salut Nines8
Lance Farbar
http://zupimages.net/up/17/31/cqay.png
Copies les lignes suivantes dans le cadre rouge
start::
CloseProcesses:
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1610259852-3925544043-3015711192-1000\...\MountPoints2: I - I:\TX_Music_USB_DN.exe
HKU\S-1-5-21-1610259852-3925544043-3015711192-1000\...\MountPoints2: {55de93f1-d662-11e6-a79f-e0ca946a2b4f} - F:\AutoRun.exe
HKU\S-1-5-21-1610259852-3925544043-3015711192-1000\...\MountPoints2: {55de9401-d662-11e6-a79f-e0ca946a2b4f} - F:\AutoRun.exe
HKU\S-1-5-21-1610259852-3925544043-3015711192-1000\...\MountPoints2: {bf4cd141-5ffa-11e6-8abc-e0ca946a2b4f} - F:\AutoRun.exe
HKU\S-1-5-21-1610259852-3925544043-3015711192-1000\...\MountPoints2: {bf4cd246-5ffa-11e6-8abc-e0ca946a2b4f} - F:\AutoRun.exe
SearchScopes: HKLM -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKLM-x32 -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
BHO: Pas de nom -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> Pas de fichier
BHO: Pas de nom -> {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} -> Pas de fichier
BHO-x32: Pas de nom -> {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} -> Pas de fichier
Toolbar: HKLM - Pas de nom - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Pas de fichier
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - Pas de fichier
Toolbar: HKU\S-1-5-21-1610259852-3925544043-3015711192-1000 -> Pas de nom - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Pas de fichier
Toolbar: HKU\S-1-5-21-1610259852-3925544043-3015711192-1000 -> Pas de nom - {51A86BB3-6602-4C85-92A5-130EE4864F13} - Pas de fichier
CHR HomePage: Default -> amazon.com/websearch/?ie=UTF8__PARAM__
CHR DefaultSearchKeyword: Default -> Random Walk Shapes
CHR DefaultSuggestURL: Default -> hxxps://randomwalktab.com/suggestions.php?q={searchTerms}
CHR HKLM-x32\...\Chrome\Extension: [fdjcngoneogjbkdakodemfopgkkncoll] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <non trouvé(e)>
CHR HKLM-x32\...\Chrome\Extension: [hgojaaaiddhmiiakpejiklijbalpckih] - C:\Users\Toshiba\AppData\Roaming\StatusWinks\statuswinks.crx <non trouvé(e)>
S3 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]
S2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe [X]
S3 MBAMProtection; system32\DRIVERS\mbam.sys [X]
S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
CustomCLSID: HKU\S-1-5-21-1610259852-3925544043-3015711192-1000_Classes\CLSID\{0D327DA6-B4DF-4842-B833-2CFF84F0948F}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2017\acad.exe /Automation => Pas de fichier
CustomCLSID: HKU\S-1-5-21-1610259852-3925544043-3015711192-1000_Classes\CLSID\{720DB9AF-D62C-4ED0-A377-429C22312852}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2017\acad.exe => Pas de fichier
StartRegEdit:
Windows Registry Editor Version 5.00
[HKCU\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="about:Blank"
EndRegEdit:
DeleteKey: HKLM\SOFTWARE\Babylon
DeleteKey: HKLM\SOFTWARE\iLividSRTB
DeleteKey: HKLM\SOFTWARE\SimplyGen
DeleteKey: HKLM\SOFTWARE\SProtector
DeleteKey: HKLM\SOFTWARE\Babylon
DeleteKey: HKLM\SOFTWARE\iLividSRTB
DeleteKey: HKLM\SOFTWARE\SimplyGen
DeleteKey: HKLM\SOFTWARE\SProtector
DeleteKey: HKCU\SOFTWARE\BabSolution
DeleteKey: HKCU\SOFTWARE\BrowserCompanion
DeleteKey: HKCU\SOFTWARE\Complitly
DeleteKey: HKCU\SOFTWARE\iLivid
DeleteKey: HKCU\SOFTWARE\ProtectedSearch
DeleteKey: HKCU\SOFTWARE\RegisteredApplicationsEx
DeleteKey: HKCU\SOFTWARE\UpToDown
DeleteKey: HKCU\SOFTWARE\AppDataLow\Software\Smartbar
C:\Program Files (x86)\File Scout
C:\Program Files (x86)\Red Sky
C:\Program Files (x86)\Ss.Helper
C:\Program Files (x86)\sureF and keep
C:\Program Files (x86)\WebSearch
C:\ProgramData\Babylon
C:\ProgramData\Browser Manager
C:\ProgramData\DowNload keepeR
C:\ProgramData\DoWnlooad keepeurr
C:\ProgramData\InstallMate
C:\ProgramData\QuickSet
C:\ProgramData\Seuruf Anda aKeep
C:\ProgramData\sureF and keep
C:\ProgramData\surf and keep
C:\ProgramData\Wincert
C:\ProgramData\YoutubeAdblocker
C:\Users\Toshiba\AppData\Roaming\Babylon
C:\Users\Toshiba\AppData\Roaming\ExpressFiles
C:\Users\Toshiba\AppData\Roaming\Hola
C:\Users\Toshiba\AppData\Local\iLivid
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\updatequalitink_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\updatequalitink_RASMANCS
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\BetterInstaller_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\BetterInstaller_RASMANCS
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\DownTangoFTToolbar_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\DownTangoFTToolbar_RASMANCS
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\FreecorderToolbarHelper_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\FreecorderToolbarHelper_RASMANCS
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASMANCS
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASMANCS
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\IminentSetup{2_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\IminentSetup{2_RASMANCS
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
DeleteKey: HKLM\Software\Microsoft\Tracing\updatequalitink_RASAPI32
DeleteKey: HKLM\Software\Microsoft\Tracing\updatequalitink_RASMANCS
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A3088BC-ADFA-4A75-9A68-90C33562F9AD}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{2A3088BC-ADFA-4A75-9A68-90C33562F9AD}
C:\Windows\System32\Tasks\{A4F4D991-9097-4626-911D-EC578DC7E253}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{34ECC83B-2667-4D12-BF70-C6A2149B72C1}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{34ECC83B-2667-4D12-BF70-C6A2149B72C1}
C:\Windows\System32\Tasks\AVAST Software\Avast settings backup
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3FEBACA4-854D-4B92-802B-031B6CCB36A8}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{3FEBACA4-854D-4B92-802B-031B6CCB36A8}
C:\Windows\System32\Tasks\{C62D3FF9-AE7A-4D01-B507-15B4509D4C77}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{859EF9BD-8506-4AA9-802E-4D6E217C76BF}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{859EF9BD-8506-4AA9-802E-4D6E217C76BF}
C:\Windows\System32\Tasks\{B353CCC7-5DC4-4DEB-B063-BF689013840E}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8FF8EF20-BBDB-4061-A94A-877EE493EDD7}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{8FF8EF20-BBDB-4061-A94A-877EE493EDD7}
C:\Windows\System32\Tasks\{0B0FFA6E-64FA-46CF-8ED7-5DF4D0ECFD22}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A54CCA4A-92D8-4C13-B66D-D8DB2B19EB33}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{A54CCA4A-92D8-4C13-B66D-D8DB2B19EB33}
C:\Windows\System32\Tasks\{119B28F5-5A78-4B3E-9AA0-A3DD4B408137}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B703228B-98B7-4A79-BFA3-A18CAC3AC8B4}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{B703228B-98B7-4A79-BFA3-A18CAC3AC8B4}
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\mcupdate
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BF149347-9D53-44B5-8104-444F84CC833B}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{BF149347-9D53-44B5-8104-444F84CC833B}
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E0F44A48-A4D8-4177-A36F-AC13BEFA5E53}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{E0F44A48-A4D8-4177-A36F-AC13BEFA5E53}
C:\Windows\System32\Tasks\{734B2326-5023-4333-865E-B282D5ECE147}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EC665FB6-8FE7-452E-A87F-6A4A4CBCBB29}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{EC665FB6-8FE7-452E-A87F-6A4A4CBCBB29}
C:\Windows\System32\Tasks\QtraxPlayer
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ED26088F-BD60-4433-A644-C6F18B86695E}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{ED26088F-BD60-4433-A644-C6F18B86695E}
C:\Windows\System32\Tasks\{DF14A488-40C4-4712-BD93-B621A6A482F0}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EFDAEFE9-CDB1-472A-834F-13E33F89FADF}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{EFDAEFE9-CDB1-472A-834F-13E33F89FADF}
C:\Windows\System32\Tasks\{3B268E47-27D7-49D5-B866-103591C32186}
DeleteValue: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SE
DeleteValue: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Akamai NetSession Interface
DeleteValue: HKU\S-1-5-21-1610259852-3925544043-3015711192-1000\Software\Microsoft\Windows\CurrentVersion\Run|SE
DeleteValue: HKU\S-1-5-21-1610259852-3925544043-3015711192-1000\Software\Microsoft\Windows\CurrentVersion\Run|Akamai NetSession Interface
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}
DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}
DeleteKey: HKLM\Software\Classes\CLSID\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
DeleteKey: HKLM\Software\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
DeleteKey: HKLM\SOFTWARE\Conduit
DeleteKey: HKLM\SOFTWARE\Conduit
DeleteKey: HKCU\SOFTWARE\APN PIP
DeleteKey: HKCU\SOFTWARE\Conduit
DeleteKey: HKCU\SOFTWARE\Softonic
DeleteKey: HKCU\SOFTWARE\TeleCharger
DeleteKey: HKCU\SOFTWARE\undefined
DeleteKey: HKCU\SOFTWARE\AppDataLow\Software\Simplytech
C:\Program Files (x86)\Conduit
C:\Users\Toshiba\AppData\Roaming\PerformerSoft
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\Autodesk.DWF.ContextMenu
DeleteKey: HKLM\Software\Classes\CLSID\{6C18531F-CA85-45F7-8278-FF33CF0A5964} <== Reinstall Software Autodesk.DWF.ContextMenu
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32
DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} <== Reinstall Software WinRAR32
DeleteKey: HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\WinRAR32
DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} <== Reinstall Software WinRAR32
DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32
DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} <== Reinstall Software WinRAR32
DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{749D71CD-CCF5-4082-B16B-5B3D7A47BF01}C:\users\toshiba\appdata\local\akamai\netsession_win.exe
DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{8D9AB93C-C64E-4799-93CD-DE10548E1BF5}C:\users\toshiba\appdata\local\akamai\netsession_win.exe
DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{1DA84D41-2AF8-4A8B-AB62-C8D7CF6B63F4}C:\users\toshiba\appdata\local\akamai\netsession_win.exe
DeleteValue: HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{794D2A73-1938-407B-88B8-12522EE7C52D}C:\users\toshiba\appdata\local\akamai\netsession_win.exe
C:\Windows\Installer\11d42143.msi
C:\Windows\Installer\1f68d424.msi
C:\Windows\Installer\20781638.msi
C:\Windows\Installer\2e06278.msi
C:\Windows\Installer\5529835.msi
C:\Windows\Installer\641d3d2.msi
C:\Windows\Installer\721a55.msi
C:\Windows\Installer\95e9fe7.msi
C:\Windows\Installer\c703ba9.msi
C:\Windows\Installer\c845023.msi
C:\Windows\Installer\df6735.msi
C:\Windows\Installer\e6a8c1.msi
C:\Windows\Installer\ef937e0.msi
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
DeleteKey: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}
DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}
DeleteKey: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\Autodesk.DWF.ContextMenu
DeleteKey: HKLM\Software\Classes\CLSID\{6C18531F-CA85-45F7-8278-FF33CF0A5964}
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32
DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
DeleteKey: HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\WinRAR32
DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32
C:\Windows\Installer\MSI10F6.tmp
C:\Windows\Installer\MSI1349.tmp
C:\Windows\Installer\MSI1597.tmp
C:\Windows\Installer\MSI1A18.tmp
C:\Windows\Installer\MSI1FEE.tmp
C:\Windows\Installer\MSI284A.tmp
C:\Windows\Installer\MSI5D65.tmp
C:\Windows\Installer\MSI86A3.tmp
C:\Windows\Installer\MSI9360.tmp
C:\Windows\Installer\MSIA6A7.tmp
C:\Windows\Installer\MSIC19E.tmp
EmptyTemp:
end::
Corrige et heberge le rapport fixlog
Didier