Bonsoir!!
voila le rapport desdfix:
SDFix: Version 1.116
Run by Administrateur on 30/11/2007 at 20:24
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
Microsoft IE Updater_1
Path:
C:\Documents and Settings\Administrateur\ie_updater1.exe /start
Microsoft IE Updater_1 - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\install\install.exe - Deleted
C:\WINDOWS\system32\RunOnce1.t__ - Deleted
C:\WINDOWS\system32\RunOnce1.tm_ - Deleted
Folder C:\WINDOWS\system32\wsnpoem - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-30 20:36:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch]
"Epoch"=dword:00005d48
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s0"=dword:09a2b132
"s1"=dword:155badfb
"s2"=dword:d667d5f5
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="D:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:0f,d5,65,e9,21,03,84,b5,81,63,46,1c,0b,0e,30,a8,ab,4b,2b,73,f3,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,84,65,d2,d9,75,42,a9,95,74,6c,cd,87,38,f6,59,e2,0a,..
"khjeh"=hex:09,06,18,59,44,03,81,af,26,27,0e,a7,98,ee,79,7b,56,8a,29,5a,bd,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:e9,e1,1d,a6,cd,b8,06,da,d8,d7,62,53,f5,46,6e,92,bb,5b,52,68,a3,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A8CEBC4-6D3D-4DAA-9783-FB88DC255EBF}]
"LeaseObtainedTime"=dword:475065ef
"T1"=dword:4750662b
"T2"=dword:4750671b
"LeaseTerminatesTime"=dword:47506847
"DhcpRetryTime"=dword:0000003a
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{0A8CEBC4-6D3D-4DAA-9783-FB88DC255EBF}\Parameters\Tcpip]
"LeaseObtainedTime"=dword:475065ef
"T1"=dword:4750662b
"T2"=dword:4750671b
"LeaseTerminatesTime"=dword:47506847
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="D:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:0f,d5,65,e9,21,03,84,b5,81,63,46,1c,0b,0e,30,a8,ab,4b,2b,73,f3,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,84,65,d2,d9,75,42,a9,95,74,6c,cd,87,38,f6,59,e2,0a,..
"khjeh"=hex:09,06,18,59,44,03,81,af,26,27,0e,a7,98,ee,79,7b,56,8a,29,5a,bd,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:e9,e1,1d,a6,cd,b8,06,da,d8,d7,62,53,f5,46,6e,92,bb,5b,52,68,a3,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\\Program Files\\TrackMania Nations ESWC\\TmNationsESWC.exe"="D:\\Program Files\\TrackMania Nations ESWC\\TmNationsESWC.exe:*:Enabled:TmNationsESWC"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Messenger"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Wed 4 Aug 2004 16 ...H. --- "C:\WINDOWS\system32\pkagpf4.dll"
Tue 25 Jul 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 11 Jun 2007 1,227,776 ...H. --- "C:\Documents and Settings\Administrateur\Bureau\Sabine\~WRL0382.tmp"
Finished!