Virus , je suis perdu

lasbi Messages postés 4 Statut Membre -  
lasbi Messages postés 4 Statut Membre -
Bonjour,
Je me permet de re soliciter votre aide car un virus s attaque encore a mon ordinateur .
a vai dire il y a a peu près un moi j ai reussi a vaindre vundo je croi bien en y passant une soirée éprouvante . et voilà qu aujourdhui les pop ups reviennent. a peu près les meme symptomes , sauf que là il ne sagirait pas de vundo ... je me permet donc de demander l aide des génie de ce forum .
je reviens dans quelque minute avec raport hi jack this et combofix fait en mode sans echec .
@ tout de suite.
merci davance .
Configuration: Windows XP
Internet Explorer 7.0

2 réponses

  1. kendoloï Messages postés 110 Statut Membre 5
     
    Pour les popups , installe firefox et ne te sers plus de internet explorer ...

    Si ça continue installe la panoplie , ccleaner , spybot , adaware !
    0
    1. VIRUS_KILLER Messages postés 2075 Statut Contributeur 68
       
      Salut
      Non ces logiciels ne font rien contre les Pubs!
      quelle genre de Pub a tu?
      Sptware Secure,Cid?,,,,,,,
      0
      1. kendoloï Messages postés 110 Statut Membre 5 > VIRUS_KILLER Messages postés 2075 Statut Contributeur
         
        Adaware , avg antispyware t'enlèvent quand même les doubleclick et tous les fichiers dans le genre !!!

        Si ça c'est pas de la pub ...
        0
      2. VIRUS_KILLER Messages postés 2075 Statut Contributeur 68 > kendoloï Messages postés 110 Statut Membre
         
        Oui mais tu voit il y a 6 mois quand je me suis fait bonbarder par des Pubs moi.
        J'ai du essayer tout les Antyspyware connus jusqu'au dernier!
        Et c'est pas ce qui enleve les Pubs!
        Il faut utiliser des logiciels spécial crée pour ces types d'infection.
        0
      3. kendoloï Messages postés 110 Statut Membre 5 > VIRUS_KILLER Messages postés 2075 Statut Contributeur
         
        T' as pas 36 solutions :

        Regsupreme pro ou hijackthis

        C'est forcement dans le registre !!!
        0
  2. lasbi Messages postés 4 Statut Membre
     
    hijackthis :
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:59, on 12/05/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Safe mode

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Trend Micro\HijackThis\scanner.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {D014E2EE-DF9B-45C6-B9FA-9C29D3893D38} - C:\WINDOWS\system32\opnNfgDw.dll
    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
    O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [08d0e808] rundll32.exe "C:\WINDOWS\system32\xcdtiogb.dll",b
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [BM0be3db94] Rundll32.exe "C:\WINDOWS\system32\sdldqmxc.dll",s
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
    O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
    O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
    O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
    O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
    O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://www.streamplug.com/StreamPlug/SP.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - https://www.eset.com/
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3182EE6A-DE8E-4A8D-9829-E1B69E5BE552}: NameServer = 212.27.53.252,212.27.54.252
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    0
    1. kendoloï Messages postés 110 Statut Membre 5
       
      T'as 3 lignes à virer sur hijackthis !

      pour te dire lesquels il faut un mec plus baleze que moi
      0
      1. lasbi Messages postés 4 Statut Membre > kendoloï Messages postés 110 Statut Membre
         
        Merci de ta réponse . reste a savoir les quelles ^:p
        0
      2. kendoloï Messages postés 110 Statut Membre 5 > lasbi Messages postés 4 Statut Membre
         
        http://www.hijackthis.de/fr

        tiens , t'auras une idée !!!!
        0
      3. lasbi Messages postés 4 Statut Membre > kendoloï Messages postés 110 Statut Membre
         
        j arrive pas a suprimer une ligne O2 - BHO: (no name) - {328C5EA3-A41C-41DE-A2F7-3E471E643BD2} - C:\WINDOWS\system32\opnNfgDw.dll

        Programme inconnu. elle revient sans cesse .
        idelm pour celle ci O4 - HKLM\..\Run: [BM0be3db94] Rundll32.exe "C:\WINDOWS\system32\sdldqmxc.dll",s
        0