Problème avec Tv wizard

Résolu
Bonjour,
J'ai un problème avec mon pc : des pages de publicité apparaissent inopinément et je constate également qu'il est plus lent. Quelqu'un peut-il m'aider ?
Merci d'avance.

13 réponses

  1. # AdwCleaner v4.106 - Rapport créé le 23/12/2014 à 17:24:00
    # Mis à jour le 21/12/2014 par Xplode
    # Database : 2014-12-21.4 [Live]
    # Système d'exploitation : Windows 8.1 (64 bits)
    # Nom d'utilisateur : Mylène - MYLENE
    # Exécuté depuis : C:\Users\Mylène\Downloads\adwcleaner_4.106.exe
    # Option : Nettoyer

    ***** [ Services ] *****

    [#] Service Supprimé : BackupStack
    Service Supprimé : servervo

    ***** [ Fichiers / Dossiers ] *****

    Dossier Supprimé : C:\TVWizard
    Dossier Supprimé : C:\ProgramData\Browser
    Dossier Supprimé : C:\ProgramData\TVWizard
    Dossier Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
    Dossier Supprimé : C:\Program Files (x86)\MyPC Backup
    Dossier Supprimé : C:\Program Files (x86)\CloudGuard
    Dossier Supprimé : C:\Program Files (x86)\gmsd_fr_20
    Dossier Supprimé : C:\Users\MYLNE~1\AppData\Local\Temp\CloudGuard
    Dossier Supprimé : C:\Users\Mylène\AppData\Local\TVWizard
    Dossier Supprimé : C:\Users\Mylène\AppData\Local\wincheck
    Dossier Supprimé : C:\Users\Mylène\AppData\Local\gmsd_fr_20
    Dossier Supprimé : C:\Users\Mylène\AppData\Roaming\VOPackage
    Dossier Supprimé : C:\Users\Mylène\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
    Dossier Supprimé : C:\Users\Mylène\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
    Dossier Supprimé : C:\Users\Mylène\AppData\Roaming\Mozilla\Firefox\Profiles\qia1ek2f.default\Extensions\ascsurfingprotection@iobit.com
    Fichier Supprimé : C:\Users\Mylène\Desktop\Continue Live Installation.lnk
    Fichier Supprimé : C:\Users\Mylène\Desktop\Sync Folder.lnk
    Fichier Supprimé : C:\Users\Mylène\AppData\Roaming\Mozilla\Firefox\Profiles\qia1ek2f.default\user.js

    ***** [ Tâches planifiées ] *****

    Tâche Supprimée : LaunchApp
    Tâche Supprimée : CloudScout

    ***** [ Raccourcis ] *****

    ***** [ Registre ] *****

    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
    Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [gmsd_fr_20]
    Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
    Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}
    Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
    Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
    Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
    Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
    Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}
    Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Clé Supprimée : HKCU\Software\InstalledBrowserExtensions
    Clé Supprimée : HKCU\Software\Tutorials
    Clé Supprimée : HKCU\Software\TutoTag
    Clé Supprimée : HKCU\Software\Wnkey
    Clé Supprimée : HKCU\Software\AppDataLow\Software\DynConIE
    Clé Supprimée : HKLM\SOFTWARE\InstalledBrowserExtensions
    Clé Supprimée : HKLM\SOFTWARE\Tutorials
    Clé Supprimée : HKLM\SOFTWARE\CloudGuard
    Clé Supprimée : HKLM\SOFTWARE\GAMESDESKTOP
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TVWizard
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CloudGuard
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wincheck
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gmsd_fr_20_is1
    Clé Supprimée : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
    Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup

    ***** [ Navigateurs ] *****

    -\\ Internet Explorer v11.0.9600.17416

    -\\ Mozilla Firefox v34.0.5 (x86 fr)

    *************************

    AdwCleaner[R0].txt - [4928 octets] - [23/12/2014 17:23:16]
    AdwCleaner[S0].txt - [4688 octets] - [23/12/2014 17:24:00]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4748 octets] ##########
    0
    1. Je n'arrive pas à télécharger FRST
      0
      1. Modérateur
        Quel est le problème ?
        0
      2. Je télécharge FRST64 et lorsque le chargement est terminé, il est écrit "échec".
        0
      3. Modérateur
        hummm, et si tu désactives ton antivirus ?
        Tu as essayé avec tous les navigateurs WEB ?

        Tu as un autre PC à la maison pour le passer par clef USB ?
        0
    2. J'ai réussi avec Google Chrome. Voici les liens :
      http://pjjoint.malekal.com/files.php?id=20141223_l10q5h12i15f12
      http://pjjoint.malekal.com/files.php?id=20141223_x10e12m5o5o8
      http://pjjoint.malekal.com/files.php?id=20141223_j15v15n8q11n12
      0
      1. Modérateur
        Deux choses à faire, correction FRST et suppression des PUM.DNS

        Voici la correction à effectuer avec FRST.
        Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix

        Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
        Copie/colle dedans ce qui suit :

        HKLM-x32\...\Run: [WinCheck] => C:\Users\Mylène\AppData\Local\wincheck\wincheck.exe
        R2 pjlSgYlLT; C:\ProgramData\aUaKhKob\pjlSgYlLT.exe [2726256 2014-12-18] (Small Island Development)
        2014-12-23 17:30 - 2014-12-23 17:30 - 00000000 ____D () C:\Users\Mylène\AppData\Local\TVWizard
        2014-12-18 20:03 - 2014-12-18 20:03 - 00000000 ____D () C:\ProgramData\aUaKhKob

        Une fois, le texte coller dans le bloc-note.
        Menu Fichier puis Enregistrer sous.
        A gauche, place toi sur le bureau.
        Dans le champs en bas, nom du fichier mets : fixlist.txt
        Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.

        Relance FRST et clic sur le bouton Fix
        Selon comment un redémarrage est nécessaire (pas obligatoire).
        Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.

        Redémarre l'ordinateur

        puis ensuite :

        Supprime les PUM.DNS avec RogueKiller : https://forum.malekal.com/viewtopic.php?t=48312&start=
        Donne le rapport de suppression RogueKiller ici.

        Like the angel you are, you laugh creating a lightness in my chest,
        Your eyes they penetrate me,
        (Your answer's always 'maybe')
        That's when I got up and left
        0
        1. Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 23-12-2014
          Ran by Mylène at 2014-12-24 00:11:13 Run:1
          Running from C:\Users\Mylène\Downloads
          Loaded Profile: Mylène (Available profiles: Mylène)
          Boot Mode: Normal
          ==============================================

          Content of fixlist:
          *****************
          HKLM-x32\...\Run: [WinCheck] => C:\Users\Mylène\AppData\Local\wincheck\wincheck.exe

          R2 pjlSgYlLT; C:\ProgramData\aUaKhKob\pjlSgYlLT.exe [2726256 2014-12-18] (Small Island Development)

          2014-12-23 17:30 - 2014-12-23 17:30 - 00000000 ____D () C:\Users\Mylène\AppData\Local\TVWizard

          2014-12-18 20:03 - 2014-12-18 20:03 - 00000000 ____D () C:\ProgramData\aUaKhKob
          *****************

          HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\WinCheck => value deleted successfully.
          pjlSgYlLT => Unable to stop service
          pjlSgYlLT => Service deleted successfully.
          C:\Users\Mylène\AppData\Local\TVWizard => Moved successfully.

          "C:\ProgramData\aUaKhKob" directory move:

          Could not move "C:\ProgramData\aUaKhKob\info.dat" => Scheduled to move on reboot.
          Could not move "C:\ProgramData\aUaKhKob\pjlSgYlLT.dat" => Scheduled to move on reboot.
          C:\ProgramData\aUaKhKob\pjlSgYlLT.exe => Moved successfully.
          C:\ProgramData\aUaKhKob\pjlSgYlLT.exe.config => Moved successfully.
          Could not move "C:\ProgramData\aUaKhKob\dat\lEBjRinPzBN.exe" => Scheduled to move on reboot.
          Could not move "C:\ProgramData\aUaKhKob\dat\lEBjRinPzBN.exe.config" => Scheduled to move on reboot.
          Could not move "C:\ProgramData\aUaKhKob\dat\MNUwmxEBw.dll" => Scheduled to move on reboot.
          Could not move "C:\ProgramData\aUaKhKob\dat\puzTApzOaOV.dll" => Scheduled to move on reboot.
          Could not move "C:\ProgramData\aUaKhKob\dat\wIWkXKFVpg.exe" => Scheduled to move on reboot.
          Could not move "C:\ProgramData\aUaKhKob\dat\wIWkXKFVpg.exe.config" => Scheduled to move on reboot.
          Could not move "C:\ProgramData\aUaKhKob" directory. => Scheduled to move on reboot.

          => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-12-24 00:13:13)<=

          C:\ProgramData\aUaKhKob\info.dat => Is moved successfully.
          C:\ProgramData\aUaKhKob\pjlSgYlLT.dat => Is moved successfully.
          C:\ProgramData\aUaKhKob\dat\lEBjRinPzBN.exe => Is moved successfully.
          C:\ProgramData\aUaKhKob\dat\lEBjRinPzBN.exe.config => Is moved successfully.
          C:\ProgramData\aUaKhKob\dat\MNUwmxEBw.dll => Is moved successfully.
          C:\ProgramData\aUaKhKob\dat\puzTApzOaOV.dll => Is moved successfully.
          C:\ProgramData\aUaKhKob\dat\wIWkXKFVpg.exe => Is moved successfully.
          C:\ProgramData\aUaKhKob\dat\wIWkXKFVpg.exe.config => Is moved successfully.
          C:\ProgramData\aUaKhKob => Is moved successfully.

          ==== End of Fixlog 00:13:13 ====
          0
          1. RogueKiller V10.1.1.0 [Dec 23 2014] par Adlice Software
            email : https://www.adlice.com/contact/
            Remontées : https://forum.adlice.com/
            Site web : https://www.adlice.com/fr/roguekiller/
            Blog : https://www.adlice.com/

            Système d'exploitation : Windows 8.1 (6.3.9200 ) 64 bits version
            Démarré en : Mode normal
            Utilisateur : Mylène [Administrateur]
            Mode : Suppression -- Date : 12/24/2014 00:42:16

            ¤¤¤ Processus : 0 ¤¤¤

            ¤¤¤ Registre : 4 ¤¤¤
            [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 0 -> Remplacé(e) (0)
            [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 0 -> Remplacé(e) (0)
            [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 0 -> Remplacé(e) (0)
            [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 0 -> Remplacé(e) (0)

            ¤¤¤ Tâches : 0 ¤¤¤

            ¤¤¤ Fichiers : 0 ¤¤¤

            ¤¤¤ Fichier Hosts : 0 ¤¤¤

            ¤¤¤ Antirootkit : 0 (Driver: Non chargé [0xc000036b]) ¤¤¤

            ¤¤¤ Navigateurs web : 0 ¤¤¤

            ¤¤¤ Vérification MBR : ¤¤¤
            +++++ PhysicalDrive0: TOSHIBA MQ01ABD075 +++++
            --- User ---
            [MBR] a84dd93b5b19931ceaddbccc47850486
            [BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
            Partition table:
            0 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 1 | Size: 2097151 MB
            User = LL1 ... OK
            User = LL2 ... OK

            ============================================
            RKreport_SCN_12242014_004124.log - RKreport_DEL_12242014_004213.log
            0
            1. Modérateur
              Tu ne sembles pas avoir coché les lignes PUM.DNS
              0
          2. RogueKiller V10.1.1.0 [Dec 23 2014] par Adlice Software
            email : https://www.adlice.com/contact/
            Remontées : https://forum.adlice.com/
            Site web : https://www.adlice.com/fr/roguekiller/
            Blog : https://www.adlice.com/

            Système d'exploitation : Windows 8.1 (6.3.9200 ) 64 bits version
            Démarré en : Mode normal
            Utilisateur : Mylène [Administrateur]
            Mode : Scan -- Date : 12/24/2014 14:28:37

            ¤¤¤ Processus : 0 ¤¤¤

            ¤¤¤ Registre : 0 ¤¤¤

            ¤¤¤ Tâches : 0 ¤¤¤

            ¤¤¤ Fichiers : 0 ¤¤¤

            ¤¤¤ Fichier Hosts : 0 ¤¤¤

            ¤¤¤ Antirootkit : 0 (Driver: Non chargé [0x20]) ¤¤¤

            ¤¤¤ Navigateurs web : 0 ¤¤¤

            ¤¤¤ Vérification MBR : ¤¤¤
            +++++ PhysicalDrive0: TOSHIBA MQ01ABD075 +++++
            --- User ---
            [MBR] a84dd93b5b19931ceaddbccc47850486
            [BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
            Partition table:
            0 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 1 | Size: 2097151 MB
            User = LL1 ... OK
            User = LL2 ... OK

            ============================================
            RKreport_DEL_12242014_004213.log - RKreport_DEL_12242014_004216.log - RKreport_SCN_12242014_004124.log
            0
            1. Je n'ai plus de publicités intempestives
              0
              1. Modérateur
                ok bonne nouvelle,
                juste pour vérifier, peux-tu refaire l'analyse FRST.
                0