Bonjour,
Bon bah... une semaine au bagne
Pas de soucis, ce n'est pas de ta faute cette fois !
Ce script te dégommera Ad-Aware, Spybot, et des infections... soit-dit en passant.
• Lance de ton bureau l'outil de scripting
ZHPFix (
de Nicolas Coolman), (Clic droit "
exécuter en tant qu'administrateur" si tu es sous
Windows Vista ou 7).
• Copie-colle dans le logiciel, le
texte ci-dessous (
en gras) grâce au bouton [
H] :
[MD5.C5F1D82D9CC8979971CC748FCB2EE7CA] - (.Lavasoft - Ad-Aware Browsing Protection.) -- C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [198032] [PID.5816]
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\At1.job => Infection Rogue (Rogue.HDDDoctor)
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\At2.job
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\At3.job
O4 - HKLM\..\Wow6432Node\Run: [Ad-Aware Browsing Protection] . (.Lavasoft - Ad-Aware Browsing Protection.) -- C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
O23 - Service: Ad-Aware Service (Ad-Aware Service) . (.Lavasoft Limited - Ad-Aware Antivirus Service.) - C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
[MD5.FD9BB1596433AE242DEF9320E4645BDC] [APT] [Ad-Aware Antivirus Scheduled Scan] (.Lavasoft Limited.) -- C:\Program Files (x86)\AD-AWA~1\AdAwareLauncher.exe
[HKCU\Software\AppDataLow\Software\adaware]
[HKLM\Software\BrowserMngr]
O43 - CFD: 10/09/2012 - 15:23:44 - [2,692] ----D C:\Program Files (x86)\adawaretb
[MD5.7EEBD2062BD0DFDEADF458066E1EFB71] [SPRF][10/09/2012] (...) -- C:\Users\LioLéo.LIOLEO-PC\AppData\Roaming\sp_data.sys [380]
SS - | Auto 12/07/2012 1239952 | (Ad-Aware Service) . (.Lavasoft Limited.) - C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
Emptytemp
O42 - Logiciel: Spybot - Search & Destroy - (.Safer Networking Limited.) [HKLM] -- {B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 => Safer Networking Limited Spybot - S&D
O43 - CFD: 09/09/2012 - 02:16:27 - [52,701] ----D C:\Program Files (x86)\Spybot - Search & Destroy => Spybot - Search & Destroy
O43 - CFD: 10/09/2012 - 14:26:30 - [0,074] ----D C:\ProgramData\Spybot - Search & Destroy => Spybot - Search & Destroy
O43 - CFD: 10/09/2012 - 15:23:45 - [0] ----D C:\Users\LioLéo.LIOLEO-PC\AppData\Local\adawarebp
O43 - CFD: 10/09/2012 - 01:02:17 - [0] ----D C:\Users\LioLéo.LIOLEO-PC\AppData\Local\ECRSC
O43 - CFD: 08/09/2012 - 14:34:27 - [0] ----D C:\Users\LioLéo.LIOLEO-PC\AppData\Local\{5105E122-5009-4EBA-84F2-897D14AE9285}
O43 - CFD: 09/09/2012 - 04:05:55 - [0] ----D C:\Users\LioLéo.LIOLEO-PC\AppData\Local\{5FEDAE53-4395-4CCD-AB52-E75CD4DB3990}
O43 - CFD: 09/09/2012 - 02:16:27 - [52,701] ----D C:\Program Files (x86)\Spybot - Search & Destroy => Spybot - Search & Destroy
SS - | Auto 26/01/2009 1153368 | (SBSDWSCService) . (.Safer Networking Ltd..) - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe => Spybot®Search & Destroy
O2 - BHO: (no name) [64Bits] - {6c97a91e-4524-4019-86af-2aa2d567bf5c} Clé orpheline
O4 - HKCU\..\Run: [SpybotSD TeaTimer] . (.Safer Networking Limited - System settings protector.) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe => Safer Net Working®Spybot S&D
O4 - HKLM\..\Wow6432Node\Run: [Ad-Aware Antivirus] Clé orpheline
O4 - HKUS\S-1-5-21-263615548-1280341671-605664653-1006-263615548-1280341671-605664653-1000\..\Run: [SpybotSD TeaTimer] . (.Safer Networking Limited - System settings protector.) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe => Safer Net Working®Spybot S&D
O23 - Service: SBSD Security Center Service (SBSDWSCService) . (.Safer Networking Ltd. - Spybot-S&D Security Center integration.) - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe => Spybot®Search & Destroy
[MD5.0D3B680986310AE5540578C0E481C6A0] [SPRF][06/10/2010] (...) -- C:\ProgramData\FullRemove.exe [131984]
Emptyflash
FirewallRAZ
• Clique sur
Nettoyer / Go, et héberge le rapport
ZHPFix.txt de ton bureau sur :
http://cjoint.com/
• Si le site ne fonctionne pas, consulte cette page :
Autres hébergeurs en ligne