Désactive ton antivirus le temps de la manipulation car OTM est détecté comme une infection à tort.
Télécharge
http://www.telecharger.sosvirus.net/download/otm/ OTM (OldTimer) sur ton Bureau :
Double-clique sur OTM.exe afin de le lancer. (clic droit "executer en tant qu'administrateur" pour Vista/7/8 )
Copie (Ctrl+C) le texte suivant ci-dessous :
Code : Tout sélectionner:reg
[HKLM\Software\Microsoft\Command Processor]
"Shell"=-
"Autorun"=-
[HKLM\Software\WOW6432Node\Microsoft\Command Processor]
"Shell"=-
"Autorun"=-
[HKCU\Software\Microsoft\Command Processor]
"Shell"=-
"Autorun"=-
[HKU\S-1-5-21-944950025-1172473004-785479979-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"SIGN.MEDIA=1EB68450 setup.EXE"=-
"SIGN.MEDIA=E35B9E Setup.exe"=-
"C:\Users\Gaël\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9D9M88PQ\PS_AIO_03_C4400_NonNet_Full_Win_WW_130_140[1].exe"=-
"C:\Users\Gaël\Desktop\HPSDU.exe"=-
"C:\Users\Gaël\Desktop\Setup_FreeConverter.exe"=-
"C:\Users\Gaël\Desktop\Megaplayer.exe"=-
"C:\Users\Gaël\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J76ED678\install_reader10_fr_gtba_aih.exe"=-
"C:\Users\Gaël\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WICL4C4I\FFSetup280.exe"=-
"C:\Users\Gaël\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J76ED678\FreemakeVideoDownloaderSetup.exe"=-
"c:\Users\Gaël\AppData\Local\Lollipop\lollipop.bat"=-
"C:\Users\GAL~1\AppData\Local\Temp\AIRA1A5.tmp\Adobe AIR Installer.exe"=-
"C:\Users\GAL~1\AppData\Local\Temp\AIR415.tmp\Adobe AIR Installer.exe"=-
"C:\Users\GAL~1\AppData\Local\Temp\IS4248~1\508005514_stp\MySearchDial.exe"=-
"C:\Users\Gaël\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6FA67POT\Pop_Redemption_2013_FRENCH_DVDRip_XviD.exe"=-
"C:\Users\Gaël\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M2RVK7S9\FreemakeVideoDownloaderSetup.exe"=-
"C:\Users\Gaël\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QWUZ2H6W\FreemakeAudioConverterSetup.exe"=-
"SIGN.MEDIA=1D71C2D hfxVolume1Full.exe"=-
"C:\Users\GAL~1\AppData\Local\Temp\AIR6AF1.tmp\Adobe AIR Installer.exe"=-
[HKU\S-1-5-21-944950025-1172473004-785479979-1001\Software\Microsoft\Internet Explorer\Main]
"IconCache"=-
"IE10RunOnceLastShown_TIMESTAMP"=-
[-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00FA007C-D99F-407F-B00B-5B3B0001D8AB}]
[-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1F1E561D-AF17-4510-B996-351BBA0862A7}]
[-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7aaae723-5fb5-4b2d-9327-75519f336825}]
[-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5054EC7-B9CB-4ad5-9F95-D8171A6D6BFA}]
[-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BD18A03F-31CC-4CC0-B52D-9E199122923D}]
[-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAF199D2-BFA7-4394-A4DE-044A08E59B32}]
[-HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00FA007C-D99F-407F-B00B-5B3B0001D8AB}]
[-HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1F1E561D-AF17-4510-B996-351BBA0862A7}]
[-HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{63D8D545-9A84-44bc-B2F8-CE1A786AB67B}]
[-HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7aaae723-5fb5-4b2d-9327-75519f336825}]
[-HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{276B262C-9510-45f8-BDD0-D9CF4BF68476}]
[-HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5054EC7-B9CB-4ad5-9F95-D8171A6D6BFA}]
[-HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BD18A03F-31CC-4CC0-B52D-9E199122923D}]
[-HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB9524B3-24F4-48fa-91C5-B8EEF1C0A14F}]
[-HKLM\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAF199D2-BFA7-4394-A4DE-044A08E59B32}]
[-HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer]
[-HKLM\Software\WOW6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
[-HKLM\SOFTWARE\WOW6432Node\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}]
[-HKU\S-1-5-21-944950025-1172473004-785479979-1001\Software\Freeware]
[-HKU\S-1-5-21-944950025-1172473004-785479979-1001\Software\IE]
[-HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E97E-E325-11CE-BFC1-08002BE10318}]
:files
C:\Users\Gaël\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\*
C:\Windows\syswow64\shortcut_ex.dat
C:\extensions.sqlite
C:\sniffer.log
C:\Users\All Users\SMRResults430.dat
C:\Windows\System32\Tasks\CreateChoiceProcessTask
C:\Windows\System32\Tasks\{07D4D886-711C-4582-A17D-CF4A053A31CD}
:commands
[emptytemp]
Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
Clique maintenant sur le bouton MoveIt!
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
*Le nom du rapport correspond au moment de sa création : date_heure.log
================
donne-moi le contenu de ces deux dossiers :
c:\windows\system32\grouppolicy
c:\windows\system32\grouppolicyuser