Search Protect, publicités intempestives

Will -  
Malekal_morte- Messages postés 180304 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   -
Bonjour,





J'ai un serieux probleme avec mon internet explorer quand je consulte un site pleins de pub s'affichent, de l'aide S'il Vous Plait. Merci
A voir également:

11 réponses

Malekal_morte- Messages postés 180304 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 685
 
Salut,

Tu as installé des adwares et programmes parasites sur ton PC qui ouvrent des publicités et ralentissent l'ordinateur et les navigateurs WEB.
Voici la procédure à suivre pour les supprimer :

Commence par ceci :

Suis le tutorial AdwCleaner https://www.malekal.com/adwcleaner-supprimer-virus-adwares-pup/?t=33839&start= ( d'Xplode )
Télécharge le sur ton bureau ou dossier de téléchargement.
Lance AdwCleaner, clique sur [Scanner].
L'analyse peux durer plusieurs minutes, patiente.
Une fois le scan terminé, ne décoche rien, clique sur [Nettoyer]

Une fois le nettoyage terminé, un rapport s'ouvrira. Copie/colle le contenu du rapport dans ta prochaine réponse par un copier/coller.
Si cela ne fonctionne pas, utilise le site http://pjjoint.malekal.com pour héberger le rapport, donne le lien du rapport dans un nouveau message.

Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt


puis :

Suis ce tutoriel FRST: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/
Télécharge et lance le scan FRST, cela va générer trois rapports FRST :
* FRST.txt
* Shortcut.txt
* Additionnal.txt

Envoie comme expliqué, ces trois rapports sur le site http://pjjoint.malekal.com et donne les trois liens pjjoint de ces rapports afin qu'ils puissent être consultés.



2
Wawa
 
Desolé du retard voici le rapport Adwcleaner:

# AdwCleaner v4.109 - Report created 05/02/2015 at 16:22:51
# Updated 24/01/2015 by Xplode
# Database : 2015-02-05.2 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : WaWa - WAWA-PC
# Running from : C:\Users\WaWa\Downloads\adwcleaner_4.109.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : CltMngSvc
Service Deleted : SPPD
Service Deleted : Orbiter
Service Deleted : Service Mgr PositiveFinds
Service Deleted : Update Mgr PositiveFinds

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\ProgramData\Partner
Folder Deleted : C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\ICQ6Toolbar
Folder Deleted : C:\Program Files (x86)\SearchProtect
Folder Deleted : C:\Program Files (x86)\Vuze_Remote
[#] Folder Deleted : C:\Program Files (x86)\ORBTR
Folder Deleted : C:\Program Files (x86)\yuna software
Folder Deleted : C:\Program Files (x86)\Positive Finds
Folder Deleted : C:\Program Files (x86)\Common Files\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602
Folder Deleted : C:\Users\WaWa\AppData\Local\SearchProtect
Folder Deleted : C:\Users\WaWa\AppData\LocalLow\Vuze_Remote
Folder Deleted : C:\Users\WaWa\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\Extensions\{27b7c23c-50cd-4b3c-a6c1-8e45175b2442}.xpi
File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin.gif
File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin.src
File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin.xml
File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-1.xml
File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-10.xml
File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-2.xml
File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-3.xml
File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-4.xml
File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-5.xml
File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-6.xml
File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-7.xml
File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-8.xml
File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-9.xml
File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\user.js
File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\trovi.xml

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2504091
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{30C85A3D-1D96-4589-B63F-91FB7EF45A41}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{50F60937-910A-4C05-8E36-FE4E299191CF}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{63C63464-1423-4FDB-BA5D-6F75F491C63E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30C85A3D-1D96-4589-B63F-91FB7EF45A41}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30C85A3D-1D96-4589-B63F-91FB7EF45A41}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30C85A3D-1D96-4589-B63F-91FB7EF45A41}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{50F60937-910A-4C05-8E36-FE4E299191CF}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\yuna software
Key Deleted : HKCU\Software\CoinisRS
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKLM\SOFTWARE\ICQ\ICQToolbar
Key Deleted : HKLM\SOFTWARE\SearchProtect
Key Deleted : HKLM\SOFTWARE\Uniblue
Key Deleted : HKLM\SOFTWARE\yuna software
Key Deleted : HKLM\SOFTWARE\ORBTR
Key Deleted : HKLM\SOFTWARE\SPPDCOM
Key Deleted : HKLM\SOFTWARE\PositiveFinds
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Positive Finds
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll
Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\icq.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\trovi.com
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17496

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]

-\\ Mozilla Firefox v34.0.5 (x86 fr)

[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("browser.newtab.url", "hxxp://www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=M016BD0CB-7889-4AEC-955B-C9184EC5DD47&SearchSource=69&CUI=&SSPV=&Lay=1&UM=8&UP=SP4F11C4BE-0782-4CE[...]
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultenginename", "Trovi");
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "Trovi");
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("browser.startup.homepage", "hxxp://www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=M016BD0CB-7889-4AEC-955B-C9184EC5DD47&SearchSource=55&CUI=&UM=8&UP=SP4F11C4BE-0782-4CED-B01B[...]
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.defSearchChange", true);
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.engineVerified", false);
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.firstTbRun", false);
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.geolastmodified", 1423171095);
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.history", "le%20finlandais%20spa71%2C%20de%20la%20Commune%20Ouest%2C%20Vieux-Montr%C3%A9al%20(Qu%C3%A9bec)%20H2Y%202C6fidoposte%20canadacilossimobinbasehijacked%3Fw[...]
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.icqgeo", 107);
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.installTime", "1346516301");
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.installsource", "1");
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.newtab_most_visited_state", "1");
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.newtab_recently_closed_state", "1");
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.newtab_state", "1");
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.numberOfSearches", 0);
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.previousFFVersion", "34.0.5");
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.skip_default_search", "no");
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.uniqueID", "129660586312966057231296726583690");
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.usageStatstTimestamp", 1423171097);
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.userEngineApproved", true);
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.version", "1.5.3");
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.voucherHideClicks", 0);
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.voucherRedeemClicks", 0);
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.voucherWasShown", 0);
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.xmlLanguage", "fr");
[9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("keyword.URL", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.5.3&q=");

*************************

AdwCleaner[R0].txt - [10221 octets] - [05/02/2015 16:20:47]
AdwCleaner[S0].txt - [9876 octets] - [05/02/2015 16:22:51]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9936 octets] ##########
0
jeanbern Messages postés 13848 Date d'inscription   Statut Contributeur Dernière intervention   4 985
 
salut,
as tu nettoyé ?
0
lilidurhone Messages postés 43355 Date d'inscription   Statut Contributeur sécurité Dernière intervention   3 807 > jeanbern Messages postés 13848 Date d'inscription   Statut Contributeur Dernière intervention  
 
Tu ne sais pas lire....
0
jeanbern Messages postés 13848 Date d'inscription   Statut Contributeur Dernière intervention   4 985 > lilidurhone Messages postés 43355 Date d'inscription   Statut Contributeur sécurité Dernière intervention  
 
Désolé il y a déjà une mélange de pseudos alors !!!!!!
0
baladur13 Messages postés 47834 Date d'inscription   Statut Modérateur Dernière intervention   13 692
 
Bonsoir Wawa
Il serait préférable, pour la bonne compréhension de tous, de ne pas changer de pseudo en cours de route...
Merci d'avance
0
Wawa
 
Bonsoir,

Excusez-moi mais je n'ai pas le choix il me disait de mettre un pseudo et j'ecrivais Will mais il ne voulait rien savoir. Bref Wawa et Will c'est moi c'est la meme personne... Et est-ce que vous pourriez répondre a la fin et non dans un post. Merci
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Malekal_morte- Messages postés 180304 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 685
 
Les rapports FRST sont à donner via pjjoint, lire les instructions.
0
Will
 
http://pjjoint.malekal.com/files.php?read=FRST_20150209_l7g11w5b13w15

http://pjjoint.malekal.com/files.php?read=20150209_i13p11r10l9h6
0
Malekal_morte- Messages postés 180304 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 685
 
manque additionnal.txt
0
Will
 
http://pjjoint.malekal.com/files.php?read=20150211_o9y5f14n12t12
0
Malekal_morte- Messages postés 180304 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 685
 
Voici la correction à effectuer avec FRST.
Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix

Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
Copie/colle dedans ce qui suit :


AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll [253200 2015-01-28] (Client Connect LTD)
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [219408 2015-01-28] (Client Connect LTD)
R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [3505936 2015-01-28] (Client Connect LTD)
2015-02-08 17:46 - 2015-02-08 17:46 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{4A688CF5-9633-4450-B80D-9057CDD25C38}
2015-02-05 22:08 - 2015-02-05 22:08 - 00000000 ____D () C:\Users\WaWa\AppData\Local\SearchProtect
2015-02-05 22:08 - 2015-02-05 22:08 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
2015-02-08 18:00 - 2015-02-08 18:01 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-02-03 19:12 - 2015-02-03 19:12 - 00003452 _____ () C:\Windows\System32\Tasks\avaxvavya
2015-02-03 19:11 - 2015-02-04 07:56 - 00000000 ____D () C:\Users\WaWa\AppData\Local\avaxvavya
2015-02-03 18:42 - 2015-02-03 18:42 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{822C7191-F4F4-46CF-87DC-0D0C6DA7DDF6}
2015-01-23 12:19 - 2015-01-23 12:20 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{FB2DE6C3-6888-4C62-84CC-C5220E644AB5}
2015-01-17 14:19 - 2015-01-19 02:21 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{76719648-998F-4011-957D-545995C0EB19}
2015-01-13 11:58 - 2015-01-15 00:00 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{9CE1411D-C25C-4907-B5BE-C1C17CBEA52E}
2015-01-12 19:30 - 2015-01-12 19:30 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{C24DBD3B-D0CF-48FE-A3F9-3D70B6C27440}
Task: {BB98ADDE-8A20-44E0-9025-09CC8709C907} - System32\Tasks\avaxvyyvyf => C:\Users\WaWa\AppData\Local\avaxvyyvyf\avaxvyyvyf.exe [2015-02-02] ()


Une fois, le texte coller dans le bloc-note.
Menu Fichier puis Enregistrer sous.
A gauche, place toi sur le bureau.
Dans le champs en bas, nom du fichier mets : fixlist.txt
Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.

Relance FRST et clic sur le bouton Fix
Selon comment un redémarrage est nécessaire (pas obligatoire).
Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.

Redémarre l'ordinateur


Like the angel you are, you laugh creating a lightness in my chest,
Your eyes they penetrate me,
(Your answer's always 'maybe')
That's when I got up and left
0
Will
 
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-02-2015 02
Ran by WaWa at 2015-02-12 22:47:23 Run:1
Running from C:\Users\WaWa\Desktop
Loaded Profiles: WaWa (Available profiles: WaWa)
Boot Mode: Normal
==============================================

Content of fixlist:

AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll [253200 2015-01-28] (Client Connect LTD)
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [219408 2015-01-28] (Client Connect LTD)
R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [3505936 2015-01-28] (Client Connect LTD)
2015-02-08 17:46 - 2015-02-08 17:46 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{4A688CF5-9633-4450-B80D-9057CDD25C38}
2015-02-05 22:08 - 2015-02-05 22:08 - 00000000 ____D () C:\Users\WaWa\AppData\Local\SearchProtect
2015-02-05 22:08 - 2015-02-05 22:08 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
2015-02-08 18:00 - 2015-02-08 18:01 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-02-03 19:12 - 2015-02-03 19:12 - 00003452 _____ () C:\Windows\System32\Tasks\avaxvavya
2015-02-03 19:11 - 2015-02-04 07:56 - 00000000 ____D () C:\Users\WaWa\AppData\Local\avaxvavya
2015-02-03 18:42 - 2015-02-03 18:42 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{822C7191-F4F4-46CF-87DC-0D0C6DA7DDF6}
2015-01-23 12:19 - 2015-01-23 12:20 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{FB2DE6C3-6888-4C62-84CC-C5220E644AB5}
2015-01-17 14:19 - 2015-01-19 02:21 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{76719648-998F-4011-957D-545995C0EB19}
2015-01-13 11:58 - 2015-01-15 00:00 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{9CE1411D-C25C-4907-B5BE-C1C17CBEA52E}
2015-01-12 19:30 - 2015-01-12 19:30 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{C24DBD3B-D0CF-48FE-A3F9-3D70B6C27440}
Task: {BB98ADDE-8A20-44E0-9025-09CC8709C907} - System32\Tasks\avaxvyyvyf => C:\Users\WaWa\AppData\Local\avaxvyyvyf\avaxvyyvyf.exe [2015-02-02] ()


"C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll" => Value Data removed successfully.
"C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll" => Value Data removed successfully.
CltMngSvc => Service stopped successfully.
CltMngSvc => Service deleted successfully.
C:\Users\WaWa\AppData\Local\{4A688CF5-9633-4450-B80D-9057CDD25C38} => Moved successfully.
C:\Users\WaWa\AppData\Local\SearchProtect => Moved successfully.
C:\Program Files (x86)\SearchProtect => Moved successfully.
C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 => Moved successfully.
"C:\Windows\System32\Tasks\avaxvavya" => File/Directory not found.
"C:\Users\WaWa\AppData\Local\avaxvavya" => File/Directory not found.
C:\Users\WaWa\AppData\Local\{822C7191-F4F4-46CF-87DC-0D0C6DA7DDF6} => Moved successfully.
C:\Users\WaWa\AppData\Local\{FB2DE6C3-6888-4C62-84CC-C5220E644AB5} => Moved successfully.
C:\Users\WaWa\AppData\Local\{76719648-998F-4011-957D-545995C0EB19} => Moved successfully.
C:\Users\WaWa\AppData\Local\{9CE1411D-C25C-4907-B5BE-C1C17CBEA52E} => Moved successfully.
C:\Users\WaWa\AppData\Local\{C24DBD3B-D0CF-48FE-A3F9-3D70B6C27440} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BB98ADDE-8A20-44E0-9025-09CC8709C907}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BB98ADDE-8A20-44E0-9025-09CC8709C907}" => Key deleted successfully.
C:\Windows\System32\Tasks\avaxvyyvyf => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avaxvyyvyf" => Key deleted successfully.

End of Fixlog 22:47:27

0
Malekal_morte- Messages postés 180304 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 685
 
Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :


Vois ce que cela donne.
0
jeanbern Messages postés 13848 Date d'inscription   Statut Contributeur Dernière intervention   4 985
 
Salut,
Commence déjà par cela : https://adblockplus.org/fr/
-1