salut
Lance Farbar
Copies les lignes suivantes dans le cadre rouge
start::
CloseProcesses:
Hosts:
CreateRestorePoint:
HKLM-x32\...\Run: [] => [X]
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-1788206838-411491774-2195662357-1000\...\MountPoints2: {32a4e093-19ad-11e7-ade7-a41f725be56d} - J:\HiSuiteDownLoader.exe
HKU\S-1-5-21-1788206838-411491774-2195662357-1000\...\MountPoints2: {32a4e097-19ad-11e7-ade7-a41f725be56d} - J:\HiSuiteDownLoader.exe
HKU\S-1-5-21-1788206838-411491774-2195662357-1000\...\MountPoints2: {5e512308-441f-11e7-8c39-a41f725be56d} - J:\Setup.exe
HKU\S-1-5-21-1788206838-411491774-2195662357-1000\...\MountPoints2: {6a5e9516-a404-11e5-a082-a41f725be56d} - F:\AutoRun.exe
HKU\S-1-5-21-1788206838-411491774-2195662357-1000\...\MountPoints2: {6fe251b1-02ce-11e6-a1e3-a41f725be56d} - J:\Setup.exe
HKU\S-1-5-21-1788206838-411491774-2195662357-1000\...\MountPoints2: {cda09ded-f706-11e5-a2fb-a41f725be56d} - J:\Setup.exe
GroupPolicy: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1788206838-411491774-2195662357-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
S4 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X]
S2 doliwampapache; "W:\SCAN copieur\dolibarr\bin\apache\apache2.4.9\bin\httpd.exe" -k runservice [X]
S2 doliwampmysqld; "W:\SCAN copieur\dolibarr\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" doliwampmysqld [X]
S2 HuaweiHiSuiteService64.exe; "C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe" -/service [X]
S2 oodoccs; \\PVE\docv7\oodoccsv7.exe [X]
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{17CCA71B-ECD7-11D0-B908-00A0C9223196}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{33156164-81D6-11D3-8006-00C04FA30A73}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{33156168-81D6-11D3-8006-00C04FA30A73}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{33D9A762-90C8-11D0-BD43-00A0C911CE86}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{4315D437-5B8C-11D0-BD3B-00A0C911CE86}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{505C2E67-8615-4CA9-9B57-48CF6EE696FD}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{62BE5D10-60EB-11D0-BD3B-00A0C911CE86}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{632B606A-BBC6-11D2-A329-006097C4E476}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{6A2E0670-28E4-11D0-A18C-00A0C9118956}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{720D4AC0-7533-11D0-A5D6-28DB04C10000}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{8D52AA2E-40BE-46D7-8F36-DB7B0F636824}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{8E849609-C7E8-4EC7-8BD3-D55E871A340D}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{A5AC04E7-3E13-48CE-A43F-9FBA59DB1544}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{AB37E6C0-194D-4C33-A924-5178414DEB98}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{AB406AAC-2B2B-11D3-B36B-00C04F6108FF}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{C1AB3D89-6973-45A6-AA44-09CEBBF872E5}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{C6E13344-30AC-11D0-A18C-00A0C9118956}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{C6E13360-30AC-11D0-A18C-00A0C9118956}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{C6E13370-30AC-11D0-A18C-00A0C9118956}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{CDA42200-BD88-11D0-BD4E-00A0C911CE86}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{CF3EBABF-3E64-4422-BE23-514BB066ADBE}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{DF0AD8E0-F91C-4109-AE46-1EAA5CD8AB08}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{DF0AD8E1-F91C-4109-AE46-1EAA5CD8AB08}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{DF0AD8E3-F91C-4109-AE46-1EAA5CD8AB08}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{E297AB5E-40B0-41BD-9E06-E4144084EE5F}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{E30629D2-27E5-11CE-875D-00608CB78066}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{E436EBB3-524F-11CE-9F53-0020AF0BA770}\InprocServer32 -> pas de chemin du fichier
CustomCLSID: HKU\S-1-5-21-1788206838-411491774-2195662357-1000_Classes\CLSID\{EE474070-5CD6-4B74-90AD-7284ADDB6331}\InprocServer32 -> pas de chemin du fichier
ContextMenuHandlers1: [BB FlashBack 2] -> {A8065B9E-193F-4797-B62D-8F6321E7FCCB} => -> Pas de fichier
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> Pas de fichier <==== ATTENTION
Task: {617678DD-0D61-4C42-A53E-A1095F7774CE} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> Pas de fichier <==== ATTENTION
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> Pas de fichier <==== ATTENTION
Task: {B9B19C21-52DC-483B-892B-CCAA2A8D8516} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> Pas de fichier <==== ATTENTION
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> Pas de fichier <==== ATTENTION
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> Pas de fichier <==== ATTENTION
IE trusted site: HKU\S-1-5-21-1788206838-411491774-2195662357-1000\...\webcompanion.com -> hxxp://webcompanion.com
C:\Windows\System32\Config\systemprofile\AppData\Local\LavasoftTcpService
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{079A0A97-5D9B-4414-AEE5-696C504EB9D5}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{079A0A97-5D9B-4414-AEE5-696C504EB9D5}
C:\Windows\System32\Tasks\{CB537526-D166-4275-8B27-46E16782AB83}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0FBB8C91-38EE-4DD9-8CA1-591FBDC2384D}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{0FBB8C91-38EE-4DD9-8CA1-591FBDC2384D}
C:\Windows\System32\Tasks\{DB087FA9-2504-4708-9CAD-DA31A98A3FD4}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{32BFACD0-54CA-4890-A679-CE0943130E1E}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{32BFACD0-54CA-4890-A679-CE0943130E1E}
C:\Windows\System32\Tasks\{B1608739-BAC4-46C9-BF31-E3C9EEAC5703}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4CBC9698-CFBF-4A03-B547-AF2311B3A139}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{4CBC9698-CFBF-4A03-B547-AF2311B3A139}
C:\Windows\System32\Tasks\{6FEB6849-96D8-41EA-BA91-09876B0D4C2C}
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|oodocprinterv7
DeleteKey: HKCU\SOFTWARE\Ad-Aware Search Protection
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BB FlashBack 2
DeleteKey: HKLM\Software\Classes\CLSID\{A8065B9E-193F-4797-B62D-8F6321E7FCCB} <== Reinstall Software BB FlashBack 2
DeleteKey: HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui
DeleteKey: HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} <== Reinstall Software igfxcui
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BB FlashBack 2
DeleteKey: HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui
EmptyTemp:
end::
Corrige et heberge le rapport fixlog
@+