Site qui s ouvre tout seul :

Bonjour,
le site http://www.onlinecashmethod.com/fr/?member=clicksor1&profile=clembronfr n arrete pas de s ouvrir tout seul en ouvrant une page vierge. sa dure et c est enervant pendant le travail je vous prie de me dire comment faire pour s en debarasser.

merci bcp
Configuration: Windows Vista
Internet Explorer 7.0

13 réponses

  1. Contributeur
    Salut,

    //!!\\Désactive l'UAC //!!\\ >> http://www.laboratoire-microsoft.org/tips-23933-desactiver-uac-vista.html
    Démarrer, puis Panneau de configuration.
    Choisis l'affichage classique sur la gauche et double-clique sur Comptes d'utilisateurs.
    Cliques ensuite sur désactiver le contrôle des comptes d'utilisateurs.
    On le réactivera à la fin de la désinfection.

    Télécharge sur le Bureau HijackThis
    http://download.hijackthis.eu/HJTInstall.exe

    = Double-clique sur dessus pour l'installer
    = Clique sur Do a system scan and save the log
    = Colle le rapport
    si problème voir l'aide
    http://perso.orange.fr/rginformatique/section%20virus/demohi­jack.htm

    Puis,

    Télécharge Navilog1 depuis-ce lien :
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
    Ensuite double clique sur navilog1.exe pour lancer l'installation.

    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Au menu principal, Fais le choix 1 >> Recherche
    Laisse toi guider et patiente.
    Patiente jusqu'au message :
    *** Analyse Termine le ..... *** >>>>> Le fix peut durer une dizaine de minutes ;)
    Appuie sur une touche le bloc note va s'ouvrir.
    Copie-colle le rapport ici.

    @+
    0
    1. Salut,
      J'ai bien lu et fait ce que tu as dit de faire E..T tout ce passe bien mais quand l'analyse qui est censée durée quelques minutes se termine, il y a le bloc note qui s'ouvre (avec des trucs écrits) (le fichier qui s'ouvre s'appelle " fixnavi " mais c'est quelles info qu'il faut coller après dans se fichier texte ? et il faut les coller où ? (à la fin au début ?)
      merci de ton aide
      A+
      0
  2. Contributeur
    salut,
    Il faut les poster ou sur les fenêtres de réponses.
    Et tu postes tout le rapport ici ;)
    @+
    0
    1. Ok merci bien ;)
      puis apparemment c'est bon sa m'a viré la pub et d'autre en même temps.
      et en plus la pub je l'ai chopé ses pages de pub sur un site qu'un prof m'a donné !! ^^
      0
      1. Contributeur
        Envoies les rapports s'il te plait ;)
        @+
        0
        1. Pk tu veux mon rapport d'hijack ?
          0
          1. Contributeur
            Salut,
            Je voulais le rapport le rapport pour voir ce qui n'allait pas sur le pc!
            Mais si pour toi c'est ok laisse comme ça.
            Bye.
            0
            1. Salut E..T,
              tient mon rapport ;) :
              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 19:21:29, on 18/11/2008
              Platform: Windows Vista (WinNT 6.00.1904)
              MSIE: Internet Explorer v7.00 (7.00.6000.16386)
              Boot mode: Normal

              Running processes:
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\Windows\System32\rundll32.exe
              C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
              C:\Windows\vVX1000.exe
              C:\Program Files\AVG\AVG8\avgtray.exe
              C:\Program Files\Windows Media Player\wmpnscfg.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\AVG\AVG8\avgscanx.exe
              C:\Program Files\AVG\AVG8\avgui.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
              C:\Windows\system32\SearchFilterHost.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              O1 - Hosts: ::1 localhost
              O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
              O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
              O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O13 - Gopher Prefix:
              O17 - HKLM\System\CCS\Services\Tcpip\..\{4EC65F52-C888-4BBA-8567-8A367B60FA9E}: NameServer = 80.10.246.134 80.10.246.7
              O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
              O20 - AppInit_DLLs: avgrsstx.dll
              O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
              O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
              O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
              O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
              0
              1. Contributeur
                Bonsoir,
                Rien de bien grave sur le rapport qui date du 18/11.
                As tu encore des soucis?
                @+
                0
                1. Bonsoir,
                  non sa a l'air d'avoir fonctionner tant mieux parce que des pages de pub ki n'arrêtent pas de s'afficher c'est vraiment galère. Et non comment avec le rapport hijack tu peux voir ou est le problème ?
                  Merci
                  A+
                  0
                  1. Contributeur
                    Hello,
                    Avec le rapport hijack this on voit ou sont les infections.
                    Et pour navilog tu avais seulement fais le choix 1?
                    ++
                    0
                    1. Salut E..T,
                      Ouais avec navilog j'ai juste fait le choix 1.
                      ++
                      0
                      1. Contributeur
                        et bien envoie le rapport.
                        ++
                        0
                        1. Salut,
                          voila mon rapport avec Navilog en faisant le choix 1 :
                          Search Navipromo version 3.6.9 commencé le 30/11/2008 à 12:24:59,27

                          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                          !!! Postez ce rapport sur le forum pour le faire analyser !!!
                          !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                          Outil exécuté depuis C:\Program Files\navilog1
                          Session actuelle : "Likaze"

                          Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO

                          Microsoft Windows Vista 6.0.6000
                          Internet Explorer : 7.0.6000.16386
                          Système de fichiers : NTFS

                          Recherche executé en mode normal

                          *** Recherche Programmes installés ***

                          *** Recherche dossiers dans "C:\Windows" ***

                          *** Recherche dossiers dans "C:\Program Files" ***

                          *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                          *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

                          *** Recherche dossiers dans "C:\ProgramData" ***

                          *** Recherche dossiers dans "c:\users\likaze\appdata\roaming\micros~1\windows\startm~1\programs" ***

                          *** Recherche dossiers dans "C:\Users\Likaze\AppData\Local\virtualstore\Program Files" ***

                          *** Recherche dossiers dans "C:\Users\Likaze\AppData\Roaming" ***

                          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                          pour + d'infos : http://www.gmer.net

                          *** Recherche avec GenericNaviSearch ***
                          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                          !!! A vérifier impérativement avant toute suppression manuelle !!!

                          * Recherche dans "C:\Windows\system32" *

                          * Recherche dans "C:\Users\Likaze\AppData\Local\Microsoft" *

                          * Recherche dans "C:\Users\Likaze\AppData\Local" *

                          *** Recherche fichiers ***

                          *** Recherche clés spécifiques dans le Registre ***

                          *** Module de Recherche complémentaire ***
                          (Recherche fichiers spécifiques)

                          1)Recherche nouveaux fichiers Instant Access :

                          2)Recherche Heuristique :

                          * Dans "C:\Windows\system32" :

                          * Dans "C:\Users\Likaze\AppData\Local\Microsoft" :

                          * Dans "C:\Users\Likaze\AppData\Local" :

                          3)Recherche Certificats :

                          Certificat Egroup absent !
                          Certificat Electronic-Group absent !
                          Certificat Montorgueil absent !
                          Certificat OOO-Favorit absent !
                          Certificat Sunny-Day-Design-Ltd absent !

                          4)Recherche fichiers connus :

                          *** Analyse terminée le 30/11/2008 à 12:34:34,39 ***

                          voila et il sert a quoi ce rapport ?
                          ++
                          0