Pages internet s'ouvrent seules windows vista - Page 2

Précédent
  • 1
  • 2
  1. riadh09
     
    le probleme est revenu les pages s'ouvrent encore j'en ai mar est ce que y aura une solution?
    0
  2. Saiyen75 Messages postés 2699 Statut Membre 184
     
    Re

    Utilise Combofix, Fait bien les étapes dans l'ordre, C'est trés important, ce logiciel est trés puissant.

    ComboFix :

    Télécharge combofix.exe(par sUBs) sur ton Bureau :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    * Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.
    * Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.


    Une fois fait, sur ton bureau double-clic sur Combofix.exe.

    - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

    /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes. /!\

    - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

    - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

    * Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

    * Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

    _____________________________________________________
    0
  3. riadh09
     
    ComboFix 08-02-21 - riadh 2008-02-21 14:53:33.1 - NTFSx86
    Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.345 [GMT 1:00]
    Endroit: C:\Users\riadh\Desktop\ComboFix.exe
    * Création d'un nouveau point de restauration
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
    C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat

    ----- BITS: Possible sites infectés -----

    hxxp://www.tucows.com
    .
    ((((((((((((((((((((((((((((( Fichiers créés 2008-01-21 to 2008-02-21 ))))))))))))))))))))))))))))))))))))
    .

    Pas de nouveau fichier créé dans cet espace de temps

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-02-21 10:53 --------- d-----w C:\Users\riadh\AppData\Roaming\Skype
    2008-02-21 10:27 27,335 ----a-w C:\Users\riadh\AppData\Roaming\nvModes.dat
    2008-02-21 10:18 --------- d-----w C:\Program Files\BrowsingAdvisor
    2008-02-20 23:02 --------- d-----w C:\ProgramData\Avira
    2008-02-20 23:02 --------- d-----w C:\Program Files\Avira
    2008-02-20 21:10 --------- d-----w C:\Program Files\Common Files\ErreurChasseur
    2008-02-20 18:47 --------- d-----w C:\Program Files\Navilog1
    2008-02-20 15:50 --------- d-----w C:\Program Files\FBrowsingAdvisor
    2008-02-20 15:50 --------- d-----w C:\Program Files\FBrowserAdvisor
    2008-02-20 07:50 --------- d-----w C:\Program Files\Spybot - Search & Destroy
    2008-02-20 07:34 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
    2008-02-20 07:19 --------- d-----w C:\Users\riadh\AppData\Roaming\Grisoft
    2008-02-20 07:19 --------- d-----w C:\ProgramData\Grisoft
    2008-02-20 07:03 --------- d-----w C:\Users\riadh\AppData\Roaming\skypePM
    2008-02-17 21:51 --------- d-----w C:\Users\riadh\AppData\Roaming\LimeWire
    2008-02-16 16:40 --------- d-----w C:\Program Files\Microsoft Etudes
    2008-02-16 16:25 --------- d-----w C:\Program Files\Learning Essentials
    2008-02-15 12:06 --------- d-----w C:\ProgramData\CyberLink
    2008-02-15 09:54 --------- d-----w C:\ProgramData\Messenger Plus!
    2008-02-15 09:45 --------- d-----w C:\Program Files\Messenger Plus! Live
    2008-02-15 08:49 --------- d-----w C:\Program Files\Common Files\Steam
    2008-02-14 02:09 194,560 ----a-w C:\Windows\System32\WebClnt.dll
    2008-02-14 02:09 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
    2008-02-14 02:04 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
    2008-02-13 23:16 32 ----a-w C:\Users\All Users\ezsid.dat
    2008-02-13 23:16 32 ----a-w C:\ProgramData\ezsid.dat
    2008-02-13 23:13 --------- d-----w C:\ProgramData\Skype
    2008-02-13 23:13 --------- d-----w C:\Program Files\Skype
    2008-02-13 23:13 --------- d-----w C:\Program Files\Common Files\Skype
    2008-02-13 21:17 --------- d-----w C:\ProgramData\Microsoft Help
    2008-02-13 20:58 824,832 ----a-w C:\Windows\System32\wininet.dll
    2008-02-13 20:58 56,320 ----a-w C:\Windows\System32\iesetup.dll
    2008-02-13 20:58 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
    2008-02-13 20:58 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
    2008-02-13 20:57 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
    2008-02-11 13:37 --------- d-----w C:\Program Files\Common Files\Adobe
    2008-02-11 12:19 --------- d-----w C:\Program Files\Disc2Phone
    2008-02-06 18:22 --------- d-----w C:\Users\riadh\AppData\Roaming\Ahead
    2008-02-06 18:19 --------- d-----w C:\Program Files\Nero
    2008-02-06 18:19 --------- d-----w C:\Program Files\Common Files\Ahead
    2008-02-04 18:25 --------- d-----w C:\ProgramData\Downloaded Installations
    2008-02-03 21:12 --------- d-----w C:\Users\riadh\AppData\Roaming\dvdcss
    2008-02-02 16:58 --------- d-----w C:\Program Files\Valve
    2008-01-23 07:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-01-23 07:41 --------- d-----w C:\Program Files\Windows Sidebar
    2008-01-23 07:41 --------- d-----w C:\Program Files\Windows Defender
    2008-01-23 07:41 --------- d-----w C:\Program Files\Common Files\LightScribe
    2008-01-21 22:01 --------- d-----w C:\Program Files\Windows Photo Gallery
    2008-01-21 22:01 --------- d-----w C:\Program Files\Windows Mail
    2008-01-21 22:01 --------- d-----w C:\Program Files\Windows Journal
    2008-01-21 22:01 --------- d-----w C:\Program Files\Windows Calendar
    2008-01-21 21:43 --------- d-----w C:\Program Files\Panda Software
    2008-01-21 21:42 --------- d-----w C:\Program Files\Common Files\Panda Software
    2008-01-17 17:18 --------- d-----w C:\Users\riadh\AppData\Roaming\Template
    2008-01-17 09:49 --------- d-----w C:\ProgramData\Kaspersky Lab
    2008-01-15 13:43 --------- d-----w C:\Program Files\CONEXANT
    2008-01-14 12:04 --------- d---a-w C:\ProgramData\TEMP
    2008-01-14 12:01 --------- d-----w C:\Users\riadh\AppData\Roaming\Roxio
    2008-01-14 12:01 --------- d-----w C:\ProgramData\Sonic
    2008-01-14 12:00 --------- d-----w C:\Program Files\Windows Live
    2008-01-10 08:52 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
    2008-01-10 08:52 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
    2008-01-10 08:51 11,776 ----a-w C:\Windows\System32\sbunattend.exe
    2008-01-09 14:22 --------- d-----w C:\Program Files\Java
    2008-01-09 12:26 --------- d-----w C:\Users\riadh\AppData\Roaming\InstallShield
    2008-01-05 23:13 --------- d-----w C:\ProgramData\LightScribe
    2008-01-03 19:14 --------- d-----w C:\Program Files\1stbenison
    2007-12-25 15:44 260,632 ----a-w C:\Users\riadh\AppData\Roaming\setup_fr[1].exe
    2007-12-25 15:36 --------- d-----w C:\Program Files\Real
    2007-12-25 15:36 --------- d-----w C:\Program Files\Common Files\xing shared
    2007-12-25 15:36 --------- d-----w C:\Program Files\Common Files\Real
    2007-12-23 18:52 80,097 ----a-w C:\Windows\System32\dcads-remove.exe
    2007-12-23 18:52 77,360 ----a-w C:\Windows\System32\dcads_sidebar_uninstall.exe
    2007-12-23 18:52 40,734 ----a-w C:\Windows\System32\superiorads-uninst.exe
    2007-12-23 18:52 --------- d-----w C:\Program Files\Dcads Games Collection
    2007-12-18 14:35 0 ----a-w C:\Users\riadh\AppData\Roaming\wklnhst.dat
    2007-12-12 23:17 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
    2007-12-12 23:17 223,232 ----a-w C:\Windows\System32\WMASF.DLL
    2007-12-12 23:17 1,327,104 ----a-w C:\Windows\System32\quartz.dll
    2007-12-04 21:26 174 --sha-w C:\Program Files\desktop.ini
    2007-12-04 21:18 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
    2007-12-04 21:18 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
    2007-12-04 21:18 542,720 ----a-w C:\Windows\System32\sysmain.dll
    2007-12-04 21:18 502,784 ----a-w C:\Windows\System32\wlansvc.dll
    2007-12-04 21:18 47,104 ----a-w C:\Windows\System32\wlanapi.dll
    2007-12-04 21:18 297,984 ----a-w C:\Windows\System32\wlansec.dll
    2007-12-04 21:18 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
    2007-12-04 21:18 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
    2007-12-04 21:18 2,923,520 ----a-w C:\Windows\explorer.exe
    2007-12-04 21:18 2,027,008 ----a-w C:\Windows\System32\win32k.sys
    2007-12-04 21:14 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
    2007-12-04 21:14 7,680 ----a-w C:\Windows\System32\spwmp.dll
    2007-12-04 21:14 4,096 ----a-w C:\Windows\System32\dxmasf.dll
    2007-12-04 21:14 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
    2007-12-04 21:13 86,016 ----a-w C:\Windows\System32\icfupgd.dll
    2007-12-04 21:13 61,952 ----a-w C:\Windows\System32\cmifw.dll
    2007-12-04 21:13 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
    2007-12-04 21:13 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
    2007-12-04 21:13 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll
    2007-12-04 21:13 16,896 ----a-w C:\Windows\System32\wfapigp.dll
    .
    [code]<pre>
    ----a-w 325,204 2006-12-21 19:56:28 C:\SwSetup\SP34746\WCAMC\FW_210_Silence Install .exe
    </pre>/code

    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F1E96EDC-E0C8-BE98-1F15-C29DBED83B53}]
    2007-12-30 21:49 1019904 --a------ C:\Program Files\BrowsingAdvisor\BrowsingAdvisor-2.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 09:51 1232896]
    "LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 12:26 484904]
    "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
    "msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
    "Steam"="C:\Program Files\Valve\Steam\Steam.exe" [2008-02-02 18:04 1266936]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2005-09-03 15:18 94208]
    "Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 17:22 21898024]
    "L08FXLRD_80990087"="C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.exe" [2007-06-12 21:34 351000]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-08-18 00:07 1006264]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 04:36 827392]
    "QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2007-04-23 17:11 176128]
    "QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 10:38 159744]
    "HP Health Check Scheduler"="C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 10:54 50696]
    "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-09 03:57 86016]
    "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-09 03:57 8433664]
    "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-09 03:57 81920]
    "hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 12:18 472776]
    "WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 15:12 317128]
    "HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11 49152]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
    "NWEReboot"="" []
    "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
    "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-21 00:05 249896]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "DisableLockWorkstation"= 0 (0x0)
    "DisableChangePassword"= 0 (0x0)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoLogoff"= 0 (0x0)

    R1 ShldDrv;Panda File Shield Driver;C:\Windows\system32\drivers\ShldDrv.sys [2005-08-29 13:23]
    R3 nvsmu;nvsmu;C:\Windows\system32\DRIVERS\nvsmu.sys [2007-02-17 00:50]
    S2 PavProc;Panda Process Protection Driver;C:\Windows\system32\DRIVERS\PavProc.sys [2006-04-25 16:02]
    S3 BCM43XV;Pilote de la carte réseau extensible Broadcom 802.11;C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-01-03 16:43]
    S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-02-15 09:48]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19741992-d7cf-11dc-a9a6-001b249c2134}]
    \shell\AutoRun\command - G:\RavMon.exe
    \shell\explore\Command - G:\RavMon.exe -e
    \shell\open\Command - G:\RavMon.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{24c2b8b5-a20b-11dc-bb19-001b249c2134}]
    \shell\AutoRun\command - F:\RavMon.exe
    \shell\explore\Command - F:\RavMon.exe -e
    \shell\open\Command - F:\RavMon.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3155a2c2-a487-11dc-9360-001b249c2134}]
    \shell\AutoRun\command - G:\RavMon.exe
    \shell\explore\Command - G:\RavMon.exe -e
    \shell\open\Command - G:\RavMon.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e0839e6f-cf69-11dc-b823-001b249c2134}]
    \shell\AutoRun\command - F:\RavMon.exe
    \shell\explore\Command - F:\RavMon.exe -e
    \shell\open\Command - F:\RavMon.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eaf9d9ad-bf59-11dc-8f37-001b249c2134}]
    \shell\AutoRun\command - G:\RavMon.exe
    \shell\explore\Command - G:\RavMon.exe -e
    \shell\open\Command - G:\RavMon.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eaf9d9b3-bf59-11dc-8f37-001b249c2134}]
    \shell\AutoRun\command - H:\RavMon.exe
    \shell\explore\Command - H:\RavMon.exe -e
    \shell\open\Command - H:\RavMon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
    .
    Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
    "2008-02-20 17:49:38 C:\Windows\Tasks\User_Feed_Synchronization-{5241619B-39BB-4141-9720-870AAC505CB4}.job"
    - C:\Windows\system32\msfeedssync.exe
    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-02-21 14:56:30
    Windows 6.0.6000 NTFS

    Balayage processus cachés ...

    Balayage caché autostart entries ...

    Balayage des fichiers cachés ...

    Scan terminé avec succès
    Les fichiers cachés: 0

    **************************************************************************
    .
    Temps d'accomplissement: 2008-02-21 14:57:28
    ComboFix-quarantined-files.txt 2008-02-21 13:57:26
    .
    2008-02-15 02:03:27 --- E O F ---

    les pages s'ouvrent encore aprés le scan
    0
  4. Saiyen75 Messages postés 2699 Statut Membre 184
     
    Re

    Va sur ce site : https://www.virustotal.com/gui/

    Ensuite tu Clique sur parcourir, tu recherche la première ligne :

    C:\Users\All Users\ezsid.dat

    Ensuite tu clique sur Envoyer le fichier
    un rapport va etre generé (peut prendre plusieurs minutes)
    Fait pareil pour les 3 fichiers
    Puis poste le rapport du fichier.

    /!\ N'oublie pas qu'il y a 1 rapport par fichier. /!\
    _____________________________________________________
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. riadh09 Messages postés 18 Statut Membre
     
    j'ai pas trouvé C:\Users\All Users\ezsid.dat
    0
  7. Saiyen75 Messages postés 2699 Statut Membre 184
     
    j'ai pas trouvé C:\Users\All Users\ezsid.dat
    Comment ça ? en faisant parcourir ?
    0
  8. riadh09 Messages postés 18 Statut Membre
     
    oui je l'ai pas trouvé
    0
  9. Saiyen75 Messages postés 2699 Statut Membre 184
     
    Pour afficher les Fichiers et Dossiers Caché :

    * Ouvrir poste de travail
    * outils
    * Options des dossiers
    * Onglet "Affichage"
    * Dans fichiers et dossiers caché, coché la case "Afficher les fichiers et dossiers cachés"

    Ensuite un peu plus bas, décocher les case "Masquer les fichiers protégés du systeème d'exploitation"

    /!\ ATTENTION : Faire attention de ne pas supprimer involontairement un fichier système, car ça peut endomager votre système d'exploitation ! /!\

    _____________________________________________________
    0
  10. riadh09 Messages postés 18 Statut Membre
     
    j'ai vista pas xp
    0
  11. Saiyen75 Messages postés 2699 Statut Membre 184
     
    C'est pareil, la seule différence, c'est ça :
    remplace Poste de travail ---> Ordinateur (qui se trouve sur le bureau)
    0
  12. riadh09 Messages postés 18 Statut Membre
     
    c quoi les 3fichiers que tu m'avais dit avant pour les envoyé g trouvé ezsid
    0
  13. riadh09 Messages postés 18 Statut Membre
     
    il a rien trouvé
    0
  14. riadh09 Messages postés 18 Statut Membre
     
    est ce que y a un moyen de ce parlé plus rapidement?c'est mieu!et pour ne pas vous ennuyez une semaine dsl
    0
Précédent
  • 1
  • 2