Virus PUPSC

Résolu
Bonjour,
j'ai lancé spybot search&Destroy, maintenant il me dit qu'il a trouvé 1 élément genre: PUPSC et problème: MyWay.MyWebSearch. Donc j'ai cliqué sur "corriger les problèmes", mais il me dit qu'il ne peut pas le résoudre, mais que en redémarrant l'ordinateur ça pourrait partir. Malheureusement, ça n'a pas fonctionné. Le problème est toujours là. Est ce que quelqu'un peut m'aider à le résoudre svp?
Merci
Configuration: Windows Vista
Firefox 3.0.4

42 réponses

Résumé de la discussion

La problématique porte sur une détection par Spybot - Search & Destroy d'un élément PUPSC et du souci MyWay.MyWebSearch sur Windows Vista et Firefox 3.0.4. En pratique, la meilleure approche consiste à mettre à jour Spybot S&D puis relancer l’analyse, car le nouveau scan peut corriger le PUPSC et permettre un balayage efficace avec Malwarebytes. D’autres éléments demandent de désinstaller des barres d’outils indésirables et d’éviter les téléchargements impulsifs, notamment SweetIM, Ask Toolbar, Yahoo Toolbar, afin d’éviter les réinfections ultérieures. Enfin, des recommandations complémentaires suggèrent de générer et partager les rapports de nettoyage et d’exécuter les outils sous administration, afin de tracer précisément les traces résiduelles.

Bobot (l’IA à votre service)
  1. Alors

    Un petit changement d'antivirus avast pour antivir ferait pas de mal à mon avis. Je te le recommande fortement.

    D'autre part penser à désinstaller les toolbar suivantes :
    Ask
    SweetIM
    WIndows live toolbar
    éventuellement celle de Yahoo (reste tout de même fortement conseillé de la virer)

    Vous en avez un nombre incroyable, vous ne seriez pas du genre à cliquer "frénétiquement" sur "suivant" quand vous installez des programmes ?

    Pour les lignes à fixer :
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/

    R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
    R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
    O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
    O2 - BHO: SweetIM Toolbar Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
    O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
    O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
    O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)

    O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
    O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4471] command /c del "C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8513] cmd /c del "C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL"
    O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb126\Dealio.dll (file missing)
    O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb126\Dealio.dll (file missing)
    O13 - Gopher Prefix:
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-24-0.cab
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    Donc on coche les cases devant les lignes suivantes. Puis on clique sur "Fix checked". On redémarre le PC, on refait un log hijack this et on le poste. merci.

    1. oui je clique tjs sur suivant :S
      dsl mais je ne m'y connais pas trop en informatique, donc je ne suis pas sûre d'avoir bien compris ce que je dois faire maintenant. Déjà pour désinstaller les toolbares, il faut que j'aille où exactement pour le faire? Puis les lignes à fixer que je dois crocher c'est avec le dernier logiciel c'est bien ça?
  2. Bonsoir,
    UN petit coup de Spybot et c'est nettoyé, je n'ai pas d'antivirus depuis 5 ans, juste Spybot jamais eut de problème
    1. merci maître g!rly :)

      je te souhaite également une bonne année 2009 et meilleurs voeux!!! :)

      nyb9
      1. Contributeur
        ok nyb9,

        nos chemins se séparent maintenant...

        je te souhaite une heureuse nouvelle année :)

        ps : si tu trouves le bouton > résolu, sers t´en :)

        c!ao`

        g!rly`
        1. Contributeur
          bon d´accord...
          oui tu peux tout supprimer a l´aide de tool cleaner et en suite supprime tool cleaner...
          1. ah c'est ce que j'avais fait, mais vu que je ne le trouvais pas, je pensais qu'il fallait peut être faire autre chose.

            Est ce que tout est bon maintenant? Je peux supprimer les logiciels hijackthis et toolbar ou j'en ai encore besoin?
            1. Contributeur
              démarrer > mon ordinateur > disk c > program files > askbar si le dossier est la supprime le.
              @+
              1. Contributeur
                ok

                fix aussi :

                O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)

                et vas vérifier et supprimer ceci : C:\Program Files\AskTBar si present

                @+
                1. ok c'est fait et j'ai téléchargé le pare feu, par contre où est ce que je vérifie et supprime ceci : C:\Program Files\AskTBar ?
              2. Contributeur
                salut,

                passe l´option 2 de toolbar sd

                si tu ne l´as plus :

                Télécharge Toolbar-S&D de Eric_71 :
                https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

                puis a l´aide de hijack this coche et fix :

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL (file missing)
                O2 - BHO: (no name) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - (no file)
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com.edgesuite.net/...
                O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-24-0.cab
                O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

                pour plus de secu :

                zone alarm ( y a pas de risque avec celui ci ) avec kerio l´ecran bleu peut arriver mais j´ai jamais rencontré le probleme que tu as eu (restauration de system)???

                https://www.malekal.com/tutoriel-zonealarm-firewall/

                anti spyware :

                spywareblaster :

                http://www.brightfort.com/spywareblaster.html

                c´est un resident, il suffit de le mettre a jour de temps en temps car la version gratuite ne le fait pas toute seul , une fois installé et mis a jour tu mets toutes les protections sur "enable"

                tuto : https://www.malekal.com/tutorial-spywareblaster/

                pour supprimer les outils utilisés, si tout va bien :

                Télécharge ToolsCleaner sur ton bureau.
                --> http://www.commentcamarche.net/telecharger/telechargement 34055291 toolsclean(...)
                # Clique sur Recherche et laisse le scan agir ...
                # Clique sur Suppression pour finaliser.
                # Tu peux, si tu le souhaites, te servir des Options facultatives.
                # Clique sur Quitter pour obtenir le rapport.
                # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                @+
                1. Salut g!rly,

                  je les ai déjà Spywareblaster et ToolsCleaner, merci quand même pour l'info!

                  Je vais faire les étapes suivantes maintenant.

                  Voilà le rapport pour option 2

                  -----------\\ ToolBar S&D 1.2.8 XP/Vista

                  Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                  X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual-Core Processor TK-55 )
                  BIOS : Default System BIOS
                  USER : Doudoune ( Not Administrator ! )
                  BOOT : Normal boot
                  Antivirus : avast! antivirus 4.8.1229 [VPS 081203-0] 4.8.1229 (Activated)
                  C:\ (Local Disk) - NTFS - Total:141 Go (Free:83 Go)
                  D:\ (CD or DVD)

                  "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                  Option : [2] ( 27/12/2008|17:59 )

                  [ UAC => 1 ]

                  -----------\\ Recherche de Fichiers / Dossiers ...

                  -----------\\ [..\Internet Explorer\Main]

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                  "Local Page"="C:\\Windows\\system32\\blank.htm"
                  "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                  "Url"="https://www.msn.com/fr-fr/actualite/"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                  "Start Page"="https://www.msn.com/fr-fr/"
                  "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                  "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                  "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                  --------------------\\ Recherche d'autres infections

                  Aucune autre infection trouvée !

                  [ UAC => 1 ]

                  1 - "C:\ToolBar SD\TB_1.txt" - 27/12/2008|17:59 - Option : [2]

                  -----------\\ Fin du rapport a 17:59:57,12
              3. Contributeur
                salut nyb9,

                j´espere que tu as passé de bonnes fêtes :)

                pour pouvoir continuer, post un rapport hijack this complet stp

                ligne 01 a 023

                @+
                1. Salut g!rly,

                  merci oui j'ai passé de bonnes fêtes, j'espère que c'était également ton cas, voici le rapport:

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 08:48:12, on 27/12/2008
                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                  MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\System32\mobsync.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Windows\RtHDVCpl.exe
                  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\LimeWire\LimeWire.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Program Files\Windows Live\Contacts\wlcomm.exe
                  C:\Program Files\Internet Explorer\IEUser.exe
                  C:\Users\Doudoune\Desktop\HiJackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL (file missing)
                  O2 - BHO: (no name) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - (no file)
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O3 - Toolbar: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
                  O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [Skytel] Skytel.exe
                  O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                  O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
                  O4 - Startup: Outil de notification Live Search.lnk = C:\Users\Doudoune\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O13 - Gopher Prefix:
                  O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
                  O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-24-0.cab
                  O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (file missing)
                  O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                  O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
              4. Contributeur
                salut nyb9,

                que de mal chance...

                post un nouveau rapport hijack this pour voir stp

                jusqu´a quand est remonté la restauration system ?

                @+
                1. Voilà le rapport:

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 07:25:35, on 24/12/2008
                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                  MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                  C:\Windows\RtHDVCpl.exe
                  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\LimeWire\LimeWire.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                  C:\Program Files\Windows Live\Contacts\wlcomm.exe
                  C:\Program Files\Internet Explorer\IEUser.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
                  C:\Users\Doudoune\Downloads\HiJackThis.exe

                  O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
                  O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-24-0.cab
                  O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (file missing)
                  O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                  O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
              5. Contributeur
                salut nyb9,

                je ne comprends pas ?

                tu click sur l´un des liens ci dessous et telecharge le set up ?!

                par feu : kerio

                telechargement : http://www.filehippo.com/download_sunbelt_personal_firewall/tech/468/

                tuto :

                http://www.malekal.com/kerio_firewall.php#mozTocId721480

                https://www.vulgarisation-informatique.com/kerio.php

                https://kerio.probb.fr/f2-sunbelt-kerio-personal-firewall

                Comodo 3 pro :

                https://www.commentcamarche.net/telecharger/ 34055041 comodo firewall pro

                tuto : https://www.malekal.com/tutorial-comodo-firewall/

                Online armor :

                https://www.commentcamarche.net/telecharger/ 34055356 online armor personal firewall

                tuto : https://www.malekal.com/tutorial-online-armor-free/

                ou zone alarm plus facil a configurer mais moins performant

                https://www.malekal.com/tutoriel-zonealarm-firewall/

                @+
                1. bon cette fois j'ai réussi à installer kiero, mais le problème quand il m'a demandée de redémarrer l'ordi, j'ai cliquer OK, puis là écran bleu toute la page écrit en anglais, donc j'ai fait Ctrl+Alt+Supp pour essayer de redémarrer, mais l'ordi était obligé de faire une restauration, car il ne voulait plus redémarrer. Donc je vais laisser tomber pour le pare feu j'ai eu trop peur, mais merci quand même.
                  Je vais juste redésinstaller les logiciels qui sont revenus.
              6. Contributeur
                salut oui supprime ad remover et tool cleaner
                pour le par feu, le par de windows est une passoire, alors je te conseil d´en installer un...
                1. ok j'ai supprimé les logiciels, par contre je n'arrive pas à télécharger le pare feu. Quand je clique sur le lien, je tombe bien sur la bonne page, donc en bas de la page je copie et colle le lien pour aller sur cette page du lien, mais ça ne marche pas.
              7. [ Rapport ToolsCleaner version 2.2.7 (par A.Rothstein & dj QUIOU) ]

                -->- Recherche:

                C:\TB.txt: trouvé !
                C:\_OtMoveIt: trouvé !
                C:\Toolbar SD: trouvé !
                C:\Program Files\Ad-remover\TOOLS\NIRCMD.exe: trouvé !
                C:\Users\Doudoune\Desktop\HijackThis.exe: trouvé !
                C:\Users\Doudoune\Desktop\ToolBarSD.exe: trouvé !
                C:\Users\Doudoune\Desktop\OTMoveIt3.exe: trouvé !
                C:\Windows\NIRCMD.exe: trouvé !

                ---------------------------------
                -->- Suppression:

                C:\Users\Doudoune\Desktop\HijackThis.exe: supprimé !
                C:\Users\Doudoune\Desktop\ToolBarSD.exe: supprimé !
                C:\TB.txt: supprimé !
                C:\Program Files\Ad-remover\TOOLS\NIRCMD.exe: supprimé !
                C:\Users\Doudoune\Desktop\OTMoveIt3.exe: supprimé !
                C:\Windows\NIRCMD.exe: supprimé !
                C:\_OtMoveIt: supprimé !
                C:\Toolbar SD: supprimé !

                SpywareBlaster je l'ai déjà :) mais merci quand même.

                Là il me reste Ad-remover je peux le supprimer dans le panneau de configuration? Et Toolscleaner ou ça peut me servir encore?
                1. ok je vais faire tout ça, par contre ça ne risque rien si je télécharge un pare feu, alors que j'ai déjà le pare feu "windows defender"?
                  1. Contributeur
                    ok nyb9,

                    a l´aide de hijack this coche et fix :

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                    R3 - URLSearchHook: (no name) - {EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
                    O2 - BHO: (no name) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - (no file)
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/...
                    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-24-0.cab
                    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
                    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

                    comment fixer :

                    Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)

                    -> http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

                    ta version de acrobat reader n´est pas a jour, tu veux la derniere verion en date alors desinstale ta version par le panneau de configuration / ajoue et suppression de programme

                    et instale la derniere :

                    https://get2.adobe.com/reader/otherversions/

                    ou oublie completement acrobat reader et instales foxit plus léger a la place:

                    https://www.clubic.com/telecharger-fiche13808-foxit-reader.html

                    pour plus de secu :

                    installes :

                    un par feu :

                    par feu : kerio

                    telechargement : http://www.filehippo.com/download_sunbelt_personal_firewall/tech/468/

                    tuto :

                    http://www.malekal.com/kerio_firewall.php#mozTocId721480

                    https://www.vulgarisation-informatique.com/kerio.php

                    https://kerio.probb.fr/f2-sunbelt-kerio-personal-firewall

                    Comodo 3 pro :

                    http://www.commentcamarche.net/telecharger/telecharger 34055041 comodo firewall pro

                    tuto : https://www.malekal.com/tutorial-comodo-firewall/

                    Online armor :

                    http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall

                    tuto : https://www.malekal.com/tutorial-online-armor-free/

                    ou zone alarm plus facil a configurer mais moins performant

                    https://www.malekal.com/tutoriel-zonealarm-firewall/

                    bonus :

                    anti spyware :

                    spywareblaster :

                    http://www.brightfort.com/spywareblaster.html

                    c´est un resident, il suffit de le mettre a jour de temps en temps car la version gratuite ne le fait pas toute seul , une fois installé et mis a jour tu mets toutes les protections sur "enable"

                    tuto : https://www.malekal.com/tutorial-spywareblaster/

                    pour supprimer les outils utilisés :

                    Télécharge ToolsCleaner sur ton bureau.
                    --> http://www.commentcamarche.net/telecharger/telechargement 34055291 toolsclean(...)
                    # Clique sur Recherche et laisse le scan agir ...
                    # Clique sur Suppression pour finaliser.
                    # Tu peux, si tu le souhaites, te servir des Options facultatives.
                    # Clique sur Quitter pour obtenir le rapport.
                    # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                    voila

                    merci , bonne fêtes a toi également :)

                    @+
                    1. Juste une dernière question: est ce que je peux désinstaller les logiciels que tu m'as fait télécharger, vu que c'est qu'avec des pros comme toi qu'il faut les utiliser?
                      1. J'ai relancé Search&Destroy après l'avoir mis à jour et cette fois il a réussi à corriger le problème PUPSC :)
                        puis j'ai refait une analyse avec Malwarebites' et c'est bon aussi, il n'a rien trouvé, donc je n'ai plus de problème. Finalement il y a que SweetIM que je n'arrive pas à désinstaller. Je ne sais pas si c'est grave ou pas.

                        En tout cas merci beaucoup de m'avoir aidé!!!

                        Bonnes fêtes g!rly !!! :)
                        • 1
                        • 2
                        • 3