Site malveillant
RésoluJ'ai été redirigée vers un site malveillant, média amoureux.com je ne sais comment, Wot m'a lancé une alerte
et l'a indiqué trés médiocre
J'ai téléchargé un fichier de commande Windows, j'ai eu l'alerte juste après
merci d'avance de vos réponses
Configuration: windows vista basique Service Pack 2, 1GO de RAM, processeur intel celeron 1,75 GHZ, Mozilla Firefox et Internet Explorer 8
33 réponses
Une redirection vers un site malveillant accompagnée d'une alerte WOT et le téléchargement d'un fichier Windows peuvent indiquer une infection potentielle, même si la menace exacte reste incertaine. Des réponses recommandent d'analyser le fichier avec VirusTotal, de poster le rapport et les logs pertinents, et d'éviter d'exécuter d'autres fichiers suspects tant que la sécurité n'est pas vérifiée. En cas de doute, certains suggèrent des outils comme RSIT, GenProc ou HijackThis, notamment pour compléter l’analyse avec des rapports et vérifier la présence de programmes malveillants au démarrage. Si des symptômes persistent après ces vérifications, il faut envisager un nettoyage plus poussé en mode sans échec et la sauvegarde préalable des données importantes, puis une éventuelle réinstallation du système ou assistance spécialisée.
-
De rien nathandre :)
-
Merci de l'aide que tu m'as apporté, cela m'a permise aussi d'exécuter des outils que je ne connaissais pas bien, cela m'aidera probablement pour ma formation
-
Il ne faut surtout pas cliquer sur les liens de la fiche de phishing
-
Ok alors supprime ce que toolscleaner a laissé. Ensuite passe CCleaner pour nettoyer les fichiers temporaires ansin que pour corriger les erreurs du registres.
Purge egalement ta restauration systeme : http://www.sophos.fr/support/knowledgebase/article/17803.html
Et creer ensuite un point de restauration : https://forums.cnetfrance.fr/tutoriels-windows-7-8-et-autres-sytemes/148799-creer-un-point-de-restauration-sous-windows-7-ou-vista
Et voila ;-)
-
Bien, fait attention a ce genre d'anarque ;-) , veux-tu que l'on fasse toolsclenaer ? l'ordi te parait propre ?
-
Je pense que c'est bon pour ton pc ?
-
Je dirais faux positif, fait le scanner sur virustotal et poste le rapport.
-
Antivirus Version Dernière mise à jour Résultat
a-squared 4.5.0.18 2009.06.23 -
AhnLab-V3 5.0.0.2 2009.06.23 -
AntiVir 7.9.0.193 2009.06.23 -
Antiy-AVL 2.0.3.1 2009.06.23 -
Authentium 5.1.2.4 2009.06.23 -
Avast 4.8.1335.0 2009.06.22 -
AVG 8.5.0.339 2009.06.22 -
BitDefender 7.2 2009.06.23 -
CAT-QuickHeal 10.00 2009.06.22 -
ClamAV 0.94.1 2009.06.23 -
Comodo 1397 2009.06.23 -
DrWeb 5.0.0.12182 2009.06.23 -
eSafe 7.0.17.0 2009.06.22 -
eTrust-Vet 31.6.6573 2009.06.22 -
F-Prot 4.4.4.56 2009.06.22 -
F-Secure 8.0.14470.0 2009.06.23 -
Fortinet 3.117.0.0 2009.06.23 -
GData 19 2009.06.23 -
Ikarus T3.1.1.59.0 2009.06.23 -
Jiangmin 11.0.706 2009.06.23 -
K7AntiVirus 7.10.768 2009.06.19 -
Kaspersky 7.0.0.125 2009.06.23 -
McAfee 5654 2009.06.22 -
McAfee+Artemis 5654 2009.06.22 -
McAfee-GW-Edition 6.7.6 2009.06.23 -
Microsoft 1.4803 2009.06.23 -
NOD32 4179 2009.06.22 -
Norman 6.01.09 2009.06.22 -
nProtect 2009.1.8.0 2009.06.23 -
Panda 10.0.0.16 2009.06.23 Trj/Deldir.A
PCTools 4.4.2.0 2009.06.22 -
Prevx 3.0 2009.06.23 -
Rising 21.35.11.00 2009.06.23 -
Sophos 4.42.0 2009.06.23 -
Sunbelt 3.2.1858.2 2009.06.23 -
Symantec 1.4.4.12 2009.06.23 -
TheHacker 6.3.4.3.351 2009.06.22 -
TrendMicro 8.950.0.1094 2009.06.23 -
VBA32 3.12.10.7 2009.06.23 -
ViRobot 2009.6.23.1800 2009.06.23 -
VirusBuster 4.6.5.0 2009.06.22 -
Information additionnelle
File size: 5080 bytes
MD5...: 895515d5a531ca542169f04c20bbd09b
SHA1..: 6f57fd2ca6df154a40a93b61effa710aa832e3e8
SHA256: 27a73cd4775a0cd202b440a772b7f103e0ef4de4d759148321e97dd306f465ab
ssdeep: 96:KJQNjRhdx+KGaBTcsbeLFNnKd6IC6nXwDSEeB5ALd+m:Kuod7LvZIC7Zd+m
PEiD..: -
TrID..: File type identification
Unknown!
PEInfo: -
Je pense aussi à un faux positif
Ce sont des droles de malins, ils font cela pour qu'on achète leur anti-virus
-
-
;***********************************************************************************************************************************************************************************
ANALYSIS: 2009-06-22 22:15:58
PROTECTIONS: 1
MALWARE: 2
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
Windows Defender 1.1.1505.0 No Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00049258 Trj/Deldir.A Virus/Trojan No 1 Yes No C:\ACER\patch\other1.cmd
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Users\killer\AppData\Roaming\Microsoft\Windows\Cookies\killer@atdmt[2].txt
;===================================================================================================================================================================================
SUSPECTS
Sent Location �%%x��9
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description �%%x��9
;===================================================================================================================================================================================
;===================================================================================================================================================================================
je suis ennuyée, j'ai un cheval de Troie qui perturbe le PC Firefox était complètement bloqué
J'ai trouvé le dossier où il se planque, c'est bizarre, le dossier dépasse 2 GO -
Il me faut les resultats d'au moins un scanner en ligne stp ! n'importe panda en ligne secuser il y en a pleins !
-
Bonjour,
j'avais commencé Kaspersky online scanner, mais cela semblait trop long, j'ai été obligée d'installer Java dont l'icone représente une tasse à café, c'est Firefox qui le demandait. Je ne sais pas quel role Java il peut avoir dans le scan en ligne
Ces fichiers est-ce que c'était des traces d'infection ?
Il y a 2 mois, le PC était infecté par des navipromos, des spywares sécure, un trojan dropper gen, internet game box, dealio et search setting, je ne sais pas si c'est lié
Mon fils avait téléchargé n'importe quoi, sans faire attention
Récemment, j'ai été sur Facebook, c'est un nid à virus -
Ok fait un scan en ligne sur bitdefender ou kaspersky ou secuser ...
Bonne nuit.
-
Poste un RSIT stp .
-
Logfile of random's system information tool 1.06 (written by random/random)
Run by killer at 2009-06-21 22:58:39
Microsoft® Windows Vista™ Édition Familiale Basique Service Pack 2
System drive C: has 76 GB (73%) free of 104 GB
Total RAM: 1013 MB (45% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:58:50, on 21/06/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\killer\Desktop\RSIT.exe
C:\Program Files\trend micro\killer.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/... E510
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: https://www.orange.fr/portail
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
-
-
comment va le pc ?
-
MSNFix 1.760
C:\Users\killer\Desktop\MSNFix\MSNFix
Fix exécuté le 21/06/2009 - 18:12:47,93 By killer
mode sans échec
************************ Recherche les fichiers présents
... C:\Windows\system32\ACER.exe
************************ Recherche les dossiers présents
Aucun dossier trouvé
************************ Suppression des fichiers
.. OK ... C:\Windows\system32\avgvrark.exe
.. OK ... C:\Users\killer\AppData\Local\Temp\winlogon.exe
.. OK ... C:\Users\killer\AppData\Local\Temp\services.exe
.. OK ... C:\Windows\system32\cftmon.exe
.. OK ... C:\Windows\system32\ACER.exe
************************ Nettoyage du registre
************************ Hostsclean
Cleanhosts v 0.1.0.7 By Laurent
-- Backup : C:\Windows\system32\drivers\etc\hosts-20090621183109
-- original size 0.74 Kb / 20 lines
-- Start cleaning Hosts file ....
-- final size 0.74 Kb / 20 lines
-- entry Found : 0 / Entry check : 310
End .............................. 10.37 Secondes
Les fichiers encore présents seront supprimés au prochain redémarrage
Aucun Fichier trouvé
************************ Hostsclean
Cleanhosts v 0.1.0.7 By Laurent
-- Backup : C:\Windows\system32\drivers\etc\hosts-20090621183327
-- original size 0.74 Kb / 20 lines
-- Start cleaning Hosts file ....
-- final size 0.74 Kb / 20 lines
-- entry Found : 0 / Entry check : 310
End .............................. 20.8 Secondes -
Fait msnfix stp...
-
alors execute MSNFIX et poste le rapport.
-
a-squared 4.5.0.18 2009.06.21 -
AhnLab-V3 5.0.0.2 2009.06.20 -
AntiVir 7.9.0.193 2009.06.21 -
Antiy-AVL 2.0.3.1 2009.06.19 -
Authentium 5.1.2.4 2009.06.20 -
Avast 4.8.1335.0 2009.06.20 -
AVG 8.5.0.339 2009.06.21 -
BitDefender 7.2 2009.06.21 -
CAT-QuickHeal 10.00 2009.06.19 -
ClamAV 0.94.1 2009.06.20 -
Comodo 1385 2009.06.21 -
DrWeb 5.0.0.12182 2009.06.21 -
eSafe 7.0.17.0 2009.06.18 -
eTrust-Vet 31.6.6570 2009.06.19 -
F-Prot 4.4.4.56 2009.06.20 -
F-Secure 8.0.14470.0 2009.06.19 -
Fortinet 3.117.0.0 2009.06.21 -
GData 19 2009.06.21 -
Ikarus T3.1.1.59.0 2009.06.21 -
Jiangmin 11.0.706 2009.06.21 -
K7AntiVirus 7.10.768 2009.06.19 -
Kaspersky 7.0.0.125 2009.06.21 -
McAfee 5652 2009.06.20 -
McAfee+Artemis 5652 2009.06.20 -
McAfee+Artemis 5652 2009.06.20 -
McAfee-GW-Edition 6.7.6 2009.06.21 -
Microsoft 1.4803 2009.06.21 -
NOD32 4174 2009.06.20 -
Norman 6.01.09 2009.06.19 -
nProtect 2009.1.8.0 2009.06.21 -
Panda 10.0.0.16 2009.06.21 -
PCTools 4.4.2.0 2009.06.20 -
Prevx 3.0 2009.06.21 -
Rising 21.34.63.00 2009.06.21 -
Sophos 4.42.0 2009.06.21 -
Sunbelt 3.2.1858.2 2009.06.20 -
Symantec 1.4.4.12 2009.06.21 -
TheHacker 6.3.4.3.350 2009.06.20 -
TrendMicro 8.950.0.1094 2009.06.20 -
VBA32 3.12.10.7 2009.06.21 -
ViRobot 2009.6.19.1796 2009.06.19 -
VirusBuster 4.6.5.0 2009.06.20 -
Information additionnelle
File size: 4439572 bytes
MD5...: 9d7be41d6331861df426fcc671f370d1
SHA1..: 93cb389e64c6535bce894842a29bf43481d0434d
SHA256: dd8086ad0561e5a12ef952fb3e02a5369c9fc08cf02e3d3b8953037d803572c1
ssdeep: 98304:QE7xHqs/Ojaxr7z/cApauuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuTuuuu
uuuuuq:QEFHqsRZ7z/lpesh37hZI0eeICzroC/3
PEiD..: -
TrID..: File type identification
InstallShield setup (42.6%)
Win32 Executable MS Visual C++ (generic) (37.3%)
Win32 Executable Generic (8.4%)
Win32 Dynamic Link Library (generic) (7.5%)
Generic Win/DOS Executable (1.9%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0xf6e30
timedatestamp.....: 0x45db9090 (Wed Feb 21 00:21:36 2007)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1d580c 0x1d6000 6.65 291e372dbd9ffea03d091ed33b40c8a4
.rdata 0x1d7000 0x275d8 0x28000 6.12 9564c98bb261e6848bc77d3e71d4f221
.data 0x1ff000 0xfae90 0x35000 6.59 fed17bb4d81a4ab36703ba11e0b63270
.rsrc 0x2fa000 0x1fef8 0x20000 5.47 b3285a39b0cded1351746f1910e31088
( 13 imports )
> WININET.dll: HttpQueryInfoA
> CRYPT32.dll: CertFreeCertificateContext, CertVerifySubjectCertificateContext, CertFindCertificateInStore, CertCreateCertificateContext, CryptGetMessageCertificates, CryptVerifyMessageSignature, CertCloseStore
> VERSION.dll: GetFileVersionInfoA, GetFileVersionInfoSizeA, VerQueryValueA
> WINMM.dll: waveInOpen, waveOutOpen, waveOutClose, waveOutUnprepareHeader, waveOutReset, waveOutWrite, waveOutPrepareHeader, waveOutGetDevCapsA, timeBeginPeriod, timeGetDevCaps, waveInGetDevCapsA, waveOutGetNumDevs, waveInGetNumDevs, waveInStart, waveInAddBuffer, waveInStop, waveInClose, waveInUnprepareHeader, waveInReset, waveInPrepareHeader, timeKillEvent, timeSetEvent, timeGetTime, timeEndPeriod
OLEAUT32.dll: -
> KERNEL32.dll: GetSystemInfo, GetUserDefaultLangID, ExitThread, GlobalFree, GetFileAttributesW, WriteFile, SetFilePointer, CreateFileA, LockResource, LoadResource, FindResourceExA, FindResourceExW, GlobalAlloc, CreateThread, SetUnhandledExceptionFilter, GetTempPathA, GetCurrentProcess, GetCurrentProcessId, FindClose, FindNextFileA, FindFirstFileA, GetTimeZoneInformation, GetSystemTime, SystemTimeToFileTime, WideCharToMultiByte, CreateDirectoryA, ReadFile, GetFileSize, GetModuleFileNameA, CreateMutexA, GetFileAttributesExA, GetCurrentDirectoryA, SetCurrentDirectoryA, VirtualQuery, GetTempFileNameA, GetFullPathNameA, GetSystemDirectoryA, UnmapViewOfFile, WaitForSingleObject, ReleaseMutex, MapViewOfFile, CreateFileMappingA, lstrcpyA, lstrlenA, InterlockedDecrement, InterlockedIncrement, GlobalUnlock, GlobalLock, IsDBCSLeadByteEx, DeleteFileW, SetEndOfFile, SetFileAttributesA, CopyFileA, GetCommandLineW, GetModuleHandleA, ExitProcess, GetStartupInfoA, GetCommandLineA, GetProcessTimes, CreateEventA, SetEvent, SetThreadPriority, ResetEvent, WaitForMultipleObjects, VirtualFree, VirtualAlloc, GetThreadPriority, GetCurrentThread, GetFileAttributesA, DeleteFileA, MoveFileA, GetSystemDefaultLangID, FreeLibrary, GetLastError, GetVersionExA, CreateProcessA, CloseHandle, LCMapStringW, LCMapStringA, GetTickCount, GetCurrentThreadId, GetLocaleInfoA, SetErrorMode, QueryPerformanceCounter, QueryPerformanceFrequency, HeapAlloc, GetProcessHeap, LoadLibraryA, GetProcAddress, IsDBCSLeadByte, GetACP, GetCPInfo, MultiByteToWideChar, InterlockedExchange, InterlockedCompareExchange, Sleep, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, HeapFree, VirtualProtect, HeapReAlloc, TerminateProcess, HeapSize, GetSystemTimeAsFileTime, RtlUnwind, SetLastError, GetStdHandle, GetOEMCP, GetStringTypeA, GetStringTypeW, Remo> USER32.dll: UnregisterClassA, LoadStringW, MoveWindow, SetMenu, UpdateWindow, ShowWindow, EnumDisplaySettingsA, SetDlgItemTextA, SetDlgItemTextW, EnableWindow, GetDlgItemTextA, GetWindowTextLengthA, GetDlgItemTextW, GetWindowTextLengthW, PostQuitMessage, GetMenuStringA, GetMenuStringW, RegisterClassA, DispatchMessageA, TranslateMessage, TranslateAcceleratorA, GetMessageA, LoadAcceleratorsA, PostThreadMessageA, GetQueueStatus, PeekMessageA, MsgWaitForMultipleObjects, RegisterWindowMessageA, GetWindow, RemoveMenu, InsertMenuW, InsertMenuA, EmptyClipboard, SetClipboardData, OpenClipboard, IsClipboardFormatAvailable, GetClipboardData, CloseClipboard, RegisterClipboardFormatA, CreateWindowExA, GetWindowLongA, DefWindowProcA, IsWindow, GetMenuItemID, DeleteMenu, ClientToScreen, TrackPopupMenu, SetCapture, ReleaseCapture, GetCapture, WindowFromPoint, GetFocus, DestroyWindow, GetMenu, BeginPaint, EndPaint, LoadCursorA, SetCursor, GetCursorPos, ScreenToClient, GetClientRect, KillTimer, SetTimer, LoadMenuA, GetSubMenu, DestroyMenu, LoadStringA, EnableMenuItem, CheckMenuItem, InvalidateRect, MapVirtualKeyA, GetKeyState, FillRect, GetForegroundWindow, WaitForInputIdle, DialogBoxParamW, DialogBoxParamA, MessageBoxA, SystemParametersInfoA, DialogBoxIndirectParamW, DialogBoxIndirectParamA, PostMessageA, EndDialog, SetWindowLongA, GetParent, GetWindowRect, GetDesktopWindow, SetWindowPos, GetDlgItem, SendMessageA, SetWindowTextA, SetFocus, GetMenuItemCount, GetMenuItemInfoA, GetSystemMetrics, InsertMenuItemA, GetDC, ReleaseDC, DdeInitializeA, DdeCreateStringHandleA, DdeConnect, DdeClientTransaction, DdeDisconnect, DdeFreeStringHandle, DdeUninitialize, SendInput, GetKeyboardLayout, GetDoubleClickTime, LoadIconA
> GDI32.dll: BitBlt, SelectObject, RealizePalette, SelectPalette, GetStockObject, CreateFontIndirectA, SetBkMode, SetTextAlign, IntersectClipRect, SelectClipRgn, ExtTextOutA, ExtTextOutW, SetTextColor, GetTextMetricsA, GetTextAlign, GetBkMode, GetTextColor, EnumFontFamiliesA, SetTextCharacterExtra, GetDeviceCaps, CreateRectRgn, DPtoLP, GetTextExtentPoint32W, GetCurrentObject, SetBkColor, GetBkColor, CreatePen, GetTextExtentPoint32A, CreatePalette, EndPage, BeginPath, EndPath, GetSystemPaletteEntries, GetClipBox, CreateSolidBrush, LPtoDP, StartDocA, EndDoc, StrokePath, ExtCreatePen, FillPath, StretchDIBits, CreateDCA, GetObjectA, RestoreDC, SaveDC, SelectClipPath, CreateCompatibleBitmap, GetDIBits, CreateDIBSection, DeleteDC, CreateCompatibleDC, GdiFlush, GetClipRgn, StartPage, PolyBezierTo, LineTo, MoveToEx, SetPolyFillMode, DeleteObjectveDirectoryA
> comdlg32.dll: GetOpenFileNameA, PrintDlgA, GetOpenFileNameW, GetSaveFileNameW, CommDlgExtendedError, GetSaveFileNameA
> ADVAPI32.dll: RegSetValueExA, RegOpenKeyExA, RegQueryValueExA, RegCloseKey, RegCreateKeyExA
> SHELL32.dll: DragQueryFileA, SHGetSpecialFolderLocation, SHBrowseForFolderA, DragQueryFileW, SHGetPathFromIDListA, SHAppBarMessage, DragAcceptFiles
> ole32.dll: CoFreeUnusedLibraries, CoInitialize, CoUninitialize, CoTaskMemFree, CoCreateInstance, CoTaskMemAlloc
> WSOCK32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
( 0 exports )
PDFiD.: -
RDS...: NSRL Reference Data Set
-
-
Re,
Fait analyser Acer.exe sur https://www.virustotal.com/gui/ et poste le rapport mais c'est bien possible que soit une infection qui se camoufle derriere ce nom, c'est courant tu sais !
-
Merci DllD,
J'attends tout de meme Genproc et apres on passera toolscleaner.
-
Rapport GenProc 2.594 [1] - 21/06/2009 à 17:20:18
@ Windows Vista Service Pack 2 - Mode normal
@ Mozilla Firefox (3.0.11) [Navigateur par défaut]
Dans CCleaner, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures" ; par la suite, laisse-le avec ses réglages par défaut. C'est tout.
# Etape 1/ Télécharge :
- MSNFix http://sosvirus.changelog.fr/MSNFix.zip (!aur3n7) et décompresse-le sur le Bureau.
Redémarre en mode sans échec comme indiqué ici https://www.wekyo.com/demarrer-le-pc-en-mode-sans-echec-windows-7-et-8/ ; Choisis ta session courante *** killer *** (pour retrouver le rapport, clique sur le raccourci "Rapport GenProc[1]" sur ton bureau).
# Etape 2/
Lance le fichier MSNFix.bat qui se trouve dans le dossier MSNfix, sur le bureau.
- Exécute l'option R.
- Si l'infection est détectée, exécute l'option N.
- Sauvegarde ce rapport sur ton bureau.
# Etape 3/
Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.
# Etape 4/
Redémarre normalement et poste, dans la même réponse :
- Le contenu du rapport msnfix.txt situé dans C:\Windows ;
- Un nouveau rapport HijackThis http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/hijackthis-version-install-sujet_199100_1.htm ;
- Un nouveau rapport GenProc ;
Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
----------------------------------------------------------------------
Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
----------------------------------------------------------------------
~~ Arguments de la procédure ~~
# Détections [1] GenProc 2.594 21/06/2009 à 17:20:34
MSNFix:le 21/06/2009 à 17:20:55 "C:\Windows\System32\ACER.exe"
~~ Fin à 17:21:06 ~~
C'est pas possible, il a du se tromper
-
-
Salut vous trois.
Nathandre je ne pense pas que tu sois infectée mais plutôt qu'en ouvrant une page web une seconde c'est ouverte en même temps [par exemple avec Kaspersky online on a ce même phénomène ; une page La Redoute je crois] et cette page pointait sur un site évalué défavorablement par WOT. C'est juste commercial : une page de pub ou un lien vers un autre site.
Rien de méchant je pense.
Bon dimanche.-
Edit :
Tien d'ailleurs même si WOT donne une mauvaise évaluation, pour ce qui est de véritables codes malveillants présents sur le site il n'y a rien :
https://safeweb.norton.com/report/show?url=media.amoureux.com&x=0&y=0
http://www.siteadvisor.com/sitereport.html?url=amoureux.com
WOT c'est juste une évaluation des sites internet par des internautes. Ce n'est pas une vérité absolue, loin de là. Je préfère garder un esprit critique sur les résultats de ses évaluations {puisque d'ailleurs c'est sur cela qu'il est basé} :-)
-
-
Re,
télécharge GenProc http://www.genproc.com/GenProc.exe
double-clique sur GenProc.exe et poste le contenu du rapport qui s'ouvre ensuite tu suit la procédure dans l'ordre .
- 1
- 2