Hijack

Résolu
Bonjour,
voici le resultat

Logfile of HijackThis v1.99.1
Scan saved at 125900, on 05102007
Platform Windows XP SP2 (WinNT 5.01.2600)
MSIE Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes
CWINDOWSSystem32smss.exe
CWINDOWSsystem32winlogon.exe
CWINDOWSsystem32services.exe
CWINDOWSsystem32lsass.exe
CWINDOWSsystem32svchost.exe
CWINDOWSSystem32svchost.exe
CWINDOWSExplorer.EXE
CWINDOWSsystem32spoolsv.exe
CProgram FilesSpyware DoctorSDTrayApp.exe
CWINDOWSsystem32ctfmon.exe
CProgram FilesMessengermsmsgs.exe
CProgram FilesSpybot - Search & DestroyTeaTimer.exe
CProgram FilesGoogleGoogle UpdaterGoogleUpdater.exe
CProgram FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
CWINDOWSsystem32wscntfy.exe
CWINDOWSsystem32wpabaln.exe
CDocuments and SettingscatheBureauHIJACKTHIS VF.exe
CDOCUME~1catheLOCALS~1Tempis-LS6LE.tmpis-F1E6Q.tmp
CProgram FilesHijackthis Version Françaisehijackthis vf.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = httpwww.google.fr
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Liens
O2 - BHO Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - CProgram FilesFichiers communsAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - CPROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - cprogram filesgooglegoogletoolbar1.dll
O2 - BHO Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - CProgram FilesGoogleGoogleToolbarNotifier2.1.615.5858swg.dll
O3 - Toolbar &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - cprogram filesgooglegoogletoolbar1.dll
O4 - HKLM..Run [Adobe Reader Speed Launcher] CProgram FilesAdobeReader 8.0ReaderReader_sl.exe
O4 - HKLM..Run [SDTray] CProgram FilesSpyware DoctorSDTrayApp.exe
O4 - HKCU..Run [CTFMON.EXE] CWINDOWSsystem32ctfmon.exe
O4 - HKCU..Run [swg] CProgram FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - HKCU..Run [MSMSGS] CProgram FilesMessengermsmsgs.exe background
O4 - HKCU..Run [SpybotSD TeaTimer] CProgram FilesSpybot - Search & DestroyTeaTimer.exe
O4 - HKCU..Run [ccleaner] CProgram FilesCCleanerccleaner.exe AUTO
O4 - Global Startup Outil de mise à jour Google.lnk = CProgram FilesGoogleGoogle UpdaterGoogleUpdater.exe
O9 - Extra button (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - CPROGRA~1SPYBOT~1SDHelper.dll
O9 - Extra 'Tools' menuitem Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - CPROGRA~1SPYBOT~1SDHelper.dll
O9 - Extra button Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - CProgram FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - CProgram FilesMessengermsmsgs.exe
O18 - Protocol livecall - {828030A1-22C1-4009-854F-8E305202313F} - CPROGRA~1MSNMES~1MSGRAP~1.DLL
O18 - Protocol msnim - {828030A1-22C1-4009-854F-8E305202313F} - CPROGRA~1MSNMES~1MSGRAP~1.DLL
O23 - Service Google Updater Service (gusvc) - Google - CProgram FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service PC Tools Auxiliary Service (sdAuxService) - PC Tools - CProgram FilesSpyware Doctorsvcntaux.exe
O23 - Service PC Tools Security Service (sdCoreService) - PC Tools - CProgram FilesSpyware Doctorswdsvc.exe

4 réponses

  1. Contributeur sécurité
    slt ,

    1 / ton rapport est mal fait: et hiacjkthis est une vielle version:

    colle un rapport hijackthis

    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

    https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

    Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

    ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

    Ensuite avec Explorer créer un dossier c:\hijackthis
    Décompresser Hijackthis dans ce dossier.
    C'est important pour les sauvegardes."

    2/ tu as quel antivirus?

    si tu n'en as pas:

    AVAST en français ou ANTIVIR (en anglais mais très efficace)

    https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)

    3/ explique tes pbs car hijackthis ne fait pas tout: des pubs? des bugs.....?????
    0
    1. je ne peux pas importer le dossier de nouveau dans le registre il me dit que ce n'est pas possible et hijacktis dans dans explorer...comment tu fais la manip
      j'ai fais l'ijackthis à partir de ce que tu m'as dis et c'est cette version que j'ai pris et je ne trouve pas non plus le dossier en exe
      0
      1. bonjour,

        je viens de refaire un hijackthis en suivant tes instructions, mais je ne sais pas ce que cela donne, merci

        Logfile of HijackThis v1.99.1
        Scan saved at 09:46:26, on 06/10/2007
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Spyware Doctor\SDTrayApp.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Program Files\Google\Google Updater\GoogleUpdater.exe
        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\wpabaln.exe
        C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
        O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
        O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
        0