[Virus] Infecté par win32/Backterra,alcan...
Résolusalwa5 -
j'ai biensur Ad-Awar SE, Spybot, etrust EZAntivirus, CCleaner!
En faisant un scan avec Ad-Awar, mon antivirus me marque que je suis infecter par 9 elements,
Win32/Backterra.G
" " /Backterra.E
" " /Backterra.F
" "/Alcan.J
" "/Boxed.BZ
Je c'est pas si cela es grave, mais j'ai remarquer parfois des ralentissements du pc et ce qui m inquiete c'est que lors du scan, cela s'affiche!
Si quelqu'un peut m'aider se serait sympa
Merci a tous
- [Virus] Infecté par win32/Backterra,alcan...
- Virus mcafee - Accueil - Piratage
- Comment détruire un virus informatique - Guide
- Impossible de terminer l'opération car le fichier contient un virus - Forum Virus
- Powershell.exe virus - Guide
- Filezilla virus ✓ - Forum Virus
55 réponses
- 1
- 2
- 3
Détection d'infections sur Windows XP Pro SP1 lors d’un balayage antivirus, les alertes Win32/Backterra et d’autres variantes coexistent avec des ralentissements du système. Plusieurs éléments de réponse essentiels préconisent de localiser les fichiers infectés et d’abord désactiver la restauration système, puis refaire un scan avec Bitdefender et joindre le rapport et un log HijackThis. En cas de détection, il est conseillé d’examiner le chemin contourné par l’infection, puis d’utiliser les outils en ligne comme Kaspersky pour générer un rapport détaillé et corroborer le diagnostic. D'autres conseils mentionnent aussi l'utilisation de CCleaner et la défragmentation du disque comme mesures complémentaires, mais elles ne remplacent pas une suppression et une vérification approfondies des éléments détectés.
scanne ton Pc avec ce log :
ewido (gratuit même après la période d’essai)
Téléchargement :
http://perso.orange.fr/entraide-hijackthis/Ewido/
Cliques sur « update » fais les mise à jour ensuite clique sur « scanner » puis sur « complete scan system ».
Tuto pour la version 4 d’Ewido :
https://www.malekal.com/tutorial-et-guide-ewido-v4/
n'oublie pas de le mettre à jour comme indiqué et "delete" tout ce qu'il te trouve
copie/colle le rapport.
A+
Je te joint le rapport.
Mais comment je doit faire pour delete tous ce qu'il trouve?Il m'a marquer egalement mettre en quarantaine 2 fichiers...je fais quoi?
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 20:52:17 30/09/2006
+ Scan result:
C:\WINDOWS\system32\nvsvcd.exe -> Downloader.Zlob : No action taken.
C:\WINDOWS\system\smss.exe -> Proxy.Horst.bq : No action taken.
:mozilla.18:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.19:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.108:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.59:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.60:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.61:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.97:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.98:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.184:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.185:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.186:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.22:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.64:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
:mozilla.99:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
:mozilla.147:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Comclick : No action taken.
:mozilla.148:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Comclick : No action taken.
:mozilla.149:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Comclick : No action taken.
:mozilla.25:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.127:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Estat : No action taken.
:mozilla.187:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.188:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.162:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.174:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.42:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Ivwbox : No action taken.
:mozilla.49:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.50:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.32:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.33:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.34:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.35:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.36:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.14:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.15:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.16:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.17:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.62:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.63:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.23:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Weborama : No action taken.
:mozilla.24:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Weborama : No action taken.
:mozilla.196:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.197:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.161:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
::Report end
Je te joint le rapport.
Mais comment je doit faire pour delete tous ce qu'il trouve?Il m'a marquer egalement mettre en quarantaine 2 fichiers...je fais quoi?
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 20:52:17 30/09/2006
+ Scan result:
C:\WINDOWS\system32\nvsvcd.exe -> Downloader.Zlob : No action taken.
C:\WINDOWS\system\smss.exe -> Proxy.Horst.bq : No action taken.
:mozilla.18:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.19:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.108:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.59:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.60:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.61:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.97:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.98:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.184:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.185:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.186:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.22:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.64:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
:mozilla.99:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
:mozilla.147:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Comclick : No action taken.
:mozilla.148:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Comclick : No action taken.
:mozilla.149:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Comclick : No action taken.
:mozilla.25:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.127:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Estat : No action taken.
:mozilla.187:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.188:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.162:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.174:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.42:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Ivwbox : No action taken.
:mozilla.49:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.50:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.32:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.33:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.34:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.35:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.36:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.14:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.15:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.16:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.17:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.62:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.63:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.23:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Weborama : No action taken.
:mozilla.24:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Weborama : No action taken.
:mozilla.196:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.197:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.161:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
::Report end
refait le scan car tu n'as rien supprimé le no action taken que tu peux voir aussi sur ton rapport signifie que tu as ignoré les M****.
Donc scan à refaire et copie/colle le rapport.
A+
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 00:01:07 01/10/2006
+ Scan result:
C:\WINDOWS\system32\nvsvcd.exe -> Downloader.Zlob : Cleaned with backup (quarantined).
C:\WINDOWS\system\smss.exe -> Proxy.Horst.bq : Cleaned with backup (quarantined).
:mozilla.25:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.26:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.122:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.77:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.78:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.79:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.111:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.112:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.189:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.190:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.191:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.51:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.113:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.82:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.153:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Comclick : Cleaned.
:mozilla.154:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Comclick : Cleaned.
:mozilla.155:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Comclick : Cleaned.
:mozilla.24:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.40:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.135:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Estat : Cleaned.
:mozilla.192:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.193:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.167:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.179:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.68:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Ivwbox : Cleaned.
:mozilla.75:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.76:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.59:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.60:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.61:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.62:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.63:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.41:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.42:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.43:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.44:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.80:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.81:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.52:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.53:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.199:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.200:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.166:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\c3ibi0b2.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
Maintenant ...
télécharge HijackThis (version francaise) ici:
http://telechargement.zebulon.fr/160-Patch-fran%C3%A7ais-pour-HijackThis.html
Dézippe le dans un dossier prévu à cet effet.
Par exemple C:\hijackthis < Enregistre le bien dans c : !
Démo (merci à Balltrap) :
instalation hijackthis
http://pageperso.aol.fr/balltrap34/Hijenr.gif
Lance le puis:
clique sur "faire un scan et sauvegarder le log" (cf démo)
faire un copier coller du log entier sur le forum
Démo : (merci à balltrap34 pour cette réalisation)
http://pageperso.aol.fr/balltrap34/demohijack.htm
A+
Logfile of HijackThis v1.99.1
Scan saved at 10:31:13, on 01/10/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\WINDOWS\System32\PuXpMan.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Hijackthis\hijackthis vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mspwr] C:\WINDOWS\System32\PuXpMan.exe
O4 - HKLM\..\Run: [PwrUpTweakMe] C:\WINDOWS\System32\PuXpTwks.exe /TWEAK
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: text/html - (no CLSID) - (no file)
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O18 - Filter: text/html - (no CLSID) - (no file)
ensuite sur "fix checked"
mets ce services ewido anti-spyware 4.0 guard sur "manuel" enfaisant démarrer ->executer -> tape services.msc double clci dessu et met le sur "manuel".
Dis moi ou en sont tes probs.
A+
Ouvre hijack -> "scanner seulement" coches la ligne ensuite cilque sur "fixer objet.
Referme Hijack.
Et fait l'autre manip.
A+
Pour hijack j'atends une reponse!
Ensuite une fois que je fais ce que tu me dira pour hijack, je fais quoi?
En faite il n'y a pas eu de changement...il me montre la meme chose qu'auparavant
Win32/Backterra.G
" " /Backterra.E
" " /Backterra.F
" "/Alcan.J
" "/Boxed.BZ
Pour vérifier, scanne ton PC avec cet antivirus en ligne (sous IE et accepte l’activX) :
http://www.bitdefender.fr/bd/site/search.php#
Clique sur « scan on line » suis les instructions.
Et colle le rapport
A+
Et pour repondre a ta premiere question, ba en faite lorsque la fenetre d'alerte aparait ba il m'es impossible d'effacer son contenu c'est a dire les 9 problemes...
Tu trouve ca normal?
De plus une fois j'ai effacer ces 9 fichiers d'ou il provenait et puis au redemarage du pc et apres avoir scanner avec AD-Aware ces 9 fichiers sont reapparu :-(
Suspect files = 0
Disinfected files = 0
Deleted files = 17
Copied files = 0
Moved files = 0
Renamed files = 0
I/O Errors = 55
[Scan Settings]
SecondAction = Delete
FirstAction = Disinfect
Heuristics = 1
Enable Warnings = 1
Exclude Ext =
Extensions = *;
Scan Emails = 1
Scan Archives = 1
Scan Packed = 1
Scan Files = 1
Scan Boot = 1
Verify Memory = 0
[Scan Results]
Line00000050 = "C:\Documents and Settings\Administrateur\Mes documents\Mes images\SUPERBE ecrans de veille 3D+CRACKS\Mechanical Clock Screensaver v1.0 Cracked\Crack\Crack - Part 1.exe Infecté par: Trojan.Regpat.A"
Line00000049 = "C:\Documents and Settings\Administrateur\Mes documents\Mes images\SUPERBE ecrans de veille 3D+CRACKS\Mechanical Clock Screensaver v1.0 Cracked\Crack\Crack - Part 1.exe Echec de la désinfection"
Line00000048 = "C:\Documents and Settings\Administrateur\Mes documents\Mes images\SUPERBE ecrans de veille 3D+CRACKS\Mechanical Clock Screensaver v1.0 Cracked\Crack\Crack - Part 1.exe Supprimé"
Line00000047 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001784.exe Infecté par: Win32.Worm.Insta.A"
Line00000046 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001784.exe Echec de la désinfection"
Line00000045 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001784.exe Supprimé"
Line00000044 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001785.exe Infecté par: Win32.Worm.Insta.A"
Line00000043 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001785.exe Echec de la désinfection"
Line00000042 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001785.exe Supprimé"
Line00000041 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001786.exe Infecté par: Win32.Worm.Insta.A"
Line00000040 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001786.exe Echec de la désinfection"
Line00000039 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001786.exe Supprimé"
Line00000038 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001787.exe Infecté par: Win32.Worm.Insta.A"
Line00000037 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001787.exe Echec de la désinfection"
Line00000036 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001787.exe Supprimé"
Line00000035 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001788.exe Infecté par: Win32.Worm.Insta.A"
Line00000034 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001788.exe Echec de la désinfection"
Line00000033 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001788.exe Supprimé"
Line00000032 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001808.exe Infecté par: Trojan.Downloader.Inservice.JZ"
Line00000031 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001808.exe Echec de la désinfection"
Line00000030 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001808.exe Supprimé"
Line00000029 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001810.exe Infecté par: Trojan.Downloader.Agent.BZ"
Line00000028 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001810.exe Echec de la désinfection"
Line00000027 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP26\A0001810.exe Supprimé"
Line00000026 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP40\A0002922.exe Infecté par: Trojan.Downloader.Small.BYY"
Line00000025 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP40\A0002922.exe Echec de la désinfection"
Line00000024 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP40\A0002922.exe Supprimé"
Line00000023 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP40\A0002925.exe Infecté par: Win32.Worm.Insta.A"
Line00000022 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP40\A0002925.exe Echec de la désinfection"
Line00000021 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP40\A0002925.exe Supprimé"
Line00000020 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP40\A0002926.exe Infecté par: Win32.Worm.Insta.A"
Line00000019 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP40\A0002926.exe Echec de la désinfection"
Line00000018 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP40\A0002926.exe Supprimé"
Line00000017 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP40\A0002927.exe Infecté par: Win32.Worm.Insta.A"
Line00000016 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP40\A0002927.exe Echec de la désinfection"
Line00000015 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP40\A0002927.exe Supprimé"
Line00000014 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP40\A0002928.exe Infecté par: Win32.Worm.Insta.A"
Line00000013 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP40\A0002928.exe Echec de la désinfection"
Line00000012 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP40\A0002928.exe Supprimé"
Line00000011 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP76\A0012443.exe Infecté par: Trojan.Proxy.Horst.BQ"
Line00000010 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP76\A0012443.exe Echec de la désinfection"
Line00000009 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP76\A0012443.exe Supprimé"
Line00000008 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP76\A0012444.exe Infecté par: Backdoor.Medbot.BB"
Line00000007 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP76\A0012444.exe Echec de la désinfection"
Line00000006 = "C:\System Volume Information\_restore{E189F090-45B3-4583-8ED3-BAB9189A3DBA}\RP76\A0012444.exe Supprimé"
Line00000005 = "C:\WINDOWS\system32\cheat_plugin.exe Infecté par: Trojan.Downloader.Inservice.JZ"
Line00000004 = "C:\WINDOWS\system32\cheat_plugin.exe Echec de la désinfection"
Line00000003 = "C:\WINDOWS\system32\cheat_plugin.exe Supprimé"
Line00000002 = "C:\WINDOWS\system32\expIorer.exe Infecté par: Trojan.Downloader.Agent.BZ"
Line00000001 = "C:\WINDOWS\system32\expIorer.exe Echec de la désinfection"
Line00000000 = "C:\WINDOWS\system32\expIorer.exe Supprimé"
- 1
- 2
- 3