Petit astucien ![]() | Bonjour, J'ai passé ADW Cleaner, rien. Mon antivirus Trend Micro, rien. J'ai mis à jour tous les pilotes. Mon dépanneur informatique me parle de reformater le disque C ? Qui peut m'aider ? Merci. PIPE
[Configuration automatique à compléter]
| |||||||
Publicité | ||||||||
Equipe PC Astuces | Bonjour, Le sujet a été déplacé par la modération dans le forum Windows 7 qui semble plus adéquat. Vous pouvez continuer la discussion à la suite de ce message. A bientôt. | |||||||
![]() ![]() | je ne sais pas quel navigateur tu utilises mais du peux essayer de désactiver l'accélération matérielle pour voir. | |||||||
Petit astucien ![]() | Bonsoir, Merci de votre message. Je vais essayer ça. PIPE | |||||||
Petit astucien ![]() | Bonjour, Un peu "largué" de l'informatique, sur Windows 7, je ne trouve pas comment désactiver l'accélération matérielle ? Merci de votre aide. PIPE | |||||||
![]() ![]() | Bonjour Charge ZHPDiag : https://www.nicolascoolman.com/fr/download/zhpdiag/ Et poste ici le rapport que ce logiciel va sortir avec Cjoint (coche privée et 21 jours) : https://www.cjoint.com/ Si tu es infecté tu pourras demander de l'aide sur le forum "analyse de rapports et désinfection" Laisse tomber ton dépanneur Modifié par Jean_Aymard le 02/02/2018 09:09 | |||||||
Petit astucien ![]() | ||||||||
![]() | Bonjour PIPE Le PC est infecté. Clique l'icone
| |||||||
Petit astucien ![]() | Re, Merci de votre aide. PIPE | |||||||
Publicité | ||||||||
Equipe PC Astuces | Bonjour, Le sujet a été déplacé par la modération dans le forum Analyse de rapports et désinfection qui semble plus adéquat. Vous pouvez continuer la discussion à la suite de ce message. A bientôt. | |||||||
Groupe Sécurité ![]() | Bienvenu PIPE dans le Forum " Analyse de rapports et Désinfections "
Tu reviendras donc avec les rapports (si ce n'est déjà fait ) Modifié par Pierre95 le 04/02/2018 11:30 | |||||||
Petit astucien ![]() | Bonjour, Merci de votre réponse. Je vais tenter ? cette manip fastidieuse... A suivre... PIPE | |||||||
Groupe Sécurité ![]() | Bonsoir,
réponse ambigüe, avec des sous entendus, et des ... Que fais tu ? Sans réponse et sans rapports , je clos et fais verrouiller la demande
| |||||||
Petit astucien ![]() | Bonjour, J'ai eu un souci familial. Je reprends ça demain. PIPE | |||||||
Petit astucien ![]() | ||||||||
Groupe Sécurité ![]() | Hello PIPE, Citation
Start::
CreateRestorePoint: CloseProcesses: VirusTotal: C:\ProgramData\mia67A4.tmp;C:\ProgramData\miaC95A.tmp StartRegEdit: Windows Registry Editor Version 5.00 [HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\tmbp] "CLSID="" EndRegEdit: DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EF35A80F-983B-42FB-9880-2F49C96EE7BC} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{EF35A80F-983B-42FB-9880-2F49C96EE7BC} C:\WINDOWS\System32\Tasks\{00055082-C014-4AC8-9488-35DB87BAEA7D} DeleteKey: HKLM\SOFTWARE\ErrorLists-crcodedownloader DeleteKey: HKLM\SOFTWARE\WOW6432Node\ErrorLists-crcodedownloader DeleteKey: HKCU\SOFTWARE\AppDataLow\Findizer C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Soft-Now bundle C:\ProgramData\InstallMate DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\Youtomato.FLVPlayer DeleteKey: HKLM\Software\Classes\CLSID\{0C671AE6-FB74-4582-AF90-3ABF895450B7} <== Reinstall Software Youtomato.FLVPlayer DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Youtomato.FLVPlayer DeleteKey: HKLM\Software\Classes\CLSID\{0C671AE6-FB74-4582-AF90-3ABF895450B7} <== Reinstall Software Youtomato.FLVPlayer DeleteKey: HKLM\Software\Classes\Installer\Products\7E203A2B4AF85854BAF7214CEDCBD023 DeleteKey: HKLM\Software\Classes\Installer\Futures\7E203A2B4AF85854BAF7214CEDCBD023 DeleteKey: HKCU\Software\Microsoft\Installer\Products\7E203A2B4AF85854BAF7214CEDCBD023 DeleteKey: HKCU\Software\Microsoft\Installer\Futures\7E203A2B4AF85854BAF7214CEDCBD023 DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\Youtomato.FLVPlayer DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Youtomato.FLVPlayer DeleteKey: HKCU\Software\Microsoft\Installer\Products\7E203A2B4AF85854BAF7214CEDCBD023 DeleteKey: HKCU\Software\Microsoft\Installer\Features\7E203A2B4AF85854BAF7214CEDCBD023 DeleteKey: HKU\S-1-5-21-2309766667-536633607-725385818-1000\Software\Microsoft\Installer\Products\7E203A2B4AF85854BAF7214CEDCBD023 DeleteKey: HKU\S-1-5-21-2309766667-536633607-725385818-1000\Software\Microsoft\Installer\Features\7E203A2B4AF85854BAF7214CEDCBD023 DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02BF2AF3-F7D9-4EEA-A0D5-B33B42A38722} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{02BF2AF3-F7D9-4EEA-A0D5-B33B42A38722} C:\WINDOWS\System32\Tasks\{74D9396B-9B74-4622-B2A6-35A3ECD5B361} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09395151-13CA-4CCE-B9F9-A0646A6DDF58} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{09395151-13CA-4CCE-B9F9-A0646A6DDF58} C:\WINDOWS\System32\Tasks\{B8507741-9D77-4D0E-B85B-21BA68FEE1F1} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0B24E9F0-FA72-47AC-84E6-90D596773E95} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{0B24E9F0-FA72-47AC-84E6-90D596773E95} C:\WINDOWS\System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2ACB8197-459E-471B-A7B9-530C2A7693A9} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{2ACB8197-459E-471B-A7B9-530C2A7693A9} C:\WINDOWS\System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{42BC3E31-9976-4A66-87EB-3C639742CF74} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{42BC3E31-9976-4A66-87EB-3C639742CF74} C:\WINDOWS\System32\Tasks\{39DEC001-62C7-4A3E-8DBD-6CFFEBA0369A} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5C8B812D-BFAE-4044-A3F2-D40148BB790A} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{5C8B812D-BFAE-4044-A3F2-D40148BB790A} C:\WINDOWS\System32\Tasks\{E95E28F3-95E8-47E5-AFA8-50321156CBD3} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7C51770D-196E-4A8C-B66D-99B59BAB5CEE} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{7C51770D-196E-4A8C-B66D-99B59BAB5CEE} C:\WINDOWS\System32\Tasks\{A7B863A4-0315-4CE0-BB2D-C1B03AF1AD58} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7D2C24D2-A2DE-416B-8FA2-606D7FF732DD} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{7D2C24D2-A2DE-416B-8FA2-606D7FF732DD} C:\WINDOWS\System32\Tasks\{CE4DBA9D-53CC-4F8A-818C-22AF4EDB7604} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{828F1264-A8A1-4834-8D1B-B73D297E9A6B} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{828F1264-A8A1-4834-8D1B-B73D297E9A6B} C:\WINDOWS\System32\Tasks\{6CB23FC6-9288-4B57-9795-92F90D336E31} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{994C86AD-A929-4B2C-88A0-4E25A107A029} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{994C86AD-A929-4B2C-88A0-4E25A107A029} C:\WINDOWS\System32\Tasks\Microsoft\Windows\SystemRestore\SR DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9B576101-A8BF-4061-8756-44A4CBD04050} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{9B576101-A8BF-4061-8756-44A4CBD04050} C:\WINDOWS\System32\Tasks\{5C69BCEC-B625-4359-BADD-0FE8EA81AC2C} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D} C:\WINDOWS\System32\Tasks\Microsoft\Windows\Location\Notifications DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AE4B3D6C-D578-452F-9264-FE5B69B1D04E} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{AE4B3D6C-D578-452F-9264-FE5B69B1D04E} C:\WINDOWS\System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B0556919-C205-47D5-9710-C5D77576F39B} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{B0556919-C205-47D5-9710-C5D77576F39B} C:\WINDOWS\System32\Tasks\{21280E30-7CAA-4C97-AD68-6EB612BDFA8C} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F17E4FD1-60E5-4E50-A158-E88F11D24F33} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{F17E4FD1-60E5-4E50-A158-E88F11D24F33} C:\WINDOWS\System32\Tasks\IPVanish.VpnClient DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F28ECC0C-C9C2-4AE8-B3FF-E046698EF38B} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{F28ECC0C-C9C2-4AE8-B3FF-E046698EF38B} C:\WINDOWS\System32\Tasks\{18E150F3-628F-4DC8-8C65-5E6FC197EB73} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F2E57BEE-5F83-4CBA-B1D0-4A9E5CC41BEF} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{F2E57BEE-5F83-4CBA-B1D0-4A9E5CC41BEF} C:\WINDOWS\System32\Tasks\{387FF528-AF92-42F0-B296-4FC76051B20B} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FE45B2B6-16D8-49E7-97D1-853520372844} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{FE45B2B6-16D8-49E7-97D1-853520372844} C:\WINDOWS\System32\Tasks\{4FCE792D-2F85-45AB-A28D-2B811E1FAF6D} DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|iTubeStudioUpdateHelper.exe DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} DeleteKey: HKLM\Software\Classes\CLSID\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} DeleteKey: HKCU\SOFTWARE\Magicbit DeleteKey: HKCU\SOFTWARE\undefined DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\Cover Designer DeleteKey: HKLM\Software\Classes\CLSID\{73FCA462-9BD5-4065-A73F-A8E5F6904EF7} DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32 DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} DeleteKey: HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files DeleteKey: HKLM\Software\Classes\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} DeleteKey: HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\ACE DeleteKey: HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000} DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files DeleteKey: HKLM\Software\Classes\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32 DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASAPI32 DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASMANCS DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32 DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS DeleteKey: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} DeleteKey: HKLM\Software\Classes\CLSID\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\Cover Designer DeleteKey: HKLM\Software\Classes\CLSID\{73FCA462-9BD5-4065-A73F-A8E5F6904EF7} DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32 DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} DeleteKey: HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files DeleteKey: HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\ACE DeleteKey: HKLM\Software\Wow6432Node\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000} DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32 DeleteKey: HKLM\SOFTWARE\Wow6432Node\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASAPI32 DeleteKey: HKLM\SOFTWARE\Wow6432Node\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASMANCS DeleteKey: HKLM\SOFTWARE\Wow6432Node\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32 DeleteKey: HKLM\SOFTWARE\Wow6432Node\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS C:\Windows\Installer\MSIFE95.tmp DeleteKey: HKLM\SYSTEM\CurrentControlSet\Services\WsDrvInst DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3CF9ECE0-1A9F-11D2-8C73-00C06C2005DE} DeleteKey: HKLM\SOFTWARE\WOW6432Node\Clients\StartMenuInternet\Firefox-3EBF1177EACBB8CA DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{A5DD9A49-152B-4620-A6FA-FB72941CC39F} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{24BC36F8-BDB8-448B-A28E-2C922E9A826F} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{F6250181-B06D-4B65-A44B-11B73250760B} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{9D748335-0336-401B-94B1-E81A719278EE} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{5FEE3329-C2D6-448A-805C-71B66ABC9B8A} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{3287CF99-09F7-47CA-9043-1A87E996DB98} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{D2A5C842-E2E4-4617-9B8C-B1A7DBC5DD6B} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{D316AF61-B6AE-4CB2-A041-5595493EFDAC} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{4EF3FCE8-5ED6-44A4-A2B7-200268C988AF} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{6377312F-B47E-4371-82CF-383B1AC2C0A9} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{535C755B-B954-487D-9F5F-56C725205ECE} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{FF575E0F-CD95-48F3-9384-7A09508450AE} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{8F26501B-B13A-4BE3-9BC4-F947E4F706E0}C:\programdata\logishrd\logioptions\software\6.60.570\logioptionsmgr.exe DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{3F4C7686-17ED-4583-90C7-91687159F570}C:\programdata\logishrd\logioptions\software\6.60.570\logioptionsmgr.exe DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{33E18200-487E-40F0-9CDE-039DA8EAE18A} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{6B6C3538-E75A-4C1E-B620-033977A1A366} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{0303795E-B058-43EC-8DC3-A6B79245DA35} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{D0717EDE-9C47-479E-AC31-0769B69B3A81} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{AB13275E-2EF6-46AB-BCEC-49C41EC64525} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{A71034A7-085E-406A-A753-126013FF793E} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{464702AE-AE4B-427D-B86E-09E2F2F982DA} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{9AE160E7-352B-4FAD-840C-2CE422FBC067} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{7BD301C0-C82F-444C-8C24-15AC6689FE35} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{A81FFBB4-5039-4DE6-8369-2022EAC38BCF} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{D833FF77-3F21-46E0-B3EF-0BB03C588E69} DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{6D278189-85E6-4D06-92FC-E266B63BCE10} Cmd: netsh advfirewall reset Cmd: Netsh advfirewall set allprofiles state on Cmd: ipconfig /flushdns End::
| |||||||
Petit astucien ![]() | ||||||||
Publicité | ||||||||
Groupe Sécurité ![]() | Le fixlist a bien fonctionné mais je n'avais pas tout mis car je n'avais pas tenu compte des rapports FRST. Je dois t'en préparer un second Pour cela Peux tu me refaire un ZHPDiag tout frais tout chaud ainsi qu'un scan FRST avec ses 3 rapports ?
| |||||||
Petit astucien ![]() | Re, Je fais ça dans la foulée, le temps que ça se fasse. PIPE | |||||||
Petit astucien ![]() | https://www.cjoint.com/c/HBfjXhBnSzw
https://www.cjoint.com/c/HBfj2aX5cLw
https://www.cjoint.com/c/HBfj3t6ASIw
https://www.cjoint.com/c/HBfj4g53etw
Voilà. PIPE
Modifié par PIPE le 05/02/2018 10:56 | |||||||
Groupe Sécurité ![]() | Deuxième tir de barrage !! Peux tu désinstaller via panneau de config Windows, ces logiciels Citation
Start::
CreateRestorePoint: CloseProcesses: Hosts: Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\9.2.1026\9.2.1026\TmBpIe32.dll Pas de fichier VirusTotal: C:\Program Files (x86)\GUTFA7E.tmp DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|iTubeStudioUpdateHelper.exe C:\ProgramData\mia67A4.tmp C:\ProgramData\miaC95A.tmp C:\Windows\Installer\MSI1A6.tmp DeleteKey: HKLM\SOFTWARE\AVAST Software DeleteKey: HKLM\SOFTWARE\WOW6432Node\AVAST Software DeleteKey: HKLM\SOFTWARE\McAfee.com DeleteKey: HKLM\SOFTWARE\WOW6432Node\McAfee.com DeleteKey: HKCU\SOFTWARE\MCAFEE C:\Program Files\McAfee Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE -> HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE -> HKU\S-1-5-21-2309766667-536633607-725385818-1000\...\MountPoints2: {a95cc76a-b1ec-11e5-97cb-50e549cd0f05} - E:\Startme.exe HKU\S-1-5-21-2309766667-536633607-725385818-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> HKU\S-1-5-18\...\Run: [] => [X] HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> ShellExecuteHooks-x32: Pas de nom - {EE761688-C137-4b04-8FAB-3C9CDF0886F0} - -> Pas de fichier ShortcutTarget: BackupRemind.lnk -> C:\Program Files (x86)\Wondershare\dr.fone toolkit pour Android\Addins\AndroidBackupRestore\BackupRemind.exe (Pas de fichier) ShortcutTarget: Directory Opus (Démarrage).lnk -> C:\Program Files\GPSoftware\Directory Opus\dopus.exe (Pas de fichier) GroupPolicy: Restriction <==== ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2309766667-536633607-725385818-1000 -> {0CE02FFA-A6B0-46F6-BA2F-BD32C3630126} URL = SearchScopes: HKU\S-1-5-21-2309766667-536633607-725385818-1000 -> {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL = SearchScopes: HKU\S-1-5-21-2309766667-536633607-725385818-1000 -> {2D0ADC46-5834-4757-9314-0164AEE3E30B} URL = hxxps://fr.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default SearchScopes: HKU\S-1-5-21-2309766667-536633607-725385818-1000 -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = Toolbar: HKU\S-1-5-21-2309766667-536633607-725385818-1000 -> Pas de nom - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Pas de fichier Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\9.2.1026\9.2.1026\TmBpIe32.dll Pas de fichier Handler: WSISAllmytubechrome - Pas de valeur CLSID FF Plugin: @microsoft.com/GENUINE -> disabled [Pas de fichier] FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Pas de fichier] CHR HKU\S-1-5-21-2309766667-536633607-725385818-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo] - hxxp://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [dflinnddekagfkncpgojoppgnppfkbkj] - CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fgbbakekmgfopcdilonmbipagcoocleb] - C:\Program Files (x86)\Youtomato\YT Downloader\YTD_GC.crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx CHR HKLM-x32\...\Chrome\Extension: [ljcdopdmbcpndfopibbkmijkhmbdgpjj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ohhcpmplhhiiaoiddkfboafbhiknefdf] - hxxps://clients2.google.com/service/update2/crx S4 LMIRfsClientNP; pas de ImagePath S3 LVcKap64; system32\DRIVERS\LVcKap64.sys [X] S3 taphss6; system32\DRIVERS\taphss6.sys [X] U2 TMAgent; pas de ImagePath U2 V2iMount; pas de ImagePath CustomCLSID: HKU\S-1-5-21-2309766667-536633607-725385818-1000_Classes\CLSID\{144DF3B2-2402-47AE-9583-5A045929A8D4}\InprocServer32 -> C:\Users\Jean Louis\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll => Pas de fichier CustomCLSID: HKU\S-1-5-21-2309766667-536633607-725385818-1000_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Jean Louis\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => Pas de fichier ContextMenuHandlers1_S-1-5-21-2309766667-536633607-725385818-1000: [OpusZip] -> {E9FE4040-3C93-11D4-8006-00201860E88A} => -> Pas de fichier ContextMenuHandlers4_S-1-5-21-2309766667-536633607-725385818-1000: [OpusZip] -> {E9FE4040-3C93-11D4-8006-00201860E88A} => -> Pas de fichier ContextMenuHandlers5_S-1-5-21-2309766667-536633607-725385818-1000: [DOpus] -> {B9DD4945-1BED-4CB7-994C-F40B72B7725A} => -> Pas de fichier Task: {01E9267A-9878-47B6-A192-AA5B8FB10777} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> Pas de fichier <==== ATTENTION Task: {1F29F723-AC4E-47C0-971E-374A3FDE4D35} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> Pas de fichier <==== ATTENTION Task: {66868859-07DC-4E37-BED9-73A99DA4AAC8} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2309766667-536633607-725385818-1000UA => C:\Users\Jean Louis\AppData\Local\Google\Update\GoogleUpdate.exe [2017-04-24] (Google Inc.) Task: {72805088-4FE1-4BA6-8FE6-CECC259594BE} - System32\Tasks\GoogleUpdateTaskMachineCore1d12d2db2b39668 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {758ACCA9-9A8F-4FE4-A9AE-BBDBF42E54C6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {95FCA8C7-F016-4364-A8E5-3E9726DD2CF1} - System32\Tasks\GoogleUpdateTaskMachineUA1d12d2db36189bb => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {A49F140C-EA32-449B-9861-181E0710867F} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> Pas de fichier <==== ATTENTION Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> Pas de fichier <==== ATTENTION Task: {B86C36DC-69F1-4305-AC17-AFC2CF8424DD} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2309766667-536633607-725385818-1000Core => C:\Users\Jean Louis\AppData\Local\Google\Update\GoogleUpdate.exe [2017-04-24] (Google Inc.) Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> Pas de fichier <==== ATTENTION Task: {EF35A80F-983B-42FB-9880-2F49C96EE7BC} - \{00055082-C014-4AC8-9488-35DB87BAEA7D} -> Pas de fichier <==== ATTENTION Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> Pas de fichier <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`28hfm [0] AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`29hfm [0] AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm [0] AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0] AlternateDataStreams: C:\ProgramData\sdpsenv.dat:naughtypirates [322] AlternateDataStreams: C:\ProgramData\TEMP:373E1720 [131] AlternateDataStreams: C:\ProgramData\TEMP:AD022376 [147] HKLM\...\batfile\DefaultIcon: %SystemRoot%\SysWow64\imageres.dll,-68 <==== ATTENTION HKLM\...\cmdfile\DefaultIcon: %SystemRoot%\SysWow64\imageres.dll,-68 <==== ATTENTION HKLM\...\comfile\DefaultIcon: %SystemRoot%\SysWow64\shell32.dll,2 <==== ATTENTION End::
| |||||||
Petit astucien ![]() | Re, Merci de votre message. Je pars en réunion et je fais ça dans la soirée. Merci encore. PIPE | |||||||
Groupe Sécurité ![]() | Pas de problème, Pipe ça roule pour ce soir Pierre | |||||||
Petit astucien ![]() | ||||||||
Petit astucien ![]() | Bonsoir, Que fait-on ? Que doit-on faire ? Que fais-je ? Que dois-je faire ? Merci. PIPE | |||||||
Groupe Sécurité ![]() | Bonsoir, | |||||||
Publicité | ||||||||
| ||||||||
Les bons plans du moment PC Astuces | Tous les Bons Plans | |||||||||||||||
|