Comment supprimer coupon downloader de chrome?

Résolu
lolo -  
Aidemoi7 Messages postés 1 Statut Membre -
Bonjour,
mon navigateur chrome est infecté par multiples fenetres publicitaires et mises a jour bidon.
Suite a ma recherche, j ai utilisé adwcleaner pour un scan et un nettoyage.
voici le lien de mon rapport adw cleaner
http://pjjoint.malekal.com/files.php?id=20140522_r8z1515f8r12

MERCI par avance pour votre aide.

11 réponses

  1. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 711
     
    Salut,

    Faire un Scan OTL - Temps : Environ 40min
    =============================================
    OTL permet de diagnostiquer les programmes qui tournent et déceler des infections - Le programme va générer deux rapports OTL.txt et Extras.txt
    Fournir les deux rapports :

    Tu peux suivre les indications de cette page pour t'aider : https://www.malekal.com/tutorial-otl/

    * Télécharge http://www.geekstogo.com/forum/files/file/398-otl-oldtimers-list-it/ sur ton bureau.
    (Sous Vista/Win7, il faut cliquer droit sur OTL et choisir Exécuter en tant qu'administrateur)

    Dans le cas d'Avast!, ne pas lancer le programme dans la Sandbox (voir lien d'aide ci-dessus).

    * Lance OTL
    * En haut à droite de Analyse rapide, coche "tous les utilisateurs"
    * Clique sur le bouton Analyse.

    **** Si durant le scan - OTL ne répond pas, ne touche à rien et laisse le scan se poursuivre ****

    * Quand le scan est fini, utilise le site http://pjjoint.malekal.com/ pour envoyer le rapport OTL.txt (et Extra.txt si présent).
    Donne le ou les liens pjjoint qui pointent vers ces rapports ici dans une réponse.
    Je répète : donne le lien du rapport pjjoint ici en réponse.

    NE PAS COPIER/COLLER LE RAPPORT ICI - DONNER LE LIEN PJJOINT DANS UN NOUVEAU MESSAGE

    1
  2. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 711
     
    Relance OTL.
    o sous Personnalisation (Custom Scan), copie_colle le contenu du cadre ci dessous (bien prendre :OTL en début).
    Clic Correction (Fix), un rapport apparraitra, copie/colle le contenu ici:

    :OTL
    SRV - [2014/05/01 16:37:44 | 000,150,528 | ---- | M] () [Auto | Running] -- c:\Program Files\CouponDownloader\CouponDownloaderService.exe -- (CouponDownloaderService)
    [2014/05/17 10:27:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flash Update
    [2014/05/17 10:27:06 | 000,000,000 | ---D | C] -- C:\Program Files\Flash Update
    [2014/05/15 23:05:28 | 000,000,000 | ---D | C] -- C:\Program Files\CouponDownloader
    [2014/05/15 23:05:24 | 000,000,000 | ---D | C] -- C:\Program Files\Coupon Downloader
    [2014/05/08 00:03:04 | 000,000,000 | ---D | C] -- C:\Program Files\004

    * poste le rapport ici

    Redémarrel l'ordinateur
    1
  3. lolo
     
    Merci Malekal morte,
    voici les liens des 2 rapports OTL
    http://pjjoint.malekal.com/files.php?id=20140523_t13q1011g8e6
    http://pjjoint.malekal.com/files.php?id=20140523_o5d14p7g14r11

    que dois je faire?
    merci par avance.
    0
  4. lolo
     
    voici;

    ========== OTL ==========
    Service CouponDownloaderService stopped successfully!
    Service CouponDownloaderService deleted successfully!
    c:\Program Files\CouponDownloader\CouponDownloaderService.exe moved successfully.
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flash Update folder moved successfully.
    C:\Program Files\Flash Update folder moved successfully.
    C:\Program Files\CouponDownloader\SSL folder moved successfully.
    C:\Program Files\CouponDownloader folder moved successfully.
    C:\Program Files\Coupon Downloader folder moved successfully.
    C:\Program Files\004 folder moved successfully.

    OTL by OldTimer - Version 3.2.69.0 log created on 05232014_205142
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 711
     
    plus de probleme ?
    0
  7. Tutur43 Messages postés 8 Statut Membre
     
    0
    1. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 711
       
      Salut,

      Relance OTL.
      o sous Personnalisation (Custom Scan), copie_colle le contenu ci dessous (bien prendre :OTL en début).
      Clic Correction (Fix), un rapport apparraitra, copie/colle le contenu ici:


      :OTL
      O2:[b]64bit:[/b] - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension64.dll File not found
      O2:[b]64bit:[/b] - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WIA6EB~1\Datamngr\x64\BROWSE~1.DLL File not found
      O2 - BHO: (PriceGong - Price Comparison) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.6.12\PriceGongIE.dll File not found
      O2 - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll File not found
      O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll File not found
      O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WIA6EB~1\Datamngr\BROWSE~1.DLL File not found
      O2 - BHO: (DealPly Shopping) - {ae48ed75-5a56-4c5f-bbce-6f1ac3875f66} - C:\Program Files (x86)\DealPly\DealPlyIE.dll File not found
      O2 - BHO: (holasearch Helper Object) - {DFF9B2DA-EF99-4B26-83CB-7058299999D8} - C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll File not found
      O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll File not found
      O3 - HKLM\..\Toolbar: (Holasearch Toolbar) - {C510DFFB-0AFE-484C-BA40-CED5B74C4EEF} - C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\holasearchTlbr.dll File not found
      O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
      O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe File not found
      O4 - HKLM..\Run: [SweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe File not found
      O4 - HKLM..\Run: [tuto4pc_fr_23] File not found
      O4 - HKLM..\Run: [tuto4pc_fr_79] File not found
      SRV:[b]64bit:[/b] - File not found [Auto | Stopped] -- C:\Program Files\004\rqpbhevlkc64.exe run options=01100010040000000000000000000000 sourceguid=F2E59BED-97F5-4486-9726-66DE2DDE3B23 -- (rqpbhevlkc64)
      SRV - [2014/06/06 18:01:08 | 000,172,544 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\F2E59BED-97F5-4486-9726-66DE2DDE3B23\CouponDownloaderService64.exe -- (CouponDownloaderService64)
      [2014/07/06 18:42:25 | 000,000,000 | ---D | C] -- C:\Program Files\CouponDownloader


      * poste le rapport ici
      0
    2. Tutur43
       
      Merci, je vais faire ce que tu m'as dit.
      0
    3. Tutur43 Messages postés 8 Statut Membre
       
      ========== OTL ==========
      Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1631550F-191D-4826-B069-D9439253D926}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D717F81-9148-4f12-8568-69135F087DB0}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ae48ed75-5a56-4c5f-bbce-6f1ac3875f66}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ae48ed75-5a56-4c5f-bbce-6f1ac3875f66}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DFF9B2DA-EF99-4B26-83CB-7058299999D8}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFF9B2DA-EF99-4B26-83CB-7058299999D8}\ deleted successfully.
      Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{99079a25-328f-4bd4-be04-00955acaa0a7} deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found.
      Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{C510DFFB-0AFE-484C-BA40-CED5B74C4EEF} deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C510DFFB-0AFE-484C-BA40-CED5B74C4EEF}\ deleted successfully.
      Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
      Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon deleted successfully.
      Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SweetIM deleted successfully.
      Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\tuto4pc_fr_23 deleted successfully.
      Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\tuto4pc_fr_79 deleted successfully.
      Service rqpbhevlkc64 stopped successfully!
      Service rqpbhevlkc64 deleted successfully!
      File C:\Program Files\004\rqpbhevlkc64.exe run options=01100010040000000000000000000000 sourceguid=F2E59BED-97F5-4486-9726-66DE2DDE3B23 not found.
      Service CouponDownloaderService64 stopped successfully!
      Service CouponDownloaderService64 deleted successfully!
      C:\Program Files (x86)\F2E59BED-97F5-4486-9726-66DE2DDE3B23\CouponDownloaderService64.exe moved successfully.
      C:\Program Files\CouponDownloader\SSL folder moved successfully.
      C:\Program Files\CouponDownloader folder moved successfully.

      OTL by OldTimer - Version 3.2.69.0 log created on 07072014_002334
      0
    4. Tutur43 Messages postés 8 Statut Membre
       
      Merci ;p
      0
    5. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 711
       
      Plus de problème ?
      0
  8. Loulou
     
    Bonjour, j'ai le même problème que l'auteur du sujet, pourrait on m'aider ?

    Je vous laisse le rapport (si en plus on peu m'aider a régler mon soucie Nvidia gforce expérience qui ne veux plus s'ouvrir :p)

    Fichier OTL: http://pjjoint.malekal.com/files.php?id=20140712_e6s14o5q15e12
    Fichier extra : http://pjjoint.malekal.com/files.php?id=20140712_e13y9u13i14y9
    0
    1. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 711
       
      Salut,

      Relance OTL.
      o sous Personnalisation (Custom Scan), copie_colle le contenu ci dessous (bien prendre :OTL en début).
      Clic Correction (Fix), un rapport apparraitra, copie/colle le contenu ici:



      :OTL
      SRV:[b]64bit:[/b] - File not found [Auto | Stopped] -- C:\Program Files\004\rqpbhevlkc64.exe run options=01100010040000000000000000000000 sourceguid=F2E59BED-97F5-4486-9726-66DE2DDE3B23 -- (rqpbhevlkc64)
      SRV - [2014/06/06 18:01:08 | 000,172,544 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\F2E59BED-97F5-4486-9726-66DE2DDE3B23\CouponDownloaderService64.exe -- (CouponDownloaderService64)
      [2014/02/17 19:45:56 | 000,000,000 | ---D | M] (Websteroids) -- C:\Users\MON-PC\AppData\Roaming\mozilla\Firefox\extensions\support@websteroidsapp.com
      [2014/07/12 17:06:25 | 000,000,000 | ---D | C] -- C:\Program Files\CouponDownloader
      :files
      C:\Program Files\004\

      * poste le rapport ici



      Redémarre l'ordinateur
      0
    2. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 711
       
      Tu peux envoyer C:\Program Files (x86)\i\i.exe sur https://www.virustotal.com/gui/
      Normalement c'est OK, c'est pour vérifier.
      0
  9. sonia1606 Messages postés 2 Date d'inscription   Statut Membre Dernière intervention  
     
    Bonsoir,

    j'ai le meme souci avec "coupon downloader", lorsque j'ouvre une page internet, je suis spammée par des petits spots de pub, parfois la connection internet s'interrompt et je suis obligé de relancer la recherche (j'utilise google chrome).

    J'ai suivi la procédure et voici OTL et voici le rapport:
    fichier OTL: https://pjjoint.malekal.com/files.php?id=OTL_20140713_c7x11j6h6r14
    fichier EXTRAT/ https://pjjoint.malekal.com/files.php?id=OTL_Extras_20140713_z6i9j11y12s5

    merci bcp pour votre aide
    0
    1. sonia1606 Messages postés 2 Date d'inscription   Statut Membre Dernière intervention  
       
      bonjour Malekal_morte, ça a marché merci bcp pour ton aide!
      0
    2. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 711
       
      De rien :)

      Pour ne plus te faire avoir.
      A lire - Programmes parasites / PUPs : https://www.malekal.com/adwares-pup-protection/
      0
  10. Aidemoi7 Messages postés 1 Statut Membre
     
    Bonsoir Malekal_morte,

    J'ai le même souci avec "coupon downloader", lorsque j'ouvre une page internet, je suis spammée par des petits spots de pub et j'utilise google chrome.

    J'ai suivi la procédure et voici OTL et le rapport:
    Fichier OTL: https://pjjoint.malekal.com/files.php?id=20140726_v8y5v14g12m11
    Fichier EXTRAT: https://pjjoint.malekal.com/files.php?id=20140726_p6g14t14b13e9

    Merci d'avance pour votre aide
    0