Rapport HijackThis v2.0.2 - Page 2

Résolu
Précédent
  • 1
  • 2
  1. momoshizabuza
     
    Logfile of random's system information tool 1.06 (written by random/random)
    Run by momoshi zabuza at 2010-01-30 22:57:48
    Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
    System drive C: has 44 GB (30%) free of 148 GB
    Total RAM: 2815 MB (50% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:58:04, on 30/01/2010
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v8.00 (8.00.6001.18882)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
    C:\Program Files\Microsoft Security Essentials\msseces.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\RocketDock\RocketDock.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Hercules\WiFi Station\WiFiStation.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\SYSTEM32\WISPTIS.EXE
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Opera\opera.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Users\momoshi zabuza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FAB5JVTO\RSIT[1].exe
    C:\Program Files\trend micro\momoshi zabuza.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R3 - URLSearchHook: PHPNukeFR Toolbar - {1c491116-c175-45e1-a570-6fb14fea8b7b} - C:\Program Files\PHPNukeFR\tbPHPN.dll
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: PHPNukeFR Toolbar - {1c491116-c175-45e1-a570-6fb14fea8b7b} - C:\Program Files\PHPNukeFR\tbPHPN.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
    O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
    O2 - BHO: TBSB06853 - {D2E45353-5501-44B3-8E61-44D023F33B64} - (no file)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1.DLL
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O3 - Toolbar: PHPNukeFR Toolbar - {1c491116-c175-45e1-a570-6fb14fea8b7b} - C:\Program Files\PHPNukeFR\tbPHPN.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
    O4 - HKLM\..\Run: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O4 - Global Startup: WiFi Station.lnk = C:\Program Files\Hercules\WiFi Station\WiFiStation.exe
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll/206 (file missing)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O13 - Gopher Prefix:
    O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (Ma-Config control) - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_5_3_0.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O20 - AppInit_DLLs: CLKERN.DLL,Files\RelevantKnowledge\rlai.dll,Files\RelevantKnowledge\rlai.dll C:\Windows\system32\cssdll32.dll
    O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
    O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
    O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
    O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
    O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
    O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
    O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
    O23 - Service: NVIDIA Performance Driver Service - Unknown owner - C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
    O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
    O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
    0
  2. momoshizabuza
     
    Fichier cssdll32.dll reçu le 2009.12.19 19:55:20 (UTC)
    Situation actuelle: terminé

    Résultat: 0/41 (0.00%)
    Formaté Impression des résultats
    Antivirus Version Dernière mise à jour Résultat
    a-squared 4.5.0.43 2009.12.19 -
    AhnLab-V3 5.0.0.2 2009.12.19 -
    AntiVir 7.9.1.114 2009.12.18 -
    Antiy-AVL 2.0.3.7 2009.12.18 -
    Authentium 5.2.0.5 2009.12.02 -
    Avast 4.8.1351.0 2009.12.19 -
    AVG 8.5.0.427 2009.12.19 -
    BitDefender 7.2 2009.12.19 -
    CAT-QuickHeal 10.00 2009.12.19 -
    ClamAV 0.94.1 2009.12.19 -
    Comodo 3299 2009.12.19 -
    DrWeb 5.0.0.12182 2009.12.19 -
    eSafe 7.0.17.0 2009.12.16 -
    eTrust-Vet 35.1.7185 2009.12.19 -
    F-Prot 4.5.1.85 2009.12.19 -
    F-Secure 9.0.15370.0 2009.12.19 -
    Fortinet 4.0.14.0 2009.12.19 -
    GData 19 2009.12.19 -
    Ikarus T3.1.1.79.0 2009.12.19 -
    Jiangmin 13.0.900 2009.12.19 -
    K7AntiVirus 7.10.923 2009.12.17 -
    Kaspersky 7.0.0.125 2009.12.19 -
    McAfee 5837 2009.12.19 -
    McAfee+Artemis 5837 2009.12.19 -
    McAfee-GW-Edition 6.8.5 2009.12.19 -
    Microsoft 1.5302 2009.12.19 -
    NOD32 4702 2009.12.19 -
    Norman 6.04.03 2009.12.19 -
    nProtect 2009.1.8.0 2009.12.18 -
    Panda 10.0.2.2 2009.12.15 -
    PCTools 7.0.3.5 2009.12.19 -
    Prevx 3.0 2009.12.19 -
    Rising 22.26.05.04 2009.12.19 -
    Sophos 4.49.0 2009.12.19 -
    Sunbelt 3.2.1858.2 2009.12.19 -
    Symantec 1.4.4.12 2009.12.19 -
    TheHacker 6.5.0.2.099 2009.12.19 -
    TrendMicro 9.100.0.1001 2009.12.19 -
    VBA32 3.12.12.0 2009.12.19 -
    ViRobot 2009.12.18.2097 2009.12.18 -
    VirusBuster 5.0.21.0 2009.12.19 -
    Information additionnelle
    File size: 253688 bytes
    MD5 : a20a975ad5c804ea4a9b043ce50237c8
    SHA1 : 02a8238fa69bebdd7a218a226b972f4e8a12aa11
    SHA256: 77ec9eb9b0f988085996589b7e0f3d6c3a3f5eac95a3c60771178f5d63c8fac6
    PEInfo: PE Structure information

    ( base data )
    entrypointaddress.: 0x1000290C
    timedatestamp.....: 0x4991C4E1 (Tue Feb 10 19:18:09 2009)
    machinetype.......: 0x14C (Intel I386)

    ( 5 sections )
    name viradd virsiz rawdsiz ntrpy md5
    .text 0x1000 0x9CB7 0xA000 6.57 b1c181e04e0037b8855cddeff57451eb
    .rdata 0xB000 0x401A 0x5000 4.66 0f4cc9fc429eccb2b64d167e8c302924
    .data 0x10000 0x1C9C 0x1000 2.28 027809311db36d743f35bdb32310ab8a
    .rsrc 0x12000 0x29454 0x2A000 7.08 7b1d2a23916d1bd6761468532410092e
    .reloc 0x3C000 0x1EB0 0x2000 4.75 a6f3a2a65113d791f3cb2b8b00d29c1c

    ( 0 imports )

    ( 0 exports )

    TrID : File type identification
    Win64 Executable Generic (59.6%)
    Win32 Executable MS Visual C++ (generic) (26.2%)
    Win32 Executable Generic (5.9%)
    Win32 Dynamic Link Library (generic) (5.2%)
    Generic Win/DOS Executable (1.3%)
    ssdeep: 3072:9AeQB96Y+OeGdkPt0AJMVeAk77AG1vP7c+LZGk5kF4OqXF40Mi0LgjgGsxb9WGWK:9P4ZAJMHknA471Gk581h7zw0/
    PEiD : -
    RDS : NSRL Reference Data Set

    voilaa
    0
  3. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    ok

    comment va le pc ?

    rame t il encore sur internet ?
    0
  4. momoshizabuza
     
    je te remercie,tout marche nikel,sauf quand j'ouvre trop de pages a la fois ou plusieurs navigateurs,mais ca je pense que cest normal!!!!
    merki bokoupssss!!!
    byebye et bone kontinuation.
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. momoshizabuza
     
    okok desolé;jvoulai fugué!!!o! a chaque fois que je lance la recherche avec toolscleaner il se bloque et ne reponds plus!!jai fais comme tu me la dis,bizare!!
    0
  7. momoshizabuza
     
    BONJOUR MON AMI
    jai telechargé loutil,jai cliké clean up,reboot lordi mais la rien se passe,lordi ne redémare pas!!jlai fai au moin 5fois!!!!et jlai lancé en tant quadministrateur!!desolé si jte pose a chaque fois dautres problemes!!o!
    0
  8. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    pas grave

    ce n'était juste que pour supprimer les outils utilisés et rapports

    tu vas donc le faire manuellement
    0
  9. momoshizabuza
     
    je te remercie 1000000000000000000000000000000fois pour ton aide!!!!!!
    Bonne continuation a toi et garde la forme malgres la eige!!o! a+++++++++++++
    0
  10. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    (sourire)
    0
Précédent
  • 1
  • 2