Virus MSN album photo

Résolu
Bonjour,

hier comme beaucoup apparemment j'ai reçu le virus...pas très malin je l'avoue...et j'aurais bien besoin d'aide.

J'ai tout d'abord supprimé le fichier téléchargé, et j'ai fait un scan avec MSNFix, j'ai vu qu'une copie du fichier était dans le dossier Windows, je suis donc allé la supprimé aussi.

Ensuite ça semblait être bon, je crois que je n'envoyais plus de messages à mes contacts, mais ce soir ça à l'air de recommencer, donc j'ai refait un scan avec MSNFix, et j'ai eu ce rapport :

MSN_Fix 1.312

C:\Documents and Settings\Chris\Bureau\MSNFix
Fix exécuté le 03/06/2007 - 22:12:49,73 By Chris
mode normal

************************ Recherche les fichiers présents

Aucun Fichier trouvé

************************ Recherche les dossiers présents

Aucun dossier trouvé

************************ Fichiers suspects

/!\ ces fichiers nécessitent un avis expérimenté avant toute intervention

------------------------------------------------------------------------
Auteur : !aur3n7 Contact: https://www.aceboard.fr/
------------------------------------------------------------------------

--------------------------------------------- END ---------------------------------------------

Il n'a pas l'air de trouver quoi que ce soit, donc j'ai fait un sac avec Hikackthis qui a fait ce rapport :

Logfile of HijackThis v1.99.1
Scan saved at 21:53:21, on 03/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Hijackthis\Scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: syshosts - {090D5D99-DDB9-43A2-9815-E6CAAC47A6C6} - syshosts.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

Voila, si vous pouviez m'aider, car c'est un peu chiant...désolé de vous prendre du temps.

Et sinon, est-ce normal que ça ait marché à nouveau correctement pendant un jour et que ça recommence à nouveau? C'est pile 24h après ou environ que ça a recommencé à envoyer des messages.

Merci beaucoup,
Chris
Configuration: Windows XP
Internet Explorer 7.0

11 réponses

  1. Contributeur sécurité
    Salut,

    Télécharge ceci (clique droit sur le lien < enregistrer sous)
    https://www.silentrunners.org/Silent%20Runners.vbs
    Exécute le, attends quelques minutes, il va créer ensuite un dossier juste a coté de Silent runner sous format texte, copie/colle le rapport.

    A+
    0
    1. Contributeur sécurité
      Bonsoir,

      Regis59, sa version de MSNFix est obsolète.
      @+
      0
      1. Bonjour,

        Déjà merci de m'aider!!! Et désolé de tarder à répondre mais je n'étais pas chez moi aujourd'hui.

        J'ai lancé Silent Runners, par contre ça n'a pas mis quelques minutes comme tu me l'avais dit mais seulement quelques secondes, alors est-ce que c'est normal ou bien est-ce que ça n'a fait qu'une partie des tests? Enfin voilà ce qu'il m'a trouvé :

        "Silent Runners.vbs", revision R50, https://www.silentrunners.org/
        Operating System: Windows XP SP2
        Output limited to non-default values, except where indicated by "{++}"

        Startup items buried in registry:
        ---------------------------------

        HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
        "CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
        "swg" = "C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" ["Google Inc."]
        "MsnMsgr" = ""C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background" [MS]
        "MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]

        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
        "High Definition Audio Property Page Shortcut" = "HDAShCut.exe" ["Windows (R) Server 2003 DDK provider"]
        "SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0\bin\jusched.exe" ["Sun Microsystems, Inc."]
        "RaidTool" = "C:\Program Files\VIA\RAID\raid_tool.exe" ["VIA Technologies"]
        "NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup" [MS]
        "nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]
        "SoundMan" = "SOUNDMAN.EXE" ["Realtek Semiconductor Corp."]
        "AlcWzrd" = "ALCWZRD.EXE" ["RealTek Semicoductor Corp."]
        "Alcmtr" = "ALCMTR.EXE" ["Realtek Semiconductor Corp."]
        "SMSERIAL" = "sm56hlpr.exe" ["Motorola Inc."]
        "SynTPLpr" = "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" ["Synaptics, Inc."]
        "SynTPEnh" = "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" ["Synaptics, Inc."]
        "avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" ["ALWIL Software"]

        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
        {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
        -> {HKLM...CLSID} = "Google Toolbar Helper"
        \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

        HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
        "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
        -> {HKLM...CLSID} = "Extension Affichage Panorama du Panneau de configuration"
        \InProcServer32\(Default) = "deskpan.dll" [file not found]
        "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
        -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
        \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
        "{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
        -> {HKLM...CLSID} = "DesktopContext Class"
        \InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]
        "{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
        -> {HKLM...CLSID} = "NVIDIA CPL Extension"
        \InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]
        "{2F603045-309F-11CF-9774-0020AFD0CFF6}" = "Synaptics Control Panel"
        -> {HKLM...CLSID} = (no title provided)
        \InProcServer32\(Default) = "C:\Program Files\Synaptics\SynTP\SynTPCpl.dll" ["Synaptics, Inc."]
        "{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
        -> {HKLM...CLSID} = "Desktop Explorer"
        \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
        "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
        -> {HKLM...CLSID} = (no title provided)
        \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
        "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
        -> {HKLM...CLSID} = "nView Desktop Context Menu"
        \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
        "{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
        -> {HKLM...CLSID} = "avast"
        \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
        "{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
        -> {HKLM...CLSID} = "Mes dossiers de partage"
        \InProcServer32\(Default) = "C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll" [MS]

        HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
        "syshosts" = "{090D5D99-DDB9-43A2-9815-E6CAAC47A6C6}"
        -> {HKLM...CLSID} = (no title provided)
        \InProcServer32\(Default) = "syshosts.dll" [null data]

        HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
        avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
        -> {HKLM...CLSID} = "avast"
        \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

        HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
        avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
        -> {HKLM...CLSID} = "avast"
        \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

        Group Policies {policy setting}:
        --------------------------------

        Note: detected settings may not have any effect.

        HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

        "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
        {Shutdown: Allow system to be shut down without having to log on}

        "undockwithoutlogon" = (REG_DWORD) hex:0x00000001
        {Devices: Allow undock without having to log on}

        Active Desktop and Wallpaper:
        -----------------------------

        Active Desktop may be disabled at this entry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

        Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
        HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
        "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

        Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
        HKCU\Control Panel\Desktop\
        "Wallpaper" = "C:\Documents and Settings\Chris\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

        Enabled Screen Saver:
        ---------------------

        HKCU\Control Panel\Desktop\
        "SCRNSAVE.EXE" = "C:\WINDOWS\system32\logon.scr" [MS]

        Winsock2 Service Provider DLLs:
        -------------------------------

        Namespace Service Providers

        HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
        000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
        000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
        000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

        Transport Service Providers

        HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
        0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
        %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15
        %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05

        Toolbars, Explorer Bars, Extensions:
        ------------------------------------

        Toolbars

        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
        "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
        -> {HKLM...CLSID} = "&Google"
        \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

        HKLM\Software\Microsoft\Internet Explorer\Toolbar\
        "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
        -> {HKLM...CLSID} = "&Google"
        \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

        Extensions (Tools menu items, main toolbar menu buttons)

        HKLM\Software\Microsoft\Internet Explorer\Extensions\
        {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
        "MenuText" = "Console Java (Sun)"
        "CLSIDExtension" = "{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}"
        -> {HKLM...CLSID} = "Java Plug-in 1.5.0"
        \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll" ["Sun Microsystems, Inc."]

        {E2E2DD38-D088-4134-82B7-F2BA38496583}\
        "MenuText" = "@xpsp3res.dll,-20001"
        "Exec" = "%windir%\Network Diagnostic\xpnetdiag.exe" [MS]

        {FB5F1910-F110-11D2-BB9E-00C04F795683}\
        "ButtonText" = "Messenger"
        "MenuText" = "Windows Messenger"
        "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]

        Running Services (Display Name, Service Name, Path {Service DLL}):
        ------------------------------------------------------------------

        avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast4\ashServ.exe"" ["ALWIL Software"]
        avast! iAVS4 Control Service, aswUpdSv, ""C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" ["ALWIL Software"]
        avast! Mail Scanner, avast! Mail Scanner, ""C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service" ["ALWIL Software"]
        avast! Web Scanner, avast! Web Scanner, ""C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"]
        NVIDIA Display Driver Service, NVSvc, "C:\WINDOWS\system32\nvsvc32.exe" ["NVIDIA Corporation"]
        Service Messenger Sharing Folders USN Journal Reader, usnjsvc, ""C:\Program Files\MSN Messenger\usnsvc.exe"" [MS]

        ----------
        + This report excludes default entries except where indicated.
        + To see *everywhere* the script checks and *everything* it finds,
        launch it from a command prompt or a shortcut with the -all parameter.
        + To search all directories of local fixed drives for DESKTOP.INI
        DLL launch points, use the -supp parameter or answer "No" at the
        first message box and "Yes" at the second message box.
        ---------- (total run time: 29 seconds, including 13 seconds for message boxes)

        PS : Lyonnais92 tu dis que ma version de MSNFix est obsolète, pourtant j'ai trouvé le lien sur une autre discussion sur ce forum, et il était conseillé de l'utiliser. Faut-il que je trouve un autre lien pour ce même logiciel ou bien que j'en utilise un autre en plus de Silent Runners que je viens de lancer?

        Merci encore,
        Chris
        0
        1. Contributeur sécurité
          Re,

          Téléchargez MSNFix.zip (de !aur3n7) sur votre bureau:
          http://sosvirus.changelog.fr/MSNFix.zip

          Décompressez-le (clic droit >> Extraire ici) et double cliquer sur le fichier MSNFix.bat.
          - Exécutez l'option R.
          -- Si l'infection est détectée, un message l'indiquera et il suffira de presser une touche pour lancer le nettoyage

          Note :
          Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal

          - Le rapport sera enregistré dans le même dossier que MSNFix sous forme date_heure.txt

          A+
          0
          1. Salut,

            C'est compliqué oh :p Merci Regis59!!

            J'ai retéléchargé MSNFix avec ton lien, j'ai lancé l'option R et j'ai lancé le nettoyage comme tu disais et voici le rapport :

            MSN_Fix 1.315

            C:\Documents and Settings\Chris\Bureau\MSNFix\MSNFix
            Fix exécuté le 04/06/2007 - 22:41:23,82 By Chris
            mode normal

            ************************ Recherche les fichiers présents

            ... C:\WINDOWS\system32\nbtstat.exe
            ... C:\WINDOWS\system32\syshosts.dll

            ************************ Recherche les dossiers présents

            Aucun dossier trouvé

            ************************ Suppression des fichiers

            .. OK ... C:\WINDOWS\system32\nbtstat.exe
            .. OK ... C:\WINDOWS\system32\syshosts.dll

            ************************ Nettoyage du registre
            .......... OK

            ************************ Fichiers suspects

            /!\ ces fichiers nécessitent un avis expérimenté avant toute intervention

            Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 04062007_22415087.zip

            ------------------------------------------------------------------------
            Auteur : !aur3n7 Contact: https://www.aceboard.fr/
            ------------------------------------------------------------------------

            --------------------------------------------- END ---------------------------------------------

            Tu penses que le problème est résolu ou pas?

            Merci encore :D
            Toujours Chris
            0
            1. Au fait...le virus infecte le pc, pas la session MSN si?
              0
              1. Contributeur sécurité
                Salut

                Oui le PC.
                As tu encore des problemes sur MSN?

                Remet moi également un Hijackthis.

                A+
                0
                1. Salut!!

                  Ben ça à l'air de marcher normalement :D Merci!!

                  Mais bon ça fait deux fois que je crois être sorti d'affaire ^^

                  J'ai fait un Hikackthis, ça me trouve ça :

                  Logfile of HijackThis v1.99.1
                  Scan saved at 22:40:51, on 05/06/2007
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16441)

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                  C:\Program Files\VIA\RAID\raid_tool.exe
                  C:\WINDOWS\SOUNDMAN.EXE
                  C:\WINDOWS\sm56hlpr.exe
                  C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                  C:\Program Files\MSN Messenger\MsnMsgr.Exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\Program Files\MSN Messenger\usnsvc.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Hijackthis\Scanner.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.01net.com/telecharger/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                  O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                  O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                  O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
                  O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                  O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
                  O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O11 - Options group: [INTERNATIONAL] International*
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                  O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                  O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                  O21 - SSODL: syshosts - {090D5D99-DDB9-43A2-9815-E6CAAC47A6C6} - syshosts.dll (file missing)
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                  O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

                  C'est réglé cette fois alors?

                  Mici,
                  a+
                  0
                  1. Contributeur sécurité
                    Re

                    ¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

                    O21 - SSODL: syshosts - {090D5D99-DDB9-43A2-9815-E6CAAC47A6C6} - syshosts.dll (file missing)

                    Ferme hijackthis

                    Redemarre ton pc et dis moi si elle a bien disparu de Hijackthis stp

                    Sinon, pour ta protection installe un firewall !

                    A+
                    0
                    1. Salut Regis,

                      Pour ma protection, j'ai avast, ça ne suffit pas? Sinon j'ai vu sur la page d'accueil de CCC qu'ils conseillaient Zone Alarm, mais j'ai aussi vu qu'il y avait des problèmes de compatibilité avec Avast...qu'il fallait entre autre désactiver la protection des mails de ZA ou Avast (apparement il vaut mieux désactiver celui de ZA, si je l'installe j'essaierai de trouver comment faire.) Alors tu me conseilles quoi? Je ne garde qu'Avast? Je mets ZA? Ou j'installe un aute logiciel?

                      Sinon j'ai fait ce que tu m'as dit, et non la ligne n'y est plus, je te remet le scan quand même :

                      Logfile of HijackThis v1.99.1
                      Scan saved at 16:07:37, on 07/06/2007
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16441)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
                      C:\Program Files\VIA\RAID\raid_tool.exe
                      C:\WINDOWS\SOUNDMAN.EXE
                      C:\WINDOWS\sm56hlpr.exe
                      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                      C:\Program Files\MSN Messenger\MsnMsgr.Exe
                      C:\Program Files\MSN Messenger\usnsvc.exe
                      C:\Hijackthis\Scanner.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                      O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
                      O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                      O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
                      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                      O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
                      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O11 - Options group: [INTERNATIONAL] International*
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

                      Merciiii, tu mérites plein de bisous ^^
                      0
                      1. Contributeur sécurité
                        Re

                        Il te faut absolument un pare feu, donc si tu ne veux pas mettre ZA, met Kério ou autre ;)

                        A+
                        0