Démarrage suspect
Résolu
abdouchefr
Messages postés
161
Date d'inscription
Statut
Membre
Dernière intervention
-
abdouchefr Messages postés 161 Date d'inscription Statut Membre Dernière intervention -
abdouchefr Messages postés 161 Date d'inscription Statut Membre Dernière intervention -
Bonjour,
Lorsque je démarre j'ai ma souris qui réagit en retard ou presque en différé lorsque le bureau est affiché avec la barre des tâches et les éléments y afférents.
Je suspecte une infiltration à distance , de toute façon cela me paraît étrange je fais quand même un hitjackthis au cas ou car même adw cleaner ne trouve rien de spécial et malware avait trouvé un adware mais le problème persiste.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:48:14, on 02/03/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Accelerer PC\PCSUService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG2013\avgidsagent.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\AVG\AVG2013\avgnsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG2013\avgemcx.exe
C:\WINDOWS\System32\StkCSrv.exe
C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe
C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe
C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe
C:\Program Files\SAMSUNG\MagicKBD\PerformanceManager.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\igfxext.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.iminent.com/?appId=9EEB36E0-7CAF-4235-8D63-A0A4C640445D
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [EDS] C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DMHotKey] C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe
O4 - HKLM\..\Run: [SUPBackground] C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe
O4 - HKLM\..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
O4 - HKLM\..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
O4 - HKLM\..\Run: [ZoneAlarm] "C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\program files\real\realplayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Envoyer à Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\docume~1\alluse~1\applic~1\browse~1\261095~1.52\{c16c1~1\browse~1.dll
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Service Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: ZoneAlarm LTD Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PC Speed Up Service (PCSUService) - Unknown owner - C:\Program Files\Accelerer PC\PCSUService.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\WINDOWS\System32\StkCSrv.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: vToolbarUpdater14.0.1 - Unknown owner - C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe
O23 - Service: vToolbarUpdater14.2.0 - Unknown owner - C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
Lorsque je démarre j'ai ma souris qui réagit en retard ou presque en différé lorsque le bureau est affiché avec la barre des tâches et les éléments y afférents.
Je suspecte une infiltration à distance , de toute façon cela me paraît étrange je fais quand même un hitjackthis au cas ou car même adw cleaner ne trouve rien de spécial et malware avait trouvé un adware mais le problème persiste.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:48:14, on 02/03/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Accelerer PC\PCSUService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG2013\avgidsagent.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\AVG\AVG2013\avgnsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG2013\avgemcx.exe
C:\WINDOWS\System32\StkCSrv.exe
C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe
C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe
C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe
C:\Program Files\SAMSUNG\MagicKBD\PerformanceManager.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\igfxext.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.iminent.com/?appId=9EEB36E0-7CAF-4235-8D63-A0A4C640445D
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [EDS] C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DMHotKey] C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe
O4 - HKLM\..\Run: [SUPBackground] C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe
O4 - HKLM\..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
O4 - HKLM\..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
O4 - HKLM\..\Run: [ZoneAlarm] "C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\program files\real\realplayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Envoyer à Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\docume~1\alluse~1\applic~1\browse~1\261095~1.52\{c16c1~1\browse~1.dll
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Service Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: ZoneAlarm LTD Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PC Speed Up Service (PCSUService) - Unknown owner - C:\Program Files\Accelerer PC\PCSUService.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\WINDOWS\System32\StkCSrv.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: vToolbarUpdater14.0.1 - Unknown owner - C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe
O23 - Service: vToolbarUpdater14.2.0 - Unknown owner - C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
A voir également:
- Démarrage suspect
- Forcer demarrage pc - Guide
- Ordinateur lent au démarrage - Guide
- Reinitialiser pc au demarrage - Guide
- Problème démarrage windows 10 - Guide
- Demarrage windows 10 - Guide
110 réponses
désolé pour le ZHPDiag mais il ne se télécharge pas malgré plusieurs tentatives et à partir de ton lien et sur le site de zebulon pareil rien ne se passe .
jacques.gache
Messages postés
33461
Date d'inscription
Statut
Contributeur sécurité
Dernière intervention
1 617
essais de le prendre ici http://sd-4.archive-host.com/membres/up/89820622056365782/ZHPDiag2.exe
j'ai un soucis avec l'installation il n'y a que le ZHPFix qui a un îcone sur le bureau le Diag lui n'est pas sur le bureau et pourtant j'ai coché la case correspondante
et voici le lien :
https://www.cjoint.com/c/CCutqIs1kDd
https://www.cjoint.com/c/CCutqIs1kDd
bonjour, tu me fais un zhpfix sur ton pc et puis un pré scan !!
1) tu fais zhpfix comme expliqué
tu prends le temps de lire la procédure avant de lancer , merci
. Copie les lignes suivantes en GRAS
SysRestore
O42 - Logiciel: Snap.Do - (.. ReSoft Ltd) [HKLM] [64Bits] - {60DF47B6-5016-4DA4-AD7B-3CEC24FE7E6E}
O42 - Logiciel: WebAdSystem - (.. KalityWeb) [HKLM] [64Bits] - {A7039FE8-5B0F-4A15-8A76-8DDF0287C74E}
[HKCU \ Software \ SweetIM]
[HKLM \ Software \ Wow6432Node \ SweetIM]
[HKLM \ Software \ Classes \ Interface \ {01947140-417F-46B6-8751-A3A2B8345E1A}]
[HKLM \ Software \ Classes \ Interface \ {819FFE21-35C7-4925-8CDA-4E0E2DB94302}]
[HKLM \ Software \ Classes \ Installer \ Features \ F479A18A22A86E3429341589FF57D81A]
[HKLM \ Software \ Wow6432Node \ Microsoft \ Tracing \ offerbox_RASAPI32]
[HKLM \ Software \ Wow6432Node \ Microsoft \ Tracing \ offerbox_RASMANCS]
[HKLM \ Software \ Wow6432Node \ Microsoft \ Tracing \ OfferBoxHTTPProxy_RASAPI32]
[HKLM \ Software \ Wow6432Node \ Microsoft \ Tracing \ OfferBoxHTTPProxy_RASMANCS]
O90 - PUC: "F479A18A22A86E3429341589FF57D81A". (SweetIM pour Messenger 3.6.). - C: \ Windows \ Installer \ {A81A974F-8A22-43E6-9243-5198FF758DA1} \ ARPPRODUCTICON.exe
O90 - PUC: "FA20CB7A821113A4CB8FA1E38E303D3B". (SweetIM Toolbar pour Internet Explorer 4.2.). - C: \ Windows \ Installer \ {A7BC02AF-1128-4A31-BCF8-1A3EE803D3B3} \ ARPPRODUCTICON.exe
FirewallRAZ
EmptyCLSID
EmptyTemp
EmptyFlash
. Lance ZHPFix de Nicolas Coolman qui se trouve sur ton bureau
. double-clique sur ZHPFix accepte l'élévation des droits avec ok
Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .
si c'est pas le cas: Clique sur gauche sur l'icone du millieu (« coller le presse papier »)
Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.
!! Déconnecte toi, désactive tes défenses (anti-virus, anti-spyware ) et ferme bien toutes autres applications ( navigateurs compris ) !!
. cliques sur GO confirmes le nettoyage !!
. Copie/colle la totalité du rapport dans ta prochaine réponse
tu le trouveras dans le dossier de zhpdiag dans program files sous le nom de ZHPFixReport
tuto si besoin merci saachaa !!
2) fais pré scan
Attention !!! : Seuls ces liens sont officiels ne pas telecharger l'outil sur d'autres liens !!
Attention !!! : cet outil peut etre détecté à tort comme virus
Attention !!! : cet outil est puissant suivre scrupuleusement les instructions ci-dessous
tous les processus "non vitaux de windows" vont être coupés , enregistre ton travail. Il y aura une extinction du bureau pendant le scan --> pas de panique.
Désactive toutes tes protections si possible , antivirus , sandbox , pare-feux , etc....: https://forum.pcastuces.com/default.asp
telecharge et enregistre Pre_Scan sur ton bureau :
http://services.service-webmaster.fr/cpt-clics/clics-30453-6820.html (renommé winlogon)
ou , si le lien n'est pas fonctionnel :
http://www.security-helpzone.com/Tools/g3n/winlogon.exe (renommé winlogon)
si l'outil est relancé plusieurs fois , il te proposera un menu et qu'aucune option n'est demandée, lance l'option "Scan|Kill"
si l'outil est bloqué par l'infection utilise cette version avec ces autres extensions :
http://www.security-helpzone.com/Tools/g3n/Pre_Scan.scr
http://www.security-helpzone.com/Tools/g3n/Pre_Scan.pif
http://www.security-helpzone.com/Tools/g3n/Pre_Scan.com
si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"
Il se peut que des fenêtres noires clignotent , laisse-le travailler.
Laisse l'outil redemarrer ton pc.
Poste Pre_Scan_la_date_et_l'heure.txt qui apparaitra à la racine de ton disque système ( généralement C:\ )
NE LE POSTE PAS SUR LE FORUM !!! (il est trop long)
Heberge le rapport sur https://www.cjoint.com/ puis donne le lien obtenu en echange sur le forum où tu te fais aider
1) tu fais zhpfix comme expliqué
tu prends le temps de lire la procédure avant de lancer , merci
. Copie les lignes suivantes en GRAS
SysRestore
O42 - Logiciel: Snap.Do - (.. ReSoft Ltd) [HKLM] [64Bits] - {60DF47B6-5016-4DA4-AD7B-3CEC24FE7E6E}
O42 - Logiciel: WebAdSystem - (.. KalityWeb) [HKLM] [64Bits] - {A7039FE8-5B0F-4A15-8A76-8DDF0287C74E}
[HKCU \ Software \ SweetIM]
[HKLM \ Software \ Wow6432Node \ SweetIM]
[HKLM \ Software \ Classes \ Interface \ {01947140-417F-46B6-8751-A3A2B8345E1A}]
[HKLM \ Software \ Classes \ Interface \ {819FFE21-35C7-4925-8CDA-4E0E2DB94302}]
[HKLM \ Software \ Classes \ Installer \ Features \ F479A18A22A86E3429341589FF57D81A]
[HKLM \ Software \ Wow6432Node \ Microsoft \ Tracing \ offerbox_RASAPI32]
[HKLM \ Software \ Wow6432Node \ Microsoft \ Tracing \ offerbox_RASMANCS]
[HKLM \ Software \ Wow6432Node \ Microsoft \ Tracing \ OfferBoxHTTPProxy_RASAPI32]
[HKLM \ Software \ Wow6432Node \ Microsoft \ Tracing \ OfferBoxHTTPProxy_RASMANCS]
O90 - PUC: "F479A18A22A86E3429341589FF57D81A". (SweetIM pour Messenger 3.6.). - C: \ Windows \ Installer \ {A81A974F-8A22-43E6-9243-5198FF758DA1} \ ARPPRODUCTICON.exe
O90 - PUC: "FA20CB7A821113A4CB8FA1E38E303D3B". (SweetIM Toolbar pour Internet Explorer 4.2.). - C: \ Windows \ Installer \ {A7BC02AF-1128-4A31-BCF8-1A3EE803D3B3} \ ARPPRODUCTICON.exe
FirewallRAZ
EmptyCLSID
EmptyTemp
EmptyFlash
. Lance ZHPFix de Nicolas Coolman qui se trouve sur ton bureau
. double-clique sur ZHPFix accepte l'élévation des droits avec ok
Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .
si c'est pas le cas: Clique sur gauche sur l'icone du millieu (« coller le presse papier »)
Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.
!! Déconnecte toi, désactive tes défenses (anti-virus, anti-spyware ) et ferme bien toutes autres applications ( navigateurs compris ) !!
. cliques sur GO confirmes le nettoyage !!
. Copie/colle la totalité du rapport dans ta prochaine réponse
tu le trouveras dans le dossier de zhpdiag dans program files sous le nom de ZHPFixReport
tuto si besoin merci saachaa !!
2) fais pré scan
Attention !!! : Seuls ces liens sont officiels ne pas telecharger l'outil sur d'autres liens !!
Attention !!! : cet outil peut etre détecté à tort comme virus
Attention !!! : cet outil est puissant suivre scrupuleusement les instructions ci-dessous
tous les processus "non vitaux de windows" vont être coupés , enregistre ton travail. Il y aura une extinction du bureau pendant le scan --> pas de panique.
Désactive toutes tes protections si possible , antivirus , sandbox , pare-feux , etc....: https://forum.pcastuces.com/default.asp
telecharge et enregistre Pre_Scan sur ton bureau :
http://services.service-webmaster.fr/cpt-clics/clics-30453-6820.html (renommé winlogon)
ou , si le lien n'est pas fonctionnel :
http://www.security-helpzone.com/Tools/g3n/winlogon.exe (renommé winlogon)
si l'outil est relancé plusieurs fois , il te proposera un menu et qu'aucune option n'est demandée, lance l'option "Scan|Kill"
si l'outil est bloqué par l'infection utilise cette version avec ces autres extensions :
http://www.security-helpzone.com/Tools/g3n/Pre_Scan.scr
http://www.security-helpzone.com/Tools/g3n/Pre_Scan.pif
http://www.security-helpzone.com/Tools/g3n/Pre_Scan.com
si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"
Il se peut que des fenêtres noires clignotent , laisse-le travailler.
Laisse l'outil redemarrer ton pc.
Poste Pre_Scan_la_date_et_l'heure.txt qui apparaitra à la racine de ton disque système ( généralement C:\ )
NE LE POSTE PAS SUR LE FORUM !!! (il est trop long)
Heberge le rapport sur https://www.cjoint.com/ puis donne le lien obtenu en echange sur le forum où tu te fais aider
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
rapport ZHPFix
Rapport de ZHPFix 2013.3.9.1 par Nicolas Coolman, Update du 9/03/2013
Fichier d'export Registre :
Run by Abdouche at 21/03/2013 20:56:48
High Elevated Privileges : OK
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Corbeille vidée
========== Logiciel(s) ==========
ABSENT Software Key: O42 - Logiciel: Snap.Do - (.. ReSoft Ltd) [HKLM] [64Bits] - {60DF47B6-5016-4DA4-AD7B-3CEC24FE7E6E}
ABSENT Software Key: O42 - Logiciel: WebAdSystem - (.. KalityWeb) [HKLM] [64Bits] - {A7039FE8-5B0F-4A15-8A76-8DDF0287C74E}
========== Clé(s) du Registre ==========
ABSENT Key: \Software\Classes\Installer\Products\\F479A18A22A86E3429341589FF57D81A". (SweetIM pour Messenger 3.6.). - C: \ Windows \ Installer \ {A81A974F-8A22-43E6-9243-5198FF758DA1} \ ARPPRODUCTICON.exe
ABSENT Key: \Software\Classes\Installer\Products\\FA20CB7A821113A4CB8FA1E38E303D3B". (SweetIM Toolbar pour Internet Explorer 4.2.). - C: \ Windows \ Installer \ {A7BC02AF-1128-4A31-BCF8-1A3EE803D3B3} \ ARPPRODUCTICON.exe
========== Valeur(s) du Registre ==========
ABSENT Valeur Standard Profile: FirewallRaz :
ABSENT Valeur Domain Profile: FirewallRaz :
========== Dossier(s) ==========
Aucun dossiers CLSID Local utilisateur vide
SUPPRIME Temporaires Windows
SUPPRIME Flash Cookies
========== Fichier(s) ==========
SUPPRIME Temporaires Windows
SUPPRIME Flash Cookies
========== Restauration Système ==========
Point de restauration du système créé avec succès
========== Autre ==========
NON TRAITE [HKCU \ Software \ SweetIM]
NON TRAITE [HKLM \ Software \ Wow6432Node \ SweetIM]
NON TRAITE [HKLM \ Software \ Classes \ Interface \ {01947140-417F-46B6-8751-A3A2B8345E1A}]
NON TRAITE [HKLM \ Software \ Classes \ Interface \ {819FFE21-35C7-4925-8CDA-4E0E2DB94302}]
NON TRAITE [HKLM \ Software \ Classes \ Installer \ Features \ F479A18A22A86E3429341589FF57D81A]
NON TRAITE [HKLM \ Software \ Wow6432Node \ Microsoft \ Tracing \ offerbox_RASAPI32]
NON TRAITE [HKLM \ Software \ Wow6432Node \ Microsoft \ Tracing \ offerbox_RASMANCS]
NON TRAITE [HKLM \ Software \ Wow6432Node \ Microsoft \ Tracing \ OfferBoxHTTPProxy_RASAPI32]
NON TRAITE [HKLM \ Software \ Wow6432Node \ Microsoft \ Tracing \ OfferBoxHTTPProxy_RASMANCS]
========== Récapitulatif ==========
2 : Clé(s) du Registre
2 : Valeur(s) du Registre
3 : Dossier(s)
2 : Fichier(s)
2 : Logiciel(s)
1 : Restauration Système
9 : Autre
End of clean in 00mn 21s
========== Chemin de fichier rapport ==========
C:\ZHP\ZHPFix[R1].txt - 21/03/2013 20:56:48 [2506]
Rapport de ZHPFix 2013.3.9.1 par Nicolas Coolman, Update du 9/03/2013
Fichier d'export Registre :
Run by Abdouche at 21/03/2013 20:56:48
High Elevated Privileges : OK
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Corbeille vidée
========== Logiciel(s) ==========
ABSENT Software Key: O42 - Logiciel: Snap.Do - (.. ReSoft Ltd) [HKLM] [64Bits] - {60DF47B6-5016-4DA4-AD7B-3CEC24FE7E6E}
ABSENT Software Key: O42 - Logiciel: WebAdSystem - (.. KalityWeb) [HKLM] [64Bits] - {A7039FE8-5B0F-4A15-8A76-8DDF0287C74E}
========== Clé(s) du Registre ==========
ABSENT Key: \Software\Classes\Installer\Products\\F479A18A22A86E3429341589FF57D81A". (SweetIM pour Messenger 3.6.). - C: \ Windows \ Installer \ {A81A974F-8A22-43E6-9243-5198FF758DA1} \ ARPPRODUCTICON.exe
ABSENT Key: \Software\Classes\Installer\Products\\FA20CB7A821113A4CB8FA1E38E303D3B". (SweetIM Toolbar pour Internet Explorer 4.2.). - C: \ Windows \ Installer \ {A7BC02AF-1128-4A31-BCF8-1A3EE803D3B3} \ ARPPRODUCTICON.exe
========== Valeur(s) du Registre ==========
ABSENT Valeur Standard Profile: FirewallRaz :
ABSENT Valeur Domain Profile: FirewallRaz :
========== Dossier(s) ==========
Aucun dossiers CLSID Local utilisateur vide
SUPPRIME Temporaires Windows
SUPPRIME Flash Cookies
========== Fichier(s) ==========
SUPPRIME Temporaires Windows
SUPPRIME Flash Cookies
========== Restauration Système ==========
Point de restauration du système créé avec succès
========== Autre ==========
NON TRAITE [HKCU \ Software \ SweetIM]
NON TRAITE [HKLM \ Software \ Wow6432Node \ SweetIM]
NON TRAITE [HKLM \ Software \ Classes \ Interface \ {01947140-417F-46B6-8751-A3A2B8345E1A}]
NON TRAITE [HKLM \ Software \ Classes \ Interface \ {819FFE21-35C7-4925-8CDA-4E0E2DB94302}]
NON TRAITE [HKLM \ Software \ Classes \ Installer \ Features \ F479A18A22A86E3429341589FF57D81A]
NON TRAITE [HKLM \ Software \ Wow6432Node \ Microsoft \ Tracing \ offerbox_RASAPI32]
NON TRAITE [HKLM \ Software \ Wow6432Node \ Microsoft \ Tracing \ offerbox_RASMANCS]
NON TRAITE [HKLM \ Software \ Wow6432Node \ Microsoft \ Tracing \ OfferBoxHTTPProxy_RASAPI32]
NON TRAITE [HKLM \ Software \ Wow6432Node \ Microsoft \ Tracing \ OfferBoxHTTPProxy_RASMANCS]
========== Récapitulatif ==========
2 : Clé(s) du Registre
2 : Valeur(s) du Registre
3 : Dossier(s)
2 : Fichier(s)
2 : Logiciel(s)
1 : Restauration Système
9 : Autre
End of clean in 00mn 21s
========== Chemin de fichier rapport ==========
C:\ZHP\ZHPFix[R1].txt - 21/03/2013 20:56:48 [2506]
j'ai AVG qui a réagit pour la prmeière fois : "Windows essaie de se connecter a un réseau public ; il est conseillé ........ etc etc etc bref de ne pas se connecter sur un réseau public. ce qui est le cas car le réseau " maison_sfr" ne prend pas
le réseau a été réinitialisé par un tech de chez SFR au téléphone et il lui a donné ce nom mais au début elle avait justement le nom suivant neuf_4D30 ; et pareil j'avais le même soucis quelques temps après par contre avec mon netbook j'arrive a me connecter sur maison_sfr donc conclusion le soucis vient du PC de bureau et non de la box j'ai un CD d'installation SFR je vais le relancer plus tard pour voir si un changement est intervenu entre temps avec toutes ces manipes et merci encore
slt
désolé de revenir mais c'est pour mon netbook le système d'exploitation uen fois ouvert beugue ( il me marque mozillafirefox ne réponds pas ) et ça me le fait à chaque ouverture de page au bout de quelques minutes :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:43:42, on 04/04/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG2013\avgidsagent.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\StkCSrv.exe
C:\Program Files\AVG\AVG2013\avgnsx.exe
C:\Program Files\AVG\AVG2013\avgemcx.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe
C:\Program Files\SAMSUNG\MagicKBD\PerformanceManager.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Updater21810\Updater21810.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-search.com/?affID=119649&tt=190313_wo3&babsrc=HP_ss&mntrId=F0460C60765E5980
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: CrossriderApp0021810 - {11111111-1111-1111-1111-110211181110} - C:\Program Files\Giant Savings Extension\Giant Savings Extension.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.10.0\bh\delta.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: DealPly - {EF7BD87A-8024-11E2-F316-F3E56188709B} - C:\Program Files\DealPly\DealPlyIE.dll (file missing)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O3 - Toolbar: Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.10.0\deltaTlbr.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [EDS] C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DMHotKey] C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe
O4 - HKLM\..\Run: [SUPBackground] C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe
O4 - HKLM\..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
O4 - HKLM\..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
O4 - HKLM\..\Run: [ZoneAlarm] "C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Updater21810.exe] C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Updater21810\Updater21810.exe /extensionid=21810 /extensionname='Giant Savings Extension' /chromeid=halffneccaebicfdfajnbfgpglahfgoe /stayidle /delay=300
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Envoyer à Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\docume~1\alluse~1\applic~1\browse~1\261095~1.52\{c16c1~1\browse~1.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Service Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ZoneAlarm LTD Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\WINDOWS\System32\StkCSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
O23 - Service: vToolbarUpdater14.0.1 - Unknown owner - C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe (file missing)
O23 - Service: vToolbarUpdater14.2.0 - Unknown owner - C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe (file missing)
désolé de revenir mais c'est pour mon netbook le système d'exploitation uen fois ouvert beugue ( il me marque mozillafirefox ne réponds pas ) et ça me le fait à chaque ouverture de page au bout de quelques minutes :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:43:42, on 04/04/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG2013\avgidsagent.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\StkCSrv.exe
C:\Program Files\AVG\AVG2013\avgnsx.exe
C:\Program Files\AVG\AVG2013\avgemcx.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe
C:\Program Files\SAMSUNG\MagicKBD\PerformanceManager.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Updater21810\Updater21810.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-search.com/?affID=119649&tt=190313_wo3&babsrc=HP_ss&mntrId=F0460C60765E5980
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: CrossriderApp0021810 - {11111111-1111-1111-1111-110211181110} - C:\Program Files\Giant Savings Extension\Giant Savings Extension.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.10.0\bh\delta.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: DealPly - {EF7BD87A-8024-11E2-F316-F3E56188709B} - C:\Program Files\DealPly\DealPlyIE.dll (file missing)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O3 - Toolbar: Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.10.0\deltaTlbr.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [EDS] C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DMHotKey] C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe
O4 - HKLM\..\Run: [SUPBackground] C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe
O4 - HKLM\..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
O4 - HKLM\..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
O4 - HKLM\..\Run: [ZoneAlarm] "C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Updater21810.exe] C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Updater21810\Updater21810.exe /extensionid=21810 /extensionname='Giant Savings Extension' /chromeid=halffneccaebicfdfajnbfgpglahfgoe /stayidle /delay=300
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Envoyer à Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\docume~1\alluse~1\applic~1\browse~1\261095~1.52\{c16c1~1\browse~1.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Service Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ZoneAlarm LTD Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\WINDOWS\System32\StkCSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
O23 - Service: vToolbarUpdater14.0.1 - Unknown owner - C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe (file missing)
O23 - Service: vToolbarUpdater14.2.0 - Unknown owner - C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe (file missing)
c'est le système de navigation et non d'exploitation excuse moi et merci
bonjour, ok ! mais le problème de ton premier pc il en est ou ??
la tu peux faire la même choses https://forums.commentcamarche.net/forum/affich-27268416-demarrage-suspect?full#1
la tu peux faire la même choses https://forums.commentcamarche.net/forum/affich-27268416-demarrage-suspect?full#1
https://www.cjoint.com/?CDfmpCTlxA2
# AdwCleaner v2.200 - Rapport créé le 05/04/2013 à 11:34:53
# Mis à jour le 02/04/2013 par Xplode
# Système d'exploitation : Microsoft Windows XP Service Pack 3 (32 bits)
# Nom d'utilisateur : Abdesalem Derdar - YOUR-10A2E35C12
# Mode de démarrage : Normal
# Exécuté depuis : C:\Documents and Settings\Abdesalem Derdar\Mes documents\Téléchargements\adwcleaner(4).exe
# Option [Suppression]
***** [Services] *****
***** [Fichiers / Dossiers] *****
Dossier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Application Data\BabSolution
Dossier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Application Data\Babylon
Dossier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Application Data\file scout
Dossier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Application Data\Mozilla\Firefox\Profiles\nzttb45z.default\extensions\ffxtlbr@delta.com
Dossier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Application Data\PerformerSoft
Dossier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Application Data\SpeedanAlysis
Dossier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Giant Savings Extension
Dossier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\halffneccaebicfdfajnbfgpglahfgoe
Dossier Supprimé : C:\Documents and Settings\All Users\Application Data\Babylon
Dossier Supprimé : C:\Documents and Settings\All Users\Application Data\Tarma Installer
Dossier Supprimé : C:\Program Files\Delta
Dossier Supprimé : C:\Program Files\Giant Savings Extension
Fichier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Application Data\Mozilla\Firefox\Profiles\nzttb45z.default\searchplugins\BrowserProtect.xml
Fichier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Application Data\Mozilla\Firefox\Profiles\nzttb45z.default\searchplugins\delta.xml
Fichier Supprimé : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
***** [Registre] *****
Clé Supprimée : HKCU\Software\Cr_Installer
Clé Supprimée : HKCU\Software\Crossrider
Clé Supprimée : HKCU\Software\d6dadfe73fb812
Clé Supprimée : HKCU\Software\DataMngr
Clé Supprimée : HKCU\Software\DataMngr_Toolbar
Clé Supprimée : HKCU\Software\Delta
Clé Supprimée : HKCU\Software\Giant Savings Extension
Clé Supprimée : HKCU\Software\InstallCore
Clé Supprimée : HKCU\Software\InstalledBrowserExtensions
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\BrowserProtect
Clé Supprimée : HKLM\Software\Babylon
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110211181110}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Clé Supprimée : HKLM\SOFTWARE\Classes\CrossriderApp0021810.BHO
Clé Supprimée : HKLM\SOFTWARE\Classes\CrossriderApp0021810.BHO.1
Clé Supprimée : HKLM\SOFTWARE\Classes\CrossriderApp0021810.Sandbox
Clé Supprimée : HKLM\SOFTWARE\Classes\CrossriderApp0021810.Sandbox.1
Clé Supprimée : HKLM\SOFTWARE\Classes\delta.deltaappCore
Clé Supprimée : HKLM\SOFTWARE\Classes\delta.deltaappCore.1
Clé Supprimée : HKLM\SOFTWARE\Classes\delta.deltadskBnd
Clé Supprimée : HKLM\SOFTWARE\Classes\delta.deltadskBnd.1
Clé Supprimée : HKLM\SOFTWARE\Classes\delta.deltaHlpr
Clé Supprimée : HKLM\SOFTWARE\Classes\delta.deltaHlpr.1
Clé Supprimée : HKLM\SOFTWARE\Classes\escort.escortIEPane
Clé Supprimée : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Clé Supprimée : HKLM\SOFTWARE\Classes\esrv.deltaESrvc
Clé Supprimée : HKLM\SOFTWARE\Classes\esrv.deltaESrvc.1
Clé Supprimée : HKLM\SOFTWARE\Classes\Prod.cap
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Clé Supprimée : HKLM\SOFTWARE\d6dadfe73fb812
Clé Supprimée : HKLM\Software\DataMngr
Clé Supprimée : HKLM\Software\Delta
Clé Supprimée : HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211181110}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110211181110}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{118D6CE9-5F18-42F9-958A-14676A629FDE}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Giant Savings Extension
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110211181110}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Giant Savings Extension
Clé Supprimée : HKLM\SOFTWARE\Software
Clé Supprimée : HKLM\Software\Tarma Installer
Valeur Supprimée : HKCU\Software\Mozilla\Firefox\Extensions [speedanalysis@SpeedAnalysis.com]
Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{82E1477C-B154-48D3-9891-33D83C26BCD3}]
Valeur Supprimée : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [speedanalysis@SpeedAnalysis.com]
Valeur Supprimée : HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist [1]
***** [Navigateurs] *****
-\\ Internet Explorer v8.0.6001.18702
Remplacé : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.delta-search.com/?affID=119649&tt=190313_wo3&babsrc=HP_ss&mntrId=F0460C60765E5980 --> hxxp://www.google.com
Remplacé : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://www.delta-search.com/?affID=119649&tt=190313_wo3&babsrc=NT_ss&mntrId=F0460C60765E5980 --> hxxp://www.google.com
-\\ Mozilla Firefox v19.0.2 (fr)
Fichier : C:\Documents and Settings\Abdesalem Derdar\Application Data\Mozilla\Firefox\Profiles\nzttb45z.default\prefs.js
C:\Documents and Settings\Abdesalem Derdar\Application Data\Mozilla\Firefox\Profiles\nzttb45z.default\user.js ... Supprimé !
Supprimée : user_pref("avg.install.userHPSettings", "hxxp://www.delta-search.com/?affID=119649&tt=190313_wo3&bab[...]
Supprimée : user_pref("avg.install.userSPSettings", "Delta Search");
Supprimée : user_pref("browser.newtab.url", "hxxp://www.delta-search.com/?affID=119649&tt=190313_wo3&babsrc=NT_s[...]
Supprimée : user_pref("browser.search.order.1", "Delta Search");
Supprimée : user_pref("browser.search.selectedEngine", "Delta Search");
Supprimée : user_pref("extensions.crossriderapp21810.21810.InstallationThankYouPage", true);
Supprimée : user_pref("extensions.crossriderapp21810.21810.InstallationTime", 1364939326);
Supprimée : user_pref("extensions.crossriderapp21810.21810.InstallationUserSettings.searchUserConifrmation", fal[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.InstallationUserSettings.setHomepage", false);
Supprimée : user_pref("extensions.crossriderapp21810.21810.InstallationUserSettings.setNewTab", false);
Supprimée : user_pref("extensions.crossriderapp21810.21810.InstallationUserSettings.setSearch", false);
Supprimée : user_pref("extensions.crossriderapp21810.21810.active", true);
Supprimée : user_pref("extensions.crossriderapp21810.21810.addressbar", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.addressbarenhanced", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.backgroundjs", "\n\n//\n");
Supprimée : user_pref("extensions.crossriderapp21810.21810.backgroundver", 34);
Supprimée : user_pref("extensions.crossriderapp21810.21810.can_run_bg_code", true);
Supprimée : user_pref("extensions.crossriderapp21810.21810.certdomaininstaller", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.changeprevious", false);
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie.InstallationTime.expiration", "Fri Feb 01 2030[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie.InstallationTime.value", "1364939326");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie.InstallerParams.expiration", "Fri Feb 01 2030 [...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:0[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_aoi.value", "1364939326");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_arbitrary_code.expiration", "Fri Apr 05 2[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_arbitrary_code.value", "%22/**/%22");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_blocklist.expiration", "Fri Apr 05 2013 1[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_blocklist.value", "%22nonexistantdomain.c[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_country_code.expiration", "Tue Apr 09 201[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_country_code.value", "%22FR%22");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:0[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_crr.value", "1365154044");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_currenttime.expiration", "Fri Feb 01 2030[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_currenttime.value", "%221364833081%22");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 0[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_hotfix20111102645.value", "%221%22");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installer_params.expiration", "Fri Feb 01[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installer_params.value", "%7B%22source_id[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installtime.expiration", "Fri Feb 01 2030[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installtime.value", "%221364833271%22");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 20[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_parent_zoneid.value", "%2258429%22");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_pc_20120828.expiration", "Fri Feb 01 2030[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_pc_20120828.value", "1364939643853");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_product_id.expiration", "Fri Feb 01 2030 [...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_product_id.value", "%221242%22");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:0[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_zoneid.value", "%22166492%22");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie.dbtest.expiration", "Fri Feb 01 2030 00:00:00 [...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie.dbtest.value", "1364939621590");
Supprimée : user_pref("extensions.crossriderapp21810.21810.description", "Save big with Giant Savings! Coupons d[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.domain", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.enablesearch", false);
Supprimée : user_pref("extensions.crossriderapp21810.21810.fbremoteurl", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.group", 0);
Supprimée : user_pref("extensions.crossriderapp21810.21810.homepage", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.iframe", false);
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.InstallerIdentifiers.expiration", "Fri Feb[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.InstallerIdentifiers.value", "%7B%22instal[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_appVer.expiration", "Fri Feb 01 [...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_appVer.value", "51");
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_lastVersion.expiration", "Fri Fe[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_lastVersion.value", "1");
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_meta.expiration", "Fri Feb 01 20[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_meta.value", "%7B%7D");
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_nextCheck.expiration", "Fri Apr [...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_nextCheck.value", "true");
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_queue.expiration", "Fri Feb 01 2[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_queue.value", "%7B%7D");
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.SoftwareDetected.expiration", "Fri Feb 01 [...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.SoftwareDetected.value", "%7B%22AnySoftwar[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.manifesturl", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.name", "Giant Savings Extension");
Supprimée : user_pref("extensions.crossriderapp21810.21810.newtab", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.opensearch", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1.code", "appAPI._cr_config={appID:fun[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1.name", "base");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1.ver", 4);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.code", "Array.prototype.indexO[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.name", "GPL Plugin (Loader)");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.ver", 15);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000015.code", "var a=appAPI.db.getLis[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000015.name", "GPL Background (BG)");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000015.ver", 35);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_13.code", "(function(a){a.selectedText[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_13.name", "CrossriderAppUtils");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_13.ver", 2);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_14.code", "if(typeof(appAPI)===\"undef[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_14.name", "CrossriderUtils");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_14.ver", 2);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.code", "if((typeof isBackground===\[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.name", "FFAppAPIWrapper");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.ver", 5);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_17.code", "if(typeof window!==\"undefi[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_17.name", "jQuery");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_17.ver", 3);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.code", "var CrossriderDebugManager=[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.name", "debug");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.ver", 3);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_22.code", "(function(a){appAPI.queueMa[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_22.name", "resources");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_22.ver", 3);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.code", "var CrossriderInitializerPl[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.name", "initializer");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.ver", 2);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.code", "var jQuery = $jquery_171 = $[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.name", "jquery_1_7_1");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.ver", 3);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_47.code", "(function(){appAPI.ready=fu[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_47.name", "resources_background");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_47.ver", 2);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.code", "(function(){var h=\"__CR_EM[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.name", "appApiMessage");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.ver", 1);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_72.code", "if(appAPI.__should_activate[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_72.name", "appApiValidation");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_72.ver", 2);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.code", "if(typeof jQuery!==\"undefi[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.name", "CrossriderInfo");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.ver", 2);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.code", "(function(){var b=\"cr_\"+a[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.name", "omniCommands");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.ver", 1);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_0", "4,14,78,16,64,47,72,98,100[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_1", "17,14,78,13,16,64,4,1,21,2[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_5", "4,14,78,13,16,64,47,72");
Supprimée : user_pref("extensions.crossriderapp21810.21810.pluginsurl", "hxxp://app-static.crossrider.com/plugin[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.pluginsversion", 45);
Supprimée : user_pref("extensions.crossriderapp21810.21810.publisher", "215 Apps");
Supprimée : user_pref("extensions.crossriderapp21810.21810.searchstatus", 0);
Supprimée : user_pref("extensions.crossriderapp21810.21810.setnewtab", false);
Supprimée : user_pref("extensions.crossriderapp21810.21810.settingsurl", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.thankyou", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.updateinterval", 360);
Supprimée : user_pref("extensions.crossriderapp21810.21810.ver", 51);
Supprimée : user_pref("extensions.crossriderapp21810.adsOldValue", -1);
Supprimée : user_pref("extensions.crossriderapp21810.apps", "21810");
Supprimée : user_pref("extensions.crossriderapp21810.bic", "13dccbd753e35036ff94952a924646a5");
Supprimée : user_pref("extensions.crossriderapp21810.cid", 21810);
Supprimée : user_pref("extensions.crossriderapp21810.firstrun", false);
Supprimée : user_pref("extensions.crossriderapp21810.hadappinstalled", true);
Supprimée : user_pref("extensions.crossriderapp21810.installationdate", 1364939601);
Supprimée : user_pref("extensions.crossriderapp21810.lastcheck", 22752568);
Supprimée : user_pref("extensions.crossriderapp21810.lastcheckitem", 22752568);
Supprimée : user_pref("extensions.crossriderapp21810.modetype", "production");
Supprimée : user_pref("extensions.crossriderapp21810.reportInstall", true);
Supprimée : user_pref("extensions.delta.admin", false);
Supprimée : user_pref("extensions.delta.aflt", "babsst");
Supprimée : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Supprimée : user_pref("extensions.delta.autoRvrt", "false");
Supprimée : user_pref("extensions.delta.dfltLng", "en");
Supprimée : user_pref("extensions.delta.excTlbr", false);
Supprimée : user_pref("extensions.delta.id", "f046c3dc0000000000000c60765e5980");
Supprimée : user_pref("extensions.delta.instlDay", "15797");
Supprimée : user_pref("extensions.delta.instlRef", "sst");
Supprimée : user_pref("extensions.delta.newTab", false);
Supprimée : user_pref("extensions.delta.prdct", "delta");
Supprimée : user_pref("extensions.delta.prtnrId", "delta");
Supprimée : user_pref("extensions.delta.rvrt", "false");
Supprimée : user_pref("extensions.delta.smplGrp", "none");
Supprimée : user_pref("extensions.delta.tlbrId", "base");
Supprimée : user_pref("extensions.delta.tlbrSrchUrl", "");
Supprimée : user_pref("extensions.delta.vrsn", "1.8.10.0");
Supprimée : user_pref("extensions.delta.vrsnTs", "1.8.10.021:29:02");
Supprimée : user_pref("extensions.delta.vrsni", "1.8.10.0");
*************************
AdwCleaner[R1].txt - [1186 octets] - [20/03/2013 16:21:07]
AdwCleaner[R2].txt - [1235 octets] - [22/03/2013 23:35:40]
AdwCleaner[R3].txt - [7667 octets] - [27/03/2013 02:36:38]
AdwCleaner[S1].txt - [1353 octets] - [18/03/2013 10:49:07]
AdwCleaner[S2].txt - [427 octets] - [20/03/2013 16:20:41]
AdwCleaner[S3].txt - [1257 octets] - [20/03/2013 16:21:38]
AdwCleaner[S4].txt - [1298 octets] - [22/03/2013 23:36:16]
AdwCleaner[S5].txt - [7821 octets] - [27/03/2013 02:37:21]
AdwCleaner[S6].txt - [24916 octets] - [05/04/2013 11:34:53]
########## EOF - C:\AdwCleaner[S6].txt - [24977 octets] ##########
# AdwCleaner v2.200 - Rapport créé le 05/04/2013 à 11:34:53
# Mis à jour le 02/04/2013 par Xplode
# Système d'exploitation : Microsoft Windows XP Service Pack 3 (32 bits)
# Nom d'utilisateur : Abdesalem Derdar - YOUR-10A2E35C12
# Mode de démarrage : Normal
# Exécuté depuis : C:\Documents and Settings\Abdesalem Derdar\Mes documents\Téléchargements\adwcleaner(4).exe
# Option [Suppression]
***** [Services] *****
***** [Fichiers / Dossiers] *****
Dossier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Application Data\BabSolution
Dossier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Application Data\Babylon
Dossier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Application Data\file scout
Dossier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Application Data\Mozilla\Firefox\Profiles\nzttb45z.default\extensions\ffxtlbr@delta.com
Dossier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Application Data\PerformerSoft
Dossier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Application Data\SpeedanAlysis
Dossier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Giant Savings Extension
Dossier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\halffneccaebicfdfajnbfgpglahfgoe
Dossier Supprimé : C:\Documents and Settings\All Users\Application Data\Babylon
Dossier Supprimé : C:\Documents and Settings\All Users\Application Data\Tarma Installer
Dossier Supprimé : C:\Program Files\Delta
Dossier Supprimé : C:\Program Files\Giant Savings Extension
Fichier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Application Data\Mozilla\Firefox\Profiles\nzttb45z.default\searchplugins\BrowserProtect.xml
Fichier Supprimé : C:\Documents and Settings\Abdesalem Derdar\Application Data\Mozilla\Firefox\Profiles\nzttb45z.default\searchplugins\delta.xml
Fichier Supprimé : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
***** [Registre] *****
Clé Supprimée : HKCU\Software\Cr_Installer
Clé Supprimée : HKCU\Software\Crossrider
Clé Supprimée : HKCU\Software\d6dadfe73fb812
Clé Supprimée : HKCU\Software\DataMngr
Clé Supprimée : HKCU\Software\DataMngr_Toolbar
Clé Supprimée : HKCU\Software\Delta
Clé Supprimée : HKCU\Software\Giant Savings Extension
Clé Supprimée : HKCU\Software\InstallCore
Clé Supprimée : HKCU\Software\InstalledBrowserExtensions
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\BrowserProtect
Clé Supprimée : HKLM\Software\Babylon
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110211181110}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Clé Supprimée : HKLM\SOFTWARE\Classes\CrossriderApp0021810.BHO
Clé Supprimée : HKLM\SOFTWARE\Classes\CrossriderApp0021810.BHO.1
Clé Supprimée : HKLM\SOFTWARE\Classes\CrossriderApp0021810.Sandbox
Clé Supprimée : HKLM\SOFTWARE\Classes\CrossriderApp0021810.Sandbox.1
Clé Supprimée : HKLM\SOFTWARE\Classes\delta.deltaappCore
Clé Supprimée : HKLM\SOFTWARE\Classes\delta.deltaappCore.1
Clé Supprimée : HKLM\SOFTWARE\Classes\delta.deltadskBnd
Clé Supprimée : HKLM\SOFTWARE\Classes\delta.deltadskBnd.1
Clé Supprimée : HKLM\SOFTWARE\Classes\delta.deltaHlpr
Clé Supprimée : HKLM\SOFTWARE\Classes\delta.deltaHlpr.1
Clé Supprimée : HKLM\SOFTWARE\Classes\escort.escortIEPane
Clé Supprimée : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Clé Supprimée : HKLM\SOFTWARE\Classes\esrv.deltaESrvc
Clé Supprimée : HKLM\SOFTWARE\Classes\esrv.deltaESrvc.1
Clé Supprimée : HKLM\SOFTWARE\Classes\Prod.cap
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Clé Supprimée : HKLM\SOFTWARE\d6dadfe73fb812
Clé Supprimée : HKLM\Software\DataMngr
Clé Supprimée : HKLM\Software\Delta
Clé Supprimée : HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211181110}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110211181110}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{118D6CE9-5F18-42F9-958A-14676A629FDE}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Giant Savings Extension
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110211181110}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Giant Savings Extension
Clé Supprimée : HKLM\SOFTWARE\Software
Clé Supprimée : HKLM\Software\Tarma Installer
Valeur Supprimée : HKCU\Software\Mozilla\Firefox\Extensions [speedanalysis@SpeedAnalysis.com]
Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{82E1477C-B154-48D3-9891-33D83C26BCD3}]
Valeur Supprimée : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [speedanalysis@SpeedAnalysis.com]
Valeur Supprimée : HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist [1]
***** [Navigateurs] *****
-\\ Internet Explorer v8.0.6001.18702
Remplacé : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.delta-search.com/?affID=119649&tt=190313_wo3&babsrc=HP_ss&mntrId=F0460C60765E5980 --> hxxp://www.google.com
Remplacé : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://www.delta-search.com/?affID=119649&tt=190313_wo3&babsrc=NT_ss&mntrId=F0460C60765E5980 --> hxxp://www.google.com
-\\ Mozilla Firefox v19.0.2 (fr)
Fichier : C:\Documents and Settings\Abdesalem Derdar\Application Data\Mozilla\Firefox\Profiles\nzttb45z.default\prefs.js
C:\Documents and Settings\Abdesalem Derdar\Application Data\Mozilla\Firefox\Profiles\nzttb45z.default\user.js ... Supprimé !
Supprimée : user_pref("avg.install.userHPSettings", "hxxp://www.delta-search.com/?affID=119649&tt=190313_wo3&bab[...]
Supprimée : user_pref("avg.install.userSPSettings", "Delta Search");
Supprimée : user_pref("browser.newtab.url", "hxxp://www.delta-search.com/?affID=119649&tt=190313_wo3&babsrc=NT_s[...]
Supprimée : user_pref("browser.search.order.1", "Delta Search");
Supprimée : user_pref("browser.search.selectedEngine", "Delta Search");
Supprimée : user_pref("extensions.crossriderapp21810.21810.InstallationThankYouPage", true);
Supprimée : user_pref("extensions.crossriderapp21810.21810.InstallationTime", 1364939326);
Supprimée : user_pref("extensions.crossriderapp21810.21810.InstallationUserSettings.searchUserConifrmation", fal[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.InstallationUserSettings.setHomepage", false);
Supprimée : user_pref("extensions.crossriderapp21810.21810.InstallationUserSettings.setNewTab", false);
Supprimée : user_pref("extensions.crossriderapp21810.21810.InstallationUserSettings.setSearch", false);
Supprimée : user_pref("extensions.crossriderapp21810.21810.active", true);
Supprimée : user_pref("extensions.crossriderapp21810.21810.addressbar", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.addressbarenhanced", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.backgroundjs", "\n\n//\n");
Supprimée : user_pref("extensions.crossriderapp21810.21810.backgroundver", 34);
Supprimée : user_pref("extensions.crossriderapp21810.21810.can_run_bg_code", true);
Supprimée : user_pref("extensions.crossriderapp21810.21810.certdomaininstaller", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.changeprevious", false);
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie.InstallationTime.expiration", "Fri Feb 01 2030[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie.InstallationTime.value", "1364939326");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie.InstallerParams.expiration", "Fri Feb 01 2030 [...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:0[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_aoi.value", "1364939326");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_arbitrary_code.expiration", "Fri Apr 05 2[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_arbitrary_code.value", "%22/**/%22");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_blocklist.expiration", "Fri Apr 05 2013 1[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_blocklist.value", "%22nonexistantdomain.c[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_country_code.expiration", "Tue Apr 09 201[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_country_code.value", "%22FR%22");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:0[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_crr.value", "1365154044");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_currenttime.expiration", "Fri Feb 01 2030[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_currenttime.value", "%221364833081%22");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 0[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_hotfix20111102645.value", "%221%22");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installer_params.expiration", "Fri Feb 01[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installer_params.value", "%7B%22source_id[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installtime.expiration", "Fri Feb 01 2030[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installtime.value", "%221364833271%22");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 20[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_parent_zoneid.value", "%2258429%22");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_pc_20120828.expiration", "Fri Feb 01 2030[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_pc_20120828.value", "1364939643853");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_product_id.expiration", "Fri Feb 01 2030 [...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_product_id.value", "%221242%22");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:0[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie._GPL_zoneid.value", "%22166492%22");
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie.dbtest.expiration", "Fri Feb 01 2030 00:00:00 [...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.cookie.dbtest.value", "1364939621590");
Supprimée : user_pref("extensions.crossriderapp21810.21810.description", "Save big with Giant Savings! Coupons d[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.domain", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.enablesearch", false);
Supprimée : user_pref("extensions.crossriderapp21810.21810.fbremoteurl", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.group", 0);
Supprimée : user_pref("extensions.crossriderapp21810.21810.homepage", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.iframe", false);
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.InstallerIdentifiers.expiration", "Fri Feb[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.InstallerIdentifiers.value", "%7B%22instal[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_appVer.expiration", "Fri Feb 01 [...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_appVer.value", "51");
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_lastVersion.expiration", "Fri Fe[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_lastVersion.value", "1");
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_meta.expiration", "Fri Feb 01 20[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_meta.value", "%7B%7D");
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_nextCheck.expiration", "Fri Apr [...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_nextCheck.value", "true");
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_queue.expiration", "Fri Feb 01 2[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_queue.value", "%7B%7D");
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.SoftwareDetected.expiration", "Fri Feb 01 [...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.internaldb.SoftwareDetected.value", "%7B%22AnySoftwar[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.manifesturl", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.name", "Giant Savings Extension");
Supprimée : user_pref("extensions.crossriderapp21810.21810.newtab", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.opensearch", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1.code", "appAPI._cr_config={appID:fun[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1.name", "base");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1.ver", 4);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.code", "Array.prototype.indexO[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.name", "GPL Plugin (Loader)");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.ver", 15);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000015.code", "var a=appAPI.db.getLis[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000015.name", "GPL Background (BG)");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000015.ver", 35);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_13.code", "(function(a){a.selectedText[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_13.name", "CrossriderAppUtils");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_13.ver", 2);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_14.code", "if(typeof(appAPI)===\"undef[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_14.name", "CrossriderUtils");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_14.ver", 2);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.code", "if((typeof isBackground===\[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.name", "FFAppAPIWrapper");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.ver", 5);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_17.code", "if(typeof window!==\"undefi[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_17.name", "jQuery");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_17.ver", 3);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.code", "var CrossriderDebugManager=[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.name", "debug");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.ver", 3);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_22.code", "(function(a){appAPI.queueMa[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_22.name", "resources");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_22.ver", 3);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.code", "var CrossriderInitializerPl[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.name", "initializer");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.ver", 2);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.code", "var jQuery = $jquery_171 = $[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.name", "jquery_1_7_1");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.ver", 3);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_47.code", "(function(){appAPI.ready=fu[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_47.name", "resources_background");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_47.ver", 2);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.code", "(function(){var h=\"__CR_EM[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.name", "appApiMessage");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.ver", 1);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_72.code", "if(appAPI.__should_activate[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_72.name", "appApiValidation");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_72.ver", 2);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.code", "if(typeof jQuery!==\"undefi[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.name", "CrossriderInfo");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.ver", 2);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.code", "(function(){var b=\"cr_\"+a[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.name", "omniCommands");
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.ver", 1);
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_0", "4,14,78,16,64,47,72,98,100[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_1", "17,14,78,13,16,64,4,1,21,2[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_5", "4,14,78,13,16,64,47,72");
Supprimée : user_pref("extensions.crossriderapp21810.21810.pluginsurl", "hxxp://app-static.crossrider.com/plugin[...]
Supprimée : user_pref("extensions.crossriderapp21810.21810.pluginsversion", 45);
Supprimée : user_pref("extensions.crossriderapp21810.21810.publisher", "215 Apps");
Supprimée : user_pref("extensions.crossriderapp21810.21810.searchstatus", 0);
Supprimée : user_pref("extensions.crossriderapp21810.21810.setnewtab", false);
Supprimée : user_pref("extensions.crossriderapp21810.21810.settingsurl", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.thankyou", "");
Supprimée : user_pref("extensions.crossriderapp21810.21810.updateinterval", 360);
Supprimée : user_pref("extensions.crossriderapp21810.21810.ver", 51);
Supprimée : user_pref("extensions.crossriderapp21810.adsOldValue", -1);
Supprimée : user_pref("extensions.crossriderapp21810.apps", "21810");
Supprimée : user_pref("extensions.crossriderapp21810.bic", "13dccbd753e35036ff94952a924646a5");
Supprimée : user_pref("extensions.crossriderapp21810.cid", 21810);
Supprimée : user_pref("extensions.crossriderapp21810.firstrun", false);
Supprimée : user_pref("extensions.crossriderapp21810.hadappinstalled", true);
Supprimée : user_pref("extensions.crossriderapp21810.installationdate", 1364939601);
Supprimée : user_pref("extensions.crossriderapp21810.lastcheck", 22752568);
Supprimée : user_pref("extensions.crossriderapp21810.lastcheckitem", 22752568);
Supprimée : user_pref("extensions.crossriderapp21810.modetype", "production");
Supprimée : user_pref("extensions.crossriderapp21810.reportInstall", true);
Supprimée : user_pref("extensions.delta.admin", false);
Supprimée : user_pref("extensions.delta.aflt", "babsst");
Supprimée : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Supprimée : user_pref("extensions.delta.autoRvrt", "false");
Supprimée : user_pref("extensions.delta.dfltLng", "en");
Supprimée : user_pref("extensions.delta.excTlbr", false);
Supprimée : user_pref("extensions.delta.id", "f046c3dc0000000000000c60765e5980");
Supprimée : user_pref("extensions.delta.instlDay", "15797");
Supprimée : user_pref("extensions.delta.instlRef", "sst");
Supprimée : user_pref("extensions.delta.newTab", false);
Supprimée : user_pref("extensions.delta.prdct", "delta");
Supprimée : user_pref("extensions.delta.prtnrId", "delta");
Supprimée : user_pref("extensions.delta.rvrt", "false");
Supprimée : user_pref("extensions.delta.smplGrp", "none");
Supprimée : user_pref("extensions.delta.tlbrId", "base");
Supprimée : user_pref("extensions.delta.tlbrSrchUrl", "");
Supprimée : user_pref("extensions.delta.vrsn", "1.8.10.0");
Supprimée : user_pref("extensions.delta.vrsnTs", "1.8.10.021:29:02");
Supprimée : user_pref("extensions.delta.vrsni", "1.8.10.0");
*************************
AdwCleaner[R1].txt - [1186 octets] - [20/03/2013 16:21:07]
AdwCleaner[R2].txt - [1235 octets] - [22/03/2013 23:35:40]
AdwCleaner[R3].txt - [7667 octets] - [27/03/2013 02:36:38]
AdwCleaner[S1].txt - [1353 octets] - [18/03/2013 10:49:07]
AdwCleaner[S2].txt - [427 octets] - [20/03/2013 16:20:41]
AdwCleaner[S3].txt - [1257 octets] - [20/03/2013 16:21:38]
AdwCleaner[S4].txt - [1298 octets] - [22/03/2013 23:36:16]
AdwCleaner[S5].txt - [7821 octets] - [27/03/2013 02:37:21]
AdwCleaner[S6].txt - [24916 octets] - [05/04/2013 11:34:53]
########## EOF - C:\AdwCleaner[S6].txt - [24977 octets] ##########
désolé mais c'est court ça coupe a chaque ouverture de navigation
tu fais cela !!
tu fais zhpfix comme expliqué , tu prends le temps de lire la procédure avant de lancer , merci
. Copie les lignes suivantes en GRAS
SysRestore
[MD5.D735BA7D6ED4D47E75DE0EB0F8253F20] - (.FileProperties_CompanyName - FileProperties_FileDescription.) -- C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Updater21810\Updater21810.exe [206336] [PID.2888]
M2 - MFEP: prefs.js [Abdesalem Derdar - nzttb45z.default\extension21810@extension21810.com] [] Giant Savings Extension v (.215 Apps.)
O4 - HKCU\..\Run: [Updater21810.exe] . (.FileProperties_CompanyName - FileProperties_FileDescription.) -- C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Updater21810\Updater21810.exe
O4 - HKUS\S-1-5-21-3659336295-3222183615-1794127435-1005\..\Run: [Updater21810.exe] . (.FileProperties_CompanyName - FileProperties_FileDescription.) -- C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Updater21810\Updater21810.exe
O42 - Logiciel: NetAssistant - (.Freeze.com.) [HKLM] -- {1266764D-FC4F-4FA7-B63B-884D53B1680F}
O42 - Logiciel: NetAssistant for Firefox - (.Freeze.com.) [HKCU] -- NetAssistant 3.6.5
O43 - CFD: 02/04/2013 - 23:59:40 - [0] ----D C:\Program Files\Software
O43 - CFD: 02/04/2013 - 23:48:40 - [0] ----D C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Software
O43 - CFD: 02/04/2013 - 23:51:42 - [0,197] ----D C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Updater21810
O61 - LFC: 02/04/2013 - 22:51:42 ---A- C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Google\Chrome\User Data\Default\databases\chrome-extension_halffneccaebicfdfajnbfgpglahfgoe_0\3 [7168]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossrider.bic", "13dccbd753e35036ff94952a924646a5");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.InstallationTime", 1365154782);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.active", true);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.addressbar", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.addressbarenhanced", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.backgroundjs", "\n\n//\n");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.backgroundver", 34);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.can_run_bg_code", true);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.certdomaininstaller", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.changeprevious", false);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie.InstallationTime.value", "1365154782");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_aoi.value", "1365154782");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_arbitrary_code.expiration", "Fri Apr 05 2013 11:49:39 GMT+0200");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_arbitrary_code.value", "%22/**/%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_blocklist.expiration", "Fri Apr 05 2013 11:49:39 GMT+0200");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_blocklist.value", "%22nonexistantdomain.com%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_country_code.expiration", "Fri Apr 12 2013 11:40:07 GMT+0200");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_country_code.value", "%22FR%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_crr.value", "1365155080");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_currenttime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_currenttime.value", "%221364833081%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_hotfix20111102645.value", "%221%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installer_params.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installer_params.value", "%7B%22source_id%22%3A%2258429%22%2C%22sub_id%[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installtime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installtime.value", "%221364833081%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_parent_zoneid.value", "%2258429%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_pc_20120828.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_pc_20120828.value", "1365155087843");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_product_id.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_product_id.value", "%221242%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_zoneid.value", "%22167904%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie.dbtest.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie.dbtest.value", "1365154806965");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.description", "Save big with Giant Savings! Coupons display instantly while you're [...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.domain", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.enablesearch", false);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.fbremoteurl", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.group", 0);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.homepage", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.iframe", false);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_appVer.value", "51");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_lastVersion.value", "1");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_meta.value", "%7B%7D");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_nextCheck.expiration", "Fri Apr 05 2013 17:39:44 GMT+0200");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_nextCheck.value", "true");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_queue.value", "%7B%7D");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _GPL_=function(){_GPL_PLUGIN.st[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.manifesturl", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.name", "Giant Savings Extension");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.newtab", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.opensearch", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;i[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1.ver", 4);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.code", "Array.prototype.indexOf||(Array.prototype.indexOf=fu[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.name", "GPL Plugin (Loader)");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.ver", 15);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000015.code", "var a=appAPI.db.getList(),cf_ran=!1,_GPL_BG={vars:{}[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000015.ver", 35);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_13.code", "(function(a){a.selectedText=function(e,c){function d(){if[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_13.ver", 2);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefined\"){appAPI={};}var CR__bIs[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_14.ver", 2);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.code", "if((typeof isBackground===\"undefined\"||isBackground!==t[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.name", "FFAppAPIWrapper");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.ver", 5);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_17.code", "if(typeof window!==\"undefined\"){\n/*!\n * jQuery JavaSc[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_17.ver", 3);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.code", "var CrossriderDebugManager=(function(h){var f={appId:appA[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.name", "debug");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.ver", 3);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:funct[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_22.ver", 3);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.code", "var CrossriderInitializerPlugin=(function(e){var c={appId[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.name", "initializer");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.ver", 2);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.code", "var jQuery = $jquery_171 = $jquery = null;\n\nif (document[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.name", "jquery_1_7_1");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.ver", 3);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_47.code", "(function(){appAPI.ready=function(a){appAPI.resources.isR[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_47.ver", 2);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.code", "(function(){var h=\"__CR_EMPTY_CHANNEL__\";var d=function[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.name", "appApiMessage");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.ver", 1);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_72.code", "if(appAPI.__should_activate_validation__===true){(functio[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_72.ver", 2);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.code", "if(typeof jQuery!==\"undefined\"&&(jQuery)&&typeof naviga[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.name", "CrossriderInfo");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.ver", 2);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.code", "(function(){var b=\"cr_\"+appAPI.appID+\"internalMessage\[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.name", "omniCommands");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.ver", 1);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_0", "4,14,78,16,64,47,72,98,1000015");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_1", "17,14,78,13,16,64,4,1,21,22,72,98,1000014,28");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_5", "4,14,78,13,16,64,47,72");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.pluginsurl", "http://app-static.crossrider.com/plugin/apps/21810/plugins/087/ff/plu[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.pluginsversion", 45);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.publisher", "215 Apps");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.searchstatus", 0);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.setnewtab", false);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.settingsurl", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.thankyou", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.updateinterval", 360);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.ver", 51);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.apps", "21810");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.bic", "13dccbd753e35036ff94952a924646a5");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.cid", 21810);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.firstrun", false);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.hadappinstalled", true);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.installationdate", 1365154780);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.lastcheck", 22752580);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.lastcheckitem", 22752585);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.modetype", "production");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.reportInstall", true);
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\PriceGong]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E5C8B5FB7CB5DD447A0BAAAF637FBD77]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF96568971BEAC14B8815883832BD484]
[HKLM\Software\Classes\Installer\Features\9EC6D81181F59F2459A84176A626F9ED]
[HKLM\Software\Classes\Installer\Products\9EC6D81181F59F2459A84176A626F9ED]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9EC6D81181F59F2459A84176A626F9ED]
[HKLM\Software\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]:Updater21810.exe
C:\Program Files\Software
C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Software
C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Updater21810
C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\\Updater21810
C:\Documents and Settings\Abdesalem Derdar\Application Data\Mozilla\Firefox\Profiles\nzttb45z.default\Extensions\extension21810@extension21810.com
O90 - PUC: "9EC6D81181F59F2459A84176A626F9ED" . (.Iminent.) -- C:\WINDOWS\Installer\{118D6CE9-5F18-42F9-958A-14676A629FDE}\imbooster.ico
FirewallRAZ
EmptyCLSID
EmptyTemp
EmptyFlash
. Lance ZHPFix de Nicolas Coolman qui se trouve sur ton bureau
. double-clique sur ZHPFix accepte l'élévation des droits avec ok
Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .
si c'est pas le cas: Clique sur gauche sur l'icone du millieu (« coller le presse papier »)
Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.
!! Déconnecte toi, désactive tes défenses (anti-virus, anti-spyware ) et ferme bien toutes autres applications ( navigateurs compris ) !!
. cliques sur GO confirmes le nettoyage !!
. Copie/colle la totalité du rapport dans ta prochaine réponse
tu le trouveras dans le dossier de zhpdiag dans program files sous le nom de ZHPFixReport
tuto si besoin merci saachaa !!
tu fais zhpfix comme expliqué , tu prends le temps de lire la procédure avant de lancer , merci
. Copie les lignes suivantes en GRAS
SysRestore
[MD5.D735BA7D6ED4D47E75DE0EB0F8253F20] - (.FileProperties_CompanyName - FileProperties_FileDescription.) -- C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Updater21810\Updater21810.exe [206336] [PID.2888]
M2 - MFEP: prefs.js [Abdesalem Derdar - nzttb45z.default\extension21810@extension21810.com] [] Giant Savings Extension v (.215 Apps.)
O4 - HKCU\..\Run: [Updater21810.exe] . (.FileProperties_CompanyName - FileProperties_FileDescription.) -- C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Updater21810\Updater21810.exe
O4 - HKUS\S-1-5-21-3659336295-3222183615-1794127435-1005\..\Run: [Updater21810.exe] . (.FileProperties_CompanyName - FileProperties_FileDescription.) -- C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Updater21810\Updater21810.exe
O42 - Logiciel: NetAssistant - (.Freeze.com.) [HKLM] -- {1266764D-FC4F-4FA7-B63B-884D53B1680F}
O42 - Logiciel: NetAssistant for Firefox - (.Freeze.com.) [HKCU] -- NetAssistant 3.6.5
O43 - CFD: 02/04/2013 - 23:59:40 - [0] ----D C:\Program Files\Software
O43 - CFD: 02/04/2013 - 23:48:40 - [0] ----D C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Software
O43 - CFD: 02/04/2013 - 23:51:42 - [0,197] ----D C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Updater21810
O61 - LFC: 02/04/2013 - 22:51:42 ---A- C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Google\Chrome\User Data\Default\databases\chrome-extension_halffneccaebicfdfajnbfgpglahfgoe_0\3 [7168]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossrider.bic", "13dccbd753e35036ff94952a924646a5");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.InstallationTime", 1365154782);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.active", true);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.addressbar", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.addressbarenhanced", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.backgroundjs", "\n\n//\n");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.backgroundver", 34);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.can_run_bg_code", true);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.certdomaininstaller", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.changeprevious", false);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie.InstallationTime.value", "1365154782");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_aoi.value", "1365154782");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_arbitrary_code.expiration", "Fri Apr 05 2013 11:49:39 GMT+0200");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_arbitrary_code.value", "%22/**/%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_blocklist.expiration", "Fri Apr 05 2013 11:49:39 GMT+0200");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_blocklist.value", "%22nonexistantdomain.com%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_country_code.expiration", "Fri Apr 12 2013 11:40:07 GMT+0200");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_country_code.value", "%22FR%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_crr.value", "1365155080");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_currenttime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_currenttime.value", "%221364833081%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_hotfix20111102645.value", "%221%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installer_params.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installer_params.value", "%7B%22source_id%22%3A%2258429%22%2C%22sub_id%[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installtime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installtime.value", "%221364833081%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_parent_zoneid.value", "%2258429%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_pc_20120828.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_pc_20120828.value", "1365155087843");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_product_id.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_product_id.value", "%221242%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_zoneid.value", "%22167904%22");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie.dbtest.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie.dbtest.value", "1365154806965");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.description", "Save big with Giant Savings! Coupons display instantly while you're [...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.domain", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.enablesearch", false);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.fbremoteurl", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.group", 0);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.homepage", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.iframe", false);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_appVer.value", "51");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_lastVersion.value", "1");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_meta.value", "%7B%7D");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_nextCheck.expiration", "Fri Apr 05 2013 17:39:44 GMT+0200");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_nextCheck.value", "true");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_queue.value", "%7B%7D");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _GPL_=function(){_GPL_PLUGIN.st[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.manifesturl", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.name", "Giant Savings Extension");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.newtab", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.opensearch", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;i[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1.ver", 4);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.code", "Array.prototype.indexOf||(Array.prototype.indexOf=fu[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.name", "GPL Plugin (Loader)");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.ver", 15);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000015.code", "var a=appAPI.db.getList(),cf_ran=!1,_GPL_BG={vars:{}[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000015.ver", 35);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_13.code", "(function(a){a.selectedText=function(e,c){function d(){if[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_13.ver", 2);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefined\"){appAPI={};}var CR__bIs[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_14.ver", 2);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.code", "if((typeof isBackground===\"undefined\"||isBackground!==t[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.name", "FFAppAPIWrapper");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.ver", 5);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_17.code", "if(typeof window!==\"undefined\"){\n/*!\n * jQuery JavaSc[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_17.ver", 3);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.code", "var CrossriderDebugManager=(function(h){var f={appId:appA[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.name", "debug");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.ver", 3);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:funct[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_22.ver", 3);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.code", "var CrossriderInitializerPlugin=(function(e){var c={appId[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.name", "initializer");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.ver", 2);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.code", "var jQuery = $jquery_171 = $jquery = null;\n\nif (document[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.name", "jquery_1_7_1");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.ver", 3);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_47.code", "(function(){appAPI.ready=function(a){appAPI.resources.isR[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_47.ver", 2);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.code", "(function(){var h=\"__CR_EMPTY_CHANNEL__\";var d=function[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.name", "appApiMessage");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.ver", 1);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_72.code", "if(appAPI.__should_activate_validation__===true){(functio[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_72.ver", 2);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.code", "if(typeof jQuery!==\"undefined\"&&(jQuery)&&typeof naviga[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.name", "CrossriderInfo");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.ver", 2);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.code", "(function(){var b=\"cr_\"+appAPI.appID+\"internalMessage\[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.name", "omniCommands");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.ver", 1);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_0", "4,14,78,16,64,47,72,98,1000015");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_1", "17,14,78,13,16,64,4,1,21,22,72,98,1000014,28");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_5", "4,14,78,13,16,64,47,72");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.pluginsurl", "http://app-static.crossrider.com/plugin/apps/21810/plugins/087/ff/plu[...]
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.pluginsversion", 45);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.publisher", "215 Apps");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.searchstatus", 0);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.setnewtab", false);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.settingsurl", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.thankyou", "");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.updateinterval", 360);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.ver", 51);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.apps", "21810");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.bic", "13dccbd753e35036ff94952a924646a5");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.cid", 21810);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.firstrun", false);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.hadappinstalled", true);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.installationdate", 1365154780);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.lastcheck", 22752580);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.lastcheckitem", 22752585);
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.modetype", "production");
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.reportInstall", true);
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\PriceGong]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E5C8B5FB7CB5DD447A0BAAAF637FBD77]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF96568971BEAC14B8815883832BD484]
[HKLM\Software\Classes\Installer\Features\9EC6D81181F59F2459A84176A626F9ED]
[HKLM\Software\Classes\Installer\Products\9EC6D81181F59F2459A84176A626F9ED]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9EC6D81181F59F2459A84176A626F9ED]
[HKLM\Software\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]:Updater21810.exe
C:\Program Files\Software
C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Software
C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Updater21810
C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\\Updater21810
C:\Documents and Settings\Abdesalem Derdar\Application Data\Mozilla\Firefox\Profiles\nzttb45z.default\Extensions\extension21810@extension21810.com
O90 - PUC: "9EC6D81181F59F2459A84176A626F9ED" . (.Iminent.) -- C:\WINDOWS\Installer\{118D6CE9-5F18-42F9-958A-14676A629FDE}\imbooster.ico
FirewallRAZ
EmptyCLSID
EmptyTemp
EmptyFlash
. Lance ZHPFix de Nicolas Coolman qui se trouve sur ton bureau
. double-clique sur ZHPFix accepte l'élévation des droits avec ok
Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .
si c'est pas le cas: Clique sur gauche sur l'icone du millieu (« coller le presse papier »)
Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.
!! Déconnecte toi, désactive tes défenses (anti-virus, anti-spyware ) et ferme bien toutes autres applications ( navigateurs compris ) !!
. cliques sur GO confirmes le nettoyage !!
. Copie/colle la totalité du rapport dans ta prochaine réponse
tu le trouveras dans le dossier de zhpdiag dans program files sous le nom de ZHPFixReport
tuto si besoin merci saachaa !!
Rapport de ZHPFix 2013.3.9.1 par Nicolas Coolman, Update du 9/03/2013
Fichier d'export Registre :
Run by Abdesalem Derdar at 06/04/2013 05:41:34
High Elevated Privileges : OK
Windows XP Home Edition Service Pack 3 (Build 2600)
Corbeille vidée
========== Logiciel(s) ==========
SUPPRIME NetAssistant
ABSENT Software Key: NetAssistant 3.6.5
========== Processus mémoire ==========
SUPPRIME Memory Process: C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Updater21810\Updater21810.exe
========== Clé(s) du Registre ==========
SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\PriceGong
SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E5C8B5FB7CB5DD447A0BAAAF637FBD77
SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF96568971BEAC14B8815883832BD484
SUPPRIME Key: HKLM\Software\Classes\Installer\Features\9EC6D81181F59F2459A84176A626F9ED
SUPPRIME Key: HKLM\Software\Classes\Installer\Products\9EC6D81181F59F2459A84176A626F9ED
SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9EC6D81181F59F2459A84176A626F9ED
SUPPRIME Key: HKLM\Software\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}
ABSENT Key: \Software\Classes\Installer\Products\\9EC6D81181F59F2459A84176A626F9ED
========== Valeur(s) du Registre ==========
SUPPRIME RunValue: Updater21810.exe
ABSENT RunValue: Updater21810.exe
ABSENT [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]:Updater21810.exe
SUPPRIME FirewallRaz (SP) : C:\Program Files\Windows Live\Messenger\wlcsdk.exe
SUPPRIME FirewallRaz (SP) : C:\Program Files\Windows Live\Messenger\msnmsgr.exe
SUPPRIME FirewallRaz (DP) : C:\Program Files\Windows Live\Messenger\wlcsdk.exe
SUPPRIME FirewallRaz (DP) : C:\Program Files\Windows Live\Messenger\msnmsgr.exe
Aucune valeur présente dans la clé d'exception du registre (FirewallRaz)
========== Préférences navigateur ==========
SUPPRIME Mozilla Pref: user_pref("extensions.crossrider.bic", "13dccbd753e35036ff94952a924646a5");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.InstallationTime", 1365154782);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.active", true);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.addressbar", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.addressbarenhanced", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.backgroundjs", "\n\n//\n");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.backgroundver", 34);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.can_run_bg_code", true);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.certdomaininstaller", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.changeprevious", false);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie.InstallationTime.value", "1365154782");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_aoi.value", "1365154782");
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_arbitrary_code.expiration", "Fri Apr 05 2013 11:49:39 GMT+0200");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_arbitrary_code.value", "%22/**/%22");
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_blocklist.expiration", "Fri Apr 05 2013 11:49:39 GMT+0200");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_blocklist.value", "%22nonexistantdomain.com%22");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_country_code.expiration", "Fri Apr 12 2013 11:40:07 GMT+0200");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_country_code.value", "%22FR%22");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_crr.value", "1365155080");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_currenttime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_currenttime.value", "%221364833081%22");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_hotfix20111102645.value", "%221%22");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installer_params.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installer_params.value", "%7B%22source_id%22%3A%2258429%22%2C%22sub_id%[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installtime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installtime.value", "%221364833081%22");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_parent_zoneid.value", "%2258429%22");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_pc_20120828.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_pc_20120828.value", "1365155087843");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_product_id.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_product_id.value", "%221242%22");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_zoneid.value", "%22167904%22");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie.dbtest.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie.dbtest.value", "1365154806965");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.description", "Save big with Giant Savings! Coupons display instantly while you're [...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.domain", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.enablesearch", false);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.fbremoteurl", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.group", 0);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.homepage", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.iframe", false);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_appVer.value", "51");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_lastVersion.value", "1");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_meta.value", "%7B%7D");
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_nextCheck.expiration", "Fri Apr 05 2013 17:39:44 GMT+0200");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_nextCheck.value", "true");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_queue.value", "%7B%7D");
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _GPL_=function(){_GPL_PLUGIN.st[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.manifesturl", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.name", "Giant Savings Extension");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.newtab", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.opensearch", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;i[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1.ver", 4);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.code", "Array.prototype.indexOf||(Array.prototype.indexOf=fu[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.name", "GPL Plugin (Loader)");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.ver", 15);
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000015.code", "var a=appAPI.db.getList(),cf_ran=!1,_GPL_BG={vars:{}[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000015.ver", 35);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_13.code", "(function(a){a.selectedText=function(e,c){function d(){if[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_13.ver", 2);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefined\"){appAPI={};}var CR__bIs[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_14.ver", 2);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.code", "if((typeof isBackground===\"undefined\"||isBackground!==t[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.name", "FFAppAPIWrapper");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.ver", 5);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_17.code", "if(typeof window!==\"undefined\"){\n/*!\n * jQuery JavaSc[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_17.ver", 3);
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.code", "var CrossriderDebugManager=(function(h){var f={appId:appA[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.name", "debug");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.ver", 3);
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:funct[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_22.ver", 3);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.code", "var CrossriderInitializerPlugin=(function(e){var c={appId[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.name", "initializer");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.ver", 2);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.code", "var jQuery
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.name", "jquery_1_7_1");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.ver", 3);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_47.code", "(function(){appAPI.ready=function(a){appAPI.resources.isR[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_47.ver", 2);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.code", "(function(){var h=\"__CR_EMPTY_CHANNEL__\";var d=function[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.name", "appApiMessage");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.ver", 1);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_72.code", "if(appAPI.__should_activate_validation__===true){(functio[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_72.ver", 2);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.code", "if(typeof jQuery!==\"undefined\"&&(jQuery)&&typeof naviga[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.name", "CrossriderInfo");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.ver", 2);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.code", "(function(){var b=\"cr_\"+appAPI.appID+\"internalMessage\[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.name", "omniCommands");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.ver", 1);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_0", "4,14,78,16,64,47,72,98,1000015");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_1", "17,14,78,13,16,64,4,1,21,22,72,98,1000014,28");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_5", "4,14,78,13,16,64,47,72");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.pluginsurl", "http://app-static.crossrider.com/plugin/apps/21810/plugins/087/ff/plu[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.pluginsversion", 45);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.publisher", "215 Apps");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.searchstatus", 0);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.setnewtab", false);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.settingsurl", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.thankyou", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.updateinterval", 360);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.ver", 51);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.apps", "21810");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.bic", "13dccbd753e35036ff94952a924646a5");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.cid", 21810);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.firstrun", false);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.hadappinstalled", true);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.installationdate", 1365154780);
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.lastcheck", 22752580);
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.lastcheckitem", 22752585);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.modetype", "production");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.reportInstall", true);
========== Dossier(s) ==========
Aucun dossiers CLSID Local utilisateur vide
SUPPRIME Temporaires Windows
SUPPRIME Flash Cookies
========== Fichier(s) ==========
SUPPRIME File***: c:\documents and settings\abdesalem derdar\local settings\application data\updater21810\updater21810.exe
ABSENT File: c:\documents and settings\abdesalem derdar\local settings\application data\updater21810\updater21810.exe
ABSENT File: c:\documents and settings\abdesalem derdar\local settings\application data\updater21810\updater21810.e
SUPPRIME File: c:\documents and settings\abdesalem derdar\local settings\application data\google\chrome\user data\default\databases\chrome-extension_halffneccaebicfdfajnbfgpglahfgoe_0\3
ABSENT Folder/File: c:\program files\software
ABSENT Folder/File: c:\documents and settings\abdesalem derdar\local settings\application data\software
ABSENT Folder/File: c:\documents and settings\abdesalem derdar\local settings\application data\updater21810
ABSENT Folder/File: c:\documents and settings\abdesalem derdar\local settings\application data\\updater21810
ABSENT Folder/File: c:\documents and settings\abdesalem derdar\application data\mozilla\firefox\profiles\nzttb45z.default\extensions\extension21810@extension21810.com
SUPPRIME Temporaires Windows
SUPPRIME Flash Cookies
========== Restauration Système ==========
Point de restauration du système créé avec succès
========== Récapitulatif ==========
1 : Processus mémoire
8 : Clé(s) du Registre
8 : Valeur(s) du Registre
3 : Dossier(s)
11 : Fichier(s)
2 : Logiciel(s)
124 : Préférences navigateur
1 : Restauration Système
End of clean in 02mn 02s
========== Chemin de fichier rapport ==========
C:\ZHP\ZHPFix[R1].txt - 06/04/2013 05:41:34 [18466]
Fichier d'export Registre :
Run by Abdesalem Derdar at 06/04/2013 05:41:34
High Elevated Privileges : OK
Windows XP Home Edition Service Pack 3 (Build 2600)
Corbeille vidée
========== Logiciel(s) ==========
SUPPRIME NetAssistant
ABSENT Software Key: NetAssistant 3.6.5
========== Processus mémoire ==========
SUPPRIME Memory Process: C:\Documents and Settings\Abdesalem Derdar\Local Settings\Application Data\Updater21810\Updater21810.exe
========== Clé(s) du Registre ==========
SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\PriceGong
SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E5C8B5FB7CB5DD447A0BAAAF637FBD77
SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF96568971BEAC14B8815883832BD484
SUPPRIME Key: HKLM\Software\Classes\Installer\Features\9EC6D81181F59F2459A84176A626F9ED
SUPPRIME Key: HKLM\Software\Classes\Installer\Products\9EC6D81181F59F2459A84176A626F9ED
SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9EC6D81181F59F2459A84176A626F9ED
SUPPRIME Key: HKLM\Software\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}
ABSENT Key: \Software\Classes\Installer\Products\\9EC6D81181F59F2459A84176A626F9ED
========== Valeur(s) du Registre ==========
SUPPRIME RunValue: Updater21810.exe
ABSENT RunValue: Updater21810.exe
ABSENT [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]:Updater21810.exe
SUPPRIME FirewallRaz (SP) : C:\Program Files\Windows Live\Messenger\wlcsdk.exe
SUPPRIME FirewallRaz (SP) : C:\Program Files\Windows Live\Messenger\msnmsgr.exe
SUPPRIME FirewallRaz (DP) : C:\Program Files\Windows Live\Messenger\wlcsdk.exe
SUPPRIME FirewallRaz (DP) : C:\Program Files\Windows Live\Messenger\msnmsgr.exe
Aucune valeur présente dans la clé d'exception du registre (FirewallRaz)
========== Préférences navigateur ==========
SUPPRIME Mozilla Pref: user_pref("extensions.crossrider.bic", "13dccbd753e35036ff94952a924646a5");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.InstallationTime", 1365154782);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.active", true);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.addressbar", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.addressbarenhanced", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.backgroundjs", "\n\n//\n");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.backgroundver", 34);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.can_run_bg_code", true);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.certdomaininstaller", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.changeprevious", false);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie.InstallationTime.value", "1365154782");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_aoi.value", "1365154782");
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_arbitrary_code.expiration", "Fri Apr 05 2013 11:49:39 GMT+0200");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_arbitrary_code.value", "%22/**/%22");
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_blocklist.expiration", "Fri Apr 05 2013 11:49:39 GMT+0200");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_blocklist.value", "%22nonexistantdomain.com%22");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_country_code.expiration", "Fri Apr 12 2013 11:40:07 GMT+0200");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_country_code.value", "%22FR%22");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_crr.value", "1365155080");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_currenttime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_currenttime.value", "%221364833081%22");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_hotfix20111102645.value", "%221%22");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installer_params.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installer_params.value", "%7B%22source_id%22%3A%2258429%22%2C%22sub_id%[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installtime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_installtime.value", "%221364833081%22");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_parent_zoneid.value", "%2258429%22");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_pc_20120828.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_pc_20120828.value", "1365155087843");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_product_id.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_product_id.value", "%221242%22");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_zoneid.value", "%22167904%22");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie.dbtest.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie.dbtest.value", "1365154806965");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.description", "Save big with Giant Savings! Coupons display instantly while you're [...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.domain", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.enablesearch", false);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.fbremoteurl", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.group", 0);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.homepage", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.iframe", false);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_appVer.value", "51");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_lastVersion.value", "1");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_meta.value", "%7B%7D");
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_nextCheck.expiration", "Fri Apr 05 2013 17:39:44 GMT+0200");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_nextCheck.value", "true");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.internaldb.Resources_queue.value", "%7B%7D");
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _GPL_=function(){_GPL_PLUGIN.st[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.manifesturl", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.name", "Giant Savings Extension");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.newtab", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.opensearch", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;i[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1.ver", 4);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.code", "Array.prototype.indexOf||(Array.prototype.indexOf=fu[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.name", "GPL Plugin (Loader)");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000014.ver", 15);
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000015.code", "var a=appAPI.db.getList(),cf_ran=!1,_GPL_BG={vars:{}[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_1000015.ver", 35);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_13.code", "(function(a){a.selectedText=function(e,c){function d(){if[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_13.ver", 2);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefined\"){appAPI={};}var CR__bIs[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_14.ver", 2);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.code", "if((typeof isBackground===\"undefined\"||isBackground!==t[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.name", "FFAppAPIWrapper");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_16.ver", 5);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_17.code", "if(typeof window!==\"undefined\"){\n/*!\n * jQuery JavaSc[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_17.ver", 3);
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.code", "var CrossriderDebugManager=(function(h){var f={appId:appA[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.name", "debug");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_21.ver", 3);
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:funct[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_22.ver", 3);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.code", "var CrossriderInitializerPlugin=(function(e){var c={appId[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.name", "initializer");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_28.ver", 2);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.code", "var jQuery
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.name", "jquery_1_7_1");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_4.ver", 3);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_47.code", "(function(){appAPI.ready=function(a){appAPI.resources.isR[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_47.ver", 2);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.code", "(function(){var h=\"__CR_EMPTY_CHANNEL__\";var d=function[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.name", "appApiMessage");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_64.ver", 1);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_72.code", "if(appAPI.__should_activate_validation__===true){(functio[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_72.ver", 2);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.code", "if(typeof jQuery!==\"undefined\"&&(jQuery)&&typeof naviga[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.name", "CrossriderInfo");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_78.ver", 2);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.code", "(function(){var b=\"cr_\"+appAPI.appID+\"internalMessage\[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.name", "omniCommands");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins.plugin_98.ver", 1);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_0", "4,14,78,16,64,47,72,98,1000015");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_1", "17,14,78,13,16,64,4,1,21,22,72,98,1000014,28");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.plugins_lists.plugins_5", "4,14,78,13,16,64,47,72");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.pluginsurl", "http://app-static.crossrider.com/plugin/apps/21810/plugins/087/ff/plu[...]
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.pluginsversion", 45);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.publisher", "215 Apps");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.searchstatus", 0);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.setnewtab", false);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.settingsurl", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.thankyou", "");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.updateinterval", 360);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.ver", 51);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.apps", "21810");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.bic", "13dccbd753e35036ff94952a924646a5");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.cid", 21810);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.firstrun", false);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.hadappinstalled", true);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.installationdate", 1365154780);
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.lastcheck", 22752580);
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.lastcheckitem", 22752585);
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.modetype", "production");
SUPPRIME Mozilla Pref: user_pref("extensions.crossriderapp21810.reportInstall", true);
========== Dossier(s) ==========
Aucun dossiers CLSID Local utilisateur vide
SUPPRIME Temporaires Windows
SUPPRIME Flash Cookies
========== Fichier(s) ==========
SUPPRIME File***: c:\documents and settings\abdesalem derdar\local settings\application data\updater21810\updater21810.exe
ABSENT File: c:\documents and settings\abdesalem derdar\local settings\application data\updater21810\updater21810.exe
ABSENT File: c:\documents and settings\abdesalem derdar\local settings\application data\updater21810\updater21810.e
SUPPRIME File: c:\documents and settings\abdesalem derdar\local settings\application data\google\chrome\user data\default\databases\chrome-extension_halffneccaebicfdfajnbfgpglahfgoe_0\3
ABSENT Folder/File: c:\program files\software
ABSENT Folder/File: c:\documents and settings\abdesalem derdar\local settings\application data\software
ABSENT Folder/File: c:\documents and settings\abdesalem derdar\local settings\application data\updater21810
ABSENT Folder/File: c:\documents and settings\abdesalem derdar\local settings\application data\\updater21810
ABSENT Folder/File: c:\documents and settings\abdesalem derdar\application data\mozilla\firefox\profiles\nzttb45z.default\extensions\extension21810@extension21810.com
SUPPRIME Temporaires Windows
SUPPRIME Flash Cookies
========== Restauration Système ==========
Point de restauration du système créé avec succès
========== Récapitulatif ==========
1 : Processus mémoire
8 : Clé(s) du Registre
8 : Valeur(s) du Registre
3 : Dossier(s)
11 : Fichier(s)
2 : Logiciel(s)
124 : Préférences navigateur
1 : Restauration Système
End of clean in 02mn 02s
========== Chemin de fichier rapport ==========
C:\ZHP\ZHPFix[R1].txt - 06/04/2013 05:41:34 [18466]
bonjour, pourrais tu nous poster un nouveau zhpdiag pour contrôle tu coche tous au tournevis !! merci
Double cliques sur le raccourci ZHPDiag sur ton Bureau pour XP sinon clique droit et en tant que administrateur !!
coches tous au tournevis http://sd-4.archive-host.com/membres/up/89820622056365782/zhpdiag_tournevis_.jpg
Cliques sur la loupe pour lancer l'analyse.
si tu as un message te demandant la validation pour SIGCHECK acceptes avec OK cela est pour nous faire un rapport plus complet et pouvoir en faire une lecture plus approfondis
Laisses l'outil travailler, il peut être assez long
A la fin de l'analyse,clique sur l'appareil photo et enregistre le rapport sur ton Bureau.
Fermes ZHPDiag en fin d'analyse.
Pour me le transmettre clique sur ce lien :
https://www.cjoint.com/
Clique sur Parcourir et cherche le fichier C:\Documents and settings\le_nom_de_ta_session\bureau\.ZHPDiag.txt
ou directement en choisissant bureau et ZHPDiag.txt clique dessus
Clique sur Ouvrir.
Clique sur "Cliquez ici pour déposer le fichier".
Un lien de cette forme :
http://cjoint.com/data/0KAoeRbq7Szgg.htm
est ajouté dans la page.
Copie ce lien dans ta réponse.
et si problème passe par celui ci : http://pjjoint.malekal.com/
Double cliques sur le raccourci ZHPDiag sur ton Bureau pour XP sinon clique droit et en tant que administrateur !!
coches tous au tournevis http://sd-4.archive-host.com/membres/up/89820622056365782/zhpdiag_tournevis_.jpg
Cliques sur la loupe pour lancer l'analyse.
si tu as un message te demandant la validation pour SIGCHECK acceptes avec OK cela est pour nous faire un rapport plus complet et pouvoir en faire une lecture plus approfondis
Laisses l'outil travailler, il peut être assez long
A la fin de l'analyse,clique sur l'appareil photo et enregistre le rapport sur ton Bureau.
Fermes ZHPDiag en fin d'analyse.
Pour me le transmettre clique sur ce lien :
https://www.cjoint.com/
Clique sur Parcourir et cherche le fichier C:\Documents and settings\le_nom_de_ta_session\bureau\.ZHPDiag.txt
ou directement en choisissant bureau et ZHPDiag.txt clique dessus
Clique sur Ouvrir.
Clique sur "Cliquez ici pour déposer le fichier".
Un lien de cette forme :
http://cjoint.com/data/0KAoeRbq7Szgg.htm
est ajouté dans la page.
Copie ce lien dans ta réponse.
et si problème passe par celui ci : http://pjjoint.malekal.com/
slt et merci
voici le lien concernant le diag ZHP
https://www.cjoint.com/?CDgxkq6pb6F
pour information je n'ai plus ces blocages récurrents je pense que j'ai du (sans le voir) télécharger des pluggings via un lecteur vidéo player pour voir des matchs en live.
voici le lien concernant le diag ZHP
https://www.cjoint.com/?CDgxkq6pb6F
pour information je n'ai plus ces blocages récurrents je pense que j'ai du (sans le voir) télécharger des pluggings via un lecteur vidéo player pour voir des matchs en live.
ok tu refais un zhpfix car de petit reste et puis tu fais WinChk
1) tu fais zhpfix comme expliqué
tu prends le temps de lire la procédure avant de lancer , merci
. Copie les lignes suivantes en GRAS
SysRestore
M3 - MFPP: Plugins - [Abdesalem Derdar] -- C:\Documents and Settings\Abdesalem Derdar\Application Data\Mozilla\Firefox\Profiles\nzttb45z.default\searchplugins\recherche-alot.xml
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_arbitrary_code.expiration", "Sat Apr 06 2013 05:42:21 GMT+0200");
FirewallRAZ
EmptyCLSID
EmptyTemp
EmptyFlash
. Lance ZHPFix de Nicolas Coolman qui se trouve sur ton bureau
. double-clique sur ZHPFix accepte l'élévation des droits avec ok
Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .
si c'est pas le cas: Clique sur gauche sur l'icone du millieu (« coller le presse papier »)
Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.
!! Déconnecte toi, désactive tes défenses (anti-virus, anti-spyware ) et ferme bien toutes autres applications ( navigateurs compris ) !!
. cliques sur GO confirmes le nettoyage !!
. Copie/colle la totalité du rapport dans ta prochaine réponse
tu le trouveras dans le dossier de zhpdiag dans program files sous le nom de ZHPFixReport
tuto si besoin merci saachaa !!
2) postes moi le rapport de WinChk
Télécharge WinChk (d'Xplode) sur ton bureau
Double clique sur winchk.exe
Clique sur le bouton Exécuter
Patiente durant la création du rapport..
Celui-ci s'affiche à l'écran à la fin de l'analyse. Si rien n'apparaît, le rapport est présent à la racine de votre disque dur : C:\WinChk.txt
Fournissez ce rapport à la personne qui vous aide sur le forum.
1) tu fais zhpfix comme expliqué
tu prends le temps de lire la procédure avant de lancer , merci
. Copie les lignes suivantes en GRAS
SysRestore
M3 - MFPP: Plugins - [Abdesalem Derdar] -- C:\Documents and Settings\Abdesalem Derdar\Application Data\Mozilla\Firefox\Profiles\nzttb45z.default\searchplugins\recherche-alot.xml
O69 - SBI: prefs.js [Abdesalem Derdar - nzttb45z.default] user_pref("extensions.crossriderapp21810.21810.cookie._GPL_arbitrary_code.expiration", "Sat Apr 06 2013 05:42:21 GMT+0200");
FirewallRAZ
EmptyCLSID
EmptyTemp
EmptyFlash
. Lance ZHPFix de Nicolas Coolman qui se trouve sur ton bureau
. double-clique sur ZHPFix accepte l'élévation des droits avec ok
Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .
si c'est pas le cas: Clique sur gauche sur l'icone du millieu (« coller le presse papier »)
Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.
!! Déconnecte toi, désactive tes défenses (anti-virus, anti-spyware ) et ferme bien toutes autres applications ( navigateurs compris ) !!
. cliques sur GO confirmes le nettoyage !!
. Copie/colle la totalité du rapport dans ta prochaine réponse
tu le trouveras dans le dossier de zhpdiag dans program files sous le nom de ZHPFixReport
tuto si besoin merci saachaa !!
2) postes moi le rapport de WinChk
Télécharge WinChk (d'Xplode) sur ton bureau
Double clique sur winchk.exe
Clique sur le bouton Exécuter
Patiente durant la création du rapport..
Celui-ci s'affiche à l'écran à la fin de l'analyse. Si rien n'apparaît, le rapport est présent à la racine de votre disque dur : C:\WinChk.txt
Fournissez ce rapport à la personne qui vous aide sur le forum.
rapport ZHPFix:
Rapport de ZHPFix 2013.3.9.1 par Nicolas Coolman, Update du 9/03/2013
Fichier d'export Registre :
Run by Abdesalem Derdar at 06/04/2013 23:47:19
High Elevated Privileges : OK
Windows XP Home Edition Service Pack 3 (Build 2600)
Corbeille vidée
========== Valeur(s) du Registre ==========
ABSENT Valeur Domain Profile: FirewallRaz :
Aucune valeur présente dans la clé d'exception du registre (FirewallRaz)
========== Préférences navigateur ==========
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_arbitrary_code.expiration", "Sat Apr 06 2013 05:42:21 GMT+0200");
========== Dossier(s) ==========
Aucun dossiers CLSID Local utilisateur vide
SUPPRIME Temporaires Windows
SUPPRIME Flash Cookies
========== Fichier(s) ==========
ABSENT File: c:\documents and settings\abdesalem derdar\application data\mozilla\firefox\profiles\nzttb45z.default\searchplugins\recherche-alot.xml
SUPPRIME Temporaires Windows
SUPPRIME Flash Cookies
========== Restauration Système ==========
Point de restauration du système créé avec succès
========== Récapitulatif ==========
2 : Valeur(s) du Registre
3 : Dossier(s)
3 : Fichier(s)
1 : Préférences navigateur
1 : Restauration Système
End of clean in 00mn 15s
========== Chemin de fichier rapport ==========
C:\ZHP\ZHPFix[R1].txt - 06/04/2013 04:41:34 [18519]
C:\ZHP\ZHPFix[R2].txt - 06/04/2013 23:47:19 [1373]
et rapport WinChk
Rapport WinChk v2.0 - 06/04/2013 à 23:49
Mis à jour le 08/07/11 à 16h par Xplode
Système d'exploitation : Microsoft Windows XP (32 bits) [version 5.1.2600] Service Pack 3
Nom d'utilisateur : Abdesalem Derdar - YOUR-10A2E35C12 (Administrateur)
Exécuté depuis : C:\Documents and Settings\Abdesalem Derdar\Mes documents\Téléchargements\winchk0.exe
¤¤¤¤¤ Recherche | Registre ¤¤¤¤¤
... OK !
¤¤¤¤¤ Recherche | AntiWPA ¤¤¤¤¤
... OK !
¤¤¤¤¤ Recherche | KMS ¤¤¤¤¤
... OK !
¤¤¤¤¤ Recherche | Fichiers suspect ¤¤¤¤¤
... OK !
¤¤¤¤¤ Vérification | Fichiers système ¤¤¤¤¤
... OK !
¤¤¤¤¤ Vérification | Fichier Hosts ¤¤¤¤¤
... OK !
¤¤¤¤¤ Vérification | Windows Update ¤¤¤¤¤
¤ Paramètres : Les mises à jour automatiques sont activées et sont installées automatiquement.
¤ Dernière mise à jour détectée le 2013-04-06 à 10:41:30
¤ Dernière mise à jour téléchargée le 2013-03-21 à 04:55:08
¤ Dernière mise à jour installée le 2013-03-22 à 02:02:32
########## EOF - "C:\WinChk.txt" - [1097 octets] ##########
Rapport de ZHPFix 2013.3.9.1 par Nicolas Coolman, Update du 9/03/2013
Fichier d'export Registre :
Run by Abdesalem Derdar at 06/04/2013 23:47:19
High Elevated Privileges : OK
Windows XP Home Edition Service Pack 3 (Build 2600)
Corbeille vidée
========== Valeur(s) du Registre ==========
ABSENT Valeur Domain Profile: FirewallRaz :
Aucune valeur présente dans la clé d'exception du registre (FirewallRaz)
========== Préférences navigateur ==========
ABSENT Mozilla Pref: user_pref("extensions.crossriderapp21810.21810.cookie._GPL_arbitrary_code.expiration", "Sat Apr 06 2013 05:42:21 GMT+0200");
========== Dossier(s) ==========
Aucun dossiers CLSID Local utilisateur vide
SUPPRIME Temporaires Windows
SUPPRIME Flash Cookies
========== Fichier(s) ==========
ABSENT File: c:\documents and settings\abdesalem derdar\application data\mozilla\firefox\profiles\nzttb45z.default\searchplugins\recherche-alot.xml
SUPPRIME Temporaires Windows
SUPPRIME Flash Cookies
========== Restauration Système ==========
Point de restauration du système créé avec succès
========== Récapitulatif ==========
2 : Valeur(s) du Registre
3 : Dossier(s)
3 : Fichier(s)
1 : Préférences navigateur
1 : Restauration Système
End of clean in 00mn 15s
========== Chemin de fichier rapport ==========
C:\ZHP\ZHPFix[R1].txt - 06/04/2013 04:41:34 [18519]
C:\ZHP\ZHPFix[R2].txt - 06/04/2013 23:47:19 [1373]
et rapport WinChk
Rapport WinChk v2.0 - 06/04/2013 à 23:49
Mis à jour le 08/07/11 à 16h par Xplode
Système d'exploitation : Microsoft Windows XP (32 bits) [version 5.1.2600] Service Pack 3
Nom d'utilisateur : Abdesalem Derdar - YOUR-10A2E35C12 (Administrateur)
Exécuté depuis : C:\Documents and Settings\Abdesalem Derdar\Mes documents\Téléchargements\winchk0.exe
¤¤¤¤¤ Recherche | Registre ¤¤¤¤¤
... OK !
¤¤¤¤¤ Recherche | AntiWPA ¤¤¤¤¤
... OK !
¤¤¤¤¤ Recherche | KMS ¤¤¤¤¤
... OK !
¤¤¤¤¤ Recherche | Fichiers suspect ¤¤¤¤¤
... OK !
¤¤¤¤¤ Vérification | Fichiers système ¤¤¤¤¤
... OK !
¤¤¤¤¤ Vérification | Fichier Hosts ¤¤¤¤¤
... OK !
¤¤¤¤¤ Vérification | Windows Update ¤¤¤¤¤
¤ Paramètres : Les mises à jour automatiques sont activées et sont installées automatiquement.
¤ Dernière mise à jour détectée le 2013-04-06 à 10:41:30
¤ Dernière mise à jour téléchargée le 2013-03-21 à 04:55:08
¤ Dernière mise à jour installée le 2013-03-22 à 02:02:32
########## EOF - "C:\WinChk.txt" - [1097 octets] ##########
ok cela est bon pour moi tu fais se qui suit et tu nous dis si c'est bon aussi pour toi !!
1) passes delfix pour supprimer les outils et rapport
télécharge delfix ( merci xplode)
compatible avec Windows XP, Vista, 7, 8 versions 32 & 64 bits.
lances delfix
et coche Suppression des outils de désinfection
et coche Purger la restauration système
ne pas oublier de cliquer sur "executer"
une fois fait tu cliques droit sur un espace vide de ton bureau
et puis nouveau document texte
tu l'ouvre et tu fais clique droit dedans et copier
normalement tu devrait avoir le rapport de delfix tu me le postes
par le biais d'un hébergeur !!
http://pjjoint.malekal.com/
PS: sinon il est à la racine de ton DD système
2) après un redémarrages du pc tu fais un nettoyage avec ccleaner et les réglages donnés
télécharges Ccleaner à partir de cette adresses
https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
.enregistres le sur le bureau
.double-cliques si sous XP sinon pour vista et seven clique droit et en tant que administrateur sur le fichier pour lancer l'installation
.sur la fenêtre de l'installation langage bien choisir français et OK
.cliques sur suivant
.lis la licence et j'accepte
.cliques sur suivant
.la tu ne gardes de coché que mettre un raccourci sur le bureau et puis contrôler automatiquement les mises à jour de Ccleaner
ATTENTION refuse l'installation de tous ce qui est google si pas intéressé !!
.cliques sur intaller
.cliques sur fermer
.double-cliques si sous XP sinon pour vista et seven clique droit et en tant que administrateur sur l'icône de Ccleaner pour l'ouvrir
.une fois ouvert tu cliques sur option et puis avancé
.tu décoches effacer uniquement les fichiers, du dossier temp de windows plus vieux que 24 heures
.cliques sur nettoyeur
.cliques sur windows et dans la colonne avancé
.cochesla première case vieilles données du perfetch que celle-la
.cliques sur analyse une fois l'analyse terminé
.cliques sur lancer le nettoyage et sur la demande de confirmation OK il vas falloir que tu le refasses une autre fois une fois fini vériffis en appuiant de nouveau sur analyse pour être sur qu'il n'y est plus rien
.cliques maintenant sur registre et puis sur rechercher les erreurs
.laisses tout cochées et cliques sur réparrer les erreurs sélectionnées
.il te demande de sauvegarder OUI
.tu lui donnes un nom pour pouvoir la retrouver et enregistre
.cliques sur corriger toutes les erreurs sélectionnées et sur la demande de confirmation OK
.il supprime et fermer tu vériffis en relancant rechercher les erreurs
.tu retournes dans option et tu recoches la case effacer uniquement les fichiers, du dossier temp de windows plus vieux que 24 heures et sur nettoyeur, windows sous avancé tu décoches la première case vieilles données du perfetch
.tu peux fermer Ccleaner
pour aider si besion tutoriel: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
1) passes delfix pour supprimer les outils et rapport
télécharge delfix ( merci xplode)
compatible avec Windows XP, Vista, 7, 8 versions 32 & 64 bits.
lances delfix
et coche Suppression des outils de désinfection
et coche Purger la restauration système
ne pas oublier de cliquer sur "executer"
une fois fait tu cliques droit sur un espace vide de ton bureau
et puis nouveau document texte
tu l'ouvre et tu fais clique droit dedans et copier
normalement tu devrait avoir le rapport de delfix tu me le postes
par le biais d'un hébergeur !!
http://pjjoint.malekal.com/
PS: sinon il est à la racine de ton DD système
2) après un redémarrages du pc tu fais un nettoyage avec ccleaner et les réglages donnés
télécharges Ccleaner à partir de cette adresses
https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
.enregistres le sur le bureau
.double-cliques si sous XP sinon pour vista et seven clique droit et en tant que administrateur sur le fichier pour lancer l'installation
.sur la fenêtre de l'installation langage bien choisir français et OK
.cliques sur suivant
.lis la licence et j'accepte
.cliques sur suivant
.la tu ne gardes de coché que mettre un raccourci sur le bureau et puis contrôler automatiquement les mises à jour de Ccleaner
ATTENTION refuse l'installation de tous ce qui est google si pas intéressé !!
.cliques sur intaller
.cliques sur fermer
.double-cliques si sous XP sinon pour vista et seven clique droit et en tant que administrateur sur l'icône de Ccleaner pour l'ouvrir
.une fois ouvert tu cliques sur option et puis avancé
.tu décoches effacer uniquement les fichiers, du dossier temp de windows plus vieux que 24 heures
.cliques sur nettoyeur
.cliques sur windows et dans la colonne avancé
.cochesla première case vieilles données du perfetch que celle-la
.cliques sur analyse une fois l'analyse terminé
.cliques sur lancer le nettoyage et sur la demande de confirmation OK il vas falloir que tu le refasses une autre fois une fois fini vériffis en appuiant de nouveau sur analyse pour être sur qu'il n'y est plus rien
.cliques maintenant sur registre et puis sur rechercher les erreurs
.laisses tout cochées et cliques sur réparrer les erreurs sélectionnées
.il te demande de sauvegarder OUI
.tu lui donnes un nom pour pouvoir la retrouver et enregistre
.cliques sur corriger toutes les erreurs sélectionnées et sur la demande de confirmation OK
.il supprime et fermer tu vériffis en relancant rechercher les erreurs
.tu retournes dans option et tu recoches la case effacer uniquement les fichiers, du dossier temp de windows plus vieux que 24 heures et sur nettoyeur, windows sous avancé tu décoches la première case vieilles données du perfetch
.tu peux fermer Ccleaner
pour aider si besion tutoriel: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
ok c'est bon et surtout merci pour l'aide cependant pour le problème de la connection sur le PC de bureau c'est la configuration requise de windows qui ne correspond pas à la configuration du réseau.
Aurais-tu un lien permettant de mieux analyser le problème et éventuellement la solution si solution y a ?
Merci
Aurais-tu un lien permettant de mieux analyser le problème et éventuellement la solution si solution y a ?
Merci
il ne se télécharge pas : délai d'attente dépassé après quelques secondes .....?c'est le netbook que tu as résolu et celui-ci c'est du bureau pour la connexion
merci
merci
bonsoir
voici le rapport ZHPDiag du PC bureau ( pour rappel problème de configuration neufbox avec le PC ) .......avec du retard et exécuté selon ta consigne :
Rapport de ZHPDiag v2013.4.13.73 par Nicolas Coolman, Update du 13/04/2013
Run by Abdouche at 14/04/2013 00:55:49
State : Problème connexion internet
High Elevated Privileges : OK
UAC : Deactivate by user
---\\ Web Browser
MSIE: Internet Explorer v8.0.7601.17514
MFIE: Mozilla Firefox 19.0.2 v19.0.2 (Defaut)
---\\ Windows Product Information
~ Langage: Français
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : 7QJB7
Windows License : OK
~ Windows Remaining Initializations Number : 3
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
---\\ System Protection
AVG 2013 v13.0.3162
Malwarebytes Anti-Malware version 1.70.0.1100
ZoneAlarm Firewall v11.0.000.054
ZoneAlarm Security v11.0.000.054
Windows Defender W7
---\\ System Optimizer
CCleaner v4.00
---\\ Software Update
Adobe Flash Player 11 Plugin
Adobe Reader 9.5.4 MUI
Java 7 Update 17
---\\ System Information
~ Processor: AMD64 Family 16 Model 6 Stepping 2, AuthenticAMD
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3839 MB (61% free)
System Restore: Activé (Enable)
System drive C: has 257 GB (56%) free of 453 GB
---\\ Logged in mode
~ Computer Name: ABDOUCHE-PC
~ User Name: Abdouche
~ All Users Names: HomeGroupUser$, Administrateur, Abdouche,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator
---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Users\Abdouche\AppData\Roaming\
~ %Desktop% : C:\Users\Abdouche\Desktop\
~ %Favorites% : C:\Users\Abdouche\Favorites\
~ %LocalAppData% : C:\Users\Abdouche\AppData\Local\
~ %StartMenu% : C:\Users\Abdouche\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 257 Go of 453 Go)
D:\ CD-ROM drive (Free 0 Go of 1 Go)
E:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
F:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
G:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
H:\ Floppy drive, Flash card reader, USB Key (Free 2 Go of 4 Go)
---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Security Center: Scanned in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.9E7687984107C81B859200C9BD570AFF] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.02/03/2013 - 06:56:00.) -- C:\Windows\System32\wininet.dll [1188864]
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.20/11/2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.1C7857B62DE5994A75B054A9FD4C3825] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/12/2011 - 04:59:24.) -- C:\Windows\system32\Drivers\AFD.sys [498688]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.B8965FB53551B5455630A4B804D0791F] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.02/03/2013 - 07:04:53.) -- C:\Windows\system32\Drivers\ntfs.sys [1655656]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 02s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 2/193
~ Mes musiques (My Musics) : 4/64
~ Mes Videos (My Videos) : 2/213
~ Mes Favoris (My Favorites) : 1/36
~ Mes Documents (My Documents) : 2/4393
~ Mon Bureau (My Desktop) : 1/31
~ Menu demarrer (Programs) : 1/28
~ Hidden Files: Scanned in 00mn 03s
---\\ Processus lancés
[MD5.7853D2AB445C10F97610B2B05FA4CF0A] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [512360] [PID.3096]
[MD5.72334F906C2E2B002CDD2FF9022FD957] - (.PixArt Imaging Incorporation - Registry Monitor.) -- C:\Windows\PixArt\Pac207\Monitor.exe [319488] [PID.3232]
[MD5.34086F1DBB4065047EA3671CB70505CC] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe [421776] [PID.3440]
[MD5.BA92C496F08D78F7DB263A20C36AA546] - (.AVG Technologies CZ, s.r.o. - AVG User Interface.) -- C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4394032] [PID.3452]
[MD5.A73731A0B0A165907799E9AFB461F856] - (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [296096] [PID.3472]
[MD5.7E5ED973D3B3EDB33507DCC37F1D975D] - (.Check Point Software Technologies LTD - ZoneAlarm.) -- C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [73832] [PID.3484]
[MD5.12916E0642E92561C98B18A2A2D01B14] - (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848] [PID.3496]
[MD5.BF2F2717C13A4BD4FD73F2788534E86B] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [917400] [PID.240]
[MD5.AA6844A5127ED4B20DF6D313467B929D] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe [17304] [PID.4720]
[MD5.680AD8F376970696B45269F074A8A28E] - (.Adobe Systems, Inc. - Adobe Flash Player 11.6 r602.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_6_602_180.exe [1822424] [PID.4420]
[MD5.00E193148E1DC8145CE4219900593705] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [6742016] [PID.5276]
[MD5.FB5FA9016DEC70B0F3D3BF80B953E32A] - (.Check Point Software Technologies LTD - TrueVector Service.) -- C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [2447888] [PID.1344]
[MD5.F401929EE0CC92BFE7F15161CA535383] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [55184] [PID.1872]
[MD5.0D8244A9DB70BC6C36E2FB56F6039AB6] - (.AVG Technologies CZ, s.r.o. - AVG Identity Protection Service.) -- C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4937264] [PID.1920]
[MD5.DC98337F0D2A9F6C0B6FB682297ECE3B] - (.AVG Technologies CZ, s.r.o. - AVG Watchdog Service.) -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [282624] [PID.1952]
[MD5.816FD5A6F3C2F3D600900096632FC60E] - (.Acer Incorporated - Global Registration Service.) -- C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe [1150496] [PID.1292]
[MD5.1ACAA67676E9E7BDA5E0C41B6E0DECAF] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [398184] [PID.1672]
[MD5.916B8954AC3E06DC9E898AFFB41F3FB6] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [682344] [PID.1840]
[MD5.70DDE3A86DBEB1D6C3C30AD687B1877A] - (.Acer - Acer Update Service.) -- C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe [240160] [PID.2160]
[MD5.50D3941555FEFDF46424431702EC5FB6] - (.Pas de propriétaire - ToolbarU Application.) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe [945328] [PID.2212] =>Toolbar.AVGSearch
[MD5.F02A533F517EB38333CB12A9E8963773] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [136176] [PID.4976]
[MD5.41ABB7150EC085EEA0D2BC5D3D691988] - (.AVG Technologies CZ, s.r.o. - AVG Installer Application.) -- C:\Program Files (x86)\AVG\AVG2013\avgmfapx.exe [7548744] [PID.5436]
~ Processes Running: Scanned in 00mn 02s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Abdouche\AppData\Local\Google\Chrome\User Data\Default\Preferences
~ Google Browser: Scanned in 00mn 00s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\Abdouche\AppData\Roaming\Mozilla\Firefox\Profiles\avs9duzp.default\prefs.js
~ Firefox Browser: 19 Legitimates Scanned in 00mn 00s
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.acer-group.com/selection.html
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.acer-group.com/selection.html
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
~ IE Browser: 15 Legitimates Scanned in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
---\\ Redirection du fichier Hosts (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21
---\\ Browser Helper Objects de navigateur (O2)
~ BHO: 8 Legitimates Scanned in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: ZoneAlarm Security Engine [64Bits] - [HKLM]{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} . (.Check Point Software Technologies - ZoneAlarm Browser Security.) -- C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
~ Toolbar: Scanned in 00mn 00s
---\\ Applications démarrées par registre & par dossier (O4)
O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
O4 - HKLM\..\Run: [Monitor] . (.PixArt Imaging Incorporation - Registry Monitor.) -- C:\Windows\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [ISW] . (.Check Point Software Technologies - ZoneAlarm Browser Security.) -- C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (.not file.)
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKCU\..\Run: [Neuf Media Center] . (.SFR - Media Center.) -- C:\Program Files (x86)\SFR\Media Center\MediaCenter.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
O4 - HKLM\..\Wow6432Node\Run: [NortonOnlineBackupReminder] . (.Symantec Corporation - Norton Online Backup Service.) -- C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Wow6432Node\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe (.not file.) =>Toolbar.AVGSearch
O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe
O4 - HKLM\..\Wow6432Node\Run: [AVG_UI] . (.AVG Technologies CZ, s.r.o. - AVG User Interface.) -- C:\Program Files (x86)\AVG\AVG2013\avgui.exe
O4 - HKLM\..\Wow6432Node\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe
O4 - HKLM\..\Wow6432Node\Run: [ZoneAlarm] . (.Check Point Software Technologies LTD - ZoneAlarm.) -- C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-21-2026369455-379429309-476914872-1000\..\Run: [msnmsgr] ~"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (.not file.)
O4 - HKUS\S-1-5-21-2026369455-379429309-476914872-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKUS\S-1-5-21-2026369455-379429309-476914872-1000\..\Run: [Neuf Media Center] . (.SFR - Media Center.) -- C:\Program Files (x86)\SFR\Media Center\MediaCenter.exe
~ Application: Scanned in 00mn 00s
---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop: Adobe Download Assistant.lnk . (...) -- C:\Program Files (x86)\Adobe Download Assistant\Adobe Download Assistant.exe
O4 - GS\Desktop: Adobe Reader 9.lnk . (.Adobe Systems Incorporated - Adobe Reader 9.5.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe
O4 - GS\Desktop: AVG 2013.lnk . (.AVG Technologies CZ, s.r.o. - AVG User Interface.) -- C:\Program Files (x86)\AVG\AVG2013\avgui.exe
O4 - GS\Desktop: CCleaner.lnk . (.Piriform Ltd - CCleaner.) -- C:\Program Files (x86)\CCleaner\CCleaner64.exe
O4 - GS\Desktop: eMachines Boutique Accessoire.lnk . (...) -- C:\Program Files (x86)\eMachines Accessory Store\StartUrl.exe (.not file.)
O4 - GS\Desktop: eMachines GameZone Console.lnk . (.Oberon Media - eMachines GameZone Console.) -- C:\Program Files (x86)\eMachines GameZone\GameConsole\eMachines Game Console.exe
O4 - GS\Desktop: Google Earth.lnk . (.Google - Google Earth.) -- C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe
O4 - GS\Desktop: Malwarebytes Anti-Malware.lnk . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
O4 - GS\Desktop: MBRCheck.lnk . (...) -- C:\Program Files (x86)\ZHPDiag\mbrcheck.exe
O4 - GS\Desktop: Microsoft Works.lnk . (.Microsoft® Corporation - Microsoft® Works.) -- C:\Program Files (x86)\Microsoft Works\MSWorks.exe
O4 - GS\Desktop: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\Desktop: Offres gratuites.lnk . (...) -- C:\Program Files (x86)\Real\RealPlayer\freeoffers.rnx (.not file.)
O4 - GS\Desktop: RealPlayer.lnk . (.RealNetworks, Inc. - RealPlayer.) -- C:\program files (x86)\real\realplayer\RealPlay.exe
O4 - GS\Desktop: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Program Files (x86)\ZHPDiag\ZHPhep.exe
O4 - GS\Desktop: ZHPFix.lnk . (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Program Files (x86)\ZHPDiag\ZHPFix\ZHPhep.exe
O4 - GS\Desktop: ZoneAlarm Security.lnk . (.Check Point Software Technologies LTD - ZoneAlarm.) -- C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
O4 - GS\TaskBar: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\TaskBar: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\TaskBar: RealPlayer.lnk . (.RealNetworks, Inc. - RealPlayer.) -- C:\program files (x86)\real\realplayer\RealPlay.exe
O4 - GS\TaskBar: Welcome Center.lnk . (.Acer Incorporated - Welcome Center.) -- C:\Program Files (x86)\eMachines\Welcome Center\OEMWelcomeCenter.exe
O4 - GS\TaskBar: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\explorer.exe
O4 - GS\TaskBar: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
O4 - GS\Programs: Crédit Mutuel.lnk . (.Microsoft Corporation - Microsoft Silverlight Out-of-Browser Launch.) -- C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe
O4 - GS\Programs: Internet Explorer (64-bit).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Programs: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\Accessories: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Accessories: Private Character Editor.lnk . (.Microsoft Corporation - Éditeur de caractères privés.) -- C:\Windows\system32\eudcedit.exe
O4 - GS\SendTo: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) -- C:\Windows\system32\WFS.exe
O4 - GS\SendTo: Skype.lnk . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
O4 - GS\Desktop: Abdouche Derdar - Raccourci.lnk . (...) -- C:\Users\Abdouche\Documents\Abdouche Derdar.doc
O4 - GS\Desktop: Documents - Raccourci.lnk . (...) -- C:\Users\Abdouche\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms
O4 - GS\Desktop: FXnet Trader Platform.lnk . (.FXnet(TM) - FXnet Trader.) -- C:\Users\Abdouche\AppData\Roaming\IFOREX\FXnet Trader Platform\iForex.Clients.Trader.exe
O4 - GS\Desktop: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Desktop: Microsoft Office Excel 2007.lnk . (...) -- C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
O4 - GS\Desktop: Microsoft Office Word 2007.lnk . (...) -- C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
O4 - GS\Desktop: photos vacances 2010-2011 - Raccourci.lnk . (...) -- C:\Users\Abdouche\photos vacances 2010-2011
O4 - GS\Desktop: ZHPDiag2(1) - Raccourci.lnk . (.Nicolas Coolman - ZHPDiag.) -- H:\ZHPDiag2(1).exe
~ Global Startup: Scanned in 00mn 03s
---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
~ IE Control Panel: 1 Legitimates Scanned in 00mn 00s
---\\ Winsock hijacker (Layered Service Provider) (O10)
~ Winsock: 9 Legitimates Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{28896894-C80E-4AA6-8ACE-B77051660AB3}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{69C7B371-EB75-4FEC-8259-F587F4918716}: DhcpNameServer = 109.0.66.10 109.0.66.20
O17 - HKLM\System\CCS\Services\Tcpip\..\{6BB37934-DA43-43FF-B37D-8FCC3EB67D72}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{865B1A97-E544-466B-AB4E-B4F38855EC83}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{ECC74A37-993D-4E10-8926-E9941F981AEE}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{28896894-C80E-4AA6-8ACE-B77051660AB3}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{69C7B371-EB75-4FEC-8259-F587F4918716}: DhcpNameServer = 109.0.66.10 109.0.66.20
O17 - HKLM\System\CS1\Services\Tcpip\..\{6BB37934-DA43-43FF-B37D-8FCC3EB67D72}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{865B1A97-E544-466B-AB4E-B4F38855EC83}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{ECC74A37-993D-4E10-8926-E9941F981AEE}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{28896894-C80E-4AA6-8ACE-B77051660AB3}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{69C7B371-EB75-4FEC-8259-F587F4918716}: DhcpNameServer = 109.0.66.10 109.0.66.20
O17 - HKLM\System\CS2\Services\Tcpip\..\{6BB37934-DA43-43FF-B37D-8FCC3EB67D72}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{865B1A97-E544-466B-AB4E-B4F38855EC83}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{ECC74A37-993D-4E10-8926-E9941F981AEE}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 109.0.66.10 109.0.66.20
~ Domain: Scanned in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
~ SSODL: 1 Legitimates Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: (vToolbarUpdater14.0.1) . (.Pas de propriétaire - ToolbarU Application.) - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe =>Toolbar.AVGSearch
~ Services: 16 Legitimates Scanned in 00mn 15s
---\\ Enumération Active Desktop & MHTML Editor (O24)
~ Desktop Component: 1 Legitimates Scanned in 00mn 00s
---\\ BootExecute (O34)
~ BEX: 1 Legitimates Scanned in 00mn 00s
---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\ROC_JAN2013_TB_rmv.job [356]
[MD5.00000000000000000000000000000000] [APT] [ROC_JAN2013_TB_rmv] (...) -- C:\Program Files (x86)\AVG Secure Search\PostInstall\ROC.exe (.not file.) [0] =>Toolbar.AVGSearch
[MD5.00000000000000000000000000000000] [APT] [Scheduled Update for Ask Toolbar] (...) -- C:\Program Files (x86)\Ask.com\UpdateTask.exe (.not file.) [0] =>Toolbar.Ask
[MD5.00000000000000000000000000000000] [APT] [{6807BECC-5D71-4203-B768-4FCD2BFF186B}] (...) -- D:\setup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{C25228CE-EA24-414F-80B7-74DBB5F8E5B0}] (...) -- C:\Users\Abdouche\Downloads\ZHPDiag2(1).exe (.not file.) [0]
~ Scheduled Task: 20 Legitimates Scanned in 00mn 41s
---\\ Composants installés (ActiveSetup Installed Components) (O40)
~ Active Setup: 11 Legitimates Scanned in 00mn 01s
---\\ Pilotes lancés au démarrage (O41)
~ Drivers: 78 Legitimates Scanned in 00mn 01s
---\\ Logiciels installés (O42)
O42 - Logiciel: FXnet Trader Platform - (.Nom de votre société.) [HKLM][64Bits] -- {B6D33E15-0B5A-4A8F-8034-A7DB28C80B15}
O42 - Logiciel: Snap.Do - (.ReSoft Ltd..) [HKLM][64Bits] -- {60DF47B6-5016-4DA4-AD7B-3CEC24FE7E6E} =>Hijacker.SmartBar
O42 - Logiciel: WebAdSystem - (.KalityWeb.) [HKLM][64Bits] -- {A7039FE8-5B0F-4A15-8A76-8DDF0287C74E}
O42 - Logiciel: ZoneAlarm Firewall - (.Check Point Software Technologies Ltd..) [HKLM][64Bits] -- {BC3EBF1D-5F30-4E53-93A5-15FD9D1CF12B}
O42 - Logiciel: ZoneAlarm Free Firewall - (.Check Point.) [HKLM][64Bits] -- ZoneAlarm Free Firewall
O42 - Logiciel: ZoneAlarm Security - (.Check Point Software Technologies Ltd..) [HKLM][64Bits] -- {A338D97B-5164-4D07-9C5D-19236976B2A2}
~ Logic: 107 Legitimates Scanned in 00mn 00s
---\\ HKCU & HKLM Software Keys
[HKCU\Software\IncrediMail]
[HKCU\Software\KeepVid]
[HKCU\Software\SweetIM] =>PUP.SweetIM
[HKLM\Software\WNLT]
[HKLM\Software\Wow6432Node\IncrediMail]
[HKLM\Software\Wow6432Node\SweetIM] =>PUP.SweetIM
~ Key Software: 206 Legitimates Scanned in 00mn 00s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 28/09/2010 - 15:20:04 - [0,000] ----D C:\ProgramData\hsswpr
O43 - CFD: 30/03/2012 - 11:41:09 - [12,856] ----D C:\Users\Abdouche\AppData\Roaming\IFOREX
O43 - CFD: 30/03/2012 - 11:43:36 - [0,007] ----D C:\Users\Abdouche\AppData\Local\FXnet(TM)
O43 - CFD: 30/03/2012 - 12:04:32 - [0,005] ----D C:\Users\Abdouche\AppData\Local\iFOREX
O43 - CFD: 02/01/2013 - 01:24:05 - [0,002] ----D C:\Users\Abdouche\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IFOREX
~ Program Folder: 176 Legitimates Scanned in 00mn 02s
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.7D38AF578D0F46E7515C8D3ABF1B2161] - 21/03/2013 - 22:19:30 R--A- . (...) -- C:\Pre_Scan_21_03_2013_21_06_29.txt [34668]
O44 - LFC:[MD5.2EAA9BD5D9D749BA411AD9C5FE2E26D8] - 19/03/2013 - 18:26:08 ---A- . (...) -- C:\DelFix.txt [1514]
O44 - LFC:[MD5.0B9EE63DFC1F49804E19BE6389624756] - 17/03/2013 - 17:46:31 RSHAD . (...) -- C:\Windows\System32\Drivers\vsconfig.xml [417564]
~ Files: 54 Legitimates Scanned in 01mn 01s
---\\ Déni du service (Local Security Authority) (O48)
~ LSA: 9 Legitimates Scanned in 00mn 00s
---\\ Contrôle du Safe Boot (CSB) (O49)
~ CBS: 13 Legitimates Scanned in 00mn 00s
---\\ Trojan Driver Search Data (HKLM) (O52)
~ TDSD: 2 Legitimates Scanned in 00mn 00s
---\\ Microsoft Control Security Providers (O54)
~ MSCP: 2 Legitimates Scanned in 00mn 00s
---\\ Microsoft Windows Policies System (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 16 Legitimates Scanned in 00mn 00s
---\\ Microsoft Windows Policies Explorer (O56)
~ MWPE Keys: 3 Legitimates Scanned in 00mn 00s
---\\ Liste des Drivers Système (O58)
O58 - SDL:[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [491088]
~ Drivers: Scanned in 00mn 00s
---\\ Liste des outils de nettoyage (O63)
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
~ ADS: Scanned in 00mn 00s
---\\ Liste des services Legacy (O64)
~ Legacy: 88 Legitimates Scanned in 00mn 01s
---\\ File Associations Shell Spawning (O67)
~ FASS Keys: 18 Legitimates Scanned in 00mn 00s
---\\ Start Menu Internet (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s
---\\ Search Browser Infection (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - https://www.bing.com/?toHttps=1&redig=69DA0EF8272048D9864AF4DB37211DE8
O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - https://www.google.com/?gws_rd=ssl
~ Keys: Scanned in 00mn 00s
---\\ Recherche des services démarrés par Svchost (O83)
~ Services: 32 Legitimates Scanned in 00mn 00s
---\\ Recherche particuliere à la racine de certains dossiers (O84)
[MD5.FC6AA20F66BD7958D3D7339B28A68B21] [SPRF][09/08/2012] (...) -- C:\Users\Abdouche\AppData\LocalLow\dt.dat [27520]
[MD5.D41D8CD98F00B204E9800998ECF8427E] [SPRF][03/04/2013] (...) -- C:\Users\Abdouche\AppData\LocalLow\prvlcl.dat [0]
[MD5.D1D494729855A825B475CF683186D195] [SPRF][20/06/2012] (.AVG Technologies - AVG Setup Self-Extractor based on 7-Zip.) -- C:\Users\Abdouche\Desktop\avg_free_stb_all_2012_2126.exe [3867720]
[MD5.AA653B7CA23C9C504C2D6050828B34B8] [SPRF][02/06/2010] (.Mozilla - Firefox.) -- C:\Users\Abdouche\Desktop\Firefox_Setup_3.6.3.exe [8412160]
~ Files: Scanned in 00mn 01s
---\\ Firewall Active Exception List (FirewallRules) (O87)
O87 - FAEL: "{1AD15E92-FAC0-4EA0-A353-52BEE8B9B241}" | In - Private - P6 - TRUE | .(...) -- C:\Windows\System32\dmwu.exe
O87 - FAEL: "{0A9A4C6D-51D3-42AA-A14B-E161F9FA84EB}" | In - Private - P17 - TRUE | .(...) -- C:\Windows\System32\dmwu.exe
O87 - FAEL: "{4ADD6EBD-357E-4921-8618-233F72393862}" | In - Public - P6 - TRUE | .(...) -- C:\Windows\System32\dmwu.exe
O87 - FAEL: "{0501FD7E-F0DF-4A16-883F-8AC9827095BE}" | In - Public - P17 - TRUE | .(...) -- C:\Windows\System32\dmwu.exe
~ Firewall: 229 Legitimates Scanned in 00mn 01s
---\\ Scan Additionnel (O88)
Database Version : v2.11523 - (13/04/2013)
Clés trouvées (Keys found) : 114
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 1
Fichiers trouvés (Files found) : 0
[HKLM\Software\Classes\Interface\{01947140-417F-46B6-8751-A3A2B8345E1A}] =>Adware.MyWebSearch
[HKLM\Software\Classes\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302}] =>Adware.MyWebSearch
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] =>Toolbar.Skype
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] =>Toolbar.Skype
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =>Toolbar.Skype
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =>Toolbar.Skype
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =>Toolbar.Skype
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635] =>PUP.SweetIM
[HKLM\Software\Classes\Installer\Features\0E9201899CF73FC4BA93F631631229A1] =>Toolbar.Agent
[HKLM\Software\Classes\Installer\Products\0E9201899CF73FC4BA93F631631229A1] =>Toolbar.Agent
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0E9201899CF73FC4BA93F631631229A1] =>Toolbar.Agent
[HKLM\Software\Wow6432Node\Classes\Installer\Features\0E9201899CF73FC4BA93F631631229A1] =>Toolbar.Agent
[HKLM\Software\Wow6432Node\Classes\Installer\Products\0E9201899CF73FC4BA93F631631229A1] =>Toolbar.Agent
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888] =>Toolbar.Ask
[HKLM\Software\Classes\Installer\Features\F479A18A22A86E3429341589FF57D81A] =>PUP.SweetIM
[HKLM\Software\Classes\Installer\Products\F479A18A22A86E3429341589FF57D81A] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F479A18A22A86E3429341589FF57D81A] =>PUP.SweetIM
[HKLM\Software\Wow6432Node\Classes\Installer\Features\F479A18A22A86E3429341589FF57D81A] =>PUP.SweetIM
[HKLM\Software\Wow6432Node\Classes\Installer\Products\F479A18A22A86E3429341589FF57D81A] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9] =>Adware.MyWebSearch
[HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\HssSrv] =>Toolbar.Agent
[HKCU\Software\SweetIM] =>PUP.SweetIM
[HKLM\Software\Wow6432Node\SweetIM] =>PUP.SweetIM
[HKLM\Software\WNLT] =>Adware.IncrediBar
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{981029E0-7FC9-4CF3-AB39-6F133621921A}] =>Toolbar.Agent
[HKLM\Software\Wow6432Node\Microsoft\Tracing\offerbox_RASAPI32] =>PUP.OfferBox
[HKLM\Software\Wow6432Node\Microsoft\Tracing\offerbox_RASMANCS] =>PUP.OfferBox
[HKLM\Software\Wow6432Node\Microsoft\Tracing\OfferBoxHTTPProxy_RASAPI32] =>PUP.OfferBox
[HKLM\Software\Wow6432Node\Microsoft\Tracing\OfferBoxHTTPProxy_RASMANCS] =>PUP.OfferBox
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}] =>Toolbar.Agent
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}] =>Toolbar.Agent
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}] =>Toolbar.Agent
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3192AA38321C641458DBDAF83979D193] =>Toolbar.Babylon
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4318DF19719275242801CBE292063A4C] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75D5168E5E176C24981B4E5DBD991078] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8724E58E6C7D00C48A0D4F3345EB2C26] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB676B0E1B9EFA049B9F7DDDA9645734] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B31BBB0B825EDEF45AB0FE7099C68C81] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B471D8D7319336B4CA89374ED0D7B806] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC30043663AA2CA4DA1DAA9CA5FDCC75] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDC83385E6C239F4C876A77A37DF581D] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F754C503375A13344B22388E18DFE87E] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420] =>PUP.SweetIM
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] =>Toolbar.Bing
[HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] =>Toolbar.Bing
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] =>Toolbar.Bing
[HKLM\Software\Classes\Installer\Features\FA20CB7A821113A4CB8FA1E38E303D3B] =>PUP.SweetIM
[HKLM\Software\Classes\Installer\Products\FA20CB7A821113A4CB8FA1E38E303D3B] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FA20CB7A821113A4CB8FA1E38E303D3B] =>PUP.SweetIM
[HKLM\Software\Wow6432Node\Classes\Installer\Features\FA20CB7A821113A4CB8FA1E38E303D3B] =>PUP.SweetIM
[HKLM\Software\Wow6432Node\Classes\Installer\Products\FA20CB7A821113A4CB8FA1E38E303D3B] =>PUP.SweetIM
[HKLM\Software\Wow6432Node\Microsoft\Tracing\Setup_RASAPI32] =>Toolbar.Conduit
[HKLM\Software\Wow6432Node\Microsoft\Tracing\Setup_RASMANCS] =>Toolbar.Conduit
[HKLM\Software\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}] =>Toolbar.Conduit
[HKLM\Software\Wow6432Node\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}] =>Toolbar.Conduit
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156] =>PUP.SweetIM^
C:\Program Files (x86)\Common Files\AVG Secure Search =>Toolbar.AVGSearch
~ Additionnel: Scanned in 00mn 21s
---\\ Product Upgrade Codes (O90)
O90 - PUC: "8EF9307AF0B551A4A867D8FD20787CE4" . (.WebAdSystem.) -- C:\Windows\Installer\{A7039FE8-5B0F-4A15-8A76-8DDF0287C74E}\icon.ico
O90 - PUC: "FA20CB7A821113A4CB8FA1E38E303D3B" . (.SweetIM Toolbar for Internet Explorer 4.2.) -- C:\Windows\Installer\{A7BC02AF-1128-4A31-BCF8-1A3EE803D3B3}\ARPPRODUCTICON.exe =>PUP.SweetIM
~ Update Products: 119 Legitimates Scanned in 00mn 00s
---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 17/03/2013 253656 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SR - | Auto 24/05/2012 55184 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SS - | Demand 167264 | (AVG Security Toolbar Service) . (...) - C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe
SR - | Auto 27/02/2013 4937264 | (AVGIDSAgent) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
SR - | Auto 19/02/2013 282624 | (avgwd) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
SR - | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 626208 | (ForceWare Intelligent Application Manager (IAM)) . (...) - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
SR - | Auto 28/08/2009 1150496 | (Greg_Service) . (.Acer Incorporated.) - C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe
SS - | Auto 03/06/2010 136176 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 03/06/2010 136176 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SR - | Demand 07/06/2012 936848 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 22/11/2012 828072 | (IswSvc) . (.Check Point Software Technologies.) - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
SR - | Auto 14/12/2012 398184 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
SR - | Auto 14/12/2012 682344 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
SS - | Demand 17/03/2013 115608 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
SR - | Auto 206880 | (nSvcIp) . (...) - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
SR - | Auto 19/09/2009 383592 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe
SS - | Auto 13/07/2012 160944 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
SR - | Auto 04/07/2009 240160 | (Updater Service) . (.Acer.) - C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
SR - | Auto 23/01/2013 2447888 | (vsmon) . (.Check Point Software Technologies LTD.) - C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
SR - | Auto 945328 | (vToolbarUpdater14.0.1) . (...) - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe =>Toolbar.AVGSearch
SS - | Demand 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 02s
~ 1132 Legitimates filtered by white list
End of the scan (660 lines in 03mn 11s)(0)
voici le rapport ZHPDiag du PC bureau ( pour rappel problème de configuration neufbox avec le PC ) .......avec du retard et exécuté selon ta consigne :
Rapport de ZHPDiag v2013.4.13.73 par Nicolas Coolman, Update du 13/04/2013
Run by Abdouche at 14/04/2013 00:55:49
State : Problème connexion internet
High Elevated Privileges : OK
UAC : Deactivate by user
---\\ Web Browser
MSIE: Internet Explorer v8.0.7601.17514
MFIE: Mozilla Firefox 19.0.2 v19.0.2 (Defaut)
---\\ Windows Product Information
~ Langage: Français
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : 7QJB7
Windows License : OK
~ Windows Remaining Initializations Number : 3
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
---\\ System Protection
AVG 2013 v13.0.3162
Malwarebytes Anti-Malware version 1.70.0.1100
ZoneAlarm Firewall v11.0.000.054
ZoneAlarm Security v11.0.000.054
Windows Defender W7
---\\ System Optimizer
CCleaner v4.00
---\\ Software Update
Adobe Flash Player 11 Plugin
Adobe Reader 9.5.4 MUI
Java 7 Update 17
---\\ System Information
~ Processor: AMD64 Family 16 Model 6 Stepping 2, AuthenticAMD
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3839 MB (61% free)
System Restore: Activé (Enable)
System drive C: has 257 GB (56%) free of 453 GB
---\\ Logged in mode
~ Computer Name: ABDOUCHE-PC
~ User Name: Abdouche
~ All Users Names: HomeGroupUser$, Administrateur, Abdouche,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator
---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Users\Abdouche\AppData\Roaming\
~ %Desktop% : C:\Users\Abdouche\Desktop\
~ %Favorites% : C:\Users\Abdouche\Favorites\
~ %LocalAppData% : C:\Users\Abdouche\AppData\Local\
~ %StartMenu% : C:\Users\Abdouche\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 257 Go of 453 Go)
D:\ CD-ROM drive (Free 0 Go of 1 Go)
E:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
F:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
G:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
H:\ Floppy drive, Flash card reader, USB Key (Free 2 Go of 4 Go)
---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Security Center: Scanned in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.9E7687984107C81B859200C9BD570AFF] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.02/03/2013 - 06:56:00.) -- C:\Windows\System32\wininet.dll [1188864]
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.20/11/2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.1C7857B62DE5994A75B054A9FD4C3825] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/12/2011 - 04:59:24.) -- C:\Windows\system32\Drivers\AFD.sys [498688]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.B8965FB53551B5455630A4B804D0791F] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.02/03/2013 - 07:04:53.) -- C:\Windows\system32\Drivers\ntfs.sys [1655656]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 02s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 2/193
~ Mes musiques (My Musics) : 4/64
~ Mes Videos (My Videos) : 2/213
~ Mes Favoris (My Favorites) : 1/36
~ Mes Documents (My Documents) : 2/4393
~ Mon Bureau (My Desktop) : 1/31
~ Menu demarrer (Programs) : 1/28
~ Hidden Files: Scanned in 00mn 03s
---\\ Processus lancés
[MD5.7853D2AB445C10F97610B2B05FA4CF0A] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [512360] [PID.3096]
[MD5.72334F906C2E2B002CDD2FF9022FD957] - (.PixArt Imaging Incorporation - Registry Monitor.) -- C:\Windows\PixArt\Pac207\Monitor.exe [319488] [PID.3232]
[MD5.34086F1DBB4065047EA3671CB70505CC] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe [421776] [PID.3440]
[MD5.BA92C496F08D78F7DB263A20C36AA546] - (.AVG Technologies CZ, s.r.o. - AVG User Interface.) -- C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4394032] [PID.3452]
[MD5.A73731A0B0A165907799E9AFB461F856] - (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [296096] [PID.3472]
[MD5.7E5ED973D3B3EDB33507DCC37F1D975D] - (.Check Point Software Technologies LTD - ZoneAlarm.) -- C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [73832] [PID.3484]
[MD5.12916E0642E92561C98B18A2A2D01B14] - (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848] [PID.3496]
[MD5.BF2F2717C13A4BD4FD73F2788534E86B] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [917400] [PID.240]
[MD5.AA6844A5127ED4B20DF6D313467B929D] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe [17304] [PID.4720]
[MD5.680AD8F376970696B45269F074A8A28E] - (.Adobe Systems, Inc. - Adobe Flash Player 11.6 r602.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_6_602_180.exe [1822424] [PID.4420]
[MD5.00E193148E1DC8145CE4219900593705] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [6742016] [PID.5276]
[MD5.FB5FA9016DEC70B0F3D3BF80B953E32A] - (.Check Point Software Technologies LTD - TrueVector Service.) -- C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [2447888] [PID.1344]
[MD5.F401929EE0CC92BFE7F15161CA535383] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [55184] [PID.1872]
[MD5.0D8244A9DB70BC6C36E2FB56F6039AB6] - (.AVG Technologies CZ, s.r.o. - AVG Identity Protection Service.) -- C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4937264] [PID.1920]
[MD5.DC98337F0D2A9F6C0B6FB682297ECE3B] - (.AVG Technologies CZ, s.r.o. - AVG Watchdog Service.) -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [282624] [PID.1952]
[MD5.816FD5A6F3C2F3D600900096632FC60E] - (.Acer Incorporated - Global Registration Service.) -- C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe [1150496] [PID.1292]
[MD5.1ACAA67676E9E7BDA5E0C41B6E0DECAF] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [398184] [PID.1672]
[MD5.916B8954AC3E06DC9E898AFFB41F3FB6] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [682344] [PID.1840]
[MD5.70DDE3A86DBEB1D6C3C30AD687B1877A] - (.Acer - Acer Update Service.) -- C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe [240160] [PID.2160]
[MD5.50D3941555FEFDF46424431702EC5FB6] - (.Pas de propriétaire - ToolbarU Application.) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe [945328] [PID.2212] =>Toolbar.AVGSearch
[MD5.F02A533F517EB38333CB12A9E8963773] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [136176] [PID.4976]
[MD5.41ABB7150EC085EEA0D2BC5D3D691988] - (.AVG Technologies CZ, s.r.o. - AVG Installer Application.) -- C:\Program Files (x86)\AVG\AVG2013\avgmfapx.exe [7548744] [PID.5436]
~ Processes Running: Scanned in 00mn 02s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Abdouche\AppData\Local\Google\Chrome\User Data\Default\Preferences
~ Google Browser: Scanned in 00mn 00s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\Abdouche\AppData\Roaming\Mozilla\Firefox\Profiles\avs9duzp.default\prefs.js
~ Firefox Browser: 19 Legitimates Scanned in 00mn 00s
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.acer-group.com/selection.html
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.acer-group.com/selection.html
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
~ IE Browser: 15 Legitimates Scanned in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
---\\ Redirection du fichier Hosts (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21
---\\ Browser Helper Objects de navigateur (O2)
~ BHO: 8 Legitimates Scanned in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: ZoneAlarm Security Engine [64Bits] - [HKLM]{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} . (.Check Point Software Technologies - ZoneAlarm Browser Security.) -- C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
~ Toolbar: Scanned in 00mn 00s
---\\ Applications démarrées par registre & par dossier (O4)
O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
O4 - HKLM\..\Run: [Monitor] . (.PixArt Imaging Incorporation - Registry Monitor.) -- C:\Windows\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [ISW] . (.Check Point Software Technologies - ZoneAlarm Browser Security.) -- C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (.not file.)
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKCU\..\Run: [Neuf Media Center] . (.SFR - Media Center.) -- C:\Program Files (x86)\SFR\Media Center\MediaCenter.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
O4 - HKLM\..\Wow6432Node\Run: [NortonOnlineBackupReminder] . (.Symantec Corporation - Norton Online Backup Service.) -- C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Wow6432Node\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe (.not file.) =>Toolbar.AVGSearch
O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe
O4 - HKLM\..\Wow6432Node\Run: [AVG_UI] . (.AVG Technologies CZ, s.r.o. - AVG User Interface.) -- C:\Program Files (x86)\AVG\AVG2013\avgui.exe
O4 - HKLM\..\Wow6432Node\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe
O4 - HKLM\..\Wow6432Node\Run: [ZoneAlarm] . (.Check Point Software Technologies LTD - ZoneAlarm.) -- C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-21-2026369455-379429309-476914872-1000\..\Run: [msnmsgr] ~"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (.not file.)
O4 - HKUS\S-1-5-21-2026369455-379429309-476914872-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKUS\S-1-5-21-2026369455-379429309-476914872-1000\..\Run: [Neuf Media Center] . (.SFR - Media Center.) -- C:\Program Files (x86)\SFR\Media Center\MediaCenter.exe
~ Application: Scanned in 00mn 00s
---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop: Adobe Download Assistant.lnk . (...) -- C:\Program Files (x86)\Adobe Download Assistant\Adobe Download Assistant.exe
O4 - GS\Desktop: Adobe Reader 9.lnk . (.Adobe Systems Incorporated - Adobe Reader 9.5.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe
O4 - GS\Desktop: AVG 2013.lnk . (.AVG Technologies CZ, s.r.o. - AVG User Interface.) -- C:\Program Files (x86)\AVG\AVG2013\avgui.exe
O4 - GS\Desktop: CCleaner.lnk . (.Piriform Ltd - CCleaner.) -- C:\Program Files (x86)\CCleaner\CCleaner64.exe
O4 - GS\Desktop: eMachines Boutique Accessoire.lnk . (...) -- C:\Program Files (x86)\eMachines Accessory Store\StartUrl.exe (.not file.)
O4 - GS\Desktop: eMachines GameZone Console.lnk . (.Oberon Media - eMachines GameZone Console.) -- C:\Program Files (x86)\eMachines GameZone\GameConsole\eMachines Game Console.exe
O4 - GS\Desktop: Google Earth.lnk . (.Google - Google Earth.) -- C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe
O4 - GS\Desktop: Malwarebytes Anti-Malware.lnk . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
O4 - GS\Desktop: MBRCheck.lnk . (...) -- C:\Program Files (x86)\ZHPDiag\mbrcheck.exe
O4 - GS\Desktop: Microsoft Works.lnk . (.Microsoft® Corporation - Microsoft® Works.) -- C:\Program Files (x86)\Microsoft Works\MSWorks.exe
O4 - GS\Desktop: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\Desktop: Offres gratuites.lnk . (...) -- C:\Program Files (x86)\Real\RealPlayer\freeoffers.rnx (.not file.)
O4 - GS\Desktop: RealPlayer.lnk . (.RealNetworks, Inc. - RealPlayer.) -- C:\program files (x86)\real\realplayer\RealPlay.exe
O4 - GS\Desktop: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Program Files (x86)\ZHPDiag\ZHPhep.exe
O4 - GS\Desktop: ZHPFix.lnk . (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Program Files (x86)\ZHPDiag\ZHPFix\ZHPhep.exe
O4 - GS\Desktop: ZoneAlarm Security.lnk . (.Check Point Software Technologies LTD - ZoneAlarm.) -- C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
O4 - GS\TaskBar: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\TaskBar: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\TaskBar: RealPlayer.lnk . (.RealNetworks, Inc. - RealPlayer.) -- C:\program files (x86)\real\realplayer\RealPlay.exe
O4 - GS\TaskBar: Welcome Center.lnk . (.Acer Incorporated - Welcome Center.) -- C:\Program Files (x86)\eMachines\Welcome Center\OEMWelcomeCenter.exe
O4 - GS\TaskBar: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\explorer.exe
O4 - GS\TaskBar: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
O4 - GS\Programs: Crédit Mutuel.lnk . (.Microsoft Corporation - Microsoft Silverlight Out-of-Browser Launch.) -- C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe
O4 - GS\Programs: Internet Explorer (64-bit).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Programs: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\Accessories: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Accessories: Private Character Editor.lnk . (.Microsoft Corporation - Éditeur de caractères privés.) -- C:\Windows\system32\eudcedit.exe
O4 - GS\SendTo: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) -- C:\Windows\system32\WFS.exe
O4 - GS\SendTo: Skype.lnk . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
O4 - GS\Desktop: Abdouche Derdar - Raccourci.lnk . (...) -- C:\Users\Abdouche\Documents\Abdouche Derdar.doc
O4 - GS\Desktop: Documents - Raccourci.lnk . (...) -- C:\Users\Abdouche\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms
O4 - GS\Desktop: FXnet Trader Platform.lnk . (.FXnet(TM) - FXnet Trader.) -- C:\Users\Abdouche\AppData\Roaming\IFOREX\FXnet Trader Platform\iForex.Clients.Trader.exe
O4 - GS\Desktop: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Desktop: Microsoft Office Excel 2007.lnk . (...) -- C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
O4 - GS\Desktop: Microsoft Office Word 2007.lnk . (...) -- C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
O4 - GS\Desktop: photos vacances 2010-2011 - Raccourci.lnk . (...) -- C:\Users\Abdouche\photos vacances 2010-2011
O4 - GS\Desktop: ZHPDiag2(1) - Raccourci.lnk . (.Nicolas Coolman - ZHPDiag.) -- H:\ZHPDiag2(1).exe
~ Global Startup: Scanned in 00mn 03s
---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
~ IE Control Panel: 1 Legitimates Scanned in 00mn 00s
---\\ Winsock hijacker (Layered Service Provider) (O10)
~ Winsock: 9 Legitimates Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{28896894-C80E-4AA6-8ACE-B77051660AB3}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{69C7B371-EB75-4FEC-8259-F587F4918716}: DhcpNameServer = 109.0.66.10 109.0.66.20
O17 - HKLM\System\CCS\Services\Tcpip\..\{6BB37934-DA43-43FF-B37D-8FCC3EB67D72}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{865B1A97-E544-466B-AB4E-B4F38855EC83}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{ECC74A37-993D-4E10-8926-E9941F981AEE}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{28896894-C80E-4AA6-8ACE-B77051660AB3}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{69C7B371-EB75-4FEC-8259-F587F4918716}: DhcpNameServer = 109.0.66.10 109.0.66.20
O17 - HKLM\System\CS1\Services\Tcpip\..\{6BB37934-DA43-43FF-B37D-8FCC3EB67D72}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{865B1A97-E544-466B-AB4E-B4F38855EC83}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{ECC74A37-993D-4E10-8926-E9941F981AEE}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{28896894-C80E-4AA6-8ACE-B77051660AB3}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{69C7B371-EB75-4FEC-8259-F587F4918716}: DhcpNameServer = 109.0.66.10 109.0.66.20
O17 - HKLM\System\CS2\Services\Tcpip\..\{6BB37934-DA43-43FF-B37D-8FCC3EB67D72}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{865B1A97-E544-466B-AB4E-B4F38855EC83}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{ECC74A37-993D-4E10-8926-E9941F981AEE}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 109.0.66.10 109.0.66.20
~ Domain: Scanned in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
~ SSODL: 1 Legitimates Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: (vToolbarUpdater14.0.1) . (.Pas de propriétaire - ToolbarU Application.) - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe =>Toolbar.AVGSearch
~ Services: 16 Legitimates Scanned in 00mn 15s
---\\ Enumération Active Desktop & MHTML Editor (O24)
~ Desktop Component: 1 Legitimates Scanned in 00mn 00s
---\\ BootExecute (O34)
~ BEX: 1 Legitimates Scanned in 00mn 00s
---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\ROC_JAN2013_TB_rmv.job [356]
[MD5.00000000000000000000000000000000] [APT] [ROC_JAN2013_TB_rmv] (...) -- C:\Program Files (x86)\AVG Secure Search\PostInstall\ROC.exe (.not file.) [0] =>Toolbar.AVGSearch
[MD5.00000000000000000000000000000000] [APT] [Scheduled Update for Ask Toolbar] (...) -- C:\Program Files (x86)\Ask.com\UpdateTask.exe (.not file.) [0] =>Toolbar.Ask
[MD5.00000000000000000000000000000000] [APT] [{6807BECC-5D71-4203-B768-4FCD2BFF186B}] (...) -- D:\setup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{C25228CE-EA24-414F-80B7-74DBB5F8E5B0}] (...) -- C:\Users\Abdouche\Downloads\ZHPDiag2(1).exe (.not file.) [0]
~ Scheduled Task: 20 Legitimates Scanned in 00mn 41s
---\\ Composants installés (ActiveSetup Installed Components) (O40)
~ Active Setup: 11 Legitimates Scanned in 00mn 01s
---\\ Pilotes lancés au démarrage (O41)
~ Drivers: 78 Legitimates Scanned in 00mn 01s
---\\ Logiciels installés (O42)
O42 - Logiciel: FXnet Trader Platform - (.Nom de votre société.) [HKLM][64Bits] -- {B6D33E15-0B5A-4A8F-8034-A7DB28C80B15}
O42 - Logiciel: Snap.Do - (.ReSoft Ltd..) [HKLM][64Bits] -- {60DF47B6-5016-4DA4-AD7B-3CEC24FE7E6E} =>Hijacker.SmartBar
O42 - Logiciel: WebAdSystem - (.KalityWeb.) [HKLM][64Bits] -- {A7039FE8-5B0F-4A15-8A76-8DDF0287C74E}
O42 - Logiciel: ZoneAlarm Firewall - (.Check Point Software Technologies Ltd..) [HKLM][64Bits] -- {BC3EBF1D-5F30-4E53-93A5-15FD9D1CF12B}
O42 - Logiciel: ZoneAlarm Free Firewall - (.Check Point.) [HKLM][64Bits] -- ZoneAlarm Free Firewall
O42 - Logiciel: ZoneAlarm Security - (.Check Point Software Technologies Ltd..) [HKLM][64Bits] -- {A338D97B-5164-4D07-9C5D-19236976B2A2}
~ Logic: 107 Legitimates Scanned in 00mn 00s
---\\ HKCU & HKLM Software Keys
[HKCU\Software\IncrediMail]
[HKCU\Software\KeepVid]
[HKCU\Software\SweetIM] =>PUP.SweetIM
[HKLM\Software\WNLT]
[HKLM\Software\Wow6432Node\IncrediMail]
[HKLM\Software\Wow6432Node\SweetIM] =>PUP.SweetIM
~ Key Software: 206 Legitimates Scanned in 00mn 00s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 28/09/2010 - 15:20:04 - [0,000] ----D C:\ProgramData\hsswpr
O43 - CFD: 30/03/2012 - 11:41:09 - [12,856] ----D C:\Users\Abdouche\AppData\Roaming\IFOREX
O43 - CFD: 30/03/2012 - 11:43:36 - [0,007] ----D C:\Users\Abdouche\AppData\Local\FXnet(TM)
O43 - CFD: 30/03/2012 - 12:04:32 - [0,005] ----D C:\Users\Abdouche\AppData\Local\iFOREX
O43 - CFD: 02/01/2013 - 01:24:05 - [0,002] ----D C:\Users\Abdouche\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IFOREX
~ Program Folder: 176 Legitimates Scanned in 00mn 02s
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.7D38AF578D0F46E7515C8D3ABF1B2161] - 21/03/2013 - 22:19:30 R--A- . (...) -- C:\Pre_Scan_21_03_2013_21_06_29.txt [34668]
O44 - LFC:[MD5.2EAA9BD5D9D749BA411AD9C5FE2E26D8] - 19/03/2013 - 18:26:08 ---A- . (...) -- C:\DelFix.txt [1514]
O44 - LFC:[MD5.0B9EE63DFC1F49804E19BE6389624756] - 17/03/2013 - 17:46:31 RSHAD . (...) -- C:\Windows\System32\Drivers\vsconfig.xml [417564]
~ Files: 54 Legitimates Scanned in 01mn 01s
---\\ Déni du service (Local Security Authority) (O48)
~ LSA: 9 Legitimates Scanned in 00mn 00s
---\\ Contrôle du Safe Boot (CSB) (O49)
~ CBS: 13 Legitimates Scanned in 00mn 00s
---\\ Trojan Driver Search Data (HKLM) (O52)
~ TDSD: 2 Legitimates Scanned in 00mn 00s
---\\ Microsoft Control Security Providers (O54)
~ MSCP: 2 Legitimates Scanned in 00mn 00s
---\\ Microsoft Windows Policies System (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 16 Legitimates Scanned in 00mn 00s
---\\ Microsoft Windows Policies Explorer (O56)
~ MWPE Keys: 3 Legitimates Scanned in 00mn 00s
---\\ Liste des Drivers Système (O58)
O58 - SDL:[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [491088]
~ Drivers: Scanned in 00mn 00s
---\\ Liste des outils de nettoyage (O63)
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
~ ADS: Scanned in 00mn 00s
---\\ Liste des services Legacy (O64)
~ Legacy: 88 Legitimates Scanned in 00mn 01s
---\\ File Associations Shell Spawning (O67)
~ FASS Keys: 18 Legitimates Scanned in 00mn 00s
---\\ Start Menu Internet (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s
---\\ Search Browser Infection (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - https://www.bing.com/?toHttps=1&redig=69DA0EF8272048D9864AF4DB37211DE8
O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - https://www.google.com/?gws_rd=ssl
~ Keys: Scanned in 00mn 00s
---\\ Recherche des services démarrés par Svchost (O83)
~ Services: 32 Legitimates Scanned in 00mn 00s
---\\ Recherche particuliere à la racine de certains dossiers (O84)
[MD5.FC6AA20F66BD7958D3D7339B28A68B21] [SPRF][09/08/2012] (...) -- C:\Users\Abdouche\AppData\LocalLow\dt.dat [27520]
[MD5.D41D8CD98F00B204E9800998ECF8427E] [SPRF][03/04/2013] (...) -- C:\Users\Abdouche\AppData\LocalLow\prvlcl.dat [0]
[MD5.D1D494729855A825B475CF683186D195] [SPRF][20/06/2012] (.AVG Technologies - AVG Setup Self-Extractor based on 7-Zip.) -- C:\Users\Abdouche\Desktop\avg_free_stb_all_2012_2126.exe [3867720]
[MD5.AA653B7CA23C9C504C2D6050828B34B8] [SPRF][02/06/2010] (.Mozilla - Firefox.) -- C:\Users\Abdouche\Desktop\Firefox_Setup_3.6.3.exe [8412160]
~ Files: Scanned in 00mn 01s
---\\ Firewall Active Exception List (FirewallRules) (O87)
O87 - FAEL: "{1AD15E92-FAC0-4EA0-A353-52BEE8B9B241}" | In - Private - P6 - TRUE | .(...) -- C:\Windows\System32\dmwu.exe
O87 - FAEL: "{0A9A4C6D-51D3-42AA-A14B-E161F9FA84EB}" | In - Private - P17 - TRUE | .(...) -- C:\Windows\System32\dmwu.exe
O87 - FAEL: "{4ADD6EBD-357E-4921-8618-233F72393862}" | In - Public - P6 - TRUE | .(...) -- C:\Windows\System32\dmwu.exe
O87 - FAEL: "{0501FD7E-F0DF-4A16-883F-8AC9827095BE}" | In - Public - P17 - TRUE | .(...) -- C:\Windows\System32\dmwu.exe
~ Firewall: 229 Legitimates Scanned in 00mn 01s
---\\ Scan Additionnel (O88)
Database Version : v2.11523 - (13/04/2013)
Clés trouvées (Keys found) : 114
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 1
Fichiers trouvés (Files found) : 0
[HKLM\Software\Classes\Interface\{01947140-417F-46B6-8751-A3A2B8345E1A}] =>Adware.MyWebSearch
[HKLM\Software\Classes\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302}] =>Adware.MyWebSearch
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] =>Toolbar.Skype
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] =>Toolbar.Skype
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =>Toolbar.Skype
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =>Toolbar.Skype
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =>Toolbar.Skype
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635] =>PUP.SweetIM
[HKLM\Software\Classes\Installer\Features\0E9201899CF73FC4BA93F631631229A1] =>Toolbar.Agent
[HKLM\Software\Classes\Installer\Products\0E9201899CF73FC4BA93F631631229A1] =>Toolbar.Agent
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0E9201899CF73FC4BA93F631631229A1] =>Toolbar.Agent
[HKLM\Software\Wow6432Node\Classes\Installer\Features\0E9201899CF73FC4BA93F631631229A1] =>Toolbar.Agent
[HKLM\Software\Wow6432Node\Classes\Installer\Products\0E9201899CF73FC4BA93F631631229A1] =>Toolbar.Agent
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888] =>Toolbar.Ask
[HKLM\Software\Classes\Installer\Features\F479A18A22A86E3429341589FF57D81A] =>PUP.SweetIM
[HKLM\Software\Classes\Installer\Products\F479A18A22A86E3429341589FF57D81A] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F479A18A22A86E3429341589FF57D81A] =>PUP.SweetIM
[HKLM\Software\Wow6432Node\Classes\Installer\Features\F479A18A22A86E3429341589FF57D81A] =>PUP.SweetIM
[HKLM\Software\Wow6432Node\Classes\Installer\Products\F479A18A22A86E3429341589FF57D81A] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9] =>Adware.MyWebSearch
[HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\HssSrv] =>Toolbar.Agent
[HKCU\Software\SweetIM] =>PUP.SweetIM
[HKLM\Software\Wow6432Node\SweetIM] =>PUP.SweetIM
[HKLM\Software\WNLT] =>Adware.IncrediBar
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{981029E0-7FC9-4CF3-AB39-6F133621921A}] =>Toolbar.Agent
[HKLM\Software\Wow6432Node\Microsoft\Tracing\offerbox_RASAPI32] =>PUP.OfferBox
[HKLM\Software\Wow6432Node\Microsoft\Tracing\offerbox_RASMANCS] =>PUP.OfferBox
[HKLM\Software\Wow6432Node\Microsoft\Tracing\OfferBoxHTTPProxy_RASAPI32] =>PUP.OfferBox
[HKLM\Software\Wow6432Node\Microsoft\Tracing\OfferBoxHTTPProxy_RASMANCS] =>PUP.OfferBox
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}] =>Toolbar.Agent
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}] =>Toolbar.Agent
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}] =>Toolbar.Agent
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3192AA38321C641458DBDAF83979D193] =>Toolbar.Babylon
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2] =>Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4318DF19719275242801CBE292063A4C] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75D5168E5E176C24981B4E5DBD991078] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8724E58E6C7D00C48A0D4F3345EB2C26] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB676B0E1B9EFA049B9F7DDDA9645734] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B31BBB0B825EDEF45AB0FE7099C68C81] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B471D8D7319336B4CA89374ED0D7B806] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC30043663AA2CA4DA1DAA9CA5FDCC75] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDC83385E6C239F4C876A77A37DF581D] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F754C503375A13344B22388E18DFE87E] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420] =>PUP.SweetIM
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] =>Toolbar.Bing
[HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] =>Toolbar.Bing
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] =>Toolbar.Bing
[HKLM\Software\Classes\Installer\Features\FA20CB7A821113A4CB8FA1E38E303D3B] =>PUP.SweetIM
[HKLM\Software\Classes\Installer\Products\FA20CB7A821113A4CB8FA1E38E303D3B] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FA20CB7A821113A4CB8FA1E38E303D3B] =>PUP.SweetIM
[HKLM\Software\Wow6432Node\Classes\Installer\Features\FA20CB7A821113A4CB8FA1E38E303D3B] =>PUP.SweetIM
[HKLM\Software\Wow6432Node\Classes\Installer\Products\FA20CB7A821113A4CB8FA1E38E303D3B] =>PUP.SweetIM
[HKLM\Software\Wow6432Node\Microsoft\Tracing\Setup_RASAPI32] =>Toolbar.Conduit
[HKLM\Software\Wow6432Node\Microsoft\Tracing\Setup_RASMANCS] =>Toolbar.Conduit
[HKLM\Software\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}] =>Toolbar.Conduit
[HKLM\Software\Wow6432Node\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}] =>Toolbar.Conduit
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156] =>PUP.SweetIM^
C:\Program Files (x86)\Common Files\AVG Secure Search =>Toolbar.AVGSearch
~ Additionnel: Scanned in 00mn 21s
---\\ Product Upgrade Codes (O90)
O90 - PUC: "8EF9307AF0B551A4A867D8FD20787CE4" . (.WebAdSystem.) -- C:\Windows\Installer\{A7039FE8-5B0F-4A15-8A76-8DDF0287C74E}\icon.ico
O90 - PUC: "FA20CB7A821113A4CB8FA1E38E303D3B" . (.SweetIM Toolbar for Internet Explorer 4.2.) -- C:\Windows\Installer\{A7BC02AF-1128-4A31-BCF8-1A3EE803D3B3}\ARPPRODUCTICON.exe =>PUP.SweetIM
~ Update Products: 119 Legitimates Scanned in 00mn 00s
---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 17/03/2013 253656 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SR - | Auto 24/05/2012 55184 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SS - | Demand 167264 | (AVG Security Toolbar Service) . (...) - C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe
SR - | Auto 27/02/2013 4937264 | (AVGIDSAgent) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
SR - | Auto 19/02/2013 282624 | (avgwd) . (.AVG Technologies CZ, s.r.o..) - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
SR - | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 626208 | (ForceWare Intelligent Application Manager (IAM)) . (...) - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
SR - | Auto 28/08/2009 1150496 | (Greg_Service) . (.Acer Incorporated.) - C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe
SS - | Auto 03/06/2010 136176 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 03/06/2010 136176 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SR - | Demand 07/06/2012 936848 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 22/11/2012 828072 | (IswSvc) . (.Check Point Software Technologies.) - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
SR - | Auto 14/12/2012 398184 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
SR - | Auto 14/12/2012 682344 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
SS - | Demand 17/03/2013 115608 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
SR - | Auto 206880 | (nSvcIp) . (...) - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
SR - | Auto 19/09/2009 383592 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe
SS - | Auto 13/07/2012 160944 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
SR - | Auto 04/07/2009 240160 | (Updater Service) . (.Acer.) - C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
SR - | Auto 23/01/2013 2447888 | (vsmon) . (.Check Point Software Technologies LTD.) - C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
SR - | Auto 945328 | (vToolbarUpdater14.0.1) . (...) - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe =>Toolbar.AVGSearch
SS - | Demand 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 02s
~ 1132 Legitimates filtered by white list
End of the scan (660 lines in 03mn 11s)(0)
bonjour, passe adwcleaner en mode suppression sur le pc !!
Télécharge AdwCleaner ( d'Xplode ) sur ton bureau.
si problème avec la sécurité de internet explorer regarde se lien : https://toolslib.net
Lance le, clique sur [Suppression] puis patiente le temps du scan.
Une fois le scan fini, un rapport s'ouvrira. Poste moi son contenu dans ta prochaine réponse.
Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt
Télécharge AdwCleaner ( d'Xplode ) sur ton bureau.
si problème avec la sécurité de internet explorer regarde se lien : https://toolslib.net
Lance le, clique sur [Suppression] puis patiente le temps du scan.
Une fois le scan fini, un rapport s'ouvrira. Poste moi son contenu dans ta prochaine réponse.
Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt
# AdwCleaner v2.200 - Rapport créé le 14/04/2013 à 16:15:06
# Mis à jour le 02/04/2013 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : Abdouche - ABDOUCHE-PC
# Mode de démarrage : Normal
# Exécuté depuis : C:\Users\Abdouche\Downloads\adwcleaner.exe
# Option [Suppression]
***** [Services] *****
***** [Fichiers / Dossiers] *****
Supprimé au redémarrage : C:\Program Files (x86)\Common Files\AVG Secure Search
***** [Registre] *****
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\offerbox_RASAPI32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\offerbox_RASMANCS
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{01947140-417F-46B6-8751-A3A2B8345E1A}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302}
***** [Navigateurs] *****
-\\ Internet Explorer v8.0.7601.17514
Remplacé : [HKCU\Software\Microsoft\Internet Explorer\SearchUrl - Default] = hxxp://feed.snap.do/?publisher=Llyx&dpid=Llyx&co=FR&userid=8de24554-a985-4ee3-816a-44992e18cfa3&searchtype=ds&q={searchTerms} --> hxxp://www.google.com
Remplacé : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl - Default] = hxxp://feed.snap.do/?publisher=Llyx&dpid=Llyx&co=FR&userid=8de24554-a985-4ee3-816a-44992e18cfa3&searchtype=ds&q={searchTerms} --> hxxp://www.google.com
-\\ Mozilla Firefox v20.0.1 (fr)
Fichier : C:\Users\Abdouche\AppData\Roaming\Mozilla\Firefox\Profiles\avs9duzp.default\prefs.js
[OK] Le fichier ne contient aucune entrée illégitime.
-\\ Google Chrome v [Impossible d'obtenir la version]
Fichier : C:\Users\Abdouche\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Le fichier ne contient aucune entrée illégitime.
*************************
AdwCleaner[S1].txt - [1788 octets] - [14/04/2013 16:15:06]
########## EOF - C:\AdwCleaner[S1].txt - [1848 octets] ##########
# Mis à jour le 02/04/2013 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : Abdouche - ABDOUCHE-PC
# Mode de démarrage : Normal
# Exécuté depuis : C:\Users\Abdouche\Downloads\adwcleaner.exe
# Option [Suppression]
***** [Services] *****
***** [Fichiers / Dossiers] *****
Supprimé au redémarrage : C:\Program Files (x86)\Common Files\AVG Secure Search
***** [Registre] *****
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\offerbox_RASAPI32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\offerbox_RASMANCS
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{01947140-417F-46B6-8751-A3A2B8345E1A}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302}
***** [Navigateurs] *****
-\\ Internet Explorer v8.0.7601.17514
Remplacé : [HKCU\Software\Microsoft\Internet Explorer\SearchUrl - Default] = hxxp://feed.snap.do/?publisher=Llyx&dpid=Llyx&co=FR&userid=8de24554-a985-4ee3-816a-44992e18cfa3&searchtype=ds&q={searchTerms} --> hxxp://www.google.com
Remplacé : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl - Default] = hxxp://feed.snap.do/?publisher=Llyx&dpid=Llyx&co=FR&userid=8de24554-a985-4ee3-816a-44992e18cfa3&searchtype=ds&q={searchTerms} --> hxxp://www.google.com
-\\ Mozilla Firefox v20.0.1 (fr)
Fichier : C:\Users\Abdouche\AppData\Roaming\Mozilla\Firefox\Profiles\avs9duzp.default\prefs.js
[OK] Le fichier ne contient aucune entrée illégitime.
-\\ Google Chrome v [Impossible d'obtenir la version]
Fichier : C:\Users\Abdouche\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Le fichier ne contient aucune entrée illégitime.
*************************
AdwCleaner[S1].txt - [1788 octets] - [14/04/2013 16:15:06]
########## EOF - C:\AdwCleaner[S1].txt - [1848 octets] ##########