Certains sites internet ne s ouvrent plus

chrismel -  
 chrismel -
Bonjour,

Help !!!
Je n'arrive plus à accéder à certains sites internet (ex : Darty, 3suissses, Isohunt) alors que d'autes sites fonctionnent sans problèmes (banque, google, boite mail).
J'ai remarqué aussi que des fenêtres pub s'ouvrent bien plus souvent qu'auparavant.
merci de votre aide
A voir également:

2 réponses

jrmlpz Messages postés 455 Date d'inscription   Statut Membre Dernière intervention   50
 
Salut,

Nettoies totalement ton PC avec HITMAN PRO.

Bon courage!
0
chrismel Messages postés 1 Statut Membre
 
merci pour le conseil, j'ai bien supprimé une cinquantaine de fichiers dits infectés, mais j'ai toujours le même problème, à savoir, la barre de recherche du site qui bloque au tiers et la connexion n'aboutit pas.....

une autre idée ??

merci d'avance
0
salma > chrismel Messages postés 1 Statut Membre
 
telecharges malwarebytes ici http://www.commentcamarche.net/telecharger/telechargement 34055379 malwarebyte s anti malware

met le à jour avant de scaner complétement ton systeme , à la fin produit un rapport et copier coller dans ta prochaine réponse
A PLUS
0
chrismel > salma
 
Bonjour,

voilà, c'est fait ...


Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f6b0e791-01ac-45ea-adc4-a2d88a39e877} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f6b0e791-01ac-45ea-adc4-a2d88a39e877} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{850c982a-4bc4-47db-b028-6439280512d0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{850c982a-4bc4-47db-b028-6439280512d0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{aa442331-a55a-4ff9-99ca-07cd0e06a477} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{aa442331-a55a-4ff9-99ca-07cd0e06a477} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mljaskax (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\4c55354f (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM4f6606d3 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{aa442331-a55a-4ff9-99ca-07cd0e06a477} (Trojan.Vundo) -> Delete on reboot.

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\yayatsll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\yayatsll -> Delete on reboot.

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\WINDOWS\system32\yayAtSll.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\llStAyay.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\llStAyay.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vpjkwwrw.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\wrwwkjpv.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bxrlbjfb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ahmucqwc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christelle\Local Settings\Temporary Internet Files\Content.IE5\13NWZA91\nm9r[1].dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Christelle\Local Settings\Temporary Internet Files\Content.IE5\OP9VW1ZH\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nnnLdAqO.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mlJASKax.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.


Alors, qu'en pensez vous ?
0
jrmlpz Messages postés 455 Date d'inscription   Statut Membre Dernière intervention   50
 
Alors?
0
chrismel
 
bonjour,

après nettoyage par hitman pro, je réussis à nouveau à consulter tous les sites mais avec un certain délais.
Par contre 3 autres anomalies maintenant :
1 - message d'erreur à chaque démarrage du PC (non bloquant) "erreur de chargement de C:\windows\system32\scptjlyr.dll le module spécifié est introuvable" et " erreur de chargement de C:\windows\system32\anqjkyep.dll le module spécifié est introuvable". Je clique OK et tout fonctionne mais cà ne doit pas être normal.....

2 - des virus me sont spécifiés très souvent.


3 - sur Internet, mes pages font comme des vagues quand je descends l'ascensceur. C'est un peu génant mais pas bloquant.

J'ai beaucoup moins de pub qui s'affichent mais un peu quand même. Je n'en avais aucune avant mon problème.

Volià, merci pour votre intérêt en tout cas, à ce jour je peux faire tout ce que je faisait avant, mais pas aussi vite et avec une moins bonne qualité.
Voici le rapport Hitman au cas où cela peut vous aider...


Hitman Pro 2.7.6.0 - Report
05-07-2008 08:37


Setup files external protection and inspection components
STATUS DESCRIPTION VERSION SIZE
Recent Archive Extraction Utility 0.0.0.0 307276 bytes
Recent RAR decompression library 3.41.0.306 158720 bytes
Recent Archive Compression Utility 0.0.0.0 276044 bytes
Recent File Encryption/Decryption Utility 0.0.0.0 69708 bytes
Recent Trend Micro CWShredder 2.19.0.1099 532480 bytes
Updated SpywareBlaster 3.5.1.0 2566736 bytes
Recent Ewido AntiSpyware Micro 4.0.0.1 153144 bytes
Recent PC Tools Spyware Doctor 5.5.1.322 18473000 bytes

Updates
Recent Hitman Pro Updater 2.6.0.0 489960 bytes
STATUS DESCRIPTION SIZE
Recent Hitman Pro uninstaller 554832 bytes
Updated Lavasoft Ad-Aware SE Definitions 0.0.0.0 4032928 bytes
Recent Prevx CSI 1.1.0.30 1563704 bytes

Prevx CSI - Free PC Malware Scanner v1.0.100.179 00:01:19
Prevx2.0 improves your existing security by providing protection against the very latest Spyware, Rootkits, Trojans, Viruses, Bots, Adware and Password Stealers - collectively known as Malware.
Fraudulent Security Program
Prevx CSI identified 4 threats since 04/07/2008

Could not install cumulative Security Update for Internet Explorer (KB912812)
Your system could be vulnerable to exploits mentioned in this Microsoft Security Bulletin: MS06-013

Adobe Flash Player 9 ActiveX control upgrade
ActiveX control is current (no upgrade needed) (9.0.124.0)

System protection and immunization
Security Update KB925486 (Vulnerability in Vector Markup Language)
This update addresses the vulnerability discussed in Microsoft Security Bulletin MS06-055

Messenger service disabled
The Messenger service can be abused to send ads and spam to computers in a network. Microsoft also released security updates to repair vulnerabilities in the Messenger service; attackers where able to run code through the Messenger service on unpatched systems. Note that the Messenger service has nothing to do with MSN Messenger en Windows Messenger.
Install on Demand has been disabled
When Install on Demand enabled, a Web page can download items to display the page properly, or perform a particular task. Web sites can abuse Installation on demand to install spyware. Note that when you disable Install on Demand you will no longer be prompted to download missing Language Pack components (for Web pages that require, for example, Japanese-text display support).
Trust level of zone Internet is set to Normal (Current User)
Trust level of zone Internet is set to Normal (All Users)
The trust level the Internet Zone should at least be set to Normal. This default setting causes Internet Explorer to prompt the user whenever potentially unsafe content is ready to download.
SpywareBlaster protection applied
Blocks the installation of spyware, adware, dialers, browser hijackers, and other potentially unwanted ActiveX-based software. With Internet Explorer 6 and Mozilla/Firefox, it also blocks cookies that may be used to track your activities, build a profile about your habits, collect information, or uniquely identify you to advertisers.
SpywareBlaster is freeware for personal and educational use. For more information visit http://www.brightfort.com/spywareblaster.html


Spybot - Search & Destroy 00:45:50
Version 1.4 (Build 2005-05-23) Latest detection update: 2008-07-02
Spybot - Search & Destroy can detect and remove spyware of different kinds from your computer (removal of adware, spyware, dialers, keyloggers, usage tracks, trojans and other baddies). Spybot S&D is also capable of blocking threatening ActiveX downloads (supplementing SpywareBlaster) to protect your system against spyware.
Virtumonde
Right Media
DirectTrack

Webroot Spy Sweeper 00:26:54
Webroot Spy Sweeper lets you protect your privacy and your computer from a variety of spyware and unwanted programs, from those that monitor all of your computer's activities (system monitors), to those that can steal or destroy data (Trojan horses). It also detects programs that pop up advertising on your computer (adware) and cookies that may contain personal information (tracking cookies).
virtumonde
mlJASKax.dll

Ewido Micro 00:59:46
ewido anti-malware offers you realtime protection against Hijackers and Spyware, Worms, Dialers, Trojans and Keyloggers. Click here for more information.
Trojan.Monder.wh
Not-A-Virus.Downloader.Win32.ImLoader.f
Trojan.Monderc

Disk Cleanup
Cleaned C:\Documents and Settings\Christelle
Cleaned C:\WINDOWS\Temp
Cleared 18 MB
Disk Cleanup clears folders with temporary Windows and Internet Files. Over time these folders can contain a lot of files, occupying a lot of disk space. This space could normally be used for documents and programs. Clearing the temporary folders is also an advantage for Hitman Pro because it will shorten inspection time of Ad-aware, Spy Sweeper and Spybot S&D. Also, the inspection programs will find fewer traces of spyware because potential spyware installation files are already wiped by Disk Cleanup.

This report is generated by Hitman Pro, created by Mark Loman
Support the resistance against spyware and make a small donation; see the link Donate




Encore merci

Cordialement
0