sélectionnes et copies les lignes ci dessous Script ZHPFix [HKCU\Software\ForumerIT] [HKCU\Software\ForumerIT] [MD5.85421474544692E7D06C8CCA9E4EF38F] - (...) -- C:\ProgramData\89c775be-12de-4e15-846c-6b3e6a8c39a2\maintainer.exe [123640] [PID.1928] O4 - HKCU\..\Run: [Yahoo! Search] C:\Users\bilout\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe (.not file.) =>PUP.PaybyAds O4 - HKUS\S-1-5-21-407189658-2721335936-744560120-1000\..\Run: [Yahoo! Search] C:\Users\bilout\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe (.not file.) =>PUP.PaybyAds O23 - Service: MaintainerSvc2.61.4907295 (MaintainerSvc2.61.4907295) . (...) - C:\ProgramData\89c775be-12de-4e15-846c-6b3e6a8c39a2\maintainer.exe =>PUP.MaintainerSvc [MD5.00000000000000000000000000000000] [APT] [{C1B9CD60-BE9C-4B9F-92E5-AED2148E438B}] (...) -- C:\Program Files (x86)\Win Palace Euro Casino French\casino.exe (.not file.) [0] O42 - Logiciel: Win Palace Euro Casino French - (.RealTimeGaming Software.) [HKLM][64Bits] -- {236D7AE8-7856-49AD-9C10-9AFD73E998E2} [HKLM\Software\Wow6432Node\vi-viewSoftware] =>Hijacker.MyhomeViview O43 - CFD: 27/06/2013 - 09:58:03 - [] ----D C:\Users\bilout\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Casino770 O44 - LFC:[MD5.7A1C4D6345096ADA99268D2D06B6F1B6] - 28/11/2014 - 08:47:32 ---A- . (.StdLib - StdLib.) -- C:\Windows\System32\Drivers\{e9ab7dfa-9d2f-4c48-8fd4-5314a020a2b5}Gw64.sys [48792] =>PUP.LinkiDoo O45 - LFCP:[MD5.3D25F29DF197B95DAC37335F5FFBBBE3] - 12/12/2014 - 16:51:28 ---A- - C:\Windows\Prefetch\SUNRISEBROWSE.BOAS.EXE-6ED38A7F.pf =>PUP.SunriseBrowse O45 - LFCP:[MD5.DC8271FBADB149B20BA0273AF80232D6] - 12/12/2014 - 16:55:18 ---A- - C:\Windows\Prefetch\SUNRISEBROWSE.BOASHELPER.EXE-47B4B487.pf =>PUP.SunriseBrowse O45 - LFCP:[MD5.F1306167AA9B0A6A8A4C41E7167888B8] - 12/12/2014 - 16:51:27 ---A- - C:\Windows\Prefetch\SUNRISEBROWSE.BOASPRT.EXE-76F6C5F5.pf =>PUP.SunriseBrowse O45 - LFCP:[MD5.D959E10598BBD4491DD634B3C187E9F2] - 12/12/2014 - 16:55:25 ---A- - C:\Windows\Prefetch\SUNRISEBROWSE.BROWSERADAPTER.-A66C107F.pf =>PUP.SunriseBrowse O45 - LFCP:[MD5.1F65CE929CD0959707311D98A4C170C9] - 12/12/2014 - 16:55:25 ---A- - C:\Windows\Prefetch\SUNRISEBROWSE.BROWSERADAPTER6-3292A071.pf =>PUP.SunriseBrowse O45 - LFCP:[MD5.82CE3DFA1ACE112D65B4291A8C06CE52] - 12/12/2014 - 16:54:27 ---A- - C:\Windows\Prefetch\SUNRISEBROWSE.BRT.HELPER.EXE-9692DE04.pf =>PUP.SunriseBrowse O45 - LFCP:[MD5.A1008ED9FF55EC70E0E2936B72F400E5] - 12/12/2014 - 16:55:17 ---A- - C:\Windows\Prefetch\SUNRISEBROWSE.EXPEXT.EXE-76CD568C.pf =>PUP.SunriseBrowse O45 - LFCP:[MD5.91B33635EE863D6D7EE71F00CCDC2D44] - 12/12/2014 - 14:33:09 ---A- - C:\Windows\Prefetch\SUNRISEBROWSE.PURBROWSE64.EXE-05024325.pf =>PUP.SunriseBrowse O45 - LFCP:[MD5.733B37D4C1B39DFC067BBE21AAE08530] - 12/12/2014 - 14:29:44 ---A- - C:\Windows\Prefetch\UPDATESUNRISEBROWSE.EXE-730F5A76.pf =>PUP.SunriseBrowse O45 - LFCP:[MD5.7BA3D24DEE688355DA115AE235DE6E4C] - 12/12/2014 - 14:32:59 ---A- - C:\Windows\Prefetch\UTILSUNRISEBROWSE.EXE-4120BBAE.pf =>PUP.SunriseBrowse O58 - SDL:27/11/2014 - 00:04:50 ---A- . (.StdLib - StdLib.) -- C:\Windows\System32\Drivers\{ac2b164b-7189-4743-b803-06981a00f9d8}Gw64.sys [48792] =>PUP.LinkiDoo O58 - SDL:28/11/2014 - 08:47:32 ---A- . (.StdLib - StdLib.) -- C:\Windows\System32\Drivers\{e9ab7dfa-9d2f-4c48-8fd4-5314a020a2b5}Gw64.sys [48792] =>PUP.LinkiDoo [MD5.9CD5109EF7367DF192989B4D26B0E344] [WIS][01/12/2013] (.BonanzaDeals - Google Update Helper.) -- C:\Windows\Installer\14dc92.msi [40960] =>Adware.BonanzaDeals SR - | Auto 12/12/2014 123640 | (MaintainerSvc2.61.4907295) . (...) - C:\ProgramData\89c775be-12de-4e15-846c-6b3e6a8c39a2\maintainer.exe =>PUP.MaintainerSvc [HKLM\SYSTEM\CurrentControlSet\Services\MaintainerSvc2.61.4907295] =>PUP.MaintainerSvc^ [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:Yahoo! Search =>PUP.PaybyAds^ [HKLM\Software\Wow6432Node\vi-viewSoftware] =>Hijacker.MyhomeViview^ C:\Windows\Installer\14dc92.msi =>Adware.BonanzaDeals^ [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank O3 - Toolbar: (no name) - [HKLM]{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} Clé orpheline O42 - Logiciel: Casino 770 - (.Global Interactive Limited.) [HKCU][64Bits] -- Casino 770 [HKCU\Software\EuroKingCasino] [HKCU\Software\Realtime Gaming Software] [HKLM\Software\Wow6432Node\EuroKingCasino] O43 - CFD: 11/02/2013 - 14:53:12 - [] ----D C:\Program Files (x86)\CasinoFiz O43 - CFD: 04/08/2013 - 19:48:49 - [] ----D C:\ProgramData\IM O43 - CFD: 20/05/2013 - 14:16:08 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EuroKingCasino O43 - CFD: 04/08/2013 - 19:50:14 - [] ----D C:\Users\bilout\AppData\Local\IM FirewallRaz EmptyFlash EmptyPrefetch Emptytemp ShortcutFix Lance ZHPFIX Cliques sur importer colles les lignes dans le cadre blanc tu supprimes avec le bouton GO copies colles le contenu du fichier C:\Users\....\AppData\Roaming\ZHP\ZHPFix[R1].txt @++