Winservice86 :(

Fermé
SMA67 Messages postés 2 Date d'inscription vendredi 23 janvier 2015 Statut Membre Dernière intervention 23 janvier 2015 - 23 janv. 2015 à 13:20
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 - 23 janv. 2015 à 15:44
Bonjour,

Bonjour Malekal_morte et Elodie !!!
Cela fait maintenant quelque temps que j'ai le même problème que Élodie !
J'ai besoin d'un peu d'aide svp!!
Merci d'avance

5 réponses

Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 656
23 janv. 2015 à 13:23
Salut,

Tu as installé des adwares et programmes parasites sur ton PC qui ouvrent des publicités et ralentissent l'ordinateur et les navigateurs WEB.
Voici la procédure à suivre pour les supprimer :

Commence par ceci :

Suis le tutorial AdwCleaner https://www.malekal.com/adwcleaner-supprimer-virus-adwares-pup/?t=33839&start= ( d'Xplode )
Télécharge le sur ton bureau ou dossier de téléchargement.
Lance AdwCleaner, clique sur [Scanner].
L'analyse peux durer plusieurs minutes, patiente.
Une fois le scan terminé, ne décoche rien, clique sur [Nettoyer]

Une fois le nettoyage terminé, un rapport s'ouvrira. Copie/colle le contenu du rapport dans ta prochaine réponse par un copier/coller.
Si cela ne fonctionne pas, utilise le site http://pjjoint.malekal.com pour héberger le rapport, donne le lien du rapport dans un nouveau message.

Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt


puis :

Suis ce tutoriel FRST: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/
Cela va générer trois rapports FRST :
* FRST.txt
* Shortcut.txt
* Additionnal.txt

Envoie comme expliqué, ces trois rapports sur le site pjjoint et donne les trois liens pjjoint de ces rapports afin qu'ils puissent être consultés.


0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 656
23 janv. 2015 à 14:09
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 656
23 janv. 2015 à 14:26
Désinstalle McAfee Security Scan et AdvancedSystemCareService



Voici la correction à effectuer avec FRST.
Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix

Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
Copie/colle dedans ce qui suit :


Startup: C:\Users\Samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
FF Homepage: hxxp://isearch.omiga-plus.com/?type=hp&ts=1422017141&from=ill&uid=HGSTXHTS541075A9E680_JA120911GUGSKKGUGSKKX [Pays US - 50.22.218.160]
FF Extension: Fast Start - C:\Users\Samuel\AppData\Roaming\Mozilla\Firefox\Profiles\wqekj2ck.default\Extensions\faststartff@gmail.com [2015-01-23]
FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Samuel\AppData\Roaming\Mozilla\Firefox\Profiles\wqekj2ck.default\extensions\faststartff@gmail.com
CHR HKLM-x32\...\Chrome\Extension: [gfkbfjcbkhnmiignagpkiijohkcdkffb] - No Path
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [53832 2014-11-25] (Just Develop It) <==== ATTENTION
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158896 2015-01-16] (XTab system)
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [464384 2015-01-23] (SysTool PasSame LIMITED) [File not signed]
2015-01-23 13:48 - 2015-01-23 13:48 - 00001988 _____ () C:\Users\Samuel\Desktop\Sync Folder.lnk
2015-01-23 13:48 - 2015-01-23 13:48 - 00001088 _____ () C:\Users\Samuel\Desktop\MyPC Backup.lnk
2015-01-23 13:48 - 2015-01-23 13:48 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2015-01-23 13:48 - 2015-01-23 13:48 - 00000000 ____D () C:\ProgramData\IHProtectUpDate
2015-01-23 13:48 - 2015-01-23 13:48 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup
2015-01-23 13:47 - 2015-01-23 13:48 - 00000000 ____D () C:\Program Files (x86)\XTab
2015-01-23 13:47 - 2015-01-23 13:47 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2015-01-23 13:46 - 2015-01-23 13:46 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\omiga-plus
2015-01-23 13:45 - 2015-01-23 13:45 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\VOPackage
2015-01-23 13:45 - 2015-01-23 13:45 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2015-01-11 00:09 - 2015-01-11 00:09 - 00003282 _____ () C:\Windows\System32\Tasks\mIVoG9aYzLyDIqJ
2015-01-11 00:08 - 2015-01-11 00:09 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\HJsC0sH
2015-01-11 00:08 - 2015-01-11 00:08 - 00003242 _____ () C:\Windows\System32\Tasks\J2Bxl4gSVTCPZMS
2015-01-11 00:08 - 2015-01-11 00:08 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\HMyRgd6
2015-01-10 22:52 - 2015-01-10 22:52 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\WildTangent
2015-01-10 22:01 - 2015-01-10 22:01 - 00000000 ____D () C:\Program Files (x86)\9b1ce805-2b51-4e2c-a877-e34adbeb3be9
2015-01-01 15:52 - 2015-01-01 15:52 - 00000000 ____D () C:\Program Files (x86)\c07c4c5f-ee62-447e-af56-fd9f5dbe8bb4
2014-12-31 15:51 - 2014-12-31 15:51 - 00000000 ____D () C:\Program Files (x86)\b2a4ef93-b11a-43d9-994c-05e45b65811c
2014-12-30 19:22 - 2014-12-30 19:22 - 00000000 ____D () C:\Program Files (x86)\7da8253d-b64b-4812-9e73-5673b4bd7446
2015-01-11 00:09 - 2014-12-12 20:52 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\lu69lOr
2015-01-11 00:09 - 2014-11-12 22:18 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\l5aivml
2015-01-01 15:52 - 2014-11-28 20:23 - 00000000 ____D () C:\Program Files (x86)\a598f85f-19f7-431c-b378-85746fb316f7
Task: {02CAA442-5DFD-449A-890A-6ECF0E3F6633} - System32\Tasks\{D4CB7CE1-DD28-40C7-86C8-71B05A22F5F5} => pcalua.exe -a C:\Users\Samuel\AppData\Roaming\webssearches\UninstallManager.exe -c -ptid=nsbfr <==== ATTENTION
Task: {4534B536-DB21-4766-8F24-85FC13192453} - System32\Tasks\mIVoG9aYzLyDIqJ => C:\Users\Samuel\AppData\Roaming\HJsC0sH\mCCimpP.exe [2015-01-11] ( )
Task: {6C625016-67D0-4788-A303-41B54C64B520} - System32\Tasks\J2Bxl4gSVTCPZMS => C:\Users\Samuel\AppData\Roaming\HMyRgd6\hslm70m.exe [2015-01-11] ( )
Task: {6F6D7A7E-C385-4214-8425-7573712B7999} - System32\Tasks\{29030E9F-71B9-4E87-88EB-964F8DA6391C} => pcalua.exe -a "C:\Users\Samuel\AppData\Roaming\Nosibay\Bubble Dock\Uninstall Bubble Dock.exe"
Task: {C0D54BA6-E21D-4CB9-A332-E30DF34E1942} - System32\Tasks\rj2mbojdsPTGktW => C:\Users\Samuel\AppData\Roaming\l5aivml\C6Rkfli.exe [2014-11-12] ( )


Une fois, le texte coller dans le bloc-note.
Menu Fichier puis Enregistrer sous.
A gauche, place toi sur le bureau.
Dans le champs en bas, nom du fichier mets : fixlist.txt
Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.

Relance FRST et clic sur le bouton Fix
Selon comment un redémarrage est nécessaire (pas obligatoire).
Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.

Redémarre l'ordinateur



0
SMA67 Messages postés 2 Date d'inscription vendredi 23 janvier 2015 Statut Membre Dernière intervention 23 janvier 2015
23 janv. 2015 à 14:48
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-01-2015
Ran by Samuel at 2015-01-23 14:38:01 Run:1
Running from C:\Users\Samuel\Desktop
Loaded Profiles: Samuel (Available profiles: Samuel)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************



Startup: C:\Users\Samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk

ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)

FF Homepage: hxxp://isearch.omiga-plus.com/?type=hp&ts=1422017141&from=ill&uid=HGSTXHTS541075A9E680_JA120911GUGSKKGUGSKKX [Pays US - 50.22.218.160]

FF Extension: Fast Start - C:\Users\Samuel\AppData\Roaming\Mozilla\Firefox\Profiles\wqekj2ck.default\Extensions\faststartff@gmail.com [2015-01-23]

FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Samuel\AppData\Roaming\Mozilla\Firefox\Profiles\wqekj2ck.default\extensions\faststartff@gmail.com

CHR HKLM-x32\...\Chrome\Extension: [gfkbfjcbkhnmiignagpkiijohkcdkffb] - No Path

S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [53832 2014-11-25] (Just Develop It) <==== ATTENTION

R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158896 2015-01-16] (XTab system)

R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [464384 2015-01-23] (SysTool PasSame LIMITED) [File not signed]

2015-01-23 13:48 - 2015-01-23 13:48 - 00001988 _____ () C:\Users\Samuel\Desktop\Sync Folder.lnk

2015-01-23 13:48 - 2015-01-23 13:48 - 00001088 _____ () C:\Users\Samuel\Desktop\MyPC Backup.lnk

2015-01-23 13:48 - 2015-01-23 13:48 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup

2015-01-23 13:48 - 2015-01-23 13:48 - 00000000 ____D () C:\ProgramData\IHProtectUpDate

2015-01-23 13:48 - 2015-01-23 13:48 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup

2015-01-23 13:47 - 2015-01-23 13:48 - 00000000 ____D () C:\Program Files (x86)\XTab

2015-01-23 13:47 - 2015-01-23 13:47 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect

2015-01-23 13:46 - 2015-01-23 13:46 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\omiga-plus

2015-01-23 13:45 - 2015-01-23 13:45 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\VOPackage

2015-01-23 13:45 - 2015-01-23 13:45 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage

2015-01-11 00:09 - 2015-01-11 00:09 - 00003282 _____ () C:\Windows\System32\Tasks\mIVoG9aYzLyDIqJ

2015-01-11 00:08 - 2015-01-11 00:09 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\HJsC0sH

2015-01-11 00:08 - 2015-01-11 00:08 - 00003242 _____ () C:\Windows\System32\Tasks\J2Bxl4gSVTCPZMS

2015-01-11 00:08 - 2015-01-11 00:08 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\HMyRgd6

2015-01-10 22:52 - 2015-01-10 22:52 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\WildTangent

2015-01-10 22:01 - 2015-01-10 22:01 - 00000000 ____D () C:\Program Files (x86)\9b1ce805-2b51-4e2c-a877-e34adbeb3be9

2015-01-01 15:52 - 2015-01-01 15:52 - 00000000 ____D () C:\Program Files (x86)\c07c4c5f-ee62-447e-af56-fd9f5dbe8bb4

2014-12-31 15:51 - 2014-12-31 15:51 - 00000000 ____D () C:\Program Files (x86)\b2a4ef93-b11a-43d9-994c-05e45b65811c

2014-12-30 19:22 - 2014-12-30 19:22 - 00000000 ____D () C:\Program Files (x86)\7da8253d-b64b-4812-9e73-5673b4bd7446

2015-01-11 00:09 - 2014-12-12 20:52 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\lu69lOr

2015-01-11 00:09 - 2014-11-12 22:18 - 00000000 ____D () C:\Users\Samuel\AppData\Roaming\l5aivml

2015-01-01 15:52 - 2014-11-28 20:23 - 00000000 ____D () C:\Program Files (x86)\a598f85f-19f7-431c-b378-85746fb316f7

Task: {02CAA442-5DFD-449A-890A-6ECF0E3F6633} - System32\Tasks\{D4CB7CE1-DD28-40C7-86C8-71B05A22F5F5} => pcalua.exe -a C:\Users\Samuel\AppData\Roaming\webssearches\UninstallManager.exe -c -ptid=nsbfr <==== ATTENTION

Task: {4534B536-DB21-4766-8F24-85FC13192453} - System32\Tasks\mIVoG9aYzLyDIqJ => C:\Users\Samuel\AppData\Roaming\HJsC0sH\mCCimpP.exe [2015-01-11] ( )

Task: {6C625016-67D0-4788-A303-41B54C64B520} - System32\Tasks\J2Bxl4gSVTCPZMS => C:\Users\Samuel\AppData\Roaming\HMyRgd6\hslm70m.exe [2015-01-11] ( )

Task: {6F6D7A7E-C385-4214-8425-7573712B7999} - System32\Tasks\{29030E9F-71B9-4E87-88EB-964F8DA6391C} => pcalua.exe -a "C:\Users\Samuel\AppData\Roaming\Nosibay\Bubble Dock\Uninstall Bubble Dock.exe"

Task: {C0D54BA6-E21D-4CB9-A332-E30DF34E1942} - System32\Tasks\rj2mbojdsPTGktW => C:\Users\Samuel\AppData\Roaming\l5aivml\C6Rkfli.exe [2014-11-12] ( )
*****************

C:\Users\Samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk => Moved successfully.
C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe => Moved successfully.
Firefox homepage deleted successfully.
C:\Users\Samuel\AppData\Roaming\Mozilla\Firefox\Profiles\wqekj2ck.default\Extensions\faststartff@gmail.com => Moved successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\faststartff@gmail.com => value deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gfkbfjcbkhnmiignagpkiijohkcdkffb" => Key deleted successfully.
BackupStack => Service deleted successfully.
IHProtect Service => Unable to stop service
IHProtect Service => Service deleted successfully.
WindowsMangerProtect => Unable to stop service
WindowsMangerProtect => Service deleted successfully.
C:\Users\Samuel\Desktop\Sync Folder.lnk => Moved successfully.
C:\Users\Samuel\Desktop\MyPC Backup.lnk => Moved successfully.
C:\Users\Samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup => Moved successfully.
C:\ProgramData\IHProtectUpDate => Moved successfully.

"C:\Program Files (x86)\MyPC Backup" directory move:

C:\Program Files (x86)\MyPC Backup\aff.conf => Moved successfully.
C:\Program Files (x86)\MyPC Backup\AlphaFS.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\AlphaVSS.51.x86.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\AlphaVSS.52.x64.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\AlphaVSS.52.x86.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\AlphaVSS.60.x64.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\AlphaVSS.60.x86.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\AlphaVSS.Common.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\BackupStack.exe => Moved successfully.
C:\Program Files (x86)\MyPC Backup\BackupStackUI.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\BplusDotNet.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\Configuration Updater.exe => Moved successfully.
C:\Program Files (x86)\MyPC Backup\de_DE.mo => Moved successfully.
C:\Program Files (x86)\MyPC Backup\es_ES.mo => Moved successfully.
C:\Program Files (x86)\MyPC Backup\fr_FR.mo => Moved successfully.
C:\Program Files (x86)\MyPC Backup\GetText.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\InstMgr.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\Ionic.Zip.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\it_IT.mo => Moved successfully.
C:\Program Files (x86)\MyPC Backup\LogicNP.EZShellExtensions.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\Microsoft.Win32.TaskScheduler.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\MPCBClient.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\MPCBContextMenu.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\mypcbackup.ico => Moved successfully.
C:\Program Files (x86)\MyPC Backup\NativeHashWrapper.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\Newtonsoft.Json.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\ObjectListView.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\PipeDiff.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\pt_PT.mo => Moved successfully.
C:\Program Files (x86)\MyPC Backup\RegisterExtensionDotNet20_x64.exe => Moved successfully.
C:\Program Files (x86)\MyPC Backup\RegisterExtensionDotNet20_x86.exe => Moved successfully.
C:\Program Files (x86)\MyPC Backup\RegisterExtensionDotNet40_x64.exe => Moved successfully.
C:\Program Files (x86)\MyPC Backup\RegisterExtensionDotNet40_x86.exe => Moved successfully.
C:\Program Files (x86)\MyPC Backup\Service Start.exe => Moved successfully.
C:\Program Files (x86)\MyPC Backup\Shared Stack.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe => Moved successfully.
C:\Program Files (x86)\MyPC Backup\SignupWizard.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\syncicon.ico => Moved successfully.
C:\Program Files (x86)\MyPC Backup\System.Data.SQLite.DLL => Moved successfully.
C:\Program Files (x86)\MyPC Backup\uninst.exe => Moved successfully.
C:\Program Files (x86)\MyPC Backup\UnRegisterExtensions.exe => Moved successfully.
C:\Program Files (x86)\MyPC Backup\Updater.exe => Moved successfully.
C:\Program Files (x86)\MyPC Backup\Updater_.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\websocket-sharp.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\x86\SQLite.Interop.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\x64\SQLite.Interop.dll => Moved successfully.
C:\Program Files (x86)\MyPC Backup\log\APPLICATION.log => Moved successfully.
C:\Program Files (x86)\MyPC Backup\log\WAIT_HANDLES.log => Moved successfully.
C:\Program Files (x86)\MyPC Backup\Database\mpcb_settings.db => Moved successfully.
Could not move "C:\Program Files (x86)\MyPC Backup" directory. => Scheduled to move on reboot.

C:\Program Files (x86)\XTab => Moved successfully.
C:\ProgramData\WindowsMangerProtect => Moved successfully.
C:\Users\Samuel\AppData\Roaming\omiga-plus => Moved successfully.
C:\Users\Samuel\AppData\Roaming\VOPackage => Moved successfully.
C:\Users\Samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage => Moved successfully.
C:\Windows\System32\Tasks\mIVoG9aYzLyDIqJ => Moved successfully.
C:\Users\Samuel\AppData\Roaming\HJsC0sH => Moved successfully.
C:\Windows\System32\Tasks\J2Bxl4gSVTCPZMS => Moved successfully.
C:\Users\Samuel\AppData\Roaming\HMyRgd6 => Moved successfully.
C:\Users\Samuel\AppData\Roaming\WildTangent => Moved successfully.
C:\Program Files (x86)\9b1ce805-2b51-4e2c-a877-e34adbeb3be9 => Moved successfully.
C:\Program Files (x86)\c07c4c5f-ee62-447e-af56-fd9f5dbe8bb4 => Moved successfully.
C:\Program Files (x86)\b2a4ef93-b11a-43d9-994c-05e45b65811c => Moved successfully.
C:\Program Files (x86)\7da8253d-b64b-4812-9e73-5673b4bd7446 => Moved successfully.
C:\Users\Samuel\AppData\Roaming\lu69lOr => Moved successfully.
C:\Users\Samuel\AppData\Roaming\l5aivml => Moved successfully.
C:\Program Files (x86)\a598f85f-19f7-431c-b378-85746fb316f7 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{02CAA442-5DFD-449A-890A-6ECF0E3F6633}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02CAA442-5DFD-449A-890A-6ECF0E3F6633}" => Key deleted successfully.
C:\Windows\System32\Tasks\{D4CB7CE1-DD28-40C7-86C8-71B05A22F5F5} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D4CB7CE1-DD28-40C7-86C8-71B05A22F5F5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4534B536-DB21-4766-8F24-85FC13192453}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4534B536-DB21-4766-8F24-85FC13192453}" => Key deleted successfully.
C:\Windows\System32\Tasks\mIVoG9aYzLyDIqJ not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\mIVoG9aYzLyDIqJ" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6C625016-67D0-4788-A303-41B54C64B520}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C625016-67D0-4788-A303-41B54C64B520}" => Key deleted successfully.
C:\Windows\System32\Tasks\J2Bxl4gSVTCPZMS not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\J2Bxl4gSVTCPZMS" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6F6D7A7E-C385-4214-8425-7573712B7999}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F6D7A7E-C385-4214-8425-7573712B7999}" => Key deleted successfully.
C:\Windows\System32\Tasks\{29030E9F-71B9-4E87-88EB-964F8DA6391C} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{29030E9F-71B9-4E87-88EB-964F8DA6391C}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C0D54BA6-E21D-4CB9-A332-E30DF34E1942}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C0D54BA6-E21D-4CB9-A332-E30DF34E1942}" => Key deleted successfully.
C:\Windows\System32\Tasks\rj2mbojdsPTGktW => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\rj2mbojdsPTGktW" => Key deleted successfully.

=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-01-23 14:44:23)<=

C:\Program Files (x86)\MyPC Backup => Is moved successfully.

==== End of Fixlog 14:44:23 ====
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 656
23 janv. 2015 à 15:44
Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :
* Firefox : https://www.malekal.com/reparer-firefox/?t=36057&start=
* Google Chrome : https://www.malekal.com/reparer-google-chrome/?t=35837&start=
* Internet Explorer et modules complémentaires / moteurs de recherche : https://forum.malekal.com/viewtopic.php?t=41399&start=


puis :

Scan Malwarebytes (temps : environ 40min de scan):
==================================================
Télécharge et installe Malwarebyte : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
Mets le à jour puis lance un examen.

A la fin du scan, clic sur "Mettre tout en quarantaine" en bas à gauche.
Redémarre l'ordinateur si besoin.
Après redémarrage, relance Malwarebytes.
Vas chercher le rapport dans l'onglet Historique.
A gauche Journal des examens.
Doube-clic sur l'examen dans la liste.
Puis en bas Copier dans le presse papier
Vas sur http://pjjoint.malekal.com et en bas, clic droit / coller pour coller le rapport du scan Malwarebytes.
Clic sur envoyer.
Dans un nouveau message ici en réponse, donne le lien pjjoint afin de pouvoir consulter le rapport.



0