Virus jecherche.org
J'aimerais supprimer jerecherche.org, j'ai besoin de quelqu'un pour me guider dans toutes les étapes. J'ai télécharger adwcleaner mais je ne sais pas quoi faire après.
Merci de répondre SVP.
28 réponses
Jerecherche.org est la cible à supprimer après le téléchargement d'ADWCleaner, la demande porte sur les étapes à suivre pour nettoyer le système sous Windows 7 et Safari 5.35.19. Plusieurs réponses préconisent des outils de nettoyage comme Malwarebytes et ADWCleaner, en indiquant d'exécuter les programmes en tant qu'administrateur, lancer un examen complet et supprimer les éléments détectés en quarantaine. Des conseils complémentaires suggèrent des outils de diagnostic et de suppression avancés tels que ZHPfix et ZHPdiag et invitent à partager les rapports pour vérifier l'efficacité des nettoyages et les redémarrages nécessaires. En cas de persistance de la page d'accueil, envisager d'analyser les extensions et paramètres du navigateur et de poursuivre les scans jusqu'à ce qu'aucun élément indésirable ne demeure.
-
j'ai désinstallé ooVoo Video Chat Toolbar et j'ai relancer ADWcleaner en tant qua admin et en cliquant sur "suppression" et voila le rapport :
http://pjjoint.malekal.com/files.php?id=20120403_c8u6j15s7h9
# AdwCleaner v1.504 - Rapport créé le 03/04/2012 à 10:39:40
# Mis à jour le 01/04/2012 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : abdel - ABDEL-PC
# Exécuté depuis : C:\Users\abdel\Downloads\adwcleaner.exe
# Option [Suppression]
***** [Services] *****
***** [Fichiers / Dossiers] *****
***** [H. Navipromo] *****
***** [Registre] *****
Clé Supprimée : HKCU\Software\AppDataLow\Software\Toolbar
***** [Registre (x64)] *****
***** [Navigateurs] *****
-\\ Internet Explorer v8.0.7601.17514
[OK] Le registre ne contient aucune entrée illégitime.
-\\ Mozilla Firefox v9.0.1 (fr)
Nom du profil : default
Fichier : C:\Users\abdel\AppData\Roaming\Mozilla\FireFox\Profiles\7jranqer.default\prefs.js
[OK] Le fichier ne contient aucune entrée illégitime.
-\\ Opera v11.62.1347.0
Fichier : C:\Users\abdel\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] Le fichier ne contient aucune entrée illégitime.
*************************
AdwCleaner[R1].txt - [1240 octets] - [02/04/2012 14:43:10]
AdwCleaner[R2].txt - [1300 octets] - [02/04/2012 14:45:04]
AdwCleaner[S1].txt - [1238 octets] - [02/04/2012 15:09:54]
AdwCleaner[R3].txt - [1420 octets] - [03/04/2012 10:17:01]
AdwCleaner[R4].txt - [1596 octets] - [03/04/2012 10:39:36]
AdwCleaner[S2].txt - [1348 octets] - [03/04/2012 10:39:40]
########## EOF - C:\AdwCleaner[S2].txt - [1476 octets] ########## -
ooVoo Video Chat Toolbar est désinstallé j'ai relancer ADWcleaner en tant qua admin et en cliquant sur "suppression" et voila le rapport :
http://pjjoint.malekal.com/files.php?id=20120403_c8u6j15s7h9 -
desintalle
ooVoo Video Chat Toolbar
relance ADWcleaner de la meme manière et clique cette fois sur "suppression"
Télécharge de AD-Remover sur ton Bureau.
http://security-domain.be/download/AD-Remover.html
/!\ Ferme toutes applications en cours /!\
- Double sur l'icône Ad-remover située sur ton Bureau.
-Pour vista/Seven : clique avec le bouton droit de la souris et choisis « exécuter en tant qu'administrateur »
- Sur la page, clique sur le bouton « chercher »
- Confirme lancement du scan
- Laisse travailler l'outil.
- Poste le rapport qui apparaît à la fin.
(Le rapport est sauvegardé aussi sous C:\Ad-report(Scan/clean).Txt) -
merci, enormement pour votre réponse, voila le rapport de adwcleaner exécuter en tant que admin :
http://pjjoint.malekal.com/files.php?id=20120403_f8r10e6u8e8 -
Re,
D'après ton rapport, ton PC est encore infecté par des adwares, adware qui auraent du être en grande partie nettoyer par ADWcleaner
Lances ADWcleaner
Pour cela places ton curseur le logo, fais un clic droit de la souris et choisis "Executer en tant qu'admistritateur"
Choisis Recherche et poste le rapport obtenu s'il te plait -
re,
je l'ai pas fais, dsl! j'ai cru que ce n'est pas obligatoire pour seven!
comment faire maintenant? -
Re,
Une question, lorsque tu as lancé ADWcleaner, tu as bien fait clique droit, ''Exécuter en tant qu'administrateur" ? -
re,
voici le rapport de ZHPDiag :
http://pjjoint.malekal.com/files.php?id=ZHPDiag_20120403_o10d12m12k11f8 -
Re,
En fait, je te demandais de relancer ZHP diag et de cliquer sur la loupe pour faire un diagnostic de ton PC afin que je puisse voir ce qui a été supprimer
Merci -
le seule rapport ZHP fix [R1] dans ce répertoire C:\ZHP\ZHPFix[R1].txt c'est celui là :
http://pjjoint.malekal.com/files.php?id=20120403_j9x10e9h11k6 -
Tu as reposter le rapport ZHP fix
Pour le diag, passe par http://pjjoint.malekal.com/ -
et ceci le rapport de ZHPDiag
Rapport de ZHPFix 1.12.3381 par Nicolas Coolman, Update du 08/02/2011
Fichier d'export Registre :
Run by abdel at 03/04/2012 08:41:28
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
Web site : http://nicolascoolman.skyrock.com/
========== Clé(s) du Registre ==========
ABSENT Key: CLSID BHO: {2BEFBCCE-46A6-4950-BCB5-7062EAC6C9C9}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{12D6D31C-C5BF-4C66-BF8D-D54D5BFD3D41}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{12D6D31C-C5BF-4C66-BF8D-D54D5BFD3D41}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{24CBAA7E-4C85-4B75-B101-9803391AC327}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{48ACB95E-38BE-4377-BE46-67F5B68C1A77}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{6D4630E6-2F14-4615-8FE3-26ECBC39AC2A}
ABSENT Key: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6D4630E6-2F14-4615-8FE3-26ECBC39AC2A}
ABSENT Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{723328FF-22D0-497f-9EB5-1AC919582DE1}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{723328FF-22D0-497f-9EB5-1AC919582DE1}
ABSENT Key: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{723328FF-22D0-497f-9EB5-1AC919582DE1}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{761f6a83-f007-49e4-8eac-cdb6808ef06f}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{76c45b18-a29e-43ea-aaf8-af55c2e1ae17}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{7cd74aff-3433-4e34-92e2-d98dfdb30754}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{7D21B744-838A-4208-8CEF-3D70162B053B}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{8273A950-A894-497B-B408-A19B33968243}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{83b2fe06-ba20-4f7d-96c6-6fc3a4e877d3}
ABSENT Key: HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA7406}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{96ef404c-24c7-43d0-9096-4ccc8bb7ccac}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{97720195-206a-42ae-8e65-260b9ba5589f}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{986f7a5a-9676-47e1-8642-f41f8c3fcf82}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{99379002-4781-440E-9002-EF5CEBC666FD}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{A0DFD148-D748-4C58-B8E7-396B85D62091}
ABSENT Key: HKLM\Software\Classes\TypeLib\{A36EC25F-1846-45D0-903F-A9F9B5CF0FD0}
ABSENT Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}
ABSENT Key: HKLM\Software\Classes\TypeLib\{A4D74ECD-AEF8-45EB-929C-DB36E4D00ECF}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{b18788a4-92bd-440e-a4d1-380c36531119}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{b32966a2-f7c2-4362-a6cf-399ec8b44110}
ABSENT Key: HKLM\Software\Classes\TypeLib\{B5E29133-7CC2-4174-B60E-42F51C7E7919}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{EAE5C2BC-AE3F-4C6F-A736-03DDF56FA2D9}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{F030DBBA-EFC2-4443-A1D1-0B716CE0CC78}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{F030DBBA-EFC2-4443-A1D1-0B716CE0CC78}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{f8b4ec8a-2407-4be0-aee2-0f430d65a90d}
========== Valeur(s) du Registre ==========
ABSENT AppInit: \Program Files\WI3C8A~1\Datamngr\x64\datamngr.dll
ABSENT {817A8F30-E362-432C-8F40-8EED45AFD99F}
ABSENT {70455272-D8C2-490E-B91F-9E491056F141}
========== Dossier(s) ==========
ABSENT C:\Users\abdel\AppData\Roaming\pdfforge
ABSENT C:\Users\abdel\AppData\Local\Ilivid Player
ABSENT C:\Users\abdel\AppData\Local\widestream6 Air
SUPPRIME Reboot Folder**: C:\Program Files (x86)\iLivid
SUPPRIME Temporaires Windows: : 2
SUPPRIME Flash Cookies: 9
========== Fichier(s) ==========
ABSENT File: \program files\wi3c8a~1\datamngr\x64\datamngr.dll
ABSENT Folder/File: c:\users\abdel\appdata\roaming\pdfforge
ABSENT Folder/File: c:\users\abdel\appdata\local\widestream6 air
ABSENT Folder/File: c:\users\abdel\appdata\locallow\shopperreports3
SUPPRIME Temporaires Windows: : 9
SUPPRIME Flash Cookies: 5
========== Récapitulatif ==========
32 : Clé(s) du Registre
3 : Valeur(s) du Registre
6 : Dossier(s)
6 : Fichier(s)
End of clean in 00mn 04s
========== Chemin de fichier rapport ==========
C:\ZHP\ZHPFix[R1].txt - 02/04/2012 21:34:29 [4599]
C:\ZHP\ZHPFix[R2].txt - 02/04/2012 21:35:23 [4613]
C:\ZHP\ZHPFix[R3].txt - 02/04/2012 21:35:51 [4665]
C:\ZHP\ZHPFix[R4].txt - 03/04/2012 08:41:28 [4665] -
ceci le rapport C:\ZHP\ZHPFix[R1].txt
Rapport de ZHPFix 1.12.3381 par Nicolas Coolman, Update du 08/02/2011
Fichier d'export Registre :
Run by abdel at 02/04/2012 22:34:29
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
Web site : http://nicolascoolman.skyrock.com/
========== Clé(s) du Registre ==========
ABSENT Key: CLSID BHO: {2BEFBCCE-46A6-4950-BCB5-7062EAC6C9C9}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{12D6D31C-C5BF-4C66-BF8D-D54D5BFD3D41}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{12D6D31C-C5BF-4C66-BF8D-D54D5BFD3D41}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{24CBAA7E-4C85-4B75-B101-9803391AC327}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{48ACB95E-38BE-4377-BE46-67F5B68C1A77}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{6D4630E6-2F14-4615-8FE3-26ECBC39AC2A}
ABSENT Key: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6D4630E6-2F14-4615-8FE3-26ECBC39AC2A}
SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{723328FF-22D0-497f-9EB5-1AC919582DE1}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{723328FF-22D0-497f-9EB5-1AC919582DE1}
ABSENT Key: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{723328FF-22D0-497f-9EB5-1AC919582DE1}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{761f6a83-f007-49e4-8eac-cdb6808ef06f}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{76c45b18-a29e-43ea-aaf8-af55c2e1ae17}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{7cd74aff-3433-4e34-92e2-d98dfdb30754}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{7D21B744-838A-4208-8CEF-3D70162B053B}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{8273A950-A894-497B-B408-A19B33968243}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{83b2fe06-ba20-4f7d-96c6-6fc3a4e877d3}
ABSENT Key: HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA7406}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{96ef404c-24c7-43d0-9096-4ccc8bb7ccac}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{97720195-206a-42ae-8e65-260b9ba5589f}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{986f7a5a-9676-47e1-8642-f41f8c3fcf82}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{99379002-4781-440E-9002-EF5CEBC666FD}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{A0DFD148-D748-4C58-B8E7-396B85D62091}
ABSENT Key: HKLM\Software\Classes\TypeLib\{A36EC25F-1846-45D0-903F-A9F9B5CF0FD0}
SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}
ABSENT Key: HKLM\Software\Classes\TypeLib\{A4D74ECD-AEF8-45EB-929C-DB36E4D00ECF}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{b18788a4-92bd-440e-a4d1-380c36531119}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{b32966a2-f7c2-4362-a6cf-399ec8b44110}
ABSENT Key: HKLM\Software\Classes\TypeLib\{B5E29133-7CC2-4174-B60E-42F51C7E7919}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{EAE5C2BC-AE3F-4C6F-A736-03DDF56FA2D9}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{F030DBBA-EFC2-4443-A1D1-0B716CE0CC78}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{F030DBBA-EFC2-4443-A1D1-0B716CE0CC78}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{f8b4ec8a-2407-4be0-aee2-0f430d65a90d}
========== Valeur(s) du Registre ==========
ABSENT AppInit: \Program Files\WI3C8A~1\Datamngr\x64\datamngr.dll
ABSENT {817A8F30-E362-432C-8F40-8EED45AFD99F}
ABSENT {70455272-D8C2-490E-B91F-9E491056F141}
========== Dossier(s) ==========
SUPPRIME Folder: C:\Users\abdel\AppData\Roaming\pdfforge
SUPPRIME Folder: C:\Users\abdel\AppData\Local\Ilivid Player
SUPPRIME Folder: C:\Users\abdel\AppData\Local\widestream6 Air
SUPPRIME Reboot Folder**: C:\Program Files (x86)\iLivid
SUPPRIME Folder: c:\users\abdel\appdata\locallow\shopperreports3
SUPPRIME Temporaires Windows: : 354
SUPPRIME Flash Cookies: 171
========== Fichier(s) ==========
ABSENT File: \program files\wi3c8a~1\datamngr\x64\datamngr.dll
ABSENT Folder/File: c:\users\abdel\appdata\roaming\pdfforge
ABSENT Folder/File: c:\users\abdel\appdata\local\widestream6 air
SUPPRIME Temporaires Windows: : 767
SUPPRIME Flash Cookies: 78
========== Récapitulatif ==========
32 : Clé(s) du Registre
3 : Valeur(s) du Registre
7 : Dossier(s)
5 : Fichier(s)
End of clean in 00mn 14s
========== Chemin de fichier rapport ==========
C:\ZHP\ZHPFix[R1].txt - 02/04/2012 22:34:29 [4547] -
Salut,
Tu as lancé plusieurs fois ZHP fix apparement
Tu peux me poster le rapport
C:\ZHP\ZHPFix[R1].txt - 02/04/2012 21:34:29 [4599]
S'il te plait
Ensuite tu peux refaire un diagnostic PC avec ZHP diag pour voir ce que le fix a virer
Merci -
bonjour,
ceci le rapport de ZHP fix après le copier coller.
merci pour votre reponse
Rapport de ZHPFix 1.12.3381 par Nicolas Coolman, Update du 08/02/2011
Fichier d'export Registre :
Run by abdel at 03/04/2012 08:41:28
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
Web site : http://nicolascoolman.skyrock.com/
========== Clé(s) du Registre ==========
ABSENT Key: CLSID BHO: {2BEFBCCE-46A6-4950-BCB5-7062EAC6C9C9}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{12D6D31C-C5BF-4C66-BF8D-D54D5BFD3D41}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{12D6D31C-C5BF-4C66-BF8D-D54D5BFD3D41}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{24CBAA7E-4C85-4B75-B101-9803391AC327}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{48ACB95E-38BE-4377-BE46-67F5B68C1A77}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{6D4630E6-2F14-4615-8FE3-26ECBC39AC2A}
ABSENT Key: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6D4630E6-2F14-4615-8FE3-26ECBC39AC2A}
ABSENT Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{723328FF-22D0-497f-9EB5-1AC919582DE1}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{723328FF-22D0-497f-9EB5-1AC919582DE1}
ABSENT Key: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{723328FF-22D0-497f-9EB5-1AC919582DE1}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{761f6a83-f007-49e4-8eac-cdb6808ef06f}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{76c45b18-a29e-43ea-aaf8-af55c2e1ae17}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{7cd74aff-3433-4e34-92e2-d98dfdb30754}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{7D21B744-838A-4208-8CEF-3D70162B053B}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{8273A950-A894-497B-B408-A19B33968243}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{83b2fe06-ba20-4f7d-96c6-6fc3a4e877d3}
ABSENT Key: HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA7406}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{96ef404c-24c7-43d0-9096-4ccc8bb7ccac}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{97720195-206a-42ae-8e65-260b9ba5589f}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{986f7a5a-9676-47e1-8642-f41f8c3fcf82}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{99379002-4781-440E-9002-EF5CEBC666FD}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{A0DFD148-D748-4C58-B8E7-396B85D62091}
ABSENT Key: HKLM\Software\Classes\TypeLib\{A36EC25F-1846-45D0-903F-A9F9B5CF0FD0}
ABSENT Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}
ABSENT Key: HKLM\Software\Classes\TypeLib\{A4D74ECD-AEF8-45EB-929C-DB36E4D00ECF}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{b18788a4-92bd-440e-a4d1-380c36531119}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{b32966a2-f7c2-4362-a6cf-399ec8b44110}
ABSENT Key: HKLM\Software\Classes\TypeLib\{B5E29133-7CC2-4174-B60E-42F51C7E7919}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{EAE5C2BC-AE3F-4C6F-A736-03DDF56FA2D9}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\CLSID\{F030DBBA-EFC2-4443-A1D1-0B716CE0CC78}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{F030DBBA-EFC2-4443-A1D1-0B716CE0CC78}
ABSENT Key: HKLM\Software\WOW6432Node\Classes\Interface\{f8b4ec8a-2407-4be0-aee2-0f430d65a90d}
========== Valeur(s) du Registre ==========
ABSENT AppInit: \Program Files\WI3C8A~1\Datamngr\x64\datamngr.dll
ABSENT {817A8F30-E362-432C-8F40-8EED45AFD99F}
ABSENT {70455272-D8C2-490E-B91F-9E491056F141}
========== Dossier(s) ==========
ABSENT C:\Users\abdel\AppData\Roaming\pdfforge
ABSENT C:\Users\abdel\AppData\Local\Ilivid Player
ABSENT C:\Users\abdel\AppData\Local\widestream6 Air
SUPPRIME Reboot Folder**: C:\Program Files (x86)\iLivid
SUPPRIME Temporaires Windows: : 2
SUPPRIME Flash Cookies: 9
========== Fichier(s) ==========
ABSENT File: \program files\wi3c8a~1\datamngr\x64\datamngr.dll
ABSENT Folder/File: c:\users\abdel\appdata\roaming\pdfforge
ABSENT Folder/File: c:\users\abdel\appdata\local\widestream6 air
ABSENT Folder/File: c:\users\abdel\appdata\locallow\shopperreports3
SUPPRIME Temporaires Windows: : 9
SUPPRIME Flash Cookies: 5
========== Récapitulatif ==========
32 : Clé(s) du Registre
3 : Valeur(s) du Registre
6 : Dossier(s)
6 : Fichier(s)
End of clean in 00mn 04s
========== Chemin de fichier rapport ==========
C:\ZHP\ZHPFix[R1].txt - 02/04/2012 21:34:29 [4599]
C:\ZHP\ZHPFix[R2].txt - 02/04/2012 21:35:23 [4613]
C:\ZHP\ZHPFix[R3].txt - 02/04/2012 21:35:51 [4665]
C:\ZHP\ZHPFix[R4].txt - 03/04/2012 08:41:28 [4665] -
comment l'obtenir le rapport de ZHP fix! j'ai pas trouver comment l'obtenir!
merci -
Tu peux poster le rapport ZHP fix, s'il te plait
-
j'ai tous fais comme vous l'avez dit mais rien ne change après redemarage! j'ai toujours le jecherche.org comme page d'acceuille et mon pc chauffe bcp
-
- Ferme toutes tes applications en cours
- Lance ZHPFix via le raccourci sur ton Bureau, (Si tu es sous Vista ou Windows 7 n'oublie pas clic droit ==> en tant qu'administrateur")
- Si tu ne l'as pas, télécharge le depuis ce lien: https://www.zebulon.fr/telechargements/securite/systeme/zhpfix.html
- Copie/colle les lignes en gras suivantes :
O2 - BHO: Interest recogniser for Widestream6 (powered by Spointer) [64Bits] - {2BEFBCCE-46A6-4950-BCB5-7062EAC6C9C9} Clé orpheline => Infection BT (Adware.SPointer)
O20 - AppInit_DLLs: . (...) - C:\Program Files\WI3C8A~1\Datamngr\x64\datamngr.dll (.not file.) => Infection BT (Adware.Bandoo)
O43 - CFD: 13/02/2012 - 17:52:50 - [0,001] ----D- C:\Users\abdel\AppData\Roaming\pdfforge => Infection BT (PUP.Dealio)
O43 - CFD: 29/04/2011 - 18:25:06 - [0,013] ----D- C:\Users\abdel\AppData\Local\Ilivid Player => Infection BT (Adware.Bandoo)
O43 - CFD: 05/03/2012 - 20:26:38 - [0,485] ----D- C:\Users\abdel\AppData\Local\widestream6 Air => Infection BT (Adware.SPointer)
O43 - CFD: 29/04/2011 - 18:47:52 - [35,323] ----D- C:\Program Files (x86)\iLivid => Infection BT (Adware.Bandoo)
O87 - FAEL: "{817A8F30-E362-432C-8F40-8EED45AFD99F}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\dtUser.exe (.not file.) => Infection BT (Adware.Bandoo)
O87 - FAEL: "{70455272-D8C2-490E-B91F-9E491056F141}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\Windows iLivid Toolbar\ToolBar\dtUser.exe (.not file.) => Infection BT (Adware.Bandoo)
[HKLM\Software\WOW6432Node\Classes\CLSID\{12D6D31C-C5BF-4C66-BF8D-D54D5BFD3D41}] => Infection BT (Adware.SPointer)
[HKLM\Software\WOW6432Node\Classes\Interface\{12D6D31C-C5BF-4C66-BF8D-D54D5BFD3D41}] => Infection BT (Adware.SPointer)
[HKLM\Software\WOW6432Node\Classes\Interface\{24CBAA7E-4C85-4B75-B101-9803391AC327}] => Infection BT (Adware.SPointer)
[HKLM\Software\WOW6432Node\Classes\CLSID\{48ACB95E-38BE-4377-BE46-67F5B68C1A77}] => Infection BT (Adware.SPointer)
[HKLM\Software\WOW6432Node\Classes\CLSID\{6D4630E6-2F14-4615-8FE3-26ECBC39AC2A}] => Infection BT (Adware.SPointer)
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6D4630E6-2F14-4615-8FE3-26ECBC39AC2A}] => Infection BT (Adware.SPointer)
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{723328FF-22D0-497f-9EB5-1AC919582DE1}] => Infection BT (Adware.SPointer)
[HKLM\Software\WOW6432Node\Classes\CLSID\{723328FF-22D0-497f-9EB5-1AC919582DE1}] => Infection BT (Adware.SPointer)
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{723328FF-22D0-497f-9EB5-1AC919582DE1}] => Infection BT (Adware.SPointer)
[HKLM\Software\WOW6432Node\Classes\CLSID\{761f6a83-f007-49e4-8eac-cdb6808ef06f}] => Infection BT (Adware.2Search)
[HKLM\Software\WOW6432Node\Classes\CLSID\{76c45b18-a29e-43ea-aaf8-af55c2e1ae17}] => Infection PUP (PUP.Eorezo)
[HKLM\Software\WOW6432Node\Classes\CLSID\{7cd74aff-3433-4e34-92e2-d98dfdb30754}] => Infection PUP (PUP.Eorezo)
[HKLM\Software\WOW6432Node\Classes\Interface\{7D21B744-838A-4208-8CEF-3D70162B053B}] => Infection BT (Adware.SPointer)
[HKLM\Software\WOW6432Node\Classes\Interface\{8273A950-A894-497B-B408-A19B33968243}] => Infection BT (Adware.SPointer)
[HKLM\Software\WOW6432Node\Classes\Interface\{83b2fe06-ba20-4f7d-96c6-6fc3a4e877d3}]
[HKLM\Software\WOW6432Node\Microsoft\Internet Explorer\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA7406}] => Infection PUP (Adware.Bandoo)
[HKLM\Software\WOW6432Node\Classes\CLSID\{96ef404c-24c7-43d0-9096-4ccc8bb7ccac}] => Infection PUP (PUP.Eorezo)
[HKLM\Software\WOW6432Node\Classes\CLSID\{97720195-206a-42ae-8e65-260b9ba5589f}] => Infection PUP (PUP.Eorezo)
[HKLM\Software\WOW6432Node\Classes\CLSID\{986f7a5a-9676-47e1-8642-f41f8c3fcf82}] => Infection PUP (PUP.Eorezo)
[HKLM\Software\WOW6432Node\Classes\Interface\{99379002-4781-440E-9002-EF5CEBC666FD}] => Infection BT (Adware.SPointer)
[HKLM\Software\WOW6432Node\Classes\Interface\{A0DFD148-D748-4C58-B8E7-396B85D62091}] => Infection BT (Adware.SPointer)
[HKLM\Software\Classes\TypeLib\{A36EC25F-1846-45D0-903F-A9F9B5CF0FD0}] => Infection BT (Adware.SPointer)
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}] => Infection PUP (Adware.Bandoo)
[HKLM\Software\Classes\TypeLib\{A4D74ECD-AEF8-45EB-929C-DB36E4D00ECF}] => Infection BT (Adware.SPointer)
[HKLM\Software\WOW6432Node\Classes\CLSID\{b18788a4-92bd-440e-a4d1-380c36531119}] => Infection PUP (PUP.Eorezo)
[HKLM\Software\WOW6432Node\Classes\Interface\{b32966a2-f7c2-4362-a6cf-399ec8b44110}]
[HKLM\Software\Classes\TypeLib\{B5E29133-7CC2-4174-B60E-42F51C7E7919}] => Infection BT (Adware.SPointer)
[HKLM\Software\WOW6432Node\Classes\Interface\{EAE5C2BC-AE3F-4C6F-A736-03DDF56FA2D9}] => Infection BT (Adware.SPointer)
[HKLM\Software\WOW6432Node\Classes\CLSID\{F030DBBA-EFC2-4443-A1D1-0B716CE0CC78}] => Infection BT (Adware.SPointer)
[HKLM\Software\WOW6432Node\Classes\Interface\{F030DBBA-EFC2-4443-A1D1-0B716CE0CC78}] => Infection BT (Adware.SPointer)
[HKLM\Software\WOW6432Node\Classes\Interface\{f8b4ec8a-2407-4be0-aee2-0f430d65a90d}]
C:\Users\abdel\AppData\Roaming\pdfforge => Infection BT (PUP.Dealio)
C:\Users\abdel\AppData\Local\widestream6 Air => Infection BT (Adware.SPointer)
C:\Users\abdel\AppData\LocalLow\ShopperReports3 => Infection BT (Adware.ShopperReports)
Emptytemp
Emptyflash -
re,
j'en ai déjà fais un! mais bon j'ai refai le diagnostic avec ZHP diag
voila le rapport:
http://pjjoint.malekal.com/files.php?id=ZHPDiag_20120402_g5w6i6r12l9
- 1
- 2