FORUM D’ENTRAIDE INFORMATIQUE (FEI)
Site d’assistance et de sécurité informatique

Aide à la désinfection (pages publicitaires, moteur de recherche remplacé, redirections, virus...).
Règles du forum : Entraide concernant la désinfection et la sécurité informatique : en cas de publicités intempestives, pop-up, redirections, logiciels indésirables, ralentissements suspects, virus, etc.
Une désinfection complète vous sera assurée : désinfection, sécurisation, puis prévention.
Seuls les helpers (personnes qualifiées et formées à la désinfection) ainsi que le staff sont autorisés à apporter leur aide dans cette section.
Merci également de prendre connaissance de la charte générale du forum.
  • Avatar du membre
#42275
Bonjour,
Merci de venir à mon secours. je n'arrive pas à éradiquer 22find et ses associés alors que j'ai essayé adwcleaner et ZHPDiag. j'ai trouvé des réponses sur votre forum, mais j'utilise WINDOWS XP. et comme je suis loin d'être une experte...je n'ai pas su convertir. je vous joins le rapport ZHPDiag s'il peut vous être utile.

Rapport de ZHPScript, Générateur de script Registres v1.10 par Nicolas Coolman, Update du 26/02/2013
Run by Yvia at 26/02/2013 12:19:30

==========[Begin]==========
Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{23AF19F7-1D5B-442c-B14C-3D1081953C94}]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{23AF19F7-1D5B-442c-B14C-3D1081953C94}]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F443A627-5009-4323-9C1D-7FD598D0D712}]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F443A627-5009-4323-9C1D-7FD598D0D712}]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\legacy_ibupdaterservice]
[-HKEY_CURRENT_USER\Software\SpeedMaxPc]
[-HKEY_LOCAL_MACHINE\Software\SpeedMaxPc]
[-HKEY_LOCAL_MACHINE\Software\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}]
[-HKEY_LOCAL_MACHINE\Software\Classes\AppID\secman.DLL]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F754C503375A13344B22388E18DFE87E]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536]
==========[End]==========

je ne vois dans ce rapport aune mention de 22find, alors que c'était ma demande.... ???

Merci d'avance de votre aide.
Yvia
#42276
Salut Yvia


On va vérifier le PC :

Télécharge OTL (de OldTimer) et enregistre-le sur ton Bureau.

- Quitte les applications en cours afin de ne pas interrompre le scan.
- Faire double clique sur OTL.exe présent sur le bureau pour lancer le programme
Vista/Seven -- Faire un clique droit sur OTL.exe présent sur le bureau et choisir exécuter en tant qu'administrateur pour lancer le programme
- Une fenêtre apparaît. Dans la section Rapport en haut de cette fenêtre, coche "Rapport standard". Fais de même avec "Tous les utilisateurs" à coté.
- Coche également les cases à côté de "Recherche LOP" et "Recherche Purity".

Ne modifie pas les autres paramètres !

Copie la liste qui se trouve en gras ci-dessous, et colle-la dans la zone sous " Personnalisation "

netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%SYSTEMDRIVE%\*.*
%SYSTEMDRIVE%\*.exe
%PROGRAMFILES%\*.*
%PROGRAMFILES%\*.
/md5start
consrv.dll
volsnap.sys
hidserv.dll
appmgmts.dll
eventlog.dll
winlogon.exe
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
wininet.dll
wininit.exe
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
explorer.exe
svchost.exe
userinit.exe
qmgr.dll
ws2_32.dll
proquota.exe
imm32.dll
kernel32.dll
ndis.sys
autochk.exe
spoolsv.exe
xmlprov.dll
ntmssvc.dll
mswsock.dll
Beep.SYS
ntfs.sys
termsrv.dll
sfcfiles.dll
st3shark.sys
winlogon.exe
wininit.ini
/md5stop
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems /s
SAVEMBR:0
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
c:\$recycle.bin\*.* /s


- Clique sur le bouton Analyse.
- Une fois l'analyse terminée, deux fenêtres vont s'ouvrir dans le Bloc-notes : OTL.txt et Extras.txt. Ils se trouvent au même endroit que OTListIT2 (donc par défaut sur le Bureau).

Utilise cjoint.com pour poster en lien tes rapports :
http://cjoint.com/

- Clique sur Parcourir pour aller chercher le rapport OTL.txt sur le bureau
- Clique sur Ouvrir ensuite sur Créer le lien Cjoint

- Fais un copier/coller du lien qui est devant Le lien a été créé: dans ta prochaine réponse.

Après fais de même avec l'autre rapport Extras.txt


@++
Avatar du membre
par Yvia
#42339
Bonjour Dédétraqué
Je te remercie pour ton aide, mais j'ai bien suivi toutes les commandes, y compris annuler les documents comme demandé par webmasterccjoin et vidé le cache du navigateur....
Et Hélas, après avoir fermé mon ordi et réouvert... 22find Tapak Portal est toujours là (avec cette adresse ( http://www.22find.com/newtab?utm_source ... 1361814747) et me nargue....
Que faire ???
merci de venir encore à mon secours.
Yvia
#42381
Dédétraqué bonsoir,

j'ai recréé les liens, mais comme j'ai mozilla, je ne suis pas sûre que ça ait marché, alors je t'envoie les 2 adresses .

OTL :
http://cjoint.com/?3BBxRBo4DqU


EXTRAS :
http://cjoint.com/?3BBxXvVh88E

peut-être dois-je archiver les 2 rapports aux adresses que tu m'indiques dans ton dernier message ? je vais le faire.

Merci et désolée de t'ennuyer encore.
Yvia

PS : je ne suis pas arrivée à ouvrir les adresses d'archives
#42444
Salut Yvia


Double clic sur OTL.exe pour le lancer.
(Vista/Seven -- Faire un clique droit sur OTL.exe pour lancer le programme et choisi "Exécuter en tant qu'administrateur".

* Copie la liste qui se trouve en citation ci-dessous, et colle-la dans la zone sous " Personnalisation "

:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\LV302AV.SYS -- (PID_08A0)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.22find.com/newtab?utm_source ... 1361814747
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Value error.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Reg Error: Value error.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.22find.com/newtab?utm_source ... 1361814747
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.22find.com/web/?utm_sourc ... 1361814749
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.22find.com/web/?utm_sourc ... 1361814749
IE - HKU\S-1-5-21-842925246-2147099731-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.22find.com/newtab?utm_source ... 1361814747
FF - prefs.js..browser.search.defaultenginename: "22find"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.order.1: "22find"
FF - prefs.js..browser.search.selectedEngine: "22find"
FF - prefs.js..browser.search.useDBForOrder: true
CHR - plugin: Babylon ToolBar (Enabled) = C:\Documents and Settings\Yvia\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.7_0\BabylonChromeToolBar.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-842925246-2147099731-725345543-1004\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-842925246-2147099731-725345543-1004\..\Toolbar\WebBrowser: (no name) - {968631B6-4729-440D-9BF4-251F5593EC9A} - No CLSID value found.
O3 - HKU\S-1-5-21-842925246-2147099731-725345543-1004\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O3 - HKU\S-1-5-21-842925246-2147099731-725345543-1004\..\Toolbar\WebBrowser: (no name) - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - No CLSID value found.
O4 - HKU\.DEFAULT\..\Run: [Nokia.PCSync] C:\Documents and Settings\Yvia\Mes documents\Mes logiciels\Nokia PC Suite 6\PcSync2.exe /NoDialog File not found
O4 - HKU\S-1-5-18\..\Run: [Nokia.PCSync] C:\Documents and Settings\Yvia\Mes documents\Mes logiciels\Nokia PC Suite 6\PcSync2.exe /NoDialog File not found
O4 - HKU\S-1-5-21-842925246-2147099731-725345543-1004\..\Run: [KiesAirMessage] C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup File not found
O16 - DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} http://assets.photobox.com/assets/v/ra3 ... _0fSS8.cab (PhotoboxPhotowaysUploader5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/sh ... tor/sw.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microso ... 2895948578 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Value error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
MsConfig - StartUpReg: LogitechCommunicationsManager - hkey= - key= - File not found
[2013/02/25 19:02:06 | 000,000,000 | ---D | C] -- C:\Program Files\Fichiers communs\337
[2013/02/25 18:52:28 | 000,000,000 | ---D | C] -- C:\Program Files\Desk 365
[2013/02/25 18:51:34 | 000,503,912 | ---- | C] (SoftStud) -- C:\Documents and Settings\Yvia\Local Settings\Application Data\22find_B_mib_br_201322215041.exe
[2013/02/16 12:14:56 | 004,152,328 | ---- | C] (Beijing 337 Technology Co., Ltd.) -- C:\Documents and Settings\Yvia\Local Settings\Application Data\Desk365-1.3.12.4557.exe
[7 C:\WINDOWS\System32\*.tmp files - C:\WINDOWS\System32\*.tmp - ]
[12 C:\WINDOWS\*.tmp files - C:\WINDOWS\*.tmp - ]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files - C:\Documents and Settings\All Users\Application Data\*.tmp - ]
[2013/02/25 19:14:33 | 000,000,676 | ---- | M] () -- C:\Documents and Settings\Yvia\Application Data\Microsoft\Internet Explorer\Quick Launch\22find.lnk
[2013/02/25 18:51:36 | 000,503,912 | ---- | M] (SoftStud) -- C:\Documents and Settings\Yvia\Local Settings\Application Data\22find_B_mib_br_201322215041.exe
[2013/02/25 18:51:33 | 004,152,328 | ---- | M] (Beijing 337 Technology Co., Ltd.) -- C:\Documents and Settings\Yvia\Local Settings\Application Data\Desk365-1.3.12.4557.exe
[2013/02/16 12:15:05 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Yvia\Local Settings\Application Data\22find_B_mib_br_201311718510.exe
[2012/11/06 08:37:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\~Browser Manager
@Alternate Data Stream - 145 bytes - C:\Documents and Settings\All Users\Application Data\TEMP:AD022376

:Commands
[Emptytemp]

* Clique sur " Correction " pour lancer la suppression.

* Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur Oui.

* Au redémarrage , autorise OTL a s'exécuter.

* Poste le rapport généré par OTL.


@++
Avatar du membre
par Yvia
#42536
Bonjour Dédétraqué.
Je te remercie de passer tant de temps à mon problème... (la gentillesse des Québecois !!! nos si charmants "cousins").

J'ai suivi tes instructions et te poste le rapport OTL...

All processes killed
========== OTL ==========
Service WDICA stopped successfully!
Service WDICA deleted successfully!
Service PID_08A0 stopped successfully!
Service PID_08A0 deleted successfully!
File system32\DRIVERS\LV302AV.SYS not found.
Service PDRFRAME stopped successfully!
Service PDRFRAME deleted successfully!
Service PDRELI stopped successfully!
Service PDRELI deleted successfully!
Service PDFRAME stopped successfully!
Service PDFRAME deleted successfully!
Service PDCOMP stopped successfully!
Service PDCOMP deleted successfully!
Service PCIDump stopped successfully!
Service PCIDump deleted successfully!
Service lbrtfdc stopped successfully!
Service lbrtfdc deleted successfully!
Service i2omgmt stopped successfully!
Service i2omgmt deleted successfully!
Service Changer stopped successfully!
Service Changer deleted successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Secondary_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Secondary Start Pages| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\CustomizeSearch| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
HKU\S-1-5-21-842925246-2147099731-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
Prefs.js: "22find" removed from browser.search.defaultenginename
Prefs.js: "" removed from browser.search.defaulturl
Prefs.js: "22find" removed from browser.search.order.1
Prefs.js: "22find" removed from browser.search.selectedEngine
Prefs.js: true removed from browser.search.useDBForOrder
File C:\Documents and Settings\Yvia\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.7_0\BabylonChromeToolBar.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_USERS\S-1-5-21-842925246-2147099731-725345543-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
Registry value HKEY_USERS\S-1-5-21-842925246-2147099731-725345543-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{968631B6-4729-440D-9BF4-251F5593EC9A} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{968631B6-4729-440D-9BF4-251F5593EC9A}\ not found.
Registry value HKEY_USERS\S-1-5-21-842925246-2147099731-725345543-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\ not found.
Registry value HKEY_USERS\S-1-5-21-842925246-2147099731-725345543-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{F2E259E8-0FC8-438C-A6E0-342DD80FA53E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2E259E8-0FC8-438C-A6E0-342DD80FA53E}\ not found.
Registry value HKEY_USERS\.DEFAULT\\Software\Microsoft\Windows\CurrentVersion\Run\\Nokia.PCSync deleted successfully.
Registry value HKEY_USERS\S-1-5-18\\Software\Microsoft\Windows\CurrentVersion\Run\\Nokia.PCSync not found.
Registry value HKEY_USERS\S-1-5-21-842925246-2147099731-725345543-1004\\Software\Microsoft\Windows\CurrentVersion\Run\\KiesAirMessage deleted successfully.
Starting removal of ActiveX control {0972B098-DEE9-4279-AC7E-4BAAA029102D}
C:\WINDOWS\Downloaded Program Files\ImageUploader5.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0972B098-DEE9-4279-AC7E-4BAAA029102D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0972B098-DEE9-4279-AC7E-4BAAA029102D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{0972B098-DEE9-4279-AC7E-4BAAA029102D}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0972B098-DEE9-4279-AC7E-4BAAA029102D}\ not found.
Starting removal of ActiveX control {166B1BCA-3F9C-11CF-8075-444553540000}
C:\WINDOWS\Downloaded Program Files\setup.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{166B1BCA-3F9C-11CF-8075-444553540000}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{166B1BCA-3F9C-11CF-8075-444553540000}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\ not found.
Starting removal of ActiveX control {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
C:\WINDOWS\Downloaded Program Files\muweb.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\ not found.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {D27CDB6E-AE6D-11CF-96B8-444553540000}
C:\WINDOWS\Downloaded Program Files\swflash64.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11CF-96B8-444553540000}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\LogitechCommunicationsManager\ deleted successfully.
C:\Program Files\Fichiers communs\337\libcef\1.963.439\locales folder moved successfully.
C:\Program Files\Fichiers communs\337\libcef\1.963.439 folder moved successfully.
C:\Program Files\Fichiers communs\337\libcef folder moved successfully.
C:\Program Files\Fichiers communs\337 folder moved successfully.
C:\Program Files\Desk 365 folder moved successfully.
C:\Documents and Settings\Yvia\Local Settings\Application Data\22find_B_mib_br_201322215041.exe moved successfully.
C:\Documents and Settings\Yvia\Local Settings\Application Data\Desk365-1.3.12.4557.exe moved successfully.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\WINDOWS\System32\SET48.tmp deleted successfully.
C:\WINDOWS\System32\SET4A.tmp deleted successfully.
C:\WINDOWS\System32\SET4E.tmp deleted successfully.
C:\WINDOWS\System32\SET56.tmp deleted successfully.
C:\WINDOWS\System32\SET9D.tmp deleted successfully.
C:\WINDOWS\System32\uxtC.tmp deleted successfully.
C:\WINDOWS\002988_.tmp deleted successfully.
C:\WINDOWS\DUMP7956.tmp deleted successfully.
C:\WINDOWS\DUMP80b9.tmp deleted successfully.
C:\WINDOWS\msdownld.tmp folder deleted successfully.
C:\WINDOWS\SET29.tmp deleted successfully.
C:\WINDOWS\SET2A.tmp deleted successfully.
C:\WINDOWS\SET2B.tmp deleted successfully.
C:\WINDOWS\SET2C.tmp deleted successfully.
C:\WINDOWS\SET2D.tmp deleted successfully.
C:\WINDOWS\SET3.tmp deleted successfully.
C:\WINDOWS\SET4.tmp deleted successfully.
C:\WINDOWS\SET8.tmp deleted successfully.
C:\Documents and Settings\All Users\Application Data\ISxC.tmp deleted successfully.
C:\Documents and Settings\Yvia\Application Data\Microsoft\Internet Explorer\Quick Launch\22find.lnk moved successfully.
File C:\Documents and Settings\Yvia\Local Settings\Application Data\22find_B_mib_br_201322215041.exe not found.
File C:\Documents and Settings\Yvia\Local Settings\Application Data\Desk365-1.3.12.4557.exe not found.
C:\Documents and Settings\Yvia\Local Settings\Application Data\22find_B_mib_br_201311718510.exe moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\~2.4.897.175\~{61d8b74e-8d89-46ff-afa6-33382c54ac73} folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\~2.4.897.175\{61d8b74e-8d89-46ff-afa6-33382c54ac73} folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\~2.4.897.175 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\~2.2.643.41\~{16cdff19-861d-48e3-a751-d99a27784753}\~traking_settings folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\~2.2.643.41\~{16cdff19-861d-48e3-a751-d99a27784753}\~FirefoxExtension\~content folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\~2.2.643.41\~{16cdff19-861d-48e3-a751-d99a27784753}\~FirefoxExtension\~components folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\~2.2.643.41\~{16cdff19-861d-48e3-a751-d99a27784753}\~FirefoxExtension folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\~2.2.643.41\~{16cdff19-861d-48e3-a751-d99a27784753} folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\~2.2.643.41 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\Browser Manager\~2.4.897.175\~{61d8b74e-8d89-46ff-afa6-33382c54ac73}\~~traking_settings\~traking_settings folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\Browser Manager\~2.4.897.175\~{61d8b74e-8d89-46ff-afa6-33382c54ac73}\~~traking_settings folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\Browser Manager\~2.4.897.175\~{61d8b74e-8d89-46ff-afa6-33382c54ac73}\~~FirefoxExtension\~~content folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\Browser Manager\~2.4.897.175\~{61d8b74e-8d89-46ff-afa6-33382c54ac73}\~~FirefoxExtension\~~components folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\Browser Manager\~2.4.897.175\~{61d8b74e-8d89-46ff-afa6-33382c54ac73}\~~FirefoxExtension\~FirefoxExtension\~~components folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\Browser Manager\~2.4.897.175\~{61d8b74e-8d89-46ff-afa6-33382c54ac73}\~~FirefoxExtension\~FirefoxExtension folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\Browser Manager\~2.4.897.175\~{61d8b74e-8d89-46ff-afa6-33382c54ac73}\~~FirefoxExtension folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\Browser Manager\~2.4.897.175\~{61d8b74e-8d89-46ff-afa6-33382c54ac73} folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\Browser Manager\~2.4.897.175 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\Browser Manager folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\2.4.897.175\{61d8b74e-8d89-46ff-afa6-33382c54ac73} folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager\2.4.897.175 folder moved successfully.
C:\Documents and Settings\All Users\Application Data\~Browser Manager folder moved successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:AD022376 deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
-Temp folder emptied: 0 bytes
-Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
-Temp folder emptied: 66016 bytes
-Temporary Internet Files folder emptied: 10578811 bytes

User: NetworkService
-Temp folder emptied: 1847252 bytes
-Temporary Internet Files folder emptied: 233988 bytes

User: Yvia
-Temp folder emptied: 2057619958 bytes
-Temporary Internet Files folder emptied: 106211909 bytes
-Java cache emptied: 0 bytes
-FireFox cache emptied: 216344035 bytes
-Google Chrome cache emptied: 0 bytes
-Flash cache emptied: 15075 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 18649739 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 1671453118 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 3 894,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 03042013_102225

Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


Merci infiniment...
Je devrais être débarrassée de 22find, maintenant ?
Merci encore..
Bien à toi.
Yvia
Avatar du membre
par Yvia
#42597
Bonjour Dédétraqué,

Hélas oui..... 22find s'incruste encore chez moi malgré tout ton boulot... et malgré fermeture et réouverture de mon ordi....

Désolée.... que faire ???
Merci de ton aide.
Amicalement
Yvia
Avatar du membre
par Yvia
#42666
Cher Dédétraqué

j'ai exécuté shortcut, comme demandé. Voilà ce que j'ai reçu comme rapport et comme j'avais toujours la mention d'attente... please wait.. 1 heure après, j'ai recommencé et obtenu le même rapport.... et à 14h48 j'ai toujours la mention d'attente...
ai-je fait une bêtise ? ou bien je dois aller chercher le rapport ailleurs ???
au secours...
Merci à toi.
Yvia

¤¤¤¤¤¤¤¤¤¤ | Shortcut_Module 1.012 - g3n-h@ckm@n

13:33:14 - 06/03/2013

¤¤¤¤¤¤¤¤¤¤ | Shortcut_Module 1.012 - g3n-h@ckm@n

14:34:34 - 06/03/2013
Avatar du membre
par Yvia
#42691
Bonjour Dédétraqué,
Tu vas bien ?

j'ai voulu te joindre le rapport OTL.Txt d'aujourd'hui, mais refusé par la longueur du message
je vais essayer cjoint, bien que j'ai eu quelques difficultés la dernière fois.
Merci encore une fois de ton aide.
Yvia
Avatar du membre
par Yvia
#42716
Youpiiiiii ! Dédétraqué, BRAVO !!!!

plus de 22find sur mon ordi....

des milliers de mercis !
je suis tellement contente que je me permets de t'embrasser.

Yvia
#42741
Salut Yvia


Bien de rien

On va faire un ménage des outils téléchargés pour la désinfection, télécharge Del Fix (de Xplode), sur ton bureau :

http://www.general-changelog-team.fr/fr ... /26-delfix

Lance-le, coche l'option "Supprimer les outils de désinfection".
Clique sur [Exécuter]
Patiente durant l'opération..


-----


Je te donne quelques consignes de sécurité :

Image Windows Update parfaitement à jour http://www.windowsupdate.com/
Image Pare-feu bien paramétré pour XP, je te conseil :
ZoneAlarm, Vista/Seven -- le pare de WINDOWS est suffisant.
Image Antivirus bien paramétré et mis à jour régulièrement (quotidiennement s'il le faut) avec un scan complet régulier (journalier s'il le faut).
Image Une attitude prudente vis à vis de la navigation (pas de sites douteux : cracks, warez, sexe...) et vis à vis de la messagerie (fichiers joints aux messages doivent être scannés avant d'être ouverts)
Image Pas de téléchargement illégal, qui est le principal facteur d’infection (µTorrent, BitTorrent, eMule, Limewire, etc..)
Le danger des cracks !
Les risques sécuritaires du peer-to-peer
Image Une attitude vigilante (être à l'affût d'un fonctionnement inhabituel de son système)
Image Nettoyage hebdomadaire du système (suppression des fichiers inutiles, nettoyage de la base de registre, scandisk)
Image Scan hebdomadaire antispyware ( je conseil MalwareByte's Anti-Malware)
Image Un contrôle régulier de la console JAVA pour s'assurer qu'elle est à jour http://www.java.com/en/download/help/testvm.xml
Image Faire régulièrement un scan de vulnérabilités afin de vérifier que tes logiciels soit à jour sans failles de sécurités :
http://www.malekal.com/scan_vulnerabilite.php

Dit moi si cela est bon et je mettrai le sujet en résolu...

Bonne journée/soirée et bon surf


@++
Avatar du membre
par Yvia
#42818
Dédétraqué Bonjour

j'ai fait ta manœuvre 26-delfix, tout à l'air effacé. Je te joins le rapport par acquis de conscience et je te remercie de tes conseils de prudence.... que je vais appliquer, bien sûr.

Merci encore de ta patience, de ton efficacité et ta gentillesse.

Yvia

# DelFix v10.1 - Rapport créé le 09/03/2013 à 14:34:01
# Mis à jour le 23/02/2013 par Xplode
# Nom d'utilisateur : Yvia - YVIA-BBDDF0B6DD

~ Suppression des outils de désinfection ...

Supprimé : C:\_OTL
Supprimé : C:\ZHP
Supprimé : C:\Documents and Settings\All Users\Menu Démarrer\Programmes\ZHP
Supprimé : C:\Program Files\ZHPDiag
Supprimé : C:\AdwCleaner[R1].txt
Supprimé : C:\AdwCleaner[R2].txt
Supprimé : C:\AdwCleaner[R3].txt
Supprimé : C:\AdwCleaner[R4].txt
Supprimé : C:\AdwCleaner[S1].txt
Supprimé : C:\AdwCleaner[S2].txt
Supprimé : C:\rapport.txt
Supprimé : C:\Documents and Settings\Yvia\Bureau\adwcleaner.lnk
Supprimé : C:\Documents and Settings\Yvia\Bureau\ZHPFixReport.txt
Supprimé : C:\Documents and Settings\All Users\Bureau\MBRCheck.lnk
Supprimé : C:\Documents and Settings\All Users\Bureau\ZHPDiag.lnk
Supprimé : C:\Documents and Settings\All Users\Bureau\ZHPFix.lnk
Supprimé : C:\Documents and Settings\Yvia\Mes documents\Téléchargements\adwcleaner(1).exe
Supprimé : C:\Documents and Settings\Yvia\Mes documents\Téléchargements\adwcleaner.exe
Supprimé : C:\Documents and Settings\Yvia\Mes documents\Téléchargements\OTL.exe
Supprimé : C:\Documents and Settings\Yvia\Mes documents\Téléchargements\ZHPDiag2.exe
Supprimée : HKLM\SOFTWARE\OldTimer Tools
Supprimée : HKLM\SOFTWARE\AdwCleaner
Supprimée : HKLM\SOFTWARE\Soeperman Enterprises Ltd.
Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1

########## - EOF - ##########
désinstaller sophos

:bonjour: tu remets frst et addition je t'ai de[…]

Hello!

Nice to meet you, guys! Opportunities like schola[…]

Bug PC

Bonjour, Essaye de voir si une application du Mic[…]

Channel effortless cool with the Lana Del Rey Fer[…]