Bonjour,
La page Dropbox ?
Prends les lignes directement ci-dessous sinon :
Script ZHPFix
OPT:O4 - HKCU\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
OPT:O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
OPT:O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
OPT:O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
OPT:O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
OPT:O4 - HKUS\S-1-5-21-1078081533-583907252-682003330-1004\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
G2 - GCE: Preference [User Data\Default] [pkndmigholgfjlniaohblojbhgjbkakn] Lightning speedDial v.1.1.7, (Désactivé) = PUP.Elex
M3 - MFPP: Plugins - [yvon] -- C:\Program Files\Mozilla FireFox\searchplugins\nationzoom.xml =Hijacker.NationZoom
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.nationzoom.com =Hijacker.NationZoom
OPT:O4 - GS\Program [yvon]: Nouvel onglet.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
http://www.google.fr
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files\Mobogenie\DaemonProcess.exe (.not file.) =PUP.Mobogenie
O4 - HKCU\..\Run: [iLivid] C:\Documents and Settings\yvon\Local Settings\Application Data\iLivid\iLivid.exe (.not file.) =Adware.Bandoo
O4 - HKUS\S-1-5-21-1078081533-583907252-682003330-1004\..\Run: [iLivid] C:\Documents and Settings\yvon\Local Settings\Application Data\iLivid\iLivid.exe (.not file.) =Adware.Bandoo
[HKLM\Software\Wpm] =PUP.WpManager
[HKLM\Software\supTab] = PUP.SupTab
[HKLM\Software\supWPM] =PUP.WpManager
O43 - CFD: 29/01/2014 - 17:37:09 - [0] ----D C:\Program Files\SupTab = PUP.SupTab
O43 - CFD: 29/01/2014 - 17:37:11 - [0] ----D C:\Documents and Settings\All Users\Application Data\RHelpers =PUP.SearchDonkey
O43 - CFD: 16/01/2014 - 14:50:12 - [1.225] ----D C:\Documents and Settings\All Users\Application Data\Updater =PUP.CrossRider
O43 - CFD: 09/01/2014 - 09:28:34 - [0.110] ----D C:\Documents and Settings\All Users\Application Data\Websteroids =PUP.TubeDimmer
O43 - CFD: 29/01/2014 - 17:36:57 - [0.000] ----D C:\Documents and Settings\All Users\Application Data\WPM =PUP.WpManager
O43 - CFD: 28/12/2013 - 19:35:06 - [0.000] ----D C:\Documents and Settings\yvon\Application Data\DigitalSites =Hijacker.DSite
O43 - CFD: 04/01/2014 - 18:57:58 - [84.349] ----D C:\Documents and Settings\yvon\Local Settings\Application Data\Mobogenie =PUP.Mobogenie
O61 - LFC: 29/01/2014 - 10:26:18 ---A- . (...) -- C:\Documents and Settings\yvon\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\JGLVY37S\www.nationzoom[1].xml [13] =Hijacker.NationZoom
O61 - LFC: 30/01/2014 - 10:26:11 ---A- . (...) -- C:\Documents and Settings\yvon\Cookies\
yvon@CAGSWPMP.txt [149] =PUP.WpManager
O61 - LFC: 31/01/2014 - 10:26:07 ---A- . (...) -- C:\Documents and Settings\yvon\Application Data\Microsoft\Internet Explorer\Quick Launch\Nouvel onglet.lnk [2143] =Adware.SearchYa
O61 - LFC: 31/01/2014 - 10:26:15 ---A- . (...) -- C:\Documents and Settings\yvon\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Applications\www.google.fr\https_80\Nouvel onglet.ico [28134] =Adware.SearchYa
O61 - LFC: 31/01/2014 - 10:26:15 ---A- . (...) -- C:\Documents and Settings\yvon\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Applications\www.google.fr\https_80\Nouvel onglet.ico.md5 [16] =Adware.SearchYa
O61 - LFC: 31/01/2014 - 10:26:19 ---A- . (...) -- C:\Documents and Settings\yvon\Menu Démarrer\Programmes\Nouvel onglet.lnk [2131] =Adware.SearchYa
OPT:O68 - StartMenuInternet: chrome.exe [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Google\Chrome\Application\chrome.exe"
http://www.nationzoom.com
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{938958E8-355C-49FF-92B0-53C1B87ACEA9}] =PUP.SpecialSavings
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{938958E8-355C-49FF-92B0-53C1B87ACEA9}] =PUP.SpecialSavings
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:mobilegeni daemon =PUP.Mobogenie^
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:iLivid =Adware.Bandoo^
C:\Documents and Settings\All Users\Application Data\RHelpers =PUP.SearchDonkey^
C:\Documents and Settings\All Users\Application Data\Updater =PUP.CrossRider^
C:\Documents and Settings\All Users\Application Data\Websteroids =PUP.TubeDimmer^
C:\Documents and Settings\All Users\Application Data\WPM =PUP.WpManager^
C:\Documents and Settings\yvon\Application Data\DigitalSites =Hijacker.DSite^
C:\Documents and Settings\yvon\Local Settings\Application Data\Mobogenie =PUP.Mobogenie^
[HKLM\Software\Wpm] =PUP.WpManager^
[HKLM\Software\supWPM] =PUP.WpManager^
O43 - CFD: 17/09/2013 - 13:49:15 - [0.000] ----D C:\Documents and Settings\yvon\Application Data\TFP
[HKLM\Software\mamverifier] = Toolbar.Mamverifier
[HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WiseConvert_1.5 Toolbar] =Toolbar.Conduit
EmptyPrefetch
EmptyTemp
EmptyFlash
EmptyCLSID
SysRestore
Gabriel.