Salut Boule
Excuse moi de ne pas t'avoir répondu au bon endroit ...
voila les rapports
Deckard's System Scanner v20070611.50
Run by rom on 2007-06-12 at 21:08:14
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
60: 2007-06-12 19:08:16 UTC - RP97 - Deckard's System Scanner Restore Point
59: 2007-06-11 18:10:21 UTC - RP96 - Point de vérification système
58: 2007-06-10 10:02:53 UTC - RP95 - Removed Google Toolbar for Internet Explorer
57: 2007-06-10 10:02:42 UTC - RP94 - Removed Google Toolbar for Firefox
56: 2007-06-09 15:48:57 UTC - RP93 - Point de vérification système
-- First Restore Point --
1: 2007-04-23 17:51:01 UTC - RP38 - Point de vérification système
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as rom.exe) -------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 21:08:52, on 12/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Pando Networks\Pando\pando.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\rom\Bureau\dss.exe
C:\DOCUME~1\rom\Bureau\rom.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://go.microsoft.com/fwlink/?LinkId=38938&mpver=11.0.5721.5145&id=C00D1197&contextid=71&originalid=80070002R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [MSNBuster] C:\Program Files\MSNBuster\MSNBuster.exe -d
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [bonainj] c:\windows\system32\bonainj.exe bonainj
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cabO16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) -
http://www.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection.cab?version=O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) -
http://game02.zylom.com/activex/zylomgamesplayer.cabO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
S0 cercsr6 - c:\windows\system32\drivers\cercsr6.sys <Not Verified; Adaptec, Inc.; Dell RAID Controller>
S3 driverhardwarev2 - c:\program files\hardwaredetection\driverhardwarev2.sys <Not Verified; Ma-Config.com; ma-config.com>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
S3 Boonty Games - "c:\program files\fichiers communs\boonty shared\service\boonty.exe" <Not Verified; BOONTY; Boonty Games>
-- Files created between 2007-05-12 and 2007-06-12 -----------------------------
2007-06-12 21:06:58 0 dr-h----- C:\Documents and Settings\rom\Recent
2007-06-12 20:01:45 0 dr-h----- C:\Documents and Settings\mallou\Recent
2007-06-10 20:40:36 0 d-------- C:\Documents and Settings\COCO\Application Data\FastStone
2007-06-04 21:22:54 2848 --a------ C:\WINDOWS\system32\tmp.reg
2007-06-04 21:22:19 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2007-06-04 21:22:19 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified;
http://www.beyondlogic.org; Command Line Process Utility>
2007-06-04 21:22:19 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-06-04 21:18:34 0 d---s---- C:\WINDOWS\Tasks
2007-06-03 11:10:32 0 d-------- C:\WINDOWS\system32\ActiveScan
2007-06-03 11:01:00 0 d-------- C:\WINDOWS\report
2007-06-03 11:00:26 1101904 --a------ C:\WINDOWS\vsapi32.dll <Not Verified; Trend Micro Inc.; VSAPI>
2007-06-03 11:00:26 267845 --a------ C:\WINDOWS\tsc.exe <Not Verified; Trend Micro Inc.; TrendSystemCleaner>
2007-06-03 11:00:26 71749 --a------ C:\WINDOWS\hcextoutput.dll
2007-06-03 11:00:26 86094 --a------ C:\WINDOWS\BPMNT.dll <Not Verified; Trend Micro Inc.; VSAPI>
2007-06-03 11:00:26 0 d-------- C:\WINDOWS\AU_Backup
2007-06-03 10:59:27 0 d-------- C:\WINDOWS\AU_Temp
2007-06-03 10:59:27 0 d-------- C:\WINDOWS\AU_Log
2007-06-03 10:59:19 69689 --a------ C:\WINDOWS\UNZIP.DLL <Not Verified; Trend Micro Inc.; Trend Active Update 1.32>
2007-06-03 10:59:19 507904 --a------ C:\WINDOWS\TMUPDATE.DLL <Not Verified; Trend Micro Inc.; ActiveUpdate Module>
2007-06-03 10:59:18 286720 --a------ C:\WINDOWS\PATCH.EXE <Not Verified; Trend Micro Inc.; ActiveUpdate Module>
2007-06-02 19:13:43 101888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL <Not Verified; Microsoft Corporation; Microsoft® Visual Basic pour Windows>
2007-06-02 19:13:43 21504 --a------ C:\WINDOWS\system32\TABCTFR.DLL <Not Verified; Microsoft Corporation; Bibliothèque d'objets TabCtl32>
2007-06-02 19:13:43 141312 --a------ C:\WINDOWS\system32\MSCMCFR.DLL <Not Verified; Microsoft Corporation; COMCTL>
2007-06-02 19:13:43 59904 --a------ C:\WINDOWS\system32\Mscc2fr.dll <Not Verified; Microsoft Corporation; Bibliothèque d'objets de Microsoft Common Controls 2>
2007-06-02 19:13:43 15360 --a------ C:\WINDOWS\system32\inetfr.DLL <Not Verified; Microsoft Corporation; DLL du contrôle Microsoft Internet Transfer>
2007-06-02 19:13:43 32768 --a------ C:\WINDOWS\system32\CMDLGFR.DLL <Not Verified; Microsoft Corporation; CMDIALOG>
2007-06-02 19:13:42 0 d-------- C:\Program Files\Free Audio Pack
2007-06-02 18:53:26 0 d-------- C:\Documents and Settings\rom\Application Data\dvdcss
2007-06-02 18:41:03 162304 --a------ C:\UNWISE.EXE
2007-06-02 09:24:42 0 d-------- C:\Program Files\Sunbelt Software
2007-05-31 19:02:22 0 d-------- C:\Documents and Settings\rom\Application Data\OpenOffice.org2
2007-05-31 17:41:35 0 d-------- C:\Program Files\AxBx
2007-05-31 17:34:16 0 d--h----- C:\WINDOWS\msdownld.tmp
2007-05-31 17:34:10 0 d-------- C:\WINDOWS\system32\fr-fr
2007-05-31 17:28:25 0 d-------- C:\WINDOWS\network diagnostic
2007-05-31 17:00:52 0 d-------- C:\Program Files\MSNBuster
2007-05-31 16:52:48 0 d-------- C:\Program Files\OpenOffice.org 2.2
2007-05-28 15:56:41 0 d-------- C:\Documents and Settings\NANOU\Application Data\vlc
2007-05-28 15:54:28 0 d-------- C:\Documents and Settings\NANOU\Application Data\LogProtect
2007-05-23 10:43:01 0 d-------- C:\Documents and Settings\mallou\Application Data\Skype
2007-05-22 23:01:32 104960 --a------ C:\WINDOWS\GizmoZone Screensaver.scr
2007-05-20 19:49:52 0 d-------- C:\Program Files\Fichiers communs\Skype
2007-05-18 21:12:14 0 d-------- C:\Documents and Settings\mallou\Application Data\vlc
2007-05-18 14:00:41 0 d-------- C:\Documents and Settings\COCO\Application Data\vlc
2007-05-18 13:53:20 0 d-------- C:\Documents and Settings\rom\Application Data\vlc
2007-05-18 13:52:48 0 d-------- C:\Program Files\VideoLAN
2007-05-15 18:53:43 0 d-------- C:\Program Files\Replay Media Catcher
2007-05-15 18:53:00 135168 --a------ C:\WINDOWS\system32\DSKernel2.dll <Not Verified; LEAD Technologies, Inc.; LEADTOOLS Multimedia Filter Pack>
2007-05-15 18:52:56 737280 --a------ C:\WINDOWS\iun6002.exe <Not Verified; Indigo Rose Corporation; Setup Factory 6.0 Runtime Module>
2007-05-15 18:52:52 2874926 --a------ C:\Program Files\FLV PlayerRCATSetup.exe
2007-05-15 18:52:37 0 d-------- C:\Program Files\Replay Converter
2007-05-15 18:49:56 0 d-------- C:\WINDOWS\FLV Player
2007-05-15 18:49:56 0 d-------- C:\Program Files\FLV Player
2007-05-13 19:52:14 0 d---s---- C:\Documents and Settings\mallou\UserData
---------