Virus ?

Résolu
Bonjour,
J'ai apparemment ouvert quelque chose qu'il ne fallait pas et depuis une fenetre de "windows antivirus pro" apparait. Je pense que c'est une pub mais très envihissante, ça me dit que j'ai des fichiers infectés, j'ai des fenetres qui s'ouvrent sans arret me disant d'acheter cet antivirus (publicité en pound je crois) et je n'arrive pas à m'en débarasser. Je ne sais pas si ça a un lien, mais depuis ce matin je n'arrive plus à ouvrir msn...
Si quelqu'un peut m'aider...
Merci d'avance pour votre aide
Configuration: Windows XP Internet Explorer 6.0

51 réponses

Résumé de la discussion

Une fenêtre d'anti-virus trompeuse s'est affichée après une action suspecte, affichant des messages d'infection et des sollicitations d'achat, et le système devient instable avec des publicités intrusives. Pour débarrasser le système, l'intervenant recommande Malwarebytes' Anti-Malware en examen rapide, qui identifie et met en quarantaine des processus, fichiers et clés de registre associées au logiciel malveillant nommé Windows AntiVirus Pro. Le rapport détaille des éléments infectés tels que svchast.exe et des fichiers dans C:\Program Files\Windows AntiVirus Pro, qui ont été quarantinés ou supprimés et des clés de registre nettoyées. D'autres conseils soulignent l'importance de vérifier les programmes de démarrage et d'envisager une analyse complémentaire, car des composants persistent parfois et nécessitent une seconde passe.

Bobot (l’IA à votre service)
  1. oui c'est clair... merci encore ! T'es vraiment calé dans le domaine, impressionnant ! a+ bon we et grand merci pour ton aide
    0
    1. Contributeur sécurité
      De rien, et prudence sur le net ! @+
      0
      1. c'est bon ça marche !
        merci encore pour ton aide et ta patience
        0
        1. Contributeur sécurité
          Lance internet explorer, puis clique sur le bouton Outils, puis sur Options Internet.
          Clique sur l’onglet Général. et tu dois pouvoir mettre " www.google.fr " dans " page de démarrage "
          0
          1. ok. oui c'est juste une question de présentation en fait...
            0
            1. Contributeur sécurité
              Pour la présentation c'est normal vu que je t'ai fais installer la dernière version d'Internet Explorer mais tu t'y habitueras !

              Pour ta page de démarrage je te dis comment remettre google dans 5min le temps que je redémarre mon PC
              0
              1. la présentation n'est plus la même et quand j'ouvre internet je ne tombe plus sur google. Enfin ça ne me gene pas plus que ça
                0
                1. Contributeur sécurité
                  Ok, quel est ce changement de page internet ?
                  0
                  1. je dirai bien... j'ai l'impression qu'il est plus rapide. Il y a juste ma page internet qui a changé, mais bon ça c'est pas un problème
                    0
                    1. Contributeur sécurité
                      Ok, sinon comment se porte ton PC ?
                      0
                      1. ok super ! Merci beaucoup pour ton aide c'est super gentil !
                        Non je connais pas ce logiciel...
                        Merci encore
                        0
                        1. Contributeur sécurité
                          Est ce que tu connais ce programme : Ulead AutoDetector v2 ?

                          Sinon ton log m'a l'air propre, tout est à jour c'est parfait.
                          0
                          1. Ca y est je les ai "exécuter"
                            Voilà le nouveau rapport :

                            Logfile of random's system information tool 1.06 (written by random/random)
                            Run by Lina at 2009-08-29 14:42:24
                            Microsoft Windows XP Édition familiale Service Pack 2
                            System drive C: has 6 GB (17%) free of 37 GB
                            Total RAM: 1014 MB (66% free)

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 14:42:32, on 29/08/2009
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\wscntfy.exe
                            C:\WINDOWS\system32\rundll32.exe
                            C:\WINDOWS\system32\igfxtray.exe
                            C:\WINDOWS\system32\hkcmd.exe
                            C:\Program Files\MSN Messenger\msnmsgr.exe
                            C:\Documents and Settings\Lina\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\WINDOWS\system32\msiexec.exe
                            C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                            C:\Program Files\Avira\AntiVir Desktop\sched.exe
                            C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                            c:\program files\avira\antivir desktop\avcenter.exe
                            C:\Documents and Settings\Lina\Bureau\ccm.exe
                            C:\Program Files\trend micro\Lina.exe

                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                            O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                            O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\Lina\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                            O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                            O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                            O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                            O23 - Service: Securitoo Antivirus Firewall (BackWeb Plug-in - 8520111) - Unknown owner - C:\PROGRA~1\SECURI~1\av_fw\backweb\8520111\Program\SERVIC~1.EXE (file missing)
                            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                            0
                            1. Contributeur sécurité
                              il faut que tu les installes ! ( donc éxecute )
                              0
                              1. si pourtant ! enfin je les ai enregistrés mais pas exécuter, je regarde ça !
                                0
                                1. Contributeur sécurité
                                  tu n'as pas mis à jour windows et tu n'as pas installé antivir ? ils sont pas présents dans le rapport
                                  0
                                  1. Voici le rapport :

                                    Logfile of random's system information tool 1.06 (written by random/random)
                                    Run by Lina at 2009-08-29 14:09:01
                                    Microsoft Windows XP Édition familiale Service Pack 2
                                    System drive C: has 7 GB (19%) free of 37 GB
                                    Total RAM: 1014 MB (59% free)

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 14:09:07, on 29/08/2009
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\WINDOWS\system32\rundll32.exe
                                    C:\WINDOWS\system32\igfxtray.exe
                                    C:\WINDOWS\system32\hkcmd.exe
                                    C:\Program Files\MSN Messenger\msnmsgr.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\wscntfy.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Documents and Settings\Lina\Bureau\ccm.exe
                                    C:\Program Files\trend micro\Lina.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.acer.com/worldwide/selection.html
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                                    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                                    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                    O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                                    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                                    O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O23 - Service: Securitoo Antivirus Firewall (BackWeb Plug-in - 8520111) - Unknown owner - C:\PROGRA~1\SECURI~1\av_fw\backweb\8520111\Program\SERVIC~1.EXE (file missing)
                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                    0
                                    1. Contributeur sécurité
                                      ok une fois que tu auras fait tout ça, reposte un rapport d'hijackthis et je crois que ce sera bon :)
                                      0
                                      1. oui c'est celui là que j'ai voulu ouvrir... du coup j'ai relancé cleaner
                                        0
                                        1. Contributeur sécurité
                                          quel fichier ? si tu parles du backup il ne faut surtout pas l'ouvrir, ca fait comme si tu n'avais pas lancé le nettoyage puisque ca réinscrit dans le registre ce que tu as supprimé. C'est " au cas ou " tu avais un problème après le nettoyage ( ce qui est très très rare avec CCleaner )
                                          0
                                          • 1
                                          • 2
                                          • 3