Bon ben voilà le résultat : que pouvez vous en conclure :
Logfile of HijackThis v1.99.1
Scan saved at 14:40:56, on 08/06/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINNTSystem32smss.exe
C:WINNTsystem32winlogon.exe
C:WINNTsystem32services.exe
C:WINNTsystem32lsass.exe
C:WINNTSystem32SCardSvr.exe
C:WINNTsystem32Ati2evxx.exe
C:WINNTsystem32svchost.exe
C:WINNTsystem32spoolsv.exe
C:Program FilesAltirisAltiris AgentAeXNSAgent.exe
C:WINNTSYSTEM32DWRCS.EXE
C:WINNTSystem32svchost.exe
C:WINNTsystem32hidserv.exe
C:PROGRA~1IomegaSystem32AppServices.exe
C:WINNTsystem32
egsvc.exe
C:WINNTsystem32MSTask.exe
C:Program FilesCheckPointSecuRemoteinSR_WatchDog.exe
C:Program FilesSophos SWEEP for NTSWEEPSRV.SYS
C:Program FilesSophos SWEEP for NTSWUPDATE.EXE
C:WINNTSystem32WBEMWinMgmt.exe
C:WINNTsystem32mspmspsv.exe
C:Program FilesCheckPointSecuRemoteinSR_Service.exe
C:WINNTsystem32Ati2evxx.exe
C:WINNTExplorer.EXE
C:Program FilesCheckPointSecuRemoteinSR_GUI.exe
C:WINNTSYSTEM32DWRCST.exe
C:WINNTsystem32carpserv.exe
C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
C:Program FilesSmpfHbwlc.exe
C:winnt empic_gatordm.exe
C:Program FilesMicrosoft ActiveSyncWCESCOMM.EXE
C:Program FilesDate ManagerDateManager.exe
C:Program FilesSophos SWEEP for NTICMON.EXE
C:Program FilesMicrosoft OfficeOfficeOSA.EXE
C:Program FilesWinZipWZQKPICK.EXE
C:PROGRA~1WINZIPwinzip32.exe
C:Documents and SettingsjdurandLocal SettingsTempHijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://fr.yahoo.com/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak =
http://www.yahoo.fr/
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Microsoft Internet Explorer fourni par Telenet Internet
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,AutoConfigURL =
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = ECSPROXY:80
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = <local>
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O2 - BHO: ShprRprts - {2A8A997F-BB9F-48F6-AA2B-2762D50F9289} - C:Program FilesShopperReportsBin1.0.5.0ShprRprt.dll
O2 - BHO: SetupHtml Class - {51641EF3-8A7A-4D84-8659-B0911E947CC8} - C:WINNTDOWNLO~1DOWNLO~1.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINNTsystem32msdxm.ocx
O4 - HKLM..Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM..Run: [CARPService] carpserv.exe
O4 - HKLM..Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [Client Access Service] "C:Program FilesIBMClient Accesscwbsvstr.exe"
O4 - HKLM..Run: [Client Access Help Update] "C:Program FilesIBMClient Accesscwbinhlp.exe"
O4 - HKLM..Run: [Client Access Check Version] "C:Program FilesIBMClient Accesscwbckver.exe" LOGIN
O4 - HKLM..Run: [Client Access Express Welcome] "C:Program FilesIBMClient Accesscwbwlwiz.exe"
O4 - HKLM..Run: [qkiospcmgwytj] C:WINNTsystem32sfozic.exe
O4 - HKLM..Run: [AeXAgentLogon] "C:Program FilesAltirisAltiris AgentAeXAgentActivate.exe" /logon
O4 - HKLM..Run: [NeroFilterCheck] C:WINNTsystem32NeroCheck.exe
O4 - HKLM..Run: [Ervrb] C:Program FilesSmpfHbwlc.exe
O4 - HKLM..Run: [navapp] C:Program FilesNavExcelNavHelperv2.0.4d
avapp.exe
O4 - HKLM..Run: [Media Access] C:Program FilesMedia AccessMediaAccK.exe
O4 - HKLM..Run: [WindUpdates] C:Program FilesWindUpdatesWinUpdt.exe
O4 - HKLM..Run: [Trickler] "c:winnt empic_gatordm.exe"
O4 - HKCU..Run: [H/PC Connection Agent] "C:Program FilesMicrosoft ActiveSyncWCESCOMM.EXE"
O4 - Startup: DskMgr.exe
O4 - Global Startup: Date Manager.lnk = C:Program FilesDate ManagerDateManager.exe
O4 - Global Startup: InterCheck Monitor.LNK = C:Program FilesSophos SWEEP for NTICMON.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:Program FilesMicrosoft OfficeOfficeFINDFAST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O4 - Global Startup: Office Startup.lnk = C:Program FilesMicrosoft OfficeOfficeOSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:Program FilesWinZipWZQKPICK.EXE
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:Program FilesMicrosoft ActiveSyncINETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:Program FilesMicrosoft ActiveSyncINETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:Program FilesMicrosoft ActiveSyncINETREPL.DLL
O9 - Extra button: ShopperReports - Compare travel rates - {946B3E9E-E21A-49c8-9F63-900533FAFE14} - C:Program FilesShopperReportsBin1.0.5.0ShprRprt.dll
O9 - Extra button: ShopperReports - Compare product prices - {E77EDA01-3C56-4a96-8D08-02B42891C169} - C:Program FilesShopperReportsBin1.0.5.0ShprRprt.dll
O12 - Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: Interface Chat Voila -
http://chat14.x-echo.com/version5/Applet/vchatsign.cab
O16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/games/c ... potd_x.cab
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) -
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) -
http://www.cult3d.com/download/cult.cab
O16 - DPF: {51641EF3-8A7A-4D84-8659-B0911E947CC8} (SetupHtml Class) -
http://www.contenidospc.com/instalador.cab
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} (HbtInstObj) -
http://installs.hotbar.com/installs/hbt ... btools.cab
O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} -
http://www.desktoplife.net/1014061.exe
O17 - HKLMSystemCCSServicesTcpipParameters: Domain = ecs.grp
O17 - HKLMSystemCS1ServicesTcpipParameters: Domain = ecs.grp
O17 - HKLMSystemCS2ServicesTcpipParameters: Domain = ecs.grp
O20 - Winlogon Notify: ckpNotify - C:WINNTSYSTEM32ckpNotify.dll
O23 - Service: Altiris Agent (AeXNSClient) - Altiris, Inc. - C:Program FilesAltirisAltiris AgentAeXNSAgent.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:WINNTsystem32Ati2evxx.exe
O23 - Service: Fonction Commande à distance de Client Access Express (Cwbrxd) - IBM Corporation - C:WINNTCWBRXD.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:WINNTSystem32dmadmin.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:WINNTSYSTEM32DWRCS.EXE
O23 - Service: Iomega App Services - Iomega Corporation - C:PROGRA~1IomegaSystem32AppServices.exe
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - C:Program FilesCheckPointSecuRemoteinSR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - C:Program FilesCheckPointSecuRemoteinSR_WatchDog.exe
O23 - Service: Sweep for Windows NT Network (SWEEPNET) - Sophos Plc - C:Program FilesSophos SWEEP for NTSWNETSUP.EXE
O23 - Service: Sophos Anti-Virus (SWEEPSRV.SYS) - Sophos Plc - C:Program FilesSophos SWEEP for NTSWEEPSRV.SYS
O23 - Service: Sweep for Windows NT Update (SWEEPUPDATE) - Sophos Plc - C:Program FilesSophos SWEEP for NTSWUPDATE.EXE