• Télécharges
RogueKiller sur ton Bureau.
/!\ Utilisateur de Windows Vista et Windows Seven : Clique droit sur le logo de RogueKiller, « Exécuter en tant qu'Administrateur » /!\• Lances RogueKiller.
• Attends que le PreScan ait fini.
• Cliques sur
Scan.
• Patientes le temps du scan.
• Cliques sur
Suppression.
• Patientes le temps de la suppression.
• Cliques sur
Rapport.
• Enregistres le rapport sur ton Bureau.
• Héberges le rapport RogueKiller sur
CJoint.com• Postes le lien donné.
=================================• Copies le contenu du cadre ci dessous dans un fichier.txt
(Clique-droit sur ton bureau et tu choisis "Nouveau > Document Texte")
- Code: Tout sélectionner
[MD5.CA52AB39FC6EB75C519C77CE07104C6F] - (.Pas de propriétaire - Updater.) -- C:\ProgramData\Premium\OptimizerPro\OptimizerPro.exe [233472] [PID.2804]
O2 - BHO: BoraowSe2saave [64Bits] - {9EE17F3E-5755-DBB2-4AA6-D984A052DFB5} . (...) -- C:\ProgramData\BoraowSe2saave\513baddd08e7d.dll
O4 - HKCU\..\Run: [Yontoo Desktop] C:\Users\sébastien\AppData\Roaming\Yontoo\YontooDesktop.exe (.not file.)
O4 - HKUS\S-1-5-21-4069087404-3107615383-3604061919-1000\..\Run: [Yontoo Desktop] C:\Users\sébastien\AppData\Roaming\Yontoo\YontooDesktop.exe (.not file.)
O4 - GS\Desktop: Optimizer Pro.lnk . (...) -- C:\Program Files (x86)\Optimizer Pro\OptimizerPro.exe (.not file.)
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\OptimizerProUpdaterTask{A0F04D0D-688E-48A6-A032-0DF833497D63}.job [414]
[MD5.00000000000000000000000000000000] [APT] [DealPly] (...) -- C:\Users\sébastien\AppData\Roaming\DealPly\UPDATE~1\UPDATE~1.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [DealPlyUpdate] (...) -- C:\Program Files (x86)\DealPly\DealPlyUpdate.exe (.not file.) [0]
[MD5.CA52AB39FC6EB75C519C77CE07104C6F] [APT] [OptimizerProUpdaterTask{A0F04D0D-688E-48A6-A032-0DF833497D63}] (...) -- C:\ProgramData\Premium\OptimizerPro\OptimizerPro.exe [233472]
O42 - Logiciel: BrowseToSave 1.74 - (...) [HKLM][64Bits] -- SP_f2a323db
O42 - Logiciel: Lollipop - (...) [HKCU][64Bits] -- lollipop_03141438
O42 - Logiciel: OptimizerPro - (.Premium.) [HKLM][64Bits] -- OptimizerPro
O42 - Logiciel: Search Assistant WebSearch 1.74 - (...) [HKLM][64Bits] -- SP_4e24eecb
O42 - Logiciel: SoearcH-NeewaTab - (.NewTab.) [HKLM][64Bits] -- {C670DCAE-E392-AA32-6F42-143C7FC4BDFD}
O43 - CFD: 12/03/2013 - 18:13:51 - [0,191] ----D C:\ProgramData\BoraowSe2saave
O43 - CFD: 10/03/2013 - 18:57:36 - [5,443] ----D C:\ProgramData\BrowserProtect
O44 - LFC:[MD5.D238C1F2097748EE3DA97B2CF1675AD0] - 09/03/2013 - 22:43:00 ---A- . (.Systweak Inc., (www.systweak.com) - Regclean Pro.) -- C:\Windows\SysNative\roboot64.exe [20488]
O44 - LFC:[MD5.D238C1F2097748EE3DA97B2CF1675AD0] - 09/03/2013 - 22:43:00 RSHAD . (.Systweak Inc., (www.systweak.com) - Regclean Pro.) -- C:\Windows\System32\roboot64.exe [20488]
[MD5.8A4AF3B0695F29186AD02E2FD766FA3B] [SPRF][18/01/2013] (.SweetIM Technologies Ltd. - SQLite DLL.) -- C:\Users\sébastien\AppData\Local\Temp\mgsqlite3.dll [393016]
[MD5.D9DA3FDE1AEE64CEE57D4C57A538A53B] [SPRF][22/10/2012] (.SweetIM Technologies Ltd. - SweetIM Installer by SweetPacks.) -- C:\Users\sébastien\AppData\Local\Temp\Shortcut_bundlesweetimsetup.exe [7739736]
[MD5.C6D792E4583FC46DB0953FBF6E46348A] [SPRF][18/01/2013] (.SweetIM Technologies Lt - This installer.) -- C:\Users\sébastien\AppData\Local\Temp\SIMEEI2Installer.exe [2962432]
[MD5.7704B843006444B69486FD27D4660845] [SPRF][18/01/2013] (.SweetIM Technologies Lt - This installer.) -- C:\Users\sébastien\AppData\Local\Temp\SIMEEIInstaller.exe [3380216]
[MD5.62520FED3AC0663F82061A8FB21E1F67] [SPRF][10/03/2013] (.Web Deals Interactive LLC - Installer.) -- C:\Users\sébastien\AppData\Local\Temp\toolbar29853786.exe [1384752]
[MD5.5AC98C84160A9400DB448D153C959BB6] [SPRF][10/03/2013] (...) -- C:\Users\sébastien\AppData\Local\Temp\toolbar29853973.exe [773104]
[MD5.CC1A55091FD96BCB624AD791CD15D179] [SPRF][09/02/2013] (...) -- C:\Users\sébastien\AppData\Roaming\BabMaint.exe [114176]
O87 - FAEL: "{3E8AB386-C9C1-4262-A8F6-B1477D04B7F4}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe (.not file.)
O87 - FAEL: "{BDCCF35D-4561-4838-8C8E-473900BB8B7D}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe (.not file.)
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3}]
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}]
[HKLM\Software\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}]
[HKLM\Software\Wow6432Node\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}]
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SP_f2a323db]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]:Yontoo Desktop
C:\Users\sébastien\Downloads\SaveAs.exe
C:\Users\sébastien\AppData\Local\Temp\Shortcut_bundlesweetimsetup.exe
C:\Users\sébastien\AppData\Local\Temp\SIMEEI2Installer.exe
C:\Users\sébastien\AppData\Local\Temp\SIMEEIInstaller.exe
C:\Users\sébastien\AppData\Local\Temp\GoogleToolbarInstaller1.log
C:\Users\sébastien\AppData\Local\Temp\GoogleToolbarInstaller2.log
C:\Users\sébastien\AppData\Local\Temp\mgsqlite3.dll
O2 - BHO: Download and Sa [64Bits] - {076DDB13-DDF7-01BD-C3AF-B0624627EC92} . (...) -- C:\ProgramData\Download and Sa\509bd6e1eb773.ocx (.not file.)
O4 - GS\Programs: Thirst of Night.lnk - Clé orpheline
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4069087404-3107615383-3604061919-1000Core.job [922]
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4069087404-3107615383-3604061919-1000UA.job [944]
[MD5.00000000000000000000000000000000] [APT] [EPUpdater] (...) -- C:\Users\sébastien\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe (.not file.) [0]
[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-4069087404-3107615383-3604061919-1000Core] (.Facebook Inc..) -- C:\Users\sébastien\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096]
[MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-4069087404-3107615383-3604061919-1000UA] (.Facebook Inc..) -- C:\Users\sébastien\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096]
O43 - CFD: 28/03/2013 - 19:10:34 - [0,040] ----D C:\ProgramData\boost_interprocess
O43 - CFD: 08/11/2012 - 16:50:27 - [0,341] ----D C:\ProgramData\Premium
O44 - LFC:[MD5.10BC73C4AEC07BCDCF5A5D3347AC9B71] - 22/03/2013 - 10:04:54 ---A- . (...) -- C:\Windows\IE10_main.log [9536]
O45 - LFCP:[MD5.65C850556462087C3B2CB1C9D425BC71] - 27/03/2013 - 12:33:25 ---A- - C:\Windows\Prefetch\REG.EXE-A93A1343.pf
O45 - LFCP:[MD5.D2C1A7E0ABC6BD6D4DBD9570D8D8F5E3] - 27/03/2013 - 21:26:28 ---A- - C:\Windows\Prefetch\FROZENWAY.EXE-E7328D0C.pf
O45 - LFCP:[MD5.5FF3DE3440979B27FFD9D82FD3080D97] - 28/03/2013 - 17:21:32 ---A- - C:\Windows\Prefetch\OPTIMIZERPRO.EXE-09CA499D.pf
O45 - LFCP:[MD5.DABEF381CDD3667B0A239A7397BB8B45] - 28/03/2013 - 17:28:06 ---A- - C:\Windows\Prefetch\SOFFICE.BIN-F938F4DB.pf
O45 - LFCP:[MD5.A945A7781317B4A291424DE12FCF7966] - 28/03/2013 - 17:28:06 ---A- - C:\Windows\Prefetch\SOFFICE.EXE-05AADC00.pf
O45 - LFCP:[MD5.A09D7E4B2D9C018CA67269F6FE1DCC76] - 28/03/2013 - 17:28:06 ---A- - C:\Windows\Prefetch\SWRITER.EXE-83F9C56D.pf
O45 - LFCP:[MD5.AC578AA34BC07601CE7A501D1C03EBD1] - 28/03/2013 - 17:53:54 ---A- - C:\Windows\Prefetch\POKKI.EXE-224EECE0.pf
O45 - LFCP:[MD5.34F1CCF06811F1AAA688503CFF817E85] - 28/03/2013 - 19:09:08 ---A- - C:\Windows\Prefetch\SETAPM.EXE-20D028F2.pf
O45 - LFCP:[MD5.9785ED8A7F258E19FC42A6EB678BEEFA] - 28/03/2013 - 19:10:45 ---A- - C:\Windows\Prefetch\NOBUCLIENT.EXE-BE9CC47C.pf
O61 - LFC: 25/03/2013 - 21:12:07 ---A- C:\Users\sébastien\AppData\Local\Temp\MessengerCache\ErrorResponse.xml [2782]
O61 - LFC: 26/03/2013 - 12:24:03 ---A- C:\Users\sébastien\AppData\Local\Temp\utt9B0C.tmp.bat [98]
O61 - LFC: 26/03/2013 - 12:24:03 ---A- C:\Users\sébastien\AppData\Local\Temp\utt9BE4.tmp.bat [98]
O61 - LFC: 27/03/2013 - 06:38:14 ---A- C:\Users\sébastien\AppData\Local\Temp\nchpfiddbhbdnagofhkjlaiaejmkdcla.crx [926]
O61 - LFC: 27/03/2013 - 21:50:31 ---A- C:\Users\sébastien\AppData\Local\Temp\19023_10152074956451494_936322907_n.jpg [101910]
O61 - LFC: 28/03/2013 - 13:28:39 ---A- C:\Users\sébastien\AppData\Local\Temp\CRX_75DAF8CB7768\crl-set [803]
O61 - LFC: 28/03/2013 - 13:28:39 ---A- C:\Users\sébastien\AppData\Local\Temp\CRX_75DAF8CB7768\manifest.json [34]
O61 - LFC: 28/03/2013 - 19:09:00 ---A- C:\Users\sébastien\AppData\Local\Temp\pokki_deskband_rvl [314]
[MD5.B82994CB256839F3F404CAFB29060EC6] [SPRF][08/11/2012] (...) -- C:\Users\sébastien\AppData\Local\Temp\FastDownload.exe [86528]
[MD5.9831C439ED0BD31D625A93DD86389843] [SPRF][07/03/2013] (.Pas de propriétaire - APN Install Checker Library for Java.) -- C:\Users\sébastien\AppData\Local\Temp\JavaIC.dll [114376]
[MD5.71571DF7DBF4705F3C88222EF1B6FA79] [SPRF][07/03/2013] (.McAfee, Inc. - Partner Offer Manager Criteria Check.) -- C:\Users\sébastien\AppData\Local\Temp\msscct32.dll [341032]
[MD5.5688D47E0E6581893DC84E6B8225657F] [SPRF][10/03/2013] (.http://www.goforfiles.com/ - GoforFiles.) -- C:\Users\sébastien\AppData\Local\Temp\uninstall29984109.exe [6220936]
[MD5.4D40CA43CD548D8EE1A2A6498EAAC266] [SPRF][26/03/2013] (...) -- C:\Users\sébastien\AppData\Local\Temp\utt9B0C.tmp.bat [98]
[MD5.4D40CA43CD548D8EE1A2A6498EAAC266] [SPRF][26/03/2013] (...) -- C:\Users\sébastien\AppData\Local\Temp\utt9BE4.tmp.bat [98]
[MD5.8AB70809D194C9FBAB509ABBE8EBE406] [SPRF][09/01/2013] (...) -- C:\Users\sébastien\AppData\Local\Temp\utt9E5.tmp.bat [98]
[MD5.8AB70809D194C9FBAB509ABBE8EBE406] [SPRF][09/01/2013] (...) -- C:\Users\sébastien\AppData\Local\Temp\uttAFE.tmp.bat [98]
[MD5.C1DC7B1D25C8931B8C93B731CB8DE20B] [SPRF][06/10/2012] (...) -- C:\Users\sébastien\AppData\Local\Temp\uttEB0A.tmp.exe [6073344]
[MD5.E563A65BAEA25CEF8F49FB0228CB8555] [SPRF][18/02/2013] (...) -- C:\Users\sébastien\AppData\Local\Temp\vlc-2.0.5-win32.exe [22916830]
[MD5.EC42E8E9768D01AF0BB0FA0A614E2290] [SPRF][19/01/2013] (.Kreapixel - WebPlayerV2.) -- C:\Users\sébastien\AppData\Local\Temp\WebPlayerV2.upgrade.exe [3510784]
[MD5.B9F8D277062D0CFF0B29AB6DF4666358] [SPRF][04/09/2012] (.Pas de propriétaire - Windows Live Installer.) -- C:\Users\sébastien\AppData\Local\Temp\wlsetupc.exe [696616]
G1 - GCS: Preference [User Data\Default] http://www.delta-search.com
R3 - URLSearchHook: (no name) [64Bits] - {8e5025c2-8ea3-430d-80b8-a14151068a6d} . (.Microsoft Corporation - Navigateur Internet.) (No version) -- (.not file.)
[MD5.00000000000000000000000000000000] [APT] [Scheduled Update for Ask Toolbar] (...) -- C:\Program Files (x86)\Ask.com\UpdateTask.exe (.not file.) [0]
O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM][64Bits] -- {C28D96C0-6A90-459E-A077-A6706F4EC0FC}
O69 - SBI: SearchScopes [HKCU] {5E3F753B-DA5D-49CB-8FC9-CC84630DF222} - (Ask Search) - http://websearch.ask.com
[MD5.CE755676AE6D27A1EFEEFB0F3C70A929] [SPRF][07/03/2013] (.Ask.com - AskStub Application.) -- C:\Users\sébastien\AppData\Local\Temp\APNStub.exe [358600]
[MD5.73406FA9287B36CA4163797C73A2CD04] [SPRF][16/07/2012] (.Conduit Ltd. - Conduit Toolbar.) -- C:\Users\sébastien\AppData\Local\Temp\tb01NE.dll [4451144]
[MD5.73406FA9287B36CA4163797C73A2CD04] [SPRF][16/07/2012] (.Conduit Ltd. - Conduit Toolbar.) -- C:\Users\sébastien\AppData\Local\Temp\tbedrs.dll [4451144]
[MD5.225CCDCFE5625795647043679CB77112] [SPRF][18/01/2013] (...) -- C:\Users\sébastien\AppData\Local\Temp\wajam_install.exe [417256]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ef79f67a-6ad7-4715-a0f8-932fca442023}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF79F67A-6AD7-4715-A0F8-932FCA442023}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2]
[HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
[HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks]:{8E5025C2-8EA3-430D-80B8-A14151068A6D}
C:\Users\sébastien\AppData\Local\Temp\wajam_install.exe
C:\Users\sébastien\AppData\Local\Temp\tb01NE.dll
C:\Users\sébastien\AppData\Local\Temp\tbedrs.dll
O90 - PUC: "0C69D82C09A6E9540A776A07F6E40CCF" . (.Bing Bar.) -- C:\Windows\Installer\{C28D96C0-6A90-459E-A077-A6706F4EC0FC}\icon_installer_ico
EmptyTemp
EmptyFlash
FirewallRaz
ProxyFix
•
DÉCONNECTES TOI D'INTERNET ET FERMES TOUTES TES APPLICATIONS/!\ Utilisateur de Windows Vista et Windows Seven : Clique droit sur le logo de ZHPFix, « Exécuter en tant qu'Administrateur » /!\• Lances ZHPFix qui est sur ton Bureau.
• Copies & Colles le texte qui est dans ton Document Texte sur ton Bureau.
• Cliques sur le
deuxième bouton en partant de la gauche "Coller le Presse-Papier".
• Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaître.
• Cliques sur le bouton
GO.
• Patientes le temps de la Suppression.
• ZHPFix va copier le rapport d'analyse sur le Bureau sous le nom ZHPFixReport.txt
• Héberges le rapport ZHPFixReport.txt sur
CJoint.com• Postes le lien donné.