[Ordinateur Infecté) Aidez-moi

Fermé
BlodDarn - 1 oct. 2007 à 15:51
BlodDarn Messages postés 196 Date d'inscription mercredi 8 août 2007 Statut Membre Dernière intervention 11 mai 2013 - 8 oct. 2007 à 21:55
Bonjour, j'ai fais un scan avec Panda (Total Scan) et voici son rapport :
Qu'est-ce que je dois faire pour me débarrasser de tous ça !

Scan details
High danger level (0)
Medium danger level (0)
Low danger level (27)

Eicar.Mod Virus Latent Hide + Info
C:\Program Files\Kaspersk...rsonal Pro\eicar_html.vir

Cookie/Doublec... Tracking Cookie Latent Show+ Info
C:\Documents and Settings...ES.TXT[.doubleclick.net/]

Cookie/Bluestr... Tracking Cookie Latent Show + Info
C:\Documents and Settings...IES.TXT[.bluestreak.com/]
C:\Documents and Settings...s\vavie@bluestreak[1].txt

Cookie/Adrevol... Tracking Cookie Latent Show + Info
C:\Documents and Settings...e@media.adrevolver[3].txt

Cookie/DomainS... Tracking Cookie Latent Show + Info
It is not a threat to the security of your PC unless it is run.
C:\Documents and Settings...nding.domainsponsor.com/]

application/fu... Tracking Application Latent Show + Info
HKEY_CURRENT_USER\Softwar...9-499C-A11F-23C360D7C3F8}
HKEY_CURRENT_USER\Softwar...0-46FC-94B8-81276E4E27DF}

Cookie/Atlas D... Tracking Cookie Latent Show + Info
C:\Documents and Settings...\COOKIES.TXT[.atdmt.com/]

Cookie/RealMed... Tracking Cookie Latent Show + Info
C:\Documents and Settings...S.TXT[.247realmedia.com/]

Cookie/Adrevol... Tracking Cookie Latent Show + Info
C:\Documents and Settings...s\vavie@adrevolver[1].txt

application/my... Tracking Application Latent Show + Info
HKEY_CURRENT_USER\Softwar...3-4961-B6BB-170DE4475CCA}
HKEY_CURRENT_USER\Softwar...3-4961-B6BB-170DE4475CCA}
HKEY_CURRENT_USER\Softwar...E-44cf-8957-5838F569A31D}

Cookie/Tribalf... Tracking Cookie Latent Show + Info
C:\Documents and Settings...S.TXT[.tribalfusion.com/]

application/ne... Tracking Application Latent Show + Info
HKEY_CLASSES_ROOT\Interfa...A-416B-BCDB-33B3EF3617D3}

dialer.su Dialer Latent Show + Info
hkey_local_machine\softwa...tversion\uninstall\switch

Cookie/2o7 Tracking Cookie Latent Show + Info
C:\Documents and Settings...\Cookies\vavie@2o7[2].txt

Cookie/Tradedo... Tracking Cookie Latent Show + Info
C:\Documents and Settings...vavie@tradedoubler[1].txt

Cookie/Weboram... Tracking Cookie Latent Show + Info
C:\Documents and Settings...ies\vavie@weborama[2].txt

Cookie/Overtur... Tracking Cookie Latent Show + Info
C:\Documents and Settings...OKIES.TXT[.overture.com/]

Cookie/Zedo Tracking Cookie Latent Show + Info
C:\Documents and Settings...Cookies\vavie@zedo[2].txt

W32/Nuwar.C.worm Virus Latent Show + Info
C:\System Volume Informat...549CA}\RP352\A0071086.EXE

Generic Malware Virus Latent Show + Info
C:\Documents and Settings...\NOD32.FiX.v1.9-nsane.exe

Cookie/Adtech Tracking Cookie Latent Show + Info
C:\Documents and Settings...okies\vavie@adtech[1].txt
C:\Documents and Settings...\COOKIES.TXT[.adtech.de/]

Cookie/Smartad... Tracking Cookie Latent Show + Info
C:\Documents and Settings...avie@smartadserver[2].txt
C:\Documents and Settings...veig@smartadserver[1].txt
C:\Documents and Settings....TXT[.smartadserver.com/]

Cookie/Statcou... Tracking Cookie Latent Show + Info
C:\Documents and Settings...ES.TXT[.statcounter.com/]

Cookie/BurstNe... Tracking Cookie Latent Show + Info
C:\Documents and Settings...OKIES.TXT[.burstnet.com/]

Cookie/Mediapl... Tracking Cookie Latent Show + Info
C:\Documents and Settings...KIES.TXT[.mediaplex.com/]

Cookie/Aspinal... Tracking Cookie Latent Show + Info
C:\Documents and Settings...S.TXT[.pacificpoker.com/]

Cookie/Xiti Tracking Cookie Latent Show + Info
A voir également:

4 réponses

Utilisateur anonyme
1 oct. 2007 à 15:52
salut,
telecharge et clique sur le premier bouton ensuite met le log ici
http://download.hijackthis.eu/hijackthis_199.zip
0
turboscript Messages postés 243 Date d'inscription lundi 12 février 2007 Statut Membre Dernière intervention 16 mai 2013 29
1 oct. 2007 à 16:03
pour supprimer le premier virus : W32/Nuwar.C.worm
telecharges le fix à cette adresse :
http://www.sophos.com/security/analyses/w32nuwarc.html
et pour le deuxième :
http://404.szm.com
pour les problèmes de cookies, selon le navigateur que tu utilises :
si Internet explorer :
panneau de configuration (affichage standard des options) --> option internet --> supprimer les cookies, et tant qu'a faire supprimer les fichiers ce qui videra ton cache internet.
si Firefox, effacer mes traces , supprimer les cookies
toutes fois, les cookies ne sont pas dangereux.
0
BlodDarn Messages postés 196 Date d'inscription mercredi 8 août 2007 Statut Membre Dernière intervention 11 mai 2013 19
2 oct. 2007 à 03:01
Ok Merci a tous les deux, je vais faire ce que vous me dîtes et je vous informe !
0
BlodDarn Messages postés 196 Date d'inscription mercredi 8 août 2007 Statut Membre Dernière intervention 11 mai 2013 19
8 oct. 2007 à 21:55
Voila le log d'Hijackthis :

Logfile of HijackThis v1.99.1
Scan saved at 15:55:05, on 2007-10-08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\a-squared free\a2service.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Cobian Backup 8\cbService.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Documents and Settings\Quentin\Mes documents\Programmes Dowloades\Download\iPod\bin\iPodService.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Soft4Ever\looknstop\looknstop.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Cobian Backup 8\cbInterface.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\Quentin\LOCALS~1\Temp\Répertoire temporaire 2 pour hijackthis_199.zip\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\Program Files\Copernic Agent\CopernicAgentExt.rdl/INTEGRATION_BAND_SEARCHBAR_HTML
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\Program Files\Copernic Agent\CopernicAgentExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Cobian Backup 8 interface] "C:\Program Files\Cobian Backup 8\cbInterface.exe" -service
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Search - ?p=ZU
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra 'Tools' menuitem: Démarrer Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - https://www.miniclip.com/games/ricochet-lost-worlds/en/ReflexiveWebGameLoader.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game08.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E1AF091A-9F23-4059-89D7-C05EE073285D} (Canal+ Active MSWAY) - https://www.canalplus.com/canalplay/
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: MsgPlusLoader.dll,wbsys.dll
O20 - Winlogon Notify: WB - C:\Program Files\AlienGUIse\fastload.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Cobian Backup 8 service (CobBMService) - Luis Cobian - C:\Program Files\Cobian Backup 8\cbService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Documents and Settings\Quentin\Mes documents\Programmes Dowloades\Download\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
0