Run Cette Hijack et après le journal.
Don OK, voici le journal de ce détournement:
Logfile de Trend Micro HijackThis v2.0.2
Scan sauvé à 12:37:46 PM, le 3.16.2009
Plate-forme: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C: \ WINNT \ System32 \ smss.exe
C: \ WINNT \ system32 \ winlogon.exe
C: \ WINNT \ system32 \ services.exe
C: \ WINNT \ system32 \ lsass. exe
C: \ WINNT \ system32 \ svchost.exe
C: \ WINNT \ system32 \ spoolsv.exe
C: \ Program Files \ Alwil Software \ Avast4 \ aswupdsv.exe
C: \ Program Files \ Alwil Software \ Avast4 \ ashServ.exe
C: \ WINNT \ system32 \ svchost.exe
C: \ Program Files \ Java \ jre6 \ bin \ jqs.exe
C: \ WINNT \ system32 \ regsvc.exe
C: \ WINNT \ system32 \ MSTask.exe
C: \ WINNT \ system32 \ stisvc.exe
C: \ WINNT \ System32 \ WBEM \ Winmgmt.exe
C: \ WINNT \ system32 \ svchost.exe
C: \ WINNT \ Explorer. EXE
C: \ Program Files \ Alwil Software \ Avast4 \ ashmaisv.exe
C: \ Program Files \ Alwil Software \ Avast4 \ ashWebSv.exe
C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ Avast4 \ ashDisp.exe
C: \ Program Files \ Java \ jre6 \ bin \ jusched.exe
C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis. exe
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Bar =
http://us.rd.yahoo.com/customize/ycomp/ ... ch/ie.htmlR1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Page =
http://us.rd.yahoo.com/customize/ycomp/ ... .yahoo.comR0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page =
http://frontier.my.yahoo.comR1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL =
http://www.yahoo.com/R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL =
http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q=R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page =
http://www.yahoo.com/R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search, Default_Search_URL =
http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q=R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ SearchURL, (Default) =
http://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q= % s
R3 - URLSearchHook: DefaultSearchHook Class - (C94E154B-1459-4A47-966B-4B843BEFC7DB) - C: \ Program Files \ AskSearch \ bin \ DefaultSearch.dll
R3 - URLSearchHook: SrchHook Class - (F4F10C1D-87C7-404A-B4B3-000000000000) - C: \ PROGRA ~ 1 \ DAP \ SBSearch. dll (file missing)
O2 - BHO: (no name) - (02478D38-C3F9-4efb-9B51-7695ECA05670) - (no file)
O2 - BHO: Java (tm) Plug-In SSV Helper - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre6 \ bin \ ssv.dll
O2 - BHO: Java (tm) Plug-In 2 SSV Helper - (DBC80044-A445-435b-BC74-9C25C1C588A9) - C: \ Program Files \ Java \ jre6 \ bin \ jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - (E7E6F031-17CE-4C07-BC86-EABFE594F69C) - C: \ Program Files \ Java \ jre6 \ lib \ déployer \ jqs \ ie \ jqs_plugin. dll
O3 - Toolbar: @ msdxmLC.dll, -1 @ 1033, & Radio - (8E718888-423F-11D2-876E-00A0C9082467) - C: \ WINNT \ system32 \ msdxm.ocx
O4 - HKLM \ .. \ Run: [Synchronization Manager] mobsync.exe / logon
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime
O4 - HKLM \ .. \ Run: [avast!] C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ Avast4 \ ashDisp.exe
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre6 \ bin \ jusched.exe"
O4 - HKCU \ .. \ Run: [Messenger (Yahoo!)] & quot; C: \ Program Files \ Yahoo! \ Messenger \ YahooMessenger.exe "-quiet
O4 - HKUS \. DEFAULT \ .. \ RunOnce: [^ SetupICWDesktop] C: \ Program Files \ Internet Explorer \ Connection Wizard \ icwconn1.exe / desktop (User utilisateur par défaut)
O4 - Global Startup: PalTalk.lnk = C: \ Program Files \ Paltalk Messenger \ paltalk.exe
O9 - Extra button: PalTalk - (4EAFEF58-EEFA-4116-983D-03B49BCBFFFE) - C: \ Program Files \ Paltalk Messenger \ Paltalk. exe (file missing)
O9 - Extra button: Related - (c95fe080-8f5d-11d2-a20b-00aa003c157a) - C: \ WINNT \ web \ related.htm
O9 - Extra "Outils" menuitem: Show & Related Links - (c95fe080-8f5d-11d2-a20b-00aa003c157a) - C: \ WINNT \ web \ liés. htm
O16 - DPF: (0CCA191D-13A6-4E29-B746-314DEE697D83) (Facebook Photo Uploader 5) --
http://upload.facebook.com/controls/Fac ... oader5.cabO16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl Class) --
http://www.update.microsoft.com/windows ... 7388425683O16 - DPF: (8AD9C840-044E-11D1-B3E9-00805F499D93) (Java Runtime Environment 1.6.0) --
http://javadl.sun.com/webapps/download/ ... leId=26688O23 - Service: avast! iAVS4 Control Service (aswupdsv) - ALWIL Software - C: \ Program Files \ Alwil Software \ Avast4 \ aswupdsv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C: \ Program Files \ Alwil Software \ Avast4 \ ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C: \ Program Files \ Alwil Software \ Avast4 \ ashmaisv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C: \ Program Files \ Alwil Software \ Avast4 \ ashWebSv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp - C: \ WINNT \ System32 \ dmadmin. exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc - C: \ Program Files \ Java \ jre6 \ bin \ jqs.exe
O24 - Desktop Component 0: (no name) --
http://images.paltalk.com/peoplepicstop ... 168794.jpg--
Fin de la file - 5129 bytes