Supprimer Toolbar Yahoo

Résolu
bonobo16 Messages postés 48 Statut Membre -  
artaban7 Messages postés 2282 Statut Membre -
Bonjour, moi je suis sur Firefox mais je ne sais pas ce que c'est Toolbar Yahoo. Quand j'ai voulu faire un rapport de ZHPDiag, il m'a affiché ce message dans le récapitulatif :
https://nicolascoolman.eu =>Toolbar.Yahoo
Je pense donc que j'ai ce toolbar.
Et je ne sais pas comment l'enlever merci de votre aide.

1 réponse

  1. artaban7 Messages postés 2282 Statut Membre 90
     
    Salut,

    tu peux poster le rapport , pour que je te fasse un script?
    0
    1. bonobo16 Messages postés 48 Statut Membre
       
      Le rapport entier ou juste le récapitulatif ?
      0
    2. bonobo16 Messages postés 48 Statut Membre
       
      Voilà le récapitulatif :
      ---\\ Récapitulatif des détections trouvées sur votre station
      https://nicolascoolman.eu =>Adware.InstallCore
      https://nicolascoolman.eu =>Toolbar.Yahoo
      ~ MSI: 2 link(s) detected in 00mn 00s
      Si vous voulez le rapport entier dites le moi.
      0
    3. artaban7 Messages postés 2282 Statut Membre 90
       
      Non...... tout ! everything :)
      0
    4. bonobo16 Messages postés 48 Statut Membre
       
      ~ Rapport de ZHPDiag v2015.4.13.38 - Nicolas Coolman (13/04/2015)
      ~ Lancé par MONTRICHARD Fabien (01/05/2015 21:55:06)
      ~ Facebook : https://www.facebook.com/nicolascoolman1
      ~ Adresse du Forum https://nicolascoolman.eu
      ~ Traduit par Nicolas Coolman
      ~ Etat de la version : Nouvelle version disponible
      ~ Liste blanche : Activée par le programme
      ~ Elévation des Privilèges : OK
      ~ User Account Control (UAC): Activate by user


      ---\\ Navigateurs Internet
      MSIE: Internet Explorer v11.0.9600.17728
      MFIE: Mozilla Firefox 37.0.2 (Defaut)
      GCIE: Google Chrome v42.0.2311.135

      ---\\ Informations sur les produits Windows
      ~ Langage: Français
      Windows Server License Manager Script : OK

      ---\\ Logiciels de protection du système
      Avast Free Antivirus v10.2.2218
      Windows Defender W8 (Deactivate)

      ---\\ Logiciels d'optimisation du système
      CCleaner v5.04

      ---\\ Logiciels de partage PeerToPeer

      ---\\ Surveillance de Logiciels
      Adobe Flash Player 17 NPAPI

      ---\\ Informations sur le système
      ~ Processor: Intel64 Family 6 Model 42 Stepping 7, GenuineIntel
      ~ Operating System: 64 Bits
      Boot mode: Normal (Normal boot)
      Total RAM: 3986 MB (55% free)
      System Restore: Activé (Enable)
      System drive C: has 565 GB (83%) free of 677 GB

      ---\\ Mode de connexion au système
      ~ Computer Name: FABIEN
      ~ User Name: MONTRICHARD Fabien
      ~ All Users Names: MONTRICHARD Fabien, HomeGroupUser$, Administrateur,
      ~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
      Logged in as Administrator

      ---\\ Variables d'environnement
      ~ System Unit : C:\
      ~ %AppZHP% : C:\Users\MONTRICHARD Fabien\AppData\Roaming\ZHP\
      ~ %AppData% : C:\Users\MONTRICHARD Fabien\AppData\Roaming\
      ~ %Desktop% : C:\Users\MONTRICHARD Fabien\Desktop\
      ~ %Favorites% : C:\Users\MONTRICHARD Fabien\Favorites\
      ~ %LocalAppData% : C:\Users\MONTRICHARD Fabien\AppData\Local\
      ~ %StartMenu% : C:\Users\MONTRICHARD Fabien\AppData\Roaming\Microsoft\Windows\Start Menu\
      ~ %Windir% : C:\Windows\
      ~ %System% : C:\Windows\System32\

      ---\\ Enumération des unités disques
      C: Hard drive, Flash drive, Thumb drive (Free 565 Go of 677 Go)
      D: Hard drive, Flash drive, Thumb drive (Free 3 Go of 21 Go)
      E: CD-ROM drive (Not Inserted)



      ---\\ Etat du Centre de Sécurité Windows
      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
      ~ Security Center: 41 Legitimates Filtered in 00mn 00s



      ---\\ Recherche particulière de fichiers génériques
      [MD5.C10A66189DC8C090E7C84873EDCEBC88] - (.Microsoft Corporation - Explorateur Windows.) (.28/01/2015 - 00:47:12.) -- C:\Windows\Explorer.exe [2501368]
      [MD5.A570A64292214C43E0BA50E6A72A6380] - (.Microsoft Corporation - Application de démarrage de Windows.) (.29/10/2014 - 02:25:54.) -- C:\Windows\System32\Wininit.exe [145920]
      [MD5.77B35D0FC22A2D2EAC8D07C3F9784DBF] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.13/03/2015 - 03:45:57.) -- C:\Windows\System32\wininet.dll [2358784]
      [MD5.EC498BAE1F0D3E0E401C963F8D76C437] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.29/10/2014 - 02:22:52.) -- C:\Windows\System32\Winlogon.exe [572416]
      [MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - (.Microsoft Corporation - Bibliothèque de licences.) (.24/09/2014 - 16:34:58.) -- C:\Windows\System32\sppcomapi.dll [447488]
      [MD5.374E27295F0A9DCAA8FC96370F9BEEA5] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) (.24/09/2014 - 17:48:38.) -- C:\Windows\system32\Drivers\AFD.sys [563200]
      [MD5.74B14192CF79A72F7536B27CB8814FBD] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.22/08/2013 - 13:43:41.) -- C:\Windows\system32\Drivers\atapi.sys [26464]
      [MD5.2FA6510E33F7DEFEC03658B74101A9B9] - (.Microsoft Corporation - CD-ROM File System Driver.) (.22/08/2013 - 12:40:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [88576]
      [MD5.C6796EA22B513E3457514D92DCDB1A3D] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.22/08/2013 - 09:46:35.) -- C:\Windows\system32\Drivers\Cdrom.sys [164352]
      [MD5.A03F362C5557E238CBFA914689C77248] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.24/09/2014 - 17:03:07.) -- C:\Windows\system32\Drivers\DfsC.sys [134144]
      [MD5.D4B7ED39C7900384D9E5C1283F1E7926] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.24/09/2014 - 16:44:42.) -- C:\Windows\system32\Drivers\HDAudBus.sys [76800]
      [MD5.49EE0AE9E5B64FFBBD06D55C4984B598] - (.Microsoft Corporation - Pilote de port i8042.) (.04/11/2014 - 07:54:54.) -- C:\Windows\system32\Drivers\i8042prt.sys [108544]
      [MD5.B7342B3C58E91107F6E946A93D9D4EFD] - (.Microsoft Corporation - IP Network Address Translator.) (.24/09/2014 - 16:35:02.) -- C:\Windows\system32\Drivers\IpNat.sys [142848]
      [MD5.31233271EDE50D1BBB220F78AFA60486] - (.Microsoft Corporation - Minirdr SMB Windows NT.) (.08/10/2014 - 08:32:10.) -- C:\Windows\system32\Drivers\MRxSmb.sys [405504]
      [MD5.0217532E19A748F0E5D569307363D5FD] - (.Microsoft Corporation - MBT Transport driver.) (.22/08/2013 - 12:37:02.) -- C:\Windows\system32\Drivers\netBT.sys [282624]
      [MD5.7F68063A5A0461E02BC860CE0E6BFDDC] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.15/10/2014 - 09:32:37.) -- C:\Windows\system32\Drivers\ntfs.sys [2025792]
      [MD5.764B1121867B2D9B31C491668AC72B2B] - (.Microsoft Corporation - Pilote de port parallèle.) (.22/08/2013 - 12:40:02.) -- C:\Windows\system32\Drivers\Parport.sys [94208]
      [MD5.1BD3022FD6E450B00DE560265638FD2A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.08/11/2014 - 04:58:31.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [112640]
      [MD5.680C1DAE268B6FB67FA21B389A8B79EF] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) (.24/09/2014 - 16:03:44.) -- C:\Windows\system32\Drivers\rdpdr.sys [195584]
      [MD5.FFF28F9F6823EB1756C60F1649560BBF] - (.Microsoft Corporation - TDI Translation Driver.) (.22/08/2013 - 14:25:35.) -- C:\Windows\system32\Drivers\tdx.sys [107520]
      [MD5.64CA2B4A49A8EAF495E435623ECCE7DB] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.24/09/2014 - 16:44:42.) -- C:\Windows\system32\Drivers\volsnap.sys [310080]
      ~ Generic Processes: Scanned in 00mn 00s



      ---\\ Etat des fichiers cachés (Caché/Total)
      ~ Mes images (My Pictures) : 2/122
      ~ Mes musiques (My Musics) : 6/10
      ~ Mes Videos (My Videos) : 2/96
      ~ Mes Favoris (My Favorites) : 1/8
      ~ Mes Documents (My Documents) : 2/3034
      ~ Mon Bureau (My Desktop) : 2/13
      ~ Menu demarrer (Programs) : 1/26
      ~ Hidden Files: Scanned in 00mn 07s



      ---\\ Processus lancés
      [MD5.369A6EB70E9309CECDFAF94D1A187F54] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe [31346784] [PID.4024]
      [MD5.B7995C675014EEBE77A0BEB7AFCCFC08] - (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432] [PID.236]
      [MD5.EBAE9EE13F51F38B57D616CF4A420682] - (.Hewlett-Packard Development Company, L.P. - HP Message Service.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [580512] [PID.3456]
      [MD5.9F3655267BA37004F519ABDDB3AEE244] - (.Hewlett-Packard Development Company, L.P. - HP CoolSense.) -- C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1342008] [PID.3628]
      [MD5.31EA4BC4328BDBC50CD5CA4870F09E06] - (.Avast Software s.r.o. - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496] [PID.3596]
      [MD5.B7F55E2AE978D3D34F7876EE5D689AAE] - (.CyberLink - YouCam Mirage.) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488] [PID.3712]
      [MD5.724CB7A116F7E1A67009D751BCF86586] - (.CyberLink - CyberLink MediaLibray Service.) -- C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120] [PID.3816]
      [MD5.345B45BE09381D2011EB7F9AC11D8AC4] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [376944] [PID.2828]
      [MD5.3446EFE5B35A7478CA26932084F2E1C6] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8197120] [PID.1244]
      ~ Processes Running: Scanned in 00mn 01s



      ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
      C:\Users\MONTRICHARD Fabien\AppData\Local\Google\Chrome\User Data\Default\Preferences

      ---\\ Liste des dossiers d'extension Google Chrome
      ~ Google Lines Browser: 8 Legitimates Filtered in 00mn 00s



      ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
      R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = preserve
      ~ IE Browser: 9 Legitimates Filtered in 00mn 00s



      ---\\ Internet Explorer, Proxy Management (R5)
      R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
      R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
      R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
      R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
      R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 0
      R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
      ~ Proxy management: Scanned in 00mn 00s



      ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
      F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
      F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
      F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
      ~ Keys: Scanned in 00mn 00s



      ---\\ Hosts file redirection (O1)
      ~ Le fichier hôte est sain (The hosts file is clean) (21)
      ~ Hosts File: Scanned in 00mn 00s



      ---\\ Applications lancées au démarrage du système (O4)
      O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray64.exe
      O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.)
      O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
      O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\MONTRICHARD Fabien\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc
      O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd
      O4 - HKLM\..\Wow6432Node\Run: [CLVirtualDrive] . (.CyberLink Corp. - CyberLink Virtual Drive.) -- C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe
      O4 - HKLM\..\Wow6432Node\Run: [RemoteControl10] . (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
      O4 - HKLM\..\Wow6432Node\Run: [HP Quick Launch] . (.Hewlett-Packard Development Company, L.P. - HP Message Service.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
      O4 - HKLM\..\Wow6432Node\Run: [HP CoolSense] . (.Hewlett-Packard Development Company, L.P. - HP CoolSense.) -- C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
      O4 - HKLM\..\Wow6432Node\Run: [AvastUI.exe] . (.Avast Software s.r.o. - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
      O4 - HKUS\S-1-5-21-1261939269-2822067955-454513539-1004\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
      O4 - HKUS\S-1-5-21-1261939269-2822067955-454513539-1004\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\MONTRICHARD Fabien\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc
      O4 - HKUS\S-1-5-21-1261939269-2822067955-454513539-1004\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>.Piriform Ltd
      ~ Application: Scanned in 00mn 00s



      ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
      O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 [64Bits] - {25510184-5A38-4A99-B273-DCA8EEF6CD08} . (...) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\Resources\Icons\HP.ico
      O9 - Extra button: Skype Click to Call settings [64Bits] - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- c:\program files (x86)\skype\toolbars\internet explorer x64\icon.ico
      ~ IE Extra Buttons: Scanned in 00mn 00s



      ---\\ Modification Domaine/Adresses DNS (O17)
      O17 - HKLM\System\CCS\Services\Tcpip\..\{843BAD57-19C8-4801-B578-55B59B89A219}: DhcpNameServer = 192.168.0.254
      O17 - HKLM\System\CS1\Services\Tcpip\..\{843BAD57-19C8-4801-B578-55B59B89A219}: DhcpNameServer = 192.168.0.254
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.254
      ~ Domain: Scanned in 00mn 00s



      ---\\ Protocole additionnel (O18)
      O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
      O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
      ~ Protocole Additionnel: Scanned in 00mn 00s



      ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
      O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
      ~ Winlogon: Scanned in 00mn 00s



      ---\\ Tâches planifiées en automatique (O39)
      O39 - APT: - (..) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
      O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1102]
      O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1106]
      O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1261939269-2822067955-454513539-1004Core [1092]
      O39 - APT: - (..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1261939269-2822067955-454513539-1004UA [1144]
      ~ Scheduled Task: 20 Legitimates Filtered in 00mn 06s



      ---\\ HKCU & HKLM Software Keys
      [HKCU\Software\Clubic]
      [HKCU\Software\Kromtech]
      [HKCU\Software\ProductSetup] =>Adware.InstallCore
      [HKLM\Software\Wow6432Node\MaxPower]
      ~ Key Software: 188 Legitimates Filtered in 00mn 00s



      ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
      O43 - CFD: 01/05/2015 - 10:03:57 - [] ----D C:\Program Files (x86)\Common Files\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15
      O43 - CFD: 01/05/2015 - 10:02:52 - [] ----D C:\ProgramData\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15
      O43 - CFD: 02/03/2015 - 22:54:45 - [0] ----D C:\ProgramData\600440862
      O43 - CFD: 01/03/2015 - 17:31:28 - [] ----D C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
      O43 - CFD: 24/09/2014 - 20:10:43 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Embedded Lockdown Manager
      O43 - CFD: 30/11/2014 - 19:47:38 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos
      O43 - CFD: 30/11/2014 - 19:47:38 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools
      O43 - CFD: 30/11/2014 - 19:43:09 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection
      O43 - CFD: 30/11/2014 - 19:43:09 - [] R---D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services
      O43 - CFD: 24/09/2014 - 17:03:53 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
      O43 - CFD: 30/11/2014 - 20:59:03 - [] -SH-D C:\Users\MONTRICHARD Fabien\AppData\Local\EmieBrowserModeList
      ~ Program Folder: 146 Legitimates Filtered in 00mn 00s



      ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
      O44 - LFC:[MD5.9D17F78BB04A3EF67426AFD087660188] - 01/05/2015 - 15:03:50 ---A- . (...) -- C:\Windows\System32\ApnDatabase.xml [410017]
      O44 - LFC:[MD5.B5B4C90E9F52DA8586F1E5461AD90A5D] - 25/04/2015 - 09:06:03 ---A- . (...) -- C:\Windows\System32\Drivers\aswHwid.sys [29168]
      ~ Files: 42 Legitimates Filtered in 00mn 37s



      ---\\ Clé de registre Shell MountPoints2 (MPSK) (O51)
      O51 - MPSK:{31614fe9-da29-11e4-bea3-8434977d7ae3}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.)
      ~ Keys: Scanned in 00mn 00s



      ---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
      O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
      O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
      ~ MWPS: 18 Legitimates Filtered in 00mn 00s



      ---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
      O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
      ~ MWPE Keys: 3 Legitimates Filtered in 00mn 00s



      ---\\ Liste des pilotes du système (SDL) (O58)
      O58 - SDL:25/04/2015 - 09:06:03 ---A- . (...) -- C:\Windows\System32\Drivers\aswHwid.sys [29168] =>.ALWIL Software
      O58 - SDL:25/04/2015 - 09:06:03 ---A- . (...) -- C:\Windows\System32\Drivers\aswRvrt.sys [65736] =>.ALWIL Software
      O58 - SDL:25/04/2015 - 09:06:03 ---A- . (...) -- C:\Windows\System32\Drivers\aswVmm.sys [272248] =>.ALWIL Software
      O58 - SDL:13/08/2013 - 00:25:46 ---A- . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\Drivers\bcmfn2.sys [17624]
      O58 - SDL:22/08/2013 - 13:43:32 ---A- . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x64.) -- C:\Windows\System32\Drivers\stexstor.sys [31072]
      O58 - SDL:09/03/2015 - 20:11:17 ---A- . (.IDT, Inc. - IDT PC Audio.) -- C:\Windows\System32\Drivers\stwrt64.sys [542208]
      ~ Drivers: 56 Legitimates Filtered in 00mn 03s



      ---\\ Liste des outils de désinfection (LATC) (O63)
      O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
      ~ ADS: Scanned in 00mn 00s



      ---\\ Associations Shell Spawning (O67)
      O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Not Key.)
      ~ FASS Keys: 11 Legitimates Filtered in 00mn 00s



      ---\\ Menu de démarrage Internet (SMI) (O68)
      O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
      O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      O68 - StartMenuInternet: <IEXPLORE.EXE> <>[HKLM\..\Shell\open\Command] (.Not Key.)
      ~ Keys: Scanned in 00mn 00s



      ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
      O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - https://www.bing.com/?toHttps=1&redig=69DA0EF8272048D9864AF4DB37211DE8
      ~ Keys: Scanned in 00mn 00s



      ---\\ Recherche particulière à la racine du système (SPRF) (O84)
      [MD5.2E1D22AC30F4B392CEAF3D7D59BE3626] [SPRF][01/05/2015] (.Pas de propriétaire - Aut2Exe.) -- C:\Users\MONTRICHARD Fabien\Desktop\adwcleaner_4.203.exe [2204160]
      ~ Files: 1 Legitimates Filtered in 00mn 00s



      ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
      SS - | Demand 01/05/2015 268464 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
      SS - | Auto 19/04/2015 107848 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
      SS - | Demand 19/04/2015 107848 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
      SS - | Demand 16/04/2015 148080 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
      SS - | Auto 02/01/2015 315488 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
      SS - | Demand 29/10/2014 38792 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
      SR - | Auto 02/08/2012 239616 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
      SR - | Auto 25/04/2015 343336 | (avast! Antivirus) . (.Avast Software s.r.o..) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
      SR - | Auto 04/11/2013 92160 | (HP Support Assistant Service) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe =>.Hewlett-Packard Co
      SR - | Demand 13/05/2013 1129760 | (hpqwmiex) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
      SR - | Auto 10/08/2012 29600 | (hpsrv) . (.Hewlett-Packard Company.) - C:\Windows\System32\Hpservice.exe
      SR - | Auto 09/07/2012 35232 | (HPWMISVC) . (.Hewlett-Packard Development Company, L.P..) - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
      SR - | Auto 20/04/2012 635104 | (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe
      SR - | Auto 18/07/2012 128896 | (Intel(R) ME Service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
      SR - | Auto 18/07/2012 165760 | (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
      SR - | Auto 18/07/2012 276864 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
      SR - | Auto 09/03/2015 323072 | (STacSV) . (.IDT, Inc..) - C:\Program Files\IDT\WDM\STacSV64.exe
      SR - | Auto 18/07/2012 364416 | (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
      SR - | Demand 22/07/1658 0 | (WdNisSvc) . (...) - C:\Program Files (x86)\Windows Defender\NisSrv.exe
      SR - | Demand 22/07/1658 0 | (WinDefend) . (...) - C:\Program Files (x86)\Windows Defender\MsMpEng.exe
      SR - | Auto 22/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
      ~ Services: Scanned in 00mn 10s



      ---\\ Scan Additionnel (O88)
      Database Version : 13008 - (13/04/2015)
      Clés trouvées (Keys found) : 1
      Valeurs trouvées (Values found) : 0
      Dossiers trouvés (Folders found) : 0
      Fichiers trouvés (Files found) : 1

      [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}] =>Toolbar.Yahoo
      [HKCU\Software\ProductSetup] =>Adware.InstallCore^
      ~ Additionnel Scan: 269500 Items scanned in 00mn 39s



      ---\\ Informations complémentaires sur les modules
      ~ https://nicolascoolman.eu =>.Internet Explorer, Proxy Management (R5)
      ~ https://nicolascoolman.eu =>.Applications lancées au démarrage du système (O4)
      ~ https://nicolascoolman.eu =>.Clé de registre Shell MountPoints2 (MPSK) (O51)
      ~ AMI: 3 Legitimates Filtered in 00mn 00s



      ---\\ Récapitulatif des détections trouvées sur votre station
      https://nicolascoolman.eu =>Adware.InstallCore
      https://nicolascoolman.eu =>Toolbar.Yahoo
      ~ MSI: 2 link(s) detected in 00mn 00s



      ~ 594 Legitimates filtered by white list
      End of the scan (370 lines in 02mn 38s)(0.2)

      Tu me feras le script dans combien de temps ?
      0
    5. artaban7 Messages postés 2282 Statut Membre 90
       
      Arghhh , en fin tout mais avec http://pjjoint.malekal.com/ :)


      je t'invites à télécharger ZHP fix : https://nicolascoolman.eu
      tu le lances et dans la fenêtre vide du soft tu fais un copier-coller du script tel quel et en entier :

      Script ZHPFix
      FirewallRaz
      EmptyPrefetch
      EmptyTemp
      EmptyFlash
      [HKCU\Software\ProductSetup]
      [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}]
      O43 - CFD: 02/03/2015 - 22:54:45 - [0] ----D C:\ProgramData\600440862


      Ensuite tu cliques sur "go", et à la fin de l'opération, tu relances l'ordinateur...
      0