Virus pub

AL.ALEX Messages postés 16 Statut Membre -  
kingk06 Messages postés 10790 Statut Membre -
Bonsoir,

J'aimerai un petit coup de main , il y a une dizaine de joueurs , j'ai eu un problème avec un virus, j'ai dû formater mon pc . Après cela , j'ai installé kapersky , il a detecté un virus publicitaire avec un rapport a WIN32 dedans , j 'ai demandé la suppression , le logiciel a éxecuté mais le virus ne semble pas vouloir partir (c'était ce virus ci qui etait présent avant la formatation) , il m'affiche des pubs incessantes , et kapersky n'arrive pas a le stopper.

Voila tout , si quelqu'un connait la marche à suivre...

Merci par avance

3 réponses

  1. kingk06 Messages postés 10790 Statut Membre 536
     
    Bonjour,

    Avant de faire quoi que ce soit on va établir un diagnostic de ton pc pour voir quel est son degré d'infection et apporter la solution la plus appropriée pour le désinfecter.

    Scan ZHPDiag :

    Nous allons utiliser cet outil de diagnostic pour voir tous les problèmes
    </pre>

    Télécharge Nicolas Coolman) sur ton bureau ==> regarde ici comme faire

    Cliquez ensuite sur le fichier téléchargé pour exécuter l'installation du logiciel.
    Laissez vous guider lors de l'installation en laissant les réglages par défaut,

    ==> Surtout, n'oublie pas d'installer son icône sur le bureau l'icône est en forme de parchemin

    Suite à ces actions,l'outil a créé"2°"raccourcis ( ZHPFix, ZHPDiag )

    Pour exécuter une analyse complète, cliquez sur l'icône bureau "ZHPDiag" représentant un "parchemin".

    Dans l'interface du logiciel, cliquez sur le bouton "Configurer" pour accéder aux réglages.

    Cliquez ensuite sur bouton "Loupe +" en bas à gauche, pour lancer un Diagnostic Full options. ==> ICI IMAGE

    L'analyse s'effectue, patientez quelques minutes pendant le travail de l'outil indiqué par "Traitement en cours..."

    A l'issue de l'analyse qui sera indiquée dans l'interface du programme, 100%, le rapport va s'ouvrir dans le bloc note. =>

    ==>NOTE: Il faut héberger ce rapport qui se trouve sur le bureau, celui-ci étant trop long pour être posté sur le forum Pour héberger le rapport Rendez vous sur le site Cjoint=> https://www.cjoint.com/ si le premier lien ne marche pas ici=>http://pjjoint.malekal.com/

    ==> Pour t'aider a héberger le rapport<==
    https://www.commentcamarche.net/faq/29493-utiliser-cjoint-pour-heberger-des-fichiers
    ==> tutorial zhpdiag<==

    Le rapport ZHPDiag.txt sera aussi sur votre bureau. En cas de nécessité, il est sauvegardé dans C:\ZHP\ZHPDiag.txt.
    0
  2. AL.ALEX Messages postés 16 Statut Membre
     
    ~ Rapport de ZHPDiag v2014.6.4.83 - Nicolas Coolman (04/06/2014)
    ~ Lancé par ALEX (05/06/2014 11:01:31)
    ~ Adresse du Site Web https://nicolascoolman.eu
    ~ Traduit par Nicolas Coolman
    ~ Etat de la version : Version à jour.
    ~ Liste blanche : Activée par le programme
    ~ Elévation des Privilèges : OK
    ~ User Account Control (UAC): Activate by user

    ---\\ Navigateurs Internet
    MSIE: Internet Explorer v11.0.9600.17107
    GCIE: Google Chrome v35.0.1916.114 (Defaut)

    ---\\ Informations sur les produits Windows
    ~ Langage: Français
    Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)
    Windows Server License Manager Script : OK
    ~ Windows Operating System - Windows(R) 7, OEM_SLP channel
    System Locked Preinstallation (OEM_SLP) : OK
    Windows ID Activation : OK
    ~ Windows Partial Key : 3Q6C9
    Windows License : OK
    ~ Windows Remaining Initializations Number : 3
    Software Protection Service (Protection logicielle) : OK
    Windows Automatic Updates : OK
    Windows Activation Technologies : OK

    ---\\ Logiciels de protection du système
    Kaspersky PURE 3.0 v13.0.2.558
    Windows Defender W7 (Activate)

    ---\\ Logiciels d'optimisation du système

    ---\\ Logiciels de partage PeerToPeer

    ---\\ Surveillance de Logiciels
    Adobe Flash Player 13 Plugin

    ---\\ Informations sur le système
    ~ Processor: Intel64 Family 6 Model 30 Stepping 5, GenuineIntel
    ~ Operating System: 64 Bits
    Boot mode: Normal (Normal boot)
    Total RAM: 8151 MB (72% free)
    System Restore: Activé (Enable)
    System drive C: has 1336 GB (96%) free of 1386 GB

    ---\\ Mode de connexion au système
    ~ Computer Name: ALEX-PC
    ~ User Name: ALEX
    ~ All Users Names: HomeGroupUser$, ALEX, Administrateur,
    ~ Unselected Option: None
    Logged in as Administrator

    ---\\ Variables d'environnement
    ~ System Unit : C:\
    ~ %AppZHP% : C:\Users\ALEX\AppData\Roaming\ZHP\
    ~ %AppData% : C:\Users\ALEX\AppData\Roaming\
    ~ %Desktop% : C:\Users\ALEX\Desktop\
    ~ %Favorites% : C:\Users\ALEX\Favorites\
    ~ %LocalAppData% : C:\Users\ALEX\AppData\Local\
    ~ %StartMenu% : C:\Users\ALEX\AppData\Roaming\Microsoft\Windows\Start Menu\
    ~ %Windir% : C:\Windows\
    ~ %System% : C:\Windows\System32\

    ---\\ Enumération des unités disques
    C: Hard drive, Flash drive, Thumb drive (Free 1336 Go of 1386 Go)
    D: Hard drive, Flash drive, Thumb drive (Free 2 Go of 12 Go)
    E: CD-ROM drive (Free 0 Go of 0 Go)
    F: Floppy drive, Flash card reader, USB Key (Not Inserted)
    G: Floppy drive, Flash card reader, USB Key (Not Inserted)
    H: Floppy drive, Flash card reader, USB Key (Not Inserted)
    I: Floppy drive, Flash card reader, USB Key (Not Inserted)

    ---\\ Etat du Centre de Sécurité Windows
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
    ~ Security Center: 41 Legitimates Filtered in 00mn 00s

    ---\\ Recherche particulière de fichiers génériques
    [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
    [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
    [MD5.F220BA78AB542C70211D73AE4729B2CD] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.28/05/2014 - 22:15:34.) -- C:\Windows\System32\wininet.dll [2260480]
    [MD5.88AB9B72B4BF3963A0DE0820B4B0B06C] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.04/03/2014 - 10:43:50.) -- C:\Windows\System32\Winlogon.exe [455168]
    [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
    [MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/09/2013 - 02:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
    [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
    [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
    [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
    [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
    [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
    [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
    [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
    [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
    [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
    [MD5.1A29A59A4C5BA6F8C85062A613B7E2B2] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:37:55.) -- C:\Windows\system32\Drivers\ntfs.sys [1684928]
    [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
    [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
    [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
    [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
    [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
    ~ Generic Processes: Scanned in 00mn 00s

    ---\\ Etat des fichiers cachés (Caché/Total)
    ~ Mes Favoris (My Favorites) : 1/19
    ~ Mes Documents (My Documents) : 1/4
    ~ Mon Bureau (My Desktop) : 1/1449
    ~ Menu demarrer (Programs) : 1/22
    ~ Hidden Files: Scanned in 00mn 00s

    ---\\ Processus lancés
    [MD5.4FF9D0D5FEC26D9F2312A8C15CA59C8F] - (.Pas de propriétaire - Monitor LED Key.) -- C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe [53248] [PID.3780]
    [MD5.554A50B5310E702029D3A675459108FF] - (.Hewlett-Packard - hpsysdrv.) -- C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe [62768] [PID.2184]
    [MD5.4298DB2F9FE4FE4C96AC4528542680F8] - (.Hewlett-Packard - HP BATTERY INDICATOR.) -- C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe [2068992] [PID.3320]
    [MD5.47DCE3A2FE0B34DD9F01EB4037303A3E] - (.Hewlett-Packard - HP Remote Solution.) -- C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe [656896] [PID.3272]
    [MD5.852F12CA7C4FC7E3D77B606492435556] - (.Intel Corporation - IAStorIcon.) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696] [PID.2564]
    [MD5.5516C26A6AF8EB4E2CAB48EC98A74398] - (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exe [54576] [PID.3408]
    [MD5.7E91655B4947EC1B18B3BC1645839145] - (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe [356128] [PID.1680]
    [MD5.66275E52615AF9D2F18EB3442D00CFE3] - (.CyberLink - CyberLink MediaLibray Service.) -- c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [210216] [PID.4008]
    [MD5.EDCB55CF7135CCF9818EEC413FB39410] - (.Hewlett-Packard - HP LED INDICATOR.) -- C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\CNYHKEY.exe [2068992] [PID.3984]
    [MD5.1620FE36666F4BBC2314B7F360FB1965] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [860488] [PID.3680]
    [MD5.09DCCADFD2EE9A303AE95E44AFC1870F] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8023040] [PID.5976]
    [MD5.6E8E51C109CA1B3D06DFC8C4F08F23A8] - (.Cherished Technololgy LIMITED - WPM Service.) -- C:\ProgramData\WPM\wprotectmanager.exe [549008] [PID.1484] =>PUP.WpManager
    [MD5.0B7E221689F370C87F640C6D2EED7D3F] - (.Infowatch - InfoWatch CryptoStorage Protected objects c.) -- C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [818888] [PID.1796]
    [MD5.2238B91AC1A12CC6CC4C4FED41258B2A] - (.Hewlett-Packard Company - LightScribe Service.) -- c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728] [PID.1852]
    [MD5.913166BBE94B6BAA2A7824FCF5DEB64B] - (...) -- C:\Program Files (x86)\webget\updatewebget.exe [317720] [PID.1084] =>PUP.WebGet
    [MD5.913166BBE94B6BAA2A7824FCF5DEB64B] - (...) -- C:\Program Files (x86)\webget\bin\utilwebget.exe [317720] [PID.1264] =>PUP.WebGet
    [MD5.7493EA4DE41348F7D3EDBF9DB298F56A] - (.Intel Corporation - IAStorDataSvc.) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [13336] [PID.1992]
    ~ Processes Running: Scanned in 00mn 01s

    ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
    C:\Users\ALEX\AppData\Local\Google\Chrome\User Data\Default\Preferences
    G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Drive v.6.3 (Activé)
    G2 - GCE: Preference [User Data\Default] [hghkgaeecgjhjkannahfamoehjmkjail] Content Blocker v.13.0.2.614 (Désactivé)
    G2 - GCE: Preference [User Data\Default] [jagncdcchgajhfhijbbhecadmaiegcmh] Virtual Keyboard v.13.0.2.614 (Désactivé)
    G2 - GCE: Preference [User Data\Default] [mfffpogegjflfpflabcdkioaeobkgjik] GaiaAuthExtension v.0.0.1, (Activé)
    G2 - GCE: Preference [User Data\Default] [neajdppkdcdipfabeoofebfddakdcjhd] Google Network Speech v.1.0 (Activé)
    G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Wallet v.0.0.6.1 (Activé)

    ---\\ Liste des dossiers d'extension Google Chrome
    ~ Google Lines Browser: 23 Legitimates Filtered in 00mn 03s

    ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/?gws_rd=ssl =>PUP.SweetPage
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.google.com/?gws_rd=ssl =>PUP.SweetPage
    R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/?gws_rd=ssl =>PUP.SweetPage
    R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.google.com/?gws_rd=ssl =>PUP.SweetPage
    ~ IE Browser: 18 Legitimates Filtered in 00mn 00s

    ---\\ Internet Explorer, Proxy Management (R5)
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
    ~ Proxy management: Scanned in 00mn 00s

    ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
    F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
    F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
    F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
    ~ Keys: Scanned in 00mn 00s

    ---\\ Hosts file redirection (O1)
    ~ Le fichier hosts est sain (The hosts file is clean).
    ~ Hosts File: Scanned in 00mn 00s
    ~ Nombre de lignes (Lines number): 21

    ---\\ Internet Explorer Toolbars (O3)
    O3 - Toolbar\WebBrowser: (no name) - [HKCU]{21FA44EF-376D-4D53-9B0F-8A89D3229068} Clé orpheline
    ~ Toolbar: Scanned in 00mn 00s

    ---\\ Applications lancées au démarrage du système (O4)
    O4 - HKLM\..\Run: [NvCplDaemon] . (.NVIDIA Corporation - NVIDIA Display Properties Extension.) -- C:\Windows\system32\NvCpl.dll =>.NVIDIA Corporation
    O4 - HKLM\..\Run: [SmartMenu] . (.Pas de propriétaire - SmartMenu.) -- C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
    O4 - HKLM\..\Run: [PC-Doctor for Windows localizer] . (.PC-Doctor, Inc. - Hardware Diagnostic Tools Localizer.) -- C:\Program Files\PC-Doctor for Windows\localizer.exe
    O4 - HKLM\..\Wow6432Node\Run: [hpsysdrv] . (.Hewlett-Packard - hpsysdrv.) -- c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe =>.Hewlett-Packard Co
    O4 - HKLM\..\Wow6432Node\Run: [BATINDICATOR] . (.Hewlett-Packard - HP BATTERY INDICATOR.) -- C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
    O4 - HKLM\..\Wow6432Node\Run: [LaunchHPOSIAPP] . (.Hewlett-Packard - Launch a application..) -- C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\LaunchApp.exe
    O4 - HKLM\..\Wow6432Node\Run: [HP Remote Solution] . (.Hewlett-Packard - HP Remote Solution.) -- C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
    O4 - HKLM\..\Wow6432Node\Run: [IAStorIcon] . (.Intel Corporation - IAStorIcon.) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    O4 - HKLM\..\Wow6432Node\Run: [HP Software Update] . (.Hewlett-Packard - hpwuSchd Application.) -- c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe =>.Hewlett-Packard Co
    O4 - HKLM\..\Wow6432Node\Run: [AVP] . (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
    O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe =>.Microsoft Corporation
    O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe =>.Microsoft Corporation
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
    ~ Application: Scanned in 00mn 00s

    ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
    O9 - Extra button: Clavier virtuel [64Bits] - {0C4CC089-D306-440D-9772-464E226F6539} . (...) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\kbrd.ico
    O9 - Extra button: Analyse des liens [64Bits] - {CCF151D8-D089-449F-A5A4-D9909053F20F} . (...) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\logo.ico
    ~ IE Extra Buttons: Scanned in 00mn 00s

    ---\\ Modification Domaine/Adresses DNS (O17)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{40CA4970-E5EA-420C-9E4F-93E93E68525D}: DhcpNameServer = 192.168.0.254
    O17 - HKLM\System\CS1\Services\Tcpip\..\{40CA4970-E5EA-420C-9E4F-93E93E68525D}: DhcpNameServer = 192.168.0.254
    O17 - HKLM\System\CS2\Services\Tcpip\..\{40CA4970-E5EA-420C-9E4F-93E93E68525D}: DhcpNameServer = 192.168.0.254
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.254
    ~ Domain: Scanned in 00mn 00s

    ---\\ Protocole additionnel (O18)
    O18 - Handler: wlmailhtml [64Bits] - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (...) --
    O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
    ~ Protocole Additionnel: Scanned in 00mn 00s

    ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
    O20 - AppInit_DLLs: . (...) - C:\Program Files (x86)\SupTab\SEARCH~2.dll (.not file.) =>PUP.SupTab
    ~ AppInit DLL: Scanned in 00mn 00s

    ---\\ Liste des services NT non Microsoft et non désactivés (O23)
    O23 - Service: Update webget (Update webget) . (...) - C:\Program Files (x86)\webget\updatewebget.exe =>PUP.WebGet
    O23 - Service: Util webget (Util webget) . (...) - C:\Program Files (x86)\webget\bin\utilwebget.exe =>PUP.WebGet
    O23 - Service: Wpm Service (Wpm) . (.Cherished Technololgy LIMITED - WPM Service.) - C:\ProgramData\WPM\wprotectmanager.exe =>PUP.WpManager
    ~ Services: 9 Legitimates Filtered in 00mn 05s

    ---\\ Tâches planifiées en automatique (O39)
    [MD5.00000000000000000000000000000000] [APT] [Advanced System Protector] (...) -- C:\Program Files (x86)\RegClean Pro\SystweakASP.exe (.not file.) [0] =>PUP.AdvancedSystemProtector
    [MD5.00000000000000000000000000000000] [APT] [Advanced System Protector_startup] (...) -- C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe (.not file.) [0] =>PUP.AdvancedSystemProtector
    [MD5.00000000000000000000000000000000] [APT] [RegClean Pro_DEFAULT] (...) -- C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe (.not file.) [0] =>Rogue.RegistryPowerCleaner
    [MD5.00000000000000000000000000000000] [APT] [RegClean Pro_UPDATES] (...) -- C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe (.not file.) [0] =>Rogue.RegistryPowerCleaner
    O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1060]
    O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1064]
    O39 - APT: - (..) -- C:\Windows\System32\Tasks\PCDRScheduledMaintenance [544]
    ~ Scheduled Task: 19 Legitimates Filtered in 00mn 03s

    ---\\ Pilotes lancés au démarrage du système (O41)
    O41 - Driver: ({55685567-4840-4a91-962b-49a412e9485a}Gw64) . (.StdLib - StdLib.) - C:\Windows\System32\drivers\{55685567-4840-4a91-962b-49a412e9485a}Gw64.sys =>PUP.LinkiDoo
    O41 - Driver: ({9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw64) . (.StdLib - StdLib.) - C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw64.sys =>PUP.LinkiDoo
    ~ Drivers: 81 Legitimates Filtered in 00mn 00s

    ---\\ Logiciels installés (O42)
    O42 - Logiciel: WPM18.8.0.304 - (.Cherished Technololgy LIMITED.) [HKLM][64Bits] -- WPM =>PUP.WpManager
    O42 - Logiciel: webget - (.webget.) [HKLM][64Bits] -- webget =>PUP.WebGet
    ~ Logic: 42 Legitimates Filtered in 00mn 00s

    ---\\ HKCU & HKLM Software Keys
    [HKCU\Software\InstallCore] =>Adware.InstallCore
    [HKCU\Software\webget] =>PUP.WebGet
    [HKLM\Software\Wow6432Node\SupDp] =>PUP.SupTab
    [HKLM\Software\Wow6432Node\Wpm] =>PUP.WpManager
    [HKLM\Software\Wow6432Node\supTab] =>PUP.SupTab
    [HKLM\Software\Wow6432Node\supWPM] =>PUP.WpManager
    [HKLM\Software\Wow6432Node\webget] =>PUP.WebGet
    ~ Key Software: 191 Legitimates Filtered in 00mn 00s

    ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
    O43 - CFD: 24/05/2014 - 14:21:53 - [] ----D C:\Program Files (x86)\SupTab =>PUP.SupTab
    O43 - CFD: 26/05/2014 - 14:22:08 - [] ----D C:\Program Files (x86)\webget =>PUP.WebGet
    O43 - CFD: 04/06/2014 - 20:16:16 - [] ----D C:\ProgramData\IePluginServices =>Trojan.SProtector
    O43 - CFD: 24/05/2014 - 14:13:38 - [] ----D C:\ProgramData\WPM =>PUP.WpManager
    O43 - CFD: 24/05/2014 - 14:21:56 - [] ----D C:\Users\ALEX\AppData\Roaming\sweet-page =>PUP.SweetPage
    ~ Program Folder: 111 Legitimates Filtered in 00mn 00s

    ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
    O44 - LFC:[MD5.83DAD654F144A51B8F18A47B4DB15915] - 04/06/2014 - 23:30:06 ---A- . (...) -- C:\Windows\win.ini [505]
    O44 - LFC:[MD5.79D64310911A295157FA93D2AF847347] - 22/05/2014 - 17:27:42 ---A- . (.StdLib - StdLib.) -- C:\Windows\System32\Drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw64.sys [61112] =>PUP.LinkiDoo
    O44 - LFC:[MD5.44BA53A8B104257348B35A6DC4725837] - 24/05/2014 - 12:49:21 RSHA- . (...) -- C:\Windows\System32\Drivers\103C_HP_CPC_WC969AA-ABF HPE-120fr_YC_0Pavi_QCZH005_EA1WEv6PrA2_49_IIONA_SMSI_V1.0_B5.11_T100128_WUH0_L40C_M8152_J1500_7Intel_8Core i7 860_92.8_#100313_N10EC8168_Z_G10DE0603_Ohp DVD-RAM GH40L_DHWP288C_HST31500341AS.MRK [1786]
    O44 - LFC:[MD5.F60FFDD648C46198060ADFC81D015DD4] - 24/05/2014 - 13:14:54 ---A- . (.Systweak Inc., (www.systweak.com) - Regclean Pro.) -- C:\Windows\System32\roboot64.exe [20312] =>Rogue.RegistryPowerCleaner
    O44 - LFC:[MD5.C7971ACB3629E8F2D83F0278B7F6BF55] - 24/05/2014 - 13:45:09 ---A- . (...) -- C:\Windows\TSSysprep.log [3540]
    O44 - LFC:[MD5.F919DC4F0449F485D5A6C0256214FA2A] - 24/05/2014 - 13:45:14 ---A- . (...) -- C:\Windows\DtcInstall.log [2790]
    O44 - LFC:[MD5.96069A20F3858327692B53BDA2135474] - 24/05/2014 - 13:57:28 ---A- . (...) -- C:\Windows\DPINST.LOG [4268]
    O44 - LFC:[MD5.04199CA5C4A6F6E935906A74EAFCA8E7] - 26/05/2014 - 12:03:08 ---A- . (.Infowatch - Cryptographic Algorithm Lib Driver..) -- C:\Windows\System32\Drivers\CSCrySec.sys [84536]
    O44 - LFC:[MD5.7D7F90460F1309B5205BF8CDFAD63E42] - 26/05/2014 - 12:03:14 ---A- . (.Infowatch - Virtual Volume Container Driver (wnet).) -- C:\Windows\System32\Drivers\CSVirtualDiskDrv.sys [66616]
    O44 - LFC:[MD5.AA0BDD351BFCFDC9D4EB7E93B46671C5] - 26/05/2014 - 19:57:16 ---A- . (.StdLib - StdLib.) -- C:\Windows\System32\Drivers\{55685567-4840-4a91-962b-49a412e9485a}Gw64.sys [61112] =>PUP.LinkiDoo
    O44 - LFC:[MD5.DDC193B9BDC4A2E746330AF5857FF387] - 26/05/2014 - 23:36:30 ---A- . (...) -- C:\Windows\IE9_main.log [4747]
    O44 - LFC:[MD5.72B25823BC8B9E95DD477641C31A77C8] - 27/05/2014 - 09:20:06 ---A- . (...) -- C:\Windows\msxml4-KB954430-enu.LOG [296290]
    O44 - LFC:[MD5.FE9609EEC97A6CFDEAE24DE34A2364D7] - 27/05/2014 - 09:20:17 ---A- . (...) -- C:\Windows\msxml4-KB973688-enu.LOG [288352]
    O44 - LFC:[MD5.C236A8735A48B165A2A7724357DBE332] - 27/05/2014 - 13:03:35 ---A- . (...) -- C:\Windows\System32\RacRules.xml [105559]
    O44 - LFC:[MD5.5C18CD22BE4628865FCB63337A6E5EF6] - 27/05/2014 - 13:03:42 ---A- . (...) -- C:\Windows\System32\ScavengeSpace.xml [10429]
    O44 - LFC:[MD5.5EC92F0EAE3CA59F647C3CA5AA7CB053] - 27/05/2014 - 13:04:29 ---A- . (...) -- C:\Windows\System32\systemsf.ebd [347904]
    O44 - LFC:[MD5.F862CD08F1AD4EE39BD506853F3C6103] - 28/05/2014 - 22:15:34 ---A- . (...) -- C:\Windows\System32\ieuinit.inf [16284]
    O44 - LFC:[MD5.0CF75C54684230DB8C391DC2DE235356] - 28/05/2014 - 22:20:06 ---A- . (...) -- C:\Windows\IE11_main.log [14016]
    ~ Files: 1022 Legitimates Filtered in 00mn 22s

    ---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
    O45 - LFCP:[MD5.F390919318A653BE8230DD7AD9EB3194] - 04/06/2014 - 19:17:49 ---A- - C:\Windows\Prefetch\WEBGET.PURBROWSE64.EXE-47B6864B.pf =>PUP.WebGet
    ~ Prefetcher: 1 Legitimates Filtered in 00mn 00s

    ---\\ Clé de registre Shell MountPoints2 (MPKS) (O51)
    O51 - MPSK:{060597af-e341-11e3-98c8-806e6f6e6963}\AutoRun\command. (...) -- E:\Install.exe
    ~ Keys: Scanned in 00mn 10s

    ---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
    O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
    O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
    ~ MWPS: 16 Legitimates Filtered in 00mn 00s

    ---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
    O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
    ~ MWPE Keys: 4 Legitimates Filtered in 00mn 00s

    ---\\ Liste des pilotes du système (SDL) (O58)
    O58 - SDL:02/06/2011 - 13:39:44 ---A- . (.Infowatch - Cryptographic Algorithm Lib Driver..) -- C:\Windows\System32\Drivers\CSCrySec.sys [84536]
    O58 - SDL:02/06/2011 - 13:39:44 ---A- . (.Infowatch - Virtual Volume Container Driver (wnet).) -- C:\Windows\System32\Drivers\CSVirtualDiskDrv.sys [66616]
    O58 - SDL:14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
    O58 - SDL:10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
    O58 - SDL:14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
    O58 - SDL:26/05/2014 - 19:57:16 ---A- . (.StdLib - StdLib.) -- C:\Windows\System32\Drivers\{55685567-4840-4a91-962b-49a412e9485a}Gw64.sys [61112] =>PUP.LinkiDoo
    O58 - SDL:22/05/2014 - 17:27:42 ---A- . (.StdLib - StdLib.) -- C:\Windows\System32\Drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw64.sys [61112] =>PUP.LinkiDoo
    ~ Drivers: 59 Legitimates Filtered in 00mn 01s

    ---\\ Liste des outils de désinfection (LATC) (O63)
    O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
    ~ ADS: Scanned in 00mn 00s

    ---\\ Liste les services legacy du registre (LALS) (O64)
    O64 - Services: CurCS - 11/11/2013 - C:\Windows\System32\DRIVERS\kneps.sys (kneps) .(.Kaspersky Lab ZAO - KNEPS Power.) - LEGACY_KNEPS
    O64 - Services: CurCS - 10/06/2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV
    O64 - Services: CurCS - 26/05/2014 - C:\Windows\System32\drivers\{55685567-4840-4a91-962b-49a412e9485a}Gw64.sys ({55685567-4840-4a91-962b-49a412e9485a}Gw64) .(.StdLib - StdLib.) - LEGACY_{55685567-4840-4A91-962B-49A412E9485A}GW64 =>PUP.LinkiDoo
    O64 - Services: CurCS - 22/05/2014 - C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw64.sys ({9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw64) .(.StdLib - StdLib.) - LEGACY_{9EDD0EA8-2819-47C2-8320-B007D5996F8A}GW64 =>PUP.LinkiDoo
    ~ Legacy: 125 Legitimates Filtered in 00mn 00s

    ---\\ Associations Shell Spawning (O67)
    O67 - Shell Spawning: <.html> <ChromeHTML>[HKCU\..\open\Command] (.Not Key.)
    ~ FASS Keys: 11 Legitimates Filtered in 00mn 00s

    ---\\ Menu de démarrage Internet (SMI) (O68)
    O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
    ~ Keys: Scanned in 00mn 00s

    ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
    O69 - SBI: SearchScopes [HKCU] {FDE3A44D-3139-4273-B670-27BF6130ED7B} - (Bing) - https://www.bing.com/?toHttps=1&redig=69DA0EF8272048D9864AF4DB37211DE8
    ~ Keys: Scanned in 00mn 00s

    ---\\ Recherche particulière à la racine du système (SPRF) (O84)
    [MD5.C5F7F53D705A7E061A3C62019C03BE1D] [SPRF][24/05/2014] (...) -- C:\Users\ALEX\AppData\Roaming\wklnhst.dat [108]
    ~ Files: 2 Legitimates Filtered in 00mn 00s

    ---\\ Enumère les codes produits des logiciels (PUC) (O90)
    O90 - PUC: "5509804B864D4A546AABA531D87D51CF" . (.Bing Bar.) -- C:\Windows\Installer\{B4089055-D468-45A4-A6BA-5A138DD715FC}\icon_installer_ico =>Toolbar.Bing
    ~ Update Products: 1 Legitimates Filtered in 00mn 00s

    ---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
    [MD5.683EF495176EB6BF6C18BDA0A304C22E] [WIS][21/10/2011] (.Microsoft Corporation - Bing Bar.) -- C:\Windows\Installer\255a025.msi [4771840] =>Toolbar.Bing
    ~ WIS: 1 Legitimates Filtered in 00mn 01s

    ---\\ Recherche de clés de registre Tracing (O100)
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SupTab_Setup302_RASAPI32 =>PUP.SupTab
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SupTab_Setup302_RASMANCS =>PUP.SupTab
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updatewebget_RASAPI32 =>PUP.WebGet
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updatewebget_RASMANCS =>PUP.WebGet
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\utilwebget_RASAPI32 =>PUP.WebGet
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\utilwebget_RASMANCS =>PUP.WebGet
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\webget_RASAPI32 =>PUP.WebGet
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\webget_RASMANCS =>PUP.WebGet
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\webget_setup_RASAPI32 =>PUP.WebGet
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\webget_setup_RASMANCS =>PUP.WebGet
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\wpm_v18_RASAPI32 =>PUP.WpManager
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\wpm_v18_RASMANCS =>PUP.WpManager
    ~ BTK: 73 Legitimates Filtered in 00mn 00s

    ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
    SS - | Demand 24/05/2014 257712 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    SS - | Auto 21/10/2011 196176 | (BBSvc) . (.Microsoft Corporation..) - C:\Program Files (x86)\Microsoft\BingBar\BBSvc.exe =>Toolbar.Bing
    SS - | Demand 06/06/2009 250616 | (GameConsoleService) . (.WildTangent, Inc..) - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
    SS - | Auto 24/05/2014 116648 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    SS - | Demand 24/05/2014 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    SS - | Demand 17/09/2009 23536 | (PCDSRVC{F36B3A4C-F95654BD-06000000}_0) . (.PC-Doctor, Inc..) - c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms
    SR - | Auto 11/11/2013 356128 | (AVP) . (.Kaspersky Lab ZAO.) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\avp.exe
    SR - | Auto 13/10/2011 249648 | (BBUpdate) . (.Microsoft Corporation.) - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.exe =>Toolbar.Bing
    SR - | Auto 25/09/2013 818888 | (CSObjectsSrv) . (.Infowatch.) - C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe
    SR - | Auto 02/10/2009 13336 | (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    SR - | Auto 20/08/2009 73728 | (LightScribeService) . (.Hewlett-Packard Company.) - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    SR - | Auto 29/09/2009 382568 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe
    SR - | Auto 04/06/2014 317720 | (Update webget) . (...) - C:\Program Files (x86)\webget\updatewebget.exe =>PUP.WebGet
    SR - | Auto 04/06/2014 317720 | (Util webget) . (...) - C:\Program Files (x86)\webget\bin\utilwebget.exe =>PUP.WebGet
    SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
    SR - | Auto 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
    SR - | Auto 12/05/2014 549008 | (Wpm) . (.Cherished Technololgy LIMITED.) - C:\ProgramData\WPM\wprotectmanager.exe =>PUP.WpManager
    SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
    ~ Services: Scanned in 00mn 05s

    ---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
    Run by ALEX at 05/06/2014 11:03:12
    ~ OS 64 not supported by MBR tool
    ~ MBR: 0 Legitimates Filtered in 00mn 00s

    ---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
    Written by ad13, http://ad13.geekstog
    Run by ALEX at 05/06/2014 11:03:14
    ********* Dump file Name *********
    C:\PhysicalDisk0_MBR.bin
    ~ MBR: Scanned in 00mn 02s

    ---\\ Scan Additionnel (O88)
    Database Version : 13026 - (04/06/2014)
    Clés trouvées (Keys found) : 7
    Valeurs trouvées (Values found) : 0
    Dossiers trouvés (Folders found) : 5
    Fichiers trouvés (Files found) : 10

    [HKLM\SYSTEM\CurrentControlSet\Services\Update webget] =>PUP.WebGet^
    [HKLM\SYSTEM\CurrentControlSet\Services\Util webget] =>PUP.WebGet^
    [HKLM\SYSTEM\CurrentControlSet\Services\Wpm] =>PUP.WpManager^
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WPM] =>PUP.WpManager^
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\webget] =>PUP.WebGet^
    [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B4089055-D468-45A4-A6BA-5A138DD715FC}] =>Toolbar.Agent
    [HKCU\Software\InstallCore] =>Adware.InstallCore
    C:\Program Files (x86)\SupTab =>PUP.SupTab^
    C:\Program Files (x86)\webget =>PUP.WebGet^
    C:\ProgramData\IePluginServices =>Trojan.SProtector^
    C:\ProgramData\WPM =>PUP.WpManager^
    C:\Users\ALEX\AppData\Roaming\sweet-page =>PUP.SweetPage^
    C:\ProgramData\WPM\wprotectmanager.exe =>PUP.WpManager^
    C:\Program Files (x86)\webget\updatewebget.exe =>PUP.WebGet^
    C:\Program Files (x86)\webget\bin\utilwebget.exe =>PUP.WebGet^
    [HKCU\Software\webget] =>PUP.WebGet^
    [HKLM\Software\Wow6432Node\SupDp] =>PUP.SupTab^
    [HKLM\Software\Wow6432Node\Wpm] =>PUP.WpManager^
    [HKLM\Software\Wow6432Node\supTab] =>PUP.SupTab^
    [HKLM\Software\Wow6432Node\supWPM] =>PUP.WpManager^
    [HKLM\Software\Wow6432Node\webget] =>PUP.WebGet^
    C:\Windows\Installer\255a025.msi =>Toolbar.Bing^
    ~ Additionnel Scan: 254376 Items scanned in 00mn 12s

    ---\\ Informations complémentaires sur les modules
    ~ https://nicolascoolman.eu =>.Google Chrome, Extensions (G2)
    ~ https://nicolascoolman.eu =>.Internet Explorer, Proxy Management (R5)
    ~ AMI: 2 Legitimates Filtered in 00mn 00s

    ---\\ Récapitulatif des détections trouvées sur votre station
    https://nicolascoolman.eu =>PUP.WpManager
    https://nicolascoolman.eu =>PUP.WebGet
    https://nicolascoolman.eu =>PUP.SweetPage
    https://nicolascoolman.eu =>PUP.SupTab
    https://nicolascoolman.eu =>PUP.AdvancedSystemProtector
    https://nicolascoolman.eu =>Rogue.RegistryPowerCleaner
    https://nicolascoolman.eu =>PUP.LinkiDoo
    https://nicolascoolman.eu =>Adware.InstallCore
    https://nicolascoolman.eu =>Trojan.SProtector
    ~ MSI: 9 link(s) detected in 00mn 00s

    ~ 1692 Legitimates filtered by white list
    End of the scan (522 lines in 01mn 56s)(0)
    0
    1. AL.ALEX Messages postés 16 Statut Membre
       
      Bonjour ,

      Voilà le rapport après le scan.
      0
    2. Utilisateur anonyme
       
      Bonjour, utilise malwarebyte
      0
    3. Utilisateur anonyme
       
      et vide tes navigateur internet.
      0
  3. kingk06 Messages postés 10790 Statut Membre 536
     
    Bonjour,

    desintaller si tu peux =>

    Logiciel: WPM18.8.0.304
    Logiciel: webget


    puis:

    Il faut être vigilante sur ce que tu valide lors de l'installation de logiciels gratuits, bien lire les conditions d'utilisation et ne pas accepter tout ce qui est proposé avec (cases pré-cochées).
    Tous les rapports demandés sans aucune exception doivent être postés en lien et dans la même réponse (si il y en a plusieurs) en utilisant cet hébergeur de fichiers : https://www.cjoint.com/
    </pre>
    Procédure à suivre en entier et dans l'ordre:

    1)Télécharge AdwCleaner (de Xplode) sur ton bureau

    Double-clique sur l'icône présente sur ton bureau pour le lancer (Vista/7/8 --> Clic droit et "Exécuter en tant qu'administrateur")
    Clique sur le bouton "Scanner"

    Lorsque l'analyse est terminée, il est indiqué "En attente. Veuillez décocher les éléments...." au dessus de la barre de progression
    Clique sur le bouton Nettoyer

    Accepte le message de fermeture des applications

    Valide, après lecture, la fenêtre d'information sur les PUP/LPI
    Accepte le message de redémarrage

    Patiente durant la suppression
    Le PC va redémarrer et un rapport s'ouvrira automatiquement dans le bloc-notes après redémarrage Copie/colle son contenu dans ta prochaine réponse

    Note:Le rapport se trouve dans : C:\AdwCleaner[S1].txt
    Poste de Travail / Mon Ordinateur => Disque C => AdwCleaner[S1].txt

    ___________________________________________________________>>>

    On va utiliser un outil en complément à Adwcleaner:

    ==> 2) Télécharge ici ==>Junkware Removal Tool

    si ça marche pas lien direct ici => http://thisisudax.org/downloads/JRT.exe

    ==> (ne clique pas sur télécharger, le téléchargement va débuter automatiquement)

    ==> Enregistre-le sur ton bureau.==> regarde ici comme faire

    ==> Ferme toutes les applications en cours.

    ==> Ouvre JRT.exe et appuie sur Entrée : si tu es sous Windows Vista, 7 ou 8, ouvre-le en faisant : clic droit => Exécuter en tant qu'administrateur.

    ==> Patiente le temps que l'outil travaille : le bureau va disparaître quelques instants, c'est tout à fait normal.

    -> À la fin de l'analyse, un rapport nommé JRT.txt va s'ouvrir. Héberge-le comme ceci http://www.forum-entraide-informatique.com/support/cjoint-com-tutoriel-t2939.html et poste le lien obtenu dans ta prochaine réponse.si le premier lien ne marche pas ici => http://pjjoint.malekal.com/

    ==>Tutoriel :=> ICI JRT

    ==> Aide JRT ici <==
    ================================================

    Shortcut_Module

    3) Désactive ton antivirus sinon l'outil ne pourra pas travailler convenablement.

    => Télécharge => Télécharge Shortcut_Module

    Note : Enregistrer votre travail avant de continuer !
    => Pour Vista,Seven et Windows 8 clic droit sur Shortcut_Module.exe et Exécuter en tant qu'administrateur
    => Clic sur Nettoyer

    Note : Patiente le temps du scan
    Laisse travailler l'outil même s'il te parait bloqué

    Après le redémarrage relance l'outil et clique sur le petit R pour ouvrir le rapport , puis poste son contenu en lien
    Héberge le rapport Shortcut_Module_date_heure.txt sur https://www.cjoint.com/ puis copie/colle le lien fourni dans ta prochaine réponse sur le forum /
    0