je t'ai fait un premier script
Lance Farbar
Copies les lignes suivantes dans le cadre rouge
start::
CloseProcesses:
CreateRestorePoint:
StartRegedit:
Windows Registry Editor Version 5.00
[-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
@=""
[-HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains]
[-HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains]
@=""
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains]
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P]
EndRegedit:
AlternateDataStreams: C:\WINDOWS\tracing:? [16]
AlternateDataStreams: C:\Users\Public\AppData:CSM [472]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [482]
AlternateDataStreams: C:\Users\WAR-machine\Application Data:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\WAR-machine\Application Data:d988fd1ce0beed92b2bcb751f85f2bf5 [394]
AlternateDataStreams: C:\Users\WAR-machine\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\WAR-machine\AppData\Roaming:d988fd1ce0beed92b2bcb751f85f2bf5 [394]
FirewallRules: [UDP Query User{C7F1696A-42DF-470F-88E5-55DFA81C696D}F:\call of duty black ops 4\blackops4.exe] => (Allow) F:\call of duty black ops 4\blackops4.exe => Pas de fichier
FirewallRules: [TCP Query User{978C0403-5166-4D7E-9915-8CE9651C0270}F:\call of duty black ops 4\blackops4.exe] => (Allow) F:\call of duty black ops 4\blackops4.exe => Pas de fichier
FirewallRules: [UDP Query User{B3DEF8B5-CA78-46C9-91AF-F8654CA7E25B}C:\users\war-machine\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\war-machine\appdata\local\akamai\netsession_win.exe => Pas de fichier
FirewallRules: [TCP Query User{878C3514-7E83-4BE5-87ED-28DF404ADC9A}C:\users\war-machine\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\war-machine\appdata\local\akamai\netsession_win.exe => Pas de fichier
FirewallRules: [UDP Query User{26F7A2B4-9DF3-4CB2-94DB-781C8D7FEE92}D:\program files (x86)\origin games\apex\r5apex.exe] => (Allow) D:\program files (x86)\origin games\apex\r5apex.exe => Pas de fichier
FirewallRules: [{AD30FE4B-7198-40B5-A3BF-A65007A43EC9}] => (Allow) D:\Program Files (x86)\Origin Games\Battlefield 1\bf1Trial.exe => Pas de fichier
FirewallRules: [{A7AF3111-55CB-4451-80AD-0D7A5C4F8C22}] => (Allow) D:\Program Files (x86)\Origin Games\Battlefield 1\bf1Trial.exe => Pas de fichier
FirewallRules: [{A153934C-9D2D-40E9-B9FE-84463C041475}] => (Allow) D:\Program Files (x86)\Origin Games\Battlefield 1\bf1.exe => Pas de fichier
FirewallRules: [{133A4ACC-1221-4461-BCC3-8309EFA5DE7F}] => (Allow) D:\Program Files (x86)\Origin Games\Battlefield 1\bf1.exe => Pas de fichier
FirewallRules: [{F442ECC1-F72C-40D4-B054-C73A6D97C156}] => (Allow) D:\Program Files (x86)\Origin Games\Apex\EasyAntiCheat_launcher.exe => Pas de fichier
FirewallRules: [{4BB40742-424F-4CA0-8163-885EE7C9AC8A}] => (Allow) D:\Program Files (x86)\Origin Games\Apex\EasyAntiCheat_launcher.exe => Pas de fichier
HKU\S-1-5-21-1838690694-512489730-1734529554-1000\...\MountPoints2: {47ac108d-e513-11ec-85e0-309c233f80dd} - "I:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1838690694-512489730-1734529554-1000\...\MountPoints2: {47ac1379-e513-11ec-85e0-309c233f80dd} - "I:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1838690694-512489730-1734529554-1000\...\MountPoints2: {68ab06a2-6af4-11ea-8549-309c233f80dd} - "J:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1838690694-512489730-1734529554-1000\...\MountPoints2: {7635f109-65fe-11eb-8596-309c233f80dd} - "J:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1838690694-512489730-1734529554-1000\...\MountPoints2: {7635feb9-65fe-11eb-8596-309c233f80dd} - "I:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1838690694-512489730-1734529554-1000\...\MountPoints2: {c0eebbcd-610f-11eb-8596-309c233f80dd} - "J:\HiSuiteDownLoader.exe"
DeleteValue: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Web Companion
DeleteValue: HKEY_USERS\S-1-5-21-1838690694-512489730-1734529554-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Web Companion
DeleteKey: HKEY_USERS\.DEFAULT\Software\Lavasoft\Web Companion
DeleteKey: HKEY_USERS\S-1-5-18\Software\Lavasoft\Web Companion
DeleteKey: HKU\S-1-5-21-1838690694-512489730-1734529554-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
DeleteKey: HKCU\Software\Lavasoft\Web Companion
DeleteKey: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Lavasoft\Web Companion
DeleteKey: HKLM\SOFTWARE\Lavasoft\Web Companion
DeleteKey: HKLM\SOFTWARE\029c4619-0385-5543-9426-46f9987161d9
DeleteKey: HKLM\SOFTWARE\da60f423-202e-5908-a438-cd6fbbc819c8
DeleteKey: HKLM\SOFTWARE\WOW6432Node\da60f423-202e-5908-a438-cd6fbbc819c8
DeleteKey: HKCU\SOFTWARE\da60f423-202e-5908-a438-cd6fbbc819c8
DeleteKey: HKU\S-1-5-21-1838690694-512489730-1734529554-1000\SOFTWARE\da60f423-202e-5908-a438-cd6fbbc819c8
C:\Users\WAR-machine\AppData\LocalLow\Company
C:\Users\WAR-machine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender
C:\Users\WAR-machine\AppData\LocalLow\IObit\Advanced SystemCare V8
StartBatch:
del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Cache\*.*"
del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Cache\*.*"
Endbatch:
EmptyTemp:
cmd: dism.exe /online /cleanup-image /restorehealth
cmd: sfc /scannow
end::
Corrige et heberge le rapport fixlog
@+