Trojan win32 fenetres intempestives

Résolu
Bonjour,

Après plusieur tentative de suppression, j ai toujours un souci de fenetre intempestives lié ou non a ce fichier : win 32 : inject-ev

j'ai vista
et un tas de logiciel incapable de le surpprimer.

merci de m'aider (cri de desespoir) si vous savez (et seulement si) comment enlever cette saleté simplement et rapidement (et sans éclater l'ordi dans le mur)

merci

dav
Configuration: Windows Vista
Internet Explorer 7.015 message(s) posté(s) depuis le lundi 28 janvier 2008
Configuration: Windows Vista
Internet Explorer 7.0

15 réponses

  1. Contributeur sécurité
    slt,

    quel fichier est infécté???

    __________________

    Fais un clic droit sur ce lien : (IL-MAFIOSO)
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie-colle l'intégralité dans une réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
    __________________

    colle un rapport hijackthis

    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

    manuel :

    https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

    Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

    ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

    Ensuite avec Explorer créer un dossier c:\hijackthis
    Décompresser Hijackthis dans ce dossier.
    C'est important pour les sauvegardes."

    _____________________
    0
    1. VOICI LES 2 RAPPORTS

      MERCI DE M AIDER

      BEAUCOUP DE CHOSE TENTE MAIS PAS RESOLU

      VISTA.....POSE PEUT ETRE PROBLEME....

      Search Navipromo version 3.4.2 commencé le 01/02/2008 à 15:56:34,79

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1
      Mise à jour le 27.01.2008 à 17h00 par IL-MAFIOSO

      Microsoft Windows Vista 6.0.6000
      Internet Explorer : 7.0.6000.16575
      Système de fichiers : NTFS

      Executé en mode normal

      *** Recherche Programmes installés ***

      *** Recherche dossiers dans C:\Windows ***

      *** Recherche dossiers dans C:\Program Files ***

      *** Recherche dossiers dans C:\ProgramData ***

      *** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***

      *** Recherche dossiers dans C:\Users\DAV\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs ***

      *** Recherche dossiers dans C:\Users\DAV\AppData\Local\virtualstore\Program Files ***

      *** Recherche dossiers dans C:\Users\DAV\AppData\Roaming ***

      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net

      Aucun Fichier trouvé

      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans C:\Windows\system32 *

      * Recherche dans C:\Users\DAV\AppData\Local\Microsoft *

      * Recherche dans C:\Users\DAV\AppData\Local *

      *** Recherche fichiers ***

      *** Recherche clés spécifiques dans le Registre ***

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :

      2)Recherche Heuristique :

      * Dans C:\Windows\system32 :

      * Dans C:\Users\DAV\AppData\Local\Microsoft :

      * Dans C:\Users\DAV\AppData\Local :

      3)Recherche Certificats :

      Certificat Egroup absent !

      4)Recherche fichiers connus :

      *** Analyse terminée le 01/02/2008 à 16:09:49,90 ***

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 17:20:46, on 28/01/2008
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16575)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Windows\OEM02Mon.exe
      C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
      C:\Windows\System32\rundll32.exe
      C:\Windows\System32\rundll32.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\Java\jre1.6.0\bin\jusched.exe
      C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
      C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
      C:\Program Files\Dell\MediaDirect\PCMService.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
      C:\Program Files\Digital Line Detect\DLG.exe
      C:\Program Files\Dell\QuickSet\quickset.exe
      C:\Windows\ehome\ehmsas.exe
      c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
      C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
      C:\Program Files\eMule\emule.exe
      C:\Program Files\Internet Explorer\ieuser.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil9d.exe
      C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe
      C:\Program Files\Windows Media Player\wmplayer.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
      O2 - BHO: BrowsingAdvisor - {F1E96EDC-E0C8-BE98-1F15-C29DBED83B53} - C:\Program Files\BrowsingAdvisor\BrowsingAdvisor-2.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
      O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
      O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
      O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: BTTray.lnk = ?
      O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
      O4 - Global Startup: QuickSet.lnk = ?
      O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
      O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O13 - Gopher Prefix:
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
      O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
      O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
      O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
      O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
      0
      1. Contributeur sécurité
        tu ne m as pas dis le nom exact du fichier infecté? Donne je moi c'est important
        0
        1. win 32 : inject-ev

          NOM ET LOCALISATION DU FICHIER : C:\Users\DAV\AppData\Local\Temp\ibppyjtv.dll

          QUEL BEAU NOM N EST CE PAS ???

          SALETE !
          VOILA MERCI
          0
          1. Contributeur sécurité
            télécharges et installes :

            kill box
            https://www.bleepingcomputer.com/download/linux/

            aide kill box
            http://perso.wanadoo.fr/jesses/Docs/Logiciels/KillBox.htm

            - Redémarre en mode sans échec, si tu sais pas comment on fait lis ceci

            - Double-clic sur fix.reg

            Ouvres killbox
            - Sélectionne "delete on reboot"
            - Clique sur le dossier jaune à droite et sélectionne le fichier : C:\WINDOWS\System32\wineij32.dll
            - Clique sur la croix rouge et et blanche
            - Répond yes et laisse redémarrer ton pc.
            N'hésite pas à consulter l'Aide killbox

            Vérifie que le fichier C:\Users\DAV\AppData\Local\Temp\ibppyjtv.dll n'est plus présent.

            _____________________

            vire ensuite le fichier kill box en allant dans poste de travail puis C puis programme files

            _______________________

            encore des soucis?
            0
            1. tout c est bien déroulé sauf qu il n y avait pas de fichier wineij32.dll a l endroit indiqué.....
              0
              1. Contributeur sécurité
                pardon une erreur de frappe

                kill box
                https://www.bleepingcomputer.com/download/linux/

                aide kill box
                http://perso.wanadoo.fr/jesses/Docs/Logiciels/KillBox.htm

                - Redémarre en mode sans échec, si tu sais pas comment on fait lis ceci

                - Double-clic sur fix.reg

                Ouvres killbox
                - Sélectionne "delete on reboot"
                - Clique sur le dossier jaune à droite et sélectionne le fichier :

                C:\Users\DAV\AppData\Local\Temp\ibppyjtv.dll

                - Clique sur la croix rouge et et blanche
                - Répond yes et laisse redémarrer ton pc.
                N'hésite pas à consulter l'Aide killbox

                Vérifie que le fichier C:\Users\DAV\AppData\Local\Temp\ibppyjtv.dll n'est plus présent.

                _____________________

                vire ensuite le fichier kill box en allant dans poste de travail puis C puis programme files

                _______________________

                encore des soucis?
                0
                1. idem opé bien déroulé
                  mais pas de fichier portant ce nom a cet emplacement.....
                  0
                  1. Contributeur sécurité
                    refais killbox et supprime ce fichier

                    C:\Users\DAV\AppData\Local\Temp

                    ________________

                    l'infection est encore presente?
                    0
                    1. toujours en mode sans echec ?
                      0
                      1. il n y est plus
                        et j ai toujorus le meme probleme

                        j ai viré avast j ai mis antivir et lorsque je lance navilog antivir détecte lui aussi mon trojan....

                        mon centre de sécurité windows est inactif est ce grave ?

                        suis je vraiment infecté ?

                        est ce que quelqu un sait ce que je peux faire ?

                        j ai installer une multitude de logiciel, j ai tenté un tas de truc pour rien donc si vous avez un doute abstenez vous de m aider svp...
                        là je commence a avoir un peu peur pour mon systeme a force de de fouiller partout et de toucher a tout...
                        0
                        1. Contributeur sécurité
                          desinstalle navilog . Refaire kill box pour virer le dossier infecté . Pour je trouver , vas dans ton panneau de configuration puis dans l'icone option des dossier . Puis onglet affichage . Puis coche afficher les fichier et dossier cachés . Puis décoche masquer les extension de fichier connu et masquer les fichiers protégé du système . Applique puis fais ok . Ensuite viré le fichier avec kill box . Puis rescanne avec antivir et colle le rappot
                          0
                          1. Contributeur sécurité
                            desinstalle navilog

                            ___________________

                            il faudra en mode sans echec affichier les dossier cachés:

                            https://www.informatruc.com

                            télécharges et installes :

                            kill box
                            https://www.bleepingcomputer.com/download/linux/

                            aide kill box
                            http://perso.wanadoo.fr/jesses/Docs/Logiciels/KillBox.htm

                            - Redémarre en mode sans échec, si tu sais pas comment on fait lis ceci

                            - Double-clic sur fix.reg

                            Ouvres killbox
                            - Sélectionne "delete on reboot"
                            - Clique sur le dossier jaune à droite et sélectionne le fichier : C:\Users\DAV\AppData\Local\Temp\ibppyjtv.dll
                            - Clique sur la croix rouge et et blanche
                            - Répond yes et laisse redémarrer ton pc.
                            N'hésite pas à consulter l'Aide killbox

                            Vérifie que le fichier C:\Users\DAV\AppData\Local\Temp\ibppyjtv.dll n'est plus présent.

                            ___________________

                            refais un rapport antivir et colle le
                            0
                            1. EN FAIT IL SEMBLE QUE NAVILOG DETECTE MON ANTIVIRUS ET LE CLASSE EN TROJAN
                              DONC JE NE SERAIS PAS INFECTE

                              MES FENËTRES INTEMPESTIVE SEMBLE AVOIR DISPARUES

                              J ESPERE
                              MERCI
                              0
                              1. Contributeur sécurité
                                oui je pense aussi
                                bonne continuation

                                pour protéger gratos ton ordi

                                http://www.commentcamarche.net/telecharger/logiciel 4 securite

                                mettre un antivirus

                                AVAST en français ou ANTIVIR (en anglais mais très efficace)
                                https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
                                -------------
                                des anti-espions :
                                AD AWARE + SPYBOT +/- si tea timer non active de spybot et ordi assez puissant: WINDOWS DEFENDER

                                +/-
                                SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

                                Rq : spybot et ad-aware on sorti de nouvelles versions cette année vérifiez que vous avez la dernière version
                                --------
                                un pare feu :
                                celui de Windows ou mieux KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)

                                https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
                                https://manuelsdaide.com/contact/
                                http://www.open-files.com/forum/index.php?showtopic=29277
                                http://www.commentcamarche.net/telecharger/telecharger 157 zonealarm

                                -----------

                                CCLEANER pour effacer les traces de surf
                                0