Répondre à : Supprimer Oneline Broswer Advetising2016-09-12T13:44:29+00:00
Anonyme
Nombre d'articles : 0

:hello: ,

Désinstalle le(s) programme(s) suivant(s) :

  • Search Protect

[hr:7nzpeytf]

  • Séléctionne et copie le script suivant :

    Script ZHPFix
    [HKCUSOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvanced] Start_ShowSetProgramAccessAndDefaults: Modified =>PUA.StartShow
    R0 - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://search.conduit.com
    O4 - GSQuickLaunch [NAFFRICHOUX]: BearShare.lnk . (...) -- C:Program Files (x86)BearShare ApplicationsBearShareBearShare.exe (.not file.) =>PUP.BearShare
    O4 - HKCU..Run: [Microsoft Application Manager] C:UsersNAFFRICHOUXAppDataRoamingMicrosoftApplicationManagerstub.exe (.not file.)
    O4 - HKUSS-1-5-21-921676338-1671880322-115735937-1000..Run: [KiesAirMessage] C:Program Files (x86)SamsungKiesKiesAirMessage.exe (.not file.)
    O4 - HKUSS-1-5-21-921676338-1671880322-115735937-1000..Run: [Microsoft Application Manager] C:UsersNAFFRICHOUXAppDataRoamingMicrosoftApplicationManagerstub.exe (.not file.)
    O23 - Service: Search Protect by Conduit Service (CltMngSvc) . (.Conduit - Search Protect by Conduit.) - C:Program Files (x86)SearchProtectMainbinCltMngSvc.exe =>Toolbar.Conduit
    O39 - APT: Scheduled scanning task - (...) -- C:WindowsTasksScheduled scanning task.job [564]
    O39 - APT: Scheduled scanning task - (...) -- C:WindowsSystem32TasksScheduled scanning task [564]
    O43 - CFD: 02/09/2013 - 20:35:55 - [] ----D C:Program Files (x86)BearShare =>PUP.BearShare
    O43 - CFD: 26/04/2014 - 09:13:23 - [] ----D C:Program Files (x86)SearchProtect =>Toolbar.Conduit
    O43 - CFD: 23/02/2014 - 11:16:34 - [] ----D C:ProgramData2210
    O43 - CFD: 24/01/2013 - 18:34:00 - [] ----D C:ProgramDataBearShare =>PUP.BearShare
    O43 - CFD: 24/01/2013 - 18:35:04 - [] --H-D C:ProgramData{D0230206-60AE-4965-A61E-6CA776BF0EB6}
    O43 - CFD: 23/02/2014 - 11:26:35 - [] ----D C:UsersNAFFRICHOUXAppDataLocalBearShare =>PUP.BearShare
    O43 - CFD: 26/04/2014 - 09:13:53 - [] ----D C:UsersNAFFRICHOUXAppDataLocalSearchProtect =>Toolbar.Conduit
    O50 - IFEO:Image File Execution Options - bpsvc.exe - (no data)
    O50 - IFEO:Image File Execution Options - browsersafeguard.exe - (no data) =>PUP.BrowserSafeguard
    O50 - IFEO:Image File Execution Options - dprotectsvc.exe - (no data) =>Trojan.Staser
    O50 - IFEO:Image File Execution Options - protectedsearch.exe - (no data) =>Spyware.ProtectedSearch
    O50 - IFEO:Image File Execution Options - rjatydimofu.exe - (no data)
    O50 - IFEO:Image File Execution Options - searchprotection.exe - (no data) =>Toolbar.Conduit
    O50 - IFEO:Image File Execution Options - searchprotector.exe - (no data) =>Toolbar.Conduit
    O50 - IFEO:Image File Execution Options - snapdo.exe - (no data) =>Hijacker.SmartBar
    O50 - IFEO:Image File Execution Options - stinst32.exe - (no data)
    O50 - IFEO:Image File Execution Options - stinst64.exe - (no data)
    O50 - IFEO:Image File Execution Options - utiljumpflip.exe - (no data) =>PUP.JumpFlip
    O61 - LFC: 23/04/2014 - 10:29:35 ---A- . (.Malwarebytes Corporation.) -- C:UsersNAFFRICHOUXMALWAREBYTES.exe [17305616]
    O61 - LFC: 23/04/2014 - 10:29:35 ---A- . (.Malwarebytes Corporation.) -- C:UsersNAFFRICHOUXmbam-setup-2.0.1.1004.exe [17305616]
    O61 - LFC: 25/04/2014 - 10:28:56 ---A- . (...) -- C:UsersNAFFRICHOUXDesktopShortcut_Module(1).exe [2459136]
    O61 - LFC: 26/04/2014 - 10:29:36 ---A- . (...) -- C:UsersNAFFRICHOUXWinRAR_TSA22KI4J10862fb395954b2638f24898890bac63_wrar501.exe [1769680]
    O61 - LFC: 26/04/2014 - 10:29:36 ---A- . (.ClientConnect.) -- C:UsersNAFFRICHOUXWinRAR_TSA22KI4J.exe [681312]
    O61 - LFC: 28/04/2014 - 10:29:08 ---A- . (.Google Inc..) -- C:UsersNAFFRICHOUXDocumentsTéléchargementsChromeSetup.exe [884712]
    O61 - LFC: 28/04/2014 - 10:29:09 ---A- . (.Mozilla.) -- C:UsersNAFFRICHOUXDownloadsFirefox Setup Stub 28.0 (1).exe [283080]
    O61 - LFC: 28/04/2014 - 10:29:09 ---A- . (.Mozilla.) -- C:UsersNAFFRICHOUXDownloadsFirefox Setup Stub 28.0 (2).exe [283080]
    O61 - LFC: 28/04/2014 - 10:29:09 ---A- . (.Mozilla.) -- C:UsersNAFFRICHOUXDownloadsFirefox Setup Stub 28.0.exe [283080]
    O61 - LFC: 30/04/2014 - 10:28:26 ---A- . (...) -- C:UsersNAFFRICHOUXAppDataLocalTempNEventMessages.dll [1536]
    O61 - LFC: 30/04/2014 - 10:28:26 ---A- . (...) -- C:UsersNAFFRICHOUXAppDataLocalTempNOSEventMessages.dll [1536]
    O61 - LFC: 30/04/2014 - 10:28:55 ---A- . (.OldTimer Tools.) -- C:UsersNAFFRICHOUXDesktopOTM.exe [522240]
    O61 - LFC: 30/04/2014 - 10:28:56 ---A- . (.Nicolas Coolman.) -- C:UsersNAFFRICHOUXDesktopzhpdiag2.exe [6780391] =>.Nicolas Coolman
    O69 - SBI: SearchScopes [HKCU] {814C76CB-2623-43F4-AAD0-58A0E5190A20} [DefaultScope] - (Orange) - http://r.orange.fr
    HKLMSOFTWAREMicrosoftTracingBackupStack_RASAPI32 =>PUP.MyPCBackup
    HKLMSOFTWAREMicrosoftTracingBackupStack_RASMANCS =>PUP.MyPCBackup
    HKLMSOFTWAREMicrosoftTracingSignup Wizard_RASAPI32 =>PUP.JDIBackup
    HKLMSOFTWAREMicrosoftTracingSignup Wizard_RASMANCS =>PUP.JDIBackup
    HKLMSOFTWAREWow6432NodeMicrosoftTracingBabMaint_RASAPI32 =>Hijacker.BabSolution
    HKLMSOFTWAREWow6432NodeMicrosoftTracingBabMaint_RASMANCS =>Hijacker.BabSolution
    HKLMSOFTWAREWow6432NodeMicrosoftTracingBearShare_RASAPI32 =>PUP.BearShare
    HKLMSOFTWAREWow6432NodeMicrosoftTracingBearShare_RASMANCS =>PUP.BearShare
    HKLMSOFTWAREWow6432NodeMicrosoftTracingBearShare_V10_fr_Setup_RASAPI32 =>PUP.BearShare
    HKLMSOFTWAREWow6432NodeMicrosoftTracingBearShare_V10_fr_Setup_RASMANCS =>PUP.BearShare
    HKLMSOFTWAREWow6432NodeMicrosoftTracingupdateglindorus_RASAPI32 =>PUP.Glindorus
    HKLMSOFTWAREWow6432NodeMicrosoftTracingupdateglindorus_RASMANCS =>PUP.Glindorus
    [HKLMSYSTEMCurrentControlSetServicesCltMngSvc] =>Toolbar.Conduit^
    [HKLMSoftwareMicrosoftWindows NTCurrentVersionScheduleTaskCacheTreeVideo-Saver_wd] =>PUP.Video-Saver^
    [HKLMSoftwareMicrosoftWindowsCurrentVersionUninstallSearchProtect] =>Toolbar.Conduit^
    [HKLMSoftwareMicrosoftWindowsCurrentVersionUninstallSoft-Now bundle] =>PUP.SoftNow^
    [HKLMSoftwareClassesAppIDBearShare.exe] =>PUP.BearShare
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsE12F736682067FDE4D1158D5940A82E] =>Toolbar.Ask
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Products90C64EA18BA25EE488BF80DCF07F2FFD] =>Toolbar.Agent
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUpgradeCodesF928123A039649549966D4C29D35B1C9] =>Adware.MyWebSearch
    [HKCUSoftwareSweetIM] =>PUP.SweetIM
    [HKLMSoftwareWow6432NodeSweetIM] =>PUP.SweetIM
    [HKLMSoftwareMicrosoftWindows NTCurrentVersionScheduleTaskCacheTreeScheduled Update for Ask Toolbar] =>Toolbar.AskTBar
    [HKLMSoftwareWow6432NodeMicrosoftWindowsCurrentVersionUninstallSearchProtect] =>Toolbar.Conduit
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUpgradeCodesA97CEC23332751B47BA4B95BAA50C9D0] =>PUP.SweetIM
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components464AA55239C100F32AF2D438EDDC0F47] =>Adware.IMBooster
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components5652BA3D5FB98AE31B337BF0AF939856] =>Adware.IMBooster
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components86EB95E1AFCBABE3DB9ECCC669B99494] =>Adware.IMBooster
    [HKCUSoftwareAppDataLow{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro
    [HKLMSoftwareWow6432Node{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components2124D8A8CF720FD44866190AF560228E] =>PUP.SweetIM^
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components350D17402BD84234EAF7D32F08172D7C] =>PUP.SweetIM^
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsBF4F885EDEE45644EB1E0C99E0162399] =>PUP.SweetIM^
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsC06C6662FA5B04646829E4A460857770] =>PUP.SweetIM^
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsCE21F3FD57B244142880EF15A165A156] =>PUP.SweetIM^
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsED1B5E9A3BDB51349BF96E842C062D98] =>PUP.SweetIM^
    C:Program Files (x86)BearShare =>PUP.BearShare^
    C:Program Files (x86)SearchProtect =>Toolbar.Conduit^
    C:ProgramDataBearShare =>PUP.BearShare^
    C:UsersNAFFRICHOUXAppDataLocalBearShare =>PUP.BearShare^
    C:UsersNAFFRICHOUXAppDataLocalSearchProtect =>Toolbar.Conduit^
    [HKCUSOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvanced] Start_ShowSetProgramAccessAndDefaults: Modified =>PUA.StartShow^
    C:Program Files (x86)SearchProtectSearchProtectbincltmng.exe =>Toolbar.Conduit^
    C:Program Files (x86)SearchProtectUIbincltmngui.exe =>Toolbar.Conduit^
    C:Program Files (x86)SearchProtectMainbinCltMngSvc.exe =>Toolbar.Conduit^
    [HKCUSoftwareBearShare] =>PUP.BearShare^
    [HKCUSoftwareConduit] =>Toolbar.Conduit^
    [HKLMSoftwareWow6432NodeBearShare] =>PUP.BearShare^
    C:WindowsInstaller168fb69.msi =>Adware.Boxore^
    C:WindowsInstaller1dc889.msi =>Adware.IncrediBar^
    C:WindowsInstaller3448aa.msi =>PUP.BearShare^
    C:UsersNAFFRICHOUXDesktopDontSleep.exe
    C:Program Files (x86)SearchProtect
    C:Program Files (x86)BearShare Applications
    C:UsersNAFFRICHOUXAppDataRoamingMicrosoftApplicationManager
    [HKCUSoftwareAppDataLow{1146AC44-2F03-4431-B4FD-889BC837521F}]
    [HKCUSoftwareBearShare] =>PUP.BearShare
    [HKCUSoftwareConduit] =>Toolbar.Conduit
    [HKCUSoftwareCondut]
    [HKCUSoftwareSoftware]
    [HKCUSoftwareSweetIM] =>PUP.SweetIM
    [HKLMSoftwareWow6432NodeBearShare] =>PUP.BearShare
    [HKLMSoftwareWow6432NodeSweetIM] =>PUP.SweetIM
    firewallraz
    emptyclsid
    emptyprefetch
    EmptyCLSID
    Emptytemp
    EmptyFlash
    ShortcutFix
  • Lances ZHPFix, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista

    1. Clique sur Importer
    2. Les lignes précedemment copiées doivent être collées dans le cadre
    3. Si c’est le cas, Clic sur “GO

  • Confirmes les nettoyages des données en cliquant sur “Oui
  • Une fois le scan terminé rends toi sur le bureau, le fichier ZHPFixReport à été crée.
  • Héberge le rapport ZHPFixReport sur SosUpload, puis copie/colle le lien fourni dans ta prochaine réponse.