Script ZHPFix G2 - GCE: Preference [User Data\Default] [ieakfmpjhljbpbfpldjkddkjmmgjmgon] WebConnect v.1.0.0 (Activé) =>PUP.WebConnect G2 - GCE: Preference [User Data\Default] [ifohbjbgfchkkfhphahclmkpgejiplfo] Lightning Newtab v.1.1.5.7, (Activé) =>PUP.Elex G2 - GCE: Preference [User Data\Default] [oifomnalkciipmgkfgdjkepdocgiipjg] weDownload Manager v.1.24.94, (Activé) =>PUP.weDownloadManager G2 - GCE: Preference [User Data\Default] [pkhojieggfgllhllcegoffdcnmdeojgb] Iminent Chrome Toolbar v.1.0 (Activé) =>Adware.IMBooster G2 - GCE: Preference [User Data\Default] [ppmfajacidhcjbddpgmcmigffpppcadd] Shockwave Flash v.10,3,181,35 (Activé) =>Adware.SafeSave M2 - MFEP: prefs.js [alain - rzxdaawa.default\d019febe-eb2b-4057-a3f2-7def88f2c9cd@1cced8ec-0ffe-43ea-b4b2-fbce5de8e9a4.com] [] Plus-HD-4.9 v (..) =>Adware.PlusHD R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 0 O2 - BHO: CrossriderApp0045918 - {11111111-1111-1111-1111-110411591118} . (.Plus HD - Plus-HD-4.9 BHO.) -- C:\Program Files\Plus-HD-4.9\Plus-HD-4.9-bho.dll =>Adware.PlusHD O4 - GS\Startup [alain]: MyPC Backup.lnk . (...) -- C:\Program Files\MyPC Backup\MyPC Backup.exe (.not file.) =>PUP.MyPCBackup O4 - HKCU\..\Run: [NTRedirect] C:\Users\alain\AppData\Roaming\BabSolution\Shared\enhancedNT.dll (.not file.) =>Hijacker.BabSolution O4 - HKUS\S-1-5-21-3719439743-3176101640-2906415232-1000\..\Run: [NTRedirect] C:\Users\alain\AppData\Roaming\BabSolution\Shared\enhancedNT.dll (.not file.) =>Hijacker.BabSolution O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Plus-HD-4.9-chromeinstaller.job [1950] =>Adware.PlusHD O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Plus-HD-4.9-codedownloader.job [1218] =>Adware.PlusHD O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Plus-HD-4.9-enabler.job [1118] =>Adware.PlusHD O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Plus-HD-4.9-firefoxinstaller.job [2080] =>Adware.PlusHD O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Plus-HD-4.9-updater.job [1316] =>Adware.PlusHD [MD5.90A64787EF51413479E44E0669116CE1] [APT] [Plus-HD-4.9-chromeinstaller] (.Plus HD.) -- C:\Program Files\Plus-HD-4.9\Plus-HD-4.9-chromeinstaller.exe [832872] =>Adware.PlusHD [MD5.5C6D3F84769CA34156392D4065700920] [APT] [Plus-HD-4.9-codedownloader] (.Plus HD.) -- C:\Program Files\Plus-HD-4.9\Plus-HD-4.9-codedownloader.exe [528232] =>Adware.PlusHD [MD5.D2B48154D86135C93C744F4531AF7C95] [APT] [Plus-HD-4.9-enabler] (.Plus HD.) -- C:\Program Files\Plus-HD-4.9\Plus-HD-4.9-enabler.exe [348520] =>Adware.PlusHD [MD5.61F935C026F0D50E7786616DB3598441] [APT] [Plus-HD-4.9-firefoxinstaller] (.Plus HD.) -- C:\Program Files\Plus-HD-4.9\Plus-HD-4.9-firefoxinstaller.exe [890728] =>Adware.PlusHD [MD5.25081264BE938982FFB12BD438CAE340] [APT] [Plus-HD-4.9-updater] (.Plus HD.) -- C:\Program Files\Plus-HD-4.9\Plus-HD-4.9-updater.exe [358248] =>Adware.PlusHD O42 - Logiciel: Plus-HD-4.9 - (.Plus HD.) [HKLM] -- Plus-HD-4.9 =>Adware.PlusHD [HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider [HKCU\Software\AppDataLow\Software\Plus-HD-4.9] =>Adware.PlusHD [HKCU\Software\InstallCore] =>Adware.InstallCore [HKCU\Software\InstalledBrowserExtensions] =>Adware.VidSaver [HKCU\Software\Vittalia] =>PUP.Vittalia O43 - CFD: 23/12/2013 - 18:32:11 - [7,312] ----D C:\Program Files\Plus-HD-4.9 =>Adware.PlusHD O43 - CFD: 16/05/2013 - 13:02:11 - [0,487] ----D C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} O43 - CFD: 28/12/2013 - 11:15:58 - [0] ----D C:\Users\alain\AppData\Local\Plus-HD-4.9 =>Adware.PlusHD O43 - CFD: 06/11/2013 - 14:47:29 - [0] ----D C:\Users\alain\AppData\Local\Software O61 - LFC: 09/01/2014 - 12:23:21 ---A- . (...) -- C:\Users\alain\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjflmfkjppbmejlfbhlpgjnomdoefkfa\1.26.36_0\crossriderManifest.json [517] =>PUP.CrossRider O61 - LFC: 09/01/2014 - 12:23:22 ---A- . (...) -- C:\Users\alain\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjflmfkjppbmejlfbhlpgjnomdoefkfa\1.26.36_0\js\lib\installer.js [757] [HKLM\Software\Google\Chrome\Extensions\ieakfmpjhljbpbfpldjkddkjmmgjmgon] =>PUP.WebConnect^ [HKLM\Software\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo] =>PUP.Elex^ [HKLM\Software\Google\Chrome\Extensions\oifomnalkciipmgkfgdjkepdocgiipjg] =>PUP.weDownloadManager^ [HKLM\Software\Google\Chrome\Extensions\pkhojieggfgllhllcegoffdcnmdeojgb] =>Adware.IMBooster^ [HKLM\Software\Google\Chrome\Extensions\ppmfajacidhcjbddpgmcmigffpppcadd] =>Adware.SafeSave^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411591118}] =>Adware.PlusHD^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Plus-HD-4.9] =>Adware.PlusHD^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\DealPly] =>PUP.DealPly [HKCU\Software\InstallCore] =>Adware.InstallCore [HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider [HKCU\Software\InstalledBrowserExtensions\] =>PUP.CrossRider [HKCU\Software\InstalledBrowserExtensions] =>PUP.CrossRider [HKLM\Software\Classes\CrossriderApp0045918.BHO] =>PUP.CrossRider [HKLM\Software\Classes\CrossriderApp0045918.BHO.1] =>PUP.CrossRider [HKLM\Software\Classes\CrossriderApp0045918.Sandbox] =>PUP.CrossRider [HKLM\Software\Classes\CrossriderApp0045918.Sandbox.1] =>PUP.CrossRider [HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311431144}] =>PUP.CrossRider [HKLM\Software\Classes\CLSID\{11111111-1111-1111-1111-110411591118}] =>PUP.CrossRider [HKLM\Software\Classes\CLSID\{22222222-2222-2222-2222-220422592218}] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311431144}] =>PUP.CrossRider [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:NTRedirect =>Hijacker.BabSolution^ C:\Users\alain\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieakfmpjhljbpbfpldjkddkjmmgjmgon =>PUP.WebConnect^ C:\Users\alain\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo =>PUP.Elex^ C:\Users\alain\AppData\Local\Google\Chrome\User Data\Default\Extensions\oifomnalkciipmgkfgdjkepdocgiipjg =>PUP.weDownloadManager^ C:\Users\alain\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkhojieggfgllhllcegoffdcnmdeojgb =>Adware.IMBooster^ C:\Users\alain\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppmfajacidhcjbddpgmcmigffpppcadd =>Adware.SafeSave^ C:\Users\alain\AppData\Roaming\Mozilla\Firefox\Profiles\rzxdaawa.default\extensions\d019febe-eb2b-4057-a3f2-7def88f2c9cd@1cced8ec-0ffe-43ea-b4b2-fbce5de8e9a4.com =>Adware.PlusHD^ C:\Program Files\Plus-HD-4.9 =>Adware.PlusHD^ C:\Users\alain\AppData\Local\Plus-HD-4.9 =>Adware.PlusHD^ C:\Users\alain\AppData\Local\Software =>Adware.Boxore C:\Users\alain\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbpohikckhbcljgombipcdoinkaedlfa =>Spyware.SmartDisplay C:\Users\alain\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff =>Adware.MyWebSearch C:\Windows\Tasks\Plus-HD-4.9-chromeinstaller.job =>Adware.PlusHD^ C:\Windows\Tasks\Plus-HD-4.9-codedownloader.job =>Adware.PlusHD^ C:\Windows\Tasks\Plus-HD-4.9-enabler.job =>Adware.PlusHD^ C:\Windows\Tasks\Plus-HD-4.9-firefoxinstaller.job =>Adware.PlusHD^ C:\Windows\Tasks\Plus-HD-4.9-updater.job =>Adware.PlusHD^ C:\Program Files\Plus-HD-4.9\Plus-HD-4.9-chromeinstaller.exe =>Adware.PlusHD^ C:\Program Files\Plus-HD-4.9\Plus-HD-4.9-codedownloader.exe =>Adware.PlusHD^ C:\Program Files\Plus-HD-4.9\Plus-HD-4.9-enabler.exe =>Adware.PlusHD^ C:\Program Files\Plus-HD-4.9\Plus-HD-4.9-firefoxinstaller.exe =>Adware.PlusHD^ C:\Program Files\Plus-HD-4.9\Plus-HD-4.9-updater.exe =>Adware.PlusHD^ [HKCU\Software\AppDataLow\Software\Plus-HD-4.9] =>Adware.PlusHD^ [HKCU\Software\Vittalia] =>PUP.Vittalia^ O43 - CFD: 15/12/2009 - 18:08:32 - [0,002] ----D C:\Users\alain\AppData\Roaming\Classes de site O43 - CFD: 15/12/2009 - 18:24:53 - [0,218] ----D C:\Users\alain\AppData\Roaming\Sites O43 - CFD: 31/08/2013 - 17:28:20 - [0,086] ----D C:\Users\alain\AppData\Local\avgchrome [MD5.AF7D79AD57715E6E110CAC0E75453094] [SPRF][09/01/2014] (...) -- C:\ProgramData\nvModes.dat [401966] P2 - FPN: [HKLM] [@pandonetworks.com/PandoWebPlugin] - (...) -- C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (.not file.) O42 - Logiciel: µTorrent - (...) [HKCU] -- uTorrent =>P2P.µTorrent [HKCU\Software\BitTorrent] =>P2P.BitTorrent O43 - CFD: 20/01/2012 - 09:26:32 - [0] ----D C:\Program Files\Pando Networks O43 - CFD: 23/03/2008 - 19:57:01 - [0,210] ----D C:\Program Files\uTorrent =>P2P.µTorrent O43 - CFD: 26/02/2012 - 14:55:35 - [0,017] ----D C:\Users\alain\AppData\Roaming\uTorrent =>P2P.µTorrent O87 - FAEL: "TCP Query User{AE56CD8C-CCC3-4905-AF43-77D8C6E9D98B}C:\program files\utorrent\utorrent.exe" | In - Public - P6 - TRUE | .(...) -- C:\program files\utorrent\utorrent.exe =>P2P.µTorrent O87 - FAEL: "UDP Query User{B99F46AB-A668-4113-975F-8582522EF8B3}C:\program files\utorrent\utorrent.exe" | In - Public - P17 - TRUE | .(...) -- C:\program files\utorrent\utorrent.exe =>P2P.µTorrent [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent] =>P2P.µTorrent^ C:\Program Files\uTorrent =>P2P.µTorrent^ C:\Users\alain\AppData\Roaming\uTorrent =>P2P.µTorrent^ [HKCU\Software\BitTorrent] =>P2P.BitTorrent^ G2 - GCE: Preference [User Data\Default] [eooncjejnppfjjklapaamhcdmjbilmde] Delta Toolbar v.1.4 (Activé) =>Toolbar.DeltaSearch [HKCU\Software\ForumerIT] =>Toolbar.Forumer [HKCU\Software\Softonic] =>Toolbar.Conduit [MD5.6989692240B930C0A368175BD1C6CCF0] [WIS][18/07/2011] (.Skype Technologies S.A. - Skype Toolbars.) -- C:\Windows\Installer\1b1489.msi [1214464] [HKLM\Software\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde] =>Toolbar.DeltaSearch^ [HKLM\Software\Classes\Interface\{D6094FC6-821F-474C-8D73-C13066CD178D}] =>Toolbar.Agent [HKCU\Software\Softonic] =>Toolbar.Conduit C:\Users\alain\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde =>Toolbar.DeltaSearch^ C:\Users\alain\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp =>Toolbar.Wajam [HKCU\Software\ForumerIT] =>Toolbar.Forumer^ FirewallRaz PROXYFix EmptyTemp EmptyFlash EmptyClsid