olivier
ton windows est légal??
O43 - CFD: 02/12/2017 - [] D -- C:\ProgramData\KMSAutoS
O43 - CFD: 01/12/2017 - [] D -- C:\Users\Olivier\AppData\Local\MSfree Inc
Lance Farbar
Copies les lignes suivantes dans le cadre rouge
start::
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-21-1398835985-718067912-1910963243-1001\...\Run: [Chromium] => "c:\users\olivier\appdata\local\chromium\application\chrome.exe" --profile-directory="Default" --auto-launch-at-startup --restore-last-session
HKU\S-1-5-21-1398835985-718067912-1910963243-1001\...\MountPoints2: {e22e99e9-0af9-11ea-9ccb-701ce72c7cfc} - "D:\HiSuiteDownLoader.exe"
Task: {1CBFAC92-4838-4300-9DB9-D507AFD1E4AB} - System32\Tasks\ChromiumUpdateTaskMachineCore => C:\Program Files (x86)\Chromium\Update\ChromiumUpdate.exe [100352 2020-02-26] (Chromium.) [Fichier non signé]
Task: {E395B303-2D0F-4AFA-81FE-75309EBF588B} - System32\Tasks\ChromiumUpdateTaskMachineUA => C:\Program Files (x86)\Chromium\Update\ChromiumUpdate.exe [100352 2020-02-26] (Chromium.) [Fichier non signé]
FF Plugin-x32: @chbrowserupdate.com/Chromium Update;version=3 -> C:\Program Files (x86)\Chromium\Update\1.3.99.0\npChromiumUpdate3.dll [2020-02-26] (Chromium.) [Fichier non signé]
FF Plugin-x32: @chbrowserupdate.com/Chromium Update;version=9 -> C:\Program Files (x86)\Chromium\Update\1.3.99.0\npChromiumUpdate3.dll [2020-02-26] (Chromium.) [Fichier non signé]
2020-03-25 18:01 - 2020-03-25 18:08 - 000000000 ____D C:\Users\Olivier\AppData\Local\chromium
C:\Users\Olivier\AppData\Local\chromium
2020-02-26 00:53 - 2020-02-26 00:53 - 001740288 ____T (Chromium.) [Fichier non signé] C:\Program Files (x86)\Chromium\Update\1.3.99.0\chromiumpdate.dll
AlternateDataStreams: C:\Users\Olivier\Application Data:6699d3ee8dd9cf775caae782c8f44f03 [394]
AlternateDataStreams: C:\Users\Olivier\AppData\Roaming:6699d3ee8dd9cf775caae782c8f44f03 [394]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [482]
C:\Users\defaultuser0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HowToRemove.lnk
C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HowToRemove.lnk
C:\Users\Public\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HowToRemove.lnk
DeleteKey: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EverestPoker.com
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13B4FB74-4334-2AF4-F2B4-5A74223489F4}
DeleteKey: HKU\S-1-5-21-1398835985-718067912-1910963243-1001\Software\csastats
DeleteKey: HKCU\Software\csastats
C:\ProgramData\KMSAutoS
C:\Users\Olivier\AppData\Local\MSfree Inc
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\uninst.exe
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\winwb_RASAPI32
DeleteKey: HKLM\SOFTWARE\Microsoft\Tracing\winwb_RASMANCS
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\HowToRemove
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\malanidat
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\misaricot
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\uninstp.dat
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\HowToRemove\chromium-min.jpg
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\HowToRemove\control panel-min-min.JPG
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\HowToRemove\down.png
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\HowToRemove\ff menu.JPG
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\HowToRemove\ff search engine-min.png
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\HowToRemove\HowToRemove.html
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\HowToRemove\hp-min ff.png
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\HowToRemove\hp-min ie.png
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\HowToRemove\search engine.gif
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\HowToRemove\setup pages.gif
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\HowToRemove\sp-min.png
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\HowToRemove\start-min.jpg
C:\Users\Olivier\AppData\Local\{8A10BC4C-AEB8-D0F4-C320-F51CE7480984}\HowToRemove\up.png
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}\deremi
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}\HowToRemove
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}\uninst.exe
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}\HowToRemove\chromium-min.jpg
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}\HowToRemove\control panel-min-min.JPG
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}\HowToRemove\down.png
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}\HowToRemove\ff menu.JPG
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}\HowToRemove\ff search engine-min.png
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}\HowToRemove\HowToRemove.html
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}\HowToRemove\hp-min ff.png
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}\HowToRemove\hp-min ie.png
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}\HowToRemove\search engine.gif
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}\HowToRemove\setup pages.gif
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}\HowToRemove\sp-min.png
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}\HowToRemove\start-min.jpg
C:\Users\Olivier\AppData\Local\{A721917D-8389-FDC5-EE11-D82DCA7924B5}\HowToRemove\up.png
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13B4FB74-4334-2AF4-F2B4-5A74223489F4}
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{13B4FB74-4334-2AF4-F2B4-5A74223489F4}
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\winwb_RASAPI32
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\winwb_RASMANCS
C:\Users\Olivier\AppData\Local\Google\Update
EmptyTemp:
end::
Corrige et heberge le rapport fixlog
@+