refais le script en mode sans echec sans prise en charge reseau
-------------- QuickScript | g3n-h@ckm@n | 2_23.09.2016.1 ---------------
----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 04/12/2016 22:54:17
Updated 23/09/2016 | 10.30 by g3n-h@ckm@n
Contact :
http://www.sosvirus.net/
Time Zone : (UTC+01:00) Bruxelles, Copenhague, Madrid, Paris
[Bruno (Administrator)] - [BRUNO-PC] (S-1-5-21-1413675022-3679237491-1003182551-1000)
System: Microsoft Windows 7 Édition Intégrale - Service Pack 1 - (6.1.7601) - BuildType: Multiprocessor Free - OSLanguage: 1036 (040c)
System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True
Boot : Microsoft Windows 7 Édition Intégrale |C:\Windows|\Device\Harddisk0\Partition2
Boot : SafeMode
PC: MS-7850 - MSI - IdNumber: To be filled by O.E.M. - UUID: 00000000-0000-0000-0000-D8CB8AEA4DFD
Processor : X64 - 3200 Mhz - Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz
BIOS Date: 03/30/15 12:56:41 Ver: V2.9B0 - en|US|iso8859-1 - American Megatrends Inc. - S/N: To be filled by O.E.M. - V2.9 - HPQOEM - 1072009
CoreTemp : 29.8 Celsius
----------| Script
Service : ZAM Not Deleted !
HKLM\.\ControlSet001\Services\ZAM Not Deleted !
HKLM\.\ControlSet001\.\Root\LEGACY_ZAM Deleted Successfully
HKLM\.\ControlSet002\Services\ZAM Not Deleted !
HKLM\.\ControlSet002\.\Root\LEGACY_ZAM Deleted Successfully
HKLM\.\MountedDevices\Services\ZAM Not Deleted !
HKLM\.\MountedDevices\.\Root\LEGACY_ZAM Not Deleted !
HKLM\.\RNG\Services\ZAM Not Deleted !
HKLM\.\RNG\.\Root\LEGACY_ZAM Not Deleted !
HKLM\.\Select\Services\ZAM Not Deleted !
HKLM\.\Select\.\Root\LEGACY_ZAM Not Deleted !
HKLM\.\Setup\Services\ZAM Not Deleted !
HKLM\.\Setup\.\Root\LEGACY_ZAM Not Deleted !
HKLM\.\Software\Services\ZAM Not Deleted !
HKLM\.\Software\.\Root\LEGACY_ZAM Not Deleted !
HKLM\.\WPA\Services\ZAM Not Deleted !
HKLM\.\WPA\.\Root\LEGACY_ZAM Not Deleted !
HKLM\.\CurrentControlSet\Services\ZAM Not Deleted !
HKLM\.\CurrentControlSet\.\Root\LEGACY_ZAM Deleted Successfully
Service : ZAM_Guard Not Deleted !
HKLM\.\ControlSet001\Services\ZAM_Guard Not Deleted !
HKLM\.\ControlSet001\.\Root\LEGACY_ZAM_Guard Deleted Successfully
HKLM\.\ControlSet002\Services\ZAM_Guard Not Deleted !
HKLM\.\ControlSet002\.\Root\LEGACY_ZAM_Guard Deleted Successfully
HKLM\.\MountedDevices\Services\ZAM_Guard Not Deleted !
HKLM\.\MountedDevices\.\Root\LEGACY_ZAM_Guard Not Deleted !
HKLM\.\RNG\Services\ZAM_Guard Not Deleted !
HKLM\.\RNG\.\Root\LEGACY_ZAM_Guard Not Deleted !
HKLM\.\Select\Services\ZAM_Guard Not Deleted !
HKLM\.\Select\.\Root\LEGACY_ZAM_Guard Not Deleted !
HKLM\.\Setup\Services\ZAM_Guard Not Deleted !
HKLM\.\Setup\.\Root\LEGACY_ZAM_Guard Not Deleted !
HKLM\.\Software\Services\ZAM_Guard Not Deleted !
HKLM\.\Software\.\Root\LEGACY_ZAM_Guard Not Deleted !
HKLM\.\WPA\Services\ZAM_Guard Not Deleted !
HKLM\.\WPA\.\Root\LEGACY_ZAM_Guard Not Deleted !
HKLM\.\CurrentControlSet\Services\ZAM_Guard Not Deleted !
HKLM\.\CurrentControlSet\.\Root\LEGACY_ZAM_Guard Deleted Successfully
Value : [HKU\S-1-5-18\Software\Classes\http\DefaultIcon]~[] Not Found !
Value : [HKU\S-1-5-18\Software\Classes\http\shell\open\command]~[] Not Found !
Value : [HKU\S-1-5-18\Software\Classes\https\DefaultIcon]~[] Not Found !
Key : [HKU\S-1-5-18\Software\Classes\https\shell\open\command] Not Found !
Value : [HKU\S-1-5-18\Software\Clients\StartMenuInternet]~[] Not Found !
Value : [HKU\S-1-5-18\Software\Classes\ftp\shell\open\command]~[] Not Found !
Value : [HKU\S-1-5-18\Software\Classes\ftp\DefaultIcon]~[] Not Found !
Key : [HKU\S-1-5-21-1413675022-3679237491-1003182551-1000\Software\Microsoft\Windows\CurrentVersion\App Paths\UCBrowser.exe] Not Found !
Value : [HKU\S-1-5-21-1413675022-3679237491-1003182551-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]~[c] Not Found !
Value : [HKU\S-1-5-21-1413675022-3679237491-1003182551-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]~[a] Deleted Successfully
Key : [HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SDTray] Not Found !
Key : [HKU\S-1-5-21-1413675022-3679237491-1003182551-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery] Deleted Successfully
Value : [HKU\S-1-5-21-1413675022-3679237491-1003182551-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery]~[] Not Found !
Key : [HKU\S-1-5-21-1413675022-3679237491-1003182551-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{97a0de53-822c-11e6-b695-d8cb8aea4dfd}] Not Found !
Key : [HKU\S-1-5-21-1413675022-3679237491-1003182551-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{e3bd1006-75dc-11e6-baf2-d8cb8aea4dfd}] Not Found !
[HKU\S-1-5-21-1413675022-3679237491-1003182551-1000\SOFTWARE\Microsoft\Internet Explorer\Toolbar]~[Locked] : 0 -> Set Successfully
Key : [HKU\S-1-5-21-1413675022-3679237491-1003182551-1000\Software\Greatis] Not Found !
Key : [HKU\S-1-5-21-1413675022-3679237491-1003182551-1000\Software\Safer Networking Limited] Not Found !
Key : [HKLM\Software\WOW6432Node\Greatis] Not Found !
Key : [HKLM\Software\WOW6432Node\Safer Networking Limited] Not Found !
-------------- | Edition C:\Reset.cmd
@echo off
setlocal
echo.
echo Determine whether we are on an 32 or 64 bit machine
echo.
if "%PROCESSOR_ARCHITECTURE%"=="x86" if "%PROCESSOR_ARCHITEW6432%"=="" goto x86
set ProgramFilesPath=%ProgramFiles(x86)%
goto startResetting
:x86
set ProgramFilesPath=%ProgramFiles%
:startResetting
echo.
if exist "%ProgramFilesPath%\Windows Resource Kits\Tools\subinacl.exe" goto filesExist
echo ***ERROR*** - Could not find file %ProgramFilesPath%\Windows Resource Kits\Tools\subinacl.exe. Double-check that SubInAcl is correctly installed and re-run this script.
goto END
:filesExist
pushd "%ProgramFilesPath%\Windows Resource Kits\Tools"
subinacl.exe /subkeyreg HKEY_LOCAL_MACHINE /grant=administrators=f /grant=system=f
subinacl.exe /subkeyreg HKEY_CURRENT_USER /grant=administrators=f /grant=system=f
subinacl.exe /subkeyreg HKEY_CLASSES_ROOT /grant=administrators=f /grant=system=f
subinacl.exe /subdirectories %windir% /grant=administrators=f /grant=system=f
echo FINISHED.
echo.
echo Press any key to exit . . .
pause >NUL
popd
:END
endlocal
-------------- | Edition C:\Windows\System32\Tasks\{47A681F9-0F95-4379-B449-3C7C944770E2}
<?xml version="1.0" encoding="UTF-16"?>
<Task version="1.2" xmlns="
http://schemas.microsoft.com/windows/2004/02/mit/task">
<RegistrationInfo />
<Triggers>
<RegistrationTrigger>
<Enabled>true</Enabled>
</RegistrationTrigger>
</Triggers>
<Settings>
<MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>
<DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>
<StopIfGoingOnBatteries>true</StopIfGoingOnBatteries>
<AllowHardTerminate>true</AllowHardTerminate>
<StartWhenAvailable>false</StartWhenAvailable>
<RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable>
<IdleSettings>
<Duration>PT10M</Duration>
<WaitTimeout>PT1H</WaitTimeout>
<StopOnIdleEnd>true</StopOnIdleEnd>
<RestartOnIdle>false</RestartOnIdle>
</IdleSettings>
<AllowStartOnDemand>true</AllowStartOnDemand>
<Enabled>false</Enabled>
<Hidden>false</Hidden>
<RunOnlyIfIdle>false</RunOnlyIfIdle>
<WakeToRun>false</WakeToRun>
<ExecutionTimeLimit>PT72H</ExecutionTimeLimit>
<Priority>7</Priority>
</Settings>
<Actions Context="Author">
<Exec>
<Command>C:\Windows\system32\pcalua.exe</Command>
<Arguments>-a C:\Users\Bruno\Downloads\LGMobileSupportTool.exe -d C:\Users\Bruno\Downloads</Arguments>
</Exec>
</Actions>
<Principals>
<Principal id="Author">
<UserId>Bruno-PC\Bruno</UserId>
<LogonType>InteractiveToken</LogonType>
<RunLevel>LeastPrivilege</RunLevel>
</Principal>
</Principals>
</Task>
-------------- | Edition C:\Windows\System32\Tasks\{C9FC4D71-5136-42C8-8904-5F5D47CA4FD1}
<?xml version="1.0" encoding="UTF-16"?>
<Task version="1.2" xmlns="
http://schemas.microsoft.com/windows/2004/02/mit/task">
<RegistrationInfo />
<Triggers>
<RegistrationTrigger>
<Enabled>true</Enabled>
</RegistrationTrigger>
</Triggers>
<Settings>
<MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>
<DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>
<StopIfGoingOnBatteries>true</StopIfGoingOnBatteries>
<AllowHardTerminate>true</AllowHardTerminate>
<StartWhenAvailable>false</StartWhenAvailable>
<RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable>
<IdleSettings>
<Duration>PT10M</Duration>
<WaitTimeout>PT1H</WaitTimeout>
<StopOnIdleEnd>true</StopOnIdleEnd>
<RestartOnIdle>false</RestartOnIdle>
</IdleSettings>
<AllowStartOnDemand>true</AllowStartOnDemand>
<Enabled>false</Enabled>
<Hidden>false</Hidden>
<RunOnlyIfIdle>false</RunOnlyIfIdle>
<WakeToRun>false</WakeToRun>
<ExecutionTimeLimit>PT72H</ExecutionTimeLimit>
<Priority>7</Priority>
</Settings>
<Actions Context="Author">
<Exec>
<Command>C:\Windows\system32\pcalua.exe</Command>
<Arguments>-a "C:\Program Files (x86)\ZHPFix\ZHPhep.exe" -d "C:\Program Files (x86)\ZHPFix"</Arguments>
</Exec>
</Actions>
<Principals>
<Principal id="Author">
<UserId>Bruno-PC\Bruno</UserId>
<LogonType>InteractiveToken</LogonType>
<RunLevel>LeastPrivilege</RunLevel>
</Principal>
</Principals>
</Task>
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\Browsers\ucbrowser.browser Not Found !
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\Browsers\ucbrowser.browser Not Found !
C:\Users\Bruno\AppData\Roaming\AdAnti Moved Successfully
C:\Users\Bruno\AppData\Local\Zemana Not Found !
C:\ProgramData\Avira Not Found !
C:\ProgramData\RegRun Not Found !
C:\ProgramData\Spybot - Search & Destroy Not Found !
C:\ProgramData\Wondershare Not Found !
C:\ProgramData\{0897014C-63E3-47DF-8A5F-4399CC5D61B9} Not Found !
C:\Windows\System32\Tasks\Safer-Networking Not Found !
-------------- | ADS
-------------- | CleanDisk :
FreeSpace : 32785
Cleaning.......
FreeSpace : 32755
----------(EOF)----------
Je redémarre en mode sans échec sans prise en charge réseau: Adanti se reconstitue tout de même.
y'a toujours un processus coreespondant qui tourne ?
J'ai bien observé en me dépêchant au redémarrage, je vais dans le Roaming et avec le gestionnaire de tâches ouvert , je surveille mes processus lors de la réapparition de Adanti, c'est Rundll32 qui agit au niveau de la demande de ressources processeur.