Pubs ou spams :/

Résolu
Bonjour,

depuis 2 jours j'ai des espèces de pubs qui s'ouvrent directement sur mes pages internet, ce ne sont pas des nouvelles pages ou nouveaux onglets qui s'ouvrent avec les pubs mais carrément sur ma page par exemple sur ma page d'acceuil google j'ai un rectangle avec une pub différente a chaque fois, ou sur ma page facebook aussi, enfin sur n'importe quelle page, j'ai lancé malwarebyte anti malware m'a trouvé un trojan que j'ai supprimé, aussi retéléchargé adw cleaner que j'ai éxécuté depuis le bureau, mais rien n'y fait, j'ai également lancé un scan rapide d'avast qui lui par contre n'a rien trouvé.

Si quelqu'un saurai m'aider
merci d 'avance

10 réponses

Résumé de la discussion

Des publicités invasives s’ouvrent directement sur les pages web, pas en tant que nouveaux onglets, sur Windows 7 et Firefox 19.0, après la détection d’un cheval de Troie par Malwarebytes. Plusieurs solutions proposées incluent l’installation d’extensions comme Adblock Plus pour Firefox et des outils de nettoyage alternatifs, tout en évitant une désinstallation inutile d’Internet Explorer. En parallèle, certains participants recommandent des outils dédiés et des rapports à poster pour clarifier l’état du système, tandis que d’autres fournissent des liens vers des tutoriels et des procédures de suppression. D’autres interventions évoquent l’usage d’outils externes comme USBFix et des diagnostics complémentaires, bien qu’un suivi des résultats et une vérification du navigateur restent essentiels pour éviter de futures intrusions.

Bobot (l’IA à votre service)
  1. re

    si tu n'as pas encore désinstallé firefox, fais ceci pour firefox

    https://addons.mozilla.org/fr/firefox/addon/adblock-plus/

    pour explorer fais ceci

    http://simple-adblock.com/

    ps: ne désinstalle pas internet explorer

    @+
    1
    1. re,

      j'ai désinstallé firefox, vais le réinstaller et télécharger ce que tu viens de me dire, pour internet explorer je l'ai pas désinstallé je me disais bien qu'il fallait pas y toucher à celui là lol vais télécharger aussi simple adblock, et reviens vers toi pr te dire, merci encore pour ton temps.
      0
    2. re

      ok

      @+
      0
    3. re,

      parfait ! plus de pubs sur aucun des navigateurs! :)
      merci beaucoup :)
      ce site et ses membres sont au top :))
      0
  2. salut

    tu peux poster les rapports (MBAM et adwcleaner)

    @+
    0
    1. bjr,

      ok je les relance et te poste les rapports
      0
    2. rapport MBAN

      Malwarebytes Anti-Malware 1.70.0.1100
      www.malwarebytes.org

      Version de la base de données: v2013.04.08.02

      Windows 7 Service Pack 1 x64 NTFS
      Internet Explorer 10.0.9200.16521
      cemoha :: CEMOHA-PC [administrateur]

      09/04/2013 07:51:42
      mbam-log-2013-04-09 (07-51-42).txt

      Type d'examen: Examen rapide
      Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
      Options d'examen désactivées: P2P
      Elément(s) analysé(s): 342485
      Temps écoulé: 3 minute(s), 19 seconde(s)

      Processus mémoire détecté(s): 0
      (Aucun élément nuisible détecté)

      Module(s) mémoire détecté(s): 0
      (Aucun élément nuisible détecté)

      Clé(s) du Registre détectée(s): 0
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre détectée(s): 0
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre détecté(s): 0
      (Aucun élément nuisible détecté)

      Dossier(s) détecté(s): 0
      (Aucun élément nuisible détecté)

      Fichier(s) détecté(s): 0
      (Aucun élément nuisible détecté)

      (fin)
      0
  3. re

    non pas besoin de relancer

    pour adwcleaner le rapport se trouve sur ton bureau et dans C:\adw[Sx].txt

    et pour MBAM il est dans rapport/log de MBAM

    @+
    0
    1. re

      tu as fait 1 scan rapide avec MBAM

      tu as trouvé le rapport d'adwcleaner dans C:\

      @+
      0
      1. # AdwCleaner v2.200 - Rapport créé le 09/04/2013 à 07:59:50
        # Mis à jour le 02/04/2013 par Xplode
        # Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
        # Nom d'utilisateur : cemoha - CEMOHA-PC
        # Mode de démarrage : Normal
        # Exécuté depuis : C:\Users\cemoha\Desktop\adwcleaner.exe
        # Option [Suppression]

        ***** [Services] *****

        ***** [Fichiers / Dossiers] *****

        Dossier Supprimé : C:\Users\cemoha\AppData\Roaming\Mozilla\Firefox\Profiles\4uhq37hd.default\jetpack

        ***** [Registre] *****

        ***** [Navigateurs] *****

        -\\ Internet Explorer v10.0.9200.16521

        [OK] Le registre ne contient aucune entrée illégitime.

        -\\ Mozilla Firefox v19.0.2 (fr)

        Fichier : C:\Users\cemoha\AppData\Roaming\Mozilla\Firefox\Profiles\4uhq37hd.default\prefs.js

        [OK] Le fichier ne contient aucune entrée illégitime.

        Fichier : C:\Users\Iness\AppData\Roaming\Mozilla\Firefox\Profiles\bepnu7b3.default\prefs.js

        [OK] Le fichier ne contient aucune entrée illégitime.

        Fichier : C:\Users\Emma\AppData\Roaming\Mozilla\Firefox\Profiles\1gw5491g.default\prefs.js

        [OK] Le fichier ne contient aucune entrée illégitime.

        Fichier : C:\Users\SHITSI\AppData\Roaming\Mozilla\Firefox\Profiles\5scbwl4u.default\prefs.js

        [OK] Le fichier ne contient aucune entrée illégitime.

        Fichier : C:\Users\sam\AppData\Roaming\Mozilla\Firefox\Profiles\45x915nt.default\prefs.js

        [OK] Le fichier ne contient aucune entrée illégitime.

        -\\ Google Chrome v26.0.1410.43

        Fichier : C:\Users\cemoha\AppData\Local\Google\Chrome\User Data\Default\Preferences

        [OK] Le fichier ne contient aucune entrée illégitime.

        Fichier : C:\Users\Emma\AppData\Local\Google\Chrome\User Data\Default\Preferences

        [OK] Le fichier ne contient aucune entrée illégitime.

        Fichier : C:\Users\sam\AppData\Local\Google\Chrome\User Data\Default\Preferences

        [OK] Le fichier ne contient aucune entrée illégitime.

        *************************

        AdwCleaner[R1].txt - [2255 octets] - [09/04/2013 07:58:54]
        AdwCleaner[S1].txt - [21570 octets] - [31/03/2013 15:02:40]
        AdwCleaner[S2].txt - [18002 octets] - [08/04/2013 11:27:03]
        AdwCleaner[S3].txt - [2626 octets] - [09/04/2013 07:21:30]
        AdwCleaner[S4].txt - [2189 octets] - [09/04/2013 07:59:50]

        ########## EOF - C:\AdwCleaner[S4].txt - [2249 octets] ##########
        0
    2. re

      relance adwcleaner et choisis "désinstaller"

      dis moi les problèmes qui persistent sur ton pc

      @+
      0
      1. adwcleaner désinstallé , j'ai ouvert ma page d'acceuil google et un rectangle en dessous de "google" avec une pub
        0
      2. je précise je sais pas si ça peut être utile, mon frère gd fan de mangas m'a souvent ramené des virus spams et autres en surfant sur ces sites pas très sécurisés, et c'est depuis qu'il est allé sur un site de mangas pr adultes que ces pubs viennent
        0
    3. re

      ajoute adblock plus dans les extentions de chrome et dis moi si ça va

      fais ceci aussi

      télécharge zhpdiag sur ton bureau (outil de diagnostic)

      le lien https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/

      le tuto http://www.security-helpzone.com/forum/Thread-ZHPDiag-Generer-un-rapport

      utilisateurs vista-w7-w8 exécuter en tant qu'administrateur (clic droit)

      pour lancer le scan clique sur le 2ème bouton en haut a gauche

      le rapport s'affichera sur ton bureau et dans C:\zhpdiag.txt

      poste le rapport via ce lien https://www.cjoint.com/

      @+
      0
      1. ok, je fais ça et reviens
        merci
        0
      2. re

        ok

        @+
        0
    4. salut

      fais ceci s'il te plaît

      télécharge usbfix sur ton bureau (clique sur la flèche verte)

      le lien http://general-changelog-team.fr/fr/downloads/viewdownload/15-outils-de-el-desaparecido/79-usbfix

      si ton pc émet 1 alerte, ignore la

      branche toutes tes sources de données externe a ton pc (clé USB, disque dur externe, etc...) sans les ouvrir

      le tuto https://www.malekal.com/tutoriels-logiciels/

      exécute le en tant qu'administrateur (clic droit)

      choisis le mode "suppression"

      le rapport s'affichera sur ton bureau et dans C:\UsbFix.txt

      poste le rapport via 1 copier/coller

      @+
      0
      1. re :)
        ok
        0
      2. re

        ############################## | UsbFix V 7.120 | [Suppression]

        Utilisateur: cemoha (Administrateur) # CEMOHA-PC
        Mis à jour le 30/03/2013 par El Desaparecido
        Lancé à 09:34:47 | 09/04/2013

        Site Web: https://www.sosvirus.net/
        Upload Malware: http://upload.sosvirus.org/
        Contact: contact@sosvirus.org

        PC: Acer (Aspire X1900) (x64-based PC)
        CPU: Pentium(R) Dual-Core CPU E5800 @ 3.20GHz (3203)
        RAM -> [Total : 4095 | Free : 1835]
        BIOS: Default System BIOS
        BOOT: Normal boot

        OS: Microsoft Windows 7 Édition Familiale Premium (6.1.7601 64-Bit) # Service Pack 1
        WB: Windows Internet Explorer 10.0.9200.16521

        SC: Security Center Service [Enabled]
        WU: Windows Update Service [Enabled]
        AV: avast! Internet Security [Enabled | Updated]
        FW: Windows FireWall Service [Enabled]

        C:\ (%systemdrive%) -> Disque fixe # 457 Go (307 Go libre(s) - 67%) [Acer] # NTFS
        D:\ -> Disque fixe # 457 Go (217 Go libre(s) - 48%) [Data] # NTFS
        E:\ -> CD-ROM
        H:\ -> CD-ROM

        ################## | El Desaparecido Section |

        HKLM\SOFTWARE | Run : [SuiteTray] - "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
        HKLM\SOFTWARE | Run : [EgisUpdate] - "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
        HKLM\SOFTWARE | Run : [EgisTecPMMUpdate] - "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
        HKLM\SOFTWARE | Run : [Hotkey Utility] - C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
        HKLM\SOFTWARE | Run : [MDS_Menu] - "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6"
        HKLM\SOFTWARE | Run : [ArcadeMovieService] - "C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe"
        HKLM\SOFTWARE | Run : [BEWINTERNET-FR-DMGP-V2SessionManager] - "C:\Program Files (x86)\Orange\IEWInternet\SessionManager\SessionManager.exe"
        HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
        HKLM\SOFTWARE | Run : [NPSStartup] -
        HKLM\SOFTWARE | Run : [EEventManager] - "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
        HKLM\SOFTWARE | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
        HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
        HKLM\SOFTWARE\wow6432Node | Run : [SuiteTray] - "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
        HKLM\SOFTWARE\wow6432Node | Run : [EgisUpdate] - "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
        HKLM\SOFTWARE\wow6432Node | Run : [EgisTecPMMUpdate] - "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
        HKLM\SOFTWARE\wow6432Node | Run : [Hotkey Utility] - C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
        HKLM\SOFTWARE\wow6432Node | Run : [MDS_Menu] - "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6"
        HKLM\SOFTWARE\wow6432Node | Run : [ArcadeMovieService] - "C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe"
        HKLM\SOFTWARE\wow6432Node | Run : [BEWINTERNET-FR-DMGP-V2SessionManager] - "C:\Program Files (x86)\Orange\IEWInternet\SessionManager\SessionManager.exe"
        HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
        HKLM\SOFTWARE\wow6432Node | Run : [NPSStartup] -
        HKLM\SOFTWARE\wow6432Node | Run : [EEventManager] - "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
        HKLM\SOFTWARE\wow6432Node | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
        HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
        HKLM\SOFTWARE | RunOnce : [] -
        HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
        HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
        HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
        HKU\S-1-5-21-3761213783-1523031584-3700297462-1000\SOFTWARE | Run : [MediaGet2] - C:\Users\cemoha\AppData\Local\MediaGet2\mediaget.exe --minimized
        HKU\S-1-5-21-3761213783-1523031584-3700297462-1000\SOFTWARE | Run : [DAEMON Tools Lite] - "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
        HKU\S-1-5-21-3761213783-1523031584-3700297462-1000\SOFTWARE | Run : [EA Core] - "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
        HKU\S-1-5-21-3761213783-1523031584-3700297462-1000\SOFTWARE | Run : [Yontoo Desktop] - "C:\Users\cemoha\AppData\Roaming\Yontoo\YontooDesktop.exe"
        HKU\S-1-5-21-3761213783-1523031584-3700297462-1005\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
        HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
        HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
        HKU\S-1-5-21-3761213783-1523031584-3700297462-1005\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
        HKU\S-1-5-21-3761213783-1523031584-3700297462-1005\SOFTWARE | RunOnce : [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default

        ################## | Processus Stoppés |

        Stoppé! C:\Windows\system32\nvvsvc.exe (856)
        Stoppé! C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (880)
        Stoppé! C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1268)
        Stoppé! C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (1360)
        Stoppé! C:\Windows\system32\nvvsvc.exe (1368)
        Stoppé! C:\Windows\System32\spoolsv.exe (1636)
        Stoppé! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1756)
        Stoppé! C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE (1836)
        Stoppé! C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE (1952)
        Stoppé! C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe (1976)
        Stoppé! C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (2004)
        Stoppé! C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe (2032)
        Stoppé! C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe (1236)
        Stoppé! C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe (1692)
        Stoppé! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (2284)
        Stoppé! C:\Program Files\Acer\Acer Updater\UpdaterService.exe (2440)
        Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2520)
        Stoppé! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (2552)
        Stoppé! C:\Windows\system32\taskhost.exe (3064)
        Stoppé! C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (2588)
        Stoppé! C:\Windows\System32\alg.exe (3536)
        Stoppé! C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (3316)
        Stoppé! C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (3932)
        Stoppé! C:\Windows\PixArt\Pac207\Monitor.exe (4044)
        Stoppé! C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe (2604)
        Stoppé! C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (3252)
        Stoppé! C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (3768)
        Stoppé! C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (3380)
        Stoppé! C:\Program Files (x86)\Twintech\UT30 Device Utilities\RTLRCtl.exe (2992)
        Stoppé! C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (4144)
        Stoppé! C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (4196)
        Stoppé! C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe (4204)
        Stoppé! C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe (4220)
        Stoppé! C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (4548)
        Stoppé! C:\Program Files\AVAST Software\Avast\AvastUI.exe (4556)
        Stoppé! C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (4564)
        Stoppé! C:\Windows\system32\SearchIndexer.exe (4816)
        Stoppé! C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (4844)
        Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (4960)
        Stoppé! C:\Windows\system32\DllHost.exe (5536)
        Stoppé! C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (1960)
        Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (4116)
        Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (3516)
        Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (4464)
        Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (6112)
        Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (3320)
        Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (2472)
        Stoppé! C:\Windows\system32\taskhost.exe (3096)
        Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (5592)
        Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (1288)

        ################## | Éléments infectieux |

        Supprimé! C:\LPCD.DAT
        Supprimé! C:\PA207.DAT

        (!) Fichiers temporaires supprimés.

        ################## | Registre |

        ################## | Mountpoints2 |

        Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\F
        Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{0b8a0180-c4bc-11e0-b549-1078d2e747ed}
        Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{6d4acdc4-edfe-11e0-8694-1078d2e747ed}
        Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{7572a450-ed05-11e0-9a20-1078d2e747ed}
        Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{9062f0a0-203a-11e1-a5ab-1078d2e747ed}
        Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{cecaabac-8955-11e1-804f-1078d2e747ed}
        Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{f9f1c4f1-6e3c-11e2-b78b-1078d2e747ed}

        ################## | Listing |

        [13/12/2012 - 20:27:55 | SHD ] C:\$RECYCLE.BIN
        [12/12/2011 - 08:21:09 | N | 16046] C:\0x040c.ini
        [12/12/2011 - 08:21:12 | N | 111104] C:\1036.MST
        [24/10/2011 - 14:29:59 | N | 12460] C:\Ad-Report-CLEAN[1].txt
        [24/10/2011 - 14:21:24 | N | 13345] C:\Ad-Report-SCAN[1].txt
        [24/10/2011 - 14:23:05 | N | 13411] C:\Ad-Report-SCAN[2].txt
        [10/10/2007 - 01:16:32 | D ] C:\book
        [25/09/2011 - 17:17:55 | D ] C:\Boonty
        [26/08/2010 - 13:12:16 | N | 8192] C:\BOOTSECT.BAK
        [05/04/2013 - 08:52:31 | D ] C:\Config.Msi
        [14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings
        [16/07/2010 - 02:33:30 | N | 5093] C:\FRZ1LP41.MD5
        [09/04/2013 - 08:00:46 | ASH | 3220627456] C:\hiberfil.sys
        [26/08/2010 - 12:27:08 | D ] C:\Intel
        [30/08/2011 - 09:33:01 | RHD ] C:\MSOCache
        [04/09/2011 - 11:29:16 | D ] C:\MyWinLockerData
        [11/01/2012 - 09:16:14 | N | 274313] C:\notice.pdf
        [22/08/2011 - 22:47:34 | D ] C:\NVIDIA
        [10/08/2011 - 17:20:49 | D ] C:\OEM
        [09/04/2013 - 08:00:46 | ASH | 4294172672] C:\pagefile.sys
        [14/07/2009 - 05:20:08 | D ] C:\PerfLogs
        [09/04/2013 - 08:35:47 | N | 512] C:\PhysicalDisk0_MBR.bin
        [31/03/2013 - 15:02:43 | D ] C:\Program Files
        [09/04/2013 - 08:24:17 | D ] C:\Program Files (x86)
        [09/04/2013 - 07:21:54 | HD ] C:\ProgramData
        [10/08/2011 - 17:19:27 | SHD ] C:\Recovery
        [10/10/2007 - 01:13:17 | N | 2246] C:\RHDSetup.log
        [12/12/2011 - 08:21:18 | N | 97979392] C:\Samsung New PC Studio.msi
        [06/04/2013 - 10:15:49 | SHD ] C:\System Volume Information
        [26/03/2013 - 13:00:53 | D ] C:\Temp
        [09/04/2013 - 09:37:25 | D ] C:\UsbFix
        [09/04/2013 - 09:37:34 | A | 11426] C:\UsbFix [Clean 2] CEMOHA-PC.txt
        [09/04/2013 - 09:30:24 | N | 11121] C:\UsbFix [Scan 1] CEMOHA-PC.txt
        [29/07/2012 - 15:23:57 | D ] C:\Users
        [24/10/2011 - 14:40:47 | D ] C:\Westwood
        [08/04/2013 - 11:29:16 | D ] C:\Windows
        [09/04/2013 - 08:35:49 | D ] C:\ZHP
        [03/10/2011 - 08:41:46 | SHD ] D:\$RECYCLE.BIN
        [05/08/2012 - 13:12:09 | N | 6745] D:\AlbumArtSmall.jpg
        [05/08/2012 - 13:12:09 | N | 25141] D:\AlbumArt_{1BC7CD96-D54A-4F0D-B4D8-080417420FB1}_Large.jpg
        [05/08/2012 - 13:12:09 | N | 6745] D:\AlbumArt_{1BC7CD96-D54A-4F0D-B4D8-080417420FB1}_Small.jpg
        [05/08/2012 - 13:12:09 | SH | 306] D:\desktop.ini
        [05/08/2012 - 13:12:09 | N | 25141] D:\Folder.jpg
        [08/04/2013 - 08:52:09 | D ] D:\Ma musique
        [11/03/2013 - 10:48:38 | D ] D:\Mes photos
        [25/03/2013 - 00:02:25 | D ] D:\Mes videos
        [22/11/2011 - 16:37:22 | D ] D:\msdownld.tmp
        [08/04/2013 - 08:48:08 | D ] D:\Progr.téléchargés
        [11/12/2011 - 20:00:49 | SHD ] D:\System Volume Information
        [27/03/2013 - 05:19:14 | RAD ] H:\VIDEO_TS
        [27/03/2013 - 05:19:14 | RAD ] H:\AUDIO_TS

        ################## | Vaccin |

        C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
        D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)

        ################## | E.O.F | https://www.sosvirus.net/ |
        0
    5. re

      maintenant, fais ceci

      télécharge MBAM sur ton bureau

      le lien https://www.malwarebytes.com/ (prend le free)

      le tuto https://www.donnemoilinfo.com/tuto/Malwarebytes-Anti-Malware/

      exécute le en tant qu'administrateur (clic droit)

      met le a jour (3ème bouton)

      fais 1 scan complet (tous les disques)

      le scan peut durer +-2H (laisse le bosser)

      si MBAM trouve quelque chose supprime la sélection (voir tuto 2ème page)

      poste le rapport via 1 copier/coller

      le rapport s'affichera sur ton bureau et dans rapport/log de MBAM

      @+
      0
      1. ok
        0
      2. examen fini rien trouvé..

        Malwarebytes Anti-Malware 1.70.0.1100
        www.malwarebytes.org

        Version de la base de données: v2013.04.09.03

        Windows 7 Service Pack 1 x64 NTFS
        Internet Explorer 10.0.9200.16521
        cemoha :: CEMOHA-PC [administrateur]

        09/04/2013 09:49:37
        mbam-log-2013-04-09 (09-49-37).txt

        Type d'examen: Examen complet (C:\|D:\|E:\|H:\|Q:\|)
        Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
        Options d'examen désactivées: P2P
        Elément(s) analysé(s): 578137
        Temps écoulé: 57 minute(s), 5 seconde(s)

        Processus mémoire détecté(s): 0
        (Aucun élément nuisible détecté)

        Module(s) mémoire détecté(s): 0
        (Aucun élément nuisible détecté)

        Clé(s) du Registre détectée(s): 0
        (Aucun élément nuisible détecté)

        Valeur(s) du Registre détectée(s): 0
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre détecté(s): 0
        (Aucun élément nuisible détecté)

        Dossier(s) détecté(s): 0
        (Aucun élément nuisible détecté)

        Fichier(s) détecté(s): 0
        (Aucun élément nuisible détecté)

        (fin)
        0
    6. re

      le rapport est propre

      tu me refais 1 zhpdiag s'il te plaît (comme le précédent)

      dis moi comment va le pc

      @+
      0
      1. re,

        d'accord j fais ça
        0
      2. les pages de pubs s ouvrent tjs..
        0
      3. salut

        je n'ai pas encore regardé ton dernier zhpdiag

        sur quel navigateur as-tu le problème?
        @+
        0
      4. re,

        sur mozilla, j utilisais tjs mozilla, mais là depuis que tu m'as fais installer adblok sur chrome j utilise google chrome pas de bup, j'ai essayé internet explorer les pubs viennent aussi, il me semble qu il n'y ai que google chrome qui ne soit pas "infesté". j'avais pas pensé a désinstaller mozilla et le réinstaller, je vais essayer de faire ça, mais pour internet explorer je n'ai jamais désinstallé ce navigateur je ne m'en sert jamais je sais pas si le désinstaller affectera mon ordi en fait. Je vais déja faire pour mozilla comme je viens de te dire et vais voir si les pubs persistent, en attendant pr surfer en tte tranquilité j utilise chrome . adblock fait bien soon travail.
        0