Modérateur: Modérateurs

OTL :netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
SAVEMBR:0
/md5start
explorer.exe
wininit.exe
winlogon.exe
userinit.exe
svchost.exe
/md5stop
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
hklm\system\CurrentControlSet\Control\Session Manager\SubSystems /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
nslookup http://www.google.fr /c
CREATERESTOREPOINT



Recommandations pendant la désinfection :
Désinstalle via Programmes et fonctionnalités (si présent) :
Bien qu'il ne soit plus tenu à jour, utilise tout de même cet outil spécifique :
AdwCleaner - Recherche :
ou j'ai encore de l'espoir
?
AdwCleaner - Suppression :
Malwarebyte's Anti-Malware : 


Installe la dernière version Java :
Mets à jour ta version d'Adobe Reader :
Mets à jour ta version Avast :
Mise à jour d'Internet Explorer :
Relance OTL comme indiqué précédemment pour générer un nouveau rapport OTL.txt que tu héberges sur cijoint.fr ou pjjoint.fr et indique le lien fourni dans ta réponse. 
OTL ::OTL
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
[2010/05/22 15:07:00 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/11/28 13:19:39 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/20 21:18:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/22 22:52:57 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
O1 - Hosts: ::1 localhost
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-4210551420-1716069962-2498686098-1000\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-4210551420-1716069962-2498686098-1000\..\Toolbar\WebBrowser: (no name) - {A65E491F-A436-4952-B49A-B24ED99A0F67} - No CLSID value found.
O3 - HKU\S-1-5-21-4210551420-1716069962-2498686098-1000\..\Toolbar\WebBrowser: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No CLSID value found.
O3 - HKU\S-1-5-21-4210551420-1716069962-2498686098-1000\..\Toolbar\WebBrowser: (no name) - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - No CLSID value found.
O4 - HKLM..\Run: [eRecoveryService] File not found
[2011/09/29 21:00:53 | 000,526,586 | ---- | M] () -- C:\Users\Nicolas\Desktop\adwcleaner0.exe
[2011/09/29 19:36:57 | 000,231,562 | ---- | M] () -- C:\Users\Nicolas\Desktop\Navilog1.exe
[2009/01/09 21:27:00 | 000,000,000 | ---D | M] -- C:\ProgramData\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/07/04 14:35:42 | 000,053,096 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x64\DifXInstall64.exe
[2008/07/04 14:35:40 | 000,054,632 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DifXInstall32.exe
[2008/07/04 14:35:42 | 000,053,096 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\Application Data\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x64\DifXInstall64.exe
[2008/07/04 14:35:40 | 000,054,632 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\Application Data\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DifXInstall32.exe
[2008/07/04 14:35:42 | 000,053,096 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\Application Data\Application Data\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x64\DifXInstall64.exe
[2008/07/04 14:35:40 | 000,054,632 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\Application Data\Application Data\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DifXInstall32.exe
[2008/07/04 14:35:42 | 000,053,096 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x64\DifXInstall64.exe
[2008/07/04 14:35:40 | 000,054,632 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DifXInstall32.exe
[2008/07/04 14:35:42 | 000,053,096 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x64\DifXInstall64.exe
[2008/07/04 14:35:40 | 000,054,632 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DifXInstall32.exe
[2008/07/04 14:35:42 | 000,053,096 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x64\DifXInstall64.exe
[2008/07/04 14:35:40 | 000,054,632 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DifXInstall32.exe
[2008/07/04 14:35:42 | 000,053,096 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x64\DifXIn
[2008/07/04 14:35:40 | 000,054,632 | ---- | M] (GEAR Software, Inc.) -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DifXIn
[2010/05/12 10:55:40 | 003,727,360 | ---- | M] (DOSBox Team) -- C:\Users\Nicolas\AppData\Roaming\Abandonware-France\Terminator Skynet - Futur Shock\DOSBox.exe
[2011/07/24 16:32:24 | 000,780,255 | ---- | M] () -- C:\Users\Nicolas\AppData\Roaming\Abandonware-France\Terminator Skynet - Futur Shock\unins000.exe
[2011/02/04 12:56:06 | 000,392,220 | ---- | M] () -- C:\Users\Nicolas\AppData\Roaming\Abandonware-France\Terminator Skynet - Futur Shock\C\SHOCK\INSTALL.EXE
[2011/02/04 12:56:06 | 000,049,194 | ---- | M] () -- C:\Users\Nicolas\AppData\Roaming\Abandonware-France\Terminator Skynet - Futur Shock\C\SHOCK\LOADPATS.EXE
[2011/02/04 12:56:06 | 000,383,595 | ---- | M] () -- C:\Users\Nicolas\AppData\Roaming\Abandonware-France\Terminator Skynet - Futur Shock\C\SHOCK\SETUP.EXE
[2011/02/04 12:56:06 | 001,411,856 | ---- | M] () -- C:\Users\Nicolas\AppData\Roaming\Abandonware-France\Terminator Skynet - Futur Shock\C\SHOCK\SHOCK.EXE
[2011/02/04 12:58:32 | 000,265,420 | ---- | M] () -- C:\Users\Nicolas\AppData\Roaming\Abandonware-France\Terminator Skynet - Futur Shock\C\SKYNET\DOS4GW.EXE
[2011/02/04 12:58:32 | 000,372,659 | ---- | M] () -- C:\Users\Nicolas\AppData\Roaming\Abandonware-France\Terminator Skynet - Futur Shock\C\SKYNET\INSTALL.EXE
[2011/02/04 12:58:32 | 000,049,194 | ---- | M] () -- C:\Users\Nicolas\AppData\Roaming\Abandonware-France\Terminator Skynet - Futur Shock\C\SKYNET\LOADPATS.EXE
[2011/02/04 12:58:32 | 000,383,595 | ---- | M] () -- C:\Users\Nicolas\AppData\Roaming\Abandonware-France\Terminator Skynet - Futur Shock\C\SKYNET\SETUP.EXE
[2011/02/04 12:58:32 | 001,839,291 | ---- | M] () -- C:\Users\Nicolas\AppData\Roaming\Abandonware-France\Terminator Skynet - Futur Shock\C\SKYNET\SKYNET.EXE
[2011/02/04 12:58:32 | 000,220,160 | ---- | M] (Bethesda Softworks) -- C:\Users\Nicolas\AppData\Roaming\Abandonware-France\Terminator Skynet - Futur Shock\C\SKYNET\DATA\SKYAUTO.EXE
File not found -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BC
File not found -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BC
File not found -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Adobe\Setup\{AC76BA86-7AD7-1036-7B4
File not found -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\D
File not found -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Google Tool
File not found -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Google Toolbar\Update\Google
File not found -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Installations\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:C46995DA
@Alternate Data Stream - 99 bytes -> C:\ProgramData\Application Data\TEMP:C46995DA
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:8AB6C1D7
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Application Data\TEMP:8AB6C1D7
:Commands
[PURITY]
[EMPTYTEMP]
[EMPTYFLASH]
[CREATERESTOREPOINT]






Retourner vers Aide pour supprimer les virus
Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 0 invités