Security-X

Forum Security-X => Désinfections => Discussion démarrée par: HENRIIV le septembre 30, 2013, 20:43:28

Titre: Nettoyage delta search
Posté par: HENRIIV le septembre 30, 2013, 20:43:28
bONJOUR,

Je voudrais me débarrasser de DELTa SEARCH.
J'ai lancé OTL.exe  et obtenu 2 fichiers EXTRA.txt et OTL.txt que j'ai hébergéici:
http://up.security-x.fr/file.php?h=R713fb30f4383092dfaad50805722a552
http://up.security-x.fr/file.php?h=R88b523467c822672bd45c1f613c869fe

merci de votre aide
David
Titre: Re : Nettoyage delta search
Posté par: chantal11 le septembre 30, 2013, 21:10:02
Bonsoir,

Il faut être vigilant sur ce que tu valides lors de l'installation de logiciels gratuits, bien lire les conditions d'utilisation et ne pas accepter tout ce qui est proposé avec (cases pré-cochées).
Stop la pub ! (http://forum.security-x.fr/securite-generale/stop-la-pub/)

---------------------------------------------------------------------------------------------

(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)   Désinstalle via Panneau de configuration -> Programmes et fonctionnalités (si présents) :

Search Protection

---------------------------------------------------------------------------------------------

(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)  OTL :

:OTL
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=FR&userid=39f0e8cd-31ba-4a89-a060-6d828f0019d7&searchtype=ds&q={searchTerms}&installDate=01/01/1970
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3281675&CUI=UN30336542153235818
IE - HKU\S-1-5-21-996900828-564255666-4172760088-1001\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.delta-search.com/?babsrc=HP_ss&mntrId=843270F1A14D7E04&affID=121562&tsp=4930
IE - HKU\S-1-5-21-996900828-564255666-4172760088-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=FR&userid=39f0e8cd-31ba-4a89-a060-6d828f0019d7&searchtype=ds&q={searchTerms}&installDate=01/01/1970
IE - HKU\S-1-5-21-996900828-564255666-4172760088-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=FR&userid=39f0e8cd-31ba-4a89-a060-6d828f0019d7&searchtype=ds&q={searchTerms}&installDate=01/01/1970
IE - HKU\S-1-5-21-996900828-564255666-4172760088-1001\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=FR&userid=39f0e8cd-31ba-4a89-a060-6d828f0019d7&searchtype=ds&q={searchTerms}&installDate=01/01/1970
IE - HKU\S-1-5-21-996900828-564255666-4172760088-1001\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-996900828-564255666-4172760088-1001\..\SearchScopes,DefaultScope = {726379F2-366D-4F2E-9033-A3DFFE941255}
IE - HKU\S-1-5-21-996900828-564255666-4172760088-1001\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=FR&userid=39f0e8cd-31ba-4a89-a060-6d828f0019d7&searchtype=ds&q={searchTerms}&installDate=01/01/1970
IE - HKU\S-1-5-21-996900828-564255666-4172760088-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&babsrc=SP_ss_gin2g&mntrId=843270F1A14D7E04&affID=121562&tsp=4930
IE - HKU\S-1-5-21-996900828-564255666-4172760088-1001\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3281675&CUI=UN30336542153235818
IE - HKU\S-1-5-21-996900828-564255666-4172760088-1001\..\SearchScopes\{F95A6A32-C9BF-4DEF-909F-D07001204896}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=FF&o=14594&src=crm&q={searchTerms}&locale=fr_FR&apn_ptnrs=^FV&apn_dtid=^YYYYYY^YY^FR&apn_uid=79ae1215-e6a8-4f11-8218-33eb7eb9d053&apn_sauid=AF1499F1-BFD2-4B7C-87B2-F008A9325675
FF - prefs.js..browser.search.defaultengine: "Ask.com"
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ihsw.9in@ccx-teqjld-.org: C:\Users\linkinico\AppData\Roaming\Mozilla\Firefox\Profiles\uziatnrt.default\extensions\ihsw.9in@ccx-teqjld-.org [2013/04/22 22:45:20 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}: C:\Program Files (x86)\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi
[2013/05/08 20:49:58 | 000,000,000 | ---D | M] ("Services x86") -- C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\217e8200-a3b3-43df-b951-8ec01d483d7f@b98c6809-1f3f-41a1-bb1c-692cf84781e9.com
[2013/01/06 16:26:49 | 000,000,000 | ---D | M] (Babylon Toolbar) -- C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\ffxtlbr@babylon.com
[2013/04/22 22:45:20 | 000,000,000 | ---D | M] (BBrowse22ssave) -- C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\ihsw.9in@ccx-teqjld-.org
[2013/05/08 20:49:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\217e8200-a3b3-43df-b951-8ec01d483d7f@b98c6809-1f3f-41a1-bb1c-692cf84781e9.com\chrome\content\extensionCode
[2012/10/21 12:11:45 | 000,214,909 | ---- | M] () (No name found) -- C:\Users\linkinico\AppData\Roaming\mozilla\firefox\profiles\uziatnrt.default\extensions\onlinehdtv@onlinehd.tv.xpi
[2013/02/01 13:46:48 | 000,002,334 | ---- | M] () -- C:\Users\linkinico\AppData\Roaming\mozilla\firefox\profiles\uziatnrt.default\searchplugins\askcom.xml
[2013/07/01 20:13:30 | 000,006,505 | ---- | M] () -- C:\Users\linkinico\AppData\Roaming\mozilla\firefox\profiles\uziatnrt.default\searchplugins\babylon.xml
[2013/01/06 16:26:51 | 000,002,432 | ---- | M] () -- C:\Users\linkinico\AppData\Roaming\mozilla\firefox\profiles\uziatnrt.default\searchplugins\babylon1.xml
[2013/07/04 22:00:45 | 000,000,921 | ---- | M] () -- C:\Users\linkinico\AppData\Roaming\mozilla\firefox\profiles\uziatnrt.default\searchplugins\BrowserDefender.xml
[2013/07/01 20:17:19 | 000,001,294 | ---- | M] () -- C:\Users\linkinico\AppData\Roaming\mozilla\firefox\profiles\uziatnrt.default\searchplugins\delta.xml
[2013/04/17 11:24:57 | 000,001,304 | ---- | M] () -- C:\Users\linkinico\AppData\Roaming\mozilla\firefox\profiles\uziatnrt.default\searchplugins\holasearch.xml
[2012/07/04 19:12:04 | 000,000,151 | ---- | M] () -- C:\Users\linkinico\AppData\Roaming\mozilla\firefox\profiles\uziatnrt.default\searchplugins\search.src
CHR - plugin: Perion plugin (Enabled) = C:\Users\linkinico\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\Plugins/PerionNewTabChrome-32.dll
O2:[b]64bit:[/b] - BHO: (no name) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - No CLSID value found.
O2 - BHO: (BBrowse22ssave) - {83681A7A-F48C-45BB-7D7F-7DE7FC696196} - C:\ProgramData\BBrowse22ssave\5175aa75ee01e.dll ()
O2 - BHO: (no name) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - No CLSID value found.
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKU\S-1-5-21-996900828-564255666-4172760088-1001\..\Toolbar\WebBrowser: (no name) - {B80F591E-FE9A-46CF-A13E-180377240586} - No CLSID value found.
O3 - HKU\S-1-5-21-996900828-564255666-4172760088-1001\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKU\S-1-5-21-996900828-564255666-4172760088-1001..\Run: [SearchProtection] C:\Users\linkinico\AppData\Roaming\Search Protection\SearchProtection.EXE (Spigot, Inc.)
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2013/01/06 16:26:23 | 000,000,000 | ---D | M] -- C:\Users\linkinico\AppData\Roaming\Babylon
2013/06/26 22:05:40 | 000,000,000 | ---D | M] -- C:\Users\linkinico\AppData\Roaming\Nosibay
[2013/07/01 20:12:32 | 000,000,000 | ---D | M] -- C:\Users\linkinico\AppData\Roaming\OpenCandy
[2013/07/04 22:00:39 | 000,000,000 | ---D | M] -- C:\Users\linkinico\AppData\Roaming\Search Protection
[2013/02/14 20:00:50 | 000,000,000 | ---D | M] -- C:\Users\linkinico\AppData\Roaming\SpeedMaxPc

:Commands
[EMPTYTEMP]
[CREATERESTOREPOINT]
/!\ Ce script a été établi pour cet utilisateur, il ne doit, en aucun cas, être appliqué sur un autre système, au risque de provoquer de graves dysfonctionnement et endommager Windows /!\

----------------------------------------------------------------------------------------------

(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)  AdwCleaner - Suppression :

Sous IE9 ou IE10, le filtre SmartScreen déclenche une alerte. Cliquer sur Actions puis sur Exécuter quand même

Si ton antivirus émet une alerte ou bloque l'outil, il faut le désactiver temporairement (le fichier AdwCleaner.exe est sûr)

Tutoriel d'utilisation AdwCleaner en images (http://forum.security-x.fr/tutoriels-317/%28tutoriel%29-adwcleaner/)

---------------------------------------------------------------------------------------------

Sont attendus les rapports :
Correctif OTL
AdwCleaner


@+
Titre: Re : Nettoyage delta search
Posté par: HENRIIV le octobre 04, 2013, 20:51:40
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
HKU\S-1-5-21-996900828-564255666-4172760088-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\bProtector Start Page| /E : value set successfully!
HKU\S-1-5-21-996900828-564255666-4172760088-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully!
HKU\S-1-5-21-996900828-564255666-4172760088-1001\SOFTWARE\Microsoft\Internet Explorer\Search\\Default_Search_URL| /E : value set successfully!
HKU\S-1-5-21-996900828-564255666-4172760088-1001\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
HKEY_USERS\S-1-5-21-996900828-564255666-4172760088-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_USERS\S-1-5-21-996900828-564255666-4172760088-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-996900828-564255666-4172760088-1001\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5}\ not found.
Registry key HKEY_USERS\S-1-5-21-996900828-564255666-4172760088-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_USERS\S-1-5-21-996900828-564255666-4172760088-1001\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_USERS\S-1-5-21-996900828-564255666-4172760088-1001\Software\Microsoft\Internet Explorer\SearchScopes\{F95A6A32-C9BF-4DEF-909F-D07001204896}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F95A6A32-C9BF-4DEF-909F-D07001204896}\ not found.
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ihsw.9in@ccx-teqjld-.org deleted successfully.
C:\Users\linkinico\AppData\Roaming\Mozilla\Firefox\Profiles\uziatnrt.default\extensions\ihsw.9in@ccx-teqjld-.org\content folder moved successfully.
C:\Users\linkinico\AppData\Roaming\Mozilla\Firefox\Profiles\uziatnrt.default\extensions\ihsw.9in@ccx-teqjld-.org folder moved successfully.
Registry value HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}\ not found.
File C:\Program Files (x86)\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi not found.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\217e8200-a3b3-43df-b951-8ec01d483d7f@b98c6809-1f3f-41a1-bb1c-692cf84781e9.com\skin folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\217e8200-a3b3-43df-b951-8ec01d483d7f@b98c6809-1f3f-41a1-bb1c-692cf84781e9.com\locale\en-US folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\217e8200-a3b3-43df-b951-8ec01d483d7f@b98c6809-1f3f-41a1-bb1c-692cf84781e9.com\locale folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\217e8200-a3b3-43df-b951-8ec01d483d7f@b98c6809-1f3f-41a1-bb1c-692cf84781e9.com\defaults\preferences folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\217e8200-a3b3-43df-b951-8ec01d483d7f@b98c6809-1f3f-41a1-bb1c-692cf84781e9.com\defaults folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\217e8200-a3b3-43df-b951-8ec01d483d7f@b98c6809-1f3f-41a1-bb1c-692cf84781e9.com\chrome\content\extensionCode folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\217e8200-a3b3-43df-b951-8ec01d483d7f@b98c6809-1f3f-41a1-bb1c-692cf84781e9.com\chrome\content\core folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\217e8200-a3b3-43df-b951-8ec01d483d7f@b98c6809-1f3f-41a1-bb1c-692cf84781e9.com\chrome\content\api folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\217e8200-a3b3-43df-b951-8ec01d483d7f@b98c6809-1f3f-41a1-bb1c-692cf84781e9.com\chrome\content folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\217e8200-a3b3-43df-b951-8ec01d483d7f@b98c6809-1f3f-41a1-bb1c-692cf84781e9.com\chrome folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\217e8200-a3b3-43df-b951-8ec01d483d7f@b98c6809-1f3f-41a1-bb1c-692cf84781e9.com folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\ffxtlbr@babylon.com\META-INF folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\ffxtlbr@babylon.com\content\imgs folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\ffxtlbr@babylon.com\content folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\ffxtlbr@babylon.com\components folder moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\ffxtlbr@babylon.com folder moved successfully.
Folder C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\ihsw.9in@ccx-teqjld-.org\ not found.
Folder C:\Users\linkinico\AppData\Roaming\mozilla\Firefox\Profiles\uziatnrt.default\extensions\217e8200-a3b3-43df-b951-8ec01d483d7f@b98c6809-1f3f-41a1-bb1c-692cf84781e9.com\chrome\content\extensionCode\ not found.
C:\Users\linkinico\AppData\Roaming\mozilla\firefox\profiles\uziatnrt.default\extensions\onlinehdtv@onlinehd.tv.xpi moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\firefox\profiles\uziatnrt.default\searchplugins\askcom.xml moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\firefox\profiles\uziatnrt.default\searchplugins\babylon.xml moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\firefox\profiles\uziatnrt.default\searchplugins\babylon1.xml moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\firefox\profiles\uziatnrt.default\searchplugins\BrowserDefender.xml moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\firefox\profiles\uziatnrt.default\searchplugins\delta.xml moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\firefox\profiles\uziatnrt.default\searchplugins\holasearch.xml moved successfully.
C:\Users\linkinico\AppData\Roaming\mozilla\firefox\profiles\uziatnrt.default\searchplugins\search.src moved successfully.
File C:\Users\linkinico\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\Plugins/PerionNewTabChrome-32.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83681A7A-F48C-45BB-7D7F-7DE7FC696196}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83681A7A-F48C-45BB-7D7F-7DE7FC696196}\ deleted successfully.
C:\ProgramData\BBrowse22ssave\5175aa75ee01e.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-996900828-564255666-4172760088-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{B80F591E-FE9A-46CF-A13E-180377240586} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B80F591E-FE9A-46CF-A13E-180377240586}\ not found.
Registry value HKEY_USERS\S-1-5-21-996900828-564255666-4172760088-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry value HKEY_USERS\S-1-5-21-996900828-564255666-4172760088-1001\Software\Microsoft\Windows\CurrentVersion\Run\\SearchProtection not found.
File C:\Users\linkinico\AppData\Roaming\Search Protection\SearchProtection.EXE not found.
C:\Windows\65F1CF6331E0450B96F34A88BE7361A6.TMP\WiseCustomCalla.dll deleted successfully.
C:\Windows\65F1CF6331E0450B96F34A88BE7361A6.TMP folder deleted successfully.
C:\Users\linkinico\AppData\Roaming\Babylon folder moved successfully.
C:\Users\linkinico\AppData\Roaming\OpenCandy\EE9887B216BF4B2CB215A03DA620FAD8 folder moved successfully.
C:\Users\linkinico\AppData\Roaming\OpenCandy\D355EC6371CA43B2B764F55AF121EA8C folder moved successfully.
C:\Users\linkinico\AppData\Roaming\OpenCandy\50DC316B8AD245878D18A76496E1764E folder moved successfully.
C:\Users\linkinico\AppData\Roaming\OpenCandy\44B3C5FA4E4644D3BDB226C6BE69398A folder moved successfully.
C:\Users\linkinico\AppData\Roaming\OpenCandy\143864E3200148D0931696EDE1049BD3 folder moved successfully.
C:\Users\linkinico\AppData\Roaming\OpenCandy\0F4FE3687A4843FC86E7B0429446FB76 folder moved successfully.
C:\Users\linkinico\AppData\Roaming\OpenCandy folder moved successfully.
Folder C:\Users\linkinico\AppData\Roaming\Search Protection\ not found.
C:\Users\linkinico\AppData\Roaming\SpeedMaxPc\SpeedMaxPc folder moved successfully.
C:\Users\linkinico\AppData\Roaming\SpeedMaxPc folder moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: AppData
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Invité
->Temp folder emptied: 952492 bytes
->Temporary Internet Files folder emptied: 5089440 bytes
->Google Chrome cache emptied: 364488304 bytes
->Flash cache emptied: 745 bytes
 
User: linkinico
->Temp folder emptied: 6677247 bytes
->Temporary Internet Files folder emptied: 50855603 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 377698552 bytes
->Flash cache emptied: 2167 bytes
 
User: Public
 
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 460106453 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50644 bytes
RecycleBin emptied: 127521021 bytes
 
Total Files Cleaned = 1 329,00 mb
 
Bonsoir et merci de votre aide. ;D

System Restore Service not available.
 
OTL by OldTimer - Version 3.2.69.0 log created on 10042013_203509

Files\Folders moved on Reboot...
File\Folder C:\Windows\temp\~bd4845.tmp not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
Titre: Re : Nettoyage delta search
Posté par: chantal11 le octobre 04, 2013, 21:26:59
Bonjour,

Pour plus de lisibilité du sujet, il est préférable d'héberger les rapports sur ce site d'hébergement de fichiers (http://security-x.fr/up/) et indiquer les liens fournis dans ta réponse. Aide en images (http://forum.security-x.fr/cours-et-tutoriels-322/(tutoriel)-impression-d%27ecran-et-hebergement-de-rapport/msg60884/#msg60884)

OK pour le rapport de correction OTL.

En attente du rapport AdwCleaner.

@+
Titre: Re : Nettoyage delta search
Posté par: HENRIIV le octobre 04, 2013, 22:06:02
Ok merci encore

http://up.security-x.fr/file.php?h=Rd608974935c34297d525eed498e8ac10
Titre: Re : Nettoyage delta search
Posté par: chantal11 le octobre 04, 2013, 22:38:16
Re,

OK pour le rapport.

Comment se comporte le système maintenant ?
Plus de soucis avec Delta Search ?


Nous allons mettre à jour et vérifier des applications présentant des failles de sécurité.

---------------------------------------------------------------------------------------------

(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)  Mise à jour d'Internet Explorer :

Même si tu n'utilises pas Internet Explorer comme navigateur, il faut tout de même le mettre à jour et passer sous IE10.
Téléchargez Internet Explorer 10 (http://windows.microsoft.com/fr-FR/internet-explorer/products/ie/home)

---------------------------------------------------------------------------------------------

(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)  SX Check&Update :

Si ton antivirus émet une alerte ou bloque l'outil, il faut le désactiver temporairement (le fichier SXCU.exe est sûr)

---------------------------------------------------------------------------------------------

Est attendu le rapport SXCU

@+
Titre: Re : Nettoyage delta search
Posté par: HENRIIV le octobre 06, 2013, 16:30:37
Bonjour,

Non + de soucis avec delta search: encore mille fois merci.
Voici le nouveau rapport attendu
A bientôt
http://up.security-x.fr/file.php?h=Raf8b2b0ba2b2586f48404354533a7e21
Titre: Re : Nettoyage delta search
Posté par: chantal11 le octobre 06, 2013, 18:38:19
Bonjour,

Tu n'as pas mis Internet Explorer à jour comme demandé, il y a une raison ?
Un navigateur non à jour, même s'il n'est que très peu utilisé, représente une faille de sécurité très exploitée par les malwares.
C'est important de le tenir à jour.

Si plus de soucis sur ce PC avec Delta Search, nous allons pouvoir finaliser la procédure.

---------------------------------------------------------------------------------------------

(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)  TFC - Nettoyage des fichiers temporaires :


---------------------------------------------------------------------------------------------

(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)   DelFix :

- Supprimer les outils de désinfection
 - Purger la restauration système

---------------------------------------------------------------------------------------------

(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fi77.servimg.com%2Fu%2Ff77%2F12%2F97%2F21%2F54%2Farrow511.gif&hash=ce44c49d46cda55a28880d5122c55094392748cc)  Quelques précisions et conseils :

Pourquoi et comment je me fais infecter ? (http://forum.malekal.com/pourquoi-et-comment-je-me-fais-infecter-t3259.html)

/!\ Toujours privilégier le téléchargement d'une application sur le site de l'éditeur

/!\ Bien lire les accords de licence (http://forum.security-x.fr/securite-generale/tuto4pc-et-accord-de-licence/msg53123/#msg53123) avant toute installlation, des études ont montré que La France est championne du monde de malwares ! (http://www.zebulon.fr/actualites/8054-france-championne-monde-malwares.html)

/!\ Etre vigilant au moment de l'installation d'une application, Stop la pub ! (http://forum.security-x.fr/securite-generale/stop-la-pub/)

/!\ Sauvegarder régulièrement les données personnelles sur un support externe

/!\ Ne jamais ouvrir une pièce-jointe dans un mail d'un expéditeur inconnu



N'hésite pas si tu as des questions.

Pour en savoir plus, clique sur l'image pour télécharger ce PDF (https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fwww.malekal.com%2Ffichiers%2Fprojetantimalwares%2Freagir_miniban.gif&hash=60f66ff5bf6c64aea37f0755aa21312762d3420f) (http://www.malekal.com/fichiers/projetantimalwares/ProjetAntiMalware.pdf)