Security-X

Forum Security-X => Désinfections => Discussion démarrée par: lelmax le octobre 01, 2015, 20:14:34

Titre: Page internet qui s'ouvre en permanence plus pubs [Résolu]
Posté par: lelmax le octobre 01, 2015, 20:14:34
Windows Version: Windows 7 Home Premium Service Pack 1
Program started at: 10/01/2015 07:53:52 PM.

Scanning for registry hijacks:

  * HKLM\Software\Microsoft\Internet Explorer\Main "Default_Page_URL" hijacked to http://www.delta-homes.com/?type=hp&ts=1429893134&from=ient04240&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142

  * HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main "Default_Page_URL" hijacked to http://www.delta-homes.com/?type=hp&ts=1429893134&from=ient04240&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142

  * HKLM\Software\Microsoft\Internet Explorer\Main "Start Page" hijacked to http://www.delta-homes.com/?type=hp&ts=1429893134&from=ient04240&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142

  * HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main "Start Page" hijacked to http://www.delta-homes.com/?type=hp&ts=1429893134&from=ient04240&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142

  * HKLM\Software\Microsoft\Internet Explorer\Main "Default_Search_URL" hijacked to http://www.sweet-page.com/web/?type=ds&ts=1405419091&from=cor&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142&q={searchTerms}

  * HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main "Default_Search_URL" hijacked to http://www.sweet-page.com/web/?type=ds&ts=1405419091&from=cor&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142&q={searchTerms}

  * HKLM\Software\Microsoft\Internet Explorer\Main "Search Page" hijacked to http://www.sweet-page.com/web/?type=ds&ts=1405419091&from=cor&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142&q={searchTerms}

  * HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main "Search Page" hijacked to http://www.sweet-page.com/web/?type=ds&ts=1405419091&from=cor&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142&q={searchTerms}

  * HKCU\Software\Microsoft\Internet Explorer\Main "Default_Page_URL" hijacked to http://www.sweet-page.com/web/?type=ds&ts=1405419091&from=cor&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142&q={searchTerms}

  * HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\Main "Default_Page_URL" hijacked to http://www.sweet-page.com/web/?type=ds&ts=1405419091&from=cor&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142&q={searchTerms}

Backup Registry file created at:
 C:\Users\Patrick\Desktop\\sc-cleaner\sc-cleaner-10-01-2015-07-53-53.reg

Searching for Hijacked Shortcuts:

Searching C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\

Searching C:\ProgramData\Microsoft\Windows\Start Menu\

Searching C:\Users\Patrick\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\

Searching C:\Users\Public\Desktop\

Searching C:\Users\Patrick\Desktop\

Searching C:\Users\Public\Desktop\


0 bad shortcuts found.

Program finished at: 10/01/2015 07:53:54 PM
Execution time: 0 hours(s), 0 minute(s), and 1 seconds(s)

Merci de votre aide
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: nicoolas le octobre 02, 2015, 00:02:07
Bonsoir,


Même pas un bonjour ? Nous sommes bénévoles, ce qui veut dire que les désinfections sont faites gratuitement. Saluer la personne qui va vous venir en aide est la moindre des choses.

Je vais quand même vous prendre en charge.

Nous allons dans un premier temps établir un diagnostic de ton pc. Je te demande donc de ne pas demander de l'aide sur un autre forum car ceci pourrait s'avérer dangereux pour ton pc.

(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)FRST :

Sous IE9, IE10 ou IE11, le filtre SmartScreen déclenche une alerte. Cliquer sur Actions puis sur Exécuter quand même

---------------------------------------------------------------------------------------------

Sont attendus les rapports FRST.txt et Addition.txt

A+
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: lelmax le octobre 02, 2015, 21:58:35
Autant pour moi
Je suis tellement stressé par  ce soucis que j'en perds mes bonne manières,
Bonjour bonsoir à tous et merci de votre aide  Nicoolas
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: lelmax le octobre 02, 2015, 22:37:07
Comme demandé voici les liens :
http://up.security-x.fr/file.php?h=Rb8f9dfc196365df5d6d3b1752dfec88a

http://up.security-x.fr/file.php?h=Rb8f9dfc196365df5d6d3b1752dfec88a

Merci
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: nicoolas le octobre 03, 2015, 18:27:02
 :AAC

Tu as mis deux fois le rapport FRST.txt, du coup je n'ai pas le rapport Addition.txt

Peux-tu me transmettre le rapport Addition.txt ?
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: lelmax le octobre 03, 2015, 19:03:54
Salut
Deuxième  lien
http://up.security-x.fr/file.php?h=R4b8a6e60a30154c73f57a64ec0c37964
merci
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: nicoolas le octobre 03, 2015, 21:47:24
 :AAC

On va commencer la procédure de désinfection.

Désinstallation des programmes :

Supprime le ou les programme(s) listé(s) ci-dessous via Panneau de configuration -> Désinstaller un programme (si tu ne trouves pas un programme, passe au suivant !) :

CCleaner Packages
File Extractor
VipBoxSportsApp
Web Assistant 2.0.0.604




(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)FRST - Correctif :

start
CreateRestorePoint:
CloseProcesses:
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => Pas de fichier
AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => Pas de fichier
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1405419091&from=cor&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.delta-homes.com/?type=hp&ts=1429893134&from=ient04240&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1405419091&from=cor&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1739335617-45622530-1743251556-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.wolframalpha.com/input/?i={searchTerms}&trackid=sp-005
HKU\S-1-5-21-1739335617-45622530-1743251556-1001\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77
HKU\S-1-5-21-1739335617-45622530-1743251556-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.wolframalpha.com/?trackid=sp-005
URLSearchHook: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 - (Pas de nom) - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - Pas de fichier
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_15_03_ch&cd=2XzuyEtN2Y1L1Qzu0EzztCtCtAtB0AtCyByEzzyC0D0F0CtDtN0D0Tzu0StCtCtCtAtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2SyByC0B0C0FyByBtAtGtAzy0DtCtG0AyB0C0CtGtA0DtB0AtGtByD0Czzzz0EzztCyDyE0E0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCzzyE0AyEzz0AzztGzzyEyB0CtGyEtCyEzztGzzyCyB0AtGzz0A0F0A0F0D0FyDyE0AzyyB2Q&cr=833149312&ir=
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_15_03_ch&cd=2XzuyEtN2Y1L1Qzu0EzztCtCtAtB0AtCyByEzzyC0D0F0CtDtN0D0Tzu0StCtCtCtAtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2SyByC0B0C0FyByBtAtGtAzy0DtCtG0AyB0C0CtGtA0DtB0AtGtByD0Czzzz0EzztCyDyE0E0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCzzyE0AyEzz0AzztGzzyEyB0CtGyEtCyEzztGzzyCyB0AtGzz0A0F0A0F0D0FyDyE0AzyyB2Q&cr=833149312&ir=
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxp://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_ggfc_14_45_ch&cd=2XzuyEtN2Y1L1Qzu0EzztCtCtAtB0AtCyByEzzyC0D0F0CtDtN0D0Tzu0StCtDtAyBtN1L2XzutAtFyDtFtCtFyEtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyB0CyB0Azy0Azz0CtG0CyE0F0AtGtBtAzzzztG0DtAtDtCtGtBtAyCtCtD0Ezz0A0DzzyDyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0C0B0CyCyEzyzytG0EzzzyzztGyEyBtAzytG0BzztDzytG0A0CtA0E0AyB0B0C0DzzyDyE2Q&cr=1784390749&ir=
SearchScopes: HKLM-x32 -> DefaultScope {2de06457-88b8-4989-9288-5fe9c2584ab8} URL = hxxps://www.wolframalpha.com/input/?i={searchTerms}&trackid=sp-005
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.certified-toolbar.com?si=38268&bs=true&tid=77&q={searchTerms}
SearchScopes: HKLM-x32 -> {2de06457-88b8-4989-9288-5fe9c2584ab8} URL = hxxps://www.wolframalpha.com/input/?i={searchTerms}&trackid=sp-005
SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=38268&bs=true&tid=77&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> DefaultScope {2de06457-88b8-4989-9288-5fe9c2584ab8} URL = hxxps://www.wolframalpha.com/input/?i={searchTerms}&trackid=sp-005
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPA6A6FDB3-4C01-4460-874A-983B4849C853&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_15_03_ch&cd=2XzuyEtN2Y1L1Qzu0EzztCtCtAtB0AtCyByEzzyC0D0F0CtDtN0D0Tzu0StCtCtCtAtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2SyByC0B0C0FyByBtAtGtAzy0DtCtG0AyB0C0CtGtA0DtB0AtGtByD0Czzzz0EzztCyDyE0E0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCzzyE0AyEzz0AzztGzzyEyB0CtGyEtCyEzztGzzyCyB0AtGzz0A0F0A0F0D0FyDyE0AzyyB2Q&cr=833149312&ir=
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.certified-toolbar.com?si=38268&bs=true&tid=77&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> {1945E092-CE7A-4B44-A259-A105B5DAB2FD} URL = hxxp://www.lookineo.com/web?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> {2de06457-88b8-4989-9288-5fe9c2584ab8} URL = hxxps://www.wolframalpha.com/input/?i={searchTerms}&trackid=sp-005
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=38268&bs=true&tid=77&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://mystart.incredibar.com/mb178/?search={searchTerms}&loc=IB_DS&a=6OyP11jcOQ&i=26
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxp://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_ggfc_14_45_ch&cd=2XzuyEtN2Y1L1Qzu0EzztCtCtAtB0AtCyByEzzyC0D0F0CtDtN0D0Tzu0StCtDtAyBtN1L2XzutAtFyDtFtCtFyEtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyB0CyB0Azy0Azz0CtG0CyE0F0AtGtBtAzzzztG0DtAtDtCtGtBtAyCtCtD0Ezz0A0DzzyDyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0C0B0CyCyEzyzytG0EzzzyzztGyEyBtAzytG0BzztDzytG0A0CtA0E0AyB0B0C0DzzyDyE2Q&cr=1784390749&ir=
BHO: Pas de nom -> {336D0C35-8A85-403a-B9D2-65C292C39087} -> Pas de fichier
BHO-x32: Pas de nom -> {336D0C35-8A85-403a-B9D2-65C292C39087} -> Pas de fichier
BHO-x32: Pas de nom -> {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} -> Pas de fichier
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - Pas de fichier
Toolbar: HKLM - Pas de nom - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - Pas de fichier
Toolbar: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> Pas de nom - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Pas de fichier
S2 Web Assistant; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [188760 2013-06-30] () [Fichier non signé]
S2 savesenselive; C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe /svc [X]
S3 savesenselivem; C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe /medsvc [X]
2015-10-01 20:50 - 2014-06-11 20:32 - 00000000 ____D C:\Program Files (x86)\globalUpdate
2015-10-02 21:20 - 2012-11-18 17:19 - 00000000 ____D C:\Program Files (x86)\Webplayer setup
2015-10-02 21:20 - 2012-11-04 15:44 - 00000000 ____D C:\Program Files (x86)\Yontoo
2015-10-01 20:50 - 2012-11-18 17:20 - 00000000 ____D C:\ProgramData\Browser Manager
2015-09-24 21:34 - 2014-12-02 12:20 - 00000000 __SHD C:\Users\Patrick\AppData\Local\EmieBrowserModeList
2015-09-24 21:34 - 2014-09-28 16:48 - 00000000 __SHD C:\Users\Patrick\AppData\Local\EmieUserList
2015-09-24 21:34 - 2014-09-28 16:48 - 00000000 __SHD C:\Users\Patrick\AppData\Local\EmieSiteList
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => Pas de fichier
Task: {392F1BDD-FFEC-4968-B791-9E2707A92ED6} - System32\Tasks\Digital Sites => C:\Users\Patrick\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {A2419BC5-434A-4568-BC78-834B597B0E14} - System32\Tasks\SaveSenseLiveUpdateTaskMachineUA => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION
Task: {F9551573-909E-45B4-8B88-2B62579D8EAF} - System32\Tasks\SaveSenseLiveUpdateTaskMachineCore => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION
Task: C:\windows\Tasks\Digital Sites.job => C:\Users\Patrick\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
cmd: sfc /scannow
cmd: ipconfig /flushdns
EmptyTemp:
end
/!\ Ce script a été établi pour cet utilisateur, il ne doit, en aucun cas, être appliqué sur un autre système, au risque de provoquer de graves dysfonctionnement et endommager Windows /!\HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-homes.com/?type=hp&ts=1429893134&from=ient04240&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142




(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)ADWCleaner:

Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: lelmax le octobre 04, 2015, 09:37:58
Bonjour Nicoolas
Suite aux différentes suppression et Maj que vous m'avez proposer, j'ai eu qq petits soucis:
Tout d'abord en mettant le correctif, le Pc c'est bien relancé et à l'ouverture de windows message
Window7
Numero7601
Cette copie de windows n'est pas authentique en permanence  coin bas droit de l'écran.
Ensuite plus du tout d'accès  à internet que cela soit en Wifi ou en LAN. J'étais bien connecté au réseau mais  la passerelle ne trouvais plus le net.
J'ai restauré le système  ce qui me permet  de pouvoir écrire ces lignes.
En attentes de votre réponse et de la marche à suivre,
Merci
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: nicoolas le octobre 04, 2015, 10:26:53
 :AAC

Il s'agit d'un windows légal ou d'une version crackée ?
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: lelmax le octobre 04, 2015, 11:19:32
légal intégré dès le départ lors de l'achat du Pc
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: nicoolas le octobre 04, 2015, 11:24:53
Re,

On va essayer un autre correctif pour voir.


(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)FRST - Correctif :

start
CreateRestorePoint:
CloseProcesses:
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => Pas de fichier
AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => Pas de fichier
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1405419091&from=cor&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.delta-homes.com/?type=hp&ts=1429893134&from=ient04240&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1405419091&from=cor&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1739335617-45622530-1743251556-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.wolframalpha.com/input/?i={searchTerms}&trackid=sp-005
HKU\S-1-5-21-1739335617-45622530-1743251556-1001\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77
HKU\S-1-5-21-1739335617-45622530-1743251556-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.wolframalpha.com/?trackid=sp-005
URLSearchHook: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 - (Pas de nom) - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - Pas de fichier
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_15_03_ch&cd=2XzuyEtN2Y1L1Qzu0EzztCtCtAtB0AtCyByEzzyC0D0F0CtDtN0D0Tzu0StCtCtCtAtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2SyByC0B0C0FyByBtAtGtAzy0DtCtG0AyB0C0CtGtA0DtB0AtGtByD0Czzzz0EzztCyDyE0E0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCzzyE0AyEzz0AzztGzzyEyB0CtGyEtCyEzztGzzyCyB0AtGzz0A0F0A0F0D0FyDyE0AzyyB2Q&cr=833149312&ir=
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_15_03_ch&cd=2XzuyEtN2Y1L1Qzu0EzztCtCtAtB0AtCyByEzzyC0D0F0CtDtN0D0Tzu0StCtCtCtAtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2SyByC0B0C0FyByBtAtGtAzy0DtCtG0AyB0C0CtGtA0DtB0AtGtByD0Czzzz0EzztCyDyE0E0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCzzyE0AyEzz0AzztGzzyEyB0CtGyEtCyEzztGzzyCyB0AtGzz0A0F0A0F0D0FyDyE0AzyyB2Q&cr=833149312&ir=
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxp://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_ggfc_14_45_ch&cd=2XzuyEtN2Y1L1Qzu0EzztCtCtAtB0AtCyByEzzyC0D0F0CtDtN0D0Tzu0StCtDtAyBtN1L2XzutAtFyDtFtCtFyEtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyB0CyB0Azy0Azz0CtG0CyE0F0AtGtBtAzzzztG0DtAtDtCtGtBtAyCtCtD0Ezz0A0DzzyDyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0C0B0CyCyEzyzytG0EzzzyzztGyEyBtAzytG0BzztDzytG0A0CtA0E0AyB0B0C0DzzyDyE2Q&cr=1784390749&ir=
SearchScopes: HKLM-x32 -> DefaultScope {2de06457-88b8-4989-9288-5fe9c2584ab8} URL = hxxps://www.wolframalpha.com/input/?i={searchTerms}&trackid=sp-005
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.certified-toolbar.com?si=38268&bs=true&tid=77&q={searchTerms}
SearchScopes: HKLM-x32 -> {2de06457-88b8-4989-9288-5fe9c2584ab8} URL = hxxps://www.wolframalpha.com/input/?i={searchTerms}&trackid=sp-005
SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=38268&bs=true&tid=77&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> DefaultScope {2de06457-88b8-4989-9288-5fe9c2584ab8} URL = hxxps://www.wolframalpha.com/input/?i={searchTerms}&trackid=sp-005
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPA6A6FDB3-4C01-4460-874A-983B4849C853&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_15_03_ch&cd=2XzuyEtN2Y1L1Qzu0EzztCtCtAtB0AtCyByEzzyC0D0F0CtDtN0D0Tzu0StCtCtCtAtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1BtAtN1L1G1B1V1N2Y1L1Qzu2SyByC0B0C0FyByBtAtGtAzy0DtCtG0AyB0C0CtGtA0DtB0AtGtByD0Czzzz0EzztCyDyE0E0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCzzyE0AyEzz0AzztGzzyEyB0CtGyEtCyEzztGzzyCyB0AtGzz0A0F0A0F0D0FyDyE0AzyyB2Q&cr=833149312&ir=
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.certified-toolbar.com?si=38268&bs=true&tid=77&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> {1945E092-CE7A-4B44-A259-A105B5DAB2FD} URL = hxxp://www.lookineo.com/web?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> {2de06457-88b8-4989-9288-5fe9c2584ab8} URL = hxxps://www.wolframalpha.com/input/?i={searchTerms}&trackid=sp-005
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=38268&bs=true&tid=77&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://mystart.incredibar.com/mb178/?search={searchTerms}&loc=IB_DS&a=6OyP11jcOQ&i=26
SearchScopes: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxp://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_ggfc_14_45_ch&cd=2XzuyEtN2Y1L1Qzu0EzztCtCtAtB0AtCyByEzzyC0D0F0CtDtN0D0Tzu0StCtDtAyBtN1L2XzutAtFyDtFtCtFyEtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyB0CyB0Azy0Azz0CtG0CyE0F0AtGtBtAzzzztG0DtAtDtCtGtBtAyCtCtD0Ezz0A0DzzyDyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0C0B0CyCyEzyzytG0EzzzyzztGyEyBtAzytG0BzztDzytG0A0CtA0E0AyB0B0C0DzzyDyE2Q&cr=1784390749&ir=
BHO: Pas de nom -> {336D0C35-8A85-403a-B9D2-65C292C39087} -> Pas de fichier
BHO-x32: Pas de nom -> {336D0C35-8A85-403a-B9D2-65C292C39087} -> Pas de fichier
BHO-x32: Pas de nom -> {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} -> Pas de fichier
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - Pas de fichier
Toolbar: HKLM - Pas de nom - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - Pas de fichier
Toolbar: HKU\S-1-5-21-1739335617-45622530-1743251556-1001 -> Pas de nom - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Pas de fichier
S2 Web Assistant; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [188760 2013-06-30] () [Fichier non signé]
S2 savesenselive; C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe /svc [X]
S3 savesenselivem; C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe /medsvc [X]
2015-10-01 20:50 - 2014-06-11 20:32 - 00000000 ____D C:\Program Files (x86)\globalUpdate
2015-10-02 21:20 - 2012-11-18 17:19 - 00000000 ____D C:\Program Files (x86)\Webplayer setup
2015-10-02 21:20 - 2012-11-04 15:44 - 00000000 ____D C:\Program Files (x86)\Yontoo
2015-10-01 20:50 - 2012-11-18 17:20 - 00000000 ____D C:\ProgramData\Browser Manager
2015-09-24 21:34 - 2014-12-02 12:20 - 00000000 __SHD C:\Users\Patrick\AppData\Local\EmieBrowserModeList
2015-09-24 21:34 - 2014-09-28 16:48 - 00000000 __SHD C:\Users\Patrick\AppData\Local\EmieUserList
2015-09-24 21:34 - 2014-09-28 16:48 - 00000000 __SHD C:\Users\Patrick\AppData\Local\EmieSiteList
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1739335617-45622530-1743251556-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Patrick\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => Pas de fichier
Task: {392F1BDD-FFEC-4968-B791-9E2707A92ED6} - System32\Tasks\Digital Sites => C:\Users\Patrick\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {A2419BC5-434A-4568-BC78-834B597B0E14} - System32\Tasks\SaveSenseLiveUpdateTaskMachineUA => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION
Task: {F9551573-909E-45B4-8B88-2B62579D8EAF} - System32\Tasks\SaveSenseLiveUpdateTaskMachineCore => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION
Task: C:\windows\Tasks\Digital Sites.job => C:\Users\Patrick\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
EmptyTemp:
end
/!\ Ce script a été établi pour cet utilisateur, il ne doit, en aucun cas, être appliqué sur un autre système, au risque de provoquer de graves dysfonctionnement et endommager Windows /!\HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-homes.com/?type=hp&ts=1429893134&from=ient04240&uid=WDCXWD7500BPVT-35HXZT1_WD-WXE1A91P9142P9142




(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)ADWCleaner:

Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: lelmax le octobre 04, 2015, 13:15:18
Mise  en place du nouveau correctif , tout fonctionne correctement merci
 ci dessus le fichier fixlog
http://up.security-x.fr/file.php?h=R6d6d0e44864a21ad7fff46241d9c6d58
Rapport Adw
http://up.security-x.fr/file.php?h=Rc1e66fe51295b0e4e2240a36dedc0ca4
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: nicoolas le octobre 04, 2015, 21:29:46
(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)ADWCleaner:

Sous IE9, IE10 ou IE11, le filtre SmartScreen déclenche une alerte. Cliquer sur Actions puis sur Exécuter quand même


Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: lelmax le octobre 04, 2015, 23:20:01
re
Donc voila le rapport après nettoyage
http://up.security-x.fr/file.php?h=R5391d49e3982db26e170b361f29ebba8

Puis Frst
http://up.security-x.fr/file.php?h=Rc5ccb4b9a175def19a34012539a3f0b8

Et pour finir Addition
http://up.security-x.fr/file.php?h=Rfbb1e69ac7492726bb1abc1057266406

Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: nicoolas le octobre 05, 2015, 19:02:02
 :AAC

Comment se porte le pc ?
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: lelmax le octobre 05, 2015, 19:43:56
salut
il y a du mieux mais dés que je clique sur un lien j ai une fenêtre qui s'ouvre   :AAM je précise une fetre intempestive  ;D

http://up.security-x.fr/file.php?h=R42f79674f63b7d7cdd974598fb106bae

Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: nicoolas le octobre 05, 2015, 20:10:24
Re,

ZHPCleaner-Scanner

/!\ Ne passe l'outil qu'une seule fois afin de ne pas fausser le rapport /!\

Héberge ce rapport sur ce site d'hébergement de fichiers (http://security-x.fr/up/) et indique les liens fournis dans ta réponse. Aide en images (http://forum.security-x.fr/cours-et-tutoriels-322/(tutoriel)-impression-d%27ecran-et-hebergement-de-rapport/msg60884/#msg60884)
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: lelmax le octobre 05, 2015, 20:23:31
Rapport ZHP
http://up.security-x.fr/file.php?h=R9ad1b3b91fdf40257e774252cc7f4011
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: nicoolas le octobre 05, 2015, 20:31:16
Re,


ZHPCleaner-Nettoyer


/!\ Ne passe l'outil qu'une seule fois afin de ne pas fausser le rapport /!\

Héberge ce rapport sur ce site d'hébergement de fichiers (http://security-x.fr/up/) et indique les liens fournis dans ta réponse. Aide en images (http://forum.security-x.fr/cours-et-tutoriels-322/(tutoriel)-impression-d%27ecran-et-hebergement-de-rapport/msg60884/#msg60884)
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: lelmax le octobre 05, 2015, 20:41:14
Rapport suite Nettoyage
http://up.security-x.fr/file.php?h=R505245e97b2a3a8866dec51453b4a877
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: nicoolas le octobre 05, 2015, 20:48:21
Re,

Tu as toujours des pubs ?
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: lelmax le octobre 05, 2015, 20:48:58
C'est à devenir fou  le moindre clic pour fermer ou suivre un lien m'ouvre ce genre de pages à la suite

http://up.security-x.fr/file.php?h=Re91588ca54497fc6749c47eaff94b0da

http://up.security-x.fr/file.php?h=R69d8eeb8b882dbbf14a3fc226ecea559
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: nicoolas le octobre 06, 2015, 18:56:47
 :AAC

Tu as des publicités en naviguant sur tous les sites ou un site en particulier ? Si c'est un site en particulier, lequel ?

On va faire une autre analyse :

Malwarebytes Anti-Malware :

Le journal d'examen est aussi enregistré sous C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Logs[/list]

Tutoriel d'utilisation Malwarebytes en images (http://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-version-2/)
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: lelmax le octobre 07, 2015, 19:39:45
Salut
Alors  concernant les sites  c'est aléatoire les pubs qui reviennent le plus souvent disent que l'utilisateur Chrome  gagner etc etc ...
J ai aussi installé  Malwarebytes Anti-Malware fait toute la procédure 
suite au redémarrage écran noir  plus accès à rien .j ai reteins  puis rallumer plusieurs fois et rien donc j ai fait démarrage sans échec puis restauration du système  avant le dernier téléchargement .
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: nicoolas le octobre 08, 2015, 18:25:55
 :AAC

On va tenter autre chose:

Réinitialisation de Google Chrome :

Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: lelmax le octobre 12, 2015, 19:04:21

Hello
J ai bien réinitialiser  Chrome, mais rien n'y fait ... j ai aussi ajouté AdBlock et j'ai  du mieux mais pas encore correcte...
Même sur votre site quand je clique sur un lien j'ai une autre page internet qui s'ouvre une fois 3/4
Et non je n'ai plus le rapport  Malwarebytes
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: nicoolas le octobre 13, 2015, 19:17:09
Allumer son ordinateur en mode sans échec :

Le journal d'examen est aussi enregistré sous C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Logs[/list]

Tutoriel d'utilisation Malwarebytes en images (http://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-version-2/)


 :AAN
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: lelmax le octobre 13, 2015, 20:37:44
Salut
  voilà le lien du rapport Malware
http://up.security-x.fr/file.php?h=R545aff868d8c63446906359c13f6b316.
Ce coup ci il a redémarré normalement  pas eu besoin de passer en mode sans échec
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: nicoolas le octobre 14, 2015, 19:59:30
 :AAC

Ton pc présente toujours des publicités ou pas ?
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: lelmax le octobre 15, 2015, 17:43:07
  salut
:sup:
non depuis le dernier nettoyage  et la mise en place de Adblocks  je n 'ai plus  de pages  de pubs.
 Merci beaucoup de ton aide et de ta patience .
Merci aussi à tous les autres qui sont dans l'ombre et qui font fonctionné  ce site d'entraide bravo à tous!
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: nicoolas le octobre 15, 2015, 18:21:39
 :AAC

On va donc finaliser la procédure de désinfection.

- Supprimer les outils de désinfection
 - Purger la restauration système



Afin d'éviter de te faire réinfecter, voici quelques conseils :

Sois vigilant lors de l'installation de logiciels :
Il faut lire les conditions d'utilisation des logiciels afin de voir comment sont gérées nos données personnelles, s'ils n'installent pas de sponsors publicitaires. Il faut aussi refuser les toolbars ou tout autre addons. Je te conseille de lire cet article (http://forum.security-x.fr/securite-generale/stop-la-pub/) et celui-ci (http://forum.security-x.fr/tutoriels-317/installation-d%27une-application-sponsorisee-les-pieges-a-eviter)

Pour éviter de te faire réinfecter par des adwares à l'avenir, entraîne-toi à ne pas tomber dans leurs pièges (http://forum.security-x.fr/tutoriels-317/installation-d%27une-application-sponsorisee-les-pieges-a-eviter/) en utilisant cet outil :

Télécharge Adware Prevention (http://security-x.fr/~guigui0001/Adware_Prevention.exe) (de guigui0001) sur ton bureau.

Sous IE9, IE10, IE11 et Windows 8 le filtre SmartScreen déclenche une alerte. Cliquer sur Actions puis sur Exécuter quand même

Maintenir ses logiciels et son système à jour :
De nombreuses infections sont dû à des failles de windows, mais aussi de logiciel tiers, comme Sun Java, Adobe Acrobat Reader, etc
Tu peux faire un scan de vulnérabilité (http://secunia.com/vulnerability_scanning/online/) pour connaitre tes logiciels présentant des failles non corrigées ou à mettre à jour.
Ou utiliser un outil comme SXCU (http://forum.security-x.fr/tutoriels-317/(tutoriel)-sx-checkupdate/) pour vérifier occasionnellement.



Enfin, le plus important reste ton comportement sur ton PC, tu restes la plus importante protection : Évites les comportement à risque : P2P, cracks, téléchargements et installations douteux via des pubs, les messageries instantanées, ou des sites inconnu, sites pornographiques.
A lire ! (http://www.tomsguide.fr/forum/id-2134891/prevention-protection-securiser-ordinateur.html)
Ici aussi ! (http://www.tomsguide.fr/forum/id-416930/dossier-prevention-protection.html)

 :AAN
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: lelmax le octobre 15, 2015, 18:44:41
Rapport Delfix

http://up.security-x.fr/file.php?h=Rc90149fe5d52aef89e06aef5b31189c4
Titre: Re : Page internet qui s'ouvre en permanence plus pubs
Posté par: nicoolas le octobre 15, 2015, 22:07:14
 :AAC

C'est ok pour moi :)

Prudence sur le net ;)