Supprimer le moteur de recherche "jerecherche"

laurentsibi Messages postés 10 Date d'inscription   Statut Membre Dernière intervention   -  
 g3n-h@ckm@n -
Bonjour,


j ai le moteur de recherche "jerecherche" qui s est installé,j ai fait des restaurations etc je n arrive pas a l enlever
quelqu un a t il la solution ?
merci

10 réponses

  1. g3n-h@ckm@n
     
    salut

    Télécharge et enregistre ADWCleaner sur ton bureau :

    Lance le,(Pour vista/7/8 => clic droit "executer en tant qu'administrateur")

    clique sur suppression et poste C:\Adwcleaner[Sx].txt
    0
    1. laurentsibi Messages postés 10 Date d'inscription   Statut Membre Dernière intervention  
       
      je te remercie de m aider
      # AdwCleaner v2.105 - Rapport créé le 12/01/2013 à 16:53:18
      # Mis à jour le 08/01/2013 par Xplode
      # Système d'exploitation : Microsoft Windows XP Service Pack 3 (32 bits)
      # Nom d'utilisateur : ---- - 5F9F0FD3037B446
      # Mode de démarrage : Normal
      # Exécuté depuis : C:\Documents and Settings\----.5F9F0FD3037B446\Mes documents\Téléchargements\AdwCleaner.exe
      # Option [Suppression]


      ***** [Services] *****


      ***** [Fichiers / Dossiers] *****

      Dossier Supprimé : C:\Program Files\IZArc\OpenCandy
      Supprimé au redémarrage : C:\WINDOWS\system32\prncnfgd

      ***** [Registre] *****


      ***** [Navigateurs] *****

      -\\ Internet Explorer v8.0.6001.18702

      [OK] Le registre ne contient aucune entrée illégitime.

      -\\ Mozilla Firefox v17.0.1 (fr)

      *************************

      AdwCleaner[S1].txt - [787 octets] - [12/01/2013 16:53:18]

      ########## EOF - C:\AdwCleaner[S1].txt - [846 octets] ##########
      0
  2. g3n-h@ckm@n
     
    Télécharge ici :OTL

    enregistre le sur ton Bureau.

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    sur OTL.exe pour le lancer.

    => Clique ici pour voir la Configuration

    ▶ Copie et colle le contenu de ce qui suit en gras dans la partie inférieure d'OTL "Personnalisation"

    /md5start
    explorer.exe
    winlogon.exe
    wininit.exe
    volsnap.sys
    atapi.sys
    ndisuio.sys
    ndis.sys
    cdrom.sys
    i8042prt.sys
    iastor.sys
    net.exe
    tdx.sys
    netbt.sys
    afd.sys
    net1.exe
    Rundll32.exe
    /md5stop
    netsvcs
    safebootminimal
    safebootnetwork
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\*.exe /lockedfiles
    %systemroot%\system32\*.ini
    %systemroot%\Tasks\*.*
    %systemroot%\system32\Tasks\*.*
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\config\*.exe /s
    %systemroot%\system32\*.sys
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa /s
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    CREATERESTOREPOINT


    ▶ Clic sur Analyse.

    A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

    Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\<Bureau ou Desktop>\OTL.txt)

    ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

    heberge OTL.txt et extra.txt sur https://www.cjoint.com/ et donne les liens
    0
  3. g3n-h@ckm@n
     
    le moteur de recherche est toujours present ?
    0
    1. laurentsibi Messages postés 10 Date d'inscription   Statut Membre Dernière intervention  
       
      oui toujours
      0
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. g3n-h@ckm@n
     
    ▶ Télécharge ici : Ad-remover sur ton bureau :

    ▶ ferme toutes fenetres !

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    ▶ sur "Ad-R.exe" pour l'installer et ne touche pas aux parametres

    ▶ clique le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

    ▶ choisis "option Nettoyer" et tape sur [entrée] .

    ▶ Laisse travailler l'outil et ne touche à rien ...

    ▶ Poste le rapport C:\Ad-report.log qui apparait à la fin , sur le forum ...

    0
    1. laurentsibi Messages postés 10 Date d'inscription   Statut Membre Dernière intervention  
       
      j ai fait ce que tu me demandes mais le rapport est Ad-report-CLEAN.log ,je le poste quand meme

      ======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======

      Mis à jour par TeamXscript le 12/04/11
      Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
      Site web: http://www.teamxscript.org

      C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 18:42:04 le 12/01/2013, Mode normal

      Microsoft Windows XP Édition familiale Service Pack 3 (X86)
      ----@5F9F0FD3037B446 ( )

      ============== ACTION(S) ==============


      Fichier supprimé: C:\Documents and Settings\----.5F9F0FD3037B446\temps11.vbs

      (!) -- Fichiers temporaires supprimés.




      ============== SCAN ADDITIONNEL ==============

      **** Mozilla Firefox Version [17.0.1 (fr)] ****

      HKLM_MozillaPlugins\Adobe Reader (x)
      Components\browsercomps.dll (Mozilla Foundation)

      -- C:\Documents and Settings\----.5F9F0FD3037B446\Application Data\Mozilla\FireFox\Profiles\ajgua8tu.default --
      Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(2) (Adblock Plus)
      Searchplugins\jerecherche.xml ( hxxp://www.jerecherche.org/result.php?)
      Prefs.js - browser.startup.homepage, hxxp://google.fr
      Prefs.js - browser.startup.homepage_override.buildID, 20121128204232
      Prefs.js - browser.startup.homepage_override.mstone, 17.0.1

      ========================================

      **** Internet Explorer Version [8.0.6001.18702] ****

      HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
      HKCU_Main|Start Page - hxxp://fr.msn.com/
      HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
      HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
      HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      HKLM_Main|Start Page - hxxp://fr.msn.com/
      HKLM_Toolbar|{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} (C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll)
      HKLM_ElevationPolicy\{5852F5ED-8BF4-11D4-A245-0080C6F74284} - C:\Program Files\Java\jre7\bin\javaws.exe (Oracle Corporation)
      HKLM_ElevationPolicy\{58F04068-17A5-41a3-B5B7-111004DDF5DC} - C:\Program Files\Real\RealPlayer\realplay.exe (x)
      HKLM_ElevationPolicy\{5A2777DF-310A-49ca-A9E8-6C9D608D257E} - C:\Program Files\Real\RealUpgrade\realupgrade.exe (x)
      HKLM_ElevationPolicy\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D} - C:\Program Files\Google\Update\1.3.21.111\GoogleUpdateBroker.exe (x)
      HKLM_ElevationPolicy\{C442AC41-9200-4770-8CC0-7CDB4F245C55} - C:\Program Files\Google\Update\GoogleUpdate.exe (x)
      HKLM_ElevationPolicy\{E56200D6-445E-45ce-89D8-E0EF39ECF849} - C:\Program Files\Real\RealPlayer\RecordingManager.exe (x)
      HKLM_Extensions\{90EAE591-7E7E-434a-8E28-ECFD00071806} - "PokerStars.fr" (?)
      BHO\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - "avast! WebRep" (C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll)

      ========================================

      C:\Program Files\Ad-Remover\Quarantine: 1 Fichier(s)
      C:\Program Files\Ad-Remover\Backup: 13 Fichier(s)

      C:\Ad-Report-CLEAN[1].txt - 12/01/2013 18:42:15 (2419 Octet(s))

      Fin à: 18:42:59, 12/01/2013

      ============== E.O.F ==============
      0
  6. g3n-h@ckm@n
     
    refais OTL ? avec la config ?
    0
    1. laurentsibi Messages postés 10 Date d'inscription   Statut Membre Dernière intervention  
       
      comment ca avec la config
      0
  7. g3n-h@ckm@n
     
    ATTENTION !!! : Script personnalisé pour cette machine uniquement , ne pas reproduire !!

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    sur OTL.exe pour le lancer.

    ▶Copie la liste qui se trouve en gras ci-dessous,

    ▶ colle-la dans la zone sous "Personnalisation" :


    :processes
    explorer.exe
    iexplore.exe
    firefox.exe
    msnmsgr.exe
    Teatimer.exe

    :OTL
    IE - HKLM\..\SearchScopes,DefaultScope =
    IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
    IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
    IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
    FF - prefs.js..network.proxy.type: 4
    FF - user.js - File not found
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: File not found
    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666: File not found
    FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666: File not found
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.666: File not found
    FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.666: File not found
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666: File not found
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: File not found
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    O4 - HKLM\..\Run: [nwiz]
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} https://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Reg Error: Value error.)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [2011/02/14 19:22:55 | 000,176,128 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc(8).dll
    [2011/02/14 19:22:55 | 000,176,128 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc(7).dll
    [2011/02/14 19:22:55 | 000,176,128 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc(6).dll
    [2011/02/14 19:22:55 | 000,176,128 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc(5).dll
    [2011/02/14 19:22:55 | 000,176,128 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc(4).dll
    [2011/02/14 19:22:55 | 000,176,128 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc(3).dll
    [2011/02/14 19:22:55 | 000,176,128 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc(2).dll
    [2011/02/14 19:22:55 | 000,176,128 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc(14).dll
    [2011/02/14 19:22:55 | 000,176,128 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc(13).dll
    [2011/02/14 19:22:55 | 000,176,128 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc(12).dll
    [2011/02/14 19:22:55 | 000,176,128 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc(11).dll
    [2011/02/14 19:22:55 | 000,176,128 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc(10).dll

    :Reg
    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
    ""="%SystemRoot%\system32\shell32.dll"

    :Files
    C:\Documents and Settings\----.5F9F0FD3037B446\Application Data\Mozilla\Firefox\Profiles\ajgua8tu.default\searchplugins\jerecherche.xml
    C:\WINDOWS\System32\csnp2uvc(9).dll

    :commands
    [CLEARALLRESTOREPOINTS]
    [emptytemp]
    [start explorer]
    [reboot]


    ▶ Clique sur "Correction" pour lancer la suppression.

    ▶ Poste le rapport qui logiquement s'ouvrira tout seul en fin de travail appres le redemarrage.

    0
    1. laurentsibi Messages postés 10 Date d'inscription   Statut Membre Dernière intervention  
       
      All processes killed
      ========== PROCESSES ==========
      No active process named explorer.exe was found!
      No active process named iexplore.exe was found!
      Process firefox.exe killed successfully!
      No active process named msnmsgr.exe was found!
      No active process named Teatimer.exe was found!
      ========== OTL ==========
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
      HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
      HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
      HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
      Prefs.js: 4 removed from network.proxy.type
      Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.666\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.666\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\Adobe Reader\ deleted successfully.
      C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll moved successfully.
      Registry key HKEY_LOCAL_MACHINE\\Software\Microsoft\Windows\CurrentVersion\Run not found.
      File not found.
      Starting removal of ActiveX control {1E54D648-B804-468d-BC78-4AFFED8E262F}
      Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1E54D648-B804-468d-BC78-4AFFED8E262F}\DownloadInformation\\INF .
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1E54D648-B804-468d-BC78-4AFFED8E262F}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1E54D648-B804-468d-BC78-4AFFED8E262F}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{1E54D648-B804-468d-BC78-4AFFED8E262F}\ not found.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1E54D648-B804-468d-BC78-4AFFED8E262F}\ not found.
      Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
      Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
      Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
      Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
      Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
      Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
      C:\WINDOWS\msdownld.tmp folder deleted successfully.
      C:\WINDOWS\system32\csnp2uvc(8).dll moved successfully.
      C:\WINDOWS\system32\csnp2uvc(7).dll moved successfully.
      C:\WINDOWS\system32\csnp2uvc(6).dll moved successfully.
      C:\WINDOWS\system32\csnp2uvc(5).dll moved successfully.
      C:\WINDOWS\system32\csnp2uvc(4).dll moved successfully.
      C:\WINDOWS\system32\csnp2uvc(3).dll moved successfully.
      C:\WINDOWS\system32\csnp2uvc(2).dll moved successfully.
      C:\WINDOWS\system32\csnp2uvc(14).dll moved successfully.
      C:\WINDOWS\system32\csnp2uvc(13).dll moved successfully.
      C:\WINDOWS\system32\csnp2uvc(12).dll moved successfully.
      C:\WINDOWS\system32\csnp2uvc(11).dll moved successfully.
      C:\WINDOWS\system32\csnp2uvc(10).dll moved successfully.
      ========== REGISTRY ==========
      HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32\\""|"%SystemRoot%\system32\shell32.dll" /E : value set successfully!
      ========== FILES ==========
      C:\Documents and Settings\----.5F9F0FD3037B446\Application Data\Mozilla\Firefox\Profiles\ajgua8tu.default\searchplugins\jerecherche.xml moved successfully.
      C:\WINDOWS\System32\csnp2uvc(9).dll moved successfully.
      ========== COMMANDS ==========
      Error creating restore point.

      [EMPTYTEMP]

      User: ----
      ->Temp folder emptied: 0 bytes
      ->Temporary Internet Files folder emptied: 134 bytes

      User: ----.5F9F0FD3037B446
      ->Temp folder emptied: 4276716 bytes
      ->Temporary Internet Files folder emptied: 95044 bytes
      ->Java cache emptied: 0 bytes
      ->FireFox cache emptied: 101223469 bytes
      ->Flash cache emptied: 506 bytes

      User: ----~1~5F9

      User: Administrateur
      ->Temp folder emptied: 0 bytes
      ->Temporary Internet Files folder emptied: 33170 bytes

      User: All Users

      User: All Users.WINDOWS

      User: Default User.WINDOWS
      ->Temp folder emptied: 0 bytes
      ->Temporary Internet Files folder emptied: 33170 bytes

      User: LocalService
      ->Temp folder emptied: 0 bytes
      ->Temporary Internet Files folder emptied: 134 bytes

      User: LocalService.AUTORITE NT
      ->Temp folder emptied: 66016 bytes
      ->Temporary Internet Files folder emptied: 49554 bytes
      ->Flash cache emptied: 405 bytes

      User: NetworkService
      ->Temp folder emptied: 0 bytes
      ->Temporary Internet Files folder emptied: 402 bytes

      User: NetworkService.AUTORITE NT
      ->Temp folder emptied: 0 bytes
      ->Temporary Internet Files folder emptied: 33170 bytes

      User: postgres
      ->Temp folder emptied: 0 bytes
      ->Temporary Internet Files folder emptied: 33170 bytes

      %systemdrive% .tmp files removed: 0 bytes
      %systemroot% .tmp files removed: 0 bytes
      %systemroot%\System32 .tmp files removed: 0 bytes
      %systemroot%\System32\dllcache .tmp files removed: 0 bytes
      %systemroot%\System32\drivers .tmp files removed: 0 bytes
      Windows Temp folder emptied: 16384 bytes
      %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 108627928 bytes
      %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
      RecycleBin emptied: 0 bytes

      Total Files Cleaned = 205,00 mb


      OTL by OldTimer - Version 3.2.69.0 log created on 01122013_194059

      Files\Folders moved on Reboot...
      File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

      PendingFileRenameOperations files...

      Registry entries deleted on Reboot...
      0
    2. laurentsibi Messages postés 10 Date d'inscription   Statut Membre Dernière intervention  
       
      ca a marché,je sais pas comment te remercier pour le temps passé.c est vraiment gentil
      0
    3. g3n-h@ckm@n
       
      ca se passe en dessous ^^
      0
  8. g3n-h@ckm@n
     
    bien un scan generaliste , le ménage , et on plie

    ====

    fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

    ▶ Télécharge ici :

    Malwarebytes

    ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

    relance malwarebytes en suivant scrupuleusement ces consignes :

    ! Déconnecte toi et ferme toutes applications en cours !

    ▶ Lance Malwarebyte's .

    Fais un examen dit "Complet" .

    ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
    ▶ à la fin tu cliques sur "résultat" .
    Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

    Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

    Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

    0
    1. laurentsibi Messages postés 10 Date d'inscription   Statut Membre Dernière intervention  
       
      Malwarebytes Anti-Malware 1.70.0.1100
      www.malwarebytes.org

      Version de la base de données: v2013.01.12.08

      Windows XP Service Pack 3 x86 NTFS (Mode sans échec)
      Internet Explorer 8.0.6001.18702
      ---- :: 5F9F0FD3037B446 [administrateur]

      13/01/2013 16:07:35
      mbam-log-2013-01-13 (16-07-35).txt

      Type d'examen: Examen complet (C:\|D:\|E:\|F:\|)
      Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
      Options d'examen désactivées: P2P
      Elément(s) analysé(s): 342550
      Temps écoulé: 46 minute(s), 30 seconde(s)

      Processus mémoire détecté(s): 0
      (Aucun élément nuisible détecté)

      Module(s) mémoire détecté(s): 0
      (Aucun élément nuisible détecté)

      Clé(s) du Registre détectée(s): 0
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre détectée(s): 0
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre détecté(s): 0
      (Aucun élément nuisible détecté)

      Dossier(s) détecté(s): 0
      (Aucun élément nuisible détecté)

      Fichier(s) détecté(s): 0
      (Aucun élément nuisible détecté)

      (fin)
      0