Pc infecté
Fermé
JEFL
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour,
Bonjour a tous un amie viens de porter son pc qui doit être infecté il le trouve lent et a un problème de réseau pouvez vous me le confirmer et m'aider à le désinfecter
Merci a tous pour votre aide
je vous poste se rapport
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:48:56, on 29/01/2012
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\G Data\TotalCare\AVKTray\AVKTray.exe
C:\Program Files\G Data\TotalCare\Firewall\GDFirewallTray.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Users\doudou\AppData\Roaming\SEO Soft 2.2.60\stat.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Little transparency.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Users\doudou\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\doudou\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\doudou\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\doudou\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\doudou\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\doudou\AppData\Local\Google\Chrome\Application\chrome.exe
H:\netoyage pc\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/accmeware/{CF295BC0-12E4-4684-8529-0991EA8F4494}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll
O2 - BHO: G Data WebFilter Class - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files\G Data\TotalCare\WebFilter\AvkWebIE.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - D:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: PriceGong - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files\PriceGong\2.5.4\PriceGongIE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Vuze Remote - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll
O2 - BHO: G Data BankGuard - {BA3295CF-17ED-4F49-9E95-D999A0ADBFDC} - C:\Program Files\Common Files\G Data\AVKProxy\BanksafeBHO.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - (no file)
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - D:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll
O3 - Toolbar: G Data WebFilter - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files\G Data\TotalCare\WebFilter\AvkWebIE.dll
O3 - Toolbar: AccmeWare DB Toolbar - {338B4DFE-2E2C-4338-9E41-E176D497299E} - (no file)
O4 - HKLM\..\Run: [G Data AntiVirus Tray Application] C:\Program Files\G Data\TotalCare\AVKTray\AVKTray.exe
O4 - HKLM\..\Run: [GDFirewallTray] C:\Program Files\G Data\TotalCare\Firewall\GDFirewallTray.exe
O4 - HKLM\..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [SEO Soft] C:\Users\doudou\AppData\Roaming\SEO Soft 2.2.60\stat.exe 15 15
O4 - HKCU\..\Run: [PowerSuite] "C:\PROGRA~1\Uniblue\POWERS~1\launcher.exe" delay 20000 -m
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-18\..\Run: [Welcome Center] C:\Windows\system32\rundll32.exe C:\Windows\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut (User 'Système')
O4 - HKUS\.DEFAULT\..\Run: [Welcome Center] C:\Windows\system32\rundll32.exe C:\Windows\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut (User 'Default user')
O4 - Global Startup: Little transparency.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Version Cue CS3 {fr_FR} (Adobe Version Cue CS3) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: G Data AntiVirus Proxy (AVKProxy) - G Data Software AG - C:\Program Files\Common Files\G Data\AVKProxy\AVKProxy.exe
O23 - Service: Planificateur G Data (AVKService) - G Data Software AG - C:\Program Files\G Data\TotalCare\AVK\AVKService.exe
O23 - Service: G Data Gardien (AVKWCtl) - G Data Software AG - C:\Program Files\G Data\TotalCare\AVK\AVKWCtl.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Service G Data Backup (GDBackupSvc) - G Data Software AG - C:\Program Files\G Data\TotalCare\AVKBackup\AVKBackupService.exe
O23 - Service: Pare-feu personnel G Data (GDFwSvc) - G Data Software AG - C:\Program Files\G Data\TotalCare\Firewall\GDFwSvc.exe
O23 - Service: G Data Scanner (GDScan) - G Data Software AG - C:\Program Files\Common Files\G Data\GDScan\GDScan.exe
O23 - Service: G Data Tuner Service (GDTunerSvc) - G Data Software AG - C:\Program Files\G Data\TotalCare\AVKTuner\AVKTunerService.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Service Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
Bonjour a tous un amie viens de porter son pc qui doit être infecté il le trouve lent et a un problème de réseau pouvez vous me le confirmer et m'aider à le désinfecter
Merci a tous pour votre aide
je vous poste se rapport
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:48:56, on 29/01/2012
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\G Data\TotalCare\AVKTray\AVKTray.exe
C:\Program Files\G Data\TotalCare\Firewall\GDFirewallTray.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Users\doudou\AppData\Roaming\SEO Soft 2.2.60\stat.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Little transparency.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Users\doudou\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\doudou\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\doudou\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\doudou\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\doudou\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\doudou\AppData\Local\Google\Chrome\Application\chrome.exe
H:\netoyage pc\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/accmeware/{CF295BC0-12E4-4684-8529-0991EA8F4494}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll
O2 - BHO: G Data WebFilter Class - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files\G Data\TotalCare\WebFilter\AvkWebIE.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - D:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: PriceGong - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files\PriceGong\2.5.4\PriceGongIE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Vuze Remote - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll
O2 - BHO: G Data BankGuard - {BA3295CF-17ED-4F49-9E95-D999A0ADBFDC} - C:\Program Files\Common Files\G Data\AVKProxy\BanksafeBHO.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - (no file)
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - D:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll
O3 - Toolbar: G Data WebFilter - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files\G Data\TotalCare\WebFilter\AvkWebIE.dll
O3 - Toolbar: AccmeWare DB Toolbar - {338B4DFE-2E2C-4338-9E41-E176D497299E} - (no file)
O4 - HKLM\..\Run: [G Data AntiVirus Tray Application] C:\Program Files\G Data\TotalCare\AVKTray\AVKTray.exe
O4 - HKLM\..\Run: [GDFirewallTray] C:\Program Files\G Data\TotalCare\Firewall\GDFirewallTray.exe
O4 - HKLM\..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [SEO Soft] C:\Users\doudou\AppData\Roaming\SEO Soft 2.2.60\stat.exe 15 15
O4 - HKCU\..\Run: [PowerSuite] "C:\PROGRA~1\Uniblue\POWERS~1\launcher.exe" delay 20000 -m
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-18\..\Run: [Welcome Center] C:\Windows\system32\rundll32.exe C:\Windows\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut (User 'Système')
O4 - HKUS\.DEFAULT\..\Run: [Welcome Center] C:\Windows\system32\rundll32.exe C:\Windows\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut (User 'Default user')
O4 - Global Startup: Little transparency.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Version Cue CS3 {fr_FR} (Adobe Version Cue CS3) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: G Data AntiVirus Proxy (AVKProxy) - G Data Software AG - C:\Program Files\Common Files\G Data\AVKProxy\AVKProxy.exe
O23 - Service: Planificateur G Data (AVKService) - G Data Software AG - C:\Program Files\G Data\TotalCare\AVK\AVKService.exe
O23 - Service: G Data Gardien (AVKWCtl) - G Data Software AG - C:\Program Files\G Data\TotalCare\AVK\AVKWCtl.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Service G Data Backup (GDBackupSvc) - G Data Software AG - C:\Program Files\G Data\TotalCare\AVKBackup\AVKBackupService.exe
O23 - Service: Pare-feu personnel G Data (GDFwSvc) - G Data Software AG - C:\Program Files\G Data\TotalCare\Firewall\GDFwSvc.exe
O23 - Service: G Data Scanner (GDScan) - G Data Software AG - C:\Program Files\Common Files\G Data\GDScan\GDScan.exe
O23 - Service: G Data Tuner Service (GDTunerSvc) - G Data Software AG - C:\Program Files\G Data\TotalCare\AVKTuner\AVKTunerService.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Service Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
A voir également:
- Pc infecté
- Reinitialiser pc - Guide
- Pc lent - Guide
- Downloader for pc - Télécharger - Téléchargement & Transfert
- Double ecran pc - Guide
- Forcer demarrage pc - Guide
35 réponses
salut
telecharge et enregistre ceci sur ton bureau :
Pre_Scan
Avertissement: tous les processus non-vitaux de windows seront coupés --> pas de panique.
une fois telechargé lance-le , laisse faire le scan jusqu'à l'apparition du rapport sur le bureau.
si 'outil est bloqué par l'infection utilise cette version : Version .pif
ou encore cette version renommée : Winlogon.exe
si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"
Il se peut qu'une multitude de fenêtres noires clignotent , laisse-le travailler
Poste Pre_Scan_la_date_et_l'heure.txt qui apparaitra sur le bureau en fin de scan après redemarrage
▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)
heberge le rapport sur http://pjjoint.malekal.com et donne le lien obtenu
telecharge et enregistre ceci sur ton bureau :
Pre_Scan
Avertissement: tous les processus non-vitaux de windows seront coupés --> pas de panique.
une fois telechargé lance-le , laisse faire le scan jusqu'à l'apparition du rapport sur le bureau.
si 'outil est bloqué par l'infection utilise cette version : Version .pif
ou encore cette version renommée : Winlogon.exe
si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"
Il se peut qu'une multitude de fenêtres noires clignotent , laisse-le travailler
Poste Pre_Scan_la_date_et_l'heure.txt qui apparaitra sur le bureau en fin de scan après redemarrage
▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)
heberge le rapport sur http://pjjoint.malekal.com et donne le lien obtenu
Bonjour et merci pour ton aide
Je viens de lancer la manip que tu m'as dit et je panique un peut. Quand je fais Pressant après 15 mn sa n'as toujours pas commençais que faire
Je viens de lancer la manip que tu m'as dit et je panique un peut. Quand je fais Pressant après 15 mn sa n'as toujours pas commençais que faire
faut desactiver GData(et son "Cloud" si present) il est trop puissant , il a du bloquer l outil
¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤_Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤_Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Bonjour je viens de faire la manip que tu m'as dit (désactiver GDATA) c'est pareil sa ne démarre toujours pas après 30mn .il est sur mon bureau il se lance et la barre ne progresse pas que faire
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
re que je le mette en mode sans échec avec prise en charge du réseau ou pas rein ne se lance j'ai un écran noir il existe pas un autre programme pour faire sa ? mon anti virus est bien désactiver
je ne te répond que maintenant je viens de revenir du travail . j'ai désactive l'antivirus + le pare feu.si tu le gros problème est que Lorsque je lance le partage de dossier (sous Explorateur - Partage et
sécurité) , j'ai le message :
"Une erreur s'est produite lors du partage de dossiers. Le service serveur
n'a pas démarré.
je suis bien en mode automatique ,et dans services il n'est pas démarrer quand je fait démarrer rien ne se passe c'est pour sa que je pense que mon pc est infecte
sécurité) , j'ai le message :
"Une erreur s'est produite lors du partage de dossiers. Le service serveur
n'a pas démarré.
je suis bien en mode automatique ,et dans services il n'est pas démarrer quand je fait démarrer rien ne se passe c'est pour sa que je pense que mon pc est infecte
Je viens de désactive l'antivirus + le pare feu +outil de surveillance antivirus les seul truc encore actif c'est mise a jour et sauvegarde . et cloud je ne sais pas se que c'est
et avec mon premier post avec HijackThis v2.0.2 un ne peut pas voir si le pc est infecté et se qui peut bloquer le réseau .je peut mettre un rapport avec malwarebyte et le propriétaire m'a dit que il avait passé ccleaner et fait un nettoyage du registre il a du virer une clé
jamais passer ccleaner quand on est infecté grosse erreur....
hijackthis ne montre absolument plus rien de nos jours mis à part les detournements dns et lees BHO et departs pourris
▶ Télécharge ZHPDiag (de Nicolas Coolman)
ou :ZHPDiag
▶ Enregistre le sur ton Bureau.
Une fois le téléchargement achevé,
▶ Installe et lance ZHPDiag.exe
▶ Clique sur le tournevis puis sur Tous pour cocher toutes les cases des options.
▶ Clique sur la loupe pour lancer l'analyse.
A la fin de l'analyse,
▶ clique sur l'appareil photo et enregistre le rapport sur ton Bureau.
heberge l'archive sur http://pjjoint.malekal.com et donne le lien
hijackthis ne montre absolument plus rien de nos jours mis à part les detournements dns et lees BHO et departs pourris
▶ Télécharge ZHPDiag (de Nicolas Coolman)
ou :ZHPDiag
▶ Enregistre le sur ton Bureau.
Une fois le téléchargement achevé,
▶ Installe et lance ZHPDiag.exe
▶ Clique sur le tournevis puis sur Tous pour cocher toutes les cases des options.
▶ Clique sur la loupe pour lancer l'analyse.
A la fin de l'analyse,
▶ clique sur l'appareil photo et enregistre le rapport sur ton Bureau.
heberge l'archive sur http://pjjoint.malekal.com et donne le lien
Tout d(abord:
-scan antivirus
- télecharge MalwareBytes et lance le scan puis supprime tous les virus
-scan antivirus
- télecharge MalwareBytes et lance le scan puis supprime tous les virus
1ère leçon :
ne pas interférer dans une prise en charge avancée
2è Leçcon
politesse et respect de la charte sont de rigueur
3è Leçon :
apprendre à lire un topic avant de poster n'importe quoi , et surtout un rapport :
Malwarebytes est deja present dans l'ordinateur de l'internaute
ne pas interférer dans une prise en charge avancée
2è Leçcon
politesse et respect de la charte sont de rigueur
3è Leçon :
apprendre à lire un topic avant de poster n'importe quoi , et surtout un rapport :
Malwarebytes est deja present dans l'ordinateur de l'internaute
si zhp passe , pre_scan doit passer
===================
ton windows n'est pas à jour
tu installes n'importe quoi , une vraie poubelle !
===================
desinstalle spybot
desinstalle registry optimizer ca va planter ta machine ce truc-là
desinstalle adobe reader 9
desinstalle pricegong
desinstalle vuze remote toolbar
desinstalle sweetIM
======================
sélectionne les lignes ci-dessous et copie les dans le Presse-papier (Ctrl C)
G2 - GCE: Preference [User Data\Default] [bkomkajifikmkfnjgphkjcfeepbnojok] PriceGong v.5.5.4 (Activé)
R3 - URLSearchHook: (no name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} . (...) (No version) -- (.not file.)
O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} Clé orpheline
O4 - HKLM\..\Run: [TaskTray] Clé orpheline
O4 - HKLM\..\Run: [RegistryMechanic] Clé orpheline
O4 - Global Startup: C:\Users\doudou\Desktop\Spybot - Search & Destroy.lnk . (.Safer Networking Limited.) -- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
O23 - Service: (gpsvc) - Clé orpheline
O23 - Service: SBSD Security Center Service (SBSDWSCService) . (.Safer Networking Ltd. - Spybot-S&D Security Center integration.) - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
[HKCU\Software\AppDataLow\Software\PriceGong]
[HKCU\Software\AppDataLow\Software\toolbar]
[HKCU\Software\OfferBox]
[HKCU\Software\SweetIM]
[HKCU\Software\WhiteSmoke]
[HKLM\Software\BrowserChoice]
[HKLM\Software\SweetIM]
[HKLM\Software\WhiteSmoke]
O43 - CFD: 14/09/2010 - 17:12:36 - [0,072] ----D- C:\Program Files\Emsisoft Anti-Malware
O43 - CFD: 29/01/2012 - 11:02:56 - [0] ----D- C:\Program Files\OfferBox
O43 - CFD: 17/12/2011 - 10:19:10 - [1,182] ----D- C:\Program Files\PriceGong
O43 - CFD: 27/10/2011 - 08:01:00 - [57,787] ----D- C:\Program Files\Spybot - Search & Destroy
O43 - CFD: 07/06/2011 - 07:34:36 - [0] ----D- C:\Program Files\WhiteSmoke
O43 - CFD: 03/11/2011 - 14:47:52 - [0,024] ----D- C:\ProgramData\Spybot - Search & Destroy
O43 - CFD: 29/01/2012 - 11:02:06 - [0,002] ----D- C:\Users\doudou\AppData\Roaming\OfferBox
O43 - CFD: 07/06/2011 - 07:31:04 - [0,001] ----D- C:\Users\doudou\AppData\Roaming\WhiteSmoke
O43 - CFD: 16/12/2010 - 21:37:50 - [0,001] --H-D- C:\Users\doudou\AppData\Local\wJHBd4gG9ZqHHbE
C:\Users\doudou\Desktop\Adobe CS4 Master_Keygen and Activation
O87 - FAEL: "{61172B87-6641-48A9-A4C4-98A2F4A08F2C}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files\Vuze\Azureus.exe (.not file.)
O87 - FAEL: "{02E5F3FA-B922-4E24-8E02-8FF7F82BDC48}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files\Vuze\Azureus.exe (.not file.)
O87 - FAEL: "{F7224A90-0D4F-4622-ADDE-19277E04FC24}" |In - Private - P6 - TRUE | .(...) -- C:\Users\doudou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NY9BTPDT\SweetImSetup.exe (.not file.)
O87 - FAEL: "{267513BF-15D6-4868-8423-6F22B1758EED}" |In - Private - P17 - TRUE | .(...) -- C:\Users\doudou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NY9BTPDT\SweetImSetup.exe (.not file.)
O87 - FAEL: "{089F0DEF-8888-47CF-BE8A-1DD44030648F}" |In - Private - P6 - TRUE | .(...) -- C:\Users\doudou\AppData\Local\Temp\SweetIMReinstall\SweetImSetup.exe (.not file.)
O87 - FAEL: "{36A20EE1-4CD3-433E-9574-E7FA48FCD2D7}" |In - Private - P17 - TRUE | .(...) -- C:\Users\doudou\AppData\Local\Temp\SweetIMReinstall\SweetImSetup.exe (.not file.)
O87 - FAEL: "{76D5D0AC-92B5-4366-A9C1-FF45B27A21EF}" |In - Private - P6 - TRUE | .(...) -- C:\Users\doudou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\85QCE3OM\SweetImSetup.exe (.not file.)
O87 - FAEL: "{B07E31D2-4569-46D1-840D-8240B7233D03}" |In - Private - P17 - TRUE | .(...) -- C:\Users\doudou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\85QCE3OM\SweetImSetup.exe (.not file.)
O87 - FAEL: "{5047FDD9-14B3-4E13-ACAC-6335AF9C234F}" |In - Private - P6 - TRUE | .(...) -- C:\Users\doudou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PLFZTOME\SweetImSetup.exe (.not file.)
O87 - FAEL: "{9DB553A7-F6C9-4605-BEB6-6C67C04A45DA}" |In - Private - P17 - TRUE | .(...) -- C:\Users\doudou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PLFZTOME\SweetImSetup.exe (.not file.)
C:\Users\doudou\Documents\prog suple tomtom one\pdf converter crack + keygen.rar
D:\keygen.exe
D:\Mes documents\Paint Shop Pro 7 Français\(gen) Paint Shop Pro 7.xx Keygen Crack.exe
O43 - CFD: 06/02/2011 - 16:04:28 - [0] ----D- C:\Users\doudou\AppData\Local\{10CD5CBC-4ACA-4851-A4D0-DEA533489B3C}
O43 - CFD: 08/02/2011 - 08:31:42 - [0] ----D- C:\Users\doudou\AppData\Local\{12E8F1D9-36FB-4C49-8C99-F6DEFF33FD5A}
O43 - CFD: 27/02/2011 - 20:26:18 - [0] ----D- C:\Users\doudou\AppData\Local\{1A22891B-C856-4A93-93D5-F045D79044E6}
O43 - CFD: 08/03/2011 - 12:06:26 - [0] ----D- C:\Users\doudou\AppData\Local\{2A47F221-E10E-4962-91DD-AA1FEFD49312}
O43 - CFD: 03/02/2011 - 11:43:38 - [0] ----D- C:\Users\doudou\AppData\Local\{2E12A963-8824-40BC-8CED-CEC789AA2D3A}
O43 - CFD: 27/02/2011 - 10:32:38 - [0] ----D- C:\Users\doudou\AppData\Local\{3C1088A5-F9DA-4782-AE41-3ECCF8EFAB58}
O43 - CFD: 12/03/2011 - 13:08:30 - [0] ----D- C:\Users\doudou\AppData\Local\{4B1AA4EF-A830-47FD-929B-84E56DBD8462}
O43 - CFD: 04/03/2011 - 16:05:18 - [0] ----D- C:\Users\doudou\AppData\Local\{5786B676-A76E-4FBA-A63B-47CA70E14C6D}
O43 - CFD: 03/02/2011 - 11:43:34 - [0] ----D- C:\Users\doudou\AppData\Local\{6150AA06-9A17-4F58-BDE8-A4AC3DE72A30}
O43 - CFD: 10/03/2011 - 10:20:14 - [0] ----D- C:\Users\doudou\AppData\Local\{8DAB09E9-E5BF-4F2E-ADA3-1F6E69D61F76}
O43 - CFD: 01/02/2011 - 10:56:38 - [0] ----D- C:\Users\doudou\AppData\Local\{950426F7-456A-4142-8DCC-83BF09AD7F0D}
O43 - CFD: 04/03/2011 - 09:09:46 - [0] ----D- C:\Users\doudou\AppData\Local\{96290E7B-BE35-4CF6-9A20-B7AB3755A273}
O43 - CFD: 04/02/2011 - 12:25:08 - [0] ----D- C:\Users\doudou\AppData\Local\{A4AAF24E-63E8-4ED2-B48D-0D9346A4E193}
O43 - CFD: 07/03/2011 - 12:48:48 - [0] ----D- C:\Users\doudou\AppData\Local\{A510A47F-28F9-4DC8-A38D-4B9CEB22CCB2}
O43 - CFD: 19/03/2011 - 13:30:38 - [0] ----D- C:\Users\doudou\AppData\Local\{B3F654E1-3682-4157-A473-26B9F069DA88}
O43 - CFD: 08/03/2011 - 12:05:46 - [0] ----D- C:\Users\doudou\AppData\Local\{B53F9C92-989B-41EB-98FF-01D7166CC010}
O43 - CFD: 06/03/2011 - 18:57:54 - [0] ----D- C:\Users\doudou\AppData\Local\{C986877C-644A-4902-9168-550218CADDB0}
O43 - CFD: 12/03/2011 - 13:09:20 - [0] ----D- C:\Users\doudou\AppData\Local\{CEC9045A-1D7F-4435-9017-870C0D19B7FC}
O43 - CFD: 13/03/2011 - 08:26:10 - [0] ----D- C:\Users\doudou\AppData\Local\{D154436E-9ED6-4471-8ED7-0EE0C2AE24EB}
O43 - CFD: 31/01/2011 - 19:04:46 - [0] ----D- C:\Users\doudou\AppData\Local\{D5CE3E02-7D72-4A89-9FC5-698B8DADD292}
O43 - CFD: 28/02/2011 - 10:16:02 - [0] ----D- C:\Users\doudou\AppData\Local\{D83F6F3C-2A01-4A55-8A52-8AF86DE26154}
O43 - CFD: 17/02/2011 - 18:09:50 - [0] ----D- C:\Users\doudou\AppData\Local\{F5A8F289-E11D-4DDE-8BF8-7F1CD37F3F93}
O43 - CFD: 14/03/2011 - 08:17:10 - [0] ----D- C:\Users\doudou\AppData\Local\{FF191D1A-294D-415C-B0B5-EA6B6E2AE28B}
O53 - SMSR:HKLM\...\startupreg\PowerSuite [Key] . (...) -- C:\Program Files\Uniblue\POWERS~1\launcher.exe (.not file.)
O69 - SBI: SearchScopes [HKCU] {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} - (Search) - http://ww1.bigseekpro.com
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Associations]:bak_Application
[HKLM\Software\Classes\AppID\PriceGongIE.DLL]
[HKLM\Software\Classes\AppID\TbCommonUtils.DLL]
[HKLM\Software\Classes\AppID\TbHelper.EXE]
[HKLM\Software\Classes\PriceFactorIE.PriceGongBHO]
[HKLM\Software\Classes\PriceFactorIE.PriceGongBHO.1]
[HKLM\Software\Classes\PriceGongIE.PriceGongCtrl]
[HKLM\Software\Classes\PriceGongIE.PriceGongCtrl.1]
[HKLM\Software\Classes\TbCommonUtils.CommonUtils]
[HKLM\Software\Classes\TbCommonUtils.CommonUtils.1]
[HKLM\Software\Classes\TbHelper.TbDownloadManager]
[HKLM\Software\Classes\TbHelper.TbDownloadManager.1]
[HKLM\Software\Classes\TbHelper.TbPropertyManager]
[HKLM\Software\Classes\TbHelper.TbPropertyManager.1]
[HKLM\Software\Classes\TbHelper.TbRequest]
[HKLM\Software\Classes\TbHelper.TbRequest.1]
[HKLM\Software\Classes\TbHelper.TbTask]
[HKLM\Software\Classes\TbHelper.TbTask.1]
[HKLM\Software\Classes\TbHelper.ToolbarHelper]
[HKLM\Software\Classes\TbHelper.ToolbarHelper.1]
[HKLM\Software\Classes\Toolbar3.ContextMenuNotifier]
[HKLM\Software\Classes\Toolbar3.ContextMenuNotifier.1]
[HKLM\Software\Classes\Toolbar3.CustomInternetSecurityImpl]
[HKLM\Software\Classes\Toolbar3.CustomInternetSecurityImpl.1]
[HKLM\Software\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}]
[HKLM\Software\Classes\Interface\{2a42d13c-d427-4787-821b-cf6973855778}]
[HKLM\Software\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{338B4DFE-2E2C-4338-9E41-E176D497299E}]
[HKLM\Software\Classes\CLSID\{338B4DFE-2E2C-4338-9E41-E176D497299E}] => Infection BT (Adware.Softomate)
[HKLM\Software\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}]
[HKLM\Software\Classes\Interface\{3d8478aa-7b88-48a9-8bcb-b85d594411ec}]
[HKLM\Software\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}]
[HKLM\Software\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}]
[HKLM\Software\Classes\Interface\{4897bba6-48d9-468c-8efa-846275d7701b}]
[HKLM\Software\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}]
[HKLM\Software\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}]
[HKLM\Software\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}]
[HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}]
[HKLM\Software\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}]
[HKLM\Software\Classes\AppID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}]
[HKLM\Software\Classes\TypeLib\{8B3372D0-09F0-41A5-8D9B-134E148672FB}]
[HKLM\Software\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}]
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}]
[HKLM\Software\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052}]
[HKLM\Software\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}]
[HKLM\Software\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}]
[HKLM\Software\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}]
[HKLM\Software\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}]
[HKLM\Software\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}]
[HKLM\Software\Classes\CLSID\{D2A2595C-4FE4-4315-AA9B-19DBD6271B71}]
[HKLM\Software\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}]
[HKLM\Software\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}]
[HKLM\Software\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}]
[HKLM\Software\Classes\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
[HKLM\Software\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
[HKLM\Software\Google\Chrome\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok]
[HKCU\Software\OfferBox]
[HKCU\Software\AppDataLow\Software\PriceGong]
[HKCU\Software\SweetIM]
[HKLM\Software\SweetIM]
[HKCU\Software\AppDataLow\Software\Toolbar]
C:\Program Files\OfferBox
C:\Program Files\PriceGong
C:\Program Files\Vuze_Remote
C:\Program Files\WhiteSmoke
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong
C:\Users\doudou\AppData\Roaming\OfferBox
C:\Users\doudou\AppData\Roaming\WhiteSmoke
C:\Users\doudou\AppData\LocalLow\Toolbar4
C:\Users\doudou\AppData\LocalLow\Vuze_Remote
Pour Xp : Double clique sur l'icône ZHPFix.exe sur ton Bureau.
Pour Vista : Clique droit sur l'icône ZHPFix.exe sur ton Bureau,
puis sélectionne 'Exécuter en tant qu'administrateur'.
- Clique sur l'icone représentant la lettre H (« coller les lignes Helper »)
- Les lignes se collent automatiquement dans ZHPFix, sinon colle les lignes
- Clique sur le bouton « GO » pour lancer le nettoyage,
- Copie/colle la totalité du rapport dans ta prochaine réponse
===================
ton windows n'est pas à jour
tu installes n'importe quoi , une vraie poubelle !
===================
desinstalle spybot
desinstalle registry optimizer ca va planter ta machine ce truc-là
desinstalle adobe reader 9
desinstalle pricegong
desinstalle vuze remote toolbar
desinstalle sweetIM
======================
sélectionne les lignes ci-dessous et copie les dans le Presse-papier (Ctrl C)
G2 - GCE: Preference [User Data\Default] [bkomkajifikmkfnjgphkjcfeepbnojok] PriceGong v.5.5.4 (Activé)
R3 - URLSearchHook: (no name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} . (...) (No version) -- (.not file.)
O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} Clé orpheline
O4 - HKLM\..\Run: [TaskTray] Clé orpheline
O4 - HKLM\..\Run: [RegistryMechanic] Clé orpheline
O4 - Global Startup: C:\Users\doudou\Desktop\Spybot - Search & Destroy.lnk . (.Safer Networking Limited.) -- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
O23 - Service: (gpsvc) - Clé orpheline
O23 - Service: SBSD Security Center Service (SBSDWSCService) . (.Safer Networking Ltd. - Spybot-S&D Security Center integration.) - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
[HKCU\Software\AppDataLow\Software\PriceGong]
[HKCU\Software\AppDataLow\Software\toolbar]
[HKCU\Software\OfferBox]
[HKCU\Software\SweetIM]
[HKCU\Software\WhiteSmoke]
[HKLM\Software\BrowserChoice]
[HKLM\Software\SweetIM]
[HKLM\Software\WhiteSmoke]
O43 - CFD: 14/09/2010 - 17:12:36 - [0,072] ----D- C:\Program Files\Emsisoft Anti-Malware
O43 - CFD: 29/01/2012 - 11:02:56 - [0] ----D- C:\Program Files\OfferBox
O43 - CFD: 17/12/2011 - 10:19:10 - [1,182] ----D- C:\Program Files\PriceGong
O43 - CFD: 27/10/2011 - 08:01:00 - [57,787] ----D- C:\Program Files\Spybot - Search & Destroy
O43 - CFD: 07/06/2011 - 07:34:36 - [0] ----D- C:\Program Files\WhiteSmoke
O43 - CFD: 03/11/2011 - 14:47:52 - [0,024] ----D- C:\ProgramData\Spybot - Search & Destroy
O43 - CFD: 29/01/2012 - 11:02:06 - [0,002] ----D- C:\Users\doudou\AppData\Roaming\OfferBox
O43 - CFD: 07/06/2011 - 07:31:04 - [0,001] ----D- C:\Users\doudou\AppData\Roaming\WhiteSmoke
O43 - CFD: 16/12/2010 - 21:37:50 - [0,001] --H-D- C:\Users\doudou\AppData\Local\wJHBd4gG9ZqHHbE
C:\Users\doudou\Desktop\Adobe CS4 Master_Keygen and Activation
O87 - FAEL: "{61172B87-6641-48A9-A4C4-98A2F4A08F2C}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files\Vuze\Azureus.exe (.not file.)
O87 - FAEL: "{02E5F3FA-B922-4E24-8E02-8FF7F82BDC48}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files\Vuze\Azureus.exe (.not file.)
O87 - FAEL: "{F7224A90-0D4F-4622-ADDE-19277E04FC24}" |In - Private - P6 - TRUE | .(...) -- C:\Users\doudou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NY9BTPDT\SweetImSetup.exe (.not file.)
O87 - FAEL: "{267513BF-15D6-4868-8423-6F22B1758EED}" |In - Private - P17 - TRUE | .(...) -- C:\Users\doudou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NY9BTPDT\SweetImSetup.exe (.not file.)
O87 - FAEL: "{089F0DEF-8888-47CF-BE8A-1DD44030648F}" |In - Private - P6 - TRUE | .(...) -- C:\Users\doudou\AppData\Local\Temp\SweetIMReinstall\SweetImSetup.exe (.not file.)
O87 - FAEL: "{36A20EE1-4CD3-433E-9574-E7FA48FCD2D7}" |In - Private - P17 - TRUE | .(...) -- C:\Users\doudou\AppData\Local\Temp\SweetIMReinstall\SweetImSetup.exe (.not file.)
O87 - FAEL: "{76D5D0AC-92B5-4366-A9C1-FF45B27A21EF}" |In - Private - P6 - TRUE | .(...) -- C:\Users\doudou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\85QCE3OM\SweetImSetup.exe (.not file.)
O87 - FAEL: "{B07E31D2-4569-46D1-840D-8240B7233D03}" |In - Private - P17 - TRUE | .(...) -- C:\Users\doudou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\85QCE3OM\SweetImSetup.exe (.not file.)
O87 - FAEL: "{5047FDD9-14B3-4E13-ACAC-6335AF9C234F}" |In - Private - P6 - TRUE | .(...) -- C:\Users\doudou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PLFZTOME\SweetImSetup.exe (.not file.)
O87 - FAEL: "{9DB553A7-F6C9-4605-BEB6-6C67C04A45DA}" |In - Private - P17 - TRUE | .(...) -- C:\Users\doudou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PLFZTOME\SweetImSetup.exe (.not file.)
C:\Users\doudou\Documents\prog suple tomtom one\pdf converter crack + keygen.rar
D:\keygen.exe
D:\Mes documents\Paint Shop Pro 7 Français\(gen) Paint Shop Pro 7.xx Keygen Crack.exe
O43 - CFD: 06/02/2011 - 16:04:28 - [0] ----D- C:\Users\doudou\AppData\Local\{10CD5CBC-4ACA-4851-A4D0-DEA533489B3C}
O43 - CFD: 08/02/2011 - 08:31:42 - [0] ----D- C:\Users\doudou\AppData\Local\{12E8F1D9-36FB-4C49-8C99-F6DEFF33FD5A}
O43 - CFD: 27/02/2011 - 20:26:18 - [0] ----D- C:\Users\doudou\AppData\Local\{1A22891B-C856-4A93-93D5-F045D79044E6}
O43 - CFD: 08/03/2011 - 12:06:26 - [0] ----D- C:\Users\doudou\AppData\Local\{2A47F221-E10E-4962-91DD-AA1FEFD49312}
O43 - CFD: 03/02/2011 - 11:43:38 - [0] ----D- C:\Users\doudou\AppData\Local\{2E12A963-8824-40BC-8CED-CEC789AA2D3A}
O43 - CFD: 27/02/2011 - 10:32:38 - [0] ----D- C:\Users\doudou\AppData\Local\{3C1088A5-F9DA-4782-AE41-3ECCF8EFAB58}
O43 - CFD: 12/03/2011 - 13:08:30 - [0] ----D- C:\Users\doudou\AppData\Local\{4B1AA4EF-A830-47FD-929B-84E56DBD8462}
O43 - CFD: 04/03/2011 - 16:05:18 - [0] ----D- C:\Users\doudou\AppData\Local\{5786B676-A76E-4FBA-A63B-47CA70E14C6D}
O43 - CFD: 03/02/2011 - 11:43:34 - [0] ----D- C:\Users\doudou\AppData\Local\{6150AA06-9A17-4F58-BDE8-A4AC3DE72A30}
O43 - CFD: 10/03/2011 - 10:20:14 - [0] ----D- C:\Users\doudou\AppData\Local\{8DAB09E9-E5BF-4F2E-ADA3-1F6E69D61F76}
O43 - CFD: 01/02/2011 - 10:56:38 - [0] ----D- C:\Users\doudou\AppData\Local\{950426F7-456A-4142-8DCC-83BF09AD7F0D}
O43 - CFD: 04/03/2011 - 09:09:46 - [0] ----D- C:\Users\doudou\AppData\Local\{96290E7B-BE35-4CF6-9A20-B7AB3755A273}
O43 - CFD: 04/02/2011 - 12:25:08 - [0] ----D- C:\Users\doudou\AppData\Local\{A4AAF24E-63E8-4ED2-B48D-0D9346A4E193}
O43 - CFD: 07/03/2011 - 12:48:48 - [0] ----D- C:\Users\doudou\AppData\Local\{A510A47F-28F9-4DC8-A38D-4B9CEB22CCB2}
O43 - CFD: 19/03/2011 - 13:30:38 - [0] ----D- C:\Users\doudou\AppData\Local\{B3F654E1-3682-4157-A473-26B9F069DA88}
O43 - CFD: 08/03/2011 - 12:05:46 - [0] ----D- C:\Users\doudou\AppData\Local\{B53F9C92-989B-41EB-98FF-01D7166CC010}
O43 - CFD: 06/03/2011 - 18:57:54 - [0] ----D- C:\Users\doudou\AppData\Local\{C986877C-644A-4902-9168-550218CADDB0}
O43 - CFD: 12/03/2011 - 13:09:20 - [0] ----D- C:\Users\doudou\AppData\Local\{CEC9045A-1D7F-4435-9017-870C0D19B7FC}
O43 - CFD: 13/03/2011 - 08:26:10 - [0] ----D- C:\Users\doudou\AppData\Local\{D154436E-9ED6-4471-8ED7-0EE0C2AE24EB}
O43 - CFD: 31/01/2011 - 19:04:46 - [0] ----D- C:\Users\doudou\AppData\Local\{D5CE3E02-7D72-4A89-9FC5-698B8DADD292}
O43 - CFD: 28/02/2011 - 10:16:02 - [0] ----D- C:\Users\doudou\AppData\Local\{D83F6F3C-2A01-4A55-8A52-8AF86DE26154}
O43 - CFD: 17/02/2011 - 18:09:50 - [0] ----D- C:\Users\doudou\AppData\Local\{F5A8F289-E11D-4DDE-8BF8-7F1CD37F3F93}
O43 - CFD: 14/03/2011 - 08:17:10 - [0] ----D- C:\Users\doudou\AppData\Local\{FF191D1A-294D-415C-B0B5-EA6B6E2AE28B}
O53 - SMSR:HKLM\...\startupreg\PowerSuite [Key] . (...) -- C:\Program Files\Uniblue\POWERS~1\launcher.exe (.not file.)
O69 - SBI: SearchScopes [HKCU] {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} - (Search) - http://ww1.bigseekpro.com
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Associations]:bak_Application
[HKLM\Software\Classes\AppID\PriceGongIE.DLL]
[HKLM\Software\Classes\AppID\TbCommonUtils.DLL]
[HKLM\Software\Classes\AppID\TbHelper.EXE]
[HKLM\Software\Classes\PriceFactorIE.PriceGongBHO]
[HKLM\Software\Classes\PriceFactorIE.PriceGongBHO.1]
[HKLM\Software\Classes\PriceGongIE.PriceGongCtrl]
[HKLM\Software\Classes\PriceGongIE.PriceGongCtrl.1]
[HKLM\Software\Classes\TbCommonUtils.CommonUtils]
[HKLM\Software\Classes\TbCommonUtils.CommonUtils.1]
[HKLM\Software\Classes\TbHelper.TbDownloadManager]
[HKLM\Software\Classes\TbHelper.TbDownloadManager.1]
[HKLM\Software\Classes\TbHelper.TbPropertyManager]
[HKLM\Software\Classes\TbHelper.TbPropertyManager.1]
[HKLM\Software\Classes\TbHelper.TbRequest]
[HKLM\Software\Classes\TbHelper.TbRequest.1]
[HKLM\Software\Classes\TbHelper.TbTask]
[HKLM\Software\Classes\TbHelper.TbTask.1]
[HKLM\Software\Classes\TbHelper.ToolbarHelper]
[HKLM\Software\Classes\TbHelper.ToolbarHelper.1]
[HKLM\Software\Classes\Toolbar3.ContextMenuNotifier]
[HKLM\Software\Classes\Toolbar3.ContextMenuNotifier.1]
[HKLM\Software\Classes\Toolbar3.CustomInternetSecurityImpl]
[HKLM\Software\Classes\Toolbar3.CustomInternetSecurityImpl.1]
[HKLM\Software\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}]
[HKLM\Software\Classes\Interface\{2a42d13c-d427-4787-821b-cf6973855778}]
[HKLM\Software\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{338B4DFE-2E2C-4338-9E41-E176D497299E}]
[HKLM\Software\Classes\CLSID\{338B4DFE-2E2C-4338-9E41-E176D497299E}] => Infection BT (Adware.Softomate)
[HKLM\Software\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}]
[HKLM\Software\Classes\Interface\{3d8478aa-7b88-48a9-8bcb-b85d594411ec}]
[HKLM\Software\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}]
[HKLM\Software\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}]
[HKLM\Software\Classes\Interface\{4897bba6-48d9-468c-8efa-846275d7701b}]
[HKLM\Software\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}]
[HKLM\Software\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}]
[HKLM\Software\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}]
[HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}]
[HKLM\Software\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}]
[HKLM\Software\Classes\AppID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}]
[HKLM\Software\Classes\TypeLib\{8B3372D0-09F0-41A5-8D9B-134E148672FB}]
[HKLM\Software\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}]
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}]
[HKLM\Software\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052}]
[HKLM\Software\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}]
[HKLM\Software\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}]
[HKLM\Software\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}]
[HKLM\Software\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}]
[HKLM\Software\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}]
[HKLM\Software\Classes\CLSID\{D2A2595C-4FE4-4315-AA9B-19DBD6271B71}]
[HKLM\Software\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}]
[HKLM\Software\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}]
[HKLM\Software\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}]
[HKLM\Software\Classes\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
[HKLM\Software\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
[HKLM\Software\Google\Chrome\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok]
[HKCU\Software\OfferBox]
[HKCU\Software\AppDataLow\Software\PriceGong]
[HKCU\Software\SweetIM]
[HKLM\Software\SweetIM]
[HKCU\Software\AppDataLow\Software\Toolbar]
C:\Program Files\OfferBox
C:\Program Files\PriceGong
C:\Program Files\Vuze_Remote
C:\Program Files\WhiteSmoke
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong
C:\Users\doudou\AppData\Roaming\OfferBox
C:\Users\doudou\AppData\Roaming\WhiteSmoke
C:\Users\doudou\AppData\LocalLow\Toolbar4
C:\Users\doudou\AppData\LocalLow\Vuze_Remote
Pour Xp : Double clique sur l'icône ZHPFix.exe sur ton Bureau.
Pour Vista : Clique droit sur l'icône ZHPFix.exe sur ton Bureau,
puis sélectionne 'Exécuter en tant qu'administrateur'.
- Clique sur l'icone représentant la lettre H (« coller les lignes Helper »)
- Les lignes se collent automatiquement dans ZHPFix, sinon colle les lignes
- Clique sur le bouton « GO » pour lancer le nettoyage,
- Copie/colle la totalité du rapport dans ta prochaine réponse
bonjour tu vas bien je te poste le rapport je n'ai pas pu desinstalé ces 2
desinstalle vuze remote toolbar il ne se sort pas
desinstalle sweetIM je ne le trouve pas
Rapport de ZHPFix 1.12.3379 par Nicolas Coolman, Update du 22/01/2011
Fichier d'export Registre : C:\ZHP\ZHPExportRegistry-31-01-2012-08-37-41.txt
Run by doudou at 31/01/2012 08:37:41
Windows 7 Ultimate Edition, 32-bit (Build 7600)
Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
Web site : http://nicolascoolman.skyrock.com/
========== Processus mémoire ==========
SUPPRIME Memory Process: D:\keygen.exe
SUPPRIME Memory Process: D:\Mes documents\Paint Shop Pro 7 Français\(gen) Paint Shop Pro 7.xx Keygen Crack.exe
========== Clé(s) du Registre ==========
SUPPRIME Key: CLSID BHO: {FCBCCB87-9224-4B8D-B117-F56D924BEB18}
ABSENT Key: Service: gpsvc
ABSENT Key: Service: SBSDWSCService
SUPPRIME Key: HKCU\Software\AppDataLow\Software\PriceGong
SUPPRIME Key: HKCU\Software\AppDataLow\Software\toolbar
SUPPRIME Key: HKCU\Software\OfferBox
SUPPRIME Key: HKCU\Software\SweetIM
SUPPRIME Key: HKCU\Software\WhiteSmoke
SUPPRIME Key: HKLM\Software\BrowserChoice
SUPPRIME Key: HKLM\Software\SweetIM
SUPPRIME Key: HKLM\Software\WhiteSmoke
SUPPRIME Key: StartupReg: PowerSuite
SUPPRIME Key: SearchScopes :{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SUPPRIME Key: HKLM\Software\Classes\AppID\PriceGongIE.DLL
SUPPRIME Key: HKLM\Software\Classes\AppID\TbCommonUtils.DLL
SUPPRIME Key: HKLM\Software\Classes\AppID\TbHelper.EXE
SUPPRIME Key: HKLM\Software\Classes\PriceFactorIE.PriceGongBHO
SUPPRIME Key: HKLM\Software\Classes\PriceFactorIE.PriceGongBHO.1
SUPPRIME Key: HKLM\Software\Classes\PriceGongIE.PriceGongCtrl
SUPPRIME Key: HKLM\Software\Classes\PriceGongIE.PriceGongCtrl.1
SUPPRIME Key: HKLM\Software\Classes\TbCommonUtils.CommonUtils
SUPPRIME Key: HKLM\Software\Classes\TbCommonUtils.CommonUtils.1
SUPPRIME Key: HKLM\Software\Classes\TbHelper.TbDownloadManager
SUPPRIME Key: HKLM\Software\Classes\TbHelper.TbDownloadManager.1
SUPPRIME Key: HKLM\Software\Classes\TbHelper.TbPropertyManager
SUPPRIME Key: HKLM\Software\Classes\TbHelper.TbPropertyManager.1
SUPPRIME Key: HKLM\Software\Classes\TbHelper.TbRequest
SUPPRIME Key: HKLM\Software\Classes\TbHelper.TbRequest.1
SUPPRIME Key: HKLM\Software\Classes\TbHelper.TbTask
SUPPRIME Key: HKLM\Software\Classes\TbHelper.TbTask.1
SUPPRIME Key: HKLM\Software\Classes\TbHelper.ToolbarHelper
SUPPRIME Key: HKLM\Software\Classes\TbHelper.ToolbarHelper.1
SUPPRIME Key: HKLM\Software\Classes\Toolbar3.ContextMenuNotifier
SUPPRIME Key: HKLM\Software\Classes\Toolbar3.ContextMenuNotifier.1
SUPPRIME Key: HKLM\Software\Classes\Toolbar3.CustomInternetSecurityImpl
SUPPRIME Key: HKLM\Software\Classes\Toolbar3.CustomInternetSecurityImpl.1
SUPPRIME Key: HKLM\Software\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
SUPPRIME Key: HKLM\Software\Classes\Interface\{2a42d13c-d427-4787-821b-cf6973855778}
ABSENT Key: HKLM\Software\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{338B4DFE-2E2C-4338-9E41-E176D497299E}
SUPPRIME Key: HKLM\Software\Classes\CLSID\{338B4DFE-2E2C-4338-9E41-E176D497299E}
SUPPRIME Key: HKLM\Software\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}
SUPPRIME Key: HKLM\Software\Classes\Interface\{3d8478aa-7b88-48a9-8bcb-b85d594411ec}
SUPPRIME Key: HKLM\Software\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
SUPPRIME Key: HKLM\Software\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
SUPPRIME Key: HKLM\Software\Classes\Interface\{4897bba6-48d9-468c-8efa-846275d7701b}
SUPPRIME Key: HKLM\Software\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
SUPPRIME Key: HKLM\Software\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
SUPPRIME Key: HKLM\Software\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
SUPPRIME Key: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
SUPPRIME Key: HKLM\Software\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
SUPPRIME Key: HKLM\Software\Classes\AppID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}
SUPPRIME Key: HKLM\Software\Classes\TypeLib\{8B3372D0-09F0-41A5-8D9B-134E148672FB}
SUPPRIME Key: HKLM\Software\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
ABSENT Key: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SUPPRIME Key: HKLM\Software\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052}
SUPPRIME Key: HKLM\Software\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
SUPPRIME Key: HKLM\Software\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
SUPPRIME Key: HKLM\Software\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
SUPPRIME Key: HKLM\Software\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
SUPPRIME Key: HKLM\Software\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
SUPPRIME Key: HKLM\Software\Classes\CLSID\{D2A2595C-4FE4-4315-AA9B-19DBD6271B71}
SUPPRIME Key: HKLM\Software\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}
SUPPRIME Key: HKLM\Software\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
SUPPRIME Key: HKLM\Software\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
SUPPRIME Key: HKLM\Software\Classes\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}
SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
ABSENT Key: HKLM\Software\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
ABSENT Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
ABSENT Key: HKLM\Software\Google\Chrome\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok
ABSENT Key: HKCU\Software\AppDataLow\Software\Toolbar
========== Valeur(s) du Registre ==========
SUPPRIME URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc}
SUPPRIME RunValue: TaskTray
ABSENT RunValue: RegistryMechanic
ABSENT inetcpl.cpl:
SUPPRIME {61172B87-6641-48A9-A4C4-98A2F4A08F2C}
SUPPRIME {02E5F3FA-B922-4E24-8E02-8FF7F82BDC48}
SUPPRIME {F7224A90-0D4F-4622-ADDE-19277E04FC24}
SUPPRIME {267513BF-15D6-4868-8423-6F22B1758EED}
SUPPRIME {089F0DEF-8888-47CF-BE8A-1DD44030648F}
SUPPRIME {36A20EE1-4CD3-433E-9574-E7FA48FCD2D7}
SUPPRIME {76D5D0AC-92B5-4366-A9C1-FF45B27A21EF}
SUPPRIME {B07E31D2-4569-46D1-840D-8240B7233D03}
SUPPRIME {5047FDD9-14B3-4E13-ACAC-6335AF9C234F}
SUPPRIME {9DB553A7-F6C9-4605-BEB6-6C67C04A45DA}
SUPPRIME [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Associations]:bak_Application
========== Préférences navigateur ==========
SUPPRIME Folder Chrome: C:\Users\doudou\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok
========== Dossier(s) ==========
SUPPRIME Folder: C:\Users\doudou\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok
SUPPRIME Folder: C:\Program Files\Emsisoft Anti-Malware
SUPPRIME Folder: C:\Program Files\OfferBox
ABSENT C:\Program Files\PriceGong
SUPPRIME Reboot Folder**: C:\Program Files\Spybot - Search & Destroy
SUPPRIME Folder: C:\Program Files\WhiteSmoke
SUPPRIME Folder: C:\ProgramData\Spybot - Search & Destroy
SUPPRIME Folder: C:\Users\doudou\AppData\Roaming\OfferBox
SUPPRIME Folder: C:\Users\doudou\AppData\Roaming\WhiteSmoke
SUPPRIME Folder: C:\Users\doudou\AppData\Local\wJHBd4gG9ZqHHbE
SUPPRIME Folder: c:\users\doudou\desktop\adobe cs4 master_keygen and activation
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{10CD5CBC-4ACA-4851-A4D0-DEA533489B3C}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{12E8F1D9-36FB-4C49-8C99-F6DEFF33FD5A}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{1A22891B-C856-4A93-93D5-F045D79044E6}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{2A47F221-E10E-4962-91DD-AA1FEFD49312}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{2E12A963-8824-40BC-8CED-CEC789AA2D3A}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{3C1088A5-F9DA-4782-AE41-3ECCF8EFAB58}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{4B1AA4EF-A830-47FD-929B-84E56DBD8462}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{5786B676-A76E-4FBA-A63B-47CA70E14C6D}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{6150AA06-9A17-4F58-BDE8-A4AC3DE72A30}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{8DAB09E9-E5BF-4F2E-ADA3-1F6E69D61F76}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{950426F7-456A-4142-8DCC-83BF09AD7F0D}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{96290E7B-BE35-4CF6-9A20-B7AB3755A273}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{A4AAF24E-63E8-4ED2-B48D-0D9346A4E193}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{A510A47F-28F9-4DC8-A38D-4B9CEB22CCB2}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{B3F654E1-3682-4157-A473-26B9F069DA88}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{B53F9C92-989B-41EB-98FF-01D7166CC010}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{C986877C-644A-4902-9168-550218CADDB0}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{CEC9045A-1D7F-4435-9017-870C0D19B7FC}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{D154436E-9ED6-4471-8ED7-0EE0C2AE24EB}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{D5CE3E02-7D72-4A89-9FC5-698B8DADD292}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{D83F6F3C-2A01-4A55-8A52-8AF86DE26154}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{F5A8F289-E11D-4DDE-8BF8-7F1CD37F3F93}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{FF191D1A-294D-415C-B0B5-EA6B6E2AE28B}
SUPPRIME Folder: c:\program files\vuze_remote
SUPPRIME Folder: c:\users\doudou\appdata\locallow\toolbar4
SUPPRIME Folder: c:\users\doudou\appdata\locallow\vuze_remote
========== Fichier(s) ==========
ABSENT File: c:\users\doudou\desktop\spybot - search & destroy.lnk
ABSENT File: c:\program files\spybot - search & destroy\spybotsd.exe
SUPPRIME File: c:\program files\spybot - search & destroy\sdwinsec.exe
SUPPRIME File: C:\Users\doudou\Documents\prog suple tomtom one\pdf converter crack + keygen.rar
SUPPRIME File*: d:\keygen.exe
SUPPRIME File***: d:\mes documents\paint shop pro 7 français\(gen) paint shop pro 7.xx keygen crack.exe
ABSENT File: c:\program files\uniblue\powers~1\launcher.exe
ABSENT Folder/File: c:\program files\offerbox
ABSENT Folder/File: c:\program files\pricegong
ABSENT Folder/File: c:\program files\whitesmoke
ABSENT Folder/File: c:\programdata\microsoft\windows\start menu\programs\pricegong
ABSENT Folder/File: c:\users\doudou\appdata\roaming\offerbox
ABSENT Folder/File: c:\users\doudou\appdata\roaming\whitesmoke
========== Récapitulatif ==========
2 : Processus mémoire
71 : Clé(s) du Registre
15 : Valeur(s) du Registre
37 : Dossier(s)
13 : Fichier(s)
1 : Préférences navigateur
End of clean in 04mn 00s
========== Chemin de fichier rapport ==========
C:\ZHP\ZHPFix[R1].txt - 31/01/2012 08:37:41 [10687]
desinstalle vuze remote toolbar il ne se sort pas
desinstalle sweetIM je ne le trouve pas
Rapport de ZHPFix 1.12.3379 par Nicolas Coolman, Update du 22/01/2011
Fichier d'export Registre : C:\ZHP\ZHPExportRegistry-31-01-2012-08-37-41.txt
Run by doudou at 31/01/2012 08:37:41
Windows 7 Ultimate Edition, 32-bit (Build 7600)
Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
Web site : http://nicolascoolman.skyrock.com/
========== Processus mémoire ==========
SUPPRIME Memory Process: D:\keygen.exe
SUPPRIME Memory Process: D:\Mes documents\Paint Shop Pro 7 Français\(gen) Paint Shop Pro 7.xx Keygen Crack.exe
========== Clé(s) du Registre ==========
SUPPRIME Key: CLSID BHO: {FCBCCB87-9224-4B8D-B117-F56D924BEB18}
ABSENT Key: Service: gpsvc
ABSENT Key: Service: SBSDWSCService
SUPPRIME Key: HKCU\Software\AppDataLow\Software\PriceGong
SUPPRIME Key: HKCU\Software\AppDataLow\Software\toolbar
SUPPRIME Key: HKCU\Software\OfferBox
SUPPRIME Key: HKCU\Software\SweetIM
SUPPRIME Key: HKCU\Software\WhiteSmoke
SUPPRIME Key: HKLM\Software\BrowserChoice
SUPPRIME Key: HKLM\Software\SweetIM
SUPPRIME Key: HKLM\Software\WhiteSmoke
SUPPRIME Key: StartupReg: PowerSuite
SUPPRIME Key: SearchScopes :{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SUPPRIME Key: HKLM\Software\Classes\AppID\PriceGongIE.DLL
SUPPRIME Key: HKLM\Software\Classes\AppID\TbCommonUtils.DLL
SUPPRIME Key: HKLM\Software\Classes\AppID\TbHelper.EXE
SUPPRIME Key: HKLM\Software\Classes\PriceFactorIE.PriceGongBHO
SUPPRIME Key: HKLM\Software\Classes\PriceFactorIE.PriceGongBHO.1
SUPPRIME Key: HKLM\Software\Classes\PriceGongIE.PriceGongCtrl
SUPPRIME Key: HKLM\Software\Classes\PriceGongIE.PriceGongCtrl.1
SUPPRIME Key: HKLM\Software\Classes\TbCommonUtils.CommonUtils
SUPPRIME Key: HKLM\Software\Classes\TbCommonUtils.CommonUtils.1
SUPPRIME Key: HKLM\Software\Classes\TbHelper.TbDownloadManager
SUPPRIME Key: HKLM\Software\Classes\TbHelper.TbDownloadManager.1
SUPPRIME Key: HKLM\Software\Classes\TbHelper.TbPropertyManager
SUPPRIME Key: HKLM\Software\Classes\TbHelper.TbPropertyManager.1
SUPPRIME Key: HKLM\Software\Classes\TbHelper.TbRequest
SUPPRIME Key: HKLM\Software\Classes\TbHelper.TbRequest.1
SUPPRIME Key: HKLM\Software\Classes\TbHelper.TbTask
SUPPRIME Key: HKLM\Software\Classes\TbHelper.TbTask.1
SUPPRIME Key: HKLM\Software\Classes\TbHelper.ToolbarHelper
SUPPRIME Key: HKLM\Software\Classes\TbHelper.ToolbarHelper.1
SUPPRIME Key: HKLM\Software\Classes\Toolbar3.ContextMenuNotifier
SUPPRIME Key: HKLM\Software\Classes\Toolbar3.ContextMenuNotifier.1
SUPPRIME Key: HKLM\Software\Classes\Toolbar3.CustomInternetSecurityImpl
SUPPRIME Key: HKLM\Software\Classes\Toolbar3.CustomInternetSecurityImpl.1
SUPPRIME Key: HKLM\Software\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
SUPPRIME Key: HKLM\Software\Classes\Interface\{2a42d13c-d427-4787-821b-cf6973855778}
ABSENT Key: HKLM\Software\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{338B4DFE-2E2C-4338-9E41-E176D497299E}
SUPPRIME Key: HKLM\Software\Classes\CLSID\{338B4DFE-2E2C-4338-9E41-E176D497299E}
SUPPRIME Key: HKLM\Software\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}
SUPPRIME Key: HKLM\Software\Classes\Interface\{3d8478aa-7b88-48a9-8bcb-b85d594411ec}
SUPPRIME Key: HKLM\Software\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
SUPPRIME Key: HKLM\Software\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
SUPPRIME Key: HKLM\Software\Classes\Interface\{4897bba6-48d9-468c-8efa-846275d7701b}
SUPPRIME Key: HKLM\Software\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
SUPPRIME Key: HKLM\Software\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
SUPPRIME Key: HKLM\Software\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
SUPPRIME Key: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
SUPPRIME Key: HKLM\Software\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
SUPPRIME Key: HKLM\Software\Classes\AppID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}
SUPPRIME Key: HKLM\Software\Classes\TypeLib\{8B3372D0-09F0-41A5-8D9B-134E148672FB}
SUPPRIME Key: HKLM\Software\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
ABSENT Key: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SUPPRIME Key: HKLM\Software\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052}
SUPPRIME Key: HKLM\Software\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
SUPPRIME Key: HKLM\Software\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
SUPPRIME Key: HKLM\Software\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
SUPPRIME Key: HKLM\Software\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
SUPPRIME Key: HKLM\Software\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
SUPPRIME Key: HKLM\Software\Classes\CLSID\{D2A2595C-4FE4-4315-AA9B-19DBD6271B71}
SUPPRIME Key: HKLM\Software\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}
SUPPRIME Key: HKLM\Software\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
SUPPRIME Key: HKLM\Software\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
SUPPRIME Key: HKLM\Software\Classes\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}
SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
ABSENT Key: HKLM\Software\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
ABSENT Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
ABSENT Key: HKLM\Software\Google\Chrome\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok
ABSENT Key: HKCU\Software\AppDataLow\Software\Toolbar
========== Valeur(s) du Registre ==========
SUPPRIME URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc}
SUPPRIME RunValue: TaskTray
ABSENT RunValue: RegistryMechanic
ABSENT inetcpl.cpl:
SUPPRIME {61172B87-6641-48A9-A4C4-98A2F4A08F2C}
SUPPRIME {02E5F3FA-B922-4E24-8E02-8FF7F82BDC48}
SUPPRIME {F7224A90-0D4F-4622-ADDE-19277E04FC24}
SUPPRIME {267513BF-15D6-4868-8423-6F22B1758EED}
SUPPRIME {089F0DEF-8888-47CF-BE8A-1DD44030648F}
SUPPRIME {36A20EE1-4CD3-433E-9574-E7FA48FCD2D7}
SUPPRIME {76D5D0AC-92B5-4366-A9C1-FF45B27A21EF}
SUPPRIME {B07E31D2-4569-46D1-840D-8240B7233D03}
SUPPRIME {5047FDD9-14B3-4E13-ACAC-6335AF9C234F}
SUPPRIME {9DB553A7-F6C9-4605-BEB6-6C67C04A45DA}
SUPPRIME [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Associations]:bak_Application
========== Préférences navigateur ==========
SUPPRIME Folder Chrome: C:\Users\doudou\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok
========== Dossier(s) ==========
SUPPRIME Folder: C:\Users\doudou\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok
SUPPRIME Folder: C:\Program Files\Emsisoft Anti-Malware
SUPPRIME Folder: C:\Program Files\OfferBox
ABSENT C:\Program Files\PriceGong
SUPPRIME Reboot Folder**: C:\Program Files\Spybot - Search & Destroy
SUPPRIME Folder: C:\Program Files\WhiteSmoke
SUPPRIME Folder: C:\ProgramData\Spybot - Search & Destroy
SUPPRIME Folder: C:\Users\doudou\AppData\Roaming\OfferBox
SUPPRIME Folder: C:\Users\doudou\AppData\Roaming\WhiteSmoke
SUPPRIME Folder: C:\Users\doudou\AppData\Local\wJHBd4gG9ZqHHbE
SUPPRIME Folder: c:\users\doudou\desktop\adobe cs4 master_keygen and activation
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{10CD5CBC-4ACA-4851-A4D0-DEA533489B3C}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{12E8F1D9-36FB-4C49-8C99-F6DEFF33FD5A}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{1A22891B-C856-4A93-93D5-F045D79044E6}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{2A47F221-E10E-4962-91DD-AA1FEFD49312}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{2E12A963-8824-40BC-8CED-CEC789AA2D3A}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{3C1088A5-F9DA-4782-AE41-3ECCF8EFAB58}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{4B1AA4EF-A830-47FD-929B-84E56DBD8462}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{5786B676-A76E-4FBA-A63B-47CA70E14C6D}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{6150AA06-9A17-4F58-BDE8-A4AC3DE72A30}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{8DAB09E9-E5BF-4F2E-ADA3-1F6E69D61F76}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{950426F7-456A-4142-8DCC-83BF09AD7F0D}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{96290E7B-BE35-4CF6-9A20-B7AB3755A273}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{A4AAF24E-63E8-4ED2-B48D-0D9346A4E193}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{A510A47F-28F9-4DC8-A38D-4B9CEB22CCB2}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{B3F654E1-3682-4157-A473-26B9F069DA88}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{B53F9C92-989B-41EB-98FF-01D7166CC010}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{C986877C-644A-4902-9168-550218CADDB0}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{CEC9045A-1D7F-4435-9017-870C0D19B7FC}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{D154436E-9ED6-4471-8ED7-0EE0C2AE24EB}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{D5CE3E02-7D72-4A89-9FC5-698B8DADD292}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{D83F6F3C-2A01-4A55-8A52-8AF86DE26154}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{F5A8F289-E11D-4DDE-8BF8-7F1CD37F3F93}
SUPPRIME Folder: C:\Users\doudou\AppData\Local\{FF191D1A-294D-415C-B0B5-EA6B6E2AE28B}
SUPPRIME Folder: c:\program files\vuze_remote
SUPPRIME Folder: c:\users\doudou\appdata\locallow\toolbar4
SUPPRIME Folder: c:\users\doudou\appdata\locallow\vuze_remote
========== Fichier(s) ==========
ABSENT File: c:\users\doudou\desktop\spybot - search & destroy.lnk
ABSENT File: c:\program files\spybot - search & destroy\spybotsd.exe
SUPPRIME File: c:\program files\spybot - search & destroy\sdwinsec.exe
SUPPRIME File: C:\Users\doudou\Documents\prog suple tomtom one\pdf converter crack + keygen.rar
SUPPRIME File*: d:\keygen.exe
SUPPRIME File***: d:\mes documents\paint shop pro 7 français\(gen) paint shop pro 7.xx keygen crack.exe
ABSENT File: c:\program files\uniblue\powers~1\launcher.exe
ABSENT Folder/File: c:\program files\offerbox
ABSENT Folder/File: c:\program files\pricegong
ABSENT Folder/File: c:\program files\whitesmoke
ABSENT Folder/File: c:\programdata\microsoft\windows\start menu\programs\pricegong
ABSENT Folder/File: c:\users\doudou\appdata\roaming\offerbox
ABSENT Folder/File: c:\users\doudou\appdata\roaming\whitesmoke
========== Récapitulatif ==========
2 : Processus mémoire
71 : Clé(s) du Registre
15 : Valeur(s) du Registre
37 : Dossier(s)
13 : Fichier(s)
1 : Préférences navigateur
End of clean in 04mn 00s
========== Chemin de fichier rapport ==========
C:\ZHP\ZHPFix[R1].txt - 31/01/2012 08:37:41 [10687]