Merci de votre passage, aider moi

Bonne journée / Soirée.
![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Nous allons essayer de régler ton problème ensemble. D'abord, quelques rappels:
- N'ouvres pas d'autres sujets pour le même problème autre part.
- N'hésites pas à poser des questions en cas de besoin.
- Sois patient(e) quand tu postes un message, je ne réponds pas instantanément:
Je ne suis pas en permanence devant mon ordinateur.
- La désinfection (si nécessaire) va se dérouler en plusieurs étapes. Même si les symptômes de l'infection disparaissent, la désinfection ne sera terminée que quand je te le confirmerai
--> Merci de revenir jusqu'au bout, sinon ce qu'on a fait n'aura servi à rien.
G0 - GCSP: Preference [User Data\Default][HomePage] http://search.babylon.com
G0 - GCSP: Preference [User Data\Default] http://search.babylon.com
M3 - MFPP: Plugins - [user] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\babylon.xml => Infection BT (Toolbar.Babylon)
M0 - MFSP: prefs.js [user - dbpnpmkj.default] http://search.babylon.com
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com
[HKLM\Software\BabylonToolbar] => Infection BT (Toolbar.Babylon)
[HKLM\Software\Babylon] => Infection BT (Toolbar.Babylon)
[HKLM\Software\Boxore] => Infection Diverse (Spyware.Boxore)
O43 - CFD: 01/09/2012 - 23:09:49 - [0] ----D C:\ProgramData\Babylon => Infection BT (Toolbar.Babylon)
O43 - CFD: 01/09/2012 - 23:09:49 - [0,007] ----D C:\Users\user\AppData\Roaming\Babylon => Infection BT (Toolbar.Babylon)
O43 - CFD: 27/08/2012 - 18:45:36 - [62,826] ----D C:\Users\user\AppData\Roaming\OpenCandy => Infection PUP (Adware.OpenCandy)
O44 - LFC:[MD5.A103FDF7348130EF3F3FEF56B1700A27] - 09/08/2012 - 11:23:54 ---A- . (...) -- C:\END [9] => Infection FakeAlert (Trojan.FakeAlert)
O61 - LFC:Last File Created 01/09/2012 - 19:32:50 ---A- C:\Users\user\AppData\Roaming\OpenCandy\944052D9E3FC4D76A677AD4FA6C0ACCF\EBB77268-338F-4C6A-8590-AD88FED26F4A [3827] => Infection PUP (Adware.OpenCandy)
O61 - LFC:Last File Created 01/09/2012 - 22:10:47 ---A- C:\Users\user\AppData\Roaming\Babylon\log_file.txt [7098] => Infection BT (Toolbar.Babylon)
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("browser.search.selectedEngine", "Search the web (Babylon)");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("browser.startup.homepage", "http://search.babylon.com/?affID=113357&tt=3512_2&babsrc=HP_ss&mntrId=5a1eb3030000000000008[...]
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("keyword.URL", "http://search.babylon.com/?affID=113357&tt=3512_2&babsrc=KW_ss&mntrId=5a1eb3030000000000008e55f991483b&q[...]
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("browser.search.defaultenginename", "Search the web (Babylon)");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("browser.search.order.1", "Search the web (Babylon)");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("browser.newtab.url", "http://search.babylon.com/?affID=113357&tt=3512_2&babsrc=NT_ss&mntrId=5a1eb3030000000000008e55f99[...]
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}] => Infection BT (Adware.MyWebSearch)
[HKLM\Software\WOW6432Node\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}] => Infection BT (Toolbar.Babylon)
[HKLM\Software\WOW6432Node\BabylonToolbar] => Infection BT (Toolbar.Babylon)
[HKLM\Software\WOW6432Node\Boxore] => Infection Diverse (Spyware.Boxore)
C:\ProgramData\Babylon => Infection BT (Toolbar.Babylon)
C:\Users\user\AppData\Roaming\Babylon => Infection BT (Toolbar.Babylon)
C:\Users\user\AppData\Roaming\OpenCandy => Infection PUP (Adware.OpenCandy)
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dbpnpmkj.default\Extensions\ffxtlbr@babylon.com
O4 - Global Startup: C:\Users\user\Desktop\BSmax Script [7.2].lnk . (.mIRC Co. Ltd..) -- C:\Program Files (x86)\BSmaxScript[7.2]\mirc.exe
O42 - Logiciel: FATE - (.WildTangent.) [HKLM] -- WTA-00bbf28d-b7c2-491a-9b30-8c70b307c797 => WildTangent Game
O42 - Logiciel: John Deere Drive Green - (.WildTangent.) [HKLM] -- WTA-c5a40275-794a-4863-931d-52a304d66790 => WildTangent
O42 - Logiciel: PackBarre - (.BPMconcept.) [HKLM] -- {6CD11532-5229-4D23-B747-455BD759E6B2} => BPMconcept
O42 - Logiciel: Polar Bowler - (.WildTangent.) [HKLM] -- WTA-d305c20a-b0cd-4743-b836-2f937139991f => WildTangent Game
O42 - Logiciel: Slingo Deluxe - (.WildTangent.) [HKLM] -- WTA-44d1f273-e063-4777-bfa1-c1cd52567fee => WildTangent Game
O43 - CFD: 01/09/2012 - 20:29:58 - [64,568] ----D C:\Program Files (x86)\BSmaxScript[7.2] => BSmaxScript
O43 - CFD: 28/07/2012 - 13:57:24 - [0,283] ----D C:\Program Files (x86)\PackBarre => BPMconcept
O43 - CFD: 07/11/2011 - 17:22:41 - [8,989] ----D C:\Program Files (x86)\WildTangent Games => WildTangent
O43 - CFD: 14/03/2012 - 21:26:33 - [0] ----D C:\Users\user\AppData\Local\{66A989D8-9CA4-4B68-8519-F301D4A19091}
O43 - CFD: 14/03/2012 - 21:26:31 - [0] ----D C:\Users\user\AppData\Local\{DA3176B1-40E4-4B0E-8747-1CCFF11ECDBC}
O43 - CFD: 28/07/2012 - 13:57:24 - [0,003] ----D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PackBarre => BPMconcept
O43 - CFD: 01/09/2012 - 20:29:58 - [64,568] ----D C:\Program Files (x86)\BSmaxScript[7.2] => BSmaxScript
O43 - CFD: 28/07/2012 - 13:57:24 - [0,283] ----D C:\Program Files (x86)\PackBarre => BPMconcept
O43 - CFD: 07/11/2011 - 17:22:41 - [8,989] ----D C:\Program Files (x86)\WildTangent Games => WildTangent
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CT3227982.InstallationType", "ConduitNSISIntegration");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CT3227982.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolb[...]
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CT3227982.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;se[...]
O87 - FAEL: "TCP Query User{407F4C8D-C8D3-4761-93CF-F53457FF78D2}C:\program files (x86)\bsmaxscript[7.2]\mirc.exe" | In - Public - P6 - TRUE | .(.mIRC Co. Ltd. - mIRC.) -- C:\program files (x86)\bsmaxscript[7.2]\mirc.exe
O87 - FAEL: "UDP Query User{5172C994-B1E8-43A7-BE3F-36315FAC03E8}C:\program files (x86)\bsmaxscript[7.2]\mirc.exe" | In - Public - P17 - TRUE | .(.mIRC Co. Ltd. - mIRC.) -- C:\program files (x86)\bsmaxscript[7.2]\mirc.exe
O87 - FAEL: "TCP Query User{AFC4AB5F-6675-4879-AF64-E42899BBA676}C:\program files (x86)\bsmaxscript[7.2]\mirc.exe" | In - Private - P6 - TRUE | .(.mIRC Co. Ltd. - mIRC.) -- C:\program files (x86)\bsmaxscript[7.2]\mirc.exe
O87 - FAEL: "UDP Query User{16FFA57A-121D-4799-AE45-B063A3A750E3}C:\program files (x86)\bsmaxscript[7.2]\mirc.exe" | In - Private - P17 - TRUE | .(.mIRC Co. Ltd. - mIRC.) -- C:\program files (x86)\bsmaxscript[7.2]\mirc.exe
SS - | Demand 12/10/2010 206072 | (GamesAppService) . (.WildTangent, Inc..) - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
SS - | Demand 12/10/2010 206072 | (gpsvc) . (.WildTangent, Inc..) - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
M3 - MFPP: Plugins - [user] -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dbpnpmkj.default\searchplugins\conduit.xml => Toolbar.Conduit
O43 - CFD: 02/09/2012 - 00:44:16 - [0] ----D C:\Program Files (x86)\Software => Toolbar.Agent
O43 - CFD: 01/09/2012 - 23:13:16 - [0] ----D C:\ProgramData\Software => Toolbar.Agent
O43 - CFD: 09/08/2012 - 13:41:05 - [0] ----D C:\Users\user\AppData\Local\Conduit => Toolbar.Conduit
O43 - CFD: 01/09/2012 - 23:10:14 - [0] ----D C:\Users\user\AppData\Local\Software => Toolbar.Agent
O43 - CFD: 02/09/2012 - 00:44:16 - [0] ----D C:\Program Files (x86)\Software => Toolbar.Agent
O69 - SBI: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dbpnpmkj.default\searchplugins\conduit.xml => Toolbar.Conduit
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CT3227982..clientLogServiceUrl", "http://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CT3227982..uninstallLogServiceUrl", "http://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CT3227982.AboutPrivacyUrl", "http://www.conduit.com/privacy/Default.aspx");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CT3227982.GroupingServiceUrl", "http://grouping.services.conduit.com/");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CT3227982.HomepageBeforeUnload", "http://search.conduit.com/?ctid=CT3227982&SearchSource=13");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CT3227982.LanguagePackServiceUrl", "http://translation.users.conduit.com/Translation.ashx");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CT3227982.SearchFromAddressBarUrl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT3227982&SearchSource=2&q=");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CT3227982.SearchInNewTabServiceUrl", "http://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CT3227982.TBHomePageUrl", "http://search.conduit.com/?ctid=CT3227982&SearchSource=13");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CT3227982.TrusteLinkUrl", "http://trust.conduit.com/CT3227982");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CT3227982.myStuffSearchUrl", "http://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&oct[...]
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CT3227982.myStuffServiceUrl", "http://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE[...]
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.ConduitHomepagesList", "http://search.conduit.com/?ctid=CT3227982&SearchSource=13");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.ConduitSearchList", "appbario8 Customized Web Search");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.ETag.http://Settings.toolbar.search.conduit.com/root/CT3227982/CT3227982", "\"1232b2fc21278e1c2646228f[...]
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.ETag.http://alerts.conduit-services.com/root/1663751/1656277/FR", "\"0\"");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.ETag.http://appsmetadata.toolbar.conduit-services.com/?ctid=CT3227982", "\"1339314778\"");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en", "G9mW7heT/8xIX1frcdu[...]
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en", "2E1/v7EfCEDbv3VaBQME[...]
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en", "UgzXjW7BIkfdx+x39Ru[...]
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en", "4BgM4MhF/sOgPsDNmIs3Yw[...]
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.ETag.http://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"8076e3ce381dcd1:0\"");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15.0.0", "\"0e0a4327275cd1:0\"")[...]
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.ETag.http://servicemap.conduit-services.com/Toolbar/?ownerId=CT3227982", "\"c912886ea3ba021d3a9ef2d6ad[...]
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.ETag.http://translation.toolbar.conduit-services.com/?locale=en", "\"c748f69e7a8a0bf03cb98209b0300d00\[...]
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\user\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\dbpnpmkj.defa[...]
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.15.1.0");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.ToolbarsList", "CT3227982");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.ToolbarsList2", "CT3227982");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.ToolbarsList4", "CT3227982");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.globalUserId", "094d760f-7753-4904-abb3-f5d20a2f3d25");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT3227982");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Fri Aug 24 2012 18:53:33 GMT+0200");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.notifications.alertEnabled", true);
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Sun Aug 26 2012 20:20:36 GMT+0200");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.notifications.clientsServerUrl", "http://alert.client.conduit.com");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.notifications.locale", "en");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Sun Aug 26 2012 20:20:28 GMT+0200");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.notifications.servicesServerUrl", "http://alert.services.conduit.com");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.notifications.showTrayIcon", false);
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.notifications.userId", "884fdcd9-c3a0-466c-8879-f376e9a00eda");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.originalHomepage", "chrome://branding/locale/browserconfig.properties");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties");
O69 - SBI: prefs.js [user - dbpnpmkj.default] user_pref("browser.search.defaulturl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT3227982&SearchSource=3&q={searchTerms}");
O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} [DefaultScope] - (Search the web (Babylon)) - http://search.babylon.com => Toolbar.Babylon
O69 - SBI: SearchScopes [HKCU] {B79890AC-BD82-460B-A079-8CA720F9821C} - (appbario8 Customized Web Search) - http://search.conduit.com
C:\Users\user\AppData\Local\Conduit => Toolbar.Conduit
C:\Users\user\AppData\LocalLow\Conduit => Toolbar.Conduit
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\dbpnpmkj.default\SearchPlugins\conduit.xml => Toolbar.Conduit
EmptyTemp
EmptyFlash
FirewallRaz
ProxyFix
/!\ Désactives ton antivirus afin de ne pas ralentir l'analyse et d'afficher des messages d'alerte ! /!\
Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 6 invités
![]() .: Nous contacter :: Flux RSS :: Données personnelles :. ![]() |