24/03-2007 à 10:31Bonjour les amis,
Je m'adresse aux spécialistes de la sécurité Internet. Excusez-moi, je dois sûrement déranger. J'ai un peu le même pb. J'ai des caractères chinois bizarres dans la barre d'outils Google. J'ai lancé "HijackThis", et ca a donné ceci. Est-ce qqun aurait la gentillesse de me dire ce qu'il faut retrancher et surtout comment sans commettre d'impair ? J'ai repéré l'intrus suspect suivant :
Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: ÑÅ»¢ÖúÊÖ -
mais je ne sais pas comment le supprimer sans faire de faute. De lĂ ma question et ma crainte.
Merci pour votre soutien. Marie.
Logfile of HijackThis v1.99.1
Scan saved at 01:01:31, on 24/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Fælles filer\Symantec
Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Programmer\Fælles filer\Symantec Shared\Security
Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\System32\alg.exe
C:\Program Filer\Ohé\OHE.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\PROGRA~1\baigoo\bgoomain.exe
C:\Programmer\Microsoft Office\Office10\msoffice.exe
C:\Programmer\Google\GoogleToolbarNotifier\1.2.908.5008\
GoogleToolbarNotifier.exe
C:\Program Files\HIJACKTHIS VF\hijackthis vf.exe
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch =
http://seek.yisou.com/srchcust.htm
R0 - HKCU\Software\Microsoft\Internet
Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ÑÅ»¢ÖúÊÖ -
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} -
C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O2 - BHO: Yahoo! Toolbar Helper -
{02478D38-C3F9-4EFB-9B51-7695ECA05670} -
C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ÑÅ»¢ÖúÊÖ -
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} -
C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O2 - BHO: YDragSearch -
{62EED7C6-9F02-42f9-B634-98E2899E147B} -
C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\YDRAGS~1.DLL
O2 - BHO: bg - {7BDAF75A-0D6F-4F50-AFE9-333D08DF4005} -
C:\Programmer\baigoo\BGooBHO.dll
O2 - BHO: Google Toolbar Helper -
{AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\programmer\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class -
{AE7CD045-E861-484f-8273-0445EE161910} -
C:\Programmer\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: FDMIECookiesBHO Class -
{CC59E0F9-7E43-44FA-9FAA-8377850BF205} -
C:\Programmer\Free Download Manager\iefdmcks.dll
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} -
C:\WINDOWS\DOWNLO~1\CnsHook.dll
O3 - Toolbar: Adobe PDF -
{47833539-D0C5-4125-9FA8-0819E2EAAC93} -
C:\Programmer\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google -
{2318C2B1-4965-11d4-9B18-009027A5CD4F} -
c:\programmer\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: ÑÅ»¢ÖúÊÖ -
{406F94F0-504F-4a40-8DFD-58B0666ABEBD} -
C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll
O4 - HKLM\..\Run: [Ad-watch]
"C:\Programmer\Lavasoft\Ad-aware 6\Ad-watch.exe"
O4 - HKLM\..\Run: [OHE] C:\Program Filer\Ohé\OHE.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles
filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [bgoomain.exe]
C:\PROGRA~1\baigoo\bgoomain.exe
O4 - Global Startup: Microsoft Office.lnk =
C:\Programmer\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: ???? -
res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O8 - Extra context menu item: Convert link target to
Adobe PDF - res://C:\Programmer\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to
existing PDF - res://C:\Programmer\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to
Adobe PDF - res://C:\Programmer\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.ht
ml
O8 - Extra context menu item: Convert selected links to
existing PDF - res://C:\Programmer\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.htm
l
O8 - Extra context menu item: Convert selection to Adobe
PDF - res://C:\Programmer\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to
existing PDF - res://C:\Programmer\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF -
res://C:\Programmer\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF -
res://C:\Programmer\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download all with Free
Download Manager - file://C:\Programmer\Free Download
Manager\dlall.htm
O8 - Extra context menu item: Download selected with
Free Download Manager - file://C:\Programmer\Free
Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free
Download Manager - file://C:\Programmer\Free Download
Manager\dllink.htm
O9 - Extra button: Yahoo 1G mail -
{507F9113-CD77-4866-BA92-0E86DA3D0B97} -
http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yaho
omail (file missing)
O9 - Extra button: E bazar -
{59BC54A2-56B3-44a0-93E5-432D58746E26} -
http://adtaobao.allyes.com/main/adfclick?db=adtaobao&bid
=138,140,18&cid=816,8,1&sid=5042&show=ignore&url=http://
www.taobao.com/vertical/mall/pro.php?allyesPara=816
(file missing)
O9 - Extra button: Yahoo Assistant -
{5D73EE86-05F1-49ed-B850-E423120EC338} -
http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yass
ist (file missing)
O9 - Extra button: (no name) -
{6354ABE6-05F1-49ed-B850-E423120EC338} -
http://cn.widget.yahoo.com/index.htm?source=Cns (file
missing)
O9 - Extra button: Instant Messenger -
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -
http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=yaho
omsg (file missing)
O9 - Extra button: (no name) -
{ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} -
http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repa
ir (file missing)
O9 - Extra 'Tools' menuitem: Repair Browser -
{ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} -
http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=repa
ir (file missing)
O9 - Extra button: (no name) -
{FD00D911-7529-4084-9946-A29F1BDF4FE5} -
http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clea
n (file missing)
O9 - Extra 'Tools' menuitem: Clean Internet access
record - {FD00D911-7529-4084-9946-A29F1BDF4FE5} -
http://cn.zs.yahoo.com/cnsbutton.htm?source=cns&btn=clea
n (file missing)
O9 - Extra button: Correcteur -
{F7C8E5F6-B6D1-45db-8D91-2BCFA5DF11A9} -
C:\PROGRA~1\Druide\Antidote\Antidote\Internet
Explorer\6\Antidote K - IE 6.htm (HKCU)
O9 - Extra button: Dictionnaire -
{FB4AE6A3-EE20-442c-9189-251885352358} -
C:\PROGRA~1\Druide\Antidote\Antidote\Internet
Explorer\6\Antidote D - IE 6.htm (HKCU)
O9 - Extra button: Synonymes -
{FDD637F8-2693-49ce-817E-1AD59574900C} -
C:\PROGRA~1\Druide\Antidote\Antidote\Internet
Explorer\6\Antidote S - IE 6.htm (HKCU)
O9 - Extra button: Conjugueur -
{FF229BEC-9E1F-48c1-99A6-AF34ABEFAB0A} -
C:\PROGRA~1\Druide\Antidote\Antidote\Internet
Explorer\6\Antidote C - IE 6.htm (HKCU)
O9 - Extra button: Grammaire -
{FFB5EE7F-726F-423e-83C2-572FE7CEB3F0} -
C:\PROGRA~1\Druide\Antidote\Antidote\Internet
Explorer\6\Antidote G - IE 6.htm (HKCU)
O20 - Winlogon Notify: WgaLogon -
C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec
Corporation -
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) -
Symantec Corporation - C:\Programmer\Fælles
filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) -
Symantec Corporation - C:\Programmer\Fælles
filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) -
Symantec Corporation - C:\Programmer\Fælles
filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access -
Unknown owner - C:\WINDOWS\system32\CTsvcCDA.exe (file
missing)
O23 - Service: LiveUpdate - Symantec Corporation -
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto Protect Service
(navapsvc) - Symantec Corporation - C:\Programmer\Norton
AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP -
C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation -
C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) -
Symantec Corporation -
C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service
(SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles
filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation -
C:\Programmer\Fælles filer\Symantec
Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec
Corporation - C:\Programmer\Fælles filer\Symantec
Shared\Security Center\SymWSC.exe
----------
Marie