Désinstaller ab by tv wizard

sandra -  
Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   -
Bonjour à tous et toutes,

Je ne sais pas comment , mais ab tv wizard est s'installé, très embettant , et il n'est nul part.
J'ai 1 rapport suite à 1 conversation du forum, j'ai 1 lien , mais après je ne sais pas comment faire,
Merci de vos aides.
http://pjjoint.malekal.com/files.php?id=20150129_r12u9q12c10l12

mon rapport ci joint
# AdwCleaner v4.109 - Rapport créé le 29/01/2015 à 10:22:53
# Mis à jour le 24/01/2015 par Xplode
# Database : 2015-01-26.1 [Live]
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : sandra - françois - SANDRA-FRANÇOIS
# Exécuté depuis : C:\Users\sandra - françois\Downloads\AdwCleaner (1).exe
# Option : Nettoyer

***** [ Services ] *****

[#] Service Supprimé : Update Solution Real

***** [ Fichiers / Dossiers ] *****

Dossier Supprimé : C:\Program Files (x86)\Solution Real
Dossier Supprimé : C:\Users\sandra - françois\AppData\Local\TVWizard
Dossier Supprimé : C:\Users\sandra - françois\AppData\Local\CleanerPro
Dossier Supprimé : C:\Users\sandra - françois\Documents\CleanerPro
Fichier Supprimé : C:\Users\sandra - françois\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage
Fichier Supprimé : C:\Users\sandra - françois\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage-journal

***** [ Tâches planifiées ] *****

***** [ Raccourcis ] *****

***** [ Registre ] *****

***** [ Navigateurs ] *****

-\\ Internet Explorer v11.0.9600.17496

-\\ Google Chrome v40.0.2214.93

*************************

AdwCleaner[R0].txt - [27406 octets] - [07/01/2015 18:42:18]
AdwCleaner[R1].txt - [1161 octets] - [20/01/2015 14:55:56]
AdwCleaner[R2].txt - [1449 octets] - [21/01/2015 10:57:38]
AdwCleaner[R3].txt - [1801 octets] - [29/01/2015 10:20:50]
AdwCleaner[S0].txt - [26010 octets] - [07/01/2015 18:44:37]
AdwCleaner[S1].txt - [1227 octets] - [20/01/2015 14:58:15]
AdwCleaner[S2].txt - [1513 octets] - [21/01/2015 11:00:59]
AdwCleaner[S3].txt - [1733 octets] - [29/01/2015 10:22:53]

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1793 octets] ##########

2 réponses

  1. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Salut,

    Suis ce tutoriel FRST: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/
    Télécharge et lance le scan FRST, cela va générer trois rapports FRST :
    * FRST.txt
    * Shortcut.txt
    * Additionnal.txt

    Envoie comme expliqué, ces trois rapports sur le site http://pjjoint.malekal.com et donne les trois liens pjjoint de ces rapports afin qu'ils puissent être consultés.

    0
    1. sandra
       
      trop de choses s'installent... :( :(
      0
    2. sandra
       
      1 er lien http://pjjoint.malekal.com/files.php?id=FRST_20150129_v10v13t13n13c6
      2 ième lien http://pjjoint.malekal.com/files.php?id=FRST_20150129_d9k613g10o11
      3 ième http://pjjoint.malekal.com/files.php?id=20150129_d12c6e10l14x13
      merci de votre aide
      0
      1. sandra > sandra
         
        Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-01-2015
        Ran by sandra - françois at 2015-01-29 12:09:21 Run:1
        Running from C:\Users\sandra - françois\Desktop
        Loaded Profiles: sandra - françois (Available profiles: sandra - françois)
        Boot Mode: Normal
        ==============================================

        Content of fixlist:
        *****************
        HKLM-x32\...\Run: [gmsd_fr_66] => [X]
        HKLM-x32\...\RunOnce: [WSE_Vosteran] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B C:\Users\SANDRA~1\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat
        HKLM-x32\...\RunOnce: [DelTr2394256] => cmd.exe /c rd /s /q C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran
        HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Run: [Infigo] => C:\Program Files (x86)\Infigo\Infigo.exe onrun
        HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\RunOnce: [DigitalSites] => [X]
        HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\RunOnce: [WSE_Vosteran] => [X]
        HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\RunOnce: [DelTr2394256] => cmd.exe /c rd /s /q C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran
        HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Policies\system: [DisableLockWorkstation] 0
        HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Policies\system: [DisableChangePassword] 0
        HKU\S-1-5-21-913213923-3936371392-864543947-1000\...409d6c4515e9\InprocServer32: [Default-shell32] <==== ATTENTION!
        CHR HomePage: Default -> hxxp://vosteran.com/?f=1&a=vst_ggfc_15_05_ch&cd=2XzuyEtN2Y1L1QzutA0C0DzytB0ByDyD0D0B0CtC0B0B0F0FtN0D0Tzu0StCtCtByEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2StCzzzyyByByCzy0FtGzz0AtAyCtG0FtDzzzytG0CtC0C0FtGyCtC0ByB0D0F0ByE0CtAtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0FzzyEtDtCyD0CtGyE0EyEtCtGyEyCyC0CtG0AtA0DzytGtAtD0EyEtB0C0C0F0CyEtC0A2Q&cr=1231686440&ir= [Pays US - 50.19.213.45]
        CHR StartupUrls: Default -> hxxp://vosteran.com/?f=7&a=vst_ggfc_15_05_ch&cd=2XzuyEtN2Y1L1QzutA0C0DzytB0ByDyD0D0B0CtC0B0B0F0FtN0D0Tzu0StCtCtByEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2StCzzzyyByByCzy0FtGzz0AtAyCtG0FtDzzzytG0CtC0C0FtGyCtC0ByB0D0F0ByE0CtAtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0FzzyEtDtCyD0CtGyE0EyEtCtGyEyCyC0CtG0AtA0DzytGtAtD0EyEtB0C0C0F0CyEtC0A2Q&cr=1231686440&ir= [Pays US - 54.235.99.6]
        CHR DefaultSearchKeyword: Default -> vosteran.com
        CHR DefaultSearchURL: Default -> http://vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_15_05_ch&cd=2XzuyEtN2Y1L1QzutA0C0DzytB0ByDyD0D0B0CtC0B0B0F0FtN0D0Tzu0StCtCtByEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2StCzzzyyByByCzy0FtGzz0AtAyCtG0FtDzzzytG0CtC0C0FtGyCtC0ByB0D0F0ByE0CtAtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0FzzyEtDtCyD0CtGyE0EyEtCtGyEyCyC0CtG0AtA0DzytGtAtD0EyEtB0C0C0F0CyEtC0A2Q&cr=1231686440&ir= [Pays US - 54.235.99.6]
        CHR HKLM\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
        CHR HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
        CHR HKLM-x32\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
        R2 cYRvMth; C:\ProgramData\QFqicbLFM\cYRvMth.exe [2726256 2015-01-07] (Small Island Development)
        2015-01-29 10:57 - 2015-01-29 10:57 - 00000000 ____D () C:\Users\sandra - françois\Documents\PC Speed Maximizer
        2015-01-29 10:55 - 2015-01-29 11:05 - 00000000 ____D () C:\Users\sandra - françois\AppData\Local\Vosteran
        2015-01-29 10:52 - 2015-01-29 11:16 - 00003300 _____ () C:\Windows\System32\Tasks\Digital Sites
        2015-01-29 10:52 - 2015-01-29 11:16 - 00000322 _____ () C:\Windows\Tasks\Digital Sites.job
        2015-01-29 10:52 - 2015-01-29 10:52 - 00000000 ____D () C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran
        2015-01-29 10:52 - 2015-01-29 10:52 - 00000000 ____D () C:\Users\sandra - françois\AppData\Roaming\DigitalSites
        2015-01-29 10:52 - 2015-01-29 10:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiPony
        2015-01-29 10:26 - 2015-01-29 10:26 - 00000000 ____D () C:\Users\sandra - françois\AppData\Local\TVWizard
        2015-01-07 16:42 - 2015-01-07 16:42 - 00003136 _____ () C:\Windows\System32\Tasks\{5FFB2D48-D301-4A2D-BACF-CA1E42A7973F}
        2015-01-07 16:41 - 2015-01-07 16:41 - 00000008 _____ () C:\Users\sandra - françois\AppData\Roaming\Syshandle.txt
        2015-01-07 16:40 - 2015-01-07 16:40 - 00000000 ____D () C:\Users\sandra - françois\AppData\Roaming\SystClean
        2015-01-07 16:39 - 2015-01-07 16:40 - 00000000 ____D () C:\ProgramData\QFqicbLFM
        2015-01-07 15:20 - 2015-01-07 15:20 - 00003488 _____ () C:\Windows\System32\Tasks\CleanerPro_Popup
        2015-01-07 15:20 - 2015-01-07 15:20 - 00003224 _____ () C:\Windows\System32\Tasks\CleanerPro_Start
        2015-01-07 15:19 - 2015-01-07 15:19 - 00846104 _____ ( ) C:\Users\sandra - françois\Downloads\Ccleaner_Setup.exe
        2015-01-07 15:14 - 2015-01-07 15:14 - 00000000 ____D () C:\ProgramData\2355320829
        2015-01-07 15:12 - 2015-01-07 15:12 - 00000000 ____D () C:\Program Files (x86)\e7d9f42f-5a57-4812-a09b-9d32e794b4bf

        *****************

        HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_66 => value deleted successfully.
        HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\WSE_Vosteran => value deleted successfully.
        HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\DelTr2394256 => value deleted successfully.
        HKU\S-1-5-21-913213923-3936371392-864543947-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Infigo => value deleted successfully.
        HKU\S-1-5-21-913213923-3936371392-864543947-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\DigitalSites => value deleted successfully.
        HKU\S-1-5-21-913213923-3936371392-864543947-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\WSE_Vosteran => value deleted successfully.
        HKU\S-1-5-21-913213923-3936371392-864543947-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\DelTr2394256 => value deleted successfully.
        HKU\S-1-5-21-913213923-3936371392-864543947-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableLockWorkstation => value deleted successfully.
        HKU\S-1-5-21-913213923-3936371392-864543947-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableChangePassword => value deleted successfully.
        "HKU\S-1-5-21-913213923-3936371392-864543947-1000\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}" => Key deleted successfully.
        Chrome HomePage deleted successfully.
        Chrome StartupUrls deleted successfully.
        Chrome DefaultSearchKeyword deleted successfully.
        Chrome DefaultSearchURL deleted successfully.
        "HKLM\SOFTWARE\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce" => Key deleted successfully.
        "HKU\S-1-5-21-913213923-3936371392-864543947-1000\SOFTWARE\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce" => Key deleted successfully.
        "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce" => Key deleted successfully.
        cYRvMth => Unable to stop service
        cYRvMth => Service deleted successfully.
        C:\Users\sandra - françois\Documents\PC Speed Maximizer => Moved successfully.
        C:\Users\sandra - françois\AppData\Local\Vosteran => Moved successfully.
        C:\Windows\System32\Tasks\Digital Sites => Moved successfully.
        C:\Windows\Tasks\Digital Sites.job => Moved successfully.
        C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran => Moved successfully.
        C:\Users\sandra - françois\AppData\Roaming\DigitalSites => Moved successfully.
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiPony => Moved successfully.
        C:\Users\sandra - françois\AppData\Local\TVWizard => Moved successfully.
        C:\Windows\System32\Tasks\{5FFB2D48-D301-4A2D-BACF-CA1E42A7973F} => Moved successfully.
        C:\Users\sandra - françois\AppData\Roaming\Syshandle.txt => Moved successfully.
        C:\Users\sandra - françois\AppData\Roaming\SystClean => Moved successfully.

        "C:\ProgramData\QFqicbLFM" directory move:

        Could not move "C:\ProgramData\QFqicbLFM\cYRvMth.dat" => Scheduled to move on reboot.
        C:\ProgramData\QFqicbLFM\cYRvMth.exe => Moved successfully.
        C:\ProgramData\QFqicbLFM\cYRvMth.exe.config => Moved successfully.
        Could not move "C:\ProgramData\QFqicbLFM\info.dat" => Scheduled to move on reboot.
        Could not move "C:\ProgramData\QFqicbLFM\dat\hpfEgcnL.dll" => Scheduled to move on reboot.
        Could not move "C:\ProgramData\QFqicbLFM\dat\kyYfBhOir.exe" => Scheduled to move on reboot.
        Could not move "C:\ProgramData\QFqicbLFM\dat\kyYfBhOir.exe.config" => Scheduled to move on reboot.
        Could not move "C:\ProgramData\QFqicbLFM\dat\SLEvWpx.exe" => Scheduled to move on reboot.
        Could not move "C:\ProgramData\QFqicbLFM\dat\SLEvWpx.exe.config" => Scheduled to move on reboot.
        Could not move "C:\ProgramData\QFqicbLFM\dat\tCmTGXeBhC.dll" => Scheduled to move on reboot.
        Could not move "C:\ProgramData\QFqicbLFM" directory. => Scheduled to move on reboot.

        C:\Windows\System32\Tasks\CleanerPro_Popup => Moved successfully.
        C:\Windows\System32\Tasks\CleanerPro_Start => Moved successfully.
        C:\Users\sandra - françois\Downloads\Ccleaner_Setup.exe => Moved successfully.
        C:\ProgramData\2355320829 => Moved successfully.
        C:\Program Files (x86)\e7d9f42f-5a57-4812-a09b-9d32e794b4bf => Moved successfully.

        => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-01-29 12:24:21)<=

        C:\ProgramData\QFqicbLFM\cYRvMth.dat => Is moved successfully.
        C:\ProgramData\QFqicbLFM\info.dat => Is moved successfully.
        C:\ProgramData\QFqicbLFM\dat\hpfEgcnL.dll => Is moved successfully.
        C:\ProgramData\QFqicbLFM\dat\kyYfBhOir.exe => Is moved successfully.
        C:\ProgramData\QFqicbLFM\dat\kyYfBhOir.exe.config => Is moved successfully.
        C:\ProgramData\QFqicbLFM\dat\SLEvWpx.exe => Is moved successfully.
        C:\ProgramData\QFqicbLFM\dat\SLEvWpx.exe.config => Is moved successfully.
        C:\ProgramData\QFqicbLFM\dat\tCmTGXeBhC.dll => Is moved successfully.
        C:\ProgramData\QFqicbLFM => Is moved successfully.

        ==== End of Fixlog 12:24:21 ====
        0
      2. sandra > sandra
         
        je redémarre où j'attends ta réponse?
        0
    3. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
       
      redémarre.
      0
  2. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Voici la correction à effectuer avec FRST.
    Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix

    Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
    Copie/colle dedans ce qui suit :

    HKLM-x32\...\Run: [gmsd_fr_66] => [X]
    HKLM-x32\...\RunOnce: [WSE_Vosteran] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B C:\Users\SANDRA~1\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat
    HKLM-x32\...\RunOnce: [DelTr2394256] => cmd.exe /c rd /s /q C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran
    HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Run: [Infigo] => C:\Program Files (x86)\Infigo\Infigo.exe onrun
    HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\RunOnce: [DigitalSites] => [X]
    HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\RunOnce: [WSE_Vosteran] => [X]
    HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\RunOnce: [DelTr2394256] => cmd.exe /c rd /s /q C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran
    HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Policies\system: [DisableLockWorkstation] 0
    HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Policies\system: [DisableChangePassword] 0
    HKU\S-1-5-21-913213923-3936371392-864543947-1000\...409d6c4515e9\InprocServer32: [Default-shell32] <==== ATTENTION!
    CHR HomePage: Default -> hxxp://vosteran.com/?f=1&a=vst_ggfc_15_05_ch&cd=2XzuyEtN2Y1L1QzutA0C0DzytB0ByDyD0D0B0CtC0B0B0F0FtN0D0Tzu0StCtCtByEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2StCzzzyyByByCzy0FtGzz0AtAyCtG0FtDzzzytG0CtC0C0FtGyCtC0ByB0D0F0ByE0CtAtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0FzzyEtDtCyD0CtGyE0EyEtCtGyEyCyC0CtG0AtA0DzytGtAtD0EyEtB0C0C0F0CyEtC0A2Q&cr=1231686440&ir= [Pays US - 50.19.213.45]
    CHR StartupUrls: Default -> hxxp://vosteran.com/?f=7&a=vst_ggfc_15_05_ch&cd=2XzuyEtN2Y1L1QzutA0C0DzytB0ByDyD0D0B0CtC0B0B0F0FtN0D0Tzu0StCtCtByEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2StCzzzyyByByCzy0FtGzz0AtAyCtG0FtDzzzytG0CtC0C0FtGyCtC0ByB0D0F0ByE0CtAtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0FzzyEtDtCyD0CtGyE0EyEtCtGyEyCyC0CtG0AtA0DzytGtAtD0EyEtB0C0C0F0CyEtC0A2Q&cr=1231686440&ir= [Pays US - 54.235.99.6]
    CHR DefaultSearchKeyword: Default -> vosteran.com
    CHR DefaultSearchURL: Default -> http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_15_05_ch&cd=2XzuyEtN2Y1L1QzutA0C0DzytB0ByDyD0D0B0CtC0B0B0F0FtN0D0Tzu0StCtCtByEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2StCzzzyyByByCzy0FtGzz0AtAyCtG0FtDzzzytG0CtC0C0FtGyCtC0ByB0D0F0ByE0CtAtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0FzzyEtDtCyD0CtGyE0EyEtCtGyEyCyC0CtG0AtA0DzytGtAtD0EyEtB0C0C0F0CyEtC0A2Q&cr=1231686440&ir= [Pays US - 54.235.99.6]
    CHR HKLM\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
    CHR HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
    CHR HKLM-x32\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
    R2 cYRvMth; C:\ProgramData\QFqicbLFM\cYRvMth.exe [2726256 2015-01-07] (Small Island Development)
    2015-01-29 10:57 - 2015-01-29 10:57 - 00000000 ____D () C:\Users\sandra - françois\Documents\PC Speed Maximizer
    2015-01-29 10:55 - 2015-01-29 11:05 - 00000000 ____D () C:\Users\sandra - françois\AppData\Local\Vosteran
    2015-01-29 10:52 - 2015-01-29 11:16 - 00003300 _____ () C:\Windows\System32\Tasks\Digital Sites
    2015-01-29 10:52 - 2015-01-29 11:16 - 00000322 _____ () C:\Windows\Tasks\Digital Sites.job
    2015-01-29 10:52 - 2015-01-29 10:52 - 00000000 ____D () C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran
    2015-01-29 10:52 - 2015-01-29 10:52 - 00000000 ____D () C:\Users\sandra - françois\AppData\Roaming\DigitalSites
    2015-01-29 10:52 - 2015-01-29 10:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiPony
    2015-01-29 10:26 - 2015-01-29 10:26 - 00000000 ____D () C:\Users\sandra - françois\AppData\Local\TVWizard
    2015-01-07 16:42 - 2015-01-07 16:42 - 00003136 _____ () C:\Windows\System32\Tasks\{5FFB2D48-D301-4A2D-BACF-CA1E42A7973F}
    2015-01-07 16:41 - 2015-01-07 16:41 - 00000008 _____ () C:\Users\sandra - françois\AppData\Roaming\Syshandle.txt
    2015-01-07 16:40 - 2015-01-07 16:40 - 00000000 ____D () C:\Users\sandra - françois\AppData\Roaming\SystClean
    2015-01-07 16:39 - 2015-01-07 16:40 - 00000000 ____D () C:\ProgramData\QFqicbLFM
    2015-01-07 15:20 - 2015-01-07 15:20 - 00003488 _____ () C:\Windows\System32\Tasks\CleanerPro_Popup
    2015-01-07 15:20 - 2015-01-07 15:20 - 00003224 _____ () C:\Windows\System32\Tasks\CleanerPro_Start
    2015-01-07 15:19 - 2015-01-07 15:19 - 00846104 _____ ( ) C:\Users\sandra - françois\Downloads\Ccleaner_Setup.exe
    2015-01-07 15:14 - 2015-01-07 15:14 - 00000000 ____D () C:\ProgramData\2355320829
    2015-01-07 15:12 - 2015-01-07 15:12 - 00000000 ____D () C:\Program Files (x86)\e7d9f42f-5a57-4812-a09b-9d32e794b4bf

    Une fois, le texte coller dans le bloc-note.
    Menu Fichier puis Enregistrer sous.
    A gauche, place toi sur le bureau.
    Dans le champs en bas, nom du fichier mets : fixlist.txt
    Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.

    Relance FRST et clic sur le bouton Fix
    Selon comment un redémarrage est nécessaire (pas obligatoire).
    Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.

    Redémarre l'ordinateur

    puis réinitialise tes navigateurs:
    ==================================
    Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :
    * Firefox : https://www.malekal.com/reparer-firefox/?t=36057&start=
    * Google Chrome : https://www.malekal.com/reparer-google-chrome/?t=35837&start=
    * Internet Explorer et modules complémentaires / moteurs de recherche : https://forum.malekal.com/viewtopic.php?t=41399&start=

    0