.
Il est possible que les extensions ne soit déjà plus là . Il faudrait tout de même vérifier.
Donc si tu trouves quelque chose qui s'appelle Bitlord ou WhenUSave, ça doit dégager.
Ensuite on réessaie ZhpFix, je veux bien que quelques lignes résistent, mais que toutes les lignes restent ce n'est pas normal.
- Envoie le rapport ZhpFix qui apparaîtra sur le bureau.
Script ZhpFix
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowMyDocs: Modified
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowMyGames: Modified
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowMyMusic: Modified
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowMyPics: Modified
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "SoftwareSASGeneration"=3
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSetProgramAccessAndDefaults: Modified =>PUA.StartShow
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowNetConn: Modified
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = http://www.qvo6.com =>Hijacker.Qvo6
O43 - CFD: 28/05/2014 - 21:15:38 - [] ----D C:\Users\Nico\AppData\Roaming\BitLord =>Adware.WhenUSave
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Mysearchdial) - http://start.mysearchdial.com =>Adware.MyWebSearch
O81 - IFC: Internet Feature Controls [HKUS\.DEFAULT] [FEATURE_BROWSER_EMULATION] -- svchost.exe =>Rootkit.TDSS
O81 - IFC: Internet Feature Controls [HKUS\S-1-5-18] [FEATURE_BROWSER_EMULATION] -- svchost.exe =>Rootkit.TDSS
[MD5.9CD5109EF7367DF192989B4D26B0E344] [WIS][24/09/2013] (.BonanzaDeals - Google Update Helper.) -- C:\Windows\Installer\2972c15.msi [40960] =>Adware.BonanzaDeals
HKLM\SOFTWARE\Microsoft\Tracing\BitLord_RASAPI32 =>Adware.WhenUSave
HKLM\SOFTWARE\Microsoft\Tracing\BitLord_RASMANCS =>Adware.WhenUSave
HKLM\SOFTWARE\Microsoft\Tracing\updateWebConnect_RASAPI32 =>PUP.WebConnect
HKLM\SOFTWARE\Microsoft\Tracing\updateWebConnect_RASMANCS =>PUP.WebConnect
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BitLordInstall(2)_RASAPI32 =>Adware.WhenUSave
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BitLordInstall(2)_RASMANCS =>Adware.WhenUSave
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BitLordInstall_RASAPI32 =>Adware.WhenUSave
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BitLordInstall_RASMANCS =>Adware.WhenUSave
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BitlordSetup_RASAPI32 =>Adware.WhenUSave
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BitlordSetup_RASMANCS =>Adware.WhenUSave
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BitLord_Installer_RASAPI32 =>Adware.WhenUSave
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BitLord_Installer_RASMANCS =>Adware.WhenUSave
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BrowseSmartSetup_RASAPI32 =>PUP.BrowseSmart
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BrowseSmartSetup_RASMANCS =>PUP.BrowseSmart
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BrowseSmart_Setup_RASAPI32 =>PUP.BrowseSmart
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BrowseSmart_Setup_RASMANCS =>PUP.BrowseSmart
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\cor_ar_2013729172639_qvo6_RASAPI32 =>Hijacker.Qvo6
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\cor_ar_2013729172639_qvo6_RASMANCS =>Hijacker.Qvo6
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\cor_ar_201396184325_qvo6_RASAPI32 =>Hijacker.Qvo6
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\cor_ar_201396184325_qvo6_RASMANCS =>Hijacker.Qvo6
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\cor_ar_qone8_RASAPI32 =>Hijacker.Qone8
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\cor_ar_qone8_RASMANCS =>Hijacker.Qone8
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\deskSvc_RASAPI32 =>Hijacker.22Find
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\deskSvc_RASMANCS =>Hijacker.22Find
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ICReinstall_BitLordInstall_RASAPI32 =>Adware.WhenUSave
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ICReinstall_BitLordInstall_RASMANCS =>Adware.WhenUSave
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WebConnect_RASAPI32 =>PUP.WebConnect
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WebConnect_RASMANCS =>PUP.WebConnect
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WebConnect_Setup_RASAPI32 =>PUP.WebConnect
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WebConnect_Setup_RASMANCS =>PUP.WebConnect
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\yontoo-C4-1A38_RASAPI32 =>Adware.Yontoo
HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\yontoo-C4-1A38_RASMANCS =>Adware.Yontoo
C:\Users\Nico\AppData\Roaming\BitLord =>Adware.WhenUSave^
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSetProgramAccessAndDefaults: Modified =>PUA.StartShow^
C:\Windows\Installer\2972c15.msi =>Adware.BonanzaDeals^
O43 - CFD: 18/08/2013 - 16:32:42 - [] ----D C:\ProgramData\Spybot - Search & Destroy
O43 - CFD: 10/06/2013 - 23:26:49 - [0] --HAD C:\Users\Nico\AppData\Local\AEm7CPsK1Z
O61 - LFC: 05/06/2014 - 18:13:56 ---A- . (...) -- C:\Users\Nico\AppData\Local\Temp\Quarantine.exe [384139]
O61 - LFC: 07/06/2014 - 18:13:56 ---A- . (...) -- C:\Users\Nico\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpjnte4g.dll [43008]