Log hijackthis

oo_achille_oo -  
 Utilisateur anonyme -
Bonjour,

j'ai quelques problèmes avec des publicités qui m'ouvrent de nouvelles fenêtres et c'est toujours les mêmes... PLZ aidé moi a résoudre mon problèmes...

voici le log et MERCI pour votre aide...:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:47:48, on 9/11/2009
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\DesktopEarth\DesktopEarth.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.gamingharbor.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Media Access Startup - {25B8D58C-B0CB-46b0-BA64-05B3804E4E86} - C:\Program Files\Media Access Startup\2.1.0.1170\HPIEAddOn.dll
O2 - BHO: NP Helper Class - {35B8D58C-B0CB-46b0-BA64-05B3804E4E86} - C:\Program Files\Internet Saving Optimizer\3.8.1.4690\NPIEAddOn.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: System Search Dispatcher - {CDBFB47B-58A8-4111-BF95-06178DCE326D} - C:\Program Files\System Search Dispatcher\1.4.3.1040\ssd.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O3 - Toolbar: (no name) - {5617ECA9-488D-4BA2-8562-9710B9AB78D2} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] "C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startup
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE RÉSEAU')
O4 - Startup: DesktopEarth AutoStart.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCfox000
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Google Update (gupdate1ca1d3ca40cd04e) (gupdate1ca1d3ca40cd04e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: QueryService Service - Unknown owner - C:\ProgramData\QueryService\queryservice125.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe

--
End of file - 6978 bytes
Configuration: Windows 7
firefox 3.5.5

9 réponses

  1. Utilisateur anonyme
     
    bonjour

    • Télécharge:https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cpVobGk5bHnxrhQ4yaoEUDJvOYNnEGyYjgqHZz5GqZLfutR3fMFPlsC3-CGIilfupPAguYATNyua3csodN_frdMK8sSzUpit10Yac-QJCOkMqJKkbdKcP6ySs8trWPgoNVIq4TGGWCe6o0txXQv-ZueJF9vZzw3RXsGwFYIqN2lvF2LPdQzS8mE1d5kWOVOz6EMzQuE5-lClSJM869uq3oc7-t7yg%3D%3D&attredirects=3
    • !! Déconnectes toi et fermes toute tes applications en cours le temps de la manipe !!
    • Double-cliques sur l'.exe pour lancer l'installe et laisses toi guider
    • Une fois fait, cliques sur le raccourci créé sur ton bureau pour lancer l'outil .
    • Choisis l'option 1 ( "recherche") et tapes "entrée" .
    • Une fois le scan finit , un rapport va apparaître, copie/colles l'intégralité de son contenu dans ta prochaine réponse ...
    • ( le rapport est en outre sauvegardé ici -> C:\TB.txt )
    • Tuto :[ https://sites.google.com/site/toolbarsd/aideenimages toolbarSD]
    0
  2. oo_achille_oo Messages postés 4 Statut Membre
     
    MERCI, je m'y colle de suite
    0
  3. youness321 Messages postés 225 Date d'inscription   Statut Membre Dernière intervention   22
     
    ou sinon tu active le bloqueur de fenetres pop up voila le site
    http://assistance.sfr.fr/internet_neufbox-de-SFR/connexion/bloquer-popup/fc-468-50397
    0
  4. oo_achille_oo Messages postés 4 Statut Membre
     
    Nanard4700: je suit a la lettre ce que tu me dicte et lorsque je choisis l'option 1 et je pousse sur entrée la fenetre se ferme mais rien ne se passe et dans le dossier c:TB, il n'y a rien comme fichier .txt
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Utilisateur anonyme
     
    Fait le en mode sans echec mais choisis directement l'option 2
    Redémarre en mode sans échec
    (Pour cela : démarrer le PC en tapotant sur la touche F8 du clavier jusqu'à ce que le menu des options avancées de Windows apparaisse puis avec les touches fléchées du clavier, sélectionner Mode sans échec puis appuyer sur la touche Entrée...)
    Attention tu n'as pas accès à Internet dans ce mode donc note ou imprime les consignes qui suivent.

    0
  7. oo_achille_oo Messages postés 4 Statut Membre
     
    voila j'ai essayé en MSE et aucun changement cela fais pareil meme avec l'option 2.... il n'est peut etre pas compatible avec windows seven?
    0
  8. Utilisateur anonyme
     
    • Télécharge et enregistre le fichier d installation sur ton bureau :
    http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe
    ou
    https://www.androidworld.fr/
    • Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( le bureau )
    • Ouvre le dossier Ad-remover présent sur ton bureau, et double clique sur Ad-remover.bat.

    * Sous Vista : clic droit sur AD-Remover et sélectionner "Exécuter en tant qu'administrateur"
    • Au menu principal choisi l'option "L" et tape sur [entrée] .
    • Laisse travailler l'outil et ne touche à rien ...
    • Poste le rapport qui apparait à la fin.
    • ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

    (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
    • Note :
    Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis
    entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels
    de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces
    antivirus.

    0
  9. oo_achille_oo Messages postés 4 Statut Membre
     
    bonjour et deso pour le retard mais ces c... qui me servent de FAI etait en greve!!!! (j'le crois pas ca!)...

    enfin voila j'ai effectuer ce que tu m'a demander et voici le rapport:

    .
    ======= LOGFILE OF AD-REMOVER 1.1.4.6_C | ONLY XP/VISTA/7 =======
    .
    Updated by C_XX on 12.11.2009 at 22:02
    Contact: AdRemover.contact@gmail.com
    Website: http://pagesperso-orange.fr/NosTools/ad_remover.html
    .
    Launch at: 4:10:32, ven. 13/11/2009 | Normal Boot | Option: CLEAN
    Executed from: C:\Program Files\Ad-Remover\
    Operating system: Microsoft® Windows 7™ Ultimate v6.1.7600
    Computer Name: JON-PC | Current user: Jon
    .
    ============== NEUTRALIZED ELEMENT(S) ==============
    .

    HKCU\Software\AppDataLow\Software\DoubleD
    HKCU\Software\AskToolbar
    HKCU\Software\Titan Poker
    HKLM\Software\Microsoft\Shared Tools\MSconfig\Startupreg\My Web Search Bar Search Scope Monitor
    HKLM\Software\Microsoft\Shared Tools\MSconfig\Startupreg\MyWebSearch Plugin
    HKLM\Software\Titan Poker
    HKLM\Software\Trymedia Systems
    .
    C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\jm1zqgo5.default\searchplugins\mywebsearch.xml
    C:\Users\Jon\AppData\Roaming\MICROS~1\Windows\Cookies\Low\jon@partypoker[1].txt

    (!) -- Temp files deleted.

    .
    ============== Added scan ==============
    .
    .
    * Mozilla FireFox Version 3.5.5 [fr] *
    .
    ProfilePath: jm1zqgo5.default (Jon)
    .
    (Jon, prefs.js) Browser.download.lastDir, C:\Users\Jon\Desktop
    (Jon, prefs.js) Browser.search.selectedEngine, MyWebSearch
    (Jon, prefs.js) Browser.startup.homepage, hxxp://www.theprizeday.com/today.php|hxxp://funnylogo.info/engines/Google/White/Achille.aspx
    .
    (Jon, prefs.js) ERASED - Browser.search.selectedEngine, MyWebSearch
    (Jon, prefs.js) ERASED - Desktopsmiley.startonce, false
    (Jon, prefs.js) ERASED - Extensions.mywebsearch.openSearchURL, hxxp://search.mywebsearch.com/mywebsearch/opensearch.jhtml?id=ZCfox000&ptb=K.9MtbNEgeETGpqMiqOhXA
    (Jon, prefs.js) ERASED - Extensions.mywebsearch.prevKwdEnabled, true
    (Jon, prefs.js) ERASED - Extensions.mywebsearch.prevKwdURL, chrome://browser-region/locale/region.properties
    (Jon, prefs.js) ERASED - General.useragent.extra.desktopsmiley, desktopsmiley_3_1_6159134544135551_19_78 DS_gamingharbor
    (Jon, prefs.js) ERASED - Keyword.URL, hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCfox000&fl=0&ptb=K.9MtbNEgeETGpqMiqOhXA&url=hxxp://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=
    .
    .
    * Internet Explorer Version 8.0.7600.16385 *
    .
    [HKEY_CURRENT_USER\..\Internet Explorer\Main]
    .
    Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
    Start Page: hxxp://fr.msn.com/
    Start Page Redirect Cache: hxxp://be.msn.com/defaultf.aspx?lang=fr-be&ocid=iehp
    Start Page Redirect Cache_TIMESTAMP: NARY 9286aac82a23ca01
    Start Page Redirect Cache AcceptLangs: fr-be
    Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
    .
    [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
    .
    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    Start Page: hxxp://fr.msn.com/
    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Search bar: hxxp://search.msn.com/spbasic.htm
    .
    [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
    .
    Tabs: res://ieframe.dll/tabswelcome.htm
    .
    ============== Suspect (Cracks, Serials, ...) ==============
    .
    C:\Users\Jon\Downloads\COD_1.4_Patch.rar
    C:\Users\Jon\Downloads\Corel_Paint_Shop_Pro_Photo_X2_(Serial).zip
    C:\Users\Jon\Downloads\Corel_Paint_Shop_Pro_Photo_X2_by_Goldocrack.zip
    C:\Users\Jon\Downloads\Corel_Paint_Shop_Pro_X2_12__2B_Keygen.part1.rar
    C:\Users\Jon\Downloads\crack fl studio 8 by dreck.zip
    C:\Users\Jon\Downloads\Crack7-upbysiskozed.zip
    C:\Users\Jon\Downloads\FIFA10_ticket_patch.rar
    C:\Users\Jon\Downloads\Manager09Patch3_090203b.exe
    C:\Users\Jon\Downloads\Patch_Window_A_0_14.exe
    C:\Users\Jon\Downloads\patchWifi.zip
    .
    ===================================
    .
    3990 Byte(s) - C:\Ad-Report-CLEAN[1].log
    .
    167 File(s) - C:\Users\Jon\AppData\Local\Temp
    0 File(s) - C:\Windows\Temp
    .
    18 File(s) - C:\Program Files\Ad-Remover\BACKUP
    2 File(s) - C:\Program Files\Ad-Remover\QUARANTINE
    .
    End at: 4:15:42 | ven. 13/11/2009 - CLEAN[1]
    .
    ============== E.O.F ==============
    .
    0
  10. Utilisateur anonyme
     
    Bonjour

    • Télécharge : http://images.malwareremoval.com/random/RSIT.exe
    /!\ Important (Sous Vista) /!\
    Vous devez exécuter RSIT avec les droits d'administrateur, pour cela Clique droit sur RSIT et "Lancer en tant qu'administrateur"
    • Double clique sur RSIT.exe pour lancer l'outil.
    • Clique sur 'Continue' à l'écran Disclaimer.
    • Si l'outil Hijackthis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
    • Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports.
    ( C:\RSIT\log.txt et C:\RSIT\info.txt )
    • CTRL A pour sélectionner tout, CTRL C pour copier et puis CTRL V pour coller
    0