Probleme fond d'ecran

Bonjour,

J'ai ete infecte par un virus qui est normalement parti mais j'ai toujours un fond d'ecran avec une alerte que je n'arrive pas a changer. Pourriez vous m'aider SVP
Configuration: Windows XP
Internet Explorer 7.0

9 réponses

  1. https://www.clubic.com/telecharger-fiche215092-malwarebytes-anti-malware.html installe sa fait une mise a jour et ensuite un examen complet ensuite a la fin du scan supprime tout et poste le rapport
    1. le scan a l'air d'etre lent je pense que ca va mettre du temps
    2. Bonjour,

      Voila le rapport:

      Malwarebytes' Anti-Malware 1.34
      Version de la base de données: 1903
      Windows 5.1.2600 Service Pack 3

      31/03/2006 13:20:53
      mbam-log-2006-03-31 (13-20-53).txt

      Type de recherche: Examen complet (C:\|)
      Eléments examinés: 161858
      Temps écoulé: 1 hour(s), 49 minute(s), 55 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 2
      Clé(s) du Registre infectée(s): 19
      Valeur(s) du Registre infectée(s): 6
      Elément(s) de données du Registre infecté(s): 9
      Dossier(s) infecté(s): 5
      Fichier(s) infecté(s): 24

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      C:\WINDOWS\system32\jawotiwi.dll (Trojan.Vundo.H) -> Delete on reboot.
      c:\WINDOWS\system32\loyodipo.dll (Trojan.Vundo.H) -> Delete on reboot.

      Clé(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bcafe054-7c7b-48d2-8a4f-2bc62194c57b} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{bcafe054-7c7b-48d2-8a4f-2bc62194c57b} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cedabb88-5383-440c-97bd-bf2e8c27b5bf} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{cedabb88-5383-440c-97bd-bf2e8c27b5bf} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
      HKEY_CLASSES_ROOT\CLSID\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6} (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Trojan.Agent) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Carlson (Dialer) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\WebMediaPlayer (Rogue.Webmediaplayer) -> Quarantined and deleted successfully.

      Valeur(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\886dbb78 (Trojan.Vundo.H) -> Delete on reboot.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jiborihita (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm8b5e88e4 (Trojan.Vundo.H) -> Delete on reboot.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo.H) -> Delete on reboot.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Update (Backdoor.Bot) -> Quarantined and deleted successfully.

      Elément(s) de données du Registre infecté(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\loyodipo.dll -> Delete on reboot.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\loyodipo.dll -> Delete on reboot.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

      Dossier(s) infecté(s):
      C:\Program Files\MyWaySA (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      C:\Program Files\Fichiers communs\Carlson (Dialer) -> Quarantined and deleted successfully.
      C:\Program Files\Temporary (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\kazaabackupfiles (Worm.Archive) -> Quarantined and deleted successfully.

      Fichier(s) infecté(s):
      C:\WINDOWS\system32\qtbknt.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\jawotiwi.dll (Trojan.Vundo.H) -> Delete on reboot.
      C:\WINDOWS\system32\iwitowaj.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\loyodipo.dll (Trojan.Vundo.H) -> Delete on reboot.
      C:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\netspools.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\sniff.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
      C:\bmf.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{C75D780B-5CD4-494E-AB96-5DA2A6677439}\RP989\A0120238.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{C75D780B-5CD4-494E-AB96-5DA2A6677439}\RP991\A0120420.exe (Trojan.Crypt) -> Quarantined and deleted successfully.
      C:\System Volume Information\_restore{C75D780B-5CD4-494E-AB96-5DA2A6677439}\RP991\A0120421.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\jowudosu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\Setup.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\drivers\ovfsth.sys (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ovfsthjxqakyvgkddxdbsnawdtmkjxfnhnrtfl.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ovfsthspxiayrlorxvieleokdfwgndvdhvxynv.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ovfsthxwponlqltitdixasimixxpddeynsnbvm.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ovfsthprvgtjglfqwcqsuemmxoewjddojwqanf.dat (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ovfsthxkbhfwblnworglegjvwwbeoapasftgwk.dat (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\Documents and Settings\All Users\Menu Démarrer\carlton (Dialer) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\warning.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ahtn.htm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\etsevxzpc_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\etsevxzpc_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\win32hlp.cnf (Trojan.Agent) -> Quarantined and deleted successfully.

      Merci de ton aide
  2. oui ca va mieux je voulais juste savoir s'il ni avait plus rien.

    Merci pour ton aide
    1. donc tu vas l'enlever et mettre antivir 9 il est en anglais mais t'inquiète pas très facile d'utilisation https://www.clubic.com/telecharger-fiche10821-avira-antivir-personal-free-antivirus.html donc tu l'installe tu fais la mise a jour ( update) et tu fais un scan après avec ( scan systeme now) met en quarantaine ce qu'il trouve et poste la rapport ici
      1. Bizarre ca ete rapide j'ai peut etre pas tout mit.

        Voila le rapport que j'ai eu.

        Avira AntiVir Personal
        Report file date: lundi 23 mars 2009 14:20

        Scanning for 1284893 virus strains and unwanted programs.

        Licensee : Avira AntiVir Personal - FREE Antivirus
        Serial number : 0000149996-ADJIE-0000001
        Platform : Windows XP
        Windows version : (Service Pack 3) [5.1.2600]
        Boot mode : Normally booted
        Username : florian
        Computer name : PCBUREAU

        Version information:
        BUILD.DAT : 9.0.0.386 17962 Bytes 11/03/2009 15:55:00
        AVSCAN.EXE : 9.0.3.3 464641 Bytes 24/02/2009 11:13:26
        AVSCAN.DLL : 9.0.3.0 40705 Bytes 27/02/2009 09:58:24
        LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:49
        LUKERES.DLL : 9.0.2.0 12033 Bytes 27/02/2009 09:58:52
        ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 11:30:36
        ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 11/02/2009 19:33:26
        ANTIVIR2.VDF : 7.1.2.105 513536 Bytes 03/03/2009 06:41:14
        ANTIVIR3.VDF : 7.1.2.127 110592 Bytes 05/03/2009 13:58:20
        Engineversion : 8.2.0.100
        AEVDF.DLL : 8.1.1.0 106868 Bytes 27/01/2009 16:36:42
        AESCRIPT.DLL : 8.1.1.56 352634 Bytes 26/02/2009 19:01:56
        AESCN.DLL : 8.1.1.7 127347 Bytes 12/02/2009 10:44:25
        AERDL.DLL : 8.1.1.3 438645 Bytes 29/10/2008 17:24:41
        AEPACK.DLL : 8.1.3.10 397686 Bytes 04/03/2009 12:06:10
        AEOFFICE.DLL : 8.1.0.36 196987 Bytes 26/02/2009 19:01:56
        AEHEUR.DLL : 8.1.0.100 1618295 Bytes 25/02/2009 14:49:16
        AEHELP.DLL : 8.1.2.2 119158 Bytes 26/02/2009 19:01:56
        AEGEN.DLL : 8.1.1.24 336244 Bytes 04/03/2009 12:06:10
        AEEMU.DLL : 8.1.0.9 393588 Bytes 09/10/2008 13:32:40
        AECORE.DLL : 8.1.6.6 176501 Bytes 17/02/2009 13:22:44
        AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 13:32:40
        AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:59
        AVPREF.DLL : 9.0.0.1 43777 Bytes 05/12/2008 09:32:15
        AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 13:34:28
        AVREG.DLL : 9.0.0.0 36609 Bytes 05/12/2008 09:32:09
        AVARKT.DLL : 9.0.0.1 292609 Bytes 09/02/2009 06:52:24
        AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:37:08
        SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
        SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:21:33
        NETNT.DLL : 9.0.0.0 11521 Bytes 05/12/2008 09:32:10
        RCIMAGE.DLL : 9.0.0.21 2438401 Bytes 09/02/2009 10:45:45
        RCTEXT.DLL : 9.0.35.0 87297 Bytes 11/03/2009 14:55:12

        Configuration settings for the scan:
        Jobname.............................: Short system scan after installation
        Configuration file..................: c:\program files\avira\antivir desktop\setupprf.dat
        Logging.............................: low
        Primary action......................: interactive
        Secondary action....................: ignore
        Scan master boot sector.............: on
        Scan boot sector....................: on
        Process scan........................: on
        Scan registry.......................: on
        Search for rootkits.................: off
        Integrity checking of system files..: off
        Scan all files......................: Intelligent file selection
        Scan archives.......................: on
        Recursion depth.....................: 20
        Smart extensions....................: on
        Macro heuristic.....................: on
        File heuristic......................: medium

        Start of the scan: lundi 23 mars 2009 14:20

        The scan of running processes will be started
        Scan process 'avscan.exe' - '1' Module(s) have been scanned
        Scan process 'avconfig.exe' - '1' Module(s) have been scanned
        Scan process 'avgnt.exe' - '1' Module(s) have been scanned
        Scan process 'sched.exe' - '1' Module(s) have been scanned
        Scan process 'avguard.exe' - '1' Module(s) have been scanned
        Scan process 'setup.exe' - '1' Module(s) have been scanned
        Scan process 'msiexec.exe' - '1' Module(s) have been scanned
        Scan process 'presetup.exe' - '1' Module(s) have been scanned
        Scan process 'avira-antivir-personal-free_avira_antiv' - '1' Module(s) have been scanned
        Scan process 'iexplore.exe' - '1' Module(s) have been scanned
        Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
        Scan process 'msimn.exe' - '1' Module(s) have been scanned
        Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
        Scan process 'alg.exe' - '1' Module(s) have been scanned
        Scan process 'CCC.exe' - '1' Module(s) have been scanned
        Scan process 'dllhost.exe' - '1' Module(s) have been scanned
        Scan process 'ashWebSv.exe' - '1' Module(s) have been scanned
        Scan process 'ashMaiSv.exe' - '1' Module(s) have been scanned
        Scan process 'WZQKPICK.EXE' - '1' Module(s) have been scanned
        Scan process 'btdna.exe' - '1' Module(s) have been scanned
        Scan process 'mcrdsvc.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
        Scan process 'StarWindService.exe' - '1' Module(s) have been scanned
        Scan process 'ashDisp.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'MaxMenuMgr.exe' - '1' Module(s) have been scanned
        Scan process 'jusched.exe' - '1' Module(s) have been scanned
        Scan process 'MOM.exe' - '1' Module(s) have been scanned
        Scan process 'PnkBstrB.exe' - '1' Module(s) have been scanned
        Scan process 'PnkBstrA.exe' - '1' Module(s) have been scanned
        Scan process 'SyncServices.exe' - '1' Module(s) have been scanned
        Scan process 'jqs.exe' - '1' Module(s) have been scanned
        Scan process 'ehSched.exe' - '1' Module(s) have been scanned
        Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned
        Scan process 'issch.exe' - '1' Module(s) have been scanned
        Scan process 'stsystra.exe' - '1' Module(s) have been scanned
        Scan process 'ehtray.exe' - '1' Module(s) have been scanned
        Scan process 'explorer.exe' - '1' Module(s) have been scanned
        Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
        Scan process 'ashServ.exe' - '1' Module(s) have been scanned
        Scan process 'aswUpdSv.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'svchost.exe' - '1' Module(s) have been scanned
        Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
        Scan process 'lsass.exe' - '1' Module(s) have been scanned
        Scan process 'services.exe' - '1' Module(s) have been scanned
        Scan process 'winlogon.exe' - '1' Module(s) have been scanned
        Scan process 'csrss.exe' - '1' Module(s) have been scanned
        Scan process 'smss.exe' - '1' Module(s) have been scanned
        53 processes with 53 modules were scanned

        Starting master boot sector scan:

        Start scanning boot sectors:

        Starting to scan executable files (registry).
        The registry was scanned ( '72' files ).

        End of the scan: lundi 23 mars 2009 14:20
        Used time: 00:21 Minute(s)

        The scan has been done completely.

        0 Scanned directories
        488 Files were scanned
        0 Viruses and/or unwanted programs were found
        0 Files were classified as suspicious
        0 files were deleted
        0 Viruses and unwanted programs were repaired
        0 Files were moved to quarantine
        0 Files were renamed
        0 Files cannot be scanned
        488 Files not concerned
        3 Archives were scanned
        0 Warnings
        0 Notes
    2. ben tout a l'air bon en tout cas si tu ne constate plus de souci met le statu en mode résolus stp
      1. Merci pour ton aide.

        Part contre j'ai ete infecte sur mon pc portable aussi, et depuis que je ne peu plus me connecte au reseau en WIfI mais je peu en cable ethernet.

        aurai tu une solution a ce prob

        Merci
    3. a si tu peut en cable c'est nickel !! ben tu fais exactement la même procédure d'abord malwares bytes et ensuite antivir
      1. Nickel le PC portable est propre aussi mais par contre toujours pas de internet par WIFI ni aucun reseau.
        Mais par contre par cable ethernet ca marche.
    4. ben la c'est ta wifi qui a un souci lol car si tu avais un nuker antivir l'aurais detecter