Ok, alors voilà pour le rapport SDFix... et je vais faire l'analyse antivirus en ligne...
SDFix: Version 1.196
Run by Mew on 25/06/2008 at 15:53
Microsoft Windows XP [version 5.1.2600]
Running From: C:SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-25 16:04:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
IPC error: 2 Le fichier spécifié est introuvable.
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesd347prtCfg Jf40]
"khjeh"=hex:20,02,00,00,f8,39,18,aa,a0,0a,0a,13,80,88,67,b9,6d,5a,fe,48,f0,..
"hj34z0"=hex:d5,62,55,b1,2f,d5,71,cd,87,49,e9,3c,64,7c,94,1e,7c,7f,0f,36,b3,..
"hj34z1"=hex:00,e9,90,b4,57,25,bc,c8,86,1f,3e,39,65,c7,4a,1b,7c,5e,e8,33,23,..
"hj34z2"=hex:00,54,18,bc,57,fd,24,c0,86,50,b5,31,65,77,f1,13,7c,82,63,3b,23,..
"hj34z3"=hex:00,4e,27,a5,57,6e,08,d9,86,03,69,28,65,a4,1c,0a,7c,18,9f,22,23,..
"hj34z4"=hex:00,53,17,aa,57,bf,38,d6,86,ea,b8,27,65,a1,c3,05,7c,69,50,2d,23,..
"hj34z5"=hex:00,7f,9d,90,57,de,be,ec,86,b0,3d,1d,65,9b,48,3f,7c,aa,ec,17,23,..
"hj34z6"=hex:00,c4,59,99,57,84,62,e5,86,b5,f1,14,65,db,b4,36,7c,2d,28,1e,23,..
"hj34z7"=hex:00,88,43,9f,57,8f,6c,e3,86,80,cb,12,65,45,be,30,7c,d7,3f,18,23,..
"hj34z8"=hex:00,ba,b9,82,57,c7,82,fe,86,02,11,0f,65,f9,6b,2d,7c,c1,0a,02,23,..
"hj34z9"=hex:00,09,c6,88,57,a6,e8,f4,86,35,77,05,65,f9,31,27,7c,f2,a4,0f,23,..
"hj34z10"=hex:00,bf,5b,8e,57,6c,65,f2,86,dc,f2,03,65,0d,b4,21,7c,32,29,09,23,..
"hj34z11"=hex:00,b7,37,f5,57,5d,19,89,86,72,86,78,65,92,e7,5a,7c,de,76,72,23,..
"hj34z12"=hex:00,18,c7,f8,57,d2,e9,84,86,dc,75,75,65,5e,37,57,7c,d0,a7,7f,23,..
"hj34z13"=hex:00,ef,f5,ff,57,22,d4,83,86,28,43,72,65,b7,24,50,7c,4a,b9,78,23,..
"hj34z14"=hex:00,19,da,e2,57,11,e5,9e,86,47,72,6f,65,2b,0b,4d,7c,de,ab,65,23,..
"hj34z15"=hex:00,0a,34,e9,57,46,17,95,86,f7,83,64,65,96,e4,46,7c,6a,79,6e,23,..
"hj34z16"=hex:00,22,4d,ec,57,9a,6c,90,86,14,ca,61,65,10,b3,43,7c,04,23,6b,23,..
"hj34z17"=hex:00,62,55,b1,57,d5,71,cd,86,49,e8,3c,65,7c,94,1e,7c,7f,0f,36,23,..
"hj34z18"=hex:00,62,55,b1,57,d5,71,cd,86,49,e8,3c,65,7c,94,1e,7c,7f,0f,36,23,..
"hj34z19"=hex:00,62,55,b1,57,d5,71,cd,86,49,e8,3c,65,7c,94,1e,7c,7f,0f,36,23,..
"hj34z20"=hex:00,62,55,b1,57,d5,71,cd,86,49,e8,3c,65,7c,94,1e,7c,7f,0f,36,23,..
"hj34z21"=hex:00,62,55,b1,57,d5,71,cd,86,49,e8,3c,65,7c,94,1e,7c,7f,0f,36,23,..
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesd347prtCfg Jf41]
"khjeh"=hex:20,02,00,00,e9,39,18,aa,dc,ca,87,08,f9,3c,e8,69,ce,91,a3,50,fa,..
"hj34z0"=hex:5e,b6,f2,e9,56,61,fe,1d,ec,dc,b4,24,65,fa,8a,49,eb,7e,90,d2,1e,..
"hj34z1"=hex:9f,b6,f2,e9,2e,61,fe,1d,ed,dc,b5,24,64,fa,8a,49,eb,7e,90,d2,8a,..
"hj34z2"=hex:9f,b6,f2,e9,2e,61,fe,1d,ed,dc,b5,24,64,fa,8a,49,eb,7e,90,d2,8a,..
"hj34z3"=hex:9f,b6,f2,e9,2e,61,fe,1d,ed,dc,b5,24,64,fa,8a,49,eb,7e,90,d2,8a,..
"hj34z4"=hex:9f,b6,f2,e9,2e,61,fe,1d,ed,dc,b5,24,64,fa,8a,49,eb,7e,90,d2,8a,..
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesd347prtCfg Jf42]
"khjeh"=hex:20,02,00,00,8b,7f,d5,9a,4f,8d,06,4e,76,a8,2b,ea,a1,c4,c8,99,f0,..
"hj34z0"=hex:1d,cc,96,4f,07,4f,95,2e,8f,aa,2e,04,cc,f9,aa,90,c4,8c,1d,6c,5b,..
"hj34z1"=hex:c8,47,53,4a,7f,bf,58,2b,8e,fc,f9,01,cd,42,74,95,c4,ad,fa,69,cb,..
"hj34z2"=hex:c8,fa,db,42,7f,67,c0,23,8e,b3,72,09,cd,f2,cf,9d,c4,71,71,61,cb,..
"hj34z3"=hex:c8,e0,e4,5b,7f,f4,ec,3a,8e,e0,ae,10,cd,21,22,84,c4,eb,8d,78,cb,..
"hj34z4"=hex:c8,fd,d4,54,7f,25,dc,35,8e,09,7f,1f,cd,24,fd,8b,c4,9a,42,77,cb,..
"hj34z5"=hex:c8,d1,5e,6e,7f,44,5a,0f,8e,53,fa,25,cd,1e,76,b1,c4,59,fe,4d,cb,..
"hj34z6"=hex:c8,6a,9a,67,7f,1e,86,06,8e,56,36,2c,cd,5e,8a,b8,c4,de,3a,44,cb,..
"hj34z7"=hex:c8,26,80,61,7f,15,88,00,8e,63,0c,2a,cd,c0,80,be,c4,24,2d,42,cb,..
"hj34z8"=hex:c8,14,7a,7c,7f,5d,66,1d,8e,e1,d6,37,cd,7c,55,a3,c4,32,18,58,cb,..
"hj34z9"=hex:c8,a7,05,76,7f,3c,0c,17,8e,d6,b0,3d,cd,7c,0f,a9,c4,01,b6,55,cb,..
"hj34z10"=hex:c8,11,98,70,7f,f6,81,11,8e,3f,35,3b,cd,88,8a,af,c4,c1,3b,53,cb,..
"hj34z11"=hex:c8,19,f4,0b,7f,c7,fd,6a,8e,91,41,40,cd,17,d9,d4,c4,2d,64,28,cb,..
"hj34z12"=hex:c8,b6,04,06,7f,48,0d,67,8e,3f,b2,4d,cd,db,09,d9,c4,23,b5,25,cb,..
"hj34z13"=hex:c8,41,36,01,7f,b8,30,60,8e,cb,84,4a,cd,32,1a,de,c4,b9,ab,22,cb,..
"hj34z14"=hex:c8,b7,19,1c,7f,8b,01,7d,8e,a4,b5,57,cd,ae,35,c3,c4,2d,b9,3f,cb,..
"hj34z15"=hex:c8,a4,f7,17,7f,dc,f3,76,8e,14,44,5c,cd,13,da,c8,c4,99,6b,34,cb,..
"hj34z16"=hex:c8,8c,8e,12,7f,00,88,73,8e,f7,0d,59,cd,95,8d,cd,c4,f7,31,31,cb,..
"hj34z17"=hex:c8,cc,96,4f,7f,4f,95,2e,8e,aa,2f,04,cd,f9,aa,90,c4,8c,1d,6c,cb,..
"hj34z18"=hex:c8,cc,96,4f,7f,4f,95,2e,8e,aa,2f,04,cd,f9,aa,90,c4,8c,1d,6c,cb,..
"hj34z19"=hex:c8,cc,96,4f,7f,4f,95,2e,8e,aa,2f,04,cd,f9,aa,90,c4,8c,1d,6c,cb,..
"hj34z20"=hex:c8,cc,96,4f,7f,4f,95,2e,8e,aa,2f,04,cd,f9,aa,90,c4,8c,1d,6c,cb,..
"hj34z21"=hex:c8,cc,96,4f,7f,4f,95,2e,8e,aa,2f,04,cd,f9,aa,90,c4,8c,1d,6c,cb,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\AOL 9.0\waol.exe"="C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL France"
"C:\Program Files\Hp\TVPlay\TVPlay.exe"="C:\Program Files\Hp\TVPlay\TVPlay.exe:*:Enabled:CyberLink PowerCinema Main Program"
"C:\Program Files\Hp\TVPlay\TVPService.exe"="C:\Program Files\Hp\TVPlay\TVPService.exe:*:Enabled:CyberLink PowerCinema Resident Program"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\pcast\podcastbar\DDD\pcastagent.exe"="C:\Program Files\pcast\podcastbar\DDD\pcastagent.exe:*:Enabled:pcastagent"
"C:\Program Files\pcast\podcastbar\PodcastBar.exe"="C:\Program Files\pcast\podcastbar\PodcastBar.exe:*:Enabled:PodcastBar"
"F:\SESSIO~2\AR