re
Lance Farbar
http://zupimages.net/up/17/31/cqay.png
Copies les lignes suivantes dans le cadre rouge
start::
CloseProcesses:
CreateRestorePoint:
HKLM-x32\...\Run: [NPSStartup] => [X]
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2297602849-3840827406-3618746197-1000\...\CurrentVersion\Windows: [Run] <==== ATTENTION
HKU\S-1-5-21-2297602849-3840827406-3618746197-1000\...\MountPoints2: J - J:\setup.exe
HKU\S-1-5-21-2297602849-3840827406-3618746197-1000\...\MountPoints2: {803d6211-be31-11e6-8e94-bc5ff4e5de1b} - H:\setup.exe
HKU\S-1-5-21-2297602849-3840827406-3618746197-1000\...\MountPoints2: {c145e8a4-6c81-11e3-9bd3-806e6f6e6963} - E:\setup.exe
HKU\S-1-5-21-2297602849-3840827406-3618746197-1000\...\MountPoints2: {cfb8a4d3-6ca9-11e3-90f5-bc5ff4e5de1b} - J:\setup.exe
AppInit_DLLs: C:\Program Files C:\Program Files C:\Program Files C:\Program Files => Pas de fichier
GroupPolicy: Restriction - Chrome <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
ProxyEnable: [.DEFAULT] => Proxy est activé.
ProxyServer: [.DEFAULT] => http=127.0.0.1:52752;https=127.0.0.1:52752
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\2067972773.js [2016-11-09] <==== ATTENTION (Pointe vers un fichier *.cfg)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\2067972773.cfg [2016-11-09] <==== ATTENTION
U4 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [X]
S3 AsrSetupDrv; \??\C:\Windows\SysWOW64\Drivers\AsrSetupDrv.sys [X]
S3 AxtuDrv; \??\C:\Windows\SysWOW64\Drivers\AxtuDrv.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
Task: {54E2DDE3-81AC-45F6-BEA8-37A9595936C1} - System32\Tasks\3c91fcc2-ce59-42b3-b901-f68079520898 => C:\Users\jpc\AppData\Local\Temp\ce98ac2e-20c0-4a93-86f6-bdb3e61caf55.exe <==== ATTENTION
DeleteKey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sweet Home 3D Packages
DeleteKey: HKLM\SOFTWARE\findopolis
DeleteKey: HKLM\SOFTWARE\findopolis
DeleteKey: HKCU\SOFTWARE\findopolis
DeleteKey: HKCU\SOFTWARE\I - Cinema-nv-ie
DeleteKey: HKLM\Software\Classes\Installer\Products\93BAD29AC2E44034A96BCB446EB8552E
DeleteKey: HKLM\Software\Classes\Installer\Futures\93BAD29AC2E44034A96BCB446EB8552E
DeleteKey: HKCU\Software\Microsoft\Installer\Products\93BAD29AC2E44034A96BCB446EB8552E
DeleteKey: HKCU\Software\Microsoft\Installer\Futures\93BAD29AC2E44034A96BCB446EB8552E
C:\Windows\Installer\38dc69da.msi
DeleteKey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sweet Home 3D Packages
DeleteKey: HKLM\Software\Classes\Installer\Products\93BAD29AC2E44034A96BCB446EB8552E
DeleteKey: HKLM\Software\Classes\Installer\Features\93BAD29AC2E44034A96BCB446EB8552E
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1BD9588E-32B3-4D5B-99F6-E7D3C0E16F3D}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{1BD9588E-32B3-4D5B-99F6-E7D3C0E16F3D}
C:\Windows\System32\Tasks\{F676A340-E8EA-4E31-9D6A-AB8B0D59CF81}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{54E2DDE3-81AC-45F6-BEA8-37A9595936C1}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{54E2DDE3-81AC-45F6-BEA8-37A9595936C1}
C:\Windows\System32\Tasks\3c91fcc2-ce59-42b3-b901-f68079520898
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7482C126-5C3D-4583-9CF1-49DD23F328BE}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{7482C126-5C3D-4583-9CF1-49DD23F328BE}
C:\Windows\System32\Tasks\{BE235EED-703B-4EED-8111-02A5B7DF5487}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8573CFE2-09D1-4C1D-A28B-11D1A195D018}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{8573CFE2-09D1-4C1D-A28B-11D1A195D018}
C:\Windows\System32\Tasks\AVAST Software\Avast settings backup
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8BBD130F-6B15-481F-8799-1C5D43A6B7B4}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{8BBD130F-6B15-481F-8799-1C5D43A6B7B4}
C:\Windows\System32\Tasks\{A3F47B7C-09D3-4CA3-8FB0-19163732CA04}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AA05CB27-4DB4-4EF2-BD6B-850D30F12ABB}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{AA05CB27-4DB4-4EF2-BD6B-850D30F12ABB}
C:\Windows\System32\Tasks\{FB27ACF8-0D8A-4E21-8D54-16A70633DA7F}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D3D84AB2-885B-4878-B8F6-39B01E0A77A3}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{D3D84AB2-885B-4878-B8F6-39B01E0A77A3}
C:\Windows\System32\Tasks\{B935D7F5-B03D-4DEF-B495-C195D09B31B0}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D63762B0-E823-484C-9B00-036A06ABE395}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{D63762B0-E823-484C-9B00-036A06ABE395}
C:\Windows\System32\Tasks\{5DFCC778-E56D-464B-A879-74259235657D}
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run:NPSStartup
C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ultimate Naruto.lnk
C:\Users\jpc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ultimate Naruto.lnk
C:\Users\Public\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ultimate Naruto.lnk
DeleteKey: HKCU\SOFTWARE\Reimage
DeleteKey: HKCU\SOFTWARE\undefined
C:\Users\jpc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GoodGameEmpire
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\EPPShellEx
DeleteKey: HKLM\Software\Classes\CLSID\{509FE1AF-ADD5-49EC-BC55-7CF81FD16E78} <== Reinstall Software EPPShellEx
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32
DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} <== Reinstall Software WinRAR32
DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32
DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} <== Reinstall Software WinRAR32
DeleteKey: HKLM\SOFTWARE\Clients\StartMenuInternet\Beamrise.4U2VEQBYVE2QTUQOX7QQV2BYMM
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\Reimage_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\Reimage_RASMANCS
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ReimagePackage_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ReimagePackage_RASMANCS
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ReimageRepair(1)_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ReimageRepair(1)_RASMANCS
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ReimageRepair_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ReimageRepair_RASMANCS
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\EPPShellEx
DeleteKey: HKLM\Software\Classes\CLSID\{509FE1AF-ADD5-49EC-BC55-7CF81FD16E78}
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32
DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32
DeleteKey: HKLM\Software\Microsoft\Tracing\ByteFence_RASAPI32
DeleteKey: HKLM\Software\Microsoft\Tracing\ByteFence_RASMANCS
DeleteKey: HKLM\Software\Microsoft\Tracing\Reimage_RASAPI32
DeleteKey: HKLM\Software\Microsoft\Tracing\Reimage_RASMANCS
C:\Users\jpc\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_fr.softonic.com_0.localstorage
C:\Users\jpc\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_fr.softonic.com_0.localstorage-journal
RemoveProxy:
EmptyTemp:
end::
Corrige et heberge le rapport fixlog
@+