salut cant cant
1/ a lire
http://assiste.com/Comment_supprimer/IOBit.html
http://assiste.com/Craptheque/advanced_ ... imate.html
2/Lance Farbar
Copies les lignes suivantes dans le cadre rouge
start::
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-21-4265624635-2019933758-61733912-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.ask.com/?o=13170&l=dis
SearchScopes: HKU\S-1-5-21-4265624635-2019933758-61733912-1001 -> {EF641CB9-A500-480E-ABFC-370E51010B2B} URL = hxxps://search.yahoo.com/search?p={searchTerms}&b={startPage?}&fr=ie8
BHO-x32: Ask Toolbar -> {D4027C7F-154A-4066-A1AD-4243D8127440} -> C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll => Pas de fichier
Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll Pas de fichier
Toolbar: HKU\S-1-5-21-4265624635-2019933758-61733912-1001 -> Pas de nom - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Pas de fichier
Handler: WSKVAllmytubechrome - {91AB862D-07B8-4A85 - Pas de fichier
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ilnidodcffjfecahcfiihlhiohnaobic] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lomojjnmhlhdepbfoknpkenickajcphi] - C:\Program Files (x86)\WinZip Courier\wzwmcgc.crx [2017-11-15]
U2 agp440; pas de ImagePath
U0 Compbatt; pas de ImagePath
S1 epp; \??\E:\makeupdirector 3 utilities\bin64\epp.sys [X]
U2 ERSvc; pas de ImagePath
S3 esihdrv; \??\C:\Users\jean-\AppData\Local\Temp\esihdrv.sys [X] <==== ATTENTION
S3 GUMHFilters; \??\C:\Program Files (x86)\Glarysoft\Malware Hunter\Native\winxp_x64\GUMHFilter.sys [X]
U2 IAStorDataMgrsvc; pas de ImagePath
U2 NIHardwareService; pas de ImagePath
U2 NVSvc; pas de ImagePath
U2 Parvdm; pas de ImagePath
U2 srService; pas de ImagePath
U2 wudfsvc; pas de ImagePath
2018-03-05 17:40 - 2018-03-05 17:45 - 090459208 _____ (IObit ) C:\Users\jean-\Documents\advanced-systemcare-ultimate_11-0-1-59_fr_432775.exe
Ask Toolbar (HKLM-x32\...\{86D4B82A-ABED-442A-BE86-96357B70F4FE}) (Version: 1.6.14.0 - Ask.com) <==== ATTENTION
ContextMenuHandlers1: [chext] -> {E7A4C2DA-F3AF-4145-AC19-E3B215306A54} => -> Pas de fichier
ContextMenuHandlers1: [PfMenu] -> {2F844462-7CB8-489C-828C-32A6422506AF} => -> Pas de fichier
ContextMenuHandlers1: [UnLockerMenu] -> {410BF280-86EF-4E0F-8279-EC5848546AD3} => -> Pas de fichier
ContextMenuHandlers2: [AdAwareContextMenu] -> {5B64240D-5B36-4B9F-A75F-4925B6A53D5B} => -> Pas de fichier
ContextMenuHandlers2-x32: [Glarysoft MalwareHunter] -> {EA847F47-97F1-4D78-AB99-C63CA1C327F0} => C:\Program Files (x86)\Glarysoft\Malware Hunter\x64\MHContextHandlerx64.dll -> Pas de fichier
ContextMenuHandlers3: [AdAwareContextMenu] -> {5B64240D-5B36-4B9F-A75F-4925B6A53D5B} => -> Pas de fichier
ContextMenuHandlers3: [Auslogics Disk Defrag Professional Shell Context Menu 4.x] -> {CC89327D-D094-40B2-82CB-F989EE26FC51} => -> Pas de fichier
ContextMenuHandlers3: [Rebit.ContextMenu] -> {7A9A2CC0-0164-41F8-8305-957DE59A6B0B} => -> Pas de fichier
ContextMenuHandlers4: [Auslogics Disk Defrag Professional Shell Context Menu 4.x] -> {CC89327D-D094-40B2-82CB-F989EE26FC51} => -> Pas de fichier
ContextMenuHandlers4: [PfMenu] -> {2F844462-7CB8-489C-828C-32A6422506AF} => -> Pas de fichier
ContextMenuHandlers4: [UnLockerMenu] -> {410BF280-86EF-4E0F-8279-EC5848546AD3} => -> Pas de fichier
ContextMenuHandlers5: [chext] -> {E7A4C2DA-F3AF-4145-AC19-E3B215306A54} => -> Pas de fichier
ContextMenuHandlers6: [PfMenu] -> {2F844462-7CB8-489C-828C-32A6422506AF} => -> Pas de fichier
Task: {9DBCFBF9-C45B-4326-969F-027A79FD06B0} - \Microsoft\Windows\UNP\RunCampaignManager -> Pas de fichier <==== ATTENTION
AlternateDataStreams: C:\ProgramData\Temp:B56E7461 [133]
DeleteKey: HKLM\SOFTWARE\0d79c293c1ed61418462e24595c90d04
DeleteKey: HKLM\SOFTWARE\WOW6432Node\0d79c293c1ed61418462e24595c90d04
DeleteKey: HKCU\SOFTWARE\csastats
DeleteKey: HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\Auslogics Disk Defrag Professional Shell Context Menu 4.x
DeleteKey: HKLM\Software\Classes\CLSID\{CC89327D-D094-40B2-82CB-F989EE26FC51}
DeleteKey: HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Auslogics Disk Defrag Professional Shell Context Menu 4.x
DeleteKey: HKLM\Software\Classes\CLSID\{CC89327D-D094-40B2-82CB-F989EE26FC51}
DeleteKey: HKLM\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\Auslogics Disk Defrag Professional Shell Context Menu 4.x
DeleteKey: HKLM\Software\Classes\CLSID\{CC89327D-D094-40B2-82CB-F989EE26FC51}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1F41298B-D003-483D-A41D-759333674C57}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1F41298B-D003-483D-A41D-759333674C57}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{1F41298B-D003-483D-A41D-759333674C57}
C:\Windows\System32\Tasks\Nero\Nero Info
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4E21D9C4-40D5-44A1-95A3-56D6FD9F96D3}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4E21D9C4-40D5-44A1-95A3-56D6FD9F96D3}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{4E21D9C4-40D5-44A1-95A3-56D6FD9F96D3}
C:\Windows\System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5A78F131-B9AB-4FD2-999A-CF022DD9DCD8}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5A78F131-B9AB-4FD2-999A-CF022DD9DCD8}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{5A78F131-B9AB-4FD2-999A-CF022DD9DCD8}
C:\Windows\System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{82131BA1-377D-47F3-AE75-C530FFB62513}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{82131BA1-377D-47F3-AE75-C530FFB62513}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{82131BA1-377D-47F3-AE75-C530FFB62513}
C:\Windows\System32\Tasks\COMODO\COMODO Maintenance {947247B5-026A-4437-9371-770782BE839D}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8537B611-EFCE-4601-AB02-B94F5ACAAEB3}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8537B611-EFCE-4601-AB02-B94F5ACAAEB3}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{8537B611-EFCE-4601-AB02-B94F5ACAAEB3}
C:\Windows\System32\Tasks\COMODO\COMODO Telemetry {18AD3DFA-30C0-4B5F-84F7-F1870B1A4921}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9BF30AA1-7E54-451E-99A8-675F3E504443}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{9BF30AA1-7E54-451E-99A8-675F3E504443}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{9BF30AA1-7E54-451E-99A8-675F3E504443}
C:\Windows\System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C300B3A2-7765-4988-822B-67D108FD0EDF}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C300B3A2-7765-4988-822B-67D108FD0EDF}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{C300B3A2-7765-4988-822B-67D108FD0EDF}
C:\Windows\System32\Tasks\COMODO\COMODO CMC {06A09C0F-DD9C-4191-A670-71115CD78627}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C4D5A7E0-11BD-4324-896C-753FAB0CA1DC}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C4D5A7E0-11BD-4324-896C-753FAB0CA1DC}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{C4D5A7E0-11BD-4324-896C-753FAB0CA1DC}
C:\Windows\System32\Tasks\WiseCleaner\WMOSkipUAC
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CAE0558C-9280-42ED-AF6F-9987F0EAC6F7}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CAE0558C-9280-42ED-AF6F-9987F0EAC6F7}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{CAE0558C-9280-42ED-AF6F-9987F0EAC6F7}
C:\Windows\System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10}
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Wondershare Helper Compact.exe
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Smart File Advisor
C:\Program Files (x86)\Smart File Advisor\sfa.exe
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SFAUpdater
C:\Program Files (x86)\Smart File Advisor\SFAUpdater.exe
C:\Users\Administrateur\Desktop\Smart File Advisor Updater.lnk
C:\Users\jean-\Desktop\Smart File Advisor Updater.lnk
C:\Users\WDAGUtilityAccount\Desktop\Smart File Advisor Updater.lnk
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Smart File Advisor_is1
DeleteKey: HKLM\SOFTWARE\Systweak
DeleteKey: HKLM\SOFTWARE\WOW6432Node\Systweak
DeleteKey: HKCU\SOFTWARE\Systweak
C:\Program Files (x86)\Smart File Advisor
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart File Advisor
C:\ProgramData\Systweak
C:\Users\jean-\AppData\Roaming\Systweak
C:\WINDOWS\System32\Config\systemprofile\AppData\Roaming\Systweak
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\chext
DeleteKey: HKLM\Software\Classes\CLSID\{E7A4C2DA-F3AF-4145-AC19-E3B215306A54}
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\PfMenu
DeleteKey: HKLM\Software\Classes\CLSID\{2F844462-7CB8-489C-828C-32A6422506AF}
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\UnLockerMenu
DeleteKey: HKLM\Software\Classes\CLSID\{410BF280-86EF-4E0F-8279-EC5848546AD3}
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\VersionsPageShellExt
DeleteKey: HKLM\Software\Classes\CLSID\{9E42900A-85F9-4E67-9778-575FBBA0A81C}
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32
DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
DeleteKey: HKLM\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\PfMenu
DeleteKey: HKLM\Software\Classes\CLSID\{2F844462-7CB8-489C-828C-32A6422506AF}
DeleteKey: HKLM\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\UnLockerMenu
DeleteKey: HKLM\Software\Classes\CLSID\{410BF280-86EF-4E0F-8279-EC5848546AD3}
DeleteKey: HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\AdAwareContextMenu
DeleteKey: HKLM\Software\Classes\CLSID\{5B64240D-5B36-4B9F-A75F-4925B6A53D5B}
DeleteKey: HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\Rebit.ContextMenu
DeleteKey: HKLM\Software\Classes\CLSID\{7A9A2CC0-0164-41F8-8305-957DE59A6B0B}
DeleteKey: HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\PfMenu
DeleteKey: HKLM\Software\Classes\CLSID\{2F844462-7CB8-489C-828C-32A6422506AF}
DeleteKey: HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\UnLockerMenu
DeleteKey: HKLM\Software\Classes\CLSID\{410BF280-86EF-4E0F-8279-EC5848546AD3}
DeleteKey: HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\chext
DeleteKey: HKLM\Software\Classes\CLSID\{E7A4C2DA-F3AF-4145-AC19-E3B215306A54}
DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\PfMenu
DeleteKey: HKLM\Software\Classes\CLSID\{2F844462-7CB8-489C-828C-32A6422506AF}
DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\UnLockerMenu
DeleteKey: HKLM\Software\Classes\CLSID\{410BF280-86EF-4E0F-8279-EC5848546AD3}
DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\VersionsPageShellExt
DeleteKey: HKLM\Software\Classes\CLSID\{9E42900A-85F9-4E67-9778-575FBBA0A81C}
DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32
DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
DeleteKey: HKLM\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\AdAwareContextMenu
DeleteKey: HKLM\Software\Classes\CLSID\{5B64240D-5B36-4B9F-A75F-4925B6A53D5B}
DeleteKey: HKLM\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\AlcoholShellEx
DeleteKey: HKLM\Software\Classes\CLSID\{32020A01-506E-484D-A2A8-BE3CF17601C3}
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\chext
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\Glarysoft MalwareHunter
DeleteKey: HKLM\Software\Classes\CLSID\{EA847F47-97F1-4D78-AB99-C63CA1C327F0}
DeleteKey: HKLM\Software\Wow6432Node\Classes\CLSID\{EA847F47-97F1-4D78-AB99-C63CA1C327F0}
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\PfMenu
DeleteKey: HKLM\Software\Wow6432Node\Classes\CLSID\{2F844462-7CB8-489C-828C-32A6422506AF}
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\UnLockerMenu
DeleteKey: HKLM\Software\Wow6432Node\Classes\CLSID\{410BF280-86EF-4E0F-8279-EC5848546AD3}
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\VersionsPageShellExt
DeleteKey: HKLM\Software\Classes\CLSID\{9E42900A-85F9-4E67-9778-575FBBA0A81C}
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32
DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
DeleteKey: HKLM\Software\Classes\lnkfile\shellex\ContextMenuHandlers\IobitStartMenu
DeleteKey: HKLM\Software\Wow6432Node\Classes\CLSID\{AF8FA9C9-9907-463e-BDC3-4CC1200D6310}
DeleteKey: HKLM\Software\Classes\lnkfile\shellex\ContextMenuHandlers\PfMenu
DeleteKey: HKLM\Software\Classes\lnkfile\shellex\ContextMenuHandlers\UnLockerMenu
DeleteKey: HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\AdAwareContextMenu
DeleteKey: HKLM\Software\Wow6432Node\Classes\CLSID\{5B64240D-5B36-4B9F-A75F-4925B6A53D5B}
DeleteKey: HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\Auslogics Disk Defrag Professional Shell Context Menu 4.x
DeleteKey: HKLM\Software\Classes\CLSID\{CC89327D-D094-40B2-82CB-F989EE26FC51}
DeleteKey: HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\Rebit.ContextMenu
DeleteKey: HKLM\Software\Wow6432Node\Classes\CLSID\{7A9A2CC0-0164-41F8-8305-957DE59A6B0B}
DeleteKey: HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Auslogics Disk Defrag Professional Shell Context Menu 4.x
DeleteKey: HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\PfMenu
DeleteKey: HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\UnLockerMenu
DeleteKey: HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\chext
DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Glarysoft MalwareHunter
DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\PfMenu
DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\UnLockerMenu
DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\VersionsPageShellExt
DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32
DeleteKey: HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\AdAwareContextMenu
DeleteKey: HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\AlcoholShellEx
DeleteKey: HKLM\Software\Classes\CLSID\{32020A01-506E-484D-A2A8-BE3CF17601C3}
DeleteKey: HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\Auslogics Disk Defrag Professional Shell Context Menu 4.x
DeleteKey: HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\Glarysoft MalwareHunter
cmd: ipconfig /flushdns
cmd: netsh winsock reset
EmptyTemp:
end::
Corrige et heberge le rapport fixlog
@+