voici mon log HijackThis please help needed

  • sanyog1
  • Born
  • Born
  • No Avatar
  • Inscription: Aoû 09, 2009
  • Messages: 1
  • Status: Offline

Message Août 9th, 2009, 8:34 am

Logfile de Trend Micro HijackThis v2.0.2
Scan sauvé à 4:34:11 PM, le 8.9.2009
Plate-forme: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C: \ WINDOWS \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ csrss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ Ati2evxx.exe
C: \ WINDOWS \ system32 \ svchost. exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ system32 \ spoolsv.exe
C: \ WINDOWS \ system32 \ Ati2evxx.exe
C: \ WINDOWS \ Explorer.EXE
C: \ Program Files \ IObit \ IObit sécurité 360 \ IS360tray.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ system32 \ Cisvc.exe
C: \ Program Files \ IObit \ IObit sécurité 360 \ IS360srv. exe
C: \ Program Files \ Common Files \ LightScribe \ LSSrvc.exe
C: \ Program Files \ Common Files \ MicroWorld \ Agent \ MWASER.EXE
C: \ Program Files \ Common Files \ MicroWorld \ Agent \ MWAgent.exe
C: \ Program Files \ Microsoft \ Search Enhancement Pack \ port \ SeaPort.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ alg.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ system32 \ wscntfy.exe
C: \ WINDOWS \ system32 \ Wuauclt.exe
C: \ WINDOWS \ system32 \ cidaemon. exe
C: \ Program Files \ IObit \ IObit sécurité 360 \ is360.exe
C: \ Program Files \ Windows Live \ Messenger \ msnmsgr.exe
C: \ Program Files \ Windows Live \ Contacts \ wlcomm.exe
E: \ smss.exe
E: \ smss.exe
E: \ smss.exe
C: \ Program Files \ WinSTEP \ workshelf.exe
C: \ WINDOWS \ system32 \ taskmgr.exe
G: \ smss.exe
F: \ smss.exe
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe
C: \ WINDOWS \ system32 \ wbem \ wmiprvse. exe

R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://my.freeze.com/?AcquisitionID=67b ... e=20090416
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://uk.yahoo.com
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://uk.rd.yahoo.com/customize/ie/def ... .yahoo.com
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://uk.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://uk.yahoo.com
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search , SearchAssistant =
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Local Page =
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Local Page =
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Toolbar, LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ cpn0 \ yt.dll
F2 - REG: system.ini: Shell = explorer.exe, killer.exe
F2 - REG: system.ini: Userinit = C: \ WINDOWS \ system32 \ userinit. exe
O2 - BHO: & Yahoo! Toolbar Helper - (02478D38-C3F9-4efb-9B51-7695ECA05670) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ cpn0 \ yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Fichiers communs \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll
O2 - BHO: Search Helper - (6EBF7485-159F-4bff-A14F-B9E3AAC4465B) - C: \ Program Files \ Microsoft \ Search Enhancement Pack \ Search Helper \ SEPsearchhelperie. dll
O2 - BHO: Windows Live Sign-in Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Program Files \ Fichiers communs \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - (E15A8DC0-8516-42A1-81EA-DC94EC1ACF10) - C: \ Program Files \ Windows Live \ Toolbar \ wltcore.dll
O2 - BHO: SingleInstance Class - (FDAD4DA1-61A2-4FD8-9C17-86F7AC245081) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ cpn0 \ YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ cpn0 \ yt.dll
O3 - Toolbar: Veoh Web Player Video Finder - (0FBB9689-D3D7-4f7a-A2E2-585B10099BFC) - C: \ Program Files \ Veoh Networks \ VeohWebPlayer \ VeohIEToolbar.dll
O3 - Toolbar: Veoh Video Compass - (52836EB0-631A-47B1-94A6-61F9D9112DAE) - C: \ Program Files \ Veoh Networks \ Veoh Video Compass \ SearchRecsPlugin. dll
O3 - Toolbar: & Windows Live Toolbar - (21FA44EF-376D-4D53-9B0F-8A89D3229068) - C: \ Program Files \ Windows Live \ Toolbar \ wltcore.dll
O4 - HKLM \ .. \ Run: [Adobe Reader Speed Launcher] "C: \ Program Files \ Adobe \ Reader 8.0 \ Reader \ Reader_sl.exe"
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ QTTask.exe"-atboottime
O4 - HKLM \ .. \ Run: [iTunesHelper] "C: \ Program Files \ iTunes \ iTunesHelper.exe"
O4 - HKLM \ .. \ Run: [IObit sécurité 360] C: \ Program Files \ IObit \ IObit sécurité 360 \ IS360tray.exe
O4 - HKCU \ .. \ Run: [VeohPlugin] "C: \ Program Files \ Veoh Networks \ VeohWebPlayer \ veohwebplayer.exe"
O4 - HKCU \ .. \ Run: [Messenger (Yahoo!)] "C: \ Program Files \ Yahoo! \ Messenger \ YahooMessenger.exe"-quiet
O4 - HKCU \ .. \ Run: [Workshelf] C: \ Program Files \ WinSTEP \ workshelf.exe autostart
O4 - HKCU \ .. \ Run: [Runonce] C: \ WINDOWS \ smss.exe
O4 - HKUS \ S-1-5-19 \ .. \ Run: [MsnMsgr] "C: \ Program Files \ MSN Messenger \ msnmsgr.exe" / background (User SERVICE LOCAL)
O4 - HKUS \ S-1-5-19 \ .. \ RunOnce: [nlpo_01] cmd.exe / c md "% USERPROFILE% \ Local Settings \ Temp" (User SERVICE LOCAL)
O4 - HKUS \ S-1-5-19 \ .. \ RunOnce: [nlpo_03] rundll32 Advpack.dll, LaunchINFSection nlite.inf, S (User SERVICE LOCAL)
O4 - HKUS \ S-1-5-20 \ .. \ Run: [MsnMsgr] "C: \ Program Files \ MSN Messenger \ msnmsgr.exe" / background (User service réseau)
O4 - HKUS \ S-1-5-20 \ .. \ RunOnce: [nlpo_01] cmd.exe / c md "% USERPROFILE% \ Local Settings \ Temp" (User service réseau)
O4 - HKUS \ S-1-5-18 \ .. \ Run: [MsnMsgr] "C: \ Program Files \ MSN Messenger \ msnmsgr.exe" / background (User "SYSTEM")
O4 - HKUS \. MORATOIRES \ .. \ Run: [MsnMsgr] "C: \ Program Files \ MSN Messenger \ msnmsgr.exe" / background (User utilisateur par défaut)
O4 - Global Startup: lsass. exe
O9 - Extra button: Web Anti-Virus statistics - (1F460357-8A94-4D71-9CA3-AA4ACF32ED8E) - C: \ WINDOWS \ system32 \ shdocvw.dll
O9 - Extra button: Blog This - (219C3416-8CB2-491a-A3C7-D9FCDDC9D600) - C: \ Program Files \ Windows Live \ Writer \ WriterBrowserExtension.dll
O9 - Extra "Outils" menuitem: Ce Blog & Windows Live Writer - (219C3416-8CB2-491a-A3C7-D9FCDDC9D600) - C: \ Program Files \ Windows Live \ Writer \ WriterBrowserExtension. dll
O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MICROS ~ 3 \ OFFICE11 \ REFIEBAR.DLL
O9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O9 - Extra "Outils" menuitem: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc - C: \ WINDOWS \ system32 \ Ati2evxx. exe
O23 - Service: iPod Service - Unknown owner - C: \ Program Files \ iPod \ bin \ iPodService.exe (file missing)
O23 - Service: IS360service - IObit - C: \ Program Files \ IObit \ IObit sécurité 360 \ IS360srv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C: \ Program Files \ Common Files \ LightScribe \ LSSrvc.exe
O23 - Service: MWAgent - MicroWorld Technologies Inc - C: \ Program Files \ Common Files \ MicroWorld \ Agent \ MWASER. EXE

--
Fin de file - 7279 bytes
  • Anonymous
  • Bot
  • No Avatar
  • Inscription: 25 Feb 2008
  • Messages: ?
  • Loc: Ozzuland
  • Status: Online

Message Août 9th, 2009, 8:34 am

  • Don2007
  • Web Master
  • Web Master
  • No Avatar
  • Inscription: Nov 21, 2006
  • Messages: 4924
  • Loc: NY
  • Status: Offline

Message Août 9th, 2009, 12:06 pm

F2 - REG: system.ini: Shell = explorer.exe, killer.exe

Supprimer ce ^ ^. Il ya d'autres choses qui ont l'air étrange comme vous avez un trop grand nombre de cas de smss.exe marche.

F2 - REG: system.ini: Userinit = C: \ WINDOWS \ system32 \ userinit.exe

Aussi, je ne sais pas pourquoi userinit.exe, qui peut être un fichier légitime, est en system.ini

Supprimer killer.exe, puis de télécharger, mettre à jour et de lutte contre les logiciels malveillants d'exécuter malwarebytes.org
How do you know when a politician is lying? His mouth is moving.

Afficher de l'information

  • Total des messages de ce sujet: 2 messages
  • Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 107 invités
  • Vous ne pouvez pas poster de nouveaux sujets
  • Vous ne pouvez pas répondre aux sujets
  • Vous ne pouvez pas éditer vos messages
  • Vous ne pouvez pas supprimer vos messages
  • Vous ne pouvez pas joindre des fichiers
 
 

© 2011 Unmelted, LLC. Ozzu® est une marque déposée de Unmelted, LLC