Antivigear

J ai lu les posts qui m interresait mais j ai toujours un petit pb.
ai ete infecté par securiy toolbar 7.1 mais également par antivigear.
Et c est ce drenier qui mepose pb.
Je n arrive pas a me debarrasser de l icone présent en bas a droite de l ecran
peut on ma ider svp
merci d avance
cyril
Configuration: Windows XP
Internet Explorer 6.0

7 réponses

  1. Contributeur sécurité
    oui fais un scan en ligne meme si tous semble bon

    _____________
    ton windows n'est pas a jours tu n'as pas le sp2? si legal...

    fais demarrer puis WINDOWSUPDATE

    ___________

    norton si c'est juste l'antivirus installe un parefeu:

    un pare feu :
    celui de Windows ou mieux KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)

    https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
    https://manuelsdaide.com/contact/
    http://www.open-files.com/forum/index.php?showtopic=29277
    zonealarm

    _____________

    en plus de l'antivirus norton installe spybot et ad aware pour scanner de temps en temps et supprimer les espions

    https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/26157.html

    https://www.01net.com/404/

    garde CCLEANER pour supprimer de temps en temps tes traces

    a plus
    0
    1. Ah j ai oublié j ai aussi utilisé rogue free mais je ne sais pas trop m en servir, j ai juste fais un scan
      merci
      cyril
      0
      1. Tout d abord un grand merci de me repondre.
        Voila ce qu j ai fait

        1) J ai nettoyé en mode sans echec avec clean et le rapport m indiquait aucune erreur.
        2) J ai nettoyé en mode sans echec avec smitfaudfrix v2 229 (j avais la version 2.127 et cela n avait pas fonctionné) et le rapport je vais le mesttre en dessous.
        3) toujours en mode sans echec j ai netoyé avec antispyware 7.5 et j'ai supprimer tous les éléments nefastes (j ai pour cela suivi ta procédure qu tu indiquait pour "la fausse blonde")
        4) j ai fixé les ligne que tu m as dit de faire dans le rapport hijackthis. je te mest le nouveau.

        A priori tout va bien maintenat faut il lancer un scan avec panda ?

        merci encore
        cyril

        SmitFraudFix v2.229

        Rapport fait à 14:28:54,95, 25/09/2007
        Executé à partir de C:\pour nettoyer\antivirgear\smitfraudfix
        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
        Le type du système de fichiers est NTFS
        Fix executé en mode sans echec

        »»»»»»»»»»»»»»»»»»»»»»»» Process

        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\System32\cmd.exe

        »»»»»»»»»»»»»»»»»»»»»»»» hosts

        »»»»»»»»»»»»»»»»»»»»»»»» C:\

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Famille.LANTZ

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Famille.LANTZ\Application Data

        »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

        »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\FAMILL~1.LAN\Favoris

        »»»»»»»»»»»»»»»»»»»»»»»» Bureau

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

        »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

        »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

        »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
        "{b02c6db1-a1ea-470f-8100-b1391463ba92}"="draughtsmanship"

        [HKEY_CLASSES_ROOT\CLSID\{b02c6db1-a1ea-470f-8100-b1391463ba92}\InProcServer32]
        @="C:\WINDOWS\System32\rnxwph.dll"

        [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{b02c6db1-a1ea-470f-8100-b1391463ba92}\InProcServer32]
        @="C:\WINDOWS\System32\rnxwph.dll"

        »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
        "AppInit_DLLs"=""
        "LoadAppInit_DLLs"=dword:00000001

        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
        "System"=""

        »»»»»»»»»»»»»»»»»»»»»»»» Rustock

        »»»»»»»»»»»»»»»»»»»»»»»» DNS

        HKLM\SYSTEM\CCS\Services\Tcpip\..\{4C130567-514C-4065-A77F-71997844CF4E}: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CS1\Services\Tcpip\..\{4C130567-514C-4065-A77F-71997844CF4E}: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CS2\Services\Tcpip\..\{4C130567-514C-4065-A77F-71997844CF4E}: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

        »»»»»»»»»»»»»»»»»»»»»»»» Fin

        Logfile of HijackThis v1.99.1
        Scan saved at 14:56:46, on 25/09/2007
        Platform: Windows XP (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\PROGRA~1\NavNT\vptray.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        C:\Program Files\NavNT\defwatch.exe
        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        C:\WINDOWS\system32\cba\pds.exe
        C:\Program Files\NavNT\rtvscan.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\cba\xfr.exe
        C:\WINDOWS\system32\MsgSys.EXE
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\WINDOWS\system32\NOTEPAD.EXE
        C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
        O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
        O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
        O9 - Extra button: Alice ADSL - {21675D51-DA13-4F2B-BBF4-F3D6546232EE} - https://portail.free.fr/ (file missing) (HKCU)
        O14 - IERESET.INF: START_PAGE_URL=https://portail.free.fr/
        O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game12.zylom.com/activex/zylomgamesplayer.cab
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
        O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINDOWS\system32\cba\xfr.exe
        O23 - Service: Intel PDS - Intel® Corporation - C:\WINDOWS\system32\cba\pds.exe
        O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
        0
        1. Contributeur sécurité
          O2 - BHO: (no name) - Software - (no file)
          O2 - BHO: (no name) - {1C3C4699-B285-475F-BE47-0B26088CE876} - C:\Program Files\Security Tools\iesplg.dll (file missing)
          O2 - BHO: (no name) - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file)
          O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
          O3 - Toolbar: Protection Bar - {F06E2ABE-3A50-4079-BE25-FC100D9EAA25} - C:\Program Files\Security Tools\iesbpl.dll (file missing)
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: (no name) - Software - (no file)

          FIX CES LIGNES avec hijackthis

          _______________

          colle le rapport d'un scan en ligne
          avec un des suivants:

          bitdefender en ligne :
          http://www.bitdefender.fr/scan_fr/scan8/ie.html

          scan en ligne firefox

          https://www.trendmicro.com/fr_fr/business.html

          Panda en ligne :
          http://pandasoftware.fr

          _______________

          recolle hijackthis et dis tes pbs
          0
          1. Contributeur sécurité
            slt,

            utilise
            smit fraud fix (colle le rapport)

            1/ telecharger :
            http://telechargement.zebulon.fr/smitfraudfix.html

            2/ double clique sur smitfraudfix. puis sélectionne 1 et appuyer sur entrée afin de créer le rapport des infection présentes. une fois le rapport effectué redémarre en mode sans échec (en appuyant sur F8 ou suppr, ou F5 au démarrage en général)

            3/ puis refaire comme en 2/ mais sélectionne l'option 2 et appuyer sur entrée pour commencer la désinfection. lorsque le programme demande si tu veut nettoyer le registre mets oui en tapant 0 et entrée
            0
            1. pour etreplus clair voici les symptomes
              j'ai un nouvel icone dans le coin droit de mon écran soir un bouclier rouge comportant un X qui clignote en alternance avec un bouclier bleu avec a son center un ?, quand je clique dessus, il m'ammène automatiquement a la page de Antivigear
              merci d avance
              cyril
              0
              1. J ai oublié au cas ou de mette mon rapprt hjackthis
                le voici
                Logfile of HijackThis v1.99.1
                Scan saved at 10:40:21, on 25/09/2007
                Platform: Windows XP (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\Explorer.EXE
                C:\PROGRA~1\NavNT\vptray.exe
                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                C:\Program Files\NavNT\defwatch.exe
                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                C:\WINDOWS\system32\cba\pds.exe
                C:\Program Files\NavNT\rtvscan.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\cba\xfr.exe
                C:\WINDOWS\system32\MsgSys.EXE
                C:\WINDOWS\System32\wuauclt.exe
                C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aliceadsl.fr
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: (no name) - Software - (no file)
                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: (no name) - {1C3C4699-B285-475F-BE47-0B26088CE876} - C:\Program Files\Security Tools\iesplg.dll (file missing)
                O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
                O2 - BHO: (no name) - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file)
                O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
                O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                O3 - Toolbar: Protection Bar - {F06E2ABE-3A50-4079-BE25-FC100D9EAA25} - C:\Program Files\Security Tools\iesbpl.dll (file missing)
                O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                O9 - Extra button: (no name) - Software - (no file)
                O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
                O9 - Extra button: Alice ADSL - {21675D51-DA13-4F2B-BBF4-F3D6546232EE} - https://portail.free.fr/ (file missing) (HKCU)
                O14 - IERESET.INF: START_PAGE_URL=http://www.aliceadsl.fr
                O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game12.zylom.com/activex/zylomgamesplayer.cab
                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
                O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINDOWS\system32\cba\xfr.exe
                O23 - Service: Intel PDS - Intel® Corporation - C:\WINDOWS\system32\cba\pds.exe
                O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
                0