OVH Cloud OVH Cloud

rapport HijackThis

1 réponse
Avatar
Peio
Salut à Tous,

J'ai téléchargé Hijackthis afin de me debarraser de la page de demarrage
super search. Bon jusque là pas de problèmes, j'ai viré ce qui me paraissait
suspect mais après un redemarrage, d'autres sont apparus. Avant de faire des
"conneries", je vous livre le rapport tel que je l'ai à présent. Si
quelqu'un veut bien l'examiner et me dire quoi virer. Par avance Merci.

Logfile of HijackThis v1.97.7
Scan saved at 19:58:37, on 30/12/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\carpserv.exe
C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Pierre\Mes documents\Charge sur le
Web\antispyware\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://81.211.105.8/search.php?v=1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://81.211.105.8/index.php?v=1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://81.211.105.8/index.php?v=1
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://desktop.presario.net/scripts/redirectors/presario/deskredir2.dll?s=co
nsumer&ap=b201&c=1c02&lc=040c&ac
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://search.presario.net/scripts/redirectors/presario/srchredir2.dll?c=1c0
2&lc=040c&s=search&ap=b204
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://search.presario.net/scripts/redirectors/presario/srchredir2.dll?c=1c0
2&lc=040c&s=search&ap=b204
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://desktop.presario.net/scripts/redirectors/presario/deskredir2.dll?s=co
nsumer&ap=b201&c=1c02&lc=040c&ac
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://search.presario.net/scripts/redirectors/presario/srchredir2.dll?c=1c0
2&lc=040c&s=search&ap=b204
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
Liens
O1 - Hosts: 81.211.105.12 www.globe-finder.cc
O1 - Hosts: 81.211.105.12 globe-finder.cc
O1 - Hosts: 81.211.105.12 searchscout.com
O1 - Hosts: 81.211.105.12 www.searchscout.com
O1 - Hosts: 81.211.105.12 193.125.201.50
O1 - Hosts: 81.211.105.12 206.161.200.105
O1 - Hosts: 81.211.105.12 209.66.114.130
O1 - Hosts: 81.211.105.12 216.200.3.32
O1 - Hosts: 81.211.105.12 64.124.45.181
O1 - Hosts: 81.211.105.12 66.250.130.194
O1 - Hosts: 81.211.105.12 66.40.16.131
O1 - Hosts: 81.211.105.12 alfa-search.com
O1 - Hosts: 81.211.105.12 allhyperlinks.com
O1 - Hosts: 81.211.105.12 approvedlinks.com
O1 - Hosts: 81.211.105.12 bestcrawler.com
O1 - Hosts: 81.211.105.12 ewebsearch.net
O1 - Hosts: 81.211.105.12 global-finder.com
O1 - Hosts: 81.211.105.12 idgsearch.com
O1 - Hosts: 81.211.105.12 ie-search.com
O1 - Hosts: 81.211.105.12 itseasy.us
O1 - Hosts: 81.211.105.12 jetseeker.com
O1 - Hosts: 81.211.105.12 martfinder.com
O1 - Hosts: 81.211.105.12 rightfinder.net
O1 - Hosts: 81.211.105.12 runsearch.com
O1 - Hosts: 81.211.105.12 search.unipages.cc
O1 - Hosts: 81.211.105.12 search.xrenoder.com
O1 - Hosts: 81.211.105.12 search-2003.com
O1 - Hosts: 81.211.105.12 searchdot.net
O1 - Hosts: 81.211.105.12 searchv.com
O1 - Hosts: 81.211.105.12 searchxp.com
O1 - Hosts: 81.211.105.12 seekwell.net
O1 - Hosts: 81.211.105.12 slawsearch.com
O1 - Hosts: 81.211.105.12 srch-us6.hpwis.com
O1 - Hosts: 81.211.105.12 start-space.com
O1 - Hosts: 81.211.105.12 searchmyrequest.com
O1 - Hosts: 81.211.105.12 therealsearch.com
O1 - Hosts: 81.211.105.12 topsearcher.com
O1 - Hosts: 81.211.105.12 unipages.cc
O1 - Hosts: 81.211.105.12 webcoolsearch.com
O1 - Hosts: 81.211.105.12 worldnet.att.net
O1 - Hosts: 81.211.105.12 yourbookmarks.ws
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program
Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Watch] C:\PROGRA~1\Minitel\Watch.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe
c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook
Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator
5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate
Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate
Bytes\CloneCD\CloneCDTray.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKLM\..\RunOnce: [tlc] C:\WINDOWS\update911.js
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Sites Perso (HKLM)
O9 - Extra 'Tools' menuitem: Compaq France (HKLM)
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 -
http://surechat.com:9000/Java/cfs31229.cab
O16 - DPF: {4FCFF034-6F56-4D65-8C31-70D98C475428}
(ddm_download.ddm_control) -
http://bins.dynamicdesktopmedia.com/cab/crack.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 -
HKLM\System\CCS\Services\Tcpip\..\{2BB47C1D-5D80-4AB5-8A38-51CEEE8D0E16}:
NameServer = 80.10.246.5 80.10.246.136

1 réponse

Avatar
joke0
Salut,

Peio:
O4 - HKLM..RunOnce: [tlc] C:WINDOWSupdate911.js


Coupable: cochez la case correspondante dans Hijack This!

O16 - DPF: {4FCFF034-6F56-4D65-8C31-70D98C475428}
(ddm_download.ddm_control) -
http://bins.ddm.com/cab/crack.CAB


C'est AdvWare.DynaDesk [KAV] un activeX qui vous balance des
pop-ups publicitaires.

Vous devriez revoir votre configuration de OE sur
http://www.aspirine.org par exemple.

--
joke0