[HIJACK] Analyse svp

Xtatic -  
aranjuez31 Messages postés 8161 Date d'inscription   Statut Contributeur -
Etant victime de déconextion intempestive avec mon FAI, je vous propose de jack pour analyse... au cas où...

Merci d'avance pour vos remarques.

Logfile of HijackThis v1.99.1
Scan saved at 15:34:07, on 26/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
C:\Program Files\Foxmail50fr\Foxmail.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DgnWebIE - {2843DAC1-05EF-11D2-95BA-0060083493D6} - C:\Program Files\Dragon Systems\NaturallySpeaking\Program\web_ie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
O4 - HKCU\..\Run: [Foxmail] "C:\Program Files\Foxmail50fr\Foxmail.exe" -min
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Télécharger tout avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: gearsec - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

9 réponses

  1. La loupiote Messages postés 2575 Statut Membre 1 541
     
    salut

    a part la ligne 09

    le reste apparait bon

    C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe - Inconnu
    C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE - Inconnu
    O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe - Inconnu
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) - Eventuellement méchant
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) - Eventuellement méch


    ne pas faire attention aux allusions de méchant concernant bitdefender
    0
  2. aranjuez31 Messages postés 8161 Date d'inscription   Statut Contributeur 354
     
    bjr
    un peu simpliste cette analyse au robot.....à ne pas utiliser car risque avéréd erreur
    les lignes 09 sont bonnes !!! c est bitdefender
    =========
    faire faire un sondage avec

    3/ - Ewido (dowload)- gratuit même après 14 jours d’essai
    http://perso.wanadoo.fr/entraide-hijackthis/Ewido/
    Copie/COLLE le rapport généré sur ce forum

    pour commencer sérieusement....
    0
  3. Xtatic
     
    Je me disais aussi...

    Ok je fais les tests...
    0
  4. Xtatic
     
    Voici le log demandé :

    ---------------------------------------------------------
    ewido anti-malware - Rapport de scan
    ---------------------------------------------------------

    + Créé le: 16:42:51, 26/04/2006
    + Somme de contrôle: A250B2E7

    + Résultats du scan:

    :mozilla.7:C:\Documents and Settings\Dada&Lili\Application Data\Mozilla\Firefox\Profiles\j2qqijye.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyer et sauvegarder
    :mozilla.9:C:\Documents and Settings\Dada&Lili\Application Data\Mozilla\Firefox\Profiles\j2qqijye.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyer et sauvegarder
    :mozilla.10:C:\Documents and Settings\Dada&Lili\Application Data\Mozilla\Firefox\Profiles\j2qqijye.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
    :mozilla.11:C:\Documents and Settings\Dada&Lili\Application Data\Mozilla\Firefox\Profiles\j2qqijye.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
    :mozilla.12:C:\Documents and Settings\Dada&Lili\Application Data\Mozilla\Firefox\Profiles\j2qqijye.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
    :mozilla.33:C:\Documents and Settings\Dada&Lili\Application Data\Mozilla\Firefox\Profiles\j2qqijye.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyer et sauvegarder
    :mozilla.58:C:\Documents and Settings\Dada&Lili\Application Data\Mozilla\Firefox\Profiles\j2qqijye.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyer et sauvegarder
    :mozilla.59:C:\Documents and Settings\Dada&Lili\Application Data\Mozilla\Firefox\Profiles\j2qqijye.default\cookies.txt -> TrackingCookie.Adtech : Nettoyer et sauvegarder
    :mozilla.60:C:\Documents and Settings\Dada&Lili\Application Data\Mozilla\Firefox\Profiles\j2qqijye.default\cookies.txt -> TrackingCookie.Adtech : Nettoyer et sauvegarder
    :mozilla.64:C:\Documents and Settings\Dada&Lili\Application Data\Mozilla\Firefox\Profiles\j2qqijye.default\cookies.txt -> TrackingCookie.Estat : Nettoyer et sauvegarder
    :mozilla.66:C:\Documents and Settings\Dada&Lili\Application Data\Mozilla\Firefox\Profiles\j2qqijye.default\cookies.txt -> TrackingCookie.Valueclick : Nettoyer et sauvegarder
    :mozilla.67:C:\Documents and Settings\Dada&Lili\Application Data\Mozilla\Firefox\Profiles\j2qqijye.default\cookies.txt -> TrackingCookie.Valueclick : Nettoyer et sauvegarder
    :mozilla.68:C:\Documents and Settings\Dada&Lili\Application Data\Mozilla\Firefox\Profiles\j2qqijye.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyer et sauvegarder
    :mozilla.69:C:\Documents and Settings\Dada&Lili\Application Data\Mozilla\Firefox\Profiles\j2qqijye.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyer et sauvegarder
    :mozilla.73:C:\Documents and Settings\Dada&Lili\Application Data\Mozilla\Firefox\Profiles\j2qqijye.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyer et sauvegarder
    C:\Documents and Settings\Dada&Lili\Cookies\dada&lili@247realmedia[1].txt -> TrackingCookie.247realmedia : Nettoyer et sauvegarder
    C:\Documents and Settings\Dada&Lili\Cookies\dada&lili@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder

    ::Fin du rapport
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. aranjuez31 Messages postés 8161 Date d'inscription   Statut Contributeur 354
     
    hello

    que des cookies-traceurs, pas vraiment des maliciels

    je ne vois rien de mauvais ds ton logfile, qques inutilités au run (04) mais bof... si tu n as pas de ralentissement notoire....

    le (file missing) en fin de 09 est un bogue de HJT - si tu as l habitude (conseillée hebdomairement) de faire des online avec bitdef, inutile de chercher à supprimer l'activX

    bien sur on pourrait faire une analyse plus poussée, mais si tu ne rencontres pas de blems notoires.....bof

    d'autres questions ?

    0
  7. Xtatic
     
    Bonjour!

    Merci pour vos remarques.
    Si vous ne voyez rien n'anormal alors me voila rassuré.
    Par précaution (ou parano?) j'ai quand même effectué vos autres tests (ceux que vous m'aviez recommandé par le passé). Donc r.a.s.. ouf !

    J'ai cherché sur Google un topic sur l'interprétation des log hijack mais j'ai pas trouvé de trucs complets sans doute parce ce que l'expérience compte aussi pour ce genre d'analyse...

    En tout cas, merci pour la rapidité de votre intervention.

    Bien cordialement.

    X.
    0
  8. Xtatic
     
    Merci bien !

    Je connaissais déjà ce super site. Je vais lire ces débuts car cela me semble très intéressant...

    Bonne soirée.
    0