Bonjour, une personne infecté de YoogSarch sur un autre forum, je lui donne la manip rcherche 1 qui donne
Yoog_Fix 2.02 de Batch_Man
Debut a 13:58 le 19/04/2009
Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3
Internet Explorer 7.0.5730.11
Mozilla Firefox 3.0.8 (fr)
ALWIL Software 4.8.1335 (Activated)
Check Point, LTD. 7.0.462.000 (Activated)
A:\ [Removable] (Total:0 Mo/Free:0 Mo)
C:\ [Fixed] - FAT32 - (Total:32474 Mo/Free:1102 Mo)
D:\ [Fixed] - NTFS - (Total:40962 Mo/Free:1887 Mo)
E:\ [Fixed] - NTFS - (Total:43770 Mo/Free:3343 Mo)
F:\ [CD-Rom] (Total:72 Mo/Free:0 Mo)
Option [1] 2 Recherche
+---------------\\ Processus cachés/bloqués
1220 -Locked- VSMON.EXE
2012 -Locked- zlclient.exe
+---------------\\ Recherche
----------\\ Recherche de fichiers
----------\\ Recherche dans prefs.js
prefs.js [Kelloggse - uoz1ejat.default] user_pref("browser.search.defaultenginename", "Yoog Search");
prefs.js [Kelloggse - uoz1ejat.default] user_pref("browser.search.defaulturl", "
http://www15.yoog.com/search.php?q=");
prefs.js [Kelloggse - uoz1ejat.default] user_pref("browser.search.selectedEngine", "Yoog Search");
prefs.js [Kelloggse - uoz1ejat.default] user_pref("keyword.URL", "
http://www15.yoog.com/search.php?q=");
user.js [Kelloggse - uoz1ejat.default] user_pref("browser.search.defaultenginename", "Yoog Search");
user.js [Kelloggse - uoz1ejat.default] user_pref("browser.search.defaulturl", "
http://www15.yoog.com/search.php?q=");
user.js [Kelloggse - uoz1ejat.default] user_pref("browser.search.selectedEngine", "Yoog Search");
user.js [Kelloggse - uoz1ejat.default] user_pref("keyword.URL", "
http://www15.yoog.com/search.php?q=");
----------\\ Recherche dans le registre
[HKEY_USERS\S-1-5-21-854245398-261903793-725345543-1007\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] @DisplayName=Yoog Search
[HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] @DisplayName=Yoog Search
----------\\ Infections associées possibles
----------\\ Suspects ( PAS FORCEMENT INFECTIEUX )
+---> Registre
+---> Fichiers
+---------------\\Analyse complémentaire
+---------\\ Tâches planifiées
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-261903793-725345543-1005.job
C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
----------\\ Analyse de Firefox
[C:\Documents and Settings\Fabien\..\prefs.js] browser.search.selectedEngine: GoogleCOM
[C:\Documents and Settings\Kelloggse\..\prefs.js] browser.search.selectedEngine: Yoog Search
[C:\Documents and Settings\Kelloggse\..\prefs.js] browser.search.defaultenginename: Yoog Search
----------\\ Extensions Firefox
[User: LocalService (tq1ty9ef.default)] - E:\fire fox\extensions\{42EE029C-1CB5-484B-9089-A61FE42FBA36}
[User: LocalService (tq1ty9ef.default)] - C:\Program Files\Real\RealPlayer\browserrecord
[User: LocalService (tq1ty9ef.default)] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff
[User: LocalService (tq1ty9ef.default)] - E:\fire fox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[User: Fabien (kpa0laci.default)] - C:\Documents and Settings\Fabien\Application Data\Mozilla\Firefox\Profiles\kpa0laci.default\extensions\{7378B8C2-FC38-41b8-A8C9-875D1F5B0A24}
[User: Fabien (kpa0laci.default)] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff
[User: Fabien (kpa0laci.default)] - E:\fire fox\extensions\{42EE029C-1CB5-484B-9089-A61FE42FBA36}
[User: Fabien (kpa0laci.default)] - C:\Program Files\Real\RealPlayer\browserrecord
[User: Fabien (kpa0laci.default)] - C:\Documents and Settings\Fabien\Application Data\Mozilla\Firefox\Profiles\kpa0laci.default\extensions\
[email protected]
[User: Fabien (kpa0laci.default)] - E:\fire fox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[User: Kelloggse (uoz1ejat.default)] - C:\Documents and Settings\Kelloggse\Application Data\Mozilla\Firefox\Profiles\uoz1ejat.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[User: Kelloggse (uoz1ejat.default)] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff
[User: Kelloggse (uoz1ejat.default)] - E:\fire fox\extensions\{42EE029C-1CB5-484B-9089-A61FE42FBA36}
[User: Kelloggse (uoz1ejat.default)] - C:\Documents and Settings\Kelloggse\Application Data\Mozilla\Firefox\Profiles\uoz1ejat.default\extensions\{e3868d2c-9a68-4c4a-87f2-4e9d78fd16ee}
[User: Kelloggse (uoz1ejat.default)] - C:\Program Files\Real\RealPlayer\browserrecord
[User: Kelloggse (uoz1ejat.default)] - E:\fire fox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
----------\\ Plugins de recherche
[User: Fabien (kpa0laci.default)] - C:\Documents and Settings\..\searchplugins\deezercom.xml: Deezer.com -
http://deezer.com/index.php
----------\\ Listing de dossiers
----------\\ Analyse d'Internet Explorer
HKEY_CURRENT_USER\..\Internet Explorer,Start Page:
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_CURRENT_USER\..\Internet Explorer,Search Page:
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKEY_LOCAL_MACHINE\..\Internet Explorer,Search Page:
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\..\Internet Explorer,Start Page:
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\..\Internet Explorer,Default_Search_URL:
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\..\Internet Explorer,CustomizeSearch:
http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm
HKEY_LOCAL_MACHINE\..\Internet Explorer,SearchAssistant:
http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm
----------\\ Browser Helper Object
BHO: {22BF413B-C6D2-4d91-82A9-A0F997BA588C},@SANS NOM=Skype add-on (mastermind)
BHO: {ccec60fc-2608-4e58-9659-3ffc159e8ea9},@SANS NOM=SHOUTcast Loader
----------\\ SearchScopes
[HKEY_USERS\S-1-5-21-854245398-261903793-725345543-1007\..\SearchScopes],@DefaultScope={40439b93-f815-4122-8073-d03bed94c303}
[HKEY_USERS\S-1-5-21-854245398-261903793-725345543-1007\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}],@DisplayName=Yoog Search
[HKEY_USERS\S-1-5-21-854245398-261903793-725345543-1007\..\SearchScopes\{40439b93-f815-4122-8073-d03bed94c303}],@DisplayName=Winamp Web Search
[HKEY_USERS\S-1-5-21-854245398-261903793-725345543-1007\..\SearchScopes\{6B1E8402-11A1-4A54-85EB-163BD6041081}],@
[email protected],-12512
[HKEY_USERS\S-1-5-21-854245398-261903793-725345543-1007\..\SearchScopes\{B0F4CF12-0238-4EB7-9462-CEEE98188511}],@DisplayName=Google
[HKCU\..\SearchScopes],@DefaultScope={40439b93-f815-4122-8073-d03bed94c303}
[HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}],@DisplayName=Yoog Search
[HKCU\..\SearchScopes\{40439b93-f815-4122-8073-d03bed94c303}],@DisplayName=Winamp Web Search
[HKCU\..\SearchScopes\{6B1E8402-11A1-4A54-85EB-163BD6041081}],@
[email protected],-12512
[HKCU\..\SearchScopes\{B0F4CF12-0238-4EB7-9462-CEEE98188511}],@DisplayName=Google
[HKLM\..\SearchScopes],@DefaultScope={40439b93-f815-4122-8073-d03bed94c303}
[HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}],@
[email protected],-12512
[HKLM\..\SearchScopes\{40439b93-f815-4122-8073-d03bed94c303}],@DisplayName=Winamp Web Search
----------\\ Extensions
@xpsp3res.dll,-20001 : %windir%\Network Diagnostic\xpnetdiag.exe - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16}
Windows Messenger: C:\Program Files\Messenger\msmsgs.exe - {1FBA04EE-3024-11D2-8F1F-0000F87ABD16}
+--------------- Fin à 14h 00min
====================
Rapport Suppression
Yoog_Fix 2.02 de Batch_Man Debut a 14:10 le 19/04/2009 Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3 Internet Explorer 7.0.5730.11 Mozilla Firefox 3.0.8 (fr) ALWIL Software 4.8.1335 (Activated) Check Point, LTD. 7.0.462.000 (Activated) A:\ [Removable] (Total:0 Mo/Free:0 Mo) C:\ [Fixed] - FAT32 - (Total:32474 Mo/Free:1083 Mo) D:\ [Fixed] - NTFS - (Total:40962 Mo/Free:1887 Mo) E:\ [Fixed] - NTFS - (Total:43770 Mo/Free:3343 Mo) F:\ [CD-Rom] (Total:72 Mo/Free:0 Mo) Option 1 [2] Suppression +---------------\\ Suppression ----------\\ Suppression dans de fichiers ----------\\ Suppression dans prefs.js et user.js ----------\\ Suppression dans le registre ----------\\ Fichiers temporaire
============
Je précise que la personne a des problemes de blocnote donc les probleme de mise an lignes ne sont pas en rapports ar contre j'ail'impression qu'aucune suppression n'a été efectuée
Merci
