HijackThis log-keyloggers possible

  • srdjanSurvive
  • Born
  • Born
  • No Avatar
  • Inscription: Nov 23, 2009
  • Messages: 1
  • Status: Offline

Message Novembre 23rd, 2009, 5:10 pm

ce week-end passé mon compte World of Warcraft a été piraté, et im not sure how. On m'a dit que c'était probablement les enregistreurs de frappe et je veux m'assurer que je n'ai pas du tout.

Running processes:
C: \ Windows \ system32 \ taskeng.exe
C: \ Windows \ system32 \ Dwm.exe
C: \ Windows \ Explorer.exe
C: \ Windows \ RtHDVCpl.exe
C: \ Program Files \ PowerDVD DX \ PDVDDXSrv.exe
C: \ Program Files \ Google \ Google Desktop Search \ GoogleDesktop.exe
C: \ Program Files \ Dell Support Center \ bin \ sprtcmd. exe
C: \ Program Files \ Fichiers communs \ Microsoft Shared \ ccApp.exe
C: \ Program Files \ iTunes \ iTunesHelper.exe
C: \ Program Files \ Zune \ ZuneLauncher.exe
C: \ Program Files \ Java \ jre6 \ bin \ ashDisp.exe
C: \ Program Files \ DAEMON Tools Lite \ daemon.exe
C: \ Program Files \ AIM6 \ aim6.exe
C: \ Program Files \ Windows Defender \ MSASCui.exe
C: \ Program Files \ Windows Media Player \ TeaTimer.exe
C: \ Program Files \ Google \ Google Desktop Search \ GoogleDesktop.exe
C: \ Program Files \ AIM6 \ aolsoftware. exe
C: \ Windows \ system32 \ wuauclt.exe
C: \ Windows \ System32 \ mobsync.exe
C: \ Program Files \ Fichiers communs \ Adobe \ Updater5 \ AdobeUpdater.exe
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe

R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://go.microsoft . com / fwlink /? LinkId = 54896
- R1 HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Local = http://go.microsoft . com / fwlink /? LinkId = 69157
- R1 HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://go.microsoft . com / fwlink /? LinkId = 54896
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://go.microsoft . com / fwlink /? LinkId = 54896
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://go.microsoft . com / fwlink /? LinkId = 69157
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search, SearchAssistant =
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search, CustomizeSearch =
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Window Title = Internet Explorer fourni par Dell
R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Settings, ProxyOverride = *. locales
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Toolbar, LinksFolderName =
- O1 Hosts::: 1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Fichiers communs \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll
O2 - BHO: (no name) - (1E8A6170-7264-4D0F-BEAE-D42A53123C75) - C: \ Program Files \ Fichiers communs \ Microsoft Shared \ coShared \ Browser \ 1.5 \ NppBho. dll
O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - C: \ Program Files \ Google \ Google Toolbar \ GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Helper - (AF69DE43-7D58-4638-B6FA-CE66B5AD205D) - C: \ Program Files \ Google \ GoogleToolbarNotifier \ 5.4.4525.1752 \ swg.dll
O2 - BHO: Google Dictionnaire sdch Compression - (C84D72FE-E17D-4195-BB24-76C02E2E7C4E) - C: \ Program Files \ Google \ Google Toolbar \ Component \ fastsearch_B7C5AC242193BB3E. dll
O2 - BHO: Browser Address Error Redirector - (CA6319C0-31B7-401E-A518-A07C3DB8F777) - C: \ Program Files \ BAE \ BAE.dll
O2 - BHO: Java (tm) Plug-In 2 SSV Helper - (DBC80044-A445-435B-BC74-9C25C1C588A9) - C: \ Program Files \ Java \ jre6 \ bin \ jp2ssv.dll
- O3 Toolbar: Show Norton Toolbar - (90222687-F593-4738-B738-FBEE9C7B26DF) - C: \ Program Files \ Fichiers communs \ Microsoft Shared \ coShared \ Browser \ 1.5 \ UIBHO. dll
- O3 Toolbar: barre d'outils Google - (2318C2B1-4965-11d4-9B18-009027A5CD4F) - C: \ Program Files \ Google \ Google Toolbar \ GoogleToolbar_32.dll
O4 - HKLM \ .. \ Run: [Windows Defender]% ProgramFiles% \ Windows Defender \ ashDisp.exe
O4 - HKLM \ .. \ Run: [eCenter] C: \ Dell \ E-Center \ EULALauncher.exe
O4 - HKLM \ .. \ Run: [Windows Defender] RtHDVCpl.exe
O4 - HKLM \ .. \ Run: [StartCCC] "C: \ Program Files \ ATI Technologies \ QuickTime \ Core-Static \ CLIStart.exe" MSRun
O4 - HKLM \ .. \ Run: [PDVDDXSrv] "C: \ Program Files \ PowerDVD DX \ PDVDDXSrv.exe"
O4 - HKLM \ .. \ Run: [Google Desktop Search] "C: \ Program Files \ Google \ Google Desktop Search \ GoogleDesktop.exe" / startup
O4 - HKLM \ .. \ Run: [dscactivate] "C: \ Program Files \ Dell Support Center \ gs_agent \ custom \ dsca.exe"
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ Dell Support Center \ bin \ sprtcmd.exe" / P iTunesHelper
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ Fichiers communs \ Microsoft Shared \ ccApp.exe"
O4 - HKLM \ .. \ Run: [Symantec PIF AlertEng] "C: \ Program Files \ Fichiers communs \ Microsoft Shared \ PIF \ (B8E1DD85-8582-4c61-B58F-2F227FCA9A08) \ PIFSvc.exe" / a / m " C: \ Program Files \ Fichiers communs \ Microsoft Shared \ PIF \ (B8E1DD85-8582-4c61-B58F-2F227FCA9A08) \ AlertEng.dll "
O4 - HKLM \ .. \ Run: [Adobe Reader Speed Launcher] "C: \ Program Files \ Adobe \ Acrobat 8.0 \ Acrobat \"
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ iTunes \ iTunesHelper.exe"
O4 - HKLM \ .. \ Run: [Zune Launcher] "C: \ Program Files \ Zune \ ZuneLauncher.exe"
O4 - HKLM \ .. \ Run: [avast!] "C: \ Program Files \ Java \ jre6 \ bin \ ashDisp.exe
O4 - HKCU \ .. \ Run: [DAEMON Tools Lite] "C: \ Program Files \ DAEMON Tools Lite \ daemon.exe"-autorun
O4 - HKCU \ .. \ Run: [QuickTime Task] "C: \ Program Files \ Dell Support Center \ bin \ sprtcmd.exe" / P iTunesHelper
O4 - HKCU \ .. \ Run: [GreedyTorrent] "C: \ Program Files \ GreedyTorrent \ GTor.exe" bac
O4 - HKCU \ .. \ Run: [Steam] "C: \ Program Files \ Steam \ Steam.exe"-silent
O4 - HKCU \ .. \ Run: [Aim6] "C: \ Program Files \ AIM6 \ aim6.exe" / d locale = fr-FR ee://aol/imApp
O4 - HKCU \ .. \ Run: [Skype] "C: \ Program Files \ Google \ GoogleToolbarNotifier \ GoogleToolbarNotifier. exe "
O4 - HKCU \ .. \ Run: [Comrade.exe] C: \ Program Files \ GameSpy \ Comrade \ Comrade.exe
O4 - HKCU \ .. \ Run: [Tunebite] C: \ Program Files \ RapidSolution \ Tunebite \ Tunebite.exe bac
O4 - HKCU \ .. \ Run: [EA Core] "C: \ Program Files \ Electronic Arts \ EADM \ Core.exe"-silent
O4 - HKCU \ .. \ Run: [Sidebar] C: \ Program Files \ Windows Media Player \ TeaTimer.exe
O4 - HKLM \ S-1-5-19 \ .. \ Run: [Sidebar]% ProgramFiles% \ Windows Sidebar \ CTFMON.EXE (User SERVICE LOCAL)
O4 - HKLM \ S-1-5-19 \. . \ Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll, ShowWelcomeCenter (User SERVICE LOCAL)
O4 - HKLM \ S-1-5-20 \ .. \ Run: [Sidebar]% ProgramFiles% \ Windows Sidebar \ CTFMON.EXE (User SERVICE RÉSEAU)
O8 - Extra context menu item: Add to Google Photos Screensa & ver -- res://C : \ Windows \ system32 \ GPhotos.scr/200
O8 - Extra context menu item: E & xporter vers Microsoft Excel -- res://C : \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ EXCEL. EXE/3000
O9 - Extra button: Envoyer à OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ MICROS ~ 3 \ Office12 \ ONBttnIE.dll
O9 - Extra "Outils" menuitem: S & end to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ MICROS ~ 3 \ Office12 \ ONBttnIE.dll
O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MICROS ~ 3 \ Office12 \ REFIEBAR.DLL
O13 - Gopher Prefix:
O20 - AppInit_DLLs: C: \ PROGRA ~ 1 \ Google \ GOOGLE ~ 2 \ GOEC62 ~ 1. DLL
O20 - Winlogon Notify: GoToAssist - C: \ Program Files \ Citrix \ GoToAssist \ 514 \ G2AWinLogon.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C: \ Windows \ system32 \ AERTSrv.exe
O23 - Service: Apple Mobile Device - Apple Inc - C: \ Program Files \ Fichiers communs \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc - C: \ Windows \ system32 \ Ati2evxx. exe
O23 - Service: Bonjour Service - Apple Inc - C: \ Program Files \ Bonjour \ mDNSResponder.exe
O23 - Service: ccEvtMgr - Symantec Corporation - C: \ Program Files \ Fichiers communs \ Microsoft Shared \ ccSvcHst.exe
O23 - Service: ccSetMgr - Symantec Corporation - C: \ Program Files \ Fichiers communs \ Microsoft Shared \ ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C: \ Program Files \ Fichiers communs \ Microsoft Shared \ ccSvcHst. exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C: \ Program Files \ Fichiers communs \ Microsoft Shared \ VAScanner \ comHost.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C: \ Program Files \ Google \ Google Desktop Search \ GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, une division de Citrix Systems, Inc - C: \ Program Files \ Citrix \ GoToAssist \ 514 \ g2aservice. exe
O23 - Service: Google Software Updater (gusvc) - Google - C: \ Program Files \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Program Files \ Fichiers communs \ InstallShield \ Driver \ 11 \ Intel 32 \ IDriverT.exe
O23 - Service: iPod Service - Apple Inc - C: \ Program Files \ iPod \ bin \ iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C: \ Program Files \ Symantec \ LiveUpdate \ LuComServer_3_4. EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C: \ Program Files \ Fichiers communs \ Microsoft Shared \ ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C: \ Program Files \ Fichiers communs \ Microsoft Shared \ PIF \ (B8E1DD85-8582-4c61-B58F-2F227FCA9A08) \ PIFSvc.exe
O23 - Service: PnkBstrA - ALWIL Software - C: \ Windows \ system32 \ PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocole V. 0 (expérimental) (rpcapd) - CACE Technologies - C: \ Program Files \ WinPcap \ rpcapd.exe
O23 - Service: SupportSoft Sprocket Service (atboottime) (sprtsvc_dellsupportcenter) - SupportSoft, Inc - C: \ Program Files \ Dell Support Center \ bin \ sprtsvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C: \ Program Files \ Common Files \ Steam \ SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc - C: \ Program Files \ Fichiers communs \ SureThing Shared \ stllssvr. exe
O23 - Service: Symantec Core LC - Unknown owner - C: \ Program Files \ Fichiers communs \ Microsoft Shared \ CCPD-LC \ symlcsvc.exe
  • Anonymous
  • Bot
  • No Avatar
  • Inscription: 25 Feb 2008
  • Messages: ?
  • Loc: Ozzuland
  • Status: Online

Message Novembre 23rd, 2009, 5:10 pm

  • Don2007
  • Web Master
  • Web Master
  • No Avatar
  • Inscription: Nov 21, 2006
  • Messages: 4924
  • Loc: NY
  • Status: Offline

Message Novembre 24th, 2009, 9:16 am

Le journal de l'air propre. Télécharger, mettre à jour et courez la lutte contre les logiciels malveillants de malwarebytes.org
How do you know when a politician is lying? His mouth is moving.

Afficher de l'information

  • Total des messages de ce sujet: 2 messages
  • Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 138 invités
  • Vous ne pouvez pas poster de nouveaux sujets
  • Vous ne pouvez pas répondre aux sujets
  • Vous ne pouvez pas éditer vos messages
  • Vous ne pouvez pas supprimer vos messages
  • Vous ne pouvez pas joindre des fichiers
 
 

© 2011 Unmelted, LLC. Ozzu® est une marque déposée de Unmelted, LLC