Comment supprimer "Reimage Repair" ?

Résolu/Fermé
Douala06 Messages postés 480 Date d'inscription mardi 2 juin 2015 Statut Membre Dernière intervention 31 janvier 2020 - 13 oct. 2015 à 09:57
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 - 16 août 2017 à 17:17
Bonjour,

J'ai téléchargé l'antivirus "Reimage Repair" présenté comme un antivirus spécialement adapté pour Windows 10 mais, je me suis retrouvé avec une offre d'achat au lieu d'une action d'antivirus que je croyais gratuite avant son téléchargement. Bien que je l'ai désinstallé de ">Programmes>Désinstaller un programme", je crains qu'il ne soit tapi dans mon ordinateur. Que pourrais-je bien faire donc comme action de nettoyage pour être certain de l'avoir complètement désinstallé de mon ordinateur ?

Merci de m'aider à résoudre ce problème.



A voir également:

10 réponses

Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 660
Modifié par Malekal_morte- le 13/10/2015 à 10:00
Salut,

Effectivement ce programme n'est pas très fiable, voir : Reimage.
Il est poussé par des adwares.
Si tu as des popups qui s'ouvrent pour en faire la promotion, ton PC est probablement infecté.

Tu as installé des adwares et programmes parasites sur ton PC qui ouvrent des publicités et ralentissent l'ordinateur et les navigateurs WEB.
Voici la procédure à suivre pour les supprimer :

Commence par ceci :

Suis le tutorial AdwCleaner( d'Xplode )
Ce programme permet de supprimer les adwares et programmes parasites :
  • Télécharge le sur ton bureau ou dossier de téléchargement.
  • Lance AdwCleaner, clique sur [Scanner].
  • L'analyse peux durer plusieurs minutes, patiente.
  • Une fois le scan terminé, ne décoche rien, clique sur [Nettoyer]
  • Une fois le nettoyage terminé, un rapport s'ouvrira. Copie/colle le contenu du rapport dans ta prochaine réponse par un copier/collé.


Si cela ne fonctionne pas, utilise le site http://pjjoint.malekal.com pour héberger le rapport, donne le lien du rapport dans un nouveau message.
Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt

puis :

Suis le tutoriel FRST.
(et bien prendre le temps de lire afin d'appliquer correctement - tout y est expliqué).
Télécharge et lance le scan FRST, cela va générer trois rapports FRST :
  • FRST.txt
  • Shortcut.txt
  • Additionnal.txt


Envoie, comme expliqué, ces trois rapports sur le site http://pjjoint.malekal.com et en retour donne les trois liens pjjoint qui mènent à ses rapports ici dans une nouvelle réponse afin que l'on puisse les consulter.

Like the angel you are, you laugh creating a lightness in my chest,
Your eyes they penetrate me,
(Your answer's always 'maybe')
That's when I got up and left
0
# AdwCleaner v6.041 - Logfile created 27/12/2016 at 04:08:11
# Updated on 16/12/2016 by Malwarebytes
# Database : 2016-12-26.3 [Server]
# Operating System : Windows 7 Ultimate Service Pack 1 (X86)
# Username : Bekale Sylver - BEKALESYLVER-PC
# Running from : C:\Users\Bekale Sylver\Downloads\adwcleaner_6.041.exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support
          • [ Services ] *****


[-] Service deleted: HomeworkSimplified_7eService
[-] Service deleted: YahooAUService
          • [ Folders ] *****


[-] Folder deleted: C:\Users\Bekale Sylver\AppData\Local\HomeworkSimplified_7e
[-] Folder deleted: C:\Users\Bekale Sylver\AppData\LocalLow\HomeworkSimplified_7e
[-] Folder deleted: C:\Users\DOE FAUSTHER\AppData\Roaming\HomeworkSimplified_7e
[-] Folder deleted: C:\Users\LOUIS NATHAN\AppData\Roaming\HomeworkSimplified_7e
[-] Folder deleted: C:\Program Files\HomeworkSimplified_7e
[#] Folder deleted on reboot: C:\Users\Bekale Sylver\AppData\Local\HomeworkSimplified_7e
[#] Folder deleted on reboot: C:\Users\Bekale Sylver\AppData\LocalLow\HomeworkSimplified_7e
[#] Folder deleted on reboot: C:\Users\DOE FAUSTHER\AppData\Roaming\HomeworkSimplified_7e
[#] Folder deleted on reboot: C:\Users\LOUIS NATHAN\AppData\Roaming\HomeworkSimplified_7e
[#] Folder deleted on reboot: C:\Program Files\HomeworkSimplified_7e
[-] Folder deleted: C:\Users\Bekale Sylver\AppData\Local\Essentware
[-] Folder deleted: C:\Users\Bekale Sylver\AppData\Local\iac
[#] Folder deleted on reboot: C:\Users\Bekale Sylver\AppData\Local\IAC
[#] Folder deleted on reboot: C:\Users\Bekale Sylver\AppData\Local\HomeworkSimplified_7e
[-] Folder deleted: C:\Users\Bekale Sylver\AppData\LocalLow\iac
[-] Folder deleted: C:\Users\Bekale Sylver\AppData\LocalLow\visi_coupon
[-] Folder deleted: C:\Users\Bekale Sylver\AppData\LocalLow\Yahoo! Companion
[-] Folder deleted: C:\Users\Bekale Sylver\AppData\LocalLow\Yahoo!\Companion
[-] Folder deleted: C:\Users\Bekale Sylver\AppData\LocalLow\YahooCouponAddOn
[#] Folder deleted on reboot: C:\Users\Bekale Sylver\AppData\LocalLow\IAC
[#] Folder deleted on reboot: C:\Users\Bekale Sylver\AppData\LocalLow\HomeworkSimplified_7e
[-] Folder deleted: C:\Users\Bekale Sylver\AppData\Roaming\Yahoo!\Companion
[-] Folder deleted: C:\Users\DOE FAUSTHER\AppData\LocalLow\visi_coupon
[-] Folder deleted: C:\Users\DOE FAUSTHER\AppData\LocalLow\Yahoo! Companion
[-] Folder deleted: C:\Users\DOE FAUSTHER\AppData\LocalLow\Yahoo!\Companion
[-] Folder deleted: C:\Users\DOE FAUSTHER\AppData\LocalLow\YahooCouponAddOn
[#] Folder deleted on reboot: C:\Users\DOE FAUSTHER\AppData\Roaming\HomeworkSimplified_7e
[-] Folder deleted: C:\Users\LOUIS NATHAN\AppData\Local\Softonic
[-] Folder deleted: C:\Users\LOUIS NATHAN\AppData\LocalLow\visi_coupon
[-] Folder deleted: C:\Users\LOUIS NATHAN\AppData\LocalLow\Yahoo! Companion
[-] Folder deleted: C:\Users\LOUIS NATHAN\AppData\LocalLow\Yahoo!\Companion
[-] Folder deleted: C:\Users\LOUIS NATHAN\AppData\LocalLow\YahooCouponAddOn
[-] Folder deleted: C:\Users\LOUIS NATHAN\AppData\Roaming\Yahoo!\Companion
[#] Folder deleted on reboot: C:\Users\LOUIS NATHAN\AppData\Roaming\HomeworkSimplified_7e
[-] Folder deleted: C:\Users\LOUIS NATHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Softonic
[-] Folder deleted: C:\ProgramData\Essentware
[-] Folder deleted: C:\ProgramData\Yahoo! Companion
[#] Folder deleted on reboot: C:\ProgramData\Application Data\Essentware
[#] Folder deleted on reboot: C:\ProgramData\Application Data\Yahoo! Companion
[-] Folder deleted: C:\Program Files\Yahoo!\Companion
[#] Folder deleted on reboot: C:\Program Files\HomeworkSimplified_7e
[-] Folder deleted: C:\Windows\system32\config\systemprofile\AppData\LocalLow\Yahoo! Companion
[-] Folder deleted: C:\Windows\system32\config\systemprofile\AppData\LocalLow\Yahoo!\Companion
[-] Folder deleted: C:\Users\Bekale Sylver\AppData\Roaming\Mozilla\Firefox\Profiles\0c6kkcfu.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[-] Folder deleted: C:\Users\DOE FAUSTHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\mppnoffgpafgpgbaigljliadgbnhljfl
[-] Folder deleted: C:\Users\DOE FAUSTHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf
          • [ Files ] *****


[-] File deleted: C:\Program Files\Yahoo!\Common\unyt.exe
[-] File deleted: C:\Windows\Reimage.ini
[-] File deleted: C:\Users\Bekale Sylver\AppData\Roaming\Mozilla\Firefox\Profiles\0c6kkcfu.default\searchplugins\bingp.xml
[-] File deleted: C:\Users\DOE FAUSTHER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mppnoffgpafgpgbaigljliadgbnhljfl_0.localstorage
[-] File deleted: C:\Users\DOE FAUSTHER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mppnoffgpafgpgbaigljliadgbnhljfl_0.localstorage-journal
[-] File deleted: C:\Users\DOE FAUSTHER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage
[-] File deleted: C:\Users\DOE FAUSTHER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage-journal
[-] File deleted: C:\Users\DOE FAUSTHER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
[-] File deleted: C:\Users\DOE FAUSTHER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
[#] File deleted: C:\Users\DOE FAUSTHER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
[#] File deleted: C:\Users\DOE FAUSTHER\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
          • [ DLL ] *****
          • [ WMI ] *****
          • [ Shortcuts ] *****
          • [ Scheduled Tasks ] *****
          • [ Registry ] *****


[-] Key deleted: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\HomeworkSimplified_7e
[#] Key deleted on reboot: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\HomeworkSimplified_7e_is1
[-] Key deleted: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\AppDataLow\Software\HomeworkSimplified_7e
[#] Key deleted on reboot: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\AppDataLow\Software\HomeworkSimplified_7e_is1
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\HomeworkSimplified_7e
[#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\HomeworkSimplified_7e_is1
[#] Key deleted on reboot: HKCU\Software\HomeworkSimplified_7e
[#] Key deleted on reboot: HKCU\Software\HomeworkSimplified_7e_is1
[#] Key deleted on reboot: HKCU\Software\AppDataLow\Software\HomeworkSimplified_7e
[#] Key deleted on reboot: HKCU\Software\AppDataLow\Software\HomeworkSimplified_7e_is1
[-] Key deleted: HKLM\SOFTWARE\HomeworkSimplified_7e
[#] Key deleted on reboot: HKLM\SOFTWARE\HomeworkSimplified_7e_is1
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.FeedManager
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.FeedManager.1
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.HTMLMenu
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.HTMLMenu.1
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.HTMLPanel
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.HTMLPanel.1
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.MultipleButton
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.MultipleButton.1
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.PseudoTransparentPlugin
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.PseudoTransparentPlugin.1
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.ScriptButton
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.ScriptButton.1
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.SettingsPlugin
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.SettingsPlugin.1
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.ThirdPartyInstaller
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.ToolbarProtector
[-] Key deleted: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.ToolbarProtector.1
[#] Key deleted on reboot: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\HomeworkSimplified_7e
[#] Key deleted on reboot: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\HomeworkSimplified_7e_is1
[#] Key deleted on reboot: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\AppDataLow\Software\HomeworkSimplified_7e
[#] Key deleted on reboot: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\AppDataLow\Software\HomeworkSimplified_7e_is1
[#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\HomeworkSimplified_7e
[#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\HomeworkSimplified_7e_is1
[#] Key deleted on reboot: HKCU\Software\HomeworkSimplified_7e
[#] Key deleted on reboot: HKCU\Software\HomeworkSimplified_7e_is1
[#] Key deleted on reboot: HKCU\Software\AppDataLow\Software\HomeworkSimplified_7e
[#] Key deleted on reboot: HKCU\Software\AppDataLow\Software\HomeworkSimplified_7e_is1
[#] Key deleted on reboot: HKLM\SOFTWARE\HomeworkSimplified_7e
[#] Key deleted on reboot: HKLM\SOFTWARE\HomeworkSimplified_7e_is1
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.FeedManager
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.FeedManager.1
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.HTMLMenu
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.HTMLMenu.1
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.HTMLPanel
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.HTMLPanel.1
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.MultipleButton
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.MultipleButton.1
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.PseudoTransparentPlugin
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.PseudoTransparentPlugin.1
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.ScriptButton
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.ScriptButton.1
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.SettingsPlugin
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.SettingsPlugin.1
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.ThirdPartyInstaller
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.ToolbarProtector
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.ToolbarProtector.1
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HomeworkSimplified_7ebar Uninstall Internet Explorer
[-] Value deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [HomeworkSimplified EPM Support]
[-] Value deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [HomeworkSimplified AppIntegrator 32-bit]
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{010f756a-8e7b-47e5-8aa5-6876d086713a}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{182010e5-3682-44b8-8fee-8c91de21f100}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6a60f594-b4bb-466d-a1b8-8c00fb419aa4}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8f50c11c-cd26-4d13-b94f-6a16dade8546}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a411f193-dd5d-4467-9099-9fa0ea6257dd}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{bc412c9d-834e-4c3c-bd3c-dfd15b78b3e0}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{137eaf98-bc4e-40bf-b9a6-2d0a2811ac7a}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{137eaf98-bc4e-40bf-b9a6-2d0a2811ac7a}
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.PseudoTransparentPlugin.HomeworkSimplified_7e.PseudoTransparentPlugin
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.PseudoTransparentPlugin.HomeworkSimplified_7e.PseudoTransparentPlugin.1
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{27eb7173-28c3-43c6-8853-afc9395f6ec3}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{27eb7173-28c3-43c6-8853-afc9395f6ec3}
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.MultipleButton.HomeworkSimplified_7e.MultipleButton
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.MultipleButton.HomeworkSimplified_7e.MultipleButton.1
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{2eb6a406-a081-4468-8a59-06890f8cae92}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{2eb6a406-a081-4468-8a59-06890f8cae92}
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.ScriptButton.HomeworkSimplified_7e.ScriptButton
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.ScriptButton.HomeworkSimplified_7e.ScriptButton.1
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{46198194-28ce-43b2-9e41-9488ad142c5f}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{46198194-28ce-43b2-9e41-9488ad142c5f}
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.SettingsPlugin.HomeworkSimplified_7e.SettingsPlugin
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.SettingsPlugin.HomeworkSimplified_7e.SettingsPlugin.1
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{469f03b7-86ed-412b-a869-99c9f50bfe17}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{469f03b7-86ed-412b-a869-99c9f50bfe17}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{5519ace3-3d08-45c3-89af-bde45ad8add2}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{5519ace3-3d08-45c3-89af-bde45ad8add2}
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.HTMLPanel.HomeworkSimplified_7e.HTMLPanel
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.HTMLPanel.HomeworkSimplified_7e.HTMLPanel.1
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{5cb955d9-bf20-4418-93e1-919ee4c46293}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{5cb955d9-bf20-4418-93e1-919ee4c46293}
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.FeedManager.HomeworkSimplified_7e.FeedManager
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.FeedManager.HomeworkSimplified_7e.FeedManager.1
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{5ecbd33b-16f4-4486-9fc6-21bbbaf2382d}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{5ecbd33b-16f4-4486-9fc6-21bbbaf2382d}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{88ef5149-a42b-4821-b8ae-7f3e715e5745}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{88ef5149-a42b-4821-b8ae-7f3e715e5745}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{8a5c2047-4d53-499d-b218-c319580ad87f}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{8a5c2047-4d53-499d-b218-c319580ad87f}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{ba55677a-9449-48b2-a399-f34f2d2bf47c}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{ba55677a-9449-48b2-a399-f34f2d2bf47c}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{bc412c9d-834e-4c3c-bd3c-dfd15b78b3e0}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{bc412c9d-834e-4c3c-bd3c-dfd15b78b3e0}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{C8348B3E-10AA-477A-A615-0C96EAEBFE5D}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{C8348B3E-10AA-477A-A615-0C96EAEBFE5D}
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.HTMLMenu.HomeworkSimplified_7e.HTMLMenu
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.HTMLMenu.HomeworkSimplified_7e.HTMLMenu.1
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{d5888ea6-a162-4fa8-8161-4c9ba32157a3}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{d5888ea6-a162-4fa8-8161-4c9ba32157a3}
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.ToolbarProtector.HomeworkSimplified_7e.ToolbarProtector
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\HomeworkSimplified_7e.ToolbarProtector.HomeworkSimplified_7e.ToolbarProtector.1
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{eeb5bac0-4179-4783-af8f-ad58585643a3}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{eeb5bac0-4179-4783-af8f-ad58585643a3}
[#] Key deleted on reboot: {3b86c427-928d-4b50-910c-117fa4830443}
[#] Key deleted on reboot: {0406A5A7-7587-456F-B3BC-5FC7CB9098DE}
[#] Key deleted on reboot: {1270339E-D395-438D-971C-8E8FB74048BC}
[#] Key deleted on reboot: {37A9B37F-105D-4F98-A7AA-C81C5B70E4F1}
[#] Key deleted on reboot: {46A58D54-3096-40C4-9C87-525B50952F6A}
[#] Key deleted on reboot: {62AAB993-C466-4D4F-889D-721202930CEA}
[#] Key deleted on reboot: {6468C3FE-6CE3-4B17-8356-B6B0B6497D42}
[#] Key deleted on reboot: {68C673F0-ED30-4F17-9569-E7B43A802916}
[#] Key deleted on reboot: {BF0C0F5E-4891-4299-A767-3DD0BC9A1272}
[#] Key deleted on reboot: {D4192777-A172-4EF4-81B6-D29D77C5FFC9}
[#] Key deleted on reboot: {FFEF1F2E-A4CB-4D0F-B5EF-5A4B6AF0AD32}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{182010E5-3682-44B8-8FEE-8C91DE21F100}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{1E445483-3C8B-4892-96E6-30E58364D147}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{1EA318C6-990E-4D6C-8A37-2AAE403A6E33}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{29615555-259C-4823-B86C-A0D55E826600}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{2C840227-7639-4DBC-90CE-E6FED8487FBA}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{3585CB12-CDA6-4DB0-B8C5-76AB019C3A6D}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{69E2105F-DD4A-4AD3-A2F2-2615912E3BAB}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{6FFBC674-0FA5-4B04-A174-4C0769529688}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{78152F1F-16D1-4AF6-BE3E-F0316E3536B1}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{7CD1C1EE-3FAF-4824-9E8A-6DF4E60EDCFB}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{7F9378C3-70D5-4030-BCD2-BA9120D528F6}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{86BD37F5-5A63-41B5-AD68-580E88195218}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{8E8DCE5E-3F96-4C6C-A169-E44594F11A9B}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{8F50C11C-CD26-4D13-B94F-6A16DADE8546}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{93D4485E-5708-446D-A289-E50281F598C9}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{A41FC8EF-79B1-457C-A3CA-429E80E8FDA6}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{A81616BA-028C-4E2F-A4D0-B24A4C9D8845}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{B3499C76-47AD-4B17-93D1-13B7704D6AFC}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{C20D5461-3213-4C6A-8D9F-C786B05DAE25}
[-] Key deleted: HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine
[-] Key deleted: HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1
[-] Key deleted: HKLM\SOFTWARE\Classes\Sample.BrowserHandler
[-] Key deleted: HKLM\SOFTWARE\Classes\Sample.BrowserHandler.1
[-] Key deleted: HKLM\SOFTWARE\Classes\Sample.YTBPartnerSample
[-] Key deleted: HKLM\SOFTWARE\Classes\Sample.YTBPartnerSample.1
[-] Key deleted: HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
[-] Key deleted: HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
[-] Key deleted: HKLM\SOFTWARE\Classes\yt.CacheLoader
[-] Key deleted: HKLM\SOFTWARE\Classes\yt.CacheLoader.1
[-] Key deleted: HKLM\SOFTWARE\Classes\yt.Clickstream
[-] Key deleted: HKLM\SOFTWARE\Classes\yt.Clickstream.1
[-] Key deleted: HKLM\SOFTWARE\Classes\yt.YTBMButton
[-] Key deleted: HKLM\SOFTWARE\Classes\yt.YTBMButton.1
[-] Key deleted: HKLM\SOFTWARE\Classes\yt.YTHelper
[-] Key deleted: HKLM\SOFTWARE\Classes\yt.YTHelper.2
[-] Key deleted: HKLM\SOFTWARE\Classes\yt.YTNavAssistPlugin
[-] Key deleted: HKLM\SOFTWARE\Classes\yt.YTNavAssistPlugin.1
[-] Key deleted: HKLM\SOFTWARE\Classes\yt.YToolbarBand
[-] Key deleted: HKLM\SOFTWARE\Classes\yt.YToolbarBand.1
[-] Key deleted: HKLM\SOFTWARE\Classes\ytbbroker.YTBAutoSearchAssistant
[-] Key deleted: HKLM\SOFTWARE\Classes\ytbbroker.YTBAutoSearchAssistant.1
[-] Key deleted: HKLM\SOFTWARE\Classes\ytbbroker.YTBAutoUpdaterAssistant
[-] Key deleted: HKLM\SOFTWARE\Classes\ytbbroker.YTBAutoUpdaterAssistant.1
[-] Key deleted: HKLM\SOFTWARE\Classes\ytbbroker.YTBCustomizerAssistant
[-] Key deleted: HKLM\SOFTWARE\Classes\ytbbroker.YTBCustomizerAssistant.1
[-] Key deleted: HKLM\SOFTWARE\Classes\ytbbroker.YTBGeneralAssistant
[-] Key deleted: HKLM\SOFTWARE\Classes\ytbbroker.YTBGeneralAssistant.1
[-] Key deleted: HKLM\SOFTWARE\Classes\ytbbroker.YTBMessengerAssistant
[-] Key deleted: HKLM\SOFTWARE\Classes\ytbbroker.YTBMessengerAssistant.1
[-] Key deleted: HKLM\SOFTWARE\Classes\ytbbroker.YTBSingleInstanceAssistant
[-] Key deleted: HKLM\SOFTWARE\Classes\ytbbroker.YTBSingleInstanceAssistant.1
[-] Key deleted: HKLM\SOFTWARE\Classes\YTNavAssist.NameSpaceCF
[-] Key deleted: HKLM\SOFTWARE\Classes\YTNavAssist.NameSpaceCF.1
[-] Key deleted: HKLM\SOFTWARE\Classes\YTNavAssist.NameSpacePP
[-] Key deleted: HKLM\SOFTWARE\Classes\YTNavAssist.NameSpacePP.1
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{1CAE874F-F5C7-4BCC-BA46-9AD26DF35B93}
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{56AD7EEE-D6C0-410E-8A7B-811DEA764554}
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{E8EB2F1F-661E-4A7F-8F9A-77DEB757A906}
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{AF85DB83-06F2-4ECF-97CF-C46EDB06BE29}
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{7375D127-3955-4654-8E7D-1949A7A9C902}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{3CCC052E-BDEE-408A-BEA7-90914EF2964B}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{61F47056-E400-43D3-AF1E-AB7DFFD4C4AD}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{E2B98EEA-EE55-4E9B-A8C1-6E5288DF785A}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{990F7D4F-09EF-47DF-9ABE-BAF2DCCF5C4B}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{1E57256D-9F39-4267-AB39-D7813D644C5A}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{31371420-098D-4C0E-A11E-EBEC2305DD01}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{3A06AA27-D94B-48C2-BB55-9FD0FF2120E3}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{46140CE4-76FE-440E-AE88-4C2272BC05C7}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{9F9C4C5C-2BA8-4E00-A697-9F710BB1026B}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{C60CCE95-6AF9-4E74-B66B-3212D19F1D2F}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{FBE30D66-39A2-4b72-8B43-6D4C335A6F34}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{3C16E079-E4C7-493C-BE9F-E0F2BB0B7430}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{6EB4349D-4333-442F-ACA4-4C72AF28B6ED}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{7DB8B625-DBF0-4491-B544-5A06F7B17BB4}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{8E74A0AE-F0ED-47ED-A940-A8E99687646B}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{9DE77B51-89F6-468E-9402-16050382E950}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{F56ACA29-1C99-40F1-AC64-2E44C4F6BC71}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{12D3E096-0FDF-42CC-8F44-04944F9C1648}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{22389F39-2CF4-47C4-B8B2-273BB16BF70C}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{23E3CEB3-D63A-433E-A5D0-4DB1C501B915}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{26A3152F-CF87-4C5B-8093-4D4B9EC084EB}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{29E3319C-4B3C-479F-8692-BDD2CA30BEDD}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{367BD1CD-74A3-451F-B1A4-6A2DE4129A2D}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{49F018EE-F362-4B5B-8EC8-BCF9246ABF21}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{63B73044-FC1A-4FE1-991B-FDBD4CDAA868}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{7207E52B-821E-4C05-A8D6-2965B2BE77CF}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{863FCF5D-DC39-4DA9-AF32-CB0025990EEE}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{B09E015A-4D4E-4F8D-A436-95E19140947D}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{B1E712C4-03AA-495F-B0F5-0F057E126E2A}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{D13DC65C-C77B-4986-9078-DEA3D34C71BB}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{371AD4A5-1520-4AA2-A8A4-F9AD3BAC6957}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{7F124846-5453-4BB8-A41D-E11481FFC9DF}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{8FD65019-BF09-45DA-AD81-E95AE911F1FD}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{61A2027D-B837-4080-A925-6E30E10DEF32}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{F6C2BABA-9E4C-425F-9AEC-24AB8F2B640D}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Value deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
[-] Key deleted: HKU\.DEFAULT\Software\Yahoo\Companion
[-] Key deleted: HKU\.DEFAULT\Software\Yahoo\YFriendsBar
[-] Key deleted: HKU\.DEFAULT\Software\AppDataLow\Software\Yahoo\Companion
[-] Key deleted: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\Essentware
[-] Key deleted: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\Reimage
[-] Key deleted: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\Yahoo\Companion
[-] Key deleted: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\Yahoo\YFriendsBar
[-] Key deleted: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
[-] Key deleted: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\AppDataLow\Software\Yahoo\Companion
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\Yahoo\YFriendsBar
[#] Key deleted on reboot: HKU\S-1-5-18\Software\Yahoo\Companion
[#] Key deleted on reboot: HKU\S-1-5-18\Software\Yahoo\YFriendsBar
[#] Key deleted on reboot: HKU\S-1-5-18\Software\AppDataLow\Software\Yahoo\Companion
[#] Key deleted on reboot: HKCU\Software\Essentware
[#] Key deleted on reboot: HKCU\Software\Reimage
[#] Key deleted on reboot: HKCU\Software\Yahoo\Companion
[#] Key deleted on reboot: HKCU\Software\Yahoo\YFriendsBar
[#] Key deleted on reboot: HKCU\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
[#] Key deleted on reboot: HKCU\Software\AppDataLow\Software\Yahoo\Companion
[-] Key deleted: HKLM\SOFTWARE\Essentware
[-] Key deleted: HKLM\SOFTWARE\Reimage
[-] Key deleted: HKLM\SOFTWARE\Yahoo\Companion
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
[-] Key deleted: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\Microsoft\Internet Explorer\SearchScopes\{a776248f-c424-4ce4-8b5e-65db029465d3}
[#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{a776248f-c424-4ce4-8b5e-65db029465d3}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{a776248f-c424-4ce4-8b5e-65db029465d3}
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
[-] Value deleted: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\Microsoft\Windows\CurrentVersion\Run [PCKeeper Antivirus]
[#] Value deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [PCKeeper Antivirus]
[-] Value deleted: HKU\S-1-5-21-1117228994-2306441563-1352761198-1000\Software\Microsoft\Windows\CurrentVersion\Run [PCKeeperLive]
[#] Value deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [PCKeeperLive]
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\yt.DLL
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\ytbbroker.EXE
[-] Key deleted: HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd
          • [ Web browsers ] *****


[-] [C:\Users\Bekale Sylver\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: fcfenmboojpjinhpgggodefccipikbpd
[-] [C:\Users\DOE FAUSTHER\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
[-] [C:\Users\DOE FAUSTHER\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com
[-] [C:\Users\DOE FAUSTHER\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: mppnoffgpafgpgbaigljliadgbnhljfl
[-] [C:\Users\DOE FAUSTHER\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: nafaimnnclfjfedmmabolbppcngeolgf
[-] [C:\Users\LOUIS NATHAN\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: dragon-ball-z-sagas.softonic.fr
[-] [C:\Users\LOUIS NATHAN\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
[-] [C:\Users\LOUIS NATHAN\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com


:: "Tracing" keys deleted
:: Winsock settings cleared


C:\AdwCleaner\AdwCleaner[C0].txt - [32397 Bytes] - [27/12/2016 04:08:11]
C:\AdwCleaner\AdwCleaner[S0].txt - [29893 Bytes] - [27/12/2016 04:04:18]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [32545 Bytes] ##########
0
Douala06 Messages postés 480 Date d'inscription mardi 2 juin 2015 Statut Membre Dernière intervention 31 janvier 2020 38
13 oct. 2015 à 18:55
# AdwCleaner v5.013 - Rapport créé le 13/10/2015 à 18:47:17
# Mis à jour le 09/10/2015 par Xplode
# Base de données : 2015-10-09.3 [Serveur]
# Système d'exploitation : Windows 10 Home (x64)
# Nom d'utilisateur : Aralia - ADAMTROPIK
# Exécuté depuis : C:\Users\Aralia\Downloads\adwcleaner_5.013.exe
# Option : Nettoyer
# Support : https://toolslib.net/forum
          • [ Services ] *****
          • [ Dossiers ] *****
          • [ Fichiers ] *****


[-] Fichier Supprimé : C:\WINDOWS\Reimage.ini
          • [ DLLs ] *****
          • [ Raccourcis ] *****
          • [ Tâches planifiées ] *****
          • [ Registre ] *****


[-] Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
[-] Clé Supprimée : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1
[-] Clé Supprimée : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine
[-] Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
[-] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
[-] Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
[-] Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
[-] Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
[-] Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
[-] Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
[-] Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
[-] Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
[-] Clé Supprimée : HKCU\Software\Reimage
[!] Clé Non Supprimée : [x64] HKCU\Software\Reimage
[-] Clé Supprimée : [x64] HKLM\SOFTWARE\Reimage
          • [ Navigateurs ] *****


[-] [C:\Users\Aralia\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Supprimé : hxxp://www.dregol.com/?f=7&a=drg_mlvi_15_21&cd=2XzuyEtN2Y1L1Qzu0A0E0ByDyB0D0D0C0EyEzyyDyEzzyEtAtN0D0Tzu0StCtBtAzztN1L2XzutAtFtCtDtFtCtDtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StDtC0B0FtAtDyD0BtG0FzytD0DtG0DtB0A0EtGtAzy0B0FtGyDyEyDzytCtA0BtDyB0A0EtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0EzzyB0ByE0F0FtGzztAyByDtGyEyD0F0AtGzztB0E0FtG0CtB0AtD0D0E0AtBtCzz0Bzy2QtN0A0LzuyE&cr=1323479875&ir=
[-] [C:\Users\Aralia\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Supprimé : hxxp://www.istartsurf.com/?type=hp&ts=1442394262&z=13c446f10be6dbcdee71ff1gdz2zao3c4t0zbe8tbm&from=smt&uid=HGSTXHTS541010A9E680_141129JA1009CRK42BNKX
[-] [C:\Users\Aralia\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Homepage] Supprimé : hxxp://www.dregol.com/?f=1&a=drg_mlvi_15_21&cd=2XzuyEtN2Y1L1Qzu0A0E0ByDyB0D0D0C0EyEzyyDyEzzyEtAtN0D0Tzu0StCtBtAzztN1L2XzutAtFtCtDtFtCtDtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StDtC0B0FtAtDyD0BtG0FzytD0DtG0DtB0A0EtGtAzy0B0FtGyDyEyDzytCtA0BtDyB0A0EtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0EzzyB0ByE0F0FtGzztAyByDtGyEyD0F0AtGzztB0E0FtG0CtB0AtD0D0E0AtBtCzz0Bzy2QtN0A0LzuyE&cr=1323479875&ir=


:: Paramètres Winsock réinitialisés

########## EOF - C:\AdwCleaner\AdwCleaner[C3].txt - [3180 octets] ##########
0
Douala06 Messages postés 480 Date d'inscription mardi 2 juin 2015 Statut Membre Dernière intervention 31 janvier 2020 38
13 oct. 2015 à 20:58
http://pjjoint.malekal.com/files.php?id=FRST_20151013_x6k8k15b6u8
http://pjjoint.malekal.com/files.php?id=20151013_e13t15f9t7c11
http://pjjoint.malekal.com/files.php?id=20151013_c14f13i10u12i10
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 660
13 oct. 2015 à 22:50
Ca a l'air bon =)

il reste quel problème ?
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Douala06 Messages postés 480 Date d'inscription mardi 2 juin 2015 Statut Membre Dernière intervention 31 janvier 2020 38
13 oct. 2015 à 23:10
(il reste quel problème ?)

Pour moi non car, il m'apparait que l'antivirus "Reimage Repair" a été définitivement désinstallé de mon ordi puisque tu ne l'évoques pas après ton analyse des différents rapports de Adwcleaner et FRST.

Je me sens complètement rasséréné pour ton aimable et rapide intervention et, je me tiens à ta disposition pour toutes suites que tu estimerais utile.

Mes sincères remerciements.
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 660
13 oct. 2015 à 23:11
Super =)


Voila, c'est terminé, tu peux supprimer les programmes utilisés.

Quelques conseils :

Pour prévenir les sites malicieux, tu peux installer Blockulicious : https://forum.malekal.com/viewtopic.php?t=46656&start=

Pour ne plus te faire avoir.
A lire - Programmes parasites / PUPs : https://www.malekal.com/adwares-pup-protection/
(Surtout active les détections LPIs pour détecter les programmes parasites et publicitaires)


Le reste de la sécurité : http://forum.malekal.com/comment-securiser-son-ordinateur.html

0
Bonjour,

Je me permets de continuer sur ce fil car je rencontre le même problème sur mon PC. J'ai lancé un nettoyage avec AdwCleaner, cependant l'antivirus Reimage semble toujours présent (j'ai toujours des onglets qui s'ouvrent me demandant d'acheter Reimage).

Si quelqu'un a l'amabilité de jeter un œil au rapport qu'AdwCleaner m'a donné pour voir où cela pêche, je vous en serai éternellement reconnaissante.

Merci!

http://pjjoint.malekal.com/files.php?id=20160201_d10r12y14w6o7

P.S: je galère un chouilla pour le scan FRST car Reimage m'ouvre pas mal de pages et fait sauter celles que lesquelles je suis, mais j'essaie de vous faire parvenir les trois autres rapports au plus vite.
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 660
Modifié par Malekal_morte- le 1/02/2016 à 19:20
Salut,


Réinitialise tes navigateurs et/ou re-paramètre manuellement tes navigateurs WEB ( page de démarrage, moteur de recherche, etc ) mais aussi supprimer/désactiver les extensions inutiles/parasites.
Pour t'aider à effectuer ce ménage, clique ci-dessous sur le nom du navigateur WEB que tu utilises :


puis :

Suis le tutoriel FRST. ( prends le temps de lire attentivement - tout y est bien expliqué ).

Télécharge et lance le scan FRST, 3 rapports FRST seront générés :
  • FRST.txt
  • Shortcut.txt
  • Additionnal.txt


Envoie ces 3 rapports sur le site http://pjjoint.malekal.com/ et en retour donne les 3 liens pjjoint qui mènent aux rapports ici dans une nouvelle réponse afin que l'on puisse les consulter.
0
Voilà pour le reste!
http://pjjoint.malekal.com/files.php?id=FRST_20160201_g10q12v11s10s12
http://pjjoint.malekal.com/files.php?id=20160201_g5f11i7u10v13
http://pjjoint.malekal.com/files.php?id=20160201_b13v10v5m10i15

Mercie encore T.T
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 660
1 févr. 2016 à 20:23
Rien mise à part :

Je te conseille de désinstaller McAfee Security Scan car c'est avant tout un programme markéting proposé à l'installation d'autres logiciels ( comme Adobe Flash) pour final tenter de te vendre l'antivirus.
0
Phoenix > Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020
1 févr. 2016 à 20:40
Ce sont les rapports après avoir réinitialisé mon navigateur (in case)
http://pjjoint.malekal.com/files.php?id=FRST_20160201_w15o6z109q15
http://pjjoint.malekal.com/files.php?id=20160201_d11q12u5n8r12
http://pjjoint.malekal.com/files.php?id=20160201_g6j5t6p8p12

Mais je crois que j'en suis enfin débarrassée!
Je suis ton conseille concernant McAfee!

Merci encore de ton aide (tes tutos sont vraiment très bien =^^=)
0
Et désolée pour les fautes d'orthographe (genre l'immonde "mercie" ou le "conseille" :O)
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 660 > Phoenix
1 févr. 2016 à 20:46
Pas de soucis pour les fautes =)

sinon bha rien de spécial !
0
# AdwCleaner v5.201 - Rapport créé le 03/08/2016 à 21:10:32
# Mis à jour le 30/06/2016 par ToolsLib
# Base de données : 2016-08-02.3 [Serveur]
# Système d'exploitation : Windows 10 Home (X64)
# Nom d'utilisateur : Anna - VAIO
# Exécuté depuis : C:\Users\Anna\Desktop\adwcleaner_5.201.exe
# Option : Nettoyer
# Support : https://toolslib.net/forum
          • [ Services ] *****


[-] Service supprimé : ReimageRealTimeProtector
[-] Service supprimé : rtop
          • [ Dossiers ] *****


[-] Dossier supprimé : C:\rei
[-] Dossier supprimé : C:\ProgramData\ByteFence
[-] Dossier supprimé : C:\ProgramData\Reimage Protector
[-] Dossier supprimé : C:\ProgramData\Nico Mak Computing\WinZip Malware Protector
[-] Dossier supprimé : C:\ProgramData\OWMiniProO
[#] Dossier supprimé : C:\ProgramData\Application Data\ByteFence
[#] Dossier supprimé : C:\ProgramData\Application Data\Reimage Protector
[#] Dossier supprimé : C:\ProgramData\Application Data\Nico Mak Computing\WinZip Malware Protector
[#] Dossier supprimé : C:\ProgramData\Application Data\OWMiniProO
[-] Dossier supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ByteFence Anti-Malware
[-] Dossier supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus
[-] Dossier supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reimage repair
[-] Dossier supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip Malware Protector
[-] Dossier supprimé : C:\Program Files (x86)\PC Clean Plus
[-] Dossier supprimé : C:\Program Files (x86)\WinZip Malware Protector
[-] Dossier supprimé : C:\Users\Anna\AppData\Roaming\istartpageing
[-] Dossier supprimé : C:\Users\Anna\AppData\Roaming\PC Clean Plus
[-] Dossier supprimé : C:\Users\Anna\AppData\Roaming\Nico Mak Computing\WinZip Malware Protector
[-] Dossier supprimé : C:\Users\Anna\AppData\Roaming\Event Monitor
[-] Dossier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd
[-] Dossier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej
[-] Dossier supprimé : C:\Program Files\ByteFence
[-] Dossier supprimé : C:\Program Files\Reimage
          • [ Fichiers ] *****


[-] Fichier supprimé : C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
[#] Fichier supprimé : C:\ProgramData\Application Data\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
[-] Fichier supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HowToRemove.html.lnk
[-] Fichier supprimé : C:\WINDOWS\Reimage.ini
[-] Fichier supprimé : C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Booking .lnk
[-] Fichier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Local Storage\hxxps_cdncache-a.akamaihd.net_0.localstorage
[-] Fichier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Local Storage\hxxps_cdncache-a.akamaihd.net_0.localstorage-journal
[-] Fichier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Local Storage\hxxps_foxi69.tlscdn.com_0.localstorage
[-] Fichier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Local Storage\hxxps_foxi69.tlscdn.com_0.localstorage-journal
[-] Fichier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage
[-] Fichier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage-journal
[-] Fichier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Local Storage\hxxps_static.re-markit00.re-markit.co_0.localstorage
[-] Fichier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Local Storage\hxxps_static.re-markit00.re-markit.co_0.localstorage-journal
[-] Fichier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Local Storage\hxxps_www.openask.com_0.localstorage
[-] Fichier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Local Storage\hxxps_www.openask.com_0.localstorage-journal
[-] Fichier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Local Storage\hxxp_searchgle.com_0.localstorage
[-] Fichier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Local Storage\hxxp_searchgle.com_0.localstorage-journal
[-] Fichier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
[-] Fichier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal
[-] Fichier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Local Storage\hxxp_static.coupontime00.coupontime.co_0.localstorage
[-] Fichier supprimé : C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Local Storage\hxxp_static.coupontime00.coupontime.co_0.localstorage-journal
[-] Fichier supprimé : C:\WINDOWS\SysNative\wsusnative64.exe
          • [ DLLs ] *****
          • [ WMI ] *****
          • [ Raccourcis ] *****
          • [ Tâches planifiées ] *****


[-] Tâche supprimée : Reimage Reminder
[-] Tâche supprimée : ReimageUpdater
[-] Tâche supprimée : WinZip Malware Protector_startup
[-] Tâche supprimée : RunAtStartup
[-] Tâche supprimée : PC Clean Plus_UPDATES
[-] Tâche supprimée : PC Clean Plus_DEFAULT
[-] Tâche supprimée : PC Clean Plus
[-] Tâche supprimée : ByteFence
[-] Tâche supprimée : ByteFence Scan
[-] Tâche supprimée : Reimage Reminder
[-] Tâche supprimée : ReimageUpdater
[-] Tâche supprimée : RunAtStartup
          • [ Registre ] *****


[-] Clé supprimée : HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
[-] Clé supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Reimage.exe
[-] Clé supprimée : HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd
[-] Clé supprimée : HKCU\Software\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej
[-] Clé supprimée : HKLM\SOFTWARE\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej
[-] Clé supprimée : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej
[-] Clé supprimée : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine
[-] Clé supprimée : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1
[-] Clé supprimée : HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
[-] Clé supprimée : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
[-] Clé supprimée : HKLM\SOFTWARE\Classes\CLSID\{0757C9D8-D8A3-33F5-CEE2-11D09918BA8F}
[-] Clé supprimée : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
[-] Clé supprimée : HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
[-] Clé supprimée : HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
[-] Clé supprimée : HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
[-] Clé supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
[-] Clé supprimée : HKCU\Software\ByteFence
[-] Clé supprimée : HKCU\Software\Conduit
[-] Clé supprimée : HKCU\Software\MediaProgramasGen
[-] Clé supprimée : HKCU\Software\PC Clean Plus
[-] Clé supprimée : HKCU\Software\PRODUCTSETUP
[-] Clé supprimée : HKCU\Software\Reimage
[-] Clé supprimée : HKCU\Software\yahooprovidedsearch
[-] Clé supprimée : HKCU\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
[-] Clé supprimée : HKCU\Software\PC
[-] Clé supprimée : HKCU\Software\csastats
[-] Clé supprimée : HKCU\Software\NICO MAK COMPUTING\WINZIP MALWARE PROTECTOR
[-] Clé supprimée : HKCU\Software\Event Monitor
[-] Clé supprimée : HKLM\SOFTWARE\ByteFence
[-] Clé supprimée : HKLM\SOFTWARE\Conduit
[-] Clé supprimée : HKLM\SOFTWARE\istartpageingSoftware
[-] Clé supprimée : HKLM\SOFTWARE\Jawego
[-] Clé supprimée : HKLM\SOFTWARE\PC Clean Plus
[-] Clé supprimée : HKLM\SOFTWARE\WdsManPro
[-] Clé supprimée : HKLM\SOFTWARE\PC
[-] Clé supprimée : HKLM\SOFTWARE\NICO MAK COMPUTING\WINZIP MALWARE PROTECTOR
[-] Clé supprimée : HKLM\SOFTWARE\Event Monitor
[-] Clé supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
[-] Clé supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC Clean Plus_is1
[-] Clé supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip Malware Protector_is1
[-] Clé supprimée : [x64] HKLM\SOFTWARE\ByteFence
[-] Clé supprimée : [x64] HKLM\SOFTWARE\Reimage
[-] Clé supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Reimage Repair
[-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2f23ab71-4ac6-41f2-a955-ea576e553146}
[-] Clé supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8CDE19E6-71C2-4B46-89B7-35F6A18C571A}
[-] Clé supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2f23ab71-4ac6-41f2-a955-ea576e553146}
[-] Clé supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8CDE19E6-71C2-4B46-89B7-35F6A18C571A}
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\akamaihd.net
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\foxi69.tlscdn.com
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\land.pckeeper.software
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\middlerush-a.akamaihd.net
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\nps.pastaleads.com
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\pastaleads.com
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\pckeeper.software
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\st.chatango.com
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\tlscdn.com
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\akamaihd.net
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\foxi69.tlscdn.com
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\land.pckeeper.software
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\middlerush-a.akamaihd.net
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\nps.pastaleads.com
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\pastaleads.com
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\pckeeper.software
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\st.chatango.com
[-] Clé supprimée : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\tlscdn.com
[-] Clé supprimée : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WdsManPro
          • [ Navigateurs ] *****


[-] [C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Web Data] [Search Provider] supprimé : yahoo! powered
[-] [C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Secure Preferences] [Startup_URLs] supprimé : hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_16_28¶m1=1¶m2=f%3D7%26b%3Dchmm%26cc%3Dfr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyBzzzzyEtA0CtAzytD0FtC0Czy0ByEyBtN0D0Tzu0StCyCyDyCtN1L2XzutAtFtBtAtFtCtFtAtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyBtByC0FyDyBtAtAtGyCyEzytDtGzy0F0CtCtGtD0DtDtCtG0F0BtByDyE0F0BzyyB0F0B0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDzztCzz0B0DtB0AtGyE0B0B0EtGyE0E0FyEtG0B0EyBtAtGyCtD0DzzyEyDtDyB0EtAyByC2QtN0A0LzuyEtN1B2Z1V1T1S1NzutBtBtBtC%26cr%3D610671512%26a%3Dwncy_ir_16_28%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&uref=chmm
[-] [C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Secure Preferences] [Extension] supprimé : fcfenmboojpjinhpgggodefccipikbpd
[-] [C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Secure Preferences] [Extension] supprimé : pilplloabdedfmialnfchjomjmpjcoej
[-] [C:\Users\Anna\AppData\Local\Chromium\User Data\Default\Secure Preferences] [Homepage] supprimé : hxxps://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_16_28¶m1=1¶m2=f%3D1%26b%3Dchmm%26cc%3Dfr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyBzzzzyEtA0CtAzytD0FtC0Czy0ByEyBtN0D0Tzu0StCyCyDyCtN1L2XzutAtFtBtAtFtCtFtAtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyBtByC0FyDyBtAtAtGyCyEzytDtGzy0F0CtCtGtD0DtDtCtG0F0BtByDyE0F0BzyyB0F0B0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDzztCzz0B0DtB0AtGyE0B0B0EtGyE0E0FyEtG0B0EyBtAtGyCtD0DzzyEyDtDyB0EtAyByC2QtN0A0LzuyEtN1B2Z1V1T1S1NzutBtBtBtC%26cr%3D610671512%26a%3Dwncy_ir_16_28%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&uref=chmm


:: Clés "Tracing" supprimées
:: Paramètres Winsock réinitialisés


C:\AdwCleaner\AdwCleaner[C1].txt - [15296 octets] - [03/08/2016 21:10:32]
C:\AdwCleaner\AdwCleaner[S1].txt - [16039 octets] - [03/08/2016 21:06:15]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [15446 octets] ##########
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 660
3 août 2016 à 23:11
Salut,


Réinitialise manuellement tes navigateurs :


puis :
Suis le tutoriel FRST. ( prends le temps de lire attentivement - tout y est bien expliqué ).

Télécharge et lance le scan FRST, 3 rapports FRST seront générés :
  • FRST.txt
  • Shortcut.txt
  • Additionnal.txt


Envoie ces 3 rapports sur le site http://pjjoint.malekal.com/ et en retour donne les 3 liens pjjoint qui mènent aux rapports ici dans une nouvelle réponse afin que l'on puisse les consulter.
0
lddrdj Messages postés 2 Date d'inscription lundi 29 août 2016 Statut Membre Dernière intervention 29 août 2016
29 août 2016 à 01:03
# AdwCleaner v6.010 - Rapport créé le 29/08/2016 à 00:36:20
# Mis à jour le 12/08/2016 par ToolsLib
# Base de données : 2016-08-28.2 [Serveur]
# Système d'exploitation : Windows 8.1 Connected (X64)
# Nom d'utilisateur : lydia - PC-JENNA
# Exécuté depuis : C:\Users\Jenna\Downloads\adwcleaner_6.010.exe
# Mode: Nettoyage
# Support : https://toolslib.net/forum
          • [ Services ] *****
          • [ Dossiers ] *****


[-] Dossier supprimé: C:\Users\Jenna\AppData\Local\jawego
[-] Dossier supprimé: C:\Users\Jenna\AppData\Roaming\PCPRJ
[-] Dossier supprimé: C:\Users\Jenna\AppData\Roaming\jawego
          • [ Fichiers ] *****
          • [ DLL ] *****
          • [ WMI ] *****
          • [ Raccourcis ] *****
          • [ Tâches planifiées ] *****
          • [ Registre ] *****


[-] Clé supprimée: [x64] HKLM\SOFTWARE\Classes\Interface\{7BCA6879-A9F8-47DE-AE05-F5CE7EA3A474}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\Interface\{7BCA6879-A9F8-47DE-AE05-F5CE7EA3A474}
[-] Clé supprimée: HKLM\SOFTWARE\Classes\TypeLib\{ADF1FA2A-6EAA-4A97-A55F-3C8B92843EF5}
[-] Clé supprimée: HKU\S-1-5-21-612951328-1649554835-1337614245-1001\Software\SECURE\PC\Cleaner
[#] Clé supprimée au redémarrage: HKCU\Software\SECURE\PC\Cleaner
[-] Clé supprimée: HKLM\SOFTWARE\SECURE\PC\Cleaner
[-] Clé supprimée: HKLM\SOFTWARE\Classes\AppID\OverlayIcon.DLL
          • [ Navigateurs ] *****


:: Clés "Tracing" supprimées
:: Paramètres Winsock réinitialisés


C:\AdwCleaner\AdwCleaner[C0].txt - [1559 octets] - [29/08/2016 00:36:20]
C:\AdwCleaner\AdwCleaner[S0].txt - [1894 octets] - [29/08/2016 00:35:54]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1707 octets] ##########
0
mdmsll__ Messages postés 2 Date d'inscription mercredi 16 août 2017 Statut Membre Dernière intervention 16 août 2017
16 août 2017 à 16:17
# AdwCleaner 7.0.1.0 - Logfile created on Wed Aug 16 13:46:35 2017
# Updated on 2017/05/08 by Malwarebytes
# Running on Windows 10 Home Single Language (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support/
          • [ Services ] *****


Deleted: ReimageRealTimeProtector
Deleted: ReimageRealTimeProtector
          • [ Folders ] *****


Deleted: C:\ProgramData\Reimage Protector
Deleted: C:\ProgramData\Application Data\Reimage Protector
Deleted: C:\Users\All Users\Reimage Protector
Deleted: C:\Program Files\Reimage
Deleted: C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
          • [ Files ] *****


Deleted: C:\Users\admin\Downloads\ReimageRepair.exe
Deleted: C:\Windows\Reimage.ini
Deleted: C:\Windows\Temp\reimage.log
Deleted: C:\Users\admin\AppData\Local\Temp\reimage.log
Deleted: C:\Users\admin\AppData\Local\Temp\ReimagePackage.exe
          • [ DLL ] *****


No malicious DLLs cleaned.
          • [ WMI ] *****


No malicious WMI cleaned.
          • [ Shortcuts ] *****


No malicious shortcuts cleaned.
          • [ Tasks ] *****


Deleted: ReimageUpdater
          • [ Registry ] *****


Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Reimage Protector
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
Deleted: [Key] - HKU\S-1-5-21-4108829606-3903038394-433394576-1001\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
Deleted: [Key] - HKCU\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
Deleted: [Key] - HKLM\SOFTWARE\Reimage
Deleted: [Key] - HKU\S-1-5-21-4108829606-3903038394-433394576-1001\Software\Reimage
Deleted: [Key] - HKCU\Software\Reimage
          • [ Firefox (and derivatives) ] *****


No malicious Firefox entries deleted.
          • [ Chromium (and derivatives) ] *****


No malicious Chromium entries deleted.


::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0


C:/AdwCleaner/AdwCleaner[S0].txt - [2956 B] - [2017/8/16 13:44:17]


########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########
0
mdmsll__ Messages postés 2 Date d'inscription mercredi 16 août 2017 Statut Membre Dernière intervention 16 août 2017
16 août 2017 à 16:49
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 660 > mdmsll__ Messages postés 2 Date d'inscription mercredi 16 août 2017 Statut Membre Dernière intervention 16 août 2017
16 août 2017 à 17:17
Salut,

Rien de spécial, tu peux désinstaller ces programmes qui sont pré-installés sur l'ordinateur :
CyberLink
McAfee LiveSafe (Windows Defender va prendre le relai)
WildTangent Games
0