non j'ai pas réussi pour ZHPfix :(
par contre voila pour mon disque , j'ai pas l'impression que ce soit très bon?
Script ZHPFix
O42 - Logiciel: Favorit (aqyywmc) - (...) [HKLM] -- aqyywmc => Infection Diverse (Favorit.Adw)
O42 - Logiciel: Boxore Client - (.Boxore OU.) [HKLM] -- {4C6F4EE5-F42F-4288-B970-2B5FAD1D85BD} =>PUP.Optional.Boxore
HKLM\SOFTWARE\Systweak =>PUP.Optional.Systweak
HKCU\SOFTWARE\LdShih => Infection Diverse (Trojan Horse)
HKCU\SOFTWARE\systweak =>PUP.Optional.Systweak
O43 - CFD: 2013/11/14 16:40:33 - [0] D -- C:\Program Files\Winletmin => Infection Diverse (TR/Agent.63216)
O43 - CFD: 2013/09/02 20:06:30 - [] D -- C:\ProgramData\Media Get LLC =>PUP.Optional.MediaGet
O43 - CFD: 2015/01/07 01:22:33 - [0] D -- C:\ProgramData\Systweak =>PUP.Optional.Systweak
O43 - CFD: 2014/11/11 00:43:46 - [0] D -- C:\Users\jeremy\AppData\Roaming\ASP => PUP.AdvancedSystemProtector
O43 - CFD: 2015/01/16 18:31:48 - [] D -- C:\Users\jeremy\AppData\Roaming\systweak =>PUP.Optional.Systweak
O53 - SMSR:HKLM\...\startupreg\HotbarSA [Key] . (...) -- C:\Program Files\Hotbar\bin\11.0.78.0\HotbarSA.exe (.not file.) => Infection BT (Adware.HotBar)
O53 - SMSR:HKLM\...\startupreg\WeatherDPA [Key] . (...) -- C:\Program Files\Hotbar\bin\11.0.78.0\Weather.exe (.not file.) => Infection BT (Adware.HotBar)
O53 - SMSR:HKLM\...\startupreg\WinUsr [Key] . (...) -- C:\Program Files\Winsudate\gibusr.exe (.not file.) => Infection Diverse (TR/Agent.63216)
O69 - SBI: SearchScopes [HKCU] {DECA3892-BA8F-44b8-A993-A466AD694AE4} - (Yahoo!) - http://fr.search.yahoo.com/ => Adware.Bandoo
O87 - FAEL: "TCP Query User{7444B985-097F-421E-A427-7F74BA090CEE}C:\program files\java\jre1.6.0_07\launch4j-tmp\crazyloader.exe" [In-None-P6-TRUE] .(.Sun Microsystems, Inc. - Java Platform SE binary.) -- C:\program files\java\jre1.6.0_07\launch4j-tmp\crazyloader.exe =>PUP.Optional.SPointer
O87 - FAEL: "UDP Query User{DC2B4114-57DC-4F2B-8F7B-3F78F6EBD660}C:\program files\java\jre1.6.0_07\launch4j-tmp\crazyloader.exe" [In-None-P17-TRUE] .(.Sun Microsystems, Inc. - Java Platform SE binary.) -- C:\program files\java\jre1.6.0_07\launch4j-tmp\crazyloader.exe =>PUP.Optional.SPointer
O90 - PUC: "5EE4F6C4F24F88249B07B2F5DAD158DB" . (.Boxore Client.) -- C:\Windows\Installer\{4C6F4EE5-F42F-4288-B970-2B5FAD1D85BD}\boxore.ico =>PUP.Optional.Boxore
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4C6F4EE5-F42F-4288-B970-2B5FAD1D85BD} =>PUP.Optional.Boxore
HKLM\SOFTWARE\Systweak =>PUP.Optional.Systweak
HKCU\SOFTWARE\systweak =>PUP.Optional.Systweak
C:\ProgramData\Media Get LLC =>PUP.Optional.MediaGet
C:\ProgramData\Systweak =>PUP.Optional.Systweak
C:\Users\jeremy\AppData\Roaming\systweak =>PUP.Optional.Systweak
C:\program files\java\jre1.6.0_07\launch4j-tmp\crazyloader.exe =>PUP.Optional.SPointer
C:\Windows\Installer\{4C6F4EE5-F42F-4288-B970-2B5FAD1D85BD}\boxore.ico =>PUP.Optional.Boxore
HKLM\Software\Classes\Installer\Products\5EE4F6C4F24F88249B07B2F5DAD158DB =>PUP.Optional.Boxore
HKLM\Software\Classes\Installer\Features\5EE4F6C4F24F88249B07B2F5DAD158DB =>PUP.Optional.Boxore
O4 - HKLM\..\Run: [NPSStartup] (Orphean)
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{00D16DF6-A23E-4973-8643-B61695434B95} [3024]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{0D5D55CE-95D0-4576-9CFA-FE4F50648063} [3034]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{0D932098-7C6B-48D7-B453-68104FF97E22} [3064]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{1EADFBCA-7C30-4A06-859A-536C4EB45948} [3050]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{2A66E1BE-AE98-4B8C-B421-1F85E2AB910A} [2954]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{407551F9-D29B-4B5D-A78C-4873A196831F} [3056]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{5F3C8AFF-AD04-47AF-916A-487B7A6E3CE9} [3024]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{61700183-2A97-44D9-BBDB-2493D3FB4FD1} [2954]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{62662EA3-D55D-46C8-8CD5-DDC793712B1A} [3076]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{A45E2B15-13C2-4E9B-95D1-F1BE01D9D8CB} [3060]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{D14F6F6A-C9E8-40C6-B4DF-45185665E466} [2980]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{D448D83E-EFD7-4526-888F-7EB80DD9C69D} [3082]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{EA54948D-E77A-4833-A4E1-0AE4E856B80C} [3030]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{F47B15C6-4BF7-490C-9649-BFDB0E184895} [3068]
O39 - APT: {FA234067-0220-45B3-9D96-4ECCA906B6AF} - (...) -- C:\Windows\System32\Tasks\{FA234067-0220-45B3-9D96-4ECCA906B6AF} [3062]
SysRestore
FirewallRaz
EmptyPrefetch
EmptyTemp
EmptyFlash
Script ZHPFix
O42 - Logiciel: Favorit (aqyywmc) - (...) [HKLM] -- aqyywmc => Infection Diverse (Favorit.Adw)
O42 - Logiciel: Boxore Client - (.Boxore OU.) [HKLM] -- {4C6F4EE5-F42F-4288-B970-2B5FAD1D85BD} =>PUP.Optional.Boxore
HKLM\SOFTWARE\Systweak =>PUP.Optional.Systweak
HKCU\SOFTWARE\LdShih => Infection Diverse (Trojan Horse)
HKCU\SOFTWARE\systweak =>PUP.Optional.Systweak
O43 - CFD: 2013/11/14 16:40:33 - [0] D -- C:\Program Files\Winletmin => Infection Diverse (TR/Agent.63216)
O43 - CFD: 2013/09/02 20:06:30 - [] D -- C:\ProgramData\Media Get LLC =>PUP.Optional.MediaGet
O43 - CFD: 2015/01/07 01:22:33 - [0] D -- C:\ProgramData\Systweak =>PUP.Optional.Systweak
O43 - CFD: 2014/11/11 00:43:46 - [0] D -- C:\Users\jeremy\AppData\Roaming\ASP => PUP.AdvancedSystemProtector
O43 - CFD: 2015/01/16 18:31:48 - [] D -- C:\Users\jeremy\AppData\Roaming\systweak =>PUP.Optional.Systweak
O53 - SMSR:HKLM\...\startupreg\HotbarSA [Key] . (...) -- C:\Program Files\Hotbar\bin\11.0.78.0\HotbarSA.exe (.not file.) => Infection BT (Adware.HotBar)
O53 - SMSR:HKLM\...\startupreg\WeatherDPA [Key] . (...) -- C:\Program Files\Hotbar\bin\11.0.78.0\Weather.exe (.not file.) => Infection BT (Adware.HotBar)
O53 - SMSR:HKLM\...\startupreg\WinUsr [Key] . (...) -- C:\Program Files\Winsudate\gibusr.exe (.not file.) => Infection Diverse (TR/Agent.63216)
O69 - SBI: SearchScopes [HKCU] {DECA3892-BA8F-44b8-A993-A466AD694AE4} - (Yahoo!) - http://fr.search.yahoo.com/ => Adware.Bandoo
O87 - FAEL: "TCP Query User{7444B985-097F-421E-A427-7F74BA090CEE}C:\program files\java\jre1.6.0_07\launch4j-tmp\crazyloader.exe" [In-None-P6-TRUE] .(.Sun Microsystems, Inc. - Java Platform SE binary.) -- C:\program files\java\jre1.6.0_07\launch4j-tmp\crazyloader.exe =>PUP.Optional.SPointer
O87 - FAEL: "UDP Query User{DC2B4114-57DC-4F2B-8F7B-3F78F6EBD660}C:\program files\java\jre1.6.0_07\launch4j-tmp\crazyloader.exe" [In-None-P17-TRUE] .(.Sun Microsystems, Inc. - Java Platform SE binary.) -- C:\program files\java\jre1.6.0_07\launch4j-tmp\crazyloader.exe =>PUP.Optional.SPointer
O90 - PUC: "5EE4F6C4F24F88249B07B2F5DAD158DB" . (.Boxore Client.) -- C:\Windows\Installer\{4C6F4EE5-F42F-4288-B970-2B5FAD1D85BD}\boxore.ico =>PUP.Optional.Boxore
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4C6F4EE5-F42F-4288-B970-2B5FAD1D85BD} =>PUP.Optional.Boxore
HKLM\SOFTWARE\Systweak =>PUP.Optional.Systweak
HKCU\SOFTWARE\systweak =>PUP.Optional.Systweak
C:\ProgramData\Media Get LLC =>PUP.Optional.MediaGet
C:\ProgramData\Systweak =>PUP.Optional.Systweak
C:\Users\jeremy\AppData\Roaming\systweak =>PUP.Optional.Systweak
C:\program files\java\jre1.6.0_07\launch4j-tmp\crazyloader.exe =>PUP.Optional.SPointer
C:\Windows\Installer\{4C6F4EE5-F42F-4288-B970-2B5FAD1D85BD}\boxore.ico =>PUP.Optional.Boxore
HKLM\Software\Classes\Installer\Products\5EE4F6C4F24F88249B07B2F5DAD158DB =>PUP.Optional.Boxore
HKLM\Software\Classes\Installer\Features\5EE4F6C4F24F88249B07B2F5DAD158DB =>PUP.Optional.Boxore
O4 - HKLM\..\Run: [NPSStartup] (Orphean)
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{00D16DF6-A23E-4973-8643-B61695434B95} [3024]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{0D5D55CE-95D0-4576-9CFA-FE4F50648063} [3034]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{0D932098-7C6B-48D7-B453-68104FF97E22} [3064]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{1EADFBCA-7C30-4A06-859A-536C4EB45948} [3050]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{2A66E1BE-AE98-4B8C-B421-1F85E2AB910A} [2954]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{407551F9-D29B-4B5D-A78C-4873A196831F} [3056]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{5F3C8AFF-AD04-47AF-916A-487B7A6E3CE9} [3024]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{61700183-2A97-44D9-BBDB-2493D3FB4FD1} [2954]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{62662EA3-D55D-46C8-8CD5-DDC793712B1A} [3076]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{A45E2B15-13C2-4E9B-95D1-F1BE01D9D8CB} [3060]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{D14F6F6A-C9E8-40C6-B4DF-45185665E466} [2980]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{D448D83E-EFD7-4526-888F-7EB80DD9C69D} [3082]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{EA54948D-E77A-4833-A4E1-0AE4E856B80C} [3030]
O39 - APT: Orphean - (...) -- C:\Windows\System32\Tasks\{F47B15C6-4BF7-490C-9649-BFDB0E184895} [3068]
O39 - APT: {FA234067-0220-45B3-9D96-4ECCA906B6AF} - (...) -- C:\Windows\System32\Tasks\{FA234067-0220-45B3-9D96-4ECCA906B6AF} [3062]
SysRestore
FirewallRaz
EmptyPrefetch
EmptyTemp
EmptyFlash
Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 8 invités
.: Nous contacter :: Flux RSS :: Données personnelles :. |