Croire que j'étais / h keylogged

  • Friendlyspy
  • Born
  • Born
  • No Avatar
  • Inscription: Sep 17, 2009
  • Messages: 1
  • Status: Offline

Message Septembre 17th, 2009, 12:30 am

Je joue un jeu en ligne et ne rien avoir récemment téléchargé. Mais, j'ai dû changer mon mot de passe pour le jeu à se connecter et peu après tout a changé. Dans l'ordre il ressemble à la personne devait se retrouver dans mon e-mail ainsi.

J'ai entendu parler de Hyjackthis et avoir le journal. Si quelqu'un ayant plus d'expérience pouvait repérer quelque chose qui va mal, je serais très reconnaissant.

Running processes:
C: \ Windows \ system32 \ Dwm.exe
C: \ Windows \ Explorer.exe
C: \ Windows \ system32 \ taskeng. exe
C: \ Program Files \ DellTPad \ Apoint.exe
C: \ Windows \ OEM02Mon.exe
C: \ Program Files \ Fichiers communs \ InstallShield \ qttask.exe
C: \ Program Files \ Dell \ MediaDirect \ PCMService.exe
C: \ Program Files \ Dell Photo AIO Printer 926 \ dlcxmon.exe
C: \ Program Files \ Dell Photo AIO Printer 926 \ memcard.exe
C: \ Program Files \ DellTPad \ ApMsgFwd.exe
C: \ Program Files \ DellTPad \ HidFind.exe
C: \ Program Files \ Windows Media Player \ TeaTimer.exe
C: \ Windows \ System32 \ Rundll32. exe
C: \ Windows \ System32 \ rundll32.exe
C: \ Program Files \ Sigmatel \ C-Major Audio \ WDM \ sttray.exe
C: \ Windows \ System32 \ rundll32.exe
C: \ Program Files \ Digital Line Detect \ DLG.exe
C: \ Program Files \ Google \ GoogleToolbarNotifier \ GoogleToolbarNotifier.exe
C: \ Program Files \ Internet Explorer \ Ieuser.exe
C: \ Program Files \ Internet Explorer \ iexplore.exe
C: \ Program Files \ Fichiers communs \ InstallShield \ UpdateService \ isuspm.exe
C: \ Program Files \ Fichiers communs \ InstallShield \ UpdateService \ agent. exe
C: \ PROGRA ~ 1 \ McAfee \ MSC \ mcshell.exe
C: \ PROGRA ~ 1 \ McAfee \ viruss ~ 1 \ mcvsshld.exe
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Windows \ system32 \ searchfilterhost.exe
C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe

- O1 Hosts::: 1 localhost
O2 - BHO: Yahoo! Toolbar Helper - (02478D38-C3F9-4EFB-9B51-7695ECA05670) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ cpn \ YT. dll
O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Fichiers communs \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - (27B4851A-3207-45A2-B947-BE8AFE6163AB) - C: \ PROGRA ~ 1 \ \ McAfee MSK \ mskapbho.dll
O2 - BHO: Yahoo! Toolbar - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - C: \ Program Files \ Google \ Common \ yinsthelper.dll
O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1. 6.0 \ bin \ ssv.dll
O2 - BHO: scriptproxy - (7DB2D5A0-7241-4E79-B68D-6309F01C5231) - C: \ PROGRA ~ 1 \ McAfee \ viruss ~ 1 \ scriptsn.dll
O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - C: \ Program Files \ Google \ Google Toolbar \ GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Helper - (AF69DE43-7D58-4638-B6FA-CE66B5AD205D) - C: \ Program Files \ Google \ GoogleToolbarNotifier \ 5.2.4204.1700 \ swg. dll
O2 - BHO: Google Dictionnaire sdch Compression - (C84D72FE-E17D-4195-BB24-76C02E2E7C4E) - C: \ Program Files \ Google \ Google Toolbar \ Component \ fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Browser Address Error Redirector - (CA6319C0-31B7-401E-A518-A07C3DB8F777) - C: \ Program Files \ BAE \ BAE.dll
- O3 Toolbar: Yahoo! ¤ u ¨ ã | C - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ cpn \ YT. dll
- O3 Toolbar: barre d'outils Google - (2318C2B1-4965-11d4-9B18-009027A5CD4F) - C: \ Program Files \ Google \ Google Toolbar \ GoogleToolbar_32.dll
O4 - HKLM \ .. \ Run: [Windows Defender]% ProgramFiles% \ Windows Defender \ ashDisp.exe
O4 - HKLM \ .. \ Run: [Apoint] C: \ Program Files \ DellTPad \ Apoint.exe
O4 - HKLM \ .. \ Run: [OEM02Mon.exe] C: \ Windows \ OEM02Mon.exe
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ Fichiers communs \ InstallShield \ qttask.exe"-start
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ Dell \ MediaDirect \ PCMService.exe"
O4 - HKLM \ .. \ Run: [Google Desktop Search] "C: \ Program Files \ Google \ Google Desktop Search \ GoogleDesktop.exe" / startup
O4 - HKLM \ .. \ Run: [QuickTime Task] C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ INSTAL ~ 1 \ ALWILS ~ 1 \ ISUSPM.exe-startup
O4 - HKLM \ .. \ Run: [FaxCenterServer] "C: \ Program Files \ Dell PC Fax \ fm3032.exe" / s
O4 - HKLM \ .. \ Run: [dlcxmon.exe] "C: \ Program Files \ Dell Photo AIO Printer 926 \ dlcxmon. exe "
O4 - HKLM \ .. \ Run: [MemoryCardManager] "C: \ Program Files \ Dell Photo AIO Printer 926 \ memcard.exe"
O4 - HKLM \ .. \ Run: [DLCXCATS] rundll32 C: \ Windows \ system32 \ spool \ drivers \ W32X86 \ 3 \ DLCXtime.dll, _RunDLLEntry @ 16
O4 - HKLM \ .. \ Run: [Adobe Reader Speed Launcher] "C: \ Program Files \ Adobe \ Acrobat 8.0 \ Acrobat \"
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ iTunes \ iTunesHelper.exe"
O4 - HKLM \ .. \ Run: [LogitechQuickCamRibbon] "C: \ Program Files \ Agent \ McUpdate.exe" / runkey
O4 - HKLM \ .. \ Run: [NvMediaCenter] RUNDLL32.EXE C: \ Windows \ system32 \ nvsvc.dll, nvsvcStart
O4 - HKLM \ .. \ Run: [avast!] Rundll32.exe C: \ Windows \ system32 \ NeroCheck.exe
O4 - HKLM \ .. \ Run: [NvMediaCenter] RUNDLL32.EXE C: \ Windows \ system32 \ igfxpers.exe
O4 - HKLM \ .. \ Run: [NVHotkey] Rundll32. exe C: \ Windows \ system32 \ nvHotkey.dll, Start
O4 - HKLM \ .. \ Run: [MSMSGS] "C: \ Program Files \ SigmaTel \ C-Major Audio \ WDM \ sttray.exe
O4 - HKCU \ .. \ Run: [Aim6] "C: \ Program Files \ AIM6 \ aim6.exe" / d locale = fr-FR ee://aol/imApp
O4 - HKCU \ .. \ Run: [Skype] "C: \ Program Files \ Google \ GoogleToolbarNotifier \ GoogleToolbarNotifier.exe"
O4 - HKCU \ .. \ Run: [Yahoo! Pager] "C: \ Program Files \ Google \ Messenger \ ypager.exe"-quiet
O4 - HKCU \ .. \ Run: [MsnMsgr] "C: \ Program Files \ Fichiers communs \ Adobe \ Updater5 \ AdobeUpdater.exe
O4 - HKCU \ .. \ Run: [Sidebar] C: \ Program Files \ Windows Media Player \ TeaTimer.exe
O4 - HKLM \ S-1-5-19 \ .. \ Run: [Sidebar]% ProgramFiles% \ Windows Sidebar \ CTFMON.EXE (User SERVICE LOCAL)
O4 - HKLM \ S-1-5-19 \ .. \ Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll, ShowWelcomeCenter (User SERVICE LOCAL)
O4 - HKLM \ S-1-5-20 \ .. \ Run: [Sidebar]% ProgramFiles% \ Windows Sidebar \ Sidebar. exe / detectMem (User SERVICE RÉSEAU)
O4 - Global Startup: BTTray.lnk =?
O4 - Global Startup: Digital Line Detect.lnk = C: \ Program Files \ Digital Line Detect \ DLG.exe
O4 - Global Startup: QuickSet.lnk =?
O8 - Extra context menu item: E & xporter vers Microsoft Excel -- res://C : \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer au périphérique & Bluetooth...- C: \ Program Files \ Alwil Software \ btsendto_ie_ctx. htm
O8 - Extra context menu item: Envoyer cette page à & Bluetooth Device...- C: \ Program Files \ Alwil Software \ btsendto_ie.htm
O9 - Extra button: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0 \ bin \ npjpi160.dll
O9 - Extra "Outils" menuitem: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0 \ bin \ npjpi160. dll
O9 - Extra button: Envoyer à OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ ONBttnIE.dll
O9 - Extra "Outils" menuitem: S & end to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ ONBttnIE.dll
O9 - Extra button: Yahoo! Services - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - C: \ Program Files \ Google \ Common Files \ yiesrvc. dll
O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ REFIEBAR.DLL
O9 - Extra button: @ btrez.dll, -4015 - (CCA281CA-C863-46ef-9331-5C8D4460577F) - C: \ Program Files \ Alwil Software \ btsendto_ie.htm
O9 - Extra "Outils" menuitem: @ btrez.dll, -12650 - (CCA281CA-C863-46ef-9331-5C8D4460577F) - C: \ Program Files \ Alwil Software \ btsendto_ie. htm
O9 - Extra button: Run IMVU - (d9288080-1BAA-4bc4-9cf8-a92d743db949) - C: \ Users \ Max \ AppData \ Roaming \ Microsoft \ Windows \ Start Menu \ Programs \ IMVU \ Run IMVU.lnk (file missing)
O13 - Gopher Prefix:
O16 - DPF: (67DABFBF-D0AB-41FA-9C46-CC0F21721616) (DivXBrowserPlugin Object)
O20 - AppInit_DLLs: C: \ PROGRA ~ 1 \ Google \ GOOGLE ~ 2 \ GOEC62 ~ 1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc - C: \ Program Files \ Fichiers communs \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService. exe
O23 - Service: dlcx_device - - C: \ Windows \ system32 \ dlcxcoms.exe
O23 - Service: DSBrokerService - ALWIL Software - C: \ Program Files \ Messenger \ brkrsvc.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C: \ Program Files \ Google \ Google Desktop Search \ GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1ca06c8ec1950d5) (gupdate1ca06c8ec1950d5) - Google - C: \ Program Files \ Google \ Update \ GoogleUpdate. exe
O23 - Service: Google Software Updater (gusvc) - Google - C: \ Program Files \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Program Files \ Fichiers communs \ InstallShield \ Driver \ 1150 \ Intel 32 \ IDriverT.exe
O23 - Service: iPod Service - Apple Inc - C: \ Program Files \ iPod \ bin \ iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc - C: \ PROGRA ~ 1 \ McAfee \ MSC \ mcmscsvc. exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc - C: \ Program Files \ Fichiers communs \ McAfee \ mna \ mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc - C: \ PROGRA ~ 1 \ McAfee \ viruss ~ 1 \ mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc - C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ \ McAfee mcproxy \ mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc - C: \ PROGRA ~ 1 \ McAfee \ viruss ~ 1 \ McShield. exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc - C: \ PROGRA ~ 1 \ McAfee \ viruss ~ 1 \ mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc - C: \ Program Files \ McAfee \ MPF \ MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc - C: \ Program Files \ McAfee \ MSK \ MskSrver.exe
O23 - Service: MySQL_Trakscape - ALWIL Software - C: \ mysql-Trakscape \ mysql-5.0.0-alpha \ bin \ mysqld. exe
O23 - Service: PnkBstrA - ALWIL Software - C: \ Windows \ system32 \ PnkBstrA.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C: \ Program Files \ Fichiers communs \ Roxio Shared \ 9.0 \ SharedCOM \ RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C: \ Program Files \ Fichiers communs \ Roxio Shared \ 9.0 \ SharedCOM \ RoxWatch9.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc - C: \ Windows \ system32 \ STacSV. exe
O23 - Service: Steam Client Service - Valve Corporation - C: \ Program Files \ Common Files \ Steam \ SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc - C: \ Program Files \ Fichiers communs \ SureThing Shared \ stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc - C: \ Windows \ system32 \ drivers \ xaudio.exe
  • Anonymous
  • Bot
  • No Avatar
  • Inscription: 25 Feb 2008
  • Messages: ?
  • Loc: Ozzuland
  • Status: Online

Message Septembre 17th, 2009, 12:30 am

  • Don2007
  • Web Master
  • Web Master
  • No Avatar
  • Inscription: Nov 21, 2006
  • Messages: 4924
  • Loc: NY
  • Status: Offline

Message Septembre 17th, 2009, 6:44 am

Je ne vois pas un keylogger. Télécharger, mettre à jour et courez la lutte contre les logiciels malveillants de malwarebytes.org juste pour être sûr.
How do you know when a politician is lying? His mouth is moving.
  • frih
  • Novice
  • Novice
  • Avatar de l’utilisateur
  • Inscription: Nov 07, 2008
  • Messages: 19
  • Status: Offline

Message Septembre 19th, 2009, 6:20 am

ouais, malwarebytes est un bon outil, vous pouvez joindre leur forum et présenter votre rapport d'analyse pour eux.

Afficher de l'information

  • Total des messages de ce sujet: 3 messages
  • Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 112 invités
  • Vous ne pouvez pas poster de nouveaux sujets
  • Vous ne pouvez pas répondre aux sujets
  • Vous ne pouvez pas éditer vos messages
  • Vous ne pouvez pas supprimer vos messages
  • Vous ne pouvez pas joindre des fichiers
 
 

© 2011 Unmelted, LLC. Ozzu® est une marque déposée de Unmelted, LLC