salut J.Underwood
ceci stp
Lance Farbar
Copies les lignes suivantes dans le cadre rouge
start::
CloseProcesses:
CreateRestorePoint:
C:\Program Files (x86)\Mail.Ru\MailRuUpdater\MailRuUpdater.exe
C:\Users\Admin\AppData\Local\Mail.Ru\MailRuUpdater.exe
HKU\S-1-5-21-532762885-270133051-936439358-1002\...\Run: [MailRuUpdater] => C:\Users\Admin\AppData\Local\Mail.Ru\MailRuUpdater.exe [3585208 2018-07-25] (Mail.Ru) <==== ATTENTION
R2 Updater.Mail.Ru; C:\Program Files (x86)\Mail.Ru\MailRuUpdater\MailRuUpdater.exe [3585208 2018-07-25] (Mail.Ru) <==== ATTENTION
2018-07-25 21:55 - 2018-07-25 21:55 - 000003174 _____ C:\WINDOWS\System32\Tasks\MailRuUpdater
C:\Users\Admin\AppData\Local\Mail.Ru\MailRuUpdater.exe
GroupPolicy: Restriction - Windows Defender <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
BHO-x32: YoutubeAdBlock -> {9F55829B-D24C-4F62-A4A5-729E53BCEA85} -> C:\Program Files (x86)\hOIxokWFAIE\ks0WLIY.dll => Pas de fichier
R2 mrupdsrv; C:\Program Files (x86)\Mail.Ru\Update Service\mrupdsrv.exe [1314008 2018-07-25] (Mail.Ru) <==== ATTENTION
R2 mweshield; C:\Program Files\My Web Shield\mweshield.exe [931640 2016-08-31] ("My Web Shield") <==== ATTENTION
R2 mweshieldup; C:\Program Files\My Web Shield\mweshieldup.exe [348472 2016-08-31] ("My Web Shield") <==== ATTENTION
R2 Updater.Mail.Ru; C:\Program Files (x86)\Mail.Ru\MailRuUpdater\MailRuUpdater.exe [3585208 2018-07-25] (Mail.Ru) <==== ATTENTION
R1 mwescontroller; C:\WINDOWS\system32\drivers\mwescontroller.sys [57680 2016-08-31] () <==== ATTENTION
YoutubeAdBlock (HKLM-x32\...\1655C0CA-7AE7-4012-8502-970C8675E5F8) (Version: 2.0.0.590 - Company Inc.) <==== ATTENTION
?????? ??????????????? ?????????? ???????? (HKU\S-1-5-21-532762885-270133051-936439358-1002\...\MailRuUpdater) (Version: - Mail.Ru) <==== ATTENTION
ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => -> Pas de fichier
ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => -> Pas de fichier
ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => -> Pas de fichier
ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => -> Pas de fichier
ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => -> Pas de fichier
ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => -> Pas de fichier
ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => -> Pas de fichier
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Pas de fichier
Task: {E38C629E-9656-4E85-B758-0BB915A54999} - System32\Tasks\MailRuUpdater => C:\Users\Admin\AppData\Local\Mail.Ru\MailRuUpdater.exe [2018-07-25] (Mail.Ru) <==== ATTENTION
2018-07-25 21:56 - 2018-07-25 21:56 - 000000000 ____D C:\Program Files (x86)\rBGfZIfFCYUn
C:\Program Files (x86)\rBGfZIfFCYUn
2018-07-25 21:56 - 2018-07-25 21:56 - 000000000 ____D C:\ProgramData\XvGEGDYvPvqgwcVB
C:\ProgramData\XvGEGDYvPvqgwcVB
DeleteKey: HKLM\SYSTEM\CurrentControlSet\Services\mweshield
C:\Program Files\My Web Shield\mweshield.exe
DeleteKey: HKLM\SYSTEM\CurrentControlSet\Services\mweshieldup
C:\Program Files\My Web Shield\mweshieldup.exe
C:\Program Files (x86)\Mozilla Firefox\browser\features\{A5FD4672-4D73-4F90-A1C0-2ABD39DB2565}.xpi
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9F55829B-D24C-4F62-A4A5-729E53BCEA85}
DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9F55829B-D24C-4F62-A4A5-729E53BCEA85}
DeleteKey: HKLM\Software\Classes\CLSID\{9F55829B-D24C-4F62-A4A5-729E53BCEA85}
C:\Program Files (x86)\hOIxokWFAIE\tBxAStke.dll
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\mweshield
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\1655C0CA-7AE7-4012-8502-970C8675E5F8
DeleteKey: HKLM\SOFTWARE\ShmAddon
DeleteKey: HKLM\SOFTWARE\WOW6432Node\ShmAddon
C:\Program Files\My Web Shield
unlock: C:\WINDOWS\System32\drivers\mwescontroller.sys
C:\WINDOWS\System32\drivers\mwescontroller.sys
C:\Users\Admin\AppData\Local\Temp\8F61CF0E-948B-4933-9F17-785501FEB7E4\8F61CF0E-948B-4933-9F17-785501FEB7E4.exe
DeleteKey: HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9F55829B-D24C-4F62-A4A5-729E53BCEA85}
DeleteKey: HKLM\Software\WOW6432Node\Classes\CLSID\{9F55829B-D24C-4F62-A4A5-729E53BCEA85}
DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9F55829B-D24C-4F62-A4A5-729E53BCEA85}
DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9F55829B-D24C-4F62-A4A5-729E53BCEA85}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1655C0CA-7AE7-4012-8502-970C8675E5F8
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{40369812-21FB-4BE0-8508-387636F329D1}_is1
C:\Program Files (x86)\Up Pro
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Up Pro
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\MEGA (Context menu)
DeleteKey: HKLM\Software\Classes\CLSID\{0229E5E7-09E9-45CF-9228-0228EC7D5F17}
DeleteKey: HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\MEGA (Context menu)
DeleteKey: HKLM\Software\Classes\CLSID\{0229E5E7-09E9-45CF-9228-0228EC7D5F17}
DeleteKey: HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\MEGA (Context menu)
DeleteKey: HKLM\Software\Classes\CLSID\{0229E5E7-09E9-45CF-9228-0228EC7D5F17}
DeleteKey: HKLM\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\MEGA (Context menu)
DeleteKey: HKLM\Software\Classes\CLSID\{0229E5E7-09E9-45CF-9228-0228EC7D5F17}
DeleteKey: HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\MEGA (Context menu)
DeleteKey: HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\MEGA (Context menu)
DeleteKey: HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\MEGA (Context menu)
DeleteKey: HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\MEGA (Context menu)
EmptyTemp:
end::
Corrige et heberge le rapport fixlog
@+
didier