Romain
Lance Farbar
Copies les lignes suivantes dans le cadre rouge
start::
CloseProcesses:
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
CHR DefaultSearchURL: Default -> hxxps://spiralstab.com/search?q={searchTerms}
CHR DefaultSearchKeyword: Default -> SpiralsTab
CHR DefaultSuggestURL: Default -> hxxps://spiralstab.com/suggestions.php?q={searchTerms}
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ikaooahnheaoeceaipjcmnamnoleeblk] - hxxps://clients2.google.com/service/update2/crx
S2 pbamw_service; "C:\Program Files\Plumbytes Software\Plumbytes Anti-Malware\AmwService.exe" run [X]
DeleteKey: HKLM\SYSTEM\CurrentControlSet\Services\pbamw_service
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0837D897-84CB-4E30-A8DD-807937A81DFC}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{0837D897-84CB-4E30-A8DD-807937A81DFC}
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\mcupdate
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD548504-31EE-43FF-A573-1E9BCB56DC76}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{DD548504-31EE-43FF-A573-1E9BCB56DC76}
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart
DeleteKey: HKCU\SOFTWARE\PartyFrance
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\Plumbytes_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\Plumbytes_RASMANCS
DeleteKey: HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\BackupContextMenuExtension
DeleteKey: HKLM\Software\Classes\CLSID\{b1b96b20-da1d-4a3c-92c1-7229b32f2325}
DeleteKey: HKLM\Software\Microsoft\Tracing\Plumbytes_RASAPI32
DeleteKey: HKLM\Software\Microsoft\Tracing\Plumbytes_RASMANCS
cmd: dism.exe /online /cleanup-image /restorehealth
cmd: sfc /scannow
EmptyTemp:
end::
Corrige et heberge le rapport fixlog
@+
L'urgent est fait, l'impossible est en cours, pour les miracles, prévoir des délais
Charte du Forum