Search Protect, publicités intempestives

Will -  
Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   -
Bonjour,



J'ai un serieux probleme avec mon internet explorer quand je consulte un site pleins de pub s'affichent, de l'aide S'il Vous Plait. Merci

11 réponses

  1. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Salut,

    Tu as installé des adwares et programmes parasites sur ton PC qui ouvrent des publicités et ralentissent l'ordinateur et les navigateurs WEB.
    Voici la procédure à suivre pour les supprimer :

    Commence par ceci :

    Suis le tutorial AdwCleaner https://www.malekal.com/adwcleaner-supprimer-virus-adwares-pup/?t=33839&start= ( d'Xplode )
    Télécharge le sur ton bureau ou dossier de téléchargement.
    Lance AdwCleaner, clique sur [Scanner].
    L'analyse peux durer plusieurs minutes, patiente.
    Une fois le scan terminé, ne décoche rien, clique sur [Nettoyer]

    Une fois le nettoyage terminé, un rapport s'ouvrira. Copie/colle le contenu du rapport dans ta prochaine réponse par un copier/coller.
    Si cela ne fonctionne pas, utilise le site http://pjjoint.malekal.com pour héberger le rapport, donne le lien du rapport dans un nouveau message.

    Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt

    puis :

    Suis ce tutoriel FRST: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/
    Télécharge et lance le scan FRST, cela va générer trois rapports FRST :
    * FRST.txt
    * Shortcut.txt
    * Additionnal.txt

    Envoie comme expliqué, ces trois rapports sur le site http://pjjoint.malekal.com et donne les trois liens pjjoint de ces rapports afin qu'ils puissent être consultés.

    2
  2. Wawa
     
    Desolé du retard voici le rapport Adwcleaner:

    # AdwCleaner v4.109 - Report created 05/02/2015 at 16:22:51
    # Updated 24/01/2015 by Xplode
    # Database : 2015-02-05.2 [Live]
    # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Username : WaWa - WAWA-PC
    # Running from : C:\Users\WaWa\Downloads\adwcleaner_4.109.exe
    # Option : Clean

    ***** [ Services ] *****

    Service Deleted : CltMngSvc
    Service Deleted : SPPD
    Service Deleted : Orbiter
    Service Deleted : Service Mgr PositiveFinds
    Service Deleted : Update Mgr PositiveFinds

    ***** [ Files / Folders ] *****

    Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
    Folder Deleted : C:\ProgramData\Partner
    Folder Deleted : C:\ProgramData\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602
    Folder Deleted : C:\Program Files (x86)\Conduit
    Folder Deleted : C:\Program Files (x86)\ICQ6Toolbar
    Folder Deleted : C:\Program Files (x86)\SearchProtect
    Folder Deleted : C:\Program Files (x86)\Vuze_Remote
    [#] Folder Deleted : C:\Program Files (x86)\ORBTR
    Folder Deleted : C:\Program Files (x86)\yuna software
    Folder Deleted : C:\Program Files (x86)\Positive Finds
    Folder Deleted : C:\Program Files (x86)\Common Files\d2d4a9d3-f3f1-4c52-8d3f-dddc91fe0602
    Folder Deleted : C:\Users\WaWa\AppData\Local\SearchProtect
    Folder Deleted : C:\Users\WaWa\AppData\LocalLow\Vuze_Remote
    Folder Deleted : C:\Users\WaWa\AppData\Roaming\OpenCandy
    Folder Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
    File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\Extensions\{27b7c23c-50cd-4b3c-a6c1-8e45175b2442}.xpi
    File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin.gif
    File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin.src
    File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin.xml
    File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-1.xml
    File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-10.xml
    File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-2.xml
    File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-3.xml
    File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-4.xml
    File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-5.xml
    File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-6.xml
    File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-7.xml
    File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-8.xml
    File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\icqplugin-9.xml
    File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\user.js
    File Deleted : C:\Users\WaWa\AppData\Roaming\Mozilla\Firefox\Profiles\9sbxvrt6.default\searchplugins\trovi.xml

    ***** [ Scheduled Tasks ] *****

    ***** [ Shortcuts ] *****

    ***** [ Registry ] *****

    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
    Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
    Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2504091
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{30C85A3D-1D96-4589-B63F-91FB7EF45A41}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{50F60937-910A-4C05-8E36-FE4E299191CF}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{63C63464-1423-4FDB-BA5D-6F75F491C63E}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30C85A3D-1D96-4589-B63F-91FB7EF45A41}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30C85A3D-1D96-4589-B63F-91FB7EF45A41}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30C85A3D-1D96-4589-B63F-91FB7EF45A41}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{50F60937-910A-4C05-8E36-FE4E299191CF}
    Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
    Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
    Key Deleted : HKCU\Software\Conduit
    Key Deleted : HKCU\Software\YahooPartnerToolbar
    Key Deleted : HKCU\Software\yuna software
    Key Deleted : HKCU\Software\CoinisRS
    Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
    Key Deleted : HKLM\SOFTWARE\ICQ\ICQToolbar
    Key Deleted : HKLM\SOFTWARE\SearchProtect
    Key Deleted : HKLM\SOFTWARE\Uniblue
    Key Deleted : HKLM\SOFTWARE\yuna software
    Key Deleted : HKLM\SOFTWARE\ORBTR
    Key Deleted : HKLM\SOFTWARE\SPPDCOM
    Key Deleted : HKLM\SOFTWARE\PositiveFinds
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Positive Finds
    Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll
    Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\icq.com
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\trovi.com
    Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local

    ***** [ Browsers ] *****

    -\\ Internet Explorer v11.0.9600.17496

    Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]

    -\\ Mozilla Firefox v34.0.5 (x86 fr)

    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("browser.newtab.url", "hxxp://www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=M016BD0CB-7889-4AEC-955B-C9184EC5DD47&SearchSource=69&CUI=&SSPV=&Lay=1&UM=8&UP=SP4F11C4BE-0782-4CE[...]
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultenginename", "Trovi");
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "Trovi");
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("browser.startup.homepage", "hxxp://www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=M016BD0CB-7889-4AEC-955B-C9184EC5DD47&SearchSource=55&CUI=&UM=8&UP=SP4F11C4BE-0782-4CED-B01B[...]
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.defSearchChange", true);
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.engineVerified", false);
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.firstTbRun", false);
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.geolastmodified", 1423171095);
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.history", "le%20finlandais%20spa71%2C%20de%20la%20Commune%20Ouest%2C%20Vieux-Montr%C3%A9al%20(Qu%C3%A9bec)%20H2Y%202C6fidoposte%20canadacilossimobinbasehijacked%3Fw[...]
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.icqgeo", 107);
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.installTime", "1346516301");
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.installsource", "1");
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.newtab_most_visited_state", "1");
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.newtab_recently_closed_state", "1");
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.newtab_state", "1");
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.numberOfSearches", 0);
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.previousFFVersion", "34.0.5");
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.skip_default_search", "no");
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.uniqueID", "129660586312966057231296726583690");
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.usageStatstTimestamp", 1423171097);
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.userEngineApproved", true);
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.version", "1.5.3");
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.voucherHideClicks", 0);
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.voucherRedeemClicks", 0);
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.voucherWasShown", 0);
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("icqtoolbar.xmlLanguage", "fr");
    [9sbxvrt6.default\prefs.js] - Line Deleted : user_pref("keyword.URL", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.5.3&q=");

    *************************

    AdwCleaner[R0].txt - [10221 octets] - [05/02/2015 16:20:47]
    AdwCleaner[S0].txt - [9876 octets] - [05/02/2015 16:22:51]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9936 octets] ##########
    0
    1. jeanbern Messages postés 13740 Date d'inscription   Statut Contributeur Dernière intervention   5 136
       
      salut,
      as tu nettoyé ?
      0
      1. lilidurhone Messages postés 800 Date d'inscription   Statut Contributeur sécurité Dernière intervention   3 818 > jeanbern Messages postés 13740 Date d'inscription   Statut Contributeur Dernière intervention  
         
        Tu ne sais pas lire....
        0
      2. jeanbern Messages postés 13740 Date d'inscription   Statut Contributeur Dernière intervention   5 136 > lilidurhone Messages postés 800 Date d'inscription   Statut Contributeur sécurité Dernière intervention  
         
        Désolé il y a déjà une mélange de pseudos alors !!!!!!
        0
  3. baladur13 Messages postés 47321 Date d'inscription   Statut Modérateur Dernière intervention   14 387
     
    Bonsoir Wawa
    Il serait préférable, pour la bonne compréhension de tous, de ne pas changer de pseudo en cours de route...
    Merci d'avance
    0
  4. Wawa
     
    Bonsoir,

    Excusez-moi mais je n'ai pas le choix il me disait de mettre un pseudo et j'ecrivais Will mais il ne voulait rien savoir. Bref Wawa et Will c'est moi c'est la meme personne... Et est-ce que vous pourriez répondre a la fin et non dans un post. Merci
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Les rapports FRST sont à donner via pjjoint, lire les instructions.
    0
  7. Will
     
    http://pjjoint.malekal.com/files.php?read=FRST_20150209_l7g11w5b13w15

    http://pjjoint.malekal.com/files.php?read=20150209_i13p11r10l9h6
    0
    1. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
       
      manque additionnal.txt
      0
  8. Will
     
    http://pjjoint.malekal.com/files.php?read=20150211_o9y5f14n12t12
    0
  9. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Voici la correction à effectuer avec FRST.
    Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix

    Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
    Copie/colle dedans ce qui suit :

    AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll [253200 2015-01-28] (Client Connect LTD)
    AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [219408 2015-01-28] (Client Connect LTD)
    R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [3505936 2015-01-28] (Client Connect LTD)
    2015-02-08 17:46 - 2015-02-08 17:46 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{4A688CF5-9633-4450-B80D-9057CDD25C38}
    2015-02-05 22:08 - 2015-02-05 22:08 - 00000000 ____D () C:\Users\WaWa\AppData\Local\SearchProtect
    2015-02-05 22:08 - 2015-02-05 22:08 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
    2015-02-08 18:00 - 2015-02-08 18:01 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
    2015-02-03 19:12 - 2015-02-03 19:12 - 00003452 _____ () C:\Windows\System32\Tasks\avaxvavya
    2015-02-03 19:11 - 2015-02-04 07:56 - 00000000 ____D () C:\Users\WaWa\AppData\Local\avaxvavya
    2015-02-03 18:42 - 2015-02-03 18:42 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{822C7191-F4F4-46CF-87DC-0D0C6DA7DDF6}
    2015-01-23 12:19 - 2015-01-23 12:20 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{FB2DE6C3-6888-4C62-84CC-C5220E644AB5}
    2015-01-17 14:19 - 2015-01-19 02:21 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{76719648-998F-4011-957D-545995C0EB19}
    2015-01-13 11:58 - 2015-01-15 00:00 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{9CE1411D-C25C-4907-B5BE-C1C17CBEA52E}
    2015-01-12 19:30 - 2015-01-12 19:30 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{C24DBD3B-D0CF-48FE-A3F9-3D70B6C27440}
    Task: {BB98ADDE-8A20-44E0-9025-09CC8709C907} - System32\Tasks\avaxvyyvyf => C:\Users\WaWa\AppData\Local\avaxvyyvyf\avaxvyyvyf.exe [2015-02-02] ()

    Une fois, le texte coller dans le bloc-note.
    Menu Fichier puis Enregistrer sous.
    A gauche, place toi sur le bureau.
    Dans le champs en bas, nom du fichier mets : fixlist.txt
    Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.

    Relance FRST et clic sur le bouton Fix
    Selon comment un redémarrage est nécessaire (pas obligatoire).
    Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.

    Redémarre l'ordinateur

    Like the angel you are, you laugh creating a lightness in my chest,
    Your eyes they penetrate me,
    (Your answer's always 'maybe')
    That's when I got up and left
    0
  10. Will
     
    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-02-2015 02
    Ran by WaWa at 2015-02-12 22:47:23 Run:1
    Running from C:\Users\WaWa\Desktop
    Loaded Profiles: WaWa (Available profiles: WaWa)
    Boot Mode: Normal
    ==============================================

    Content of fixlist:
    AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll [253200 2015-01-28] (Client Connect LTD)
    AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [219408 2015-01-28] (Client Connect LTD)
    R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [3505936 2015-01-28] (Client Connect LTD)
    2015-02-08 17:46 - 2015-02-08 17:46 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{4A688CF5-9633-4450-B80D-9057CDD25C38}
    2015-02-05 22:08 - 2015-02-05 22:08 - 00000000 ____D () C:\Users\WaWa\AppData\Local\SearchProtect
    2015-02-05 22:08 - 2015-02-05 22:08 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
    2015-02-08 18:00 - 2015-02-08 18:01 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
    2015-02-03 19:12 - 2015-02-03 19:12 - 00003452 _____ () C:\Windows\System32\Tasks\avaxvavya
    2015-02-03 19:11 - 2015-02-04 07:56 - 00000000 ____D () C:\Users\WaWa\AppData\Local\avaxvavya
    2015-02-03 18:42 - 2015-02-03 18:42 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{822C7191-F4F4-46CF-87DC-0D0C6DA7DDF6}
    2015-01-23 12:19 - 2015-01-23 12:20 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{FB2DE6C3-6888-4C62-84CC-C5220E644AB5}
    2015-01-17 14:19 - 2015-01-19 02:21 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{76719648-998F-4011-957D-545995C0EB19}
    2015-01-13 11:58 - 2015-01-15 00:00 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{9CE1411D-C25C-4907-B5BE-C1C17CBEA52E}
    2015-01-12 19:30 - 2015-01-12 19:30 - 00000000 ____D () C:\Users\WaWa\AppData\Local\{C24DBD3B-D0CF-48FE-A3F9-3D70B6C27440}
    Task: {BB98ADDE-8A20-44E0-9025-09CC8709C907} - System32\Tasks\avaxvyyvyf => C:\Users\WaWa\AppData\Local\avaxvyyvyf\avaxvyyvyf.exe [2015-02-02] ()

    "C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll" => Value Data removed successfully.
    "C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll" => Value Data removed successfully.
    CltMngSvc => Service stopped successfully.
    CltMngSvc => Service deleted successfully.
    C:\Users\WaWa\AppData\Local\{4A688CF5-9633-4450-B80D-9057CDD25C38} => Moved successfully.
    C:\Users\WaWa\AppData\Local\SearchProtect => Moved successfully.
    C:\Program Files (x86)\SearchProtect => Moved successfully.
    C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 => Moved successfully.
    "C:\Windows\System32\Tasks\avaxvavya" => File/Directory not found.
    "C:\Users\WaWa\AppData\Local\avaxvavya" => File/Directory not found.
    C:\Users\WaWa\AppData\Local\{822C7191-F4F4-46CF-87DC-0D0C6DA7DDF6} => Moved successfully.
    C:\Users\WaWa\AppData\Local\{FB2DE6C3-6888-4C62-84CC-C5220E644AB5} => Moved successfully.
    C:\Users\WaWa\AppData\Local\{76719648-998F-4011-957D-545995C0EB19} => Moved successfully.
    C:\Users\WaWa\AppData\Local\{9CE1411D-C25C-4907-B5BE-C1C17CBEA52E} => Moved successfully.
    C:\Users\WaWa\AppData\Local\{C24DBD3B-D0CF-48FE-A3F9-3D70B6C27440} => Moved successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BB98ADDE-8A20-44E0-9025-09CC8709C907}" => Key deleted successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BB98ADDE-8A20-44E0-9025-09CC8709C907}" => Key deleted successfully.
    C:\Windows\System32\Tasks\avaxvyyvyf => Moved successfully.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avaxvyyvyf" => Key deleted successfully.

    End of Fixlog 22:47:27

    0
  11. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :

    Vois ce que cela donne.
    0