Désinstaller ab by tv wizard
Fermé
sandra
-
29 janv. 2015 à 10:46
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 - 29 janv. 2015 à 12:33
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 - 29 janv. 2015 à 12:33
A voir également:
- Désinstaller ab by tv wizard
- Desinstaller edge - Guide
- Désinstaller mcafee - Guide
- Desinstaller logiciel windows - Guide
- Installer chromecast sur tv - Guide
- Pas de signal tv - Guide
2 réponses
Malekal_morte-
Messages postés
180304
Date d'inscription
mercredi 17 mai 2006
Statut
Modérateur, Contributeur sécurité
Dernière intervention
15 décembre 2020
24 656
29 janv. 2015 à 10:46
29 janv. 2015 à 10:46
Salut,
Suis ce tutoriel FRST: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/
Télécharge et lance le scan FRST, cela va générer trois rapports FRST :
* FRST.txt
* Shortcut.txt
* Additionnal.txt
Envoie comme expliqué, ces trois rapports sur le site http://pjjoint.malekal.com et donne les trois liens pjjoint de ces rapports afin qu'ils puissent être consultés.
Suis ce tutoriel FRST: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/
Télécharge et lance le scan FRST, cela va générer trois rapports FRST :
* FRST.txt
* Shortcut.txt
* Additionnal.txt
Envoie comme expliqué, ces trois rapports sur le site http://pjjoint.malekal.com et donne les trois liens pjjoint de ces rapports afin qu'ils puissent être consultés.
Malekal_morte-
Messages postés
180304
Date d'inscription
mercredi 17 mai 2006
Statut
Modérateur, Contributeur sécurité
Dernière intervention
15 décembre 2020
24 656
29 janv. 2015 à 12:03
29 janv. 2015 à 12:03
Voici la correction à effectuer avec FRST.
Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix
Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
Copie/colle dedans ce qui suit :
HKLM-x32\...\Run: [gmsd_fr_66] => [X]
HKLM-x32\...\RunOnce: [WSE_Vosteran] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B C:\Users\SANDRA~1\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat
HKLM-x32\...\RunOnce: [DelTr2394256] => cmd.exe /c rd /s /q C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Run: [Infigo] => C:\Program Files (x86)\Infigo\Infigo.exe onrun
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\RunOnce: [DigitalSites] => [X]
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\RunOnce: [WSE_Vosteran] => [X]
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\RunOnce: [DelTr2394256] => cmd.exe /c rd /s /q C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...409d6c4515e9\InprocServer32: [Default-shell32] <==== ATTENTION!
CHR HomePage: Default -> hxxp://vosteran.com/?f=1&a=vst_ggfc_15_05_ch&cd=2XzuyEtN2Y1L1QzutA0C0DzytB0ByDyD0D0B0CtC0B0B0F0FtN0D0Tzu0StCtCtByEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2StCzzzyyByByCzy0FtGzz0AtAyCtG0FtDzzzytG0CtC0C0FtGyCtC0ByB0D0F0ByE0CtAtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0FzzyEtDtCyD0CtGyE0EyEtCtGyEyCyC0CtG0AtA0DzytGtAtD0EyEtB0C0C0F0CyEtC0A2Q&cr=1231686440&ir= [Pays US - 50.19.213.45]
CHR StartupUrls: Default -> hxxp://vosteran.com/?f=7&a=vst_ggfc_15_05_ch&cd=2XzuyEtN2Y1L1QzutA0C0DzytB0ByDyD0D0B0CtC0B0B0F0FtN0D0Tzu0StCtCtByEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2StCzzzyyByByCzy0FtGzz0AtAyCtG0FtDzzzytG0CtC0C0FtGyCtC0ByB0D0F0ByE0CtAtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0FzzyEtDtCyD0CtGyE0EyEtCtGyEyCyC0CtG0AtA0DzytGtAtD0EyEtB0C0C0F0CyEtC0A2Q&cr=1231686440&ir= [Pays US - 54.235.99.6]
CHR DefaultSearchKeyword: Default -> vosteran.com
CHR DefaultSearchURL: Default -> http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_15_05_ch&cd=2XzuyEtN2Y1L1QzutA0C0DzytB0ByDyD0D0B0CtC0B0B0F0FtN0D0Tzu0StCtCtByEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2StCzzzyyByByCzy0FtGzz0AtAyCtG0FtDzzzytG0CtC0C0FtGyCtC0ByB0D0F0ByE0CtAtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0FzzyEtDtCyD0CtGyE0EyEtCtGyEyCyC0CtG0AtA0DzytGtAtD0EyEtB0C0C0F0CyEtC0A2Q&cr=1231686440&ir= [Pays US - 54.235.99.6]
CHR HKLM\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
CHR HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
CHR HKLM-x32\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
R2 cYRvMth; C:\ProgramData\QFqicbLFM\cYRvMth.exe [2726256 2015-01-07] (Small Island Development)
2015-01-29 10:57 - 2015-01-29 10:57 - 00000000 ____D () C:\Users\sandra - françois\Documents\PC Speed Maximizer
2015-01-29 10:55 - 2015-01-29 11:05 - 00000000 ____D () C:\Users\sandra - françois\AppData\Local\Vosteran
2015-01-29 10:52 - 2015-01-29 11:16 - 00003300 _____ () C:\Windows\System32\Tasks\Digital Sites
2015-01-29 10:52 - 2015-01-29 11:16 - 00000322 _____ () C:\Windows\Tasks\Digital Sites.job
2015-01-29 10:52 - 2015-01-29 10:52 - 00000000 ____D () C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran
2015-01-29 10:52 - 2015-01-29 10:52 - 00000000 ____D () C:\Users\sandra - françois\AppData\Roaming\DigitalSites
2015-01-29 10:52 - 2015-01-29 10:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiPony
2015-01-29 10:26 - 2015-01-29 10:26 - 00000000 ____D () C:\Users\sandra - françois\AppData\Local\TVWizard
2015-01-07 16:42 - 2015-01-07 16:42 - 00003136 _____ () C:\Windows\System32\Tasks\{5FFB2D48-D301-4A2D-BACF-CA1E42A7973F}
2015-01-07 16:41 - 2015-01-07 16:41 - 00000008 _____ () C:\Users\sandra - françois\AppData\Roaming\Syshandle.txt
2015-01-07 16:40 - 2015-01-07 16:40 - 00000000 ____D () C:\Users\sandra - françois\AppData\Roaming\SystClean
2015-01-07 16:39 - 2015-01-07 16:40 - 00000000 ____D () C:\ProgramData\QFqicbLFM
2015-01-07 15:20 - 2015-01-07 15:20 - 00003488 _____ () C:\Windows\System32\Tasks\CleanerPro_Popup
2015-01-07 15:20 - 2015-01-07 15:20 - 00003224 _____ () C:\Windows\System32\Tasks\CleanerPro_Start
2015-01-07 15:19 - 2015-01-07 15:19 - 00846104 _____ ( ) C:\Users\sandra - françois\Downloads\Ccleaner_Setup.exe
2015-01-07 15:14 - 2015-01-07 15:14 - 00000000 ____D () C:\ProgramData\2355320829
2015-01-07 15:12 - 2015-01-07 15:12 - 00000000 ____D () C:\Program Files (x86)\e7d9f42f-5a57-4812-a09b-9d32e794b4bf
Une fois, le texte coller dans le bloc-note.
Menu Fichier puis Enregistrer sous.
A gauche, place toi sur le bureau.
Dans le champs en bas, nom du fichier mets : fixlist.txt
Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.
Relance FRST et clic sur le bouton Fix
Selon comment un redémarrage est nécessaire (pas obligatoire).
Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.
Redémarre l'ordinateur
puis réinitialise tes navigateurs:
==================================
Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :
* Firefox : https://www.malekal.com/reparer-firefox/?t=36057&start=
* Google Chrome : https://www.malekal.com/reparer-google-chrome/?t=35837&start=
* Internet Explorer et modules complémentaires / moteurs de recherche : https://forum.malekal.com/viewtopic.php?t=41399&start=
Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix
Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
Copie/colle dedans ce qui suit :
HKLM-x32\...\Run: [gmsd_fr_66] => [X]
HKLM-x32\...\RunOnce: [WSE_Vosteran] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B C:\Users\SANDRA~1\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat
HKLM-x32\...\RunOnce: [DelTr2394256] => cmd.exe /c rd /s /q C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Run: [Infigo] => C:\Program Files (x86)\Infigo\Infigo.exe onrun
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\RunOnce: [DigitalSites] => [X]
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\RunOnce: [WSE_Vosteran] => [X]
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\RunOnce: [DelTr2394256] => cmd.exe /c rd /s /q C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...409d6c4515e9\InprocServer32: [Default-shell32] <==== ATTENTION!
CHR HomePage: Default -> hxxp://vosteran.com/?f=1&a=vst_ggfc_15_05_ch&cd=2XzuyEtN2Y1L1QzutA0C0DzytB0ByDyD0D0B0CtC0B0B0F0FtN0D0Tzu0StCtCtByEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2StCzzzyyByByCzy0FtGzz0AtAyCtG0FtDzzzytG0CtC0C0FtGyCtC0ByB0D0F0ByE0CtAtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0FzzyEtDtCyD0CtGyE0EyEtCtGyEyCyC0CtG0AtA0DzytGtAtD0EyEtB0C0C0F0CyEtC0A2Q&cr=1231686440&ir= [Pays US - 50.19.213.45]
CHR StartupUrls: Default -> hxxp://vosteran.com/?f=7&a=vst_ggfc_15_05_ch&cd=2XzuyEtN2Y1L1QzutA0C0DzytB0ByDyD0D0B0CtC0B0B0F0FtN0D0Tzu0StCtCtByEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2StCzzzyyByByCzy0FtGzz0AtAyCtG0FtDzzzytG0CtC0C0FtGyCtC0ByB0D0F0ByE0CtAtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0FzzyEtDtCyD0CtGyE0EyEtCtGyEyCyC0CtG0AtA0DzytGtAtD0EyEtB0C0C0F0CyEtC0A2Q&cr=1231686440&ir= [Pays US - 54.235.99.6]
CHR DefaultSearchKeyword: Default -> vosteran.com
CHR DefaultSearchURL: Default -> http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_15_05_ch&cd=2XzuyEtN2Y1L1QzutA0C0DzytB0ByDyD0D0B0CtC0B0B0F0FtN0D0Tzu0StCtCtByEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2StCzzzyyByByCzy0FtGzz0AtAyCtG0FtDzzzytG0CtC0C0FtGyCtC0ByB0D0F0ByE0CtAtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0FzzyEtDtCyD0CtGyE0EyEtCtGyEyCyC0CtG0AtA0DzytGtAtD0EyEtB0C0C0F0CyEtC0A2Q&cr=1231686440&ir= [Pays US - 54.235.99.6]
CHR HKLM\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
CHR HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
CHR HKLM-x32\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
R2 cYRvMth; C:\ProgramData\QFqicbLFM\cYRvMth.exe [2726256 2015-01-07] (Small Island Development)
2015-01-29 10:57 - 2015-01-29 10:57 - 00000000 ____D () C:\Users\sandra - françois\Documents\PC Speed Maximizer
2015-01-29 10:55 - 2015-01-29 11:05 - 00000000 ____D () C:\Users\sandra - françois\AppData\Local\Vosteran
2015-01-29 10:52 - 2015-01-29 11:16 - 00003300 _____ () C:\Windows\System32\Tasks\Digital Sites
2015-01-29 10:52 - 2015-01-29 11:16 - 00000322 _____ () C:\Windows\Tasks\Digital Sites.job
2015-01-29 10:52 - 2015-01-29 10:52 - 00000000 ____D () C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran
2015-01-29 10:52 - 2015-01-29 10:52 - 00000000 ____D () C:\Users\sandra - françois\AppData\Roaming\DigitalSites
2015-01-29 10:52 - 2015-01-29 10:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiPony
2015-01-29 10:26 - 2015-01-29 10:26 - 00000000 ____D () C:\Users\sandra - françois\AppData\Local\TVWizard
2015-01-07 16:42 - 2015-01-07 16:42 - 00003136 _____ () C:\Windows\System32\Tasks\{5FFB2D48-D301-4A2D-BACF-CA1E42A7973F}
2015-01-07 16:41 - 2015-01-07 16:41 - 00000008 _____ () C:\Users\sandra - françois\AppData\Roaming\Syshandle.txt
2015-01-07 16:40 - 2015-01-07 16:40 - 00000000 ____D () C:\Users\sandra - françois\AppData\Roaming\SystClean
2015-01-07 16:39 - 2015-01-07 16:40 - 00000000 ____D () C:\ProgramData\QFqicbLFM
2015-01-07 15:20 - 2015-01-07 15:20 - 00003488 _____ () C:\Windows\System32\Tasks\CleanerPro_Popup
2015-01-07 15:20 - 2015-01-07 15:20 - 00003224 _____ () C:\Windows\System32\Tasks\CleanerPro_Start
2015-01-07 15:19 - 2015-01-07 15:19 - 00846104 _____ ( ) C:\Users\sandra - françois\Downloads\Ccleaner_Setup.exe
2015-01-07 15:14 - 2015-01-07 15:14 - 00000000 ____D () C:\ProgramData\2355320829
2015-01-07 15:12 - 2015-01-07 15:12 - 00000000 ____D () C:\Program Files (x86)\e7d9f42f-5a57-4812-a09b-9d32e794b4bf
Une fois, le texte coller dans le bloc-note.
Menu Fichier puis Enregistrer sous.
A gauche, place toi sur le bureau.
Dans le champs en bas, nom du fichier mets : fixlist.txt
Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.
Relance FRST et clic sur le bouton Fix
Selon comment un redémarrage est nécessaire (pas obligatoire).
Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.
Redémarre l'ordinateur
puis réinitialise tes navigateurs:
==================================
Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :
* Firefox : https://www.malekal.com/reparer-firefox/?t=36057&start=
* Google Chrome : https://www.malekal.com/reparer-google-chrome/?t=35837&start=
* Internet Explorer et modules complémentaires / moteurs de recherche : https://forum.malekal.com/viewtopic.php?t=41399&start=
29 janv. 2015 à 11:23
29 janv. 2015 à 11:39
2 ième lien http://pjjoint.malekal.com/files.php?id=FRST_20150129_d9k613g10o11
3 ième http://pjjoint.malekal.com/files.php?id=20150129_d12c6e10l14x13
merci de votre aide
29 janv. 2015 à 12:28
Ran by sandra - françois at 2015-01-29 12:09:21 Run:1
Running from C:\Users\sandra - françois\Desktop
Loaded Profiles: sandra - françois (Available profiles: sandra - françois)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKLM-x32\...\Run: [gmsd_fr_66] => [X]
HKLM-x32\...\RunOnce: [WSE_Vosteran] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B C:\Users\SANDRA~1\AppData\Roaming\WSE_Vosteran\UpdateProc\bkup.dat
HKLM-x32\...\RunOnce: [DelTr2394256] => cmd.exe /c rd /s /q C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Run: [Infigo] => C:\Program Files (x86)\Infigo\Infigo.exe onrun
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\RunOnce: [DigitalSites] => [X]
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\RunOnce: [WSE_Vosteran] => [X]
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\RunOnce: [DelTr2394256] => cmd.exe /c rd /s /q C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-913213923-3936371392-864543947-1000\...409d6c4515e9\InprocServer32: [Default-shell32] <==== ATTENTION!
CHR HomePage: Default -> hxxp://vosteran.com/?f=1&a=vst_ggfc_15_05_ch&cd=2XzuyEtN2Y1L1QzutA0C0DzytB0ByDyD0D0B0CtC0B0B0F0FtN0D0Tzu0StCtCtByEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2StCzzzyyByByCzy0FtGzz0AtAyCtG0FtDzzzytG0CtC0C0FtGyCtC0ByB0D0F0ByE0CtAtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0FzzyEtDtCyD0CtGyE0EyEtCtGyEyCyC0CtG0AtA0DzytGtAtD0EyEtB0C0C0F0CyEtC0A2Q&cr=1231686440&ir= [Pays US - 50.19.213.45]
CHR StartupUrls: Default -> hxxp://vosteran.com/?f=7&a=vst_ggfc_15_05_ch&cd=2XzuyEtN2Y1L1QzutA0C0DzytB0ByDyD0D0B0CtC0B0B0F0FtN0D0Tzu0StCtCtByEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2StCzzzyyByByCzy0FtGzz0AtAyCtG0FtDzzzytG0CtC0C0FtGyCtC0ByB0D0F0ByE0CtAtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0FzzyEtDtCyD0CtGyE0EyEtCtGyEyCyC0CtG0AtA0DzytGtAtD0EyEtB0C0C0F0CyEtC0A2Q&cr=1231686440&ir= [Pays US - 54.235.99.6]
CHR DefaultSearchKeyword: Default -> vosteran.com
CHR DefaultSearchURL: Default -> http://vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ggfc_15_05_ch&cd=2XzuyEtN2Y1L1QzutA0C0DzytB0ByDyD0D0B0CtC0B0B0F0FtN0D0Tzu0StCtCtByEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2StCzzzyyByByCzy0FtGzz0AtAyCtG0FtDzzzytG0CtC0C0FtGyCtC0ByB0D0F0ByE0CtAtAzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0FzzyEtDtCyD0CtGyE0EyEtCtGyEyCyC0CtG0AtA0DzytGtAtD0EyEtB0C0C0F0CyEtC0A2Q&cr=1231686440&ir= [Pays US - 54.235.99.6]
CHR HKLM\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
CHR HKU\S-1-5-21-913213923-3936371392-864543947-1000\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
CHR HKLM-x32\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - No Path
R2 cYRvMth; C:\ProgramData\QFqicbLFM\cYRvMth.exe [2726256 2015-01-07] (Small Island Development)
2015-01-29 10:57 - 2015-01-29 10:57 - 00000000 ____D () C:\Users\sandra - françois\Documents\PC Speed Maximizer
2015-01-29 10:55 - 2015-01-29 11:05 - 00000000 ____D () C:\Users\sandra - françois\AppData\Local\Vosteran
2015-01-29 10:52 - 2015-01-29 11:16 - 00003300 _____ () C:\Windows\System32\Tasks\Digital Sites
2015-01-29 10:52 - 2015-01-29 11:16 - 00000322 _____ () C:\Windows\Tasks\Digital Sites.job
2015-01-29 10:52 - 2015-01-29 10:52 - 00000000 ____D () C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran
2015-01-29 10:52 - 2015-01-29 10:52 - 00000000 ____D () C:\Users\sandra - françois\AppData\Roaming\DigitalSites
2015-01-29 10:52 - 2015-01-29 10:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiPony
2015-01-29 10:26 - 2015-01-29 10:26 - 00000000 ____D () C:\Users\sandra - françois\AppData\Local\TVWizard
2015-01-07 16:42 - 2015-01-07 16:42 - 00003136 _____ () C:\Windows\System32\Tasks\{5FFB2D48-D301-4A2D-BACF-CA1E42A7973F}
2015-01-07 16:41 - 2015-01-07 16:41 - 00000008 _____ () C:\Users\sandra - françois\AppData\Roaming\Syshandle.txt
2015-01-07 16:40 - 2015-01-07 16:40 - 00000000 ____D () C:\Users\sandra - françois\AppData\Roaming\SystClean
2015-01-07 16:39 - 2015-01-07 16:40 - 00000000 ____D () C:\ProgramData\QFqicbLFM
2015-01-07 15:20 - 2015-01-07 15:20 - 00003488 _____ () C:\Windows\System32\Tasks\CleanerPro_Popup
2015-01-07 15:20 - 2015-01-07 15:20 - 00003224 _____ () C:\Windows\System32\Tasks\CleanerPro_Start
2015-01-07 15:19 - 2015-01-07 15:19 - 00846104 _____ ( ) C:\Users\sandra - françois\Downloads\Ccleaner_Setup.exe
2015-01-07 15:14 - 2015-01-07 15:14 - 00000000 ____D () C:\ProgramData\2355320829
2015-01-07 15:12 - 2015-01-07 15:12 - 00000000 ____D () C:\Program Files (x86)\e7d9f42f-5a57-4812-a09b-9d32e794b4bf
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_66 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\WSE_Vosteran => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\DelTr2394256 => value deleted successfully.
HKU\S-1-5-21-913213923-3936371392-864543947-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Infigo => value deleted successfully.
HKU\S-1-5-21-913213923-3936371392-864543947-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\DigitalSites => value deleted successfully.
HKU\S-1-5-21-913213923-3936371392-864543947-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\WSE_Vosteran => value deleted successfully.
HKU\S-1-5-21-913213923-3936371392-864543947-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\DelTr2394256 => value deleted successfully.
HKU\S-1-5-21-913213923-3936371392-864543947-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableLockWorkstation => value deleted successfully.
HKU\S-1-5-21-913213923-3936371392-864543947-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableChangePassword => value deleted successfully.
"HKU\S-1-5-21-913213923-3936371392-864543947-1000\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}" => Key deleted successfully.
Chrome HomePage deleted successfully.
Chrome StartupUrls deleted successfully.
Chrome DefaultSearchKeyword deleted successfully.
Chrome DefaultSearchURL deleted successfully.
"HKLM\SOFTWARE\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce" => Key deleted successfully.
"HKU\S-1-5-21-913213923-3936371392-864543947-1000\SOFTWARE\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce" => Key deleted successfully.
cYRvMth => Unable to stop service
cYRvMth => Service deleted successfully.
C:\Users\sandra - françois\Documents\PC Speed Maximizer => Moved successfully.
C:\Users\sandra - françois\AppData\Local\Vosteran => Moved successfully.
C:\Windows\System32\Tasks\Digital Sites => Moved successfully.
C:\Windows\Tasks\Digital Sites.job => Moved successfully.
C:\Users\sandra - françois\AppData\Roaming\WSE_Vosteran => Moved successfully.
C:\Users\sandra - françois\AppData\Roaming\DigitalSites => Moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiPony => Moved successfully.
C:\Users\sandra - françois\AppData\Local\TVWizard => Moved successfully.
C:\Windows\System32\Tasks\{5FFB2D48-D301-4A2D-BACF-CA1E42A7973F} => Moved successfully.
C:\Users\sandra - françois\AppData\Roaming\Syshandle.txt => Moved successfully.
C:\Users\sandra - françois\AppData\Roaming\SystClean => Moved successfully.
"C:\ProgramData\QFqicbLFM" directory move:
Could not move "C:\ProgramData\QFqicbLFM\cYRvMth.dat" => Scheduled to move on reboot.
C:\ProgramData\QFqicbLFM\cYRvMth.exe => Moved successfully.
C:\ProgramData\QFqicbLFM\cYRvMth.exe.config => Moved successfully.
Could not move "C:\ProgramData\QFqicbLFM\info.dat" => Scheduled to move on reboot.
Could not move "C:\ProgramData\QFqicbLFM\dat\hpfEgcnL.dll" => Scheduled to move on reboot.
Could not move "C:\ProgramData\QFqicbLFM\dat\kyYfBhOir.exe" => Scheduled to move on reboot.
Could not move "C:\ProgramData\QFqicbLFM\dat\kyYfBhOir.exe.config" => Scheduled to move on reboot.
Could not move "C:\ProgramData\QFqicbLFM\dat\SLEvWpx.exe" => Scheduled to move on reboot.
Could not move "C:\ProgramData\QFqicbLFM\dat\SLEvWpx.exe.config" => Scheduled to move on reboot.
Could not move "C:\ProgramData\QFqicbLFM\dat\tCmTGXeBhC.dll" => Scheduled to move on reboot.
Could not move "C:\ProgramData\QFqicbLFM" directory. => Scheduled to move on reboot.
C:\Windows\System32\Tasks\CleanerPro_Popup => Moved successfully.
C:\Windows\System32\Tasks\CleanerPro_Start => Moved successfully.
C:\Users\sandra - françois\Downloads\Ccleaner_Setup.exe => Moved successfully.
C:\ProgramData\2355320829 => Moved successfully.
C:\Program Files (x86)\e7d9f42f-5a57-4812-a09b-9d32e794b4bf => Moved successfully.
=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-01-29 12:24:21)<=
C:\ProgramData\QFqicbLFM\cYRvMth.dat => Is moved successfully.
C:\ProgramData\QFqicbLFM\info.dat => Is moved successfully.
C:\ProgramData\QFqicbLFM\dat\hpfEgcnL.dll => Is moved successfully.
C:\ProgramData\QFqicbLFM\dat\kyYfBhOir.exe => Is moved successfully.
C:\ProgramData\QFqicbLFM\dat\kyYfBhOir.exe.config => Is moved successfully.
C:\ProgramData\QFqicbLFM\dat\SLEvWpx.exe => Is moved successfully.
C:\ProgramData\QFqicbLFM\dat\SLEvWpx.exe.config => Is moved successfully.
C:\ProgramData\QFqicbLFM\dat\tCmTGXeBhC.dll => Is moved successfully.
C:\ProgramData\QFqicbLFM => Is moved successfully.
==== End of Fixlog 12:24:21 ====
29 janv. 2015 à 12:29
29 janv. 2015 à 12:33