voici le rapport de yoog fix
Yoog_Fix 2.08 de Batch_Man
Debut a 22:51 le 22/06/2009
OS : Microsoft Windows XP
Service Pack : Service Pack 3
Internet Explorer : 7.0.5730.13
Mozilla Firefox : 3.0.11 (fr)
Diablogirl : Administrateur
Proco : Genuine Intel(R) CPU T2250 @ 1.73GHz
Ram : 1014,1 Mo
Mode de démarrage : Normal
Lancé de "C:\Documents and Settings\Diablogirl\Bureau\Yoog_Fix.bat"
Option [1] 2 Recherche
-------------[ Recherche ]-------------
TROUVE - C:\Program Files\Adssite Games Collection
TROUVE - C:\Program Files\Adssite Games Collection
TROUVE - C:\Program Files\Adssite Games Collection
TROUVE - C:\Program Files\Adssite Games Collection
TROUVE - C:\Program Files\Adssite Games Collection
TROUVE - C:\Program Files\Adssite Games Collection
TROUVE - C:\Program Files\Adssite Advanced Toolbar
TROUVE - C:\Program Files\Adssite Advanced Toolbar
TROUVE - C:\Program Files\Adssite Advanced Toolbar
TROUVE - C:\Program Files\Adssite Advanced Toolbar
TROUVE - C:\Program Files\Adssite Advanced Toolbar
TROUVE - C:\Program Files\Adssite Advanced Toolbar
TROUVE - C:\Program Files\Mozilla Firefox\components\b667e9a2-4346-4e8f-68fc-3349a74ada94.dll
TROUVE - C:\Program Files\Mozilla Firefox\components\nsadssite.dll
TROUVE - C:\WINDOWS\System32\d988fc52-73c6-403d-6c29-3c28849ba79b.exe
TROUVE - C:\WINDOWS\System32\d988fc52-73c6-403d-6c29-3c28849ba79b.exe
TROUVE - C:\WINDOWS\System32\d988fc52-73c6-403d-6c29-3c28849ba79b.exe
TROUVE - C:\WINDOWS\System32\whoiscl.exe
TROUVE - C:\Documents and Settings\Diablogirl\Application Data\Mozilla\Firefox\Profiles\bg9wltko.default\searchplugins\Yoog Search.xml
TROUVE - C:\WINDOWS\system32\adssite-remove.exe
TROUVE - C:\WINDOWS\system32\cont_adssite-remove.exe
TROUVE - C:\WINDOWS\system32\gzmrot-uninst.exe
TROUVE - C:\WINDOWS\system32\cont_adssite-remove.exe
TROUVE - HKCR\interface\{81b7f2df-3427-4704-b441-f74a4de94ce1}
TROUVE - HKLM\SOFTWARE\Classes\Interface\{81B7F2DF-3427-4704-B441-F74A4DE94CE1}
TROUVE - HKCR\typelib\{2ed7cd5f-aee2-4b09-82f4-c96eb7c02c87}
TROUVE - HKCU\software\microsoft\hid_layer
TROUVE - HKLM\software\microsoft\windows\currentversion\uninstall\rightonadz
TROUVE - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AdssiteGames
TROUVE - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\d988fc52-73c6-403d-6c29-3c28849ba79b
TROUVE - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\d988fc52-73c6-403d-6c29-3c28849ba79b
TROUVE - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\d988fc52-73c6-403d-6c29-3c28849ba79b
TROUVE - HKEY_USERS\S-1-5-21-4240429896-1842131182-466568329-1005\..\SearchScopes\{D8C0D4AF-7DD7-45B4-9866-196E2B6EC3F9}
TROUVE - [HKCU\Software\Microsoft\Internet Explorer\SearchScopes],@DefaultScope={D8C0D4AF-7DD7-45B4-9866-196E2B6EC3F9}
TROUVE - HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D8C0D4AF-7DD7-45B4-9866-196E2B6EC3F9}
TROUVE - user.js [Diablogirl - bg9wltko.default] user_pref("browser.search.selectedEngine", "Yoog Search");
TROUVE - user.js [Diablogirl - bg9wltko.default] user_pref("keyword.URL", "
http://www1.yoog.com/search.php?q=");
TROUVE - user.js [Diablogirl - bg9wltko.default] user_pref("browser.search.defaultenginename", "Yoog Search");
TROUVE - user.js [Diablogirl - bg9wltko.default] user_pref("browser.search.defaulturl", "
http://www1.yoog.com/search.php?q=");
TROUVE - prefs.js [Diablogirl - bg9wltko.default] user_pref("browser.search.defaultenginename", "Yoog Search");
TROUVE - prefs.js [Diablogirl - bg9wltko.default] user_pref("browser.search.defaulturl", "
http://www1.yoog.com/search.php?q=");
TROUVE - prefs.js [Diablogirl - bg9wltko.default] user_pref("browser.search.selectedEngine", "Yoog Search");
TROUVE - prefs.js [Diablogirl - bg9wltko.default] user_pref("keyword.URL", "
http://www1.yoog.com/search.php?q=");
-------------[ Suspects ]
-------------[ Autres infections ]
--------------[ Analyse complementaire : [Firefox] ]--------------
Mozilla Firefox 3.0.11 (fr)
Firefox non installé : C:\Program Files\Mozilla Firefox
Path Configuration: C:\Documents and Settings\Diablogirl\Application Data\Mozilla\Firefox\Profiles\bg9wltko.default
[C:\Documents and Settings\Diablogirl\..\prefs.js] browser.search.selectedEngine: Yoog Search
[C:\Documents and Settings\Diablogirl\..\prefs.js] browser.search.defaultenginename: Yoog Search
--------[ Extensions Firefox ]
--------[ Mozilla Plugins ]
Path = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
XPTPath = C:\WINDOWS\system32\Macromed\Flash\flashplayer.xpt
ProductName = Adobe® Flash® Player Plugin
Vendor = Adobe Systems Incorporated
Version = 10.0.22.87
Path = C:\Program Files\DivX\DivX Web Player\npdivx32.dll
XPTPath = C:\Program Files\DivX\DivX Web Player\npdivx32.xpt
GeckoVersion = 1.00
Version = 1.0.0
Vendor = DivX,Inc.
ProductName = DivX® Web Player
Path = C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
XPTPath = C:\Program Files\DivX\DivX Content Uploader\npUpload.xpt
GeckoVersion = 1.00
Version = 1.0.0
Vendor = DivX,Inc.
ProductName = DivX® Content Upload Plugin
GeckoVersion = 1.7.5
Path = c:\Program Files\Microsoft Silverlight\2.0.40115.0\npctrl.dll
ProductName = Ag Player
Vendor = Microsoft
Version = 2.0
Path = C:\Program Files\Microsoft\Office Live\npOLW.dll
Version = 1.3
Vendor = Microsoft
ProductName = Microsoft Office Live Plug-in for Firefox
Path = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
GeckoVersion = 1.0
ProductName = Windows Live Photo Gallery
Version = 14.0.8064.0206
Vendor = Microsoft
Path = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
XPTPath = C:\WINDOWS\system32\Macromed\Flash\flashplayer.xpt
ProductName = Adobe Flash Player
Vendor = Adobe Systems Inc.
Version = 9.0.47.0
--------[ Plugins de recherche ]
[Program Files] amazon-france.xml =
http://www.amazon.fr/
[Program Files] eBay-france.xml =
http://search.ebay.fr/
[Program Files] google.xml =
http://www.google.com/firefox
[Program Files] MediaDICO-fr.xml =
http://www.dictionnaire-mediadico.com/dictionnaires.asp
[Program Files] wikipedia-fr.xml =
http://fr.wikipedia.org/wiki/Special:Recherche
[Program Files] yahoo-france.xml =
http://fr.search.yahoo.com/
--------[ Listing de dossiers ]
[07/04/2009 14:45 | --a------ | 683008 bytes] C:\Program Files\Mozilla Firefox\Components\b667e9a2-4346-4e8f-68fc-3349a74ada94.dll
[03/06/2009 06:12 | --a------ | 23032 bytes] C:\Program Files\Mozilla Firefox\Components\browserdirprovider.dll
[03/06/2009 06:12 | --a------ | 134648 bytes] C:\Program Files\Mozilla Firefox\Components\brwsrcmp.dll
[30/12/2008 13:18 | --a------ | 651776 bytes] C:\Program Files\Mozilla Firefox\Components\nsadssite.dll
[27/07/2007 00:03 | --a------ | 717312 bytes] C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll
[03/06/2009 06:12 | --a------ | 65528 bytes] C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[22/03/2007 18:23 | --a------ | 17248 bytes] C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
--------------[ Analyse du Registre ]
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL:
http://fr.yahoo.com/fsc/
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL:
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL:
http://google.fr/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL:
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL:
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
[HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet =
NavigationFailure = res://ieframe.dll/navcancl.htm
DesktopItemNavigationFailure = res://ieframe.dll/navcancl.htm
NavigationCanceled = res://ieframe.dll/navcancl.htm
OfflineInformation = res://ieframe.dll/offcancl.htm
Home = 0x10e
blank = res://mshtml.dll/blank.htm
PostNotCached = res://ieframe.dll/repost.htm
NoAdd-ons = res://ieframe.dll/noaddon.htm
NoAdd-onsInfo = res://ieframe.dll/noaddoninfo.htm
SecurityRisk = res://ieframe.dll/securityatrisk.htm
Tabs = res://ieframe.dll/tabswelcome.htm
--------[ Browser Helper Object ]
BHO: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3},@SANS NOM=3.0
BHO: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac},@SANS NOM=3.0
BHO: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac},@SANS NOM=Windows Live Family Safety Browser Helper
BHO: {53707962-6F74-2D53-2644-206D7942484F},@SANS NOM=3.0
BHO: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B},@SANS NOM=3.0
BHO: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B},@SANS NOM=Search Helper
BHO: {9030D464-4C02-4ABF-8ECC-5164760863C6},@SANS NOM=3.0
BHO: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10},@SANS NOM=3.0
--------[ SearchScopes ]
[HKEY_USERS\S-1-5-21-4240429896-1842131182-466568329-1005\..\SearchScopes],@DefaultScope={D8C0D4AF-7DD7-45B4-9866-196E2B6EC3F9}
[HKEY_USERS\S-1-5-21-4240429896-1842131182-466568329-1005\..\SearchScopes\{861C414C-1204-4874-A6AB-A9B6219E3F5F}],@DisplayName=Google
[HKEY_USERS\S-1-5-21-4240429896-1842131182-466568329-1005\..\SearchScopes\{D8C0D4AF-7DD7-45B4-9866-196E2B6EC3F9}],@DisplayName=Yoog Search
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes],@DefaultScope={D8C0D4AF-7DD7-45B4-9866-196E2B6EC3F9}
[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes],@DefaultScope={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}],@DisplayName=@ieframe.dll,-12512
[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{861C414C-1204-4874-A6AB-A9B6219E3F5F}],@DisplayName=Google
[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D8C0D4AF-7DD7-45B4-9866-196E2B6EC3F9}],@DisplayName=Yoog Search
--------[ Extensions ]
@xpsp3res.dll,-20001 : %windir%\Network Diagnostic\xpnetdiag.exe - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16}
Windows Messenger: C:\Program Files\Messenger\msmsgs.exe - {1FBA04EE-3024-11D2-8F1F-0000F87ABD16}
--------[ Clé Run ]
--------[ Tâches planifiées ]
+--------------[ Autres rapports ]
[22/06/2009 22:53] C:\Yoog_Fix\Yoog_Fix_Rapport_n1.txt - Choix 1 : Recherche
+--------------[ Fin à 22h 53min ]