|
 Posté le 12/05/2009 @ 16:13 |
Nouvel astucien
| Bonjour,
Je suis nouveau sur le forum. J'espère que je poste ma question dans la bonne rubrique.
Depuis quelques jours, j'ai un barre de recherche (Yoog search) qui s'est intallé sur Firefox et je n'arrive pas à m'en débarasser.
Je vous recmercie de votre aide.
Cordialement
Fets
|
|
|
|
|
|
Posté le 12/05/2009 à 16:49 |
Grand Maître astucien | Bonjour.
Télécharge Yoog_Fix de Batch_Man sur le Bureau. http://batchdhelus.open-web.fr/programme/Yoog_Fix.exe
Recherche
Double-clique dessus et choisir l'option 1 Attend la fin du scan, un rapport va s'ouvrir. Poste le dans la prochaine réponse. Le rapport sera disponible ici : C:\Yoog_Fix.txt
Nettoyage
Relance Yoog_Fix et choisis l'option 2 Attends que la suppression se termine et appuies sur une touche, un rapport s'ouvre. Poste le dans la prochaine réponse. Le rapport sera disponible ici : C:\Yoog_Fix.txt
@+
|
|
Posté le 12/05/2009 à 21:30 |
Nouvel astucien
| Bonjour et merci pour ton aide,
Voici le rapport otenu après l'option 1 :
Yoog_Fix 2.02 de Batch_Man Debut a 21:27 le 12/05/2009 Microsoft Windows XP Professional (5.1.2600) Service Pack 3 Internet Explorer 7.0.5730.11 Mozilla Firefox 3.0.10 (fr) McAfee (Activated) McAfee (Activated)
C:\ [Fixed] - NTFS - (Total:20000 Mo/Free:498 Mo) D:\ [Fixed] - NTFS - (Total:56316 Mo/Free:1466 Mo) E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) F:\ [Removable] (Total:0 Mo/Free:0 Mo)
Option [1] 2 Recherche
+---------------\\ Processus cachés/bloqués
+---------------\\ Recherche
----------\\ Recherche de fichiers
C:\WINDOWS\system32\brphdlsaqfnu.dll-uninst.exe FOUND! C:\Documents and Settings\perso\Application Data\Mozilla\Firefox\Profiles\40n0e0kl.default\searchplugins\Yoog Search.xml FOUND! C:\Documents and Settings\perso\Application Data\Mozilla\Firefox\Profiles\umg3myft.default\searchplugins\Yoog Search.xml FOUND!
----------\\ Recherche dans prefs.js
prefs.js [perso - umg3myft.default] user_pref("browser.search.defaultenginename", "Yoog Search"); prefs.js [perso - umg3myft.default] user_pref("browser.search.defaulturl", "http://www7.yoog.com/search.php?q="); prefs.js [perso - umg3myft.default] user_pref("keyword.URL", "http://www7.yoog.com/search.php?q=");
user.js [perso - 40n0e0kl.default] user_pref("browser.search.defaultenginename", "Yoog Search"); user.js [perso - 40n0e0kl.default] user_pref("browser.search.defaulturl", "http://www7.yoog.com/search.php?q="); user.js [perso - 40n0e0kl.default] user_pref("browser.search.selectedEngine", "Yoog Search"); user.js [perso - 40n0e0kl.default] user_pref("keyword.URL", "http://www7.yoog.com/search.php?q="); user.js [perso - umg3myft.default] user_pref("browser.search.defaultenginename", "Yoog Search"); user.js [perso - umg3myft.default] user_pref("browser.search.defaulturl", "http://www7.yoog.com/search.php?q="); user.js [perso - umg3myft.default] user_pref("browser.search.selectedEngine", "Yoog Search"); user.js [perso - umg3myft.default] user_pref("keyword.URL", "http://www7.yoog.com/search.php?q=");
----------\\ Recherche dans le registre
[HKEY_USERS\S-1-5-21-823518204-842925246-854245398-1004\..\SearchScopes],@DefaultScope={52CEC30F-DCB7-4E18-A75A-61574B77285D} [HKEY_USERS\S-1-5-21-823518204-842925246-854245398-1004\..\SearchScopes\{52CEC30F-DCB7-4E18-A75A-61574B77285D}] @DisplayName=Yoog Search [HKCU\..\SearchScopes],@DefaultScope={52CEC30F-DCB7-4E18-A75A-61574B77285D} [HKCU\..\SearchScopes\{52CEC30F-DCB7-4E18-A75A-61574B77285D}] @DisplayName=Yoog Search ----------\\ Infections associées possibles ----------\\ Suspects ( PAS FORCEMENT INFECTIEUX ) +---> Registre +---> Fichiers [--a------ + 06/05/2009 12:13 + 566272] C:\WINDOWS\system32\brphdlsaqfnu.dll [--a------ + 06/05/2009 12:13 + 566272] C:\WINDOWS\system32\brphdlsaqfnu.dll
+---------------\\Analyse complémentaire +---------\\ Tâches planifiées C:\WINDOWS\Tasks\AppleSoftwareUpdate.job C:\WINDOWS\Tasks\GoogleUpdateTaskMachine.job C:\WINDOWS\Tasks\McDefragTask.job C:\WINDOWS\Tasks\McQcTask.job ----------\\ Analyse de Firefox [C:\Documents and Settings\Administrateur\..\prefs.js] browser.startup.homepage: http://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official [C:\Documents and Settings\perso\..\prefs.js] browser.startup.homepage: http://fr.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official [C:\Documents and Settings\Administrateur\..\prefs.js] browser.startup.homepage: http://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official [C:\Documents and Settings\perso\..\prefs.js] browser.startup.homepage: http://fr.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official [C:\Documents and Settings\perso\..\prefs.js] browser.search.selectedEngine: Yahoo [C:\Documents and Settings\perso\..\prefs.js] browser.search.selectedEngine: Google [C:\Documents and Settings\perso\..\prefs.js] browser.search.defaultenginename: Yoog Search ----------\\ Extensions Firefox [User: Administrateur (218zk1xp.default)] - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} [User: Administrateur (218zk1xp.default)] - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} [User: Administrateur (218zk1xp.default)] - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [User: Administrateur (218zk1xp.default)] - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [User: Administrateur (218zk1xp.default)] - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [User: perso (40n0e0kl.default)] - C:\Documents and Settings\perso\Application Data\Mozilla\Firefox\Profiles\40n0e0kl.default\extensions\fr@dictionaries.addons.mozilla.org [User: perso (40n0e0kl.default)] - C:\Documents and Settings\perso\Application Data\Mozilla\Firefox\Profiles\40n0e0kl.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED} [User: perso (40n0e0kl.default)] - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [User: perso (umg3myft.default)] - C:\Documents and Settings\perso\Application Data\Mozilla\Firefox\Profiles\umg3myft.default\extensions\fr@dictionaries.addons.mozilla.org [User: perso (umg3myft.default)] - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [User: perso (umg3myft.default)] - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [User: perso (umg3myft.default)] - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} [User: perso (umg3myft.default)] - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} [User: perso (umg3myft.default)] - C:\Program Files\McAfee\SiteAdvisor [User: perso (umg3myft.default)] - C:\Documents and Settings\perso\Application Data\Mozilla\Firefox\Profiles\umg3myft.default\extensions\timetrack@usablehack.com [User: perso (umg3myft.default)] - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ----------\\ Plugins de recherche [08/10/2008 21:05|1516] - C:\Program Files\Mozilla Firefox\searchplugins\amazon-france.xml: Amazon.fr - Recherche Amazon.fr: http://www.amazon.fr/ [21/11/2008 23:58|757] - C:\Program Files\Mozilla Firefox\searchplugins\eBay-france.xml: eBay France - eBay - Enchères en ligne: http://search.ebay.fr/ [08/10/2008 21:05|1706] - C:\Program Files\Mozilla Firefox\searchplugins\google.xml: Google - Google Search: http://www.google.com/firefox [08/10/2008 21:05|748] - C:\Program Files\Mozilla Firefox\searchplugins\MediaDICO-fr.xml: MediaDICO - Les Dictionnaires Mediadico: http://www.dictionnaire-mediadico.com/dictionnaires.asp [08/10/2008 21:05|1426] - C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-fr.xml: Wikipédia (fr) - Wikipédia, l'encyclopédie libre: http://fr.wikipedia.org/wiki/Special:Recherche [08/10/2008 21:05|652] - C:\Program Files\Mozilla Firefox\searchplugins\yahoo-france.xml: Yahoo - Recherche Yahoo: http://fr.search.yahoo.com/ ----------\\ Listing de dossiers [25/04/2009 17:49 | --a------ | 348547 bytes] C:\Program Files\Mozilla Firefox\Components\browser.xpt [30/04/2009 10:13 | --a------ | 23032 bytes] C:\Program Files\Mozilla Firefox\Components\browserdirprovider.dll [23/03/2009 11:05 | --a------ | 491008 bytes] C:\Program Files\Mozilla Firefox\Components\brphdlsaqfnu.dll [30/04/2009 10:13 | --a------ | 134648 bytes] C:\Program Files\Mozilla Firefox\Components\brwsrcmp.dll [23/03/2007 14:18 | d-------- | 0 bytes] C:\Program Files\Mozilla Firefox\Components\myspell [27/06/2008 16:11 | --a------ | 324 bytes] C:\Program Files\Mozilla Firefox\Components\nsILegitCheckPlugin.xpt [05/12/2005 23:31 | --a------ | 343 bytes] C:\Program Files\Mozilla Firefox\Components\nsIMozAxPlugin.xpt [28/01/2009 00:05 | --a------ | 2394 bytes] C:\Program Files\Mozilla Firefox\Components\nsIQTScriptablePlugin.xpt [06/05/2006 18:42 | --a------ | 7260160 bytes] C:\Program Files\Mozilla Firefox\plugins\libvlc.dll [10/04/2007 18:21 | --a------ | 163256 bytes] C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll [03/09/2006 14:12 | --a------ | 49152 bytes] C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll [27/06/2008 17:03 | --a------ | 1446440 bytes] C:\Program Files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll [05/12/2005 23:31 | --a------ | 114688 bytes] C:\Program Files\Mozilla Firefox\plugins\npmozax.dll [30/04/2009 10:13 | --a------ | 65528 bytes] C:\Program Files\Mozilla Firefox\plugins\npnul32.dll [22/03/2007 19:23 | --a------ | 17248 bytes] C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL [14/10/2008 22:33 | --a------ | 95600 bytes] C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll [23/10/2006 02:26 | --a--c--- | 6144 bytes] C:\Program Files\Mozilla Firefox\plugins\nppdf32.FRA [28/01/2009 00:05 | --a------ | 143360 bytes] C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll [28/01/2009 00:05 | --a------ | 143360 bytes] C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll [28/01/2009 00:05 | --a------ | 143360 bytes] C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll [28/01/2009 00:05 | --a------ | 143360 bytes] C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll [28/01/2009 00:05 | --a------ | 143360 bytes] C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll [28/01/2009 00:05 | --a------ | 143360 bytes] C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll [28/01/2009 00:05 | --a------ | 143360 bytes] C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll [16/05/2007 09:22 | --a------ | 151300 bytes] C:\Program Files\Mozilla Firefox\plugins\np_gp.dll [28/01/2009 00:05 | --a------ | 4208 bytes] C:\Program Files\Mozilla Firefox\plugins\QuickTimePlugin.class [12/01/2006 13:49 | --a--c--- | 1144 bytes] C:\Program Files\Mozilla Firefox\plugins\ShockwavePlugin.class [30/03/2007 11:43 | --a--c--- | 149569 bytes] C:\Program Files\Mozilla Firefox\plugins\WMP Firefox Plugin License.rtf [30/03/2007 11:43 | --a--c--- | 3352 bytes] C:\Program Files\Mozilla Firefox\plugins\WMP Firefox Plugin RelNotes.txt ----------\\ Analyse d'Internet Explorer HKEY_CURRENT_USER\..\Internet Explorer,Start Page: about:blank HKEY_CURRENT_USER\..\Internet Explorer,Search Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKEY_LOCAL_MACHINE\..\Internet Explorer,Search Page: http://go.microsoft.com/fwlink/?LinkId=54896 HKEY_LOCAL_MACHINE\..\Internet Explorer,Start Page: http://www.msn.com/ HKEY_LOCAL_MACHINE\..\Internet Explorer,Default_Search_URL: http://go.microsoft.com/fwlink/?LinkId=54896 HKEY_LOCAL_MACHINE\..\Internet Explorer,CustomizeSearch: http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm HKEY_LOCAL_MACHINE\..\Internet Explorer,SearchAssistant: http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ----------\\ Browser Helper Object BHO: {27B4851A-3207-45A2-B947-BE8AFE6163AB},@SANS NOM=McAfee Phishing Filter BHO: {7DB2D5A0-7241-4E79-B68D-6309F01C5231},@SANS NOM=scriptproxy ----------\\ SearchScopes [HKEY_USERS\S-1-5-21-823518204-842925246-854245398-1004\..\SearchScopes],@DefaultScope={52CEC30F-DCB7-4E18-A75A-61574B77285D} [HKEY_USERS\S-1-5-21-823518204-842925246-854245398-1004\..\SearchScopes\{52CEC30F-DCB7-4E18-A75A-61574B77285D}],@DisplayName=Yoog Search [HKEY_USERS\S-1-5-21-823518204-842925246-854245398-1004\..\SearchScopes\{75BB6646-5AA6-4587-AFA3-CAC081E0F0F2}],@DisplayName=@ieframe.dll,-12512 [HKCU\..\SearchScopes],@DefaultScope={52CEC30F-DCB7-4E18-A75A-61574B77285D} [HKCU\..\SearchScopes\{52CEC30F-DCB7-4E18-A75A-61574B77285D}],@DisplayName=Yoog Search [HKCU\..\SearchScopes\{75BB6646-5AA6-4587-AFA3-CAC081E0F0F2}],@DisplayName=@ieframe.dll,-12512 [HKLM\..\SearchScopes],@DefaultScope={0633EE93-D776-472f-A0FF-E1416B8B2E3A} [HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}],@DisplayName=@ieframe.dll,-12512 ----------\\ Extensions @xpsp3res.dll,-20001 : %windir%\Network Diagnostic\xpnetdiag.exe - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} Windows Messenger: C:\Program Files\Messenger\msmsgs.exe - {1FBA04EE-3024-11D2-8F1F-0000F87ABD16}
+--------------- Fin à 21h 28min |
|
Posté le 12/05/2009 à 21:36 |
Nouvel astucien
| Voici le 2nd rapport.
Yoog_Fix 2.02 de Batch_Man Debut a 21:32 le 12/05/2009 Microsoft Windows XP Professional (5.1.2600) Service Pack 3 Internet Explorer 7.0.5730.11 Mozilla Firefox 3.0.10 (fr) McAfee (Activated) McAfee (Activated)
C:\ [Fixed] - NTFS - (Total:20000 Mo/Free:504 Mo) D:\ [Fixed] - NTFS - (Total:56316 Mo/Free:1466 Mo) E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) F:\ [Removable] (Total:0 Mo/Free:0 Mo)
Option 1 [2] Suppression
+---------------\\ Suppression
----------\\ Suppression dans de fichiers
DELETED - C:\WINDOWS\system32\*.DLL-UNINST.EXE DELETED - C:\Documents and Settings\perso\Application Data\Mozilla\Firefox\Profiles\40n0e0kl.default\searchplugins\Yoog Search.xml DELETED - C:\Documents and Settings\perso\Application Data\Mozilla\Firefox\Profiles\umg3myft.default\searchplugins\Yoog Search.xml
----------\\ Suppression dans prefs.js et user.js
prefs.js [perso - umg3myft.default] user_pref("browser.search.defaultenginename", "Yoog Search"); - DELETED prefs.js [perso - umg3myft.default] user_pref("browser.search.defaulturl", "http://www7.yoog.com/search.php?q="); - DELETED prefs.js [perso - umg3myft.default] user_pref("browser.search.selectedEngine", "Yoog Search"); - DELETED prefs.js [perso - umg3myft.default] user_pref("keyword.URL", "http://www7.yoog.com/search.php?q="); - DELETED user.js [perso - 40n0e0kl.default] user_pref("browser.search.defaultenginename", "Yoog Search"); - DELETED user.js [perso - 40n0e0kl.default] user_pref("browser.search.defaulturl", "http://www7.yoog.com/search.php?q="); - DELETED user.js [perso - 40n0e0kl.default] user_pref("browser.search.selectedEngine", "Yoog Search"); - DELETED user.js [perso - 40n0e0kl.default] user_pref("keyword.URL", "http://www7.yoog.com/search.php?q="); - DELETED user.js [perso - umg3myft.default] user_pref("browser.search.defaultenginename", "Yoog Search"); - DELETED user.js [perso - umg3myft.default] user_pref("browser.search.defaulturl", "http://www7.yoog.com/search.php?q="); - DELETED user.js [perso - umg3myft.default] user_pref("browser.search.selectedEngine", "Yoog Search"); - DELETED user.js [perso - umg3myft.default] user_pref("keyword.URL", "http://www7.yoog.com/search.php?q="); - DELETED
----------\\ Suppression dans le registre
[HKEY_USERS\S-1-5-21-823518204-842925246-854245398-1004\..\SearchScopes],@DefaultScope={52CEC30F-DCB7-4E18-A75A-61574B77285D} - DELETED [HKEY_USERS\S-1-5-21-823518204-842925246-854245398-1004\..\SearchScopes\{52CEC30F-DCB7-4E18-A75A-61574B77285D}],@DisplayName=Yoog Search - NOT DELETED
----------\\ Fichiers temporaires
Est ce qu'il y a d'autres choses à faire.
|
|
Posté le 12/05/2009 à 22:00 |
Grand Maître astucien | |
|
Posté le 13/05/2009 à 14:03 |
Nouvel astucien
| Bonjour,
J'ai effectué le pré-nettoyage et voici les rapports :
Malwarebytes' Anti-Malware 1.36 Version de la base de données: 2061 Windows 5.1.2600 Service Pack 3
13/05/2009 13:41:10 mbam-log-2009-05-13 (13-41-10).txt
Type de recherche: Examen complet (C:\|D:\|) Eléments examinés: 169126 Temps écoulé: 58 minute(s), 48 second(s)
Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 0 Clé(s) du Registre infectée(s): 2 Valeur(s) du Registre infectée(s): 0 Elément(s) de données du Registre infecté(s): 0 Dossier(s) infecté(s): 0 Fichier(s) infecté(s): 1
Processus mémoire infecté(s): (Aucun élément nuisible détecté)
Module(s) mémoire infecté(s): (Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s): HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79b586f2-6e92-0487-9208-bc3b89959244} (Adware.Adrotator) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{79b586f2-6e92-0487-9208-bc3b89959244} (Adware.Adrotator) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s): (Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté)
Dossier(s) infecté(s): (Aucun élément nuisible détecté)
Fichier(s) infecté(s): C:\WINDOWS\system32\brphdlsaqfnu.dll (Adware.Adrotator) -> Quarantined and deleted successfully.
et voilà celui d'Hijackthis
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:50:11, on 13/05/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16827) Boot mode: Normal
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\ibmpmsvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\S24EvMon.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\WINDOWS\AGRSMMSG.exe C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe C:\WINDOWS\system32\CRYPSERV.EXE C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\McAfee\SiteAdvisor\McSACore.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe C:\Program Files\IBM\Bluetooth Software\BTTray.exe C:\PROGRA~1\MICROS~3\rapimgr.exe C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\McAfee\MSK\MskSrver.exe C:\Program Files\CDBurnerXP\NMSAccessU.exe C:\WINDOWS\system32\RegSrvc.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\OrangeHSS\systray\systrayapp.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe C:\WINDOWS\system32\NOTEPAD.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" -s O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -scheduler O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Fichiers communs\logishrd\WUApp32.exe -v 0x046d -p 0x08c1 -f video -m logitech -d 11.0.0.1217 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Fichiers communs\logishrd\WUApp32.exe -v 0x046d -p 0x08c1 -f video -m logitech -d 11.0.0.1217 (User 'Default user') O4 - Global Startup: BTTray.lnk = ? O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\IBM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\IBM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=about:blank O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,4982/mcfscan.cab O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = get.com O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\CRYPSERV.EXE O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe O23 - Service: Service Google Update (gupdate1c9d003cfb1b2b0) (gupdate1c9d003cfb1b2b0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Process Monitor (LVPrcSrv) - Unknown owner - (no file) O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
-- End of file - 12672 bytes
|
|
Posté le 13/05/2009 à 14:14 |
Grand Maître astucien | Bonjour
MBAM a supprimé encore un intrus. Tu relances Hijackthis par Do a system scan only, sans autre application lancée. Coche la ligne suivante :
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
Clique sur Fix checked et referme le programme.
Il faut procéder à la mise à jour des programmes suivants
-Java Runtime Environment (JRE)6u13 : http://java.sun.com/javase/downloads/index.jsp Clique sur Download Java Runtime Environment (JRE) 6 update13 Dans la page suivante, choisis Windows dans Platform coche I agree to the Java SE Runtime Environment 6 License Agreement et Continue Dans la nouvelle page, coche Windows Offline Installation, et clique sur jre-6u13-windows-i586-p.exe //15.53 MB. Tu l'installeras hors connexion. Par Ajout/Suppression des programmes, tu désinstalles toutes les autres versions si présentes.
Rencontres-tu encore des problèmes ? @+ |
|
Posté le 13/05/2009 à 18:31 |
Nouvel astucien
| Bonsoir,
Tout semble régler. Je te remercie ton aide rapide et efficace.
Cordialement |
|