une petite verif scan hijackthis svp [RESOLU]
Posté : 21 juil. 2008, 17:04
voici mon rapport merci
par securiter merci :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:00:47, on 21/07/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00
(7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\hp\KBD\kbd.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\HP\HP Software
Update\hpwuSchd2.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\taskeng.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Avira\AntiVir PersonalEdition
Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_07
\bin\jusched.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\Spybot - Search &
Destroy\TeaTimer.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\mobile
PhoneTools\mPhonetools.exe
C:\Program Files\Windows Media
Player\wmplayer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows
Live\Messenger\msnmsgr.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\conime.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\fab et angel\Desktop\maintenance et
securiter\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet
Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?
TYPE=3&tp=iehome&locale=FR_FR&c=71&bd=Pavilion
&pf=desktop
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?
TYPE=3&tp=iehome&locale=FR_FR&c=71&bd=Pavilion
&pf=desktop
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet
Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-
4283-A596-FA578C2EBDC3} - C:\Program
Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.d
ll
O2 - BHO: RealPlayer Download and Record
Plugin for Internet Explorer - {3049C3E9-B461
-4BC5-8870-4C09146192CA} - C:\Program
Files\Real\RealPlayer\rpbrowserrecordplugin.dl
l
O2 - BHO: Spybot-S&D IE Protection -
{53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-
462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de
connexion Windows Live - {9030D464-4C02-4ABF-
8ECC-5164760863C6} - C:\Program Files\Common
Files\Microsoft Shared\Windows
Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-
01DD-4d91-8333-CF10577473F7} - c:\program
files\google\googletoolbar2.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-
7E43-44FA-9FAA-8377850BF205} - C:\Program
Files\Free Download Manager\iefdm2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-
9B18-009027A5CD4F} - c:\program
files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %
ProgramFiles%\Windows Defender\MSASCui.exe -
hide
O4 - HKLM\..\Run: [hpsysdrv]
c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update]
c:\Program Files\HP\HP Software
Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE
C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program
Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avgnt] "C:\Program
Files\Avira\AntiVir PersonalEdition
Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed
Launcher] "C:\Program Files\Adobe\Reader 9.0
\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_07
\bin\jusched.exe"
O4 - HKCU\..\Run: [Free Download Manager]
"C:\Program Files\Free Download
Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer]
C:\Program Files\Spybot - Search &
Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1
\ISUSPM.exe -startup
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %
ProgramFiles%\Windows Sidebar\Sidebar.exe
/detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run:
[WindowsWelcomeCenter] rundll32.exe
oobefldr.dll,ShowWelcomeCenter (User 'SERVICE
LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %
ProgramFiles%\Windows Sidebar\Sidebar.exe
/detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media
Detector] C:\Program Files\Picasa2
\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media
Detector] C:\Program Files\Picasa2
\PicasaMediaDetector.exe (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet
Explorer\Restrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB
-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java
(Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
- C:\Program Files\Java\jre1.6.0_07
\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8
-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1
\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search &
Destroy Configuration - {DFB852A3-47F8-48C4-
A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1
\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {2D8ED06D-3C30-438B-96AE-
4D110FDC1FB8} (ActiveScan 2.0 Installer Class)
-
http://acs.pandasoftware.com/activescan/cabs/a
s2stubie.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-
444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwav
e/cabs/flash/swflash.cab
O17 -
HKLM\System\CCS\Services\Tcpip\..\{5E7FDCF1-
8139-40D6-9E95-54EC3B5230BB}: NameServer =
194.51.3.56 194.51.3.76
O23 - Service: Avira AntiVir Personal - Free
Antivirus Scheduler (AntiVirScheduler) - Avira
GmbH - C:\Program Files\Avira\AntiVir
PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free
Antivirus Guard (AntiVirService) - Avira GmbH
- C:\Program Files\Avira\AntiVir
PersonalEdition Classic\avguard.exe
O23 - Service: Symantec Lic NetConnect service
(CLTNetCnService) - Unknown owner - c:\Program
Files\Common Files\Symantec
Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Updater Service (gusvc)
- Google - C:\Program
Files\Google\Common\Google
Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc
Labeling Service (LightScribeService) -
Hewlett-Packard Company - c:\Program
Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec
Corporation - C:\PROGRA~1\Symantec\LIVEUP~1
\LUCOMS~1.EXE
O23 - Service: Planificateur LiveUpdate
automatique - Symantec Corporation -
C:\Program
Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: SBSD Security Center Service
(SBSDWSCService) - Safer Networking Ltd. -
C:\Program Files\Spybot - Search &
Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision
Development, Inc. - c:\Program Files\Common
Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\System32
\TuneUpDefragService.exe,-1 (TuneUp.Defrag) -
TuneUp Software GmbH - C:\Windows\System32
\TuneUpDefragService.exe
--
End of file - 7601 bytes

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:00:47, on 21/07/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00
(7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\hp\KBD\kbd.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\HP\HP Software
Update\hpwuSchd2.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\taskeng.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Avira\AntiVir PersonalEdition
Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_07
\bin\jusched.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\Spybot - Search &
Destroy\TeaTimer.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\mobile
PhoneTools\mPhonetools.exe
C:\Program Files\Windows Media
Player\wmplayer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows
Live\Messenger\msnmsgr.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\conime.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\fab et angel\Desktop\maintenance et
securiter\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet
Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?
TYPE=3&tp=iehome&locale=FR_FR&c=71&bd=Pavilion
&pf=desktop
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?
TYPE=3&tp=iehome&locale=FR_FR&c=71&bd=Pavilion
&pf=desktop
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet
Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-
4283-A596-FA578C2EBDC3} - C:\Program
Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.d
ll
O2 - BHO: RealPlayer Download and Record
Plugin for Internet Explorer - {3049C3E9-B461
-4BC5-8870-4C09146192CA} - C:\Program
Files\Real\RealPlayer\rpbrowserrecordplugin.dl
l
O2 - BHO: Spybot-S&D IE Protection -
{53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-
462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de
connexion Windows Live - {9030D464-4C02-4ABF-
8ECC-5164760863C6} - C:\Program Files\Common
Files\Microsoft Shared\Windows
Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-
01DD-4d91-8333-CF10577473F7} - c:\program
files\google\googletoolbar2.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-
7E43-44FA-9FAA-8377850BF205} - C:\Program
Files\Free Download Manager\iefdm2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-
9B18-009027A5CD4F} - c:\program
files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %
ProgramFiles%\Windows Defender\MSASCui.exe -
hide
O4 - HKLM\..\Run: [hpsysdrv]
c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update]
c:\Program Files\HP\HP Software
Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE
C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program
Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avgnt] "C:\Program
Files\Avira\AntiVir PersonalEdition
Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed
Launcher] "C:\Program Files\Adobe\Reader 9.0
\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_07
\bin\jusched.exe"
O4 - HKCU\..\Run: [Free Download Manager]
"C:\Program Files\Free Download
Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer]
C:\Program Files\Spybot - Search &
Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1
\ISUSPM.exe -startup
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %
ProgramFiles%\Windows Sidebar\Sidebar.exe
/detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run:
[WindowsWelcomeCenter] rundll32.exe
oobefldr.dll,ShowWelcomeCenter (User 'SERVICE
LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %
ProgramFiles%\Windows Sidebar\Sidebar.exe
/detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media
Detector] C:\Program Files\Picasa2
\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media
Detector] C:\Program Files\Picasa2
\PicasaMediaDetector.exe (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet
Explorer\Restrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB
-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java
(Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
- C:\Program Files\Java\jre1.6.0_07
\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8
-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1
\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search &
Destroy Configuration - {DFB852A3-47F8-48C4-
A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1
\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {2D8ED06D-3C30-438B-96AE-
4D110FDC1FB8} (ActiveScan 2.0 Installer Class)
-
http://acs.pandasoftware.com/activescan/cabs/a
s2stubie.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-
444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwav
e/cabs/flash/swflash.cab
O17 -
HKLM\System\CCS\Services\Tcpip\..\{5E7FDCF1-
8139-40D6-9E95-54EC3B5230BB}: NameServer =
194.51.3.56 194.51.3.76
O23 - Service: Avira AntiVir Personal - Free
Antivirus Scheduler (AntiVirScheduler) - Avira
GmbH - C:\Program Files\Avira\AntiVir
PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free
Antivirus Guard (AntiVirService) - Avira GmbH
- C:\Program Files\Avira\AntiVir
PersonalEdition Classic\avguard.exe
O23 - Service: Symantec Lic NetConnect service
(CLTNetCnService) - Unknown owner - c:\Program
Files\Common Files\Symantec
Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Updater Service (gusvc)
- Google - C:\Program
Files\Google\Common\Google
Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc
Labeling Service (LightScribeService) -
Hewlett-Packard Company - c:\Program
Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec
Corporation - C:\PROGRA~1\Symantec\LIVEUP~1
\LUCOMS~1.EXE
O23 - Service: Planificateur LiveUpdate
automatique - Symantec Corporation -
C:\Program
Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: SBSD Security Center Service
(SBSDWSCService) - Safer Networking Ltd. -
C:\Program Files\Spybot - Search &
Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision
Development, Inc. - c:\Program Files\Common
Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\System32
\TuneUpDefragService.exe,-1 (TuneUp.Defrag) -
TuneUp Software GmbH - C:\Windows\System32
\TuneUpDefragService.exe
--
End of file - 7601 bytes