infection par win32:Horst trop Galère ! - Sécurité - Windows & Software
Marsh Posté le 16-08-2006 à 08:25:44
as tu essaye le virus sweeper telechargeable sur le site d'avast, et de faire tourner ca en safe mode?? 
Marsh Posté le 17-08-2006 à 19:59:25
Bonjour, 
 
telecharge la version original de hijackthis http://www.merijn.org/files/hijackthis.zip 
 
déconnecte toi du net et installe le. 
 
lance le en cliquant sur Do a system scan and save a logfile  a la fin du scan le bloc note va s'ouvrir tu fais un copier coller de tout son contenu.
Marsh Posté le 11-10-2006 à 15:19:35
Salut,  j'ai le même probleme. pareil, une vingtaine de spam, des alertes avast de trojan Win32:Horst toutes les 10 minutes,... 
 
J'ai scanné mon pc avec spybot et ad-aware, il ont les deux trouvé pas mal de saloperies, et ont tout supprimé, mais j'ai toujours ce problème...  
  
 
Aidez-nous svp ![]()
Marsh Posté le 11-10-2006 à 15:22:20
voila le log de hijackthis : 
 
Logfile of HijackThis v1.99.1 
Scan saved at 15:20:32, on 11/10/2006 
Platform: Windows XP SP2 (WinNT 5.01.2600) 
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) 
 
Running processes: 
C:\WINDOWS\System32\smss.exe 
C:\WINDOWS\system32\winlogon.exe 
C:\WINDOWS\system32\services.exe 
C:\WINDOWS\system32\lsass.exe 
C:\WINDOWS\system32\svchost.exe 
C:\WINDOWS\System32\svchost.exe 
C:\WINDOWS\system32\spoolsv.exe 
C:\WINDOWS\Explorer.EXE 
C:\WINDOWS\SOUNDMAN.EXE 
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe 
C:\Program Files\D-Tools\daemon.exe 
C:\Acer\Empowering Technology\eRecovery\Monitor.exe 
C:\PROGRA~1\HDTune\HDTune.exe 
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe 
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe 
C:\Program Files\MessengerPlus! 3\MsgPlus.exe 
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe 
C:\WINDOWS\system32\svchost.exe 
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe 
C:\WINDOWS\system32\RUNDLL32.EXE 
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe 
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe 
C:\Program Files\MSN Messenger\msnmsgr.exe 
C:\Program Files\Shareaza\Shareaza.exe 
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe 
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe 
C:\Corel\Graphics8\Programs\MFIndexer.exe 
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe 
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe 
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe 
C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe 
C:\Program Files\Logitech\SetPoint\KEM.exe 
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE 
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 
C:\Program Files\Pixoria\Konfabulator\YahooWidgetEngine.exe 
C:\Program Files\Alwil Software\Avast4\ashServ.exe 
C:\wamp\wampserver.exe 
C:\WINDOWS\system32\drivers\CDAC11BA.EXE 
C:\WINDOWS\system32\CTsvcCDA.exe 
C:\Program Files\TechSmith\SnagIt 8\TSCHelp.exe 
C:\Program Files\Pixoria\Konfabulator\YahooWidgetEngine.exe 
C:\Program Files\Pixoria\Konfabulator\YahooWidgetEngine.exe 
C:\Program Files\Pixoria\Konfabulator\YahooWidgetEngine.exe 
C:\Program Files\Pixoria\Konfabulator\YahooWidgetEngine.exe 
C:\WINDOWS\system32\nvsvc32.exe 
C:\WINDOWS\system32\svchost.exe 
c:\wamp\apache2\bin\Apache.exe 
c:\wamp\mysql\bin\mysqld-nt.exe 
C:\wamp\apache2\bin\Apache.exe 
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 
C:\Documents and Settings\Pascal Heitz\Mes documents\HijackThis.exe 
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com 
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens 
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.smart-positron.com/" ); (C:\Documents and Settings\Pascal Heitz\Application Data\Mozilla\Profiles\default\93tdmi9b.slt\prefs.js) 
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CNetscape_France.src" ); (C:\Documents and Settings\Pascal Heitz\Application Data\Mozilla\Profiles\default\93tdmi9b.slt\prefs.js) 
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll 
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll 
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll 
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll 
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll 
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll 
O4 - HKLM\..\Run: [LaunchApp] Alaunch 
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE 
O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe 
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC 
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC 
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName 
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup 
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install 
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe 
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe 
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033 
O4 - HKLM\..\Run: [HD Tune] C:\PROGRA~1\HDTune\HDTune.exe 
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe"  -osboot 
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime 
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs 
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe 
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" 
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause 
O4 - HKLM\..\Run: [.nvsvc] C:\WINDOWS\system\smss.exe /w 
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup 
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" 
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon 
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit 
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.1] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash 
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background 
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R 
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe 
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Pixoria\Konfabulator\YahooWidgetEngine.exe 
O4 - Startup: WampServer.lnk = C:\wamp\wampserver.exe 
O4 - Global Startup: Corel MEDIA FOLDERS INDEXER 8.LNK = C:\Corel\Graphics8\Programs\MFIndexer.exe 
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe 
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE 
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe 
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe 
O4 - Global Startup: SnagIt 8.lnk = C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe 
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe 
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe 
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html 
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html 
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html 
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html 
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll 
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll 
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b31267.cab 
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab 
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b31267.cab 
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab 
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/ [...] loader.cab 
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/bina [...] b32846.cab 
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/bina [...] b31267.cab 
O18 - Protocol: bw+0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw+0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw-0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw-0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw00 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw00s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw10 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw10s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw20 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw20s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw30 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw30s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw40 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw40s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw50 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw50s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw60 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw60s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw70 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw70s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw80 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw80s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw90 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bw90s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwa0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwa0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwb0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwb0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwc0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwc0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwd0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwd0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwe0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwe0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwf0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwf0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll 
O18 - Protocol: bwg0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwg0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwh0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwh0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwi0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwi0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwj0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwj0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwk0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwk0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwl0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwl0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwm0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwm0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwn0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwn0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwo0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwo0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwp0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwp0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwq0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwq0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwr0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwr0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bws0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bws0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwt0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwt0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwu0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwu0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwv0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwv0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bww0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bww0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwx0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwx0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwy0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwy0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwz0 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: bwz0s - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) 
O18 - Protocol: offline-8876480 - {336D0A39-98C5-4CE3-9954-C4DD9C19DB93} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll 
O20 - AppInit_DLLs: MsgPlusLoader.dll C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL 
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll 
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe 
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) 
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) 
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe 
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE 
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe 
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe 
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing) 
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe 
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe 
O23 - Service: wampapache - Unknown owner - c:\wamp\apache2\bin\Apache.exe" -k runservice (file missing) 
O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe 
 
si ca peut t'aider ![]()
Marsh Posté le 11-10-2006 à 16:39:58
Bonjour 
 
$$ Télécharge 
 SDFix sur ton bureau  
http://downloads.andymanchesta.com [...] /SDFix.zip  
 
 clean.zip  
http://www.malekal.com/download/clean.zip  
Décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier clean.  
 
$$ Redémarre en mode sans échec. 
 
$$ Ouvre le dossier Clean qui se trouve sur ton bureau, et double-clic sur clean.cmd. 
Une fenêtre noire va apparaître pendant un instant, laisse la ouverte.  
 
$$ Fais un clic droit sur SDFix.zip et choisis "Extraire tout"  
Double-clique sur RunThis.bat  
Tape Y pour lancer le script.  
Le Fix supprime les services du virus et nettoie le registre, de ce fait un redémarrage est nécessaire  
Presse une touche pour redémarrer  
Le PC va mettre du temps avant de démarrer, presse une touche lorsque "Finished" s'affiche  
 
Ouvre le dossier SDFix et copie/colle ici le contenu du fichier "Report.txt" avec le rapport qui se trouve ici  
 
C:\rapport_clean.txt  et un nouveau HijackThis.
Marsh Posté le 12-10-2006 à 20:02:46
Voila  
  
 
Report.txt 
 
| Citation : SDFix: Version 1.28   | 
 
 
C:\rapport_clean.txt 
| Citation : Script clean par Malekal_morte - http://www.malekal.com    | 
 
 
Hijackthis : 
| Citation : Logfile of HijackThis v1.99.1   | 
Marsh Posté le 12-10-2006 à 21:33:31
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray 
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart  
 
Commence par supprimer ça ... ![]()
Marsh Posté le 13-10-2006 à 06:42:56
Pourquoi donc ? Shareaza démarre a chaque démarrage, par contre emule est désinstallé, ca m'étonne qu'il soit toujours la... 
 
Hum ca sert à quoi de supprimer ca dans un rapport en plus. ca va pas changer le fonctionnement de mon ordi ! 
 
Bon maintenant j'ai un nouveau probleme : a chaque démarrage, j'ai cette erreur : explorer.exe a rencontré un probleme et doit fermer. 
 
Bordel quand ya un virus en moins yen a un nouveau !
Marsh Posté le 13-10-2006 à 06:44:27
| freds45 a écrit : O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray   | 
 
 
Ah c'est pour le "politiquement correct"  
 
Marsh Posté le 13-10-2006 à 08:12:16
| Citation :    | 
 
cf les règles du forum. 
Ya pas longtemps, les topics dans le genre de celui ci avec du P2P, étaient fermés.
Marsh Posté le 13-10-2006 à 22:06:16
freds45 a écrit :
    | 
 
 
Okok je respecte  
  
 
hum est-ce utile d'ouvrir un nouveau topic pour dire que "explorer a rencontré un probleme et doit fermer" apparait a chaque démarrage ?  
 
Marsh Posté le 14-10-2006 à 00:23:06
 
 
logiciel BPS Spyware Remover, desinfecte tout sans se prendre la tete. 
 
payant malheureusement mais tres efficace ![]()
Marsh Posté le 14-10-2006 à 03:12:55
| yves53 a écrit : logiciel BPS Spyware Remover, desinfecte tout sans se prendre la tete.  | 
 
 
c'est de la merde ce soft laisse béton 
 
Marsh Posté le 14-10-2006 à 10:37:13
Bah je vais suivre eZula, n'ayant pas le portefeuille très gras... ^^
Marsh Posté le 16-08-2006 à 00:22:09
J'arrive pas a me debarasser de ce virus dont voici les caractéristiques:
J'avais le pare feu windows+avast
_Pare-feu desactivé a chaque redemarrage
_Envoi massif de mails avec je ne sais quel moteur a je ne sais quel destinataire (outlook et outlook express sont désinstallés de mon pc)
_Modification du c:/windows/system32/svchost.exe (le svchost.exe d un autre PC sain avec le meme os n est pas de taille identique)
_Fichiers .temp infectés dans c:/documents and settings/local settings/temp/
_Avast detecte les .temp infectés il les efface mais ne trouve rien d autre meme en plannifiant un scan au demarrage
J'ai desinstallé avast j'ai installé une version d evaluation de 30 jours de kapersky
Meme chose avec kaspersky il trouve ancun virus horsmis les .temp qu il efface et dans la protection mail on voit des centaine de mails qui defilent
Si quelqu un a le meme probleme et s en est debarrassé merci de m en informer
Message édité par gueno le 16-08-2006 à 00:54:48
---------------
L'utopie ce n'est pas l'irréalisable mais l'irréalisé