Virus infecte ordinateur ( dnsunlocker )

Fermé
icelande Messages postés 7 Date d'inscription mercredi 22 juillet 2015 Statut Membre Dernière intervention 27 octobre 2016 - 22 juil. 2015 à 14:38
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 - 23 juil. 2015 à 19:16
Salut, je rencontre le même soucis. Lorsque je suis sur mon navigateur web, de nombreuses publicités apparaissent, certains mots sont accompagnés d'une flèche verte ou souligné en bleu. J'ai installé adwcleaner ainsi que malwayrebeates et lancé l'analyse sans succès, j'ai vérifié dans les modules de mon navigateur ( firefox ) et désactivé les extensions louches mais rien.

Voici mon rapport adwcleaner :
Malwarebytes Anti-Malware
www.malwarebytes.org

Date de l'analyse: 22/07/2015
Heure de l'analyse: 13:17
Fichier journal: Rapprtmalwarebytes.txt
Administrateur: Oui

Version: 2.1.8.1057
Base de données de programmes malveillants: v2015.07.22.02
Base de données de rootkits: v2015.07.17.01
Licence: Gratuit
Protection contre les programmes malveillants: Désactivé
Protection contre les sites Web malveillants: Désactivé
Autoprotection: Désactivé

Système d'exploitation: Windows 7 Service Pack 1
Processeur: x86
Système de fichiers: NTFS
Utilisateur: Yolande 2

Type d'analyse: Analyse des menaces
Résultat: Terminé
Objets analysés: 449636
Temps écoulé: 27 min, 25 s

Mémoire: Activé
Démarrage: Activé
Système de fichiers: Activé
Archives: Activé
Rootkits: Désactivé
Heuristique: Activé
PUP: Activé
PUM: Activé

Processus: 3
PUP.Optional.PullUpdate.A, C:\ProgramData\bPmMfOR\nQHJSJWW.exe, 2324, Supprimer au redémarrage, [02c838acdeacf046d56f5b10a560ab55]
PUP.Optional.PullUpdate.Gen, C:\ProgramData\Iihefaufjia\1.0.4.1\oaueunoi.exe, 3256, Supprimer au redémarrage, [6f5bc0242961290d55c032696a9ad12f]
PUP.Optional.PullUpdate.Gen, C:\ProgramData\Iihefaufjia\1.0.4.1\oaueunoi.exe, 5900, Supprimer au redémarrage, [6f5bc0242961290d55c032696a9ad12f]

Modules: 1
PUP.Optional.PullUpdate.Gen, C:\ProgramData\Iihefaufjia\1.0.4.1\sqlite3.dll, Supprimer au redémarrage, [6f5bc0242961290d55c032696a9ad12f],

Clés du registre: 65
PUP.Optional.PullUpdate.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\nQHJSJWW, En quarantaine, [02c838acdeacf046d56f5b10a560ab55],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\CLSID\{1F91A9A1-01BA-4c81-863D-3BA0751E1419}, En quarantaine, [5e6c9c4897f35fd7f9d21a698e74a15f],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{7D3C47ED-E0BE-4940-9DDA-A7A097AEBD88}, En quarantaine, [5e6c9c4897f35fd7f9d21a698e74a15f],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{1F91A9A1-01BA-4C81-863D-3BA0751E1419}, En quarantaine, [5e6c9c4897f35fd7f9d21a698e74a15f],
PUP.Optional.SupTab.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{1F91A9A1-01BA-4C81-863D-3BA0751E1419}, En quarantaine, [5e6c9c4897f35fd7f9d21a698e74a15f],
PUP.Optional.SupTab.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{1F91A9A1-01BA-4C81-863D-3BA0751E1419}, En quarantaine, [5e6c9c4897f35fd7f9d21a698e74a15f],
PUP.Optional.MultiPlug, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}, En quarantaine, [6e5c5b89583211251d5b8b3ac43e08f8],
PUP.Optional.Snapdo.T, HKU\S-1-5-18\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, En quarantaine, [4c7efbe92763e4520f13804425ddee12],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, En quarantaine, [a327af35bcce1f17b27c87024fb3d729],
PUP.Optional.BubbleDock.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{23AF19F7-1D5B-442C-B14C-3D1081953C94}, En quarantaine, [f3d7c1234e3cc27432871873a35f2cd4],
PUP.Optional.BubbleDock.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{23AF19F7-1D5B-442C-B14C-3D1081953C94}, En quarantaine, [f3d7c1234e3cc27432871873a35f2cd4],
PUP.Optional.MultiPlug.Gen, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\vutyweki, En quarantaine, [c406a440315991a58f3c8706d03453ad],
PUP.Optional.MobilePCStarterKit.A, HKLM\SOFTWARE\MOBILEPCSTARTERKIT, En quarantaine, [17b326be1f6b9c9a05cf8f8827dcb848],
PUP.Optional.WordShark.A, HKLM\SOFTWARE\WordShark_1.10.0.19, En quarantaine, [428800e44149d264465ca9efd23250b0],
PUP.Optional.CrossRider.C, HKLM\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, En quarantaine, [8644f8ecec9ea195edeb937752b17090],
PUP.Optional.Binkiland.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\Binkiland.3OF33UJLW66R32RTQB6JK6Y5NU, En quarantaine, [82487074bdcd1e183570f89154b01de3],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE, En quarantaine, [b01ac123d1b9c373d36a177fa064b64a],
PUP.Optional.PCSpeedUp.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\PCSUUCDRV, En quarantaine, [ab1fc420d7b37eb88ce74057d133df21],
PUP.Optional.SuperOptimizer.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, En quarantaine, [7357e202c2c845f1919ffe9a48bc16ea],
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\BlockAndSurf, En quarantaine, [309af2f28efc270f4e7791a0669d9070],
PUP.Optional.Cinema.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\CinemaDPV1, En quarantaine, [5c6e5e8651399c9ae3f1fb3183807f81],
PUP.Optional.Deeal.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\Deeal_fr 0.2, En quarantaine, [983210d4e6a4cd690d51bf8dc43f07f9],
PUP.Optional.FreeVideoGrabber.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\Free Video Grabber 6.6, En quarantaine, [efdb2eb61971f93d381a390126dd30d0],
PUP.Optional.HQVideo.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\HQ-Video-Pro-1.6, En quarantaine, [12b84e961c6e191da461ef955ba926da],
PUP.Optional.PlusHD.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-V1.1, En quarantaine, [97339054d5b5e5516542fd471de67a86],
PUP.Optional.SmartSaver.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\SmartSaver+ 3, En quarantaine, [f0daeafa414940f6b67e3f0db0535ba5],
PUP.Optional.Crossrider.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\_CrossriderRegNamePlaceHolder_, En quarantaine, [9733786c2268979fac4eb3dd6f95cc34],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\HQ_Vid 1.4cV13.03-nv-ie, En quarantaine, [ab1fa0441f6b0c2aab9e74a1e61d5fa1],
PUP.Optional.ICinema.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\I - Cinema-nv-ie, En quarantaine, [4e7c2eb6f09aa98d362ffc337093738d],
PUP.Optional.ICinema.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\I-Cinema, En quarantaine, [b2181cc80981221422c6c469b251629e],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-V1.1, En quarantaine, [69617173c3c7c96d1295ab993dc6936d],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1733C4ED-7119-4B01-93C2-3E639D1CEADD}, En quarantaine, [3f8b8b59682260d67edc3d56a65e8080],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{19C8C261-3D1A-48FD-BEF9-8A54D7974BF2}, En quarantaine, [d4f637add5b5b28462f88d06956ff010],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2CCBFE0E-F25D-421A-8A4A-E69A798575BC}, En quarantaine, [daf0479d57335adcc596ddb61de7aa56],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2F753A1F-6CDD-46E5-9556-C872B3D69BA2}, En quarantaine, [d5f5e6feeb9f1c1a2931c8cbf80c44bc],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3592D8B7-4C1C-46B7-ABE2-E41342F4459D}, En quarantaine, [a228776dfe8cc86e0951d6bdd52f33cd],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{37700451-9809-4B7D-A122-BA9FEF39EED7}, En quarantaine, [03c707dd93f767cfdc7ecac96d972ed2],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{382F1E95-76C7-484A-B3C6-543D123A398C}, En quarantaine, [b713ac3883079a9c80db3d5626de43bd],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3DEF753E-6058-4F18-86F1-F589822CD14A}, En quarantaine, [e9e1dc080486c274bf9ba4ef48bc4ab6],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3DFEA52C-B4BA-42FF-ABF6-4AEDEAB9D121}, En quarantaine, [c7032eb63f4bda5c4e0d365da46026da],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{406A2342-E1AB-4984-BF16-B77383EF70F7}, En quarantaine, [c406687c791121155efd543f43c1b848],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4791000A-33AE-4B0B-89F8-EC96F98E8698}, En quarantaine, [5278c0243852af87b5a5345fee161fe1],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4898AB87-2204-49CA-B457-EBB7E4256FBC}, En quarantaine, [903a4e964f3be0564c0fb4df15ef44bc],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5B17442F-9631-459E-BF76-66A4AC4EAD52}, En quarantaine, [26a441a353374fe7c9922d6613f1fe02],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5C9238DD-22E6-4DFF-AD6A-29AA52FFCF1D}, En quarantaine, [1ab0a341d5b5e84ee179326128dcfd03],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{61EB668A-F8E7-4153-93AA-C2BA6BCFC72F}, En quarantaine, [fecc5094a0eaa09667f3ddb6b15306fa],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{63600527-2FEF-403B-BB1D-B123E3CAED87}, En quarantaine, [e2e840a4dfabfb3bb9a1d9bac93b8b75],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B4740AB-BC20-4638-8D85-1CFE11177EB3}, En quarantaine, [dbef0ed6d3b7f54126352f64d92b45bb],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{701B1D88-3BF1-4F34-96C0-F78560927460}, En quarantaine, [08c28c589feb8bab1545246ffb098c74],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{72FE5BF5-E52F-4E2E-BE71-83FF8E209850}, En quarantaine, [21a9786cdfab59dd8cce9300867eb050],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{83F4A349-74A8-4501-A14F-9AE1EC857676}, En quarantaine, [fdcd3aaac2c84aec1d3dc9ca29dbee12],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{921D44B9-54C3-40D4-B88E-7D10E1DE33C0}, En quarantaine, [f0da7e66dfabd75f37241b787f856a96],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{99D53486-2594-40C9-B85F-E3C8B7AA177C}, En quarantaine, [a1298c58e8a26fc72436c5ce907450b0],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B10901D8-8173-4FF4-9989-7624D2A6292C}, En quarantaine, [e2e88c58a1e941f5b5a5ff94a95b5fa1],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D67FA7E8-A3C8-4FCB-88F3-6B98D9B9A3A9}, En quarantaine, [ac1e1acad0bac27469f2890af3117e82],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DB63843A-2CA0-4206-A875-4C544196B5E2}, En quarantaine, [537730b4dbaf4de946151b787094d52b],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F3DF36A4-DDA1-43D8-98BC-D5DC47B9861E}, En quarantaine, [a02a6f75008a63d3bd9d5a39689cdd23],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FB589881-C344-45D6-8C39-A3A6C09B1F88}, En quarantaine, [b01ad90bb5d5f24406556132ff05cb35],
PUP.Optional.Crossbrowse.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\CrossBrowser, En quarantaine, [8842e00441494ceaea4122ebaa59d52b],
PUP.Optional.Iminent.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\Iminent, En quarantaine, [03c78f55ed9dcf67be860a4733d0768a],
PUP.Optional.InstallCore.C, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\InstallCore, En quarantaine, [bc0e12d20f7bc67040eca3f533d16997],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\mysearchdial, En quarantaine, [e7e3786c25650036fdba23422cd87e82],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\SweetIM, En quarantaine, [3595974dd5b545f1d06eff1e49ba18e8],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{50DCDB96-3842-462E-AC78-8589CD25F15A}, En quarantaine, [55757074dfabd165b46f0c018083e917],
PUP.Optional.InstallBrain.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\WNLT, En quarantaine, [bf0b657faddd979fa60133387d875ea2],

Valeurs du registre: 51
PUP.Optional.CertifiedToolBar.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURI|(Default), http://search.certified-toolbar.com?si=77302&st=bs&tid=18195&ver=5.7&ts=1401215211073&tguid=77302-18195-1401215211073-7C2F65982D8905BC2670B3630F75DAE1&q=%s, En quarantaine, [9535a63e93f7171fe6101721cf34c43c]
PUP.Optional.SearchCertified.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURI, http://search.certified-toolbar.com?si=77302&st=bs&tid=18195&ver=6.1&ts=1401141600000.000000&tguid=77302-18195-1401215211073-7C2F65982D8905BC2670B3630F75DAE1&q=%s, En quarantaine, [73578b59f8921422478376c3a36014ec]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\chrome.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130691790658936595, En quarantaine, [e4e6af35eb9ffb3b9401672fd92be31d]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\explorer.xxx|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130691790658936595, En quarantaine, [5476b232adddb4825e372274b84ce61a]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\firefox.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130691790658936595, En quarantaine, [9139ba2a8ffb8da99cf9d6c019ebce32]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\iexplore.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130691790658936595, En quarantaine, [27a333b1ec9e6acc3065c3d341c38878]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\msiexec.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130691790658936595, En quarantaine, [25a544a0a2e8d95d9500187e4db7a35d]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\SettingsManagerSetup.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130691790658936595, En quarantaine, [af1bcc181d6dab8b563fa1f5fd0753ad]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\SetupDataMg.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130691790658936595, En quarantaine, [57739e46e6a42214fb9a682ec4408d73]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\software_removal_tool.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130691790658936595, En quarantaine, [b4165a8a8a009b9b8f06098dfc087090]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\software_reporter_tool.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130691790658936595, En quarantaine, [7a50588c3a50e155bbdaa3f3a361f20e]
PUP.Optional.OpinionSquare.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}, C:\Program Files\RelevantKnowledge\firefox, En quarantaine, [ccfece16acde2b0b38bdf8445da6fa06]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, En quarantaine, [b01ac123d1b9c373d36a177fa064b64a]
PUP.Optional.Binkiland.A, HKLM\SOFTWARE\REGISTEREDAPPLICATIONS|Binkiland.3OF33UJLW66R32RTQB6JK6Y5NU, Software\Clients\StartMenuInternet\Binkiland.3OF33UJLW66R32RTQB6JK6Y5NU\Capabilities, En quarantaine, [408a5f850a80c76f0d24d53d08fba957]
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\vutyweki|ImagePath, C:\Users\Yolande 2\AppData\Roaming\4C4C4544-1426290862-5810-8051-C8C04F465331\jnsnA3D4.tmp, En quarantaine, [49818f558dfd50e60b4e226a48bc32ce]
PUP.Optional.SnapDo.A, HKU\S-1-5-18\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}|URL, https://search.safefinder.com/?st=ds&q={searchTerms}, En quarantaine, [814914d0038788ae2cadeea0729213ed]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1733C4ED-7119-4B01-93C2-3E639D1CEADD}|AppName, 88b7d303-e7b5-403f-b123-2d5dc634f959-2.exe-buttonutil.exe, En quarantaine, [3f8b8b59682260d67edc3d56a65e8080]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{19C8C261-3D1A-48FD-BEF9-8A54D7974BF2}|AppName, e9c921c6-2ead-4e87-80bb-37f9afa2d8e1-2.exe-buttonutil.exe, En quarantaine, [d4f637add5b5b28462f88d06956ff010]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2CCBFE0E-F25D-421A-8A4A-E69A798575BC}|AppName, 0d5e438e-eb9f-4ae3-b34b-343a750e00ef-2.exe-codedownloader.exe, En quarantaine, [daf0479d57335adcc596ddb61de7aa56]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2F753A1F-6CDD-46E5-9556-C872B3D69BA2}|AppName, 1ddb608b-094b-497b-b74b-4187dba914f0-2.exe-buttonutil.exe, En quarantaine, [d5f5e6feeb9f1c1a2931c8cbf80c44bc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3592D8B7-4C1C-46B7-ABE2-E41342F4459D}|AppName, e9c921c6-2ead-4e87-80bb-37f9afa2d8e1-2.exe-buttonutil.exe, En quarantaine, [a228776dfe8cc86e0951d6bdd52f33cd]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{37700451-9809-4B7D-A122-BA9FEF39EED7}|AppName, 239bfa84-3c4c-43f6-8028-ceeb9113bb49-2.exe-buttonutil.exe, En quarantaine, [03c707dd93f767cfdc7ecac96d972ed2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{382F1E95-76C7-484A-B3C6-543D123A398C}|AppName, 0d5e438e-eb9f-4ae3-b34b-343a750e00ef-2.exe-codedownloader.exe, En quarantaine, [b713ac3883079a9c80db3d5626de43bd]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3DEF753E-6058-4F18-86F1-F589822CD14A}|AppName, 6b8fe38f-05e9-47ba-9bdc-22e87d0c6fbe-2.exe-buttonutil.exe, En quarantaine, [e9e1dc080486c274bf9ba4ef48bc4ab6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3DFEA52C-B4BA-42FF-ABF6-4AEDEAB9D121}|AppName, 1ddb608b-094b-497b-b74b-4187dba914f0-2.exe-codedownloader.exe, En quarantaine, [c7032eb63f4bda5c4e0d365da46026da]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{406A2342-E1AB-4984-BF16-B77383EF70F7}|AppName, d3d4776f-8ab6-4542-92fb-06a4fd65397e-2.exe-codedownloader.exe, En quarantaine, [c406687c791121155efd543f43c1b848]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4791000A-33AE-4B0B-89F8-EC96F98E8698}|AppName, e9c921c6-2ead-4e87-80bb-37f9afa2d8e1-2.exe-buttonutil.exe, En quarantaine, [5278c0243852af87b5a5345fee161fe1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4898AB87-2204-49CA-B457-EBB7E4256FBC}|AppName, dadefa9f-f4c0-4347-9744-6a37726b5bdc-2.exe-codedownloader.exe, En quarantaine, [903a4e964f3be0564c0fb4df15ef44bc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5B17442F-9631-459E-BF76-66A4AC4EAD52}|AppName, e9c921c6-2ead-4e87-80bb-37f9afa2d8e1-2.exe-codedownloader.exe, En quarantaine, [26a441a353374fe7c9922d6613f1fe02]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5C9238DD-22E6-4DFF-AD6A-29AA52FFCF1D}|AppName, d3d4776f-8ab6-4542-92fb-06a4fd65397e-2.exe-buttonutil.exe, En quarantaine, [1ab0a341d5b5e84ee179326128dcfd03]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{61EB668A-F8E7-4153-93AA-C2BA6BCFC72F}|AppName, d3d4776f-8ab6-4542-92fb-06a4fd65397e-2.exe-buttonutil.exe, En quarantaine, [fecc5094a0eaa09667f3ddb6b15306fa]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{63600527-2FEF-403B-BB1D-B123E3CAED87}|AppName, 1ddb608b-094b-497b-b74b-4187dba914f0-2.exe-buttonutil.exe, En quarantaine, [e2e840a4dfabfb3bb9a1d9bac93b8b75]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B4740AB-BC20-4638-8D85-1CFE11177EB3}|AppName, 239bfa84-3c4c-43f6-8028-ceeb9113bb49-2.exe-codedownloader.exe, En quarantaine, [dbef0ed6d3b7f54126352f64d92b45bb]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{701B1D88-3BF1-4F34-96C0-F78560927460}|AppName, d3d4776f-8ab6-4542-92fb-06a4fd65397e-2.exe-buttonutil.exe, En quarantaine, [08c28c589feb8bab1545246ffb098c74]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{72FE5BF5-E52F-4E2E-BE71-83FF8E209850}|AppName, dadefa9f-f4c0-4347-9744-6a37726b5bdc-2.exe-buttonutil.exe, En quarantaine, [21a9786cdfab59dd8cce9300867eb050]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{83F4A349-74A8-4501-A14F-9AE1EC857676}|AppName, dadefa9f-f4c0-4347-9744-6a37726b5bdc-2.exe-buttonutil.exe, En quarantaine, [fdcd3aaac2c84aec1d3dc9ca29dbee12]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{921D44B9-54C3-40D4-B88E-7D10E1DE33C0}|AppName, dadefa9f-f4c0-4347-9744-6a37726b5bdc-2.exe-codedownloader.exe, En quarantaine, [f0da7e66dfabd75f37241b787f856a96]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{99D53486-2594-40C9-B85F-E3C8B7AA177C}|AppName, 239bfa84-3c4c-43f6-8028-ceeb9113bb49-2.exe-buttonutil.exe, En quarantaine, [a1298c58e8a26fc72436c5ce907450b0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B10901D8-8173-4FF4-9989-7624D2A6292C}|AppName, 0d5e438e-eb9f-4ae3-b34b-343a750e00ef-2.exe-buttonutil.exe, En quarantaine, [e2e88c58a1e941f5b5a5ff94a95b5fa1]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D67FA7E8-A3C8-4FCB-88F3-6B98D9B9A3A9}|AppName, e9c921c6-2ead-4e87-80bb-37f9afa2d8e1-2.exe-codedownloader.exe, En quarantaine, [ac1e1acad0bac27469f2890af3117e82]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DB63843A-2CA0-4206-A875-4C544196B5E2}|AppName, 239bfa84-3c4c-43f6-8028-ceeb9113bb49-2.exe-codedownloader.exe, En quarantaine, [537730b4dbaf4de946151b787094d52b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F3DF36A4-DDA1-43D8-98BC-D5DC47B9861E}|AppName, 0d5e438e-eb9f-4ae3-b34b-343a750e00ef-2.exe-buttonutil.exe, En quarantaine, [a02a6f75008a63d3bd9d5a39689cdd23]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FB589881-C344-45D6-8C39-A3A6C09B1F88}|AppName, 88b7d303-e7b5-403f-b123-2d5dc634f959-2.exe-codedownloader.exe, En quarantaine, [b01ad90bb5d5f24406556132ff05cb35]
PUP.Optional.CrossBrowse.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|GoogleChromeAutoLaunch_81DB61DCD09135923CCC3909997E67FB, "C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe" --no-startup-window, En quarantaine, [408afce8375392a4a4cf9702e02405fb]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{50DCDB96-3842-462E-AC78-8589CD25F15A}|DisplayName, Mysearchdial, En quarantaine, [55757074dfabd165b46f0c018083e917]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{50DCDB96-3842-462E-AC78-8589CD25F15A}|URL, http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=airmsd&cd=2XzuyEtN2Y1L1Qzu0EyE0DyDtA0D0EtAyD0FyCyByBtD0B0FtN0D0Tzu0CyDtBzytN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1T1L1C1H1B1Q&cr=1683866469&ir=, En quarantaine, [deec855f6a2088ae66bddf2ed231827e]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{50DCDB96-3842-462E-AC78-8589CD25F15A}|FaviconURL, http://start.mysearchdial.com/favicon.ico En quarantaine, [537741a34c3ecf6779aac449c63dcc34]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{50DCDB96-3842-462E-AC78-8589CD25F15A}|TopResultURLFallback, http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=airmsd&cd=2XzuyEtN2Y1L1Qzu0EyE0DyDtA0D0EtAyD0FyCyByBtD0B0FtN0D0Tzu0CyDtBzytN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1T1L1C1H1B1Q&cr=1683866469&ir=, En quarantaine, [408ab0344a409f97ab78cc41c0434fb1]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{50DCDB96-3842-462E-AC78-8589CD25F15A}|FaviconURLFallback, http://start.mysearchdial.com/favicon.ico En quarantaine, [7753cd17543695a124fffa132bd8f20e]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{50DCDB96-3842-462E-AC78-8589CD25F15A}, Mysearchdial, En quarantaine, [eedc9b4992f841f53ee5917c6e958c74]
PUP.Optional.InstallBrain.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-501\SOFTWARE\WNLT|URL, SIM, En quarantaine, [bf0b657faddd979fa60133387d875ea2]

Données du registre: 6
PUP.Optional.SnapDo.A, HKU\S-1-5-18\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, https://search.safefinder.com/?st=ds&q={searchTerms}, Bon : (www.google.com), Mauvais : (https://search.safefinder.com/?st=ds&q={searchTerms}),Remplacé,[e5e55a8ae1a965d16577f83407fe3bc5]
PUP.Optional.SearchCertifiedTB.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURI|(Default), http://search.certified-toolbar.com?si=77302&st=bs&tid=18195&ver=5.7&ts=1401215211073&tguid=77302-18195-1401215211073-7C2F65982D8905BC2670B3630F75DAE1&q=%s, Bon : (www.google.com), Mauvais : (http://search.certified-toolbar.com?si=77302&st=bs&tid=18195&ver=5.7&ts=1401215211073&tguid=77302-18195-1401215211073-7C2F65982D8905BC2670B3630F75DAE1&q=%s),Remplacé,[a2281cc88dfd45f18e88cb6d0ff611ef]
PUP.Optional.SearchCertifiedTB.A, HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURI, http://search.certified-toolbar.com?si=77302&st=bs&tid=18195&ver=6.1&ts=1401141600000.000000&tguid=77302-18195-1401215211073-7C2F65982D8905BC2670B3630F75DAE1&q=%s, Bon : (www.google.com), Mauvais : (http://search.certified-toolbar.com?si=77302&st=bs&tid=18195&ver=6.1&ts=1401141600000.000000&tguid=77302-18195-1401215211073-7C2F65982D8905BC2670B3630F75DAE1&q=%s),Remplacé,[3199f3f1e9a178bee333ac8c8c7937c9]
Trojan.DNSChanger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{14B2B687-7B7C-4FB6-B873-4652DF65DD6D}|NameServer, 82.163.143.152,82.163.142.154, Bon : (), Mauvais : (82.163.143.152,82.163.142.154),Remplacé,[1fab92528109ec4a768add5dc3426c94]
Trojan.DNSChanger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{7CE44FE2-939A-401C-AE5E-31F8997D8F58}|NameServer, 82.163.143.152,82.163.142.154, Bon : (), Mauvais : (82.163.143.152,82.163.142.154),Remplacé,[c20831b32763c76f52ae9d9d3ec79868]
Trojan.DNSChanger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{C6E1E432-CBA6-40D8-A545-521F849B2F44}|NameServer, 82.163.143.152,82.163.142.154, Bon : (), Mauvais : (82.163.143.152,82.163.142.154),Remplacé,[bb0fe6feddad2214956b9c9e72932fd1]

Dossiers: 17
PUP.Optional.MultiPlug.Gen, C:\Users\Yolande 2\AppData\Roaming\4C4C4544-1426290862-5810-8051-C8C04F465331, En quarantaine, [c406a440315991a58f3c8706d03453ad],
PUP.Optional.MultiPlug.Gen, C:\Users\Yolande 2\AppData\Roaming\4C4C4544-1426290883-5810-8051-C8C04F465331, En quarantaine, [3c8ec81cfe8c5dd94983e2abdf25837d],
PUP.Optional.MultiPlug.Gen, C:\Users\Yolande 2\AppData\Roaming\4C4C4544-1426290933-5810-8051-C8C04F465331, En quarantaine, [6d5d19cbef9ba4927359ff8eaf55a060],
PUP.Optional.OptimizerPro.A, C:\Users\Yolande 2\Documents\Optimizer Pro, En quarantaine, [3199faeae5a564d29a468a0b54b002fe],
PUP.Optional.DeskTopSearch.A, C:\Users\Yolande 2\AppData\Local\DesktopSearch, En quarantaine, [f3d7bf250288bb7bf89b24760103aa56],
PUP.Optional.PullUpdate.Gen, C:\ProgramData\Iihefaufjia\1.0.4.1, Supprimer au redémarrage, [6f5bc0242961290d55c032696a9ad12f],
PUP.Optional.PullUpdate.Gen, C:\ProgramData\Iihefaufjia, Supprimer au redémarrage, [6f5bc0242961290d55c032696a9ad12f],
PUP.Optional.PullUpdate.A, C:\ProgramData\Radio, En quarantaine, [4b7f4d97e9a1d46280237f1c4cb8a65a],
PUP.Optional.DesktopSearch.A, C:\Users\Yolande 2\AppData\Roaming\Microsoft\Windows\Start Menu\Desktop Search, En quarantaine, [4f7b5b89b9d1e353745403980ff5be42],
PUP.Optional.Extutil.A, C:\Users\Invité\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B, En quarantaine, [53776d77c2c80036c0ad40a725ddae52],
PUP.Optional.Managera.A, C:\Users\Invité\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42, En quarantaine, [6862da0a5832bd79b5b9a74025dd24dc],
PUP.Optional.MobilePCStarterKit.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MOBILEPCSTARTERKIT, En quarantaine, [0dbd6d7769210531cb45e31b46bca759],
PUP.Optional.Crossbrowse.C, C:\Users\Yolande 2\AppData\Local\Crossbrowse, En quarantaine, [f0daad37d6b47cba4062a55ca26103fd],
PUP.Optional.Crossbrowse.C, C:\Users\Yolande 2\AppData\Local\Crossbrowse\Crossbrowse, En quarantaine, [f0daad37d6b47cba4062a55ca26103fd],
PUP.Optional.Crossbrowse.C, C:\Users\Yolande 2\AppData\Local\Crossbrowse\Crossbrowse\User Data, En quarantaine, [f0daad37d6b47cba4062a55ca26103fd],
PUP.Optional.PullUpdate.A, C:\ProgramData\bPmMfOR\dat, Supprimer au redémarrage, [09c1a53f8901e6508d1d046960a5718f],
PUP.Optional.PullUpdate.A, C:\ProgramData\bPmMfOR, Supprimer au redémarrage, [09c1a53f8901e6508d1d046960a5718f],

Fichiers: 47
PUP.Optional.PullUpdate.A, C:\ProgramData\bPmMfOR\nQHJSJWW.exe, Supprimer au redémarrage, [02c838acdeacf046d56f5b10a560ab55],
PUP.Optional.ZombieInvasion.A, C:\ProgramData\bPmMfOR\dat\BlPxoXJpon.dll, Supprimer au redémarrage, [d4f65f857218a5910027e6327d88d828],
PUP.Optional.PullUpdate.A, C:\ProgramData\bPmMfOR\dat\IFksyg.exe, Supprimer au redémarrage, [74560ada9eecb08685bf7bf03bca9e62],
PUP.Optional.PullUpdate.A, C:\ProgramData\Radio\prompt.exe, En quarantaine, [a723786c701a40f6a865bb0234cdb34d],
PUP.Optional.InstallCore.SID.C, C:\Users\Yolande 2\Downloads\caesium_1-7-0_fr_340274.exe, En quarantaine, [bc0e6a7aa7e384b24af0214a34d1d030],
PUP.Optional.SnapDo.A, C:\Windows\Installer\7d41e6.msi, En quarantaine, [c00a34b06a20ed499214cb5f4cb5857b],
PUP.Optional.VeriStaff, C:\Windows\Installer\7d41eb.msi, En quarantaine, [ac1ef0f44d3d6ccadeba6cd3bd433fc1],
PUP.Optional.Binkiland.C, C:\Users\Yolande 2\AppData\LocalLow\Microsoft\Internet Explorer\Services\FavIcon.icoWSE_Binkiland, En quarantaine, [54762db78efcc274982aa66438cb768a],
FraudTool.YAC, C:\Users\Yolande 2\AppData\Roaming\Microsoft\Windows\SendTo\YAC Desktop.lnk, En quarantaine, [854544a0f49646f0a790ac64af54d030],
PUP.Optional.SearchProtect.A, C:\Windows\System32\Tasks\avayvxvaxc, En quarantaine, [e4e624c0e7a3eb4bff0a1301f013de22],
PUP.Optional.WebInstr.A, C:\Windows\System32\drivers\Msft_Kernel_webinstrNew_01009.Wdf, En quarantaine, [e5e508dc6d1d3df9b98323f732d10cf4],
PUP.Optional.Hosts, C:\Windows\System32\Tasks\Updater21810.exe, En quarantaine, [e9e1f7eda2e84ee8555e50e058abd828],
PUP.Optional.Vosteran.A, C:\Windows\Tasks\Vosteran_helper.job, En quarantaine, [eedc23c1e4a6f244722ba8de9371a45c],
PUP.Optional.Vosteran.A, C:\Windows\System32\Tasks\Vosteran_helper, En quarantaine, [5a705c888dfdca6c603e63233fc5c33d],
PUP.Optional.MultiPlug.Gen, C:\Users\Yolande 2\AppData\Roaming\4C4C4544-1426290862-5810-8051-C8C04F465331\nsk5F21.tmp, En quarantaine, [c406a440315991a58f3c8706d03453ad],
PUP.Optional.MultiPlug.Gen, C:\Users\Yolande 2\AppData\Roaming\4C4C4544-1426290862-5810-8051-C8C04F465331\jnsnA3D4.tmp, En quarantaine, [c406a440315991a58f3c8706d03453ad],
PUP.Optional.MultiPlug.Gen, C:\Users\Yolande 2\AppData\Roaming\4C4C4544-1426290862-5810-8051-C8C04F465331\nsk90FC.tmp, En quarantaine, [c406a440315991a58f3c8706d03453ad],
PUP.Optional.MultiPlug.Gen, C:\Users\Yolande 2\AppData\Roaming\4C4C4544-1426290862-5810-8051-C8C04F465331\rnsd9EB2.exe, En quarantaine, [c406a440315991a58f3c8706d03453ad],
PUP.Optional.MultiPlug.Gen, C:\Users\Yolande 2\AppData\Roaming\4C4C4544-1426290862-5810-8051-C8C04F465331\Uninstall.exe, En quarantaine, [c406a440315991a58f3c8706d03453ad],
PUP.Optional.MultiPlug.Gen, C:\Users\Yolande 2\AppData\Roaming\4C4C4544-1426290862-5810-8051-C8C04F465331\vnss614B.tmp, En quarantaine, [c406a440315991a58f3c8706d03453ad],
PUP.Optional.MultiPlug.Gen, C:\Users\Yolande 2\AppData\Roaming\4C4C4544-1426290883-5810-8051-C8C04F465331\vnssA8E7.tmp, En quarantaine, [3c8ec81cfe8c5dd94983e2abdf25837d],
PUP.Optional.MultiPlug.Gen, C:\Users\Yolande 2\AppData\Roaming\4C4C4544-1426290883-5810-8051-C8C04F465331\Uninstall.exe, En quarantaine, [3c8ec81cfe8c5dd94983e2abdf25837d],
PUP.Optional.MultiPlug.Gen, C:\Users\Yolande 2\AppData\Roaming\4C4C4544-1426290933-5810-8051-C8C04F465331\vnsd6C26.tmp, En quarantaine, [6d5d19cbef9ba4927359ff8eaf55a060],
PUP.Optional.MultiPlug.Gen, C:\Users\Yolande 2\AppData\Roaming\4C4C4544-1426290933-5810-8051-C8C04F465331\Uninstall.exe, En quarantaine, [6d5d19cbef9ba4927359ff8eaf55a060],
PUP.Optional.Multiplug.A, C:\Windows\System32\Tasks\Bidaily Synchronize Task[8da6], En quarantaine, [4684558fa1e91b1b9b65306453b103fd],
PUP.Optional.Multiplug.A, C:\Windows\Tasks\Bidaily Synchronize Task[8da6].job, En quarantaine, [b911598bb9d14de9d829583cf90b1ee2],
PUP.Optional.OptimizerPro.A, C:\Users\Yolande 2\Documents\Optimizer Pro\CookiesException.txt, En quarantaine, [3199faeae5a564d29a468a0b54b002fe],
PUP.Optional.Runner.A, C:\Windows\System32\Tasks\Test TimeTrigger, En quarantaine, [67634e969befbd795bba5c3df90be020],
PUP.Optional.DeskTopSearch.A, C:\Users\Yolande 2\AppData\Local\DesktopSearch\data2.dat, En quarantaine, [f3d7bf250288bb7bf89b24760103aa56],
PUP.Optional.PullUpdate.Gen, C:\ProgramData\Iihefaufjia\1.0.4.1\oaueunoi.exe.config, En quarantaine, [6f5bc0242961290d55c032696a9ad12f],
PUP.Optional.PullUpdate.Gen, C:\ProgramData\Iihefaufjia\1.0.4.1\oaueunoi.exe, Supprimer au redémarrage, [6f5bc0242961290d55c032696a9ad12f],
PUP.Optional.PullUpdate.Gen, C:\ProgramData\Iihefaufjia\1.0.4.1\sqlite3.dll, Supprimer au redémarrage, [6f5bc0242961290d55c032696a9ad12f],
PUP.Optional.PullUpdate.Gen, C:\ProgramData\Iihefaufjia\dat.dat, En quarantaine, [6f5bc0242961290d55c032696a9ad12f],
PUP.Optional.PullUpdate.A, C:\ProgramData\Radio\prompt.exe.config, En quarantaine, [4b7f4d97e9a1d46280237f1c4cb8a65a],
PUP.Optional.DesktopSearch.A, C:\Users\Yolande 2\AppData\Roaming\Microsoft\Windows\Start Menu\Desktop Search\Uninstall Desktop Search.lnk, En quarantaine, [4f7b5b89b9d1e353745403980ff5be42],
PUP.Optional.DesktopSearch.A, C:\Users\Yolande 2\AppData\Roaming\Microsoft\Windows\Start Menu\Desktop Search\Desktop Search FAQ.lnk, En quarantaine, [4f7b5b89b9d1e353745403980ff5be42],
PUP.Optional.DesktopSearch.A, C:\Users\Yolande 2\AppData\Roaming\Microsoft\Windows\Start Menu\Desktop Search\Desktop Search.lnk, En quarantaine, [4f7b5b89b9d1e353745403980ff5be42],
PUP.Optional.Extutil.A, C:\Users\Invité\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\bk.js, En quarantaine, [53776d77c2c80036c0ad40a725ddae52],
PUP.Optional.Extutil.A, C:\Users\Invité\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\manifest.json, En quarantaine, [53776d77c2c80036c0ad40a725ddae52],
PUP.Optional.Managera.A, C:\Users\Invité\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\cs.js, En quarantaine, [6862da0a5832bd79b5b9a74025dd24dc],
PUP.Optional.Managera.A, C:\Users\Invité\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\manifest.json, En quarantaine, [6862da0a5832bd79b5b9a74025dd24dc],
PUP.Optional.MobilePCStarterKit.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MOBILEPCSTARTERKIT\MobilePCStarterKit.lnk, En quarantaine, [0dbd6d7769210531cb45e31b46bca759],
PUP.Optional.PullUpdate.A, C:\ProgramData\bPmMfOR\dat\IFksyg.exe.config, Supprimer au redémarrage, [09c1a53f8901e6508d1d046960a5718f],
PUP.Optional.PullUpdate.A, C:\ProgramData\bPmMfOR\info.dat, Supprimer au redémarrage, [09c1a53f8901e6508d1d046960a5718f],
PUP.Optional.PullUpdate.A, C:\ProgramData\bPmMfOR\nQHJSJWW.dat, Supprimer au redémarrage, [09c1a53f8901e6508d1d046960a5718f],
PUP.Optional.PullUpdate.A, C:\ProgramData\bPmMfOR\nQHJSJWW.exe.config, En quarantaine, [09c1a53f8901e6508d1d046960a5718f],
PUP.Optional.QuickStart.A, C:\Users\Yolande 2\AppData\Roaming\Mozilla\Firefox\Profiles\8007ns6v.default-1415829113837\prefs.js, Bon : (), Mauvais : (user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");), Remplacé,[f2d835af296181b5227ca4cba65f19e7]

Secteurs physiques: 0
(Aucun élément malveillant détecté)


(end)
A voir également:

6 réponses

Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 659
22 juil. 2015 à 14:40
Salut,

Tu as installé des adwares et programmes parasites sur ton PC qui ouvrent des publicités et ralentissent l'ordinateur et les navigateurs WEB.
Voici la procédure à suivre pour les supprimer :

Commence par ceci :

Suis le tutorial AdwCleaner( d'Xplode )
Ce programme permet de supprimer les adwares et programmes parasites :
  • Télécharge le sur ton bureau ou dossier de téléchargement.
  • Lance AdwCleaner, clique sur [Scanner].
  • L'analyse peux durer plusieurs minutes, patiente.
  • Une fois le scan terminé, ne décoche rien, clique sur [Nettoyer]
  • Une fois le nettoyage terminé, un rapport s'ouvrira. Copie/colle le contenu du rapport dans ta prochaine réponse par un copier/coller.


Si cela ne fonctionne pas, utilise le site http://pjjoint.malekal.com pour héberger le rapport, donne le lien du rapport dans un nouveau message.
Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt


puis :

Suis le tutoriel FRST.
(et bien prendre le temps de lire afin d'appliquer correctement - tout y est expliqué).
Télécharge et lance le scan FRST, cela va générer trois rapports FRST :
  • FRST.txt
  • Shortcut.txt
  • Additionnal.txt


Envoie, comme expliqué, ces trois rapports sur le site http://pjjoint.malekal.com et en retour donne les trois liens pjjoint qui mènent à ses rapports ici dans une nouvelle réponse afin que l'on puisse les consulter.

0
icelande Messages postés 7 Date d'inscription mercredi 22 juillet 2015 Statut Membre Dernière intervention 27 octobre 2016
22 juil. 2015 à 15:32
Premier lien :
https://pjjoint.malekal.com/files.php?id=20150722_s9k8m12j15m15

Deuxième lien :
https://pjjoint.malekal.com/files.php?id=20150722_y5n10p5y10x13

Troisième lien :
https://pjjoint.malekal.com/files.php?id=20150722_z8x7q8m15h11

Je vous envois le mot de passe en privé ? car je ne l'ai pas mis en mode public.



Voici mon rapport Adwcleaner :

# AdwCleaner v4.208 - Rapport créé le 22/07/2015 à 14:50:15
# Mis à jour le 09/07/2015 par Xplode
# Base de données : 2015-07-15.1 [Serveur]
# Système d'exploitation : Windows 7 Professional Service Pack 1 (x86)
# Nom d'utilisateur : Yolande 2 - PC-PC
# Exécuté depuis : C:\Users\Yolande 2\Desktop\adwcleaner_4.208.exe
# Option : Scanner
          • [ Services ] *****
          • [ Fichiers / Dossiers ] *****
          • [ Tâches planifiées ] *****
          • [ Raccourcis ] *****
          • [ Registre ] *****


Clé Trouvée : HKCU\Software\SpeedBit
Clé Trouvée : HKLM\SOFTWARE\SpeedBit
Clé Trouvée : HKU\.DEFAULT\Software\SpeedBit
          • [ Navigateurs ] *****


-\\ Internet Explorer v11.0.9600.17909


-\\ Mozilla Firefox v39.0 (x86 fr)

[8007ns6v.default-1415829113837] - Ligne Trouvée : user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");
[8007ns6v.default-1415829113837] - Ligne Trouvée : user_pref("extensions.quick_start.enable_search1", false);
[8007ns6v.default-1415829113837] - Ligne Trouvée : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);

-\\ Google Chrome v43.0.2357.134


AdwCleaner[R0].txt - [46675 octets] - [30/05/2014 00:00:03]
AdwCleaner[R1].txt - [23363 octets] - [04/07/2014 12:44:27]
AdwCleaner[R2].txt - [17901 octets] - [31/10/2014 07:35:54]
AdwCleaner[R3].txt - [17534 octets] - [14/03/2015 17:25:25]
AdwCleaner[R4].txt - [3187 octets] - [15/03/2015 01:04:30]
AdwCleaner[R5].txt - [19286 octets] - [20/07/2015 10:48:32]
AdwCleaner[R6].txt - [2373 octets] - [21/07/2015 19:22:48]
AdwCleaner[R7].txt - [2292 octets] - [22/07/2015 11:58:21]
AdwCleaner[R8].txt - [1680 octets] - [22/07/2015 14:50:15]
AdwCleaner[S0].txt - [42308 octets] - [30/05/2014 00:03:21]
AdwCleaner[S1].txt - [20748 octets] - [04/07/2014 12:46:33]
AdwCleaner[S2].txt - [16591 octets] - [31/10/2014 07:38:00]
AdwCleaner[S3].txt - [17500 octets] - [14/03/2015 17:28:55]
AdwCleaner[S4].txt - [3128 octets] - [15/03/2015 01:08:55]
AdwCleaner[S5].txt - [18919 octets] - [20/07/2015 11:12:58]

########## EOF - C:\AdwCleaner\AdwCleaner[R8].txt - [2105 octets] ##########
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 659
22 juil. 2015 à 16:43
oui il faut le mot de passe.
0
icelande Messages postés 7 Date d'inscription mercredi 22 juillet 2015 Statut Membre Dernière intervention 27 octobre 2016
22 juil. 2015 à 16:46
yankeh
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 659
Modifié par Malekal_morte- le 22/07/2015 à 17:02
Désinstalle SPEEDbit, Lavasoft


Voici la correction à effectuer avec FRST.
Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix

Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
Copie/colle dedans ce qui suit :


S2 CompilerDesktopSchema.exe; C:\Users\Yolande 2\AppData\Local\CompilerDesktopSchema\CompilerDesktopSchema.exe [X]
Winsock: Catalog9 01 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
Winsock: Catalog9 02 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
Winsock: Catalog9 03 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
Winsock: Catalog9 04 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
Winsock: Catalog9 05 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
Winsock: Catalog9 06 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
Winsock: Catalog9 07 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
Winsock: Catalog9 08 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
Winsock: Catalog9 46 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
2015-07-15 17:00 - 2015-07-15 17:00 - 00002952 _____ C:\Windows\system32\LavasoftTcpServiceOff.ini
2015-07-15 16:59 - 2015-07-15 16:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2015-07-15 16:59 - 2015-06-08 14:13 - 00348488 _____ (Lavasoft Limited) C:\Windows\system32\LavasoftTcpService.dll
HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\...\Run: [SpeedBitVideoAccelerator] => C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe [1517224 2014-12-07] (SPEEDbit)
HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\...\Run: [GoogleChromeAutoLaunch_5A19C308F869C5EB8F6B85F17FD23324] => "C:\Users\Yolande 2\AppData\Local\Binkiland\Application\binkiland.exe" --no-startup-window --auto-launch-at-startup --profile-directory="Default"
HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\...\Run: [Web Companion] => C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
Task: {E589E52B-6EAD-406E-8F55-C0D81AA171CF} - \Test TimeTrigger No Task File <==== ATTENTION
Task: {E5A0E937-B71A-4117-9CBA-C5E8B226F5AE} - System32\Tasks\{97C36135-3AD5-423A-91E3-541F97F866C7} => pcalua.exe -a "C:\Users\Yolande 2\AppData\Roaming\webssearches\UninstallManager.exe" -c -ptid=amt <==== ATTENTION
Task: {F4508CA1-37A9-4B7E-952A-E62F5AE9CD6D} - \avayvxvaxc No Task
File <==== ATTENTION
Task: {962A06F6-CDA1-43A8-9B5C-4256EE546696} - System32\Tasks\DNSWABENO => dnswabeno.exe
Task: {2C2C2FD3-081F-465E-AB08-C09675F7B126} - System32\Tasks\{0B7CAEA5-08FD-415F-8C64-88FAABD300C2} => pcalua.exe -a "C:\Users\Yolande 2\AppData\Roaming\sweet-page\UninstallManager.exe" -c -ptid=cor
cmd: netsh winsock reset


Une fois, le texte coller dans le bloc-note.
Menu Fichier puis Enregistrer sous.
A gauche, place toi sur le bureau.F
Dans le champs en bas, nom du fichier mets : fixlist.txt
Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.

Relance FRST et clic sur le bouton Fix
Selon comment un redémarrage est nécessaire (pas obligatoire).
Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.

Redémarre l'ordinateur


puis réinitialise tes navigateurs:
==================================
Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :


Like the angel you are, you laugh creating a lightness in my chest,
Your eyes they penetrate me,
(Your answer's always 'maybe')
That's when I got up and left
0
icelande Messages postés 7 Date d'inscription mercredi 22 juillet 2015 Statut Membre Dernière intervention 27 octobre 2016
22 juil. 2015 à 22:51
Voici le fichier texte qui apparaît.


Fix result of Farbar Recovery Scan Tool (x86) Version: 20-07-2015
Ran by Yolande 2 at 2015-07-22 22:42:04 Run:1
Running from C:\Users\Yolande 2\Desktop
Loaded Profiles: Yolande 2 (Available Profiles: Yolande 2 & Invité)
Boot Mode: Normal

==============================================

fixlist content:


S2 CompilerDesktopSchema.exe; C:\Users\Yolande 2\AppData\Local\CompilerDesktopSchema\CompilerDesktopSchema.exe [X]
Winsock: Catalog9 01 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
Winsock: Catalog9 02 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
Winsock: Catalog9 03 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
Winsock: Catalog9 04 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
Winsock: Catalog9 05 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
Winsock: Catalog9 06 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
Winsock: Catalog9 07 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
Winsock: Catalog9 08 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
Winsock: Catalog9 46 C:\PROGRA~1\SPEEDB~1\sblsp.dll [177320 2014-12-07] (SPEEDbit)
2015-07-15 17:00 - 2015-07-15 17:00 - 00002952 _____ C:\Windows\system32\LavasoftTcpServiceOff.ini
2015-07-15 16:59 - 2015-07-15 16:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2015-07-15 16:59 - 2015-06-08 14:13 - 00348488 _____ (Lavasoft Limited) C:\Windows\system32\LavasoftTcpService.dll
HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\...\Run: [SpeedBitVideoAccelerator] => C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe [1517224 2014-12-07] (SPEEDbit)
HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\...\Run: [GoogleChromeAutoLaunch_5A19C308F869C5EB8F6B85F17FD23324] => "C:\Users\Yolande 2\AppData\Local\Binkiland\Application\binkiland.exe" --no-startup-window --auto-launch-at-startup --profile-directory="Default"
HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\...\Run: [Web Companion] => C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
Task: {E589E52B-6EAD-406E-8F55-C0D81AA171CF} - \Test TimeTrigger No Task File <==== ATTENTION
Task: {E5A0E937-B71A-4117-9CBA-C5E8B226F5AE} - System32\Tasks\{97C36135-3AD5-423A-91E3-541F97F866C7} => pcalua.exe -a "C:\Users\Yolande 2\AppData\Roaming\webssearches\UninstallManager.exe" -c -ptid=amt <==== ATTENTION
Task: {F4508CA1-37A9-4B7E-952A-E62F5AE9CD6D} - \avayvxvaxc No Task
File <==== ATTENTION
Task: {962A06F6-CDA1-43A8-9B5C-4256EE546696} - System32\Tasks\DNSWABENO => dnswabeno.exe
Task: {2C2C2FD3-081F-465E-AB08-C09675F7B126} - System32\Tasks\{0B7CAEA5-08FD-415F-8C64-88FAABD300C2} => pcalua.exe -a "C:\Users\Yolande 2\AppData\Roaming\sweet-page\UninstallManager.exe" -c -ptid=cor
cmd: netsh winsock reset


CompilerDesktopSchema.exe => Service removed successfully.
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001" => key removed successfully.
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002" => key removed successfully.
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003" => key removed successfully.
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004" => key removed successfully.
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005" => key removed successfully.
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006" => key removed successfully.
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007" => key removed successfully.
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008" => key removed successfully.
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000046" => key removed successfully.
C:\Windows\system32\LavasoftTcpServiceOff.ini => moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft => moved successfully.
C:\Windows\system32\LavasoftTcpService.dll => moved successfully.
HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\Software\Microsoft\Windows\CurrentVersion\Run\\SpeedBitVideoAccelerator => value removed successfully.
HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_5A19C308F869C5EB8F6B85F17FD23324 => value removed successfully.
HKU\S-1-5-21-3010253614-3118212038-2179959183-1012\Software\Microsoft\Windows\CurrentVersion\Run\\Web Companion => value removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E589E52B-6EAD-406E-8F55-C0D81AA171CF}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E589E52B-6EAD-406E-8F55-C0D81AA171CF}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Test TimeTrigger" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E5A0E937-B71A-4117-9CBA-C5E8B226F5AE}" => key removed successfully.


"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E5A0E937-B71A-4117-9CBA-C5E8B226F5AE}" => key removed successfully.
C:\Windows\System32\Tasks\{97C36135-3AD5-423A-91E3-541F97F866C7} => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{97C36135-3AD5-423A-91E3-541F97F866C7}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F4508CA1-37A9-4B7E-952A-E62F5AE9CD6D}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4508CA1-37A9-4B7E-952A-E62F5AE9CD6D}" => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\TreeTask: {F4508CA1-37A9-4B7E-952A-E62F5AE9CD6D} - \avayvxvaxc No Task => key not found.
File <==== ATTENTION => Error: No automatic fix found for this entry.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{962A06F6-CDA1-43A8-9B5C-4256EE546696}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{962A06F6-CDA1-43A8-9B5C-4256EE546696}" => key removed successfully.
C:\Windows\System32\Tasks\DNSWABENO => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DNSWABENO" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2C2C2FD3-081F-465E-AB08-C09675F7B126}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2C2C2FD3-081F-465E-AB08-C09675F7B126}" => key removed successfully.
C:\Windows\System32\Tasks\{0B7CAEA5-08FD-415F-8C64-88FAABD300C2} => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0B7CAEA5-08FD-415F-8C64-88FAABD300C2}" => key removed successfully.

========= netsh winsock reset =========

Le d?marrage de la fonction d'initialisation InitHelperDll dans NSHHTTP.DLL a ?chou??;
code d'erreur?: 10107

Le catalogue Winsock a ?t? r?initialis? correctement.
Vous devez red?marrer l'ordinateur afin de finaliser la r?initialisation.


========= End of CMD: =========

End of Fixlog 22:42:07

0
icelande Messages postés 7 Date d'inscription mercredi 22 juillet 2015 Statut Membre Dernière intervention 27 octobre 2016
22 juil. 2015 à 23:26
Je n'ai pas la possibilité de réinitialiser Firefox car en cliquant sur informations de dépannage seule un nouvel onglet vide s'ouvre, pareille en ouvrant le navigateur et en appuyant enfoncé sur la touche Majuscule.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 659
23 juil. 2015 à 07:15
ok fais ceci :


Exporte tes favoris : https://support.mozilla.org/fr/kb/exporter-marque-pages-firefox-fichier-html
Désinstalle Mozilla Firefox en cochant l'option de suppression du profil.

Affiche les fichiers cachés et systèmes : https://www.commentcamarche.net/informatique/windows/185-afficher-les-extensions-et-les-fichiers-caches-sous-windows/

Supprimer le profil :
Mon Ordinateur => Disque C => Utilisateurs => Ton user => AppData => Roaming
clic droit sur le dossier Mozilla puis renommer
renomme le en Mozilla.old

Mon Ordinateur => Disque C => Program Files => supprime le dossier Mozilla.

Réinstalle Firefox à partir de ce lien : https://telecharger.malekal.com/download/mozilla-firefox/

Réimporte tes favoris.

0
icelande Messages postés 7 Date d'inscription mercredi 22 juillet 2015 Statut Membre Dernière intervention 27 octobre 2016
23 juil. 2015 à 19:03
Je te remercie infiniment pour toute ton aide. Le virus n'est plus là plus aucun problème de publicité ni autres. Seule mes favoris on été perdu mais ce n'est pas bien grave, je pense qu'il y a eu un problème avec l'enregistrement de la page html.bookmarks ou était stocker les favoris car en la réimportant dans mon navigateur Firefox rien ne se passe.
Bonne soirée à toi.
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 659
23 juil. 2015 à 19:16
Je pense pas pouvoir faire grand chose si ça bloque :/
0