Voila donc le rapport SDfix :
[b]SDFix: Version 1.240 /b
Run by barth on 29/11/2008 at 18:41
Microsoft Windows XP [Version 5.1.2600]
Running From: F:\Documents and Settings\barthi\Desktop\SDFix
[b]Checking Services /b:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files /b:
No Trojan Files Found
Removing Temp Files
[b]ADS Check /b:
[b]Final Check /b:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-29 22:08:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="F:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:90,54,b6,55,52,16,2e,09,01,47,ef,8f,04,27,33,65,00,62,19,98,b6,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,d9,59,75,92,37,af,13,c9,71,1f,08,fc,27,36,f6,75,ef,..
"khjeh"=hex:1b,cd,01,06,6e,c4,b6,0b,65,3b,80,ce,99,35,64,f0,16,b4,ce,52,5f,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:d2,d1,e8,97,10,30,98,0e,fa,20,20,61,24,9f,cb,5f,df,e3,67,67,0f,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:90,05,05,f0,bd,28,14,7c,a2,32,bf,d0,84,45,3d,cf,1c,fb,9c,06,76,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:10,26,c9,96,9d,9c,46,f9,4a,97,1b,15,09,52,be,fe,a5,2e,ba,e4,e9,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="F:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:90,54,b6,55,52,16,2e,09,01,47,ef,8f,04,27,33,65,00,62,19,98,b6,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,d9,59,75,92,37,af,13,c9,71,1f,08,fc,27,36,f6,75,ef,..
"khjeh"=hex:1b,cd,01,06,6e,c4,b6,0b,65,3b,80,ce,99,35,64,f0,16,b4,ce,52,5f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:d2,d1,e8,97,10,30,98,0e,fa,20,20,61,24,9f,cb,5f,df,e3,67,67,0f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:90,05,05,f0,bd,28,14,7c,a2,32,bf,d0,84,45,3d,cf,1c,fb,9c,06,76,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:10,26,c9,96,9d,9c,46,f9,4a,97,1b,15,09,52,be,fe,a5,2e,ba,e4,e9,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}]
"DisplayName"="Alcohol 120%"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{04339641-EADD-5E09-EC33-DBD91597AC72}]
"pakjgpcgbhegoifdihlimpakiilcjdfl"=hex:6b,61,64,6f,63,70,6e,68,6e,6b,68,66,6d,6c,65,67,6a,6c,6e,62,6e,..
"oaioanopiekpommpdcimgjnifbhkjk"=hex:6b,61,64,6f,63,70,6e,68,6e,6b,68,66,6d,6c,65,67,6a,6c,6e,62,6e,..
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services /b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"E:\\Warcraft III.exe"="E:\\Warcraft III.exe:*:Enabled:Warcraft III"
"F:\\Program Files\\eMule\\emule.exe"="F:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"D:\\CounterStrikeSource\\srcdsold.exe"="D:\\CounterStrikeSource\\srcdsold.exe:*:Enabled:srcdsold"
"F:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="F:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"F:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="F:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"F:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="F:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Counter-Strike Source\\hl2.exe"="C:\\Counter-Strike Source\\hl2.exe:*:Enabled:hl2"
"C:\\Counter-Strike Source\\srcds.exe"="C:\\Counter-Strike Source\\srcds.exe:*:Enabled:srcds"
"F:\\Program Files\\DNA\\btdna.exe"="F:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA"
"F:\\Program Files\\BitTorrent\\bittorrent.exe"="F:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"F:\\WINDOWS\\Temp\\~osB.tmp\\ossproxy.exe"="F:\\WINDOWS\\Temp\\~osB.tmp\\ossproxy.exe:*:Enabled:ossproxy.exe"
"F:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\RM.exe"="F:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\RM.exe:*:Enabled:Render Manager"
"F:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\PMSRegisterFile.exe"="F:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile"
"F:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\umi.exe"="F:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\umi.exe:*:Enabled:umi"
"F:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\VideoSpin.exe"="F:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\VideoSpin.exe:*:Enabled:Pinnacle VideoSpin"
"F:\\Program Files\\LimeWire\\LimeWire.exe"="F:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"F:\\Program Files\\Ares\\Ares.exe"="F:\\Program Files\\Ares\\Ares.exe:*:Enabled:Ares p2p for windows"
"F:\\Program Files\\GigaTribe\\gigatribe.exe"="F:\\Program Files\\GigaTribe\\gigatribe.exe:*:Enabled:gigatribe"
"F:\\Program Files\\EA Sports\\FIFA 08\\FIFA08.exe"="F:\\Program Files\\EA Sports\\FIFA 08\\FIFA08.exe:*:Enabled:FIFA08"
"F:\\Program Files\\SYSTRAN\\6\\SystranTranslationProjectManager.exe"="F:\\Program Files\\SYSTRAN\\6\\SystranTranslationProjectManager.exe:*:Enabled:SystranTranslationProjectManager"
"F:\\Program Files\\SYSTRAN\\6\\SystranToolbar.exe"="F:\\Program Files\\SYSTRAN\\6\\SystranToolbar.exe:*:Enabled:SYSTRAN Translation Toolbar"
"F:\\Program Files\\SYSTRAN\\6\\Dicts\\SystranTranslationEngine.exe"="F:\\Program Files\\SYSTRAN\\6\\Dicts\\SystranTranslationEngine.exe:*:Enabled:Systran Translation Engine "
"F:\\Program Files\\SYSTRAN\\6\\Dicts\\SystranCodingEngine.exe"="F:\\Program Files\\SYSTRAN\\6\\Dicts\\SystranCodingEngine.exe:*:Enabled:Systran Coding Engine "
"F:\\Program Files\\SYSTRAN\\6\\Dicts\\SystranFilterEngine.exe"="F:\\Program Files\\SYSTRAN\\6\\Dicts\\SystranFilterEngine.exe:*:Enabled:Systran Filter Engine "
"F:\\Program Files\\SYSTRAN\\6\\SystranDictionaryManager.exe"="F:\\Program Files\\SYSTRAN\\6\\SystranDictionaryManager.exe:*:Enabled:SYSTRAN Dictionary Manager"
"F:\\Program Files\\Lecteur CANALPLAY\\CanalPlayer.exe"="F:\\Program Files\\Lecteur CANALPLAY\\CanalPlayer.exe:*:Enabled:Lecteur CANALPLAY"
"F:\\Program Files\\Virtual Skipper 4\\Vsk4.exe"="F:\\Program Files\\Virtual Skipper 4\\Vsk4.exe:*:Enabled:Vsk4"
"F:\\Program Files\\TmSunrise\\TmSunrise.exe"="F:\\Program Files\\TmSunrise\\TmSunrise.exe:*:Enabled:TmSunrise"
"F:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe"="F:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe:*:Enabled:BlueSoleilCS"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"F:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="F:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"F:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="F:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files /b:
[b]Files with Hidden Attributes /b:
Wed 22 Oct 2008 949,072 A.SHR --- "F:\Program Files\Spybot - Search & Destroy\advcheck.dll"
Mon 15 Sep 2008 1,562,960 A.SHR --- "F:\Program Files\Spybot - Search & Destroy\SDHelper.dll"
Mon 7 Jul 2008 1,429,840 A.SHR --- "F:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 7 Jul 2008 4,891,472 A.SHR --- "F:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Tue 16 Sep 2008 1,833,296 A.SHR --- "F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Wed 22 Oct 2008 962,896 A.SHR --- "F:\Program Files\Spybot - Search & Destroy\Tools.dll"
Sun 5 Oct 2008 0 A.SH. --- "F:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Thu 2 Oct 2008 1,131,560 A..H. --- "F:\WINDOWS\SoftwareDistribution\Download\94e2de28cb8ee27606822ca199876d4a\BIT122.tmp"
[b]Finished!/b