re
Lance Farbar
http://zupimages.net/up/17/31/cqay.png
Copies les lignes suivantes dans le cadre rouge
start::
CloseProcesses:
CreateRestorePoint:
GroupPolicy: Restriction - Chrome <==== ATTENTION
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKU\S-1-5-21-1832879478-2515121904-386043235-1001 -> Pas de nom - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - Pas de fichier
FF NewTab: Mozilla\Firefox\Profiles\kvy3yy74.default -> about:newtab
CHR NewTab: Default -> Not-active:"chrome-extension://jepibmfmhopgkplegmkjgifmhabbjadg/newtab/newtab.html"
CHR DefaultSearchURL: Default -> hxxp://srch.bar/{searchTerms}
CHR DefaultSuggestURL: Default -> hxxp://srch.bar/?s={searchTerms}
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Pas de fichier
Task: {9430BE76-2CBA-4F08-8E6D-E47B59AFDE57} - System32\Tasks\{60767AAF-A62E-08C8-ABAB-428F9D35EF23} => C:\Users\JACQUES\AppData\Local\60767A~1\SYNHEL~1.EXE <==== ATTENTION
Task: C:\WINDOWS\Tasks\{60767AAF-A62E-08C8-ABAB-428F9D35EF23}.job => C:\Users\JACQUES\AppData\Local\60767A~1\SYNHEL~1.EXE <==== ATTENTION
Shortcut: C:\Users\JACQUES\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\G?ogle ?hrom?.lnk -> C:\Users\JACQUES\AppData\Roaming\Browsers\exe.emorhc.bat (Pas de fichier) <==== Cyrillic
Shortcut: C:\Users\JACQUES\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\G??gle ?hr?m?.lnk -> C:\Users\JACQUES\AppData\Roaming\Browsers\exe.emorhc.bat (Pas de fichier) <==== Cyrillic
Shortcut: C:\Users\JACQUES\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Int?rn?t Ex?lor?r.lnk -> C:\Users\JACQUES\AppData\Roaming\Browsers\exe.erolpxei.bat (Pas de fichier) <==== Cyrillic
Shortcut: C:\Users\JACQUES\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\?ozill? Firef??.lnk -> C:\Users\JACQUES\AppData\Roaming\Browsers\exe.xoferif.bat (Pas de fichier) <==== Cyrillic
DeleteKey: HKCU\SOFTWARE\webservice
C:\WINDOWS\Prefetch\ONESYSTEMCARE.TMP-8C9039E2.pf
C:\WINDOWS\Prefetch\ONESYSTEMCARE.TMP-A60FB1C2.pf
C:\WINDOWS\Prefetch\ONESYSTEMCARE.TMP-BC7000B7.pf
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3D31354B-DA2A-4988-AD21-03F193117BC0}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{3D31354B-DA2A-4988-AD21-03F193117BC0}
C:\Windows\System32\Tasks\NCH Software\RecordpadSevenDays
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7A78ACAB-DC79-4DA0-A776-6A0F624EF8FB}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{7A78ACAB-DC79-4DA0-A776-6A0F624EF8FB}
C:\Windows\System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9430BE76-2CBA-4F08-8E6D-E47B59AFDE57}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{9430BE76-2CBA-4F08-8E6D-E47B59AFDE57}
C:\Windows\System32\Tasks\{60767AAF-A62E-08C8-ABAB-428F9D35EF23}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5FB9C6C-7FA2-46F2-81C5-3BF8A7045C0A}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{B5FB9C6C-7FA2-46F2-81C5-3BF8A7045C0A}
C:\Windows\System32\Tasks\NkDiPyfqWSj8
C:\WINDOWS\Prefetch\HDWALLPAPER.TMP-9F49D818.pf
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ByteFenceService_RASMANCS
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS
DeleteKey: HKLM\Software\Microsoft\Tracing\ByteFenceService_RASAPI32
DeleteKey: HKLM\Software\Microsoft\Tracing\ByteFenceService_RASMANCS
DeleteKey: HKLM\Software\Microsoft\Tracing\ByteFence_RASAPI32
DeleteKey: HKLM\Software\Microsoft\Tracing\ByteFence_RASMANCS
EmptyTemp:
end::
Corrige et heberge le rapport fixlog
@+
L'urgent est fait, l'impossible est en cours, pour les miracles, prévoir des délais
Charte du Forum