Infecter par security2K

morpheus2_be Messages postés 3 Statut Membre -  
zaltern Messages postés 4 Statut Membre -
J'ai essayé toutes les solutions que je connaissais et pourtant il est toujours là. Les antivirus et antispywre sont inéficasse. J'ai installé firefox qui lui ne semble pas infecté. Mais par contre IE me renvoie constament vers security2k.net lorsque je tente de consulter mes mails. Et j'aimerais me débarraser de ce spyware.

Si quelqu'un peut m'aider, merci de le faire.

Merci à tous
Configuration: Windows home edition (sp2)

2 réponses

  1. zaltern Messages postés 4 Statut Membre
     
    ca marche !!

    http://www.geekstogo.com/forum/index.php?showtopic=63500

    ****
    open Hijackthis and do a scan. Please check off the following items:

    R3 - URLSearchHook: (no name) - {DA133D55-8B02-2670-3B1B-47DB3C5CDCD0} - (no file)
    O2 - BHO: HomepageBHO - {893fad3a-931e-4e53-b515-b1426d63799b} - C:\WINDOWS\system32\hpE9F2.tmp

    click FIX CHECKED then close Hijackthis

    Launch Notepad, and copy/paste the box below into a new text file. Save it as fixme.reg (make sure that Save as Type is set at "All Files") on your Desktop. Ensure there is no space at or above REGEDIT 4.

    QUOTE
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    "kernel32.dll"=-
    "nvctrl.exe"=-
    "wininet.dll"=-

    Locate fixme.reg on your Desktop and double-click on it. You will receive a prompt similar to: "Do you wish to merge the information into the registry?". Answer "Yes" and wait for a message to appear similar to "Merged Successfully".

    Please download the Killbox.

    Please run Killbox.

    * Select "Delete on Reboot".
    * Copy the file names below to the clipboard by highlighting them and pressing Control-C:

    C:\WINDOWS\system32\mssearchnet.exe
    C:\WINDOWS\system32\nvctrl.exe
    C:\WINDOWS\System32\mscornet.exe

    * Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
    * Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

    Please post a fresh hijackthis log and fresh silentrunners log
    *********
    0