Comment bloqué les popups

Résolu
j.joey Messages postés 237 Statut Membre -  
 panographe -
bonjour,j'ai des popups de femmes a poil sur mes fenetres malgré que j'ai spybot,et sa me dérange
svp aidez moi,merci
Configuration: Windows XP
Firefox 2.0.0.12

14 réponses

Résumé de la discussion

Le sujet concerne des popups invitant à des contenus pour adultes qui apparaissent malgré l’utilisation de Spybot, sur un système Windows XP accompagné de Firefox 2.0.0.12. Des solutions et outils de désinfection ont été proposés, notamment SmitFraudFix et VundoFix, avec des rapports détaillant les emplacements des fichiers infectés et les étapes de réparation du registre et des processus. Plusieurs messages décrivent l’exécution d’outils et la suppression de fichiers malveillants dans Windows, suivies d’un redémarrage et d’une correction du registre pour neutraliser les suites d’intrusions. En cas de doute, il est recommandé de comparer les rapports d’outils multiples et de vérifier les clés du registre et les processus système, afin d’éviter une rechute due à des modules résiduels.

Bobot (l'IA à votre service)
  1. VIRUS_KILLER Messages postés 2075 Statut Contributeur 68
     
    Salut,
    OK MDR
    Tu a un adware qui affichent des PUB.?
    OK:
    Telecharge POP UP STOPPER Ici:
    --https://www.01net.com/telecharger/
    J'étais comme vous,un debutant.Au debut,les VIRUS,etait plus fort que moi.Mais maitenant,il ne passeront pas.Mon metier de + tard=un pro en informatique,surtout en securité!j'adore l'informatique,je vai KILL ces VIRUS!!!!!!!qui pourisent nos PC!!!!
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      oui je l'ai deja
      0
  2. Utilisateur anonyme
     
    Bonjour, tout simplement: allez dans outils -> options -> Confidentialité et en bas, cochez Activer le bloqueur de fenetres intempestives.
    En éspérant que cela vous ait aidé
    0
  3. dou-l Messages postés 2871 Statut Membre 61
     
    salut,

    -fait un log hijack:

    ftp://ftp.commentcamarche.com/download/HJTInstall.exe

    Fait un clic droit sur l'icone hijackthis.

    /!\Renome hijackthis en skimboard.exe ( a le place de hijacktihs.exe) c'est important.

    Après avoir fais ca double-clic dessus.

    Clic sur Do a system scan and save the log

    A la fin de l'analyse un rapport va etre générer colle le ici.

    Une démo d'hijackthis :
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

    va a cette adressse et télécharge Navilog:

    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    -Choisis Enregistrer et enregistre-le sur ton bureau.

    - Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    -Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
    Patiente jusqu'au message " Analyse Termine le ....."

    -Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie/colle l'intégralité du rapport dans ta réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

    -Si ton antivirus detecte un virus ou un cheval de troie durant l'analyse ignore le.
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 12:46:24, on 15/03/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\VIDAL\Communs\VIDAL.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\Rundll32.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\Ares\Ares.exe
      C:\WINDOWS\system32\spoolsv.exe
      D:\chreb logiciel\utorrent.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\DOCUME~1\SEDRATI\LOCALS~1\Temp\Répertoire temporaire 2 pour HiJackThis.zip\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.fr.msn.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
      O1 - Hosts: "http://www.w3.org/TR/html4/loose.dtd">
      O1 - Hosts: <html>
      O1 - Hosts: <head>
      O1 - Hosts: <script LANGUAGE="JavaScript">
      O1 - Hosts: <!--
      O1 - Hosts: if (window != top)
      O1 - Hosts: top.location.href = location.href;
      O1 - Hosts: // -->
      O1 - Hosts: </script>
      O1 - Hosts: <title>Site Unavailable</title>
      O1 - Hosts: <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
      O1 - Hosts: <style type="text/css">
      O1 - Hosts: body{text-align:center;}
      O1 - Hosts: .geohead {font-family:Verdana, Arial, Helvetica, sans-serif; font-size:10px;width:750px;margin:10px 0 10px 0;height:35px;}
      O1 - Hosts: .geohead #geologo {width:270px;display:block; float:left; }
      O1 - Hosts: .geohead #rightside {width:480px;display:block; float:right;border-bottom:1px solid #999999; height:27px;}
      O1 - Hosts: .geohead #rightside #welcome {width:50%;display:block; float:left; text-align:left;}
      O1 - Hosts: .geohead #rightside #wlinks {width:50%;display:block; float:right; text-align:right;}
      O1 - Hosts: .ftr { margin:0px; color:#404040; font:x-small Arial,sans-serif; text-align:center; width:750px;}
      O1 - Hosts: .bodywrap{display:block;height:470px;}
      O1 - Hosts: .bodycnt{width:510px; display:block; float:left; background-color:#EEE9F5; height:auto; text-align:left; font-family:Arial, Helvetica, sans-serif;font-size:13px; color:#000000; padding:20px 20px 35px 20px;}
      O1 - Hosts: .title { font-family:Arial, Helvetica, sans-serif; font-weight:bold; font-size:24px; color:#7C56A9}
      O1 - Hosts: .adcnt{width:172px; display:block; float:right; text-align:left;cursor:pointer;cursor:hand;}
      O1 - Hosts: .adcnt td {text-align:left;}
      O1 - Hosts: .adsubt{font-size:10px; font-family:verdana; font-weight:bold; color:#b4b4b4; cursor:default;margin-top:5px;}
      O1 - Hosts: .ybadge { font-family: Verdana, Arial, Helvetica, sans-serif; font-size:10px; color: #666666; margin-top:10px;}
      O1 - Hosts: .ybadge img {margin-top:6px;}
      O1 - Hosts: .adtable {font-family:Verdana, Arial, Helvetica, sans-serif; font-size:10px;border: 1px solid #d6dbe7; background-color:#eff7ff; padding:3px; margin-bottom:10px; width:172px;}
      O1 - Hosts: .adttl{font-weight:bold;margin-bottom:3px;}
      O1 - Hosts: .addescr{color:#6b6b6b; margin-bottom:3px;}
      O1 - Hosts: .adlink a {color:#008200; text-decoration:none;}
      O1 - Hosts: </style>
      O1 - Hosts: </head>
      O1 - Hosts: <body>
      O1 - Hosts: <!-- following code added by server. PLEASE REMOVE -->
      O1 - Hosts: <!-- preceding code added by server. PLEASE REMOVE -->
      O1 - Hosts: <div id="maincnt">
      O1 - Hosts: <div class="geohead"><div id="geologo"><a href="https://smallbusiness.yahoo.com/"><img height=33 alt="Yahoo! GeoCities" src="http://us.i1.yimg.com/us.yimg.com/i/us/nt/ma/ma_geo_1.gif" width=259 border=0></a></div>
      O1 - Hosts: <div id="rightside"><div id="wlinks"><a href="https://smallbusiness.yahoo.com/">GeoCities Home</a> - <a href="https://fr.yahoo.com/?p=us">Yahoo!</a> - <a href="https://help.yahoo.com/kb/account">Help</a></div>
      O1 - Hosts: </div></div>
      O1 - Hosts: <div class="bodywrap">
      O1 - Hosts: <div class="bodycnt">
      O1 - Hosts: <div class="title">Sorry, this GeoCities site is currently unavailable.</div>
      O1 - Hosts: <p>The GeoCities web site you were trying to view has temporarily exceeded its data transfer limit. Please try again later. </p>
      O1 - Hosts: <p>Are you the site owner?
      O1 - Hosts: Avoid service interruptions in the future by increasing your data transfer limit!
      O1 - Hosts: <a href="https://help.yahoo.com/kb/account" target="_blank">Find out how.</a> </p>
      O1 - Hosts: <p><a href="https://help.yahoo.com/kb/account" target="_blank">Learn more about data transfer.</a></p>
      O1 - Hosts: </div>
      O1 - Hosts: <div class="adcnt">
      O1 - Hosts: <a target="_top" href="https://smallbusiness.yahoo.com/"><img src="http://us.i1.yimg.com/us.yimg.com/i/us/smbiz/b/geo_mast_small2.gif" alt="Yahoo! GeoCities" border="0" height="15" hspace="0" vspace="0" width="141"></a>
      O1 - Hosts: <div class="adsubt">SPONSORED LINKS</div>
      O1 - Hosts: <!--<table width="172" border="0" bgcolor="#FFFFFF" class="adtable"><tr><td align=left>-->
      O1 - Hosts: <div class="adtable">
      O1 - Hosts: <div class="adttl" title="Reliable plans include domain & 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27166/*https://smallbusiness.yahoo.com/hosting" target="_blank">Yahoo! Web Hosting<br>
      O1 - Hosts: $25 Setup Waived</a></div>
      O1 - Hosts: <div class="addescr" title="Reliable plans include domain & 24x7 support.">Reliable plans include domain & 24x7 support.</div>
      O1 - Hosts: <div class="adlink" title="Reliable plans include domain & 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27166/*https://smallbusiness.yahoo.com/hosting" target="_blank">webhosting.yahoo.com</a></div>
      O1 - Hosts: </div>
      O1 - Hosts: <div class="adtable">
      O1 - Hosts: <div class="adttl" title="Reliable plans include domain & 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27176/*https://smallbusiness.yahoo.com/domains" target="_blank">Domain Names from Yahoo! only $9.95/yr</a></div>
      O1 - Hosts: <div class="addescr" title="Includes starter web page, email & domain forwarding, 24x7 support.">Includes starter web page, email & domain forwarding, 24x7 support.</div>
      O1 - Hosts: <div class="adlink" title="Includes starter web page, email & domain forwarding, 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27176/*https://smallbusiness.yahoo.com/domains" target="_blank">domains.yahoo.com</a></div>
      O1 - Hosts: </div>
      O1 - Hosts: <div class="adtable">
      O1 - Hosts: <div class="adttl" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27184/*https://smallbusiness.yahoo.com/mail" target="_blank">Yahoo! Business Email<br> Domain Included</a></div>
      O1 - Hosts: <div class="addescr" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning.">Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning.</div>
      O1 - Hosts: <div class="adlink" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27184/*https://smallbusiness.yahoo.com/mail" target="_blank">smallbusiness.yahoo.com</a></div>
      O1 - Hosts: </div>
      O1 - Hosts: <div class="adtable">
      O1 - Hosts: <div class="adttl" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=/27190/*https://smallbusiness.yahoo.com/stores" target="_blank">Ecommerce from Yahoo!<br> 1 Month Free</a></div>
      O1 - Hosts: <div class="addescr" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support.">$50 setup fee waived. A reliable ecommerce plan, 24x7 support.</div>
      O1 - Hosts: <div class="adlink" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=/27190/*https://smallbusiness.yahoo.com/stores" target="_blank">smallbusiness.yahoo.com</a></div>
      O1 - Hosts: </div>
      O1 - Hosts: <div class="ybadge">
      O1 - Hosts: Get your own web site at <br><a target="_top" href="https://smallbusiness.yahoo.com/">Yahoo! GeoCities</a>
      O1 - Hosts: <a href="https://smallbusiness.yahoo.com/hosting" target="_top"><img src="http://us.i1.yimg.com/us.yimg.com/i/us/wh/gr/badge_hostedby_purp_2.gif" alt="Hosted by Yahoo! Web Hosting" align="middle" border="0" height="31" width="88"></a>
      O1 - Hosts: </div>
      O1 - Hosts: </div>
      O1 - Hosts: </div>
      O1 - Hosts: <div class=ftr>
      O1 - Hosts: <hr size=1 width=100%>
      O1 - Hosts: Copyright ©
      O1 - Hosts: 2005 Yahoo! Inc. All rights reserved<br>
      O1 - Hosts: <a href="https://www.verizonmedia.com/policies/">Privacy Policy</a>
      O1 - Hosts: - <a href="https://fr.yahoo.com/?p=us">Copyright Policy</a>
      O1 - Hosts: - <a href="https://fr.yahoo.com/?p=us">Guidelines</a>
      O1 - Hosts: - <a href="https://fr.yahoo.com/?p=us">Terms of Service</a>
      O1 - Hosts: - <a href="https://help.yahoo.com/kb/account">Help</a>
      O1 - Hosts: </div>
      O1 - Hosts: </div>
      O1 - Hosts: </body>
      O1 - Hosts: </html>
      O1 - Hosts: <!-- text below generated by server. PLEASE REMOVE --></object></layer></div></span></style></noscript></table></script></applet>
      O1 - Hosts: <IMG SRC="http://geo.yahoo.com/serv?s=19190039&t=1167440002&f=us-w68" ALT=1 WIDTH=1 HEIGHT=1>
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {23D44BCF-AA7A-41D6-8905-E808F16322EF} - (no file)
      O2 - BHO: {d72fc016-b9df-5be9-0ed4-943688231b44} - {44b13288-6349-4de0-9eb5-fd9b610cf27d} - C:\WINDOWS\system32\cwrvfcan.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: (no name) - {7EBC0867-D52E-47A6-886D-4B71966AA8C9} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
      O3 - Toolbar: (no name) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - (no file)
      O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [spnsrv9x] C:\MAGIC830\SPNSRV9X.EXE
      O4 - HKLM\..\Run: [vdlDeamon] C:\Program Files\VIDAL\Communs\VIDAL.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [e401cfd2] rundll32.exe "C:\WINDOWS\system32\qdwxykey.dll",b
      O4 - HKLM\..\Run: [BMe732fc4e] Rundll32.exe "C:\WINDOWS\system32\agnpkeuw.dll",s
      O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
      O4 - HKCU\..\Run: [uTorrent] "D:\chreb logiciel\utorrent.exe"
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?3d3f48081ee64d64bffa050357dc76c7
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?3d3f48081ee64d64bffa050357dc76c7
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=http://www.fr.msn.com
      O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - http://67.15.101.3/g_bin/eng/billard8_2_0_0_29.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{F5CB3436-C175-4243-893A-FDF2D278FCF1}: NameServer = 41.221.20.244 213.140.2.12
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O20 - Winlogon Notify: awtursq - awtursq.dll (file missing)
      O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      0
    2. j.joey Messages postés 237 Statut Membre 2
       
      Search Navipromo version 3.5.0 commencé le 15/03/2008 à 12:52:25,00

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1
      Mise à jour le 04.03.2008 à 17h00 par IL-MAFIOSO

      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 6.0.2900.2180
      Système de fichiers : NTFS

      Executé en mode normal

      *** Recherche Programmes installés ***

      *** Recherche dossiers dans C:\WINDOWS ***

      *** Recherche dossiers dans C:\Program Files ***

      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

      *** Recherche dossiers dans "C:\Documents and Settings\SEDRATI\applic~1" ***

      *** Recherche dossiers dans "C:\Documents and Settings\SEDRATI\locals~1\applic~1" ***

      *** Recherche dossiers dans "C:\Documents and Settings\SEDRATI\menudm~1\progra~1" ***

      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net

      Aucun Fichier trouvé

      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans C:\WINDOWS\system32 *

      * Recherche dans "C:\Documents and Settings\SEDRATI\locals~1\applic~1" *

      *** Recherche fichiers ***

      *** Recherche clés spécifiques dans le Registre ***

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :

      2)Recherche Heuristique :

      * Dans C:\WINDOWS\system32 :

      * Dans "C:\Documents and Settings\SEDRATI\locals~1\applic~1" :

      3)Recherche Certificats :

      Certificat Egroup absent !
      Certificat Electronic-Group absent !
      Certificat OOO-Favorit absent !

      4)Recherche fichiers connus :

      C:\WINDOWS\system32\oqstv.ini2 trouvé ! infection Vundo possible non traitée par cet outil !

      *** Analyse terminée le 15/03/2008 à 12:55:13,01 ***
      0
  4. dou-l Messages postés 2871 Statut Membre 61
     
    Navliog stp.
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      alors maintenant qu'est ce que je dois faire?,merci.
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Jack
     
    Bonjour,

    spybot gratuit a un résident. gardes le.

    POP UP STOPPER met des barrières en + dans le navigateur ie, (même peu utilisé).
    Aujourd' hui le lien de VIRUS-KILLER ne marche pas:
    http://www.darkcristal.com/panicware/produits.php

    Pour firefox il y a le module adblockplus (extension de firefox) qui fait pareil dans firefox.
    https://www.hugedomains.com/domain_profile.cfm?d=geckozone&e=org

    Mais si un truc est déjà installé, nettoyer l' intérieur du pc.

    Celui- ci nettoie très bien. Pour rester en gratuit ne demandes pas mise à jour auto et ne fais rien dans l' onglet protection: fais un scan de nettoyage : Onglet recherche, nettoyage complet. dis nous ?
    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
    0
  7. Jack
     
    Ps, malwarebytes nettoierait vundo
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      Malwarebytes' Anti-Malware 1.08
      Version de la base de données: 471

      Type de recherche: Examen rapide
      Eléments examinés: 27924
      Temps écoulé: 6 minute(s), 3 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 1
      Clé(s) du Registre infectée(s): 13
      Valeur(s) du Registre infectée(s): 1
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 4

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      C:\WINDOWS\system32\qdwxykey.dll (Trojan.Vundo) -> Unloaded module successfully.

      Clé(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{23d44bcf-aa7a-41d6-8905-e808f16322ef} (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\Microsoft\aldd (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

      Valeur(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{23d44bcf-aa7a-41d6-8905-e808f16322ef} (Trojan.Vundo) -> Quarantined and deleted successfully.

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      C:\WINDOWS\system32\ehhauetd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\dteuahhe.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\qdwxykey.dll (Trojan.Vundo) -> Delete on reboot.
      C:\WINDOWS\system32\yekyxwdq.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
      0
      1. Jack > j.joey Messages postés 237 Statut Membre
         
        Super, merci, continues avec DOU-I, il verra ce que Malwarebyte a laissé passer.
        0
  8. dou-l Messages postés 2871 Statut Membre 61
     
    télécharge smitfraudfix: http://siri.urz.free.fr/Fix/SmitfraudFix.exe

    #
    Double clique sur l'icone de smitfraud pui choisis l'option 1 et poste le rapport.
    0
  9. dou-l Messages postés 2871 Statut Membre 61
     
    Ok JACK ta fait avancer c'est du vundo

    # Téléchargez VundoFix.exe

    * Double-cliquez sur VundoFix.exe
    * Cliquez sur le bouton Scan for Vundo
    * Si le programme vous demande de supprimer des fichiers, faites oui
    * Lorsque le programme a fini de scanner votre ordinateur, ce dernier doit être éteint, redémarrez le.
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      je l'ai supprimé avec malawarebyte,et j'ai redémarré mon pc,maintenant?
      0
  10. dou-l Messages postés 2871 Statut Membre 61
     
    fait vundofix c'est un outil exprès: http://www.atribune.org/ccount/click.php?id=4
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      j'ai telechargé vundofix,il a supprimé 2fichiers,et mtn?,merci
      0
    2. j.joey Messages postés 237 Statut Membre 2
       
      SmitFraudFix v2.303

      Rapport fait à 14:09:12,35, 15/03/2008
      Executé à partir de D:\chreb logiciel\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\VIDAL\Communs\VIDAL.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\Rundll32.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\Ares\Ares.exe
      D:\chreb logiciel\utorrent.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\system32\cmd.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      Fichier hosts corrompu !

      127.0.0.1 legal-at-spybot.info
      127.0.0.1 www.legal-at-spybot.info

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\SEDRATI

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\SEDRATI\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\SEDRATI\Favoris

      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="Ma page d'accueil"

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Rustock

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: WAN (PPP/SLIP) Interface
      DNS Server Search Order: 41.221.20.244
      DNS Server Search Order: 213.140.2.12

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{F5CB3436-C175-4243-893A-FDF2D278FCF1}: NameServer=41.221.20.244 213.140.2.12
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{F5CB3436-C175-4243-893A-FDF2D278FCF1}: NameServer=41.221.20.244 213.140.2.12

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

      »»»»»»»»»»»»»»»»»»»»»»»» Fin
      0
  11. Jack
     
    Copie/colle le contenu du rapport situé dans C:\vundofix.txt
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      VundoFix V7.0.3

      Scan started at 13:42:26 15/03/2008

      Listing files found while scanning....

      C:\WINDOWS\system32\gsfdkmlv.dll
      C:\WINDOWS\system32\xkmdgtmj.dll

      Beginning removal...

      Attempting to delete C:\WINDOWS\system32\gsfdkmlv.dll
      C:\WINDOWS\system32\gsfdkmlv.dll Has been deleted!

      Attempting to delete C:\WINDOWS\system32\xkmdgtmj.dll
      C:\WINDOWS\system32\xkmdgtmj.dll Has been deleted!

      Performing Repairs to the registry.
      Done!
      0
  12. dou-l Messages postés 2871 Statut Membre 61
     
    Ou en sont tes soucis ??
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      j'ai encore les popups quand j'ouvre une fenetre,c'est pas normale,non?,merci
      0
    2. j.joey Messages postés 237 Statut Membre 2
       
      je crois que le problème est résolu,1000 merci a vous,a+
      0
  13. dou-l Messages postés 2871 Statut Membre 61
     
    comment ca c'est bon ???

    COche résole en haut.
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      enfin,ok j'ai coché,encore merci,bye
      0
  14. panographe
     
    crack + serial de Pinnacle Studio Plus 10 ?
    0