Pub intenpestif

Résolu
Bonjour
depuis un bon bou de temps j'ai des pub qui s'affiche quand je navigue sur le net
les pub sont du genre telecharger de la musique ou sa me di que mon pc est infecter de spyware et il fo ke g clique sur la pub pour telecharger un antispyware

je possede kaspersky mais il ne détecte rien
j'ai aussi analyser mon pc avec spybot, ad-aware, a-squared
mais tous ses logiciels ne detecte rien d'anormal

pouver me dire commen faire s'il vous plai

ps: j'ai un pc sous vista

merci
Configuration: Windows Vista
Internet Explorer 7.0

14 réponses

  1. sa a ler davoir marcher
    merci bocou bone continuation
    0
    1. il a detecter et effacer un virus mai g c pa si c le bon gv surfer et gt redi sa
      merci bocou
      0
      1. Contributeur sécurité
        regarde la essaye black light

        popups ouverture de fenetres internet publicitaires pop up
        0
        1. Contributeur sécurité
          essaye le scan en ligne liveone care

          http://onecare.live.com/site/fr-fr/default.htm
          0
          1. impossible d'analyser en ligne avec kaspersky bitdefender et panda
            car il ne son pa encor compatible vista
            commen faire g toujour de page pub ki saffiche
            0
            1. pa pu faire l'option 2 en mode san echec car quand je lance smitfraudfix il me demande pa doption mm si g tap 2 et ke g fai entrer rien ne se pass
              g v faire une analyse antivirus en ligne
              0
              1. mitFraudFix v2.195

                Scan done at 22:22:49,61, 12/06/2007
                Run from C:\Users\Lucien\SmitfraudFix
                OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                The filesystem type is NTFS
                Fix run in normal mode

                »»»»»»»»»»»»»»»»»»»»»»»» Process

                C:\Windows\system32\csrss.exe
                C:\Windows\system32\wininit.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\services.exe
                C:\Windows\system32\lsass.exe
                C:\Windows\system32\lsm.exe
                C:\Windows\system32\winlogon.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\SLsvc.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\spoolsv.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\system32\taskeng.exe
                C:\Windows\Explorer.EXE
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Program Files\DAEMON Tools\daemon.exe
                C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
                C:\Program Files\Common Files\logishrd\LComMgr\Communications_Helper.exe
                C:\Program Files\Common Files\logishrd\LComMgr\LVComSX.exe
                C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
                C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
                C:\Windows\System32\akxgyxjx.exe
                C:\Windows\System32\rundll32.exe
                C:\Windows\ehome\ehtray.exe
                C:\Windows\System32\rundll32.exe
                C:\Windows\ehome\ehmsas.exe
                C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
                C:\Program Files\a-squared Free\a2service.exe
                C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
                C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                C:\Windows\system32\PnkBstrA.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\SearchIndexer.exe
                C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                C:\Windows\system32\WUDFHost.exe
                C:\Windows\ehome\ehsched.exe
                C:\Windows\system32\taskeng.exe
                C:\Windows\system32\wbem\wmiprvse.exe
                C:\Windows\ehome\ehRecvr.exe
                C:\Windows\system32\wbem\unsecapp.exe
                C:\Windows\system32\SearchProtocolHost.exe
                C:\Program Files\Internet Explorer\ieuser.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                C:\Windows\servicing\TrustedInstaller.exe
                C:\Windows\system32\SearchFilterHost.exe
                C:\Windows\system32\Macromed\Flash\FlashUtil9c.exe
                C:\Windows\system32\cmd.exe
                C:\Windows\system32\conime.exe
                C:\Windows\system32\wbem\wmiprvse.exe

                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                »»»»»»»»»»»»»»»»»»»»»»»» C:\

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                C:\Windows\system32\sysmain.dll FOUND !

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Lucien

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Lucien\Application Data

                »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Lucien\FAVORI~1

                »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                !!!Attention, following keys are not inevitably infected!!!

                SrchSTS.exe by S!Ri
                Search SharedTaskScheduler's .dll

                »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                !!!Attention, following keys are not inevitably infected!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                "AppInit_DLLs"="C:\\PROGRA~1\\KASPER~1\\KASPER~1.0\\r3hook.dll"
                "LoadAppInit_DLLs"=dword:00000001

                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                !!!Attention, following keys are not inevitably infected!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                Description: 802.11 USB Wireless LAN Adapter #2
                DNS Server Search Order: 192.168.1.1

                HKLM\SYSTEM\CCS\Services\Tcpip\..\{4E9EB204-615D-45C2-B062-EBCD4945CCFF}: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CCS\Services\Tcpip\..\{E6133079-667E-41D5-8F25-44F874AB4FC0}: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CS1\Services\Tcpip\..\{4E9EB204-615D-45C2-B062-EBCD4945CCFF}: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CS1\Services\Tcpip\..\{E6133079-667E-41D5-8F25-44F874AB4FC0}: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                »»»»»»»»»»»»»»»»»»»»»»»» End
                0
                1. Contributeur sécurité
                  fait la suite et smitfraud fix

                  smit fraud fix

                  http://telechargement.zebulon.fr/smitfraudfix.html

                  2/ double clique sur smitfraudfix. puis selectionne 1 et appuyer sur entrée afin de créer le rapport des infection présentes. une fois le rapport effectué redemarre en mode sans echec (en appuyant sur F8 ou suppr, ou F5 au demarrage en général)

                  3/ puis refaire comme en 2/ mais selectionne l'option 2 et appuyer sur entrée pour commencer la desinfection. lorsque le programme demande si tu veut nettoyer le registre metsoui en tapant 0 et entrée

                  puis avg antispyware

                  https://www.01net.com/telecharger/
                  0
                  1. rogue remover et cwshredder ne detecte rien

                    bhodemon 2vert pa de rouge
                    et 3 unknow navilog me met ne fonctionne que sous xp dc sane march pa car g vista
                    0
                    1. Logfile of HijackThis v1.99.1
                      Scan saved at 20:52:19, on 12/06/2007
                      Platform: Unknown Windows (WinNT 6.00.1904)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16386)

                      Running processes:
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\Explorer.EXE
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
                      C:\Program Files\Common Files\logishrd\LComMgr\Communications_Helper.exe
                      C:\Program Files\Common Files\logishrd\LComMgr\LVComSX.exe
                      C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
                      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
                      C:\Windows\System32\akxgyxjx.exe
                      C:\Windows\System32\rundll32.exe
                      C:\Windows\System32\rundll32.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Windows\ehome\ehmsas.exe
                      C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
                      C:\Windows\system32\wbem\unsecapp.exe
                      C:\Program Files\Windows Media Player\wmplayer.exe
                      C:\Program Files\Internet Explorer\IEUser.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Program Files\CCleaner\ccleaner.exe
                      C:\Windows\system32\Macromed\Flash\FlashUtil9c.exe
                      C:\Windows\system32\SearchFilterHost.exe
                      C:\PROGRA~1\IZArc\IZArc.exe
                      C:\Users\Lucien\AppData\Local\Temp\ARC373D\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.medion.com/
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                      O1 - Hosts: ::1 localhost
                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                      O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
                      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
                      O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe"
                      O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
                      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
                      O4 - HKLM\..\Run: [akxgyxjx] c:\windows\system32\akxgyxjx.exe akxgyxjx
                      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
                      O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                      O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                      O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
                      O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
                      O11 - Options group: [INTERNATIONAL] International*
                      O13 - Gopher Prefix:
                      O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
                      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                      O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll
                      O20 - Winlogon Notify: klogon - C:\Windows\system32\klogon.dll
                      O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
                      O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
                      O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
                      O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
                      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero 7\Nero BackItUp\NBService.exe
                      O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                      O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                      O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
                      O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
                      O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                      0
                      1. Contributeur sécurité
                        colle un rapport hijackthis

                        https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/29061.html

                        -----------------------------------
                        scan avec rogue remover::

                        http://www.libellules.ch/dotclear/index.php?2006/11/29/1518-rogue-remover

                        -------------------------------------
                        puis cwshredder

                        https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/27497.html

                        ------------------------
                        installe et lance BHO DEMON

                        https://www.01net.com/telecharger/windows/Utilitaire/cryptage_et_securite/fiches/32724.html

                        dans la fenetre qui s'affiche, il y a indiqueé tous les barres d'outils et autres logiciles gréfés sur ton ordi. les lignes vertes sont jugées saines, les rouges et jaunes sont estimées comme dangereuses: dans ce cas il faut les desactiver en decochant la case situé a gauche de chaque ligne.

                        si la ligne n'est pas colorée et comporte la mention unknown, double clique dessus , des explication apparaitrons, si il y a un doute desactiv ces ligne aussi.

                        -----------------------

                        http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                        Télécharger sur le bureau
                        Navilog.zip
                        = Double-Clic navilog1.zip
                        = Extraire tout sur le bureau
                        = Double-Clic navilog1 qui est sur le bureau
                        = Appuyer sur une touche jusqu' arriver aux options
                        = Choisir option 1

                        un rapport : fixnavi.txt dans C : va se creer
                        le copier/coller dans ton prochain message.

                        = Redémarrer en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
                        Attention, pas d’accès à internet dans ce mode. Enregistrer ou imprimer les consignes. Relancer le Pc et tapoter la touche F8, jusqu’à l’apparition des inscriptions avec choix de démarrage
                        Avec les touches « flèches », sélectionner Mode sans échec ==> entrée ==>nom utilisateur habituel
                        = Lance navilog1
                        = Cette fois-ci choisi l'option 2
                        = Navilog va faire le nettoyage.. patient jusqu'à ce qui soit marqué *** Nettoyage Termine le ..... ***
                        = Un rapport va être génrer sur ton C:\ qui sera en option 2
                        Note: le bureau disparaît

                        = Redémarre en mode normal et colle le contenu du rapport de navilog (qui est en option 2)

                        utilise aussi pour supprimer tes traces

                        -----------------------------------------
                        CCLEANER: (lance un netoyage et repare les clés) sans installer la barre yahoo
                        https://www.01net.com/

                        ensuite:

                        scan avec des antiespions(en mode sans echec):

                        spybot :

                        https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/26157.html

                        si tout c'est bien passer redemarre en mode normal et desactive la restauration syteme pour purger les virus qui seraient dedans puis reactive là (dans DEMARRER puis TOUS LES PROGRAMMES puis ACCESSOIRE puis OUTILS SYSTEME puis RESTAURATION SYSTEME puis parametre)

                        D/puis fait un scan en ligne avec un des suivants: et colle le rapport)

                        Panda en ligne :
                        http://pandasoftware.fr

                        kaspersky en ligne :
                        https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr

                        bitdefender en ligne :
                        http://www.bitdefender.fr/scan_fr/scan8/ie.html
                        0