Yandex

Résolu
Bonjours a tous^^
Voila ce matin en allumant mon pc je me retrouve avec une nouvelle barre de tache !!!
(yandex)
je ne la trouve nul part pour la désinstaller , et pourtant j'aimerais bien ^^
un conseil, une idée?, je suis preneur
merci a tous par avance
--
yoyochtka

9 réponses

  1. Modérateur
    Bonjour,

    Elle est placée où ?

    --> Télécharge Farbar Recovery Scan Tool (de Farbar) sur ton Bureau.

    Attention : tu dois prendre la version compatible avec ton système : 32 ou 64 bits.

    32 ou 64 bits - Comment savoir ?

    --> Ferme toutes les applications en cours.
    --> Lance FRST (Sous Windows Vista/7/8/10, clic droit sur FRST > Exécuter en tant qu'administrateur).
    --> Coche la case Addition.txt.
    --> Clique sur Analyser.
    --> Une fois le scan terminé, deux rapports FRST.txt et Addition.txt seront présents sur le Bureau.
    --> Héberge les deux rapports sur pjjoint.malekal.com et copie-colle les liens fournis dans ta prochaine réponse.
    1. bonjour Destrio je viens d'envoyer les fichier sur le site conseiller !!
      Merci
    2. Modérateur
      N'oublie pas de me donner les liens pour que je puisse aller les consulter.
    3. Modérateur
      @Destrio5et copie-colle les liens fournis dans ta prochaine réponse.

      Il faut donner les liens ici.
  2. Modérateur
    "Pokki Start Menu" et "Host App Service" --> A désinstaller si tu ne t'en sers pas.

    --> Ouvre le Bloc-notes.
    --> Copie-colle le texte en gras ci-dessous dans le Bloc-notes :

    start
    CreateRestorePoint:
    CloseProcesses:
    HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
    HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
    HKU\S-1-5-21-171270494-2155061012-1424955240-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
    HKU\S-1-5-21-171270494-2155061012-1424955240-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yandex.ru/?win=217&clid=2256027
    SearchScopes: HKLM -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
    SearchScopes: HKLM-x32 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
    SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
    SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
    SearchScopes: HKU\S-1-5-21-171270494-2155061012-1424955240-1001 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://yandex.ru/search/?win=217&clid=2256028&text={searchTerms}
    SearchScopes: HKU\S-1-5-21-171270494-2155061012-1424955240-1001 -> 3C45828731836935EB6F4000621E7CF7 URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
    SearchScopes: HKU\S-1-5-21-171270494-2155061012-1424955240-1001 -> {0281B534-0CDC-4BE7-98D0-0ED0D219571F} URL =
    SearchScopes: HKU\S-1-5-21-171270494-2155061012-1424955240-1001 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://yandex.ru/search/?win=217&clid=2256028&text={searchTerms}
    SearchScopes: HKU\S-1-5-21-171270494-2155061012-1424955240-1001 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://fr.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
    SearchScopes: HKU\S-1-5-21-171270494-2155061012-1424955240-1001 -> {D2736CF4-4039-11E5-828B-448A5BD26ECD} URL = hxxps://secure.homepage-web.com/?src=omnibox&partner=acer&q={searchTerms}
    Edge HomeButtonPage: HKU\S-1-5-21-171270494-2155061012-1424955240-1001 -> hxxp://www.yandex.ru/?win=217&clid=2256027
    FF DefaultSearchUrl: Mozilla\Firefox\Profiles\piljiz8w.default -> hxxp://www.bing.com/search
    FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\piljiz8w.default -> Bing (Microsoft)
    FF SelectedSearchEngine: Mozilla\Firefox\Profiles\piljiz8w.default -> Bing (Microsoft)
    FF Keyword.URL: Mozilla\Firefox\Profiles\piljiz8w.default -> hxxp://www.bing.com/search
    FF SearchPlugin: C:\Users\yoyochtka\AppData\Roaming\Mozilla\Firefox\Profiles\piljiz8w.default\searchplugins\google-avast.xml [2015-02-07]
    FF SearchPlugin: C:\Users\yoyochtka\AppData\Roaming\Mozilla\Firefox\Profiles\piljiz8w.default\searchplugins\Web Search.xml [2015-08-11]
    CHR HomePage: Default -> yandex.ru/?__PARAM__from=chromehp
    CHR DefaultSearchURL: Default -> hxxps://yandex.ru/search/?__PARAM__from=chromesearch&text={searchTerms}
    CHR DefaultSearchKeyword: Default -> yandex.ru
    CHR DefaultSuggestURL: Default -> hxxps://suggest.yandex.net/suggest-ff.cgi?uil=ru&part={searchTerms}
    CHR HKLM-x32\...\Chrome\Extension: [bejnpnkhfgfkcpgikiinojlmdcjimobi] - hxxp://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [fdjdjkkjoiomafnihnobkinnfjnnlhdg] - hxxp://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [gehngeifmelphpllncobkmimphfkckne] - hxxp://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [ihenkjeihefokohmemphikjnjbmegdik] - "C:\Program Files (x86)\Sony\Media Go\MediaGoDetector.crx" <non trouvé(e)>
    CHR HKLM-x32\...\Chrome\Extension: [pfigaoamnncijbgomifamkmkidnnlikl] - hxxp://clients2.google.com/service/update2/crx
    EmptyTemp:
    end


    --> Enregistre le fichier dans le dossier "Téléchargements" (au même endroit que FRST) sous le nom fixlist.txt
    --> Lance FRST (Sous Windows Vista/7/8/10, clic droit sur FRST > Exécuter en tant qu'administrateur).
    --> Clique sur Corriger. Patiente le temps de la correction.

    Note : si l'outil a besoin d'un redémarrage, accepte pour qu'il termine son travail.

    --> Une fois la correction terminée, un rapport Fixlog.txt remplacera le fichier fixlist.
    --> Héberge le rapport sur pjjoint.malekal.com et copie-colle le lien fourni dans ta prochaine réponse.
    1. ok je fais ça
      1. je ne sais pas si yandex m'embête mais quand j'ouvre une boite de dialogue sur un site mon écran se met à 300%
      2. Modérateur
        Tout est "zoomé" ?

        Sur un site en particulier ?

        Peu importe le navigateur ?
      3. sur le site good games empire , et non que sous firefox apparemment
      4. Modérateur
        "Mozilla Firefox 52.4.0 ESR (x64 fr)"
        "Mozilla Firefox 55.0.3 (x86 fr)"

        --> Pourquoi avoir deux versions de Firefox ?
      5. ah ben c'est nouveau ça !!! Mozilla Firefox 52.4.0 ESR (x64 fr) c'est installé seul aujourd'hui . lequel je supprime?
    2. voila c'est fait merci a toi Destrio. Apparemment tt est ok
      1. Modérateur
        Pour finir :

        ---> Télécharge DelFix sur ton Bureau puis lance-le.
        • Coche Purger la restauration système et laisse Supprimer les outils de désinfection coché.
        • Clique sur Exécuter.
        • Poste le rapport.


        ==Prévention==

        Malwarebytes' Anti-Malware peut être pratique en cas d'infection :
        https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/

        Adware Prevention permet de t'entraîner à ne pas accepter de PUPs / adwares lors d'installations de logiciels :
        https://security-x.fr/~guigui0001/

        https://www.malekal.com/adwares-pup-protection/

        Un dossier sur la prévention et sécurité sur Internet est disponible ici.
        1. Voila le rapport
          # DelFix v1.013 - Rapport créé le 30/09/2017 à 23:49:33
          # Mis à jour le 17/04/2016 par Xplode
          # Nom d'utilisateur : yoyochtka - PCYOYOCHTKA
          # Système d'exploitation : Windows 10 Home (64 bits)

          ~ Suppression des outils de désinfection ...

          Supprimé : C:\FRST
          Supprimé : C:\Users\yoyochtka\Downloads\Addition.txt
          Supprimé : C:\Users\yoyochtka\Downloads\Fixlog.txt
          Supprimé : C:\Users\yoyochtka\Downloads\FRST.txt
          Supprimé : C:\Users\yoyochtka\Downloads\FRST64.exe

          ~ Purge de la restauration système ...

          Supprimé : RP #48 [Point de contrôle planifié | 09/09/2017 08:41:21]
          Supprimé : RP #49 [Windows Update | 09/13/2017 09:42:13]
          Supprimé : RP #50 [Windows Update | 09/13/2017 09:43:56]
          Supprimé : RP #51 [Point de contrôle planifié | 09/21/2017 07:59:59]
          Supprimé : RP #52 [Avast Cleanup | 09/23/2017 16:21:16]
          Supprimé : RP #53 [Avast Cleanup | 09/25/2017 11:45:57]
          Supprimé : RP #54 [Avast Cleanup | 09/26/2017 16:31:50]

          Nouveau point de restauration créé !

          ########## - EOF - ##########