Pub Ads by name et EFIX PRO

Fermé
oxx - Modifié par Malekal_morte- le 2/06/2015 à 13:03
 oxx - 2 juin 2015 à 13:54
Bonjour,
Bonjour,
J'ai un problème avec les pubs Ads by name, et EFIX PRO. J'ai tenté d'utiliser ADWCLEANER et MALWARBYTES sans succès j'ai ensuite vu FRST et j ai fait les démarches pour les liens :

FRST :http://pjjoint.malekal.com/files.php?id=20150602_p13w13f6l12q7
SHORTCUT : http://pjjoint.malekal.com/files.php?id=20150602_c6k10d5c11e6
ADDITIONNAL : http://pjjoint.malekal.com/files.php?id=20150602_o6v5j14c6k9

Merci beaucoup pour votre futur aide.
Loïc
A voir également:

3 réponses

Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 656
2 juin 2015 à 13:02
Salut,

OK je regarde les rapports =)
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 656
Modifié par Malekal_morte- le 2/06/2015 à 13:07
Voici la correction à effectuer avec FRST.
Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix

Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
Copie/colle dedans ce qui suit :

C:\ProgramData\Kikblaster
C:\ProgramData\Gsiirperoia
Task: C:\Windows\Tasks\m1nc75K7BGvsM9SBDnUbj.job => C:\Users\Sonia\AppData\Roaming\m1nc75K7BGvsM9SBDnUbj.exe <==== ATTENTION
Task: C:\Windows\Tasks\MSBRG1.job => C:\ProgramData\Kikblaster\Kikblaster.exe
Task: {2E389145-AEC9-4DE0-AEFF-6F365B5E2CAC} - System32\Tasks\m1nc75K7BGvsM9SBDnUbj => C:\Users\Sonia\AppData\Roaming\m1nc75K7BGvsM9SBDnUbj.exe <==== ATTENTION
Task: {4DD225D4-1DB9-44B9-BD96-96EE4AA9EDC7} - System32\Tasks\Gsiirperoia => C:\ProgramData\Gsiirperoia\1.0.1.0\wemobriu.exe [2015-05-27] ()
Task: {EEFAE637-E061-4E31-B05C-3A0A5841993C} - System32\Tasks\MSBRG1 => C:\ProgramData\Kikblaster\Kikblaster.exe
AppInit_DLLs: c:\programdata\kikblaster\kikblaster32.dll => c:\programdata\kikblaster\kikblaster32.dll File not found
S2 IMService; C:\Program Files\Common Files\Umbrella\Umbrella235.exe [X]
2015-05-29 14:27 - 2015-06-02 10:31 - 00145408 _____ () C:\Windows\Provider.dll
2015-05-29 14:27 - 2015-06-02 09:30 - 00145408 _____ () C:\Windows\Provider20150602103133.dll
2015-05-29 14:27 - 2015-06-02 08:29 - 00145408 _____ () C:\Windows\Provider20150602093044.dll
2015-05-29 14:27 - 2015-06-01 18:28 - 00145408 _____ () C:\Windows\Provider20150602082956.dll
2015-05-29 14:27 - 2015-06-01 17:28 - 00145408 _____ () C:\Windows\Provider20150601182828.dll
2015-05-29 14:27 - 2015-06-01 15:19 - 00145408 _____ () C:\Windows\Provider20150601172758.dll
2015-05-29 14:27 - 2015-06-01 14:18 - 00145408 _____ () C:\Windows\Provider20150601151921.dll
2015-05-29 14:27 - 2015-06-01 13:18 - 00145408 _____ () C:\Windows\Provider20150601141854.dll
2015-05-29 14:27 - 2015-06-01 12:18 - 00145408 _____ () C:\Windows\Provider20150601131840.dll
2015-05-29 14:27 - 2015-06-01 11:17 - 00145408 _____ () C:\Windows\Provider20150601121827.dll
2015-05-29 14:27 - 2015-06-01 10:16 - 00145408 _____ () C:\Windows\Provider20150601111747.dll
2015-05-29 14:27 - 2015-06-01 09:16 - 00145408 _____ () C:\Windows\Provider20150601101658.dll
2015-05-29 14:27 - 2015-05-29 15:27 - 00145408 _____ () C:\Windows\Provider20150601091605.dll
2015-05-29 14:27 - 2015-05-29 14:27 - 00000000 ____D () C:\Windows\Provider
2015-05-29 14:27 - 2015-05-29 14:27 - 00000000 _____ () C:\Windows\system32\0
2015-05-29 14:27 - 2015-05-28 13:56 - 00145408 _____ () C:\Windows\Provider20150529152755.dll
2015-05-28 08:34 - 2015-05-28 08:34 - 00613255 _____ (CMI Limited) C:\Users\Sonia\AppData\Local\nsp1237.tmp
2015-05-28 08:31 - 2015-06-02 12:29 - 00001014 _____ () C:\Windows\Tasks\m1nc75K7BGvsM9SBDnUbj.job
2015-05-28 08:08 - 2015-05-28 08:08 - 00000000 ____D () C:\Users\Sonia\AppData\Local\ICSharpCode.net
2015-05-27 15:20 - 2015-05-27 15:23 - 00000902 _____ () C:\Windows\system32\${LOGFILE}
2015-05-27 15:11 - 2015-05-27 15:11 - 00613255 _____ (CMI Limited) C:\Users\Sonia\AppData\Local\nsoC41B.tmp
2015-05-27 14:25 - 2015-05-27 14:25 - 00000000 ____D () C:\ProgramData\Gsiirperoia
2015-05-26 10:19 - 2015-05-26 10:19 - 00613255 _____ (CMI Limited) C:\Users\Sonia\AppData\Local\nsiCEAA.tmp
2015-05-26 09:42 - 2015-06-01 09:42 - 00000000 ____D () C:\ProgramData\{00db2d1d-d1d2-03f3-00db-b2d1dd1db477}
2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Sonia\AppData\Roaming\m1nc75K7BGvsM9SBDnUbj
2015-05-26 10:19 - 2015-05-26 10:19 - 0613255 _____ (CMI Limited) C:\Users\Sonia\AppData\Local\nsiCEAA.tmp
2015-05-27 15:11 - 2015-05-27 15:11 - 0613255 _____ (CMI Limited) C:\Users\Sonia\AppData\Local\nsoC41B.tmp
2015-05-28 08:34 - 2015-05-28 08:34 - 0613255 _____ (CMI Limited) C:\Users\Sonia\AppData\Local\nsp1237.tmp


Une fois, le texte coller dans le bloc-note.
Menu Fichier puis Enregistrer sous.
A gauche, place toi sur le bureau.
Dans le champs en bas, nom du fichier mets : fixlist.txt
Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.

Relance FRST et clic sur le bouton Fix
Selon comment un redémarrage est nécessaire (pas obligatoire).
Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.

Redémarre l'ordinateur



puis réinitialise tes navigateurs:
==================================
Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :


si pas mieux et si tu utilises Firefox :

Exporte tes favoris : https://support.mozilla.org/fr/kb/exporter-marque-pages-firefox-fichier-html
Désinstalle Mozilla Firefox en cochant l'option de suppression du profil.

Affiche les fichiers cachés et systèmes : https://www.commentcamarche.net/informatique/windows/185-afficher-les-extensions-et-les-fichiers-caches-sous-windows/

Supprimer le profil :
Mon Ordinateur => Disque C => Utilisateurs => Ton user => AppData => Roaming
clic droit sur le dossier Mozilla puis renommer
renomme le en Mozilla.old

Mon Ordinateur => Disque C => Program Files => supprime le dossier Mozilla.

Réinstalle Firefox à partir de ce lien : https://telecharger.malekal.com/download/mozilla-firefox/

Réimporte tes favoris.



Like the angel you are, you laugh creating a lightness in my chest,
Your eyes they penetrate me,
(Your answer's always 'maybe')
That's when I got up and left
0
Voici le contenu du fichier log

Fix result of Farbar Recovery Scan Tool (x86) Version: 29-05-2015
Ran by Sonia at 2015-06-02 13:36:47 Run:1
Running from C:\Users\Sonia\Desktop
Loaded Profiles: Sonia (Available Profiles: Sonia)
Boot Mode: Normal

==============================================

fixlist content:


*

C:\ProgramData\Kikblaster
C:\ProgramData\Gsiirperoia
Task: C:\Windows\Tasks\m1nc75K7BGvsM9SBDnUbj.job => C:\Users\Sonia\AppData\Roaming\m1nc75K7BGvsM9SBDnUbj.exe <==== ATTENTION
Task: C:\Windows\Tasks\MSBRG1.job => C:\ProgramData\Kikblaster\Kikblaster.exe
Task: {2E389145-AEC9-4DE0-AEFF-6F365B5E2CAC} - System32\Tasks\m1nc75K7BGvsM9SBDnUbj => C:\Users\Sonia\AppData\Roaming\m1nc75K7BGvsM9SBDnUbj.exe <==== ATTENTION
Task: {4DD225D4-1DB9-44B9-BD96-96EE4AA9EDC7} - System32\Tasks\Gsiirperoia => C:\ProgramData\Gsiirperoia\1.0.1.0\wemobriu.exe [2015-05-27] ()
Task: {EEFAE637-E061-4E31-B05C-3A0A5841993C} - System32\Tasks\MSBRG1 => C:\ProgramData\Kikblaster\Kikblaster.exe
AppInit_DLLs: c:\programdata\kikblaster\kikblaster32.dll => c:\programdata\kikblaster\kikblaster32.dll File not found
S2 IMService; C:\Program Files\Common Files\Umbrella\Umbrella235.exe [X]
2015-05-29 14:27 - 2015-06-02 10:31 - 00145408 _____ () C:\Windows\Provider.dll
2015-05-29 14:27 - 2015-06-02 09:30 - 00145408 _____ () C:\Windows\Provider20150602103133.dll
2015-05-29 14:27 - 2015-06-02 08:29 - 00145408 _____ () C:\Windows\Provider20150602093044.dll
2015-05-29 14:27 - 2015-06-01 18:28 - 00145408 _____ () C:\Windows\Provider20150602082956.dll
2015-05-29 14:27 - 2015-06-01 17:28 - 00145408 _____ () C:\Windows\Provider20150601182828.dll
2015-05-29 14:27 - 2015-06-01 15:19 - 00145408 _____ () C:\Windows\Provider20150601172758.dll
2015-05-29 14:27 - 2015-06-01 14:18 - 00145408 _____ () C:\Windows\Provider20150601151921.dll
2015-05-29 14:27 - 2015-06-01 13:18 - 00145408 _____ () C:\Windows\Provider20150601141854.dll
2015-05-29 14:27 - 2015-06-01 12:18 - 00145408 _____ () C:\Windows\Provider20150601131840.dll
2015-05-29 14:27 - 2015-06-01 11:17 - 00145408 _____ () C:\Windows\Provider20150601121827.dll
2015-05-29 14:27 - 2015-06-01 10:16 - 00145408 _____ () C:\Windows\Provider20150601111747.dll
2015-05-29 14:27 - 2015-06-01 09:16 - 00145408 _____ () C:\Windows\Provider20150601101658.dll
2015-05-29 14:27 - 2015-05-29 15:27 - 00145408 _____ () C:\Windows\Provider20150601091605.dll
2015-05-29 14:27 - 2015-05-29 14:27 - 00000000 ____D () C:\Windows\Provider
2015-05-29 14:27 - 2015-05-29 14:27 - 00000000 _____ () C:\Windows\system32\0
2015-05-29 14:27 - 2015-05-28 13:56 - 00145408 _____ () C:\Windows\Provider20150529152755.dll
2015-05-28 08:34 - 2015-05-28 08:34 - 00613255 _____ (CMI Limited) C:\Users\Sonia\AppData\Local\nsp1237.tmp
2015-05-28 08:31 - 2015-06-02 12:29 - 00001014 _____ () C:\Windows\Tasks\m1nc75K7BGvsM9SBDnUbj.job
2015-05-28 08:08 - 2015-05-28 08:08 - 00000000 ____D () C:\Users\Sonia\AppData\Local\ICSharpCode.net
2015-05-27 15:20 - 2015-05-27 15:23 - 00000902 _____ () C:\Windows\system32\${LOGFILE}
2015-05-27 15:11 - 2015-05-27 15:11 - 00613255 _____ (CMI Limited) C:\Users\Sonia\AppData\Local\nsoC41B.tmp
2015-05-27 14:25 - 2015-05-27 14:25 - 00000000 ____D () C:\ProgramData\Gsiirperoia
2015-05-26 10:19 - 2015-05-26 10:19 - 00613255 _____ (CMI Limited) C:\Users\Sonia\AppData\Local\nsiCEAA.tmp
2015-05-26 09:42 - 2015-06-01 09:42 - 00000000 ____D () C:\ProgramData\{00db2d1d-d1d2-03f3-00db-b2d1dd1db477}
2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Sonia\AppData\Roaming\m1nc75K7BGvsM9SBDnUbj
2015-05-26 10:19 - 2015-05-26 10:19 - 0613255 _____ (CMI Limited) C:\Users\Sonia\AppData\Local\nsiCEAA.tmp
2015-05-27 15:11 - 2015-05-27 15:11 - 0613255 _____ (CMI Limited) C:\Users\Sonia\AppData\Local\nsoC41B.tmp
2015-05-28 08:34 - 2015-05-28 08:34 - 0613255 _____ (CMI Limited) C:\Users\Sonia\AppData\Local\nsp1237.tmp


*


"C:\ProgramData\Kikblaster" => File/Folder not found.
C:\ProgramData\Gsiirperoia => Moved successfully.
C:\Windows\Tasks\m1nc75K7BGvsM9SBDnUbj.job => Moved successfully.
C:\Windows\Tasks\MSBRG1.job => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2E389145-AEC9-4DE0-AEFF-6F365B5E2CAC}" => key Removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2E389145-AEC9-4DE0-AEFF-6F365B5E2CAC}" => key Removed successfully.
C:\Windows\System32\Tasks\m1nc75K7BGvsM9SBDnUbj => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\m1nc75K7BGvsM9SBDnUbj" => key Removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{4DD225D4-1DB9-44B9-BD96-96EE4AA9EDC7}" => key Removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4DD225D4-1DB9-44B9-BD96-96EE4AA9EDC7}" => key Removed successfully.
C:\Windows\System32\Tasks\Gsiirperoia => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Gsiirperoia" => key Removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EEFAE637-E061-4E31-B05C-3A0A5841993C}" => key Removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EEFAE637-E061-4E31-B05C-3A0A5841993C}" => key Removed successfully.
C:\Windows\System32\Tasks\MSBRG1 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MSBRG1" => key Removed successfully.
"c:\programdata\kikblaster\kikblaster32.dll" => value data Removed successfully..
IMService => Service Removed successfully.
C:\Windows\Provider.dll => Moved successfully.
C:\Windows\Provider20150602103133.dll => Moved successfully.
C:\Windows\Provider20150602093044.dll => Moved successfully.
C:\Windows\Provider20150602082956.dll => Moved successfully.
C:\Windows\Provider20150601182828.dll => Moved successfully.
C:\Windows\Provider20150601172758.dll => Moved successfully.
C:\Windows\Provider20150601151921.dll => Moved successfully.
C:\Windows\Provider20150601141854.dll => Moved successfully.
C:\Windows\Provider20150601131840.dll => Moved successfully.
C:\Windows\Provider20150601121827.dll => Moved successfully.
C:\Windows\Provider20150601111747.dll => Moved successfully.
C:\Windows\Provider20150601101658.dll => Moved successfully.
C:\Windows\Provider20150601091605.dll => Moved successfully.

"C:\Windows\Provider" folder move:

Could not move "C:\Windows\Provider" folder => Scheduled to move on reboot.

C:\Windows\system32\0 => Moved successfully.
C:\Windows\Provider20150529152755.dll => Moved successfully.
C:\Users\Sonia\AppData\Local\nsp1237.tmp => Moved successfully.
"C:\Windows\Tasks\m1nc75K7BGvsM9SBDnUbj.job" => File/Folder not found.
C:\Users\Sonia\AppData\Local\ICSharpCode.net => Moved successfully.
C:\Windows\system32\${LOGFILE} => Moved successfully.
C:\Users\Sonia\AppData\Local\nsoC41B.tmp => Moved successfully.
"C:\ProgramData\Gsiirperoia" => File/Folder not found.
C:\Users\Sonia\AppData\Local\nsiCEAA.tmp => Moved successfully.
C:\ProgramData\{00db2d1d-d1d2-03f3-00db-b2d1dd1db477} => Moved successfully.
C:\Users\Sonia\AppData\Roaming\m1nc75K7BGvsM9SBDnUbj => Moved successfully.
"C:\Users\Sonia\AppData\Local\nsiCEAA.tmp" => File/Folder not found.
"C:\Users\Sonia\AppData\Local\nsoC41B.tmp" => File/Folder not found.
"C:\Users\Sonia\AppData\Local\nsp1237.tmp" => File/Folder not found.

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-06-02 13:38:51)<=

C:\Windows\Provider => is moved successfully

End of Fixlog 13:38:52

apres avoir reinitialisé firefox et Ie apres avoir vérifié les modules complementaires, apres avoir désinstallé et réinstallé firefox le probleme perciste j essaie la suppression du profil firefox pour voir.

Merci pour l aide !!!
0