You are missing the plugin to play the video

Résolu
Bonjour,
Infecté par ce virus sous forme de fenêtre qui ralentit mon pc, ouvre des pages de pub...rien à faire pour le faire sauter, adwcleaner, malwarebyte....
merci de votre aide

6 réponses

  1. Modérateur
    Salut,

    Tu as installé des adwares et programmes parasites sur ton PC.
    Voici la procédure à suivre pour les supprimer :

    Commence par ceci :

    Suis ce tutorial : https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/
    Cela va générer deux rapports FRST.
    Envoie comme expliqué, ces deux rapports sur le site http://pjjoint.malekal.com et donne les trois liens pjjoint de ces rapports afin qu'ils puissent être consultés.

    0
    1. merci, voici les 3 liens
      http://pjjoint.malekal.com/files.php?id=20150419_c9e511p13s11
      http://pjjoint.malekal.com/files.php?id=20150419_h5g11e9m8c8
      http://pjjoint.malekal.com/files.php?id=FRST_20150419_d14q8f6z6i5
      0
  2. Modérateur
    Voici la correction à effectuer avec FRST.
    Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix

    Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
    Copie/colle dedans ce qui suit :

    () C:\Users\SOCOOL\AppData\Roaming\Wandoujia2\Applications\2.76.0.7151\wandoujia_helper.exe
    S2 034f3c40; c:\Program Files (x86)\SystemMolder\SystemMolder.dll [1646592 2015-02-15] () [File not signed]
    S2 pizogoru; C:\Users\SOCOOL\AppData\Roaming\VOPackage\VOsrv.exe [X] <==== ATTENTION
    2015-02-15 14:28 - 2015-02-15 14:28 - 00000000 ____D () C:\Program Files (x86)\SystemMolder
    2015-02-15 14:27 - 2015-02-16 16:56 - 00000000 ____D () C:\Program Files (x86)\UniDeals
    2015-02-15 14:26 - 2015-02-16 09:28 - 00000000 ____D () C:\ProgramData\{6945b07d-5ef8-9ad5-6945-5b07d5efc1f5}
    2015-02-15 14:26 - 2015-02-15 14:26 - 00000000 ____D () C:\Program Files (x86)\UniDeealsi
    HKU\S-1-5-21-2599192488-2471704336-1159247255-1000\...\Run: [SoftonicAssistant] => C:\Users\SOCOOL\AppData\Local\SoftonicAssistant\SoftonicAssistant.exe
    Startup: C:\Users\SOCOOL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wandoujia_helper.lnk
    ShortcutTarget: wandoujia_helper.lnk -> C:\Users\SOCOOL\AppData\Roaming\Wandoujia2\Applications\2.76.0.7151\wandoujia_helper.exe ()

    Une fois, le texte coller dans le bloc-note.
    Menu Fichier puis Enregistrer sous.
    A gauche, place toi sur le bureau.
    Dans le champs en bas, nom du fichier mets : fixlist.txt
    Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.

    Relance FRST et clic sur le bouton Fix
    Selon comment un redémarrage est nécessaire (pas obligatoire).
    Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.

    Redémarre l'ordinateur

    puis réinitialise tes navigateurs:
    ==================================
    Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :

    0
    1. fixlog

      Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-02-2015
      Ran by SOCOOL at 2015-02-16 19:50:27 Run:1
      Running from C:\Users\SOCOOL\Desktop
      Loaded Profiles: SOCOOL (Available profiles: SOCOOL & Administrateur & Invité)
      Boot Mode: Normal
      ==============================================

      Content of fixlist:
      () C:\Users\SOCOOL\AppData\Roaming\Wandoujia2\Applications\2.76.0.7151\wandoujia_helper.exe
      S2 034f3c40; c:\Program Files (x86)\SystemMolder\SystemMolder.dll [1646592 2015-02-15] () [File not signed]
      S2 pizogoru; C:\Users\SOCOOL\AppData\Roaming\VOPackage\VOsrv.exe [X] <==== ATTENTION
      2015-02-15 14:28 - 2015-02-15 14:28 - 00000000 ____D () C:\Program Files (x86)\SystemMolder
      2015-02-15 14:27 - 2015-02-16 16:56 - 00000000 ____D () C:\Program Files (x86)\UniDeals
      2015-02-15 14:26 - 2015-02-16 09:28 - 00000000 ____D () C:\ProgramData\{6945b07d-5ef8-9ad5-6945-5b07d5efc1f5}
      2015-02-15 14:26 - 2015-02-15 14:26 - 00000000 ____D () C:\Program Files (x86)\UniDeealsi
      HKU\S-1-5-21-2599192488-2471704336-1159247255-1000\...\Run: [SoftonicAssistant] => C:\Users\SOCOOL\AppData\Local\SoftonicAssistant\SoftonicAssistant.exe
      Startup: C:\Users\SOCOOL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wandoujia_helper.lnk
      ShortcutTarget: wandoujia_helper.lnk -> C:\Users\SOCOOL\AppData\Roaming\Wandoujia2\Applications\2.76.0.7151\wandoujia_helper.exe ()

      [3472] C:\Users\SOCOOL\AppData\Roaming\Wandoujia2\Applications\2.76.0.7151\wandoujia_helper.exe => Process closed successfully.
      034f3c40 => Error deleting Service
      pizogoru => Error deleting Service

      "C:\Program Files (x86)\SystemMolder" directory move:

      Could not move "C:\Program Files (x86)\SystemMolder\SystemMolder.dll" => Scheduled to move on reboot.
      Could not move "C:\Program Files (x86)\SystemMolder" directory. => Scheduled to move on reboot.

      "C:\Program Files (x86)\UniDeals" directory move:

      Could not move "C:\Program Files (x86)\UniDeals\RjhDYpmax3bTwY.dat" => Scheduled to move on reboot.
      Could not move "C:\Program Files (x86)\UniDeals\RjhDYpmax3bTwY.dll" => Scheduled to move on reboot.
      Could not move "C:\Program Files (x86)\UniDeals\RjhDYpmax3bTwY.tlb" => Scheduled to move on reboot.
      Could not move "C:\Program Files (x86)\UniDeals\RjhDYpmax3bTwY.x64.dll" => Scheduled to move on reboot.
      Could not move "C:\Program Files (x86)\UniDeals" directory. => Scheduled to move on reboot.

      "C:\ProgramData\{6945b07d-5ef8-9ad5-6945-5b07d5efc1f5}" directory move:

      Could not move "C:\ProgramData\{6945b07d-5ef8-9ad5-6945-5b07d5efc1f5}\537dda47ad4db69c" => Scheduled to move on reboot.
      Could not move "C:\ProgramData\{6945b07d-5ef8-9ad5-6945-5b07d5efc1f5}\9e807c128a995148" => Scheduled to move on reboot.
      Could not move "C:\ProgramData\{6945b07d-5ef8-9ad5-6945-5b07d5efc1f5}\iViNi-app BMW v13.04 1304.dat" => Scheduled to move on reboot.
      Could not move "C:\ProgramData\{6945b07d-5ef8-9ad5-6945-5b07d5efc1f5}\iViNi-app BMW v13.04 1304.exe" => Scheduled to move on reboot.
      Could not move "C:\ProgramData\{6945b07d-5ef8-9ad5-6945-5b07d5efc1f5}" directory. => Scheduled to move on reboot.

      "C:\Program Files (x86)\UniDeealsi" directory move:

      Could not move "C:\Program Files (x86)\UniDeealsi\UniDeealsi.dat" => Scheduled to move on reboot.
      Could not move "C:\Program Files (x86)\UniDeealsi\UniDeealsi.exe" => Scheduled to move on reboot.
      Could not move "C:\Program Files (x86)\UniDeealsi" directory. => Scheduled to move on reboot.

      HKU\S-1-5-21-2599192488-2471704336-1159247255-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SoftonicAssistant => value deleted successfully.
      C:\Users\SOCOOL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wandoujia_helper.lnk => Moved successfully.
      C:\Users\SOCOOL\AppData\Roaming\Wandoujia2\Applications\2.76.0.7151\wandoujia_helper.exe => Moved successfully.
      0
      1. Un énorme MERCI à toi !
        Tout est rentré dans l'ordre.
        0
        1. Bonjour,
          Merci pour votre aide,
          Voici les trois liens

          http://pjjoint.malekal.com/files.php?id=20150410_d6l14s12r9m15
          http://pjjoint.malekal.com/files.php?id=20150410_w12v7q9o8r13
          http://pjjoint.malekal.com/files.php?id=20150410_g15h11h9c12r15
          0
          1. Modérateur
            Salut eve,

            Voici la correction à effectuer avec FRST.
            Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix

            Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
            Copie/colle dedans ce qui suit :

            FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} [2014-09-25]
            R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [493712 2015-04-10] (SysTool PasSame LIMITED)
            R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [493712 2015-04-10] (SysTool PasSame LIMITED)
            2014-11-28 21:37 - 2014-11-28 21:37 - 1857496 _____ (Enter) C:\Users\Utilisateur\AppData\Roaming\OGLG.exe
            2014-11-28 21:38 - 2014-11-28 21:38 - 1535448 _____ (Enter) C:\Users\Utilisateur\AppData\Roaming\WDFYUBZ.exe
            2015-04-06 20:47 - 2015-02-03 20:51 - 00000000 ____D () C:\ProgramData\9987022526927081539
            2015-04-10 15:46 - 2015-04-10 15:46 - 00000000 ____D () C:\ProgramData\IHProtectUpDate
            2015-04-10 15:45 - 2015-04-10 15:46 - 00000000 ___DC () C:\Program Files\XTab
            2015-04-10 15:45 - 2015-04-10 15:45 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
            2015-04-10 15:44 - 2015-04-10 15:44 - 00000000 ____D () C:\Users\Utilisateur\AppData\Roaming\istartsurf
            2015-04-10 15:43 - 2015-04-10 15:43 - 00000000 ___DC () C:\Program Files\Software Updater
            Task: {7C0C333E-2620-4DD0-8AFF-7A0D7F24A3D0} - System32\Tasks\Test TimeTrigger => C:\Users\UTILIS~1\AppData\Local\Temp\Runner.exe <==== ATTENTION
            Task: {1426BB2A-1DF6-4D31-BCD3-B14B593EFFB7} - System32\Tasks\{118918B2-A801-4728-8506-18E404CF463D} => pcalua.exe -a C:\Users\Utilisateur\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=tugs <==== ATTENTION

            Une fois, le texte coller dans le bloc-note.
            Menu Fichier puis Enregistrer sous.
            A gauche, place toi sur le bureau.
            Dans le champs en bas, nom du fichier mets : fixlist.txt
            Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.

            Relance FRST et clic sur le bouton Fix
            Selon comment un redémarrage est nécessaire (pas obligatoire).
            Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.

            Redémarre l'ordinateur

            puis réinitialise tes navigateurs:
            ==================================
            Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :

            Supprime les PUM.DNS avec RogueKiller en suivant ce tutorial : https://forum.malekal.com/viewtopic.php?t=48312&start=
            Donne le rapport de suppression de RogueKiller.
            0