Barre ASKBAR Toolbar - S'en débarasser

Bonjour,

Comment supprimer toutes traces de "ASk BAR" Toolbar, (différent de AskBarDis)
Je pense avoir supprimé proprement ce log mais il reste des traces

en particulier ici
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - (no file)

Chaque fois que je vois apparaître Ask Bar dans le registre à partir de regedit
puis je supprimer ces lignes ?

Merci à ceux qui m'avaient répondu de bien vouloir reposter
(à propos des pages de pub intempestives dues à cette barre)
Configuration: Windows Vista
Internet Explorer 7.0

18 réponses

  1. Il me semble que cette barre s'est installée seule,
    ceux qui ont eu ce problème en sont-ils venus à bout ? Merci
    1
    1. Contributeur sécurité
      Bonjour,

      Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
      https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

      Fais un clic-droit sur le raccourci de Toolbar-S&D sur le Bureau et choisis " Exécuter en tant qu' Administrateur"
      * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
      * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
      * Poste le rapport généré. (C:\TB.txt)

      0
      1. ok
        voici le rapport :

        -----------\\ ToolBar S&D 1.2.4 XP/Vista

        Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
        X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 CPU T7200 @ 2.00GHz )
        BIOS : Default System BIOS
        USER : Work ( Administrator )
        BOOT : Normal boot
        Antivirus : avast! antivirus 4.8.1229 [VPS 081031-1] 4.8.1229 (Activated)
        C:\ (Local Disk) - NTFS - Total:137 Go (Free:62 Go)
        D:\ (Local Disk) - FAT32 - Total:11 Go (Free:6 Go)
        E:\ (CD or DVD)

        "C:\ToolBar SD" ( MAJ : 27-10-2008|09:25 )
        Option : [1] ( 01/11/2008|15:00 )

        [ UAC => 1 ]

        -----------\\ Recherche de Fichiers / Dossiers ...

        -----------\\ [..\Internet Explorer\Main]

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
        "Local Page"="C:\\Windows\\system32\\blank.htm"
        "Search Page"="https://www.google.com/?gws_rd=ssl"
        "Start Page"="https://www.google.com/?gws_rd=ssl"
        "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
        "Url"="http://www.microsoft.com/athome/community/rss.xml"
        "Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
        "Url"="http://www.microsoft.com/atwork/community/rss.xml"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
        "Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
        "Default_Page_URL"="http://www.medion.com/"
        "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
        "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

        --------------------\\ Recherche d'autres infections

        Aucune autre infection trouvée !

        [ UAC => 1 ]

        1 - "C:\ToolBar SD\TB_1.txt" - 01/11/2008|15:01 - Option : [1]

        -----------\\ Fin du rapport a 15:01:12,46
        0
        1. Contributeur sécurité
          ToolbarS&D (spécialisé dans la suppression des barres d'outils infectieuses) n'a trouvé aucune trace de la AskBar

          Télécharge hijackthis (logiciel de diagnostique) sur ton bureau : https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/

          Installe le, lance le et clique sur "Do a system scan and save a logfile".
          Fais un copier-coller du rapport entier sur le forum

          0
          1. il n'a trouvé aucune trace, tant mieux, c'est qu'elle n'est plus "active"

            en revanche, c'est la suppression propre de toutes traces encore visibles
            que j'aimerais supprimer

            comme ces lignes dans le regsitre :
            - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} par défaut REG_SZ Ask Toolbar BHO
            et ASK Toolbar Options
            dans HKEY CLASSES ROOT / CLSID
            0
            1. Voici le rapport hijackthis:

              Running processes:
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\Windows\RtHDVCpl.exe
              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              C:\Program Files\epson\Creativity Suite\Event Manager\EEventManager.exe
              C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
              C:\Program Files\Alwil Software\Avast4\ashDisp.exe
              C:\Program Files\DAP\DAP.exe
              C:\Windows\vspc1300.exe
              C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
              C:\Windows\System32\p2phost.exe
              C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolb­arNotifier.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\Philips\Philips SPC1300NC Webcam\TrayMin1300.exe
              C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
              C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
              C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
              C:\Windows\System32\wsqmcons.exe
              C:\Program Files\Internet Explorer\ieuser.exe
              C:\Windows\system32\conime.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.medion.com/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              O1 - Hosts: ::1 localhost
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
              O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
              O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - (no file)
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
              O4 - HKLM\..\Run: [BullGuard Install] "C:\Program Files\BullGuard Install\Install BullGuard.exe" fr Medion
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
              O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE"
              O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
              O4 - HKLM\..\Run: [SPC1300] C:\Windows\vspc1300.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
              O4 - HKCU\..\Run: [CollaborationHost] C:\Windows\system32\p2phost.exe -s
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
              O4 - Global Startup: TrayMin1300.lnk = ?
              O8 - Extra context menu item: Ouvrir dans WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
              O13 - Gopher Prefix:
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{B8C9F31C-17DB-41C3-93EC-2B7F7FAC954E}: NameServer = 84.103.237.144 86.64.145.144
              O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
              O23 - Service: O2Micro Flash Memory (O2Flash) - O2Micro International - C:\Windows\system32\o2flash.exe
              O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
              0
          2. Contributeur sécurité
            Tu as une autre infection par contre...

            UAC pour Vista : désactive le contrôle des comptes utilisateurs : Menu démarrer --> panneau de configuration --> comptes utilisateurs --> activer ou désactiver le controle des comptes utilisateur --> décoche la case "utiliser le contrôle....." Puis redémarre ton ordinateur.

            Télécharge SmitfraudFix : http://siri.urz.free.fr/Fix/SmitfraudFix.exe

            - Enregistre-le sur le bureau

            - Double-clique sur SmitfraudFix.exe et choisis l'option 1 puis Entrée

            - Un rapport sera généré, poste-le dans ta prochaine réponse stp.

            Tutoriel ici pour t'aider : http://www.malekal.com//tutorial_SmitFraudfix.php

            0
            1. j'ai une infection sur quelle ligne ? merci

              ok je poste le rapport après téléchargement de smitfraud
              (encore un log de nettoyage, lol, j'en aurai bientôt une pleine collection)
              0
              1. Contributeur sécurité
                Cette ligne :
                O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto

                Et je cherche des infos sur celle la, tu sais ce que c'est ?
                O4 - HKLM\..\Run: [SPC1300] C:\Windows\vspc1300.exe

                P.S : Je vais partir pour la soirée, je reprendrais demain là où on en était ;)

                0
                1. msconfig.exe /AUTO est une infection ? ok
                  Non, l'autre , je ne sais pas ce que c'est (sorry)
                  0

                  1. Problème pour télécharger smitfraud ( pages bizarres qui s'ouvrent)
                    je voulais être rapide mais le téléchargement ne se fait pas , "overload2.html n'a pu être téléchargé"

                    PS : ok, je vais tenter de télécharger ce log
                    (bonne soirée)
                    0
                    1. Voici le rapport

                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\wininit.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\services.exe
                      C:\Windows\system32\lsass.exe
                      C:\Windows\system32\lsm.exe
                      C:\Windows\system32\winlogon.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\Ati2evxx.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\SLsvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\Ati2evxx.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\Windows\RtHDVCpl.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
                      C:\Windows\System32\spoolsv.exe
                      C:\Program Files\epson\Creativity Suite\Event Manager\EEventManager.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                      C:\Windows\vspc1300.exe
                      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\Windows\System32\msconfig.exe
                      C:\Program Files\Windows Sidebar\sidebar.exe
                      C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
                      C:\Windows\System32\p2phost.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Program Files\Philips\Philips SPC1300NC Webcam\TrayMin1300.exe
                      C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
                      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      C:\Windows\system32\o2flash.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\SearchIndexer.exe
                      C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                      C:\Program Files\iPod\bin\iPodService.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Windows\system32\conime.exe
                      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Program Files\DAP\DAP.EXE
                      C:\Windows\system32\SearchProtocolHost.exe
                      C:\Windows\system32\SearchFilterHost.exe
                      C:\Windows\system32\cmd.exe
                      C:\Windows\system32\wbem\wmiprvse.exe

                      »»»»»»»»»»»»»»»»»»»»»»»» hosts

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Work

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Work\Application Data

                      »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Work\FAVORI~1

                      »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                      »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                      »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                      »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                      !!!Attention, following keys are not inevitably infected!!!

                      o4Patch
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                      !!!Attention, following keys are not inevitably infected!!!

                      IEDFix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                      !!!Attention, following keys are not inevitably infected!!!

                      VACFix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                      !!!Attention, following keys are not inevitably infected!!!

                      404Fix
                      Credits: Malware Analysis & Diagnostic
                      Code: S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
                      !!!Attention, following keys are not inevitably infected!!!

                      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                      !!!Attention, following keys are not inevitably infected!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                      !!!Attention, following keys are not inevitably infected!!!
                      0
                      1. petite info supplémentaire :
                        après avoir décoché le contrôle utilisateur, le pc a démarré en mode sélectif,
                        je peux le faire redémarrer en mode normal comme proposé ?
                        0
                        1. Contributeur sécurité
                          SmitFraudFix ne l'a pas détecté...

                          Télécharge et installe Malwarebytes' Anti-Malware
                          - A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée
                          - Lance MBAM, laisse les Mises à jour se télécharger et referme le programme

                          Redémarre en "Mode sans échec" : redémarre ton ordinateur et tapote sur la touche F8 jusqu'à l'affichage du menu des options avancées de Windows, et sélectionne "Mode sans échec". Choisis ta session habituelle

                          Lance MBAM
                          - Puis va dans l'onglet "Recherche", coche "Exécuter un examen complet" puis "Rechercher"
                          - Sélectionne tes disques durs" puis clique sur "Lancer l’examen"
                          - A la fin du scan, clique sur Afficher les résultats
                          - Coche tous les éléments détectés puis clique sur Supprimer la sélection
                          - Enregistre le rapport
                          - S'il t'est demandé de redémarrer, clique sur Yes

                          Poste le rapport de scan après la suppression ici

                          0
                          1. anthony, bonjour

                            désolée de venir un peu tard,
                            pour répondre à ta question,
                            j'avais déjà Malwarebytes Anti-Malware , la version 1354 qui ne détecte aucune nfection
                            et la nouvelle version 1373 qui ne détecte toujours aucune infection

                            (je n'ai pas fait le scan en mode sans échec en revanche,
                            je le fais si tu veux,
                            le mode sans échec a son importanece ? )

                            merci
                            0
                            1. Contributeur sécurité
                              Re,

                              Pas de problème, je ne suis pas pressé ;)

                              Poste un nouveau rapport hijackthis stp.

                              0
                              1. ok :-)

                                un nouveau rapport hijackthis
                                ok , just a minut
                                0
                                1. le voici :

                                  C:\Windows\system32\Dwm.exe
                                  C:\Windows\Explorer.EXE
                                  C:\Program Files\Windows Defender\MSASCui.exe
                                  C:\Windows\RtHDVCpl.exe
                                  C:\Program Files\epson\Creativity Suite\Event Manager\EEventManager.exe
                                  C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Program Files\Java\jre6\bin\jusched.exe
                                  C:\Program Files\iTunes\iTunesHelper.exe
                                  C:\Program Files\Windows Sidebar\sidebar.exe
                                  C:\Windows\System32\p2phost.exe
                                  C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                  C:\Program Files\Philips\Philips SPC1300NC Webcam\TrayMin1300.exe
                                  C:\Program Files\Internet Explorer\ieuser.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                  C:\Windows\system32\conime.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Windows\system32\NOTEPAD.EXE
                                  C:\Program Files\Trend Micro\HijackThis\HJT.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.medion.com/
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                  O1 - Hosts: ::1 localhost
                                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                  O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
                                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                  O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE"
                                  O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
                                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                  O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
                                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                  O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                  O4 - HKCU\..\Run: [CollaborationHost] C:\Windows\system32\p2phost.exe -s
                                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                  O4 - Global Startup: TrayMin1300.lnk = ?
                                  O8 - Extra context menu item: Ouvrir dans WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
                                  O13 - Gopher Prefix:
                                  O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - https://www.eset.com/
                                  O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-03.sun.com/s/ESD5/JSCDL/jdk/6u10/jinstall-6u10-windows-i586-jc.cab?e=1225974102514&h=ac125b7bf5a3907d5e62b8dc9dcbcc91/&filename=jinstall-6u10-windows-i586-jc.cab
                                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                  O17 - HKLM\System\CCS\Services\Tcpip\..\{B8C9F31C-17DB-41C3-93EC-2B7F7FAC954E}: NameServer = 86.64.145.145 84.103.237.145
                                  O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                  O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                                  O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                                  O23 - Service: O2Micro Flash Memory (O2Flash) - O2Micro International - C:\Windows\system32\o2flash.exe
                                  O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
                                  O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio.exe (file missing)
                                  0
                                  1. Contributeur sécurité
                                    Il manque le début du rapport, peux-tu le poster en entier stp ?

                                    0