re-salut
la 2eme action n a rien donné aucun probleme detecté
pour SDfix apres le scan une fenetre c'est ouverte pour me dire que le rapport avait été sauvegardé dans le dossier sdfix et mon pc c est figé a ce moment là??? j espere que c'est le bon rapport
SDFix: Version 1.229
Run by Administrateur on 26/09/2008 at 20:17
Microsoft Windows XP [version 5.1.2600]
Running From: C:SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-26 20:34:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINESYSTEMControlSet001ServicessptdCfg19659239224E364682FA4BAF72C53EA4]
"p0"="C:Program FilesDAEMON Tools"
"h0"=dword:00000000
"khjeh"=hex:47,e4,60,8a,f2,f1,04,54,7d,52,0b,06,38,72,03,0f,a6,ef,4f,72,01,..
[HKEY_LOCAL_MACHINESYSTEMControlSet001ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001]
"a0"=hex:20,01,00,00,61,da,b6,da,8e,bd,21,9d,c1,54,bd,a6,7f,d6,92,58,e7,..
"khjeh"=hex:26,12,8c,08,9e,a0,ed,b8,02,a4,83,fc,b6,43,50,9a,c3,ad,4e,e5,5e,..
[HKEY_LOCAL_MACHINESYSTEMControlSet001ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001 Jf40]
"khjeh"=hex:49,24,73,86,1f,40,15,41,17,a1,c2,c6,8f,46,60,4f,c9,83,5e,4f,1c,..
[HKEY_LOCAL_MACHINESYSTEMControlSet002ServicessptdCfg19659239224E364682FA4BAF72C53EA4]
"p0"="C:Program FilesDAEMON Tools"
"h0"=dword:00000000
"khjeh"=hex:47,e4,60,8a,f2,f1,04,54,7d,52,0b,06,38,72,03,0f,a6,ef,4f,72,01,..
[HKEY_LOCAL_MACHINESYSTEMControlSet002ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001]
"a0"=hex:20,01,00,00,61,da,b6,da,8e,bd,21,9d,c1,54,bd,a6,7f,d6,92,58,e7,..
"khjeh"=hex:26,12,8c,08,9e,a0,ed,b8,02,a4,83,fc,b6,43,50,9a,c3,ad,4e,e5,5e,..
[HKEY_LOCAL_MACHINESYSTEMControlSet002ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001 Jf40]
"khjeh"=hex:21,b5,d1,5b,d0,1a,74,79,0b,91,59,53,f7,bb,7f,4f,2a,9f,9d,1b,5a,..
[HKEY_LOCAL_MACHINESYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4]
"p0"="C:Program FilesDAEMON Tools"
"h0"=dword:00000000
"khjeh"=hex:47,e4,60,8a,f2,f1,04,54,7d,52,0b,06,38,72,03,0f,a6,ef,4f,72,01,..
[HKEY_LOCAL_MACHINESYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001]
"a0"=hex:20,01,00,00,61,da,b6,da,8e,bd,21,9d,c1,54,bd,a6,7f,d6,92,58,e7,..
"khjeh"=hex:26,12,8c,08,9e,a0,ed,b8,02,a4,83,fc,b6,43,50,9a,c3,ad,4e,e5,5e,..
[HKEY_LOCAL_MACHINESYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001 Jf40]
"khjeh"=hex:49,24,73,86,1f,40,15,41,17,a1,c2,c6,8f,46,60,4f,c9,83,5e,4f,1c,..
[HKEY_LOCAL_MACHINESYSTEMControlSet004ServicessptdCfg19659239224E364682FA4BAF72C53EA4]
"p0"="C:Program FilesDAEMON Tools"
"h0"=dword:00000000
"khjeh"=hex:47,e4,60,8a,f2,f1,04,54,7d,52,0b,06,38,72,03,0f,a6,ef,4f,72,01,..
[HKEY_LOCAL_MACHINESYSTEMControlSet004ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001]
"a0"=hex:20,01,00,00,61,da,b6,da,8e,bd,21,9d,c1,54,bd,a6,7f,d6,92,58,e7,..
"khjeh"=hex:26,12,8c,08,9e,a0,ed,b8,02,a4,83,fc,b6,43,50,9a,c3,ad,4e,e5,5e,..
[HKEY_LOCAL_MACHINESYSTEMControlSet004ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001 Jf40]
"khjeh"=hex:21,b5,d1,5b,d0,1a,74,79,0b,91,59,53,f7,bb,7f,4f,2a,9f,9d,1b,5a,..
[HKEY_LOCAL_MACHINESYSTEMControlSet005ServicessptdCfg19659239224E364682FA4BAF72C53EA4]
"p0"="C:Program FilesDAEMON Tools"
"h0"=dword:00000000
"khjeh"=hex:47,e4,60,8a,f2,f1,04,54,7d,52,0b,06,38,72,03,0f,a6,ef,4f,72,01,..
[HKEY_LOCAL_MACHINESYSTEMControlSet005ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001]
"a0"=hex:20,01,00,00,61,da,b6,da,8e,bd,21,9d,c1,54,bd,a6,7f,d6,92,58,e7,..
"khjeh"=hex:26,12,8c,08,9e,a0,ed,b8,02,a4,83,fc,b6,43,50,9a,c3,ad,4e,e5,5e,..
[HKEY_LOCAL_MACHINESYSTEMControlSet005ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001 Jf40]
"khjeh"=hex:21,b5,d1,5b,d0,1a,74,79,0b,91,59,53,f7,bb,7f,4f,2a,9f,9d,1b,5a,..
[HKEY_LOCAL_MACHINESYSTEMControlSet006ServicessptdCfg19659239224E364682FA4BAF72C53EA4]
"p0"="C:Program FilesDAEMON Tools"
"h0"=dword:00000000
"khjeh"=hex:47,e4,60,8a,f2,f1,04,54,7d,52,0b,06,38,72,03,0f,a6,ef,4f,72,01,..
[HKEY_LOCAL_MACHINESYSTEMControlSet006ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001]
"a0"=hex:20,01,00,00,61,da,b6,da,8e,bd,21,9d,c1,54,bd,a6,7f,d6,92,58,e7,..
"khjeh"=hex:26,12,8c,08,9e,a0,ed,b8,02,a4,83,fc,b6,43,50,9a,c3,ad,4e,e5,5e,..
[HKEY_LOCAL_MACHINESYSTEMControlSet006ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001 Jf40]
"khjeh"=hex:21,b5,d1,5b,d0,1a,74,79,0b,91,59,53,f7,bb,7f,4f,2a,9f,9d,1b,5a,..
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessptdCfg]
"s1"=dword:ccb3fa5a
"s2"=dword:3b857dcb
"h0"=dword:00000001
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4]
"p0"="C:Program FilesDAEMON Tools"
"h0"=dword:00000000
"khjeh"=hex:47,e4,60,8a,f2,f1,04,54,7d,52,0b,06,38,72,03,0f,a6,ef,4f,72,01,..
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001]
"a0"=hex:20,01,00,00,61,da,b6,da,8e,bd,21,9d,c1,54,bd,a6,7f,d6,92,58,e7,..
"khjeh"=hex:26,12,8c,08,9e,a0,ed,b8,02,a4,83,fc,b6,43,50,9a,c3,ad,4e,e5,5e,..
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001 Jf40]
"khjeh"=hex:21,b5,d1,5b,d0,1a,74,79,0b,91,59,53,f7,bb,7f,4f,2a,9f,9d,1b,5a,..
[HKEY_LOCAL_MACHINESYSTEMControlSet008ServicessptdCfg19659239224E364682FA4BAF72C53EA4]
"p0"="C:Program FilesDAEMON Tools"
"h0"=dword:00000000
"khjeh"=hex:47,e4,60,8a,f2,f1,04,54,7d,52,0b,06,38,72,03,0f,a6,ef,4f,72,01,..
[HKEY_LOCAL_MACHINESYSTEMControlSet008ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001]
"a0"=hex:20,01,00,00,61,da,b6,da,8e,bd,21,9d,c1,54,bd,a6,7f,d6,92,58,e7,..
"khjeh"=hex:26,12,8c,08,9e,a0,ed,b8,02,a4,83,fc,b6,43,50,9a,c3,ad,4e,e5,5e,..
[HKEY_LOCAL_MACHINESYSTEMControlSet008ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001 Jf40]
"khjeh"=hex:21,b5,d1,5b,d0,1a,74,79,0b,91,59,53,f7,bb,7f,4f,2a,9f,9d,1b,5a,..
[HKEY_LOCAL_MACHINESYSTEMControlSet009ServicessptdCfg19659239224E364682FA4BAF72C53EA4]
"p0"="C:Program FilesDAEMON Tools"
"h0"=dword:00000000
"khjeh"=hex:47,e4,60,8a,f2,f1,04,54,7d,52,0b,06,38,72,03,0f,a6,ef,4f,72,01,..
[HKEY_LOCAL_MACHINESYSTEMControlSet009ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001]
"a0"=hex:20,01,00,00,61,da,b6,da,8e,bd,21,9d,c1,54,bd,a6,7f,d6,92,58,e7,..
"khjeh"=hex:26,12,8c,08,9e,a0,ed,b8,02,a4,83,fc,b6,43,50,9a,c3,ad,4e,e5,5e,..
[HKEY_LOCAL_MACHINESYSTEMControlSet009ServicessptdCfg19659239224E364682FA4BAF72C53EA4 0000001 Jf40]
"khjeh"=hex:21,b5,d1,5b,d0,1a,74,79,0b,91,59,53,f7,bb,7f,4f,2a,9f,9d,1b,5a,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\Starcraft\StarCraft.exe"="C:\Program Files\Starcraft\StarCraft.exe:*:Enabled:Starcraft"
"D:\La Bataille pour la Terre du Milieu\game.dat"="D:\La Bataille pour la Terre du Milieu\game.dat:*:Enabled:La Bataille pour la Terre du Milieu(tm)"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:æTorrent"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"C:\Program Files\Azureus\Azureus.exe"="C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
"C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe"="C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"C:\World of Warcraft\WoW-2.0.4.6314-to-2.0.5.6320-frFR-downloader.exe"="C:\World of Warcraft\WoW-2.0.4.6314-to-2.0.5.6320-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\World of Warcraft\WoW-2.0.5.6320-to-2.0.6.6337-frFR-downloader.exe"="C:\World of Warcraft\WoW-2.0.5.6320-to-2.0.6.6337-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\World of Warcraft\WoW-2.0.6.6337-to-2.0.7.6383-frFR-downloader.exe"="C:\World of Warcraft\WoW-2.0.6.6337-to-2.0.7.6383-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\World of Warcraft\WoW-2.0.7.6383-to-2.0.8.6403-frFR-downloader.exe"="C:\World of Warcraft\WoW-2.0.7.6383-to-2.0.8.6403-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\World of Warcraft\WoW-2.0.8.6403-to-2.0.10.6448-frFR-downloader.exe"="C:\World of Warcraft\WoW-2.0.8.6403-to-2.0.10.6448-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\World of Warcraft\WoW-2.0.10.6448-to-2.0.12.6546-frFR-downloader.exe"="C:\World of Warcraft\WoW-2.0.10.6448-to-2.0.12.6546-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Atari\Neverwinter Nights 2\nwn2main.exe"="C:\Program Files\Atari\Neverwinter Nights 2\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main"
"C:\Program Files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe"="C:\Program Files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD"
"C:\Program Files\Atari\Neverwinter Nights 2\nwupdate.exe"="C:\Program Files\Atari\Neverwinter Nights 2\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater"
"C:\Program Files\Atari\Neverwinter Nights 2\nwn2server.exe"="C:\Program Files\Atari\Neverwinter Nights 2\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Documents and Settings\Robin\Local Settings\Temporary Internet Files\Content.IE5\KHW1HXWS\WoW-BurningCrusade-frFR-Installer-downloader[1].exe"="C:\Documents and Settings\Robin\Local Settings\Temporary Internet Files\Content.IE5\KHW1HXWS\WoW-BurningCrusade-frFR-Installer-downloader[1].exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Program Files\Weflirt\weflirt.exe"="C:\Program Files\Weflirt\weflirt.exe:*:Enabled:Weflirt"
"C:\Program Files\Sony\Station\LaunchPad\LaunchPad.exe"="C:\Program Files\Sony\Station\LaunchPad\LaunchPad.exe:*:Enabled:LaunchPad"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\World of Warcraft\BackgroundDownloader.exe"="C:\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\THQ\Titan Quest Immortal Throne\Tqit.exe"="C:\Program Files\THQ\Titan Quest Immortal Throne\Tqit.exe:*:Enabled:Tqit"
"D:\setup.exe"="D:\setup.exe:*:Enabled:Programme d'installation de Kaspersky Internet Security 2009"
[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
Remaining Files :
Files with Hidden Attributes :
Thu 14 Aug 2008 1,429,840 A.SHR --- "C:Program FilesSpybot - Search & DestroySDUpdate.exe"
Wed 30 Jul 2008 4,891,984 A.SHR --- "C:Program FilesSpybot - Search & DestroySpybotSD.exe"
Wed 8 Dec 2004 56 ..SHR --- "C:WINDOWSsystem325DF3DCD56E.sys"
Tue 22 May 2007 8 ..SHR --- "C:WINDOWSsystem32FEB5029C57.sys"
Thu 24 May 2007 1,056 A.SH. --- "C:WINDOWSsystem32KGyGaAvL.sys"
Sun 8 May 2005 4,348 ..SH. --- "C:Documents and SettingsAll UsersDRMDRMv1.bak"
Fri 7 Dec 2007 0 A.SH. --- "C:Documents and SettingsAll UsersDRMCacheIndiv02.tmp"
Finished!