Rapport Hijackthis + ordi lent/page acceuil & recherche chrome

Baloo83 - 3 juil. 2014 à 20:10
Malekal_morte- - 4 juil. 2014 à 16:08

Mon probème que mon ordinateur est un peu lent. De plus m page d'acceuil chrome s'était modifiée à mon insus ainsi que le moteur de recherche par défut. Il s'avère que mon antivirus n'était plus en marche premièrement. J'ai donc installé Kaspersky et fait une analyse complète de mon ordi (un AZUS sous windows 7). J'ai fait des scans Spybot Search & Destroy et CCleaner aussi et corrigé tout ce que ces analyses me trouvaient.

Maintenant je fini avec une analyse HijackThis que je ne parvient pas trop a comprendre. Quelqu'un pourrait me dire si des problèmes sont visibles et comment faire pour les corriger ?
Sachant que je ne parvient pas a "fix checked" ces 3 lignes :
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://do-search.com/?type=hp&ts=1384896134&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9CC506080
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://do-search.com/web/?type=ds&ts=1384896134&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9CC506080&q={searchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://do-search.com/web/?type=ds&ts=1384896134&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9CC506080&q={searchTerms}

Voici le rapport complet :
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 20:08:50, on 03/07/2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16555)

FIREFOX: 18.0 (fr)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe
C:\Program Files (x86)\Common Files\Umbrella\Umbrella227.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rts.dsrlte.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://do-search.com/?type=hp&ts=1384896134&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9CC506080
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://do-search.com/web/?type=ds&ts=1384896134&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9CC506080&q={searchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://do-search.com/web/?type=ds&ts=1384896134&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9CC506080&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=;https=
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
R3 - URLSearchHook: (no name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: PriceGong - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.6.8\PriceGongIE.dll
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: TrustMediaViewerV1alpha5186 - {7d8d9cc9-010b-40c9-9e8d-c9737482a388} - (no file)
O2 - BHO: (no name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file)
O2 - BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll
O2 - BHO: Wajam IE BHO - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll
O2 - BHO: mysearchdial Helper Object - {EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} - C:\Program Files (x86)\Mysearchdial\\bh\mysearchdial.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: mysearchdial Toolbar - {3004627E-F8E9-4E8B-909D-316753CBA923} - C:\Program Files (x86)\Mysearchdial\\mysearchdialTlbr.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\\AsusWSPanel.exe /S
O4 - HKLM\..\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKCU\..\Run: [systray] C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe
O4 - HKCU\..\Run: [Mobile Partner] C:\Program Files (x86)\Wi-Fi Modem\Wi-Fi Modem
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Timo\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [cacaoweb] "C:\Users\Timo\AppData\Roaming\cacaoweb\cacaoweb.exe" -noplayer
O4 - HKCU\..\Run: [GetNowUpdater] "C:\Users\Timo\AppData\Roaming\GetNowUpdater\bin\GetNowUpdater.exe" /silent_startup
O4 - HKUS\S-1-5-18\..\Run: [systray] C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe (User 'Système')
O4 - HKUS\.DEFAULT\..\Run: [systray] C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe (User 'Default user')
O4 - Global Startup: AsusVibeLauncher.lnk = C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: PokerStars.fr - {90EAE591-7E7E-434a-8E28-ECFD00071806} - C:\Program Files (x86)\PokerStars.FR\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
Malekal_morte- - 3 juil. 2014 à 20:13
3 juil. 2014 à 20:13

Tu as installé des adwares et programmes parasites sur ton PC qui ouvrent des publicités et ralentissent l'ordinateur et les navigateurs WEB.
Voici la procédure à suivre pour les supprimer :

Suis la procédure suivante donnée dans ce lien :

==> https://www.commentcamarche.net/faq/2490-supprimer-les-adwares-publicites-intempestives-pop-up-etc <===

Clic sur le lien ci-dessus et suis la procédure à la lettre.
Fournis TOUS les rapports demandés via le site pjjoint comme cela est demandé.

Merci pour votre rapidité et vos conseils. J'ai tout effectué et voici les 3 liens des 3 rapports :
AdwCleaner : http://pjjoint.malekal.com/files.php?id=20140703_r5v6m10i5u15
OLX.exe : http://pjjoint.malekal.com/files.php?id=OTL_20140703_o15g1414u6j13
Extras.txt : http://pjjoint.malekal.com/files.php?id=OTL_Extras_20140703_e12p13s7o11p8

Que dois-je faire à présent ? Y a t'il des irrégularités dns ces rapports ?
Malekal_morte- - 3 juil. 2014 à 23:07
3 juil. 2014 à 23:07
Relance OTL.
o sous Personnalisation (Custom Scan), copie_colle le contenu ci dessous (bien prendre :OTL en début).
Clic Correction (Fix), un rapport apparraitra, copie/colle le contenu ici:

O4 - HKU\.DEFAULT..\Run: [systray] C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe (TheBestMatch)
O4 - HKU\S-1-5-18..\Run: [systray] C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe (TheBestMatch)
O4 - HKU\S-1-5-19..\Run: [systray] C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe (TheBestMatch)
O4 - HKU\S-1-5-20..\Run: [systray] C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe (TheBestMatch)
[2014/06/23 02:48:18 | 000,000,000 | ---D | C] -- C:\ProgramData\726a9a91e9097b86
[2014/06/07 18:42:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GetNowUpdater
[2014/06/07 15:13:03 | 000,000,000 | ---D | C] -- C:\Users\Timo\AppData\Roaming\GetNowUpdater
[2014/06/07 15:11:24 | 000,000,000 | ---D | C] -- C:\Users\Timo\AppData\Roaming\Fixila
[2014/06/07 15:10:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Fixila PC Optimizer
[2014/07/02 15:11:09 | 000,000,308 | ---- | M] () -- C:\Windows\tasks\Fixila PC Optimizer_UPDATES.job

* poste le rapport ici

Redémarre l'ordinateur
Je viens d'effectuer ces manipulations, voici le rapport obtenu :

========== OTL ==========
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\\systray deleted successfully.
C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe moved successfully.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\systray not found.
File C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe not found.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\\systray deleted successfully.
File C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe not found.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\\systray deleted successfully.
File C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe not found.
C:\ProgramData\726a9a91e9097b86 folder moved successfully.
C:\Program Files (x86)\GetNowUpdater\inst\Bootstrapper folder moved successfully.
C:\Program Files (x86)\GetNowUpdater\inst folder moved successfully.
C:\Program Files (x86)\GetNowUpdater folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\plugins\sqldrivers folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\plugins\sensors folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\plugins\sensorgestures folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\plugins\qmltooling folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\plugins\qml1tooling folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\plugins\printsupport folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\plugins\playlistformats folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\plugins\platforms folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\plugins\mediaservice folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\plugins\imageformats folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\plugins\iconengines folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\plugins\designer folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\plugins\bearer folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\plugins\accessible folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\plugins folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\html_res\img folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\html_res\icon_cache folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\html_res\adbF\driver folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\html_res\adbF folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\html_res folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater\bin folder moved successfully.
C:\Users\Timo\AppData\Roaming\GetNowUpdater folder moved successfully.
C:\Users\Timo\AppData\Roaming\Fixila\PCOptimizer folder moved successfully.
C:\Users\Timo\AppData\Roaming\Fixila folder moved successfully.
C:\Program Files (x86)\Fixila PC Optimizer folder moved successfully.
C:\Windows\Tasks\Fixila PC Optimizer_UPDATES.job moved successfully.

OTL by OldTimer - Version log created on 07042014_145042
Malekal_morte- - Modifié le 4/07/2014 à 16:08
Modifié par Malekal_morte- le 4/07/2014 à 16:08
ca va mieux ?

Désinstalle les programmes McAfee vu que tu as tjrs Kaspersky.

