Se débarasser de storm alert

Résolu
Sublimo2 Messages postés 8 Statut Membre -  
¡El Desaparecido! Messages postés 1519 Date d'inscription   Statut Membre Dernière intervention   -
Bonjour,

Storm Alert (et un espèce de questionnaire en ligne à la con) me harcèle depuis quelques heures maintenant ! Que faire pour s'en débarasser ?!

Merci d'avance.

13 réponses

  1. ¡El Desaparecido! Messages postés 1519 Date d'inscription   Statut Membre Dernière intervention   195
     
    Hello ,

    Tu as installé des adwares et des logiciels indésirables sur ton PC (Certainement à ton insu).
    Pour comprendre, je t'invite à lire ce sujet : http://www.sosvirus.net/topic82172.html

    # Télécharge AdwCleaner par Xplode sur ton bureau.
    # Exécute AdwCleaner.exe.

    # Fais clic droit dessus, exécuter en tant qu'administrateur sous Windows : 7/8 et Vista
    # Choisi l'option Scanner
    # Choisi l'option Nettoyer
    # Accepte l'avertissement en cliquant sur OK



    # Une fois le scan fini, un rapport s'ouvrira. Poste son contenu dans ta prochaine réponse.
    -> Si le copié collé ne fonctionne pas, utilise SosUpload pour héberger le rapport, et communique le lien généré dans ta réponse.
    # Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt
    0
  2. Sublimo2 Messages postés 8 Statut Membre
     
    Merci de ton aide !!!

    AdwCleaner v4.104 - Rapport créé le 08/12/2014 à 19:29:07
    # Mis à jour le 05/12/2014 par Xplode
    # Database : 2014-12-08.1 [Live]
    # Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Nom d'utilisateur : Romain - ROMAIN-PC
    # Exécuté depuis : C:\Users\Romain\Downloads\adwcleaner_4.104.exe
    # Option : Nettoyer

    ***** [ Services ] *****

    ***** [ Fichiers / Dossiers ] *****

    Dossier Supprimé : C:\Users\Romain\AppData\Local\StormAlert
    Fichier Supprimé : C:\Users\Romain\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
    Fichier Supprimé : C:\Users\Romain\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal

    ***** [ Tâches planifiées ] *****

    ***** [ Raccourcis ] *****

    ***** [ Registre ] *****

    Clé Supprimée : HKCU\Software\Classes\keepmysearch

    ***** [ Navigateurs ] *****

    -\\ Internet Explorer v11.0.9600.17420

    -\\ Mozilla Firefox v30.0 (fr)

    -\\ Google Chrome v39.0.2171.71

    *************************

    AdwCleaner[R0].txt - [11348 octets] - [10/10/2013 02:07:26]
    AdwCleaner[R1].txt - [3170 octets] - [08/12/2014 19:01:55]
    AdwCleaner[R2].txt - [1460 octets] - [08/12/2014 19:26:48]
    AdwCleaner[R3].txt - [1516 octets] - [08/12/2014 19:28:24]
    AdwCleaner[S0].txt - [9669 octets] - [10/10/2013 02:08:02]
    AdwCleaner[S1].txt - [3313 octets] - [08/12/2014 19:04:31]
    AdwCleaner[S2].txt - [1441 octets] - [08/12/2014 19:29:07]
    0
  3. Sublimo2 Messages postés 8 Statut Membre
     
    ?
    0
  4. Sublimo2 Messages postés 8 Statut Membre
     
    Et un petit offer4u s'est rajouté par dessus.
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. ¡El Desaparecido! Messages postés 1519 Date d'inscription   Statut Membre Dernière intervention   195
     
    Re,

    Désolé, je dinais ..

    # Télécharge MalwareBytes
    # Procède à l'installation de celui çi (Décocher "Activer l'essai gratuit de Malwarebytes Anti-Malware Premium")

    # Clic sur Mettre à jour (à droite, au centre)
    # Clic sur Examen (en haut)
    # Sélectionne Examen "Menaces"
    # Clic sur Examiner maintenant


    # A la fin du scan clic sur Tout mettre en quarantaine !
    # Clic sur Copier dans le Presse-papiers
    # Un rapport va s'ouvrir. Copie/Colle son contenue dans ta prochaine réponse.

    0
  7. Sublimo2 Messages postés 8 Statut Membre
     
    Re !

    Oui excuse mon empressement, mais là il se met à partir un peu dans tous les sens ^^

    Voilà !

    Malwarebytes Anti-Malware
    www.malwarebytes.org

    Scan Date: 08/12/2014
    Scan Time: 20:55:39
    Logfile:
    Administrator: Yes

    Version: 2.00.4.1028
    Malware Database: v2014.12.08.08
    Rootkit Database: v2014.12.08.01
    License: Free
    Malware Protection: Disabled
    Malicious Website Protection: Disabled
    Self-protection: Disabled

    OS: Windows 7 Service Pack 1
    CPU: x64
    File System: NTFS
    User: Romain

    Scan Type: Threat Scan
    Result: Completed
    Objects Scanned: 326593
    Time Elapsed: 8 min, 47 sec

    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Enabled
    PUM: Enabled

    Processes: 2
    PUP.Optional.StormAlert.A, C:\ProgramData\YgjHaD\JlqRGWq.exe, 2280, Delete-on-Reboot, [0167352bf08c3105411de40b12ef38c8]
    PUP.Optional.StartPoint.A, C:\Users\Romain\AppData\Local\StartPoint\startpoint\1.3.17.3\startpoint.exe, 3972, Delete-on-Reboot, [83e5d58bfa82cb6b13b4ff5ca35dea16]

    Modules: 1
    PUP.Optional.StartPoint.A, C:\Users\Romain\AppData\Local\StartPoint\startpoint\1.3.17.3\rlbnaliI.dll, Delete-on-Reboot, [a2c68fd1d4a8ee48fbc2262114ef3bc5],

    Registry Keys: 2
    PUP.Optional.StormAlert.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\JlqRGWq, Quarantined, [0167352bf08c3105411de40b12ef38c8],
    PUP.Optional.StartPoint.A, HKU\S-1-5-21-3197756155-1369968048-3753250289-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\startpoint, Quarantined, [a2c68fd1d4a8ee48fbc2262114ef3bc5],

    Registry Values: 1
    PUP.Optional.StartPoint.A, HKU\S-1-5-21-3197756155-1369968048-3753250289-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|StartPoint, C:\Users\Romain\AppData\Local\StartPoint\startpoint\1.3.17.3\startpoint.exe, Quarantined, [83e5d58bfa82cb6b13b4ff5ca35dea16]

    Registry Data: 0
    (No malicious items detected)

    Folders: 3
    PUP.Optional.StormAlert.A, C:\Users\Romain\AppData\Local\StormAlert, Quarantined, [5b0da4bc8af27abc1637bb9432d1ef11],
    PUP.Optional.StartPoint.A, C:\Users\Romain\AppData\Local\StartPoint\startpoint, Delete-on-Reboot, [a2c68fd1d4a8ee48fbc2262114ef3bc5],
    PUP.Optional.StartPoint.A, C:\Users\Romain\AppData\Local\StartPoint\startpoint\1.3.17.3, Delete-on-Reboot, [a2c68fd1d4a8ee48fbc2262114ef3bc5],

    Files: 31
    PUP.Optional.StormAlert.A, C:\ProgramData\YgjHaD\JlqRGWq.exe, Delete-on-Reboot, [0167352bf08c3105411de40b12ef38c8],
    PUP.Optional.StartPoint.A, C:\Users\Romain\AppData\Local\StartPoint\startpoint\1.3.17.3\startpoint.exe, Delete-on-Reboot, [83e5d58bfa82cb6b13b4ff5ca35dea16],
    PUP.Optional.StormAlert.A, C:\ProgramData\YgjHaD\dat\aiVBwsQ.exe, Delete-on-Reboot, [afb966fa1e5eaf87263805ea738ea55b],
    PUP.Optional.StormAlert.A, C:\ProgramData\YgjHaD\dat\hRRLZNYlU.exe, Delete-on-Reboot, [f771560ae49843f3ed71a14e9e6326da],
    PUP.Optional.HealthAlert.A, C:\ProgramData\YgjHaD\dat\xkXGpd.dll, Delete-on-Reboot, [3d2b4d132c50d5616dceb3a252b3fa06],
    PUP.Optional.InstalleRex, C:\$Recycle.Bin\S-1-5-21-3197756155-1369968048-3753250289-1000\$RO21L59.exe, Quarantined, [5f09055b2359d462c74c632ab849847c],
    PUP.Optional.StormAlert.A, C:\Users\Romain\AppData\Local\Temp\Setup.exe, Quarantined, [1e4ab0b0047844f216edf1706799d42c],
    PUP.Optional.StartPoint.A, C:\Users\Romain\AppData\Local\Temp\startpoint_1.exe, Quarantined, [abbdc799e79571c5a522124968981be5],
    PUP.Optional.SmartBar.A, C:\Users\Romain\AppData\Local\Temp\Installer.exe, Quarantined, [60082937c1bbfe380b95d14d8a76619f],
    PUP.Optional.QuickShare.A, C:\Users\Romain\AppData\Local\Temp\QuickShare1.exe, Quarantined, [ce9ab3ad6d0fec4afed921ff09f710f0],
    Trojan.Exploit, C:\Users\Romain\AppData\Local\Temp\aznettor-win32_0.6.zip, Quarantined, [244464fc2755b581bf9c86c1c93ca858],
    PUP.Optional.Somoto, C:\Users\Romain\AppData\Local\Temp\bitool.dll, Quarantined, [5d0b6af6acd078be31445e359b67e41c],
    PUP.Optional.Somoto.A, C:\Users\Romain\AppData\Local\Temp\nsbF05F.tmp, Quarantined, [7fe9fd63403c191db8dcc56f7f8219e7],
    PUP.Optional.Somoto.A, C:\Users\Romain\AppData\Local\Temp\nse98A.tmp, Quarantined, [acbc90d095e78aaca2f2d0641ae7fc04],
    PUP.Optional.Conduit.A, C:\Users\Romain\AppData\Local\Temp\ct2504091\ism.exe, Quarantined, [15538ed24e2e122403c4b0f48b768e72],
    PUP.Optional.Wajam.A, C:\Users\Romain\AppData\Local\Temp\is42483369\39002970_stp\wajam_download.exe, Quarantined, [a9bf4b1599e347ef68e765e25fa19b65],
    PUP.Optional.Net01.A, C:\Users\Romain\Downloads\7z922.exe, Quarantined, [6bfd81df7804c472909e4a86ff05ad53],
    PUP.Optional.OpenCandy.A, C:\Users\Romain\Downloads\winamp565_full_emusic-7plus_fr-fr.exe, Quarantined, [a0c83b25ec909b9b21a15ee4956b3cc4],
    PUP.Optional.OpenCandy, C:\Users\Romain\Downloads\DTLite4471-0337.exe, Quarantined, [0e5a134d324a05318d55d1bab74e6e92],
    PUP.Optional.OpenCandy, C:\Users\Romain\Downloads\daemon-tools-lite_4-47-1-0337_fr_10729.exe, Quarantined, [a1c7421e4933211522c027649f662cd4],
    PUP.Optional.SnapDo.A, C:\Windows\Installer\317cd.msi, Quarantined, [2147d98791ebb086e4e747593bc65fa1],
    PUP.Optional.StormAlert.A, C:\Users\Romain\AppData\Local\StormAlert\data2.dat, Quarantined, [5b0da4bc8af27abc1637bb9432d1ef11],
    PUP.Optional.StartPoint.A, C:\Users\Romain\AppData\Local\StartPoint\startpoint\1.3.17.3\app.ini, Quarantined, [a2c68fd1d4a8ee48fbc2262114ef3bc5],
    PUP.Optional.StartPoint.A, C:\Users\Romain\AppData\Local\StartPoint\startpoint\1.3.17.3\ieds.xml, Quarantined, [a2c68fd1d4a8ee48fbc2262114ef3bc5],
    PUP.Optional.StartPoint.A, C:\Users\Romain\AppData\Local\StartPoint\startpoint\1.3.17.3\pffKohpb.dll, Quarantined, [a2c68fd1d4a8ee48fbc2262114ef3bc5],
    PUP.Optional.StartPoint.A, C:\Users\Romain\AppData\Local\StartPoint\startpoint\1.3.17.3\res.dll, Quarantined, [a2c68fd1d4a8ee48fbc2262114ef3bc5],
    PUP.Optional.StartPoint.A, C:\Users\Romain\AppData\Local\StartPoint\startpoint\1.3.17.3\rlbnaliI.dll, Delete-on-Reboot, [a2c68fd1d4a8ee48fbc2262114ef3bc5],
    PUP.Optional.StartPoint.A, C:\Users\Romain\AppData\Local\StartPoint\startpoint\1.3.17.3\rvt.js, Quarantined, [a2c68fd1d4a8ee48fbc2262114ef3bc5],
    PUP.Optional.StartPoint.A, C:\Users\Romain\AppData\Local\StartPoint\startpoint\1.3.17.3\serp.js, Quarantined, [a2c68fd1d4a8ee48fbc2262114ef3bc5],
    PUP.Optional.StartPoint.A, C:\Users\Romain\AppData\Local\StartPoint\startpoint\1.3.17.3\sqlite.dll, Quarantined, [a2c68fd1d4a8ee48fbc2262114ef3bc5],
    PUP.Optional.StartPoint.A, C:\Users\Romain\AppData\Local\StartPoint\startpoint\1.3.17.3\startup.exe, Quarantined, [a2c68fd1d4a8ee48fbc2262114ef3bc5],

    Physical Sectors: 0
    (No malicious items detected)

    (end)
    0
  8. ¡El Desaparecido! Messages postés 1519 Date d'inscription   Statut Membre Dernière intervention   195
     
    Je comprend ton impatience ;)

    # Télécharge OTM de OldTimer sur ton bureau.

    # Double-clique sur OTM.exe pour le lancer.
    # Sous Vista/Seven/8 , clic droit -> lancer en tant qu'administrateur
    # Copie la liste ci-dessous et colle-la dans le cadre de gauche de OTM sous Paste Instructions for Items to be Moved.




    :services
    JlqRGWq

    :files
    C:\ProgramData\YgjHaD
    C:\Users\Romain\AppData\Local\StormAlert
    C:\Users\Romain\AppData\Local\StartPoint
    %TEMP%\*.*
    %TEMP%\*_*

    :Reg

    :commands
    [emptytemp]


    # Clique sur "MoveIt!" .
    # Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demanderas de redémarrer l'ordinateur.
    # Si c'est le cas, accepte en cliquant sur "YES".
    # Post le rapport dans ta prochaine réponse.
    # Le rapport est situé dans C:\_OTM\MovedFiles (Le nom du rapport correspond au moment de sa création : date_heure.log).

    ########

    Nous allons éffectuer un diagnostic de ton ordinateur.

    # Télécharge ZHPDiag de Nicolas Coolman et enregistre-le sur ton Bureau.

    # Installe le logiciel.
    # Sous Windows Vista et Windows 7, il faut lancer le fichier par clic-droit -> Exécuter en tant qu'administrateur.
    # N'oublie pas de cocher la case qui permet de mettre un raccourci sur le Bureau.

    # L'outil a créé 2 icônes ZHPDiag et ZHPFix sur le Bureau.
    # Double-clique sur ZHPDiag pour lancer l'exécution.

    # Clic sur Complet .
    # Tu patientes jusqu'à ce que le scan affiche 100%.

    -> http://upload.sosvirus.net/images/2014/04/16/ZHPDiagc82cd.png

    # Le rapport est sauvegardé sur le bureau.
    # Ferme ZHPDiag.

    # Héberger et transmettre un rapport.

    # Rend toi sur SosUpload.
    # Clique sur Parcourir et cherche le rapport de ZHPDiag sur ton bureau
    # Clique ensuite sur Envoyer le fichier.
    # Tu obtiendras un lien de téléchargement du rapport.
    # Transmet ce lien dans ta prochaine réponse stp.

    0
  9. Sublimo2 Messages postés 8 Statut Membre
     
    ZHP

    http://upload.sosvirus.net/www/?a=d&i=amovfqSQly

    OTM:

    http://upload.sosvirus.net/www/?a=d&i=H11UN2NBrE
    0
  10. ¡El Desaparecido! Messages postés 1519 Date d'inscription   Statut Membre Dernière intervention   195
     
    Hello,

    # Copie tout le texte présent ci-dessous ( clic sur doit ("Tout sélectionner") / Clique droit ("copier").


    Script ZHPFix
    M3 - MFPP: Plugins - [Romain] -- C:\Users\Romain\AppData\Roaming\Mozilla\Firefox\Profiles\sae8lwxw.default\searchplugins\startpointkms.xml
    M0 - MFSP: prefs.js [Romain - sae8lwxw.default] http://search.strtpoint.com
    R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.strtpoint.com
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 186.215.126.175:3128
    O2 - BHO: (no name) [64Bits] - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Clé orpheline
    O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
    O4 - GS\Desktop [Romain]: orbit_api - Raccourci.lnk . (...) -- C:\Users\Romain\Documents\Vuze Downloads\Far Cry 3 [MULTI12][PCDVD][2DVDs][RELOADED][WwW.GamesTorrents.CoM]\Far.Cry.3.Crack.Only-RELOADED\orbit_api.ini (.not file.) =>P2P.Azureus
    O17 - HKLM\System\CCS\Services\Tcpip\..\{1D9A0C8C-43F8-4F3D-93DD-F05A41AB5455}: DhcpNameServer = 212.27.40.241 212.27.40.240
    O17 - HKLM\System\CS1\Services\Tcpip\..\{1D9A0C8C-43F8-4F3D-93DD-F05A41AB5455}: DhcpNameServer = 212.27.40.241 212.27.40.240
    O17 - HKLM\System\CS2\Services\Tcpip\..\{1D9A0C8C-43F8-4F3D-93DD-F05A41AB5455}: DhcpNameServer = 212.27.40.241 212.27.40.240
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240
    [MD5.00000000000000000000000000000000] [APT] [StartPoint] (...) -- C:\Users\Romain\AppData\Local\StartPoint\startpoint\1.3.17.3\startpoint.exe (.not file.) [0]
    [MD5.00000000000000000000000000000000] [APT] [StartPoint Updater] (...) -- C:\Users\Romain\AppData\Local\StartPoint\startpoint\1.3.17.3\startup.exe (.not file.) [0]
    [MD5.00000000000000000000000000000000] [APT] [{71C08F39-D699-4374-9830-2E333A18BC21}] (...) -- E:\INSTALL.exe (.not file.) [0]
    [MD5.00000000000000000000000000000000] [APT] [{742B0B1B-8B89-4170-B9C5-AF7DF3665D2D}] (...) -- E:\INSTALL.exe (.not file.) [0]
    [MD5.00000000000000000000000000000000] [APT] [{A5F0E2CC-F435-487D-BFCB-04C93C20A7C0}] (...) -- C:\Users\Romain\AppData\Local\Temp\Temp1_Install_Win7_7072_05222013.zip\Install_Win7_7072_05222013\setup.exe (.not file.) [0]
    [MD5.47066BD8E5553B821D355449310EF858] [APT] [{B0CD538B-744E-4C8D-95FA-4F46570160B2}] (.Intel Corporation.) -- C:\Users\Romain\Downloads\Win64_15319.exe [154970456]
    O61 - LFC: 08/12/2014 - 21:39:22 ---A- . (...) -- C:\Users\Romain\Downloads\7z920.exe [1110476]
    O69 - SBI: SearchScopes [HKCU] {26F21ED7-33CE-449C-8C10-F2ECC9A2D1A0} - (Search The Web (Start Point)) - http://search.strtpoint.com =>Adware.IMBooster
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CC1C2EE8-8E03-4D79-9758-C208D4438A3E}] =>PUP.QuickShare^
    [HKLM\Software\Classes\setup.player] =>Spyware.MarketScore
    [HKLM\Software\Classes\setup.player.2k2] =>Spyware.MarketScore
    [HKCR\CLSID\{33BCC8EC-0D01-4E10-AD3D-4DAF749873ED}] (Browser Application State) =>PUP.CrossRider^
    [HKCR\CLSID\{ADBE6DEC-9B04-4A3D-A09C-4BB38EF1351C}] (XAML Browser Application) =>PUP.CrossRider^
    [HKCR\CLSID\{E569BDE7-A8DC-47F3-893F-FD2B31B3EEFD}] (Browser Application State) =>PUP.CrossRider^
    EmptyTemp
    EmptyFlash
    EMPTYCLSID


    # Lance ZHPFix à partir du raccourci sur ton Bureau (si tu es sous Windows Vista ou 7, fais un clic-droit -> Exécuter en temps qu'administrateur).
    # Clique sur Importer
    # Les lignes précedemment copiées doivent être collées dans le cadre
    # Si c'est le cas, Clic sur GO



    # Confirmes les nettoyages des données en cliquant sur "Oui"

    # Une fois le scan terminé rends toi sur le bureau, le fichier[b] ZHPFixReport /bà été crée.
    # Héberge le rapport ZHPFixReport sur SosUpload, puis copie/colle le lien fourni dans ta prochaine réponse.
    # Attention : Ce script a été spécialement fait pour ce PC . Toute réutilisation peut endommager sévèrement votre système.
    0
  11. Sublimo2 Messages postés 8 Statut Membre
     
    Voilà le travail !

    http://upload.sosvirus.net/www/?a=d&i=rUykc7UCLC
    0
  12. ¡El Desaparecido! Messages postés 1519 Date d'inscription   Statut Membre Dernière intervention   195
     
    Hello,

    Comment va ton PC après ce nettoyage ?
    0
  13. Sublimo2 Messages postés 8 Statut Membre
     
    Oui beaucoup mieux le problème semble réglé merci beaucoup !
    0
  14. ¡El Desaparecido! Messages postés 1519 Date d'inscription   Statut Membre Dernière intervention   195
     
    Hello , impec :)

    Oublie pas de mettre résolu stp (Tout en haut de ton sujet)

    Pour supprimer les outils de désinfections utilisés :

    Télécharges DelFix par Xplode sur ton Bureau.

    Lance DelFix, exécuter en tant qu'administrateur sous Windows : 7/8 et Vista
    Coche les cases suivantes :

    Supprimer les outils de désinfection
    Purger la restauration système



    Bonne fin de semaine :)
    0