Ordinateur qui freeze

Jotech057 -  
 Jotech057 -
Bonjour,

Voilà j'ai fait une analyse avec sdfix et j'aimerais savoir ce qui l'en est.


[b]SDFix: Version 1.240 [/b]
Run by Jordan on 25/09/2009 at 18:34

Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix

[b]Checking Services [/b]:


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


[b]Checking Files [/b]:

No Trojan Files Found






Removing Temp Files

[b]ADS Check [/b]:


C:\WINDOWS\system32
:{DA6227CB-326B-4B4D-9A81-04B61F1538DD} 12
Total size: 12 bytes.
system32: deleted 12 bytes in 1 streams.

Checking for remaining Streams

C:\WINDOWS\system32
No streams found.


[b]Final Check [/b]:

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-25 19:04:08
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"hdf12"=hex:0e,60,94,a3,49,f9,49,b9,b9,1a,48,1d,53,70,13,a0,c2,bf,85,78,86,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
"a0"=hex:20,01,00,00,5f,11,c5,70,62,0e,99,f6,7b,48,ca,3c,e1,f7,fa,82,81,..
"hdf12"=hex:76,f6,15,6e,71,3e,08,04,3b,a4,df,30,2c,af,46,59,6f,dd,f4,b7,eb,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
"hdf12"=hex:cb,a0,e2,8b,50,8f,6c,57,37,d2,23,be,67,d9,32,a3,e1,44,0a,24,22,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1]
"hdf12"=hex:de,79,d9,50,e0,aa,58,a5,1b,f2,7b,ea,bd,df,f1,da,30,ce,20,4f,fa,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2]
"hdf12"=hex:9d,f5,0a,10,5b,73,7e,71,d3,30,a0,da,a2,26,9f,58,e4,72,63,2c,ed,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3]
"hdf12"=hex:2f,08,7b,ec,12,d3,41,15,8e,0d,e1,aa,6f,38,10,d4,1d,06,20,d1,5c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"hdf12"=hex:0e,60,94,a3,49,f9,49,b9,b9,1a,48,1d,53,70,13,a0,c2,bf,85,78,86,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
"a0"=hex:20,01,00,00,5f,11,c5,70,62,0e,99,f6,7b,48,ca,3c,e1,f7,fa,82,81,..
"hdf12"=hex:76,f6,15,6e,71,3e,08,04,3b,a4,df,30,2c,af,46,59,6f,dd,f4,b7,eb,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
"hdf12"=hex:cb,a0,e2,8b,50,8f,6c,57,37,d2,23,be,67,d9,32,a3,e1,44,0a,24,22,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1]
"hdf12"=hex:de,79,d9,50,e0,aa,58,a5,1b,f2,7b,ea,bd,df,f1,da,30,ce,20,4f,fa,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2]
"hdf12"=hex:9d,f5,0a,10,5b,73,7e,71,d3,30,a0,da,a2,26,9f,58,e4,72,63,2c,ed,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3]
"hdf12"=hex:2f,08,7b,ec,12,d3,41,15,8e,0d,e1,aa,6f,38,10,d4,1d,06,20,d1,5c,..

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


[b]Remaining Services [/b]:




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\ma-config.com\\maconfservice.exe"="C:\\Program Files\\ma-config.com\\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
"C:\\Program Files\\HLSW\\hlsw.exe"="C:\\Program Files\\HLSW\\hlsw.exe:*:Enabled:HLSW Application"
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\\Program Files\\Steam\\steamapps\\bapt057\\counter-strike source\\hl2.exe"="C:\\Program Files\\Steam\\steamapps\\bapt057\\counter-strike source\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Steam\\steamapps\\bapt057\\source sdk base\\hl2.exe"="C:\\Program Files\\Steam\\steamapps\\bapt057\\source sdk base\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Java\\jre6\\bin\\java.exe"="C:\\Program Files\\Java\\jre6\\bin\\java.exe:*:Enabled:Java(TM) Platform SE binary"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Steam\\steam.exe"="C:\\Program Files\\Steam\\steam.exe:*:Enabled:Steam"
"C:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"="C:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe:*:Enabled:Application de pilotage … distance TeamViewer"
"C:\\Program Files\\Sony\\Vegas 7.0\\VegSrv70.exe"="C:\\Program Files\\Sony\\Vegas 7.0\\VegSrv70.exe:*:Enabled:Sony Vegas Network Render Service Control"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\PokerTH\\pokerth.exe"="C:\\Program Files\\PokerTH\\pokerth.exe:*:Enabled:pokerth"
"C:\\Program Files\\Steam\\steamapps\\bapt057\\day of defeat source\\hl2.exe"="C:\\Program Files\\Steam\\steamapps\\bapt057\\day of defeat source\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Steam\\steamapps\\common\\company of heroes\\RelicCOH.exe"="C:\\Program Files\\Steam\\steamapps\\common\\company of heroes\\RelicCOH.exe:*:Enabled:Company of Heroes"
"C:\\Program Files\\Steam\\steamapps\\common\\company of heroes\\help.htm"="C:\\Program Files\\Steam\\steamapps\\common\\company of heroes\\help.htm:*:Enabled:Company of Heroes"
"C:\\Program Files\\Steam\\steamapps\\common\\company of heroes\\RelicDownloader\\RelicDownloader.exe"="C:\\Program Files\\Steam\\steamapps\\common\\company of heroes\\RelicDownloader\\RelicDownloader.exe:*:Enabled:Relic Patch Download Manager"
"C:\\Program Files\\Steam\\steamapps\\axe057\\counter-strike source\\hl2.exe"="C:\\Program Files\\Steam\\steamapps\\axe057\\counter-strike source\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Electronic Arts\\EADM\\Core.exe"="C:\\Program Files\\Electronic Arts\\EADM\\Core.exe:*:Enabled:EA Download Manager"
"C:\\Program Files\\Steam\\steamapps\\nico77000nico\\counter-strike source\\hl2.exe"="C:\\Program Files\\Steam\\steamapps\\nico77000nico\\counter-strike source\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\mIRC\\mirc.exe"="C:\\Program Files\\mIRC\\mirc.exe:*:Enabled:mIRC"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"C:\\Program Files\\Activision\\Prototype\\prototypef.exe"="C:\\Program Files\\Activision\\Prototype\\prototypef.exe:*:Enabled:Prototype(TM)"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\wamp\\bin\\apache\\Apache2.2.11\\bin\\httpd.exe"="C:\\wamp\\bin\\apache\\Apache2.2.11\\bin\\httpd.exe:*:Enabled:Apache HTTP Server"
"C:\\Program Files\\FileZilla FTP Client\\filezilla.exe"="C:\\Program Files\\FileZilla FTP Client\\filezilla.exe:*:Enabled:FileZilla FTP Client"
"C:\\Program Files\\Steam\\steamapps\\frenchfire\\garrysmod\\hl2.exe"="C:\\Program Files\\Steam\\steamapps\\frenchfire\\garrysmod\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Steam\\steamapps\\bapt057\\garrysmod\\hl2.exe"="C:\\Program Files\\Steam\\steamapps\\bapt057\\garrysmod\\hl2.exe:*:Enabled:hl2"
"C:\\Nexon\\NEXON_EU_Downloader\\NEXON_EU_Downloader_Engine.exe"="C:\\Nexon\\NEXON_EU_Downloader\\NEXON_EU_Downloader_Engine.exe:*:Enabled:NEXON_EU_Downloader_Engine"
"C:\\Program Files\\SecondLife\\SLVoice.exe"="C:\\Program Files\\SecondLife\\SLVoice.exe:*:Enabled:SLVoice"
"C:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"="C:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe:*:Enabled:Far Cry 2"
"C:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"="C:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe:*:Enabled:Far Cry 2 Updater"
"C:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"="C:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe:*:Enabled:Editeur"
"C:\\Documents and Settings\\Jordan\\Application Data\\Octoshape\\Octoshape Streaming Services\\OctoshapeClient.exe"="C:\\Documents and Settings\\Jordan\\Application Data\\Octoshape\\Octoshape Streaming Services\\OctoshapeClient.exe:*:Enabled:Main program for Octoshape client"
"C:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"="C:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe:*:Enabled:Left 4 Dead"
"C:\\Program Files\\EslWire\\wire.exe"="C:\\Program Files\\EslWire\\wire.exe:*:Enabled:ESL Wire Client"
"C:\\Program Files\\SoulseekNS\\slsk.exe"="C:\\Program Files\\SoulseekNS\\slsk.exe:*:Enabled:SoulSeek"
"C:\\Program Files\\Java\\jre6\\bin\\javaw.exe"="C:\\Program Files\\Java\\jre6\\bin\\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Documents and Settings\\All Users.WINDOWS\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\French\\setup.exe"="C:\\Documents and Settings\\All Users.WINDOWS\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\French\\setup.exe:*:Enabled:Programme d'installation de Kaspersky Internet Security 2009"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

[b]Remaining Files [/b]:



[b]Files with Hidden Attributes [/b]:

Mon 14 Apr 2008 93,184 A.SH. --- "C:\Program Files\Internet Explorer\iexplore.exe"
Mon 1 Jun 2009 57,344 A..H. --- "C:\Program Files\nn\test.exe"
Tue 28 Jul 2009 1,548,120 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\advcheck.dll"
Thu 5 Mar 2009 2,260,480 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Tue 24 Mar 2009 20 ...H. --- "C:\Program Files\Common Files\LocalUser\AQ@30_10.dll"
Tue 7 Apr 2009 0 A.SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\Cache\Indiv01.tmp"
Fri 18 Sep 2009 2,421 ...HR --- "C:\Documents and Settings\Jordan\Application Data\SecuROM\UserData\securom_v7_01.bak"
Fri 19 Sep 2008 2,826,240 A.SH. --- "C:\Documents and Settings\Jordan\Bureau\Logiciel cr‚ation\PhotoshopPortable\App\Photoshop\amtlib.dll"

[b]Finished![/b]
A voir également:

2 réponses

Utilisateur anonyme
 
salut

Voilà j'ai fait une analyse avec sdfix et j'aimerais savoir ce qui l'en est.


tu peu aussi reformuler ta demande avec un peux plus de m ot magique.

sans rancune ? ;-)
0
Jotech057
 
Re,

Merci pour ta moral.

Donc
Voilà j'ai fait une analyse avec sdfix et j'aimerais savoir ce qui l'en est. SVP


La prochaine fois badawan76 ne post pas sur le sujet sa sert à rien et part flooder.

Cordialement Jordan
0