Pub intenpestif

Résolu
Bonjour
depuis un bon bou de temps j'ai des pub qui s'affiche quand je navigue sur le net
les pub sont du genre telecharger de la musique ou sa me di que mon pc est infecter de spyware et il fo ke g clique sur la pub pour telecharger un antispyware

je possede kaspersky mais il ne détecte rien
j'ai aussi analyser mon pc avec spybot, ad-aware, a-squared
mais tous ses logiciels ne detecte rien d'anormal

pouver me dire commen faire s'il vous plai

ps: j'ai un pc sous vista

merci
Configuration: Windows Vista
Internet Explorer 7.0

14 réponses

  1. Contributeur sécurité
    colle un rapport hijackthis

    https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/29061.html

    -----------------------------------
    scan avec rogue remover::

    http://www.libellules.ch/dotclear/index.php?2006/11/29/1518-rogue-remover

    -------------------------------------
    puis cwshredder

    https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/27497.html

    ------------------------
    installe et lance BHO DEMON

    https://www.01net.com/telecharger/windows/Utilitaire/cryptage_et_securite/fiches/32724.html

    dans la fenetre qui s'affiche, il y a indiqueé tous les barres d'outils et autres logiciles gréfés sur ton ordi. les lignes vertes sont jugées saines, les rouges et jaunes sont estimées comme dangereuses: dans ce cas il faut les desactiver en decochant la case situé a gauche de chaque ligne.

    si la ligne n'est pas colorée et comporte la mention unknown, double clique dessus , des explication apparaitrons, si il y a un doute desactiv ces ligne aussi.

    -----------------------

    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    Télécharger sur le bureau
    Navilog.zip
    = Double-Clic navilog1.zip
    = Extraire tout sur le bureau
    = Double-Clic navilog1 qui est sur le bureau
    = Appuyer sur une touche jusqu' arriver aux options
    = Choisir option 1

    un rapport : fixnavi.txt dans C : va se creer
    le copier/coller dans ton prochain message.

    = Redémarrer en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
    Attention, pas d’accès à internet dans ce mode. Enregistrer ou imprimer les consignes. Relancer le Pc et tapoter la touche F8, jusqu’à l’apparition des inscriptions avec choix de démarrage
    Avec les touches « flèches », sélectionner Mode sans échec ==> entrée ==>nom utilisateur habituel
    = Lance navilog1
    = Cette fois-ci choisi l'option 2
    = Navilog va faire le nettoyage.. patient jusqu'à ce qui soit marqué *** Nettoyage Termine le ..... ***
    = Un rapport va être génrer sur ton C:\ qui sera en option 2
    Note: le bureau disparaît

    = Redémarre en mode normal et colle le contenu du rapport de navilog (qui est en option 2)

    utilise aussi pour supprimer tes traces

    -----------------------------------------
    CCLEANER: (lance un netoyage et repare les clés) sans installer la barre yahoo
    https://www.01net.com/

    ensuite:

    scan avec des antiespions(en mode sans echec):

    spybot :

    https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/26157.html

    si tout c'est bien passer redemarre en mode normal et desactive la restauration syteme pour purger les virus qui seraient dedans puis reactive là (dans DEMARRER puis TOUS LES PROGRAMMES puis ACCESSOIRE puis OUTILS SYSTEME puis RESTAURATION SYSTEME puis parametre)

    D/puis fait un scan en ligne avec un des suivants: et colle le rapport)

    Panda en ligne :
    http://pandasoftware.fr

    kaspersky en ligne :
    https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr

    bitdefender en ligne :
    http://www.bitdefender.fr/scan_fr/scan8/ie.html
    0
    1. Logfile of HijackThis v1.99.1
      Scan saved at 20:52:19, on 12/06/2007
      Platform: Unknown Windows (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16386)

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
      C:\Program Files\Common Files\logishrd\LComMgr\Communications_Helper.exe
      C:\Program Files\Common Files\logishrd\LComMgr\LVComSX.exe
      C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
      C:\Windows\System32\akxgyxjx.exe
      C:\Windows\System32\rundll32.exe
      C:\Windows\System32\rundll32.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Program Files\Windows Media Player\wmplayer.exe
      C:\Program Files\Internet Explorer\IEUser.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\CCleaner\ccleaner.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil9c.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\PROGRA~1\IZArc\IZArc.exe
      C:\Users\Lucien\AppData\Local\Temp\ARC373D\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.medion.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
      O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe"
      O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
      O4 - HKLM\..\Run: [akxgyxjx] c:\windows\system32\akxgyxjx.exe akxgyxjx
      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
      O11 - Options group: [INTERNATIONAL] International*
      O13 - Gopher Prefix:
      O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll
      O20 - Winlogon Notify: klogon - C:\Windows\system32\klogon.dll
      O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
      O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
      O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
      O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
      O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
      O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
      O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
      O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
      0
      1. rogue remover et cwshredder ne detecte rien

        bhodemon 2vert pa de rouge
        et 3 unknow navilog me met ne fonctionne que sous xp dc sane march pa car g vista
        0
        1. Contributeur sécurité
          fait la suite et smitfraud fix

          smit fraud fix

          http://telechargement.zebulon.fr/smitfraudfix.html

          2/ double clique sur smitfraudfix. puis selectionne 1 et appuyer sur entrée afin de créer le rapport des infection présentes. une fois le rapport effectué redemarre en mode sans echec (en appuyant sur F8 ou suppr, ou F5 au demarrage en général)

          3/ puis refaire comme en 2/ mais selectionne l'option 2 et appuyer sur entrée pour commencer la desinfection. lorsque le programme demande si tu veut nettoyer le registre metsoui en tapant 0 et entrée

          puis avg antispyware

          https://www.01net.com/telecharger/
          0
          1. mitFraudFix v2.195

            Scan done at 22:22:49,61, 12/06/2007
            Run from C:\Users\Lucien\SmitfraudFix
            OS: Microsoft Windows [version 6.0.6000] - Windows_NT
            The filesystem type is NTFS
            Fix run in normal mode

            »»»»»»»»»»»»»»»»»»»»»»»» Process

            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\spoolsv.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\Dwm.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\DAEMON Tools\daemon.exe
            C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
            C:\Program Files\Common Files\logishrd\LComMgr\Communications_Helper.exe
            C:\Program Files\Common Files\logishrd\LComMgr\LVComSX.exe
            C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
            C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
            C:\Windows\System32\akxgyxjx.exe
            C:\Windows\System32\rundll32.exe
            C:\Windows\ehome\ehtray.exe
            C:\Windows\System32\rundll32.exe
            C:\Windows\ehome\ehmsas.exe
            C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
            C:\Program Files\a-squared Free\a2service.exe
            C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
            C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            C:\Windows\system32\PnkBstrA.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\SearchIndexer.exe
            C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
            C:\Windows\system32\WUDFHost.exe
            C:\Windows\ehome\ehsched.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\wbem\wmiprvse.exe
            C:\Windows\ehome\ehRecvr.exe
            C:\Windows\system32\wbem\unsecapp.exe
            C:\Windows\system32\SearchProtocolHost.exe
            C:\Program Files\Internet Explorer\ieuser.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Windows\servicing\TrustedInstaller.exe
            C:\Windows\system32\SearchFilterHost.exe
            C:\Windows\system32\Macromed\Flash\FlashUtil9c.exe
            C:\Windows\system32\cmd.exe
            C:\Windows\system32\conime.exe
            C:\Windows\system32\wbem\wmiprvse.exe

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            »»»»»»»»»»»»»»»»»»»»»»»» C:\

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

            C:\Windows\system32\sysmain.dll FOUND !

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Lucien

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Lucien\Application Data

            »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Lucien\FAVORI~1

            »»»»»»»»»»»»»»»»»»»»»»»» Desktop

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

            »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, following keys are not inevitably infected!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, following keys are not inevitably infected!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLs"="C:\\PROGRA~1\\KASPER~1\\KASPER~1.0\\r3hook.dll"
            "LoadAppInit_DLLs"=dword:00000001

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
            !!!Attention, following keys are not inevitably infected!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

            »»»»»»»»»»»»»»»»»»»»»»»» Rustock

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            Description: 802.11 USB Wireless LAN Adapter #2
            DNS Server Search Order: 192.168.1.1

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{4E9EB204-615D-45C2-B062-EBCD4945CCFF}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CCS\Services\Tcpip\..\{E6133079-667E-41D5-8F25-44F874AB4FC0}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{4E9EB204-615D-45C2-B062-EBCD4945CCFF}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{E6133079-667E-41D5-8F25-44F874AB4FC0}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

            »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

            »»»»»»»»»»»»»»»»»»»»»»»» End
            0
            1. pa pu faire l'option 2 en mode san echec car quand je lance smitfraudfix il me demande pa doption mm si g tap 2 et ke g fai entrer rien ne se pass
              g v faire une analyse antivirus en ligne
              0
              1. impossible d'analyser en ligne avec kaspersky bitdefender et panda
                car il ne son pa encor compatible vista
                commen faire g toujour de page pub ki saffiche
                0
                1. Contributeur sécurité
                  essaye le scan en ligne liveone care

                  http://onecare.live.com/site/fr-fr/default.htm
                  0
                  1. Contributeur sécurité
                    regarde la essaye black light

                    popups ouverture de fenetres internet publicitaires pop up
                    0
                    1. il a detecter et effacer un virus mai g c pa si c le bon gv surfer et gt redi sa
                      merci bocou
                      0
                      1. sa a ler davoir marcher
                        merci bocou bone continuation
                        0