Chargement en cours...
Connexion au forum informatique de Sur-la-Toile
La discussion « virus serwab » se trouve dans le forum « Virus, troyens, etc... »
Statut de la discussion » virus serwab « ( normale)

virus serwab




Le  5-08-2006 à 13:03 #

bonjour
nouveau venu chez vous
je suppose que pour resoudre mon probleme de virus il faut recreer une discussions si ce n est pas le cas je vous demande de bien vouloir m excuser
j ai vue la discussions existait et j ai telecharger les 4 logiciels.
j attend votre aide pour la suite cela evitera les erreurs
en vous remerciant

Le  5-08-2006 à 13:17 #

Bonjour. Je te une procédure si tu as déjà les logiciels ne lé retélécharge pas bien évidement mais suis la procédure dans l'ordre merci.


I) Fais un scan antivirus en linge avec IE : http://www.pandasoftware.fr/Activescan/Activescan.html. Enregistre et post ensuite le rapport. (Si tu as avast désactive le le temps du scan.)



II) Téléchargement des logiciels :


1) Télécharge Ccleaner.

2) Télécharge Ewido V4.

3) Télécharge HijackThis. et enregistre le dans un répertoire spécialement dédié.


III) Utiliser avec les logiciels :



1) Lance Ccleaner, clique sur analyse. Quand elle est terminée, clique sur lancer le nettoyage. Si tu as des problème n'hésite pas à regarder son Tuto explicatif


2) Lance Ewido puis :

a) Mets le à jour en cliquant update now.
b) Redémarre en mode sans échec (tapote la touche F8 au démarage de ton ordinateur)et
c) Fais un "complete system scan".
d) A la fin du scan, vérifie qu'il y est bien marqué "delete à côté de chaque malware et clique seulement sur : "Apply all actions"
e) Ensuite, clique sur "Save Report " puis "Save report as" et sauve le rapport dans tes documents.
f) Redémarre normalement et post le rapport.

Si tu as des problème ou que tu ne comprends pas quelques chose n'hésite pas à regarder ce tuto explicatif by Rub_Mic.


3) Lance HijackThis et clique sur "Do a system scan and save logfile". A la fin du scan, le bloc note vas s'ouvrir. Post en le contenu en fesant un copier-coller Post en le contenu en fesant un copier-coller.





Le  5-08-2006 à 15:09 #

salut

voila le rapport de panda


Incident Statut Analyse

Spyware:Cookie/Tradedoubler No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.tradedoubler.com/]
Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.xiti.com/]
Spyware:Cookie/Serving-sys No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.serving-sys.com/]
Spyware:Cookie/Serving-sys No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.serving-sys.com/]
Spyware:Cookie/Comclick No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[fl01.ct2.comclick.com/]
Spyware:Cookie/Adtech No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.adtech.de/]
Spyware:Cookie/Comclick No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[fl01.ct2.comclick.com/]
Spyware:Cookie/Adtech No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.adtech.de/]
Spyware:Cookie/Mediaplex No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.mediaplex.com/]
Spyware:Cookie/Casalemedia No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.casalemedia.com/]
Spyware:Cookie/FastClick No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.fastclick.net/]
Spyware:Cookie/Doubleclick No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.doubleclick.net/]
Spyware:Cookie/Advertising No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.advertising.com/]
Spyware:Cookie/Atlas DMT No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.atdmt.com/]
Spyware:Cookie/2o7 No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.2o7.net/]
Spyware:Cookie/Tribalfusion No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.tribalfusion.com/]
Spyware:Cookie/YieldManager No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[ad.yieldmanager.com/]
Spyware:Cookie/Bluestreak No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.bluestreak.com/]
Spyware:Cookie/Statcounter No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.statcounter.com/]
Spyware:Cookie/Zedo No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.zedo.com/]
Spyware:Cookie/Weborama No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt[.weborama.fr/]
Spyware:Cookie/Mediaplex No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Falkag No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/Tradedoubler No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Falkag No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/Tradedoubler No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Tradedoubler No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Falkag No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/Bluestreak No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Doubleclick No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/2o7 No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Weborama No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.weborama.fr/]
Spyware:Cookie/Advertising No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Searchportal No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/Serving-sys No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Adtech No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.adtech.de/]
Spyware:Cookie/PointRoll No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/RealMedia No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Atlas DMT No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Toplist No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/YieldManager No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Hbmediapro No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/Comclick No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[fl01.ct2.comclick.com/]
Spyware:Cookie/FastClick No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Zedo No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Casalemedia No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Tribalfusion No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Statcounter No Désinfecté C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies.txt[.statcounter.com/]
Outil indésirable:Application/Processor No Désinfecté C:\Documents and Settings\coralie\Bureau\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Spyware:Cookie/2o7 No Désinfecté C:\Documents and Settings\coralie\Cookies\coralie@2o7[2].txt
Spyware:Cookie/YieldManager No Désinfecté C:\Documents and Settings\coralie\Cookies\coralie@ad.yieldmanager[1].txt
Spyware:Cookie/Atlas DMT No Désinfecté C:\Documents and Settings\coralie\Cookies\coralie@atdmt[2].txt
Spyware:Cookie/Bluestreak No Désinfecté C:\Documents and Settings\coralie\Cookies\coralie@bluestreak[1].txt
Spyware:Cookie/Clubdicecasino No Désinfecté C:\Documents and Settings\coralie\Cookies\coralie@clubdicecasino[1].txt
Spyware:Cookie/Mediaplex No Désinfecté C:\Documents and Settings\coralie\Cookies\coralie@mediaplex[1].txt
Spyware:Cookie/Reliablestats No Désinfecté C:\Documents and Settings\coralie\Cookies\coralie@stats1.reliablestats[1].txt
Spyware:Cookie/Weborama No Désinfecté C:\Documents and Settings\coralie\Cookies\coralie@weborama[1].txt
Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\coralie\Cookies\coralie@xiti[1].txt
Outil indésirable:Application/Processor No Désinfecté C:\Documents and Settings\coralie\Local Settings\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\Cache\633285D9d01[SmitfraudFix/Process.exe]
Spyware:spyware/media-motor No Désinfecté C:\WINDOWS\unstall.exe

Le  5-08-2006 à 15:26 #

Bonjour.

Continue la procédure je te répondrais ce soir si personne ne l'as fait.



Le  5-08-2006 à 17:47 #

salut

voila le resultat ewido et hijack

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 17:26:28 05/08/2006

+ Scan result:



C:\Program Files\HbTools\Bin\4.8.0.0\HbtHostIE.dll -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\HbTools\Bin\4.8.0.0\HbtHostOE.dll -> Adware.Hotbar : Cleaned with backup (quarantined).
C:\Program Files\HbTools\Bin\4.8.0.0\HbtOEAddOn.exe -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\HbTools\Bin\4.8.0.0\HbtSrv.exe -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\HbTools\Bin\4.8.0.0\HbtWeatherOnTray.exe -> Adware.Hotbar : Cleaned with backup (quarantined).
C:\Program Files\HbTools\HBTV\HBTVHelper.dll -> Adware.Hotbar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\AppID\WeatherOnTray.EXE -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbCoreSrv.DynamicProp -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbCoreSrv.DynamicProp.1 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbCoreSrv.DynamicProp\CLSID -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbCoreSrv.DynamicProp\CurVer -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbTools.HbtCommBand -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbTools.HbtCommBand.1 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbTools.HbtCommBand\CLSID -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbTools.HbtCommBand\CurVer -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbTools.HbtTravelCompareBar -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbTools.HbtTravelCompareBar.1 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbTools.HbtTravelCompareBar\CLSID -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbTools.HbtTravelCompareBar\CurVer -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtCoreSrv.HbtCoreServices -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtCoreSrv.HbtCoreServices.1 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtCoreSrv.HbtCoreServices\CLSID -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtCoreSrv.HbtCoreServices\CurVer -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtCoreSrv.LfgAx -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtCoreSrv.LfgAx.1 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtCoreSrv.LfgAx\CLSID -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtCoreSrv.LfgAx\CurVer -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtHostIE.Bho -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtHostIE.Bho.1 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtHostIE.Bho\CLSID -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtHostIE.Bho\CurVer -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtHostOL.HbtMailAnim -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtHostOL.HbtMailAnim.1 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtHostOL.HbtMailAnim\CLSID -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtHostOL.HbtMailAnim\CurVer -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtHostOL.HbtWebmailSend -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtHostOL.HbtWebmailSend.1 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtHostOL.HbtWebmailSend\CLSID -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtHostOL.HbtWebmailSend\CurVer -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtSrv.HbtCoreServices -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtSrv.HbtCoreServices.1 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtSrv.HbtCoreServices\CLSID -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtSrv.HbtCoreServices\CurVer -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtToolbar.HbtHtmlMenuUI -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtToolbar.HbtHtmlMenuUI.1 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtToolbar.HbtHtmlMenuUI\CLSID -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtToolbar.HbtHtmlMenuUI\CurVer -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtToolbar.HbtToolbarCtl -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtToolbar.HbtToolbarCtl.1 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtToolbar.HbtToolbarCtl\CLSID -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtToolbar.HbtToolbarCtl\CurVer -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtTools.HbMain -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtTools.HbMain.1 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtTools.HbMain\CLSID -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\HbtTools.HbMain\CurVer -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Wallpaper.WallpaperManager -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Wallpaper.WallpaperManager.1 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Wallpaper.WallpaperManager\CLSID -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Wallpaper.WallpaperManager\CurVer -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\HbTools -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\HbTools\HbTools -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\HbTools\HbTools\Install -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\HbTools\HbTools\MachineInfo -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\HbTools\HbTools\Mail -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\HbTools\HbTools\PI -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\HbTools\HbTools\PI\3.2 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\HbTools\HbTools\Updates -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\HbTools\HbTools\Upgrade -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\HbTools\Hotbar -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\HbTools\Hotbar\Install -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\HbTools\Install -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\HbTools\Install\CmpMap -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HbToolsOutlookTools -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HbToolsWebTools -> Adware.HotBar : Cleaned with backup (quarantined).
:mozilla.108:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.78:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.79:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.43:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.45:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.66:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.67:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.68:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.69:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.70:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.96:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.60:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.41:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Comclick : Cleaned.
:mozilla.42:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Comclick : Cleaned.
:mozilla.44:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Comclick : Cleaned.
:mozilla.65:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.20:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Estat : Cleaned.
:mozilla.63:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.64:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.135:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.140:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.46:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.35:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.36:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.37:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.38:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.39:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.51:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.54:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.55:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.111:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.27:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.28:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.89:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.141:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.91:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.123:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.124:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.125:C:\Documents and Settings\coralie\Application Data\Mozilla\Firefox\Profiles\kq8t5mr2.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned.


::Report end

++++++++++++++++++++++++++++++

Logfile of HijackThis v1.99.1
Scan saved at 17:30:33, on 05/08/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Trust\460LR MOUSE WIRELESS OPTICALOFFICE\1.1\moffice.exe
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Trust\460LR MOUSE WIRELESS OPTICALOFFICE\1.1\MOUSE32A.DAT
C:\Program Files\Baliciel\Bali TOOLBAR\BaliBAR.exe
C:\Program Files\Slim Multimedia Keyboard\MagicKey.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\WinZip 8.1 Fr\WZQKPICK.EXE
C:\Program Files\Slim Multimedia Keyboard\OSD.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\HbTools\Bin\4.8.0.0\HbtWeatherOnTray.exe
C:\Program Files\HbTools\Bin\4.8.0.0\HbtOEAddOn.exe
C:\Program Files\Hbtools\HBTV\HBTV.exe
C:\WINDOWS\system32\mshearts.exe
C:\Documents and Settings\coralie\Bureau\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://resultsmaster.com/SmartOffers/Services/resultsmaster/ResultsMasterHomeLeftPane.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: TVEngine Helper /fleok=1D8A83A5C2E6107C91A475760EA83FA5EF80752B94E3D67E5E7F4F2F3FC6 - {4B18DD50-C996-44fc-AC52-0FECFF82ED58} - c:\program files\hbtools\hbtv\hbtvhelper.dll
O2 - BHO: HbTools - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\HbTools\Bin\4.8.0.0\HbtHostIE.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: H&otbar - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\HbTools\Bin\4.8.0.0\HbtHostIE.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Trust\460LR MOUSE WIRELESS OPTICALOFFICE\1.1\moffice.exe
O4 - HKLM\..\Run: [CmUsbAudio] RunDll32 cmcnfg2.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [mryqjqhz] C:\WINDOWS\System32\qbimjhge.exe
O4 - HKLM\..\Run: [HbTools] C:\Program Files\HbTools\Bin\4.8.0.0\HbtOEAddOn.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WeatherOnTray] C:\Program Files\HbTools\Bin\4.8.0.0\HbtWeatherOnTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bali TOOLBAR.lnk = C:\Program Files\Baliciel\Bali TOOLBAR\BaliBAR.exe
O4 - Global Startup: Slim Multimedia Keyboard.lnk = C:\Program Files\Slim Multimedia Keyboard\MagicKey.exe
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip 8.1 Fr\WZQKPICK.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe

merci a tous

Le  5-08-2006 à 18:17 #

Bonsoir.

I) Va mettre à jour ton windowd via windows update ( si tu peux biensur )



II) Télécharge un pare feu si tu n'est pas derrière un routeur :

- Je te conseil Kerio.
- Pour le configurer regarde ce tuto explicatif.



III) Relance Hijackthis, coche les lignes qui suivent et clique sur fix checked :



O2 - BHO: TVEngine Helper /fleok=1D8A83A5C2E6107C91A475760EA83FA5EF80752B94E3D67E5E7F4F2F3FC6 - {4B18DD50-C996-44fc-AC52-0FECFF82ED58} - c:\program files\hbtools\hbtv\hbtvhelper.d

O2 - BHO: HbTools - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\HbTools\Bin\4.8.0.0\HbtHostIE.dl

O3 - Toolbar: H&otbar - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\HbTools\Bin\4.8.0.0\HbtHostIE.dll

O4 - HKLM\..\Run: [WeatherOnTray] C:\Program Files\HbTools\Bin\4.8.0.0\HbtWeatherOnTray.exe





IV) Assure toi d'avoir accés au fichier caché :


Démarrer, Poste de travail ou autre dossier, Menu Outils, Option des dossiers, onglet Affichage :
Activer l'option : Afficher les fichiers et dossiers cachés
Désactiver l'option : Masquer les extensions des fichiers dont le type est connu
Désactiver l'option : Masquer les fichiers protégés du système d'exploitation
Puis cliquer sur "Appliquer à tous les dossiers"




V) Supprime ce fichier :

C:\Program Files\HbTools




VI) Télécharge F-Secure Blacklight : https://europe.f-secure.com/blacklight/try.shtml

Lance-le en double-cliquant sur le fichier blbeta.exe
Accepte la licence, et clique enfin sur "Scan"
- Poste le rapport qui a été créé dans le fichier fsbl-bxxxx.log en l'ouvrant avec le bloc-note.
Tu peux consulter le tutorial de F-Secure BlackLight




Le  5-08-2006 à 20:33 #

bonsoir

voila j ai fait ceque tu demandais je crois que l on est proche de la fin
j ai chargé kerio meme si j ai un routeur car le firewall du routeur n est pas activé(peut etre je devrais l activé?c est un barricade)
voila

08/05/06 20:27:35 [Info]: BlackLight Engine 1.0.42 initialized
08/05/06 20:27:35 [Info]: OS: 5.1 build 2600 (Service Pack 1)
08/05/06 20:27:35 [Note]: 7019 4
08/05/06 20:27:35 [Note]: 7005 0
08/05/06 20:27:40 [Note]: 7006 0
08/05/06 20:27:40 [Note]: 7011 1832
08/05/06 20:27:40 [Note]: 7026 0
08/05/06 20:27:41 [Note]: 7026 0
08/05/06 20:27:48 [Note]: FSRAW library version 1.7.1019
08/05/06 20:28:57 [Note]: 7007 0

merci


Le  5-08-2006 à 20:35 #

Bonsoir.

Ton rapport BlackLight est propre.

Fias comme tu veix pour ton routeur mais jamais 2 pare feu en même temps .



As-tu encore des problèmes ?


[ Ce message a ete modifié par : : freeman206 le 05-08-2006 20:36 ]



Le  5-08-2006 à 20:43 #

oups!!
j avais oublie hijack
maintenant c est fait voila le resultat

08/05/06 20:37:12 [Info]: BlackLight Engine 1.0.42 initialized
08/05/06 20:37:12 [Info]: OS: 5.1 build 2600 (Service Pack 1)
08/05/06 20:37:13 [Note]: 7019 4
08/05/06 20:37:13 [Note]: 7005 0
08/05/06 20:37:14 [Note]: 7006 0
08/05/06 20:37:14 [Note]: 7011 1832
08/05/06 20:37:14 [Note]: 7026 0
08/05/06 20:37:15 [Note]: 7026 0
08/05/06 20:37:19 [Note]: FSRAW library version 1.7.1019
08/05/06 20:38:18 [Note]: 7007 0


a noter que j ai du enlever le fichier "C:\Program Files\HbTools " en mode sans echec et que la ligne

O2 - BHO: TVEngine Helper /fleok=1D8A83A5C2E6107C91A475760EA83FA5EF80752B94E3D67E5E7F4F2F3FC6 - {4B18DD50-C996-44fc-AC52-0FECFF82ED58} - c:\program files\hbtools\hbtv\hbtvhelper.d

n existait pas

bon ce ccoup la j espere que c est bon

a demain car je suis nase et je vais glander devant la tele
bonne soirée

Le  5-08-2006 à 20:44 #

Oui c'est ce qu'il fallais faire pour le fichier.

As-tu encore des problèmes ?
» Liste des Forums » Virus, troyens, etc...

Sujets Connexes

Arakien & WéWé


Forums

Navigation


Publicité

Connectés

Il y a actuellement 647 visiteurs et 26 toiliens en ligne, ainsi que 11 connectés sur le tchat.

Recherche

Concours


Sauf mention contraire, le contenu du blog et du forum est sous licence Creative Commons By-Sa. Vous avez le droit de le reproduire à condition de citer l'auteur, de faire un lien vers la page d'origine, et de partager vos travaux dérivés selon les mêmes conditions.

Conditions d'utilisation -

Partenaires: [Informatique Multimédia] [Portail du Maroc] [Actualité High Tech]
[Tutoriaux Photoshop] [éligibilité ADSL] [Astuces Windows]

Page générée en 239 millisecondes sur WWW1.