Rapport Hijackthis

Résolu/Fermé
BattaL Messages postés 12 Date d'inscription samedi 24 février 2007 Statut Membre Dernière intervention 7 août 2007 - 24 févr. 2007 à 19:58
Kristopher Messages postés 3731 Date d'inscription vendredi 18 novembre 2005 Statut Contributeur Dernière intervention 10 juillet 2009 - 27 févr. 2007 à 19:35
Bonjour,
Je voudrais faire vérifier mon système, voir s'il n'est pas infecté.
Pour cela voici mon rapport HijackThis:

Logfile of HijackThis v1.99.1
Scan saved at 16:57:58, on 24/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\Explorer.EXE
E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
E:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
E:\Program Files\Analog Devices\SoundMAX\Smtray.exe
E:\PROGRA~1\FICHIE~1\PCSuite\Services\SERVIC~1.EXE
E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
E:\WINDOWS\ATKKBService.exe
E:\Program Files\Alwil Software\Avast4\ashServ.exe
E:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
E:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
E:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
E:\Program Files\iPod\bin\iPodService.exe
E:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
E:\Program Files\eMule\emule.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Documents and Settings\Bat\Bureau\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://koyotstar.free.fr/indexEn.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [avast!] E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] E:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [Smapp] E:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [TkBellExe] "E:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "E:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - E:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - E:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - E:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

7 réponses

Kristopher Messages postés 3731 Date d'inscription vendredi 18 novembre 2005 Statut Contributeur Dernière intervention 10 juillet 2009 106
24 févr. 2007 à 20:25
Salut,

Ton log HT est clean, mais cela ne signifie pas que ton PC le soit :>

Commence par ceci (à faire à la lettre !) :

virus methode preliminaire de desinfection version fr

a+
0
Salut,
J'ai fait exactement comme tu m'as dis.
Rapport AVG antispyware: rien à signaler
Rapport Bitdefender: no virus found
Rapport Hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 16:12:39, on 25/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.EXE
E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
E:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
E:\Program Files\Analog Devices\SoundMAX\Smtray.exe
E:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
E:\WINDOWS\system32\ctfmon.exe
E:\PROGRA~1\FICHIE~1\PCSuite\Services\SERVIC~1.EXE
E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
E:\WINDOWS\ATKKBService.exe
E:\Program Files\Alwil Software\Avast4\ashServ.exe
E:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
E:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
E:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
E:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://koyotstar.free.fr/indexEn.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [avast!] E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] E:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [Smapp] E:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [TkBellExe] "E:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "E:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - E:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - E:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - E:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe


Apparemment, mon PC est clean.
A part ça, j'ai d'autres questions à te poser:
-je voudrais réaliser une image de mon PC. Quel logiciel me préconises-tu? (gratuit si possible)
-quel système de sécurité me conseilles-tu? sachant que comme tu as pu le voir, j'ai: avast + adaware + spybot + kerio
-dernière chose, concernant avast: lorsque je programme un scan au démarrage, au moment de commencer, avast m'affiche: "keyboard error" alors que mon clavier fonctionne correctement.
Merci pour ta réponse.
0
Kristopher Messages postés 3731 Date d'inscription vendredi 18 novembre 2005 Statut Contributeur Dernière intervention 10 juillet 2009 106
26 févr. 2007 à 20:01
Re,

Fais un dernier scan pour voir :

Scanne ton PC avec cet antivirus en ligne :
https://www.kaspersky.fr/downloads
- Choisis "Kaspersky Online Scanner"
- Clique sur "Accept" -> "Next" -> "My computer"
- Laisse le scan se faire et copie/colle le rapport ici (si infecté)
0
Salut Kristopher,
j'ai fait le scan Kaspersky et il a l'air d'être clean aussi (à part les "objects locked"):
Scan Statistics
Total number of scanned objects 74057
Number of viruses found 0
Number of infected objects 0 / 0
Number of suspicious objects 0
Duration of the scan process 01:50:56

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{BB883F58-4F35-4FB7-AD55-3FD334BA7FE1}\RP47\change.log Object is locked skipped

D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

D:\System Volume Information\_restore{BB883F58-4F35-4FB7-AD55-3FD334BA7FE1}\RP47\change.log Object is locked skipped

E:\Documents and Settings\Bat\Cookies\index.dat Object is locked skipped

E:\Documents and Settings\Bat\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

E:\Documents and Settings\Bat\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

E:\Documents and Settings\Bat\Local Settings\Historique\History.IE5\index.dat Object is locked skipped

E:\Documents and Settings\Bat\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

E:\Documents and Settings\Bat\NTUSER.DAT Object is locked skipped

E:\Documents and Settings\Bat\ntuser.dat.LOG Object is locked skipped

E:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

E:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

E:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

E:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped

E:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

E:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

E:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

E:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

E:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

E:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

E:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

E:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped

E:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped

E:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped

E:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped

E:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped

E:\Program Files\Alwil Software\Avast4\DATA\report\Protection résidente.txt Object is locked skipped

E:\Program Files\Sunbelt Software\Personal Firewall\logs\debug.log Object is locked skipped

E:\Program Files\Sunbelt Software\Personal Firewall\logs\debug.log.idx Object is locked skipped

E:\Program Files\Sunbelt Software\Personal Firewall\logs\error.log Object is locked skipped

E:\Program Files\Sunbelt Software\Personal Firewall\logs\error.log.idx Object is locked skipped

E:\Program Files\Sunbelt Software\Personal Firewall\logs\hips.log Object is locked skipped

E:\Program Files\Sunbelt Software\Personal Firewall\logs\hips.log.idx Object is locked skipped

E:\Program Files\Sunbelt Software\Personal Firewall\logs\ids.log Object is locked skipped

E:\Program Files\Sunbelt Software\Personal Firewall\logs\ids.log.idx Object is locked skipped

E:\Program Files\Sunbelt Software\Personal Firewall\logs\network.log Object is locked skipped

E:\Program Files\Sunbelt Software\Personal Firewall\logs\network.log.idx Object is locked skipped

E:\Program Files\Sunbelt Software\Personal Firewall\logs\system.log Object is locked skipped

E:\Program Files\Sunbelt Software\Personal Firewall\logs\system.log.idx Object is locked skipped

E:\Program Files\Sunbelt Software\Personal Firewall\logs\warning.log Object is locked skipped

E:\Program Files\Sunbelt Software\Personal Firewall\logs\warning.log.idx Object is locked skipped

E:\Program Files\Sunbelt Software\Personal Firewall\logs\web.log Object is locked skipped

E:\Program Files\Sunbelt Software\Personal Firewall\logs\web.log.idx Object is locked skipped

E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

E:\System Volume Information\_restore{BB883F58-4F35-4FB7-AD55-3FD334BA7FE1}\RP47\change.log Object is locked skipped

E:\WINDOWS\CSC\00000001 Object is locked skipped

E:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

E:\WINDOWS\SchedLgU.Txt Object is locked skipped

E:\WINDOWS\SoftwareDistribution\EventCache\{E7A0B315-8DDA-4A8B-8C4C-38963B806498}.bin Object is locked skipped

E:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

E:\WINDOWS\Sti_Trace.log Object is locked skipped

E:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

E:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

E:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped

E:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped

E:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

E:\WINDOWS\system32\config\default Object is locked skipped

E:\WINDOWS\system32\config\default.LOG Object is locked skipped

E:\WINDOWS\system32\config\SAM Object is locked skipped

E:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

E:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

E:\WINDOWS\system32\config\SECURITY Object is locked skipped

E:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

E:\WINDOWS\system32\config\software Object is locked skipped

E:\WINDOWS\system32\config\software.LOG Object is locked skipped

E:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

E:\WINDOWS\system32\config\system Object is locked skipped

E:\WINDOWS\system32\config\system.LOG Object is locked skipped

E:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

E:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

E:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

E:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

E:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

E:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

E:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

E:\WINDOWS\Temp\Perflib_Perfdata_7a0.dat Object is locked skipped

E:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped

E:\WINDOWS\wiadebug.log Object is locked skipped

E:\WINDOWS\wiaservc.log Object is locked skipped

E:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Kristopher Messages postés 3731 Date d'inscription vendredi 18 novembre 2005 Statut Contributeur Dernière intervention 10 juillet 2009 106
27 févr. 2007 à 11:09
Re,

"Pour réaliser une image de mon PC"

gratos :
https://www.pcastuces.com/logitheque/savepart.htm
Payant : https://www.avanquest.com/France/logiciels-utilitaires/sauvegarde-recuperation/sauvegarde/?rs2=REDIRECT_FP_NVELLE_REF

Pour tes logiciels de sécurité, c'est pas trop mal mais rajoute ça encore Windows Defender :
https://www.clubic.com/telecharger-fiche13691-windows-defender.html

Pour Avast, t'as un tuto ici:
http://www.tutopat.com/viewtopic.php?t=1541

a+
0
BattaL Messages postés 12 Date d'inscription samedi 24 février 2007 Statut Membre Dernière intervention 7 août 2007
27 févr. 2007 à 13:04
Ok merci Kristopher pour ton aide et tes conseils!
A+
0
Kristopher Messages postés 3731 Date d'inscription vendredi 18 novembre 2005 Statut Contributeur Dernière intervention 10 juillet 2009 106
27 févr. 2007 à 19:35
De rien ;)

Bon surf ^^
0