Suspect keylogger sur l'ordinateur

  • Slip
  • Born
  • Born
  • No Avatar
  • Inscription: Oct 24, 2008
  • Messages: 2
  • Status: Offline

Message Octobre 24th, 2008, 7:58 pm

Bonjour, J'ai lu récemment un thread ici sur quelques gars qui avaient le même problème que moi (il a pensé qu'il avait un keylogger sur son ordinateur). Ive got a HJT log ici, si quelqu'un pouvait lire au travers. Merci :) .

Edit:

Ive terme et AdAware S & D sur le mode sans échec maintenant, et fait ce qu'il a demandé. Également utilisé le scan en ligne Trend Micro chose. Espérons que le rend plus facile.

Logfile de Trend Micro HijackThis v2.0. 2
Scan sauvé à 6:11:50 PM, le 10.25.2008
Plate-forme: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C: \ WINDOWS \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Program Files \ Lavasoft \ Ad-Aware \ aawservice.exe
C: \ WINDOWS \ Explorer. EXE
C: \ WINDOWS \ system32 \ spoolsv.exe
C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
C: \ Program Files \ Bonjour \ mDNSResponder.exe
C: \ Program Files \ Internet Security Suite Optus \ Anti-Virus \ fsgk32st.exe
C: \ Program Files \ Internet Security Suite Optus \ Common \ FSMA32.EXE
C: \ Program Files \ Internet Security Suite Optus \ Anti-Virus \ FSGK32.EXE
C: \ Program Files \ Internet Security Suite Optus \ Common \ FSMB32.EXE
C: \ WINDOWS \ system32 \ nvsvc32. exe
C: \ Program Files \ Internet Security Suite Optus \ Common \ FCH32.EXE
C: \ Program Files \ Internet Security Suite Optus \ Anti-Virus \ fssm32.exe
C: \ Program Files \ Internet Security Suite Optus \ Anti-Virus \ fsqh.exe
C: \ Program Files \ Internet Security Suite Optus \ Common \ FAMEH32.EXE
C: \ Program Files \ Internet Security Suite Optus \ FSAUA \ program \ fsaua.exe
C: \ Program Files \ Internet Security Suite Optus \ FWES \ Program \ fsdfwd.exe
C: \ WINDOWS \ sonorisateur. EXE
C: \ Program Files \ Internet Security Suite Optus \ Common \ FSM32.EXE
C: \ Program Files \ Internet Security Suite Optus \ FSGUI \ fsguidll.exe
C: \ Program Files \ iTunes \ iTunesHelper.exe
C: \ WINDOWS \ system32 \ RUNDLL32.EXE
C: \ Program Files \ Windows Live \ Messenger \ msnmsgr.exe
C: \ WINDOWS \ system32 \ ctfmon.exe
C: \ Program Files \ Curse \ CurseClient.exe
C: \ Program Files \ Internet Security Suite Optus \ FSAUA \ program \ fsus.exe
C: \ WINDOWS \ System32 \ svchost. exe
C: \ Program Files \ Internet Security Suite Optus \ Anti-Virus \ fsav32.exe
C: \ Program Files \ iPod \ bin \ iPodService.exe
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe

R1 - HKCU \ Software \ Microsoft \ Internet Connection Wizard, ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Settings, ProxyOverride = *. local
O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Fichiers communs \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - (3CA2F312-6F6E-4B53-A66E-4E65E497C8C0) - C: \ Program Files \ AVG \ AVG8 \ avgssie.dll (file missing)
O2 - BHO: Spybot-S & D IE Protection - (53707962-6F74-2D53-2644-206D7942484F) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper. etc
O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_01 \ bin \ ssv.dll
O2 - BHO: (no name) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (no file)
O2 - BHO: Windows Live Sign-in Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Program Files \ Fichiers communs \ Microsoft Shared \ Windows Live \ WindowsLiveLogin. dll
O3 - Toolbar: Veoh Browser Plug-in - (D0943516-5076-4020-A3B5-AEFAF26AB263) - C: \ Program Files \ Veoh Networks \ Veoh \ Plugins \ reg \ VeohToolbar.dll (file missing)
O4 - HKLM \ .. \ Run: [NvCplDaemon] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvCpl.dll, NvStartup
O4 - HKLM \ .. \ Run: [sonorisateur] SOUNDMAN.EXE
O4 - HKLM \ .. \ Run: [nwiz] nwiz.exe / install
O4 - HKLM \ .. \ Run: [F-Secure TNB] "C: \ Program Files \ Internet Security Suite Optus \ FSGUI \ TNBUtil.exe" / CHECKALL / WAITFORSW
O4 - HKLM \ .. \ Run: [F-Secure Manager] "C: \ Program Files \ Internet Security Suite Optus \ Common \ FSM32.EXE" / splash
O4 - HKLM \ .. \ Run: [Adobe Reader Speed Launcher] "C: \ Program Files \ Adobe \ Reader 8.0 \ Reader \ Reader_sl.exe"
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ QTTask.exe"-atboottime
O4 - HKLM \ .. \ Run: [AppleSyncNotifier] C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleSyncNotifier.exe
O4 - HKLM \ .. \ Run: [iTunesHelper] "C: \ Program Files \ iTunes \ iTunesHelper.exe"
O4 - HKLM \ .. \ Run: [NvMediaCenter] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvMcTray.dll, NvTaskbarInit
O4 - HKCU \ .. \ Run: [MsnMsgr] "C: \ Program Files \ Windows Live \ Messenger \ msnmsgr.exe" / background
O4 - HKCU \ .. \ Run: [ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe
O4 - HKCU \ .. \ Run: [CurseClient] C: \ Program Files \ Curse \ CurseClient.exe-silent
O4 - HKCU \ .. \ Run: [SpybotSD TeaTimer] C: \ Program Files \ Spybot - Search & Destroy \ TeaTimer.exe
O8 - Extra du menu contextuel: E & xporter vers Microsoft Excel -- res://C : \ PROGRA ~ 1 \ MICROS ~ 2 \ OFFICE11 \ EXCEL.EXE/3000
O9 - Extra button: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_01 \ bin \ ssv.dll
O9 - Extra "Outils" menuitem: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_01 \ bin \ ssv. dll
O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ OFFICE11 \ REFIEBAR.DLL
O9 - Extra button: Run IMVU - (d9288080-1BAA-4bc4-9cf8-a92d743db949) - C: \ Documents and Settings \ user \ Start Menu \ Programs \ IMVU \ Run IMVU.lnk
O9 - Extra button: (no name) - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper. dll
O9 - Extra "Outils" menuitem: Spybot - Search & Destroy Configuration - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper.dll
O9 - Extra button: (no name) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe
O9 - Extra "Outils" menuitem: @ xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag. exe
O9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O9 - Extra "Outils" menuitem: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O12 - Plugin for. Spop: C: \ Program Files \ Internet Explorer \ Plugins \ NPDocBox. dll
O16 - DPF: (17492023-C23A-453E-A040-C7C580BBF700) (Windows Genuine Advantage Validation Tool) -- http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: (20A60F0D-9AFA-4515-A0FD-83BD84642501) (Checkers Class) -- http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: (2931566C-B8A6-46C5-BF4D-E6AB9251E953) (Nexon Package Manager Control) -- http://s.nx.com/activex/public_new/nxpm.cab
O16 - DPF: (39B0684F-D7BF-4743-B050-FDC3F48F7E3B) -- http://www.fileplanet.com/fpdlmgr/cabs/ ... .6.108.cab
O16 - DPF: (5C051655-FCD5-4969-9182-770EA5AA5565) (Solitaire Showdown Class) -- http://messenger.zone.msn.com/binary/So ... b56986.cab
O16 - DPF: (5D6F45B3-9043 -443D-A792-115447494D24) (UnoCtrl Class) -- http://messenger.zone.msn.com/EN-AU/a-U ... E_UNO1.cab
O16 - DPF: (70BA88C8-DAE8-4CE9-92BB-979C4A75F53B) -- http://launch.gamespyarcade.com/softwar ... launch.cab
O16 - DPF: (8E0D4DE5-3180-4024-A327-4DFAD1796A8D) (MessengerStatsClient Class) -- http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: (C3F79A2B-B9B4-4A66-B012-3EE46475B072) (MessengerStatsClient Class) -- http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: (F5A7706B-B9C0-4C89-A715-7A0C6B05DD48) (Minesweeper Flags Class) -- http://messenger.zone.msn.com/binary/Mi ... b56986.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C: \ Program Files \ Lavasoft \ Ad-Aware \ aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc - C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc - C: \ Program Files \ Bonjour \ mDNSResponder.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C: \ Program Files \ Internet Security Suite Optus \ Anti-Virus \ fsgk32st. exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd - C: \ Program Files \ Fichiers communs \ Macrovision Shared \ FLEXnet Publisher \ FNPLicensingService.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C: \ Program Files \ Internet Security Suite Optus \ FSAUA \ program \ fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C: \ Program Files \ Internet Security Suite Optus \ FWES \ Program \ fsdfwd. exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C: \ Program Files \ Internet Security Suite Optus \ Common \ FSMA32.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Program Files \ Fichiers communs \ InstallShield \ Driver \ 1050 \ Intel 32 \ IDriverT.exe
O23 - Service: iPod Service - Apple Inc - C: \ Program Files \ iPod \ bin \ iPodService. exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C: \ WINDOWS \ system32 \ nvsvc32.exe
O23 - Service: wampapache - Unknown owner - C: \ Documents and Settings \ - Dean - \ Desktop \ Private Server files \ Wampserver \ wamp \ bin \ apache \ apache2.2.8 \ bin \ httpd.exe (file missing)
O23 - Service: wampmysqld - Unknown owner - C: \ Documents and Settings \ - Dean - \ Desktop \ Private Server files \ Wampserver \ wamp \ bin \ mysql \ mysql5.0.51a \ bin \ mysqld-nt. exe (file missing)

--
Fin de la file - 9080 bytes
  • Anonymous
  • Bot
  • No Avatar
  • Inscription: 25 Feb 2008
  • Messages: ?
  • Loc: Ozzuland
  • Status: Online

Message Octobre 24th, 2008, 7:58 pm

  • Don2007
  • Web Master
  • Web Master
  • No Avatar
  • Inscription: Nov 21, 2006
  • Messages: 4924
  • Loc: NY
  • Status: Offline

Message Octobre 25th, 2008, 4:24 pm

Si vous avez installé et Optus WAMP, je ne vois rien de mal.
How do you know when a politician is lying? His mouth is moving.
  • Slip
  • Born
  • Born
  • No Avatar
  • Inscription: Oct 24, 2008
  • Messages: 2
  • Status: Offline

Message Octobre 25th, 2008, 4:48 pm

Don2007 a écrit:
Si vous avez installé et Optus WAMP, je ne vois rien de mal.


Awesome, grâce :P .

Afficher de l'information

  • Total des messages de ce sujet: 3 messages
  • Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 194 invités
  • Vous ne pouvez pas poster de nouveaux sujets
  • Vous ne pouvez pas répondre aux sujets
  • Vous ne pouvez pas éditer vos messages
  • Vous ne pouvez pas supprimer vos messages
  • Vous ne pouvez pas joindre des fichiers
 
 

© 2011 Unmelted, LLC. Ozzu® est une marque déposée de Unmelted, LLC