buckhulk
Participant
Nombre d'articles : 2398

oui j’ai eu mais plus compliqué pour moi…….!

Au sujet de LimeWire Java PeerToPeer ,P2P.BitTorrent je n'arrive pas à les supprimer car je ne les trouve pas.

je m’en arrangerais….
Windows 7 n’est pas à jour !!

2 anti virus c’est pas bon !

OK bon tu vas passer ce script (et après tu me referas un ZHPDiag pour que je vois ce qu’il reste à faire :

  • Séléctionne et copie le script suivant :

    Script ZHPFix
    ShortcutFix
    O2 - BHO: Shareaza Web Download Hook [64Bits] - {0EEDB912-C5FA-486F-8334-57288578C627} . (.Shareaza Development Team - Shareaza Web Download Hook.) -- C:Program Files (x86)ShareazaRazaWebHook32.dll => P2P.Shareaza*
    O3 - Toolbar: avast! Online Security - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} . (...) -- (.not file.) => Toolbar.Avast
    O3 - Toolbar: (no name) - [HKLM]{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} Clé orpheline => Orphean Key not necessary
    O3 - ToolbarWebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline => Toolbar.Google
    O4 - GSDesktop [Public]: EuroPoker.lnk . (...) -- C:EuroPokerStartEuropoker.fr.exe => OnlineGame.Poker
    O4 - GSDesktop [Public]: PokerStrategy.com Equilab.lnk . (...) -- C:Program Files (x86)PokerStrategy.comPokerStrategy.com EquilabEquilab.exe => Online.PokerGame
    O4 - GSAccessories [postgres]: Run.lnk - Clé orpheline => Orphean Key not necessary
    O4 - GSQuickLaunch [jeanmarie]: Mikogo 4.lnk . (...) -- C:UsersjeanmarieAppDataRoamingMikogo 4mikogo-host.exe
    O4 - GSQuickLaunch [jeanmarie]: PokerStove.lnk . (...) -- C:Program Files (x86)PokerStovePokerStove.exe => PokerStove
    O4 - GSQuickLaunch [jeanmarie]: Shareaza.lnk . (.Shareaza Development Team - Shareaza Ultimate File Sharing.) -- C:Program Files (x86)ShareazaShareaza.exe => P2P.Shareaza*
    O4 - GSProgram [jeanmarie]: Chilipoker.fr.lnk . (.Playtech - Playtech Client Engine Application.) -- C:PokerChilipoker.frcasino.exe
    O4 - GSAccessories [jeanmarie]: Run.lnk - Clé orpheline => Orphean Key not necessary
    O4 - GSDesktop [jeanmarie]: Mikogo 4.lnk . (...) -- C:UsersjeanmarieAppDataRoamingMikogo 4mikogo-host.exe
    O4 - HKUS.DEFAULT..Run: [Mikogo] . (...) -- C:UsersjeanmarieAppDataRoamingMikogo 4mikogo-host.exe
    O4 - HKUSS-1-5-18..Run: [Mikogo] . (...) -- C:UsersjeanmarieAppDataRoamingMikogo 4mikogo-host.exe
    O17 - HKLMSystemCCSServicesTcpipParameters: Domain = DNS
    O23 - Service: Bitdefender 60-Second Virus Scanner Service (pdserv) . (.Bitdefender - 60-Second Scan Service.) - C:Program FilesBitdefender60-Second Virus Scannerpdscan.exe => BitDefender*
    [MD5.00000000000000000000000000000000] [APT] [3d6799c0-7f57-4f60-ab8f-1e65a97fb73f-3] (...) -- C:Program Files (x86)MediaPlayerplus3d6799c0-7f57-4f60-ab8f-1e65a97fb73f-3.exe (.not file.) [0] =>PUP.CrossRider
    [MD5.00000000000000000000000000000000] [APT] [3d6799c0-7f57-4f60-ab8f-1e65a97fb73f-5] (...) -- C:Program Files (x86)MediaPlayerplus3d6799c0-7f57-4f60-ab8f-1e65a97fb73f-5.exe (.not file.) [0] =>PUP.CrossRider
    [MD5.00000000000000000000000000000000] [APT] [6aed6323-ffe2-4460-9bef-d21d53747009-3] (...) -- C:Program Files (x86)Freeven pro 1.26aed6323-ffe2-4460-9bef-d21d53747009-3.exe (.not file.) [0] =>PUP.Freeven
    [MD5.00000000000000000000000000000000] [APT] [6aed6323-ffe2-4460-9bef-d21d53747009-5] (...) -- C:Program Files (x86)Freeven pro 1.26aed6323-ffe2-4460-9bef-d21d53747009-5.exe (.not file.) [0] =>PUP.Freeven
    [MD5.00000000000000000000000000000000] [APT] [{1FF6E270-5B41-45FF-9750-2F1AF2272E75}] (...) -- C:UsersjeanmarieDesktopMAINTENANCERevo UninstallerRevouninstaller.exe (.not file.) [0] => VS Revo Group - Revo Uninstaller
    [MD5.00000000000000000000000000000000] [APT] [{7BF68FF5-F9F1-44D6-AC6A-753D3A591B6D}] (...) -- C:UsersjeanmarieDesktopPokerStoveSetup121.exe (.not file.) [0] => Fichier absent
    [MD5.CCC6996D0DC3D700946DB02CBA713A25] [APT] [{D2848510-5F23-472D-AF44-4FB4EF13462D}] (...) -- C:UsersjeanmarieDownloadspokerstove_pokerstove_anglais_327098.exe [769401]
    O42 - Logiciel: Adobe Flash Player 12 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX => Adobe Systems
    O42 - Logiciel: Bitdefender 60-Second Virus Scanner - (.Bitdefender.) [HKLM][64Bits] -- {CCEA2053-D975-4E38-AC09-4D5E6DAC6B6F} => BitDefender*
    O42 - Logiciel: PokerStove version 1.23 - (...) [HKLM][64Bits] -- {6D0C6BE4-F674-43D2-96BC-3509345108C9}_is1 => PokerStove Game
    O42 - Logiciel: PokerStrategy.com Equilab - (.PokerStrategy.com.) [HKLM][64Bits] -- {86D09F48-CDAB-4B4C-8806-F6C16F17935A}
    O42 - Logiciel: RAW FILE CONVERTER EX powered by SILKYPIX - (.Ichikawa Soft Laboratory.) [HKLM][64Bits] -- InstallShield_{30B1CCDB-209B-4E94-8311-379F2E6B6B59}
    O42 - Logiciel: Shareaza 2.7.3.0 - (.Shareaza Development Team.) [HKLM][64Bits] -- Shareaza_is1 => P2P.Shareaza*
    [HKCUSoftware5ce8dd8b269b915] =>Hijacker.Eazel
    [HKCUSoftwareChilipokerFR] => Chilipoker Game
    [HKCUSoftwareESET] => ESET Online Scanner
    [HKCUSoftwareHoldemManager] => Online Poker Game
    [HKCUSoftwarePokerStove] => Online. PokerGame
    [HKCUSoftwareShareaza] => P2P.Shareaza*
    [HKCUSoftwareWNLT] =>Adware.IncrediBar
    OPT:[HKLMSoftwareBrowserChoice] => Microsoft BrowserChoice
    [HKLMSoftwareESET] => ESET Online Scanner
    [HKLMSoftwareHoldemManager2] => Online Poker Game
    [HKLMSoftwareWow6432NodeFileConverter_1.5] => Toolbar.FileConverter
    [HKLMSoftwareWow6432NodeIncrediMail] => Messaging.Incredimail
    [HKLMSoftwareWow6432NodeMS3]
    [HKLMSoftwareWow6432NodeShareaza] => P2P.Shareaza*
    O43 - CFD: 11/08/2012 - 18:05:20 - [0] ----D C:Program Files (x86)FileConverter_1.5 => Toolbar.FileConverter
    O43 - CFD: 07/11/2011 - 13:34:23 - [] ----D C:Program Files (x86)Full Tilt Poker.Fr => Online. PokerGame
    O43 - CFD: 26/04/2012 - 18:53:30 - [] ----D C:Program Files (x86)LimeWire => LimeWire Java PeerToPeer
    O43 - CFD: 10/09/2011 - 16:13:50 - [] ----D C:Program Files (x86)McAfee
    O43 - CFD: 26/01/2013 - 16:10:41 - [0] ----D C:Program Files (x86)PokerStars.FR => Online.PokerGame
    O43 - CFD: 05/04/2014 - 12:50:47 - [] ----D C:Program Files (x86)PokerStove => Online. PokerGame
    O43 - CFD: 22/03/2014 - 03:01:28 - [] ----D C:Program Files (x86)PokerStrategy.com => Online. PokerGame
    O43 - CFD: 17/04/2014 - 19:41:14 - [0] ----D C:Program Files (x86)predm
    O43 - CFD: 22/03/2014 - 21:56:46 - [] ----D C:Program Files (x86)Shareaza => P2P.Shareaza*
    O43 - CFD: 01/05/2012 - 04:45:52 - [0] ----D C:ProgramDataeMule => P2P.eMule
    O43 - CFD: 10/09/2011 - 16:13:51 - [] ----D C:ProgramDataMcAfee
    O43 - CFD: 23/01/2013 - 00:29:30 - [] ----D C:UsersjeanmarieAppDataRoamingESET => ESET Online Scanner
    O43 - CFD: 21/08/2013 - 19:31:14 - [] ----D C:UsersjeanmarieAppDataRoamingfr.barrierepoker.air => Online.PokerGame
    O43 - CFD: 05/09/2011 - 14:41:30 - [] ----D C:UsersjeanmarieAppDataRoamingfr.barrierepoker.air.D043989C8F5E91300BF71855036B28F854BB8613.1 => OnlineGame.Casino
    O43 - CFD: 17/04/2014 - 00:04:00 - [] ----D C:UsersjeanmarieAppDataRoamingHoldemManager => Online Poker Game
    O43 - CFD: 12/09/2012 - 11:37:51 - [] ----D C:UsersjeanmarieAppDataRoamingShareaza => P2P.Shareaza*
    O43 - CFD: 01/08/2013 - 18:03:54 - [] ----D C:UsersjeanmarieAppDataRoamingwam => Winimax Poker Game
    O43 - CFD: 07/11/2011 - 13:53:44 - [] ----D C:UsersjeanmarieAppDataRoamingwam.04351C371E530C3762CBA45FA283ED972DCDEFB6.1 => Winimax Poker Game
    O43 - CFD: 17/04/2014 - 22:23:51 - [0] ----D C:UsersjeanmarieAppDataLocalCRE => Toolbar.Conduit
    O43 - CFD: 09/04/2014 - 20:42:49 - [] ----D C:UsersjeanmarieAppDataLocalEquilab => Online. PokerGame
    O43 - CFD: 07/03/2013 - 23:00:34 - [] ----D C:UsersjeanmarieAppDataLocalESET => ESET Online Scanner
    O43 - CFD: 05/09/2011 - 15:59:55 - [] ----D C:UsersjeanmarieAppDataLocalFullTiltPoker.fr => Game
    O43 - CFD: 06/03/2012 - 21:19:37 - [] ----D C:UsersjeanmarieAppDataLocalHold'em_Manager => Online Poker Game
    O43 - CFD: 26/01/2013 - 16:10:34 - [0] ----D C:UsersjeanmarieAppDataLocalPokerStars.FR => Online.PokerGame
    O43 - CFD: 01/05/2012 - 05:04:23 - [] ----D C:UsersjeanmarieAppDataLocalShareaza => P2P.Shareaza*
    O44 - LFC:[MD5.F042EE4C8D66248D9B86DCF52ABAE416] - 22/04/2014 - 18:32:14 ---A- . (...) -- C:WindowsPEV.exe [256000] => Possible W32/Heuristic-210!Eldorado
    O44 - LFC:[MD5.0277C027A26428DB64EF4F64F52BB4FD] - 22/04/2014 - 18:32:15 ---A- . (...) -- C:WindowsMBR.exe [208896]
    O53 - SMSR:HKLM...startupregMikogo [Key] . (...) -- C:UsersjeanmarieAppDataRoamingMikogo 4mikogo-host.exe
    O53 - SMSR:HKLM...startupregShareaza [Key] . (.Shareaza Development Team - Shareaza Ultimate File Sharing.) -- C:Program Files (x86)ShareazaShareaza.exe
    O53 - SMSR:HKLM...startupregSpybotSD TeaTimer [Key] . (...) -- C:Program Files (x86)Spybot - Search & DestroyTeaTimer.exe (.not file.) => Safer Net Working%Spybot S&D
    O61 - LFC: 18/04/2014 - 23:49:53 ---A- . (.Enigma Software Group USA, LLC..) -- C:UsersjeanmarieDownloadsSpyHunter-Installer.exe [728960] =>Crapware.SpyHunter
    O61 - LFC: 24/04/2014 - 23:45:36 ---A- . (...) -- C:UsersjeanmarieAppDataLocalAdobeAIH.d55cf7040d4f001d099ae44c8c3c776d04980d30install_flash_player.exe [17929904]
    O61 - LFC: 24/04/2014 - 23:45:51 ---A- . (.Solid State Networks.) -- C:UsersjeanmarieAppDataLocalTempinstall_flashplayer13x32_mssd_aaa_aih.exe [1069776] => Temporary file not necessary
    O61 - LFC: 24/04/2014 - 23:45:53 ---A- . (...) -- C:UsersjeanmarieAppDataLocalLowSunJavajre1.7.0_55lzma.exe [145408]
    O61 - LFC: 24/04/2014 - 23:49:45 ---A- . (...) -- C:UsersjeanmarieAppDataRoamingMikogo 4M4-Capture.exe [1592632]
    O64 - Services: CurCS - 24/04/2014 - C:Program FilesEnigma Software GroupSpyHunteresgiguard.sys (esgiguard) .(...) - LEGACY_ESGIGUARD =>Crapware.SpyHunter
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("browser.search.order.1", "Mysearchdial"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.crossrider.bic", "14570b7e359b3ff0baf533eca3a448ff"); =>PUP.CrossRider
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.AL", 2); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.aflt", "tele_14_11_ff"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzutBtDyC0Azz0AtAtA0D0A0A0DyC0E0E0DtN0D0Tzu0SzztDyCtN1L2XzutBtFtCzztFtBtFtDt[...] =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.cntry", "FR"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.cr", "1769817091"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.dfltLng", ""); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.dfltSrch", true); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.dnsErr", true); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497[...] =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.excTlbr", false); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.hdrMd5", "AA13ECE9FB6E5191B81E40C1D8DF3B3E"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.hmpg", true); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.hmpgUrl", "http://start.mysearchdial.com/?f=1&a=tele_14_11_ff&cd=2XzuyEtN2Y1L1QzutBtDyC0Azz0AtA[...] =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.id", "206A8A33DAAD6EED"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.instlDay", "16145"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.instlRef", "140305_a"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.lastB", "http://start.mysearchdial.com/?f=1&a=tele_14_11_ff&cd=2XzuyEtN2Y1L1QzutBtDyC0Azz0AtAtA[...] =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.lastVrsnTs", "1.8.29.020:39:1"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.newTabUrl", "http://start.mysearchdial.com/?f=2&a=tele_14_11_ff&cd=2XzuyEtN2Y1L1QzutBtDyC0Azz0A[...] =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.pnu_base", "{"newVrsn":"90","lastVrsn":"90","vrsnLoad":"","showMsg":"false","s[...] =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.prdct", "mysearchdial"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.prtnrId", "mysearchdial"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.sg", "none"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.tlbrId", "base"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.tlbrSrchUrl", "http://start.mysearchdial.com/?f=3&a=tele_14_11_ff&cd=2XzuyEtN2Y1L1QzutBtDyC0Azz[...] =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.vrsn", "1.8.29.0"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial.vrsni", "1.8.29.0"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial_i.newTab", false); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial_i.smplGrp", "none"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [jeanmarie - zm15sty0.default-1385923903423] user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.29.020:39:1"); =>Adware.MyWebSearch
    [MD5.965E8C8E82AC591D6F93AC9A809998CF] [SPRF][22/04/2014] (...) -- C:ProgramData1398192506.bdinstall.bin [51298] => BitDedender Random File Installation
    [MD5.233D38A6AFFB8153A888D9DDBABC1208] [SPRF][24/04/2014] (...) -- C:ProgramData1398367380.bdinstall.bin [18338] => BitDedender Random File Installation
    O90 - PUC: "547B38670606DF14AA57B0BB83F3AE4D" . (.SweetIM for Messenger 3.7.) -- C:WindowsInstaller{7683B745-6060-41FD-AA75-0BBB383FEAD4}ARPPRODUCTICON.exe =>PUP.SweetIM
    [HKCUSoftware5ce8dd8b269b915history{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.5.911.18]:guid="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" =>Hijacker.Eazel
    [HKCUSoftware5ce8dd8b269b915history{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.5.911.18]:version="2.5.911.18" =>Hijacker.Eazel
    [HKCUSoftware5ce8dd8b269b915history{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1095.52]:guid="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" =>Hijacker.Eazel
    [HKCUSoftware5ce8dd8b269b915history{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1095.52]:version="2.6.1095.52" =>Hijacker.Eazel
    [HKCUSoftware5ce8dd8b269b915] =>PUP.Babylon^
    HKLMSOFTWAREWow6432NodeMicrosoftTracingBabylonToolbarsrv_RASMANCS =>PUP.Babylon
    HKLMSOFTWAREWow6432NodeMicrosoftTracingbiclient_RASAPI32 =>Adware.MegaSearch
    HKLMSOFTWAREWow6432NodeMicrosoftTracingbiclient_RASMANCS =>Adware.MegaSearch
    HKLMSOFTWAREWow6432NodeMicrosoftTracingBingBar_RASAPI32 =>Toolbar.Bing
    HKLMSOFTWAREWow6432NodeMicrosoftTracingBingBar_RASMANCS =>Toolbar.Bing
    HKLMSOFTWAREWow6432NodeMicrosoftTracingBitTorrent_RASAPI32 =>P2P.BitTorrent
    HKLMSOFTWAREWow6432NodeMicrosoftTracingBitTorrent_RASMANCS =>P2P.BitTorrent
    HKLMSOFTWAREWow6432NodeMicrosoftTracingBuzzSearchSetup_RASAPI32 =>PUP.BuzzSearch
    HKLMSOFTWAREWow6432NodeMicrosoftTracingBuzzSearchSetup_RASMANCS =>PUP.BuzzSearch
    HKLMSOFTWAREWow6432NodeMicrosoftTracingBuzzSearch_Setup_RASAPI32 =>PUP.BuzzSearch
    HKLMSOFTWAREWow6432NodeMicrosoftTracingBuzzSearch_Setup_RASMANCS =>PUP.BuzzSearch
    HKLMSOFTWAREWow6432NodeMicrosoftTracingdlLogic_RASAPI32 =>Toolbar.Conduit
    HKLMSOFTWAREWow6432NodeMicrosoftTracingdlLogic_RASMANCS =>Toolbar.Conduit
    HKLMSOFTWAREWow6432NodeMicrosoftTracingEverest Pokerfr_RASAPI32 =>PUP.Casino
    HKLMSOFTWAREWow6432NodeMicrosoftTracingEverest Pokerfr_RASMANCS =>PUP.Casino
    HKLMSOFTWAREWow6432NodeMicrosoftTracingGoogleToolbarInstaller_en32_signed_RASAPI32 =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracingGoogleToolbarInstaller_en32_signed_RASMANCS =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracinggoogletoolbarinstaller_en64_signed_RASAPI32 =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracinggoogletoolbarinstaller_en64_signed_RASMANCS =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracinggoogletoolbarinstaller_full_signed_RASAPI32 =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracinggoogletoolbarinstaller_full_signed_RASMANCS =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracinggoogletoolbarinstaller_stub_signed_RASAPI32 =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracinggoogletoolbarinstaller_stub_signed_RASMANCS =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracingGoogleToolbarInstaller_updater_signed_RASAPI32 =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracingGoogleToolbarInstaller_updater_signed_RASMANCS =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracingGoogleToolbarManager_08875ABF44579E20_RASAPI32 =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracingGoogleToolbarManager_08875ABF44579E20_RASMANCS =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracingGoogleToolbarManager_94DDE1EDD1CDF6A3_RASAPI32 =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracingGoogleToolbarManager_94DDE1EDD1CDF6A3_RASMANCS =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracingGoogleToolbarManager_B6E98F0202354167_RASAPI32 =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracingGoogleToolbarManager_B6E98F0202354167_RASMANCS =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracingGoogleToolbarManager_F91D44FAA5479127_RASAPI32 =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracingGoogleToolbarManager_F91D44FAA5479127_RASMANCS =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracingGoogleToolbarNotifier_RASAPI32 =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracingGoogleToolbarNotifier_RASMANCS =>Toolbar.Google
    HKLMSOFTWAREWow6432NodeMicrosoftTracingIminentSetup_RASMANCS =>Adware.IMBooster
    HKLMSOFTWAREWow6432NodeMicrosoftTracingincredibar_installer_RASAPI32 =>Adware.IncrediBar
    HKLMSOFTWAREWow6432NodeMicrosoftTracingincredibar_installer_RASMANCS =>Adware.IncrediBar
    HKLMSOFTWAREWow6432NodeMicrosoftTracingMYSEAR~1_RASAPI32 =>Adware.MyWebSearch
    HKLMSOFTWAREWow6432NodeMicrosoftTracingMYSEAR~1_RASMANCS =>Adware.MyWebSearch
    HKLMSOFTWAREWow6432NodeMicrosoftTracingpackage_startertv_installer_multilang_RASAPI32 =>Adware.StarterTV
    HKLMSOFTWAREWow6432NodeMicrosoftTracingpackage_startertv_installer_multilang_RASMANCS =>Adware.StarterTV
    HKLMSOFTWAREWow6432NodeMicrosoftTracingquestscan133_RASMANCS =>Adware.QuestScan
    HKLMSOFTWAREWow6432NodeMicrosoftTracingquestscan137_RASMANCS =>Adware.QuestScan
    HKLMSOFTWAREWow6432NodeMicrosoftTracingquestscan141_RASMANCS =>Adware.QuestScan
    HKLMSOFTWAREWow6432NodeMicrosoftTracingQuickShare_RASAPI32 =>PUP.QuickShare
    HKLMSOFTWAREWow6432NodeMicrosoftTracingQuickShare_RASMANCS =>PUP.QuickShare
    HKLMSOFTWAREWow6432NodeMicrosoftTracingSecondOffer2_RASAPI32 =>PUP.Linkular
    HKLMSOFTWAREWow6432NodeMicrosoftTracingSecondOffer2_RASMANCS =>PUP.Linkular
    HKLMSOFTWAREWow6432NodeMicrosoftTracingSoftonicDownloader_pour_visual-pinball_RASMANCS =>Toolbar.Conduit
    HKLMSOFTWAREWow6432NodeMicrosoftTracingspeedupmypc_RASMANCS =>PUP.SpeedUpMyPC
    HKLMSOFTWAREWow6432NodeMicrosoftTracingSweetIM_RASMANCS =>PUP.SweetIM
    HKLMSOFTWAREWow6432NodeMicrosoftTracingTornTV_RASMANCS =>Hijacker.TornTV
    HKLMSOFTWAREWow6432NodeMicrosoftTracingupdateBuzzSearch_RASAPI32 =>PUP.BuzzSearch
    HKLMSOFTWAREWow6432NodeMicrosoftTracingupdateBuzzSearch_RASMANCS =>PUP.BuzzSearch
    HKLMSOFTWAREWow6432NodeMicrosoftTracingutilBuzzSearch_RASAPI32 =>PUP.BuzzSearch
    HKLMSOFTWAREWow6432NodeMicrosoftTracingutilBuzzSearch_RASMANCS =>PUP.BuzzSearch
    HKLMSOFTWAREWow6432NodeMicrosoftTracingWajamUpdater_RASMANCS =>PUP.Wajam
    HKLMSOFTWAREWow6432NodeMicrosoftTracingYontooSetup-S-1918_RASMANCS =>Adware.Yontoo
    [HKLMSoftwareClassesAppID{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}] =>Adware.Bandoo
    [HKLMSoftwareWow6432NodeClassesAppID{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}] =>Adware.Bandoo
    [HKLMSoftwareClassesAppIDBrowserConnection.dll] =>Adware.Bandoo
    [HKLMSoftwareClassesAppIDDNSBHO.dll] =>Adware.Bandoo
    [HKLMSoftwareWow6432NodeMicrosoftTracingBingBar_RASMANCS] =>Toolbar.Bing
    [HKLMSoftwareWow6432NodeFileConverter_1.5] =>Toolbar.Agent
    [HKCUSoftwareWNLT] =>Adware.IncrediBar
    [HKLMSoftwareWow6432NodeMicrosoftTracingincredibar_installer_RASAPI32] =>Adware.IncrediBar
    [HKLMSoftwareWow6432NodeMicrosoftTracingincredibar_installer_RASMANCS] =>Adware.IncrediBar
    [HKLMSoftwareClassesProd.cap] =>PUP.Babylon
    [HKLMSoftwareWow6432NodeMicrosoftTracingBingBar_RASAPI32] =>Toolbar.Bing
    [HKLMSoftwareClassesInstallerFeatures547B38670606DF14AA57B0BB83F3AE4D] =>PUP.SweetIM
    [HKLMSoftwareClassesInstallerProducts547B38670606DF14AA57B0BB83F3AE4D] =>PUP.SweetIM
    [HKLMSoftwareWow6432NodeClassesInstallerFeatures547B38670606DF14AA57B0BB83F3AE4D] =>PUP.SweetIM
    [HKLMSoftwareWow6432NodeClassesInstallerProducts547B38670606DF14AA57B0BB83F3AE4D] =>PUP.SweetIM
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUpgradeCodes789034A89BAC50E4782F0A7BDBF75632] =>PUP.SweetIM
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components75D5168E5E176C24981B4E5DBD991078] =>PUP.SweetIM
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsF754C503375A13344B22388E18DFE87E] =>PUP.SweetIM
    [HKLMSoftwareWow6432NodeMicrosoftTracingQuickShare_RASAPI32] =>PUP.QuickShare
    [HKLMSoftwareWow6432NodeMicrosoftTracingQuickShare_RASMANCS] =>PUP.QuickShare
    [HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{338C5D66-6B92-40A7-A216-9830D2E54103}] =>Toolbar.Conduit
    [HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{338C5D66-6B92-40A7-A216-9830D2E54103}] =>Toolbar.Conduit
    [HKLMSoftwareWow6432NodeMicrosoftTracingI Want This_RASAPI32] =>Adware.GamePlayLabs
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUpgradeCodesF1057DD419AED0B468AD8888429E139A] =>Adware.IMBooster
    [HKLMSoftwareWow6432NodeMicrosoftTracingspeedupmypc_RASMANCS] =>PUP.SpeedUpMyPC
    [HKLMSoftwareMicrosoftInternet ExplorerSearchScopes{9BB47C17-9C68-4BB3-B188-DD9AF0FD2417}] =>Adware.Bandoo^
    [HKCUSoftware5ce8dd8b269b915history{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.5.911.18]:guid="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" =>Hijacker.Eazel^
    [HKCUSoftware5ce8dd8b269b915history{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1095.52]:guid="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" =>Hijacker.Eazel^
    [HKCUSoftware5ce8dd8b269b915] =>PUP.Babylon^^
    ProxyFix
    EmptyPrefetch
    EmptyFlash
    SysRestore
    FirewallRAZ
    EmptyTemp
  • Lances ZHPFix, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista

    1. Clique sur Importer
    2. Les lignes précedemment copiées doivent être collées dans le cadre
    3. Si c’est le cas, Clic sur « GO« 


    exemple :

  • Confirmes les nettoyages des données en cliquant sur « Oui« 
  • Une fois le scan terminé rends toi sur le bureau, le fichier ZHPFixReport à été crée.
  • Héberge le rapport ZHPFixReport sur SosUpload, puis copie/colle le lien fourni dans ta prochaine réponse.

Tu me referas donc un ZHPDiag après avoir passé ce script car il faudra surement recommencer car trop d’infections diverses
:merci2: