Supprimer winsnare et amule c

phillalli1 -  
Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   -
Bonjour,

J'ai essayé de m'en débarasser plusieurs fois (avec des anti virus, etc...)
Mais pas de resultat donc je me suis tourné vers frst , pourriez vous m'aider?
(je vous fournis les liens pjjoint)
Frst: http://pjjoint.malekal.com/files.php?id=FRST_20170408_n8i11g15n9h7
additionnal : http://pjjoint.malekal.com/files.php?id=20170408_t9m12q8e8k5
shortcut: http://pjjoint.malekal.com/files.php?id=20170408_d14d11g5q5x8

3 réponses

  1. Kuroki. Messages postés 20 Statut Membre 4
     
    Pour le supprimer, essaye d'aller dans :
    Panneau de configuration -> Désinstaller un programme -> puis tu a toute la liste des programmes installés, tu fait clique gauche sur le/les programme(s) à désinstaller puis clique sur désinstaller, normalement ça marche.
    0
  2. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 711
     
    Salut,

    Je regarde les rapports.
    0
  3. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 711
     
    Voici la correction à effectuer avec FRST. Tu peux t'aider de cette note explicative avec des captures d'écran.

    Ouvre le bloc-notes : Touche Windows + R,
    Dans le champs "Exécuter", saisir notepad et OK.
    Copie/Colle dedans ce qui suit :

    CreateRestorePoint:
    CloseProcesses:
    HKLM\...\Run: [gplyra] => C:\Users\C3Consultants\AppData\Roaming\gplyra\gplyra.exe [1538048 2017-02-05] () <===== ATTENTION
    HKLM-x32\...\Run: [] => [X]
    HKU\S-1-5-21-1821689846-2012740900-1950354591-1002\...\Run: [BingSvc] => C:\Users\C3Consultants\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-13] (© 2015 Microsoft Corporation)
    HKU\S-1-5-21-1821689846-2012740900-1950354591-1002\...\Run: [WahOO] => C:\Program Files (x86)\KowMedia\WahOO\WahOO.exe [5444416 2016-04-13] ()
    HKU\S-1-5-21-1821689846-2012740900-1950354591-1002\...\Run: [sjcYAfa&ie.exe] => C:\Users\C3Consultants\AppData\Local\Temp\{c70-9a-c3-7d4a3-b0506-cdc0-bc67f}\sjcYAfa&ie.exe [687616 2017-02-19] (Sunday) <===== ATTENTION
    HKU\S-1-5-21-1821689846-2012740900-1950354591-1002\...\Run: [I'aD3-kb3G.exe] => C:\Users\C3Consultants\AppData\Local\Temp\{c70-9a-c3-7d4a3-b0506-cdc0-bc67f}\I'aD3-kb3G.exe [891904 2017-02-19] (KApitale) <===== ATTENTION
    HKU\S-1-5-21-1821689846-2012740900-1950354591-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27545048 2017-03-14] (Skype Technologies S.A.)
    HKU\S-1-5-21-1821689846-2012740900-1950354591-1002\...\Run: [GameJoltClient] => C:\Users\C3Consultants\AppData\Local\GameJoltClient\GameJoltClient.exe [46705152 2016-12-20] ()
    HKU\S-1-5-21-1821689846-2012740900-1950354591-1002\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3044848 2017-04-07] (Electronic Arts)
    HKLM-x32\...\Run: [BtTray] => c:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe [364032 2012-08-16] (IVT Corporation)
    HKLM-x32\...\Run: [HP HD Webcam Driver_Monitor] => C:\Program Files (x86)\HP HD Webcam Driver\monitor.exe [303480 2012-07-26] ()
    HKLM-x32\...\Run: [CLMLServer_For_P2G8] => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink)
    HKLM-x32\...\Run: [CLVirtualDrive] => c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-24] (CyberLink Corp.)
    HKLM-x32\...\Run: [RemoteControl10] => c:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
    HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
    R2 clean; C:\Users\C3Consultants\AppData\Local\clean\Kyubey.exe [114688 2017-04-06] () [Fichier non signé]
    R2 GubedZL; C:\Program Files (x86)\Gubed\GubedZL.dll [118272 2017-02-04] () [Fichier non signé]
    R2 Gubed_WMI; C:\Program Files (x86)\Gubed_WMI\Gubed_WMI.exe [110080 2016-12-26] () [Fichier non signé]
    R2 Convxxxx; C:\Users\C3Consultants\AppData\Roaming\fibei\UvConverter.exe [396800 2016-12-26]
    R3 iThemes5; C:\Program Files (x86)\Common Files\Services\iThemes.dll [526848 2017-02-04] () [Fichier non signé] <==== ATTENTION
    S2 Kyubey; C:\Users\C3Consultants\AppData\Roaming\Kyubey\Kyubey.exe [236032 2017-04-01] () [Fichier non signé]
    R2 Nettrans; C:\ProgramData\NetworkPacketManitor\Nettrans.exe [43520 2017-02-19] () [Fichier non signé]
    R2 Themes; C:\WINDOWS\system32\themeservice.dll [59392 2014-10-29] (Microsoft Corporation) [DependOnService: iThemes5]<==== ATTENTION
    R2 UncheckitSvc; C:\Program Files (x86)\Uncheckit\UncheckitSvc.exe [247552 2016-07-05] (evangel technology (hk) limited)
    R2 WinSAPSvc; C:\Users\C3Consultants\AppData\Roaming\WinSAPSvc\WinSAP.dll [188416 2017-04-07] (Windows) [Fichier non signé]
    R2 WINSNARE; C:\Users\C3Consultants\AppData\Roaming\WINSNARE\WinSnare.dll [1293312 2017-04-01] (InterSect Alliance Pty Ltd) [Fichier non signé] <==== ATTENTION
    R2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [1094264 2016-08-25] (ExWzp Pvt Ltd.) [Fichier non signé] <==== ATTENTION
    S2 Archer; C:\Program Files (x86)\WinArcher\Archer.dll [X]
    S2 ed2kidle; "C:\Program Files (x86)\amuleC\ed2k.exe" -downloadwhenidle [X] <==== ATTENTION
    S2 FirefoxDL; "C:\Users\C3CONS~1\AppData\Local\Temp\5\QQBrowser.exe" -isvc [X] <==== ATTENTION
    S2 jIxmRfR_update; "C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe" [X]
    S2 serverss; C:\WINDOWS\Temp\DCBC.tmp [X]
    2017-04-07 00:57 - 2017-04-07 00:57 - 00000000 ____D C:\Program Files (x86)\{750416E0-9FE5-4AA5-AE94-95CA5C81C470}
    2017-03-04 23:01 - 2017-04-08 01:06 - 00000000 ____D C:\Program Files (x86)\BikaQRss
    2017-03-04 22:58 - 2017-03-04 22:58 - 00000000 ____D C:\Users\Public\Documents\CyberLink
    2017-03-04 22:58 - 2017-03-04 22:58 - 00000000 ____D C:\Users\Public\CyberLink
    2017-03-04 01:04 - 2017-04-07 00:21 - 00000000 _____ C:\WINDOWS\SysWOW64\4
    2017-03-04 01:04 - 2017-04-01 17:28 - 00000000 _____ C:\WINDOWS\SysWOW64\3
    2017-03-04 01:04 - 2017-03-04 01:04 - 00000000 ____D C:\Program Files (x86)\Firefox
    2017-03-03 22:38 - 2017-03-03 22:38 - 00000000 ____D C:\Users\C3Consultants\AppData\Roaming\Kyubey
    2017-02-23 14:25 - 2017-02-23 14:25 - 00000000 ____D C:\Users\C3Consultants\Desktop\M.S
    2017-02-23 13:32 - 2017-02-23 13:32 - 69717250 _____ C:\Users\C3Consultants\Desktop\M.S.rar
    2017-02-23 11:12 - 2017-02-23 11:12 - 00000000 ____D C:\Users\C3Consultants\Desktop\C.H_2
    2017-02-23 11:11 - 2017-02-23 11:11 - 67033364 _____ C:\Users\C3Consultants\Desktop\C.H_2.rar
    2017-02-23 11:09 - 2017-02-23 11:09 - 00000000 ____D C:\Users\C3Consultants\Desktop\Deadlock_1
    2017-02-23 11:08 - 2017-02-23 11:08 - 48117867 _____ C:\Users\C3Consultants\Desktop\Deadlock_1.rar
    2017-02-23 11:05 - 2017-02-23 11:05 - 00000000 ____D C:\Users\C3Consultants\Desktop\I.A_1
    2017-02-23 11:04 - 2017-02-23 11:04 - 49390442 _____ C:\Users\C3Consultants\Desktop\I.A_1.rar
    2017-02-23 10:54 - 2017-02-23 10:54 - 00000000 ____D C:\Users\C3Consultants\Desktop\Viewfinder_08
    2017-02-22 14:03 - 2017-02-22 14:03 - 00000000 ____D C:\Users\C3Consultants\Downloads\B_F
    2017-02-22 13:48 - 2017-04-07 12:31 - 00000000 ____D C:\Users\C3Consultants\AppData\Roaming\WinSAPSvc
    2017-02-20 17:42 - 2017-02-20 17:42 - 00000772 _____ C:\WINDOWS\SysWOW64\ping.cfg
    2017-02-20 17:42 - 2017-02-20 17:42 - 00000000 _____ C:\temp.dat
    2017-02-20 09:57 - 2017-03-05 03:57 - 00003208 _____ C:\WINDOWS\System32\Tasks\BikaQ_FetchAndUpgrade_CanBeDel
    2017-02-20 09:57 - 2017-03-04 23:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BikaQ
    2017-02-20 03:37 - 2017-02-20 03:37 - 00002166 _____ C:\Users\Public\Desktop\Google Earth.lnk
    2017-02-20 03:37 - 2017-02-20 03:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
    2017-02-20 02:34 - 2017-02-20 17:40 - 00000000 ____D C:\Users\C3Consultants\AppData\Local\BrowserAir
    2017-02-20 02:34 - 2017-02-20 02:34 - 00004286 _____ C:\WINDOWS\System32\Tasks\SMW_UpdateTask_Time_323232353334383331372d2a55456c2d5a34575b413234
    2017-02-19 21:45 - 2017-04-07 19:45 - 00000326 _____ C:\WINDOWS\Tasks\PC Clean Plus_DEFAULT.job
    2017-02-19 21:45 - 2017-02-22 21:45 - 00000334 _____ C:\WINDOWS\Tasks\PC Clean Plus_UPDATES.job
    2017-02-19 21:45 - 2017-02-19 21:45 - 00003260 _____ C:\WINDOWS\System32\Tasks\PC Clean Plus_DEFAULT
    2017-02-19 21:45 - 2017-02-19 21:45 - 00003086 _____ C:\WINDOWS\System32\Tasks\PC Clean Plus_UPDATES
    2017-02-19 21:44 - 2017-04-01 13:26 - 00003020 _____ C:\WINDOWS\System32\Tasks\RunAtStartup
    2017-02-19 21:44 - 2017-04-01 13:26 - 00000000 ____D C:\Users\C3Consultants\AppData\Roaming\Event Monitor
    2017-02-19 21:44 - 2017-02-19 21:44 - 00003122 _____ C:\WINDOWS\System32\Tasks\PC Clean Plus
    2017-02-19 21:44 - 2017-02-19 21:44 - 00000000 ____D C:\Users\C3Consultants\AppData\Roaming\PC Clean Plus
    2017-02-19 21:44 - 2017-02-19 21:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus
    2017-02-19 21:42 - 2017-02-19 21:42 - 00003154 _____ C:\WINDOWS\System32\Tasks\{352A360E-CECD-4C49-A977-4DB060F894C5}
    2017-02-19 21:39 - 2017-02-19 21:39 - 00003602 _____ C:\WINDOWS\System32\Tasks\{7F1F24F0-550B-4900-BB8D-86231EE58D05}
    2017-02-19 21:38 - 2017-02-19 21:38 - 00000000 ____D C:\ProgramData\Microleaves
    2017-02-19 21:37 - 2017-02-19 21:37 - 00002398 _____ C:\WINDOWS\SysWOW64\findit.xml
    2017-02-19 21:37 - 2017-02-19 21:37 - 00000000 ____D C:\ProgramData\Zaamlas
    2017-02-19 21:35 - 2017-04-08 01:33 - 00000364 _____ C:\WINDOWS\Tasks\Traffic Exchange v209 - 3.job
    2017-02-19 21:35 - 2017-04-08 01:33 - 00000364 _____ C:\WINDOWS\Tasks\Traffic Exchange v209 - 2.job
    2017-02-19 21:35 - 2017-04-08 01:33 - 00000364 _____ C:\WINDOWS\Tasks\Traffic Exchange v209 - 1.job
    2017-02-19 21:35 - 2017-04-08 01:33 - 00000354 _____ C:\WINDOWS\Tasks\Traffic Exchange v2 - 3.job
    2017-02-19 21:35 - 2017-04-08 01:33 - 00000354 _____ C:\WINDOWS\Tasks\Traffic Exchange v2 - 2.job
    2017-02-19 21:35 - 2017-04-08 01:33 - 00000354 _____ C:\WINDOWS\Tasks\Traffic Exchange v2 - 1.job
    2017-02-19 21:35 - 2017-04-07 23:38 - 00000406 ____H C:\WINDOWS\Tasks\Traffic Exchange Updater.job
    2017-02-19 21:35 - 2017-02-19 21:35 - 01938536 _____ C:\Users\C3Consultants\AppData\Roaming\Zumdox.bin
    2017-02-19 21:35 - 2017-02-19 21:35 - 00003580 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange Guardian
    2017-02-19 21:35 - 2017-02-19 21:35 - 00003580 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange Guard
    2017-02-19 21:35 - 2017-02-19 21:35 - 00003580 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange
    2017-02-19 21:35 - 2017-02-19 21:35 - 00003210 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange Updater
    2017-02-19 21:35 - 2017-02-19 21:35 - 00003170 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v209 - 3
    2017-02-19 21:35 - 2017-02-19 21:35 - 00003170 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v209 - 2
    2017-02-19 21:35 - 2017-02-19 21:35 - 00003170 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v209 - 1
    2017-02-19 21:35 - 2017-02-19 21:35 - 00003160 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v2 - 3
    2017-02-19 21:35 - 2017-02-19 21:35 - 00003160 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v2 - 2
    2017-02-19 21:35 - 2017-02-19 21:35 - 00003160 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v2 - 1
    2017-02-19 21:35 - 2017-02-19 21:35 - 00000000 ____D C:\ProgramData\Logic Handler
    2017-02-19 21:34 - 2017-03-03 22:21 - 00000000 ____D C:\ProgramData\NetworkPacketManitor
    2017-02-19 21:34 - 2017-02-19 21:37 - 00000000 ____D C:\Users\C3Consultants\AppData\Roaming\Microleaves
    2017-02-19 21:34 - 2017-02-19 21:36 - 00000000 ____D C:\Users\C3Consultants\AppData\Local\app
    2017-02-19 21:34 - 2017-02-19 21:34 - 07319040 _____ C:\Users\C3Consultants\AppData\Roaming\agent.dat
    2017-02-19 21:34 - 2017-02-19 21:34 - 01908111 _____ C:\Users\C3Consultants\AppData\Roaming\S-zap.tst
    2017-02-19 21:34 - 2017-02-19 21:34 - 00278521 _____ C:\Users\C3Consultants\AppData\Roaming\Quadlam.bin
    2017-02-19 21:34 - 2017-02-19 21:34 - 00126464 _____ C:\Users\C3Consultants\AppData\Roaming\noah.dat
    2017-02-19 21:34 - 2017-02-19 21:34 - 00070752 _____ C:\Users\C3Consultants\AppData\Roaming\Config.xml
    2017-02-19 21:34 - 2017-02-19 21:34 - 00018432 _____ C:\Users\C3Consultants\AppData\Roaming\Main.dat
    2017-02-19 21:34 - 2017-02-19 21:34 - 00005568 _____ C:\Users\C3Consultants\AppData\Roaming\md.xml
    2017-02-19 21:34 - 2017-02-19 21:34 - 00000000 ____D C:\Users\Default\AppData\Local\AdvinstAnalytics
    2017-02-19 21:34 - 2017-02-19 21:34 - 00000000 ____D C:\Users\Default User\AppData\Local\AdvinstAnalytics
    2017-02-19 21:33 - 2017-02-19 21:33 - 00005040 _____ C:\WINDOWS\System32\Tasks\Atowerpyplowat
    2017-02-19 21:33 - 2017-02-19 21:33 - 00000000 ____D C:\Users\C3Consultants\AppData\Local\Bijlyirerge
    2017-02-19 21:33 - 2017-02-19 21:33 - 00000000 ____D C:\ProgramData\SearchModule
    2017-02-19 21:32 - 2017-02-19 21:41 - 00000000 ____D C:\Users\C3Consultants\AppData\Local\WikiThemes
    2017-02-19 21:32 - 2017-02-19 21:36 - 00000000 ____D C:\Users\C3Consultants\AppData\Local\AppTrailers
    2017-02-19 21:32 - 2017-02-19 21:32 - 00000000 ____D C:\Program Files\Common Files\Noobzo
    2017-02-19 21:31 - 2017-02-19 21:34 - 00016224 _____ C:\Users\C3Consultants\AppData\Roaming\InstallationConfiguration.xml
    2017-02-19 21:31 - 2017-02-19 21:32 - 00000000 ____D C:\Users\C3Consultants\AppData\Roaming\gplyra
    2017-02-19 21:31 - 2017-02-19 21:31 - 00140288 _____ C:\Users\C3Consultants\AppData\Roaming\Installer.dat
    2017-02-19 21:31 - 2017-02-19 21:31 - 00000000 _____ C:\TOSTACK
    2017-02-19 21:28 - 2017-02-19 21:43 - 00000000 ____D C:\WINDOWS\system32\SSL
    2011-09-26 21:45 - 2011-09-26 21:45 - 0001126 _____ () C:\Users\C3Consultants\AppData\Roaming\404-11.htm
    2017-02-19 21:34 - 2017-02-19 21:34 - 7319040 _____ () C:\Users\C3Consultants\AppData\Roaming\agent.dat
    2017-02-19 21:31 - 2017-02-19 21:31 - 0023622 _____ () C:\Users\C3Consultants\AppData\Roaming\aliexpress.ico
    2017-02-19 21:31 - 2017-02-19 21:31 - 0099678 _____ () C:\Users\C3Consultants\AppData\Roaming\booking.ico
    2017-02-19 21:34 - 2017-02-19 21:34 - 0070752 _____ () C:\Users\C3Consultants\AppData\Roaming\Config.xml
    2013-10-02 04:54 - 2013-10-02 04:54 - 0000321 _____ () C:\Users\C3Consultants\AppData\Roaming\Eirunepe
    2017-02-19 21:31 - 2017-02-19 21:34 - 0016224 _____ () C:\Users\C3Consultants\AppData\Roaming\InstallationConfiguration.xml
    2017-02-19 21:31 - 2017-02-19 21:31 - 0140288 _____ () C:\Users\C3Consultants\AppData\Roaming\Installer.dat
    2017-02-19 21:34 - 2017-02-19 21:34 - 0018432 _____ () C:\Users\C3Consultants\AppData\Roaming\Main.dat
    2017-02-19 21:34 - 2017-02-19 21:34 - 0005568 _____ () C:\Users\C3Consultants\AppData\Roaming\md.xml
    2016-04-17 17:27 - 2016-04-17 17:27 - 0052885 _____ () C:\Users\C3Consultants\AppData\Roaming\Nairobi
    2017-02-19 21:34 - 2017-02-19 21:34 - 0126464 _____ () C:\Users\C3Consultants\AppData\Roaming\noah.dat
    2013-10-02 04:54 - 2013-10-02 04:54 - 0001004 _____ () C:\Users\C3Consultants\AppData\Roaming\Petersburg
    2017-02-19 21:34 - 2017-02-19 21:34 - 0278521 _____ () C:\Users\C3Consultants\AppData\Roaming\Quadlam.bin
    2017-02-19 21:34 - 2017-02-19 21:34 - 1908111 _____ () C:\Users\C3Consultants\AppData\Roaming\S-zap.tst
    2016-04-17 17:27 - 2016-04-17 17:27 - 0002205 _____ () C:\Users\C3Consultants\AppData\Roaming\SunbakeBerryInnuendo
    2015-05-20 03:28 - 2015-05-20 03:28 - 0002670 _____ () C:\Users\C3Consultants\AppData\Roaming\system.xml
    2013-10-02 04:56 - 2013-10-02 04:56 - 0003850 _____ () C:\Users\C3Consultants\AppData\Roaming\ua.js
    2017-02-19 21:35 - 2017-02-19 21:35 - 0032038 _____ () C:\Users\C3Consultants\AppData\Roaming\uninstall_temp.ico
    2013-10-02 04:59 - 2013-10-02 04:59 - 0001447 _____ () C:\Users\C3Consultants\AppData\Roaming\Xusage.txt
    2017-02-19 21:35 - 2017-02-19 21:35 - 1938536 _____ () C:\Users\C3Consultants\AppData\Roaming\Zumdox.bin
    2014-01-07 17:02 - 2014-01-07 17:02 - 0000057 _____ () C:\ProgramData\Ament.ini
    ShortcutWithArgument: C:\Users\C3Consultants\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www%2dsearching.com/?prd=set_epf&s=h2jzftpbl0cshmobu,de825189-7290-48fd-8250-4bbf85316770,
    ShortcutWithArgument: C:\Users\C3Consultants\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet-Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www%2dsearching.com/?prd=set_epf&s=h2jzftpbl0cshmobu,de825189-7290-48fd-8250-4bbf85316770,
    ShortcutWithArgument: C:\Users\C3Consultants\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www%2dsearching.com/?prd=set_epf&s=h2jzftpbl0cshmobu,de825189-7290-48fd-8250-4bbf85316770,
    ShortcutWithArgument: C:\Users\C3Consultants\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www-searching.com/?prd=set_epf&s=h2jzftpbl0cshmobu,de825189-7290-48fd-8250-4bbf85316770,
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www-searching.com/?prd=set_epf&s=h2jzftpbl0cshmobu,de825189-7290-48fd-8250-4bbf85316770,
    ShortcutWithArgument: C:\Users\Public\Desktop\Formations Office 2010.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.nuesearch.com/?type=sc&ts=1466494450&z=a1111b41e8c4298291c38c5g9zcq4q7z3t5zfz9w7o&from=wpm0616&uid=ST9500423AS_S2V0E9RJ
    ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www-searching.com/?prd=set_epf&s=h2jzftpbl0cshmobu,de825189-7290-48fd-8250-4bbf85316770,
    C:\Users\C3Consultants\AppData\Roaming\gplyra
    Task: C:\WINDOWS\Tasks\PC Clean Plus_DEFAULT.job => C:\Program Files (x86)\PC Clean Plus\PCCleanPlus.exe <==== ATTENTION
    Task: C:\WINDOWS\Tasks\PC Clean Plus_UPDATES.job => C:\Program Files (x86)\PC Clean Plus\PCCleanPlus.exe <==== ATTENTION
    Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    Task: C:\WINDOWS\Tasks\Traffic Exchange Updater.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Traffic Exchange Updater.exe <==== ATTENTION
    Task: C:\WINDOWS\Tasks\Traffic Exchange v2 - 1.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION
    Task: C:\WINDOWS\Tasks\Traffic Exchange v2 - 2.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION
    Task: C:\WINDOWS\Tasks\Traffic Exchange v2 - 3.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION
    Task: C:\WINDOWS\Tasks\Traffic Exchange v209 - 1.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
    Task: C:\WINDOWS\Tasks\Traffic Exchange v209 - 2.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
    Task: C:\WINDOWS\Tasks\Traffic Exchange v209 - 3.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
    Task: {6DFA2433-FA3C-4D09-9FFA-2F562B75BA09} - System32\Tasks\SMW_UpdateTask_Time_323232353334383331372d2a55456c2d5a34575b413234 => Wscript.exe //B "C:\ProgramData\SearchModule\smhe.js" smu.exe /invoke /f:check_services /l:0 <==== ATTENTION
    Task: {4D05202B-04A0-4B5F-8E16-CBFC0E88B020} - System32\Tasks\jIxmRfRCheckTask => C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe <==== ATTENTION
    Task: {57B61D8D-4C92-46F6-B078-E2AEA764673E} - System32\Tasks\UncheckitUpdateTaskDB => C:\Program Files (x86)\Uncheckit\UncheckitUpdate.exe [2016-07-05] (EVANGEL TECHNOLOGY (HK) LIMITED) <==== ATTENTION
    Task: {9D0D9FE9-1514-4CDA-B677-484B10739520} - System32\Tasks\{7F1F24F0-550B-4900-BB8D-86231EE58D05} => pcalua.exe -a "C:\Program Files (x86)\Common Files\MoveBam\uninstall.exe" -c shuz -f "C:\Program Files (x86)\Common Files\MoveBam\uninstall.dat" -a uninstallme 748899DE-9C2F-4AFF-A463-921125FDEA4F DeviceId=3dc722f1-48ea-b2eb-ee3b-6f7236f78c8c BarcodeId=51107003 ChannelId=3 DistributerName=APSFClickMeIn
    EmptyTemp:
    RemoveProxy:
    Reboot:


    Une fois, le texte collé dans le Bloc-notes,
    Menu "Fichier" puis "Enregistrer sous",
    A gauche, place toi sur le Bureau,
    Dans le champs en bas, nom du fichier mets : fixlist.txt
    Clique sur "Enregistrer", cela va créer fixlist.txt sur le Bureau.

    Relance FRST et clique sur le bouton "Corriger / Fix"
    Un redémarrage sera peut-être nécessaire ( pas obligatoire )
    Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.

    Redémarre l'ordinateur.

    2°)
    Réinitialise/Répare les navigateurs WEB concernés par les problèmes :

    3°)
    Fais un nettoyage Malwarebytes - Tutoriel Malwarebytes Anti-Malware version gratuite

    4°)
    Refais un scan FRST et donne les nouveaux rapports via pjjoint

    0