Script ZHPFix O1 - Hosts: 37.59.14.123 www.blocked-website.com => Infection Hosts (Hosts.Redirection)↓ O1 - Hosts: 37.59.14.123 block.opendns.com => Infection Hosts (Hosts.Redirection)↓ O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Mysearchdial) - http://start.mysearchdial.com =>Adware.MyWebSearch HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\yontoo-C4-08FC_RASAPI32 =>Adware.Yontoo HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\yontoo-C4-08FC_RASMANCS =>Adware.Yontoo [HKLM\Software\Classes\TypeLib\{3277CD27-4001-4EF8-9D96-C6CA745AC2F9}] =>Trojan.BHO [HKLM\Software\Classes\Interface\{38493F7F-2922-4C6C-9A9A-8DA2C940D0EE}] =>Trojan.BHO [HKLM\Software\Wow6432Node\Classes\Interface\{38493F7F-2922-4C6C-9A9A-8DA2C940D0EE}] =>Trojan.BHO [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375] =>PUP.Tarma [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5] =>PUP.Tarma [MD5.3728763324AA67F118EA50E2AFB48D66] - (...) -- C:\Users\Stephane\AppData\Roaming\Dashlane\Dashlane.exe [219832] [PID.1248] => Toolbar.Dashlane O4 - HKCU\..\Run: [Dashlane] . (...) -- C:\Users\Stephane\AppData\Roaming\Dashlane\Dashlane.exe => Toolbar.Dashlane O4 - HKUS\S-1-5-21-4241621152-3669274375-1654822481-1000\..\Run: [Dashlane] . (...) -- C:\Users\Stephane\AppData\Roaming\Dashlane\Dashlane.exe => Toolbar.Dashlane [HKCU\Software\Conduit_Search_Protect] => Toolbar.Conduit O69 - SBI: SearchScopes [HKCU] {26FEF2BE-C203-4396-A7FF-A9AE5D6B9A79} - (blekko) - http://blekko.com => Toolbar.Blekko* O69 - SBI: SearchScopes [HKCU] {460B204C-DDDF-4561-B958-29228A90D731} - (Ask Search) - http://websearch.ask.com =>Toolbar.Ask [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{669695BC-A811-4A9D-8CDF-BA8C795F261C}] =>Toolbar.Dashlane [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{669695BC-A811-4A9D-8CDF-BA8C795F261C}] =>Toolbar.Dashlane [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]:Dashlane =>Toolbar.Dashlane R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank Spybot - Search & Destroy v1.6.2 => Safer Networking Ltd - Spybot S&D [MD5.794D4B48DFB6E999537C7C3947863463] - (.Safer Networking Ltd. - Spybot-S&D Security Center integration.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368] [PID.2060] R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank O2 - BHO: Spybot-S&D IE Protection [64Bits] - {53707962-6F74-2D53-2644-206D7942484F} . (.Safer Networking Limited - SBSD IE Protection.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll => Safer Networking Ltd - Spybot S&D O3 - Toolbar: (no name) - [HKLM]{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} Clé orpheline => Orphean Key not necessary O23 - Service: SBSD Security Center Service (SBSDWSCService) . (.Safer Networking Ltd. - Spybot-S&D Security Center integration.) - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe => Safer Networking Ltd - Spybot S&D [MD5.00000000000000000000000000000000] [APT] [{A7B21D09-FEAA-48D4-B2A6-2DCC91423AD1}] (...) -- E:\USBDriver\ComMass\setup.exe (.not file.) [0] => Fichier absent [MD5.00000000000000000000000000000000] [APT] [{D0F990CB-0076-42BB-8EC0-DEDF1DE911C6}] (...) -- C:\Users\Stephane\Desktop\Mass_storage_USB_DRIVER\setup.exe (.not file.) [0] => Fichier absent O42 - Logiciel: Spybot - Search & Destroy - (.Safer Networking Limited.) [HKLM][64Bits] -- {B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 => Safer Networking Ltd - Spybot S&D O43 - CFD: 08/06/2014 - 08:55:51 - [] ----D C:\Program Files (x86)\Spybot - Search & Destroy => Safer Networking Ltd - Spybot S&D O43 - CFD: 03/06/2014 - 16:47:57 - [] ----D C:\Program Files (x86)\Spybot - Search & Destroy 2 => Safer Networking Ltd - Spybot S&D O43 - CFD: 21/05/2014 - 14:06:22 - [] ----D C:\ProgramData\boost_interprocess => boost.org O43 - CFD: 11/06/2014 - 22:37:42 - [] ----D C:\ProgramData\Spybot - Search & Destroy => Safer Networking Ltd - Spybot S&D O51 - MPSK:{9dd2b1cd-7b4f-11e2-893b-806e6f6e6963}\AutoRun\command. (...) -- E:\CheckID.exe (.not file.) => Fichier absent O61 - LFC: 12/06/2014 - 20:30:29 ---A- . (...) -- C:\Users\Stephane\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\26b5dc9e48691a8035dafb2b7ed76562_fce8395c8fd8a876_7d471b9a49f37860_0_0.bin [16384] => Temporary file not necessary O61 - LFC: 12/06/2014 - 20:30:29 ---A- . (...) -- C:\Users\Stephane\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\26b5dc9e48691a8035dafb2b7ed76562_fce8395c8fd8a876_7d471b9a49f37860_0_1.bin [1048576] => Temporary file not necessary O61 - LFC: 12/06/2014 - 20:30:29 ---A- . (...) -- C:\Users\Stephane\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\26b5dc9e48691a8035dafb2b7ed76562_fce8395c8fd8a876_7d471b9a49f37860_1_0.bin [16384] => Temporary file not necessary O61 - LFC: 12/06/2014 - 20:30:29 ---A- . (...) -- C:\Users\Stephane\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\26b5dc9e48691a8035dafb2b7ed76562_fce8395c8fd8a876_7d471b9a49f37860_1_1.bin [1048576] => Temporary file not necessary O61 - LFC: 12/06/2014 - 20:30:29 ---A- . (...) -- C:\Users\Stephane\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\26b5dc9e48691a8035dafb2b7ed76562_fce8395c8fd8a876_7d471b9a49f37860_2_0.bin [16384] => Temporary file not necessary O61 - LFC: 12/06/2014 - 20:30:29 ---A- . (...) -- C:\Users\Stephane\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\26b5dc9e48691a8035dafb2b7ed76562_fce8395c8fd8a876_7d471b9a49f37860_2_1.bin [1048576] => Temporary file not necessary O61 - LFC: 12/06/2014 - 20:30:29 ---A- . (...) -- C:\Users\Stephane\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\26b5dc9e48691a8035dafb2b7ed76562_fce8395c8fd8a876_7d471b9a49f37860_3_0.bin [16384] => Temporary file not necessary O61 - LFC: 12/06/2014 - 20:30:29 ---A- . (...) -- C:\Users\Stephane\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\26b5dc9e48691a8035dafb2b7ed76562_fce8395c8fd8a876_7d471b9a49f37860_3_1.bin [1048576] => Temporary file not necessary O61 - LFC: 12/06/2014 - 20:30:29 ---A- . (...) -- C:\Users\Stephane\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\26b5dc9e48691a8035dafb2b7ed76562_fce8395c8fd8a876_7d471b9a49f37860_4_0.bin [16384] => Temporary file not necessary SR - | Auto 26/01/2009 1153368 | (SBSDWSCService) . (.Safer Networking Ltd..) - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe => Safer Networking Ltd - Spybot S&D ShortcutFix FirewallRaz Emptytemp SysRestore HostFix