Rapport ComboFix:
ComboFix 08-05-01.3 - Lucas 2008-05-03 11:46:41.1 - NTFSx86 MINIMAL
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.412 [GMT 2:00]
Endroit: D:\Documents and Settings\Lucas\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Documents and Settings\NetworkService\Application Data\NetMon
D:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt
D:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt
D:\WINDOWS\pskt.ini
D:\WINDOWS\system32\avtbirua.dll
D:\WINDOWS\system32\awttqnKB.dll
D:\WINDOWS\system32\bcudhchb.ini
D:\WINDOWS\system32\bhchducb.dll
D:\WINDOWS\system32\byXQJDvT.dll
D:\WINDOWS\system32\fccaXPig.dll
D:\WINDOWS\system32\giPXaccf.ini
D:\WINDOWS\system32\giPXaccf.ini2
D:\WINDOWS\system32\j7
D:\WINDOWS\system32\j7\binx12l.exe
D:\WINDOWS\system32\khfETlKb.dll
D:\WINDOWS\system32\lcgnnvub.dll
D:\WINDOWS\system32\msnav32.ax
D:\WINDOWS\system32\n4
D:\WINDOWS\system32\n4\evb5ui.exe
D:\WINDOWS\system32\ooogpfyu.ini
D:\WINDOWS\system32\qouhqlwk.dll
D:\WINDOWS\system32\topnuvqv.dll
D:\WINDOWS\system32\ymbols~1
D:\WINDOWS\system32\zxdnt3d.cfg
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMDSERVICE
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-03 to 2008-05-03 ))))))))))))))))))))))))))))))))))))
.
2008-05-03 11:55 . 2008-05-03 11:55 21 --a------ D:\WINDOWS\system32\zxdnt3d.cfg
2008-05-03 10:58 . 2008-05-03 11:07 628 --a------ D:\WINDOWS\system32\tmp.reg
2008-05-03 10:57 . 2007-09-06 00:22 289,144 --a------ D:\WINDOWS\system32\VCCLSID.exe
2008-05-03 10:57 . 2006-04-27 17:49 288,417 --a------ D:\WINDOWS\system32\SrchSTS.exe
2008-05-03 10:57 . 2008-04-24 08:10 86,528 --a------ D:\WINDOWS\system32\VACFix.exe
2008-05-03 10:57 . 2008-04-28 08:03 82,944 --a------ D:\WINDOWS\system32\IEDFix.exe
2008-05-03 10:57 . 2008-04-28 08:03 82,944 --a------ D:\WINDOWS\system32\404Fix.exe
2008-05-03 10:57 . 2003-06-05 21:13 53,248 --a------ D:\WINDOWS\system32\Process.exe
2008-05-03 10:57 . 2004-07-31 18:50 51,200 --a------ D:\WINDOWS\system32\dumphive.exe
2008-05-03 10:57 . 2007-10-04 00:36 25,600 --a------ D:\WINDOWS\system32\WS2Fix.exe
2008-05-03 10:54 . 2008-05-03 10:54 49,181 --a------ D:\WINDOWS\system32\rwwnw64d.exe
2008-05-03 10:24 . 2008-05-03 10:24 <REP> d-------- D:\WINDOWS\ERUNT
2008-05-03 10:12 . 2008-05-03 10:52 <REP> d-------- D:\SDFix
2008-05-02 23:21 . 2008-05-02 23:21 <REP> d-------- D:\Program Files\Yahoo!
2008-05-02 23:20 . 2008-05-02 23:22 <REP> d-------- D:\Program Files\CCleaner
2008-05-02 23:10 . 2008-05-03 11:42 292,896 --ahs---- D:\WINDOWS\system32\drivers\fidbox.dat
2008-05-02 23:10 . 2008-05-03 11:42 4,256 --ahs---- D:\WINDOWS\system32\drivers\fidbox.idx
2008-05-02 23:05 . 2008-05-02 23:05 <REP> d-------- D:\Documents and Settings\All Users\Application Data\MailFrontier
2008-05-02 23:04 . 2008-04-02 21:07 75,248 --a------ D:\WINDOWS\zllsputility.exe
2008-05-02 23:04 . 2008-04-02 21:08 54,672 --a------ D:\WINDOWS\system32\vsutil_loc040c.dll
2008-05-02 23:04 . 2008-04-02 21:08 42,384 --a------ D:\WINDOWS\zllsputility_loc040c.dll
2008-05-02 23:04 . 2008-04-02 21:08 21,904 --a------ D:\WINDOWS\system32\imsinstall_loc040c.dll
2008-05-02 23:04 . 2008-04-02 21:08 17,808 --a------ D:\WINDOWS\system32\imslsp_install_loc040c.dll
2008-05-02 23:04 . 2004-04-27 05:40 11,264 --a------ D:\WINDOWS\system32\SpOrder.dll
2008-05-02 23:04 . 2008-05-02 23:08 4,212 ---h----- D:\WINDOWS\system32\zllictbl.dat
2008-05-02 23:03 . 2008-04-02 21:07 1,086,952 --a------ D:\WINDOWS\system32\zpeng24.dll
2008-05-02 23:02 . 2008-05-02 23:04 <REP> d-------- D:\WINDOWS\system32\ZoneLabs
2008-05-02 23:02 . 2008-05-03 11:55 <REP> d-------- D:\WINDOWS\Internet Logs
2008-05-02 23:02 . 2008-05-02 23:02 <REP> d-------- D:\Program Files\Zone Labs
2008-05-02 23:02 . 2008-05-03 11:52 358,382 --a------ D:\WINDOWS\system32\vsconfig.xml
2008-05-02 22:59 . 2008-05-02 22:59 <REP> d-------- D:\Program Files\Trend Micro
2008-05-02 22:47 . 2008-05-02 22:47 1,024 --ah----- D:\Documents and Settings\Default User\NTUSER.DAT.LOG
2008-05-02 22:40 . 2004-08-05 14:00 482,304 --a--c--- D:\WINDOWS\system32\dllcache\pintlgnt.ime
2008-05-02 22:39 . 2004-08-05 14:00 1,875,968 --a--c--- D:\WINDOWS\system32\dllcache\msir3jp.lex
2008-05-02 22:38 . 2004-08-05 14:00 13,463,552 --a--c--- D:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-05-02 22:37 . 2004-08-05 14:00 1,677,824 --a--c--- D:\WINDOWS\system32\dllcache\chsbrkr.dll
2008-05-02 22:36 . 2004-05-13 00:39 876,653 --a--c--- D:\WINDOWS\system32\dllcache\fp4awel.dll
2008-05-02 22:28 . 2008-05-02 22:28 749 -rah----- D:\WINDOWS\WindowsShell.Manifest
2008-05-02 22:28 . 2008-05-02 22:28 749 -rah----- D:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-05-02 22:28 . 2008-05-02 22:28 749 -rah----- D:\WINDOWS\system32\sapi.cpl.manifest
2008-05-02 22:28 . 2008-05-02 22:28 749 -rah----- D:\WINDOWS\system32\ncpa.cpl.manifest
2008-05-02 22:28 . 2008-05-02 22:28 488 -rah----- D:\WINDOWS\system32\logonui.exe.manifest
2008-05-02 22:11 . 2004-08-05 14:00 1,086,058 -ra------ D:\WINDOWS\SET77.tmp
2008-05-02 22:11 . 2004-08-05 14:00 1,014,836 -ra------ D:\WINDOWS\SET74.tmp
2008-05-02 22:11 . 2004-08-05 14:00 14,043 -ra------ D:\WINDOWS\SET83.tmp
2008-05-02 21:37 . 2008-05-02 21:37 399,604 --a------ D:\WINDOWS\system32\g89.exe
2008-05-02 21:37 . 2008-05-02 21:37 49,172 --a------ D:\WINDOWS\system32\jpwnw64k.exe
2008-05-02 21:27 . 2008-05-02 21:28 <REP> d-------- D:\WINDOWS\system32\fr-fr
2008-05-02 21:11 . 2008-05-02 22:58 109,794 --a------ D:\WINDOWS\BMd39f6c2c.xml
2008-05-02 21:06 . 2008-05-02 21:06 88,961 --a------ D:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
2008-05-02 21:06 . 2008-05-02 21:06 862 --a------ D:\WINDOWS\system32\winpfz33.sys
2008-05-02 21:05 . 2008-05-02 21:05 298,314 --a------ D:\WINDOWS\system32\gside.exe
2008-05-02 21:05 . 2008-05-02 21:05 200,775 --a------ D:\WINDOWS\system32\ocntqkdm.exe
2008-05-02 21:04 . 2008-05-02 21:04 <REP> d-------- D:\WINDOWS\system32\bkEur01
2008-05-02 21:00 . 2008-05-02 21:00 <REP> d-------- D:\WINDOWS\Sun
2008-05-01 11:04 . 2008-05-02 21:50 <REP> d-------- D:\Program Files\Warcraft III
2008-05-01 10:12 . 2008-05-01 10:13 <REP> d-------- D:\Program Files\Google
2008-04-30 18:05 . 2004-08-05 14:00 1,086,058 -ra------ D:\WINDOWS\SET24.tmp
2008-04-30 18:05 . 2004-08-05 14:00 1,014,836 -ra------ D:\WINDOWS\SET21.tmp
2008-04-30 18:05 . 2004-10-28 03:50 15,304 -ra------ D:\WINDOWS\SET68.tmp
2008-04-30 18:05 . 2004-08-05 14:00 14,043 -ra------ D:\WINDOWS\SET33.tmp
2008-04-30 18:05 . 2004-09-29 21:14 13,249 -ra------ D:\WINDOWS\SET6A.tmp
2008-04-30 18:05 . 2004-10-29 02:42 11,421 -ra------ D:\WINDOWS\SET67.tmp
2008-04-30 18:05 . 2004-08-12 20:12 10,425 -ra------ D:\WINDOWS\SET69.tmp
2008-04-30 18:05 . 2004-10-21 19:09 10,425 -ra------ D:\WINDOWS\SET66.tmp
2008-04-30 18:04 . 2008-05-02 21:32 390,042 --a------ D:\WINDOWS\setupapi.old
2008-04-30 16:21 . 2004-08-05 14:00 221,184 --a------ D:\WINDOWS\system32\wmpns.dll
2008-04-30 16:21 . 2008-05-03 11:56 65,536 --ah----- D:\Documents and Settings\Lucas\ntuser.dat.LOG
2008-04-30 16:20 . 2008-04-30 19:42 <REP> d--h----- D:\Documents and Settings\Lucas\Voisinage r‚seau
2008-04-30 16:20 . 2008-04-30 19:42 <REP> d--h----- D:\Documents and Settings\Lucas\Voisinage d'impression
2008-04-30 16:20 . 2008-04-30 15:56 <REP> d--h----- D:\Documents and Settings\Lucas\ModŠles
2008-04-30 16:20 . 2008-05-02 22:47 <REP> dr------- D:\Documents and Settings\Lucas\Mes documents
2008-04-30 16:20 . 2008-04-30 19:42 <REP> dr------- D:\Documents and Settings\Lucas\Menu D‚marrer
2008-04-30 16:20 . 2008-05-02 22:58 <REP> dr------- D:\Documents and Settings\Lucas\Favoris
2008-04-30 16:20 . 2008-05-03 11:49 <REP> d-------- D:\Documents and Settings\Lucas\Bureau
2008-04-30 16:20 . 2008-05-03 11:41 <REP> d-------- D:\Documents and Settings\Lucas
2008-04-30 16:17 . 2008-04-30 16:17 <REP> d---s---- D:\WINDOWS\system32\Microsoft
2008-04-30 16:17 . 2008-04-30 16:17 <REP> d--hs---- D:\Documents and Settings\LocalService
2008-04-30 16:17 . 2008-05-03 11:54 1,024 --ah----- D:\Documents and Settings\LocalService\ntuser.dat.LOG
2008-04-30 16:16 . 2008-04-30 16:16 <REP> d--hs---- D:\Documents and Settings\NetworkService
2008-04-30 16:16 . 2008-04-30 16:16 8,192 --a------ D:\WINDOWS\REGLOCS.OLD
2008-04-30 16:16 . 2008-05-03 11:52 1,024 --ah----- D:\Documents and Settings\NetworkService\ntuser.dat.LOG
2008-04-30 16:14 . 2008-04-30 19:42 <REP> d--h----- D:\WINDOWS\system32\config\systemprofile\Voisinage r‚seau
2008-04-30 16:14 . 2008-04-30 19:42 <REP> d--h----- D:\WINDOWS\system32\config\systemprofile\Voisinage d'impression
2008-04-30 16:14 . 2008-04-30 15:56 <REP> d--h----- D:\WINDOWS\system32\config\systemprofile\ModŠles
2008-04-30 16:14 . 2008-04-30 19:42 <REP> d-------- D:\WINDOWS\system32\config\systemprofile\Mes documents
2008-04-30 16:14 . 2008-04-30 19:42 <REP> dr------- D:\WINDOWS\system32\config\systemprofile\Menu D‚marrer
2008-04-30 16:14 . 2008-04-30 19:42 <REP> d-------- D:\WINDOWS\system32\config\systemprofile\Favoris
2008-04-30 16:14 . 2008-04-30 19:42 <REP> d-------- D:\WINDOWS\system32\config\systemprofile\Bureau
2008-04-30 16:11 . 2003-03-24 15:52 618,605 --a--c--- D:\WINDOWS\system32\dllcache\fp4autl.dll
2008-04-30 16:09 . 2008-04-30 16:09 <REP> d-------- D:\WINDOWS\system32\xircom
2008-04-30 16:09 . 2008-04-30 16:09 <REP> d-------- D:\Program Files\microsoft frontpage
2008-04-30 16:09 . 2008-04-30 16:08 49,262 --a------ D:\WINDOWS\system32\jpicpl32.cpl
2008-04-30 16:09 . 2002-02-19 17:14 17,638 --a------ D:\WINDOWS\system32\OEMLOGO.BMP
2008-04-30 16:09 . 2001-11-14 10:26 996 --a------ D:\WINDOWS\system32\OEMINFO.INI
2008-04-30 16:08 . 2008-04-30 16:08 <REP> d-------- D:\Program Files\Java
2008-04-30 16:08 . 2008-04-30 16:08 <REP> d-------- D:\Program Files\Fichiers communs\Java
2008-04-30 16:06 . 2008-04-30 16:06 <REP> d-------- D:\WINDOWS\system32\URTTemp
2008-04-30 16:05 . 2008-04-30 16:09 <REP> d-------- D:\WINDOWS\fsc
2008-04-30 16:05 . 2008-04-30 16:09 <REP> d-------- D:\AddOn
2008-04-30 16:04 . 2008-05-02 21:23 <REP> d--h----- D:\WINDOWS\$hf_mig$
2008-04-30 16:04 . 2006-09-06 17:43 22,752 --a------ D:\WINDOWS\system32\spupdsvc.exe
2008-04-30 16:04 . 2008-04-30 16:04 3,072 --a------ D:\WINDOWS\system32\CONFIG.NT
2008-04-30 16:04 . 2008-04-30 16:04 0 --a------ D:\WINDOWS\control.ini
2008-04-30 16:03 . 2008-05-02 22:33 316,640 --a------ D:\WINDOWS\WMSysPr9.prx
2008-04-30 16:03 . 2008-05-02 22:33 23,392 --a------ D:\WINDOWS\system32\nscompat.tlb
2008-04-30 16:03 . 2008-05-02 22:33 16,832 --a------ D:\WINDOWS\system32\amcompat.tlb
2008-04-30 16:01 . 2008-05-02 23:15 <REP> d---s---- D:\WINDOWS\Downloaded Program Files
2008-04-30 16:01 . 2008-04-30 16:03 <REP> d--hs---- D:\Documents and Settings\All Users\DRM
2008-04-30 16:01 . 2008-05-02 22:28 749 -rah----- D:\WINDOWS\system32\nwc.cpl.manifest
2008-04-30 16:01 . 2008-05-02 22:28 749 -rah----- D:\WINDOWS\system32\cdplayer.exe.manifest
2008-04-30 16:01 . 2008-05-02 22:28 488 -rah----- D:\WINDOWS\system32\WindowsLogon.manifest
2008-04-30 16:00 . 2008-04-30 16:00 <REP> d-------- D:\Program Files\Services en ligne
2008-04-30 16:00 . 2004-08-05 14:00 4,399,505 --a--c--- D:\WINDOWS\system32\dllcache\nls302en.lex
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"swg"="D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-02 20:49 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"{A9-9A-AB-BE-DW}"="D:\windows\system32\rwwnw64d.exe" [2008-05-03 10:54 49181]
"ZoneAlarm Client"="D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 21:07 919016]
"ExploreUpdSched"="D:\WINDOWS\system32\ocntqkdm.exe" [2008-05-02 21:05 200775]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byXQJDvT]
byXQJDvT.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-03 11:53:22
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
D:\WINDOWS\system32\zxdnt3d.cfg 21 bytes
Scan termin‚ avec succŠs
Les fichiers cach‚s: 1
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
D:\WINDOWS\system32\ZoneLabs\vsmon.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\system32\wpabaln.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
.
**************************************************************************
.
Temps d'accomplissement: 2008-05-03 11:58:34 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-03 09:58:23
Pre-Run: 3,614,482,432 octets libres
Post-Run: 3,046,322,176 octets libres
204 --- E O F --- 2008-05-02 21:36:42
------------------------------------------------------------------------------------------------------------------------
Rapport HijackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:01:38, on 03/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\ZoneLabs\vsmon.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\wscntfy.exe
D:\windows\system32\rwwnw64d.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\WINDOWS\system32\ocntqkdm.exe
D:\WINDOWS\system32\wpabaln.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\system32\wuauclt.exe
D:\WINDOWS\explorer.exe
D:\WINDOWS\system32\notepad.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Trend Micro\HijackThis\MonJack.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [{A9-9A-AB-BE-DW}] D:\windows\system32\rwwnw64d.exe DWram
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Deewoo.lnk = D:\WINDOWS\system32\ocntqkdm.exe
O4 - Startup: DW_Start.lnk = D:\WINDOWS\system32\rwwnw64d.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: byXQJDvT - byXQJDvT.dll (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINDOWS\system32\ZoneLabs\vsmon.exe
End of file - 4042 bytes
--------------------------------------------------------------------------------------------
Et toujours ce fichier là: D:\windows\system32\rwwnw64d.exe
qui me semble etre un virus...
j'accepte ou pas? (les publicités continuent à apparaitre)