Security-X

Forum Security-X => Désinfections => Discussion démarrée par: jeanda le octobre 25, 2014, 23:56:32

Titre: omiga-plus [Résolu]
Posté par: jeanda le octobre 25, 2014, 23:56:32
Bonjour, :AAC

Ehhhh!!!! bien je me pensais à l'abri de tous virus, ben là je me suis fait avoir, en téléchargeant un lecteur flash player , j'ai rien compris un tas de logiciels se sont installés tout seul j'ai tout désinstallé en passant par le panneau mais reste "uninstal omiga-plus" je suis sec devant je n'ose pas passer par le registre. Merci d'avance de votre aide :AAN
Titre: Re : omiga-plus
Posté par: nicoolas le octobre 26, 2014, 01:39:05
Bonjour,

Nous allons dans un premier temps établir un diagnostic de ton pc. Je te demande donc de ne pas demander de l'aide sur un autre forum car ceci pourrait s'avérer dangereux pour ton pc.

(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)FRST :

Sous IE9, IE10 ou IE11, le filtre SmartScreen déclenche une alerte. Cliquer sur Actions puis sur Exécuter quand même

---------------------------------------------------------------------------------------------

Sont attendus les rapports FRST.txt et Addition.txt

A+
Titre: Re : omiga-plus
Posté par: jeanda le octobre 26, 2014, 07:55:08
Bonjour,  :AAC

Merci nicoolas de ton aide t'inquiètes je ne vais pas aller sur d'autres furum je sais bien que vous êtes très compétents.
Ci-joint les liens:
http://up.security-x.fr/file.php?h=Rb4d52ca43e0ab573e9943720af846ae2
http://up.security-x.fr/file.php?h=Rdb983709d12698b70be77c24e6bb16c4

 :AAN
Titre: Re : omiga-plus
Posté par: nicoolas le octobre 26, 2014, 11:36:34
Bonjour,

Nous allons débuter la désinfection.


Désinstallation des programmes :

Supprime les programmes listés ci-dessous via Panneau de configuration -> Désinstaller un programme (si tu ne trouves pas un programme, passe au suivant !) :

Final Media Player 2012
omiga-plus uninstall






(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)FRST - Correctif :

/!\ Crée un point de restauration manuel avant d'appliquer le correctif - Tutoriel en images (http://forum.security-x.fr/windows-7/%28tutoriel%29-creer-un-point-de-restauration-sous-windows-7/) /!\

start
CloseProcesses:
HKLM-x32\...\Run: [ConvertAd] => C:\Users\Jeanda\AppData\Local\ConvertAd\ConvertAd.exe
HKLM-x32\...\Run: [mbot_fr_193] => [X]
HKLM-x32\...\Run: [mbot_fr_194] => [X]
HKU\S-1-5-21-3961015808-2698317561-3448096706-1000\...\Run: [Price-Horse] => C:\Users\Jeanda\AppData\Local\pricehorse\pricehorse\1.3.13.12\pricehorse.exe
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hp&ts=1414270710&from=tugs&uid=HitachiXHTS547575A9E384_J2140054ETW2JAETW2JAX
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hp&ts=1414270710&from=tugs&uid=HitachiXHTS547575A9E384_J2140054ETW2JAETW2JAX
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc&ts=1414270710&from=tugs&uid=HitachiXHTS547575A9E384_J2140054ETW2JAETW2JAX
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dsites&cd=2XzuyEtN2Y1L1Qzu0FtD0B0FzyyBtDtBtDyBtA0FtByBtAtBtN0D0Tzu0SyBzyyBtN1L2XzutBtFtCyBtFtDtFtBtN1L1CzutDtBtCtC1V1RtN1L1G1B1V1N2Y1L1Qzu2StC0EyEtCtAyByE0CtG0ByEyCtBtGyB0C0C0EtG0EyCzyzztGtCyDyCtC0B0FyE0AyEyB0CyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByDtD0A0AzzyDyDtGyByDyCtBtGyB0CzytAtGzyzz0FtCtGtAyCtD0FtDyCyEtAtA0FyE0C2Q&cr=1812935370&ir=
SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1414270710&from=tugs&uid=HitachiXHTS547575A9E384_J2140054ETW2JAETW2JAX&q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dsites&cd=2XzuyEtN2Y1L1Qzu0FtD0B0FzyyBtDtBtDyBtA0FtByBtAtBtN0D0Tzu0SyBzyyBtN1L2XzutBtFtCyBtFtDtFtBtN1L1CzutDtBtCtC1V1RtN1L1G1B1V1N2Y1L1Qzu2StC0EyEtCtAyByE0CtG0ByEyCtBtGyB0C0C0EtG0EyCzyzztGtCyDyCtC0B0FyE0AyEyB0CyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyByDtD0A0AzzyDyDtGyByDyCtBtGyB0CzytAtGzyzz0FtCtGtAyCtD0FtDyCyEtAtA0FyE0C2Q&cr=1812935370&ir=
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type=ds&ts=1414270710&from=tugs&uid=HitachiXHTS547575A9E384_J2140054ETW2JAETW2JAX&q={searchTerms}
BHO-x32: No Name -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> No File
2014-10-25 22:21 - 2014-10-25 22:24 - 00000000 ____D () C:\Program Files (x86)\Accelerer PC
2014-10-25 22:21 - 2014-10-25 22:21 - 00000000 ____D () C:\Program Files (x86)\predm
2014-10-25 22:16 - 2014-10-25 22:16 - 00612324 _____ (CMI Limited) C:\Users\Jeanda\AppData\Local\nsbAB5D.tmp
2014-10-25 22:15 - 2014-10-25 22:15 - 00000000 ____D () C:\ProgramData\374311380
2014-10-25 22:10 - 2014-10-25 22:10 - 00612324 _____ (CMI Limited) C:\Users\Jeanda\AppData\Local\nsbF04B.tmp
2014-10-25 22:04 - 2014-10-25 22:04 - 00000000 ____D () C:\Users\Jeanda\Documents\Optimizer Pro
2014-10-25 21:59 - 2014-10-25 22:20 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-10-25 21:59 - 2014-10-25 21:59 - 00000000 __SHD () C:\Users\Jeanda\AppData\Roaming\AnyProtectEx
2014-10-25 21:58 - 2014-10-25 22:29 - 00000000 ____D () C:\Users\Jeanda\AppData\Roaming\omiga-plus
2014-10-25 21:56 - 2014-10-25 21:56 - 00000000 ____D () C:\Users\Jeanda\AppData\Local\pricehorse
C:\Program Files (x86)\AnyProtectEx
:\Users\Jeanda\AppData\Roaming\DIGITA~1
C:\Program Files (x86)\MyPC Backup
Task: {9EBB90C4-28DC-445C-908A-247FAC8CE4D3} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {3BBCB23F-8898-45D9-8CA3-479D756218D6} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {3BE3B670-0285-45C8-A4D0-42B7BA946FC7} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {EF586851-7620-4618-8636-5E3A4C085BD8} - System32\Tasks\Digital Sites => C:\Users\Jeanda\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {F776405B-ACAF-441A-9364-E52DEAFB2917} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\Digital Sites.job => C:\Users\Jeanda\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
AlternateDataStreams: C:\ProgramData\Temp:AD022376
EmptyTemp:
end
/!\ Ce script a été établi pour cet utilisateur, il ne doit, en aucun cas, être appliqué sur un autre système, au risque de provoquer de graves dysfonctionnement et endommager Windows /!\



(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)ADWCleaner:

Titre: Re : omiga-plus
Posté par: jeanda le octobre 26, 2014, 16:39:47
 :) Re :AAC

Final Media Player 2012 s'est bien désinstallé mais pas omiga-plus uninstall toujours pareil.....
Je pense qu'il ne faut cliquer sur nettoyer?

Voici les 2 rapports:
http://up.security-x.fr/file.php?h=Rbc282d3c312d8177c1c0f8716a8c3922
http://up.security-x.fr/file.php?h=R3997dfa61644b23d5a7e6b98e9e9806f

Merci encore de prendre du temps pour s'occuper de mon problème. :AAN

Titre: Re : omiga-plus
Posté par: nicoolas le octobre 26, 2014, 17:01:36
Re,

(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)ADWCleaner:

Titre: Re : omiga-plus
Posté par: jeanda le octobre 26, 2014, 17:23:22
 :) :)

Merci omiga-plus à disparu du panneau.
Ci-joint le rapport:
http://up.security-x.fr/file.php?h=R69ddfb480cac36fbd852c07e0a8fae1b
 :AAN
Titre: Re : omiga-plus
Posté par: nicoolas le octobre 26, 2014, 17:33:46
re,

comment se porte le pc ?
Titre: Re : omiga-plus
Posté par: jeanda le octobre 26, 2014, 17:39:07
 :)

Ben le pc se porte très bien omiga à disparu, mais m^me avant ça il ne semblait pas aller plus mal, c'est lorsque j'ai vu tous ces logiciels s'installer tout seul j'ai eu très peur....Encore un grand merci à toi...c'est cool nicoolas :D
Titre: Re : omiga-plus
Posté par: nicoolas le octobre 26, 2014, 18:28:39
Re,

bien on va finaliser alors !


- Supprimer les outils de désinfection
 - Purger la restauration système



Mise à jour du système et des logiciels :

Télécharge SX Check&Update (http://tools.security-x.fr/download.php?f=SXCU.exe) (de Igor51 ) sur ton bureau.

Titre: Re : omiga-plus
Posté par: jeanda le octobre 26, 2014, 19:19:17
 ;)

Ce fut un peut long mais bon je pense que c'est fini, que dois je faire de tout ce que tu m'as fait installé?

 :AAC
Titre: Re : omiga-plus
Posté par: nicoolas le octobre 26, 2014, 19:57:13
 :AAC


- Supprimer les outils de désinfection
 - Purger la restauration système

Titre: Re : omiga-plus
Posté par: jeanda le octobre 26, 2014, 20:16:12
 :)

Bon c'est fait mais ça n'a pas enlevé beaucoup de logiciels....peut être faire un redémarrage du système, j'ai redémarré tout est parti sauf le dernier rapport

http://up.security-x.fr/file.php?h=R54a9ff220359f9321cd4b6c0ce2120f6
 :AAN
Titre: Re : omiga-plus
Posté par: nicoolas le octobre 26, 2014, 21:12:50
oki tout est bon pour moi, à toi de faire attention à l'avenir  pour ne pas réinfecter ton pc.
Titre: Re : omiga-plus
Posté par: jeanda le octobre 26, 2014, 22:18:30
 :)

Un grand merci à toi.

Pourtant franchement je fais très attention, apparemment faut croire que ce n'est pas encore assez. Sur ce coup là j'ai pensé installé un flash player d'adobe, j'ai été distrait par une action de Federrer (ah le tennis me perdra) et quand j'ai reporté mes yeux sur le pc il y avait un logiciel de contrôle d'infection de pc qui s'installait j'ai compris tout de suite ce qui se passait mais trop tard je me suis affolé je ne savais plus comment m'en sortir j'ai quand même réussi à interrompre le téléchargement et à supprimer des logiciels mais rien à faire pour omiga.
promis je vais faire gaffe encore plus ++++ :AAC