Aide pour supprimer Browse Pulse

Aide à la désinfection pour supprimer les virus, adwares, ransomwares, trojans.

Modérateurs : Mods Windows, Helper

Shoowa

Aide pour supprimer Browse Pulse

par Shoowa »

Bonjour,

Je ne parviens pas à supprimer Browse Pulse qui ne cesse d'ouvrir des onglets de pubs ou incruste des annonces sur les pages que je consulte sur Internet.
Je ne suis pas du tout experte en informatique, mais j'ai pu générer les 3 rapports grâce à l'outil FRST en suivant votre tutoriel. Les voici :
Frst : http://pjjoint.malekal.com/files.php?id ... 13b6m14u11
Addition : http://pjjoint.malekal.com/files.php?id ... z14q8s13e5
Shortcut : http://pjjoint.malekal.com/files.php?id ... 5y9h13g9q9

D'après ce que j'ai compris, ces rapports vous sont indispensables pour diagnostiquer et pouvoir apporter une solution.
Je vous remercie d'avance de votre aide

Cordialement
Avatar de l’utilisateur
angelique
Messages : 31535
Inscription : 28 févr. 2008 13:58
Localisation : Breizhilienne

Re: Aide pour supprimer Browse Pulse

par angelique »

  • Désinstalle si tu peux sinon continue:

    Buzzdock (HKLM-x32\...\{cfd32d46-7d3f-483f-bace-7172aec5592d}) (Version: - Alactro LLC)
  • Ouvre le bloc-notes : Menu Démarrer / Tous les programmes / Accessoires et Bloc-Notes. (ou executer---> notepad)
    Copie/colle dedans ce qui suit :

    R2 Service Mgr browsepulse; C:\ProgramData\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15\plugincontainer.exe [648976 2015-07-12] ()
    AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll File not found
    AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => "C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll" File not found
    GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    CHR HKU\S-1-5-21-2389356166-1710917720-1756746154-1001\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    C:\ProgramData\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15
    2015-07-12 00:37 - 2015-07-11 12:52 - 00032016 _____ () C:\Users\Anita\AppData\Local\Temp\{0CC01548-73AC-438B-BE82-7D1F63DB34EB}.xpi
    2015-07-12 00:41 - 2015-07-11 12:52 - 00032016 _____ () C:\Users\Anita\AppData\Local\Temp\{901B4CBF-4E23-45F4-9709-6F0C3FCC08C9}.xpi
    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds& ... earchTerms}
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds& ... earchTerms}
    SearchScopes: HKU\S-1-5-21-2389356166-1710917720-1756746154-1001 -> OldSearch URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
    SearchScopes: HKU\S-1-5-21-2389356166-1710917720-1756746154-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_18 ... earchTerms}
    SearchScopes: HKU\S-1-5-21-2389356166-1710917720-1756746154-1001 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
    SearchScopes: HKU\S-1-5-21-2389356166-1710917720-1756746154-1001 -> {36351101-9B91-4403-A3D5-F99A0A77D8E7} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
    SearchScopes: HKU\S-1-5-21-2389356166-1710917720-1756746154-1001 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
    SearchScopes: HKU\S-1-5-21-2389356166-1710917720-1756746154-1001 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
    SearchScopes: HKU\S-1-5-21-2389356166-1710917720-1756746154-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = http://fr.search.yahoo.com/yhs/search?h ... earchTerms}
    SearchScopes: HKU\S-1-5-21-2389356166-1710917720-1756746154-1001 -> {F6109F05-7762-4FDF-96F7-E53AB945F69C} URL = http://do-search.com/web/?utm_source=b& ... earchTerms}
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1 ... XZ35NSDXVS
    2015-07-11 17:49 - 2015-03-29 22:25 - 00000000 ____D C:\ProgramData\WindowsMangerProtect
    2015-07-11 17:43 - 2015-05-20 23:31 - 00000000 ____D C:\Program Files (x86)\XTab
    2015-07-09 18:54 - 2015-02-15 21:11 - 00000000 ____D C:\Users\Anita\AppData\Local\avaxvbxvgx
    C:\Users\Anita\AppData\Local\Temp\BoxoreInstaller.exe
    C:\Users\Anita\AppData\Local\Temp\fp_pl_pfs_installer-1.exe
    C:\Users\Anita\AppData\Local\Temp\fp_pl_pfs_installer.exe
    C:\Users\Anita\AppData\Local\Temp\HPInstaller.exe
    C:\Users\Anita\AppData\Local\Temp\optprosetup.exe
    C:\Users\Anita\AppData\Local\Temp\SimBundD.exe
    C:\Users\Anita\AppData\Local\Temp\uttA527.tmp.exe
    C:\Users\Anita\AppData\Local\Temp\zafwSetupWeb_120_121_000-4-.exe
    C:\Users\Anita\AppData\Local\Temp\{76A6FAAF-F293-4AB9-90B5-F6821BD73DB7}-43.0.2357.124_43.0.2357.81_chrome_updater.exe
    EmptyTemp:
  • Menu Fichier / Enregistrer-sous
    Place toi sur le bureau.
    Dans le champs en bas, nom du fichier mets : fixlist.txt
    Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.
  • Ferme toutes les applications, y compris ton navigateur
  • Double-clique sur FRST.exe
    /!\ Sous Vista, Windows 7 et 8, il faut lancer le fichier par clic-droit -> Exécuter en tant qu'administrateur
    Sur le menu principal, clique une seule fois sur Fix et patiente le temps de la correction


    Un redémarrage peut être nécessaire (pas obligatoire).
  • L'outil va créer un rapport de correction Fixlog.txt. Poste ce rapport dans ta réponse.
  • Réinitialiser ses navigateurs WEB:
    ---------------------------------

    Dans le cas où vous avez installé des programmes parasites.
    Il peux-être nécessaire de re-paramétrer ses navigateurs WEB.

    ❃ Internet Explorer et modules complémentaires / moteurs de recherche : http://forum.malekal.com/
    ❃ Firefox : http://forum.malekal.com/firefox-extens ... 36057.html
    ❃ Google Chrome : http://forum.malekal.com/google-chrome- ... 35837.html
Avec Gnu_Linux t'as un Noyau ... avec Ѡindows t'as que les pépins
https://helicium.altervista.org/
Supprimer les "virus" gratuitement http://www.supprimer-trojan.com/
Un p'tit Don à Angélique PDT_018 Merci.
Image
Shoowa

Re: Aide pour supprimer Browse Pulse

par Shoowa »

Bonjour Angélique,
Merci de ton aide.
J'ai suivi toutes les étapes. Mon PC a redémarré automatiquement. Je copie/colle le rapport Fixlog.txt:

Fix result of Farbar Recovery Scan Tool (x64) Version:11-07-2015
Ran by Anita at 2015-07-12 13:57:36 Run:1
Running from C:\Users\Anita\Desktop
Loaded Profiles: Anita (Available Profiles: Anita)
Boot Mode: Normal
==============================================

fixlist content:
*****************
R2 Service Mgr browsepulse; C:\ProgramData\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15\plugincontainer.exe [648976 2015-07-12] ()
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll File not found
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => "C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll" File not found
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-2389356166-1710917720-1756746154-1001\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
C:\ProgramData\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15
2015-07-12 00:37 - 2015-07-11 12:52 - 00032016 _____ () C:\Users\Anita\AppData\Local\Temp\{0CC01548-73AC-438B-BE82-7D1F63DB34EB}.xpi
2015-07-12 00:41 - 2015-07-11 12:52 - 00032016 _____ () C:\Users\Anita\AppData\Local\Temp\{901B4CBF-4E23-45F4-9709-6F0C3FCC08C9}.xpi
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds& ... 5NSDXVS&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds& ... 5NSDXVS&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2389356166-1710917720-1756746154-1001 -> OldSearch URL = http://do-search.com/web/?utm_source=b& ... default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2389356166-1710917720-1756746154-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=bl_18 ... b7634a2&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2389356166-1710917720-1756746154-1001 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://do-search.com/web/?utm_source=b& ... default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2389356166-1710917720-1756746154-1001 -> {36351101-9B91-4403-A3D5-F99A0A77D8E7} URL = http://do-search.com/web/?utm_source=b& ... default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2389356166-1710917720-1756746154-1001 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://do-search.com/web/?utm_source=b& ... default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2389356166-1710917720-1756746154-1001 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://do-search.com/web/?utm_source=b& ... default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2389356166-1710917720-1756746154-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = http://fr.search.yahoo.com/yhs/search?h ... _bd_com&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2389356166-1710917720-1756746154-1001 -> {F6109F05-7762-4FDF-96F7-E53AB945F69C} URL = http://do-search.com/web/?utm_source=b& ... default&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1 ... XZ35NSDXVS
2015-07-11 17:49 - 2015-03-29 22:25 - 00000000 ____D C:\ProgramData\WindowsMangerProtect
2015-07-11 17:43 - 2015-05-20 23:31 - 00000000 ____D C:\Program Files (x86)\XTab
2015-07-09 18:54 - 2015-02-15 21:11 - 00000000 ____D C:\Users\Anita\AppData\Local\avaxvbxvgx
C:\Users\Anita\AppData\Local\Temp\BoxoreInstaller.exe
C:\Users\Anita\AppData\Local\Temp\fp_pl_pfs_installer-1.exe
C:\Users\Anita\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Anita\AppData\Local\Temp\HPInstaller.exe
C:\Users\Anita\AppData\Local\Temp\optprosetup.exe
C:\Users\Anita\AppData\Local\Temp\SimBundD.exe
C:\Users\Anita\AppData\Local\Temp\uttA527.tmp.exe
C:\Users\Anita\AppData\Local\Temp\zafwSetupWeb_120_121_000-4-.exe
C:\Users\Anita\AppData\Local\Temp\{76A6FAAF-F293-4AB9-90B5-F6821BD73DB7}-43.0.2357.124_43.0.2357.81_chrome_updater.exe
EmptyTemp:

*****************

Service Mgr browsepulse => Unable to stop service.
Service Mgr browsepulse => Service removed successfully
"C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll" => value data removed successfully.
"C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll" => value data removed successfully.
C:\Windows\system32\GroupPolicy\Machine => moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
"HKU\S-1-5-21-2389356166-1710917720-1756746154-1001\SOFTWARE\Policies\Google" => key removed successfully

"C:\ProgramData\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15" folder move:

Could not move "C:\ProgramData\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15" folder => Scheduled to move on reboot.

C:\Users\Anita\AppData\Local\Temp\{0CC01548-73AC-438B-BE82-7D1F63DB34EB}.xpi => moved successfully.
C:\Users\Anita\AppData\Local\Temp\{901B4CBF-4E23-45F4-9709-6F0C3FCC08C9}.xpi => moved successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
"HKU\S-1-5-21-2389356166-1710917720-1756746154-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\OldSearch" => key removed successfully
HKCR\CLSID\OldSearch => key not found.
"HKU\S-1-5-21-2389356166-1710917720-1756746154-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
"HKU\S-1-5-21-2389356166-1710917720-1756746154-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}" => key removed successfully
HKCR\CLSID\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => key not found.
"HKU\S-1-5-21-2389356166-1710917720-1756746154-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{36351101-9B91-4403-A3D5-F99A0A77D8E7}" => key removed successfully
HKCR\CLSID\{36351101-9B91-4403-A3D5-F99A0A77D8E7} => key not found.
"HKU\S-1-5-21-2389356166-1710917720-1756746154-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}" => key removed successfully
HKCR\CLSID\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5} => key not found.
"HKU\S-1-5-21-2389356166-1710917720-1756746154-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}" => key removed successfully
HKCR\CLSID\{E733165D-CBCF-4FDA-883E-ADEF965B476C} => key not found.
"HKU\S-1-5-21-2389356166-1710917720-1756746154-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}" => key removed successfully
HKCR\CLSID\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key not found.
"HKU\S-1-5-21-2389356166-1710917720-1756746154-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F6109F05-7762-4FDF-96F7-E53AB945F69C}" => key removed successfully
HKCR\CLSID\{F6109F05-7762-4FDF-96F7-E53AB945F69C} => key not found.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => value restored successfully
C:\ProgramData\WindowsMangerProtect => moved successfully.
C:\Program Files (x86)\XTab => moved successfully.
C:\Users\Anita\AppData\Local\avaxvbxvgx => moved successfully.
C:\Users\Anita\AppData\Local\Temp\BoxoreInstaller.exe => moved successfully.
C:\Users\Anita\AppData\Local\Temp\fp_pl_pfs_installer-1.exe => moved successfully.
C:\Users\Anita\AppData\Local\Temp\fp_pl_pfs_installer.exe => moved successfully.
C:\Users\Anita\AppData\Local\Temp\HPInstaller.exe => moved successfully.
C:\Users\Anita\AppData\Local\Temp\optprosetup.exe => moved successfully.
C:\Users\Anita\AppData\Local\Temp\SimBundD.exe => moved successfully.
C:\Users\Anita\AppData\Local\Temp\uttA527.tmp.exe => moved successfully.
C:\Users\Anita\AppData\Local\Temp\zafwSetupWeb_120_121_000-4-.exe => moved successfully.
C:\Users\Anita\AppData\Local\Temp\{76A6FAAF-F293-4AB9-90B5-F6821BD73DB7}-43.0.2357.124_43.0.2357.81_chrome_updater.exe => moved successfully.
EmptyTemp: => 10 GB temporary data Removed.

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-07-12 14:08:51)<=

C:\ProgramData\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15 => moved successfully

==== End of Fixlog 14:08:52 ====
Avatar de l’utilisateur
angelique
Messages : 31535
Inscription : 28 févr. 2008 13:58
Localisation : Breizhilienne

Re: Aide pour supprimer Browse Pulse

par angelique »

ça devrait être bon


➫ supprime frst.exe, ses rapports et C:\FRST



➫ Quelques conseils :


Pour prévenir les sites malicieux, tu peux installer Blockulicious : http://forum.malekal.com/blockulicious- ... 46656.html


Pour ne plus te faire avoir.
A lire - Programmes parasites / PUPs : https://www.malekal.com/adwares-pup-protection/
Avec Gnu_Linux t'as un Noyau ... avec Ѡindows t'as que les pépins
https://helicium.altervista.org/
Supprimer les "virus" gratuitement http://www.supprimer-trojan.com/
Un p'tit Don à Angélique PDT_018 Merci.
Image
Shoowa

Re: Aide pour supprimer Browse Pulse

par Shoowa »

Génial ! :-)
Merci beaucoup de ton coup de main et les conseils du site.
  • Sujets similaires
    Réponses
    Vues
    Dernier message

Revenir à « Supprimer/Desinfecter les virus (Trojan, Adwares, Ransomwares, Backdoor, Spywares) »