Virus ?
RésoluJ'ai apparemment ouvert quelque chose qu'il ne fallait pas et depuis une fenetre de "windows antivirus pro" apparait. Je pense que c'est une pub mais très envihissante, ça me dit que j'ai des fichiers infectés, j'ai des fenetres qui s'ouvrent sans arret me disant d'acheter cet antivirus (publicité en pound je crois) et je n'arrive pas à m'en débarasser. Je ne sais pas si ça a un lien, mais depuis ce matin je n'arrive plus à ouvrir msn...
Si quelqu'un peut m'aider...
Merci d'avance pour votre aide
Configuration: Windows XP Internet Explorer 6.0
51 réponses
Une fenêtre d'anti-virus trompeuse s'est affichée après une action suspecte, affichant des messages d'infection et des sollicitations d'achat, et le système devient instable avec des publicités intrusives. Pour débarrasser le système, l'intervenant recommande Malwarebytes' Anti-Malware en examen rapide, qui identifie et met en quarantaine des processus, fichiers et clés de registre associées au logiciel malveillant nommé Windows AntiVirus Pro. Le rapport détaille des éléments infectés tels que svchast.exe et des fichiers dans C:\Program Files\Windows AntiVirus Pro, qui ont été quarantinés ou supprimés et des clés de registre nettoyées. D'autres conseils soulignent l'importance de vérifier les programmes de démarrage et d'envisager une analyse complémentaire, car des composants persistent parfois et nécessitent une seconde passe.
-
oui c'est clair... merci encore ! T'es vraiment calé dans le domaine, impressionnant ! a+ bon we et grand merci pour ton aide
-
Contributeur sécuritéDe rien, et prudence sur le net ! @+
-
c'est bon ça marche !
merci encore pour ton aide et ta patience -
Contributeur sécuritéLance internet explorer, puis clique sur le bouton Outils, puis sur Options Internet.
Clique sur l’onglet Général. et tu dois pouvoir mettre " www.google.fr " dans " page de démarrage " -
ok. oui c'est juste une question de présentation en fait...
-
Contributeur sécuritéPour la présentation c'est normal vu que je t'ai fais installer la dernière version d'Internet Explorer mais tu t'y habitueras !
Pour ta page de démarrage je te dis comment remettre google dans 5min le temps que je redémarre mon PC -
la présentation n'est plus la même et quand j'ouvre internet je ne tombe plus sur google. Enfin ça ne me gene pas plus que ça
-
Contributeur sécuritéOk, quel est ce changement de page internet ?
-
je dirai bien... j'ai l'impression qu'il est plus rapide. Il y a juste ma page internet qui a changé, mais bon ça c'est pas un problème
-
Contributeur sécuritéOk, sinon comment se porte ton PC ?
-
ok super ! Merci beaucoup pour ton aide c'est super gentil !
Non je connais pas ce logiciel...
Merci encore -
Contributeur sécuritéEst ce que tu connais ce programme : Ulead AutoDetector v2 ?
Sinon ton log m'a l'air propre, tout est à jour c'est parfait. -
Ca y est je les ai "exécuter"
Voilà le nouveau rapport :
Logfile of random's system information tool 1.06 (written by random/random)
Run by Lina at 2009-08-29 14:42:24
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 6 GB (17%) free of 37 GB
Total RAM: 1014 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:42:32, on 29/08/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\Lina\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
c:\program files\avira\antivir desktop\avcenter.exe
C:\Documents and Settings\Lina\Bureau\ccm.exe
C:\Program Files\trend micro\Lina.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\Lina\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Securitoo Antivirus Firewall (BackWeb Plug-in - 8520111) - Unknown owner - C:\PROGRA~1\SECURI~1\av_fw\backweb\8520111\Program\SERVIC~1.EXE (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
-
Contributeur sécuritéil faut que tu les installes ! ( donc éxecute )
-
si pourtant ! enfin je les ai enregistrés mais pas exécuter, je regarde ça !
-
Contributeur sécuritétu n'as pas mis à jour windows et tu n'as pas installé antivir ? ils sont pas présents dans le rapport
-
Voici le rapport :
Logfile of random's system information tool 1.06 (written by random/random)
Run by Lina at 2009-08-29 14:09:01
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 7 GB (19%) free of 37 GB
Total RAM: 1014 MB (59% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:09:07, on 29/08/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Lina\Bureau\ccm.exe
C:\Program Files\trend micro\Lina.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.acer.com/worldwide/selection.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Securitoo Antivirus Firewall (BackWeb Plug-in - 8520111) - Unknown owner - C:\PROGRA~1\SECURI~1\av_fw\backweb\8520111\Program\SERVIC~1.EXE (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
-
Contributeur sécuritéok une fois que tu auras fait tout ça, reposte un rapport d'hijackthis et je crois que ce sera bon :)
-
oui c'est celui là que j'ai voulu ouvrir... du coup j'ai relancé cleaner
-
Contributeur sécuritéquel fichier ? si tu parles du backup il ne faut surtout pas l'ouvrir, ca fait comme si tu n'avais pas lancé le nettoyage puisque ca réinscrit dans le registre ce que tu as supprimé. C'est " au cas ou " tu avais un problème après le nettoyage ( ce qui est très très rare avec CCleaner )
- 1
- 2
- 3