Problème avec un "Optimuminstaller"
Résolu/Fermé
Brambel
Messages postés
22
Date d'inscription
mardi 18 décembre 2012
Statut
Membre
Dernière intervention
22 décembre 2012
-
18 déc. 2012 à 19:46
Utilisateur anonyme - 22 déc. 2012 à 13:47
Utilisateur anonyme - 22 déc. 2012 à 13:47
40 réponses
Brambel
Messages postés
22
Date d'inscription
mardi 18 décembre 2012
Statut
Membre
Dernière intervention
22 décembre 2012
21 déc. 2012 à 19:00
21 déc. 2012 à 19:00
Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org
Version de la base de données: v2012.12.21.15
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Louis :: LOUIS-PC [administrateur]
21/12/2012 18:51:35
mbam-log-2012-12-21 (18-51-35).txt
Type d'examen: Examen rapide
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d'examen désactivées: P2P
Elément(s) analysé(s): 230415
Temps écoulé: 3 minute(s), 1 seconde(s)
Processus mémoire détecté(s): 0
(Aucun élément nuisible détecté)
Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)
Clé(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)
Valeur(s) du Registre détectée(s): 2
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|Load (PUM.UserWLoad) -> Données: C:\Users\Louis\LOCALS~1\Temp\mswbpcq.com -> Suppression au redémarrage.
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|Load (Trojan.Ransom) -> Données: C:\Users\Louis\LOCALS~1\Temp\mswbpcq.com -> Suppression au redémarrage.
Elément(s) de données du Registre détecté(s): 0
(Aucun élément nuisible détecté)
Dossier(s) détecté(s): 0
(Aucun élément nuisible détecté)
Fichier(s) détecté(s): 0
(Aucun élément nuisible détecté)
(fin)
www.malwarebytes.org
Version de la base de données: v2012.12.21.15
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Louis :: LOUIS-PC [administrateur]
21/12/2012 18:51:35
mbam-log-2012-12-21 (18-51-35).txt
Type d'examen: Examen rapide
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d'examen désactivées: P2P
Elément(s) analysé(s): 230415
Temps écoulé: 3 minute(s), 1 seconde(s)
Processus mémoire détecté(s): 0
(Aucun élément nuisible détecté)
Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)
Clé(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)
Valeur(s) du Registre détectée(s): 2
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|Load (PUM.UserWLoad) -> Données: C:\Users\Louis\LOCALS~1\Temp\mswbpcq.com -> Suppression au redémarrage.
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|Load (Trojan.Ransom) -> Données: C:\Users\Louis\LOCALS~1\Temp\mswbpcq.com -> Suppression au redémarrage.
Elément(s) de données du Registre détecté(s): 0
(Aucun élément nuisible détecté)
Dossier(s) détecté(s): 0
(Aucun élément nuisible détecté)
Fichier(s) détecté(s): 0
(Aucun élément nuisible détecté)
(fin)
Brambel
Messages postés
22
Date d'inscription
mardi 18 décembre 2012
Statut
Membre
Dernière intervention
22 décembre 2012
21 déc. 2012 à 20:37
21 déc. 2012 à 20:37
Voilàààà!
https://www.cjoint.com/?3LvuLaF7Jhr
https://www.cjoint.com/?3LvuLaF7Jhr
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Utilisateur anonyme
21 déc. 2012 à 21:28
21 déc. 2012 à 21:28
bon ok on va le faire comme ca
Télécharge ici :OTL
▶ enregistre le sur ton Bureau.
si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."
sur OTL.exe pour le lancer.
▶ => Clique ici pour voir la Configuration
▶ Copie et colle le contenu de ce qui suit en gras dans la partie inférieure d'OTL "Personnalisation"
/md5start
explorer.exe
winlogon.exe
wininit.exe
volsnap.sys
atapi.sys
ndisuio.sys
ndis.sys
cdrom.sys
i8042prt.sys
net.exe
tdx.sys
netbt.sys
afd.sys
net1.exe
Rundll32.exe
/md5stop
netsvcs
safebootminimal
safebootnetwork
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\*.exe /lockedfiles
%systemroot%\system32\*.ini
%systemroot%\Tasks\*.*
%systemroot%\system32\Tasks\*.*
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\config\*.exe /s
%systemroot%\system32\*.sys
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa /s
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
CREATERESTOREPOINT
▶ Clic sur Analyse.
A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).
Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\<Bureau ou Desktop>\OTL.txt)
▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)
heberge OTL.txt et extra.txt sur https://www.cjoint.com/ et donne les liens
Télécharge ici :OTL
▶ enregistre le sur ton Bureau.
si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."
sur OTL.exe pour le lancer.
▶ => Clique ici pour voir la Configuration
▶ Copie et colle le contenu de ce qui suit en gras dans la partie inférieure d'OTL "Personnalisation"
/md5start
explorer.exe
winlogon.exe
wininit.exe
volsnap.sys
atapi.sys
ndisuio.sys
ndis.sys
cdrom.sys
i8042prt.sys
net.exe
tdx.sys
netbt.sys
afd.sys
net1.exe
Rundll32.exe
/md5stop
netsvcs
safebootminimal
safebootnetwork
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\*.exe /lockedfiles
%systemroot%\system32\*.ini
%systemroot%\Tasks\*.*
%systemroot%\system32\Tasks\*.*
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\config\*.exe /s
%systemroot%\system32\*.sys
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa /s
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
CREATERESTOREPOINT
▶ Clic sur Analyse.
A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).
Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\<Bureau ou Desktop>\OTL.txt)
▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)
heberge OTL.txt et extra.txt sur https://www.cjoint.com/ et donne les liens
Brambel
Messages postés
22
Date d'inscription
mardi 18 décembre 2012
Statut
Membre
Dernière intervention
22 décembre 2012
21 déc. 2012 à 22:15
21 déc. 2012 à 22:15
Utilisateur anonyme
21 déc. 2012 à 22:48
21 déc. 2012 à 22:48
ATTENTION !!! : Script personnalisé pour cette machine uniquement , ne pas reproduire !!
si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."
sur OTL.exe pour le lancer.
▶Copie la liste qui se trouve en gras ci-dessous,
▶ colle-la dans la zone sous "Personnalisation" :
:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
Teatimer.exe
:OTL
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&FORM=IE8SRC
IE - HKLM\..\URLSearchHook: {8e5025c2-8ea3-430d-80b8-a14151068a6d} - SOFTWARE\Classes\CLSID\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\InprocServer32 File not found
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2628705839-2724818738-3904685141-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2628705839-2724818738-3904685141-1001\..\URLSearchHook: {8e5025c2-8ea3-430d-80b8-a14151068a6d} - SOFTWARE\Classes\CLSID\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\InprocServer32 File not found
IE - HKU\S-1-5-21-2628705839-2724818738-3904685141-1001\..\SearchScopes\{13D1BE2A-D2F4-421B-A534-0224CB9284C5}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3128284&CUI=UN12353693282825013&SSPV=IESB15
IE - HKU\S-1-5-21-2628705839-2724818738-3904685141-1001\..\SearchScopes\{58252F0C-EA18-409D-BBDA-32E3D9588DCB}: "URL" = http://www.search.ask.com/?l=dis{searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYBE&apn_uid=EE95B7AE-
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Louis\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll File not found
O1 - Hosts: 66.197.194.232 www.google-analytics.com.
O1 - Hosts: 66.197.194.232 ad-emea.doubleclick.net.
O1 - Hosts: 66.197.194.232 www.statcounter.com.
O1 - Hosts: 66.197.194.232 connect.facebook.net.
O1 - Hosts: 93.115.241.27 www.google-analytics.com.
O1 - Hosts: 93.115.241.27 ad-emea.doubleclick.net.
O1 - Hosts: 93.115.241.27 www.statcounter.com.
O1 - Hosts: 93.115.241.27 connect.facebook.net.
O2 - BHO: (01NET.com Toolbar) - {8e5025c2-8ea3-430d-80b8-a14151068a6d} - C:\Users\Louis\AppData\LocalLow\CT3128284\ldrtb01NE.dll File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (01NET.com Toolbar) - {8e5025c2-8ea3-430d-80b8-a14151068a6d} - C:\Users\Louis\AppData\LocalLow\CT3128284\ldrtb01NE.dll File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2628705839-2724818738-3904685141-1001\..\Toolbar\WebBrowser: (01NET.com Toolbar) - {8E5025C2-8EA3-430D-80B8-A14151068A6D} - C:\Users\Louis\AppData\LocalLow\CT3128284\ldrtb01NE.dll File not found
F3 - HKU\S-1-5-21-2628705839-2724818738-3904685141-1001 WinNT: Load - (C:\Users\Louis\LOCALS~1\Temp\mswbpcq.com) - File not found
F3 - HKU\S-1-5-21-2628705839-2724818738-3904685141-1001 WinNT: Load - (C:\Users\Louis\LOCALS~1\Temp\mswbpcq.com) - File not found
[2012/11/20 13:30:12 | 000,987,080 | ---- | M] (McAfee, Inc.) -- C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M\contentDATs[1].exe
[2012/11/20 13:29:35 | 003,758,512 | ---- | M] (McAfee, Inc.) -- C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5\SecurityScan_Release[1].exe
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
""=-
"iTunesHelper"=-
:Files
C:\ProgramData\Spybot - Search & Destroy
C:\Program Files (x86)\Spybot - Search & Destroy
C:\Program Files (x86)\Pando Networks
C:\END
:commands
[CLEARALLRESTOREPOINTS]
[emptytemp]
[start explorer]
[reboot]
▶ Clique sur "Correction" pour lancer la suppression.
▶ Poste le rapport qui logiquement s'ouvrira tout seul en fin de travail appres le redemarrage.
si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."
sur OTL.exe pour le lancer.
▶Copie la liste qui se trouve en gras ci-dessous,
▶ colle-la dans la zone sous "Personnalisation" :
:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
Teatimer.exe
:OTL
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&FORM=IE8SRC
IE - HKLM\..\URLSearchHook: {8e5025c2-8ea3-430d-80b8-a14151068a6d} - SOFTWARE\Classes\CLSID\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\InprocServer32 File not found
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2628705839-2724818738-3904685141-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2628705839-2724818738-3904685141-1001\..\URLSearchHook: {8e5025c2-8ea3-430d-80b8-a14151068a6d} - SOFTWARE\Classes\CLSID\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\InprocServer32 File not found
IE - HKU\S-1-5-21-2628705839-2724818738-3904685141-1001\..\SearchScopes\{13D1BE2A-D2F4-421B-A534-0224CB9284C5}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3128284&CUI=UN12353693282825013&SSPV=IESB15
IE - HKU\S-1-5-21-2628705839-2724818738-3904685141-1001\..\SearchScopes\{58252F0C-EA18-409D-BBDA-32E3D9588DCB}: "URL" = http://www.search.ask.com/?l=dis{searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYBE&apn_uid=EE95B7AE-
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Louis\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll File not found
O1 - Hosts: 66.197.194.232 www.google-analytics.com.
O1 - Hosts: 66.197.194.232 ad-emea.doubleclick.net.
O1 - Hosts: 66.197.194.232 www.statcounter.com.
O1 - Hosts: 66.197.194.232 connect.facebook.net.
O1 - Hosts: 93.115.241.27 www.google-analytics.com.
O1 - Hosts: 93.115.241.27 ad-emea.doubleclick.net.
O1 - Hosts: 93.115.241.27 www.statcounter.com.
O1 - Hosts: 93.115.241.27 connect.facebook.net.
O2 - BHO: (01NET.com Toolbar) - {8e5025c2-8ea3-430d-80b8-a14151068a6d} - C:\Users\Louis\AppData\LocalLow\CT3128284\ldrtb01NE.dll File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (01NET.com Toolbar) - {8e5025c2-8ea3-430d-80b8-a14151068a6d} - C:\Users\Louis\AppData\LocalLow\CT3128284\ldrtb01NE.dll File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2628705839-2724818738-3904685141-1001\..\Toolbar\WebBrowser: (01NET.com Toolbar) - {8E5025C2-8EA3-430D-80B8-A14151068A6D} - C:\Users\Louis\AppData\LocalLow\CT3128284\ldrtb01NE.dll File not found
F3 - HKU\S-1-5-21-2628705839-2724818738-3904685141-1001 WinNT: Load - (C:\Users\Louis\LOCALS~1\Temp\mswbpcq.com) - File not found
F3 - HKU\S-1-5-21-2628705839-2724818738-3904685141-1001 WinNT: Load - (C:\Users\Louis\LOCALS~1\Temp\mswbpcq.com) - File not found
[2012/11/20 13:30:12 | 000,987,080 | ---- | M] (McAfee, Inc.) -- C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M\contentDATs[1].exe
[2012/11/20 13:29:35 | 003,758,512 | ---- | M] (McAfee, Inc.) -- C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5\SecurityScan_Release[1].exe
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
""=-
"iTunesHelper"=-
:Files
C:\ProgramData\Spybot - Search & Destroy
C:\Program Files (x86)\Spybot - Search & Destroy
C:\Program Files (x86)\Pando Networks
C:\END
:commands
[CLEARALLRESTOREPOINTS]
[emptytemp]
[start explorer]
[reboot]
▶ Clique sur "Correction" pour lancer la suppression.
▶ Poste le rapport qui logiquement s'ouvrira tout seul en fin de travail appres le redemarrage.
Brambel
Messages postés
22
Date d'inscription
mardi 18 décembre 2012
Statut
Membre
Dernière intervention
22 décembre 2012
21 déc. 2012 à 23:00
21 déc. 2012 à 23:00
avant de faire une betise, quelle configuration de otl? La même qu'avant ou celle par défaut?
Utilisateur anonyme
22 déc. 2012 à 00:50
22 déc. 2012 à 00:50
non tu touches rien d autre , tu fais juste ce que je dis au dessus
Brambel
Messages postés
22
Date d'inscription
mardi 18 décembre 2012
Statut
Membre
Dernière intervention
22 décembre 2012
22 déc. 2012 à 08:52
22 déc. 2012 à 08:52
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
No active process named iexplore.exe was found!
No active process named firefox.exe was found!
No active process named msnmsgr.exe was found!
No active process named Teatimer.exe was found!
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{8e5025c2-8ea3-430d-80b8-a14151068a6d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_USERS\S-1-5-21-2628705839-2724818738-3904685141-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-2628705839-2724818738-3904685141-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{8e5025c2-8ea3-430d-80b8-a14151068a6d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\ not found.
Registry key HKEY_USERS\S-1-5-21-2628705839-2724818738-3904685141-1001\Software\Microsoft\Internet Explorer\SearchScopes\{13D1BE2A-D2F4-421B-A534-0224CB9284C5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{13D1BE2A-D2F4-421B-A534-0224CB9284C5}\ not found.
Registry key HKEY_USERS\S-1-5-21-2628705839-2724818738-3904685141-1001\Software\Microsoft\Internet Explorer\SearchScopes\{58252F0C-EA18-409D-BBDA-32E3D9588DCB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58252F0C-EA18-409D-BBDA-32E3D9588DCB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin\ deleted successfully.
Unable to save new HOSTS file
66.197.194.232 ad-emea.doubleclick.net. removed from HOSTS file successfully
66.197.194.232 www.statcounter.com. removed from HOSTS file successfully
66.197.194.232 connect.facebook.net. removed from HOSTS file successfully
93.115.241.27 www.google-analytics.com. removed from HOSTS file successfully
93.115.241.27 ad-emea.doubleclick.net. removed from HOSTS file successfully
93.115.241.27 www.statcounter.com. removed from HOSTS file successfully
93.115.241.27 connect.facebook.net. removed from HOSTS file successfully
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{8e5025c2-8ea3-430d-80b8-a14151068a6d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked not found.
Registry value HKEY_USERS\S-1-5-21-2628705839-2724818738-3904685141-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{8E5025C2-8EA3-430D-80B8-A14151068A6D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E5025C2-8EA3-430D-80B8-A14151068A6D}\ not found.
Registry value HKEY_USERS\S-1-5-21-2628705839-2724818738-3904685141-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Load:C:\Users\Louis\LOCALS~1\Temp\mswbpcq.com deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2628705839-2724818738-3904685141-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Load:C:\Users\Louis\LOCALS~1\Temp\mswbpcq.com deleted successfully.
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M\contentDATs[1].exe moved successfully.
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5\SecurityScan_Release[1].exe moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper deleted successfully.
========== FILES ==========
C:\ProgramData\Spybot - Search & Destroy\Recovery folder moved successfully.
C:\ProgramData\Spybot - Search & Destroy\Logs folder moved successfully.
C:\ProgramData\Spybot - Search & Destroy folder moved successfully.
C:\Program Files (x86)\Spybot - Search & Destroy folder moved successfully.
C:\Program Files (x86)\Pando Networks folder moved successfully.
C:\END moved successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Louis
->Temp folder emptied: 119900985 bytes
->Temporary Internet Files folder emptied: 9201608 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 165538229 bytes
->Flash cache emptied: 3493 bytes
User: Public
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 48634494 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67977 bytes
RecycleBin emptied: 5536945 bytes
Total Files Cleaned = 333.00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 12222012_084758
Files\Folders moved on Reboot...
C:\Users\Louis\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
========== PROCESSES ==========
No active process named explorer.exe was found!
No active process named iexplore.exe was found!
No active process named firefox.exe was found!
No active process named msnmsgr.exe was found!
No active process named Teatimer.exe was found!
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{8e5025c2-8ea3-430d-80b8-a14151068a6d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_USERS\S-1-5-21-2628705839-2724818738-3904685141-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-2628705839-2724818738-3904685141-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{8e5025c2-8ea3-430d-80b8-a14151068a6d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\ not found.
Registry key HKEY_USERS\S-1-5-21-2628705839-2724818738-3904685141-1001\Software\Microsoft\Internet Explorer\SearchScopes\{13D1BE2A-D2F4-421B-A534-0224CB9284C5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{13D1BE2A-D2F4-421B-A534-0224CB9284C5}\ not found.
Registry key HKEY_USERS\S-1-5-21-2628705839-2724818738-3904685141-1001\Software\Microsoft\Internet Explorer\SearchScopes\{58252F0C-EA18-409D-BBDA-32E3D9588DCB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58252F0C-EA18-409D-BBDA-32E3D9588DCB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin\ deleted successfully.
Unable to save new HOSTS file
66.197.194.232 ad-emea.doubleclick.net. removed from HOSTS file successfully
66.197.194.232 www.statcounter.com. removed from HOSTS file successfully
66.197.194.232 connect.facebook.net. removed from HOSTS file successfully
93.115.241.27 www.google-analytics.com. removed from HOSTS file successfully
93.115.241.27 ad-emea.doubleclick.net. removed from HOSTS file successfully
93.115.241.27 www.statcounter.com. removed from HOSTS file successfully
93.115.241.27 connect.facebook.net. removed from HOSTS file successfully
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{8e5025c2-8ea3-430d-80b8-a14151068a6d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked not found.
Registry value HKEY_USERS\S-1-5-21-2628705839-2724818738-3904685141-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{8E5025C2-8EA3-430D-80B8-A14151068A6D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E5025C2-8EA3-430D-80B8-A14151068A6D}\ not found.
Registry value HKEY_USERS\S-1-5-21-2628705839-2724818738-3904685141-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Load:C:\Users\Louis\LOCALS~1\Temp\mswbpcq.com deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2628705839-2724818738-3904685141-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Load:C:\Users\Louis\LOCALS~1\Temp\mswbpcq.com deleted successfully.
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M\contentDATs[1].exe moved successfully.
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5\SecurityScan_Release[1].exe moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper deleted successfully.
========== FILES ==========
C:\ProgramData\Spybot - Search & Destroy\Recovery folder moved successfully.
C:\ProgramData\Spybot - Search & Destroy\Logs folder moved successfully.
C:\ProgramData\Spybot - Search & Destroy folder moved successfully.
C:\Program Files (x86)\Spybot - Search & Destroy folder moved successfully.
C:\Program Files (x86)\Pando Networks folder moved successfully.
C:\END moved successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Louis
->Temp folder emptied: 119900985 bytes
->Temporary Internet Files folder emptied: 9201608 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 165538229 bytes
->Flash cache emptied: 3493 bytes
User: Public
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 48634494 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67977 bytes
RecycleBin emptied: 5536945 bytes
Total Files Cleaned = 333.00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 12222012_084758
Files\Folders moved on Reboot...
C:\Users\Louis\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
Utilisateur anonyme
22 déc. 2012 à 09:30
22 déc. 2012 à 09:30
voila je pense que si tu n'as plus de soucis , on peut faire le menage final si tu es d'accord :D
Brambel
Messages postés
22
Date d'inscription
mardi 18 décembre 2012
Statut
Membre
Dernière intervention
22 décembre 2012
22 déc. 2012 à 09:34
22 déc. 2012 à 09:34
Génial! on dirait que ca marche! :)
Je suis d'accord ;)
Waaaa merci beaucoup!
Je suis d'accord ;)
Waaaa merci beaucoup!
Brambel
Messages postés
22
Date d'inscription
mardi 18 décembre 2012
Statut
Membre
Dernière intervention
22 décembre 2012
22 déc. 2012 à 11:02
22 déc. 2012 à 11:02
D'accord, je vais faire ça!
Merci beaucoup pour ton aide, et le temps que tu as pris pour m'aider!
Bonne continuation! :)
Merci beaucoup pour ton aide, et le temps que tu as pris pour m'aider!
Bonne continuation! :)
Brambel
Messages postés
22
Date d'inscription
mardi 18 décembre 2012
Statut
Membre
Dernière intervention
22 décembre 2012
22 déc. 2012 à 13:07
22 déc. 2012 à 13:07
voila, je viens de voir que je devais poster ça :)
# DelFix v6.2 - Rapport créé le 22/12/2012 à 13:06:28
# Mis à jour le 11/11/2012 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : Louis - LOUIS-PC
# Exécuté depuis : C:\Users\Louis\Downloads\delfix.exe
# Option [Suppression]
~~~~~~ Dossier(s) ~~~~~~
Supprimé : C:\_OTL
Supprimé : C:\pre_scan
~~~~~~ Fichier(s) ~~~~~~
Supprimé : C:\Users\Louis\Desktop\AdwCleaner.exe
Supprimé : C:\Users\Louis\Desktop\Extras.Txt
Supprimé : C:\Users\Louis\Desktop\JavaRa.zip
Supprimé : C:\Users\Louis\Desktop\OTL.Txt
Supprimé : C:\Users\Louis\Desktop\OTL.exe
Supprimé : C:\Users\Louis\Desktop\Pre_script.txt
Supprimé : C:\Users\Louis\Downloads\winlogon(1).exe
~~~~~~ Registre ~~~~~~
Clé Supprimée : HKCU\Software\g3n-h@ckm@n
Clé Supprimée : HKLM\SOFTWARE\OldTimer Tools
Clé Supprimée : HKLM\SOFTWARE\AdwCleaner
~~~~~~ Autres ~~~~~~
-> Prefetch Vidé
*************************
DelFix[S1].txt - [961 octets] - [22/12/2012 13:06:28]
########## EOF - C:\DelFix[S1].txt - [1084 octets] ##########
# DelFix v6.2 - Rapport créé le 22/12/2012 à 13:06:28
# Mis à jour le 11/11/2012 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : Louis - LOUIS-PC
# Exécuté depuis : C:\Users\Louis\Downloads\delfix.exe
# Option [Suppression]
~~~~~~ Dossier(s) ~~~~~~
Supprimé : C:\_OTL
Supprimé : C:\pre_scan
~~~~~~ Fichier(s) ~~~~~~
Supprimé : C:\Users\Louis\Desktop\AdwCleaner.exe
Supprimé : C:\Users\Louis\Desktop\Extras.Txt
Supprimé : C:\Users\Louis\Desktop\JavaRa.zip
Supprimé : C:\Users\Louis\Desktop\OTL.Txt
Supprimé : C:\Users\Louis\Desktop\OTL.exe
Supprimé : C:\Users\Louis\Desktop\Pre_script.txt
Supprimé : C:\Users\Louis\Downloads\winlogon(1).exe
~~~~~~ Registre ~~~~~~
Clé Supprimée : HKCU\Software\g3n-h@ckm@n
Clé Supprimée : HKLM\SOFTWARE\OldTimer Tools
Clé Supprimée : HKLM\SOFTWARE\AdwCleaner
~~~~~~ Autres ~~~~~~
-> Prefetch Vidé
*************************
DelFix[S1].txt - [961 octets] - [22/12/2012 13:06:28]
########## EOF - C:\DelFix[S1].txt - [1084 octets] ##########
Brambel
Messages postés
22
Date d'inscription
mardi 18 décembre 2012
Statut
Membre
Dernière intervention
22 décembre 2012
22 déc. 2012 à 13:16
22 déc. 2012 à 13:16
Brambel
Messages postés
22
Date d'inscription
mardi 18 décembre 2012
Statut
Membre
Dernière intervention
22 décembre 2012
22 déc. 2012 à 13:21
22 déc. 2012 à 13:21
Total space cleaned: 14.96 MB
Brambel
Messages postés
22
Date d'inscription
mardi 18 décembre 2012
Statut
Membre
Dernière intervention
22 décembre 2012
22 déc. 2012 à 13:44
22 déc. 2012 à 13:44
Voilà j'ai tout fait! Merci beaucoup pour tout! :) Bonnes fêtes!