Répondre à : [Résolu par Batch_Man] Plus de connection apres un nettoyage sous adwcleaner 2016-09-08T13:42:04+00:00

SOSVirus : Dépannage PC Gratuit Support Aide à la désinfection – Forum Virus Sécurité [Résolu par Batch_Man] Plus de connection apres un nettoyage sous adwcleaner Répondre à : [Résolu par Batch_Man] Plus de connection apres un nettoyage sous adwcleaner

Batch_Man
Participant
Post count: 33

Aucune information sensible te concernant n’est divulgué par les rapports. Tout ce que je vois ici c’est que la photo/videos ça demande l’installation de beaucoup de logiciels :p

Il y a pas mal de choses, si j’ai bien compris tu as restauré la quarantaine de AdwCleaner ?

Désinstalle les logiciels suivants:

  • PC Health Advisor
    FoxTab

Connais-tu “NCH Software” ? Et l’utilises-tu ?

ZHPFix

  • Copie les lignes ci dessous :
    Script ZHPFix
    ProxyFix
    C:UsersThierryAppDataRoamingMozillaFirefoxProfiles7dcujqhs.defaultuser.js
    M3 - MFPP: Plugins - [Thierry] -- C:UsersThierryAppDataRoamingMozillaFirefoxProfiles7dcujqhs.defaultsearchpluginsdelta.xml =>Toolbar.DeltaSearch
    M3 - MFPP: Plugins - [Thierry] -- C:UsersThierryAppDataRoamingMozillaFirefoxProfiles7dcujqhs.defaultsearchpluginsMysearchdial.xml =>Adware.MyWebSearch
    M3 - MFPP: Plugins - [Thierry] -- C:UsersThierryAppDataRoamingMozillaFirefoxProfiles7dcujqhs.defaultsearchpluginsSweetIm.xml =>PUP.SweetIM
    M2 - MFEP: prefs.js [Thierry - 7dcujqhs.defaultffxtlbr@mysearchdial.com] [] mysearchdial.com v1.6.0 (..) =>Adware.MyWebSearch
    O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} Clé orpheline
    O3 - Toolbar: (no name) - [HKLM]{0BF43445-2F28-4351-9252-17FE6E806AA0} Clé orpheline
    O3 - ToolbarWebBrowser: (no name) - [HKCU]{47833539-D0C5-4125-9FA8-0819E2EAAC93} Clé orpheline
    O4 - GSDesktop [Thierry]: ParetoLogic PC Health Advisor.lnk . (.ParetoLogic, Inc. - ParetoLogic PC Health Advisor.) -- C:Program FilesParetoLogicPCHAPCHA.exe =>Rogue.PCHealthAdvisor
    O4 - HKLM..Run: [USBToolTip] . (.Pinnacle Systems GmbH - Pinnacle USB Tip - for Multi Media eXtensio.) -- C:Program FilesPinnacleShared FilesProgramsUSBTipUSBTip.exe
    O4 - HKLM..Run: [ArcSoft Connection Service] . (.ArcSoft Inc. - ArcSoft Connect Daemon.) -- C:Program FilesCommon FilesArcSoftConnection ServiceBinACDaemon.exe
    O4 - HKLM..Run: [Nikon Message Center 2] . (.Nikon Corporation - Nikon Message Center 2.) -- C:Program FilesNikonNikon Message Center 2NkMC2.exe
    O4 - HKLM..Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:Program FilesCommon FilesAppleApple Application SupportAPSDaemon.exe
    O4 - HKLM..Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:Program FilesCommon FilesAdobeOOBEPDAppUWAUpdaterStartupUtility.exe =>.Adobe Systems Incorporated
    O4 - HKLM..Run: [SwitchBoard] . (.Adobe Systems Incorporated - SwitchBoard Server (32 bit).) -- C:Program FilesCommon FilesAdobeSwitchBoardSwitchBoard.exe
    O4 - HKLM..Run: [AdobeCS5.5ServiceManager] . (.Adobe Systems Incorporated - Adobe CS5.5 Service Manager.) -- C:Program FilesCommon FilesAdobeCS5.5ServiceManagerCS5.5ServiceManager.exe
    O4 - HKLM..Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:Program FilesCommon FilesAdobeARM1.0AdobeARM.exe =>.Adobe Systems Incorporated
    O4 - HKLM..Run: [Adobe Acrobat Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:Program FilesAdobeAcrobat 10.0AcrobatAcrobat_sl.exe
    O4 - HKLM..Run: [Acrobat Assistant 8.0] C:Program FilesAdobeAcrobat 8.0AcrobatAcrotray.exe (.not file.)
    O4 - HKLM..Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:Program FilesQuickTimeQTTask.exe
    O4 - HKLM..Run: [NDSTray.exe] Clé orpheline
    O4 - HKLM..Run: [NBKeyScan] C:Program FilesNeroNero8Nero BackItUpNBKeyScan.exe (.not file.)
    O4 - HKLM..Run: [Google EULA Launcher] c:Program FilesGoogleGoogle EULAGoogleEULALauncher.exe (.not file.)
    O4 - HKLM..Run: [cfFncEnabler.exe] Clé orpheline
    O4 - HKLM..Run: [Camera Assistant Software] C:Program FilesCamera Assistant Software for Toshibatraybar.exe (.not file.)
    O4 - HKLM..Run: [AdobeCS5ServiceManager] C:Program FilesCommon FilesAdobeCS5ServiceManagerCS5ServiceManager.exe (.not file.)
    O4 - HKLM..Run: [Adobe Reader Speed Launcher] C:Program FilesAdobeReader 10.0ReaderReader_sl.exe (.not file.)
    O4 - HKCU..Run: [AdobeBridge] Clé orpheline
    O4 - HKCU..Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:Program FilesSkypePhoneSkype.exe =>.Skype Technologies S.A.
    O4 - HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe (.not file.) =>.Microsoft Corporation
    O4 - HKCU..Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:Program FilesCommon FilesNeroLibNMIndexStoreSvr.exe (.not file.)
    O4 - HKUS.DEFAULT..Run: [TOSHIBA Online Product Information] C:Program FilesTOSHIBAToshiba Online Product Informationtopi.exe (.not file.) =>.Toshiba Corporation
    O4 - HKUSS-1-5-18..Run: [TOSHIBA Online Product Information] C:Program FilesTOSHIBAToshiba Online Product Informationtopi.exe (.not file.) =>.Toshiba Corporation
    O4 - HKUSS-1-5-19..Run: [WindowsWelcomeCenter] Clé orpheline
    O4 - HKUSS-1-5-20..Run: [WindowsWelcomeCenter] Clé orpheline
    O4 - HKUSS-1-5-21-1665293871-3462291429-2976931260-1000..Run: [AdobeBridge] Clé orpheline
    O4 - HKUSS-1-5-21-1665293871-3462291429-2976931260-1000..Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:Program FilesSkypePhoneSkype.exe =>.Skype Technologies S.A.
    O4 - HKUSS-1-5-21-1665293871-3462291429-2976931260-1000..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe (.not file.) =>.Microsoft Corporation
    O4 - HKUSS-1-5-21-1665293871-3462291429-2976931260-1000..Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:Program FilesCommon FilesNeroLibNMIndexStoreSvr.exe (.not file.)
    O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} . (...) -- c:toshibaWebshopsebay.ico =>Toolbar.eBay
    O24 - Desktop General: BackupWallPaper - .(...) - C:UsersPublicPicturesSample PicturesSuivez-moi.jpg
    O24 - Desktop General: WallPaper - .(...) - C:UsersPublicPicturesSample PicturesSuivez-moi.jpg
    O39 - APT: - (..) -- C:WindowsTasksFoxTab.job [284]
    O39 - APT: - (..) -- C:WindowsSystem32TasksFoxTab [284]
    O39 - APT: - (..) -- C:WindowsTasksparetologic registration3.job [448] =>PUP.Paretologic
    O39 - APT: - (..) -- C:WindowsSystem32Tasksparetologic registration3 [448] =>PUP.Paretologic
    O39 - APT: - (..) -- C:WindowsTasksparetologic update version3.job [422] =>PUP.Paretologic
    O39 - APT: - (..) -- C:WindowsSystem32Tasksparetologic update version3 [422] =>PUP.Paretologic
    O39 - APT: - (..) -- C:WindowsTasksPC Health Advisor Defrag.job [380] =>Rogue.PCHealthAdvisor
    O39 - APT: - (..) -- C:WindowsSystem32TasksPC Health Advisor Defrag [380] =>Rogue.PCHealthAdvisor
    O39 - APT: APT: - (..) -- C:WindowsTasksPC Health Advisor Defrag.job [380] - (..) -- C:WindowsTasksPC Health Advisor.job [362] =>Rogue.PCHealthAdvisor
    O39 - APT: APT: - (..) -- C:WindowsSystem32TasksPC Health Advisor Defrag [380] - (..) -- C:WindowsSystem32TasksPC Health Advisor [362] =>Rogue.PCHealthAdvisor
    O43 - CFD: 20/05/2014 - 23:36:17 - [] ----D C:Program FilesBabylon =>PUP.Babylon
    O43 - CFD: 20/05/2014 - 23:36:17 - [] ----D C:Program FilesIminent =>Adware.IMBooster
    O43 - CFD: 20/05/2014 - 23:36:17 - [] ----D C:Program FilesParetoLogic =>PUP.Paretologic
    O43 - CFD: 20/05/2014 - 23:36:36 - [] ----D C:Program FilesCommon FilesParetoLogic =>PUP.Paretologic
    O43 - CFD: 20/05/2014 - 23:36:15 - [] ----D C:ProgramDataMovieMode =>PUP.MovieMode
    O43 - CFD: 20/05/2014 - 23:36:16 - [] ----D C:ProgramDataParetoLogic =>PUP.Paretologic
    O43 - CFD: 20/05/2014 - 23:36:16 - [] ----D C:ProgramDataTarma Installer =>PUP.Tarma
    O43 - CFD: 20/05/2014 - 23:36:57 - [] ----D C:UsersThierryAppDataRoamingBabylon =>PUP.Babylon
    O43 - CFD: 20/05/2014 - 23:36:57 - [] ----D C:UsersThierryAppDataRoamingDriverCure =>PUP.DriverCure
    O43 - CFD: 20/05/2014 - 23:36:57 - [] ----D C:UsersThierryAppDataRoamingParetoLogic =>PUP.Paretologic
    O44 - LFC:[MD5.D8C5C232406A6AC6F0E4D2E2749BFFCE] - 21/05/2014 - 10:01:36 ---A- . (...) -- C:WindowsSystem32perfc009.dat [104914]
    O44 - LFC:[MD5.6500E1686AADB8A0A270535EBC9DEB62] - 21/05/2014 - 10:01:36 ---A- . (...) -- C:WindowsSystem32perfc00C.dat [127504]
    O44 - LFC:[MD5.4DE66EFAAD8D8B56817F95B1AC1CCE7B] - 21/05/2014 - 10:01:36 ---A- . (...) -- C:WindowsSystem32perfh009.dat [598900]
    O44 - LFC:[MD5.3E093FACF3BA7D9F92E12C205F2C06BA] - 21/05/2014 - 10:01:36 ---A- . (...) -- C:WindowsSystem32perfh00C.dat [681798]
    O51 - MPSK:{86519f4e-bcf5-11e0-a143-00269e2f2e63}AutoRuncommand. (...) -- I:setup.exe (.not file.)
    O51 - MPSK:{a1cef035-abb5-11df-be3b-00269e2f2e63}AutoRuncommand. (...) -- H:LaunchU3.exe (.not file.)
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.BabylonToolbar.admin", false); =>PUP.Babylon
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.BabylonToolbar.aflt", "babsst"); =>PUP.Babylon
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}"); =>PUP.Babylon
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.BabylonToolbar.dfltLng", "en"); =>PUP.Babylon
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.BabylonToolbar.excTlbr", false); =>PUP.Babylon
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.BabylonToolbar.id", "44417768000000000000001e65a06bca"); =>PUP.Babylon
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.BabylonToolbar.instlDay", "15676"); =>PUP.Babylon
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.BabylonToolbar.instlRef", "na"); =>PUP.Babylon
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); =>PUP.Babylon
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); =>PUP.Babylon
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.BabylonToolbar.tlbrId", "irhnew"); =>PUP.Babylon
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "http://search.babylon.com/?babsrc=TB_def&mntrId=44417768000000000000001e65a06b[...] =>PUP.Babylon
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.BabylonToolbar.vrsn", "1.8.3.8"); =>PUP.Babylon
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.BabylonToolbar.vrsni", "1.8.3.8"); =>PUP.Babylon
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); =>PUP.Babylon
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.3.820:00:37"); =>PUP.Babylon
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.admin", false);
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.aflt", "babsst");
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.autoRvrt", "false");
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.dfltLng", "en");
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.excTlbr", false);
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.id", "44417768000000000000001e65a06bca");
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.instlDay", "15752");
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.instlRef", "sst");
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.newTab", false);
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.prdct", "delta");
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.prtnrId", "delta");
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.rvrt", "false");
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.smplGrp", "none");
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.tlbrId", "base");
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.tlbrSrchUrl", "");
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.vrsn", "1.8.10.0");
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.vrsnTs", "1.8.10.011:51:17");
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.delta.vrsni", "1.8.10.0");
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.enabledAddons", "%7B4D9AE42B-F4C0-40e6-AEDB-4EC6E42B77AF%7D:1.2.5.0,ffxtlbr%40mysearchdial.com:1.6.0,plugin%[...] =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.AL", 2); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.aflt", "tele0202ff"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzutDtDtByCzy0EtB0FtB0EyCtAyByByCzztN0D0Tzu0SyBzzzytN1L2XzutBtFtBtFtCyDtFtCy[...] =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.cr", "1302682962"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.dfltLng", ""); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.dfltSrch", true); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.dnsErr", true); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.excTlbr", false); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.hmpg", true); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.hmpgUrl", "http://start.mysearchdial.com/?f=1&a=tele0202ff&cd=2XzuyEtN2Y1L1QzutDtDtByCzy0EtB0Ft[...] =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.id", "00269E2F2E637768"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.instlDay", "16128"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.instlRef", ""); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.newTabUrl", "http://start.mysearchdial.com/?f=2&a=tele0202ff&cd=2XzuyEtN2Y1L1QzutDtDtByCzy0EtB0[...] =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.prdct", "mysearchdial"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.prtnrId", "mysearchdial"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.tlbrId", "base"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.tlbrSrchUrl", "http://start.mysearchdial.com/?f=3&a=tele0202ff&cd=2XzuyEtN2Y1L1QzutDtDtByCzy0Et[...] =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.vrsn", "1.8.21.0"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial.vrsni", "1.8.21.0"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial_i.hmpg", true); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial_i.newTab", false); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial_i.smplGrp", "none"); =>Adware.MyWebSearch
    O69 - SBI: prefs.js [Thierry - 7dcujqhs.default] user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.020:5:25"); =>Adware.MyWebSearch
    E:en plus persofredantis toutKeygen_Zemana_AntiLogger_1.9.x.xxx_-_SND.exe =>.Crack,Keygen
    [MD5.67C006BB114572D1B45648E451D426A3] [WIS][04/01/2013] (.SweetIM Technologies Ltd. - SweetPacks bundle uninstaller.) -- C:WindowsInstaller46d3323.msi [2555392] =>PUP.SweetIM
    [HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{C9A6357B-25CC-4BCF-96C1-78736985D412}] =>Toolbar.Orange
    [HKLMSoftwareClassesCLSID{C9A6357B-25CC-4BCF-96C1-78736985D412}] =>Toolbar.Orange
    C:UsersThierryAppDataRoamingMozillaFirefoxProfiles7dcujqhs.defaultextensionsffxtlbr@mysearchdial.com =>Adware.MyWebSearch^
    C:Program FilesBabylon =>PUP.Babylon^
    C:Program FilesIminent =>Adware.IMBooster^
    C:Program FilesParetoLogic =>PUP.Paretologic^
    C:Program FilesCommon FilesParetoLogic =>PUP.Paretologic^
    C:ProgramDataMovieMode =>PUP.MovieMode^
    C:ProgramDataParetoLogic =>PUP.Paretologic^
    C:ProgramDataTarma Installer =>PUP.Tarma^
    C:UsersThierryAppDataRoamingBabylon =>PUP.Babylon^
    C:UsersThierryAppDataRoamingDriverCure =>PUP.DriverCure^
    C:UsersThierryAppDataRoamingParetoLogic =>PUP.Paretologic^
    C:UsersThierryAppDataLocalWajam =>PUP.Wajam^
    C:UsersThierryAppDataRoamingMicrosoftWindowsStart MenuProgramsParetoLogic =>PUP.Paretologic^
    C:UsersThierryAppDataLocalConduit =>Toolbar.Conduit
    C:UsersThierryAppDataLocalLowConduit =>Toolbar.Conduit
    C:UsersThierryAppDataLocalLowNCH_FR =>Toolbar.Conduit
    C:UsersThierryAppDataRoamingMozillaFirefoxProfiles7dcujqhs.defaultSearchPluginssweetim.xml =>PUP.SweetIM
    C:WindowsTasksparetologic registration3.job =>PUP.Paretologic^
    C:WindowsSystem32Tasksparetologic registration3 =>PUP.Paretologic^
    C:WindowsTasksparetologic update version3.job =>PUP.Paretologic^
    C:WindowsSystem32Tasksparetologic update version3 =>PUP.Paretologic^
    C:WindowsTasksPC Health Advisor Defrag.job =>Rogue.PCHealthAdvisor^
    C:WindowsSystem32TasksPC Health Advisor Defrag =>Rogue.PCHealthAdvisor^
    C:WindowsTasksPC Health Advisor Defrag.job .job [362] =>Rogue.PCHealthAdvisor^
    C:WindowsSystem32TasksPC Health Advisor Defrag h Advisor [362] =>Rogue.PCHealthAdvisor^
    C:WindowsInstaller46d3323.msi =>PUP.SweetIM^
    C:WindowsTasksParetoLogic Update Version3.job =>PUP.Paretologic
    C:WindowsTasksParetoLogic Registration3.job =>PUP.Paretologic
    C:WindowsTasksPC Health Advisor.job =>Rogue.PCHealthAdvisor
    EmptyCLSID
    EmptyTemp
    EmptyFlash
    EmptyPrefetch

  • Lances ZHPFix, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista

    1. Clique sur Importer
    2. Puis Clic sur “GO

  • Confirmes les nettoyages des données en cliquant sur “Oui
  • Une fois le scan terminé rends toi sur le bureau, le fichier ZHPFixReport à été crée.
  • Héberge le rapport ZHPFixReport sur SosUpload, puis copie/colle le lien fourni dans ta prochaine réponse.

AdwCleaner

  • Télécharge Adwcleaner (de Xplode) sur ton Bureau !
  • Fais clic droit dessus, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista,sinon double-clique pour XP
    1. Choisis l’option Scanner
    2. Choisis l’option Nettoyer
  • Accepte l’avertissement en cliquant sur OK

  • Accepte les avertissements/informations en cliquant sur OK
  • Copie et Colle le contenu du rapport qui apparaît au redémarrage du PC

Junkware Removal Tool

  • Télécharge Junkware Removal Tool (de thisisu) sur ton bureau.
  • Lance Junkware Removal Tool, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista
  • Appuie sur n’importe quelle touche.

  • Une fois le scan terminé rends toi sur le bureau, le fichier JRT.txt à été créé.
  • Héberge le rapport JRT.txt surSosUpload, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum

A bientôt,