Fenêtres publicitaire, spyware ... ? - Page 2

Précédent
  • 1
  • 2
Fankine
 
Voila le rapport, ça n'a pas été trop long =P

1. ========================= SEAF 1.0.0.6 - C_XX | 19:50:03,74
2.
3. Valeur(s) recherchée(s):
4.
5. Adssite
6.
7.
8. ========================= Fichier(s)/Dossier(s):
9.
10. (!) --- 0 ligne(s) contenant la/les valeur(s) recherchée(s).
11. "C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Data\ports_mail.dat"
12. MD5: c305ed976c9e6285a6ccbdafebed305e | --a------ | 09/07/2009 19:08
13.
14. =========================
15.
16. (!) --- 1 ligne(s) contenant la/les valeur(s) recherchée(s).
17. "C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Report\05\00000001_objdt.dat"
18. MD5: DENIED | --a------ | 28/09/2009 12:13
19.
20. =========================
21.
22. (!) --- 1 ligne(s) contenant la/les valeur(s) recherchée(s).
23. "C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab\AVP9\Report\05\00000009_objdt.dat"
24. MD5: DENIED | --a------ | 08/01/2010 19:52
25.
26. =========================
27.
28. (!) --- 1 ligne(s) contenant la/les valeur(s) recherchée(s).
29. "C:\ToolBar SD\Fich.cmd"
30. MD5: 7aea8a151ba08911b5402f873cecc0fb | --a------ | 21/12/2008 20:40
31.
32. =========================
33.
34.
35. ========================= Registre:
36.
37.
38.
39. [HKEY_CLASSES_ROOT\optimizer.adssite2\CurVer]
40. ""="optimizer.adssite2.1"
41.
42. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\optimizer.adssite2\CurVer]
43. ""="optimizer.adssite2.1"
44.
45.
46. ========================= E.O.F | 19:58:14,19

Fankine
0
crapoulou Messages postés 28002 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   8 047
 
Qu'y a-t-il dans ce dossier ?
C:\Program Files\IndisputablyBetterBrowsingExperienceTool

*********

Pour supprimer le service sous XP :
Clique sur Démarrer puis Exécuter
Tape ceci dans la petite fenêtre qui s’est ouverte :
cmd
Dans la fenêtre noire qui s’affiche, tape ceci :
sc stop mchInjDrv
Puis tape sur Entrée.
sc delete mchInjDrv
Puis tape sur Entrée à nouveau.
Ferme ensuite la fenêtre noire.

********
Supprime ceci :
play2p.lnk

de ce dossier :
C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage

**********

/!\ Procédure réservée à ????????. Ne tentez pas de la reproduire si vous avez un problème similaire sous peine de planter votre machine /!\
Télécharge OTM (de Old_Timer) sur ton Bureau.
= = = = >>> En cliquant ici <<< = = = =
Une fois installé sur le bureau, double-clique sur OTMoveIt.exe pour le lancer.
Assure toi que la case Unregister Dll’s and Ocx’s soit bien cochée
Copie la liste qui se trouve en gras ci-dessous, et colle-la dans le cadre de gauche de OTMoveIt :
Paste Instructions for Items to be moved.

:Processes
explorer.exe

:Files
C:\WINDOWS\system32\cf8cc459-23b1-1106-9315-bb13ec9c902f.dll
C:\WINDOWS\system32\e8a47fb3-e45f-bec7-d7f5-6b4b2b9791e3.exe
C:\WINDOWS\system32\^^^^^^.exe

:reg
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d82ac558-396d-11de-8f99-001d602932d6}]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\^^^^^^.exe"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"nwiz"=-
"QuickTime Task"=-
"iTunesHelper"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5132f24c-e59b-92d9-d6d7-87d778e69f8a}]

:Commands
[purity]
[emptytemp]
[Reboot]


Clique sur MoveIt! pour lancer la suppression.
Après avoir fait Moveit!, une fenêtre s’affiche :
"The system requires a reboot to finish removing files. Do you want to reboot now ?"
Réponds Yes.
Le résultat apparaîtra dans le cadre "Results".
Clique sur Exit pour fermer.
Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
0
Fankine
 
Il y a juste un uninstal... ( j'avais deja supprimier l'adware via suppression de programmes )

Par contre l'invte de commande me dit que le service spécifié n'existe pas en tant que service installé

J'ai supprimé le fichier Play2p

Voici le rapport d'OTM

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
C:\WINDOWS\system32\cf8cc459-23b1-1106-9315-bb13ec9c902f.dll moved successfully.
C:\WINDOWS\system32\e8a47fb3-e45f-bec7-d7f5-6b4b2b9791e3.exe moved successfully.
File/Folder C:\WINDOWS\system32\^^^^^^.exe not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\WINDOWS\system32\^^^^^^.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\nwiz deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrateur
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32768 bytes
->FireFox cache emptied: 20756 bytes

User: All Users

User: All Users.WINDOWS

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Dream Team
->Temp folder emptied: 2639918 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Dream Team.ORDINATEUR
->Temp folder emptied: 2355613 bytes
->Temporary Internet Files folder emptied: 61306806 bytes
->Java cache emptied: 44466405 bytes
->FireFox cache emptied: 83727352 bytes

User: DREAMT~1~ORD

User: Epoxy Dream

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 255969 bytes

User: LocalService.AUTORITE NT
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes

User: LocalService.AUTORITE NT.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 10966631 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 98692 bytes

User: NetworkService.AUTORITE NT
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes

User: NetworkService.AUTORITE NT.000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 646391 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 24 bytes
%systemroot%\System32 .tmp files removed: 4182528 bytes
Windows Temp folder emptied: 895623893 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 36241 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1 055,00 mb

OTM by OldTimer - Version 3.1.4.0 log created on 01092010_202822

Files moved on Reboot...
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\BXCSLRN1\432&ga_sid=1261062078&ga_hid=1773275443&ga_fc=1&u_tz=60&u_his=3&u_java=1&u_h=1024&u_w=1280&u_ah=1002&u_aw=1280&u_cd=32&u_nplug=0&u_nmime=0&biw=1259&bih=832&fu=0&ifi=1&dtd=31 not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\BXCSLRN1\adlink%7C224%7C2333768%7C0%7C170%7CAdId%3D2743529%3BBnId%3D2%3Bitime%3D67039162%3Blink%3Dhttp%3A%2F%2Fmedia%2Efastclick%2Enet%2Fw%2Fclick%2Ehere%3Fcid%3D206487%26mid[2] not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\BXCSLRN1\adlink%7C224%7C2333768%7C0%7C170%7CAdId%3D2743529%3BBnId%3D2%3Bitime%3D68274151%3Blink%3Dhttp%3A%2F%2Fmedia%2Efastclick%2Enet%2Fw%2Fclick%2Ehere%3Fcid%3D206487%26mid[1] not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\BXCSLRN1\CAXSH2UK.fr%2Fsearch%3Fsourceid%3Dnavclient%26hl%3Dfr%26ie%3DUTF-8%26rlz%3D1T4GGIH_frFR254FR254%26q%3Drecette%2Bgalette%2Bfrangipane&fu=0&ifi=1&dtd=79 not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\BXCSLRN1\id=1716847323&ga_fc=1&u_tz=60&u_his=2&u_java=1&u_h=1024&u_w=1280&u_ah=1002&u_aw=1280&u_cd=32&u_nplug=0&u_nmime=0&biw=-12245933&bih=-12245933&ifk=231638215&fu=0&ifi=1&dtd=610 not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\9TNZEWQ5\8Ko85qf7pGDPRDJ9jBLg14NQAAABrHicdVA_S8NAHP21VbQKteAiuPQDJJfLpX-unRQnFykq1E0uubsmvTQJudR09Gt06eog-CncBD-DiIOL4OxS00rBpfzg8d4b3o_3_GMOtXHs-QHj-vYuELnDKn7FBdj6cqEEMxfKH[1].swf not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\9TNZEWQ5\;bp=OK;var1=;var2=;var3=;var4=;var21=;var22=;var23=;var24=;var25=;var26=;var7=;var8=0;var9=0;var10=0;var11=;var14=;tile=1;sz=300x250;ord=6234170589898180[2] not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\9TNZEWQ5\adlink%7C224%7C2333768%7C0%7C170%7CAdId%3D2743529%3BBnId%3D2%3Bitime%3D67623502%3Blink%3Dhttp%3A%2F%2Fmedia%2Efastclick%2Enet%2Fw%2Fclick%2Ehere%3Fcid%3D206487%26mid[2] not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\8H2R8T67\activity;src=1979018;met=1;v=1;pid=44159207;aid=220478549;ko=0;cid=34744459;rid=34762337;rv=1;&timestamp=1261060559519;eid1=2;ecn1=0;etm1=6;eid2=217844;ecn2=0;etm2=6[1].gif not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\4HIF0XA7\id=1825352587&ga_fc=0&u_tz=60&u_his=60&u_java=1&u_h=1024&u_w=1280&u_ah=1002&u_aw=1280&u_cd=32&u_nplug=0&u_nmime=0&biw=-12245933&bih=-12245933&ifk=608607343&fu=0&ifi=1&dtd=31 not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\3LVSHBZK\;bp=OK;var1=;var2=;var3=;var4=;var21=;var22=;var23=;var24=;var25=;var26=;var7=;var8=0;var9=0;var10=0;var11=;var14=;tile=1;sz=300x250;ord=4380454937757257[2].5 not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\3LVSHBZK\activity;src=1979018;met=1;v=1;pid=44165231;aid=220078532;ko=0;cid=34508918;rid=34526796;rv=1;&timestamp=1261062063410;eid1=2;ecn1=1;etm1=7;eid2=12;ecn2=1;etm2=0;eid[1].gif not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\3LVSHBZK\adlink%7C224%7C2333768%7C0%7C170%7CAdId%3D2743529%3BBnId%3D2%3Bitime%3D67921510%3Blink%3Dhttp%3A%2F%2Fmedia%2Efastclick%2Enet%2Fw%2Fclick%2Ehere%3Fcid%3D206487%26mid[2] not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\0RGFAJ0R\;bp=OK;var1=;var2=;var3=;var4=;var21=;var22=;var23=;var24=;var25=;var26=;var7=;var8=0;var9=0;var10=0;var11=;var14=;tile=1;sz=300x250;ord=3048342845600955[2] not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\0RGFAJ0R\activity;src=1979018;met=1;v=1;pid=44165231;aid=220078532;ko=0;cid=34508918;rid=34526796;rv=1;&timestamp=1261062065988;eid1=2;ecn1=0;etm1=3;eid2=12;ecn2=0;etm2=3;[1].gif not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\0RGFAJ0R\adlink%7C224%7C2333768%7C0%7C170%7CAdId%3D2743529%3BBnId%3D2%3Bitime%3D68553630%3Blink%3Dhttp%3A%2F%2Fmedia%2Efastclick%2Enet%2Fw%2Fclick%2Ehere%3Fcid%3D206487%26mid[2] not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\0RGFAJ0R\CAFC54VA.fr%2Fsearch%3Fsourceid%3Dnavclient%26hl%3Dfr%26ie%3DUTF-8%26rlz%3D1T4GGIH_frFR254FR254%26q%3Drecette%2Bgalette%2Bfrangipane&fu=0&ifi=1&dtd=63 not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\0HANG96R\;bp=OK;var1=;var2=;var3=;var4=;var21=;var22=;var23=;var24=;var25=;var26=;var7=;var8=0;var9=0;var10=0;var11=;var14=;tile=1;sz=300x250;ord=5498127136417928[2] not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\09QV8TEJ\432&ga_sid=1261051432&ga_hid=708757799&ga_fc=1&u_tz=60&u_his=49&u_java=1&u_h=1024&u_w=1280&u_ah=1002&u_aw=1280&u_cd=32&u_nplug=0&u_nmime=0&biw=1259&bih=832&fu=0&ifi=1&dtd=32 not found!
File C:\Documents and Settings\Dream Team.ORDINATEUR\Local Settings\Temp\Temporary Internet Files\Content.IE5\09QV8TEJ\activity;src=1979018;met=1;v=1;pid=44159207;aid=220478549;ko=0;cid=34744459;rid=34762337;rv=1;&timestamp=1261060553550;eid1=2;ecn1=1;etm1=2;eid2=217844;ecn2=1;etm2=0[1].gif not found!

Registry entries deleted on Reboot...

C'est qu'ils sont coriaces ces saloperies :o
0
Fankine
 
Ps: le fichier Thumbs.db je peut le supprimer ?
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
crapoulou Messages postés 28002 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   8 047
 
Quel fichier Thumbs ?
Ce n'est pas nocif, tu peux le laisser ou le supprimer, c'est pour les fichiers audios / vidéos.

Recommence la même étape avec OTM que précédemment mais en mettant ce script stp :

:processes
explorer.exe

:reg
[-HKEY_CLASSES_ROOT\optimizer.adssite2\]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\optimizer.adssite2]

:command
[reboot]

0
crapoulou Messages postés 28002 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   8 047
 
Pas de nouvelle, bonne nouvelle ???
0
Précédent
  • 1
  • 2