Infection .scr Msn

Bonjour,


je suis infecté par un trojan, via un .scr ouvert depuis msn... bien connu ici je crois


avast me fait regulierement des alertes sans pouvoir supprimer le fichier, à savoir ghost.exe


Je ne sais pas quoi faire pour corriger le problème... mon hijackthis.log :


Logfile of HijackThis v1.99.1


Scan saved at 01:40:47, on 04/07/2007


Platform: Windows XP SP2 (WinNT 5.01.2600)


MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


Running processes:


C:\WINDOWS\System32\smss.exe


C:\WINDOWS\system32\winlogon.exe


C:\WINDOWS\system32\services.exe


C:\WINDOWS\system32\lsass.exe


C:\WINDOWS\system32\svchost.exe


C:\WINDOWS\System32\svchost.exe


C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe


C:\Program Files\Alwil Software\Avast4\ashServ.exe


C:\WINDOWS\system32\spoolsv.exe


C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe


C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE


C:\WINDOWS\system32\CAPRPCSK.EXE


C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe


C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe


C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe


C:\WINDOWS\system32\nvsvc32.exe


C:\Program Files\Kerio\Personal Firewall\persfw.exe


C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindService.exe


C:\WINDOWS\system32\svchost.exe


C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe


C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe


C:\Program Files\Alwil Software\Avast4\ashWebSv.exe


C:\WINDOWS\system32\wscntfy.exe


C:\WINDOWS\Explorer.EXE


C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe


C:\Program Files\Analog Devices\Core\smax4pnp.exe


C:\Program Files\Analog Devices\SoundMAX\Smax4.exe


C:\Program Files\Google\Gmail Notifier\gnotify.exe


C:\Program Files\QuickTime\qttask.exe


C:\Program Files\ASUS\PC Probe II\Probe2.exe


C:\Program Files\Saitek\Software\Profiler.exe


C:\Program Files\Saitek\Software\SaiSmart.exe


C:\Program Files\Saitek\Software\SaiMfd.exe


C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe


C:\WINDOWS\system32\RunDLL32.exe


C:\Program Files\Alwil Software\Avast4\ashDisp.exe


C:\WINDOWS\CameraFixer.exe


C:\WINDOWS\tsnpstd3.exe


C:\Program Files\MSN Messenger\MsnMsgr.Exe


C:\WINDOWS\system32\ctfmon.exe


C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE


C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE


C:\Documents and Settings\Administrateur\Bureau\vincent\HijackThis.exe


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ie/defaul...earch.yahoo.com


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.yahoo.com


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://fr.rd.yahoo.com/customize/ie/defaul...earch.yahoo.com


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ie/defaul...earch.yahoo.com


R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com


R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =


R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaul...earch.yahoo.com


R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens


R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll


O1 - Hosts: 213.41.44.120 warrantytest


O1 - Hosts: 84.14.102.22 pp.warranty.staples-eu.com


O1 - Hosts: 84.14.102.80 testSession


O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll


O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll


O2 - BHO: Alcohol Toolbar Helper - {52D06F97-5511-43FA-8FDA-C481864FD26E} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll


O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll


O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll


O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx


O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll


O3 - Toolbar: Alcohol Toolbar - {4C4E7CDB-5BFC-4D74-83E2-8AE659B7EDA2} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll


O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe


O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"


O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe


O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe


O4 - HKLM\..\Run: [soundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray


O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup


O4 - HKLM\..\Run: [nwiz] nwiz.exe /install


O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe


O4 - HKLM\..\Run: [CAPON] C:\WINDOWS\system32\Spool\Drivers\w32x86\3\CAPONN.EXE


O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


O4 - HKLM\..\Run: [Launch PC Probe II] "C:\Program Files\ASUS\PC Probe II\Probe2.exe" 1


O4 - HKLM\..\Run: [Profiler] C:\Program Files\Saitek\Software\Profiler.exe


O4 - HKLM\..\Run: [saiSmart] C:\Program Files\Saitek\Software\SaiSmart.exe


O4 - HKLM\..\Run: [saiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe


O4 - HKLM\..\Run: [amd_dc_opt] "C:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe"


O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe


O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit


O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"


O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE


O4 - HKLM\..\Run: [CameraFixer] C:\WINDOWS\CameraFixer.exe


O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe


O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe


O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background


O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet


O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe


O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized


O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1


O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe


O4 - Global Startup: Finestra di stato di Canon LBP-800.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE


O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe


O4 - Global Startup: RaConfig2500.lnk = C:\Program Files\RALINK\RT2500 USB Wireless LAN Card\Installer\WINXP\RaConfig2500.exe


O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\OFFICE11\EXCEL.EXE/3000


O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll


O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll


O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll


O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll


O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\OFFICE11\REFIEBAR.DLL


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta...staller_gmn.cab


O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll


O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab


O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSN Messenger\msgrapp.8.1.0178.00.dll


O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll


O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSN Messenger\msgrapp.8.1.0178.00.dll


O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\Skype4COM.dll


O21 - SSODL: system32 - {B2639CFD-B99C-472D-86AC-373A6FD48A65} - sysprinters.dll (file missing)


O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe


O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe


O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)


O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)


O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe


O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)


O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe


O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)


O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe


O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe


O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe


O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007\Win32\RpcDataSrv.exe


O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007\RpcSandraSrv.exe


O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindService.exe

Réponses

  • Salut Pimousse;


    Téléchargez MSNFix.zip (de !aur3n7) sur votre bureau:


    http://sosvirus.changelog.fr/MSNFix.zip


    Décompressez-le (clic droit >> Extraire ici) et double cliquer sur le fichier MSNFix.bat.


    - Exécutez l'option R.


    -- Si l'infection est détectée, un message l'indiquera et il suffira de presser une touche pour lancer le nettoyage


    Note :


    Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal


    - Le rapport sera enregistré dans le même dossier que MSNFix sous forme date_heure.txt


    A+

  • Je ne suis pas sûr que cela suffit :


    voila mon rapport msn fix (j'avais déjà exécuté ccleaner) :


    MSN_Fix 1.331


    C:\Documents and Settings\Administrateur\Bureau\MSNFix


    Fix exécuté le 04/07/2007 - 12:07:59,79 By Administrateur


    mode normal


    ************************ Recherche les fichiers présents


    ... C:\WINDOWS\myalbum*.zip


    ... C:\WINDOWS\*album*.zip


    ... C:\WINDOWS\myalbum2007.zip


    ... C:\WINDOWS\system32\sysprinters.dll


    ************************ Recherche les dossiers présents


    Aucun dossier trouvé


    ************************ Suppression des fichiers


    .. OK ... C:\WINDOWS\myalbum*.zip


    .. OK ... C:\WINDOWS\*album*.zip


    .. OK ... C:\WINDOWS\myalbum2007.zip


    /!\ ... C:\WINDOWS\system32\sysprinters.dll


    ************************ Nettoyage du registre


    Les fichiers encore présents seront supprimés au prochain redémarrage


    Aucun dossier trouvé


    ************************ Suppression des fichiers


    .. OK ... C:\WINDOWS\system32\sysprinters.dll


    ************************ Fichiers suspects


    /!\ ces fichiers nécessitent un avis expérimenté avant toute intervention


    Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 04072007_12115456.zip


    ------------------------------------------------------------------------


    Auteur : !aur3n7 Contact: http://246694.aceboard.fr


    ------------------------------------------------------------------------


    --------------------------------------------- END ---------------------------------------------


    puis le hijackThis.log où l'on peut voir notament que cameraFexer.exe est toujours présent...


    Logfile of HijackThis v1.99.1


    Scan saved at 12:27:13, on 04/07/2007


    Platform: Windows XP SP2 (WinNT 5.01.2600)


    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


    Running processes:


    C:\WINDOWS\System32\smss.exe


    C:\WINDOWS\system32\winlogon.exe


    C:\WINDOWS\system32\services.exe


    C:\WINDOWS\system32\lsass.exe


    C:\WINDOWS\system32\svchost.exe


    C:\WINDOWS\System32\svchost.exe


    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe


    C:\Program Files\Alwil Software\Avast4\ashServ.exe


    C:\WINDOWS\system32\spoolsv.exe


    C:\WINDOWS\Explorer.EXE


    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe


    C:\Program Files\Analog Devices\Core\smax4pnp.exe


    C:\Program Files\Analog Devices\SoundMAX\Smax4.exe


    C:\WINDOWS\system32\CAPRPCSK.EXE


    C:\Program Files\Google\Gmail Notifier\gnotify.exe


    C:\Program Files\ASUS\PC Probe II\Probe2.exe


    C:\Program Files\Saitek\Software\Profiler.exe


    C:\Program Files\Saitek\Software\SaiSmart.exe


    C:\Program Files\Saitek\Software\SaiMfd.exe


    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe


    C:\WINDOWS\system32\RunDLL32.exe


    C:\Program Files\Alwil Software\Avast4\ashDisp.exe


    C:\WINDOWS\CameraFixer.exe


    C:\WINDOWS\tsnpstd3.exe


    C:\WINDOWS\system32\ctfmon.exe


    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe


    C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE


    C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE


    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe


    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE


    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe


    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe


    C:\WINDOWS\system32\nvsvc32.exe


    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe


    C:\Program Files\Kerio\Personal Firewall\persfw.exe


    C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindService.exe


    C:\WINDOWS\system32\svchost.exe


    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe


    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe


    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe


    C:\WINDOWS\system32\wscntfy.exe


    C:\WINDOWS\system32\msiexec.exe


    C:\Documents and Settings\Administrateur\Bureau\vincent\HijackThis.exe


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ie/defaul...earch.yahoo.com


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.yahoo.com


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://fr.rd.yahoo.com/customize/ie/defaul...earch.yahoo.com


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ie/defaul...earch.yahoo.com


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com


    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =


    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaul...earch.yahoo.com


    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens


    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll


    O1 - Hosts: 213.41.44.120 warrantytest


    O1 - Hosts: 84.14.102.22 pp.warranty.staples-eu.com


    O1 - Hosts: 84.14.102.80 testSession


    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll


    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll


    O2 - BHO: Alcohol Toolbar Helper - {52D06F97-5511-43FA-8FDA-C481864FD26E} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll


    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll


    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll


    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx


    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll


    O3 - Toolbar: Alcohol Toolbar - {4C4E7CDB-5BFC-4D74-83E2-8AE659B7EDA2} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll


    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe


    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"


    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe


    O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe


    O4 - HKLM\..\Run: [soundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray


    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup


    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install


    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe


    O4 - HKLM\..\Run: [CAPON] C:\WINDOWS\system32\Spool\Drivers\w32x86\3\CAPONN.EXE


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


    O4 - HKLM\..\Run: [Launch PC Probe II] "C:\Program Files\ASUS\PC Probe II\Probe2.exe" 1


    O4 - HKLM\..\Run: [Profiler] C:\Program Files\Saitek\Software\Profiler.exe


    O4 - HKLM\..\Run: [saiSmart] C:\Program Files\Saitek\Software\SaiSmart.exe


    O4 - HKLM\..\Run: [saiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe


    O4 - HKLM\..\Run: [amd_dc_opt] "C:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe"


    O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe


    O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit


    O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"


    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE


    O4 - HKLM\..\Run: [CameraFixer] C:\WINDOWS\CameraFixer.exe


    O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe


    O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe


    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background


    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet


    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe


    O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized


    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1


    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe


    O4 - Global Startup: Finestra di stato di Canon LBP-800.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE


    O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe


    O4 - Global Startup: RaConfig2500.lnk = C:\Program Files\RALINK\RT2500 USB Wireless LAN Card\Installer\WINXP\RaConfig2500.exe


    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\OFFICE11\EXCEL.EXE/3000


    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll


    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll


    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll


    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll


    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\OFFICE11\REFIEBAR.DLL


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll


    O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta...staller_gmn.cab


    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll


    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab


    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll


    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\Skype4COM.dll


    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe


    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe


    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)


    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)


    O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe


    O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)


    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe


    O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)


    O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe


    O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe


    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


    O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe


    O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007\Win32\RpcDataSrv.exe


    O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007\RpcSandraSrv.exe


    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindService.exe


    Aussi une autre question en parallèle : comment lancer une analyse avec Avast au démarrage du pc ? je l'ai déjà fait mais ne me souvient plus comment...

  • Salut,


    Tu veux lancer Avast à chaque fois que tu démarreras ton PC?


    Vas sur le site http://virusscan.jotti.org/


    - Clic en haut à droite sur "Parcourir", navigue dans les dossiers et sélectionne ce fichier : C:\WINDOWS\CameraFixer.exe


    - Clic sur submit toujours en haut à droite


    - Le scan va se lancer, ça va prendre un petit instant


    - En bas, tu as le résultat du scan, copie/colle le résultat complet du scan ici.


    Aide : http://www.malekal.com/scan_Av_en_ligne.html#mozTocId662799


    A+