KYDO
-
13 oct. 2006 à 18:17
Séb08
Messages postés16503Date d'inscriptiondimanche 13 novembre 2005StatutContributeurDernière intervention17 février 2023
-
14 oct. 2006 à 18:05
Bonjour,
j'ai le virus win32.myzor... sur ma machine. j'ai suivi les premières étapes d'une réponse sur le forum. voic donc le rapport de hijackthis, puis de ewido et enfin de bidefender.
Merci pour votre aide
Logfile of HijackThis v1.99.1
Scan saved at 17:57:23, on 13/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
HKLM\SOFTWARE\Classes\CLSID\{479fd0cf-5be9-4c63-8cda-b6d371c67bd5} -> Adware.Generic : No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{479fd0cf-5be9-4c63-8cda-b6d371c67bd5} -> Adware.Generic : No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Security Add-On -> Adware.Generic : No action taken.
HKU\S-1-5-21-2787369945-1776269519-765011511-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{479FD0CF-5BE9-4C63-8CDA-B6D371C67BD5} -> Adware.Generic : No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Security Plugin 2006 -> Adware.IntCodec : No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03 -> Adware.IntCodec : No action taken.
HKU\S-1-5-21-2787369945-1776269519-765011511-1006\Software\Internet Security -> Adware.IntCodec : No action taken.
C:\Documents and Settings\Samuel\Application Data\winantiviruspro2006freeinstall_fr[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\Documents and Settings\Samuel\Local Settings\Temp\laf10.tmp -> Not-A-Virus.Hoax.Win32.Renos.dv : No action taken.
C:\Documents and Settings\Samuel\Cookies\samuel@247realmedia[2].txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.14:C:\Documents and Settings\Roxana\Application Data\Mozilla\Firefox\Profiles\p07ha9lh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@ad.adnet[1].txt -> TrackingCookie.Adnet : No action taken.
:mozilla.17:C:\Documents and Settings\Roxana\Application Data\Mozilla\Firefox\Profiles\p07ha9lh.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.18:C:\Documents and Settings\Roxana\Application Data\Mozilla\Firefox\Profiles\p07ha9lh.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.7:C:\Documents and Settings\Samuel\Application Data\Mozilla\Firefox\Profiles\83qgltf0.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.8:C:\Documents and Settings\Samuel\Application Data\Mozilla\Firefox\Profiles\83qgltf0.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
:mozilla.20:C:\Documents and Settings\Roxana\Application Data\Mozilla\Firefox\Profiles\p07ha9lh.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@atdmt[1].txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.16:C:\Documents and Settings\Roxana\Application Data\Mozilla\Firefox\Profiles\p07ha9lh.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@bluestreak[2].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\Samuel\Cookies\samuel@bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@promo.casinotropez[1].txt -> TrackingCookie.Casinotropez : No action taken.
:mozilla.55:C:\Documents and Settings\Samuel\Application Data\Mozilla\Firefox\Profiles\83qgltf0.default\cookies.txt -> TrackingCookie.Comclick : No action taken.
:mozilla.56:C:\Documents and Settings\Samuel\Application Data\Mozilla\Firefox\Profiles\83qgltf0.default\cookies.txt -> TrackingCookie.Comclick : No action taken.
:mozilla.57:C:\Documents and Settings\Samuel\Application Data\Mozilla\Firefox\Profiles\83qgltf0.default\cookies.txt -> TrackingCookie.Comclick : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : No action taken.
:mozilla.12:C:\Documents and Settings\Roxana\Application Data\Mozilla\Firefox\Profiles\p07ha9lh.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Samuel\Cookies\samuel@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.20:C:\Documents and Settings\Samuel\Application Data\Mozilla\Firefox\Profiles\83qgltf0.default\cookies.txt -> TrackingCookie.Estat : No action taken.
:mozilla.35:C:\Documents and Settings\Roxana\Application Data\Mozilla\Firefox\Profiles\p07ha9lh.default\cookies.txt -> TrackingCookie.Estat : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@estat[1].txt -> TrackingCookie.Estat : No action taken.
:mozilla.61:C:\Documents and Settings\Samuel\Application Data\Mozilla\Firefox\Profiles\83qgltf0.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@ehg-neuftelecom.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@server.iad.liveperson[2].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@ads.pointroll[2].txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.58:C:\Documents and Settings\Samuel\Application Data\Mozilla\Firefox\Profiles\83qgltf0.default\cookies.txt -> TrackingCookie.Sitestat : No action taken.
:mozilla.44:C:\Documents and Settings\Roxana\Application Data\Mozilla\Firefox\Profiles\p07ha9lh.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.45:C:\Documents and Settings\Roxana\Application Data\Mozilla\Firefox\Profiles\p07ha9lh.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.46:C:\Documents and Settings\Roxana\Application Data\Mozilla\Firefox\Profiles\p07ha9lh.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.63:C:\Documents and Settings\Samuel\Application Data\Mozilla\Firefox\Profiles\83qgltf0.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.64:C:\Documents and Settings\Samuel\Application Data\Mozilla\Firefox\Profiles\83qgltf0.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.65:C:\Documents and Settings\Samuel\Application Data\Mozilla\Firefox\Profiles\83qgltf0.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@smartadserver[1].txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.30:C:\Documents and Settings\Roxana\Application Data\Mozilla\Firefox\Profiles\p07ha9lh.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.47:C:\Documents and Settings\Samuel\Application Data\Mozilla\Firefox\Profiles\83qgltf0.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.31:C:\Documents and Settings\Roxana\Application Data\Mozilla\Firefox\Profiles\p07ha9lh.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.9:C:\Documents and Settings\Roxana\Application Data\Mozilla\Firefox\Profiles\p07ha9lh.default\cookies.txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@weborama[1].txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\Roxana\Cookies\roxana@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : No action taken.
:mozilla.51:C:\Documents and Settings\Samuel\Application Data\Mozilla\Firefox\Profiles\83qgltf0.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.52:C:\Documents and Settings\Samuel\Application Data\Mozilla\Firefox\Profiles\83qgltf0.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.53:C:\Documents and Settings\Samuel\Application Data\Mozilla\Firefox\Profiles\83qgltf0.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
C:\Documents and Settings\Samuel\Local Settings\Temp\NI.UWA6PV_0001_N91M2107\setup.exe -> Trojan.Fakealert : No action taken.
Séb08
Messages postés16503Date d'inscriptiondimanche 13 novembre 2005StatutContributeurDernière intervention17 février 20231 430 14 oct. 2006 à 05:13
Désactive ta restauration système (uniquement si tu es sous XP):
Clic droit sur poste de travail puis,
propriété, tu cliques sur onglet restauration système
tu coches la case « désactiver la restauration » et applique
C:\Program Files\MMediaCodec <--- à virer
Ensuite refait un scan Ewido car celui que tu as fait n'a servi à rien ...
Le no action taken que tu peux voir signifie que tu n'as rien nettoyé du tout donc relance le et "delete" (supprime) tout ce qu'il te trouve et colle le rapport.
14 oct. 2006 à 12:20
Je m'étais rendu compte entre-temps que je n'avais rien deleté sur ewido!
voici le nouveau rapport.
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 12:15:11 14/10/2006
+ Scan result:
C:\Documents and Settings\Samuel\Cookies\samuel@247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\Samuel\Cookies\samuel@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Samuel\Cookies\samuel@estat[1].txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\Samuel\Cookies\samuel@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
::Report end
-------------------------------------------------------