Suppression WebShield, NetEngine et crossbrowser
Fermé
emifit
Messages postés
4
Date d'inscription
dimanche 17 mai 2015
Statut
Membre
Dernière intervention
17 mai 2015
-
Modifié par Malekal_morte- le 17/05/2015 à 19:17
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 - 18 mai 2015 à 08:00
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 - 18 mai 2015 à 08:00
A voir également:
- Suppression WebShield, NetEngine et crossbrowser
- Forcer suppression fichier - Guide
- Suppression page word - Guide
- Suppression cookies - Guide
- Suppression compte gmail - Guide
- Suppression compte instagram - Guide
4 réponses
Malekal_morte-
Messages postés
180304
Date d'inscription
mercredi 17 mai 2006
Statut
Modérateur, Contributeur sécurité
Dernière intervention
15 décembre 2020
24 658
17 mai 2015 à 18:35
17 mai 2015 à 18:35
Salut,
Suis ce tutoriel FRST: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/
(et bien prendre le temps de lire afin d'appliquer correctement - tout y est expliqué).
Télécharge et lance le scan FRST, cela va générer trois rapports FRST :
Envoie, comme expliqué, ces trois rapports sur le site http://pjjoint.malekal.com et en retour donne les trois liens pjjoint qui mènent à ses rapports ici dans une nouvelle réponse afin que l'on puisse les consulter.
Suis ce tutoriel FRST: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/
(et bien prendre le temps de lire afin d'appliquer correctement - tout y est expliqué).
Télécharge et lance le scan FRST, cela va générer trois rapports FRST :
- FRST.txt
- Shortcut.txt
- Additionnal.txt
Envoie, comme expliqué, ces trois rapports sur le site http://pjjoint.malekal.com et en retour donne les trois liens pjjoint qui mènent à ses rapports ici dans une nouvelle réponse afin que l'on puisse les consulter.
emifit
Messages postés
4
Date d'inscription
dimanche 17 mai 2015
Statut
Membre
Dernière intervention
17 mai 2015
17 mai 2015 à 19:15
17 mai 2015 à 19:15
j'ai suivi toutes les étapes, voici les liens des rapports:
https://pjjoint.malekal.com/files.php?id=20150517_w6y5t5p5h11
https://pjjoint.malekal.com/files.php?id=20150517_y9r14p13e15w5
https://pjjoint.malekal.com/files.php?id=20150517_v6f12c9b14t12
merci
https://pjjoint.malekal.com/files.php?id=20150517_w6y5t5p5h11
https://pjjoint.malekal.com/files.php?id=20150517_y9r14p13e15w5
https://pjjoint.malekal.com/files.php?id=20150517_v6f12c9b14t12
merci
Malekal_morte-
Messages postés
180304
Date d'inscription
mercredi 17 mai 2006
Statut
Modérateur, Contributeur sécurité
Dernière intervention
15 décembre 2020
24 658
17 mai 2015 à 19:21
17 mai 2015 à 19:21
Désinstalle McAfee Security Scan.
Voici la correction à effectuer avec FRST.
Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix
Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
Copie/colle dedans ce qui suit :
Task: {5122DDC2-51A2-416A-BCD0-5B23E73AF7EF} - System32\Tasks\{C75E4E9E-2D03-448C-B441-7BE89138A111} => pcalua.exe -a C:\ProgramData\WebShield\uninstall.exe -c /kb=y /ic=1
Task: {6A44241D-8901-45AE-9139-036656927C8B} - System32\Tasks\{3FA0D995-E8DB-460B-9FFC-6BADE456AC9E} => pcalua.exe -a C:\Users\emilile\AppData\Roaming\istartsurf\UninstallManager.exe -c -ptid=tugs
Task: {826DFC7F-7C80-442C-9DC9-55B284C9EEC6} - System32\Tasks\Yr4IPqI5a54zlMma3 => C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe [2015-04-20] () <==== ATTENTION
Task: {B2360877-ED51-448A-940C-EFC4F0092D5E} - System32\Tasks\NetEngine => C:\ProgramData\NetEngine\bin\D10\netengine.exe [2015-05-17] () <==== ATTENTION
Task: {D8E9DBE8-CAD6-42C7-93C7-79A17B8F434D} - System32\Tasks\{B054486F-07AC-41BD-B44B-1CDC187CB65D} => C:\Users\emilile\Downloads\freac.exe
Task: C:\Windows\Tasks\Yr4IPqI5a54zlMma3.job => C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe <==== ATTENTION
HKLM\...\Run: [gmsd_fr_535] => [X]
HKU\S-1-5-21-2061915745-2614720195-4293636210-1000\...\Run: [GoogleChromeAutoLaunch_8A081EDD1277D9F30E2D5533BB501092] => "C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe" --no-startup-window
FF HKLM\...\Firefox\Extensions: [offerboxffx@offerbox.com] - C:\Program Files\OfferBox\offerboxffx@offerbox.com
R2 xixynyko; C:\Users\emilile\AppData\Roaming\0000F9AF-1431787995-1454-D325-4E45435F4349\jnsiC495.tmp [235520 2015-05-16] () [File not signed]
R2 lupucylu; C:\Users\emilile\AppData\Roaming\0000F9AF-1431787995-1454-D325-4E45435F4349\nss9065.tmpfs [X]
R2 insvc_1.10.0.14; C:\Program Files\Infonaut_1.10.0.14\Service\insvc.exe [278600 2015-04-10] (Infonaut)
S1 innfd_1_10_0_14; system32\drivers\innfd_1_10_0_14.sys [X]
2015-05-17 18:28 - 2015-05-17 18:28 - 00000000 ____D () C:\ProgramData\NetEngine
2015-05-17 18:05 - 2015-05-17 18:23 - 00001014 _____ () C:\Windows\Tasks\Yr4IPqI5a54zlMma3.job
2015-05-17 18:04 - 2015-05-17 18:04 - 00000004 _____ () C:\Windows\system32\029B560A371F4E00AB32838EBC01B9E7
2015-05-17 18:04 - 2015-05-17 18:04 - 00000000 ____D () C:\Program Files\bd41c615-25b0-4c6d-8aea-bb307eef87c6
2015-05-16 17:49 - 2015-05-16 17:49 - 00768512 _____ (Reimage®) C:\Users\emilile\Downloads\ReimageRepair.exe
2015-05-16 17:31 - 2015-05-16 17:31 - 00000000 ____D () C:\Users\emilile\Documents\Optimizer Pro
2015-05-16 17:31 - 2015-05-16 17:31 - 00000000 ____D () C:\Users\emilile\AppData\Roaming\Optimizer Pro
2015-05-16 17:30 - 2015-05-16 17:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2015-05-16 17:28 - 2015-05-16 17:28 - 00000000 _____ () C:\Windows\system32\Number of results
2015-05-16 16:53 - 2015-05-16 16:53 - 00000000 ____D () C:\Users\emilile\AppData\Roaming\0000F9AF-1431787995-1454-D325-4E45435F4349
2015-05-15 21:46 - 2015-05-15 21:46 - 00002211 _____ () C:\Users\Public\Desktop\Search.lnk
2015-05-15 21:43 - 2015-05-16 16:52 - 00000000 ____D () C:\Program Files\gmsd_fr_535
2015-05-15 21:43 - 2015-05-15 21:46 - 00000000 ____D () C:\ProgramData\pPHoaktyU
2015-05-15 21:43 - 2015-05-15 21:43 - 00000000 ____D () C:\ProgramData\WebShield
2015-05-15 21:42 - 2015-05-15 21:43 - 00631296 _____ () C:\Windows\eah.dat
2015-05-15 21:40 - 2015-05-16 17:46 - 00000000 ____D () C:\Program Files\Software
2015-05-15 21:38 - 2015-05-15 21:39 - 00000554 _____ () C:\Users\emilile\Downloads\Setup .website
2015-05-10 19:02 - 2015-05-10 19:04 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-04-20 16:05 - 2015-04-20 16:05 - 01579520 _____ () C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe
2015-04-19 14:20 - 2015-04-19 14:20 - 00005872 _____ () C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3
2015-04-20 16:05 - 2015-04-20 16:05 - 1579520 _____ () C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe
Une fois, le texte coller dans le bloc-note.
Menu Fichier puis Enregistrer sous.
A gauche, place toi sur le bureau.
Dans le champs en bas, nom du fichier mets : fixlist.txt
Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.
Relance FRST et clic sur le bouton Fix
Selon comment un redémarrage est nécessaire (pas obligatoire).
Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.
Redémarre l'ordinateur
puis réinitialise tes navigateurs:
==================================
Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :
Voici la correction à effectuer avec FRST.
Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix
Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
Copie/colle dedans ce qui suit :
Task: {5122DDC2-51A2-416A-BCD0-5B23E73AF7EF} - System32\Tasks\{C75E4E9E-2D03-448C-B441-7BE89138A111} => pcalua.exe -a C:\ProgramData\WebShield\uninstall.exe -c /kb=y /ic=1
Task: {6A44241D-8901-45AE-9139-036656927C8B} - System32\Tasks\{3FA0D995-E8DB-460B-9FFC-6BADE456AC9E} => pcalua.exe -a C:\Users\emilile\AppData\Roaming\istartsurf\UninstallManager.exe -c -ptid=tugs
Task: {826DFC7F-7C80-442C-9DC9-55B284C9EEC6} - System32\Tasks\Yr4IPqI5a54zlMma3 => C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe [2015-04-20] () <==== ATTENTION
Task: {B2360877-ED51-448A-940C-EFC4F0092D5E} - System32\Tasks\NetEngine => C:\ProgramData\NetEngine\bin\D10\netengine.exe [2015-05-17] () <==== ATTENTION
Task: {D8E9DBE8-CAD6-42C7-93C7-79A17B8F434D} - System32\Tasks\{B054486F-07AC-41BD-B44B-1CDC187CB65D} => C:\Users\emilile\Downloads\freac.exe
Task: C:\Windows\Tasks\Yr4IPqI5a54zlMma3.job => C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe <==== ATTENTION
HKLM\...\Run: [gmsd_fr_535] => [X]
HKU\S-1-5-21-2061915745-2614720195-4293636210-1000\...\Run: [GoogleChromeAutoLaunch_8A081EDD1277D9F30E2D5533BB501092] => "C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe" --no-startup-window
FF HKLM\...\Firefox\Extensions: [offerboxffx@offerbox.com] - C:\Program Files\OfferBox\offerboxffx@offerbox.com
R2 xixynyko; C:\Users\emilile\AppData\Roaming\0000F9AF-1431787995-1454-D325-4E45435F4349\jnsiC495.tmp [235520 2015-05-16] () [File not signed]
R2 lupucylu; C:\Users\emilile\AppData\Roaming\0000F9AF-1431787995-1454-D325-4E45435F4349\nss9065.tmpfs [X]
R2 insvc_1.10.0.14; C:\Program Files\Infonaut_1.10.0.14\Service\insvc.exe [278600 2015-04-10] (Infonaut)
S1 innfd_1_10_0_14; system32\drivers\innfd_1_10_0_14.sys [X]
2015-05-17 18:28 - 2015-05-17 18:28 - 00000000 ____D () C:\ProgramData\NetEngine
2015-05-17 18:05 - 2015-05-17 18:23 - 00001014 _____ () C:\Windows\Tasks\Yr4IPqI5a54zlMma3.job
2015-05-17 18:04 - 2015-05-17 18:04 - 00000004 _____ () C:\Windows\system32\029B560A371F4E00AB32838EBC01B9E7
2015-05-17 18:04 - 2015-05-17 18:04 - 00000000 ____D () C:\Program Files\bd41c615-25b0-4c6d-8aea-bb307eef87c6
2015-05-16 17:49 - 2015-05-16 17:49 - 00768512 _____ (Reimage®) C:\Users\emilile\Downloads\ReimageRepair.exe
2015-05-16 17:31 - 2015-05-16 17:31 - 00000000 ____D () C:\Users\emilile\Documents\Optimizer Pro
2015-05-16 17:31 - 2015-05-16 17:31 - 00000000 ____D () C:\Users\emilile\AppData\Roaming\Optimizer Pro
2015-05-16 17:30 - 2015-05-16 17:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2015-05-16 17:28 - 2015-05-16 17:28 - 00000000 _____ () C:\Windows\system32\Number of results
2015-05-16 16:53 - 2015-05-16 16:53 - 00000000 ____D () C:\Users\emilile\AppData\Roaming\0000F9AF-1431787995-1454-D325-4E45435F4349
2015-05-15 21:46 - 2015-05-15 21:46 - 00002211 _____ () C:\Users\Public\Desktop\Search.lnk
2015-05-15 21:43 - 2015-05-16 16:52 - 00000000 ____D () C:\Program Files\gmsd_fr_535
2015-05-15 21:43 - 2015-05-15 21:46 - 00000000 ____D () C:\ProgramData\pPHoaktyU
2015-05-15 21:43 - 2015-05-15 21:43 - 00000000 ____D () C:\ProgramData\WebShield
2015-05-15 21:42 - 2015-05-15 21:43 - 00631296 _____ () C:\Windows\eah.dat
2015-05-15 21:40 - 2015-05-16 17:46 - 00000000 ____D () C:\Program Files\Software
2015-05-15 21:38 - 2015-05-15 21:39 - 00000554 _____ () C:\Users\emilile\Downloads\Setup .website
2015-05-10 19:02 - 2015-05-10 19:04 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-04-20 16:05 - 2015-04-20 16:05 - 01579520 _____ () C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe
2015-04-19 14:20 - 2015-04-19 14:20 - 00005872 _____ () C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3
2015-04-20 16:05 - 2015-04-20 16:05 - 1579520 _____ () C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe
Une fois, le texte coller dans le bloc-note.
Menu Fichier puis Enregistrer sous.
A gauche, place toi sur le bureau.
Dans le champs en bas, nom du fichier mets : fixlist.txt
Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.
Relance FRST et clic sur le bouton Fix
Selon comment un redémarrage est nécessaire (pas obligatoire).
Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.
Redémarre l'ordinateur
puis réinitialise tes navigateurs:
==================================
Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :
- Firefox : https://www.malekal.com/reparer-firefox/?t=36057&start=
- Google Chrome : https://www.malekal.com/reparer-google-chrome/?t=35837&start=
- Internet Explorer et modules complémentaires / moteurs de recherche : https://forum.malekal.com/viewtopic.php?t=41399&start=
emifit
Messages postés
4
Date d'inscription
dimanche 17 mai 2015
Statut
Membre
Dernière intervention
17 mai 2015
17 mai 2015 à 19:49
17 mai 2015 à 19:49
merci mais ca ne fonctionne pas!!!
apres le redemarrage de l'ordi je n'ai plus google chrome et cross browser est a nouveau sur mon bureau et me balance des pubs et des logiciels...
une idée?
apres le redemarrage de l'ordi je n'ai plus google chrome et cross browser est a nouveau sur mon bureau et me balance des pubs et des logiciels...
une idée?
emifit
Messages postés
4
Date d'inscription
dimanche 17 mai 2015
Statut
Membre
Dernière intervention
17 mai 2015
17 mai 2015 à 19:51
17 mai 2015 à 19:51
voila le dernier message!
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 16-05-2015 02
Ran by emilile at 2015-05-17 19:29:32 Run:1
Running from C:\Users\emilile\Desktop
Loaded Profiles: emilile (Available profiles: emilile)
Boot Mode: Normal
==============================================
Content of fixlist:
Task: {5122DDC2-51A2-416A-BCD0-5B23E73AF7EF} - System32\Tasks\{C75E4E9E-2D03-448C-B441-7BE89138A111} => pcalua.exe -a C:\ProgramData\WebShield\uninstall.exe -c /kb=y /ic=1
Task: {6A44241D-8901-45AE-9139-036656927C8B} - System32\Tasks\{3FA0D995-E8DB-460B-9FFC-6BADE456AC9E} => pcalua.exe -a C:\Users\emilile\AppData\Roaming\istartsurf\UninstallManager.exe -c -ptid=tugs
Task: {826DFC7F-7C80-442C-9DC9-55B284C9EEC6} - System32\Tasks\Yr4IPqI5a54zlMma3 => C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe [2015-04-20] () <==== ATTENTION
Task: {B2360877-ED51-448A-940C-EFC4F0092D5E} - System32\Tasks\NetEngine => C:\ProgramData\NetEngine\bin\D10\netengine.exe [2015-05-17] () <==== ATTENTION
Task: {D8E9DBE8-CAD6-42C7-93C7-79A17B8F434D} - System32\Tasks\{B054486F-07AC-41BD-B44B-1CDC187CB65D} => C:\Users\emilile\Downloads\freac.exe
Task: C:\Windows\Tasks\Yr4IPqI5a54zlMma3.job => C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe <==== ATTENTION
HKLM\...\Run: [gmsd_fr_535] => [X]
HKU\S-1-5-21-2061915745-2614720195-4293636210-1000\...\Run: [GoogleChromeAutoLaunch_8A081EDD1277D9F30E2D5533BB501092] => "C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe" --no-startup-window
FF HKLM\...\Firefox\Extensions: [offerboxffx@offerbox.com] - C:\Program Files\OfferBox\offerboxffx@offerbox.com
R2 xixynyko; C:\Users\emilile\AppData\Roaming\0000F9AF-1431787995-1454-D325-4E45435F4349\jnsiC495.tmp [235520 2015-05-16] () [File not signed]
R2 lupucylu; C:\Users\emilile\AppData\Roaming\0000F9AF-1431787995-1454-D325-4E45435F4349\nss9065.tmpfs [X]
R2 insvc_1.10.0.14; C:\Program Files\Infonaut_1.10.0.14\Service\insvc.exe [278600 2015-04-10] (Infonaut)
S1 innfd_1_10_0_14; system32\drivers\innfd_1_10_0_14.sys [X]
2015-05-17 18:28 - 2015-05-17 18:28 - 00000000 ____D () C:\ProgramData\NetEngine
2015-05-17 18:05 - 2015-05-17 18:23 - 00001014 _____ () C:\Windows\Tasks\Yr4IPqI5a54zlMma3.job
2015-05-17 18:04 - 2015-05-17 18:04 - 00000004 _____ () C:\Windows\system32\029B560A371F4E00AB32838EBC01B9E7
2015-05-17 18:04 - 2015-05-17 18:04 - 00000000 ____D () C:\Program Files\bd41c615-25b0-4c6d-8aea-bb307eef87c6
2015-05-16 17:49 - 2015-05-16 17:49 - 00768512 _____ (Reimage®) C:\Users\emilile\Downloads\ReimageRepair.exe
2015-05-16 17:31 - 2015-05-16 17:31 - 00000000 ____D () C:\Users\emilile\Documents\Optimizer Pro
2015-05-16 17:31 - 2015-05-16 17:31 - 00000000 ____D () C:\Users\emilile\AppData\Roaming\Optimizer Pro
2015-05-16 17:30 - 2015-05-16 17:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2015-05-16 17:28 - 2015-05-16 17:28 - 00000000 _____ () C:\Windows\system32\Number of results
2015-05-16 16:53 - 2015-05-16 16:53 - 00000000 ____D () C:\Users\emilile\AppData\Roaming\0000F9AF-1431787995-1454-D325-4E45435F4349
2015-05-15 21:46 - 2015-05-15 21:46 - 00002211 _____ () C:\Users\Public\Desktop\Search.lnk
2015-05-15 21:43 - 2015-05-16 16:52 - 00000000 ____D () C:\Program Files\gmsd_fr_535
2015-05-15 21:43 - 2015-05-15 21:46 - 00000000 ____D () C:\ProgramData\pPHoaktyU
2015-05-15 21:43 - 2015-05-15 21:43 - 00000000 ____D () C:\ProgramData\WebShield
2015-05-15 21:42 - 2015-05-15 21:43 - 00631296 _____ () C:\Windows\eah.dat
2015-05-15 21:40 - 2015-05-16 17:46 - 00000000 ____D () C:\Program Files\Software
2015-05-15 21:38 - 2015-05-15 21:39 - 00000554 _____ () C:\Users\emilile\Downloads\Setup .website
2015-05-10 19:02 - 2015-05-10 19:04 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-04-20 16:05 - 2015-04-20 16:05 - 01579520 _____ () C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe
2015-04-19 14:20 - 2015-04-19 14:20 - 00005872 _____ () C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3
2015-04-20 16:05 - 2015-04-20 16:05 - 1579520 _____ () C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5122DDC2-51A2-416A-BCD0-5B23E73AF7EF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5122DDC2-51A2-416A-BCD0-5B23E73AF7EF}" => Key deleted successfully.
C:\Windows\System32\Tasks\{C75E4E9E-2D03-448C-B441-7BE89138A111} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C75E4E9E-2D03-448C-B441-7BE89138A111}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A44241D-8901-45AE-9139-036656927C8B}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A44241D-8901-45AE-9139-036656927C8B}" => Key deleted successfully.
C:\Windows\System32\Tasks\{3FA0D995-E8DB-460B-9FFC-6BADE456AC9E} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3FA0D995-E8DB-460B-9FFC-6BADE456AC9E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{826DFC7F-7C80-442C-9DC9-55B284C9EEC6}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{826DFC7F-7C80-442C-9DC9-55B284C9EEC6}" => Key deleted successfully.
C:\Windows\System32\Tasks\Yr4IPqI5a54zlMma3 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Yr4IPqI5a54zlMma3" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{B2360877-ED51-448A-940C-EFC4F0092D5E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B2360877-ED51-448A-940C-EFC4F0092D5E}" => Key deleted successfully.
C:\Windows\System32\Tasks\NetEngine => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NetEngine" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D8E9DBE8-CAD6-42C7-93C7-79A17B8F434D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D8E9DBE8-CAD6-42C7-93C7-79A17B8F434D}" => Key deleted successfully.
C:\Windows\System32\Tasks\{B054486F-07AC-41BD-B44B-1CDC187CB65D} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B054486F-07AC-41BD-B44B-1CDC187CB65D}" => Key deleted successfully.
C:\Windows\Tasks\Yr4IPqI5a54zlMma3.job => Moved successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_535 => value deleted successfully.
HKU\S-1-5-21-2061915745-2614720195-4293636210-1000\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_8A081EDD1277D9F30E2D5533BB501092 => value deleted successfully.
HKLM\Software\Mozilla\Firefox\Extensions\\offerboxffx@offerbox.com => value deleted successfully.
xixynyko => Service stopped successfully.
xixynyko => Service deleted successfully.
lupucylu => Service stopped successfully.
lupucylu => Service deleted successfully.
insvc_1.10.0.14 => Service stopped successfully.
insvc_1.10.0.14 => Service deleted successfully.
innfd_1_10_0_14 => Service deleted successfully.
"C:\ProgramData\NetEngine" directory move:
Could not move "C:\ProgramData\NetEngine" directory. => Scheduled to move on reboot.
"C:\Windows\Tasks\Yr4IPqI5a54zlMma3.job" => File/Directory not found.
C:\Windows\system32\029B560A371F4E00AB32838EBC01B9E7 => Moved successfully.
C:\Program Files\bd41c615-25b0-4c6d-8aea-bb307eef87c6 => Moved successfully.
C:\Users\emilile\Downloads\ReimageRepair.exe => Moved successfully.
C:\Users\emilile\Documents\Optimizer Pro => Moved successfully.
C:\Users\emilile\AppData\Roaming\Optimizer Pro => Moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 => Moved successfully.
C:\Windows\system32\Number of results => Moved successfully.
C:\Users\emilile\AppData\Roaming\0000F9AF-1431787995-1454-D325-4E45435F4349 => Moved successfully.
C:\Users\Public\Desktop\Search.lnk => Moved successfully.
C:\Program Files\gmsd_fr_535 => Moved successfully.
"C:\ProgramData\pPHoaktyU" directory move:
Could not move "C:\ProgramData\pPHoaktyU" directory. => Scheduled to move on reboot.
C:\ProgramData\WebShield => Moved successfully.
C:\Windows\eah.dat => Moved successfully.
C:\Program Files\Software => Moved successfully.
"C:\Users\emilile\Downloads\Setup .website" => File/Directory not found.
C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB => Moved successfully.
C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe => Moved successfully.
C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3 => Moved successfully.
"C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3" => File/Directory not found.
"C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe" => File/Directory not found.
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-05-17 19:33:57)<=
C:\ProgramData\NetEngine => Is moved successfully.
C:\ProgramData\pPHoaktyU => Is moved successfully.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 16-05-2015 02
Ran by emilile at 2015-05-17 19:29:32 Run:1
Running from C:\Users\emilile\Desktop
Loaded Profiles: emilile (Available profiles: emilile)
Boot Mode: Normal
==============================================
Content of fixlist:
Task: {5122DDC2-51A2-416A-BCD0-5B23E73AF7EF} - System32\Tasks\{C75E4E9E-2D03-448C-B441-7BE89138A111} => pcalua.exe -a C:\ProgramData\WebShield\uninstall.exe -c /kb=y /ic=1
Task: {6A44241D-8901-45AE-9139-036656927C8B} - System32\Tasks\{3FA0D995-E8DB-460B-9FFC-6BADE456AC9E} => pcalua.exe -a C:\Users\emilile\AppData\Roaming\istartsurf\UninstallManager.exe -c -ptid=tugs
Task: {826DFC7F-7C80-442C-9DC9-55B284C9EEC6} - System32\Tasks\Yr4IPqI5a54zlMma3 => C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe [2015-04-20] () <==== ATTENTION
Task: {B2360877-ED51-448A-940C-EFC4F0092D5E} - System32\Tasks\NetEngine => C:\ProgramData\NetEngine\bin\D10\netengine.exe [2015-05-17] () <==== ATTENTION
Task: {D8E9DBE8-CAD6-42C7-93C7-79A17B8F434D} - System32\Tasks\{B054486F-07AC-41BD-B44B-1CDC187CB65D} => C:\Users\emilile\Downloads\freac.exe
Task: C:\Windows\Tasks\Yr4IPqI5a54zlMma3.job => C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe <==== ATTENTION
HKLM\...\Run: [gmsd_fr_535] => [X]
HKU\S-1-5-21-2061915745-2614720195-4293636210-1000\...\Run: [GoogleChromeAutoLaunch_8A081EDD1277D9F30E2D5533BB501092] => "C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe" --no-startup-window
FF HKLM\...\Firefox\Extensions: [offerboxffx@offerbox.com] - C:\Program Files\OfferBox\offerboxffx@offerbox.com
R2 xixynyko; C:\Users\emilile\AppData\Roaming\0000F9AF-1431787995-1454-D325-4E45435F4349\jnsiC495.tmp [235520 2015-05-16] () [File not signed]
R2 lupucylu; C:\Users\emilile\AppData\Roaming\0000F9AF-1431787995-1454-D325-4E45435F4349\nss9065.tmpfs [X]
R2 insvc_1.10.0.14; C:\Program Files\Infonaut_1.10.0.14\Service\insvc.exe [278600 2015-04-10] (Infonaut)
S1 innfd_1_10_0_14; system32\drivers\innfd_1_10_0_14.sys [X]
2015-05-17 18:28 - 2015-05-17 18:28 - 00000000 ____D () C:\ProgramData\NetEngine
2015-05-17 18:05 - 2015-05-17 18:23 - 00001014 _____ () C:\Windows\Tasks\Yr4IPqI5a54zlMma3.job
2015-05-17 18:04 - 2015-05-17 18:04 - 00000004 _____ () C:\Windows\system32\029B560A371F4E00AB32838EBC01B9E7
2015-05-17 18:04 - 2015-05-17 18:04 - 00000000 ____D () C:\Program Files\bd41c615-25b0-4c6d-8aea-bb307eef87c6
2015-05-16 17:49 - 2015-05-16 17:49 - 00768512 _____ (Reimage®) C:\Users\emilile\Downloads\ReimageRepair.exe
2015-05-16 17:31 - 2015-05-16 17:31 - 00000000 ____D () C:\Users\emilile\Documents\Optimizer Pro
2015-05-16 17:31 - 2015-05-16 17:31 - 00000000 ____D () C:\Users\emilile\AppData\Roaming\Optimizer Pro
2015-05-16 17:30 - 2015-05-16 17:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2015-05-16 17:28 - 2015-05-16 17:28 - 00000000 _____ () C:\Windows\system32\Number of results
2015-05-16 16:53 - 2015-05-16 16:53 - 00000000 ____D () C:\Users\emilile\AppData\Roaming\0000F9AF-1431787995-1454-D325-4E45435F4349
2015-05-15 21:46 - 2015-05-15 21:46 - 00002211 _____ () C:\Users\Public\Desktop\Search.lnk
2015-05-15 21:43 - 2015-05-16 16:52 - 00000000 ____D () C:\Program Files\gmsd_fr_535
2015-05-15 21:43 - 2015-05-15 21:46 - 00000000 ____D () C:\ProgramData\pPHoaktyU
2015-05-15 21:43 - 2015-05-15 21:43 - 00000000 ____D () C:\ProgramData\WebShield
2015-05-15 21:42 - 2015-05-15 21:43 - 00631296 _____ () C:\Windows\eah.dat
2015-05-15 21:40 - 2015-05-16 17:46 - 00000000 ____D () C:\Program Files\Software
2015-05-15 21:38 - 2015-05-15 21:39 - 00000554 _____ () C:\Users\emilile\Downloads\Setup .website
2015-05-10 19:02 - 2015-05-10 19:04 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-04-20 16:05 - 2015-04-20 16:05 - 01579520 _____ () C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe
2015-04-19 14:20 - 2015-04-19 14:20 - 00005872 _____ () C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3
2015-04-20 16:05 - 2015-04-20 16:05 - 1579520 _____ () C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5122DDC2-51A2-416A-BCD0-5B23E73AF7EF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5122DDC2-51A2-416A-BCD0-5B23E73AF7EF}" => Key deleted successfully.
C:\Windows\System32\Tasks\{C75E4E9E-2D03-448C-B441-7BE89138A111} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C75E4E9E-2D03-448C-B441-7BE89138A111}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A44241D-8901-45AE-9139-036656927C8B}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A44241D-8901-45AE-9139-036656927C8B}" => Key deleted successfully.
C:\Windows\System32\Tasks\{3FA0D995-E8DB-460B-9FFC-6BADE456AC9E} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3FA0D995-E8DB-460B-9FFC-6BADE456AC9E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{826DFC7F-7C80-442C-9DC9-55B284C9EEC6}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{826DFC7F-7C80-442C-9DC9-55B284C9EEC6}" => Key deleted successfully.
C:\Windows\System32\Tasks\Yr4IPqI5a54zlMma3 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Yr4IPqI5a54zlMma3" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{B2360877-ED51-448A-940C-EFC4F0092D5E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B2360877-ED51-448A-940C-EFC4F0092D5E}" => Key deleted successfully.
C:\Windows\System32\Tasks\NetEngine => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NetEngine" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D8E9DBE8-CAD6-42C7-93C7-79A17B8F434D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D8E9DBE8-CAD6-42C7-93C7-79A17B8F434D}" => Key deleted successfully.
C:\Windows\System32\Tasks\{B054486F-07AC-41BD-B44B-1CDC187CB65D} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B054486F-07AC-41BD-B44B-1CDC187CB65D}" => Key deleted successfully.
C:\Windows\Tasks\Yr4IPqI5a54zlMma3.job => Moved successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_535 => value deleted successfully.
HKU\S-1-5-21-2061915745-2614720195-4293636210-1000\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_8A081EDD1277D9F30E2D5533BB501092 => value deleted successfully.
HKLM\Software\Mozilla\Firefox\Extensions\\offerboxffx@offerbox.com => value deleted successfully.
xixynyko => Service stopped successfully.
xixynyko => Service deleted successfully.
lupucylu => Service stopped successfully.
lupucylu => Service deleted successfully.
insvc_1.10.0.14 => Service stopped successfully.
insvc_1.10.0.14 => Service deleted successfully.
innfd_1_10_0_14 => Service deleted successfully.
"C:\ProgramData\NetEngine" directory move:
Could not move "C:\ProgramData\NetEngine" directory. => Scheduled to move on reboot.
"C:\Windows\Tasks\Yr4IPqI5a54zlMma3.job" => File/Directory not found.
C:\Windows\system32\029B560A371F4E00AB32838EBC01B9E7 => Moved successfully.
C:\Program Files\bd41c615-25b0-4c6d-8aea-bb307eef87c6 => Moved successfully.
C:\Users\emilile\Downloads\ReimageRepair.exe => Moved successfully.
C:\Users\emilile\Documents\Optimizer Pro => Moved successfully.
C:\Users\emilile\AppData\Roaming\Optimizer Pro => Moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 => Moved successfully.
C:\Windows\system32\Number of results => Moved successfully.
C:\Users\emilile\AppData\Roaming\0000F9AF-1431787995-1454-D325-4E45435F4349 => Moved successfully.
C:\Users\Public\Desktop\Search.lnk => Moved successfully.
C:\Program Files\gmsd_fr_535 => Moved successfully.
"C:\ProgramData\pPHoaktyU" directory move:
Could not move "C:\ProgramData\pPHoaktyU" directory. => Scheduled to move on reboot.
C:\ProgramData\WebShield => Moved successfully.
C:\Windows\eah.dat => Moved successfully.
C:\Program Files\Software => Moved successfully.
"C:\Users\emilile\Downloads\Setup .website" => File/Directory not found.
C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB => Moved successfully.
C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe => Moved successfully.
C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3 => Moved successfully.
"C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3" => File/Directory not found.
"C:\Users\emilile\AppData\Roaming\Yr4IPqI5a54zlMma3.exe" => File/Directory not found.
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-05-17 19:33:57)<=
C:\ProgramData\NetEngine => Is moved successfully.
C:\ProgramData\pPHoaktyU => Is moved successfully.
End of Fixlog 19:33:57
Malekal_morte-
Messages postés
180304
Date d'inscription
mercredi 17 mai 2006
Statut
Modérateur, Contributeur sécurité
Dernière intervention
15 décembre 2020
24 658
18 mai 2015 à 08:00
18 mai 2015 à 08:00
il reste quel problème et sur quel navigateur WEB ?