Bonjour,
Arme-toi de courage, tu sembles avoir choppé une belle sal...rie ! :o(((
A l'adresse suivante, tu trouveras un post -compliqué- qui fait le nettoyage :
http://forums.thetechguys.com/showthread.php?t=10776[...
Please download and run:
SpywareBlaster 3.2
http://www.short-media.com/download.php?dc=69CWSHREDDER
http://forums.thetechguys.com/showthread.php?t=7822Copy This To Notepad!!!
You will have to close this window so you might want to save these instructions to Notepad
----------------------------------------------------------------------
Next
Disable hidden Files & Folders (see link below for how to)
How To Show Hidden Files And Folders!!!
http://service1.symantec.com/SUPPOR...x&osv=&osv_lvl=Turn Off System Restore (see links below for how to)
Windows XP
http://service1.symantec.com/SUPPOR...src=sec_doc_namWindows Me
http://service1.symantec.com/SUPPOR...src=sec_doc_namReboot your computer to safemode (see link below for how to)
How To Boot Into SafeMode!!!
WINDOWS 95
WINDOWS 98/ME
WINDOWS 2000
Windows XP
WINDOWS as part of a multi boot system
http://service1.symantec.com/SUPPOR...src=sec_doc_nam1. Open Hijackthis and Rescan Your Computer
2. Place a Check Beside Each Item Listed Below
3. DO NTO CLICK FIX YET
--------------------------------------------------------------------
I see that you have "Messenger Plus! 3" This may be the cause of your infection. If you installed "Messenger Plus! 3" with it's defaults then you are being infected by bundled spyware that is loaded with the program. Suggest you uninstall "Messenger Plus! 3", and re-install it without the sponser programs (if you check through what looks like the license agreement, you'll find a check box at the bottom that allows you to install without the sponser programs).
4. While in SAFE MODE
Locate and delete if found:
C:\Program Files\Messenger Plus! 3\MsgPlus.exe" <<<---uninstall program
C:\WINDOWS\System\MSMSGSVC.exe
C:\WINDOWS\dpe.dll
--------------------------------------------------------------------
5. Close all Browser Windows (Including This One) and Click The Fix Checked Button on Hijackthis
----------------------------------------------------------------------
Here are the items To Check for Removal.
----------------------------------------------------------------------
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.e-finder.cc/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.e-finder.cc/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.e-finder.cc/search/ (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://default.homeR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.e-finder.cc/search/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.e-finder.cc/search/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.e-finder.cc/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://default.homeR1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.e-finder.cc/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.e-finder.cc/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) =
http://www.e-finder.cc/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.e-finder.cc/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.e-finder.cc/search/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) =
http://www.e-finder.cc/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.e-finder.cc/search/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.e-finder.cc/search/ (obfuscated)
O2 - BHO: DOMPeek Class - {834261E1-DD97-4177-853B-C907E5D5BD6E} - C:\WINDOWS\dpe.dll
-------------------------------------------------------------------
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKCU\..\Run: [MSMsgSvc] C:\WINDOWS\System\MSMSGSVC.exe
---------------------------------------------------------------------
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
---------------------------------------------------------------------
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) -
http://aolcc.aolsvc.aol.co.uk/compu...kup/qdiagcc.cabO16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) -
http://launch.gamespyarcade.com/sof...nch/alaunch.cab----------------------------------------------------------------------
Download and Install the free version of Ad-Aware SE Personal 1.05
http://www.short-media.com/download.php?dc=69Ensure you have this version or later
After installation-CHECK FOR UPDATES
Do a Full system scan----Remove All Critical objects
RESTART your computer to finish the cleaning process
---------------------------------------------------------------------
Delete all temp internet files and empty recycle bin
---------------------------------------------------------------------
Reboot to normal and enable system restore.
----------------------------------------------------------------------
Please Post A New Log So We Can Cleanup Anything Thats Is Left Behind
...]
Amitiés.