Rédiger un script
Fermé
deniro23
Messages postés
10
Date d'inscription
vendredi 21 mars 2014
Statut
Membre
Dernière intervention
18 avril 2014
-
9 avril 2014 à 12:53
Fish66 Messages postés 17505 Date d'inscription dimanche 24 juillet 2011 Statut Contributeur sécurité Dernière intervention 16 juin 2021 - 18 avril 2014 à 21:31
Fish66 Messages postés 17505 Date d'inscription dimanche 24 juillet 2011 Statut Contributeur sécurité Dernière intervention 16 juin 2021 - 18 avril 2014 à 21:31
Bonjour à tous,
je cherche à supprimer les liens pub INTEXT qui s'affichent sur mes navigateurs, j'alors télécharger ZHPdiag. J'ai donc besoin d'aide pour rédiger le script à utiliser sur ZHPfix.
Merci d'avance.
PS: Le lien du rapport: https://pjjoint.malekal.com/files.php?id=ZHPDiag_20140322_o15j5v8b6f10
je cherche à supprimer les liens pub INTEXT qui s'affichent sur mes navigateurs, j'alors télécharger ZHPdiag. J'ai donc besoin d'aide pour rédiger le script à utiliser sur ZHPfix.
Merci d'avance.
PS: Le lien du rapport: https://pjjoint.malekal.com/files.php?id=ZHPDiag_20140322_o15j5v8b6f10
A voir également:
- Rédiger un script
- Script vidéo youtube - Guide
- Ghost script - Télécharger - Polices de caractères
- Microsoft activation script - Accueil - Windows
- Script bat - Guide
- Script download - Télécharger - Édition & Programmation
8 réponses
Fish66
Messages postés
17505
Date d'inscription
dimanche 24 juillet 2011
Statut
Contributeur sécurité
Dernière intervention
16 juin 2021
1 318
9 avril 2014 à 13:55
9 avril 2014 à 13:55
Bonjour,
Tu as installé des adwares et programmes indésérables sur ton PC.
----------------------------
Télécharge : AdwCleaner (merci à Xplode)
Lance AdwCleaner
Clique sur Scanner puis Nettoyer, et patiente le temps du nettoyage.
Poste le rapport qui apparait en fin de recherche.
(Le rapport est sauvegardé aussi sous C:\AdwCleaner\AdwCleaner[x].txt)
----------------------------
Pour éviter d'avoir des publicités et des toolbars, tu peux lire <<< ceci >>>
2/
Télécharge: Junkware Removal Tool à partir ce lien : https://www.bleepingcomputer.com/download/junkware-removal-tool/dl/131/
!!! Ne clique pas sur Download !!! , attends simplement que la fenetre de telechargement arrive pour confirmation
* Enregistre ce fichier sur le bureau.
* Ferme tout tes navigateurs
Sous XP, double-clique sur l'icône et presse une touche lorsque cela sera demandé.
Sous Vista/7/8, clic droit et Exécuter en temps qu'administrateur.
* NB: Le bureau disparaitra un instant, c'est normal.
* Laisse le programme travailler ne touche plus à rien
* Poste le rapport généré à la fin de l'analyse.
Tuto : http://hackinginterdit.blogspot.fr/2013/02/junkware-removal-tool.html
Tu as installé des adwares et programmes indésérables sur ton PC.
----------------------------
Télécharge : AdwCleaner (merci à Xplode)
Lance AdwCleaner
Clique sur Scanner puis Nettoyer, et patiente le temps du nettoyage.
Poste le rapport qui apparait en fin de recherche.
(Le rapport est sauvegardé aussi sous C:\AdwCleaner\AdwCleaner[x].txt)
----------------------------
Pour éviter d'avoir des publicités et des toolbars, tu peux lire <<< ceci >>>
2/
Télécharge: Junkware Removal Tool à partir ce lien : https://www.bleepingcomputer.com/download/junkware-removal-tool/dl/131/
!!! Ne clique pas sur Download !!! , attends simplement que la fenetre de telechargement arrive pour confirmation
* Enregistre ce fichier sur le bureau.
* Ferme tout tes navigateurs
Sous XP, double-clique sur l'icône et presse une touche lorsque cela sera demandé.
Sous Vista/7/8, clic droit et Exécuter en temps qu'administrateur.
* NB: Le bureau disparaitra un instant, c'est normal.
* Laisse le programme travailler ne touche plus à rien
* Poste le rapport généré à la fin de l'analyse.
Tuto : http://hackinginterdit.blogspot.fr/2013/02/junkware-removal-tool.html
deniro23
Messages postés
10
Date d'inscription
vendredi 21 mars 2014
Statut
Membre
Dernière intervention
18 avril 2014
10 avril 2014 à 21:51
10 avril 2014 à 21:51
Merci pour ta réponse.
Le rapport Adw Cleaner:
# AdwCleaner v3.023 - Rapport créé le 10/04/2014 à 20:56:34
# Mis à jour le 01/04/2014 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : Sébastien - SÉBASTIEN-VAIO
# Exécuté depuis : C:\Users\Sébastien\Downloads\adwcleaner (1).exe
# Option : Nettoyer
***** [ Services ] *****
***** [ Fichiers / Dossiers ] *****
***** [ Raccourcis ] *****
***** [ Registre ] *****
Clé Supprimée : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Clé Supprimée : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
***** [ Navigateurs ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Mozilla Firefox v27.0.1 (fr)
[ Fichier : C:\Users\Sébastien\AppData\Roaming\Mozilla\Firefox\Profiles\4sr9zrcc.default\prefs.js ]
-\\ Google Chrome v
[ Fichier : C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [29862 octets] - [21/03/2014 16:48:42]
AdwCleaner[R1].txt - [1069 octets] - [21/03/2014 16:57:51]
AdwCleaner[R2].txt - [1284 octets] - [10/04/2014 20:46:32]
AdwCleaner[S0].txt - [27942 octets] - [21/03/2014 16:50:59]
AdwCleaner[S1].txt - [1207 octets] - [10/04/2014 20:56:34]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1267 octets] ##########
Le rapport Adw Cleaner:
# AdwCleaner v3.023 - Rapport créé le 10/04/2014 à 20:56:34
# Mis à jour le 01/04/2014 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : Sébastien - SÉBASTIEN-VAIO
# Exécuté depuis : C:\Users\Sébastien\Downloads\adwcleaner (1).exe
# Option : Nettoyer
***** [ Services ] *****
***** [ Fichiers / Dossiers ] *****
***** [ Raccourcis ] *****
***** [ Registre ] *****
Clé Supprimée : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Clé Supprimée : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
***** [ Navigateurs ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Mozilla Firefox v27.0.1 (fr)
[ Fichier : C:\Users\Sébastien\AppData\Roaming\Mozilla\Firefox\Profiles\4sr9zrcc.default\prefs.js ]
-\\ Google Chrome v
[ Fichier : C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [29862 octets] - [21/03/2014 16:48:42]
AdwCleaner[R1].txt - [1069 octets] - [21/03/2014 16:57:51]
AdwCleaner[R2].txt - [1284 octets] - [10/04/2014 20:46:32]
AdwCleaner[S0].txt - [27942 octets] - [21/03/2014 16:50:59]
AdwCleaner[S1].txt - [1207 octets] - [10/04/2014 20:56:34]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1267 octets] ##########
deniro23
Messages postés
10
Date d'inscription
vendredi 21 mars 2014
Statut
Membre
Dernière intervention
18 avril 2014
10 avril 2014 à 21:52
10 avril 2014 à 21:52
Et le rapport JRT:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by S'bastien on 10/04/2014 at 21:05:53,50
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1062016641-3885170610-492797851-1001\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CFC01EB9-82F4-4FC1-8922-42DC2249076F}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}
~~~ Files
Successfully deleted: [File] "C:\Program Files (x86)\adobe\reader 10.0\reader\plug_ins\babylon\babylonrpi.api"
Successfully deleted: [File] C:\Windows\syswow64\sho3091.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho3AAA.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho9327.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoB4C9.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoBDE5.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoF696.tmp
~~~ Folders
Successfully deleted: [Folder] "C:\Users\S'bastien\AppData\Roaming\dll-files.com"
Successfully deleted: [Folder] "C:\Program Files (x86)\dll-files.com fixer"
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{05785C5F-5031-4C18-89D7-A96DC9523259}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{08C1C066-7373-4C1B-B73A-79401333D86E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{094192ED-2EA7-4037-B39E-B27A9BAFD24E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{095BA4C7-5D64-4786-93A8-6604B2F797DD}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{09C03DD3-57F0-458F-8FD6-CBEE12767E7C}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{0A36CC85-07A9-4788-BDD3-58D95D41B793}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{0B8E268C-6EA7-46F8-846B-94612A5792D4}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{0BA076EA-0FCB-41AB-879E-3C34F5DB15FB}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{0BBAE0A7-68B4-48AE-89FA-EED4B3126699}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{10397230-D89A-4FAB-89A6-C39527AD878B}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{11968B28-CC3C-4B8A-B479-5D1C1CD2566E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{195C34BC-FD04-44FD-8821-FC44F45DDF24}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{1A1B610E-2813-4240-823D-5B220AF6EC3A}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{1AE6283D-DDF2-4F6E-AA82-7CDCCF39FF9E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{1CAABDEB-1DBF-4A29-A887-EC20FAAEE1A0}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{1CF40146-F4A1-4836-95A2-E93789446788}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{1DE6E419-4885-463A-9497-9A244A10338A}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{231F0F9F-BD19-44A9-B6AD-5564BB014A87}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{24B8F0BF-60EB-4C7A-AC2A-3CBCADA66E08}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{256290FF-4E12-4546-9E4B-586C784ECBE5}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{27264100-24A1-4024-81E0-5DB9EACB3943}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{2756245F-FC9C-4144-832F-4B92C07CFE66}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{2A893695-BF28-4F99-BB1D-14C109F5973B}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{2BADED93-B9D3-4185-807C-D1DED2A9CFC7}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{2EDF88FE-B68B-4511-B244-E0B79042B2C2}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{3097AD93-5D86-4EBF-AC93-2D009E0E52CB}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{320BDAA4-B741-4B75-BB8A-2F04D3BA7C69}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{340433DA-C142-4867-A111-E6FEE3849524}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{3605E3C4-056E-4C24-A096-411337CEFBDF}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{36237C4C-7206-4B03-BA19-9A8CAD671CD8}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{36A9A2A2-77C8-486C-8729-35ECAAD909B6}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{388A382E-4849-4AE2-9D38-B4D36C8CE83C}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{39F3EA63-3469-44C3-903C-336AAA44E8BE}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{3A6E7865-58A3-443C-B035-D2509D38C997}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{3C2C07EA-6525-49F5-8F0E-748A5FD7C107}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{3E527F18-B08B-4136-B790-F194F25F1E33}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{3E80A485-F311-4BE6-A2FF-8E0DF1015A67}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{3EE2E44E-C496-4A54-A106-97F90BA267EE}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{3FDAB8FB-3AC9-4DC7-967C-866B4EB57FE1}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{407A27C0-88C1-4646-88A5-ACB5B24D95AB}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{42070389-6D87-4788-8662-5B1B695C9AD2}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{4303F39F-2C4C-4FE8-8C62-4B44621E8BF1}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{49733585-C2D3-4B24-A2A2-9C26D371FF41}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{4BE1C8CA-5DC1-43FA-83BE-65D70D94CE6B}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{4D3476A3-52CE-4F90-99D7-769F5EB82D2A}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{4ECBFE43-0AB6-40A8-A790-4092C4E40CA2}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{4F084E42-4836-4BE8-930B-CED99B60775F}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{4FC30947-E674-4286-9D04-8927920565CD}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{52E46D42-FBE8-47DC-9E49-A50C356C6D29}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{5306BB77-8FC1-4C63-AC70-A408E573D786}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{558EB269-887F-4385-B461-F0CE3EC47CBE}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{579BDA5E-C959-4C2A-A418-4992741A0615}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{5AC66324-A0F5-426F-BCCC-F62B757ED469}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{5C4EC279-9D23-4923-B79F-22BBDBAED7C3}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{5FE4FCD6-C780-499A-A274-2606FD80603E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{60ED2CBF-0D19-4E48-99B8-5384A2AC6192}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{612A2D66-51BE-449F-9E35-05BBE73B6C69}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{67E39669-C3B8-4938-95C9-9C1CAD710AC8}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{695CD312-41E9-4BE9-B610-8376D911A91E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{6973622E-3993-4D96-B829-3E311B4B2003}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{69D0240F-D6C0-4842-AF7D-9D3395919339}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{6AFE1133-796A-4624-9F94-3513461670C0}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{6C5B73E4-69F1-412F-A718-952354830878}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{6D11E16B-E60F-43CD-9921-EA49CFE6BFA1}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{6EA7C39D-61A3-4762-B6B1-E7DB78688CB6}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{6EC6B4FE-80A8-4216-A96A-B329E7D01588}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{717D587B-DCA8-4E1E-9276-9EF559283BBE}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{72150EFD-A86C-4162-8BFE-D346D14C8428}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{76AB4651-53C4-4F9A-8C2E-A4DA4DC17D30}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{799A6483-0D84-41ED-82E5-C2403718E6A6}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{7F1DCEF6-7A05-44FE-ADFB-996C640D7CC4}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{7F6D5773-2749-40F0-B640-50BC8D684B07}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{7FE2367D-EF39-4376-8869-679F0D33EF49}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{823ECDB7-9565-4208-8158-859160CD00DA}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{83DB9877-7D91-43C0-A34B-4F510FAEBA5D}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{859E0288-C283-4E56-A0B0-F263A1CA4066}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{8A0607FE-B532-46F9-9E86-31838766E185}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{8A13284E-FC16-4FC5-B78F-5A10BAD53DF9}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{8ADA6261-04D3-49E3-A17F-BBE1B7BB5BA5}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{9564FB14-3CA1-4270-BDEE-1C86342D1222}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{9A11EEFF-13DE-4B81-BE96-42AE07AD08E1}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{9B59B657-BD6A-4106-A14A-AA976818F7A2}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{9D599EF6-B81F-4282-A11E-66451811FB60}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{9E5C6D1C-99E7-4DED-A772-F11857810CD7}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{9F2A12B5-C190-4082-817A-D30011E85FFF}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{A09B58A3-B53E-4D48-BAF3-D05BE4AD9CAA}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{A19AB111-F16B-4696-913E-D9702A9A59BD}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{A4AC3B8C-E921-48B6-B733-C7AF7AB60542}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{A533DDB9-43C2-4530-8559-592EDB3CB0BB}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{A7259FCA-7521-4B9A-AB0D-5586A8682FC4}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{A76ADEE7-458B-4A1B-ACC5-944542E04DC7}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{A76FBDB5-CF05-4A26-9F7C-A6A99F2B46D9}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{A8CFFEAC-D6E3-46ED-923B-0BCD26C2FD07}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{AA84DED0-45A6-47DA-9E64-C7684DC74EE7}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{AB319CA5-CDA0-49C9-A9FB-C2D4859D013F}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{AE136F0B-14BA-48EC-9A73-BEA8CDD3FB62}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{AE176F10-2161-42AD-B90B-84AEDCAD1EA9}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B08D9EB0-A1D5-475D-8C47-570EC72882A4}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B1F6609C-55CC-477A-AC7C-79F7AD83DA6C}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B4238A9C-A048-49F0-B6FB-9CC8049AEFF4}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B47CF07D-3390-4092-8876-9FF227BB0424}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B536E533-08D3-4EC6-A33C-D49534666B30}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B5D74696-16CF-4414-B0C5-59246CA761D6}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B6CE6295-9263-4FB7-9852-072EAA0FD860}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B7D5B2D5-D118-418A-818C-801047AFF733}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B87A8F00-6985-4A91-9387-773DE6E87C7A}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B9303563-D7CB-4E2F-B162-25C0C96EDE7E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B95EA58E-ACD2-48E7-A95A-99FCAC93872F}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{BF77E1A8-03ED-43DA-8250-4F824963CC68}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{C628A98D-F492-4108-84CC-CC060497B045}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{C677FA8A-47D7-4268-9340-6B776A0732B2}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{C6AD5BED-66FD-40F4-B048-D12E029258F2}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{C76E1A16-20C6-4392-B220-21F9CB4CFF4B}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{CAF15881-2462-4C3A-ABAD-A10EAAD6E9AF}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{CB799981-9338-4F88-AC1F-11E5C2072A94}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{CF8F2064-6557-4810-B87C-4F65F6AB2E3F}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{D09F09D6-4735-488F-9243-B7B799601B01}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{D2F9A7C8-8F6A-4C47-9C3D-95F5AD71B255}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{D67ECED1-40D0-4187-9EF6-CECAA2694F4A}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{D8610FB8-EEFA-4FC7-AA0B-4D4A2E66917C}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{DA4F4B50-69E5-4698-A460-E3843C97A923}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{DC42F813-BE9B-4295-BCE7-2E86C707F78C}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{DE8B6C25-1AFE-4E43-BFA7-FE9A8E91390E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{E18017FC-E895-445A-86FA-99522519A8C7}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{E391E560-962A-4A2F-ABBB-E921B5F02B3D}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{E3BEFF6E-F64E-48B3-9D26-6AECC481FCAB}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{E486D539-48C4-4521-82D8-2D4B0D5C8C1A}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{EB36896E-F900-4CB8-A6AE-8BED6503499B}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{EDD726A1-9372-438F-A9F2-12E2C4F79489}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{EFC3A120-A7AC-4C8B-83AC-D31FACABCD6E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{F2427655-F82D-47EC-A8A8-2F284A64E723}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{F3397D6F-4361-4667-8A2D-123AE6D14416}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{F8BD7257-0752-46FC-A5C8-283CE3CF5D41}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{F9C33844-75EF-4C45-94EC-7139758F67CE}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{FAFE01BE-D556-4EA4-BB7A-D336513D30AD}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{FD13B1A6-A0B2-4802-B4A8-DEE54387045B}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{FD13D88F-76C8-4989-BDD3-B9DEF4F06486}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{FD52EC00-6D5E-4E73-9CDB-5DD218195FBE}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{FD6FDF8C-9094-4AF0-B0D7-AB3D95E30C02}
~~~ FireFox
Successfully deleted: [File] C:\user.js
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 10/04/2014 at 21:18:39,89
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by S'bastien on 10/04/2014 at 21:05:53,50
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1062016641-3885170610-492797851-1001\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CFC01EB9-82F4-4FC1-8922-42DC2249076F}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}
~~~ Files
Successfully deleted: [File] "C:\Program Files (x86)\adobe\reader 10.0\reader\plug_ins\babylon\babylonrpi.api"
Successfully deleted: [File] C:\Windows\syswow64\sho3091.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho3AAA.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho9327.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoB4C9.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoBDE5.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoF696.tmp
~~~ Folders
Successfully deleted: [Folder] "C:\Users\S'bastien\AppData\Roaming\dll-files.com"
Successfully deleted: [Folder] "C:\Program Files (x86)\dll-files.com fixer"
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{05785C5F-5031-4C18-89D7-A96DC9523259}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{08C1C066-7373-4C1B-B73A-79401333D86E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{094192ED-2EA7-4037-B39E-B27A9BAFD24E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{095BA4C7-5D64-4786-93A8-6604B2F797DD}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{09C03DD3-57F0-458F-8FD6-CBEE12767E7C}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{0A36CC85-07A9-4788-BDD3-58D95D41B793}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{0B8E268C-6EA7-46F8-846B-94612A5792D4}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{0BA076EA-0FCB-41AB-879E-3C34F5DB15FB}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{0BBAE0A7-68B4-48AE-89FA-EED4B3126699}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{10397230-D89A-4FAB-89A6-C39527AD878B}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{11968B28-CC3C-4B8A-B479-5D1C1CD2566E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{195C34BC-FD04-44FD-8821-FC44F45DDF24}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{1A1B610E-2813-4240-823D-5B220AF6EC3A}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{1AE6283D-DDF2-4F6E-AA82-7CDCCF39FF9E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{1CAABDEB-1DBF-4A29-A887-EC20FAAEE1A0}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{1CF40146-F4A1-4836-95A2-E93789446788}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{1DE6E419-4885-463A-9497-9A244A10338A}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{231F0F9F-BD19-44A9-B6AD-5564BB014A87}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{24B8F0BF-60EB-4C7A-AC2A-3CBCADA66E08}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{256290FF-4E12-4546-9E4B-586C784ECBE5}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{27264100-24A1-4024-81E0-5DB9EACB3943}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{2756245F-FC9C-4144-832F-4B92C07CFE66}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{2A893695-BF28-4F99-BB1D-14C109F5973B}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{2BADED93-B9D3-4185-807C-D1DED2A9CFC7}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{2EDF88FE-B68B-4511-B244-E0B79042B2C2}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{3097AD93-5D86-4EBF-AC93-2D009E0E52CB}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{320BDAA4-B741-4B75-BB8A-2F04D3BA7C69}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{340433DA-C142-4867-A111-E6FEE3849524}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{3605E3C4-056E-4C24-A096-411337CEFBDF}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{36237C4C-7206-4B03-BA19-9A8CAD671CD8}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{36A9A2A2-77C8-486C-8729-35ECAAD909B6}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{388A382E-4849-4AE2-9D38-B4D36C8CE83C}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{39F3EA63-3469-44C3-903C-336AAA44E8BE}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{3A6E7865-58A3-443C-B035-D2509D38C997}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{3C2C07EA-6525-49F5-8F0E-748A5FD7C107}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{3E527F18-B08B-4136-B790-F194F25F1E33}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{3E80A485-F311-4BE6-A2FF-8E0DF1015A67}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{3EE2E44E-C496-4A54-A106-97F90BA267EE}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{3FDAB8FB-3AC9-4DC7-967C-866B4EB57FE1}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{407A27C0-88C1-4646-88A5-ACB5B24D95AB}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{42070389-6D87-4788-8662-5B1B695C9AD2}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{4303F39F-2C4C-4FE8-8C62-4B44621E8BF1}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{49733585-C2D3-4B24-A2A2-9C26D371FF41}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{4BE1C8CA-5DC1-43FA-83BE-65D70D94CE6B}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{4D3476A3-52CE-4F90-99D7-769F5EB82D2A}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{4ECBFE43-0AB6-40A8-A790-4092C4E40CA2}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{4F084E42-4836-4BE8-930B-CED99B60775F}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{4FC30947-E674-4286-9D04-8927920565CD}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{52E46D42-FBE8-47DC-9E49-A50C356C6D29}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{5306BB77-8FC1-4C63-AC70-A408E573D786}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{558EB269-887F-4385-B461-F0CE3EC47CBE}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{579BDA5E-C959-4C2A-A418-4992741A0615}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{5AC66324-A0F5-426F-BCCC-F62B757ED469}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{5C4EC279-9D23-4923-B79F-22BBDBAED7C3}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{5FE4FCD6-C780-499A-A274-2606FD80603E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{60ED2CBF-0D19-4E48-99B8-5384A2AC6192}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{612A2D66-51BE-449F-9E35-05BBE73B6C69}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{67E39669-C3B8-4938-95C9-9C1CAD710AC8}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{695CD312-41E9-4BE9-B610-8376D911A91E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{6973622E-3993-4D96-B829-3E311B4B2003}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{69D0240F-D6C0-4842-AF7D-9D3395919339}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{6AFE1133-796A-4624-9F94-3513461670C0}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{6C5B73E4-69F1-412F-A718-952354830878}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{6D11E16B-E60F-43CD-9921-EA49CFE6BFA1}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{6EA7C39D-61A3-4762-B6B1-E7DB78688CB6}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{6EC6B4FE-80A8-4216-A96A-B329E7D01588}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{717D587B-DCA8-4E1E-9276-9EF559283BBE}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{72150EFD-A86C-4162-8BFE-D346D14C8428}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{76AB4651-53C4-4F9A-8C2E-A4DA4DC17D30}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{799A6483-0D84-41ED-82E5-C2403718E6A6}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{7F1DCEF6-7A05-44FE-ADFB-996C640D7CC4}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{7F6D5773-2749-40F0-B640-50BC8D684B07}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{7FE2367D-EF39-4376-8869-679F0D33EF49}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{823ECDB7-9565-4208-8158-859160CD00DA}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{83DB9877-7D91-43C0-A34B-4F510FAEBA5D}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{859E0288-C283-4E56-A0B0-F263A1CA4066}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{8A0607FE-B532-46F9-9E86-31838766E185}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{8A13284E-FC16-4FC5-B78F-5A10BAD53DF9}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{8ADA6261-04D3-49E3-A17F-BBE1B7BB5BA5}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{9564FB14-3CA1-4270-BDEE-1C86342D1222}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{9A11EEFF-13DE-4B81-BE96-42AE07AD08E1}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{9B59B657-BD6A-4106-A14A-AA976818F7A2}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{9D599EF6-B81F-4282-A11E-66451811FB60}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{9E5C6D1C-99E7-4DED-A772-F11857810CD7}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{9F2A12B5-C190-4082-817A-D30011E85FFF}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{A09B58A3-B53E-4D48-BAF3-D05BE4AD9CAA}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{A19AB111-F16B-4696-913E-D9702A9A59BD}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{A4AC3B8C-E921-48B6-B733-C7AF7AB60542}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{A533DDB9-43C2-4530-8559-592EDB3CB0BB}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{A7259FCA-7521-4B9A-AB0D-5586A8682FC4}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{A76ADEE7-458B-4A1B-ACC5-944542E04DC7}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{A76FBDB5-CF05-4A26-9F7C-A6A99F2B46D9}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{A8CFFEAC-D6E3-46ED-923B-0BCD26C2FD07}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{AA84DED0-45A6-47DA-9E64-C7684DC74EE7}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{AB319CA5-CDA0-49C9-A9FB-C2D4859D013F}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{AE136F0B-14BA-48EC-9A73-BEA8CDD3FB62}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{AE176F10-2161-42AD-B90B-84AEDCAD1EA9}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B08D9EB0-A1D5-475D-8C47-570EC72882A4}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B1F6609C-55CC-477A-AC7C-79F7AD83DA6C}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B4238A9C-A048-49F0-B6FB-9CC8049AEFF4}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B47CF07D-3390-4092-8876-9FF227BB0424}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B536E533-08D3-4EC6-A33C-D49534666B30}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B5D74696-16CF-4414-B0C5-59246CA761D6}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B6CE6295-9263-4FB7-9852-072EAA0FD860}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B7D5B2D5-D118-418A-818C-801047AFF733}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B87A8F00-6985-4A91-9387-773DE6E87C7A}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B9303563-D7CB-4E2F-B162-25C0C96EDE7E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{B95EA58E-ACD2-48E7-A95A-99FCAC93872F}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{BF77E1A8-03ED-43DA-8250-4F824963CC68}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{C628A98D-F492-4108-84CC-CC060497B045}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{C677FA8A-47D7-4268-9340-6B776A0732B2}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{C6AD5BED-66FD-40F4-B048-D12E029258F2}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{C76E1A16-20C6-4392-B220-21F9CB4CFF4B}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{CAF15881-2462-4C3A-ABAD-A10EAAD6E9AF}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{CB799981-9338-4F88-AC1F-11E5C2072A94}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{CF8F2064-6557-4810-B87C-4F65F6AB2E3F}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{D09F09D6-4735-488F-9243-B7B799601B01}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{D2F9A7C8-8F6A-4C47-9C3D-95F5AD71B255}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{D67ECED1-40D0-4187-9EF6-CECAA2694F4A}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{D8610FB8-EEFA-4FC7-AA0B-4D4A2E66917C}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{DA4F4B50-69E5-4698-A460-E3843C97A923}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{DC42F813-BE9B-4295-BCE7-2E86C707F78C}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{DE8B6C25-1AFE-4E43-BFA7-FE9A8E91390E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{E18017FC-E895-445A-86FA-99522519A8C7}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{E391E560-962A-4A2F-ABBB-E921B5F02B3D}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{E3BEFF6E-F64E-48B3-9D26-6AECC481FCAB}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{E486D539-48C4-4521-82D8-2D4B0D5C8C1A}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{EB36896E-F900-4CB8-A6AE-8BED6503499B}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{EDD726A1-9372-438F-A9F2-12E2C4F79489}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{EFC3A120-A7AC-4C8B-83AC-D31FACABCD6E}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{F2427655-F82D-47EC-A8A8-2F284A64E723}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{F3397D6F-4361-4667-8A2D-123AE6D14416}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{F8BD7257-0752-46FC-A5C8-283CE3CF5D41}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{F9C33844-75EF-4C45-94EC-7139758F67CE}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{FAFE01BE-D556-4EA4-BB7A-D336513D30AD}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{FD13B1A6-A0B2-4802-B4A8-DEE54387045B}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{FD13D88F-76C8-4989-BDD3-B9DEF4F06486}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{FD52EC00-6D5E-4E73-9CDB-5DD218195FBE}
Successfully deleted: [Empty Folder] C:\Users\S'bastien\appdata\local\{FD6FDF8C-9094-4AF0-B0D7-AB3D95E30C02}
~~~ FireFox
Successfully deleted: [File] C:\user.js
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 10/04/2014 at 21:18:39,89
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fish66
Messages postés
17505
Date d'inscription
dimanche 24 juillet 2011
Statut
Contributeur sécurité
Dernière intervention
16 juin 2021
1 318
10 avril 2014 à 22:04
10 avril 2014 à 22:04
Bonsoir,
Avant de lancer le Script de ZHPFix :
* Télécharge ZHPDiag de Nicolas Coolman à partir ce lien :
https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
* Une fois le téléchargement achevé,
* Double-clique sur l'icône pour lancer le programme. Sous Vista , Seven ou Windows 8 clic droit « exécuter en tant qu'administrateur »
* Dans la fenêtre ZHPDiag qui vient de s'ouvrir , clique sur "Configurer"
* Clique sur la loupe en bas à gauche sans signe pour lancer l'analyse.
* Clique sur OUI à la question "Voulez-vous un rapport full options"
* Laisse l'outil travailler, il peut être assez long.
* Un rapport s'ouvre. Ce rapport se trouve également sur ton bureau
* Héberge le rapport ZHPDiag.txt de ton bureau sur : FEC Upload ou : malekal.com
* Fais copier/coller le lien fourni dans ta prochaine réponse
Aide ZHPDiag :http://nicolascoolman.webs.com/tutorials.htm
Bonne soirée
Avant de lancer le Script de ZHPFix :
* Télécharge ZHPDiag de Nicolas Coolman à partir ce lien :
https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
* Une fois le téléchargement achevé,
* Double-clique sur l'icône pour lancer le programme. Sous Vista , Seven ou Windows 8 clic droit « exécuter en tant qu'administrateur »
* Dans la fenêtre ZHPDiag qui vient de s'ouvrir , clique sur "Configurer"
* Clique sur la loupe en bas à gauche sans signe pour lancer l'analyse.
* Clique sur OUI à la question "Voulez-vous un rapport full options"
* Laisse l'outil travailler, il peut être assez long.
* Un rapport s'ouvre. Ce rapport se trouve également sur ton bureau
* Héberge le rapport ZHPDiag.txt de ton bureau sur : FEC Upload ou : malekal.com
* Fais copier/coller le lien fourni dans ta prochaine réponse
Aide ZHPDiag :http://nicolascoolman.webs.com/tutorials.htm
Bonne soirée
deniro23
Messages postés
10
Date d'inscription
vendredi 21 mars 2014
Statut
Membre
Dernière intervention
18 avril 2014
11 avril 2014 à 18:02
11 avril 2014 à 18:02
https://forums-fec.be/upload/www/?a=d&i=1119236313
Fish66
Messages postés
17505
Date d'inscription
dimanche 24 juillet 2011
Statut
Contributeur sécurité
Dernière intervention
16 juin 2021
1 318
11 avril 2014 à 19:52
11 avril 2014 à 19:52
Bonsoir,
1/
Désinstalle depuis le panneau de configuration et s'il est possible :
- Logiciel: BitSaverr
- Logiciel: BrowseToSave
- Logiciel: Intelewin filter
- Logiciel: Bing Bar
2/
--> Copie tout le texte présent en gras ci-dessous (Sélectionne-le, clique droit dessus et choisis "Copier").
Script ZHPFix
EmptyPrefetch
ShortcutFix
O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM][64Bits] -- {1E03DB52-D5CB-4338-A338-E526DD4D4DB1} =>Toolbar.Bing
[HKLM\Software\Wow6432Node\KoyoteSRTB]
O69 - SBI: SearchScopes [HKCU] {CE3FB171-B68E-49F6-BB46-5D6F7BCEF26D} - (eBay) - http://rover.ebay.com =>Toolbar.eBay
O90 - PUC: "25BD30E1BC5D83343A835E62DDD4D41B" . (.Bing Bar.) -- C:\Windows\Installer\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}\icon_installer_ico =>Toolbar.Bing
SS - | Demand 01/03/2011 183560 | (BBSvc) . (.Microsoft Corporation..) - C:\Program Files (x86)\Microsoft\BingBar\BBSvc.exe
SR - | Auto 25/02/2011 249648 | (SeaPort) . (.Microsoft Corporation.) - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.exe
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}] =>Toolbar.Bing^
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}] =>Toolbar.Bing
[HKLM\Software\Classes\Installer\Features\25BD30E1BC5D83343A835E62DDD4D41B] =>Toolbar.Bing
[HKLM\Software\Classes\Installer\Products\25BD30E1BC5D83343A835E62DDD4D41B] =>Toolbar.Bing
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\25BD30E1BC5D83343A835E62DDD4D41B] =>Toolbar.Bing
[HKLM\Software\Wow6432Node\Classes\Installer\Features\25BD30E1BC5D83343A835E62DDD4D41B] =>Toolbar.Bing
[HKLM\Software\Wow6432Node\Classes\Installer\Products\25BD30E1BC5D83343A835E62DDD4D41B] =>Toolbar.Bing
[HKLM\Software\Wow6432Node\KoyoteSRTB] =>Toolbar.CoyoteSoft
G2 - GCE: Preference [User Data\Default] [dhkplhfnhceodhffomolpfigojocbpcb] Babylon Translator v.1.8 (Désactivé) =>PUP.Babylon
G2 - GCE: Preference [User Data\Default] [jcdgjdiieiljkfkdcloehkohchhpekkn] SweetIM for Facebook v.1.1.0.1 (Désactivé) =>PUP.SweetIM
G2 - GCE: Preference [User Data\Default] [leahdjjpjmnamomgpojikeapflgbmjab] cacaoweb v.1.16 (Désactivé) =>PUP.CacaoWeb
O42 - Logiciel: BitSaverr - (.BitSaver.) [HKLM][64Bits] -- {A3FC46A0-9B62-0EF3-B475-743B3A2762B1}
O42 - Logiciel: BrowseToSave - (...) [HKLM][64Bits] -- {9D08E4BC-DE07-44E0-A60B-962546EBC64A} =>Adware.Browse2Save
O42 - Logiciel: Intelewin filter - (.Intellitech.) [HKLM][64Bits] -- {5F189DF5-2D05-472B-9091-84D9848AE48B}{ef65f95a}
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}]
O43 - CFD: 18/04/2013 - 22:56:53 - [2,146] ----D C:\ProgramData\InstallMate =>PUP.Tarma
O43 - CFD: 31/01/2014 - 16:42:32 - [7,913] ----D C:\ProgramData\Intelewin filter
O61 - LFC: 08/04/2014 - 14:57:03 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cdncache-a.akamaihd.net_0.localstorage [3072] =>PUP.AkamaiHD
O61 - LFC: 08/04/2014 - 14:57:03 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cdncache-a.akamaihd.net_0.localstorage-journal [3608] =>PUP.AkamaiHD
O61 - LFC: 09/04/2014 - 14:57:01 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ad.doubleclick.net_0.localstorage [3072]
O61 - LFC: 09/04/2014 - 14:57:01 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ad.doubleclick.net_0.localstorage-journal [3608]
O61 - LFC: 10/04/2014 - 14:56:59 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_cdncache-a.akamaihd.net_0.localstorage [5120] =>PUP.AkamaiHD
O61 - LFC: 10/04/2014 - 14:56:59 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_cdncache-a.akamaihd.net_0.localstorage-journal [5672] =>PUP.AkamaiHD
O61 - LFC: 10/04/2014 - 14:57:01 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ad.turn.com_0.localstorage [3072]
O61 - LFC: 10/04/2014 - 14:57:01 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ad.turn.com_0.localstorage-journal [3608]
O61 - LFC: 10/04/2014 - 14:57:03 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cdn.turn.com_0.localstorage [3072]
O61 - LFC: 10/04/2014 - 14:57:03 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cdn.turn.com_0.localstorage-journal [3608]
O61 - LFC: 10/04/2014 - 14:57:06 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pixel.quantserve.com_0.localstorage [3072]
O61 - LFC: 10/04/2014 - 14:57:06 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pixel.quantserve.com_0.localstorage-journal [3608]
O61 - LFC: 11/04/2014 - 14:57:18 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2U446WLK\cdncache-a.akamaihd.net\items\e6a00\storage.swf\gpl.sol [1152] =>PUP.AkamaiHD
O87 - FAEL: "{6271C9AE-BFA1-4A99-893B-E4FD979AAF28}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe (.not file.) =>PUP.SweetIM
O87 - FAEL: "{5FB63DEF-F9C0-491E-BA42-20688FD7E55E}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe (.not file.) =>PUP.SweetIM
O87 - FAEL: "TCP Query User{39E759BB-1C69-47D9-A1D5-BA2AB71ECEB1}C:\users\sébastien\appdata\roaming\cacaoweb\cacaoweb.exe" |In - Private - P6 - TRUE | .(...) -- C:\users\sébastien\appdata\roaming\cacaoweb\cacaoweb.exe (.not file.) =>PUP.CacaoWeb
O87 - FAEL: "UDP Query User{8D5CEC15-BA6F-4EF4-BF68-5D0B6C144F44}C:\users\sébastien\appdata\roaming\cacaoweb\cacaoweb.exe" |In - Private - P17 - TRUE | .(...) -- C:\users\sébastien\appdata\roaming\cacaoweb\cacaoweb.exe (.not file.) =>PUP.CacaoWeb
O87 - FAEL: "TCP Query User{44C2A216-5B24-4CAF-B2D6-860BE42FB449}C:\users\sébastien\appdata\roaming\cacaoweb\cacaoweb.exe" |In - Public - P6 - TRUE | .(...) -- C:\users\sébastien\appdata\roaming\cacaoweb\cacaoweb.exe (.not file.) =>PUP.CacaoWeb
O87 - FAEL: "UDP Query User{341AB37A-E0FA-43DF-B237-BE8D09B5A2EC}C:\users\sébastien\appdata\roaming\cacaoweb\cacaoweb.exe" |In - Public - P17 - TRUE | .(...) -- C:\users\sébastien\appdata\roaming\cacaoweb\cacaoweb.exe (.not file.) =>PUP.CacaoWeb
[MD5.EDD21B7C504C7E3F36DE766B31BD3178] [WIS][08/10/2012] (.SweetIM Technologies Ltd. - SweetPacks Toolbar for Internet Explorer 4.0.) -- C:\Windows\Installer\2ea76f.msi [3304960] =>PUP.SweetIM
[MD5.3CD19859CD377AD00B30E4BEE49D374E] [WIS][08/10/2012] (.SweetIM Technologies Ltd. - Sweetpacks Communicator 1.1.) -- C:\Windows\Installer\2ea774.msi [2997248] =>PUP.SweetIM
[HKLM\Software\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb] =>PUP.Babylon^
[HKLM\Software\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn] =>PUP.SweetIM^
[HKLM\Software\Google\Chrome\Extensions\leahdjjpjmnamomgpojikeapflgbmjab] =>PUP.CacaoWeb^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9D08E4BC-DE07-44E0-A60B-962546EBC64A}] =>Adware.Browse2Save^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EB6AF8AEEB922FA4392548F13812E50B] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9EE58E3C298524145B73CBBED3CAC4D3] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375] =>PUP.Tarma
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5] =>PUP.Tarma
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12BF94BD06C95F343A77631402B9556A] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2124D8A8CF720FD44866190AF560228E] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\27A325ACED8CA4743A30127638591ADB] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\350D17402BD84234EAF7D32F08172D7C] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EE8C5F419057E1478A654868CEE60B5] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4735D908D66E1BA46B6C2D7185A12B2B] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76D8378E2DDAED3428720A631F6E3BF0] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A001B259DB7D694E818BE29B973992C] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAE2EC163C6A68A48921573E0E7E199D] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C06C6662FA5B04646829E4A460857770] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CEEB3E14ABE8270419B0FD762E18F7C6] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1B5E9A3BDB51349BF96E842C062D98] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FECBC2BC14DA6CD459BD59A041709836] =>PUP.SweetIM^
C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb =>PUP.Babylon^
C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn =>PUP.SweetIM^
C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Extensions\leahdjjpjmnamomgpojikeapflgbmjab =>PUP.CacaoWeb^
C:\ProgramData\InstallMate =>PUP.Tarma^
C:\Windows\Installer\2ea76f.msi =>PUP.SweetIM^
C:\Windows\Installer\2ea774.msi =>PUP.SweetIM^
C:\Users\Sébastien\Downloads\cacaoweb.exe =>PUP.CacaoWeb
C:\Users\Sébastien\AppData\Local\Temp\uninst1.exe =>PUP.Babylon
C:\Users\Sébastien\AppData\Local\Temp\BundleSweetIMSetup.exe =>PUP.SweetIM
C:\Users\Sébastien\AppData\Local\Temp\SIMEEIInstaller.exe =>PUP.SweetIM
C:\Users\Sébastien\AppData\Local\Temp\YontooSetup-S.exe =>Adware.Yontoo
C:\Users\Sébastien\AppData\Local\Temp\MybabylonTB.exe =>PUP.SweetIM
C:\Users\Sébastien\AppData\Local\Temp\GUninstaller.exe =>PUP.Babylon
C:\Users\Sébastien\AppData\Local\Temp\mgsqlite3.dll =>PUP.SweetIM
C:\Users\Sébastien\AppData\Local\Temp\Shortcut_setup.exe =>PUP.SweetIM
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
EmptyCLSID
EmptyFlash
EmptyTemp
=> Puis lance ZHPFix depuis le raccourci situé sur ton Bureau.
(Sous Vista/Win7/Win8, il faut cliquer droit sur le raccourci de ZHPFix et choisir Exécuter en tant qu'administrateur)
=> Une fois ZHPFix ouvert, clique sur "importer" puis sur "ok" et ensuite colle le texte dans la fenêtre, clique sur GO en bas de page et confirme par oui pour lancer le nettoyage des données
=> laisse travailler l'outil et ne touche à rien ...
=> S'il t'est demandé de redémarrer le PC pour finir le nettoyage, fais le !
Une fois terminé, un nouveau rapport s'affiche : poste le contenu de ce dernier dans ta prochaine réponse ...
Ce rapport est copié sur le bureau
( ce rapport est en outre sauvegardé dans ce dossier C:/ZHP/ZHPDIAG)
===================================
Aide :http://helper-formation.fr/entraide/viewtopic.php?f=31&t=2333
@+
1/
Désinstalle depuis le panneau de configuration et s'il est possible :
- Logiciel: BitSaverr
- Logiciel: BrowseToSave
- Logiciel: Intelewin filter
- Logiciel: Bing Bar
2/
--> Copie tout le texte présent en gras ci-dessous (Sélectionne-le, clique droit dessus et choisis "Copier").
Script ZHPFix
EmptyPrefetch
ShortcutFix
O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM][64Bits] -- {1E03DB52-D5CB-4338-A338-E526DD4D4DB1} =>Toolbar.Bing
[HKLM\Software\Wow6432Node\KoyoteSRTB]
O69 - SBI: SearchScopes [HKCU] {CE3FB171-B68E-49F6-BB46-5D6F7BCEF26D} - (eBay) - http://rover.ebay.com =>Toolbar.eBay
O90 - PUC: "25BD30E1BC5D83343A835E62DDD4D41B" . (.Bing Bar.) -- C:\Windows\Installer\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}\icon_installer_ico =>Toolbar.Bing
SS - | Demand 01/03/2011 183560 | (BBSvc) . (.Microsoft Corporation..) - C:\Program Files (x86)\Microsoft\BingBar\BBSvc.exe
SR - | Auto 25/02/2011 249648 | (SeaPort) . (.Microsoft Corporation.) - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.exe
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}] =>Toolbar.Bing^
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}] =>Toolbar.Bing
[HKLM\Software\Classes\Installer\Features\25BD30E1BC5D83343A835E62DDD4D41B] =>Toolbar.Bing
[HKLM\Software\Classes\Installer\Products\25BD30E1BC5D83343A835E62DDD4D41B] =>Toolbar.Bing
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\25BD30E1BC5D83343A835E62DDD4D41B] =>Toolbar.Bing
[HKLM\Software\Wow6432Node\Classes\Installer\Features\25BD30E1BC5D83343A835E62DDD4D41B] =>Toolbar.Bing
[HKLM\Software\Wow6432Node\Classes\Installer\Products\25BD30E1BC5D83343A835E62DDD4D41B] =>Toolbar.Bing
[HKLM\Software\Wow6432Node\KoyoteSRTB] =>Toolbar.CoyoteSoft
G2 - GCE: Preference [User Data\Default] [dhkplhfnhceodhffomolpfigojocbpcb] Babylon Translator v.1.8 (Désactivé) =>PUP.Babylon
G2 - GCE: Preference [User Data\Default] [jcdgjdiieiljkfkdcloehkohchhpekkn] SweetIM for Facebook v.1.1.0.1 (Désactivé) =>PUP.SweetIM
G2 - GCE: Preference [User Data\Default] [leahdjjpjmnamomgpojikeapflgbmjab] cacaoweb v.1.16 (Désactivé) =>PUP.CacaoWeb
O42 - Logiciel: BitSaverr - (.BitSaver.) [HKLM][64Bits] -- {A3FC46A0-9B62-0EF3-B475-743B3A2762B1}
O42 - Logiciel: BrowseToSave - (...) [HKLM][64Bits] -- {9D08E4BC-DE07-44E0-A60B-962546EBC64A} =>Adware.Browse2Save
O42 - Logiciel: Intelewin filter - (.Intellitech.) [HKLM][64Bits] -- {5F189DF5-2D05-472B-9091-84D9848AE48B}{ef65f95a}
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}]
O43 - CFD: 18/04/2013 - 22:56:53 - [2,146] ----D C:\ProgramData\InstallMate =>PUP.Tarma
O43 - CFD: 31/01/2014 - 16:42:32 - [7,913] ----D C:\ProgramData\Intelewin filter
O61 - LFC: 08/04/2014 - 14:57:03 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cdncache-a.akamaihd.net_0.localstorage [3072] =>PUP.AkamaiHD
O61 - LFC: 08/04/2014 - 14:57:03 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cdncache-a.akamaihd.net_0.localstorage-journal [3608] =>PUP.AkamaiHD
O61 - LFC: 09/04/2014 - 14:57:01 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ad.doubleclick.net_0.localstorage [3072]
O61 - LFC: 09/04/2014 - 14:57:01 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ad.doubleclick.net_0.localstorage-journal [3608]
O61 - LFC: 10/04/2014 - 14:56:59 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_cdncache-a.akamaihd.net_0.localstorage [5120] =>PUP.AkamaiHD
O61 - LFC: 10/04/2014 - 14:56:59 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_cdncache-a.akamaihd.net_0.localstorage-journal [5672] =>PUP.AkamaiHD
O61 - LFC: 10/04/2014 - 14:57:01 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ad.turn.com_0.localstorage [3072]
O61 - LFC: 10/04/2014 - 14:57:01 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ad.turn.com_0.localstorage-journal [3608]
O61 - LFC: 10/04/2014 - 14:57:03 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cdn.turn.com_0.localstorage [3072]
O61 - LFC: 10/04/2014 - 14:57:03 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cdn.turn.com_0.localstorage-journal [3608]
O61 - LFC: 10/04/2014 - 14:57:06 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pixel.quantserve.com_0.localstorage [3072]
O61 - LFC: 10/04/2014 - 14:57:06 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pixel.quantserve.com_0.localstorage-journal [3608]
O61 - LFC: 11/04/2014 - 14:57:18 ---A- . (...) -- C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\2U446WLK\cdncache-a.akamaihd.net\items\e6a00\storage.swf\gpl.sol [1152] =>PUP.AkamaiHD
O87 - FAEL: "{6271C9AE-BFA1-4A99-893B-E4FD979AAF28}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe (.not file.) =>PUP.SweetIM
O87 - FAEL: "{5FB63DEF-F9C0-491E-BA42-20688FD7E55E}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe (.not file.) =>PUP.SweetIM
O87 - FAEL: "TCP Query User{39E759BB-1C69-47D9-A1D5-BA2AB71ECEB1}C:\users\sébastien\appdata\roaming\cacaoweb\cacaoweb.exe" |In - Private - P6 - TRUE | .(...) -- C:\users\sébastien\appdata\roaming\cacaoweb\cacaoweb.exe (.not file.) =>PUP.CacaoWeb
O87 - FAEL: "UDP Query User{8D5CEC15-BA6F-4EF4-BF68-5D0B6C144F44}C:\users\sébastien\appdata\roaming\cacaoweb\cacaoweb.exe" |In - Private - P17 - TRUE | .(...) -- C:\users\sébastien\appdata\roaming\cacaoweb\cacaoweb.exe (.not file.) =>PUP.CacaoWeb
O87 - FAEL: "TCP Query User{44C2A216-5B24-4CAF-B2D6-860BE42FB449}C:\users\sébastien\appdata\roaming\cacaoweb\cacaoweb.exe" |In - Public - P6 - TRUE | .(...) -- C:\users\sébastien\appdata\roaming\cacaoweb\cacaoweb.exe (.not file.) =>PUP.CacaoWeb
O87 - FAEL: "UDP Query User{341AB37A-E0FA-43DF-B237-BE8D09B5A2EC}C:\users\sébastien\appdata\roaming\cacaoweb\cacaoweb.exe" |In - Public - P17 - TRUE | .(...) -- C:\users\sébastien\appdata\roaming\cacaoweb\cacaoweb.exe (.not file.) =>PUP.CacaoWeb
[MD5.EDD21B7C504C7E3F36DE766B31BD3178] [WIS][08/10/2012] (.SweetIM Technologies Ltd. - SweetPacks Toolbar for Internet Explorer 4.0.) -- C:\Windows\Installer\2ea76f.msi [3304960] =>PUP.SweetIM
[MD5.3CD19859CD377AD00B30E4BEE49D374E] [WIS][08/10/2012] (.SweetIM Technologies Ltd. - Sweetpacks Communicator 1.1.) -- C:\Windows\Installer\2ea774.msi [2997248] =>PUP.SweetIM
[HKLM\Software\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb] =>PUP.Babylon^
[HKLM\Software\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn] =>PUP.SweetIM^
[HKLM\Software\Google\Chrome\Extensions\leahdjjpjmnamomgpojikeapflgbmjab] =>PUP.CacaoWeb^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9D08E4BC-DE07-44E0-A60B-962546EBC64A}] =>Adware.Browse2Save^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EB6AF8AEEB922FA4392548F13812E50B] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9EE58E3C298524145B73CBBED3CAC4D3] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375] =>PUP.Tarma
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5] =>PUP.Tarma
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420] =>PUP.SweetIM
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12BF94BD06C95F343A77631402B9556A] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2124D8A8CF720FD44866190AF560228E] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\27A325ACED8CA4743A30127638591ADB] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\350D17402BD84234EAF7D32F08172D7C] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EE8C5F419057E1478A654868CEE60B5] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4735D908D66E1BA46B6C2D7185A12B2B] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76D8378E2DDAED3428720A631F6E3BF0] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A001B259DB7D694E818BE29B973992C] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAE2EC163C6A68A48921573E0E7E199D] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C06C6662FA5B04646829E4A460857770] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CEEB3E14ABE8270419B0FD762E18F7C6] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1B5E9A3BDB51349BF96E842C062D98] =>PUP.SweetIM^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FECBC2BC14DA6CD459BD59A041709836] =>PUP.SweetIM^
C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb =>PUP.Babylon^
C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn =>PUP.SweetIM^
C:\Users\Sébastien\AppData\Local\Google\Chrome\User Data\Default\Extensions\leahdjjpjmnamomgpojikeapflgbmjab =>PUP.CacaoWeb^
C:\ProgramData\InstallMate =>PUP.Tarma^
C:\Windows\Installer\2ea76f.msi =>PUP.SweetIM^
C:\Windows\Installer\2ea774.msi =>PUP.SweetIM^
C:\Users\Sébastien\Downloads\cacaoweb.exe =>PUP.CacaoWeb
C:\Users\Sébastien\AppData\Local\Temp\uninst1.exe =>PUP.Babylon
C:\Users\Sébastien\AppData\Local\Temp\BundleSweetIMSetup.exe =>PUP.SweetIM
C:\Users\Sébastien\AppData\Local\Temp\SIMEEIInstaller.exe =>PUP.SweetIM
C:\Users\Sébastien\AppData\Local\Temp\YontooSetup-S.exe =>Adware.Yontoo
C:\Users\Sébastien\AppData\Local\Temp\MybabylonTB.exe =>PUP.SweetIM
C:\Users\Sébastien\AppData\Local\Temp\GUninstaller.exe =>PUP.Babylon
C:\Users\Sébastien\AppData\Local\Temp\mgsqlite3.dll =>PUP.SweetIM
C:\Users\Sébastien\AppData\Local\Temp\Shortcut_setup.exe =>PUP.SweetIM
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
EmptyCLSID
EmptyFlash
EmptyTemp
=> Puis lance ZHPFix depuis le raccourci situé sur ton Bureau.
(Sous Vista/Win7/Win8, il faut cliquer droit sur le raccourci de ZHPFix et choisir Exécuter en tant qu'administrateur)
=> Une fois ZHPFix ouvert, clique sur "importer" puis sur "ok" et ensuite colle le texte dans la fenêtre, clique sur GO en bas de page et confirme par oui pour lancer le nettoyage des données
=> laisse travailler l'outil et ne touche à rien ...
=> S'il t'est demandé de redémarrer le PC pour finir le nettoyage, fais le !
Une fois terminé, un nouveau rapport s'affiche : poste le contenu de ce dernier dans ta prochaine réponse ...
Ce rapport est copié sur le bureau
( ce rapport est en outre sauvegardé dans ce dossier C:/ZHP/ZHPDIAG)
===================================
Aide :http://helper-formation.fr/entraide/viewtopic.php?f=31&t=2333
@+
deniro23
Messages postés
10
Date d'inscription
vendredi 21 mars 2014
Statut
Membre
Dernière intervention
18 avril 2014
12 avril 2014 à 03:31
12 avril 2014 à 03:31
Bonsoir, merci pour ton aide, voici le rapport ZHPFix:
Rapport de ZHPFix 2014.3.19.4 par Nicolas Coolman, Update du 19/03/2014
Fichier d'export Registre :
Run by Sébastien at 12/04/2014 03:28:59
High Elevated Privileges : OK
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Corbeille vidée (00mn 05s)
Dossier Prefetcher vidé
Réparation des raccourcis navigateur
========== Eléments de donnée du Registre ==========
REMPLACÉ Value NoActiveDesktopChanges : Good (0) - Bad (1)
========== Dossiers ==========
Aucun dossiers CLSID Local utilisateur vide
SUPPRIMÉS Flash Cookies (0)
SUPPRIMÉS Temporaires Windows (755)
========== Fichiers ==========
SUPPRIMÉS Flash Cookies (0) (0 octets)
SUPPRIMÉS Temporaires Windows (3921) (1 054 058 497 octets)
========== Récapitulatif ==========
1 : Eléments de donnée du Registre
3 : Dossiers
2 : Fichiers
End of clean in 01mn 11s
========== Chemin de fichier rapport ==========
C:\Users\Sébastien\AppData\Roaming\ZHP\ZHPFix[R1].txt - 12/04/2014 03:29:05 [920]
Rapport de ZHPFix 2014.3.19.4 par Nicolas Coolman, Update du 19/03/2014
Fichier d'export Registre :
Run by Sébastien at 12/04/2014 03:28:59
High Elevated Privileges : OK
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Corbeille vidée (00mn 05s)
Dossier Prefetcher vidé
Réparation des raccourcis navigateur
========== Eléments de donnée du Registre ==========
REMPLACÉ Value NoActiveDesktopChanges : Good (0) - Bad (1)
========== Dossiers ==========
Aucun dossiers CLSID Local utilisateur vide
SUPPRIMÉS Flash Cookies (0)
SUPPRIMÉS Temporaires Windows (755)
========== Fichiers ==========
SUPPRIMÉS Flash Cookies (0) (0 octets)
SUPPRIMÉS Temporaires Windows (3921) (1 054 058 497 octets)
========== Récapitulatif ==========
1 : Eléments de donnée du Registre
3 : Dossiers
2 : Fichiers
End of clean in 01mn 11s
========== Chemin de fichier rapport ==========
C:\Users\Sébastien\AppData\Roaming\ZHP\ZHPFix[R1].txt - 12/04/2014 03:29:05 [920]
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Fish66
Messages postés
17505
Date d'inscription
dimanche 24 juillet 2011
Statut
Contributeur sécurité
Dernière intervention
16 juin 2021
1 318
Modifié par Fish66 le 12/04/2014 à 15:29
Modifié par Fish66 le 12/04/2014 à 15:29
Bonjour,
1/
Avant de cliquer sur "GO" , est ce que tu as vérifié que toutes les lignes en gras sont copiées dans ZHPFix?
2/
* Télécharge MBAM et installe le selon l'emplacement par défaut
https://www.malwarebytes.com/mwb-download/
* Mets le à jour puis lance un examen "Menaces".
* A la fin du scan, clic sur "Mettre tous en quarantaine" en bas à gauche.
* Redémarre l'ordinateur si besoin.
* Après redémarrage, relance Malwarebytes.
* Vas chercher le rapport dans l'onglet "Historique".
* Clic à gauche sur l'onglet Journaux de l'application.
* Double-clic sur le journal d'examen pour l'afficher.
* En bas à gauche choisis "Copier dans le presse papier"
* colle le rapport le contenu du journal ici
=================================
Si tu as besoin d'aide tu peux voir ce tutoriel : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
@+
¤¤¤ Le meilleur remède pour tous les problèmes, c'est la patience.... ¤¤¤
1/
Avant de cliquer sur "GO" , est ce que tu as vérifié que toutes les lignes en gras sont copiées dans ZHPFix?
2/
* Télécharge MBAM et installe le selon l'emplacement par défaut
https://www.malwarebytes.com/mwb-download/
* Mets le à jour puis lance un examen "Menaces".
* A la fin du scan, clic sur "Mettre tous en quarantaine" en bas à gauche.
* Redémarre l'ordinateur si besoin.
* Après redémarrage, relance Malwarebytes.
* Vas chercher le rapport dans l'onglet "Historique".
* Clic à gauche sur l'onglet Journaux de l'application.
* Double-clic sur le journal d'examen pour l'afficher.
* En bas à gauche choisis "Copier dans le presse papier"
* colle le rapport le contenu du journal ici
=================================
Si tu as besoin d'aide tu peux voir ce tutoriel : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
@+
¤¤¤ Le meilleur remède pour tous les problèmes, c'est la patience.... ¤¤¤
deniro23
Messages postés
10
Date d'inscription
vendredi 21 mars 2014
Statut
Membre
Dernière intervention
18 avril 2014
14 avril 2014 à 19:28
14 avril 2014 à 19:28
Bonjour, voici le rapport Malwarebytes:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 14/04/2014
Scan Time: 19:15:17
Logfile:
Administrator: Yes
Version: 2.00.1.1004
Malware Database: v2014.04.14.06
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Sébastien
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 273413
Time Elapsed: 17 min, 6 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 104
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\RobboSaveR.RobboSaveR, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\RobboSaveR.RobboSaveR.6.1, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\RobboSaveR.RobboSaveR, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\RobboSaveR.RobboSaveR.6.1, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKU\S-1-5-21-1062016641-3885170610-492797851-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKU\S-1-5-21-1062016641-3885170610-492797851-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}\INPROCSERVER32, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{82007EA4-8640-1DE0-F6B7-C062D3A40543}, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{82007EA4-8640-1DE0-F6B7-C062D3A40543}, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\DDIgieSaveR.DDIgieSaveR, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\DDIgieSaveR.DDIgieSaveR.6.7, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DDIgieSaveR.DDIgieSaveR, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DDIgieSaveR.DDIgieSaveR.6.7, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{82007EA4-8640-1DE0-F6B7-C062D3A40543}, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{82007EA4-8640-1DE0-F6B7-C062D3A40543}\INPROCSERVER32, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\BitSaver.BitSaver, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\BitSaver.BitSaver.5.1, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BitSaver.BitSaver, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BitSaver.BitSaver.5.1, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKU\S-1-5-21-1062016641-3885170610-492797851-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKU\S-1-5-21-1062016641-3885170610-492797851-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}\INPROCSERVER32, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\TuobeIotAdBoloockApu.TuobeIotAdBoloockApu, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\TuobeIotAdBoloockApu.TuobeIotAdBoloockApu.2.6, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TuobeIotAdBoloockApu.TuobeIotAdBoloockApu, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TuobeIotAdBoloockApu.TuobeIotAdBoloockApu.2.6, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKU\S-1-5-21-1062016641-3885170610-492797851-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKU\S-1-5-21-1062016641-3885170610-492797851-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}\INPROCSERVER32, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{FF72A948-C601-8D37-4485-EAA304CE4D80}, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{FF72A948-C601-8D37-4485-EAA304CE4D80}, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\ShopDoropi.ShopDoropi, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\ShopDoropi.ShopDoropi.4.7, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopDoropi.ShopDoropi, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopDoropi.ShopDoropi.4.7, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{FF72A948-C601-8D37-4485-EAA304CE4D80}, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{FF72A948-C601-8D37-4485-EAA304CE4D80}\INPROCSERVER32, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{FBC322D5-407E-4854-8C0B-555B951FD8E3}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0400EBCA-042C-4000-AA89-9713FBEDB671}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0BD19251-4B4B-4B94-AB16-617106245BB7}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{44B29DDD-CF7A-454A-A275-A322A398D93F}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B2DB115C-8278-4947-9A07-57B53D1C4215}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B97FC455-DB33-431D-84DB-6F1514110BD5}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E72E9312-0367-4216-BFC7-21485FA8390B}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0400EBCA-042C-4000-AA89-9713FBEDB671}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0BD19251-4B4B-4B94-AB16-617106245BB7}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{44B29DDD-CF7A-454A-A275-A322A398D93F}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B2DB115C-8278-4947-9A07-57B53D1C4215}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B97FC455-DB33-431D-84DB-6F1514110BD5}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E72E9312-0367-4216-BFC7-21485FA8390B}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{FBC322D5-407E-4854-8C0B-555B951FD8E3}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4B62762D-AA67-4312-A5BF-91BCB7A4720A}, Quarantined, [ae90de4c710a6bcbc78bc08aeb17f50b],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\TypeLib\{105F25A9-C42F-48A6-998D-0494E8AE336A}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{506DD7C6-B05D-43CE-81FF-AA05E11DBDFD}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{6D3C9858-2674-46E1-9112-107340758481}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{79C9FA6C-352A-49BA-89BA-85077BC35DC3}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{909112FE-C4A2-4990-A499-E58867D55B15}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9BEEB5A2-8B02-465A-904D-FE5A447F59EB}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B618C19D-A418-4586-80C6-09DBDA9C748E}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B68B00A0-95B9-4162-BA45-7A1113317DA9}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{BFE45A8B-650C-4E99-A3F4-CC6A2874893B}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E413D78F-283C-45F1-9992-8EF7D55A4933}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E7C2FDF1-1635-41B4-8207-C1684B6807D7}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F9F5A267-FA5A-4CA3-8BE5-4C1EEAD01011}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4B62762D-AA67-4312-A5BF-91BCB7A4720A}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{506DD7C6-B05D-43CE-81FF-AA05E11DBDFD}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6D3C9858-2674-46E1-9112-107340758481}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{79C9FA6C-352A-49BA-89BA-85077BC35DC3}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{909112FE-C4A2-4990-A499-E58867D55B15}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9BEEB5A2-8B02-465A-904D-FE5A447F59EB}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B618C19D-A418-4586-80C6-09DBDA9C748E}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B68B00A0-95B9-4162-BA45-7A1113317DA9}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{BFE45A8B-650C-4E99-A3F4-CC6A2874893B}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E413D78F-283C-45F1-9992-8EF7D55A4933}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E7C2FDF1-1635-41B4-8207-C1684B6807D7}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F9F5A267-FA5A-4CA3-8BE5-4C1EEAD01011}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TypeLib\{105F25A9-C42F-48A6-998D-0494E8AE336A}, Quarantined, [a19d0723b5c6eb4b82d065e56e94728e],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{BE360B8B-0F10-CA89-FC84-A5EAB71A6AF8}, Quarantined, [be8088a2e596f93d52427acac63b649c],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 21
PUP.Optional.MultiPlug.A, C:\ProgramData\RooboSaver\sbbtOW4mR.x64.dll, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, C:\ProgramData\DDigiSaver\Ywuym.x64.dll, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, C:\ProgramData\BitSaverr\aL7H.x64.dll, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, C:\ProgramData\TUbEItAdBlockAp\qtcjJQO_.x64.dll, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, C:\ProgramData\TUbEItAdBlockAp\qtcjJQO_.dll, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, C:\ProgramData\ShopDropp\h.x64.dll, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MultiPlug.A, C:\ProgramData\BitSaverr\aL7H.dll, Quarantined, [5be38aa065163df9f1a3ec5831d09d63],
PUP.Optional.MultiPlug.A, C:\ProgramData\RooboSaver\sbbtOW4mR.dll, Quarantined, [f648e04a0477b97d7a1a8fb534cda35d],
PUP.Optional.MultiPlug.A, C:\ProgramData\RooboSaver\sbbtOW4mR.exe, Quarantined, [be8088a2e596f93d52427acac63b649c],
PUP.Optional.SweetIM, C:\Users\Sébastien\AppData\Roaming\ZHP\Quarantine\mgsqlite3.dll.VIR, Quarantined, [65d9a6845a2145f1997ef74edf250ff1],
PUP.Optional.SweetIM, C:\Users\Sébastien\AppData\Roaming\ZHP\Quarantine\shortcut_setup.exe.VIR, Quarantined, [49f5b278b4c730062ee9a69f60a416ea],
PUP.Optional.Conduit.A, C:\Users\Sébastien\Downloads\01net_Free_MP3_WMA_Converter.exe, Quarantined, [0a340b1f0d6e033355754301e021fd03],
PUP.Optional.Bandoo, C:\Users\Sébastien\Downloads\iLividSetup-r834-n-bc.exe, Quarantined, [64dae2482259bf77d030c44020e1d030],
PUP.Optional.Softonic, C:\Users\Sébastien\Downloads\SoftonicDownloader_pour_logomaker.exe, Quarantined, [51eda98179028babbf41936c1ce4c23e],
PUP.Optional.OpenCandy, C:\Users\Sébastien\Downloads\DTLite4461-0328.exe, Quarantined, [65d9e347e7940d29e89ea0a5a65ed12f],
PUP.Optional.AirInstaller, C:\Users\Sébastien\Downloads\setup (1).exe, Quarantined, [4af44bdfafcc6dc92feb17ff9968bb45],
PUP.BundleInstaller.VG, C:\Users\Sébastien\Downloads\setup.exe, Quarantined, [94aada50c9b2da5ce964d9aa16ea51af],
PUP.Optional.InstallCore, C:\Users\Sébastien\Downloads\BitTorrent.exe, Quarantined, [dc62d159fb80092d1a51a27fba46659b],
PUP.Optional.InstallCore, C:\Users\Sébastien\Downloads\Winrar.exe, Quarantined, [c37bf634a0db82b4bcaf8899c33d28d8],
PUP.Optional.InstallCore.A, C:\Users\Sébastien\Downloads\vegaspro12.0.394 (1).exe, Quarantined, [70ce44e67ffcd75fe7342197ec17bf41],
PUP.Optional.InstallCore.A, C:\Users\Sébastien\Downloads\vegaspro12.0.394.exe, Quarantined, [e757e9413546c175d14a0eaa25deac54],
Physical Sectors: 0
(No malicious items detected)
(end)
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 14/04/2014
Scan Time: 19:15:17
Logfile:
Administrator: Yes
Version: 2.00.1.1004
Malware Database: v2014.04.14.06
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Sébastien
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 273413
Time Elapsed: 17 min, 6 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 104
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\RobboSaveR.RobboSaveR, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\RobboSaveR.RobboSaveR.6.1, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\RobboSaveR.RobboSaveR, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\RobboSaveR.RobboSaveR.6.1, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKU\S-1-5-21-1062016641-3885170610-492797851-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKU\S-1-5-21-1062016641-3885170610-492797851-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{A46C8A57-F26F-A091-42C9-5956C1EC94E5}\INPROCSERVER32, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{82007EA4-8640-1DE0-F6B7-C062D3A40543}, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{82007EA4-8640-1DE0-F6B7-C062D3A40543}, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\DDIgieSaveR.DDIgieSaveR, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\DDIgieSaveR.DDIgieSaveR.6.7, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DDIgieSaveR.DDIgieSaveR, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DDIgieSaveR.DDIgieSaveR.6.7, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{82007EA4-8640-1DE0-F6B7-C062D3A40543}, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{82007EA4-8640-1DE0-F6B7-C062D3A40543}\INPROCSERVER32, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\BitSaver.BitSaver, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\BitSaver.BitSaver.5.1, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BitSaver.BitSaver, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BitSaver.BitSaver.5.1, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKU\S-1-5-21-1062016641-3885170610-492797851-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKU\S-1-5-21-1062016641-3885170610-492797851-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{D5FB20A9-EBF0-2D33-2DE3-40EEFDEBBB52}\INPROCSERVER32, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\TuobeIotAdBoloockApu.TuobeIotAdBoloockApu, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\TuobeIotAdBoloockApu.TuobeIotAdBoloockApu.2.6, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TuobeIotAdBoloockApu.TuobeIotAdBoloockApu, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TuobeIotAdBoloockApu.TuobeIotAdBoloockApu.2.6, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKU\S-1-5-21-1062016641-3885170610-492797851-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKU\S-1-5-21-1062016641-3885170610-492797851-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{A2313244-1B2B-B78E-E7A0-080D360FB8C8}\INPROCSERVER32, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{FF72A948-C601-8D37-4485-EAA304CE4D80}, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{FF72A948-C601-8D37-4485-EAA304CE4D80}, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\ShopDoropi.ShopDoropi, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\ShopDoropi.ShopDoropi.4.7, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopDoropi.ShopDoropi, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ShopDoropi.ShopDoropi.4.7, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{FF72A948-C601-8D37-4485-EAA304CE4D80}, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{FF72A948-C601-8D37-4485-EAA304CE4D80}\INPROCSERVER32, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{FBC322D5-407E-4854-8C0B-555B951FD8E3}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0400EBCA-042C-4000-AA89-9713FBEDB671}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0BD19251-4B4B-4B94-AB16-617106245BB7}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{44B29DDD-CF7A-454A-A275-A322A398D93F}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B2DB115C-8278-4947-9A07-57B53D1C4215}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B97FC455-DB33-431D-84DB-6F1514110BD5}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E72E9312-0367-4216-BFC7-21485FA8390B}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0400EBCA-042C-4000-AA89-9713FBEDB671}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0BD19251-4B4B-4B94-AB16-617106245BB7}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{44B29DDD-CF7A-454A-A275-A322A398D93F}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B2DB115C-8278-4947-9A07-57B53D1C4215}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B97FC455-DB33-431D-84DB-6F1514110BD5}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E72E9312-0367-4216-BFC7-21485FA8390B}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{FBC322D5-407E-4854-8C0B-555B951FD8E3}, Quarantined, [a39bd951700bf5417bbb1237808214ec],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4B62762D-AA67-4312-A5BF-91BCB7A4720A}, Quarantined, [ae90de4c710a6bcbc78bc08aeb17f50b],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\TypeLib\{105F25A9-C42F-48A6-998D-0494E8AE336A}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{506DD7C6-B05D-43CE-81FF-AA05E11DBDFD}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{6D3C9858-2674-46E1-9112-107340758481}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{79C9FA6C-352A-49BA-89BA-85077BC35DC3}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{909112FE-C4A2-4990-A499-E58867D55B15}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9BEEB5A2-8B02-465A-904D-FE5A447F59EB}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B618C19D-A418-4586-80C6-09DBDA9C748E}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B68B00A0-95B9-4162-BA45-7A1113317DA9}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{BFE45A8B-650C-4E99-A3F4-CC6A2874893B}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E413D78F-283C-45F1-9992-8EF7D55A4933}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E7C2FDF1-1635-41B4-8207-C1684B6807D7}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F9F5A267-FA5A-4CA3-8BE5-4C1EEAD01011}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4B62762D-AA67-4312-A5BF-91BCB7A4720A}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{506DD7C6-B05D-43CE-81FF-AA05E11DBDFD}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6D3C9858-2674-46E1-9112-107340758481}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{79C9FA6C-352A-49BA-89BA-85077BC35DC3}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{909112FE-C4A2-4990-A499-E58867D55B15}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9BEEB5A2-8B02-465A-904D-FE5A447F59EB}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B618C19D-A418-4586-80C6-09DBDA9C748E}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B68B00A0-95B9-4162-BA45-7A1113317DA9}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{BFE45A8B-650C-4E99-A3F4-CC6A2874893B}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E413D78F-283C-45F1-9992-8EF7D55A4933}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E7C2FDF1-1635-41B4-8207-C1684B6807D7}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F9F5A267-FA5A-4CA3-8BE5-4C1EEAD01011}, Quarantined, [c47afe2c7a01ce68ce84c783ee1438c8],
PUP.Optional.SearchGolTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TypeLib\{105F25A9-C42F-48A6-998D-0494E8AE336A}, Quarantined, [a19d0723b5c6eb4b82d065e56e94728e],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{BE360B8B-0F10-CA89-FC84-A5EAB71A6AF8}, Quarantined, [be8088a2e596f93d52427acac63b649c],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 21
PUP.Optional.MultiPlug.A, C:\ProgramData\RooboSaver\sbbtOW4mR.x64.dll, Quarantined, [1c2211195526f145cbc970d458a95fa1],
PUP.Optional.MultiPlug.A, C:\ProgramData\DDigiSaver\Ywuym.x64.dll, Quarantined, [51ed34f6c9b200369df7182c827f1ee2],
PUP.Optional.MultiPlug.A, C:\ProgramData\BitSaverr\aL7H.x64.dll, Quarantined, [1e20fd2d5427270ff1a3ee5661a08d73],
PUP.Optional.MultiPlug.A, C:\ProgramData\TUbEItAdBlockAp\qtcjJQO_.x64.dll, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, C:\ProgramData\TUbEItAdBlockAp\qtcjJQO_.dll, Quarantined, [a5995fcbdd9e67cf4a4ab19320e1e41c],
PUP.Optional.MultiPlug.A, C:\ProgramData\ShopDropp\h.x64.dll, Quarantined, [8faf36f4e59679bd9bf9dd6758a944bc],
PUP.Optional.MultiPlug.A, C:\ProgramData\BitSaverr\aL7H.dll, Quarantined, [5be38aa065163df9f1a3ec5831d09d63],
PUP.Optional.MultiPlug.A, C:\ProgramData\RooboSaver\sbbtOW4mR.dll, Quarantined, [f648e04a0477b97d7a1a8fb534cda35d],
PUP.Optional.MultiPlug.A, C:\ProgramData\RooboSaver\sbbtOW4mR.exe, Quarantined, [be8088a2e596f93d52427acac63b649c],
PUP.Optional.SweetIM, C:\Users\Sébastien\AppData\Roaming\ZHP\Quarantine\mgsqlite3.dll.VIR, Quarantined, [65d9a6845a2145f1997ef74edf250ff1],
PUP.Optional.SweetIM, C:\Users\Sébastien\AppData\Roaming\ZHP\Quarantine\shortcut_setup.exe.VIR, Quarantined, [49f5b278b4c730062ee9a69f60a416ea],
PUP.Optional.Conduit.A, C:\Users\Sébastien\Downloads\01net_Free_MP3_WMA_Converter.exe, Quarantined, [0a340b1f0d6e033355754301e021fd03],
PUP.Optional.Bandoo, C:\Users\Sébastien\Downloads\iLividSetup-r834-n-bc.exe, Quarantined, [64dae2482259bf77d030c44020e1d030],
PUP.Optional.Softonic, C:\Users\Sébastien\Downloads\SoftonicDownloader_pour_logomaker.exe, Quarantined, [51eda98179028babbf41936c1ce4c23e],
PUP.Optional.OpenCandy, C:\Users\Sébastien\Downloads\DTLite4461-0328.exe, Quarantined, [65d9e347e7940d29e89ea0a5a65ed12f],
PUP.Optional.AirInstaller, C:\Users\Sébastien\Downloads\setup (1).exe, Quarantined, [4af44bdfafcc6dc92feb17ff9968bb45],
PUP.BundleInstaller.VG, C:\Users\Sébastien\Downloads\setup.exe, Quarantined, [94aada50c9b2da5ce964d9aa16ea51af],
PUP.Optional.InstallCore, C:\Users\Sébastien\Downloads\BitTorrent.exe, Quarantined, [dc62d159fb80092d1a51a27fba46659b],
PUP.Optional.InstallCore, C:\Users\Sébastien\Downloads\Winrar.exe, Quarantined, [c37bf634a0db82b4bcaf8899c33d28d8],
PUP.Optional.InstallCore.A, C:\Users\Sébastien\Downloads\vegaspro12.0.394 (1).exe, Quarantined, [70ce44e67ffcd75fe7342197ec17bf41],
PUP.Optional.InstallCore.A, C:\Users\Sébastien\Downloads\vegaspro12.0.394.exe, Quarantined, [e757e9413546c175d14a0eaa25deac54],
Physical Sectors: 0
(No malicious items detected)
(end)
Fish66
Messages postés
17505
Date d'inscription
dimanche 24 juillet 2011
Statut
Contributeur sécurité
Dernière intervention
16 juin 2021
1 318
14 avril 2014 à 21:27
14 avril 2014 à 21:27
Bonsoir,
Lance ZHPDiag depuis le bureau
lance l'analyse et héberge le rapport. colle le lien dans ta prochaine réponse
@+
Lance ZHPDiag depuis le bureau

lance l'analyse et héberge le rapport. colle le lien dans ta prochaine réponse
@+
deniro23
Messages postés
10
Date d'inscription
vendredi 21 mars 2014
Statut
Membre
Dernière intervention
18 avril 2014
16 avril 2014 à 18:37
16 avril 2014 à 18:37
Voila la lien :)
https://forums-fec.be/upload/www/?a=d&i=4006314629
https://forums-fec.be/upload/www/?a=d&i=4006314629
Fish66
Messages postés
17505
Date d'inscription
dimanche 24 juillet 2011
Statut
Contributeur sécurité
Dernière intervention
16 juin 2021
1 318
16 avril 2014 à 21:25
16 avril 2014 à 21:25
Bonsoir,
1/
Désinstalle depuis le panneau de configuration le logiciel: Bing Bar
2/
--> Copie tout le texte présent en gras ci-dessous (Sélectionne-le, clique droit dessus et choisis "Copier").
Script ZHPFix
EmptyPrefetch
ShortcutFix
O2 - BHO: Bing Bar Helper [64Bits] - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} . (...) -- "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (.not file.) =>Toolbar.Bing
O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM][64Bits] -- {B4089055-D468-45A4-A6BA-5A138DD715FC} =>Toolbar.Bing
O90 - PUC: "5509804B864D4A546AABA531D87D51CF" . (.Bing Bar.) -- C:\Windows\Installer\{B4089055-D468-45A4-A6BA-5A138DD715FC}\icon_installer_ico =>Toolbar.Bing
SS - | Auto 21/10/2011 196176 | (BBSvc) . (.Microsoft Corporation..) - C:\Program Files (x86)\Microsoft\BingBar\BBSvc.exe =>Toolbar.Bing
SR - | Auto 13/10/2011 249648 | (BBUpdate) . (.Microsoft Corporation.) - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.exe =>Toolbar.Bing
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}] =>Toolbar.Bing^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B4089055-D468-45A4-A6BA-5A138DD715FC}] =>Toolbar.Bing^
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B4089055-D468-45A4-A6BA-5A138DD715FC}] =>Toolbar.Agent
O43 - CFD: 14/04/2014 - 19:15:27 - [0,007] ----D C:\ProgramData\BitSaverr =>PUP.BitSaver
O43 - CFD: 14/04/2014 - 19:15:27 - [0,007] ----D C:\ProgramData\RooboSaver =>PUP.RoboSaver
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32 =>PUP.AdvancedSystemProtector
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS =>PUP.AdvancedSystemProtector
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\YontooSetup-S-1FE0_RASAPI32 =>Adware.Yontoo
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\YontooSetup-S-1FE0_RASMANCS =>Adware.Yontoo
C:\ProgramData\BitSaverr =>PUP.BitSaver^
C:\ProgramData\RooboSaver =>PUP.RoboSaver^
[MD5.00000000000000000000000000000000] [APT] [RDReminder] (...) -- C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{B13005FC-176E-4296-8C61-7FFA44D69DD5}] (...) -- C:\Program Files (x86)\A Game of Thrones\Agot.exe (.not file.) [0]
EmptyCLSID
EmptyFlash
EmptyTemp
=> Puis lance ZHPFix depuis le raccourci situé sur ton Bureau.
(Sous Vista/Win7/Win8, il faut cliquer droit sur le raccourci de ZHPFix et choisir Exécuter en tant qu'administrateur)
=> Une fois ZHPFix ouvert, clique sur "importer" puis sur "ok" et ensuite colle le texte dans la fenêtre, clique sur GO en bas de page et confirme par oui pour lancer le nettoyage des données
=> laisse travailler l'outil et ne touche à rien ...
=> S'il t'est demandé de redémarrer le PC pour finir le nettoyage, fais le !
Une fois terminé, un nouveau rapport s'affiche : poste le contenu de ce dernier dans ta prochaine réponse ...
Ce rapport est copié sur le bureau
( ce rapport est en outre sauvegardé dans ce dossier C:/ZHP/ZHPDIAG)
===================================
Aide :http://helper-formation.fr/entraide/viewtopic.php?f=31&t=2333
1/
Désinstalle depuis le panneau de configuration le logiciel: Bing Bar
2/
--> Copie tout le texte présent en gras ci-dessous (Sélectionne-le, clique droit dessus et choisis "Copier").
Script ZHPFix
EmptyPrefetch
ShortcutFix
O2 - BHO: Bing Bar Helper [64Bits] - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} . (...) -- "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (.not file.) =>Toolbar.Bing
O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM][64Bits] -- {B4089055-D468-45A4-A6BA-5A138DD715FC} =>Toolbar.Bing
O90 - PUC: "5509804B864D4A546AABA531D87D51CF" . (.Bing Bar.) -- C:\Windows\Installer\{B4089055-D468-45A4-A6BA-5A138DD715FC}\icon_installer_ico =>Toolbar.Bing
SS - | Auto 21/10/2011 196176 | (BBSvc) . (.Microsoft Corporation..) - C:\Program Files (x86)\Microsoft\BingBar\BBSvc.exe =>Toolbar.Bing
SR - | Auto 13/10/2011 249648 | (BBUpdate) . (.Microsoft Corporation.) - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.exe =>Toolbar.Bing
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}] =>Toolbar.Bing^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B4089055-D468-45A4-A6BA-5A138DD715FC}] =>Toolbar.Bing^
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B4089055-D468-45A4-A6BA-5A138DD715FC}] =>Toolbar.Agent
O43 - CFD: 14/04/2014 - 19:15:27 - [0,007] ----D C:\ProgramData\BitSaverr =>PUP.BitSaver
O43 - CFD: 14/04/2014 - 19:15:27 - [0,007] ----D C:\ProgramData\RooboSaver =>PUP.RoboSaver
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32 =>PUP.AdvancedSystemProtector
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS =>PUP.AdvancedSystemProtector
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\YontooSetup-S-1FE0_RASAPI32 =>Adware.Yontoo
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\YontooSetup-S-1FE0_RASMANCS =>Adware.Yontoo
C:\ProgramData\BitSaverr =>PUP.BitSaver^
C:\ProgramData\RooboSaver =>PUP.RoboSaver^
[MD5.00000000000000000000000000000000] [APT] [RDReminder] (...) -- C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{B13005FC-176E-4296-8C61-7FFA44D69DD5}] (...) -- C:\Program Files (x86)\A Game of Thrones\Agot.exe (.not file.) [0]
EmptyCLSID
EmptyFlash
EmptyTemp
=> Puis lance ZHPFix depuis le raccourci situé sur ton Bureau.
(Sous Vista/Win7/Win8, il faut cliquer droit sur le raccourci de ZHPFix et choisir Exécuter en tant qu'administrateur)
=> Une fois ZHPFix ouvert, clique sur "importer" puis sur "ok" et ensuite colle le texte dans la fenêtre, clique sur GO en bas de page et confirme par oui pour lancer le nettoyage des données
=> laisse travailler l'outil et ne touche à rien ...
=> S'il t'est demandé de redémarrer le PC pour finir le nettoyage, fais le !
Une fois terminé, un nouveau rapport s'affiche : poste le contenu de ce dernier dans ta prochaine réponse ...
Ce rapport est copié sur le bureau
( ce rapport est en outre sauvegardé dans ce dossier C:/ZHP/ZHPDIAG)
===================================
Aide :http://helper-formation.fr/entraide/viewtopic.php?f=31&t=2333
deniro23
Messages postés
10
Date d'inscription
vendredi 21 mars 2014
Statut
Membre
Dernière intervention
18 avril 2014
18 avril 2014 à 15:31
18 avril 2014 à 15:31
Bonjour,
le rapport ZHp fix:
Rapport de ZHPFix 2014.4.13.3 par Nicolas Coolman, Update du 13/04/2014
Fichier d'export Registre :
Run by Sébastien at 18/04/2014 15:30:22
High Elevated Privileges : OK
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Corbeille vidée (00mn 06s)
Dossier Prefetcher vidé
Réparation des raccourcis navigateur
========== Clés du Registre ==========
SUPPRIMÉ: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
SUPPRIMÉ: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
SUPPRIMÉ: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\YontooSetup-S-1FE0_RASAPI32
SUPPRIMÉ: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\YontooSetup-S-1FE0_RASMANCS
========== Dossiers ==========
SUPPRIMÉ: C:\Users\Sébastien\AppData\Local\{40B54BF8-3AE5-4D91-91B6-95C7908D7BE4}
SUPPRIMÉ: C:\Users\Sébastien\AppData\Local\{B7E68AB2-EFD7-4392-99D6-741057A36478}
SUPPRIMÉ: C:\Users\Sébastien\AppData\Local\{E45C94B4-924F-4CDF-AA4C-E3311FFDA13E}
SUPPRIMÉS Flash Cookies (0)
SUPPRIMÉS Temporaires Windows (34)
========== Fichiers ==========
SUPPRIMÉS Flash Cookies (0) (0 octets)
SUPPRIMÉS Temporaires Windows (59) (97 955 009 octets)
========== Tache planifiée ==========
SUPPRIMÉ: RDReminder
SUPPRIMÉ: {B13005FC-176E-4296-8C61-7FFA44D69DD5}
========== Récapitulatif ==========
4 : Clés du Registre
5 : Dossiers
2 : Fichiers
2 : Tache planifiée
End of clean in 00mn 24s
le rapport ZHp fix:
Rapport de ZHPFix 2014.4.13.3 par Nicolas Coolman, Update du 13/04/2014
Fichier d'export Registre :
Run by Sébastien at 18/04/2014 15:30:22
High Elevated Privileges : OK
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Corbeille vidée (00mn 06s)
Dossier Prefetcher vidé
Réparation des raccourcis navigateur
========== Clés du Registre ==========
SUPPRIMÉ: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
SUPPRIMÉ: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
SUPPRIMÉ: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\YontooSetup-S-1FE0_RASAPI32
SUPPRIMÉ: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\YontooSetup-S-1FE0_RASMANCS
========== Dossiers ==========
SUPPRIMÉ: C:\Users\Sébastien\AppData\Local\{40B54BF8-3AE5-4D91-91B6-95C7908D7BE4}
SUPPRIMÉ: C:\Users\Sébastien\AppData\Local\{B7E68AB2-EFD7-4392-99D6-741057A36478}
SUPPRIMÉ: C:\Users\Sébastien\AppData\Local\{E45C94B4-924F-4CDF-AA4C-E3311FFDA13E}
SUPPRIMÉS Flash Cookies (0)
SUPPRIMÉS Temporaires Windows (34)
========== Fichiers ==========
SUPPRIMÉS Flash Cookies (0) (0 octets)
SUPPRIMÉS Temporaires Windows (59) (97 955 009 octets)
========== Tache planifiée ==========
SUPPRIMÉ: RDReminder
SUPPRIMÉ: {B13005FC-176E-4296-8C61-7FFA44D69DD5}
========== Récapitulatif ==========
4 : Clés du Registre
5 : Dossiers
2 : Fichiers
2 : Tache planifiée
End of clean in 00mn 24s
Fish66
Messages postés
17505
Date d'inscription
dimanche 24 juillet 2011
Statut
Contributeur sécurité
Dernière intervention
16 juin 2021
1 318
18 avril 2014 à 21:31
18 avril 2014 à 21:31
Bonsoir,
1/
* Désinstalle :
- Logiciel: Java 7 Update 51
- Logiciel: Java 7 Update 1
* Télécharges et enregistre ce fichier java sur le bureau de ton PC
* Exécutes le pour installer la dernière version de Java
2/
Que contient ces dossiers :
C:\ProgramData\ljgpajnbkbehapdhjnpmpbdllilocbpd
C:\ProgramData\lmhhkogodmahhfdclajdchngphjombce
C:\ProgramData\2fbe11d69e06573c
3/
Comment fonctionne ton PC maintenant?
Bonne soirée
1/
* Désinstalle :
- Logiciel: Java 7 Update 51
- Logiciel: Java 7 Update 1
* Télécharges et enregistre ce fichier java sur le bureau de ton PC
* Exécutes le pour installer la dernière version de Java
2/
Que contient ces dossiers :
C:\ProgramData\ljgpajnbkbehapdhjnpmpbdllilocbpd
C:\ProgramData\lmhhkogodmahhfdclajdchngphjombce
C:\ProgramData\2fbe11d69e06573c
3/
Comment fonctionne ton PC maintenant?
Bonne soirée