re alberto69
1/ Attention a ce qui s'installe quand tu télécharges
liens publicitaires: mc afee truekey et security scan a désinstaller
2/Lance Farbar
http://zupimages.net/up/17/31/cqay.pngCopies les lignes suivantes dans le cadre rouge
start::
CloseProcesses:
CreateRestorePoint:
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
SearchScopes: HKU\S-1-5-21-3415745520-1902539971-99246408-1002 -> DefaultScope {73cd434e-8e1e-46b6-bb8d-7dd935140717} URL =
CHR HKU\S-1-5-21-3415745520-1902539971-99246408-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3415745520-1902539971-99246408-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10042017152207804\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
2016-03-23 17:13 - 2016-06-01 12:13 - 000000228 _____ () C:\Users\Natacha\AppData\Roaming\WB.CFG
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Pas de fichier
Task: {291CD9D0-5672-4626-99DF-BE95A9D8173E} - \Microsoft\Windows\RemoteApp and Desktop Connections Update\Natacha\Start Workspace Runtime at logon -> Pas de fichier <==== ATTENTION
Task: {7B4E38F9-16C0-4AB3-976C-676FFB6A6C79} - \Microsoft\Windows\RemoteApp and Desktop Connections Update\Natacha\Update connections -> Pas de fichier <==== ATTENTION
Task: {84385F07-C4CC-4BBF-AF0A-1C3C53A1D2AA} - \Microsoft\Windows\RemoteApp and Desktop Connections Update\Natacha\Report update status -> Pas de fichier <==== ATTENTION
C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WinBrowModule.lnk
C:\Users\digischool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WinBrowModule.lnk
C:\Users\natac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WinBrowModule.lnk
C:\Users\Natacha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WinBrowModule.lnk
DeleteKey: HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{621D8D38-A0DC-4121-A1A5-882E3C5BC32D}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{621D8D38-A0DC-4121-A1A5-882E3C5BC32D}
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{621D8D38-A0DC-4121-A1A5-882E3C5BC32D}
C:\WINDOWS\System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime
w32time task_started
C:\Users\marie christine\AppData\Local\Google\Chrome\User Data\Default\bfciogmhhimhgmgabbccfbdibjhgijda
C:\Users\marie christine\AppData\Local\Google\Chrome\User Data\Default\jlincbpgbkpbjepghokdnhnnpphmegig
DeleteKey: HKCU\SOFTWARE\Tuguu
C:\Users\Natacha\AppData\Local\5d58c83d4bebe135
O45 - LFCP:[MD5.839C177AC596C1442CD3F9FE80404902] 30/08/2017 A -- C:\WINDOWS\Prefetch\REIMAGE.EXE-02B30964.pf
O45 - LFCP:[MD5.C9EFAA38DB6E11D9F70065B1AF1C7C71] 23/08/2017 A -- C:\WINDOWS\Prefetch\REIMAGEPACKAGE.EXE-7993F1AC.pf
O45 - LFCP:[MD5.1C6C69BD531820FAAF32A419C33ACBA5] 26/05/2017 A -- C:\WINDOWS\Prefetch\REIMAGEREPAIR.EXE-48FDC0DA.pf
O45 - LFCP:[MD5.C7385B1F689C935440179BCE202791AD] 28/08/2017 A -- C:\WINDOWS\Prefetch\REIMAGEREPAIR.EXE-9C5E4F2B.pf
C:\Users\Natacha\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bfciogmhhimhgmgabbccfbdibjhgijda
C:\Users\Natacha\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jlincbpgbkpbjepghokdnhnnpphmegig
C:\WINDOWS\Prefetch\REIMAGE.EXE-02B30964.pf
C:\WINDOWS\Prefetch\REIMAGEPACKAGE.EXE-7993F1AC.pf
C:\WINDOWS\Prefetch\REIMAGEREPAIR.EXE-48FDC0DA.pf
C:\WINDOWS\Prefetch\REIMAGEREPAIR.EXE-9C5E4F2B.pf
EmptyTemp:
end::
Corrige et heberge le rapport fixlog
@+