Hacked by morokat@gmail.com

Bonjour,
voila j'ai depuis peu sur la ligne bleue en haut de page internet
hacked by morokat@mail qui se place apres l'adresse de la page visitée
que dois-je en penser ?
ordi sous XP

merci
Configuration: Windows XP
Internet Explorer 7.0

6 réponses

  1. bon pas grand monde qui a une idée ....
    un coup d'avast en scan de démarage et c'est toujours la
    j'ai aussi effectuéun scan avec itman pro et la aussi toujours la
    franchement je ne vois pas comment virer ce truc
    alors si vous avez une idée je prends ....
    merci
    0
    1. Tu a pas été piraté par un individu par hasard ?!
      0
      1. telecharge cela:
        http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

        ouvre le , clique sur do a scan and sava a logfile , tu obtiens un rapport que tu colles.
        1
        1. Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 21:05:01, on 22/06/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16674)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\ZONELABS\vsmon.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\System32\igfxtray.exe
          C:\WINDOWS\System32\hkcmd.exe
          C:\WINDOWS\AGRSMMSG.exe
          C:\Program Files\Apoint2K\Apoint.exe
          C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
          C:\WINDOWS\SOUNDMAN.EXE
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
          C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
          C:\Program Files\Spyware Doctor\pctsTray.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\PROGRA~1\Druide\Antidote\Antidote\Gestionnaire Antidote.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\FinePixViewer\QuickDCF.exe
          C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
          C:\Program Files\Google\Google Updater\GoogleUpdater.exe
          C:\Program Files\Apoint2K\Apntex.exe
          C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Hacked by MOROKAT@gmail.com
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O4 - HKLM\..\Run: [LaunchApp] Alaunch
          O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
          O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
          O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
          O4 - HKLM\..\Run: [REGSHAVE] "C:\Program Files\REGSHAVE\REGSHAVE.EXE" /AUTORUN
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [Omnipage] "C:\Program Files\ScanSoft\OmniPageSE\opware32.exe"
          O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\PROGRA~1\Druide\Antidote\Antidote\Gestionnaire Antidote.exe
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
          O4 - Startup: CD-MENU.LNK = D:\AutoMenu.exe
          O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
          O4 - Global Startup: Exif Launcher.lnk = ?
          O4 - Global Startup: TrayMin220.lnk = ?
          O4 - Global Startup: La Solution Ciel.lnk = ?
          O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
          O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra button: Correcteur - {F7C8E5F6-B6D1-45db-8D91-2BCFA5DF11A9} - C:\PROGRA~1\Druide\Antidote\Antidote\Internet Explorer\6\Antidote K - IE 6.htm (HKCU)
          O9 - Extra button: Dictionnaire - {FB4AE6A3-EE20-442c-9189-251885352358} - C:\PROGRA~1\Druide\Antidote\Antidote\Internet Explorer\6\Antidote D - IE 6.htm (HKCU)
          O9 - Extra button: Synonymes - {FDD637F8-2693-49ce-817E-1AD59574900C} - C:\PROGRA~1\Druide\Antidote\Antidote\Internet Explorer\6\Antidote S - IE 6.htm (HKCU)
          O9 - Extra button: Conjugueur - {FF229BEC-9E1F-48c1-99A6-AF34ABEFAB0A} - C:\PROGRA~1\Druide\Antidote\Antidote\Internet Explorer\6\Antidote C - IE 6.htm (HKCU)
          O9 - Extra button: Grammaire - {FFB5EE7F-726F-423e-83C2-572FE7CEB3F0} - C:\PROGRA~1\Druide\Antidote\Antidote\Internet Explorer\6\Antidote G - IE 6.htm (HKCU)
          O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
          O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
          O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
          O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
          O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
          O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
          O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
          0
      2. refais hijhack clique juste sur :do a scan

        ensuite clique sur fix check pour ces lignes

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Hacked by MOROKAT@gmail.com
        O4 - Global Startup: Exif Launcher.lnk = ?
        O4 - Global Startup: TrayMin220.lnk = ?
        O4 - Global Startup: La Solution Ciel.lnk = ?
        O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

        je ne pense pas que tu sois pirate , pour moi c est une mauvaise blague fait directement sur ton ordinateur par quelqu un.

        ad aware a la traine tu peux le desinstaller.

        pour avast change le au profit d antivir car plus performant
        http://www.commentcamarche.net/telecharger/telecharger 55 antivir personal

        pour ton pare feu il est correct mais tu as mieux et egalement gratuit
        http://www.matousec.com/index.html?num=7

        voila les liens
        http://www.commentcamarche.net/telecharger/telecharger 34055041 comodo firewall pro
        et le tuto https://www.malekal.com/tutorial-comodo-firewall/

        ou

        http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall
        et le tuto https://www.malekal.com/tutorial-online-armor-free/

        tu peux egalement passer d internet explorer a firefox, car bien plus securise
        http://www.commentcamarche.net/telecharger/telecharger 111 firefox

        n oublie pas les mise a jour de temps en temps d adobe et java
        1
        1. bonsoir
          j'ai fais une modification que tu m'as proposée
          firefox entre autre
          pour refaire hijhack pas de problème mais je n'ai plus les lignes demandées

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Hacked by MOROKAT@gmail.com
          O4 - Global Startup: Exif Launcher.lnk = ?
          O4 - Global Startup: TrayMin220.lnk = ?
          O4 - Global Startup: La Solution Ciel.lnk = ?
          O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

          voila mais avec firefox plus de hacked by morokat
          merci
          0
      3. a mon avis il faudrait en faire d autres mais c est toi qui voit et ce n est qu un debut.regarde les differents pb et tu te rendras compte que 90 a 95 % des personnes infectees on avast mais egalement elle n ont pas de pare feu(pare feu windows ne compte pas)

        pour firefox c est normal car la ligne enleve etait
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Hacked by MOROKAT@gmail.com

        il y a en tout cas un outil aque tout le monde devrait avoir c est c cleaner, tres bien pour enlever ce qu il reste de tes surfs sur le net et de faire le balai.en tout cas regarde bien comment il fonctionne fait une recherche.

        a bon entendeur.
        1
        1. je te reùercie pour le coup de main
          je suis l'utilisateur de bas point .... alors des que cela ne marche plus galère
          suivant tes informations , je dois encore faire quoi d'indispensable
          j'ai bien firefox mais j'ai aussi IE en meme temps ( je dois le virer ou pas ? possible ? )
          par feu ?
          c cleaner ( j'ai )
          antivir ( j'ai depuis tes remarques )
          autre chose
          bonne journée
          0
      4. tres bien mais si tu as antivir , tu n as plus de avast . il doit etre desinstalle

        pour le pare feu message 5 j avai ecris.(regarde chaque lien et choisis celui que tu veux car il se vale, un est mieux note, pas de grande difference mais l autre est plus leger.)les 2 en anglais voila pourquoi les tuto.

        pour ton pare feu il est correct mais tu as mieux et egalement gratuit
        http://www.matousec.com/index.html?num=7

        voila les liens
        https://www.commentcamarche.net/telecharger/ 34055041 comodo firewall pro
        et le tuto https://www.malekal.com/tutorial-comodo-firewall/

        ou

        https://www.commentcamarche.net/telecharger/ 34055356 online armor personal firewall
        et le tuto https://www.malekal.com/tutorial-online-armor-free/
        1