Probléme avec Ezula et Weboffer

Résolu
Bonjour,
Alors voila j'ai un probléme : Ezula et weboffer s'installe a chaque démarage et je narive pas a les suprimer
aidez moi svp je ne sais plus quoi fair :(

9 réponses

  1. Contributeur
    salut

    telecharge hijackthis et poste nous un rapport

    avant ca tu peut commencer a nettoyer ton pc en scannant avec des utiliatires commes

    clean up 4.0
    ccleaner
    spybot
    ad aware
    a2 free
    ewido

    ensuite fais un scan en ligne sur http://www.bitdefender.fr/bd/site/page.php

    colle nous le rapport final de bit defender ainsi que ton hijackthis

    bye
    0
    1. Ok je pense avoir réussi de mettre débarassé de ezula mais voici comme méme le rapport de hijackthis:

      Logfile of HijackThis v1.99.1
      Scan saved at 16:07:12, on 27/11/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\System32\nvsvc32.exe
      C:\Program Files\Spyware Doctor\sdhelp.exe
      C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\wdfmgr.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\PROGRA~1\SPYWAR~1\swdoctor.exe
      C:\Program Files\Alcohol Soft\Alcohol 120\Alcohol.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Documents and Settings\Steeve\Mes documents\Downloads\Programs\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
      O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
      O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
      O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
      O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
      O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
      O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
      O4 - HKLM\..\Run: [LVCOMS] C:\WINDOWS\System32\LVCOMS.EXE
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [shell32] C:\WINDOWS\system32\wuauclt10.exe
      O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [autoupdatev2] C:\WINDOWS\System32\autoupdatev2.exe
      O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
      O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
      O4 - Startup: POPUP KILLER.lnk = C:\Program Files\POPUPKILLER\PopupKiller.exe
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
      O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
      O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
      O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe
      O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
      0
      1. Contributeur
        bonsoir,

        ¤Désactive ta restauration système (uniquement si tu es sous XP):
        Clic droit sur poste de travail puis,
        propriété, tu cliques sur onglet restauration système
        tu coches la case « désactiver la restauration » et applique.
        ----------------------------------------------------------------------------
        ¤Affiche tous les fichiers et dossiers :
        Clique sur démarrer/panneau de configuration/outil/option des dossiers/affichage

        Coche « afficher les fichiers et dossiers cachés »

        Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

        Décoche « masquer les extensions dont le type est connu »
        Puis fais «Ok» pour valider les changements.

        Et appliquer !
        ----------------------------------------------------------------------------
        ¤Vide tes fichiers temps et temporary internet file:

        :: Supprimer les fichiers temporaires ::
        vider tout le contenu de ces dossiers.

        * C:\Documents and Settings\ton compte\Local Settings\Temp
        * C:\Documents and Settings\tous les autres comptes\Local Settings\Temp
        * C:\Windows\Temp

        :: Le contenu du dossier prefetch ::

        * C:\WINDOWS\Prefetch <= sauf le fichier layout.ini

        * Ne pas oublier de vider la corbeille !
        ----------------------------------------------------------------------------
        ¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

        O4 - HKLM\..\Run: [shell32] C:\WINDOWS\system32\wuauclt10.exe

        O4 - HKCU\..\Run: [autoupdatev2] C:\WINDOWS\System32\autoupdatev2.exe

        ----------------------------------------------------------------------------
        ¤Démarre en mode sans échec :
        Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
        Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
        Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
        (Si F8 ne marche pas utilise la touche F5).
        ----------------------------------------------------------------------------
        ¤Recherche et supprime ceci:
        attention seulement les fichiers (si présents).

        C:\WINDOWS\system32\wuauclt10.exe
        C:\WINDOWS\System32\autoupdatev2.exe

        ----------------------------------------------------------------------------
        ¤
        ¤ Passe Ad-Aware et supprime tout ce qu’il trouve + supprime les quarantaines…
        ----------------------------------------------------------------------------
        ¤ Passe Spybot et corrige tout ce qu’il trouve + vaccine + supprime les quarantaines…
        ----------------------------------------------------------------------------
        ¤ Vide ta Corbeille.
        ----------------------------------------------------------------------------
        ¤ Redémarre en mode normal, relance Hijackthis et copie/colle un nouveau rapport sur le forum.

        Bon Courage.

        A+
        0
        1. merci pour ta réponse mais je n'arive pas a suprimer tout le contenu de ce dossier : * C:\Documents and Settings\ton compte\Local Settings\Temp
          0
          1. Voila j'ai fais tou ce que tu ma dis et voila ce que ca donne :

            Logfile of HijackThis v1.99.1
            Scan saved at 17:11:16, on 27/11/2005
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\SOUNDMAN.EXE
            C:\WINDOWS\system32\RUNDLL32.EXE
            C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\PROGRA~1\SPYWAR~1\swdoctor.exe
            C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            C:\WINDOWS\System32\nvsvc32.exe
            C:\Program Files\Spyware Doctor\sdhelp.exe
            C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\wdfmgr.exe
            C:\WINDOWS\System32\alg.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Documents and Settings\Steeve\Mes documents\Downloads\Programs\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
            O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
            O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
            O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
            O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
            O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
            O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
            O4 - HKLM\..\Run: [LVCOMS] C:\WINDOWS\System32\LVCOMS.EXE
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
            O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
            O4 - Startup: POPUP KILLER.lnk = C:\Program Files\POPUPKILLER\PopupKiller.exe
            O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
            O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
            O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
            O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
            O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
            O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe
            O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
            0
            1. Contributeur
              Bonsoir,

              en attendant que je regarde ton log, peux tu tester ce fichier :
              C:\WINDOWS\System32\wdfmgr.exe

              sur ce site :
              http://www.virustotal.com/xhtml/virustotal_en.html

              tu cliques sur le bouton parcourir, tu selectionnes le fichier wdfmgr.exe et tu cliques sur Send.

              Colles le rapport du scan ici.

              Et précise moi où en sont tes soucis.

              A+
              0
              1. Re , J'ai fait ce que tu ma dis voila le scan:

                Antivirus Version Update Result
                AntiVir 6.32.0.6 11.27.2005 no virus found
                Avast 4.6.695.0 11.26.2005 no virus found
                AVG 718 11.27.2005 no virus found
                Avira 6.32.0.6 11.27.2005 no virus found
                BitDefender 7.2 11.27.2005 no virus found
                CAT-QuickHeal 8.00 11.25.2005 no virus found
                ClamAV devel-20051108 11.25.2005 no virus found
                DrWeb 4.33 11.27.2005 no virus found
                eTrust-Iris 7.1.194.0 11.27.2005 no virus found
                eTrust-Vet 11.9.1.0 11.25.2005 no virus found
                Fortinet 2.48.0.0 11.26.2005 no virus found
                F-Prot 3.16c 11.24.2005 no virus found
                Ikarus 0.2.59.0 11.26.2005 no virus found
                Kaspersky 4.0.2.24 11.27.2005 no virus found
                McAfee 4637 11.25.2005 no virus found
                NOD32v2 1.1305 11.25.2005 no virus found
                Norman 5.70.10 11.25.2005 no virus found
                Panda 8.02.00 11.27.2005 no virus found
                Sophos 4.00.0 11.27.2005 no virus found
                Symantec 8.0 11.27.2005 no virus found
                TheHacker 5.9.1.044 11.24.2005 no virus found
                VBA32 3.10.5 11.26.2005 no virus found

                Sinon ca à l'air d'aller pour le moment :)
                merci pour ton aide

                ps: (rien à voir avec ca ) je jouer a need for speed most wanted cette aprem et le jeu ce ferme tout seul j'y est pourtant jouer hier toute la journée ! si quelqun peu me dire pourquoi ou me dirigé sur un forum .

                encore merci pour ton aide incognito02
                0
                1. Contributeur
                  Bonsoir Steeve,

                  Pas de quoi.
                  pour ton probème de Need for speed, c'est pas trop ma tasse de thé !

                  Bon surf

                  0

                  Discussions similaires

                  eZula & Web Offer...

                  9 réponses