Comment bloqué les popups

Résolu
j.joey Messages postés 237 Statut Membre -  
 panographe -
bonjour,j'ai des popups de femmes a poil sur mes fenetres malgré que j'ai spybot,et sa me dérange
svp aidez moi,merci
Configuration: Windows XP
Firefox 2.0.0.12

14 réponses

  1. VIRUS_KILLER Messages postés 2075 Statut Contributeur 68
     
    Salut,
    OK MDR
    Tu a un adware qui affichent des PUB.?
    OK:
    Telecharge POP UP STOPPER Ici:
    --https://www.01net.com/telecharger/
    J'étais comme vous,un debutant.Au debut,les VIRUS,etait plus fort que moi.Mais maitenant,il ne passeront pas.Mon metier de + tard=un pro en informatique,surtout en securité!j'adore l'informatique,je vai KILL ces VIRUS!!!!!!!qui pourisent nos PC!!!!
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      oui je l'ai deja
      0
  2. Utilisateur anonyme
     
    Bonjour, tout simplement: allez dans outils -> options -> Confidentialité et en bas, cochez Activer le bloqueur de fenetres intempestives.
    En éspérant que cela vous ait aidé
    0
  3. dou-l Messages postés 2871 Statut Membre 61
     
    salut,

    -fait un log hijack:

    ftp://ftp.commentcamarche.com/download/HJTInstall.exe

    Fait un clic droit sur l'icone hijackthis.

    /!\Renome hijackthis en skimboard.exe ( a le place de hijacktihs.exe) c'est important.

    Après avoir fais ca double-clic dessus.

    Clic sur Do a system scan and save the log

    A la fin de l'analyse un rapport va etre générer colle le ici.

    Une démo d'hijackthis :
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

    va a cette adressse et télécharge Navilog:

    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    -Choisis Enregistrer et enregistre-le sur ton bureau.

    - Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    -Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
    Patiente jusqu'au message " Analyse Termine le ....."

    -Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie/colle l'intégralité du rapport dans ta réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

    -Si ton antivirus detecte un virus ou un cheval de troie durant l'analyse ignore le.
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 12:46:24, on 15/03/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\VIDAL\Communs\VIDAL.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\Rundll32.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\Ares\Ares.exe
      C:\WINDOWS\system32\spoolsv.exe
      D:\chreb logiciel\utorrent.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\DOCUME~1\SEDRATI\LOCALS~1\Temp\Répertoire temporaire 2 pour HiJackThis.zip\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.fr.msn.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
      O1 - Hosts: "http://www.w3.org/TR/html4/loose.dtd">
      O1 - Hosts: <html>
      O1 - Hosts: <head>
      O1 - Hosts: <script LANGUAGE="JavaScript">
      O1 - Hosts: <!--
      O1 - Hosts: if (window != top)
      O1 - Hosts: top.location.href = location.href;
      O1 - Hosts: // -->
      O1 - Hosts: </script>
      O1 - Hosts: <title>Site Unavailable</title>
      O1 - Hosts: <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
      O1 - Hosts: <style type="text/css">
      O1 - Hosts: body{text-align:center;}
      O1 - Hosts: .geohead {font-family:Verdana, Arial, Helvetica, sans-serif; font-size:10px;width:750px;margin:10px 0 10px 0;height:35px;}
      O1 - Hosts: .geohead #geologo {width:270px;display:block; float:left; }
      O1 - Hosts: .geohead #rightside {width:480px;display:block; float:right;border-bottom:1px solid #999999; height:27px;}
      O1 - Hosts: .geohead #rightside #welcome {width:50%;display:block; float:left; text-align:left;}
      O1 - Hosts: .geohead #rightside #wlinks {width:50%;display:block; float:right; text-align:right;}
      O1 - Hosts: .ftr { margin:0px; color:#404040; font:x-small Arial,sans-serif; text-align:center; width:750px;}
      O1 - Hosts: .bodywrap{display:block;height:470px;}
      O1 - Hosts: .bodycnt{width:510px; display:block; float:left; background-color:#EEE9F5; height:auto; text-align:left; font-family:Arial, Helvetica, sans-serif;font-size:13px; color:#000000; padding:20px 20px 35px 20px;}
      O1 - Hosts: .title { font-family:Arial, Helvetica, sans-serif; font-weight:bold; font-size:24px; color:#7C56A9}
      O1 - Hosts: .adcnt{width:172px; display:block; float:right; text-align:left;cursor:pointer;cursor:hand;}
      O1 - Hosts: .adcnt td {text-align:left;}
      O1 - Hosts: .adsubt{font-size:10px; font-family:verdana; font-weight:bold; color:#b4b4b4; cursor:default;margin-top:5px;}
      O1 - Hosts: .ybadge { font-family: Verdana, Arial, Helvetica, sans-serif; font-size:10px; color: #666666; margin-top:10px;}
      O1 - Hosts: .ybadge img {margin-top:6px;}
      O1 - Hosts: .adtable {font-family:Verdana, Arial, Helvetica, sans-serif; font-size:10px;border: 1px solid #d6dbe7; background-color:#eff7ff; padding:3px; margin-bottom:10px; width:172px;}
      O1 - Hosts: .adttl{font-weight:bold;margin-bottom:3px;}
      O1 - Hosts: .addescr{color:#6b6b6b; margin-bottom:3px;}
      O1 - Hosts: .adlink a {color:#008200; text-decoration:none;}
      O1 - Hosts: </style>
      O1 - Hosts: </head>
      O1 - Hosts: <body>
      O1 - Hosts: <!-- following code added by server. PLEASE REMOVE -->
      O1 - Hosts: <!-- preceding code added by server. PLEASE REMOVE -->
      O1 - Hosts: <div id="maincnt">
      O1 - Hosts: <div class="geohead"><div id="geologo"><a href="https://smallbusiness.yahoo.com/"><img height=33 alt="Yahoo! GeoCities" src="http://us.i1.yimg.com/us.yimg.com/i/us/nt/ma/ma_geo_1.gif" width=259 border=0></a></div>
      O1 - Hosts: <div id="rightside"><div id="wlinks"><a href="https://smallbusiness.yahoo.com/">GeoCities Home</a> - <a href="https://fr.yahoo.com/?p=us">Yahoo!</a> - <a href="https://help.yahoo.com/kb/account">Help</a></div>
      O1 - Hosts: </div></div>
      O1 - Hosts: <div class="bodywrap">
      O1 - Hosts: <div class="bodycnt">
      O1 - Hosts: <div class="title">Sorry, this GeoCities site is currently unavailable.</div>
      O1 - Hosts: <p>The GeoCities web site you were trying to view has temporarily exceeded its data transfer limit. Please try again later. </p>
      O1 - Hosts: <p>Are you the site owner?
      O1 - Hosts: Avoid service interruptions in the future by increasing your data transfer limit!
      O1 - Hosts: <a href="https://help.yahoo.com/kb/account" target="_blank">Find out how.</a> </p>
      O1 - Hosts: <p><a href="https://help.yahoo.com/kb/account" target="_blank">Learn more about data transfer.</a></p>
      O1 - Hosts: </div>
      O1 - Hosts: <div class="adcnt">
      O1 - Hosts: <a target="_top" href="https://smallbusiness.yahoo.com/"><img src="http://us.i1.yimg.com/us.yimg.com/i/us/smbiz/b/geo_mast_small2.gif" alt="Yahoo! GeoCities" border="0" height="15" hspace="0" vspace="0" width="141"></a>
      O1 - Hosts: <div class="adsubt">SPONSORED LINKS</div>
      O1 - Hosts: <!--<table width="172" border="0" bgcolor="#FFFFFF" class="adtable"><tr><td align=left>-->
      O1 - Hosts: <div class="adtable">
      O1 - Hosts: <div class="adttl" title="Reliable plans include domain & 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27166/*https://smallbusiness.yahoo.com/hosting" target="_blank">Yahoo! Web Hosting<br>
      O1 - Hosts: $25 Setup Waived</a></div>
      O1 - Hosts: <div class="addescr" title="Reliable plans include domain & 24x7 support.">Reliable plans include domain & 24x7 support.</div>
      O1 - Hosts: <div class="adlink" title="Reliable plans include domain & 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27166/*https://smallbusiness.yahoo.com/hosting" target="_blank">webhosting.yahoo.com</a></div>
      O1 - Hosts: </div>
      O1 - Hosts: <div class="adtable">
      O1 - Hosts: <div class="adttl" title="Reliable plans include domain & 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27176/*https://smallbusiness.yahoo.com/domains" target="_blank">Domain Names from Yahoo! only $9.95/yr</a></div>
      O1 - Hosts: <div class="addescr" title="Includes starter web page, email & domain forwarding, 24x7 support.">Includes starter web page, email & domain forwarding, 24x7 support.</div>
      O1 - Hosts: <div class="adlink" title="Includes starter web page, email & domain forwarding, 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27176/*https://smallbusiness.yahoo.com/domains" target="_blank">domains.yahoo.com</a></div>
      O1 - Hosts: </div>
      O1 - Hosts: <div class="adtable">
      O1 - Hosts: <div class="adttl" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27184/*https://smallbusiness.yahoo.com/mail" target="_blank">Yahoo! Business Email<br> Domain Included</a></div>
      O1 - Hosts: <div class="addescr" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning.">Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning.</div>
      O1 - Hosts: <div class="adlink" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=27184/*https://smallbusiness.yahoo.com/mail" target="_blank">smallbusiness.yahoo.com</a></div>
      O1 - Hosts: </div>
      O1 - Hosts: <div class="adtable">
      O1 - Hosts: <div class="adttl" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=/27190/*https://smallbusiness.yahoo.com/stores" target="_blank">Ecommerce from Yahoo!<br> 1 Month Free</a></div>
      O1 - Hosts: <div class="addescr" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support.">$50 setup fee waived. A reliable ecommerce plan, 24x7 support.</div>
      O1 - Hosts: <div class="adlink" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support."><a href="https://fr.yahoo.com/?p=us*http://us.rd.yahoo.com/evt=/27190/*https://smallbusiness.yahoo.com/stores" target="_blank">smallbusiness.yahoo.com</a></div>
      O1 - Hosts: </div>
      O1 - Hosts: <div class="ybadge">
      O1 - Hosts: Get your own web site at <br><a target="_top" href="https://smallbusiness.yahoo.com/">Yahoo! GeoCities</a>
      O1 - Hosts: <a href="https://smallbusiness.yahoo.com/hosting" target="_top"><img src="http://us.i1.yimg.com/us.yimg.com/i/us/wh/gr/badge_hostedby_purp_2.gif" alt="Hosted by Yahoo! Web Hosting" align="middle" border="0" height="31" width="88"></a>
      O1 - Hosts: </div>
      O1 - Hosts: </div>
      O1 - Hosts: </div>
      O1 - Hosts: <div class=ftr>
      O1 - Hosts: <hr size=1 width=100%>
      O1 - Hosts: Copyright ©
      O1 - Hosts: 2005 Yahoo! Inc. All rights reserved<br>
      O1 - Hosts: <a href="https://www.verizonmedia.com/policies/">Privacy Policy</a>
      O1 - Hosts: - <a href="https://fr.yahoo.com/?p=us">Copyright Policy</a>
      O1 - Hosts: - <a href="https://fr.yahoo.com/?p=us">Guidelines</a>
      O1 - Hosts: - <a href="https://fr.yahoo.com/?p=us">Terms of Service</a>
      O1 - Hosts: - <a href="https://help.yahoo.com/kb/account">Help</a>
      O1 - Hosts: </div>
      O1 - Hosts: </div>
      O1 - Hosts: </body>
      O1 - Hosts: </html>
      O1 - Hosts: <!-- text below generated by server. PLEASE REMOVE --></object></layer></div></span></style></noscript></table></script></applet>
      O1 - Hosts: <IMG SRC="http://geo.yahoo.com/serv?s=19190039&t=1167440002&f=us-w68" ALT=1 WIDTH=1 HEIGHT=1>
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {23D44BCF-AA7A-41D6-8905-E808F16322EF} - (no file)
      O2 - BHO: {d72fc016-b9df-5be9-0ed4-943688231b44} - {44b13288-6349-4de0-9eb5-fd9b610cf27d} - C:\WINDOWS\system32\cwrvfcan.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: (no name) - {7EBC0867-D52E-47A6-886D-4B71966AA8C9} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
      O3 - Toolbar: (no name) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - (no file)
      O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [spnsrv9x] C:\MAGIC830\SPNSRV9X.EXE
      O4 - HKLM\..\Run: [vdlDeamon] C:\Program Files\VIDAL\Communs\VIDAL.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [e401cfd2] rundll32.exe "C:\WINDOWS\system32\qdwxykey.dll",b
      O4 - HKLM\..\Run: [BMe732fc4e] Rundll32.exe "C:\WINDOWS\system32\agnpkeuw.dll",s
      O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
      O4 - HKCU\..\Run: [uTorrent] "D:\chreb logiciel\utorrent.exe"
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?3d3f48081ee64d64bffa050357dc76c7
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?3d3f48081ee64d64bffa050357dc76c7
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=http://www.fr.msn.com
      O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - http://67.15.101.3/g_bin/eng/billard8_2_0_0_29.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{F5CB3436-C175-4243-893A-FDF2D278FCF1}: NameServer = 41.221.20.244 213.140.2.12
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O20 - Winlogon Notify: awtursq - awtursq.dll (file missing)
      O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      0
    2. j.joey Messages postés 237 Statut Membre 2
       
      Search Navipromo version 3.5.0 commencé le 15/03/2008 à 12:52:25,00

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1
      Mise à jour le 04.03.2008 à 17h00 par IL-MAFIOSO


      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 6.0.2900.2180
      Système de fichiers : NTFS

      Executé en mode normal

      *** Recherche Programmes installés ***




      *** Recherche dossiers dans C:\WINDOWS ***



      *** Recherche dossiers dans C:\Program Files ***



      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***




      *** Recherche dossiers dans "C:\Documents and Settings\SEDRATI\applic~1" ***



      *** Recherche dossiers dans "C:\Documents and Settings\SEDRATI\locals~1\applic~1" ***



      *** Recherche dossiers dans "C:\Documents and Settings\SEDRATI\menudm~1\progra~1" ***


      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***


      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net

      Aucun Fichier trouvé



      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans C:\WINDOWS\system32 *

      * Recherche dans "C:\Documents and Settings\SEDRATI\locals~1\applic~1" *



      *** Recherche fichiers ***




      *** Recherche clés spécifiques dans le Registre ***


      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :


      2)Recherche Heuristique :

      * Dans C:\WINDOWS\system32 :


      * Dans "C:\Documents and Settings\SEDRATI\locals~1\applic~1" :


      3)Recherche Certificats :

      Certificat Egroup absent !
      Certificat Electronic-Group absent !
      Certificat OOO-Favorit absent !

      4)Recherche fichiers connus :

      C:\WINDOWS\system32\oqstv.ini2 trouvé ! infection Vundo possible non traitée par cet outil !


      *** Analyse terminée le 15/03/2008 à 12:55:13,01 ***
      0
  4. dou-l Messages postés 2871 Statut Membre 61
     
    Navliog stp.
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      alors maintenant qu'est ce que je dois faire?,merci.
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Jack
     
    Bonjour,

    spybot gratuit a un résident. gardes le.

    POP UP STOPPER met des barrières en + dans le navigateur ie, (même peu utilisé).
    Aujourd' hui le lien de VIRUS-KILLER ne marche pas:
    http://www.darkcristal.com/panicware/produits.php

    Pour firefox il y a le module adblockplus (extension de firefox) qui fait pareil dans firefox.
    https://www.hugedomains.com/domain_profile.cfm?d=geckozone&e=org

    Mais si un truc est déjà installé, nettoyer l' intérieur du pc.

    Celui- ci nettoie très bien. Pour rester en gratuit ne demandes pas mise à jour auto et ne fais rien dans l' onglet protection: fais un scan de nettoyage : Onglet recherche, nettoyage complet. dis nous ?
    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
    0
  7. Jack
     
    Ps, malwarebytes nettoierait vundo
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      Malwarebytes' Anti-Malware 1.08
      Version de la base de données: 471

      Type de recherche: Examen rapide
      Eléments examinés: 27924
      Temps écoulé: 6 minute(s), 3 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 1
      Clé(s) du Registre infectée(s): 13
      Valeur(s) du Registre infectée(s): 1
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 4

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      C:\WINDOWS\system32\qdwxykey.dll (Trojan.Vundo) -> Unloaded module successfully.

      Clé(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{23d44bcf-aa7a-41d6-8905-e808f16322ef} (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\Microsoft\aldd (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

      Valeur(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{23d44bcf-aa7a-41d6-8905-e808f16322ef} (Trojan.Vundo) -> Quarantined and deleted successfully.

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      C:\WINDOWS\system32\ehhauetd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\dteuahhe.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\qdwxykey.dll (Trojan.Vundo) -> Delete on reboot.
      C:\WINDOWS\system32\yekyxwdq.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
      0
      1. Jack > j.joey Messages postés 237 Statut Membre
         
        Super, merci, continues avec DOU-I, il verra ce que Malwarebyte a laissé passer.
        0
  8. dou-l Messages postés 2871 Statut Membre 61
     
    télécharge smitfraudfix: http://siri.urz.free.fr/Fix/SmitfraudFix.exe

    #
    Double clique sur l'icone de smitfraud pui choisis l'option 1 et poste le rapport.
    0
  9. dou-l Messages postés 2871 Statut Membre 61
     
    Ok JACK ta fait avancer c'est du vundo

    # Téléchargez VundoFix.exe

    * Double-cliquez sur VundoFix.exe
    * Cliquez sur le bouton Scan for Vundo
    * Si le programme vous demande de supprimer des fichiers, faites oui
    * Lorsque le programme a fini de scanner votre ordinateur, ce dernier doit être éteint, redémarrez le.
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      je l'ai supprimé avec malawarebyte,et j'ai redémarré mon pc,maintenant?
      0
  10. dou-l Messages postés 2871 Statut Membre 61
     
    fait vundofix c'est un outil exprès: http://www.atribune.org/ccount/click.php?id=4
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      j'ai telechargé vundofix,il a supprimé 2fichiers,et mtn?,merci
      0
    2. j.joey Messages postés 237 Statut Membre 2
       
      SmitFraudFix v2.303

      Rapport fait à 14:09:12,35, 15/03/2008
      Executé à partir de D:\chreb logiciel\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\VIDAL\Communs\VIDAL.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\Rundll32.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\Ares\Ares.exe
      D:\chreb logiciel\utorrent.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\system32\cmd.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      Fichier hosts corrompu !

      127.0.0.1 legal-at-spybot.info
      127.0.0.1 www.legal-at-spybot.info

      »»»»»»»»»»»»»»»»»»»»»»»» C:\


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\SEDRATI


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\SEDRATI\Application Data


      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer


      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\SEDRATI\Favoris


      »»»»»»»»»»»»»»»»»»»»»»»» Bureau


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues


      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="Ma page d'accueil"


      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri


      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri


      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll


      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""


      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "System"=""


      »»»»»»»»»»»»»»»»»»»»»»»» Rustock



      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: WAN (PPP/SLIP) Interface
      DNS Server Search Order: 41.221.20.244
      DNS Server Search Order: 213.140.2.12

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{F5CB3436-C175-4243-893A-FDF2D278FCF1}: NameServer=41.221.20.244 213.140.2.12
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{F5CB3436-C175-4243-893A-FDF2D278FCF1}: NameServer=41.221.20.244 213.140.2.12


      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll


      »»»»»»»»»»»»»»»»»»»»»»»» Fin
      0
  11. Jack
     
    Copie/colle le contenu du rapport situé dans C:\vundofix.txt
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      VundoFix V7.0.3

      Scan started at 13:42:26 15/03/2008

      Listing files found while scanning....

      C:\WINDOWS\system32\gsfdkmlv.dll
      C:\WINDOWS\system32\xkmdgtmj.dll

      Beginning removal...

      Attempting to delete C:\WINDOWS\system32\gsfdkmlv.dll
      C:\WINDOWS\system32\gsfdkmlv.dll Has been deleted!

      Attempting to delete C:\WINDOWS\system32\xkmdgtmj.dll
      C:\WINDOWS\system32\xkmdgtmj.dll Has been deleted!

      Performing Repairs to the registry.
      Done!
      0
  12. dou-l Messages postés 2871 Statut Membre 61
     
    Ou en sont tes soucis ??
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      j'ai encore les popups quand j'ouvre une fenetre,c'est pas normale,non?,merci
      0
    2. j.joey Messages postés 237 Statut Membre 2
       
      je crois que le problème est résolu,1000 merci a vous,a+
      0
  13. dou-l Messages postés 2871 Statut Membre 61
     
    comment ca c'est bon ???

    COche résole en haut.
    0
    1. j.joey Messages postés 237 Statut Membre 2
       
      enfin,ok j'ai coché,encore merci,bye
      0
  14. panographe
     
    crack + serial de Pinnacle Studio Plus 10 ?
    0