Desinstallation crossbrowser
Fermé
Gwendolinem27
Messages postés
6
Date d'inscription
dimanche 19 juillet 2015
Statut
Membre
Dernière intervention
19 juillet 2015
-
Modifié par Gwendolinem27 le 19/07/2015 à 15:20
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 - 19 juil. 2015 à 16:53
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 - 19 juil. 2015 à 16:53
A voir également:
- Desinstallation crossbrowser
- Logiciel de desinstallation - Télécharger - Nettoyage
- Mcafee desinstallation - Guide
- Désinstallation avast - Télécharger - Antivirus & Antimalwares
- Comment recuperer les message whatsapp après desinstallation - Guide
- Comment forcer la desinstallation d'une application - Guide
3 réponses
Malekal_morte-
Messages postés
180304
Date d'inscription
mercredi 17 mai 2006
Statut
Modérateur, Contributeur sécurité
Dernière intervention
15 décembre 2020
24 663
19 juil. 2015 à 15:19
19 juil. 2015 à 15:19
Salut,
Tu as installé des adwares et programmes parasites sur ton PC qui ouvrent des publicités et ralentissent l'ordinateur et les navigateurs WEB.
Voici la procédure à suivre pour les supprimer :
Commence par ceci :
Suis le tutoriel FRST.
(et bien prendre le temps de lire afin d'appliquer correctement - tout y est expliqué).
Télécharge et lance le scan FRST, cela va générer trois rapports FRST :
Envoie, comme expliqué, ces trois rapports sur le site http://pjjoint.malekal.com et en retour donne les trois liens pjjoint qui mènent à ses rapports ici dans une nouvelle réponse afin que l'on puisse les consulter.
Tu as installé des adwares et programmes parasites sur ton PC qui ouvrent des publicités et ralentissent l'ordinateur et les navigateurs WEB.
Voici la procédure à suivre pour les supprimer :
Commence par ceci :
Suis le tutoriel FRST.
(et bien prendre le temps de lire afin d'appliquer correctement - tout y est expliqué).
Télécharge et lance le scan FRST, cela va générer trois rapports FRST :
- FRST.txt
- Shortcut.txt
- Additionnal.txt
Envoie, comme expliqué, ces trois rapports sur le site http://pjjoint.malekal.com et en retour donne les trois liens pjjoint qui mènent à ses rapports ici dans une nouvelle réponse afin que l'on puisse les consulter.
Malekal_morte-
Messages postés
180304
Date d'inscription
mercredi 17 mai 2006
Statut
Modérateur, Contributeur sécurité
Dernière intervention
15 décembre 2020
24 663
19 juil. 2015 à 16:22
19 juil. 2015 à 16:22
Voici la correction à effectuer avec FRST.
Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix
Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
Copie/colle dedans ce qui suit :
HKLM\...\Run: [Windesk Winsearch] => C:\Program Files (x86)\WindeskWinsearch\Windesk Winsearch.exe
KLM-x32\...\Run: [fst_fr_16] => [X]
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [gmsd_fr_495] => [X]
HKLM-x32\...\Run: [gmsd_fr_618] => [X]
HKLM-x32\...\Run: [gmsd_fr_634] => [X]
HKLM-x32\...\Run: [gmsd_fr_640] => [X]
HKLM-x32\...\Run: [gmsd_fr_636] => [X]
HKLM-x32\...\Run: [gmsd_fr_010010011] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010013] => [X]
HKLM-x32\...\Run: [gmsd_fr_002020013] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010020] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010025] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010026] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010032] => [X]
HKU\S-1-5-21-652598870-1085955634-3562869207-1000\...\Run: [GoogleChromeAutoLaunch_4CFCB66392E5F69049D64C5AC8C4083C] => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe --no-startup-window
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled
ProxyServer: [.DEFAULT] => http=127.0.0.1:58756;https=127.0.0.1:58756 [Attention - Possible Proxy Malicieux]
R2 cusepefu; C:\Users\GWENDOLINE\AppData\Roaming\F15B5000-1430673986-815C-33D3-E840F22A96FC\jnsxEAFA.tmp [147456 2015-05-03] () [File not signed]
R2 nuryriqu; C:\Program Files (x86)\F15B5000-1430673986-815C-33D3-E840F22A96FC\knsxBAE9.tmp [326656 2015-07-16] () [File not signed]
R2 Spotless Routine; C:\Program Files (x86)\Spotless Routine\Spotless Routine.exe [8016570 2015-07-15] () [File not signed] <==== ATTENTION
2015-07-16 19:53 - 2015-07-16 19:53 - 00000000 _____ C:\Windows\SysWOW64\sho1ABB.tmp
2015-07-16 18:49 - 2015-07-16 23:11 - 00000000 ____D C:\Program Files (x86)\F15B5000-1430673986-815C-33D3-E840F22A96FC
2015-07-15 22:05 - 2015-07-15 22:05 - 00000000 _____ C:\places.sqlite
2015-07-15 22:01 - 2015-07-15 22:00 - 00613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsp1186.tmp
2015-07-15 21:59 - 2015-07-15 21:59 - 00003098 _____ C:\Windows\System32\Tasks\tet3008
2015-07-15 19:29 - 2015-07-15 19:29 - 00000000 ____D C:\Program Files (x86)\Spotless Routine
2015-07-15 19:28 - 2015-07-15 19:29 - 08016570 _____ C:\Windows\SysWOW64\1.exe
2015-07-09 22:33 - 2015-07-09 22:32 - 00613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsoEA7B.tmp
2015-07-08 22:06 - 2015-07-08 22:06 - 00613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsb9168.tmp
2015-07-07 23:30 - 2015-07-07 23:30 - 00000017 _____ C:\Windows\SysWOW64\sho9870.tmp
2015-07-03 09:52 - 2015-07-03 09:52 - 00003290 _____ C:\Windows\System32\Tasks\E6aRljYT7O5P49d
2015-07-03 09:50 - 2015-07-03 09:52 - 00000000 ____D C:\Users\GWENDOLINE\AppData\Roaming\k4uNqgO
2015-07-03 09:50 - 2015-07-03 09:50 - 00003250 _____ C:\Windows\System32\Tasks\wENL72fkui4EkEa
2015-07-03 09:48 - 2015-07-03 09:50 - 00000000 ____D C:\Users\GWENDOLINE\AppData\Roaming\j9RP85a
2015-07-03 09:41 - 2015-07-03 09:41 - 00196608 _____ ( ) C:\E4F9.tmp
2015-07-02 14:08 - 2015-07-16 23:11 - 00000000 ____D C:\ProgramData\abc
2015-07-01 19:28 - 2015-07-18 23:02 - 00000364 _____ C:\Windows\Tasks\SpeedSurf.job
2015-07-01 19:28 - 2015-07-01 19:28 - 00003286 _____ C:\Windows\System32\Tasks\SpeedSurf
2015-06-27 12:50 - 2015-06-27 12:50 - 00000000 _____ C:\Users\GWENDOLINE\AppData\Local\Temp.dat
2015-06-27 12:45 - 2015-07-18 23:02 - 00000364 _____ C:\Windows\Tasks\SoundSpin.job
2015-06-27 12:45 - 2015-06-27 12:45 - 00003286 _____ C:\Windows\System32\Tasks\SoundSpin
2015-06-26 14:41 - 2015-06-26 14:40 - 00613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsuA753.tmp
2015-06-26 14:38 - 2015-06-26 14:38 - 00000000 ____D C:\Users\GWENDOLINE\Documents\Optimizer Pro
2015-07-16 18:50 - 2015-05-03 19:26 - 00000000 ____D C:\Users\GWENDOLINE\AppData\Roaming\F15B5000-1430673986-815C-33D3-E840F22A96FC
2015-07-03 09:52 - 2015-03-25 19:37 - 00000000 ____D C:\Users\GWENDOLINE\AppData\Roaming\hQmc787
2015-06-30 20:52 - 2015-06-09 17:53 - 00000000 ____D C:\ProgramData\15583883210834475548
2015-06-24 20:42 - 2015-05-04 14:48 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-06-22 13:39 - 2015-06-02 11:07 - 00000000 ____D C:\ProgramData\ddaf31c0000643b
2013-11-10 15:24 - 2013-11-10 15:28 - 3993600 _____ () C:\Program Files (x86)\GUT22EC.tmp
2013-12-30 21:45 - 2013-12-30 21:46 - 49940480 _____ () C:\Program Files (x86)\GUTE16E.tmp
2015-07-08 22:06 - 2015-07-08 22:06 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsb9168.tmp
2015-07-09 22:33 - 2015-07-09 22:32 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsoEA7B.tmp
2015-07-15 22:01 - 2015-07-15 22:00 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsp1186.tmp
2015-06-08 16:56 - 2015-06-08 16:55 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nst2C81.tmp
2015-05-03 20:47 - 2015-05-03 20:04 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nst373B.tmp
2015-06-26 14:41 - 2015-06-26 14:40 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsuA753.tmp
Task: {116A9555-9C4A-4CE0-A0FD-92A93B650A27} - System32\Tasks\{21B0F981-4506-4C99-B5AF-A99C056B0AD8} => pcalua.exe -a C:\ProgramData\BreakingNewsAlert\uninstall.exe -c /kb=y /ic=1
Task: {38813972-33AB-4A63-AB73-47280E5A045C} - System32\Tasks\WIN-GGfIfEGCfEGbGffIfCfEGC => C:\Users\GWENDOLINE\AppData\Roaming\~igkqask.exe
Task: {4582ECB4-8CA4-47F4-A3CD-90C551421CFA} - System32\Tasks\SpeedSurf => c:\programdata\{a484470d-5db4-ea5d-a484-4470d5db1c35}\1972881275069008971c.exe <==== ATTENTION
Task: {59A01B17-D75A-45F1-A063-9E9D54BD93D3} - System32\Tasks\6ofvw00n0n1x54p => C:\Users\GWENDOLINE\AppData\Roaming\hQmc787\xbHQxVl.exe [2015-03-25] ( ) <==== ATTENTION
Task: {A477A939-C583-4EF4-8F9C-80C2DAD29E55} - System32\Tasks\Bidaily Synchronize Task[74c7] => c:\programdata\{1bb7125c-375a-577a-1bb7-7125c3754970}\hqghumeaylnlf.exe <==== ATTENTION
Task: {AC0D81C4-2242-4D41-B834-3D0C88E61835} - System32\Tasks\wENL72fkui4EkEa => C:\Users\GWENDOLINE\AppData\Roaming\j9RP85a\TEukbuO.exe [2015-07-03] ( )
Task: {BC87EF21-D042-4ED8-B30D-950B59B95E55} - System32\Tasks\SoundSpin => c:\programdata\{8d672993-bc56-c2b2-8d67-72993bc5a64e}\3866338875848017634c.exe <==== ATTENTION
Task: {C51AEACF-B7A2-42C2-9B85-82F6EF580E2C} - System32\Tasks\tet3008 => C:\PROGRA~2\FASTSE~1\tet3008.exe
Task: {D421C0F0-1516-4D64-8AB6-3F66C338F104} - System32\Tasks\Bidaily Synchronize Task[8da6] => c:\programdata\{113a7f9f-b757-7103-113a-a7f9fb75fe7e}\hqghumeaylnlf.exe <==== ATTENTION
Task: {D5C3DD15-48EC-4459-8013-25532AE37FC5} - System32\Tasks\WIN-statsAdmin => C:\Users\GWENDOLINE\AppData\Local\Microsoft\WinU\~cmstwwn.exe <==== ATTENTION
Task: {DF6AC71E-B590-4F12-97AC-69DD0ED0B324} - System32\Tasks\E6aRljYT7O5P49d => C:\Users\GWENDOLINE\AppData\Roaming\k4uNqgO\fiYX5O1.exe [2015-07-03] ( )
Task: {E44DB637-46F3-4D8D-8CDA-118D7FDEA98E} - System32\Tasks\ChocoThemes => c:\programdata\{d253bfca-2936-4447-d253-3bfca293ff28}\1381265083770620175e.exe <==== ATTENTION
Task: {FA98676F-53F0-423E-9365-1B7652D83EC7} - System32\Tasks\WIN-fdfEfEfAfC => C:\Users\GWENDOLINE\AppData\Roaming\~ykobzhk.exe
Task: C:\Windows\Tasks\Bidaily Synchronize Task[74c7].job => c:\programdata\{1bb7125c-375a-577a-1bb7-7125c3754970}\hqghumeaylnlf.exe <==== ATTENTION
Task: C:\Windows\Tasks\Bidaily Synchronize Task[8da6].job => c:\programdata\{113a7f9f-b757-7103-113a-a7f9fb75fe7e}\hqghumeaylnlf.exe <==== ATTENTION
Task: C:\Windows\Tasks\ChocoThemes.job => c:\programdata\{d253bfca-2936-4447-d253-3bfca293ff28}\1381265083770620175e.exe <==== ATTENTION
Task: C:\Windows\Tasks\SoundSpin.job => c:\programdata\{8d672993-bc56-c2b2-8d67-72993bc5a64e}\3866338875848017634c.exe <==== ATTENTION
Task: C:\Windows\Tasks\SpeedSurf.job => c:\programdata\{a484470d-5db4-ea5d-a484-4470d5db1c35}\1972881275069008971c.exe <==== ATTENTION
Une fois, le texte coller dans le bloc-note.
Menu Fichier puis Enregistrer sous.
A gauche, place toi sur le bureau.F
Dans le champs en bas, nom du fichier mets : fixlist.txt
Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.
Relance FRST et clic sur le bouton Fix
Selon comment un redémarrage est nécessaire (pas obligatoire).
Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.
Redémarre l'ordinateur
puis réinitialise tes navigateurs:
==================================
Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :
Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix
Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
Copie/colle dedans ce qui suit :
HKLM\...\Run: [Windesk Winsearch] => C:\Program Files (x86)\WindeskWinsearch\Windesk Winsearch.exe
KLM-x32\...\Run: [fst_fr_16] => [X]
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [gmsd_fr_495] => [X]
HKLM-x32\...\Run: [gmsd_fr_618] => [X]
HKLM-x32\...\Run: [gmsd_fr_634] => [X]
HKLM-x32\...\Run: [gmsd_fr_640] => [X]
HKLM-x32\...\Run: [gmsd_fr_636] => [X]
HKLM-x32\...\Run: [gmsd_fr_010010011] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010013] => [X]
HKLM-x32\...\Run: [gmsd_fr_002020013] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010020] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010025] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010026] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010032] => [X]
HKU\S-1-5-21-652598870-1085955634-3562869207-1000\...\Run: [GoogleChromeAutoLaunch_4CFCB66392E5F69049D64C5AC8C4083C] => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe --no-startup-window
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled
ProxyServer: [.DEFAULT] => http=127.0.0.1:58756;https=127.0.0.1:58756 [Attention - Possible Proxy Malicieux]
R2 cusepefu; C:\Users\GWENDOLINE\AppData\Roaming\F15B5000-1430673986-815C-33D3-E840F22A96FC\jnsxEAFA.tmp [147456 2015-05-03] () [File not signed]
R2 nuryriqu; C:\Program Files (x86)\F15B5000-1430673986-815C-33D3-E840F22A96FC\knsxBAE9.tmp [326656 2015-07-16] () [File not signed]
R2 Spotless Routine; C:\Program Files (x86)\Spotless Routine\Spotless Routine.exe [8016570 2015-07-15] () [File not signed] <==== ATTENTION
2015-07-16 19:53 - 2015-07-16 19:53 - 00000000 _____ C:\Windows\SysWOW64\sho1ABB.tmp
2015-07-16 18:49 - 2015-07-16 23:11 - 00000000 ____D C:\Program Files (x86)\F15B5000-1430673986-815C-33D3-E840F22A96FC
2015-07-15 22:05 - 2015-07-15 22:05 - 00000000 _____ C:\places.sqlite
2015-07-15 22:01 - 2015-07-15 22:00 - 00613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsp1186.tmp
2015-07-15 21:59 - 2015-07-15 21:59 - 00003098 _____ C:\Windows\System32\Tasks\tet3008
2015-07-15 19:29 - 2015-07-15 19:29 - 00000000 ____D C:\Program Files (x86)\Spotless Routine
2015-07-15 19:28 - 2015-07-15 19:29 - 08016570 _____ C:\Windows\SysWOW64\1.exe
2015-07-09 22:33 - 2015-07-09 22:32 - 00613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsoEA7B.tmp
2015-07-08 22:06 - 2015-07-08 22:06 - 00613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsb9168.tmp
2015-07-07 23:30 - 2015-07-07 23:30 - 00000017 _____ C:\Windows\SysWOW64\sho9870.tmp
2015-07-03 09:52 - 2015-07-03 09:52 - 00003290 _____ C:\Windows\System32\Tasks\E6aRljYT7O5P49d
2015-07-03 09:50 - 2015-07-03 09:52 - 00000000 ____D C:\Users\GWENDOLINE\AppData\Roaming\k4uNqgO
2015-07-03 09:50 - 2015-07-03 09:50 - 00003250 _____ C:\Windows\System32\Tasks\wENL72fkui4EkEa
2015-07-03 09:48 - 2015-07-03 09:50 - 00000000 ____D C:\Users\GWENDOLINE\AppData\Roaming\j9RP85a
2015-07-03 09:41 - 2015-07-03 09:41 - 00196608 _____ ( ) C:\E4F9.tmp
2015-07-02 14:08 - 2015-07-16 23:11 - 00000000 ____D C:\ProgramData\abc
2015-07-01 19:28 - 2015-07-18 23:02 - 00000364 _____ C:\Windows\Tasks\SpeedSurf.job
2015-07-01 19:28 - 2015-07-01 19:28 - 00003286 _____ C:\Windows\System32\Tasks\SpeedSurf
2015-06-27 12:50 - 2015-06-27 12:50 - 00000000 _____ C:\Users\GWENDOLINE\AppData\Local\Temp.dat
2015-06-27 12:45 - 2015-07-18 23:02 - 00000364 _____ C:\Windows\Tasks\SoundSpin.job
2015-06-27 12:45 - 2015-06-27 12:45 - 00003286 _____ C:\Windows\System32\Tasks\SoundSpin
2015-06-26 14:41 - 2015-06-26 14:40 - 00613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsuA753.tmp
2015-06-26 14:38 - 2015-06-26 14:38 - 00000000 ____D C:\Users\GWENDOLINE\Documents\Optimizer Pro
2015-07-16 18:50 - 2015-05-03 19:26 - 00000000 ____D C:\Users\GWENDOLINE\AppData\Roaming\F15B5000-1430673986-815C-33D3-E840F22A96FC
2015-07-03 09:52 - 2015-03-25 19:37 - 00000000 ____D C:\Users\GWENDOLINE\AppData\Roaming\hQmc787
2015-06-30 20:52 - 2015-06-09 17:53 - 00000000 ____D C:\ProgramData\15583883210834475548
2015-06-24 20:42 - 2015-05-04 14:48 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-06-22 13:39 - 2015-06-02 11:07 - 00000000 ____D C:\ProgramData\ddaf31c0000643b
2013-11-10 15:24 - 2013-11-10 15:28 - 3993600 _____ () C:\Program Files (x86)\GUT22EC.tmp
2013-12-30 21:45 - 2013-12-30 21:46 - 49940480 _____ () C:\Program Files (x86)\GUTE16E.tmp
2015-07-08 22:06 - 2015-07-08 22:06 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsb9168.tmp
2015-07-09 22:33 - 2015-07-09 22:32 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsoEA7B.tmp
2015-07-15 22:01 - 2015-07-15 22:00 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsp1186.tmp
2015-06-08 16:56 - 2015-06-08 16:55 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nst2C81.tmp
2015-05-03 20:47 - 2015-05-03 20:04 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nst373B.tmp
2015-06-26 14:41 - 2015-06-26 14:40 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsuA753.tmp
Task: {116A9555-9C4A-4CE0-A0FD-92A93B650A27} - System32\Tasks\{21B0F981-4506-4C99-B5AF-A99C056B0AD8} => pcalua.exe -a C:\ProgramData\BreakingNewsAlert\uninstall.exe -c /kb=y /ic=1
Task: {38813972-33AB-4A63-AB73-47280E5A045C} - System32\Tasks\WIN-GGfIfEGCfEGbGffIfCfEGC => C:\Users\GWENDOLINE\AppData\Roaming\~igkqask.exe
Task: {4582ECB4-8CA4-47F4-A3CD-90C551421CFA} - System32\Tasks\SpeedSurf => c:\programdata\{a484470d-5db4-ea5d-a484-4470d5db1c35}\1972881275069008971c.exe <==== ATTENTION
Task: {59A01B17-D75A-45F1-A063-9E9D54BD93D3} - System32\Tasks\6ofvw00n0n1x54p => C:\Users\GWENDOLINE\AppData\Roaming\hQmc787\xbHQxVl.exe [2015-03-25] ( ) <==== ATTENTION
Task: {A477A939-C583-4EF4-8F9C-80C2DAD29E55} - System32\Tasks\Bidaily Synchronize Task[74c7] => c:\programdata\{1bb7125c-375a-577a-1bb7-7125c3754970}\hqghumeaylnlf.exe <==== ATTENTION
Task: {AC0D81C4-2242-4D41-B834-3D0C88E61835} - System32\Tasks\wENL72fkui4EkEa => C:\Users\GWENDOLINE\AppData\Roaming\j9RP85a\TEukbuO.exe [2015-07-03] ( )
Task: {BC87EF21-D042-4ED8-B30D-950B59B95E55} - System32\Tasks\SoundSpin => c:\programdata\{8d672993-bc56-c2b2-8d67-72993bc5a64e}\3866338875848017634c.exe <==== ATTENTION
Task: {C51AEACF-B7A2-42C2-9B85-82F6EF580E2C} - System32\Tasks\tet3008 => C:\PROGRA~2\FASTSE~1\tet3008.exe
Task: {D421C0F0-1516-4D64-8AB6-3F66C338F104} - System32\Tasks\Bidaily Synchronize Task[8da6] => c:\programdata\{113a7f9f-b757-7103-113a-a7f9fb75fe7e}\hqghumeaylnlf.exe <==== ATTENTION
Task: {D5C3DD15-48EC-4459-8013-25532AE37FC5} - System32\Tasks\WIN-statsAdmin => C:\Users\GWENDOLINE\AppData\Local\Microsoft\WinU\~cmstwwn.exe <==== ATTENTION
Task: {DF6AC71E-B590-4F12-97AC-69DD0ED0B324} - System32\Tasks\E6aRljYT7O5P49d => C:\Users\GWENDOLINE\AppData\Roaming\k4uNqgO\fiYX5O1.exe [2015-07-03] ( )
Task: {E44DB637-46F3-4D8D-8CDA-118D7FDEA98E} - System32\Tasks\ChocoThemes => c:\programdata\{d253bfca-2936-4447-d253-3bfca293ff28}\1381265083770620175e.exe <==== ATTENTION
Task: {FA98676F-53F0-423E-9365-1B7652D83EC7} - System32\Tasks\WIN-fdfEfEfAfC => C:\Users\GWENDOLINE\AppData\Roaming\~ykobzhk.exe
Task: C:\Windows\Tasks\Bidaily Synchronize Task[74c7].job => c:\programdata\{1bb7125c-375a-577a-1bb7-7125c3754970}\hqghumeaylnlf.exe <==== ATTENTION
Task: C:\Windows\Tasks\Bidaily Synchronize Task[8da6].job => c:\programdata\{113a7f9f-b757-7103-113a-a7f9fb75fe7e}\hqghumeaylnlf.exe <==== ATTENTION
Task: C:\Windows\Tasks\ChocoThemes.job => c:\programdata\{d253bfca-2936-4447-d253-3bfca293ff28}\1381265083770620175e.exe <==== ATTENTION
Task: C:\Windows\Tasks\SoundSpin.job => c:\programdata\{8d672993-bc56-c2b2-8d67-72993bc5a64e}\3866338875848017634c.exe <==== ATTENTION
Task: C:\Windows\Tasks\SpeedSurf.job => c:\programdata\{a484470d-5db4-ea5d-a484-4470d5db1c35}\1972881275069008971c.exe <==== ATTENTION
Une fois, le texte coller dans le bloc-note.
Menu Fichier puis Enregistrer sous.
A gauche, place toi sur le bureau.F
Dans le champs en bas, nom du fichier mets : fixlist.txt
Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.
Relance FRST et clic sur le bouton Fix
Selon comment un redémarrage est nécessaire (pas obligatoire).
Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.
Redémarre l'ordinateur
puis réinitialise tes navigateurs:
==================================
Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :
- Internet Explorer et modules complémentaires / moteurs de recherche : https://forum.malekal.com/viewtopic.php?t=41399&start=
- Firefox : https://www.malekal.com/reparer-firefox/?t=36057&start=
- Google Chrome : https://www.malekal.com/reparer-google-chrome/?t=35837&start=
Gwendolinem27
Messages postés
6
Date d'inscription
dimanche 19 juillet 2015
Statut
Membre
Dernière intervention
19 juillet 2015
19 juil. 2015 à 16:31
19 juil. 2015 à 16:31
Fix result of Farbar Recovery Scan Tool (x64) Version:18-07-2015 01
Ran by GWENDOLINE at 2015-07-19 16:29:20 Run:1
Running from C:\Users\GWENDOLINE\Desktop
Loaded Profiles: GWENDOLINE (Available Profiles: GWENDOLINE)
Boot Mode: Normal
==============================================
fixlist content:
HKLM\...\Run: [Windesk Winsearch] => C:\Program Files (x86)\WindeskWinsearch\Windesk Winsearch.exe
KLM-x32\...\Run: [fst_fr_16] => [X]
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [gmsd_fr_495] => [X]
HKLM-x32\...\Run: [gmsd_fr_618] => [X]
HKLM-x32\...\Run: [gmsd_fr_634] => [X]
HKLM-x32\...\Run: [gmsd_fr_640] => [X]
HKLM-x32\...\Run: [gmsd_fr_636] => [X]
HKLM-x32\...\Run: [gmsd_fr_010010011] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010013] => [X]
HKLM-x32\...\Run: [gmsd_fr_002020013] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010020] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010025] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010026] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010032] => [X]
HKU\S-1-5-21-652598870-1085955634-3562869207-1000\...\Run: [GoogleChromeAutoLaunch_4CFCB66392E5F69049D64C5AC8C4083C] => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe --no-startup-window
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled
ProxyServer: [.DEFAULT] => http=127.0.0.1:58756;https=127.0.0.1:58756 [Attention - Possible Proxy Malicieux]
R2 cusepefu; C:\Users\GWENDOLINE\AppData\Roaming\F15B5000-1430673986-815C-33D3-E840F22A96FC\jnsxEAFA.tmp [147456 2015-05-03] () [File not signed]
R2 nuryriqu; C:\Program Files (x86)\F15B5000-1430673986-815C-33D3-E840F22A96FC\knsxBAE9.tmp [326656 2015-07-16] () [File not signed]
R2 Spotless Routine; C:\Program Files (x86)\Spotless Routine\Spotless Routine.exe [8016570 2015-07-15] () [File not signed] <==== ATTENTION
2015-07-16 19:53 - 2015-07-16 19:53 - 00000000 _____ C:\Windows\SysWOW64\sho1ABB.tmp
2015-07-16 18:49 - 2015-07-16 23:11 - 00000000 ____D C:\Program Files (x86)\F15B5000-1430673986-815C-33D3-E840F22A96FC
2015-07-15 22:05 - 2015-07-15 22:05 - 00000000 _____ C:\places.sqlite
2015-07-15 22:01 - 2015-07-15 22:00 - 00613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsp1186.tmp
2015-07-15 21:59 - 2015-07-15 21:59 - 00003098 _____ C:\Windows\System32\Tasks\tet3008
2015-07-15 19:29 - 2015-07-15 19:29 - 00000000 ____D C:\Program Files (x86)\Spotless Routine
2015-07-15 19:28 - 2015-07-15 19:29 - 08016570 _____ C:\Windows\SysWOW64\1.exe
2015-07-09 22:33 - 2015-07-09 22:32 - 00613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsoEA7B.tmp
2015-07-08 22:06 - 2015-07-08 22:06 - 00613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsb9168.tmp
2015-07-07 23:30 - 2015-07-07 23:30 - 00000017 _____ C:\Windows\SysWOW64\sho9870.tmp
2015-07-03 09:52 - 2015-07-03 09:52 - 00003290 _____ C:\Windows\System32\Tasks\E6aRljYT7O5P49d
2015-07-03 09:50 - 2015-07-03 09:52 - 00000000 ____D C:\Users\GWENDOLINE\AppData\Roaming\k4uNqgO
2015-07-03 09:50 - 2015-07-03 09:50 - 00003250 _____ C:\Windows\System32\Tasks\wENL72fkui4EkEa
2015-07-03 09:48 - 2015-07-03 09:50 - 00000000 ____D C:\Users\GWENDOLINE\AppData\Roaming\j9RP85a
2015-07-03 09:41 - 2015-07-03 09:41 - 00196608 _____ ( ) C:\E4F9.tmp
2015-07-02 14:08 - 2015-07-16 23:11 - 00000000 ____D C:\ProgramData\abc
2015-07-01 19:28 - 2015-07-18 23:02 - 00000364 _____ C:\Windows\Tasks\SpeedSurf.job
2015-07-01 19:28 - 2015-07-01 19:28 - 00003286 _____ C:\Windows\System32\Tasks\SpeedSurf
2015-06-27 12:50 - 2015-06-27 12:50 - 00000000 _____ C:\Users\GWENDOLINE\AppData\Local\Temp.dat
2015-06-27 12:45 - 2015-07-18 23:02 - 00000364 _____ C:\Windows\Tasks\SoundSpin.job
2015-06-27 12:45 - 2015-06-27 12:45 - 00003286 _____ C:\Windows\System32\Tasks\SoundSpin
2015-06-26 14:41 - 2015-06-26 14:40 - 00613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsuA753.tmp
2015-06-26 14:38 - 2015-06-26 14:38 - 00000000 ____D C:\Users\GWENDOLINE\Documents\Optimizer Pro
2015-07-16 18:50 - 2015-05-03 19:26 - 00000000 ____D C:\Users\GWENDOLINE\AppData\Roaming\F15B5000-1430673986-815C-33D3-E840F22A96FC
2015-07-03 09:52 - 2015-03-25 19:37 - 00000000 ____D C:\Users\GWENDOLINE\AppData\Roaming\hQmc787
2015-06-30 20:52 - 2015-06-09 17:53 - 00000000 ____D C:\ProgramData\15583883210834475548
2015-06-24 20:42 - 2015-05-04 14:48 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-06-22 13:39 - 2015-06-02 11:07 - 00000000 ____D C:\ProgramData\ddaf31c0000643b
2013-11-10 15:24 - 2013-11-10 15:28 - 3993600 _____ () C:\Program Files (x86)\GUT22EC.tmp
2013-12-30 21:45 - 2013-12-30 21:46 - 49940480 _____ () C:\Program Files (x86)\GUTE16E.tmp
2015-07-08 22:06 - 2015-07-08 22:06 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsb9168.tmp
2015-07-09 22:33 - 2015-07-09 22:32 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsoEA7B.tmp
2015-07-15 22:01 - 2015-07-15 22:00 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsp1186.tmp
2015-06-08 16:56 - 2015-06-08 16:55 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nst2C81.tmp
2015-05-03 20:47 - 2015-05-03 20:04 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nst373B.tmp
2015-06-26 14:41 - 2015-06-26 14:40 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsuA753.tmp
Task: {116A9555-9C4A-4CE0-A0FD-92A93B650A27} - System32\Tasks\{21B0F981-4506-4C99-B5AF-A99C056B0AD8} => pcalua.exe -a C:\ProgramData\BreakingNewsAlert\uninstall.exe -c /kb=y /ic=1
Task: {38813972-33AB-4A63-AB73-47280E5A045C} - System32\Tasks\WIN-GGfIfEGCfEGbGffIfCfEGC => C:\Users\GWENDOLINE\AppData\Roaming\~igkqask.exe
Task: {4582ECB4-8CA4-47F4-A3CD-90C551421CFA} - System32\Tasks\SpeedSurf => c:\programdata\{a484470d-5db4-ea5d-a484-4470d5db1c35}\1972881275069008971c.exe <==== ATTENTION
Task: {59A01B17-D75A-45F1-A063-9E9D54BD93D3} - System32\Tasks\6ofvw00n0n1x54p => C:\Users\GWENDOLINE\AppData\Roaming\hQmc787\xbHQxVl.exe [2015-03-25] ( ) <==== ATTENTION
Task: {A477A939-C583-4EF4-8F9C-80C2DAD29E55} - System32\Tasks\Bidaily Synchronize Task[74c7] => c:\programdata\{1bb7125c-375a-577a-1bb7-7125c3754970}\hqghumeaylnlf.exe <==== ATTENTION
Task: {AC0D81C4-2242-4D41-B834-3D0C88E61835} - System32\Tasks\wENL72fkui4EkEa => C:\Users\GWENDOLINE\AppData\Roaming\j9RP85a\TEukbuO.exe [2015-07-03] ( )
Task: {BC87EF21-D042-4ED8-B30D-950B59B95E55} - System32\Tasks\SoundSpin => c:\programdata\{8d672993-bc56-c2b2-8d67-72993bc5a64e}\3866338875848017634c.exe <==== ATTENTION
Task: {C51AEACF-B7A2-42C2-9B85-82F6EF580E2C} - System32\Tasks\tet3008 => C:\PROGRA~2\FASTSE~1\tet3008.exe
Task: {D421C0F0-1516-4D64-8AB6-3F66C338F104} - System32\Tasks\Bidaily Synchronize Task[8da6] => c:\programdata\{113a7f9f-b757-7103-113a-a7f9fb75fe7e}\hqghumeaylnlf.exe <==== ATTENTION
Task: {D5C3DD15-48EC-4459-8013-25532AE37FC5} - System32\Tasks\WIN-statsAdmin => C:\Users\GWENDOLINE\AppData\Local\Microsoft\WinU\~cmstwwn.exe <==== ATTENTION
Task: {DF6AC71E-B590-4F12-97AC-69DD0ED0B324} - System32\Tasks\E6aRljYT7O5P49d => C:\Users\GWENDOLINE\AppData\Roaming\k4uNqgO\fiYX5O1.exe [2015-07-03] ( )
Task: {E44DB637-46F3-4D8D-8CDA-118D7FDEA98E} - System32\Tasks\ChocoThemes => c:\programdata\{d253bfca-2936-4447-d253-3bfca293ff28}\1381265083770620175e.exe <==== ATTENTION
Task: {FA98676F-53F0-423E-9365-1B7652D83EC7} - System32\Tasks\WIN-fdfEfEfAfC => C:\Users\GWENDOLINE\AppData\Roaming\~ykobzhk.exe
Task: C:\Windows\Tasks\Bidaily Synchronize Task[74c7].job => c:\programdata\{1bb7125c-375a-577a-1bb7-7125c3754970}\hqghumeaylnlf.exe <==== ATTENTION
Task: C:\Windows\Tasks\Bidaily Synchronize Task[8da6].job => c:\programdata\{113a7f9f-b757-7103-113a-a7f9fb75fe7e}\hqghumeaylnlf.exe <==== ATTENTION
Task: C:\Windows\Tasks\ChocoThemes.job => c:\programdata\{d253bfca-2936-4447-d253-3bfca293ff28}\1381265083770620175e.exe <==== ATTENTION
Task: C:\Windows\Tasks\SoundSpin.job => c:\programdata\{8d672993-bc56-c2b2-8d67-72993bc5a64e}\3866338875848017634c.exe <==== ATTENTION
Task: C:\Windows\Tasks\SpeedSurf.job => c:\programdata\{a484470d-5db4-ea5d-a484-4470d5db1c35}\1972881275069008971c.exe <==== ATTENTION
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Windesk Winsearch => value removed successfully
KLM-x32\...\Run: [fst_fr_16] => [X] => Error: No automatic fix found for this entry.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\HP Software Update => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_495 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_618 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_634 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_640 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_636 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_010010011 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_005010013 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_002020013 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_005010020 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_005010025 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_005010026 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_005010032 => value removed successfully
HKU\S-1-5-21-652598870-1085955634-3562869207-1000\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_4CFCB66392E5F69049D64C5AC8C4083C => value removed successfully
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value removed successfully
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully
cusepefu => Service stopped successfully.
cusepefu => Service removed successfully
nuryriqu => Service stopped successfully.
nuryriqu => Service removed successfully
Spotless Routine => Service stopped successfully.
Spotless Routine => Service removed successfully
C:\Windows\SysWOW64\sho1ABB.tmp => moved successfully.
C:\Program Files (x86)\F15B5000-1430673986-815C-33D3-E840F22A96FC => moved successfully.
C:\places.sqlite => moved successfully.
C:\Users\GWENDOLINE\AppData\Local\nsp1186.tmp => moved successfully.
C:\Windows\System32\Tasks\tet3008 => moved successfully.
C:\Program Files (x86)\Spotless Routine => moved successfully.
C:\Windows\SysWOW64\1.exe => moved successfully.
C:\Users\GWENDOLINE\AppData\Local\nsoEA7B.tmp => moved successfully.
C:\Users\GWENDOLINE\AppData\Local\nsb9168.tmp => moved successfully.
C:\Windows\SysWOW64\sho9870.tmp => moved successfully.
C:\Windows\System32\Tasks\E6aRljYT7O5P49d => moved successfully.
C:\Users\GWENDOLINE\AppData\Roaming\k4uNqgO => moved successfully.
C:\Windows\System32\Tasks\wENL72fkui4EkEa => moved successfully.
C:\Users\GWENDOLINE\AppData\Roaming\j9RP85a => moved successfully.
C:\E4F9.tmp => moved successfully.
C:\ProgramData\abc => moved successfully.
C:\Windows\Tasks\SpeedSurf.job => moved successfully.
C:\Windows\System32\Tasks\SpeedSurf => moved successfully.
C:\Users\GWENDOLINE\AppData\Local\Temp.dat => moved successfully.
C:\Windows\Tasks\SoundSpin.job => moved successfully.
C:\Windows\System32\Tasks\SoundSpin => moved successfully.
C:\Users\GWENDOLINE\AppData\Local\nsuA753.tmp => moved successfully.
C:\Users\GWENDOLINE\Documents\Optimizer Pro => moved successfully.
C:\Users\GWENDOLINE\AppData\Roaming\F15B5000-1430673986-815C-33D3-E840F22A96FC => moved successfully.
C:\Users\GWENDOLINE\AppData\Roaming\hQmc787 => moved successfully.
C:\ProgramData\15583883210834475548 => moved successfully.
C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 => moved successfully.
C:\ProgramData\ddaf31c0000643b => moved successfully.
C:\Program Files (x86)\GUT22EC.tmp => moved successfully.
C:\Program Files (x86)\GUTE16E.tmp => moved successfully.
"C:\Users\GWENDOLINE\AppData\Local\nsb9168.tmp" => File/Folder not found.
"C:\Users\GWENDOLINE\AppData\Local\nsoEA7B.tmp" => File/Folder not found.
"C:\Users\GWENDOLINE\AppData\Local\nsp1186.tmp" => File/Folder not found.
C:\Users\GWENDOLINE\AppData\Local\nst2C81.tmp => moved successfully.
C:\Users\GWENDOLINE\AppData\Local\nst373B.tmp => moved successfully.
"C:\Users\GWENDOLINE\AppData\Local\nsuA753.tmp" => File/Folder not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{116A9555-9C4A-4CE0-A0FD-92A93B650A27}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{116A9555-9C4A-4CE0-A0FD-92A93B650A27}" => key removed successfully
C:\Windows\System32\Tasks\{21B0F981-4506-4C99-B5AF-A99C056B0AD8} => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{21B0F981-4506-4C99-B5AF-A99C056B0AD8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{38813972-33AB-4A63-AB73-47280E5A045C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{38813972-33AB-4A63-AB73-47280E5A045C}" => key removed successfully
C:\Windows\System32\Tasks\WIN-GGfIfEGCfEGbGffIfCfEGC => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WIN-GGfIfEGCfEGbGffIfCfEGC" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4582ECB4-8CA4-47F4-A3CD-90C551421CFA}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4582ECB4-8CA4-47F4-A3CD-90C551421CFA}" => key removed successfully
C:\Windows\System32\Tasks\SpeedSurf not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SpeedSurf" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{59A01B17-D75A-45F1-A063-9E9D54BD93D3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{59A01B17-D75A-45F1-A063-9E9D54BD93D3}" => key removed successfully
C:\Windows\System32\Tasks\6ofvw00n0n1x54p => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\6ofvw00n0n1x54p" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A477A939-C583-4EF4-8F9C-80C2DAD29E55}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A477A939-C583-4EF4-8F9C-80C2DAD29E55}" => key removed successfully
C:\Windows\System32\Tasks\Bidaily Synchronize Task[74c7] => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Bidaily Synchronize Task[74c7]" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AC0D81C4-2242-4D41-B834-3D0C88E61835}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC0D81C4-2242-4D41-B834-3D0C88E61835}" => key removed successfully
C:\Windows\System32\Tasks\wENL72fkui4EkEa not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\wENL72fkui4EkEa" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BC87EF21-D042-4ED8-B30D-950B59B95E55}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BC87EF21-D042-4ED8-B30D-950B59B95E55}" => key removed successfully
C:\Windows\System32\Tasks\SoundSpin not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SoundSpin" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C51AEACF-B7A2-42C2-9B85-82F6EF580E2C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C51AEACF-B7A2-42C2-9B85-82F6EF580E2C}" => key removed successfully
C:\Windows\System32\Tasks\tet3008 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\tet3008" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D421C0F0-1516-4D64-8AB6-3F66C338F104}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D421C0F0-1516-4D64-8AB6-3F66C338F104}" => key removed successfully
C:\Windows\System32\Tasks\Bidaily Synchronize Task[8da6] => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Bidaily Synchronize Task[8da6]" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D5C3DD15-48EC-4459-8013-25532AE37FC5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D5C3DD15-48EC-4459-8013-25532AE37FC5}" => key removed successfully
C:\Windows\System32\Tasks\WIN-statsAdmin => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WIN-statsAdmin" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DF6AC71E-B590-4F12-97AC-69DD0ED0B324}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DF6AC71E-B590-4F12-97AC-69DD0ED0B324}" => key removed successfully
C:\Windows\System32\Tasks\E6aRljYT7O5P49d not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\E6aRljYT7O5P49d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E44DB637-46F3-4D8D-8CDA-118D7FDEA98E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E44DB637-46F3-4D8D-8CDA-118D7FDEA98E}" => key removed successfully
C:\Windows\System32\Tasks\ChocoThemes => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ChocoThemes" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FA98676F-53F0-423E-9365-1B7652D83EC7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA98676F-53F0-423E-9365-1B7652D83EC7}" => key removed successfully
C:\Windows\System32\Tasks\WIN-fdfEfEfAfC => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WIN-fdfEfEfAfC" => key removed successfully
C:\Windows\Tasks\Bidaily Synchronize Task[74c7].job => moved successfully.
C:\Windows\Tasks\Bidaily Synchronize Task[8da6].job => moved successfully.
C:\Windows\Tasks\ChocoThemes.job => moved successfully.
C:\Windows\Tasks\SoundSpin.job not found.
C:\Windows\Tasks\SpeedSurf.job not found.
Ran by GWENDOLINE at 2015-07-19 16:29:20 Run:1
Running from C:\Users\GWENDOLINE\Desktop
Loaded Profiles: GWENDOLINE (Available Profiles: GWENDOLINE)
Boot Mode: Normal
==============================================
fixlist content:
HKLM\...\Run: [Windesk Winsearch] => C:\Program Files (x86)\WindeskWinsearch\Windesk Winsearch.exe
KLM-x32\...\Run: [fst_fr_16] => [X]
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [gmsd_fr_495] => [X]
HKLM-x32\...\Run: [gmsd_fr_618] => [X]
HKLM-x32\...\Run: [gmsd_fr_634] => [X]
HKLM-x32\...\Run: [gmsd_fr_640] => [X]
HKLM-x32\...\Run: [gmsd_fr_636] => [X]
HKLM-x32\...\Run: [gmsd_fr_010010011] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010013] => [X]
HKLM-x32\...\Run: [gmsd_fr_002020013] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010020] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010025] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010026] => [X]
HKLM-x32\...\Run: [gmsd_fr_005010032] => [X]
HKU\S-1-5-21-652598870-1085955634-3562869207-1000\...\Run: [GoogleChromeAutoLaunch_4CFCB66392E5F69049D64C5AC8C4083C] => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe --no-startup-window
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled
ProxyServer: [.DEFAULT] => http=127.0.0.1:58756;https=127.0.0.1:58756 [Attention - Possible Proxy Malicieux]
R2 cusepefu; C:\Users\GWENDOLINE\AppData\Roaming\F15B5000-1430673986-815C-33D3-E840F22A96FC\jnsxEAFA.tmp [147456 2015-05-03] () [File not signed]
R2 nuryriqu; C:\Program Files (x86)\F15B5000-1430673986-815C-33D3-E840F22A96FC\knsxBAE9.tmp [326656 2015-07-16] () [File not signed]
R2 Spotless Routine; C:\Program Files (x86)\Spotless Routine\Spotless Routine.exe [8016570 2015-07-15] () [File not signed] <==== ATTENTION
2015-07-16 19:53 - 2015-07-16 19:53 - 00000000 _____ C:\Windows\SysWOW64\sho1ABB.tmp
2015-07-16 18:49 - 2015-07-16 23:11 - 00000000 ____D C:\Program Files (x86)\F15B5000-1430673986-815C-33D3-E840F22A96FC
2015-07-15 22:05 - 2015-07-15 22:05 - 00000000 _____ C:\places.sqlite
2015-07-15 22:01 - 2015-07-15 22:00 - 00613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsp1186.tmp
2015-07-15 21:59 - 2015-07-15 21:59 - 00003098 _____ C:\Windows\System32\Tasks\tet3008
2015-07-15 19:29 - 2015-07-15 19:29 - 00000000 ____D C:\Program Files (x86)\Spotless Routine
2015-07-15 19:28 - 2015-07-15 19:29 - 08016570 _____ C:\Windows\SysWOW64\1.exe
2015-07-09 22:33 - 2015-07-09 22:32 - 00613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsoEA7B.tmp
2015-07-08 22:06 - 2015-07-08 22:06 - 00613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsb9168.tmp
2015-07-07 23:30 - 2015-07-07 23:30 - 00000017 _____ C:\Windows\SysWOW64\sho9870.tmp
2015-07-03 09:52 - 2015-07-03 09:52 - 00003290 _____ C:\Windows\System32\Tasks\E6aRljYT7O5P49d
2015-07-03 09:50 - 2015-07-03 09:52 - 00000000 ____D C:\Users\GWENDOLINE\AppData\Roaming\k4uNqgO
2015-07-03 09:50 - 2015-07-03 09:50 - 00003250 _____ C:\Windows\System32\Tasks\wENL72fkui4EkEa
2015-07-03 09:48 - 2015-07-03 09:50 - 00000000 ____D C:\Users\GWENDOLINE\AppData\Roaming\j9RP85a
2015-07-03 09:41 - 2015-07-03 09:41 - 00196608 _____ ( ) C:\E4F9.tmp
2015-07-02 14:08 - 2015-07-16 23:11 - 00000000 ____D C:\ProgramData\abc
2015-07-01 19:28 - 2015-07-18 23:02 - 00000364 _____ C:\Windows\Tasks\SpeedSurf.job
2015-07-01 19:28 - 2015-07-01 19:28 - 00003286 _____ C:\Windows\System32\Tasks\SpeedSurf
2015-06-27 12:50 - 2015-06-27 12:50 - 00000000 _____ C:\Users\GWENDOLINE\AppData\Local\Temp.dat
2015-06-27 12:45 - 2015-07-18 23:02 - 00000364 _____ C:\Windows\Tasks\SoundSpin.job
2015-06-27 12:45 - 2015-06-27 12:45 - 00003286 _____ C:\Windows\System32\Tasks\SoundSpin
2015-06-26 14:41 - 2015-06-26 14:40 - 00613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsuA753.tmp
2015-06-26 14:38 - 2015-06-26 14:38 - 00000000 ____D C:\Users\GWENDOLINE\Documents\Optimizer Pro
2015-07-16 18:50 - 2015-05-03 19:26 - 00000000 ____D C:\Users\GWENDOLINE\AppData\Roaming\F15B5000-1430673986-815C-33D3-E840F22A96FC
2015-07-03 09:52 - 2015-03-25 19:37 - 00000000 ____D C:\Users\GWENDOLINE\AppData\Roaming\hQmc787
2015-06-30 20:52 - 2015-06-09 17:53 - 00000000 ____D C:\ProgramData\15583883210834475548
2015-06-24 20:42 - 2015-05-04 14:48 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-06-22 13:39 - 2015-06-02 11:07 - 00000000 ____D C:\ProgramData\ddaf31c0000643b
2013-11-10 15:24 - 2013-11-10 15:28 - 3993600 _____ () C:\Program Files (x86)\GUT22EC.tmp
2013-12-30 21:45 - 2013-12-30 21:46 - 49940480 _____ () C:\Program Files (x86)\GUTE16E.tmp
2015-07-08 22:06 - 2015-07-08 22:06 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsb9168.tmp
2015-07-09 22:33 - 2015-07-09 22:32 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsoEA7B.tmp
2015-07-15 22:01 - 2015-07-15 22:00 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsp1186.tmp
2015-06-08 16:56 - 2015-06-08 16:55 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nst2C81.tmp
2015-05-03 20:47 - 2015-05-03 20:04 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nst373B.tmp
2015-06-26 14:41 - 2015-06-26 14:40 - 0613255 _____ (CMI Limited) C:\Users\GWENDOLINE\AppData\Local\nsuA753.tmp
Task: {116A9555-9C4A-4CE0-A0FD-92A93B650A27} - System32\Tasks\{21B0F981-4506-4C99-B5AF-A99C056B0AD8} => pcalua.exe -a C:\ProgramData\BreakingNewsAlert\uninstall.exe -c /kb=y /ic=1
Task: {38813972-33AB-4A63-AB73-47280E5A045C} - System32\Tasks\WIN-GGfIfEGCfEGbGffIfCfEGC => C:\Users\GWENDOLINE\AppData\Roaming\~igkqask.exe
Task: {4582ECB4-8CA4-47F4-A3CD-90C551421CFA} - System32\Tasks\SpeedSurf => c:\programdata\{a484470d-5db4-ea5d-a484-4470d5db1c35}\1972881275069008971c.exe <==== ATTENTION
Task: {59A01B17-D75A-45F1-A063-9E9D54BD93D3} - System32\Tasks\6ofvw00n0n1x54p => C:\Users\GWENDOLINE\AppData\Roaming\hQmc787\xbHQxVl.exe [2015-03-25] ( ) <==== ATTENTION
Task: {A477A939-C583-4EF4-8F9C-80C2DAD29E55} - System32\Tasks\Bidaily Synchronize Task[74c7] => c:\programdata\{1bb7125c-375a-577a-1bb7-7125c3754970}\hqghumeaylnlf.exe <==== ATTENTION
Task: {AC0D81C4-2242-4D41-B834-3D0C88E61835} - System32\Tasks\wENL72fkui4EkEa => C:\Users\GWENDOLINE\AppData\Roaming\j9RP85a\TEukbuO.exe [2015-07-03] ( )
Task: {BC87EF21-D042-4ED8-B30D-950B59B95E55} - System32\Tasks\SoundSpin => c:\programdata\{8d672993-bc56-c2b2-8d67-72993bc5a64e}\3866338875848017634c.exe <==== ATTENTION
Task: {C51AEACF-B7A2-42C2-9B85-82F6EF580E2C} - System32\Tasks\tet3008 => C:\PROGRA~2\FASTSE~1\tet3008.exe
Task: {D421C0F0-1516-4D64-8AB6-3F66C338F104} - System32\Tasks\Bidaily Synchronize Task[8da6] => c:\programdata\{113a7f9f-b757-7103-113a-a7f9fb75fe7e}\hqghumeaylnlf.exe <==== ATTENTION
Task: {D5C3DD15-48EC-4459-8013-25532AE37FC5} - System32\Tasks\WIN-statsAdmin => C:\Users\GWENDOLINE\AppData\Local\Microsoft\WinU\~cmstwwn.exe <==== ATTENTION
Task: {DF6AC71E-B590-4F12-97AC-69DD0ED0B324} - System32\Tasks\E6aRljYT7O5P49d => C:\Users\GWENDOLINE\AppData\Roaming\k4uNqgO\fiYX5O1.exe [2015-07-03] ( )
Task: {E44DB637-46F3-4D8D-8CDA-118D7FDEA98E} - System32\Tasks\ChocoThemes => c:\programdata\{d253bfca-2936-4447-d253-3bfca293ff28}\1381265083770620175e.exe <==== ATTENTION
Task: {FA98676F-53F0-423E-9365-1B7652D83EC7} - System32\Tasks\WIN-fdfEfEfAfC => C:\Users\GWENDOLINE\AppData\Roaming\~ykobzhk.exe
Task: C:\Windows\Tasks\Bidaily Synchronize Task[74c7].job => c:\programdata\{1bb7125c-375a-577a-1bb7-7125c3754970}\hqghumeaylnlf.exe <==== ATTENTION
Task: C:\Windows\Tasks\Bidaily Synchronize Task[8da6].job => c:\programdata\{113a7f9f-b757-7103-113a-a7f9fb75fe7e}\hqghumeaylnlf.exe <==== ATTENTION
Task: C:\Windows\Tasks\ChocoThemes.job => c:\programdata\{d253bfca-2936-4447-d253-3bfca293ff28}\1381265083770620175e.exe <==== ATTENTION
Task: C:\Windows\Tasks\SoundSpin.job => c:\programdata\{8d672993-bc56-c2b2-8d67-72993bc5a64e}\3866338875848017634c.exe <==== ATTENTION
Task: C:\Windows\Tasks\SpeedSurf.job => c:\programdata\{a484470d-5db4-ea5d-a484-4470d5db1c35}\1972881275069008971c.exe <==== ATTENTION
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Windesk Winsearch => value removed successfully
KLM-x32\...\Run: [fst_fr_16] => [X] => Error: No automatic fix found for this entry.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\HP Software Update => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_495 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_618 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_634 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_640 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_636 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_010010011 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_005010013 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_002020013 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_005010020 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_005010025 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_005010026 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_005010032 => value removed successfully
HKU\S-1-5-21-652598870-1085955634-3562869207-1000\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_4CFCB66392E5F69049D64C5AC8C4083C => value removed successfully
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value removed successfully
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully
cusepefu => Service stopped successfully.
cusepefu => Service removed successfully
nuryriqu => Service stopped successfully.
nuryriqu => Service removed successfully
Spotless Routine => Service stopped successfully.
Spotless Routine => Service removed successfully
C:\Windows\SysWOW64\sho1ABB.tmp => moved successfully.
C:\Program Files (x86)\F15B5000-1430673986-815C-33D3-E840F22A96FC => moved successfully.
C:\places.sqlite => moved successfully.
C:\Users\GWENDOLINE\AppData\Local\nsp1186.tmp => moved successfully.
C:\Windows\System32\Tasks\tet3008 => moved successfully.
C:\Program Files (x86)\Spotless Routine => moved successfully.
C:\Windows\SysWOW64\1.exe => moved successfully.
C:\Users\GWENDOLINE\AppData\Local\nsoEA7B.tmp => moved successfully.
C:\Users\GWENDOLINE\AppData\Local\nsb9168.tmp => moved successfully.
C:\Windows\SysWOW64\sho9870.tmp => moved successfully.
C:\Windows\System32\Tasks\E6aRljYT7O5P49d => moved successfully.
C:\Users\GWENDOLINE\AppData\Roaming\k4uNqgO => moved successfully.
C:\Windows\System32\Tasks\wENL72fkui4EkEa => moved successfully.
C:\Users\GWENDOLINE\AppData\Roaming\j9RP85a => moved successfully.
C:\E4F9.tmp => moved successfully.
C:\ProgramData\abc => moved successfully.
C:\Windows\Tasks\SpeedSurf.job => moved successfully.
C:\Windows\System32\Tasks\SpeedSurf => moved successfully.
C:\Users\GWENDOLINE\AppData\Local\Temp.dat => moved successfully.
C:\Windows\Tasks\SoundSpin.job => moved successfully.
C:\Windows\System32\Tasks\SoundSpin => moved successfully.
C:\Users\GWENDOLINE\AppData\Local\nsuA753.tmp => moved successfully.
C:\Users\GWENDOLINE\Documents\Optimizer Pro => moved successfully.
C:\Users\GWENDOLINE\AppData\Roaming\F15B5000-1430673986-815C-33D3-E840F22A96FC => moved successfully.
C:\Users\GWENDOLINE\AppData\Roaming\hQmc787 => moved successfully.
C:\ProgramData\15583883210834475548 => moved successfully.
C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 => moved successfully.
C:\ProgramData\ddaf31c0000643b => moved successfully.
C:\Program Files (x86)\GUT22EC.tmp => moved successfully.
C:\Program Files (x86)\GUTE16E.tmp => moved successfully.
"C:\Users\GWENDOLINE\AppData\Local\nsb9168.tmp" => File/Folder not found.
"C:\Users\GWENDOLINE\AppData\Local\nsoEA7B.tmp" => File/Folder not found.
"C:\Users\GWENDOLINE\AppData\Local\nsp1186.tmp" => File/Folder not found.
C:\Users\GWENDOLINE\AppData\Local\nst2C81.tmp => moved successfully.
C:\Users\GWENDOLINE\AppData\Local\nst373B.tmp => moved successfully.
"C:\Users\GWENDOLINE\AppData\Local\nsuA753.tmp" => File/Folder not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{116A9555-9C4A-4CE0-A0FD-92A93B650A27}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{116A9555-9C4A-4CE0-A0FD-92A93B650A27}" => key removed successfully
C:\Windows\System32\Tasks\{21B0F981-4506-4C99-B5AF-A99C056B0AD8} => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{21B0F981-4506-4C99-B5AF-A99C056B0AD8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{38813972-33AB-4A63-AB73-47280E5A045C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{38813972-33AB-4A63-AB73-47280E5A045C}" => key removed successfully
C:\Windows\System32\Tasks\WIN-GGfIfEGCfEGbGffIfCfEGC => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WIN-GGfIfEGCfEGbGffIfCfEGC" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4582ECB4-8CA4-47F4-A3CD-90C551421CFA}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4582ECB4-8CA4-47F4-A3CD-90C551421CFA}" => key removed successfully
C:\Windows\System32\Tasks\SpeedSurf not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SpeedSurf" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{59A01B17-D75A-45F1-A063-9E9D54BD93D3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{59A01B17-D75A-45F1-A063-9E9D54BD93D3}" => key removed successfully
C:\Windows\System32\Tasks\6ofvw00n0n1x54p => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\6ofvw00n0n1x54p" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A477A939-C583-4EF4-8F9C-80C2DAD29E55}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A477A939-C583-4EF4-8F9C-80C2DAD29E55}" => key removed successfully
C:\Windows\System32\Tasks\Bidaily Synchronize Task[74c7] => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Bidaily Synchronize Task[74c7]" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AC0D81C4-2242-4D41-B834-3D0C88E61835}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC0D81C4-2242-4D41-B834-3D0C88E61835}" => key removed successfully
C:\Windows\System32\Tasks\wENL72fkui4EkEa not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\wENL72fkui4EkEa" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BC87EF21-D042-4ED8-B30D-950B59B95E55}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BC87EF21-D042-4ED8-B30D-950B59B95E55}" => key removed successfully
C:\Windows\System32\Tasks\SoundSpin not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SoundSpin" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C51AEACF-B7A2-42C2-9B85-82F6EF580E2C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C51AEACF-B7A2-42C2-9B85-82F6EF580E2C}" => key removed successfully
C:\Windows\System32\Tasks\tet3008 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\tet3008" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D421C0F0-1516-4D64-8AB6-3F66C338F104}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D421C0F0-1516-4D64-8AB6-3F66C338F104}" => key removed successfully
C:\Windows\System32\Tasks\Bidaily Synchronize Task[8da6] => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Bidaily Synchronize Task[8da6]" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D5C3DD15-48EC-4459-8013-25532AE37FC5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D5C3DD15-48EC-4459-8013-25532AE37FC5}" => key removed successfully
C:\Windows\System32\Tasks\WIN-statsAdmin => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WIN-statsAdmin" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DF6AC71E-B590-4F12-97AC-69DD0ED0B324}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DF6AC71E-B590-4F12-97AC-69DD0ED0B324}" => key removed successfully
C:\Windows\System32\Tasks\E6aRljYT7O5P49d not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\E6aRljYT7O5P49d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E44DB637-46F3-4D8D-8CDA-118D7FDEA98E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E44DB637-46F3-4D8D-8CDA-118D7FDEA98E}" => key removed successfully
C:\Windows\System32\Tasks\ChocoThemes => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ChocoThemes" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FA98676F-53F0-423E-9365-1B7652D83EC7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA98676F-53F0-423E-9365-1B7652D83EC7}" => key removed successfully
C:\Windows\System32\Tasks\WIN-fdfEfEfAfC => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WIN-fdfEfEfAfC" => key removed successfully
C:\Windows\Tasks\Bidaily Synchronize Task[74c7].job => moved successfully.
C:\Windows\Tasks\Bidaily Synchronize Task[8da6].job => moved successfully.
C:\Windows\Tasks\ChocoThemes.job => moved successfully.
C:\Windows\Tasks\SoundSpin.job not found.
C:\Windows\Tasks\SpeedSurf.job not found.
End of Fixlog 16:29:39
Malekal_morte-
Messages postés
180304
Date d'inscription
mercredi 17 mai 2006
Statut
Modérateur, Contributeur sécurité
Dernière intervention
15 décembre 2020
24 663
19 juil. 2015 à 16:53
19 juil. 2015 à 16:53
ok, voici la suite :
Malwarebytes (temps : environ 40min de scan):
==================================================
Télécharge et installe Malwarebyte : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
Mets le à jour puis lance un examen.
A la fin du scan, clic sur "Supprimer Selection" en bas à gauche.
Redémarre l'ordinateur si besoin.
Après redémarrage, relance Malwarebytes.
Vas chercher le rapport dans l'onglet Historique.
A gauche Journal des examens.
Doube-clic sur l'examen dans la liste.
Puis en bas Copier dans le presse papier
Vas sur http://pjjoint.malekal.com et en bas, clic droit / coller pour coller le rapport du scan Malwarebytes.
Clic sur envoyer.
Dans un nouveau message ici en réponse, donne le lien pjjoint afin de pouvoir consulter le rapport.
Malwarebytes (temps : environ 40min de scan):
==================================================
Télécharge et installe Malwarebyte : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
Mets le à jour puis lance un examen.
A la fin du scan, clic sur "Supprimer Selection" en bas à gauche.
Redémarre l'ordinateur si besoin.
Après redémarrage, relance Malwarebytes.
Vas chercher le rapport dans l'onglet Historique.
A gauche Journal des examens.
Doube-clic sur l'examen dans la liste.
Puis en bas Copier dans le presse papier
Vas sur http://pjjoint.malekal.com et en bas, clic droit / coller pour coller le rapport du scan Malwarebytes.
Clic sur envoyer.
Dans un nouveau message ici en réponse, donne le lien pjjoint afin de pouvoir consulter le rapport.
19 juil. 2015 à 15:52
19 juil. 2015 à 15:54
19 juil. 2015 à 15:57
19 juil. 2015 à 15:59
https://pjjoint.malekal.com/files.php?id=20150719_v14r13r5h5e7
https://pjjoint.malekal.com/files.php?id=20150719_v12h968c9