8F5C27E4FD2A70617D97DA4C679A4F19AAFBFE93DDADBBA7779343BC8AA4F03466ACC3049503B51C35D4790DA899A7E06ACBAAC5AEB3FF0C9CF347D742576AA4D4CE79AC89B4222B9776D809F4D9BF21C838F9FAA924DD87364A848D19E597BC97B96DA22DA6C8B5D1E324AB290E7AF5A5FE1F63261773FAA3737CC720B3850C96B9EBB0C086C17B5D81C7915F04389E07D991ADC39B2E5C759C8EE46B3D97981238ABFA171F7BE6F45774CA8E175C9762E65A4F6537783C9F289C6A4B5083946BE291C6437CB755A12D2B53729492E81D63265B13BC04252BC6CA2C6020FC5136B0BBAB4D0241CE904015A6E628F669071B660A25091402785A4014DDC404B88EE86395C07C50D36F39A175C7C1C98548AE9CD43C7EC8FB2AFAC17395E7368679E38680578F4137B4EF8F9F7B9C45DA0440798F0A75C3402B1414DF07481AF98E67A4EBF17FE6E1992BBC396B16642705310E06CCCEB2B4794E3414060C6A92546F2A4FEA7B05414D447EC774D60C65E00C8F85C66AB61D9F85842D2B4A6CF3DD084D899C3DCEA13BEC0203A4E97622DA9386949F8B2B8B00FA956BCDC8691B32DDC8B4CD9DA4FE20B95B962C471FBC040AB6CA15C9707EB9D25337414CED2FD176713B5AB8591720BF24ED7985BF022493273B4BAF6954D7ED9C755EA6DE8395DD679594FBAB5D6A14C23E88344927D5E21A0B91572A3BA229EB41BC6D4202364237C9EADDDB247C8D93445962027A5AC8FCB4A3F2D633C088BCCEAE0FAB71EA2048BD00654769E0C962E0132E5E60E"
"OODEFRAG10.00.00.01WORKSTATION"="37B09FAFE5554B5EBB33F305BA6D6DA78936020AB77A3BDE0CA9DDDDF747FD255CC747E7C75865BFBF182FCBD17071CCF7F88C6F8FA8B18F643E01859A964F50F3E4CCB93D8468BEDFCD91586033C170C5096B1BC2363E6C013C5175FED42D445B0A4AF8E90768BE101573C63175BD909D8B52FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79339DB7CE019D40AA5CFEBC9E127BECC74CA9C6AECB7A5D140766A5286D49B9777AD48CEF52559CA4C85BBE2B215E9F2B26F7BB801635D55E09EC3CA9BA86C5F846B7E37A5A9541A8648CB3FD37898530BD73D5911C46251579DEB3A636D35358CDE4DF80BF5FE8CF1581CE8F03BF4E79B0685CD89E15A573BEE5AA67AAEDCEF19F53C3D61C8535D4481795E9888EF343E7BDBAADB00AC2D85E131235583438647C59A4D9FB035AB99B90E59744A67F8E01BC326FD6AD7BE51357AE5F742CA4125CB56F6960722342E310EE2B225E8EA1CA1657FE8E32E103C80D1C38A5FBBBA36A8761E9BE176AF5A7A1B4B706B1D3044B59934145679F58A1ED48960870B98203D10EC100D4A42123310ED6443B9603397E2221DF466ED4F39973D52D78EEDE3A00DBDC80B254D3C59128A4A7BF30B10360168BB3699D2BC79333D3172A40AB565C062B92E014E233F602C2EEA30FE2C83B52730C8E11D05C4373F2BE3AA42052189BA079AE1065427B6F554A70B4B1DDB4904C291ABE7FA1F3EF1A11872AB7DBC67D3570118B387F9B1884E15538F8CBCFDB11BB9134373ED43BB46C906F31D5E1E3E22221D97CA9BA77FC4EA344DCCF7918BFEDA08E380B79BC31A579A98FD546D9A9B11BE414B41C5FF01E519640587F77D9D796828815D92A01050A9F1AA832BD8EB2E1AA294869709253F702CC8B9205638AE456F32050951B45AEB05CCA4BC1192E773C263FB1A41D64556BEF41CB1BE8872566071F1EDDFA98F54AA46F1A6ED3A206BEBB29E4C74BBA4C4EDA07A3EA75460FA015BD64BA9F211572077D8B9C4F00DA6ADFC9D877DD34E1B9829CF9FA9C33030934572CB48AF7E3C0DA0F6EFB1EABE78DC899C6AA9AA240CC20F58F2272AB8437BDFE5F2A43A85DDF3A72F88F597D3F0972C24CA6C94D35C1B03C0C8F90033956D0FACFCB5333229304ABC2AD1C449C539E266A08376DB3E0754C79C117016D25CEC1AD214A0CF62D5C6FC68085BF5B745056073F3530CF877436C50E25600FF7DD041382BB1BC1172B2868873A26FB89CF9A6C8F16B944A9753FC49CE04F30B468217A9E3CBB90CB9976E916609FA444A96EC590B49EEF4D85DD2B6CF4F10A579CB043F6E63F905C982B745225C81E6A2D82A5AD6CE8D30CF64114CB0EDEF5EE6D7AB0615C68986CDACC1437B63454D46FB982279E979415DEC87EE05E2173"
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services /b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\svchost.exe"="C:\\WINDOWS\\system32\\svchost.exe:*:Enabled:Microsoft Update"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"="C:\\Program Files\\IncrediMail\\bin\\IMApp.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\Avant Browser\\avant.exe"="C:\\Program Files\\Avant Browser\\avant.exe:*:Enabled:Avant Browser"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[b]Remaining Files /b:
[b]Files with Hidden Attributes /b:
Sat 4 Nov 2006 80,384 A.SHR --- "C:\eraseme_45742.exe"
Thu 5 Jun 2003 24,576 A..H. --- "C:\Program Files\RamBoost XP\StopRam.exe"
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Wed 28 Sep 2005 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sun 8 Apr 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Sat 21 Jun 2003 377,344 A..H. --- "C:\Program Files\Smart Projects\IsoBuster\Help\AHlp.exe"
Sun 31 Aug 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\523d056929e13eacf8392044f602e53e\BIT18.tmp"
Sun 31 Aug 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\71fa8e4b1f1c72b0e3a5d30a0a049f55\BIT19.tmp"
[b]Finished!/b
Système d'exploitation : Windows [XP ]
Purity[0.7] lancé [1] fois! le 30/08/2008 à 21:11:40,84
Fix lancé en mode sans echec.
Liste des éléments rencontrés au cours de la Recherche...
C:\Documents and Settings\Propriétaire\Application Data\DOBE~1
C:\WINDOWS\system32\RACLE~1
fichiers,dossiers sauvegardés dans C:\Documents and Settings\Propriétaire\Bureau\Purity\Purity\Purity40.zip
Fin du rapport
Système d'exploitation : Windows [XP ]
Purity[0.7] lancé [2] fois! le 31/08/2008 à 11:52:00,35
Liste des éléments rencontrés au cours de la Recherche...
Aucun élément nuisible rencontré.
Fin du rapport
Système d'exploitation : Windows [XP ]
Purity[0.7] lancé [3] fois! le 31/08/2008 à 11:56:15,20
Fix lancé en mode sans echec.
Liste des éléments rencontrés au cours de la Recherche...
Aucun élément nuisible rencontré.
Fin du rapport
SmitFraudFix v2.342
Rapport fait à 12:02:03,75, 31/08/2008
Executé à partir de C:\Documents and Settings\Propri‚taire\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
AntiXPVSTFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» RK
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: D-Link DGE-530T Gigabit Ethernet Adapter - Miniport d'ordonnancement de paquets
DNS Server Search Order: 192.168.123.250
Description: D-Link DGE-530T Gigabit Ethernet Adapter - Miniport d'ordonnancement de paquets
DNS Server Search Order: 192.168.1.1
Description: D-Link DGE-530T Gigabit Ethernet Adapter - Miniport d'ordonnancement de paquets
DNS Server Search Order: 192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{5B5CCF37-BDBA-45C6-B2E5-7E5E9896ECF9}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{6DC5C938-3663-4306-901F-7AE271A0F977}: DhcpNameServer=192.168.123.250
HKLM\SYSTEM\CCS\Services\Tcpip\..\{9BBB37B1-AE44-4489-8820-98DE61F34389}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{5B5CCF37-BDBA-45C6-B2E5-7E5E9896ECF9}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{6DC5C938-3663-4306-901F-7AE271A0F977}: DhcpNameServer=192.168.123.250
HKLM\SYSTEM\CS1\Services\Tcpip\..\{9BBB37B1-AE44-4489-8820-98DE61F34389}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{5B5CCF37-BDBA-45C6-B2E5-7E5E9896ECF9}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{6DC5C938-3663-4306-901F-7AE271A0F977}: DhcpNameServer=192.168.123.250
HKLM\SYSTEM\CS2\Services\Tcpip\..\{9BBB37B1-AE44-4489-8820-98DE61F34389}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"system"=""
»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre
Nettoyage terminé.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin