Comment supprimer certified toolbar
Résolu
THESO
Messages postés
17
Statut
Membre
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour,
En voulant installer un webplayer, j'ai certified toolbar search qui s'est installé et impossible d'ouvrir internet.
Merci de votre aide.
En voulant installer un webplayer, j'ai certified toolbar search qui s'est installé et impossible d'ouvrir internet.
Merci de votre aide.
A voir également:
- Comment supprimer certified toolbar
- Supprimer rond bleu whatsapp - Guide
- Comment supprimer une page sur word - Guide
- Supprimer pub youtube - Accueil - Streaming
- Comment supprimer une application préinstallée sur android - Guide
- Fichier impossible à supprimer - Guide
27 réponses
Bonjour,
Utilisez ceci sur le pc infecté:
https://www.security-helpzone.com/2013/02/24/securite-adware-adwcleaner_suprimer_logiciels_indesirables/
Utilisez ceci sur le pc infecté:
https://www.security-helpzone.com/2013/02/24/securite-adware-adwcleaner_suprimer_logiciels_indesirables/
Re,
Voici le rapport AdwCleaner,
# AdwCleaner v2.100 - Rapport crÈÈ le 15/12/2012 # 16:45:37
# Mis # jour le 09/12/2012 par Xplode
# SystËme d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : NADIA - NADIA-PC
# Mode de dÈmarrage : Normal
# ExÈcutÈ depuis : C:\Users\NADIA\Desktop\adwcleaner.exe
# Option [Suppression]
***** [Services] *****
***** [Fichiers / Dossiers] *****
Dossier SupprimÈ : C:\ProgramData\Partner
Dossier SupprimÈ : C:\Users\NADIA\AppData\Local\lollipop
Fichier SupprimÈ : C:\Program Files (x86)\Common Files\plugin.crx
***** [Registre] *****
ClÈ SupprimÈe : HKCU\Software\lollipop
ClÈ SupprimÈe : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
ClÈ SupprimÈe : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\lollipop
ClÈ SupprimÈe : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
ClÈ SupprimÈe : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Valeur SupprimÈe : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [lollipop]
***** [Navigateurs] *****
-\\ Internet Explorer v9.0.8112.16457
RemplacÈ : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77 --> hxxp://www.google.com
RemplacÈ : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77 --> hxxp://www.google.com
RemplacÈ : [HKCU\Software\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77 --> hxxp://www.google.com
RemplacÈ : [HKCU\Software\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77 --> hxxp://www.google.com
RemplacÈ : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77 --> hxxp://www.google.com
RemplacÈ : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77 --> hxxp://www.google.com
RemplacÈ : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77 --> hxxp://www.google.com
RemplacÈ : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77 --> hxxp://www.google.com
*************************
AdwCleaner[S1].txt - [2609 octets] - [15/12/2012 16:45:37]
########## EOF - C:\AdwCleaner[S1].txt - [2669 octets] ##########
Voici le rapport AdwCleaner,
# AdwCleaner v2.100 - Rapport crÈÈ le 15/12/2012 # 16:45:37
# Mis # jour le 09/12/2012 par Xplode
# SystËme d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : NADIA - NADIA-PC
# Mode de dÈmarrage : Normal
# ExÈcutÈ depuis : C:\Users\NADIA\Desktop\adwcleaner.exe
# Option [Suppression]
***** [Services] *****
***** [Fichiers / Dossiers] *****
Dossier SupprimÈ : C:\ProgramData\Partner
Dossier SupprimÈ : C:\Users\NADIA\AppData\Local\lollipop
Fichier SupprimÈ : C:\Program Files (x86)\Common Files\plugin.crx
***** [Registre] *****
ClÈ SupprimÈe : HKCU\Software\lollipop
ClÈ SupprimÈe : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
ClÈ SupprimÈe : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\lollipop
ClÈ SupprimÈe : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
ClÈ SupprimÈe : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Valeur SupprimÈe : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [lollipop]
***** [Navigateurs] *****
-\\ Internet Explorer v9.0.8112.16457
RemplacÈ : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77 --> hxxp://www.google.com
RemplacÈ : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77 --> hxxp://www.google.com
RemplacÈ : [HKCU\Software\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77 --> hxxp://www.google.com
RemplacÈ : [HKCU\Software\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77 --> hxxp://www.google.com
RemplacÈ : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77 --> hxxp://www.google.com
RemplacÈ : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77 --> hxxp://www.google.com
RemplacÈ : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77 --> hxxp://www.google.com
RemplacÈ : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=38268&home=true&tid=77 --> hxxp://www.google.com
*************************
AdwCleaner[S1].txt - [2609 octets] - [15/12/2012 16:45:37]
########## EOF - C:\AdwCleaner[S1].txt - [2669 octets] ##########
Après avoir exécuté AdwCleaner, ma page d'acceuil s'ouvre, mais lorsque je veux aller sur un site, celui si ne s'ouvre pas, et recherche continuellement.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
J'avais pas compris que je devais aussi exécuter Ad-Remover.
Voice le rapport de Ad-Remover
======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======
Mis # jour par TeamXscript le 12/04/11
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
Site web: http://www.teamxscript.org
C:\Program Files (x86)\Ad-Remover\main.exe (CLEAN [1]) -> LancÈ # 18:31:25 le 15/12/2012, Mode normal
Microsoft Windows+7 ...dition Familiale Premium Service Pack 1 (X64)
NADIA@NADIA-PC (ASUSTeK Computer Inc. K93SV)
============== ACTION(S) ==============
(!) -- Fichiers temporaires supprimÈs.
============== SCAN ADDITIONNEL ==============
**** Internet Explorer Version [9.0.8112.16421] ****
HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
HKCU_Main|Start Page - hxxp://fr.msn.com/
HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Start Page - hxxp://fr.msn.com/
HKLM_Toolbar|{8dcb7100-df86-4384-8842-8fa844297b3f} ("C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll") (x)
HKCU_ElevationPolicy\{1024F1BE-76DC-40d5-AB98-664A4185E5FA} - C:\Users\NADIA\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe (Skype Limited)
HKCU_ElevationPolicy\{825B0769-578F-4DF5-91CB-C05DFEE4336F} - C:\Users\NADIA\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe (Skype Limited)
HKLM_ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a} - C:\Windows\SysWOW64\wpcer.exe (x)
HKLM_ElevationPolicy\{0a402d70-1f10-4ae7-bec9-286a98240695} - C:\Windows\SysWOW64\winfxdocobj.exe (x)
HKLM_ElevationPolicy\{1024F1BE-76DC-40d5-AB98-664A4185E5FA} - C:\Users\NADIA\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe (Skype Limited)
HKLM_ElevationPolicy\{1C306DF7-2171-45c8-9324-D36448104BD5} - C:\Program Files (x86)\Free Download Manager\fdm.exe (x)
HKLM_ElevationPolicy\{6A7C9604-8A57-4B28-821B-BDEDF0E04788} - C:\Program Files\Microsoft Office\Office14\winproj.exe (x)
HKLM_ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files (x86)\Internet Explorer\iedw.exe (x)
HKLM_ElevationPolicy\{A6E2003F-95C5-4591-BA9A-0093080FDB5C} - C:\Program Files (x86)\Common Files\Oberon Media\OberonBroker\1.0.0.63\OberonBroker.exe (?)
HKLM_ElevationPolicy\{aa851425-0109-43f3-9ed2-7b7090125861} - C:\Program Files (x86)\Microsoft\BingBar\BingBar.exe (Microsoft Corporation.)
HKLM_ElevationPolicy\{B43A0C1E-B63F-4691-B68F-CD807A45DA01} - C:\Windows\system32\TSWbPrxy.exe (x)
HKLM_ElevationPolicy\{cfd485f0-96bd-47cd-bb6d-cd7dda95f102} - C:\Windows\Launcher.exe (?)
BHO\{1CA1377B-DC1D-4A52-9585-6E06050FAC53} - "TmIEPlugInBHO Class" (C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg32.dll)
BHO\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - "Skype Browser Helper" (C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll)
BHO\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - "TmBpIeBHO Class" (C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe32.dll)
BHO\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - "Google Dictionary Compression sdch" (C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll)
BHO\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "Bing Bar Helper" ("C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll") (x)
========================================
C:\Program Files (x86)\Ad-Remover\Quarantine: 0 Fichier(s)
C:\Program Files (x86)\Ad-Remover\Backup: 14 Fichier(s)
C:\Ad-Report-CLEAN[1].txt - 15/12/2012 18:31:52 (3804 Octet(s))
Fin #: 18:32:30, 15/12/2012
============== E.O.F ==============
Voice le rapport de Ad-Remover
======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======
Mis # jour par TeamXscript le 12/04/11
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
Site web: http://www.teamxscript.org
C:\Program Files (x86)\Ad-Remover\main.exe (CLEAN [1]) -> LancÈ # 18:31:25 le 15/12/2012, Mode normal
Microsoft Windows+7 ...dition Familiale Premium Service Pack 1 (X64)
NADIA@NADIA-PC (ASUSTeK Computer Inc. K93SV)
============== ACTION(S) ==============
(!) -- Fichiers temporaires supprimÈs.
============== SCAN ADDITIONNEL ==============
**** Internet Explorer Version [9.0.8112.16421] ****
HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
HKCU_Main|Start Page - hxxp://fr.msn.com/
HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Start Page - hxxp://fr.msn.com/
HKLM_Toolbar|{8dcb7100-df86-4384-8842-8fa844297b3f} ("C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll") (x)
HKCU_ElevationPolicy\{1024F1BE-76DC-40d5-AB98-664A4185E5FA} - C:\Users\NADIA\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe (Skype Limited)
HKCU_ElevationPolicy\{825B0769-578F-4DF5-91CB-C05DFEE4336F} - C:\Users\NADIA\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe (Skype Limited)
HKLM_ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a} - C:\Windows\SysWOW64\wpcer.exe (x)
HKLM_ElevationPolicy\{0a402d70-1f10-4ae7-bec9-286a98240695} - C:\Windows\SysWOW64\winfxdocobj.exe (x)
HKLM_ElevationPolicy\{1024F1BE-76DC-40d5-AB98-664A4185E5FA} - C:\Users\NADIA\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe (Skype Limited)
HKLM_ElevationPolicy\{1C306DF7-2171-45c8-9324-D36448104BD5} - C:\Program Files (x86)\Free Download Manager\fdm.exe (x)
HKLM_ElevationPolicy\{6A7C9604-8A57-4B28-821B-BDEDF0E04788} - C:\Program Files\Microsoft Office\Office14\winproj.exe (x)
HKLM_ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files (x86)\Internet Explorer\iedw.exe (x)
HKLM_ElevationPolicy\{A6E2003F-95C5-4591-BA9A-0093080FDB5C} - C:\Program Files (x86)\Common Files\Oberon Media\OberonBroker\1.0.0.63\OberonBroker.exe (?)
HKLM_ElevationPolicy\{aa851425-0109-43f3-9ed2-7b7090125861} - C:\Program Files (x86)\Microsoft\BingBar\BingBar.exe (Microsoft Corporation.)
HKLM_ElevationPolicy\{B43A0C1E-B63F-4691-B68F-CD807A45DA01} - C:\Windows\system32\TSWbPrxy.exe (x)
HKLM_ElevationPolicy\{cfd485f0-96bd-47cd-bb6d-cd7dda95f102} - C:\Windows\Launcher.exe (?)
BHO\{1CA1377B-DC1D-4A52-9585-6E06050FAC53} - "TmIEPlugInBHO Class" (C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg32.dll)
BHO\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - "Skype Browser Helper" (C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll)
BHO\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - "TmBpIeBHO Class" (C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe32.dll)
BHO\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - "Google Dictionary Compression sdch" (C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll)
BHO\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "Bing Bar Helper" ("C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll") (x)
========================================
C:\Program Files (x86)\Ad-Remover\Quarantine: 0 Fichier(s)
C:\Program Files (x86)\Ad-Remover\Backup: 14 Fichier(s)
C:\Ad-Report-CLEAN[1].txt - 15/12/2012 18:31:52 (3804 Octet(s))
Fin #: 18:32:30, 15/12/2012
============== E.O.F ==============
J'avais pas compris que je devais aussi exécuter Ad-Remover.
Ne vous mentez pas à vous même... Nous ne sommes pas des truffes.
---> http://www.security-helpzone.com/Thread-ZHPDiag-Generer-un-rapport
O44 - LFC:[MD5.C819237F701E104E5F2894F73FF29962] - 14/12/2012 - 21:20:59 ---A- . (...) -- C:\SetSearchAndHomepageInBrowserLog.txt [224]
[HKCU\Software\ProtectedSearch] => ProtectedSearch
O43 - CFD: 14/12/2012 - 21:20:10 - [0] ----D C:\Users\NADIA\AppData\Local\Programs
O43 - CFD: 20/06/2012 - 20:41:40 - [0] ----D C:\Users\NADIA\AppData\Local\{1A7AADC2-CBDC-4367-B0F4-2A3DB5F5873B}
O43 - CFD: 20/06/2012 - 20:41:48 - [0] ----D C:\Users\NADIA\AppData\Local\{CA2ED2C0-44E1-4D58-AE9E-1F61F16ADB1F}
O43 - CFD: 23/08/2011 - 06:46:50 - [0] ----D C:\Users\NADIA\AppData\Local\{EC0F35A2-B40F-4DC4-989B-49615478C5C2}
[MD5.90E1D86D979B92738A47D7072CB22DA8] [SPRF][07/07/2010] (...) -- C:\ProgramData\FullRemove.exe [131472]
[MD5.B62767DCE3DB80AE1A7259205C437192] [SPRF][14/12/2012] (.Webplayer Toolbar - Webplayer Toolbar Setup.) -- C:\Users\NADIA\Desktop\Addon.exe [4091960]
[HKLM\Software\Wow6432Node\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] => Toolbar.Skype
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] => Toolbar.Skype
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
[HKLM\Software\Wow6432Node\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
O90 - PUC: "25BD30E1BC5D83343A835E62DDD4D41B" . (.Bing Bar.) -- C:\Windows\Installer\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}\icon_installer_ico
O2 - BHO: (no name) [64Bits] - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Clé orpheline => Toolbar.Skype
O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM][64Bits] -- {1E03DB52-D5CB-4338-A338-E526DD4D4DB1}
Copiez ces lignes et suivez ceci:
http://www.security-helpzone.com/Thread-ZHPFix-Script
Voici le rapport de ZHPFix :
O44 - LFC:[MD5.C819237F701E104E5F2894F73FF29962] - 14/12/2012 - 21:20:59 ---A- . (...) -- C:\SetSearchAndHomepageInBrowserLog.txt [224]
[HKCU\Software\ProtectedSearch] => ProtectedSearch
O43 - CFD: 14/12/2012 - 21:20:10 - [0] ----D C:\Users\NADIA\AppData\Local\Programs
O43 - CFD: 20/06/2012 - 20:41:40 - [0] ----D C:\Users\NADIA\AppData\Local\{1A7AADC2-CBDC-4367-B0F4-2A3DB5F5873B}
O43 - CFD: 20/06/2012 - 20:41:48 - [0] ----D C:\Users\NADIA\AppData\Local\{CA2ED2C0-44E1-4D58-AE9E-1F61F16ADB1F}
O43 - CFD: 23/08/2011 - 06:46:50 - [0] ----D C:\Users\NADIA\AppData\Local\{EC0F35A2-B40F-4DC4-989B-49615478C5C2}
[MD5.90E1D86D979B92738A47D7072CB22DA8] [SPRF][07/07/2010] (...) -- C:\ProgramData\FullRemove.exe [131472]
[MD5.B62767DCE3DB80AE1A7259205C437192] [SPRF][14/12/2012] (.Webplayer Toolbar - Webplayer Toolbar Setup.) -- C:\Users\NADIA\Desktop\Addon.exe [4091960]
[HKLM\Software\Wow6432Node\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] => Toolbar.Skype
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] => Toolbar.Skype
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
[HKLM\Software\Wow6432Node\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
O90 - PUC: "25BD30E1BC5D83343A835E62DDD4D41B" . (.Bing Bar.) -- C:\Windows\Installer\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}\icon_installer_ico
O2 - BHO: (no name) [64Bits] - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} ClÈ orpheline => Toolbar.Skype
O44 - LFC:[MD5.C819237F701E104E5F2894F73FF29962] - 14/12/2012 - 21:20:59 ---A- . (...) -- C:\SetSearchAndHomepageInBrowserLog.txt [224]
[HKCU\Software\ProtectedSearch] => ProtectedSearch
O43 - CFD: 14/12/2012 - 21:20:10 - [0] ----D C:\Users\NADIA\AppData\Local\Programs
O43 - CFD: 20/06/2012 - 20:41:40 - [0] ----D C:\Users\NADIA\AppData\Local\{1A7AADC2-CBDC-4367-B0F4-2A3DB5F5873B}
O43 - CFD: 20/06/2012 - 20:41:48 - [0] ----D C:\Users\NADIA\AppData\Local\{CA2ED2C0-44E1-4D58-AE9E-1F61F16ADB1F}
O43 - CFD: 23/08/2011 - 06:46:50 - [0] ----D C:\Users\NADIA\AppData\Local\{EC0F35A2-B40F-4DC4-989B-49615478C5C2}
[MD5.90E1D86D979B92738A47D7072CB22DA8] [SPRF][07/07/2010] (...) -- C:\ProgramData\FullRemove.exe [131472]
[MD5.B62767DCE3DB80AE1A7259205C437192] [SPRF][14/12/2012] (.Webplayer Toolbar - Webplayer Toolbar Setup.) -- C:\Users\NADIA\Desktop\Addon.exe [4091960]
[HKLM\Software\Wow6432Node\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] => Toolbar.Skype
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] => Toolbar.Skype
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
[HKLM\Software\Wow6432Node\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
O90 - PUC: "25BD30E1BC5D83343A835E62DDD4D41B" . (.Bing Bar.) -- C:\Windows\Installer\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}\icon_installer_ico
O2 - BHO: (no name) [64Bits] - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} ClÈ orpheline => Toolbar.Skype
j'ai recommencé l'analyse de ZHPFix et voici le rapport.
O44 - LFC:[MD5.C819237F701E104E5F2894F73FF29962] - 14/12/2012 - 21:20:59 ---A- . (...) -- C:\SetSearchAndHomepageInBrowserLog.txt [224]
[HKCU\Software\ProtectedSearch] => ProtectedSearch
O43 - CFD: 14/12/2012 - 21:20:10 - [0] ----D C:\Users\NADIA\AppData\Local\Programs
O43 - CFD: 20/06/2012 - 20:41:40 - [0] ----D C:\Users\NADIA\AppData\Local\{1A7AADC2-CBDC-4367-B0F4-2A3DB5F5873B}
O43 - CFD: 20/06/2012 - 20:41:48 - [0] ----D C:\Users\NADIA\AppData\Local\{CA2ED2C0-44E1-4D58-AE9E-1F61F16ADB1F}
O43 - CFD: 23/08/2011 - 06:46:50 - [0] ----D C:\Users\NADIA\AppData\Local\{EC0F35A2-B40F-4DC4-989B-49615478C5C2}
[MD5.90E1D86D979B92738A47D7072CB22DA8] [SPRF][07/07/2010] (...) -- C:\ProgramData\FullRemove.exe [131472]
[MD5.B62767DCE3DB80AE1A7259205C437192] [SPRF][14/12/2012] (.Webplayer Toolbar - Webplayer Toolbar Setup.) -- C:\Users\NADIA\Desktop\Addon.exe [4091960]
[HKLM\Software\Wow6432Node\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] => Toolbar.Skype
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] => Toolbar.Skype
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
[HKLM\Software\Wow6432Node\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
O90 - PUC: "25BD30E1BC5D83343A835E62DDD4D41B" . (.Bing Bar.) -- C:\Windows\Installer\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}\icon_installer_ico
O2 - BHO: (no name) [64Bits] - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} ClÈ orpheline => Toolbar.Skype
O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM][64Bits] -- {1E03DB52-D5CB-4338-A338-E526DD4D4DB1}
O44 - LFC:[MD5.C819237F701E104E5F2894F73FF29962] - 14/12/2012 - 21:20:59 ---A- . (...) -- C:\SetSearchAndHomepageInBrowserLog.txt [224]
[HKCU\Software\ProtectedSearch] => ProtectedSearch
O43 - CFD: 14/12/2012 - 21:20:10 - [0] ----D C:\Users\NADIA\AppData\Local\Programs
O43 - CFD: 20/06/2012 - 20:41:40 - [0] ----D C:\Users\NADIA\AppData\Local\{1A7AADC2-CBDC-4367-B0F4-2A3DB5F5873B}
O43 - CFD: 20/06/2012 - 20:41:48 - [0] ----D C:\Users\NADIA\AppData\Local\{CA2ED2C0-44E1-4D58-AE9E-1F61F16ADB1F}
O43 - CFD: 23/08/2011 - 06:46:50 - [0] ----D C:\Users\NADIA\AppData\Local\{EC0F35A2-B40F-4DC4-989B-49615478C5C2}
[MD5.90E1D86D979B92738A47D7072CB22DA8] [SPRF][07/07/2010] (...) -- C:\ProgramData\FullRemove.exe [131472]
[MD5.B62767DCE3DB80AE1A7259205C437192] [SPRF][14/12/2012] (.Webplayer Toolbar - Webplayer Toolbar Setup.) -- C:\Users\NADIA\Desktop\Addon.exe [4091960]
[HKLM\Software\Wow6432Node\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] => Toolbar.Skype
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] => Toolbar.Skype
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
[HKLM\Software\Wow6432Node\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype
O90 - PUC: "25BD30E1BC5D83343A835E62DDD4D41B" . (.Bing Bar.) -- C:\Windows\Installer\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}\icon_installer_ico
O2 - BHO: (no name) [64Bits] - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} ClÈ orpheline => Toolbar.Skype
O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM][64Bits] -- {1E03DB52-D5CB-4338-A338-E526DD4D4DB1}
je crois avoir compris mon erreur.
Rapport de ZHPFix 1.3.10 par Nicolas Coolman, Update du 11/12/2012
Fichier d'export Registre :
Run by NADIA at 16/12/2012 13:59:26
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
========== Logiciel(s) ==========
SUPPRIME Bing Bar
========== Processus mÈmoire ==========
SUPPRIME Memory Process: C:\ProgramData\FullRemove.exe
SUPPRIME Memory Process: C:\Users\NADIA\Desktop\Addon.exe
========== ClÈ(s) du Registre ==========
SUPPRIME Key: HKCU\Software\ProtectedSearch
SUPPRIME Key: HKLM\Software\Wow6432Node\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
SUPPRIME Key: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
SUPPRIME Key: HKLM\Software\Wow6432Node\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
SUPPRIME Key: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
ABSENT Key: [HKLM\\Software\Classes\Installer\Products\\25BD30E1BC5D83343A835E62DDD4D41B]
ABSENT Key: CLSID BHO: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
========== Dossier(s) ==========
SUPPRIME Folder: C:\Users\NADIA\AppData\Local\Programs
SUPPRIME Folder: C:\Users\NADIA\AppData\Local\{1A7AADC2-CBDC-4367-B0F4-2A3DB5F5873B}
SUPPRIME Folder: C:\Users\NADIA\AppData\Local\{CA2ED2C0-44E1-4D58-AE9E-1F61F16ADB1F}
SUPPRIME Folder: C:\Users\NADIA\AppData\Local\{EC0F35A2-B40F-4DC4-989B-49615478C5C2}
========== Fichier(s) ==========
SUPPRIME File: c:\setsearchandhomepageinbrowserlog.txt
SUPPRIME File: c:\programdata\fullremove.exe
SUPPRIME File*: c:\users\nadia\desktop\addon.exe
========== RÈcapitulatif ==========
2 : Processus mÈmoire
9 : ClÈ(s) du Registre
4 : Dossier(s)
3 : Fichier(s)
1 : Logiciel(s)
End of clean in 00mn 49s
========== Chemin de fichier rapport ==========
C:\ZHP\ZHPFix[R1].txt - 16/12/2012 13:59:26 [2097]
Rapport de ZHPFix 1.3.10 par Nicolas Coolman, Update du 11/12/2012
Fichier d'export Registre :
Run by NADIA at 16/12/2012 13:59:26
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
========== Logiciel(s) ==========
SUPPRIME Bing Bar
========== Processus mÈmoire ==========
SUPPRIME Memory Process: C:\ProgramData\FullRemove.exe
SUPPRIME Memory Process: C:\Users\NADIA\Desktop\Addon.exe
========== ClÈ(s) du Registre ==========
SUPPRIME Key: HKCU\Software\ProtectedSearch
SUPPRIME Key: HKLM\Software\Wow6432Node\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
SUPPRIME Key: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
SUPPRIME Key: HKLM\Software\Wow6432Node\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
SUPPRIME Key: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
ABSENT Key: [HKLM\\Software\Classes\Installer\Products\\25BD30E1BC5D83343A835E62DDD4D41B]
ABSENT Key: CLSID BHO: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
========== Dossier(s) ==========
SUPPRIME Folder: C:\Users\NADIA\AppData\Local\Programs
SUPPRIME Folder: C:\Users\NADIA\AppData\Local\{1A7AADC2-CBDC-4367-B0F4-2A3DB5F5873B}
SUPPRIME Folder: C:\Users\NADIA\AppData\Local\{CA2ED2C0-44E1-4D58-AE9E-1F61F16ADB1F}
SUPPRIME Folder: C:\Users\NADIA\AppData\Local\{EC0F35A2-B40F-4DC4-989B-49615478C5C2}
========== Fichier(s) ==========
SUPPRIME File: c:\setsearchandhomepageinbrowserlog.txt
SUPPRIME File: c:\programdata\fullremove.exe
SUPPRIME File*: c:\users\nadia\desktop\addon.exe
========== RÈcapitulatif ==========
2 : Processus mÈmoire
9 : ClÈ(s) du Registre
4 : Dossier(s)
3 : Fichier(s)
1 : Logiciel(s)
End of clean in 00mn 49s
========== Chemin de fichier rapport ==========
C:\ZHP\ZHPFix[R1].txt - 16/12/2012 13:59:26 [2097]