Redémarre en Mode Sans Échec avec Prise en Charge de Réseau
/!\ Utilisateur de Windows Vista et Windows Seven : Clique droit sur le logo de OTL, « Exécuter en tant qu'Administrateur » /!\ • Lances OTL.
• Coches en haut à droite
Rapport Minimal.
• Sous Personnalisation, copies & colles ceci:
- Code: Tout sélectionner
:OTL
PRC - [2012/11/28 16:41:36 | 001,123,720 | ---- | M] (Spigot, Inc.) -- C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe => Infection PUP (PUP.Dealio)
PRC - [2012/11/28 16:34:18 | 000,793,600 | ---- | M] (Spigot, Inc.) -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe => Infection PUP (PUP.Dealio)
PRC - [2012/08/15 18:08:34 | 000,231,768 | ---- | M] (SweetIM Technologies Ltd.) -- C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe => Infection PUP (PUP.SweetIM)
PRC - [2012/05/29 14:50:04 | 000,115,032 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe => Infection PUP (PUP.SweetIM)
SRV - [2012/11/28 16:34:18 | 000,793,600 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe -- (Application Updater) => Infection PUP (PUP.Dealio)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000.10014&barid={6441FFDA-1193-11E2-A2E6-40618691ABDD}
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=108988&tt=3612_7&babsrc=SP_ss&mntrId=3a06b7eb00000000000040618691abdd => Infection PUP (PUP.ClaroSearch)
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\SearchScopes\{b41306c6-96d0-442a-bcc4-b0f621e82ce9}: "URL" = http://www.fissa.com/fr/results/?s=b&c=1008088779&suid=EjVOZu1uj&d=3&pid=23&q={searchTerms} => Infection BT (PUP.OfferBox)
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=108988&tt=3612_7&babsrc=SP_ss&mntrId=3a06b7eb00000000000040618691abdd => Infection PUP (PUP.ClaroSearch)
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\SearchScopes\{b41306c6-96d0-442a-bcc4-b0f621e82ce9}: "URL" = http://www.fissa.com/fr/results/?s=b&c=1008088779&suid=EjVOZu1uj&d=3&pid=23&q={searchTerms} => Infection BT (PUP.OfferBox)
FF - prefs.js..browser.startup.homepage: "http://search.babylon.com/?affID=108988&tt=3612_7&babsrc=HP_ss_cr&mntrId=3a06b7eb00000000000040618691abdd"
[2012/12/08 17:17:51 | 000,169,792 | ---- | M] () (No name found) -- C:\Users\Dominique\AppData\Roaming\mozilla\firefox\profiles\4zds3n0j.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi => Infection PUP (PUP.SweetIM)
[2010/08/10 01:50:58 | 000,002,559 | ---- | M] () -- C:\Users\Dominique\AppData\Roaming\mozilla\firefox\profiles\4zds3n0j.default\searchplugins\fissa.xml => Infection BT (PUP.Offerbox)
[2012/10/08 22:59:18 | 000,003,915 | ---- | M] () -- C:\Users\Dominique\AppData\Roaming\mozilla\firefox\profiles\4zds3n0j.default\searchplugins\sweetim.xml => Infection PUP (PUP.SweetIM)
[2012/12/13 00:17:45 | 000,000,000 | ---D | M] (Widgi Toolbar Platform) -- C:\PROGRAM FILES (X86)\COMMON FILES\SPIGOT\WTXPCOM => Infection PUP (PUP.Dealio)
[2012/09/03 17:45:27 | 000,002,349 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml => Infection BT (Toolbar.Babylon)
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.6.7\PriceGongIE.dll (PriceGong) => Infection BT (Adware.PriceGong)
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.6.9.12\bh\BabylonToolbar.dll (Babylon BHO) => Infection BT (Toolbar.Babylon)
O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) => Infection PUP (PUP.SweetIM)
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.6.9.12\BabylonToolbarTlbr.dll (Babylon Ltd.) => Infection BT (Toolbar.Babylon)
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) => Infection PUP (PUP.SweetIM)
O3 - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technolo => Infection PUP (PUP.SweetIM)
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.) => Infection PUP (PUP.Dealio)
O4 - HKLM\..\Run: [SweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.) => Infection PUP (PUP.SweetIM)
O4 - HKLM\..\Run: [Sweetpacks Communicator] C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe (SweetIM Technologies Ltd.) => Infection PUP (PUP.SweetIM)
[2012/12/05 19:55:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Spigot => Infection PUP (PUP.Dealio)
[2012/12/05 19:55:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Application Updater => Infection PUP (PUP.Dealio)
[2010/11/19 10:32:16 | 000,000,000 | ---- | C] () -- C:\Users\Dominique\AppData\Roaming\chrtmp => Infection Diverse (Malware.Trace)
PRC - [2012/10/09 09:53:36 | 004,441,920 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Dominique\AppData\Local\Akamai\netsession_win.exe => Akamai Technologies, Inc. - Akamai NetSession Client
O4 - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\Run: [Akamai NetSession Interface] C:\Users\Dominique\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) => Akamai%NetSession Interface
O4 - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\Run: [Akamai NetSession Interface] C:\Users\Dominique\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) => Akamai%NetSession Interface
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Google/Seekeen.com or Web Search
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 => Google/Seekeen.com or Web Search
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 => Google/Seekeen.com or Web Search
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sour => Google/Seekeen.com or Web Search
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sour => Google/Seekeen.com or Web Search
O13 - gopher Prefix: missing => Malware sous Windows NT5
O13 - gopher Prefix: missing => Malware sous Windows NT5
O32 - AutoRun File - [2011/08/04 18:13:52 | 000,000,110 | -H-- | M] () - J:\autorun.inf -- [ FAT32 ] => Légitime or Malware (Worm.Mabezat)
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) => Toolbar.Conduit
IE - HKLM\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} => Toolbar.Conduit
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 => Toolbar.Conduit
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\URLSearchHook: {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files (x86)\IObit Toolbar\IE\6.6\iobitToolbarIE.dll (Spigot, Inc.) => Toolbar.IObit
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\URLSearchHook: {51a86bb3-6602-4c85-92a5-130ee4864f13} - No CLSID value found => Toolbar.BrotherSoft Extreme
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) => Toolbar.Conduit
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\URLSearchHook: {8e5025c2-8ea3-430d-80b8-a14151068a6d} - No CLSID value found => Toolbar.01NET
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233} => Toolbar.AVGSearch
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={71D1F97B-49BD-4C4C-89AD-2B443E468165}&mid=7eb1a0517a7e47d0a7ed9128c075422e-9f957ae6c867cb3b15f95474e5 => Toolbar.AVGSearch
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpro.com/search/browser/hypercam/{577011CB-CACF-4DB8-9E72-3050FD3E410A}?q={searchTerms} => Toolbar.Agent
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 => Toolbar.Conduit
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\URLSearchHook: {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files (x86)\IObit Toolbar\IE\6.6\iobitToolbarIE.dll (Spigot, Inc.) => Toolbar.IObit
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\URLSearchHook: {51a86bb3-6602-4c85-92a5-130ee4864f13} - No CLSID value found => Toolbar.BrotherSoft Extreme
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) => Toolbar.Conduit
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\URLSearchHook: {8e5025c2-8ea3-430d-80b8-a14151068a6d} - No CLSID value found => Toolbar.01NET
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpro.com/search/browser/hypercam/{577011CB-CACF-4DB8-9E72-3050FD3E410A}?q={searchTerms} => Toolbar.Agent
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050 => Toolbar.Conduit
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3128284&SearchSource=3&q={searchTerms}"
FF - prefs.js..extensions.enabledItems: {51a86bb3-6602-4c85-92a5-130ee4864f13}:3.3.3.2 => Toolbar.BrotherSoft Extreme
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:3.3.3.2 => DVDVideoSoftTB Toolbar
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\13.2.0\\npsitesafety.dll () => Toolbar.AVGSearch
[2012/12/12 23:58:54 | 000,000,000 | ---D | M] (BrotherSoft Extreme Community Toolbar) -- C:\Users\Dominique\AppData\Roaming\mozilla\Firefox\Profiles\4zds3n0j.default\extensions\{51a86bb3-6602-4c85-92a5-130ee4864f13} => Toolbar.BrotherSoft Extreme
[2012/12/12 23:59:35 | 000,000,000 | ---D | M] (DVDVideoSoftTB) -- C:\Users\Dominique\AppData\Roaming\mozilla\Firefox\Profiles\4zds3n0j.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} => DVDVideoSoftTB Toolbar
[2012/03/22 18:18:20 | 000,000,921 | ---- | M] () -- C:\Users\Dominique\AppData\Roaming\mozilla\firefox\profiles\4zds3n0j.default\searchplugins\conduit.xml => Toolbar.Conduit
[2012/12/14 04:21:49 | 000,003,573 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml => Toolbar.AVGSearch
CHR - Extension: 01NET.com = C:\Users\Dominique\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehdmaehkiiampolokajdcelladmnopgp\2.3.18.20_0\ => Toolbar.01NET.com
CHR - Extension: SweetPacks Chrome Extension = C:\Users\Dominique\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.1.0.1_0\ => Toolbar.SweetIM
CHR - Extension: 01NET.com = C:\Users\Dominique\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehdmaehkiiampolokajdcelladmnopgp\2.3.18.20_0\ => Toolbar.01NET.com
CHR - Extension: SweetPacks Chrome Extension = C:\Users\Dominique\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.1.0.1_0\ => Toolbar.SweetIM
O2 - BHO: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files (x86)\IObit Toolbar\IE\6.6\iobitToolbarIE.dll (Spigot, Inc.) => Toolbar.IObit
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) => Toolbar.Conduit
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll () => Toolbar.AVGSearch
O3 - HKLM\..\Toolbar: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files (x86)\IObit Toolbar\IE\6.6\iobitToolbarIE.dll (Spigot, Inc.) => Toolbar.IObit
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) => Toolbar.Conduit
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll () => Toolbar.AVGSearch
O3 - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) => Toolbar.Conduit
O3 - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVD0.dll (Conduit Ltd.) => Toolbar.Conduit
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\13.2.0\ViProtocol.dll () => Toolbar.AVGSearch
[2012/12/12 15:02:03 | 000,000,000 | ---D | C] -- C:\Users\Dominique\AppData\Local\AVG Secure Search => Toolbar.AVGSearch
[2012/12/12 15:01:44 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Secure Search => Toolbar.AVGSearch
[2012/12/12 15:01:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG Secure Search => Toolbar.AVGSearch
[2012/12/12 14:59:37 | 000,000,000 | -HSD | C] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} => Toolbar.TuneUp
[2012/12/05 19:55:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IObit Toolbar => IObit Toolbar
IE - HKLM\..\SearchScopes\{FDE3A44D-3139-4273-B670-27BF6130ED7B}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{FDE3A44D-3139-4273-B670-27BF6130ED7B}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\SearchScopes\{5E09DD1A-083C-49BE-AA7C-B45C7938AEE0}: "URL" = http://fr.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=685749&p={searchTerms}
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\SearchScopes\{6AC63E17-B56A-4A89-A130-EEFF78EBCE4D}: "URL" = http://mywwwsites.com/?q={searchTerms}
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\SearchScopes\{9D5BD211-422C-4164-9298-BB4186A30F31}: "URL" = http://www.bing.com/search?q={searchTerms}&mkt=fr-FR&form=MIAWB1
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\SearchScopes\{A05743A4-704B-403E-8FD8-769E0C7BE0F6}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\..\SearchScopes\{FDE3A44D-3139-4273-B670-27BF6130ED7B}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://g.uk.msn.com/HPDSK/3
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\SearchScopes,DefaultScope = {5E09DD1A-083C-49BE-AA7C-B45C7938AEE0}
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\SearchScopes\{5E09DD1A-083C-49BE-AA7C-B45C7938AEE0}: "URL" = http://fr.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=685749&p={searchTerms}
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\SearchScopes\{6AC63E17-B56A-4A89-A130-EEFF78EBCE4D}: "URL" = http://mywwwsites.com/?q={searchTerms}
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\SearchScopes\{9D5BD211-422C-4164-9298-BB4186A30F31}: "URL" = http://www.bing.com/search?q={searchTerms}&mkt=fr-FR&form=MIAWB1
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\SearchScopes\{A05743A4-704B-403E-8FD8-769E0C7BE0F6}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\..\SearchScopes\{FDE3A44D-3139-4273-B670-27BF6130ED7B}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
IE - HKU\S-1-5-21-778703484-1029993363-2472904834-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "01NET.com Customized Web Search"
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=685749"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "msn.fr"
FF - prefs.js..extensions.enabledAddons: wtxpcom%40mybrowserbar.com:6.6
FF - prefs.js..extensions.enabledAddons: %7B635abd67-4fe9-1b23-4f01-e679fa7484c1%7D:2.5.1.20121012015120
FF - prefs.js..extensions.enabledAddons: %7BACAA314B-EEBA-48e4-AD47-84E31C44796C%7D:1.0.10
FF - prefs.js..extensions.enabledAddons: %7BEEE6C361-6118-11DC-9C72-001320C79847%7D:1.6.0.3
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1
FF - prefs.js..extensions.enabledItems: offerboxffx@offerbox.com:2.1.2613.41
FF - prefs.js..extensions.enabledItems: dealio@mybrowserbar.com:4.3
FF - prefs.js..extensions.enabledItems: wtxpcom@mybrowserbar.com:4.3
FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.3.2
FF - prefs.js..extensions.enabledItems: {c41be492-d9e6-4262-a0bd-e8cf6dc4208d}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {1D3DB383-DB45-45b2-9F46-91218CA2CBCB}:0.6.0.0
FF - prefs.js..extensions.enabledItems: ffxtlbr@babylon.com:1.1.4
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@raidcall.com/RCplugin: C:\Users\Dominique\AppData\LocalLow\raidcall\plugins\webplugin.dll (Raidcall)
FF - HKLM\Software\MozillaPlugins\@raidcall.kr/RCplugin: C:\Users\Dominique\AppData\Roaming\RCKR\plugins\nprcplugin.dll (Raidcall)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Dominique\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Dominique\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\13.2.0.5 [2012/12/14 04:21:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/12/13 00:17:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/12/12 14:46:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/12/13 00:17:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/12/12 14:46:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/12/13 00:17:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/12/12 14:46:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/12/13 00:17:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/12/12 14:46:01 | 000,000,000 | ---D | M]
[2010/06/17 21:20:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dominique\AppData\Roaming\mozilla\Extensions
[2010/01/28 20:47:56 | 000,000,000 | ---D | M] (Tamper Data) -- C:\Users\Dominique\AppData\Roaming\mozilla\Firefox\Profiles\4zds3n0j.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2011/04/20 01:16:26 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Dominique\AppData\Roaming\mozilla\Firefox\Profiles\4zds3n0j.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012/12/12 23:59:39 | 000,000,000 | ---D | M] (ST.France Community Toolbar) -- C:\Users\Dominique\AppData\Roaming\mozilla\Firefox\Profiles\4zds3n0j.default\extensions\{c41be492-d9e6-4262-a0bd-e8cf6dc4208d}
[2012/05/31 16:34:56 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/12/08 17:51:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
CHR - homepage: http://isearch.avg.com/?cid={71D1F97B-49BD-4C4C-89AD-2B443E468165}&mid=7eb1a0517a7e47d0a7ed9128c075422e-9f957ae6c867cb3b15f95474e50056b04ae3d9aa&lang=fr&ds=tt014&pr=sa&d=2012-12-12 15:01:27&v=13.2.0.4&sap=hp
CHR - default_search_provider: Yahoo! (Enabled)
CHR - default_search_provider: search_url = http://fr.search.yahoo.com/search?fr=chr-greentree_gc&ei=utf-8&ilc=12&type=685749&p={searchTerms}
CHR - default_search_provider: suggest_url = http://ff.search.yahoo.com/gossip?output=fxjson&command={searchTerms}
CHR - homepage: http://isearch.avg.com/?cid={71D1F97B-49BD-4C4C-89AD-2B443E468165}&mid=7eb1a0517a7e47d0a7ed9128c075422e-9f957ae6c867cb3b15f95474e50056b04ae3d9aa&lang=fr&ds=tt014&pr=sa&d=2012-12-12 15:01:27&v=13.2.0.4&sap=hp
"AVG Secure Search" = AVG Security Toolbar => Toolbar.AVGSearch
"{1B8B014E-DAB5-47D7-978A-39CFD3CEA7C6}" = protocol=6 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe | => Infection PUP (PUP.SweetIM)
"{661C50B8-3CD8-4BBC-A60A-D1519F54E537}" = protocol=17 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe | => Infection PUP (PUP.SweetIM)
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers 1.10.01 => Infection BT (Adware.Yontoo)
"{7683B745-6060-41FD-AA75-0BBB383FEAD4}" = SweetIM for Messenger 3.7 => Infection PUP (PUP.SweetIM)
"{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}" = Internet Explorer Toolbar 4.6 by SweetPacks => Infection PUP (PUP.SweetIM)
"{E55E7026-EF2A-4A17-AAA7-DB98EA3FD1B1}" = BabylonObjectInstaller => Infection BT (Toolbar.Babylon)
"{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}" = Update Manager for SweetPacks 1.1 => Infection PUP (PUP.SweetIM)
"BabylonToolbar" = Babylon toolbar on IE => Infection BT (Toolbar.Babylon)
"Fissa" = Fissa => Infection PUP (PUP.OfferBox)
"PriceGong" = PriceGong 2.6.7 => Infection Diverse (Adware.PriceGong)
"TCP Query User{3C873405-8920-4B07-814F-E08D7ABF513F}C:\users\dominique\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\dominique\appdata\local\akamai\netsession_win.exe | => Akamai Technologies, Inc. - Akamai NetSession Client
"TCP Query User{7E6F476B-3F1C-4404-836D-721B431A7036}C:\users\dominique\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\dominique\appdata\local\akamai\netsession_win.exe | => Akamai Technologies, Inc. - Akamai NetSession Client
"UDP Query User{9283158A-A875-403A-B633-D09903146271}C:\users\dominique\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\dominique\appdata\local\akamai\netsession_win.exe | => Akamai Technologies, Inc. - Akamai NetSession Client
"UDP Query User{D0BA8582-CCD0-41D9-9178-1DFD3AF20998}C:\users\dominique\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\dominique\appdata\local\akamai\netsession_win.exe | => Akamai Technologies, Inc. - Akamai NetSession Client
"Akamai" = Akamai NetSession Interface Service => Akamai
"Akamai" = Akamai NetSession Interface => Akamai
"2365181835.www.pcspeedup.com" = PCSpeedUp => www.pcspeedup.com
"Akamai" = Akamai NetSession Interface => Akamai
"{290838A9-3F15-4401-8C13-8C972C985305}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | => Apple Computer%Bonjour for Windows
"{55CB4A8A-6A9E-488F-8BDB-4F691693F3D8}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | => Apple Computer%Bonjour for Windows
"{76CF36A4-2E18-4E7F-8B5B-D1C673EC6454}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | => Apple Computer%Bonjour for Windows
"{D1FCE877-BB80-4E4F-9A92-33FBB713402B}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | => Apple Computer%Bonjour for Windows
:Commands
[emptytemp]
[emptyflash]
• Cliques sur
Correction.
• Patientes le temps de l'analyse.
• OTL va te demander de redemarrer ton ordinateur, Cliques sur
Ok.
• Au redémarrage, OTL va ouvrir le rapport dans le bloc-notes (OTL.log).
• Enregistres le rapport sur ton Bureau.
• Héberges le rapport OTL.log sur
CJoint.com• Postes le lien donnés.
/!\ Note : Pour éviter de figer l'analyse OTL, laisses le travailler sans toucher à ton PC ! /!\