voici le fameux rapport merci de l'aide.
Deckard's System Scanner v20071014.68
Run by BORE on 2008-07-01 13:50:17
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
67: 2008-07-01 11:50:38 UTC - RP535 - Deckard's System Scanner Restore Point
66: 2008-07-01 10:04:01 UTC - RP534 - Point de vérification système
65: 2008-06-30 07:03:00 UTC - RP533 - Point de vérification système
64: 2008-06-29 06:22:52 UTC - RP532 - Point de vérification système
63: 2008-06-27 09:17:51 UTC - RP531 - Point de vérification système
-- First Restore Point --
1: 2008-04-03 11:26:26 UTC - RP469 - Point de vérification système
Backed up registry hives.
Performed disk cleanup.
Percentage of Memory in Use: 80% (more than 75%).
Total Physical Memory: 256 MiB (512 MiB recommended).
-- HijackThis (run as BORE.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:40:02, on 01/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\OCS Inventory Agent\ocsservice.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZipm12.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Documents and Settings\BORE\Bureau\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\BORE.exe
C:\WINDOWS\system32\dumprep.exe
C:\WINDOWS\system32\dumprep.exe
C:\Program Files\Mozilla Firefox\firefox.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.inra.fr/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = cache.angers.inra.fr:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [braviax] C:\WINDOWS\system32\braviax.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_s(...)
O23 - Service: Microsoft ASPI Manager (aspimgr) - Unknown owner - C:\WINDOWS\system32\aspimgr.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: OCS INVENTORY SERVICE (OCS INVENTORY) -
http://ocsinventory.sourceforge.net - C:\Program Files\OCS Inventory Agent\ocsservice.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VNC Server (winvnc) - TightVNC Group - C:\Program Files\TightVNC\WinVNC.exe
O24 - Desktop Component 0: (no name) -
http://www.supphoto.net/galerie/fonds_ecrans_gratuits/tunisie_palmiers.jpg
--
End of file - 5491 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 BANTExt (Belarc SMBios Access) - c:\windows\system32\drivers\bantext.sys
S0 cercsr6 - c:\windows\system32\drivers\cercsr6.sys <Not Verified; Adaptec, Inc.; Dell RAID Controller>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 OCS INVENTORY (OCS INVENTORY SERVICE) - "c:\program files\ocs inventory agent\ocsservice.exe" <Not Verified;
http://ocsinventory.sourceforge.net; Open Computers and Software Inventory>
R2 winvnc (VNC Server) - "c:\program files\tightvnc\winvnc.exe" -service <Not Verified; TightVNC Group; TightVNC Win32 Server>
S2 aspimgr (Microsoft ASPI Manager) - c:\windows\system32\aspimgr.exe (file missing)
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318}
Description: C-Media AC97 Audio Device
Device ID: PCI\VEN_1039&DEV_7012&SUBSYS_20071631&REV_A0\3&61AAA01&0&17
Manufacturer: C-Media
Name: C-Media AC97 Audio Device
PNP Device ID: PCI\VEN_1039&DEV_7012&SUBSYS_20071631&REV_A0\3&61AAA01&0&17
Service: cmuda
-- Files created between 2008-06-01 and 2008-07-01 -----------------------------
2008-07-01 14:38:53 0 d-------- C:\Program Files\Trend Micro
2008-07-01 11:37:51 0 d-------- C:\Program Files\Navilog1
2008-07-01 10:06:42 13528 --a------ C:\WINDOWS\system32\openicywo.bin
2008-07-01 10:06:42 11805 --a------ C:\WINDOWS\system32\kekaf.exe
2008-07-01 10:06:42 19939 --a------ C:\Program Files\Fichiers communs\gunobyloso.pif
2008-07-01 10:06:42 10202 --a------ C:\Documents and Settings\BORE\Application Data\azufon.vbs
2008-07-01 10:06:42 17878 --a------ C:\Documents and Settings\All Users\Application Data\fome.scr
2008-07-01 10:06:41 10996 --a------ C:\WINDOWS\vyzujitaq.reg
2008-07-01 10:06:41 10898 --a------ C:\WINDOWS\system32\tuvu.sys
2008-07-01 10:06:41 14925 --a------ C:\WINDOWS\seqyqamu.dat
2008-07-01 10:06:41 16085 --a------ C:\WINDOWS\obitobyku.scr
2008-07-01 10:06:41 13886 --a------ C:\WINDOWS\hupibe.bin
2008-07-01 10:06:41 10867 --a------ C:\Program Files\Fichiers communs\ukud.pif
2008-07-01 10:06:41 16212 --a------ C:\Documents and Settings\BORE\Application Data\uginuwolek.exe
2008-07-01 10:06:41 15192 --a------ C:\Documents and Settings\All Users\Application Data\titi.bin
2008-07-01 10:06:41 14161 --a------ C:\Documents and Settings\All Users\Application Data\oqeqikisa.sys
2008-07-01 10:06:41 19558 --a------ C:\Documents and Settings\All Users\Application Data\iryqi.reg
2008-07-01 10:06:41 13581 --a------ C:\Documents and Settings\All Users\Application Data\guwarite.exe
2008-07-01 09:18:43 114 --a------ C:\WINDOWS\system32\delself.bat
2008-07-01 09:18:36 8192 --a------ C:\WINDOWS\system32\braviax.exe
2008-06-02 09:33:33 0 d-------- C:\Documents and Settings\All Users\KONICA MINOLTA
2008-06-02 09:32:45 0 d-------- C:\Program Files\KONICA MINOLTA
2008-06-02 09:30:40 0 d-------- C:\WINDOWS\Downloaded Installations
-- Find3M Report ---------------------------------------------------------------
2008-07-01 14:20:44 0 d-------- C:\Program Files\Symantec AntiVirus
2008-07-01 12:28:13 0 d-------- C:\Program Files\Mozilla Thunderbird
2008-07-01 10:06:42 0 d-------- C:\Program Files\Fichiers communs
2008-07-01 06:41:19 0 d-------- C:\Program Files\OCS Inventory Agent
2008-06-18 10:34:59 0 d-------- C:\Documents and Settings\BORE\Application Data\Mozilla
2008-04-07 10:32:11 370414 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-04-07 10:32:11 49494 --a------ C:\WINDOWS\system32\perfc00C.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="cmicnfg.cpl" []
"C-Media Mixer"="Mixer.exe" [15/10/2002 18:00 C:\WINDOWS\mixer.exe]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [12/07/2005 12:35]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [18/08/2005 13:11]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [06/07/2006 12:19]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [11/06/2007 11:25]
"WinVNC"="C:\Program Files\TightVNC\WinVNC.exe" [07/05/2007 20:28]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 23:16]
"braviax"="C:\WINDOWS\system32\braviax.exe" [01/07/2008 09:18]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [05/08/2004 14:00]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"braviax"=C:\WINDOWS\system32\braviax.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
*Newly Created Service* - CATCHME
-- End of Deckard's System Scanner: finished at 2008-07-01 14:41:43 ------------