Aide pour désinistaller Ask toolbar svp :)
jack38
-
jack38 -
jack38 -
Bonjour,
je souhaiterai désinstaller Ask Toolbar, car cliquer sur désinstaller ne suffit pas à désinstaller cette m****, surtout que je suis sur mon pc de boulot.
voici le rapport de scan.
j'aurai aimé aussi le viré sur Internet Explorer (7)
Merci beaucoup ! :)
======= REPORT FROM AD-REMOVER 2.0.0.2,D | ONLY XP/VISTA/7 =======
Updated by TeamXscript on 29/01/11 at 16:00
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
website: http://www.teamxscript.org
C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Launched at 15:25:59 on 02/02/2011, Normal boot
Microsoft Windows XP Professional Service Pack 3 (X86)
aaudouar@CZC0196NFV ( )
============== SEARCH ==============
Service: "Application Updater" Service found
File found: C:\Program Files\Mozilla Firefox\extensions\searchsettings@spigot.com
File found: C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
Folder found: C:\Documents and Settings\aaudouar\Application Data\Mozilla\FireFox\Profiles\a5qrw7c5.default\extensions\toolbar@ask.com
Folder found: C:\Program Files\Ask.com
Folder found: C:\Documents and Settings\aaudouar\Local Settings\Application Data\AskToolbar
Folder found: C:\Program Files\Application Updater
Folder found: C:\Program Files\FunWebProducts
Folder found: C:\Documents and Settings\aaudouar\Application Data\pdfforge
Folder found: C:\Program Files\pdfforge Toolbar
Folder found: C:\Documents and Settings\aaudouar\Application Data\Search Settings
-- File opened: C:\Documents and Settings\aaudouar\Application Data\Mozilla\FireFox\Profiles\a5qrw7c5.default\Prefs.js --
Line found: user_pref("extensions.asktb.cbid", "AG");
Line found: user_pref("extensions.asktb.crumb", "2011.02.02+03.36.37-toolbar002iad-FR-UGFyaXMsRnJhbmNl");
Line found: user_pref("extensions.asktb.default-channel-url-mask", "hxxp://fr.ask.com/web?q={query}&qsrc={qsrc}&...
Line found: user_pref("extensions.asktb.dtid", "YYYYYYYYFR");
Line found: user_pref("extensions.asktb.fresh-install", false);
Line found: user_pref("extensions.asktb.l", "dis");
Line found: user_pref("extensions.asktb.last-config-req", "1296656266817");
Line found: user_pref("extensions.asktb.locale", "en_FR");
Line found: user_pref("extensions.asktb.o", "15084");
Line found: user_pref("extensions.asktb.options-lang", "en");
Line found: user_pref("extensions.asktb.options-locale", "UK");
Line found: user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
Line found: user_pref("extensions.asktb.qsrc", "2871");
Line found: user_pref("extensions.asktb.r", "4");
Line found: user_pref("extensions.asktb.search-suggestions-enabled", true);
Line found: user_pref("extensions.enabledItems", "{dc572301-7619-498c-a57d-39143191b318}:0.3.8.4,searchsettings@...
-- File closed --
Key found: HKLM\Software\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key found: HKLM\Software\Classes\CLSID\{601ac3dc-786a-4eb0-bf40-ee3521e70bfb}
Key found: HKLM\Software\Classes\CLSID\{72b3882f-453a-4633-aac9-8c3dced62aff}
Key found: HKLM\Software\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key found: HKLM\Software\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key found: HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key found: HKLM\Software\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
Key found: HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key found: HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key found: HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key found: HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key found: HKLM\Software\Classes\TypeLib\{39CAFD20-BAFF-454D-A94C-7115710AE6E3}
Key found: HKLM\Software\Classes\BHO.HelperObject
Key found: HKLM\Software\Classes\BHO.HelperObject.1
Key found: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd
Key found: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd.1
Key found: HKLM\Software\Classes\AppID\GenericAskToolbar.DLL
Key found: HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key found: HKLM\Software\Classes\AppID\BHO.dll
Key found: HKLM\Software\Classes\AppID\{59AEAD8A-6822-4794-AF2E-8CC27312E26E}
Key found: HKLM\Software\Application Updater
Key found: HKLM\Software\pdfforge
Key found: HKLM\Software\Search Settings
Key found: HKCU\Software\Ask.com
Key found: HKCU\Software\AskToolbar
Key found: HKCU\Software\pdfforge
Key found: HKCU\Software\Search Settings
Key found: HKCU\Software\AppDataLow\AskToolbarInfo
Key found: HKCU\Software\AppDataLow\Software\pdfforge
Key found: HKLM\Software\Classes\Installer\Products\3D7B197543B881247905A6E8540DDA23
Key found: HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\3D7B197543B881247905A6E8540DDA23
Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
Key found: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
Key found: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5791B7D3-8B34-4218-9750-6A8E45D0AD32}
Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
Key found: HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Search
Key found: HKLM\Software\Classes\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239}
Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
Key found: HKLM\Software\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Value found: HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SearchSettings
Value found: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Value found: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{D4027C7F-154A-4066-A1AD-4243D8127440}
Value found: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{B922D405-6D13-4A2B-AE89-08A030DA4402}
Value found: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D4027C7F-154A-4066-A1AD-4243D8127440}
============== ADDITIONNAL SCAN ==============
** Mozilla Firefox Version [3.6.13 (fr)] **
-- C:\Documents and Settings\aaudouar\Application Data\Mozilla\FireFox\Profiles\a5qrw7c5.default\Prefs.js --
browser.download.lastDir, C:\\Documents and Settings\\aaudouar\\My Documents\\Perso\\Mes images-perso
browser.startup.homepage, hxxp://be.agilent.com
browser.startup.homepage_override.mstone, rv:1.9.2.13
========================================
** Internet Explorer Version [7.0.5730.13] **
[HKCU\Software\Microsoft\Internet Explorer\Main]
Do404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search bar: hxxp://be.agilent.com
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Show_ToolBar: yes
Start Page: be.agilent.com
[HKLM\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Delete_Temp_Files_On_Exit: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157
[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
Blank: res://mshtml.dll/blank.htm
========================================
C:\Program Files\Ad-Remover\Quarantine: 0 File(s)
C:\Program Files\Ad-Remover\Backup: 1 File(s)
C:\Ad-Report-SCAN[1].txt - 02/02/2011 (7212 Byte(s))
End at: 15:26:19, 02/02/2011
============== E.O.F ==============
je souhaiterai désinstaller Ask Toolbar, car cliquer sur désinstaller ne suffit pas à désinstaller cette m****, surtout que je suis sur mon pc de boulot.
voici le rapport de scan.
j'aurai aimé aussi le viré sur Internet Explorer (7)
Merci beaucoup ! :)
======= REPORT FROM AD-REMOVER 2.0.0.2,D | ONLY XP/VISTA/7 =======
Updated by TeamXscript on 29/01/11 at 16:00
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
website: http://www.teamxscript.org
C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Launched at 15:25:59 on 02/02/2011, Normal boot
Microsoft Windows XP Professional Service Pack 3 (X86)
aaudouar@CZC0196NFV ( )
============== SEARCH ==============
Service: "Application Updater" Service found
File found: C:\Program Files\Mozilla Firefox\extensions\searchsettings@spigot.com
File found: C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
Folder found: C:\Documents and Settings\aaudouar\Application Data\Mozilla\FireFox\Profiles\a5qrw7c5.default\extensions\toolbar@ask.com
Folder found: C:\Program Files\Ask.com
Folder found: C:\Documents and Settings\aaudouar\Local Settings\Application Data\AskToolbar
Folder found: C:\Program Files\Application Updater
Folder found: C:\Program Files\FunWebProducts
Folder found: C:\Documents and Settings\aaudouar\Application Data\pdfforge
Folder found: C:\Program Files\pdfforge Toolbar
Folder found: C:\Documents and Settings\aaudouar\Application Data\Search Settings
-- File opened: C:\Documents and Settings\aaudouar\Application Data\Mozilla\FireFox\Profiles\a5qrw7c5.default\Prefs.js --
Line found: user_pref("extensions.asktb.cbid", "AG");
Line found: user_pref("extensions.asktb.crumb", "2011.02.02+03.36.37-toolbar002iad-FR-UGFyaXMsRnJhbmNl");
Line found: user_pref("extensions.asktb.default-channel-url-mask", "hxxp://fr.ask.com/web?q={query}&qsrc={qsrc}&...
Line found: user_pref("extensions.asktb.dtid", "YYYYYYYYFR");
Line found: user_pref("extensions.asktb.fresh-install", false);
Line found: user_pref("extensions.asktb.l", "dis");
Line found: user_pref("extensions.asktb.last-config-req", "1296656266817");
Line found: user_pref("extensions.asktb.locale", "en_FR");
Line found: user_pref("extensions.asktb.o", "15084");
Line found: user_pref("extensions.asktb.options-lang", "en");
Line found: user_pref("extensions.asktb.options-locale", "UK");
Line found: user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
Line found: user_pref("extensions.asktb.qsrc", "2871");
Line found: user_pref("extensions.asktb.r", "4");
Line found: user_pref("extensions.asktb.search-suggestions-enabled", true);
Line found: user_pref("extensions.enabledItems", "{dc572301-7619-498c-a57d-39143191b318}:0.3.8.4,searchsettings@...
-- File closed --
Key found: HKLM\Software\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key found: HKLM\Software\Classes\CLSID\{601ac3dc-786a-4eb0-bf40-ee3521e70bfb}
Key found: HKLM\Software\Classes\CLSID\{72b3882f-453a-4633-aac9-8c3dced62aff}
Key found: HKLM\Software\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key found: HKLM\Software\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key found: HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key found: HKLM\Software\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
Key found: HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key found: HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key found: HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key found: HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key found: HKLM\Software\Classes\TypeLib\{39CAFD20-BAFF-454D-A94C-7115710AE6E3}
Key found: HKLM\Software\Classes\BHO.HelperObject
Key found: HKLM\Software\Classes\BHO.HelperObject.1
Key found: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd
Key found: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd.1
Key found: HKLM\Software\Classes\AppID\GenericAskToolbar.DLL
Key found: HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key found: HKLM\Software\Classes\AppID\BHO.dll
Key found: HKLM\Software\Classes\AppID\{59AEAD8A-6822-4794-AF2E-8CC27312E26E}
Key found: HKLM\Software\Application Updater
Key found: HKLM\Software\pdfforge
Key found: HKLM\Software\Search Settings
Key found: HKCU\Software\Ask.com
Key found: HKCU\Software\AskToolbar
Key found: HKCU\Software\pdfforge
Key found: HKCU\Software\Search Settings
Key found: HKCU\Software\AppDataLow\AskToolbarInfo
Key found: HKCU\Software\AppDataLow\Software\pdfforge
Key found: HKLM\Software\Classes\Installer\Products\3D7B197543B881247905A6E8540DDA23
Key found: HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\3D7B197543B881247905A6E8540DDA23
Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
Key found: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
Key found: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5791B7D3-8B34-4218-9750-6A8E45D0AD32}
Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key found: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
Key found: HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Search
Key found: HKLM\Software\Classes\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239}
Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
Key found: HKLM\Software\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Value found: HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SearchSettings
Value found: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Value found: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{D4027C7F-154A-4066-A1AD-4243D8127440}
Value found: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{B922D405-6D13-4A2B-AE89-08A030DA4402}
Value found: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D4027C7F-154A-4066-A1AD-4243D8127440}
============== ADDITIONNAL SCAN ==============
** Mozilla Firefox Version [3.6.13 (fr)] **
-- C:\Documents and Settings\aaudouar\Application Data\Mozilla\FireFox\Profiles\a5qrw7c5.default\Prefs.js --
browser.download.lastDir, C:\\Documents and Settings\\aaudouar\\My Documents\\Perso\\Mes images-perso
browser.startup.homepage, hxxp://be.agilent.com
browser.startup.homepage_override.mstone, rv:1.9.2.13
========================================
** Internet Explorer Version [7.0.5730.13] **
[HKCU\Software\Microsoft\Internet Explorer\Main]
Do404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search bar: hxxp://be.agilent.com
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Show_ToolBar: yes
Start Page: be.agilent.com
[HKLM\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Delete_Temp_Files_On_Exit: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157
[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
Blank: res://mshtml.dll/blank.htm
========================================
C:\Program Files\Ad-Remover\Quarantine: 0 File(s)
C:\Program Files\Ad-Remover\Backup: 1 File(s)
C:\Ad-Report-SCAN[1].txt - 02/02/2011 (7212 Byte(s))
End at: 15:26:19, 02/02/2011
============== E.O.F ==============
A voir également:
- Aide pour désinistaller Ask toolbar svp :)
- Google toolbar - Télécharger - Navigateurs
- Google toolbar firefox - Télécharger - Outils pour navigateurs
- Ask photo - Accueil - Photo
- Babylon toolbar ✓ - Forum Virus
- Google toolbar notifier - Forum Virus
3 réponses
Salut
1) /!\ Déconnecte-toi d'internet et ferme toutes applications en cours /!\
* Double-clique sur l'icône Ad-remover située sur ton Bureau.
* Sur la page, clique sur le bouton « Nettoyer »
* Confirme l'opération
* Poste le rapport qui apparaît à la fin.
* (Le rapport est sauvegardé aussi sous C:\Ad-report.)
* (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
ensuite
2) * Télécharge ZHPDiag (de Nicolas coolman)
* ZHPDiag est un outil de diagnostic (Réalisé par Nicolas Coolman) .
Le logiciel permet d'effectuer un diagnostic rapide et complet de son système d'exploitation plus complet qu un rapport d'HijackThis
Il scrute ta Base de Registre et énumère les zones sensibles qui sont susceptibles d'être infectées.
ICI >> ZHPDiag (de Nicolas coolman)
* Une fois le téléchargement achevé,
* double clique sur ZHPDiag.exe et suis les instructions.
* /!\Utilisateurs de Windows Vista et Windows 7
* >> Clique droit sur le logo de ZHPDiag.exe, « exécuter en tant qu'Administrateur »
* Laisse toi guider lors de l'installation,
* coche >> créer une icône sur le bureau
* il se lancera automatiquement à la fin.
* Clique sur l'icône représentant une loupe (« Lancer le diagnostic »)
* Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
* Héberge le rapport sur ce site,
>> Cijoint.fr
* puis copie/colle le lien fourni dans ta prochaine réponse sur le forum.
* Pour t aider ,pour heberger le rapport
* rends toi sur Cijoint.fr
* clic sur Parcourir
* trouve >> le rapport que tu viens d'enregistrer qui doit par exemple être sur ton bureau
* et valide en cliquant sur >> Cliquez ici pour déposer le Fichier
* un lien de ce genre http://www.cijoint.fr/cjlink.php?file=cj201004/cijecaEGX.txt te sera généré,
* il te suffit de le poster ici pour que je puisse voir le rapport
Membre Contributeur sécurité CCM
1) /!\ Déconnecte-toi d'internet et ferme toutes applications en cours /!\
* Double-clique sur l'icône Ad-remover située sur ton Bureau.
* Sur la page, clique sur le bouton « Nettoyer »
* Confirme l'opération
* Poste le rapport qui apparaît à la fin.
* (Le rapport est sauvegardé aussi sous C:\Ad-report.)
* (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
ensuite
2) * Télécharge ZHPDiag (de Nicolas coolman)
* ZHPDiag est un outil de diagnostic (Réalisé par Nicolas Coolman) .
Le logiciel permet d'effectuer un diagnostic rapide et complet de son système d'exploitation plus complet qu un rapport d'HijackThis
Il scrute ta Base de Registre et énumère les zones sensibles qui sont susceptibles d'être infectées.
ICI >> ZHPDiag (de Nicolas coolman)
* Une fois le téléchargement achevé,
* double clique sur ZHPDiag.exe et suis les instructions.
* /!\Utilisateurs de Windows Vista et Windows 7
* >> Clique droit sur le logo de ZHPDiag.exe, « exécuter en tant qu'Administrateur »
* Laisse toi guider lors de l'installation,
* coche >> créer une icône sur le bureau
* il se lancera automatiquement à la fin.
* Clique sur l'icône représentant une loupe (« Lancer le diagnostic »)
* Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
* Héberge le rapport sur ce site,
>> Cijoint.fr
* puis copie/colle le lien fourni dans ta prochaine réponse sur le forum.
* Pour t aider ,pour heberger le rapport
* rends toi sur Cijoint.fr
* clic sur Parcourir
* trouve >> le rapport que tu viens d'enregistrer qui doit par exemple être sur ton bureau
* et valide en cliquant sur >> Cliquez ici pour déposer le Fichier
* un lien de ce genre http://www.cijoint.fr/cjlink.php?file=cj201004/cijecaEGX.txt te sera généré,
* il te suffit de le poster ici pour que je puisse voir le rapport
Membre Contributeur sécurité CCM
jack, on reprend ici
On va vérifier s'il y a pas d'autres infections
* Télécharge ZHPDiag (de Nicolas Coolman)
https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
Au cas où le premier lien ne marcherai pas, clique sur celui de dessous
ftp://zebulon.fr/ZHPDiag.exe
* Laisse toi guider lors de l'installation, il se lancera automatiquement à la fin.
* Clique sur l'icône représentant une loupe (« Lancer le diagnostic »)
* Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
Héberge le rapport ICI
On va vérifier s'il y a pas d'autres infections
* Télécharge ZHPDiag (de Nicolas Coolman)
https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
Au cas où le premier lien ne marcherai pas, clique sur celui de dessous
ftp://zebulon.fr/ZHPDiag.exe
* Laisse toi guider lors de l'installation, il se lancera automatiquement à la fin.
* Clique sur l'icône représentant une loupe (« Lancer le diagnostic »)
* Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
Héberge le rapport ICI
le truc c'est que je n'ai pas trop envie d'installer d'autre outils sur ce pc c'est un pc qui appartient à mon boulot, je n'ai pas le droit, surtout si c'est un soft pour lire les clés etc...
si jamais j'ai d'autres soucis ou que des trucs bizarre se reproduisent, je le ferai.
là c'est en voulant installer une imprimante pdf que ça s'est installé, j'essaie juste de récupérer ma bêtise.
Merci quand même ! :-)
si jamais j'ai d'autres soucis ou que des trucs bizarre se reproduisent, je le ferai.
là c'est en voulant installer une imprimante pdf que ça s'est installé, j'essaie juste de récupérer ma bêtise.
Merci quand même ! :-)
En effet, mais cela doit se faire en respectant la procédure décrite ici : https://www.commentcamarche.net/faq/25714-desinstaller-ask-toolbar ...
:)
J'ai fait nettoyer, mais ça m'a tout planté à 35%, j'ai dû tuer le programme et relancer un explorer !
j'essaie encore et vous tien au courant.
merci
voici le rapport:
======= REPORT FROM AD-REMOVER 2.0.0.2,D | ONLY XP/VISTA/7 =======
Updated by TeamXscript on 29/01/11 at 16:00
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
website: http://www.teamxscript.org
C:\Program Files\Ad-Remover\main.exe (CLEAN [2]) -> Launched at 15:55:00 on 02/02/2011, Normal boot
Microsoft Windows XP Professional Service Pack 3 (X86)
aaudouar@CZC0196NFV ( )
============== ACTION(S) ==============
Folder deleted: C:\Program Files\Ask.com
Folder deleted: C:\Documents and Settings\aaudouar\Local Settings\Application Data\AskToolbar
Folder deleted: C:\Program Files\Application Updater
Folder deleted: C:\Program Files\FunWebProducts
Folder deleted: C:\Documents and Settings\aaudouar\Application Data\pdfforge
Folder deleted: C:\Program Files\pdfforge Toolbar
Folder deleted: C:\Documents and Settings\aaudouar\Application Data\Search Settings
(!) -- Temporary files deleted.
-- File opened: C:\Documents and Settings\aaudouar\Application Data\Mozilla\FireFox\Profiles\a5qrw7c5.default\Prefs.js --
Line deleted: user_pref("extensions.asktb.cbid", "AG");
Line deleted: user_pref("extensions.asktb.crumb", "2011.02.02+03.36.37-toolbar002iad-FR-UGFyaXMsRnJhbmNl");
Line deleted: user_pref("extensions.asktb.default-channel-url-mask", "hxxp://fr.ask.com/web?q={query}&qsrc={qsrc}&...
Line deleted: user_pref("extensions.asktb.dtid", "YYYYYYYYFR");
Line deleted: user_pref("extensions.asktb.fresh-install", false);
Line deleted: user_pref("extensions.asktb.l", "dis");
Line deleted: user_pref("extensions.asktb.last-config-req", "1296656266817");
Line deleted: user_pref("extensions.asktb.locale", "en_FR");
Line deleted: user_pref("extensions.asktb.o", "15084");
Line deleted: user_pref("extensions.asktb.options-lang", "en");
Line deleted: user_pref("extensions.asktb.options-locale", "UK");
Line deleted: user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
Line deleted: user_pref("extensions.asktb.qsrc", "2871");
Line deleted: user_pref("extensions.asktb.r", "4");
Line deleted: user_pref("extensions.asktb.search-suggestions-enabled", true);
-- File closed --
Key deleted: HKLM\Software\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key deleted: HKLM\Software\Classes\CLSID\{601ac3dc-786a-4eb0-bf40-ee3521e70bfb}
Key deleted: HKLM\Software\Classes\CLSID\{72b3882f-453a-4633-aac9-8c3dced62aff}
Key deleted: HKLM\Software\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key deleted: HKLM\Software\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key deleted: HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key deleted: HKLM\Software\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
Key deleted: HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key deleted: HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key deleted: HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key deleted: HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key deleted: HKLM\Software\Classes\TypeLib\{39CAFD20-BAFF-454D-A94C-7115710AE6E3}
Key deleted: HKLM\Software\Classes\BHO.HelperObject
Key deleted: HKLM\Software\Classes\BHO.HelperObject.1
Key deleted: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd
Key deleted: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd.1
Key deleted: HKLM\Software\Classes\AppID\GenericAskToolbar.DLL
Key deleted: HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key deleted: HKLM\Software\Classes\AppID\BHO.dll
Key deleted: HKLM\Software\Classes\AppID\{59AEAD8A-6822-4794-AF2E-8CC27312E26E}
Key deleted: HKLM\Software\Application Updater
Key deleted: HKLM\Software\pdfforge
Key deleted: HKLM\Software\Search Settings
Key deleted: HKCU\Software\Ask.com
Key deleted: HKCU\Software\AskToolbar
Key deleted: HKCU\Software\pdfforge
Key deleted: HKCU\Software\Search Settings
Key deleted: HKCU\Software\AppDataLow\AskToolbarInfo
Key deleted: HKCU\Software\AppDataLow\Software\pdfforge
Key deleted: HKLM\Software\Classes\Installer\Products\3D7B197543B881247905A6E8540DDA23
Key deleted: HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\3D7B197543B881247905A6E8540DDA23
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
Key deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
Key deleted: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5791B7D3-8B34-4218-9750-6A8E45D0AD32}
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
Key deleted: HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Search
Key deleted: HKLM\Software\Classes\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239}
Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
Key deleted: HKLM\Software\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Value deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SearchSettings
Value deleted: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Value deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{D4027C7F-154A-4066-A1AD-4243D8127440}
Value deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{B922D405-6D13-4A2B-AE89-08A030DA4402}
Value deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D4027C7F-154A-4066-A1AD-4243D8127440}
============== ADDITIONNAL SCAN ==============
** Mozilla Firefox Version [3.6.13 (fr)] **
-- C:\Documents and Settings\aaudouar\Application Data\Mozilla\FireFox\Profiles\a5qrw7c5.default\Prefs.js --
browser.download.lastDir, C:\\Documents and Settings\\aaudouar\\My Documents\\Perso\\Mes images-perso
browser.startup.homepage, hxxp://be.agilent.com
browser.startup.homepage_override.mstone, rv:1.9.2.13
========================================
** Internet Explorer Version [7.0.5730.13] **
[HKCU\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Do404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Show_ToolBar: yes
Start Page: hxxp://fr.msn.com/
[HKLM\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Delete_Temp_Files_On_Exit: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
Blank: res://mshtml.dll/blank.htm
========================================
C:\Program Files\Ad-Remover\Quarantine: 257 File(s)
C:\Program Files\Ad-Remover\Backup: 16 File(s)
C:\Ad-Report-CLEAN[1].txt - 02/02/2011 (652 Byte(s))
C:\Ad-Report-CLEAN[2].txt - 02/02/2011 (7057 Byte(s))
C:\Ad-Report-SCAN[1].txt - 02/02/2011 (8816 Byte(s))
End at: 15:55:29, 02/02/2011
============== E.O.F ==============
*/!\ Déconnectez-vous et fermez toutes les applications en cours /!\
Pour la suite, tu peux t'en remettre à ce que dit VIRUS-C-C