Script ZHPFix
SysRestore

[MD5.6D8D4EF5E23EC7A3E739BBD9AE941961] - (.PCTuto - autoupdater.) -- C:\Users\7ProTest\AppData\Roaming\PCTuto\PCTuto\autoupdater.exe [663168]
[MD5.29B5117C0D0944090531AF477BBEBADC] - (.EoRezo - SoftwareHelper.) -- C:\Users\7ProTest\AppData\Roaming\EoRezo\EoRezo\SoftwareUpdateHP.exe [728688]
[MD5.E89AF3748774C10C12264E57AB3BAF4B] - (.PCTUTO - PCTUTO.) -- C:\Program Files\pctuto\pctuto.exe [982656]
[MD5.C1BEC28EE4E25F5F653B26866B48947D] - (.Pas de propriétaire - Application MFC EoEngine.) -- C:\Program Files\EoRezo\EoEngine.exe [470640]
[MD5.8F715698C8816751E8E00AF3DF191974] - (.EoRezo - EoRezo.) -- C:\Program Files\EoRezo\EoRezo.exe [683632]
[MD5.30192AA3DA2527343DAB266EAE425A68] - (...) -- C:\Users\7ProTest\acrobat32.exe [27136]
[MD5.08A1624BD552601773FF43ED022F5C82] - (...) -- C:\Users\7ProTest\wogof.exe [118784]

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://y.lo.st
R0 - HKUS\S-1-5-21-1454910967-2183443150-715450999-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://y.lo.st

O2 - BHO: PCTBHO - {293A63F7-C3B6-423a-9845-901AC0A7EE6E} . (.PCTUTO - ....) -- C:\Program Files\PCTuto\pctutoBHO.dll
O2 - BHO: EOBHO - {C10DC1F4-CCDF-4224-A24D-B23AFC3573C8} . (.EoRezo - ....) -- C:\Program Files\EoRezo\EoRezoBHO.dll

O4 - HKLM\..\Run: [pctuto] . (.PCTUTO - PCTUTO.) -- C:\Program Files\PCTuto\pctuto.exe
O4 - HKLM\..\Run: [EoWeather] Clé orpheline
O4 - HKLM\..\Run: [EoEngine] . (.Pas de propriétaire - Application MFC EoEngine.) -- C:\Program Files\EoRezo\EoEngine.exe
O4 - HKLM\..\Run: [eorezo] . (.EoRezo - EoRezo.) -- C:\Program Files\EoRezo\eorezo.exe
O4 - HKLM\..\RunOnce: [autoupdater] . (.PCTuto - autoupdater.) -- C:\Users\7ProTest\AppData\Roaming\PCTuto\PCTuto\autoupdater.exe
O4 - HKLM\..\RunOnce: [SoftwareHelper] . (.EoRezo - SoftwareHelper.) -- C:\Users\7ProTest\AppData\Roaming\EoRezo\EoRezo\SoftwareUpdateHP.exe
O4 - HKCU\..\Run: [wogof] . (...) -- C:\Users\7ProTest\wogof.exe
O4 - HKCU\..\Run: [CreoLab].(...) -- C:\ProgramData\xp\nbpoarwmcewqhy.exe
O4 - HKCU\..\RunOnce: [lI10300CcKgN10300].(...) -- C:\ProgramData\lI10300CcKgN10300\lI10300CcKgN10300.exe
O4 - HKUS\S-1-5-21-1454910967-2183443150-715450999-1001-1454910967-2183443150-715450999-1000\..\Run: [CreoLab].(...) -- C:\ProgramData\xp\nbpoarwmcewqhy.exe
O4 - HKUS\S-1-5-21-1454910967-2183443150-715450999-1001-1454910967-2183443150-715450999-1000\..\RunOnce: [lI10300CcKgN10300].(...) -- C:\ProgramData\lI10300CcKgN10300\lI10300CcKgN10300.exe


O42 - Logiciel: PCTuto 1.0 - (.PCTuto.) [HKLM] -- PCTuto_is1
O42 - Logiciel: Tuto Ccleaner1.0.0.0 - (.pctuto.) [HKLM] -- Tuto Ccleaner_is1
O42 - Logiciel: Tuto Notepad++1.0.0.0 - (.PCTuto.) [HKLM] -- Tuto Notepad++_is1
O42 - Logiciel: eoEngine 13.1 - (.EoRezo.) [HKLM] -- eoEngine_is1
O42 - Logiciel: eoRezo 15.0 - (.EoRezo.) [HKLM] -- EoRezo_is1

[HKCU\Software\Agence-Exclusive]
[HKCU\Software\EoRezo]
[HKLM\Software\Agence-Exclusive]
[HKLM\Software\EoRezo]
[HKLM\Software\PCTuto]
[HKCU\Software\PCTuto]
[HKCU\Software\YahooPartnerToolbar]
[HKCU\Software\VDC]


O43 - CFD: 18/07/2011 - 13:40:34 - [2457167] ----D- C:\Program Files\Agence-Exclusive
O43 - CFD: 18/07/2011 - 16:46:46 - [16542956] ----D- C:\Program Files\EoRezo
O43 - CFD: 18/07/2011 - 14:14:30 - [14541074] ----D- C:\Program Files\pctuto
O43 - CFD: 18/07/2011 - 15:10:20 - [2919473] ----D- C:\ProgramData\xp
O43 - CFD: 18/07/2011 - 15:00:40 - [2916864] ----D- C:\ProgramData\9f5132
O43 - CFD: 18/07/2011 - 15:08:28 - [405712] ----D- C:\ProgramData\lI10300CcKgN10300
O43 - CFD: 18/07/2011 - 13:40:34 - [1450308] ----D- C:\Users\7ProTest\AppData\Roaming\Agence-Exclusive
O43 - CFD: 18/07/2011 - 16:46:48 - [3693944] ----D- C:\Users\7ProTest\AppData\Roaming\EoRezo
O43 - CFD: 18/07/2011 - 14:13:54 - [1434128] ----D- C:\Users\7ProTest\AppData\Roaming\PCTuto
O43 - CFD: 18/07/2011 - 13:40:34 - [513872] ----D- C:\Users\7ProTest\AppData\Local\Agence-Exclusive
O43 - CFD: 18/07/2011 - 14:30:10 - [515248] ----D- C:\Users\7ProTest\AppData\Local\EoRezo
O43 - CFD: 18/07/2011 - 14:13:54 - [515964] ----D- C:\Users\7ProTest\AppData\Local\PCTuto

O44 - LFC:[MD5.F172ECCC8E3013FBF4A2C751EE0963B5] - 18/07/2011 - 13:55:51 ---A- . (...) -- C:\Windows\System32\c_7265170.nls [129028]

O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0


[MD5.9F922587B260D4B0013BD226F1711EBC] [SPRF][18/07/2011] (...) -- C:\Users\7ProTest\AppData\Local\Temp\287.sys [99712]
[MD5.FB1BAC48D3599CCC9A7DB61D3932570A] [SPRF][18/07/2011] (.pctuto - Tuto Ccleaner Setup.) -- C:\Users\7ProTest\AppData\Local\Temp\ins1D61.tmp.exe [3219768]
[MD5.70F14E00FCDF145D8418CCD3726AD8AD] [SPRF][18/07/2011] (.PCTuto - Tuto Notepad++ Setup.) -- C:\Users\7ProTest\AppData\Local\Temp\ins6C9A.tmp.exe [2567933]
[MD5.B2BFBEA6241734F53920653CA8B909A7] [SPRF][18/07/2011] (.OldTimer Tools - Pas de description.) -- C:\Users\7ProTest\Desktop\OTL.exe [579584]
[MD5.EDE948BD5C7D64C5760121E06AB98772] [SPRF][18/07/2011] (.PCTuto - PCTuto Setup.) -- C:\Users\7ProTest\Desktop\pctuto.exe [1895280]
[MD5.BFFF91B97C9C677896E6F57F7918FC41] [SPRF][18/07/2011] (.Agence-Exclusive - PCTuto Setup.) -- C:\Users\7ProTest\Desktop\pctuto_01net_ccleaner.exe [1970216]
[MD5.95A960B7C3C05CB9BBF0EDD80086F770] [SPRF][12/07/2011] (.C_XX - SEAF.) -- C:\Users\7ProTest\Desktop\SEAF.exe [498868]

O81 - IFC: Internet Feature Controls [HKUS\.DEFAULT] [FEATURE_BROWSER_EMULATION] -- svchost.exe
O81 - IFC: Internet Feature Controls [HKUS\S-1-5-18] [FEATURE_BROWSER_EMULATION] -- svchost.exe

C:\ProgramData\9f5132
[MD5.F86FC869CE512580FD2187F48893F6DA] [SRI] (...) -- C:\ProgramData\9f5132\VD9f5_287.exe [2916864]


O87 - FAEL: "TCP Query User{EDD0FE41-133A-462C-8DB6-675F9FF7A7D2}C:\programdata\9f5132\vd9f5_287.exe" | In - Private - P6 - TRUE | .(...) -- C:\programdata\9f5132\vd9f5_287.exe
O87 - FAEL: "UDP Query User{F630DA4F-E79F-4331-9431-9398E0720235}C:\programdata\9f5132\vd9f5_287.exe" | In - Private - P17 - TRUE | .(...) -- C:\programdata\9f5132\vd9f5_287.exe
O87 - FAEL: "TCP Query User{3FD75A92-1E69-47C9-8B41-D3A3659678F6}C:\programdata\xp\nbpoarwmcewqhy.exe" | In - Private - P6 - TRUE | .(...) -- C:\programdata\xp\nbpoarwmcewqhy.exe
O87 - FAEL: "UDP Query User{1AF00510-F399-4615-B7B4-582019BBB8B8}C:\programdata\xp\nbpoarwmcewqhy.exe" | In - Private - P17 - TRUE | .(...) -- C:\programdata\xp\nbpoarwmcewqhy.exe

[HKLM\Software\Classes\AppID\eoenginebho.dll] =>PUP.Eorezo
[HKLM\Software\Classes\eoenginebho.eobho] =>PUP.Eorezo
[HKLM\Software\Classes\eoenginebho.eobho.1] =>PUP.Eorezo
[HKLM\Software\Classes\PCTutoBHO.PCTBHO] =>Spyware.AgenceExclusive
[HKLM\Software\Classes\PCTutoBHO.PCTBHO.1] =>Spyware.AgenceExclusive
[HKLM\Software\Classes\TypeLib\{0BF73E27-2734-4F7B-925A-4BBB1457F5FA}] =>PUP.Eorezo
[HKLM\Software\Classes\TypeLib\{18AF7201-4F14-4BCF-93FE-45617CF259FF}] =>PUP.Eorezo
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{293A63F7-C3B6-423A-9845-901AC0A7EE6E}] =>PUP.Eorezo
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{293A63F7-C3B6-423A-9845-901AC0A7EE6E}] =>PUP.Eorezo
[HKLM\Software\Classes\CLSID\{293A63F7-C3B6-423A-9845-901AC0A7EE6E}] =>PUP.Eorezo
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{293A63F7-C3B6-423A-9845-901AC0A7EE6E}] =>PUP.Eorezo
[HKLM\Software\Classes\AppID\{AFBB7970-789A-4264-BA70-E8127DECE400}] =>PUP.Eorezo
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C10DC1F4-CCDF-4224-A24D-B23AFC3573C8}] =>PUP.Eorezo
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C10DC1F4-CCDF-4224-A24D-B23AFC3573C8}] =>PUP.Eorezo
[HKLM\Software\Classes\CLSID\{C10DC1F4-CCDF-4224-A24D-B23AFC3573C8}] =>PUP.Eorezo
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C10DC1F4-CCDF-4224-A24D-B23AFC3573C8}] =>PUP.Eorezo
[HKLM\Software\Classes\Interface\{DF76E9B7-35EC-46FC-AF56-5B79DED9D64F}] =>PUP.Eorezo
[HKLM\Software\Classes\Interface\{E2ED56B6-35FC-4484-9530-EC87FB458E78}] =>PUP.Eorezo
[HKCU\Software\Agence-Exclusive] =>Spyware.AgenceExclusive
[HKLM\Software\Agence-Exclusive] =>Spyware.AgenceExclusive
[HKCU\Software\eorezo] =>PUP.Eorezo
[HKLM\Software\eorezo] =>PUP.Eorezo
[HKCU\Software\PCTuto] =>Spyware.AgenceExclusive
[HKLM\Software\PCTuto] =>Spyware.AgenceExclusive
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\eoengine_is1] =>PUP.Eorezo
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\EoRezo_is1] =>PUP.Eorezo
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PcTuto_is1] =>Spyware.AgenceExclusive
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]:EoEngine =>PUP.Eorezo
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]:eorezo =>PUP.Eorezo
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]:EoWeather =>PUP.Eorezo
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]:PCTuto =>Spyware.AgenceExclusive

C:\Program Files\Agence-Exclusive =>Spyware.AgenceExclusive
C:\Program Files\EoRezo =>PUP.Eorezo
C:\Program Files\PCTuto =>Spyware.AgenceExclusive
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EoRezo =>PUP.Eorezo
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCTuto =>Spyware.AgenceExclusive
C:\Users\7ProTest\AppData\Roaming\Agence-Exclusive =>Spyware.AgenceExclusive
C:\Users\7ProTest\AppData\Roaming\EoRezo =>PUP.Eorezo
C:\Users\7ProTest\AppData\Roaming\PCTuto =>Spyware.AgenceExclusive
C:\Users\7ProTest\AppData\Local\Agence-Exclusive =>Spyware.AgenceExclusive
C:\Users\7ProTest\AppData\Local\EoRezo =>PUP.Eorezo
C:\Users\7ProTest\AppData\Local\PCTuto =>Spyware.AgenceExclusive
EMPTYTEMP
EmptyFlash
EMPTYCLSID
FirewallRaz