Urgence probleme de publicité

Bonjour,
urgence probleme de publicité des que je me connecte sur internet il y a des publicitées qui apparaise sans arret que faire sela et orible
merci de votre aide
Configuration: Windows Vista
Internet Explorer 7.0

18 réponses

  1. qui a t il de marquer en haut des fenetre de pub ? la mention CiD ou autre ?

    télécharge HijackThis ici:
    http://telechargement.zebulon.fr/138-hijackthis-1991.html

    Dézippe le dans un dossier prévu à cet effet.
    Par exemple C:\hijackthis < Enregistre le bien dans c : !
    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/Hijenr.gif

    Lance le puis:
    clique sur "do a system scan and save logfile" (cf démo)
    faire un copier coller du log entier sur le forum
    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/demohijack.htm
    http://www.tutoriaux-excalibur.com/hijackthis.htm
    https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html
    1
    1. Salut
      t' as pas tout fait. rapport?
      Hijackthis ne nettoie pas tout seul, on lit dans le rapport pour te donner une solution
      1
      1. Utilise Firefox pour naviguer sur le Web ;)
        Un petit résolu dans le titre de ton post? :p
        0
        1. bonsoir jonathan,
          installe un logiciel anti popup a sa devrai faire l'affaire rapidement,
          0
          1. bonsoir,
            j'ai deja installer un anti pop up et j'ai deja essayer d'utliser firefox
            0
            1. Salut
              Vas plutôt voir ici (tu es sous Vista)
              http://www.commentcamarche.net/faq/sujet 2490 popups ouverture de fenetres internet publicitaires pop up
              A+
              0
              1. bonsoir,
                j'ai fait tous se que vous mavais dis mais il y a encore des pub
                0
                1. Contributeur sécurité
                  re, si tu as passer navilog1 le rapport tu peux nous l'envoyer merci
                  0
              2. Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 22:09:05, on 29/05/2008
                Platform: Windows Vista (WinNT 6.00.1904)
                MSIE: Internet Explorer v7.00 (7.00.6000.16643)
                Boot mode: Normal

                Running processes:
                C:\Windows\System32\smss.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\wininit.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\services.exe
                C:\Windows\system32\lsass.exe
                C:\Windows\system32\lsm.exe
                C:\Windows\system32\winlogon.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\Ati2evxx.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\SLsvc.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\Ati2evxx.exe
                c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
                C:\Windows\System32\spoolsv.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\Dwm.exe
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Windows\RtHDVCpl.exe
                c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                C:\Program Files\Spyware Doctor\pctsTray.exe
                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                C:\Program Files\Windows Sidebar\sidebar.exe
                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\Windows\System32\rundll32.exe
                C:\Program Files\Windows Media Player\wmpnscfg.exe
                C:\Windows\System32\p2phost.exe
                C:\Windows\System32\rundll32.exe
                C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                C:\Program Files\Windows Sidebar\sidebar.exe
                C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                C:\Windows\system32\svchost.exe
                C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                C:\Program Files\Spyware Doctor\pctsAuxs.exe
                C:\Program Files\Spyware Doctor\pctsSvc.exe
                C:\Windows\system32\svchost.exe
                C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\SearchIndexer.exe
                C:\Windows\system32\taskeng.exe
                C:\Program Files\Windows Media Player\wmpnetwk.exe
                C:\Windows\system32\taskeng.exe
                C:\Program Files\Internet Explorer\ieuser.exe
                C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Windows Live\Messenger\usnsvc.exe
                C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Windows\explorer.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                C:\Windows\system32\wbem\wmiprvse.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                O1 - Hosts: ::1 localhost
                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                O4 - HKLM\..\Run: [StartCCC] c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
                O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                O4 - HKCU\..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe 20080524
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\jonathan\AppData\Local\Temp\pMdBuSKc.dll,#1
                O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\jonathan\AppData\Local\Temp\byXNGwvT.dll,c
                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                O4 - HKCU\..\Run: [CollaborationHost] C:\Windows\system32\p2phost.exe -s
                O4 - HKCU\..\Run: [4a97ba50] rundll32.exe "C:\Users\jonathan\AppData\Local\Temp\dothqvre.dll",b
                O4 - HKCU\..\Run: [BM49a489cc] Rundll32.exe "C:\Users\jonathan\AppData\Local\Temp\pbnqdgym.dll",s
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                O13 - Gopher Prefix:
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
                O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
                O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
                0
                1. Contributeur sécurité
                  bon tes salopperies son dans le dossier temps tu lances navilog pour la recherche et après avoir eu le rapport pour confirmation tu le relancera et tu tapperas 2 suis le tutoriel http://mickael.barroux.free.fr/securite/navilog.php
                  0
              3. Re

                Bon puisque tu as passé Navilog sans succès (???)

                Clique sur ce lien
                http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
                pour télécharger le fichier d'installation d'HijackThis.

                Enregistre HJTInstall.exe sur ton bureau.
                Double-clique sur HJTInstall.exe pour lancer le programme
                Installe le programme sur c:\ et lance le
                Choisis l'option "Do a system scan and save a log file"
                Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
                Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport
                Colle le rapport
                A+
                0
                1. Re

                  1 / Télécharge SmitFraudFix avec tuto

                  2 / Double clique sur smitfraudfix. puis sélectionne 1 et appuie sur entrée afin de créer le rapport des infections présentes.
                  Une fois le rapport effectué redémarre en mode sans échec (en appuyant sur F8 ou suppr, ou F5 au démarrage en général)
                  3 / Refaire comme en 2/ mais sélectionne l'option 2 et appuie sur entrée pour commencer la désinfection.
                  Lorsque le programme demande si tu veux nettoyer le registre mets oui en tapant O et entrée (colle le rapport)

                  A+
                  0
                  1. merci mais sa ne marche toujour pas
                    0
                    1. Contributeur sécurité
                      qu'est ce qui ne marche pas
                      0
                  2. Contributeur sécurité
                    mais pourquoi ne passe tu pas navilog et tu nous mets le rapport
                    0
                    1. Re
                      Il est vrai qu'avec des réponses comme ça ...

                      Télécharge combofix sur ton Bureau
                      http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                      IMPORTANT

                      désactive ton antivirus, durant l'utilisation de ComboFix . Merci. Tu réactives ensuite
                      puis

                      Double clique combofix.exe.
                      Tape sur la touche Y (Yes) pour démarrer le scan.
                      Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse
                      NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                      A+
                      AVEC LE RAPPORT !!!!!!!!!!!!!!!!!!!!
                      0
                      1. Re

                        Sous Vista :
                        Désactiver le contrôle des comptes utilisateurs (le réactiver à la fin de la désinfection) :
                        Aller dans démarrer puis panneau de configuration
                        Double Cliquer sur l'icône Comptes d'utilisateurs
                        Cliquer ensuite sur désactiver et valider.
                        Démarrer en mode sans échec
                        Faire un clic-droit sur combofix présent sur le bureau et choisir Exécuter en tant qu'administrateur
                        Double cliquer sur combofix.exe.
                        Appuyer sur la touche Y (Yes) pour démarrer le scan
                        A+
                        0
                        1. jonathan fais un effort et suit ce que l'on te dit sans ça on saura jamais ce que tu as fait et si ton ordi est infecté ou pas. Tu suis les procédures c'est tout y'a rien de compliqué
                          0