Merci beaucoup pour ces explications/instructions très claires. On dirait que ça va mieux maintenant, je ne suis plus harcelé par Antivirus XP 2008. Le fond d'écran est encore bleu mais il n'y a plus le Warning!...
SDFix: Version 1.217 Run by Administrator on 2008-08-18 at 17:59
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Folder C:\Program Files\rhc5jmj0e94g - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-18 18:06:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40]
"khjeh"=hex:20,02,00,00,af,c6,28,52,f1,a0,e1,44,b3,65,ac,7a,a1,08,35,53,1f,..
"hj34z0"=hex:71,23,f9,e7,0c,39,ba,0e,ea,54,22,27,8b,8e,c7,77,19,13,e8,49,5e,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf41]
"khjeh"=hex:20,02,00,00,85,31,cf,f8,dd,30,88,65,fc,bb,c2,1f,ef,92,24,8b,16,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s0"=dword:cf2cc25a
"s1"=dword:a9d54b33
"s2"=dword:f4fddb1a
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Utilitaires\Alcohol 120\"
"h0"=dword:00000000
"ujdew"=hex:9a,79,58,50,a2,72,1c,03,6e,2a,30,77,14,f0,d4,eb,73,8d,78,28,10,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Utilitaires\Alcohol 120\"
"h0"=dword:00000000
"ujdew"=hex:9a,79,58,50,a2,72,1c,03,6e,2a,30,77,14,f0,d4,eb,73,8d,78,28,10,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Utilitaires\\BitComet\\BitComet.exe"="C:\\Utilitaires\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
"C:\\Utilitaires\\Network Associates\\Common Framework\\FrameworkService.exe"="C:\\Utilitaires\\Network Associates\\Common Framework\\FrameworkService.exe:*:Enabled:McAfee Framework Service"
"C:\\Jeux\\Ubisoft\\Pacific Fighters\\pf.exe"="C:\\Jeux\\Ubisoft\\Pacific Fighters\\pf.exe:*:Disabled:pf"
"C:\\Utilitaires\\eMule\\emule.exe"="C:\\Utilitaires\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\WINDOWS\\system32\\drivers\\svchost.exe"="C:\\WINDOWS\\system32\\drivers\\svchost.exe:*:Disabled:svchost"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
Files with Hidden Attributes :
Sun 16 Apr 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 5 Aug 2004 19,456 A..H. --- "C:\Ecole\Stage1\Rapport\~WRL0004.tmp"
Wed 7 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\BIT5.tmp"
Tue 12 Oct 2004 161,792 A..H. --- "C:\Ecole\S5\S5\APP3\APP3\~WRL0003.tmp"
Tue 12 Oct 2004 167,936 A..H. --- "C:\Ecole\S5\S5\APP3\APP3\~WRL0086.tmp"
Tue 12 Oct 2004 186,880 A..H. --- "C:\Ecole\S5\S5\APP3\APP3\~WRL1962.tmp"
Tue 12 Oct 2004 167,936 A..H. --- "C:\Ecole\S5\S5\APP3\APP3\~WRL3131.tmp"
Finished!