J'ai attrapé Mystart search depuis...
chris74600
Messages postés
10
Date d'inscription
Statut
Membre
Dernière intervention
-
juju666 Messages postés 35446 Date d'inscription Statut Contributeur sécurité Dernière intervention -
juju666 Messages postés 35446 Date d'inscription Statut Contributeur sécurité Dernière intervention -
Bonjour,
Il y a 15 jours j'ai attrapé my strat search, j'ai réussi à l'enlever j'ai utilisé Malwarebytes puis adwcleaner mais voilà depuis mon ordi rame beaucoup et je me dis qu'il y a peut-être quelque chose d'autres... quelqu'un pour m'aider?
Merci beaucoup.
Il y a 15 jours j'ai attrapé my strat search, j'ai réussi à l'enlever j'ai utilisé Malwarebytes puis adwcleaner mais voilà depuis mon ordi rame beaucoup et je me dis qu'il y a peut-être quelque chose d'autres... quelqu'un pour m'aider?
Merci beaucoup.
A voir également:
- J'ai attrapé Mystart search depuis...
- Spybot search and destroy - Télécharger - Antivirus & Antimalwares
- Www.google.com search video download - Télécharger - TV & Vidéo
- Search tool - Télécharger - Divers Web & Internet
- IP-Tools Lite - Télécharger - Web & Internet
- Music search mp3 - Télécharger - Conversion & Extraction
6 réponses
Salut,
▶ Télécharge ici : FRST (de Farbar)
!!! En fonction de ta version de Windows, prends la "32-Bit Version" ou la "64-Bit Version" !!!
Aide : va dans Démarrer > Panneau de configuration > Système pour savoir si tu es sous 32 bits ou 64 bits.
▶ Double-clique sur l'icône FRST.exe pour lancer le programme. (Sous Windows Vista, 7 et 8, il faut faire un clic droit dessus, puis exécuter en tant qu'administrateur.) Clique ensuite sur Oui lorsqu'un message d'avertissement (Disclaimer) s'affiche.
▶ Sur le menu principal, clique sur le bouton Scan et patiente le temps de l'analyse.
▶ A la fin du scan, deux rapports s'affichent, FRST.txt et Addition.txt Poste les rapports dans ta prochaine réponse.
Les rapport se trouvent ici : C:\FRST\Logs
▶ Envoie-les sur http://pjjoint.malekal.com et poste les liens obtenus en échange.
▶ Télécharge ici : FRST (de Farbar)
!!! En fonction de ta version de Windows, prends la "32-Bit Version" ou la "64-Bit Version" !!!
Aide : va dans Démarrer > Panneau de configuration > Système pour savoir si tu es sous 32 bits ou 64 bits.
▶ Double-clique sur l'icône FRST.exe pour lancer le programme. (Sous Windows Vista, 7 et 8, il faut faire un clic droit dessus, puis exécuter en tant qu'administrateur.) Clique ensuite sur Oui lorsqu'un message d'avertissement (Disclaimer) s'affiche.
▶ Sur le menu principal, clique sur le bouton Scan et patiente le temps de l'analyse.
▶ A la fin du scan, deux rapports s'affichent, FRST.txt et Addition.txt Poste les rapports dans ta prochaine réponse.
Les rapport se trouvent ici : C:\FRST\Logs
▶ Envoie-les sur http://pjjoint.malekal.com et poste les liens obtenus en échange.
Bien, j'ai vu et analysé les deux documents.
Il ya effectivement une correction à effectuer, la voici :
▶ /!\ Crée un point de restauration manuel avant d'appliquer le correctif - Tutoriel en images/!\
▶ Ouvre le Bloc-notes (Démarrer => Tous les programmes => Accessoires => Bloc-notes)
▶ Copie/colle la totalité du contenu de la zone Code ci-dessous dans le Bloc-notes
▶ Enregistre le fichier sur ton Bureau (au même endroit que FRST) sous le nom fixlist.txt
▶ Ferme toutes les applications, y compris ton navigateur
▶ Double-clique sur FRST.exe
/!\ Sous Vista, Windows 7 et 8, il faut lancer le fichier par clic-droit -> Exécuter en tant qu'administrateur
▶ Sur le menu principal, clique une seule fois sur Fix et patiente le temps de la correction
▶ L'outil va créer un rapport de correction Fixlog.txt. Poste ce rapport dans ta réponse.
▶ /!\ Ce script a été établi pour cet utilisateur, il ne doit, en aucun cas, être appliqué sur un autre système, au risque de provoquer de graves dysfonctionnement et endommager Windows /!\
L'ordinateur va redémarrer automatiquement après la procédure, c'est normal.
A tout à l'heure.
Il ya effectivement une correction à effectuer, la voici :
▶ /!\ Crée un point de restauration manuel avant d'appliquer le correctif - Tutoriel en images/!\
▶ Ouvre le Bloc-notes (Démarrer => Tous les programmes => Accessoires => Bloc-notes)
▶ Copie/colle la totalité du contenu de la zone Code ci-dessous dans le Bloc-notes
start
(PC Utilities Software Limited) C:\ProgramData\{290602b1-94d5-f4af-2906-602b194d0ac6}\hqghumeaylnlf.exe
Startup: C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk [2015-05-07]
ShortcutTarget: hqghumeaylnlf.lnk -> C:\ProgramData\{290602b1-94d5-f4af-2906-602b194d0ac6}\hqghumeaylnlf.exe (PC Utilities Software Limited)
2015-05-15 09:59 - 2015-05-15 09:59 - 00000000 ____D () C:\15653a8e7d2a8d1e93535758d48d
2015-05-07 19:28 - 2015-05-07 19:28 - 00000000 ____D () C:\ProgramData\d554bfb4000078d5
2015-05-07 18:38 - 2015-05-07 18:38 - 00000000 ____D () C:\Users\Chris\Documents\Optimizer Pro
2015-05-07 18:32 - 2015-05-13 07:09 - 00000000 ____D () C:\ProgramData\{290602b1-94d5-f4af-2906-602b194d0ac6}
2015-05-01 23:13 - 2015-05-02 09:57 - 00000000 ____D () C:\Users\Chris\AppData\Local\20551
2015-05-01 21:23 - 2015-05-16 10:56 - 00001024 _____ () C:\WINDOWS\Tasks\dB33E7CnWQb5bDHfgS.job
2015-05-01 21:23 - 2015-05-16 10:56 - 00001016 _____ () C:\WINDOWS\Tasks\Tchje7bQculxP6.job
2015-05-01 21:23 - 2015-05-01 21:23 - 00004030 _____ () C:\WINDOWS\System32\Tasks\dB33E7CnWQb5bDHfgS
2015-05-01 21:23 - 2015-05-01 21:23 - 00004020 _____ () C:\WINDOWS\System32\Tasks\Tchje7bQculxP6
2015-05-01 21:22 - 2015-05-02 09:57 - 00000000 ____D () C:\Program Files (x86)\42eadb88-130e-4cee-aab6-d0064be565fc
2015-05-01 13:26 - 2015-05-01 13:31 - 00000000 ____D () C:\Program Files (x86)\Software
2015-05-01 13:26 - 2015-05-01 13:26 - 00000000 ____D () C:\Users\Chris\AppData\Local\Software
2015-05-01 11:36 - 2015-05-16 10:56 - 00001040 _____ () C:\WINDOWS\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI.job
2015-05-01 11:36 - 2015-05-16 10:56 - 00001024 _____ () C:\WINDOWS\Tasks\rSDUW7BbgGiSrVMrdh.job
2015-05-01 11:36 - 2015-05-01 11:36 - 00004044 _____ () C:\WINDOWS\System32\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI
2015-05-01 11:36 - 2015-05-01 11:36 - 00004028 _____ () C:\WINDOWS\System32\Tasks\rSDUW7BbgGiSrVMrdh
2015-05-01 11:26 - 2015-05-01 11:26 - 00004012 _____ () C:\WINDOWS\System32\Tasks\JtBudg1Ww
2015-05-01 11:25 - 2015-05-16 10:56 - 00001006 _____ () C:\WINDOWS\Tasks\JtBudg1Ww.job
2015-05-01 11:25 - 2015-05-01 11:25 - 00004022 _____ () C:\WINDOWS\System32\Tasks\2nOJkR5Ifg0tiD9
2015-05-01 11:24 - 2015-05-16 10:56 - 00001018 _____ () C:\WINDOWS\Tasks\2nOJkR5Ifg0tiD9.job
2015-05-01 11:23 - 2015-05-15 16:53 - 00000000 ___HD () C:\ProgramData\dqx
2015-05-01 11:23 - 2015-05-02 09:25 - 00000004 _____ () C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-05-01 11:21 - 2015-05-01 12:44 - 00000000 ____D () C:\ProgramData\fkDykAiFI
2015-05-01 11:20 - 2015-05-01 11:20 - 00631296 _____ () C:\WINDOWS\dqx.dat
2015-04-19 14:20 - 2015-04-19 14:20 - 00005872 _____ () C:\Users\Chris\AppData\Roaming\rSDUW7BbgGiSrVMrdh
2015-04-19 14:20 - 2015-04-19 14:20 - 00005872 _____ () C:\Users\Chris\AppData\Roaming\dB33E7CnWQb5bDHfgS
2015-04-19 14:20 - 2015-04-19 14:20 - 00005872 _____ () C:\Users\Chris\AppData\Roaming\2nOJkR5Ifg0tiD9
2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Chris\AppData\Roaming\JtBudg1Ww
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\Chris\AppData\Roaming\rSDUW7BbgGiSrVMrdh
2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Chris\AppData\Roaming\Tchje7bQculxP6
Task: {0C55E23C-74DA-48F0-BA5A-74F139D893E3} - System32\Tasks\rSDUW7BbgGiSrVMrdh => C:\Users\Chris\AppData\Roaming\rSDUW7BbgGiSrVMrdh.exe <==== ATTENTION
Task: {71C54FF4-0F3B-498E-A151-D6A28D067BA2} - System32\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI => C:\Users\Chris\AppData\Roaming\EDukLGr3CcgwcayS3f8ZnmeBBI.exe <==== ATTENTION
Task: {AC6032E7-A042-4ADE-9315-592B6FF67455} - System32\Tasks\JtBudg1Ww => C:\Users\Chris\AppData\Roaming\JtBudg1Ww.exe <==== ATTENTION
Task: {AD86DBD8-D2FE-4354-876C-520B9A19B221} - System32\Tasks\Tchje7bQculxP6 => C:\Users\Chris\AppData\Roaming\Tchje7bQculxP6.exe <==== ATTENTION
Task: {D48D1B75-4117-4FD2-A8E1-798C09062925} - System32\Tasks\dB33E7CnWQb5bDHfgS => C:\Users\Chris\AppData\Roaming\dB33E7CnWQb5bDHfgS.exe <==== ATTENTION
Task: {E3CA6DF4-86CD-4C24-B13E-B00E19B548AE} - System32\Tasks\2nOJkR5Ifg0tiD9 => C:\Users\Chris\AppData\Roaming\2nOJkR5Ifg0tiD9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\2nOJkR5Ifg0tiD9.job => C:\Users\Chris\AppData\Roaming\2nOJkR5Ifg0tiD9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\dB33E7CnWQb5bDHfgS.job => C:\Users\Chris\AppData\Roaming\dB33E7CnWQb5bDHfgS.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI.job => C:\Users\Chris\AppData\Roaming\EDukLGr3CcgwcayS3f8ZnmeBBI.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\JtBudg1Ww.job => C:\Users\Chris\AppData\Roaming\JtBudg1Ww.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\rSDUW7BbgGiSrVMrdh.job => C:\Users\Chris\AppData\Roaming\rSDUW7BbgGiSrVMrdh.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Tchje7bQculxP6.job => C:\Users\Chris\AppData\Roaming\Tchje7bQculxP6.exe <==== ATTENTION
CMD: del /F /Q C:\Users\Chris\AppData\Roaming\*.exe
EmptyTemp:
end
▶ Enregistre le fichier sur ton Bureau (au même endroit que FRST) sous le nom fixlist.txt
▶ Ferme toutes les applications, y compris ton navigateur
▶ Double-clique sur FRST.exe
/!\ Sous Vista, Windows 7 et 8, il faut lancer le fichier par clic-droit -> Exécuter en tant qu'administrateur
▶ Sur le menu principal, clique une seule fois sur Fix et patiente le temps de la correction
▶ L'outil va créer un rapport de correction Fixlog.txt. Poste ce rapport dans ta réponse.
▶ /!\ Ce script a été établi pour cet utilisateur, il ne doit, en aucun cas, être appliqué sur un autre système, au risque de provoquer de graves dysfonctionnement et endommager Windows /!\
L'ordinateur va redémarrer automatiquement après la procédure, c'est normal.
A tout à l'heure.
Voici le rapport :
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-05-2015 02
Ran by Chris at 2015-05-16 17:58:55 Run:2
Running from C:\Users\Chris\Downloads
Loaded Profiles: Chris (Available profiles: Chris & Administrateur)
Boot Mode: Normal
==============================================
Content of fixlist:
start
(PC Utilities Software Limited) C:\ProgramData\{290602b1-94d5-f4af-2906-602b194d0ac6}\hqghumeaylnlf.exe
Startup: C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk [2015-05-07]
ShortcutTarget: hqghumeaylnlf.lnk -> C:\ProgramData\{290602b1-94d5-f4af-2906-602b194d0ac6}\hqghumeaylnlf.exe (PC Utilities Software Limited)
2015-05-15 09:59 - 2015-05-15 09:59 - 00000000 ____D () C:\15653a8e7d2a8d1e93535758d48d
2015-05-07 19:28 - 2015-05-07 19:28 - 00000000 ____D () C:\ProgramData\d554bfb4000078d5
2015-05-07 18:38 - 2015-05-07 18:38 - 00000000 ____D () C:\Users\Chris\Documents\Optimizer Pro
2015-05-07 18:32 - 2015-05-13 07:09 - 00000000 ____D () C:\ProgramData\{290602b1-94d5-f4af-2906-602b194d0ac6}
2015-05-01 23:13 - 2015-05-02 09:57 - 00000000 ____D () C:\Users\Chris\AppData\Local\20551
2015-05-01 21:23 - 2015-05-16 10:56 - 00001024 _____ () C:\WINDOWS\Tasks\dB33E7CnWQb5bDHfgS.job
2015-05-01 21:23 - 2015-05-16 10:56 - 00001016 _____ () C:\WINDOWS\Tasks\Tchje7bQculxP6.job
2015-05-01 21:23 - 2015-05-01 21:23 - 00004030 _____ () C:\WINDOWS\System32\Tasks\dB33E7CnWQb5bDHfgS
2015-05-01 21:23 - 2015-05-01 21:23 - 00004020 _____ () C:\WINDOWS\System32\Tasks\Tchje7bQculxP6
2015-05-01 21:22 - 2015-05-02 09:57 - 00000000 ____D () C:\Program Files (x86)\42eadb88-130e-4cee-aab6-d0064be565fc
2015-05-01 13:26 - 2015-05-01 13:31 - 00000000 ____D () C:\Program Files (x86)\Software
2015-05-01 13:26 - 2015-05-01 13:26 - 00000000 ____D () C:\Users\Chris\AppData\Local\Software
2015-05-01 11:36 - 2015-05-16 10:56 - 00001040 _____ () C:\WINDOWS\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI.job
2015-05-01 11:36 - 2015-05-16 10:56 - 00001024 _____ () C:\WINDOWS\Tasks\rSDUW7BbgGiSrVMrdh.job
2015-05-01 11:36 - 2015-05-01 11:36 - 00004044 _____ () C:\WINDOWS\System32\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI
2015-05-01 11:36 - 2015-05-01 11:36 - 00004028 _____ () C:\WINDOWS\System32\Tasks\rSDUW7BbgGiSrVMrdh
2015-05-01 11:26 - 2015-05-01 11:26 - 00004012 _____ () C:\WINDOWS\System32\Tasks\JtBudg1Ww
2015-05-01 11:25 - 2015-05-16 10:56 - 00001006 _____ () C:\WINDOWS\Tasks\JtBudg1Ww.job
2015-05-01 11:25 - 2015-05-01 11:25 - 00004022 _____ () C:\WINDOWS\System32\Tasks\2nOJkR5Ifg0tiD9
2015-05-01 11:24 - 2015-05-16 10:56 - 00001018 _____ () C:\WINDOWS\Tasks\2nOJkR5Ifg0tiD9.job
2015-05-01 11:23 - 2015-05-15 16:53 - 00000000 ___HD () C:\ProgramData\dqx
2015-05-01 11:23 - 2015-05-02 09:25 - 00000004 _____ () C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-05-01 11:21 - 2015-05-01 12:44 - 00000000 ____D () C:\ProgramData\fkDykAiFI
2015-05-01 11:20 - 2015-05-01 11:20 - 00631296 _____ () C:\WINDOWS\dqx.dat
2015-04-19 14:20 - 2015-04-19 14:20 - 00005872 _____ () C:\Users\Chris\AppData\Roaming\rSDUW7BbgGiSrVMrdh
2015-04-19 14:20 - 2015-04-19 14:20 - 00005872 _____ () C:\Users\Chris\AppData\Roaming\dB33E7CnWQb5bDHfgS
2015-04-19 14:20 - 2015-04-19 14:20 - 00005872 _____ () C:\Users\Chris\AppData\Roaming\2nOJkR5Ifg0tiD9
2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Chris\AppData\Roaming\JtBudg1Ww
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\Chris\AppData\Roaming\rSDUW7BbgGiSrVMrdh
2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Chris\AppData\Roaming\Tchje7bQculxP6
Task: {0C55E23C-74DA-48F0-BA5A-74F139D893E3} - System32\Tasks\rSDUW7BbgGiSrVMrdh => C:\Users\Chris\AppData\Roaming\rSDUW7BbgGiSrVMrdh.exe <==== ATTENTION
Task: {71C54FF4-0F3B-498E-A151-D6A28D067BA2} - System32\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI => C:\Users\Chris\AppData\Roaming\EDukLGr3CcgwcayS3f8ZnmeBBI.exe <==== ATTENTION
Task: {AC6032E7-A042-4ADE-9315-592B6FF67455} - System32\Tasks\JtBudg1Ww => C:\Users\Chris\AppData\Roaming\JtBudg1Ww.exe <==== ATTENTION
Task: {AD86DBD8-D2FE-4354-876C-520B9A19B221} - System32\Tasks\Tchje7bQculxP6 => C:\Users\Chris\AppData\Roaming\Tchje7bQculxP6.exe <==== ATTENTION
Task: {D48D1B75-4117-4FD2-A8E1-798C09062925} - System32\Tasks\dB33E7CnWQb5bDHfgS => C:\Users\Chris\AppData\Roaming\dB33E7CnWQb5bDHfgS.exe <==== ATTENTION
Task: {E3CA6DF4-86CD-4C24-B13E-B00E19B548AE} - System32\Tasks\2nOJkR5Ifg0tiD9 => C:\Users\Chris\AppData\Roaming\2nOJkR5Ifg0tiD9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\2nOJkR5Ifg0tiD9.job => C:\Users\Chris\AppData\Roaming\2nOJkR5Ifg0tiD9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\dB33E7CnWQb5bDHfgS.job => C:\Users\Chris\AppData\Roaming\dB33E7CnWQb5bDHfgS.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI.job => C:\Users\Chris\AppData\Roaming\EDukLGr3CcgwcayS3f8ZnmeBBI.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\JtBudg1Ww.job => C:\Users\Chris\AppData\Roaming\JtBudg1Ww.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\rSDUW7BbgGiSrVMrdh.job => C:\Users\Chris\AppData\Roaming\rSDUW7BbgGiSrVMrdh.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Tchje7bQculxP6.job => C:\Users\Chris\AppData\Roaming\Tchje7bQculxP6.exe <==== ATTENTION
CMD: del /F /Q C:\Users\Chris\AppData\Roaming\*.exe
EmptyTemp:
end
C:\ProgramData\{290602b1-94d5-f4af-2906-602b194d0ac6}\hqghumeaylnlf.exe => No running process found
C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk not found.
C:\ProgramData\{290602b1-94d5-f4af-2906-602b194d0ac6}\hqghumeaylnlf.exe not found.
"C:\15653a8e7d2a8d1e93535758d48d" => File/Directory not found.
"C:\ProgramData\d554bfb4000078d5" => File/Directory not found.
"C:\Users\Chris\Documents\Optimizer Pro" => File/Directory not found.
"C:\ProgramData\{290602b1-94d5-f4af-2906-602b194d0ac6}" => File/Directory not found.
"C:\Users\Chris\AppData\Local\20551" => File/Directory not found.
"C:\WINDOWS\Tasks\dB33E7CnWQb5bDHfgS.job" => File/Directory not found.
"C:\WINDOWS\Tasks\Tchje7bQculxP6.job" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\dB33E7CnWQb5bDHfgS" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\Tchje7bQculxP6" => File/Directory not found.
"C:\Program Files (x86)\42eadb88-130e-4cee-aab6-d0064be565fc" => File/Directory not found.
"C:\Program Files (x86)\Software" => File/Directory not found.
"C:\Users\Chris\AppData\Local\Software" => File/Directory not found.
"C:\WINDOWS\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI.job" => File/Directory not found.
"C:\WINDOWS\Tasks\rSDUW7BbgGiSrVMrdh.job" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\rSDUW7BbgGiSrVMrdh" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\JtBudg1Ww" => File/Directory not found.
"C:\WINDOWS\Tasks\JtBudg1Ww.job" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\2nOJkR5Ifg0tiD9" => File/Directory not found.
"C:\WINDOWS\Tasks\2nOJkR5Ifg0tiD9.job" => File/Directory not found.
"C:\ProgramData\dqx" => File/Directory not found.
"C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7" => File/Directory not found.
"C:\ProgramData\fkDykAiFI" => File/Directory not found.
"C:\WINDOWS\dqx.dat" => File/Directory not found.
"C:\Users\Chris\AppData\Roaming\rSDUW7BbgGiSrVMrdh" => File/Directory not found.
"C:\Users\Chris\AppData\Roaming\dB33E7CnWQb5bDHfgS" => File/Directory not found.
"C:\Users\Chris\AppData\Roaming\2nOJkR5Ifg0tiD9" => File/Directory not found.
"C:\Users\Chris\AppData\Roaming\JtBudg1Ww" => File/Directory not found.
"C:\Users\Chris\AppData\Roaming\rSDUW7BbgGiSrVMrdh" => File/Directory not found.
"C:\Users\Chris\AppData\Roaming\Tchje7bQculxP6" => File/Directory not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0C55E23C-74DA-48F0-BA5A-74F139D893E3} => Key not found.
C:\Windows\System32\Tasks\rSDUW7BbgGiSrVMrdh not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\rSDUW7BbgGiSrVMrdh" => Key Deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{71C54FF4-0F3B-498E-A151-D6A28D067BA2}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{71C54FF4-0F3B-498E-A151-D6A28D067BA2}" => Key deleted successfully.
C:\Windows\System32\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EDukLGr3CcgwcayS3f8ZnmeBBI" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AC6032E7-A042-4ADE-9315-592B6FF67455}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC6032E7-A042-4ADE-9315-592B6FF67455}" => Key deleted successfully.
C:\Windows\System32\Tasks\JtBudg1Ww not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\JtBudg1Ww" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AD86DBD8-D2FE-4354-876C-520B9A19B221}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AD86DBD8-D2FE-4354-876C-520B9A19B221}" => Key deleted successfully.
C:\Windows\System32\Tasks\Tchje7bQculxP6 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Tchje7bQculxP6" => Key Deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D48D1B75-4117-4FD2-A8E1-798C09062925}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D48D1B75-4117-4FD2-A8E1-798C09062925}" => Key deleted successfully.
C:\Windows\System32\Tasks\dB33E7CnWQb5bDHfgS not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\dB33E7CnWQb5bDHfgS" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E3CA6DF4-86CD-4C24-B13E-B00E19B548AE}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3CA6DF4-86CD-4C24-B13E-B00E19B548AE}" => Key deleted successfully.
C:\Windows\System32\Tasks\2nOJkR5Ifg0tiD9 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\2nOJkR5Ifg0tiD9" => Key deleted successfully.
C:\WINDOWS\Tasks\2nOJkR5Ifg0tiD9.job not found.
C:\WINDOWS\Tasks\dB33E7CnWQb5bDHfgS.job not found.
C:\WINDOWS\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI.job not found.
C:\WINDOWS\Tasks\JtBudg1Ww.job not found.
C:\WINDOWS\Tasks\rSDUW7BbgGiSrVMrdh.job not found.
C:\WINDOWS\Tasks\Tchje7bQculxP6.job not found.
========= del /F /Q C:\Users\Chris\AppData\Roaming\*.exe =========
Impossible de trouver C:\Users\Chris\AppData\Roaming\*.exe
========= End of CMD: =========
EmptyTemp: => Removed 785 MB temporary data.
The system needed a reboot.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-05-2015 02
Ran by Chris at 2015-05-16 17:58:55 Run:2
Running from C:\Users\Chris\Downloads
Loaded Profiles: Chris (Available profiles: Chris & Administrateur)
Boot Mode: Normal
==============================================
Content of fixlist:
start
(PC Utilities Software Limited) C:\ProgramData\{290602b1-94d5-f4af-2906-602b194d0ac6}\hqghumeaylnlf.exe
Startup: C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk [2015-05-07]
ShortcutTarget: hqghumeaylnlf.lnk -> C:\ProgramData\{290602b1-94d5-f4af-2906-602b194d0ac6}\hqghumeaylnlf.exe (PC Utilities Software Limited)
2015-05-15 09:59 - 2015-05-15 09:59 - 00000000 ____D () C:\15653a8e7d2a8d1e93535758d48d
2015-05-07 19:28 - 2015-05-07 19:28 - 00000000 ____D () C:\ProgramData\d554bfb4000078d5
2015-05-07 18:38 - 2015-05-07 18:38 - 00000000 ____D () C:\Users\Chris\Documents\Optimizer Pro
2015-05-07 18:32 - 2015-05-13 07:09 - 00000000 ____D () C:\ProgramData\{290602b1-94d5-f4af-2906-602b194d0ac6}
2015-05-01 23:13 - 2015-05-02 09:57 - 00000000 ____D () C:\Users\Chris\AppData\Local\20551
2015-05-01 21:23 - 2015-05-16 10:56 - 00001024 _____ () C:\WINDOWS\Tasks\dB33E7CnWQb5bDHfgS.job
2015-05-01 21:23 - 2015-05-16 10:56 - 00001016 _____ () C:\WINDOWS\Tasks\Tchje7bQculxP6.job
2015-05-01 21:23 - 2015-05-01 21:23 - 00004030 _____ () C:\WINDOWS\System32\Tasks\dB33E7CnWQb5bDHfgS
2015-05-01 21:23 - 2015-05-01 21:23 - 00004020 _____ () C:\WINDOWS\System32\Tasks\Tchje7bQculxP6
2015-05-01 21:22 - 2015-05-02 09:57 - 00000000 ____D () C:\Program Files (x86)\42eadb88-130e-4cee-aab6-d0064be565fc
2015-05-01 13:26 - 2015-05-01 13:31 - 00000000 ____D () C:\Program Files (x86)\Software
2015-05-01 13:26 - 2015-05-01 13:26 - 00000000 ____D () C:\Users\Chris\AppData\Local\Software
2015-05-01 11:36 - 2015-05-16 10:56 - 00001040 _____ () C:\WINDOWS\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI.job
2015-05-01 11:36 - 2015-05-16 10:56 - 00001024 _____ () C:\WINDOWS\Tasks\rSDUW7BbgGiSrVMrdh.job
2015-05-01 11:36 - 2015-05-01 11:36 - 00004044 _____ () C:\WINDOWS\System32\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI
2015-05-01 11:36 - 2015-05-01 11:36 - 00004028 _____ () C:\WINDOWS\System32\Tasks\rSDUW7BbgGiSrVMrdh
2015-05-01 11:26 - 2015-05-01 11:26 - 00004012 _____ () C:\WINDOWS\System32\Tasks\JtBudg1Ww
2015-05-01 11:25 - 2015-05-16 10:56 - 00001006 _____ () C:\WINDOWS\Tasks\JtBudg1Ww.job
2015-05-01 11:25 - 2015-05-01 11:25 - 00004022 _____ () C:\WINDOWS\System32\Tasks\2nOJkR5Ifg0tiD9
2015-05-01 11:24 - 2015-05-16 10:56 - 00001018 _____ () C:\WINDOWS\Tasks\2nOJkR5Ifg0tiD9.job
2015-05-01 11:23 - 2015-05-15 16:53 - 00000000 ___HD () C:\ProgramData\dqx
2015-05-01 11:23 - 2015-05-02 09:25 - 00000004 _____ () C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-05-01 11:21 - 2015-05-01 12:44 - 00000000 ____D () C:\ProgramData\fkDykAiFI
2015-05-01 11:20 - 2015-05-01 11:20 - 00631296 _____ () C:\WINDOWS\dqx.dat
2015-04-19 14:20 - 2015-04-19 14:20 - 00005872 _____ () C:\Users\Chris\AppData\Roaming\rSDUW7BbgGiSrVMrdh
2015-04-19 14:20 - 2015-04-19 14:20 - 00005872 _____ () C:\Users\Chris\AppData\Roaming\dB33E7CnWQb5bDHfgS
2015-04-19 14:20 - 2015-04-19 14:20 - 00005872 _____ () C:\Users\Chris\AppData\Roaming\2nOJkR5Ifg0tiD9
2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Chris\AppData\Roaming\JtBudg1Ww
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\Chris\AppData\Roaming\rSDUW7BbgGiSrVMrdh
2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Chris\AppData\Roaming\Tchje7bQculxP6
Task: {0C55E23C-74DA-48F0-BA5A-74F139D893E3} - System32\Tasks\rSDUW7BbgGiSrVMrdh => C:\Users\Chris\AppData\Roaming\rSDUW7BbgGiSrVMrdh.exe <==== ATTENTION
Task: {71C54FF4-0F3B-498E-A151-D6A28D067BA2} - System32\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI => C:\Users\Chris\AppData\Roaming\EDukLGr3CcgwcayS3f8ZnmeBBI.exe <==== ATTENTION
Task: {AC6032E7-A042-4ADE-9315-592B6FF67455} - System32\Tasks\JtBudg1Ww => C:\Users\Chris\AppData\Roaming\JtBudg1Ww.exe <==== ATTENTION
Task: {AD86DBD8-D2FE-4354-876C-520B9A19B221} - System32\Tasks\Tchje7bQculxP6 => C:\Users\Chris\AppData\Roaming\Tchje7bQculxP6.exe <==== ATTENTION
Task: {D48D1B75-4117-4FD2-A8E1-798C09062925} - System32\Tasks\dB33E7CnWQb5bDHfgS => C:\Users\Chris\AppData\Roaming\dB33E7CnWQb5bDHfgS.exe <==== ATTENTION
Task: {E3CA6DF4-86CD-4C24-B13E-B00E19B548AE} - System32\Tasks\2nOJkR5Ifg0tiD9 => C:\Users\Chris\AppData\Roaming\2nOJkR5Ifg0tiD9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\2nOJkR5Ifg0tiD9.job => C:\Users\Chris\AppData\Roaming\2nOJkR5Ifg0tiD9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\dB33E7CnWQb5bDHfgS.job => C:\Users\Chris\AppData\Roaming\dB33E7CnWQb5bDHfgS.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI.job => C:\Users\Chris\AppData\Roaming\EDukLGr3CcgwcayS3f8ZnmeBBI.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\JtBudg1Ww.job => C:\Users\Chris\AppData\Roaming\JtBudg1Ww.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\rSDUW7BbgGiSrVMrdh.job => C:\Users\Chris\AppData\Roaming\rSDUW7BbgGiSrVMrdh.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Tchje7bQculxP6.job => C:\Users\Chris\AppData\Roaming\Tchje7bQculxP6.exe <==== ATTENTION
CMD: del /F /Q C:\Users\Chris\AppData\Roaming\*.exe
EmptyTemp:
end
C:\ProgramData\{290602b1-94d5-f4af-2906-602b194d0ac6}\hqghumeaylnlf.exe => No running process found
C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk not found.
C:\ProgramData\{290602b1-94d5-f4af-2906-602b194d0ac6}\hqghumeaylnlf.exe not found.
"C:\15653a8e7d2a8d1e93535758d48d" => File/Directory not found.
"C:\ProgramData\d554bfb4000078d5" => File/Directory not found.
"C:\Users\Chris\Documents\Optimizer Pro" => File/Directory not found.
"C:\ProgramData\{290602b1-94d5-f4af-2906-602b194d0ac6}" => File/Directory not found.
"C:\Users\Chris\AppData\Local\20551" => File/Directory not found.
"C:\WINDOWS\Tasks\dB33E7CnWQb5bDHfgS.job" => File/Directory not found.
"C:\WINDOWS\Tasks\Tchje7bQculxP6.job" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\dB33E7CnWQb5bDHfgS" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\Tchje7bQculxP6" => File/Directory not found.
"C:\Program Files (x86)\42eadb88-130e-4cee-aab6-d0064be565fc" => File/Directory not found.
"C:\Program Files (x86)\Software" => File/Directory not found.
"C:\Users\Chris\AppData\Local\Software" => File/Directory not found.
"C:\WINDOWS\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI.job" => File/Directory not found.
"C:\WINDOWS\Tasks\rSDUW7BbgGiSrVMrdh.job" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\rSDUW7BbgGiSrVMrdh" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\JtBudg1Ww" => File/Directory not found.
"C:\WINDOWS\Tasks\JtBudg1Ww.job" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\2nOJkR5Ifg0tiD9" => File/Directory not found.
"C:\WINDOWS\Tasks\2nOJkR5Ifg0tiD9.job" => File/Directory not found.
"C:\ProgramData\dqx" => File/Directory not found.
"C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7" => File/Directory not found.
"C:\ProgramData\fkDykAiFI" => File/Directory not found.
"C:\WINDOWS\dqx.dat" => File/Directory not found.
"C:\Users\Chris\AppData\Roaming\rSDUW7BbgGiSrVMrdh" => File/Directory not found.
"C:\Users\Chris\AppData\Roaming\dB33E7CnWQb5bDHfgS" => File/Directory not found.
"C:\Users\Chris\AppData\Roaming\2nOJkR5Ifg0tiD9" => File/Directory not found.
"C:\Users\Chris\AppData\Roaming\JtBudg1Ww" => File/Directory not found.
"C:\Users\Chris\AppData\Roaming\rSDUW7BbgGiSrVMrdh" => File/Directory not found.
"C:\Users\Chris\AppData\Roaming\Tchje7bQculxP6" => File/Directory not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0C55E23C-74DA-48F0-BA5A-74F139D893E3} => Key not found.
C:\Windows\System32\Tasks\rSDUW7BbgGiSrVMrdh not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\rSDUW7BbgGiSrVMrdh" => Key Deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{71C54FF4-0F3B-498E-A151-D6A28D067BA2}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{71C54FF4-0F3B-498E-A151-D6A28D067BA2}" => Key deleted successfully.
C:\Windows\System32\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EDukLGr3CcgwcayS3f8ZnmeBBI" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AC6032E7-A042-4ADE-9315-592B6FF67455}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC6032E7-A042-4ADE-9315-592B6FF67455}" => Key deleted successfully.
C:\Windows\System32\Tasks\JtBudg1Ww not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\JtBudg1Ww" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AD86DBD8-D2FE-4354-876C-520B9A19B221}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AD86DBD8-D2FE-4354-876C-520B9A19B221}" => Key deleted successfully.
C:\Windows\System32\Tasks\Tchje7bQculxP6 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Tchje7bQculxP6" => Key Deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D48D1B75-4117-4FD2-A8E1-798C09062925}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D48D1B75-4117-4FD2-A8E1-798C09062925}" => Key deleted successfully.
C:\Windows\System32\Tasks\dB33E7CnWQb5bDHfgS not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\dB33E7CnWQb5bDHfgS" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E3CA6DF4-86CD-4C24-B13E-B00E19B548AE}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3CA6DF4-86CD-4C24-B13E-B00E19B548AE}" => Key deleted successfully.
C:\Windows\System32\Tasks\2nOJkR5Ifg0tiD9 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\2nOJkR5Ifg0tiD9" => Key deleted successfully.
C:\WINDOWS\Tasks\2nOJkR5Ifg0tiD9.job not found.
C:\WINDOWS\Tasks\dB33E7CnWQb5bDHfgS.job not found.
C:\WINDOWS\Tasks\EDukLGr3CcgwcayS3f8ZnmeBBI.job not found.
C:\WINDOWS\Tasks\JtBudg1Ww.job not found.
C:\WINDOWS\Tasks\rSDUW7BbgGiSrVMrdh.job not found.
C:\WINDOWS\Tasks\Tchje7bQculxP6.job not found.
========= del /F /Q C:\Users\Chris\AppData\Roaming\*.exe =========
Impossible de trouver C:\Users\Chris\AppData\Roaming\*.exe
========= End of CMD: =========
EmptyTemp: => Removed 785 MB temporary data.
The system needed a reboot.
End of Fixlog 18:00:07
Mouais il a pas accepté le joker dans la commande et y'a plein de "not found".
Tu n'as pas exécuté deux fois le script à tout hasard ?
Tu n'as pas exécuté deux fois le script à tout hasard ?
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Salut,
Refais un scan avec FRST : https://forums.commentcamarche.net/forum/affich-31973842-j-ai-attrape-mystart-search-depuis#1
Poste les deux liens, et nous verrons ce qu'il y a lieu de faire.
A+
Refais un scan avec FRST : https://forums.commentcamarche.net/forum/affich-31973842-j-ai-attrape-mystart-search-depuis#1
Poste les deux liens, et nous verrons ce qu'il y a lieu de faire.
A+