aider

  • hizza
  • Born
  • Born
  • No Avatar
  • Inscription: Fév 03, 2011
  • Messages: 1
  • Status: Offline

Message Février 3rd, 2011, 1:10 pm

Je pense avoir un keylogger

Logfile of Trend Micro HijackThis v2.0.4
Scan sauvé à 20:05:44, le 02/03/2011
Windows Vista SP2 (WinNT 6.00.1906): Plate-forme
MSIE: Internet Explorer v8.00 (8.00.6001.18999)
Boot mode: Normal

Les processus en cours:
C: \ Windows \ system32 \ taskeng.exe
C: \ Windows \ system32 \ dwm.exe
C: \ Windows \ Explorer.EXE
\ Program Files \ Synaptics \ SynTP \ Syntpenh.exe: C
C: \ Program Files \ HP \ QuickPlay \ QPService. exe
\ Program Files \ Hewlett-Packard \ HP Quick Launch Buttons \ QLBCTRL.exe: C
\ Program Files \ Hewlett-Packard \ bilan de santé HP \ HPHC_Scheduler.exe: C
C: \ Program Files \ HP \ HP Software Update \ hpwuSchd2.exe
\ Program Files \ Hewlett-Packard \ HP Wireless Assistant \ HPWAMain.exe: C
C: \ Program Files \ Lexmark 3600-4600 Series \ lxdxmon.exe
\ Program Files \ Common Files \ Nokia \ MPlatform \ NokiaMServer.exe: C
C: \ Program Files \ Adobe \ Reader 8.0 \ Reader \ reader_sl.exe
C: \ Program Files \ Common Files \ Adobe \ ARM \ 1. 0 \ AdobeARM.exe
C: \ Program Files \ Common Files \ Java \ Java Update \ jusched.exe
C: \ Program Files \ iTunes \ iTunesHelper.exe
C: \ WINDOWS \ System32 \ igfxtray.exe
C: \ Program Files \ Lexmark 3600-4600 Series \ lxdxMsdMon.exe
C: \ WINDOWS \ System32 \ hkcmd.exe
C: \ WINDOWS \ System32 \ igfxpers.exe
C: \ Program Files \ Microsoft Client Security \ msseces.exe
C: \ Program Files \ Windows Sidebar \ sidebar.exe
\ Program Files \ Fichiers communs \ LightScribe \ LightScribeControlPanel: C. exe
C: \ Windows \ system32 \ igfxsrvc.exe
C: \ Program Files \ Norton 360 \ Engine \ 4.3.0.5 \ ccSvcHst.exe
C: \ Program Files \ Windows Sidebar \ sidebar.exe
C: \ Program Files \ Hewlett-Packard \ HP Wireless Assistant \ WiFiMsg.EXE
\ Program Files \ Hewlett-Packard \ Shared \ HpqToaster.exe: C
\ Program Files \ Synaptics \ SynTP \ SynTPHelper.exe: C
C: \ Windows \ system32 \ SearchFilterHost.exe
C: \ Users \ ANTHONY \ Desktop \ HijackThis. exe

R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL ciel =
R1 - Explorer HKCU \ Software \ Microsoft \ Internet \ Main page de recherche, = http://go.microsoft/fwlink/?LinkId=54896
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = skybroadband
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://ie.redirect.hp/svs/rdr?TYPE=3&tp ... io&pf=cnnb
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft/fwlink/?LinkId=54896
R1 - Explorer HKLM \ Software \ Microsoft \ Internet \ Main page de recherche, = R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://ie.redirect.hp/svs/rdr?TYPE=3&tp ... io&pf=cnnb
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search =
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search, Page =
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main Title fenêtre, Internet Explorer = Fourni par Sky Broadband
HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Settings, ProxyOverride = *. - R1 locales
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Toolbar, LinksFolderName =
O1 - Hosts::: 1 localhost
O2 - BHO: Adobe Link Helper PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C: \ Program Files \ Common Files \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C: \ Program Files \ Norton 360 \ Engine \ 4.3.0.5 \ coIEPlg. dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C: \ Program Files \ Norton 360 \ Engine \ 4.3.0.5 \ IPSBHO.DLL
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C: \ Program Files \ AOL \ AOL Toolbar 5.0 \ aoltb.dll
O2 - BHO: Java (tm) Plug-In 2 SSV Helper - {DBC80044-A445-435B-BC74-9C25C1C588A9} - C: \ Program Files \ Java \ jre6 \ bin \ jp2ssv.dll
O3 - Toolbar: barre d'outils AOL - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C: \ Program Files \ AOL Toolbar \ AOL 5. 0 \ aoltb.dll
O3 - Toolbar: barre d'outils Norton - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C: \ Program Files \ Norton 360 \ Engine \ 4.3.0.5 \ coIEPlg.dll
O4 - HKLM \ .. \ Run: [SynTPEnh] C: \ Program Files \ Synaptics \ SynTP \ Syntpenh.exe
O4 - HKLM \ .. \ Run: [QPService] "C: \ Program Files \ HP \ QuickPlay \ QPService.exe"
O4 - HKLM \ .. \ Run: [Windows Defender]% ProgramFiles% \ Windows Defender \ MSASCui.exe-hide
O4 - HKLM \ .. \ Run: QlbCtrl [. exe] C: \ Program Files \ Hewlett-Packard \ HP Quick Launch Buttons \ QlbCtrl.exe / Start
O4 - HKLM \ .. \ Run: [HP Health Check Scheduler] c: \ Program Files \ bilan de santé Hewlett-Packard \ HP \ HPHC_Scheduler.exe
O4 - HKLM \ .. \ Run: [HP Software Update] C: \ Program Files \ HP Software \ HP Update \ HPWuSchd2.exe
O4 - HKLM \ .. \ Run: [hpWirelessAssistant] C: \ Program Files \ Hewlett-Packard \ HP Wireless Assistant \ HPWAMain.exe
O4 - HKLM \ .. \ Run: [lxdxmon.exe] "C: \ Program Files \ Lexmark 3600-4600 Series \ lxdxmon. exe "
O4 - HKLM \ .. \ Run: [lxdxamon] "C: \ Program Files \ Lexmark 3600-4600 Series \ lxdxamon.exe"
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime
O4 - HKLM \ .. \ Run: ": \ Program Files \ CyberLink \ YouCam \ MUITransfer \ MUIStartMenu.exe C" "C: [UCam_Menu] \ Program Files \ CyberLink \ YouCam" UpdateWithCreateOnce "Software \ CyberLink \ YouCam \ 2.0"
O4 - HKLM \ .. \ Run: [NokiaMServer] C: \ Program Files \ Common Files \ Nokia \ MPlatform \ NokiaMServer / démarrage watchfiles
O4 - HKLM \ .. \ Run: [Adobe Reader Speed Launcher] "C: \ Program Files \ Adobe \ Reader 8.0 \ Reader \ reader_sl.exe"
O4 - HKLM \ .. \ Run: [Adobe ARM] "C: \ Program Files \ Common Files \ Adobe \ ARM \ 1.0 \ AdobeARM.exe"
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Common Files \ Java \ Java Update \ jusched.exe"
O4 - HKLM \ .. \ Run: [iTunesHelper] "C: \ Program Files \ iTunes \ iTunesHelper.exe"
O4 - HKLM \ .. \ Run: [IgfxTray] C: \ Windows \ system32 \ igfxtray.exe
O4 - HKLM \ .. \ Run: [HotKeysCmds] C: \ Windows \ system32 \ hkcmd.exe
O4 - HKLM \ .. \ Run: [persistance] C: \ Windows \ system32 \ igfxpers.exe
O4 - HKLM \ .. \ Run: [MSC] "c: \ Program Files \ Microsoft Client Security \ msseces.exe"-hide-runkey
O4 - HKLM \ .. \ Run: [Sidebar] C: \ Program Files \ Windows Sidebar \ sidebar.exe / AutoRun
O4 - HKLM \ .. \ Run: [LightScribe Panneau de configuration] C: \ Program Files \ Fichiers communs \ LightScribe \ LightScribeControlPanel.exe-cachés
O4 - HKUS \ S-1-5-19 \ .. \ Run: [Sidebar]% ProgramFiles% \ Windows Sidebar \ Sidebar.exe / detectMem (User Service local)
O4 - HKUS \ S-1-5-19 \ .. \ Run: [WindowsWelcomeCenter] oobefldr.dll rundll32.exe, ShowWelcomeCenter (User Service local)
O4 - HKUS \ S-1-5-20 \ .. \ Run: [Sidebar]% ProgramFiles% \ Windows Sidebar \ Sidebar.exe / detectMem (User SERVICE RÉSEAU)
O4 - HKUS \ S-1-5-18 \ .. \ Run: [Nokia.PCSync] C: \ Program Files \ Nokia \ Nokia PC Suite 6 \ PcSync2.exe / nodialog (utilisateur "SYSTEM")
O4 - HKUS \ DEFAULT \ .. \ Run: [Nokia.PCSync] C: \ Program Files \ Nokia \ Nokia PC Suite 6 \ PcSync2.exe / nodialog (utilisateur par défaut de l'utilisateur).
O8 - Extra context menu item: & Recherche AOL Toolbar - C: \ ProgramData \ AOL \ ieToolbar \ resources \ fr-FR \ local \ search.html
O8 - Extra context menu item: E & xporter vers Microsoft Excel - res://C : \ PROGRA ~ 1 \ MICROS ~ 3 \ Office12 \ EXCEL. EXE/3000
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - skybroadband (file missing)
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-8081-4f3c-5663EE0C6C49} - C: \ PROGRA ~ 1 \ MICROS ~ 3 \ Office12 \ ONBttnIE.dll
O9 - Extra "Outils" menuitem: S & fin à OneNote - {2670000A-7350-8081-4f3c-5663EE0C6C49} - C: \ PROGRA ~ 1 \ MICROS ~ 3 \ Office12 \ ONBttnIE.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C: \ PROGRA ~ 1 \ MICROS ~ 3 \ Office12 \ REFIEBAR. DLL
O16 - DPF: {1D4DB7D2-47A3-6EC9-BD87-1E41684E07BB} - http://ak.exe.imgfarm/images/nocache/fu ... .0.1.1.cab
O16 - DPF: {E2883E8F-472f-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Démon de cache de composants Catégories - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C: \ Windows \ system32 \ browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc - C: \ Program Files \ Fichiers communs \ Apple \ Mobile Device Support \ AppleMobileDeviceService.exe
O23 - Service: Service Bonjour - Apple Inc - C: \ Program Files \ Bonjour \ mDNSResponder.exe
O23 - Service: \ Program Files \ Hewlett-Packard \ HP Quick Launch Buttons \ Com4QLBEx.exe: Com4QLBEx - - Société de développement Hewlett-Packard, LP C
GameConsoleService - WildTangent, Inc - C:: Service - O23 \ Program Files \ HP Games \ My Game Console HP \ GameConsoleService.exe
O23 - Service: Service HP Health Check - Hewlett-Packard - c: \ Program Files \ Hewlett-Packard \ HP Health Check \ hphc_service. exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, LP - C: \ Program Files \ Hewlett-Packard \ Shared \ hpqwmiex.exe
O23 - Service: Gestionnaire de tableau InstallDriver (IDriverT) - Macrovision Corporation - C: \ Program Files \ Fichiers communs \ InstallShield \ Driver \ 32 1050 \ Intel \ IDriverT.exe
O23 - Service: iPod Service - Apple Inc - C: \ Program Files \ iPod \ bin \ iPodService. exe
O23 - Service: Disc Labeling Service LightScribeService Direct (LightScribeService) - Hewlett-Packard Company - C: \ Program Files \ Fichiers communs \ LightScribe \ LSSrvc.exe
O23 - Service: lxdxCATSCustConnectService - Lexmark International, Inc - C: \ Windows \ system32 \ spool \ drivers \ w32x86 \ 3 \ \ lxdxserv.exe
O23 - Service: lxdx_device - - C: \ Windows \ system32 \ lxdxcoms.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C: \ Program Files \ Norton 360 \ Engine \ 4.3.0.5 \ ccSvcHst. exe
O23 - Service: Service de récupération pour Windows - Unknown owner - C: \ Windows \ SMINST \ BLService.exe
O23 - Service: Cyberlink RichVideo Service (EVRC) (RichVideo) - Unknown owner - C: \ Program Files \ CyberLink \ Shared Files \ RichVideo.exe
O23 - Service: ServiceLayer - Nokia - C: \ Program Files \ PC Connectivity Solution \ ServiceLayer.exe
O23 - Service: XAudioService - Conexant Systems, Inc - C: \ Windows \ system32 \ drivers \ xaudio.exe

-
End of file - 9658 bytes
  • Anonymous
  • Bot
  • No Avatar
  • Inscription: 25 Feb 2008
  • Messages: ?
  • Loc: Ozzuland
  • Status: Online

Message Février 3rd, 2011, 1:10 pm

  • Don2007
  • Web Master
  • Web Master
  • No Avatar
  • Inscription: Nov 21, 2006
  • Messages: 4924
  • Loc: NY
  • Status: Offline

Message Février 3rd, 2011, 4:38 pm

Je ne vois pas un enregistreur de frappe. Cependant, je voudrais désinstaller toutes les barres d'outils.
How do you know when a politician is lying? His mouth is moving.

Afficher de l'information

  • Total des messages de ce sujet: 2 messages
  • Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 120 invités
  • Vous ne pouvez pas poster de nouveaux sujets
  • Vous ne pouvez pas répondre aux sujets
  • Vous ne pouvez pas éditer vos messages
  • Vous ne pouvez pas supprimer vos messages
  • Vous ne pouvez pas joindre des fichiers
 
 

© 2011 Unmelted, LLC. Ozzu® est une marque déposée de Unmelted, LLC