Ce script va cibler certains éléments à supprimer :
• Lance OTL.
• Copie/colle dans la zone "
Personnalisation" de OTL le script en qui est indiqué ci-dessous :
:OTL
PRC - [2013/09/12 23:29:11 | 000,342,592 | ---- | M] (Woodtale Technology Inc) -- C:\Users\Cyrille\AppData\Local\DProtect\DProtectSvc.exe
PRC - [2013/02/05 17:48:44 | 000,272,248 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
PRC - [2012/02/10 11:28:06 | 000,240,408 | ---- | M] (Microsoft Corporation.) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.EXE
MOD - [2013/09/12 23:29:11 | 000,506,944 | ---- | M] () -- C:\Users\Cyrille\AppData\Local\DProtect\eBP.dll
MOD - [2013/09/12 23:29:11 | 000,062,016 | ---- | M] () -- C:\Users\Cyrille\AppData\Local\DProtect\eBPSD.dll
MOD - [2013/02/05 17:48:44 | 000,272,248 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
SRV - [2013/09/12 23:29:11 | 000,342,592 | ---- | M] (Woodtale Technology Inc) [Auto | Running] -- C:\Users\Cyrille\AppData\Local\DProtect\DProtectSvc.exe -- (DPService)
SRV - [2012/02/10 11:28:06 | 000,240,408 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.EXE -- (BBUpdate)
SRV - [2012/02/10 11:28:06 | 000,193,816 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.EXE -- (BBSvc)
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.qvo6.com/?utm_source=butm_me ... 1379585359 b[Pays - ]/b
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.qvo6.com/?utm_source=butm_me ... 1379585359 b[Pays - ]/b
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKU\S-1-5-21-3763821033-858617334-2237367008-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.qvo6.com/?utm_source=butm_me ... 1379155005 b[Pays - ]/b
IE - HKU\S-1-5-21-3763821033-858617334-2237367008-1000\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: URL =
http://search.qvo6.com/web/?utm_source= ... 1379155005 b[Pays - ]/b
IE - HKU\S-1-5-21-3763821033-858617334-2237367008-1000\..\SearchScopes\{844BF0C5-95F3-4464-86E5-5D49DA5D9383}: URL =
http://search.conduit.com/ResultsExt.as ... 713325UM=3 b[Pays NL - 195.78.120.88]/b
IE - HKU\S-1-5-21-3763821033-858617334-2237367008-1002\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
CHR - default_search_provider: qvo6 (Enabled)
CHR - default_search_provider: search_url =
http://search.qvo6.com/web/?utm_source= ... earchTerms} b[Pays - ]/b
CHR - homepage:
http://www.qvo6.com/?utm_source=butm_me ... 1379607024 b[Pays - ]/b
CHR - plugin: McAfee Security Scanner + (Enabled) = C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll
CHR - Extension: 01NET.com V1 = C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\biahaobfpkgeiomkihcdgknebbhadonc\10.19.2.5_0\
CHR - plugin: Mailocash (Enabled) = C:\Program Files (x86)\Mailocash\np_mc_ns_invoke_helper_Win32.dll
O2:
64bit: - BHO: (Mailocash Information) - {5C3FF33E-6686-49f1-B4DB-8D24CD1FCF6F} - C:\Program Files (x86)\Mailocash\x64\MailoramaBHO_Win64.dll ()
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (Bubble Dock SurfMatch) - {23AF19F7-1D5B-442c-B14C-3D1081953C94} - C:\Program Files (x86)\Nosibay\Bubble Dock\extensions\axSurfMatch.dll File not found
O2 - BHO: (Mailocash Information) - {5C3FF33E-6686-49f1-B4DB-8D24CD1FCF6F} - C:\Program Files (x86)\Mailocash\MailoramaBHO_Win32.dll ()
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3:
64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKU\S-1-5-21-3763821033-858617334-2237367008-1000..\Run: [ConduitFloatingPlugin_biahaobfpkgeiomkihcdgknebbhadonc] C:\Windows\SysWOW64\Rundll32.exe C:\Program Files (x86)\Conduit\CT3307695\plugins\TBVerifier.dll,RunConduitFloatingPlugin biahaobfpkgeiomkihcdgknebbhadonc File not found
O20 - AppInit_DLLs: (C:\Users\Cyrille\AppData\Local\DProtect\eBP.dll) - C:\Users\Cyrille\AppData\Local\DProtect\eBP.dll ()
O20 - AppInit_DLLs: (C:\Users\Cyrille\AppData\Local\DProtect\eBPSD.dll) - C:\Users\Cyrille\AppData\Local\DProtect\eBPSD.dll ()
[2011/04/02 19:18:26 | 000,000,000 | -H-D | M] -- C:\OEM
@Alternate Data Stream - 112 bytes - C:\ProgramData\TEMP:D1B5B4F1
:REG
[HKEY_CURRENT_USER\Software\MCAFEE]=-
[HKEY_LOCAL_MACHINE\Software\DProtect]=-
[HKEY_LOCAL_MACHINE\Software\mcafeeupdater]=-
:COMMANDS
[EMTYTEMP]
• Clique sur «
Correction » et laisse l'outil travailler. Il est possible que l'ordinateur redémarre.
• Copie/colle la totalité du rapport dans ta prochaine réponse.