Encore go save
Résolu
rom00026
Messages postés
2
Statut
Membre
-
Malekal_morte- Messages postés 184347 Date d'inscription Statut Modérateur, Contributeur sécurité Dernière intervention -
Malekal_morte- Messages postés 184347 Date d'inscription Statut Modérateur, Contributeur sécurité Dernière intervention -
bonjour
j'ai également des soucis avec GOSAVE... j'ai suivi bcp de forum sur le sujet et j'ai aussi téléchargé bcp d'appli pour l'éliminer mais rien n'y fait... dès que je rouvre chrome gosave revient.
je l'ai supprimé des programmes window, des extensions chrome, réinitialisé chrome, lancé adwcleaner, SpyHunter, ZHPCleaner, Malwarebytes Anti-Malware.....
un coup de main svp....
j'ai également des soucis avec GOSAVE... j'ai suivi bcp de forum sur le sujet et j'ai aussi téléchargé bcp d'appli pour l'éliminer mais rien n'y fait... dès que je rouvre chrome gosave revient.
je l'ai supprimé des programmes window, des extensions chrome, réinitialisé chrome, lancé adwcleaner, SpyHunter, ZHPCleaner, Malwarebytes Anti-Malware.....
un coup de main svp....
A voir également:
- Encore go save
- Save as pdf office 2007 - Télécharger - Bureautique
- Tablette samsung a9+ 128 go avis - Accueil - Tablettes
- Save tube - Télécharger - Téléchargement & Transfert
- 8gb en go - Forum Carte-mère/mémoire
- 4gb en go ✓ - Forum Clé USB / Carte mémoire
9 réponses
Salut,
Sur quel navigateur WEB ?
Chrome ?
Désinstalle spyhunter.
Like the angel you are, you laugh creating a lightness in my chest,
Your eyes they penetrate me,
(Your answer's always 'maybe')
That's when I got up and left
Sur quel navigateur WEB ?
Chrome ?
Désinstalle spyhunter.
Like the angel you are, you laugh creating a lightness in my chest,
Your eyes they penetrate me,
(Your answer's always 'maybe')
That's when I got up and left
Fais ceci :
Exporte tes favoris : https://support.google.com/chrome/answer/96816?hl=fr
Désinstalle Google Chrome en cochant la case pour supprimer les profils.
Réinstalle Google Chrome : https://telecharger.malekal.com/download/google-chrome/
puis :
Suis ce tutorial : https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/
Cela va générer deux rapports FRST.
Envoie comme expliqué, ces deux rapports sur le site pjjoint et donne les deux liens pjjoint de ces rapports afin qu'ils puissent être consultés.
Exporte tes favoris : https://support.google.com/chrome/answer/96816?hl=fr
Désinstalle Google Chrome en cochant la case pour supprimer les profils.
Réinstalle Google Chrome : https://telecharger.malekal.com/download/google-chrome/
puis :
Suis ce tutorial : https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/
Cela va générer deux rapports FRST.
Envoie comme expliqué, ces deux rapports sur le site pjjoint et donne les deux liens pjjoint de ces rapports afin qu'ils puissent être consultés.
Voici les rapports
http://pjjoint.malekal.com/files.php?id=FRST_20141129_x13y6y5d5w14
et
http://pjjoint.malekal.com/files.php?id=20141129_6t15h5u11m8
Déja apres avoir desinstallé chrome mon PC a planté.... et quand je l'ai rallumé et réinstallé chrome gosave avait disparu des extensions....
http://pjjoint.malekal.com/files.php?id=FRST_20141129_x13y6y5d5w14
et
http://pjjoint.malekal.com/files.php?id=20141129_6t15h5u11m8
Déja apres avoir desinstallé chrome mon PC a planté.... et quand je l'ai rallumé et réinstallé chrome gosave avait disparu des extensions....
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Voici la correction à effectuer avec FRST.
Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix
Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
Copie/colle dedans ce qui suit :
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro 3.11\OptProLauncher.exe [148048 2014-11-20] (PC Utilities Software Limited)
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\...\RunOnce: [DigitalSites] => wscript /E:vbscript /B C:\Users\ROMAIN~1\AppData\Roaming\DigitalSites\UpdateProc\bkup.dat
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\...\RunOnce: [WSE_Vosteran] => wscript /E:vbscript /B C:\Users\ROMAIN~1\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat
SearchScopes: HKU\S-1-5-21-152911911-3783976331-3591253923-1001 -> DefaultScope {ABD646BB-502B-42AD-99AA-7B279276251B} URL = http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 50.16.204.38]
SearchScopes: HKU\S-1-5-21-152911911-3783976331-3591253923-1001 -> {9081B7F4-CAA5-490A-8E3C-1A645CB04015} URL =
SearchScopes: HKU\S-1-5-21-152911911-3783976331-3591253923-1001 -> {ABD646BB-502B-42AD-99AA-7B279276251B} URL = http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 50.16.204.38]
SearchScopes: HKU\S-1-5-21-152911911-3783976331-3591253923-1001 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = https://fr.search.yahoo.com/web?fr=mcafee{SearchTerms} [Pays - ]
BHO-x32: Hold Page 1.0.0.4 -> {6c14185e-4de6-4a79-985b-19f23fd1e638} -> C:\Program Files (x86)\Hold Page\HoldPagebho.dll (Hold Page)
CHR HomePage: Default -> hxxp://Vosteran.com/?f=1&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 54.235.99.6]
CHR StartupUrls: Default -> hxxp://Vosteran.com/?f=7&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 54.235.99.6]
CHR DefaultSearchKeyword: Default -> vosteran.com
CHR DefaultSearchURL: Default -> http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 54.235.99.6]
S2 51cdb72; c:\Program Files (x86)\Optimizer Pro 3.11\OptProCrash.dll [3105792 2014-11-29] () [File not signed]
R2 Update Hold Page; C:\Program Files (x86)\Hold Page\updateHoldPage.exe [525552 2014-11-29] ()
2014-11-29 15:39 - 2014-11-29 15:39 - 00002658 _____ () C:\WINDOWS\System32\Tasks\WSE_Vosteran
2014-11-29 15:39 - 2014-11-29 15:39 - 00002658 _____ () C:\WINDOWS\System32\Tasks\Digital Sites
2014-11-29 15:39 - 2014-11-29 15:39 - 00000320 _____ () C:\WINDOWS\Tasks\WSE_Vosteran.job
2014-11-29 15:39 - 2014-11-29 15:39 - 00000320 _____ () C:\WINDOWS\Tasks\Digital Sites.job
2014-11-29 15:39 - 2014-11-29 15:39 - 00000000 ____D () C:\Users\romain pc\AppData\Roaming\WSE_Vosteran
2014-11-29 15:39 - 2014-11-29 15:39 - 00000000 ____D () C:\Users\romain pc\AppData\Roaming\DigitalSites
2014-11-29 15:39 - 2014-11-29 15:39 - 00000000 ____D () C:\Program Files (x86)\WSE_Vosteran
2014-11-29 15:39 - 2014-11-29 15:39 - 00000000 ____D () C:\Program Files (x86)\Hold Page
2014-11-29 15:38 - 2014-11-29 15:38 - 00001122 _____ () C:\Users\romain pc\Desktop\Optimizer Pro.lnk
2014-11-29 15:38 - 2014-11-29 15:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2014-11-29 15:38 - 2014-11-29 15:38 - 00000000 ____D () C:\Program Files\PDFCreator
2014-11-29 15:38 - 2014-11-29 15:38 - 00000000 ____D () C:\Program Files (x86)\PDF Creator
2014-11-15 16:22 - 2014-11-15 16:22 - 00000000 ____D () C:\ProgramData\klhbfeahopdchgbgopbapolnbphalmkc
Une fois, le texte coller dans le bloc-note.
Menu Fichier puis Enregistrer sous.
A gauche, place toi sur le bureau.
Dans le champs en bas, nom du fichier mets : fixlist.txt
Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.
Relance FRST et clic sur le bouton Fix
Selon comment un redémarrage est nécessaire (pas obligatoire).
Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.
Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix
Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
Copie/colle dedans ce qui suit :
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro 3.11\OptProLauncher.exe [148048 2014-11-20] (PC Utilities Software Limited)
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\...\RunOnce: [DigitalSites] => wscript /E:vbscript /B C:\Users\ROMAIN~1\AppData\Roaming\DigitalSites\UpdateProc\bkup.dat
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\...\RunOnce: [WSE_Vosteran] => wscript /E:vbscript /B C:\Users\ROMAIN~1\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat
SearchScopes: HKU\S-1-5-21-152911911-3783976331-3591253923-1001 -> DefaultScope {ABD646BB-502B-42AD-99AA-7B279276251B} URL = http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 50.16.204.38]
SearchScopes: HKU\S-1-5-21-152911911-3783976331-3591253923-1001 -> {9081B7F4-CAA5-490A-8E3C-1A645CB04015} URL =
SearchScopes: HKU\S-1-5-21-152911911-3783976331-3591253923-1001 -> {ABD646BB-502B-42AD-99AA-7B279276251B} URL = http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 50.16.204.38]
SearchScopes: HKU\S-1-5-21-152911911-3783976331-3591253923-1001 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = https://fr.search.yahoo.com/web?fr=mcafee{SearchTerms} [Pays - ]
BHO-x32: Hold Page 1.0.0.4 -> {6c14185e-4de6-4a79-985b-19f23fd1e638} -> C:\Program Files (x86)\Hold Page\HoldPagebho.dll (Hold Page)
CHR HomePage: Default -> hxxp://Vosteran.com/?f=1&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 54.235.99.6]
CHR StartupUrls: Default -> hxxp://Vosteran.com/?f=7&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 54.235.99.6]
CHR DefaultSearchKeyword: Default -> vosteran.com
CHR DefaultSearchURL: Default -> http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 54.235.99.6]
S2 51cdb72; c:\Program Files (x86)\Optimizer Pro 3.11\OptProCrash.dll [3105792 2014-11-29] () [File not signed]
R2 Update Hold Page; C:\Program Files (x86)\Hold Page\updateHoldPage.exe [525552 2014-11-29] ()
2014-11-29 15:39 - 2014-11-29 15:39 - 00002658 _____ () C:\WINDOWS\System32\Tasks\WSE_Vosteran
2014-11-29 15:39 - 2014-11-29 15:39 - 00002658 _____ () C:\WINDOWS\System32\Tasks\Digital Sites
2014-11-29 15:39 - 2014-11-29 15:39 - 00000320 _____ () C:\WINDOWS\Tasks\WSE_Vosteran.job
2014-11-29 15:39 - 2014-11-29 15:39 - 00000320 _____ () C:\WINDOWS\Tasks\Digital Sites.job
2014-11-29 15:39 - 2014-11-29 15:39 - 00000000 ____D () C:\Users\romain pc\AppData\Roaming\WSE_Vosteran
2014-11-29 15:39 - 2014-11-29 15:39 - 00000000 ____D () C:\Users\romain pc\AppData\Roaming\DigitalSites
2014-11-29 15:39 - 2014-11-29 15:39 - 00000000 ____D () C:\Program Files (x86)\WSE_Vosteran
2014-11-29 15:39 - 2014-11-29 15:39 - 00000000 ____D () C:\Program Files (x86)\Hold Page
2014-11-29 15:38 - 2014-11-29 15:38 - 00001122 _____ () C:\Users\romain pc\Desktop\Optimizer Pro.lnk
2014-11-29 15:38 - 2014-11-29 15:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2014-11-29 15:38 - 2014-11-29 15:38 - 00000000 ____D () C:\Program Files\PDFCreator
2014-11-29 15:38 - 2014-11-29 15:38 - 00000000 ____D () C:\Program Files (x86)\PDF Creator
2014-11-15 16:22 - 2014-11-15 16:22 - 00000000 ____D () C:\ProgramData\klhbfeahopdchgbgopbapolnbphalmkc
Une fois, le texte coller dans le bloc-note.
Menu Fichier puis Enregistrer sous.
A gauche, place toi sur le bureau.
Dans le champs en bas, nom du fichier mets : fixlist.txt
Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.
Relance FRST et clic sur le bouton Fix
Selon comment un redémarrage est nécessaire (pas obligatoire).
Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.
ok voila le resultat
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 26-11-2014 01
Ran by romain pc at 2014-11-29 16:16:14 Run:2
Running from C:\Users\romain pc\Desktop
Loaded Profile: romain pc (Available profiles: romain pc & Administrateur)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro 3.11\OptProLauncher.exe [148048 2014-11-20] (PC Utilities Software Limited)
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\...\RunOnce: [DigitalSites] => wscript /E:vbscript /B C:\Users\ROMAIN~1\AppData\Roaming\DigitalSites\UpdateProc\bkup.dat
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\...\RunOnce: [WSE_Vosteran] => wscript /E:vbscript /B C:\Users\ROMAIN~1\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat
SearchScopes: HKU\S-1-5-21-152911911-3783976331-3591253923-1001 -> DefaultScope {ABD646BB-502B-42AD-99AA-7B279276251B} URL = http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 50.16.204.38]
SearchScopes: HKU\S-1-5-21-152911911-3783976331-3591253923-1001 -> {9081B7F4-CAA5-490A-8E3C-1A645CB04015} URL =
SearchScopes: HKU\S-1-5-21-152911911-3783976331-3591253923-1001 -> {ABD646BB-502B-42AD-99AA-7B279276251B} URL = http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 50.16.204.38]
SearchScopes: HKU\S-1-5-21-152911911-3783976331-3591253923-1001 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = https://fr.search.yahoo.com/search?fr=mcafee&type=B011FR501D20140810&p={SearchTerms} [Pays - ]
BHO-x32: Hold Page 1.0.0.4 -> {6c14185e-4de6-4a79-985b-19f23fd1e638} -> C:\Program Files (x86)\Hold Page\HoldPagebho.dll (Hold Page)
CHR HomePage: Default -> hxxp://Vosteran.com/?f=1&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 54.235.99.6]
CHR StartupUrls: Default -> hxxp://Vosteran.com/?f=7&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 54.235.99.6]
CHR DefaultSearchKeyword: Default -> vosteran.com
CHR DefaultSearchURL: Default -> http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 54.235.99.6]
S2 51cdb72; c:\Program Files (x86)\Optimizer Pro 3.11\OptProCrash.dll [3105792 2014-11-29] () [File not signed]
R2 Update Hold Page; C:\Program Files (x86)\Hold Page\updateHoldPage.exe [525552 2014-11-29] ()
2014-11-29 15:39 - 2014-11-29 15:39 - 00002658 _____ () C:\WINDOWS\System32\Tasks\WSE_Vosteran
2014-11-29 15:39 - 2014-11-29 15:39 - 00002658 _____ () C:\WINDOWS\System32\Tasks\Digital Sites
2014-11-29 15:39 - 2014-11-29 15:39 - 00000320 _____ () C:\WINDOWS\Tasks\WSE_Vosteran.job
2014-11-29 15:39 - 2014-11-29 15:39 - 00000320 _____ () C:\WINDOWS\Tasks\Digital Sites.job
2014-11-29 15:39 - 2014-11-29 15:39 - 00000000 ____D () C:\Users\romain pc\AppData\Roaming\WSE_Vosteran
2014-11-29 15:39 - 2014-11-29 15:39 - 00000000 ____D () C:\Users\romain pc\AppData\Roaming\DigitalSites
2014-11-29 15:39 - 2014-11-29 15:39 - 00000000 ____D () C:\Program Files (x86)\WSE_Vosteran
2014-11-29 15:39 - 2014-11-29 15:39 - 00000000 ____D () C:\Program Files (x86)\Hold Page
2014-11-29 15:38 - 2014-11-29 15:38 - 00001122 _____ () C:\Users\romain pc\Desktop\Optimizer Pro.lnk
2014-11-29 15:38 - 2014-11-29 15:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2014-11-29 15:38 - 2014-11-29 15:38 - 00000000 ____D () C:\Program Files\PDFCreator
2014-11-29 15:38 - 2014-11-29 15:38 - 00000000 ____D () C:\Program Files (x86)\PDF Creator
2014-11-15 16:22 - 2014-11-15 16:22 - 00000000 ____D () C:\ProgramData\klhbfeahopdchgbgopbapolnbphalmkc
*****************
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Optimizer Pro => Value not found.
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\DigitalSites => Value not found.
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\WSE_Vosteran => Value not found.
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value not found.
"HKU\S-1-5-21-152911911-3783976331-3591253923-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9081B7F4-CAA5-490A-8E3C-1A645CB04015}" => Key not found.
"HKCR\CLSID\{9081B7F4-CAA5-490A-8E3C-1A645CB04015}" => Key not found.
"HKU\S-1-5-21-152911911-3783976331-3591253923-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ABD646BB-502B-42AD-99AA-7B279276251B}" => Key not found.
"HKCR\CLSID\{ABD646BB-502B-42AD-99AA-7B279276251B}" => Key not found.
"HKU\S-1-5-21-152911911-3783976331-3591253923-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}" => Key not found.
"HKCR\CLSID\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6c14185e-4de6-4a79-985b-19f23fd1e638}" => Key not found.
"HKCR\Wow6432Node\CLSID\{6c14185e-4de6-4a79-985b-19f23fd1e638}" => Key not found.
Chrome HomePage deleted successfully.
Chrome StartupUrls deleted successfully.
Chrome DefaultSearchKeyword deleted successfully.
Chrome DefaultSearchURL deleted successfully.
51cdb72 => Service not found.
Update Hold Page => Service not found.
"C:\WINDOWS\System32\Tasks\WSE_Vosteran" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\Digital Sites" => File/Directory not found.
"C:\WINDOWS\Tasks\WSE_Vosteran.job" => File/Directory not found.
"C:\WINDOWS\Tasks\Digital Sites.job" => File/Directory not found.
"C:\Users\romain pc\AppData\Roaming\WSE_Vosteran" => File/Directory not found.
"C:\Users\romain pc\AppData\Roaming\DigitalSites" => File/Directory not found.
"C:\Program Files (x86)\WSE_Vosteran" => File/Directory not found.
"C:\Program Files (x86)\Hold Page" => File/Directory not found.
"C:\Users\romain pc\Desktop\Optimizer Pro.lnk" => File/Directory not found.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2" => File/Directory not found.
"C:\Program Files\PDFCreator" => File/Directory not found.
"C:\Program Files (x86)\PDF Creator" => File/Directory not found.
"C:\ProgramData\klhbfeahopdchgbgopbapolnbphalmkc" => File/Directory not found.
==== End of Fixlog ====
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 26-11-2014 01
Ran by romain pc at 2014-11-29 16:16:14 Run:2
Running from C:\Users\romain pc\Desktop
Loaded Profile: romain pc (Available profiles: romain pc & Administrateur)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro 3.11\OptProLauncher.exe [148048 2014-11-20] (PC Utilities Software Limited)
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\...\RunOnce: [DigitalSites] => wscript /E:vbscript /B C:\Users\ROMAIN~1\AppData\Roaming\DigitalSites\UpdateProc\bkup.dat
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\...\RunOnce: [WSE_Vosteran] => wscript /E:vbscript /B C:\Users\ROMAIN~1\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat
SearchScopes: HKU\S-1-5-21-152911911-3783976331-3591253923-1001 -> DefaultScope {ABD646BB-502B-42AD-99AA-7B279276251B} URL = http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 50.16.204.38]
SearchScopes: HKU\S-1-5-21-152911911-3783976331-3591253923-1001 -> {9081B7F4-CAA5-490A-8E3C-1A645CB04015} URL =
SearchScopes: HKU\S-1-5-21-152911911-3783976331-3591253923-1001 -> {ABD646BB-502B-42AD-99AA-7B279276251B} URL = http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 50.16.204.38]
SearchScopes: HKU\S-1-5-21-152911911-3783976331-3591253923-1001 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = https://fr.search.yahoo.com/search?fr=mcafee&type=B011FR501D20140810&p={SearchTerms} [Pays - ]
BHO-x32: Hold Page 1.0.0.4 -> {6c14185e-4de6-4a79-985b-19f23fd1e638} -> C:\Program Files (x86)\Hold Page\HoldPagebho.dll (Hold Page)
CHR HomePage: Default -> hxxp://Vosteran.com/?f=1&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 54.235.99.6]
CHR StartupUrls: Default -> hxxp://Vosteran.com/?f=7&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 54.235.99.6]
CHR DefaultSearchKeyword: Default -> vosteran.com
CHR DefaultSearchURL: Default -> http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_14_48_ch&cd=2XzuyEtN2Y1L1QzuyBtDyDyE0DtB0CtDzz0FtD0DyD0CzztCtN0D0Tzu0StCtDyCtAtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyDyEtD0AzyyBtA0DtGzzzzyEtCtG0CzzyEzztGyEyByEzztGyDyD0Ezy0C0A0A0B0D0E0EtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0ByDtC0DtDtCzytGtB0F0C0AtGyEtC0EzztGzytD0AtCtG0EtDyDyB0CyBzztD0CtB0C0A2Q&cr=1528585221&ir= [Pays US - 54.235.99.6]
S2 51cdb72; c:\Program Files (x86)\Optimizer Pro 3.11\OptProCrash.dll [3105792 2014-11-29] () [File not signed]
R2 Update Hold Page; C:\Program Files (x86)\Hold Page\updateHoldPage.exe [525552 2014-11-29] ()
2014-11-29 15:39 - 2014-11-29 15:39 - 00002658 _____ () C:\WINDOWS\System32\Tasks\WSE_Vosteran
2014-11-29 15:39 - 2014-11-29 15:39 - 00002658 _____ () C:\WINDOWS\System32\Tasks\Digital Sites
2014-11-29 15:39 - 2014-11-29 15:39 - 00000320 _____ () C:\WINDOWS\Tasks\WSE_Vosteran.job
2014-11-29 15:39 - 2014-11-29 15:39 - 00000320 _____ () C:\WINDOWS\Tasks\Digital Sites.job
2014-11-29 15:39 - 2014-11-29 15:39 - 00000000 ____D () C:\Users\romain pc\AppData\Roaming\WSE_Vosteran
2014-11-29 15:39 - 2014-11-29 15:39 - 00000000 ____D () C:\Users\romain pc\AppData\Roaming\DigitalSites
2014-11-29 15:39 - 2014-11-29 15:39 - 00000000 ____D () C:\Program Files (x86)\WSE_Vosteran
2014-11-29 15:39 - 2014-11-29 15:39 - 00000000 ____D () C:\Program Files (x86)\Hold Page
2014-11-29 15:38 - 2014-11-29 15:38 - 00001122 _____ () C:\Users\romain pc\Desktop\Optimizer Pro.lnk
2014-11-29 15:38 - 2014-11-29 15:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2014-11-29 15:38 - 2014-11-29 15:38 - 00000000 ____D () C:\Program Files\PDFCreator
2014-11-29 15:38 - 2014-11-29 15:38 - 00000000 ____D () C:\Program Files (x86)\PDF Creator
2014-11-15 16:22 - 2014-11-15 16:22 - 00000000 ____D () C:\ProgramData\klhbfeahopdchgbgopbapolnbphalmkc
*****************
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Optimizer Pro => Value not found.
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\DigitalSites => Value not found.
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\WSE_Vosteran => Value not found.
HKU\S-1-5-21-152911911-3783976331-3591253923-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value not found.
"HKU\S-1-5-21-152911911-3783976331-3591253923-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9081B7F4-CAA5-490A-8E3C-1A645CB04015}" => Key not found.
"HKCR\CLSID\{9081B7F4-CAA5-490A-8E3C-1A645CB04015}" => Key not found.
"HKU\S-1-5-21-152911911-3783976331-3591253923-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ABD646BB-502B-42AD-99AA-7B279276251B}" => Key not found.
"HKCR\CLSID\{ABD646BB-502B-42AD-99AA-7B279276251B}" => Key not found.
"HKU\S-1-5-21-152911911-3783976331-3591253923-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}" => Key not found.
"HKCR\CLSID\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6c14185e-4de6-4a79-985b-19f23fd1e638}" => Key not found.
"HKCR\Wow6432Node\CLSID\{6c14185e-4de6-4a79-985b-19f23fd1e638}" => Key not found.
Chrome HomePage deleted successfully.
Chrome StartupUrls deleted successfully.
Chrome DefaultSearchKeyword deleted successfully.
Chrome DefaultSearchURL deleted successfully.
51cdb72 => Service not found.
Update Hold Page => Service not found.
"C:\WINDOWS\System32\Tasks\WSE_Vosteran" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\Digital Sites" => File/Directory not found.
"C:\WINDOWS\Tasks\WSE_Vosteran.job" => File/Directory not found.
"C:\WINDOWS\Tasks\Digital Sites.job" => File/Directory not found.
"C:\Users\romain pc\AppData\Roaming\WSE_Vosteran" => File/Directory not found.
"C:\Users\romain pc\AppData\Roaming\DigitalSites" => File/Directory not found.
"C:\Program Files (x86)\WSE_Vosteran" => File/Directory not found.
"C:\Program Files (x86)\Hold Page" => File/Directory not found.
"C:\Users\romain pc\Desktop\Optimizer Pro.lnk" => File/Directory not found.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2" => File/Directory not found.
"C:\Program Files\PDFCreator" => File/Directory not found.
"C:\Program Files (x86)\PDF Creator" => File/Directory not found.
"C:\ProgramData\klhbfeahopdchgbgopbapolnbphalmkc" => File/Directory not found.
==== End of Fixlog ====
:)
Quelques conseils :
Installe Malwarebyte's Anti-Malware : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
Fais des scans réguliers avec, il est efficace.
Pour prévenir les sites malicieux, tu peux installer Blockulicious : https://forum.malekal.com/viewtopic.php?t=46656&start=
Pour ne plus te faire avoir.
A lire - Programmes parasites / PUPs : https://www.malekal.com/adwares-pup-protection/
Quelques conseils :
Installe Malwarebyte's Anti-Malware : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
Fais des scans réguliers avec, il est efficace.
Pour prévenir les sites malicieux, tu peux installer Blockulicious : https://forum.malekal.com/viewtopic.php?t=46656&start=
Pour ne plus te faire avoir.
A lire - Programmes parasites / PUPs : https://www.malekal.com/adwares-pup-protection/