Url non valide et touche du clavier inverser

Bonjour,
il y a quelque jour, j'ai eu un gros virus qui me ralentissez énormément mon ordinateur ,j'ai réussi a le supprimer mais maintenant quand je vais sur internet par j'ai une fenêtre qui s'ouvre avec "alerte" "URL non valide" et ça me bug l'ordinateur!!Et quand j'ecrit un texte certaine touche de mon clavier sont inverser ....J'ai déjà essayer un scan avast et spybot mais le problème persiste ...un petit coup de main ne me serait pas de refut.
Merci.
Configuration: Windows XP
Firefox 3.0.14

5 réponses

  1. Contributeur sécurité
    Slt,

    scan avec malwarebyte , fais un scan rapide et colle le rapport obtenu et vire ce qui est trouvé:

    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/­

    ______________________

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    1
    1. voila le scan...

      Malwarebytes' Anti-Malware 1.41
      Version de la base de données: 2856
      Windows 5.1.2600 Service Pack 2 (Safe Mode)

      24/09/2009 21:23:57
      mbam-log-2009-09-24 (21-23-57).txt

      Type de recherche: Examen rapide
      Eléments examinés: 132745
      Temps écoulé: 11 minute(s), 51 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 5
      Valeur(s) du Registre infectée(s): 16
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 2
      Fichier(s) infecté(s): 8

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\OneStepSearch (Adware.OneStepSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE (Trojan.Downloader) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR (Trojan.DNSChanger) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AlerterALG (Trojan.Downloader) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cmdService (Adware.CommAd) -> Quarantined and deleted successfully.

      Valeur(s) du Registre infectée(s):
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingb1751 (Rootkit.TDSS) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingd7511 (Rootkit.TDSS) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletinga9241 (Rootkit.TDSS) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingc4989 (Rootkit.TDSS) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingb4674 (Rootkit.TDSS) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingd2421 (Rootkit.TDSS) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletinga1567 (Rootkit.TDSS) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingc4543 (Rootkit.TDSS) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingb8434 (Rootkit.TDSS) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingd1240 (Rootkit.TDSS) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletinga1105 (Rootkit.TDSS) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingc5780 (Rootkit.TDSS) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingb2996 (Rootkit.TDSS) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingd6594 (Rootkit.TDSS) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletinga1218 (Rootkit.TDSS) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingc3510 (Rootkit.TDSS) -> Quarantined and deleted successfully.

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      C:\Documents and Settings\Weyandt\Application Data\SpamBlockerUtility_Icons (Adware.Hotbar) -> Quarantined and deleted successfully.
      C:\Program Files\OneStepSearch (Adware.OneStepSearch) -> Quarantined and deleted successfully.

      Fichier(s) infecté(s):
      C:\WINDOWS\system32\drivers\gasfkymyxvmhbl.sys (Rootkit.TDSS) -> Delete on reboot.
      C:\WINDOWS\system32\gasfkyixrlfles.dll (Rootkit.TDSS) -> Delete on reboot.
      C:\WINDOWS\system32\gasfkytehrkngq.dll (Rootkit.TDSS) -> Delete on reboot.
      C:\WINDOWS\system32\gasfkytoqooevx.dll (Rootkit.TDSS) -> Delete on reboot.
      C:\Documents and Settings\Weyandt\Local Settings\Temp\warcraft3keygen.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Weyandt\Application Data\SpamBlockerUtility_Icons\Registryrepair.ico (Adware.Hotbar) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Weyandt\Application Data\SpamBlockerUtility_Icons\Software_Online_8.ico (Adware.Hotbar) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Weyandt\Application Data\SpamBlockerUtility_Icons\wallpapere1.ico (Adware.Hotbar) -> Quarantined and deleted successfully.
      0
      1. Contributeur sécurité
        le rapport RSIT ?

        puis

        télécharge combofix (par sUBs) ici :

        http://download.bleepingcomputer.com/sUBs/ComboFix.exe

        et enregistre le sur le bureau.

        sous le nom de antibagle. Fais le avant que le fichier ne soit enregistré sur le bureau

        déconnecte toi d'internet et ferme toutes tes applications.

        désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

        double-clique sur combofix.exe et suis les instructions

        à la fin, il va produire un rapport C:\ComboFix.txt

        réactive ton parefeu, ton antivirus, la garde de ton antispyware

        copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

        Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

        Tu as un tutoriel complet ici :

        https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
        0
        1. bonsoir désole pour le retard..
          pour le rapport rsit il m affiche une erreur quand je veut installer le logiciel et marrete linstalation...
          0
      2. Contributeur sécurité
        ok alors passe a combofix
        0
        1. conbofix ma détecte des fichier infecte mais il ne n fait aucun rapport....et il ma demander de redémarrer lordi pour les suppr mais toujours rien ....
          0
      3. Contributeur sécurité
        le rapport se trouve dans le poste de travail puis c puis combofix. Colle le puis remets un rapport rsit et dis tes soucis actuels
        0