[quote="georgiou"]Fais un log avec [url=http://80.237.140.193/downloads/hijackthis_199.zip]HijackThis[/url] et poste le içi.[/quote]
Voila :
Logfile of HijackThis v1.99.1
Scan saved at 20:15:18, on 11/04/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSSystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
C:WINDOWSSOUNDMAN.EXE
C:PROGRA~1A4TechMouseAmoumain.exe
D:MessageStopMessageStop.exe
C:Program FilesAntivirus-Profi-PaketAVKPOP.EXE
C:WINDOWSSystem32
undll32.exe
D:Program FilesSpybot - Search & DestroyTeaTimer.exe
D:Program FilesskipeSkype.exe
C:Program FilesKerioWinRoute FirewallWrCtrl.exe
C:Program FilesMSN Messengermsnmsgr.exe
C:Program FilesMozilla Thunderbird hunderbird.exe
C:PROGRA~1MOZILL~1FIREFOX.EXE
C:Program FilesESTsoftALZipALZip.exe
C:Documents and SettingsdavidLocal SettingsTemp\_AZTMP0_HijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://my.freeze.com/start.shtml
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) =
http://search.qsrch.com/
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Microsoft Internet Explorer
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:Program Filesadobe acrobatReaderActiveXAcroIEHelper.dll
O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:Program FilesNewDotNet
ewdotnet6_38.dll
O2 - BHO: Quick! - {4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} - C:PROGRA~1quickbarquickbar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:PROGRA~1SPYBOT~1SDHelper.dll
O3 - Toolbar: Quick! - {4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} - C:PROGRA~1quickbarquickbar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O4 - HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [WheelMouse] C:PROGRA~1A4TechMouseAmoumain.exe
O4 - HKLM..Run: [MessageStop] D:MessageStopMessageStop.exe
O4 - HKLM..Run: [AVK Mail Checker] "C:Program FilesAntivirus-Profi-PaketAVKPOP.EXE"
O4 - HKLM..Run: [New.net Startup] rundll32 C:PROGRA~1NEWDOT~1NEWDOT~1.DLL,NewDotNetStartup -s
O4 - HKLM..Run: [QuickTime Task] "D:quick timeqttask.exe" -atboottime
O4 - HKCU..Run: [SpybotSD TeaTimer] D:Program FilesSpybot - Search & DestroyTeaTimer.exe
O4 - HKCU..Run: [Skype] "D:Program FilesskipeSkype.exe" /nosplash /minimized
O4 - HKCU..Run: [WrCtrl] C:Program FilesKerioWinRoute FirewallWrCtrl.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:Program FilesFichiers communsAdobeCalibrationAdobe Gamma Loader.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengerMSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengerMSMSGS.EXE
O9 - Extra button: Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:Program FilesAgnitumOutpost Firewall 1.0 rash.exe (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Show Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:Program FilesAgnitumOutpost Firewall 1.0 rash.exe (file missing) (HKCU)
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004 ... scan53.cab
O17 - HKLMSystemCCSServicesTcpip..{B401CEC1-5BAE-44FE-A83D-02BAFC484D08}: NameServer = 212.151.136.250 130.244.127.161
O23 - Service: Ati HotKey Poller - Unknown owner - C:WINDOWSSystem32Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe
O23 - Service: Kerio WinRoute Firewall (WinRoute) - Kerio Technologies - C:Program FilesKerioWinRoute Firewallwinroute.exe