Author Topic: Pbm with avast + rapport hijackthis  (Read 2885 times)

0 Members and 1 Guest are viewing this topic.

Laetitia2007

  • Guest
Pbm with avast + rapport hijackthis
« on: January 05, 2007, 05:27:44 PM »
Posté ailleurs le 03 janvier 2007. Je n'ai obtenu aucune aide.
___________________________________________________

(I can try in english but my english is really really bad.... sorry)


Hello

Day before yesterday Avast functioned and even intercepted a virus.
I followed the procedure to eliminate it. No problem.
I turned off the computer towards 21h.
Yesterday morning : I noted that the 2 icons Avast (I and A) were pale, and “A” was "crossed out" (round with a red line).
While passing my mouse above, they disappeared!! I then wanted to launch AVAST via his short cut (start menu) and a window with a small lamp said to me that the way was incorrect to arrive at the program “ashAvast.exe”.
I didn't find the file on my computer!.
I uninstalled AVAST with the 'unistall utility'  proposed on avast.com, then I installed it again. Same problem.




It's the same thing with Spybot. On the desk, the short cuts of Avast and spybot changed :




A scan on line with "trendmicro" antivirus  showed and disinfected “Mitglieder.LX” (the column “disinfected” was ok in any case).
It also found (but not eliminated) some software of hacking (??))

A scan on line with "secuser.com" didn't give anything.
My computer passed under CCleaner (cleaning + errors). If it should be remade I remake it of course.

As for AVG antispyware, he doesn't want to make the update.





What to make?

The restoration system is deactivated.

In waiting of your assistance, I wish you a beautiful year 2007 ----


I post a hijackthis report/ratio below

Configuration: Windows XP

---------------------

Logfile of HijackThis v1.99.1
Scan saved at 21:40:26, on 01/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Calendrier\Cld2000.exe
C:\Program Files\VIA Technologies, Inc\VIA Audio Driver Setup Program\AudioDeck\AudioDeck.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijackthis\hijackthis\bonjour.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netecolo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\WANADOO\SEARCH~1.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Cld2000.exe] C:\Program Files\Calendrier\Cld2000.exe
O4 - Global Startup: AudioDeck.lnk = C:\Program Files\VIA Technologies, Inc\VIA Audio Driver Setup Program\AudioDeck\AudioDeck.exe
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} (PIXACO Drag and Drop upload plugin) - http://www.pixaco.fr/static/download/pixacodndupload.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/...
O16 - DPF: {92E7E45A-D8C8-480E-AF99-176E43997CAA} (Aurigma Image Uploader 3.5 Combo Control) - http://www.pixdiscount.fr/clients/ImageUploader3.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.extrafilm.fr/NET/Import/ImageUploader3.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/574/webolr/OCX/FlashAX.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Unknown owner - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
« Last Edit: January 05, 2007, 06:46:17 PM by Laetitia2007 »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Pbm with avast + rapport hijackthis
« Reply #1 on: January 05, 2007, 09:51:47 PM »
I can try in english but my english is really really bad.... sorry
It's perfect. We can understand you...

I uninstalled AVAST with the 'unistall utility'  proposed on avast.com, then I installed it again. Same problem.
It's better to use the Control Panel > Add/Remove Programs before... anyway, did you use the same folder for installation? Which is it (full path)?
 
Do you have any other antivirus in your computer? Did you have in the past?
The best things in life are free.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Pbm with avast + rapport hijackthis
« Reply #2 on: January 05, 2007, 09:54:09 PM »
The best things in life are free.

Laetitia2007

  • Guest
Re: Pbm with avast + rapport hijackthis
« Reply #3 on: January 06, 2007, 10:05:40 AM »

It's better to use the Control Panel > Add/Remove Programs before

I tried but it asked me for installation ! I didn't understand why, I tried 3 times and I gave up this solution.




... anyway, did you use the same folder for installation? Which is it (full path)?

I removed the folder (setupfre.exe) and I downloaded an other from this page (in french but I show you in english) :
http://www.avast.com/eng/download-avast-home.html

(avast! 4 Home - French version (length 11.65 MB))
 
I even asked another registration key :
http://www.avast.com/i_kat_207.php

(but I couldn't use it because Avast doesn't open)




Do you have any other antivirus in your computer? Did you have in the past?

Today I have 0 antivirus ! It's really dangerous I know, but I don't use my email box, I don't read and open my emails, I only 'surf' on the web and forums.

In the past I had Norton but I removed it (and there is no other "symantec" files in my computer). And Avast was Ok before few days.


I hope you could understand me.

Thank you very much for your help, now I'm going to read the thread.




Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Pbm with avast + rapport hijackthis
« Reply #4 on: January 06, 2007, 03:13:11 PM »
It's better to use the Control Panel > Add/Remove Programs before
I tried but it asked me for installation ! I didn't understand why, I tried 3 times and I gave up this solution.
Ok, you've done the right thing  ;)

... anyway, did you use the same folder for installation? Which is it (full path)?
I removed the folder (setupfre.exe) and I downloaded an other from this page (in french but I show you in english) :
http://www.avast.com/eng/download-avast-home.html
No, I want to know the local path you're installing avast... something like:
C:\Program Files\Alwil Software\Avast4\
 
Do you have any other antivirus in your computer? Did you have in the past?
Today I have 0 antivirus ! It's really dangerous I know, but I don't use my email box, I don't read and open my emails, I only 'surf' on the web and forums.
In the past I had Norton but I removed it (and there is no other "symantec" files in my computer). And Avast was Ok before few days.
Please, follow:
1) Remove NAV through Add/Remove programs from Control Panel. Boot.
2) Use Symantec removal tool following the three steps defined in the SymNRT tool info or here.
3) Boot.
4) Install avast! Boot.
5) See what you get.
The best things in life are free.