~ ZHPCleaner v2014.11.28.239 by Nicolas Coolman (28/11/2014) ~ Run by martine salmon (Administrator) (28/11/2014 15:17:45) ~ Forum : http://forum.nicolascoolman.fr ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Type : Réparer ~ Report : C:\Documents and Settings\martine salmon\Bureau\ZHPCleaner.txt ~ Quarantine : C:\Documents and Settings\martine salmon\Application Data\ZHP\ZHPCleaner_Quarantine.txt ~ UAC : Deactivate ~ Windows XP, 32-bit Service Pack 3 (Build 2600) ---\\ Service. (0) ~ Aucun élément malicieux trouvé. ---\\ Navigateur internet. (45) REMPLACÉ Proxy: ProxyOverride ( ) REMPLACÉ IE Params: Tabs ( about:newtab ) REMPLACÉ IE Params: Search Bar ( hxxps://fr.yahoo.com/?fr=hp-avast&type=avastbcl ) TROUVÉ FF: C:\Documents and Settings\martine salmon\Application Data\Mozilla\Firefox\Profiles\uvaj2kyb.default\prefs.js REMPLACÉ FF: [uvaj2kyb.default] - user_pref("browser.search.order.1", "Recherche sécurisée"); (PUP.Babylon) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.irmysearch.aflt", "dsites0301"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzutDtDtCtAtBtD0DyDzyyDzz0F0E0EtBtCtN0D0Tzu0SyBz[...] (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.irmysearch.cr", "518430286"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.irmysearch.instlRef", ""); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.AL", 2); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.aflt", "dsites0301"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzutDtDtCtAtBtD0DyDzyyDzz0F0E0EtBtCtN0D0Tzu0Sy[...] (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.cntry", "FR"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.cr", "518430286"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.dfltLng", ""); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.dfltSrch", true); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.dnsErr", true); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,6[...] (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.dpk_blck", "true"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.dspFFXOld", "Orange"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.excTlbr", false); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.hdrMd5", "5FE06A7C6F96B178D69D9E658FE6B3F7"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.hmpg", true); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.hmpgUrl", "http://start.mysearchdial.com/?f=1&a=dsites0301&cd=2Xz[...] (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.hpFFXOld", "http://r.orange.fr/r/Ohome_portail?ref=O_OI_defaultPa[...] (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.id", "001320D5958FEE21"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.instlDay", "16130"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.instlRef", ""); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.lastB", "http://r.orange.fr/r/Ohome_portail?ref=O_OI_defaultPage_[...] (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.lastVrsnTs", "1.8.21.08:54:1"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.newTabUrl", "http://start.mysearchdial.com/?f=2&a=dsites0301&cd=2[...] (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.prdct", "mysearchdial"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.prtnrId", "mysearchdial"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.sg", "none"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.tlbrId", "base"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.tlbrSrchUrl", "http://start.mysearchdial.com/?f=3&a=dsites0301&cd[...] (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.vrsn", "1.8.21.0"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial.vrsni", "1.8.21.0"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial_i.hmpg", true); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial_i.newTab", false); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial_i.smplGrp", "none"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.08:54:1"); (Adware.MyWebSearch) REMPLACÉ FF: [uvaj2kyb.default] - user_pref("extensions.wrc@avast.com.install-event-fired", true); (Toolbar.Ask) ---\\ Fichier hôte. (1) ~ Le fichier hôte est légitime. (20) ---\\ Tâche planifiée. (0) ~ Aucun élément malicieux trouvé. ---\\ Explorateur ( Dossiers, Fichiers ). (19) DEPLACÉ: C:\Documents and Settings\martine salmon\Application Data\Mozilla\Firefox\Profiles\uvaj2kyb.default\searchplugins\Mysearchdial.xml [] (Adware.MyWebSearch) DEPLACÉ: C:\Program Files\AskPartnerNetwork (Toolbar.Ask) DEPLACÉ: C:\Program Files\AskPartnerNetwork\Toolbar [ - ] (Toolbar.Ask) DEPLACÉ: C:\Program Files\MyPC Backup (PUP.MyPCBackup) DEPLACÉ: C:\Program Files\MyPC Backup\Database [ - ] (PUP.MyPCBackup) DEPLACÉ: C:\Program Files\MyPC Backup\DEL_AWSSDK.dll [ - ] (PUP.MyPCBackup) DEPLACÉ: C:\Program Files\MyPC Backup\DEL_GetText.dll [ - ] (PUP.MyPCBackup) DEPLACÉ: C:\Program Files\MyPC Backup\DEL_MPCBClient.dll [ - ] (PUP.MyPCBackup) DEPLACÉ: C:\Program Files\MyPC Backup\DEL_MyPC Backup.exe [ - ] (PUP.MyPCBackup) DEPLACÉ: C:\Program Files\MyPC Backup\DEL_ObjectListView.dll [ - ] (PUP.MyPCBackup) DEPLACÉ: C:\Program Files\MyPC Backup\DEL_Shared Stack.dll [ - ] (PUP.MyPCBackup) DEPLACÉ: C:\Program Files\MyPC Backup\x86 [ - ] (PUP.MyPCBackup) DEPLACÉ: C:\Program Files\PC Speed Maximizer (Rogue.PCSpeedMaximizer) DEPLACÉ: C:\Documents and Settings\All Users\Application Data\APN (Toolbar.Ask) DEPLACÉ: C:\Documents and Settings\All Users\Application Data\APN\APN-Stub [ - ] (Toolbar.Ask) DEPLACÉ: C:\Documents and Settings\martine salmon\Application Data\DigitalSites (Hijacker.DSite) DEPLACÉ: C:\Documents and Settings\martine salmon\Mes documents\PC Speed Maximizer (Rogue.PCSpeedMaximizer) DEPLACÉ: C:\Documents and Settings\martine salmon\Mes documents\PC Speed Maximizer\CookiesException.txt [ - ] (Rogue.PCSpeedMaximizer) DEPLACÉ: C:\WINDOWS\System32\SkinBoxer43.dll[SmartBrain Software] (PUP.InboxEmail) ---\\ Base de Registres ( Clés, Valeurs, Données ). (7) SUPPRIMÉ: HKCR\CLSID\{2a6eb050-7f1c-11ce-be57-00aa0051fe20} [French_French Stemmer Resources] (Toolbar.Conduit) SUPPRIMÉ: HKCR\CLSID\{59e09848-8099-101b-8df3-00000b65c3b5} [French_French Word Breaker Resources] (Toolbar.Conduit) SUPPRIMÉ: HKCU\Software\DSiteproducts (Hijacker.DSite) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\FindRight (PUP.FindRight) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup (PUP.MyPCBackup) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\mysearchdial (Adware.MyWebSearch) SUPPRIMÉ: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\PC Speed Maximizer_is1 (Rogue.PCSpeedMaximizer) ---\\ Bilan de la réparation ~ Réparation réalisée avec succès. ~ Ce navigateur est absent (Opera Software) ~ Réparation annulée par l'utilisateur (Mozilla Firefox) ~ Réparation annulée par l'utilisateur (Internet Explorer) End of clean at 15:30:12