Bonjour carine
Lance Farbar
Copies les lignes suivantes dans le cadre rouge
start::
CloseProcesses:
CreateRestorePoint:
Hosts:
HKLM\...\Run: [] => [X]
HKU\S-1-5-21-3121653835-709416453-2940897799-1001\...\Run: [dergda] => rundll32.exe "C:\Users\fabien\AppData\Local\dergda.dll",dergda <==== ATTENTION
HKU\S-1-5-21-3121653835-709416453-2940897799-1001\...\MountPoints2: {5a48f869-c85b-11e5-8279-18cf5e21c068} - "F:\Setup.exe"
HKU\S-1-5-21-3121653835-709416453-2940897799-1001\...\MountPoints2: {a9067a56-b46d-11e5-8273-18cf5e21c068} - "D:\WD SmartWare.exe" autoplay=true
HKU\S-1-5-21-3121653835-709416453-2940897799-1001\...\MountPoints2: {b4e4a290-d033-11e7-82b2-6002923ae6ac} - "D:\HiSuiteDownLoader.exe"
SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - Pas de fichier
SSODL-x32: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - Pas de fichier
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3121653835-709416453-2940897799-1001 -> DefaultScope {A14E9399-840D-4D1E-B928-4AD3D9BEC459} URL =
SearchScopes: HKU\S-1-5-21-3121653835-709416453-2940897799-1001 -> {A14E9399-840D-4D1E-B928-4AD3D9BEC459} URL =
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\96445843.js [2018-03-05] <==== ATTENTION (Pointe vers un fichier *.cfg)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\secure_cert.js [2018-03-07]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\firefox.js [2018-03-05]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\96445843.cfg [2018-03-05] <==== ATTENTION
R2 svchost64; C:\Program Files\System Native\Main Services\winreg64.exe [3795968 2018-03-05] () [Fichier non signé] <==== ATTENTION
S3 updater; C:\Program Files\System Native\Main Services\updater.exe [662528 2018-03-05] (System Native) [Fichier non signé] <==== ATTENTION
S3 McODS; "C:\ProgramData\McAfee\Update\Installs\pkg_default\Download_Files\default\vso\vso_li_cat\%VSINSTALL_DIR64%\mcods.exe" [X]
S3 Fdcsvcunsvc; pas de ImagePath
Task: {0F1D06CC-7176-4693-9B27-925A9ACE5DB8} - System32\Tasks\GoogleUpdateSecurityTaskMachine_YP => C:\ProgramData\1a4d76136ca34e4b98409f7eb4867823\HandlerExecution.exe [2018-03-05] () <==== ATTENTION
Task: {2C677CD3-77E2-4653-9E7E-A1CE8589F3C3} - System32\Tasks\updater => C:\Program Files\System Native\Main Services\updater.exe [2018-03-05] (System Native) <==== ATTENTION
Task: {30D75FD4-A059-4BDD-8DEE-3D4EBE68108C} - System32\Tasks\GoogleUpdateSecurityTaskMachine_PX => C:\ProgramData\c8b2cc8a0da547dcaef84305a34f2b12\HandlerExecution.exe [2018-03-05] () <==== ATTENTION
Task: {563F7B30-EE14-4BCE-8CA3-019A539A5AEA} - System32\Tasks\GoogleUpdateSecurityTaskMachine_IV => C:\ProgramData\723d9cb2290d42eea45d0a20ba0e6bd6\HandlerExecution.exe [2018-03-05] () <==== ATTENTION
Task: {6D1657E1-17A6-4838-9506-C4D317F899C5} - System32\Tasks\4b239e5d416839e27891e257f57f8890 => sc start 4b239e5d416839e27891e257f57f8890 <==== ATTENTION
Task: {A3FFEA74-B445-4842-9898-7824635EBAAF} - System32\Tasks\GoogleUpdateSecurityTaskMachine_SW => C:\Users\fabien\AppData\Roaming\47427c4816254474ac6c2287f884a793\HandlerExecution.exe [2018-03-05] () <==== ATTENTION
Task: {C6B54363-9616-437B-B363-2DFFC698FB7B} - System32\Tasks\GoogleUpdateSecurityTaskMachine_KA => C:\Users\fabien\AppData\Local\05d4075f13174f40b64bc2e6587bc46a\HandlerExecution.exe [2018-03-05] () <==== ATTENTION
DeleteKey: HKLM\SYSTEM\CurrentControlSet\Services\4b239e5d416839e27891e257f57f8890
C:\Program Files\4b239e5d416839e27891e257f57f8890\90561a05b598f3ba938861b744cc2c1c.exe
DeleteKey: HKLM\SYSTEM\CurrentControlSet\Services\93c3f0c1982bd396721f2234f5d6c9d6
C:\Windows\93c3f0c1982bd396721f2234f5d6c9d6.dll
DeleteValue: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|CV5IF5GBB83UIWT
C:\Program Files\H8PXOWJGLA\847KW2HL8.exe
DeleteValue: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|CMO8U2QPZABFK3P
C:\Program Files (x86)\jjmkswymv0v\1MIDF.exe
DeleteValue: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|4B4OKAG64DRYC1H
C:\Program Files\42AUQUMKLZ\42AUQUMKL.exe
DeleteValue: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|dergda
C:\Users\fabien\AppData\Local\dergda.dll
DeleteValue: HKU\S-1-5-21-3121653835-709416453-2940897799-1001\Software\Microsoft\Windows\CurrentVersion\Run|CV5IF5GBB83UIWT
DeleteValue: HKU\S-1-5-21-3121653835-709416453-2940897799-1001\Software\Microsoft\Windows\CurrentVersion\Run|CMO8U2QPZABFK3P
DeleteValue: HKU\S-1-5-21-3121653835-709416453-2940897799-1001\Software\Microsoft\Windows\CurrentVersion\Run|4B4OKAG64DRYC1H
DeleteValue: HKU\S-1-5-21-3121653835-709416453-2940897799-1001\Software\Microsoft\Windows\CurrentVersion\Run|dergda
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\bestDownloader_is1
DeleteKey: HKCU\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HardNet
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\4b239e5d416839e27891e257f57f8890
DeleteKey: HKLM\SOFTWARE\ShmAddon
DeleteKey: HKLM\SOFTWARE\SrcAAAesom Browser Enhancer
DeleteKey: HKLM\SOFTWARE\WOW6432Node\ShmAddon
DeleteKey: HKLM\SOFTWARE\WOW6432Node\SrcAAAesom Browser Enhancer
DeleteKey: HKCU\SOFTWARE\SpeeDownloader
DeleteKey: HKCU\SOFTWARE\WajIEnhance
C:\Program Files\42AUQUMKLZ
C:\Program Files\H8PXOWJGLA
C:\Program Files (x86)\bestDownloader
C:\Program Files (x86)\texttotalk
C:\ProgramData\1a4d76136ca34e4b98409f7eb4867823
C:\ProgramData\723d9cb2290d42eea45d0a20ba0e6bd6
C:\ProgramData\c57b316fc85c4eca82eecfba740cbba0
C:\ProgramData\c8b2cc8a0da547dcaef84305a34f2b12
C:\Users\fabien\AppData\Roaming\Browsers
C:\Users\fabien\AppData\Roaming\n4azehhqblk
C:\Users\fabien\AppData\Roaming\SPI
C:\Users\fabien\AppData\Roaming\zbtxug2ze2h
C:\WINDOWS\Prefetch\SPEEDOWNLOADER.TMP-C23F7B11.pf
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bestDownloader_is1
DeleteKey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HardNet
C:\Program Files\42AUQUMKLZ\uninstaller.exe
C:\Program Files\H8PXOWJGLA\uninstaller.exe
C:\Users\fabien\AppData\Roaming\n4azehhqblk\u0n52mxwcl3.exe
C:\Users\fabien\AppData\Roaming\zbtxug2ze2h\stqqai4x31g.exe
C:\WINDOWS\System32\Drivers\dfcf3709fb7500a035fcee5056e8ff12.sys
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F41F4EBB-7372-4C25-8A18-94A0AA619F3F}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F41F4EBB-7372-4C25-8A18-94A0AA619F3F}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{F41F4EBB-7372-4C25-8A18-94A0AA619F3F}
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WindowsDefender
DeleteValue: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Gsj'ZGdmE4.exe
DeleteValue: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|MldPuyOyQXLJ.exe
DeleteValue: HKU\S-1-5-21-3121653835-709416453-2940897799-1001\Software\Microsoft\Windows\CurrentVersion\Run|Gsj'ZGdmE4.exe
DeleteValue: HKU\S-1-5-21-3121653835-709416453-2940897799-1001\Software\Microsoft\Windows\CurrentVersion\Run|MldPuyOyQXLJ.exe
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{40369812-21FB-4BE0-8508-387636F329D1}_is1
C:\Program Files\Plumbytes Software
C:\Program Files (x86)\Up Pro
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Up Pro
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32
DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32
DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
C:\WINDOWS\Installer\1be07601.msp
C:\WINDOWS\Installer\227b2226.msp
C:\WINDOWS\Installer\26a5ec40.msp
C:\WINDOWS\Installer\46f2251.msp
C:\WINDOWS\Installer\5750ca4.msp
C:\WINDOWS\Installer\5c8a3db.msp
C:\WINDOWS\Installer\731921.msp
C:\WINDOWS\Installer\ea816.msp
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32
DeleteKey: HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
DeleteKey: HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32
cmd: ipconfig /flushdns
EmptyTemp:
end::
Corrige et heberge le rapport fixlog
Didier