~ ZHPCleaner v2014.11.19.230 by Nicolas Coolman (19/11/2014) ~ Run by serge (Administrator) (20/11/2014 17:11:35) ~ Forum : http://forum.nicolascoolman.fr ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Type : Réparer ~ Report : C:\Users\serge\Desktop\ZHPCleaner.txt ~ Quarantine : C:\Users\serge\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt ~ UAC : Activate ~ Windows 7, 32-bit Service Pack 1 (Build 7601) ---\\ Service. (0) ~ Aucun élément malicieux trouvé. ---\\ Navigateur internet. (103) REMPLACÉ Quicklaunch: C:\Users\serge\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk (http://isearch.omiga-plus.com/?type=sc&ts=14052816[...]) REMPLACÉ SystemTools: C:\Users\serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk (http://isearch.omiga-plus.com/?type=sc&ts=14052816[...]) REMPLACÉ Programs: C:\Users\serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk (http://isearch.omiga-plus.com/?type=sc&ts=14052816[...]) REMPLACÉ IE Params: Start Page ( hxxps://fr.yahoo.com/?fr=hp-avast&type=avastbcl ) REMPLACÉ IE Params: Search Page ( hxxps://fr.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} ) REMPLACÉ IE Params: Search Bar ( hxxps://fr.yahoo.com/?fr=hp-avast&type=avastbcl ) REMPLACÉ IE Params: Tabs ( about:newtab ) REMPLACÉ IE Params: Start Page ( hxxps://fr.yahoo.com/?fr=hp-avast&type=avastbcl ) REMPLACÉ IE Params: Search Page ( hxxps://fr.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms} ) REMPLACÉ IE Params: Search Bar ( hxxps://fr.yahoo.com/?fr=hp-avast&type=avastbcl ) REMPLACÉ Firefox: [clz6jt6r.default] user_pref( extensions.toolbar.mindspark._8hMembers_.browser.startup.homepage.prev , hxxp://www.trov[...] TROUVÉ FF: C:\Users\serge\AppData\Roaming\Mozilla\Firefox\Profiles\clz6jt6r.default\prefs.js REMPLACÉ FF: [clz6jt6r.default] - user_pref("CT3232586.SearchFromAddressBarUrl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT323[...] (Toolbar.Conduit) REMPLACÉ FF: [clz6jt6r.default] - user_pref("CT3232586.installId", "ConduitStubGeneric"); (Toolbar.Conduit) REMPLACÉ FF: [clz6jt6r.default] - user_pref("CT3232586.installType", "ConduitIntegration"); (Toolbar.Conduit) REMPLACÉ FF: [clz6jt6r.default] - user_pref("CT3232586.originalSearchEngine", "Mysearchdial"); (Adware.MyWebSearch) REMPLACÉ FF: [clz6jt6r.default] - user_pref("CT3232586.originalSearchEngineName", "Mysearchdial"); (Adware.MyWebSearch) REMPLACÉ FF: [clz6jt6r.default] - user_pref("browser.search.order.1", "Yahoo! (Avast)"); (PUP.Babylon) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.AL", 4); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.aflt", "ast_cmi_14_44_ch"); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.appId", "{9CB2CD61-FFA0-406C-9D2D-8FDE6F4A4D8A}"); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.cd", "2XzuyEtN2Y1L1QzutDtDtC0A0AtDzytB0D0EtBtD0DtCyEzytN0D0Tzu0StCt[...] (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.cr", "785484714"); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.dfltLng", ""); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.dfltSrch", true); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.dnsErr", true); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.excTlbr", false); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.hmpg", true); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.hmpgUrl", "http://astromenda.com/?f=1&a=ast_cmi_14_44_ch&cd=2XzuyEt[...] (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.id", "001AA092DE20D149"); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.instlDay", "16373"); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.instlRef", "142905_b"); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.newTabUrl", "http://astromenda.com/?f=2&a=ast_cmi_14_44_ch&cd=2Xzuy[...] (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.prdct", "astrmndasr"); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.prtnrId", "WSE_Astromenda"); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.srchPrvdr", "Astromenda"); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.tlbrId", ""); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.tlbrSrchUrl", "http://astromenda.com/?f=3&a=ast_cmi_14_44_ch&cd=2Xz[...] (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.vrsn", ""); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr.vrsni", ""); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr_i.newTab", true); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr_i.smplGrp", "none"); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.astrmndasr_i.vrsnTs", "12:40:29"); (PUP.Astromenda) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.awrigtdamonyahoocom65055.65055.internaldb.monetization_plugin_bundledUrls.expi[...] (PUP.Monetization) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.awrigtdamonyahoocom65055.65055.internaldb.monetization_plugin_bundledUrls.valu[...] (PUP.Monetization) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.awrigtdamonyahoocom65055.65055.internaldb.monetization_plugin_bundledWithHash.[...] (PUP.Monetization) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.awrigtdamonyahoocom65055.65055.internaldb.monetization_plugin_bundledWithHash.[...] (PUP.Monetization) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.awrigtdamonyahoocom65055.65055.internaldb.monetization_plugin_notBundledArr_.e[...] (PUP.Monetization) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.awrigtdamonyahoocom65055.65055.internaldb.monetization_plugin_notBundledArr_.v[...] (PUP.Monetization) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.awrigtdamonyahoocom65055.65055.internaldb.monetization_plugin_regBundledWithSo[...] (PUP.Monetization) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.awrigtdamonyahoocom65055.65055.internaldb.monetization_plugin_regBundledWithSo[...] (PUP.Monetization) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.crossrider.bic", "14960e4c025d4e7e11b1f0c6ba887d58"); (PUP.CrossRider) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.irmysearch.aflt", "ir_14_17_ch"); (Adware.MyWebSearch) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzutDtDtC0A0AtDzytB0D0EtBtD0DtCyEzytN0D0Tzu0Szzy[...] (Adware.MyWebSearch) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.irmysearch.cr", "74245029"); (Adware.MyWebSearch) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.irmysearch.instlRef", "140305_b"); (Adware.MyWebSearch) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.mywebsearch.prevKwdEnabled", true); (Adware.MyWebSearch) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.mywebsearch.prevKwdURL", "http://trovi.com/ResultsExt.aspx?ctid=CT3232586&octi[...] (Adware.MyWebSearch) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.browser.search.defaultenginename.prev", "Conduit[...] (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.browser.search.defaultenginename.savedPrev", "tr[...] (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.browser.search.defaultenginename.tb", "Ask Web S[...] (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.browser.search.selectedEngine.prev", "Conduit Se[...] (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.browser.search.selectedEngine.savedPrev", "true"[...] (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.browser.search.selectedEngine.tb", "Ask Web Sear[...] (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.browser.startup.homepage.savedPrev", "true"); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.browser.startup.homepage.tb", "http://home.tb.as[...] (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.browser.startup.page.savedPrev", 1); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.browser.startup.page.tb", 1); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.firstKnownVersion", "6.33.3.42841"); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.homepage", "http://home.tb.ask.com/index.jhtml?p[...] (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.hp.enabled", true); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.hp.lastGuardTime", -1753437261); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.hp.numGuards", 1); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.initialized", true); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.installKeysSource", "LocalStorage"); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.installType", "XPI"); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.installation.contextKey", ""); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.installation.installDate", "2014032604"); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.installation.partnerId", "^AYY^xdm073^YYA^fr"); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.installation.partnerSubId", "flvrunner"); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.installation.pixelUrl", "http://allin1convert.dl[...] (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.installation.success", true); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.installation.toolbarId", "96198D6C-6F08-4549-A11[...] (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.isCompliantUninstallImplementation", true); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.lastActivePing", "1406287999775"); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.lastKnownVersion", "6.58.4.18153"); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.options.defaultSearch", true); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.options.homePageEnabled", true); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.options.keywordEnabled", true); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.options.tabEnabled", true); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.partnerPixelFired", true); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.searchHistory", "support@gcextract.com"); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.successUrl", "http://flvrunner.com/thankyou.php"[...] (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.toolbarCollapsed", true); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark._8hMembers_.weather.location", "10001"); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark.hp.enabled", true); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "allin1convert@mindspark.com"); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("extensions.toolbar.mindspark.lastInstalled", "allin1convert@mindspark.com"); (Adware.Bandoo) REMPLACÉ FF: [clz6jt6r.default] - user_pref("smartbar.conduitHomepageList", "http://search.conduit.com/?ctid=CT3232586&octid=CT3232586[...] (Toolbar.Conduit) REMPLACÉ FF: [clz6jt6r.default] - user_pref("smartbar.conduitSearchAddressUrlList", "http://search.conduit.com/ResultsExt.aspx?ctid=CT[...] (Toolbar.Conduit) REMPLACÉ FF: [clz6jt6r.default] - user_pref("smartbar.homepageList", "http://search.conduit.com/?ctid=CT3232586&octid=CT3232586&CUI=UN[...] (Toolbar.Conduit) REMPLACÉ FF: [clz6jt6r.default] - user_pref("smartbar.searchAddressUrlList", "http://search.conduit.com/ResultsExt.aspx?ctid=CT3232586[...] (Toolbar.Conduit) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs [C:\PROGRA~1\SupTab\SEARCH~1.DLL] (PUP.SupTab) ---\\ Fichier hôte. (1) ~ Le fichier hôte est légitime. (21) ---\\ Tâche planifiée. (0) ~ Aucun élément malicieux trouvé. ---\\ Explorateur ( Dossiers, Fichiers ). (102) DEPLACÉ: C:\Windows\Tasks\APSnotifierPP1.job (PUP.AnyProtect) DEPLACÉ: C:\Windows\Tasks\APSnotifierPP2.job (PUP.AnyProtect) DEPLACÉ: C:\Windows\Tasks\APSnotifierPP3.job (PUP.AnyProtect) DEPLACÉ: C:\Program Files\BearShare Applications (PUP.BearShare) DEPLACÉ: C:\Program Files\globalUpdate (PUP.GlobalUpdate) DEPLACÉ: C:\Program Files\globalUpdate\CrashReports [ - ] (PUP.GlobalUpdate) DEPLACÉ: C:\Program Files\Nosibay (Adware.SPointer) DEPLACÉ: C:\Program Files\predm (Adware.Downware) DEPLACÉ: C:\Program Files\Systweak Support Dock (PUP.SystSupportDock) DEPLACÉ: C:\ProgramData\APN (Toolbar.Ask) DEPLACÉ: C:\ProgramData\APN\APN-Stub [ - ] (Toolbar.Ask) DEPLACÉ: C:\ProgramData\BitGuard (PUP.BitGuard) DEPLACÉ: C:\ProgramData\Browser Manager (PUP.Babylon) DEPLACÉ: C:\ProgramData\BrowserProtect (Hijacker.Eazel) DEPLACÉ: C:\ProgramData\WinSpeed (Trojan.SProtector) DEPLACÉ: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip (PUP.PepperZip) DEPLACÉ: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip\Uninstall.lnk [ - ] (PUP.PepperZip) DEPLACÉ: C:\Users\serge\AppData\Roaming\AnyProtectEx (PUP.AnyProtect) DEPLACÉ: C:\Users\serge\AppData\Roaming\AnyProtectEx\installer [ - ] (PUP.AnyProtect) DEPLACÉ: C:\Users\serge\AppData\Roaming\AnyProtectEx\language [ - ] (PUP.AnyProtect) DEPLACÉ: C:\Users\serge\AppData\Roaming\AnyProtectEx\logs [ - ] (PUP.AnyProtect) DEPLACÉ: C:\Users\serge\AppData\Roaming\AnyProtectEx\scan_results [ - ] (PUP.AnyProtect) DEPLACÉ: C:\Users\serge\AppData\Roaming\AnyProtectEx\swf [ - ] (PUP.AnyProtect) DEPLACÉ: C:\Users\serge\AppData\Roaming\Nosibay (Adware.SPointer) DEPLACÉ: C:\Users\serge\AppData\Roaming\systweak (PUP.Systweak) DEPLACÉ: C:\Users\serge\AppData\Roaming\systweak\BeforeUninstall [ - ] (PUP.Systweak) DEPLACÉ: C:\Users\serge\AppData\Local\globalUpdate (PUP.GlobalUpdate) DEPLACÉ: C:\Users\serge\AppData\Local\globalUpdate\CrashReports [ - ] (PUP.GlobalUpdate) DEPLACÉ: C:\Users\serge\AppData\Local\Mobogenie (PUP.Mobogenie) DEPLACÉ: C:\Users\serge\AppData\Local\Mobogenie\adb.black_devices [ - ] (PUP.Mobogenie) DEPLACÉ: C:\Users\serge\AppData\Local\Mobogenie\adb.write_devices [ - ] (PUP.Mobogenie) DEPLACÉ: C:\Users\serge\AppData\Local\Mobogenie\backup [ - ] (PUP.Mobogenie) DEPLACÉ: C:\Users\serge\AppData\Local\Mobogenie\client.time [ - ] (PUP.Mobogenie) DEPLACÉ: C:\Users\serge\AppData\Local\Mobogenie\damo.time [ - ] (PUP.Mobogenie) DEPLACÉ: C:\Users\serge\AppData\Local\Mobogenie\Data [ - ] (PUP.Mobogenie) DEPLACÉ: C:\Users\serge\AppData\Local\Mobogenie\device [ - ] (PUP.Mobogenie) DEPLACÉ: C:\Users\serge\AppData\Local\Mobogenie\Download [ - ] (PUP.Mobogenie) DEPLACÉ: C:\Users\serge\AppData\Local\Mobogenie\driver [ - ] (PUP.Mobogenie) DEPLACÉ: C:\Users\serge\AppData\Local\Mobogenie\mobo.uuid [ - ] (PUP.Mobogenie) DEPLACÉ: C:\Users\serge\AppData\Local\Mobogenie\Source.mu [ - ] (PUP.Mobogenie) DEPLACÉ: C:\Users\serge\AppData\Local\Mobogenie\updatepop.time [ - ] (PUP.Mobogenie) DEPLACÉ: C:\Users\serge\AppData\Local\Mobogenie\Version [ - ] (PUP.Mobogenie) DEPLACÉ: C:\Users\serge\Documents\Mobogenie (PUP.Mobogenie) DEPLACÉ: C:\Users\serge\Music\BearShare (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\-Going up the Country- [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Ahmed_Chawki_Feat_Magic_System_-_Magic_in_the_air_(_Prod_By_RedOne_)_-_sc_kiwimp3.com (1).mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Artiste inconnu [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Aston Martin Music [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\AVF [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Black M [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Black M - Sur ma route (Paroles) HD (Lyrics).mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Chris Brown feat.santana [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Dj Hamida [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\DJ HAMiDA FEAT GSX [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\DJ HAMIDA Feat. KAYNA SAMET, LARTISTE, RIMK du 113 - DÉCONNECTÉS (Clip Officiel HD).mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\DJ HAMiDA Ft KAYNA SAMET, LARTiSTE, RiMK du 113 - DÉCONNECTÉS (clip officiel).mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Dj Hamida, Lartiste & Kader Japonais - Trabendo Musical.mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\DJ KAYZ feat RIM-K JUL DIESELLE - Jnouné - SON OFFICIEL (inedit).mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Dj Mikl ft. GOK [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\DJ_Kayz_Presente_H_-_Magnum__Maitre_Gims__Du_Swagg__Extended_PIRATE_Mix_www.mp3vube.com.mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\GOK Taba da guèl (kuduro) 2011.mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\http- [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\I'm So Fly [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\JMI SISSOKO - C'WOW.mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\JUL [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Kamelenouvo [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Konshens & J Capri [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\L'Algérino - Wesh Dani - YouTube.mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Lartiste - Remettez ! (D'Banj's Oliver Twist Remix)2.mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\MaC Tyer-Kayliah [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\magic system in the air.mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Maitre Gim's [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Marin Monster Pour Commencer ft Maître Gims.mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\PAS TRES CLAIR - DJAZZI feat DJ ERISE CANARDO LECK - Re´alise´ par Beat Bounce.mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Pitbull,Jennifer Lopez,Cláudia Leitte [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Rick Ross F Drake [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Run It! [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Stromae - ta fête (Audio)-[www_flvto_com].mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Stromaé [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\Tempted To Touch [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\The Shin Sekai [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\The Shin Sekai - Du Berceau Au Linceul - Musique Officiel.mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\Music\BearShare\The Shin Sekai - Du Berceau Au Linceul.mp3 [ - ] (PUP.BearShare) DEPLACÉ: C:\Users\serge\AppData\Roaming\Bubble Dock.installation.log[] (PUP.BubbleDock) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_api.wiseenhance.com_0.localstorage[] (PUP.WiseEnhance) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_api.wiseenhance.com_0.localstorage-journal[] (PUP.WiseEnhance) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_hdapp1008-a.akamaihd.net_0.localstorage[] (PUP.AkamaiHD) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_hdapp1008-a.akamaihd.net_0.localstorage-journal[] (PUP.AkamaiHD) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.livelyrics00.live-lyrics.com_0.localstorage[] (Adware.AddLyrics) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.livelyrics00.live-lyrics.com_0.localstorage-journal[] (Adware.AddLyrics) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage[] (PUP.SpecialSavings) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal[] (PUP.SpecialSavings) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_powerbundle.systweak.com_0.localstorage[] (PUP.Systweak) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_powerbundle.systweak.com_0.localstorage-journal[] (PUP.Systweak) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.select-n-go00.select-n-go.com_0.localstorage[] (PUP.SelectNGo) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.select-n-go00.select-n-go.com_0.localstorage-journal[] (PUP.SelectNGo) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.anyprotect.com_0.localstorage[] (PUP.AnyProtect) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.anyprotect.com_0.localstorage-journal[] (PUP.AnyProtect) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage[] (PUP.SpecialSavings) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal[] (PUP.SpecialSavings) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.systweak.com_0.localstorage[] (PUP.Systweak) DEPLACÉ: C:\Users\serge\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.systweak.com_0.localstorage-journal[] (PUP.Systweak) ---\\ Base de Registres ( Clés, Valeurs, Données ). (61) SUPPRIMÉ: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=32&sy[...] [Ask.com] (Adware.Bandoo) SUPPRIMÉ: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2002}\\http://start.mysearchdial.com/results.php?f=4&q={search[...] [Mysearchdial] (Adware.MyWebSearch) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=32&sy[...] [Ask.com] (Adware.Bandoo) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2002}\\http://start.mysearchdial.com/results.php?f=4&q={search[...] [Mysearchdial] (Adware.MyWebSearch) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{100EB1FD-D03E-47FD-81F3-EE91287F9465} [ShopperReports.dll] (Adware.ShopperReports) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{258C9770-1713-4021-8D7E-1F184A2BD754} [ShoppingReport.dll] (Adware.ShoppingReport) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B} [BabylonToolbar.dll] (PUP.Babylon) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} [BabylonToolbar.dll] (PUP.Babylon) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC} [BabylonToolbarTlbr.dll] (PUP.Babylon) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{BDEA95CF-F0E6-41E0-BD3D-B00F39A4E939} [ShoppingReport.dll] (Adware.ShoppingReport) SUPPRIMÉ: HKCR\Toolbar.CT3232586 (Toolbar.Conduit) SUPPRIMÉ: HKCU\Software\AnyProtect (PUP.AnyProtect) SUPPRIMÉ: HKCU\Software\BearShare (PUP.BearShare) SUPPRIMÉ: HKCU\Software\Boxore (Adware.Boxore) SUPPRIMÉ: HKCU\Software\Conduit (Toolbar.Conduit) SUPPRIMÉ: HKCU\Software\globalUpdate (PUP.GlobalUpdate) SUPPRIMÉ: HKCU\Software\Nosibay (Adware.SPointer) SUPPRIMÉ: HKCU\Software\Optimizer Pro (PUP.OptimizerPro) SUPPRIMÉ: HKCU\Software\systweak (PUP.Systweak) SUPPRIMÉ: HKCU\Software\AppDataLow\Software\Smartbar (Hijacker.SmartBar) SUPPRIMÉ: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\portaldosites.com (Hijacker.PortaldoSites) SUPPRIMÉ: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.portaldosites.com (Hijacker.PortaldoSites) SUPPRIMÉ: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com (PUP.SpecialSavings) SUPPRIMÉ: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\omiga-plus.com (Hijacker.OmigaPlus) SUPPRIMÉ: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\portaldosites.com (Hijacker.PortaldoSites) SUPPRIMÉ: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.portaldosites.com (Hijacker.PortaldoSites) SUPPRIMÉ: HKLM\SOFTWARE\GlobalUpdate (PUP.GlobalUpdate) SUPPRIMÉ: HKLM\SOFTWARE\Systweak (PUP.Systweak) SUPPRIMÉ: HKLM\SOFTWARE\Tutorials (PUP.AgenceExclusive) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Tracing\MySearchDial_RASAPI32 (Adware.MyWebSearch) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Tracing\MySearchDial_RASMANCS (Adware.MyWebSearch) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32 (PUP.UpdateTask) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS (PUP.UpdateTask) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Tracing\updateWiseEnhance_RASAPI32 (PUP.WiseEnhance) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Tracing\updateWiseEnhance_RASMANCS (PUP.WiseEnhance) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Tracing\updateZebar_RASAPI32 (PUP.Zebar) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Tracing\updateZebar_RASMANCS (PUP.Zebar) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Tracing\utilWiseEnhance_RASAPI32 (PUP.WiseEnhance) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Tracing\utilWiseEnhance_RASMANCS (PUP.WiseEnhance) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Tracing\WajamInternetEnhancer_RASAPI32 (PUP.Wajam) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Tracing\WajamInternetEnhancer_RASMANCS (PUP.Wajam) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Tracing\WiseEnhance_RASAPI32 (PUP.WiseEnhance) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Tracing\WiseEnhance_RASMANCS (PUP.WiseEnhance) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Tracing\Zebar_RASAPI32 (PUP.Zebar) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Tracing\Zebar_RASMANCS (PUP.Zebar) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsermngr.exe (PUP.Babylon) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe (PUP.BrowserSafeguard) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta babylon.exe (Toolbar.DeltaSearch) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta tb.exe (Toolbar.DeltaSearch) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta2.exe (Toolbar.DeltaSearch) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltainstaller.exe (Toolbar.DeltaSearch) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltasetup.exe (Toolbar.DeltaSearch) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb_2501-c733154b.exe (Toolbar.DeltaSearch) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iminentsetup.exe (Adware.IMBooster) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe (Spyware.ProtectedSearch) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe (PUP.SearchProtect) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe (PUP.SearchProtect) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftwareUpdate.exe (Adware.Boxore) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweetimsetup.exe (PUP.SweetIM) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbdelta.exetoolbar783881609.exe (Toolbar.DeltaSearch) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe (PUP.JumpFlip) ---\\ Bilan de la réparation ~ Réparation réalisée avec succès. ~ Ce navigateur est absent (Opera Software) End of clean at 17:14:54