• Copies le contenu du cadre ci dessous dans un fichier.txt
(Clique-droit sur ton bureau et tu choisis "Nouveau > Document Texte")
- Code: Tout sélectionner
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: Modified
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Associations]:bak_Application
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF]
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
O4 - HKCU\..\Run: [AdobeBridge] Clé orpheline
O4 - HKUS\S-1-5-21-2424557879-144882163-3155651499-1000\..\Run: [AdobeBridge] Clé orpheline
O4 - GS\Desktop: Achiwa.lnk . (...) -- C:\Program Files (x86)\Achiwa\achiwant.exe (.not file.)
[MD5.00000000000000000000000000000000] [APT] [{0D21F864-6134-4106-BDC0-4EC485AD0886}] (...) -- C:\Users\Ivan\Downloads\WoW-3.3.3.11723-to-3.3.5.12213-frFR-patch.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{5AA5C46A-211B-44B7-B8F1-07B8533EF0AC}] (...) -- C:\Users\Ivan\Downloads\WoW-3.3.3.11723-to-3.3.5.12213-frFR-patch.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{5F767127-B96E-4117-B347-9210840AA8C7}] (...) -- C:\Users\Ivan\Downloads\WoW-3.3.3.11723-to-3.3.5.12213-frFR-patch.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{B3648572-8FB6-4C7B-A4C1-024B3BD81D07}] (...) -- C:\Users\Ivan\Downloads\hot-jingle-player-1-0-c.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{E6730555-30F4-42B6-AD4B-E27C4764631A}] (...) -- C:\Users\Ivan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DUAXKSCM\Windows_Movie_Maker_2.0.exe (.not file.) [0]
O44 - LFC:[MD5.B301A313D95BD344A0EE65CD67DB978B] - 29/03/2013 - 19:07:08 ---A- . (...) -- C:\AdwCleaner[S3].txt [1861]
O44 - LFC:[MD5.7DC02D17BC170CD24A6B7EE991F54234] - 29/03/2013 - 19:06:36 ---A- . (...) -- C:\AdwCleaner[S2].txt [358]
O45 - LFCP:[MD5.58968B94AA3A274EDF3B5A64F83B6862] - 29/03/2013 - 20:32:24 ---A- - C:\Windows\Prefetch\OTL.EXE-7A295D1D.pf
O45 - LFCP:[MD5.4B67FC718A79C239E412DE361F378ACB] - 29/03/2013 - 20:32:29 ---A- - C:\Windows\Prefetch\UPDATERSTARTUPUTILITY.EXE-E056967B.pf
O45 - LFCP:[MD5.8A33D8168A048B8F6E4E9ADF266075ED] - 29/03/2013 - 20:32:38 ---A- - C:\Windows\Prefetch\NVTMRU.EXE-231A7003.pf
O45 - LFCP:[MD5.6B437C3FF077B63564CF63F9BA030D09] - 29/03/2013 - 20:32:40 ---A- - C:\Windows\Prefetch\SWITCHBOARD.EXE-44EC7AA8.pf
O45 - LFCP:[MD5.9C2AB371779689D8B911583472148508] - 29/03/2013 - 20:33:14 ---A- - C:\Windows\Prefetch\TURBOBOOST.EXE-C4055C7C.pf
O45 - LFCP:[MD5.0A9D7E7C3F86B05C4ABD116673264643] - 29/03/2013 - 20:34:56 ---A- - C:\Windows\Prefetch\VDS.EXE-6E7946F9.pf
O45 - LFCP:[MD5.0A163D3031AA4D18EB43B7AE51927A48] - 29/03/2013 - 20:39:49 ---A- - C:\Windows\Prefetch\GW2.EXE-8BB1D5DD.pf
O45 - LFCP:[MD5.46E4DA39C3BFFC57B7DD83956D637437] - 29/03/2013 - 21:07:08 ---A- - C:\Windows\Prefetch\MUMBLE.EXE-5D7B72ED.pf
O45 - LFCP:[MD5.43F26FEF67D5D1D31508E24910A3981F] - 29/03/2013 - 21:27:10 ---A- - C:\Windows\Prefetch\AWESOMIUM_PROCESS.EXE-B108C9B0.pf
O51 - MPSK:{7e0cd2f7-9467-11e2-bfd1-6c626dd6f6fb}\AutoRun\command. (...) -- G:\Startme.exe (.not file.)
O51 - MPSK:{b7462d31-670f-11e2-97e5-83f069466756}\AutoRun\command. (...) -- G:\SFRLauncher.exe (.not file.)
O51 - MPSK:{b7462d3d-670f-11e2-97e5-83f069466756}\AutoRun\command. (...) -- G:\SFRLauncher.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\Akamai NetSession Interface [Key] . (...) -- C:\Users\Ivan\AppData\Local\Akamai\netsession_win.exe (.not file.)
[MD5.00000000000000000000000000000000] [APT] [{8B4A718B-6825-47D0-AE4C-0E39E687A47B}] (...) -- F:\setup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{CF70BA12-6E91-4F91-8ADC-0311A379D5F8}] (...) -- F:\setup.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{FAE5AC8C-E580-4082-B414-5DC973BC5AB4}] (...) -- F:\setup.exe (.not file.) [0]
O51 - MPSK:{2dc5a8d0-729c-11e0-9345-806e6f6e6963}\AutoRun\command. (...) -- F:\SETUP.exe (.not file.)
[MD5.00000000000000000000000000000000] [APT] [Scheduled Update for Ask Toolbar] (...) -- C:\Program Files (x86)\Ask.com\UpdateTask.exe (.not file.) [0]
O69 - SBI: SearchScopes [HKCU] {C3072774-1799-48A9-B342-C61DCCB3A840} - (Ask Search) - http://websearch.ask.com
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}]
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}]
[HKLM\Software\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}]
[HKLM\Software\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}]
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
[HKLM\Software\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2]
[HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
EmptyTemp
EmptyFlash
FirewallRaz
ProxyFix
•
DÉCONNECTES TOI D'INTERNET ET FERMES TOUTES TES APPLICATIONS/!\ Utilisateur de Windows Vista et Windows Seven : Clique droit sur le logo de ZHPFix, « Exécuter en tant qu'Administrateur » /!\• Lances ZHPFix qui est sur ton Bureau.
• Copies & Colles le texte qui est dans ton Document Texte sur ton Bureau.
• Cliques sur le
deuxième bouton en partant de la gauche "Coller le Presse-Papier".
• Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaître.
• Cliques sur le bouton
GO.
• Patientes le temps de la Suppression.
• ZHPFix va copier le rapport d'analyse sur le Bureau sous le nom ZHPFixReport.txt
• Héberges le rapport ZHPFixReport.txt sur
CJoint.com• Postes le lien donné.
======================
• Vas sur
VirusTotal.com• Cliques sur
Choose File et dans Nom de Fichier, mets ceci:
C:\Windows\Installer\{ED4108A9-60FD-4F18-AF42-122219977773}\ARPPRODUCTICON.exe• Puis cliques sur
Scan It!• Patientes le temps de l'UpLoad ...
/!\ Si tu as un messages signifiant "File already analysed", cliques sur
Reanalyse /!\
• Attends ton tour et attends l'analyse des antivirus.
• Une fois l'analyse terminée, copies le lien dans la barre d'adresse et postes la moi.