Supprimer winsnare et amule c

Fermé
phillalli1 - 8 avril 2017 à 01:49
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 - 8 avril 2017 à 10:50
Bonjour,

J'ai essayé de m'en débarasser plusieurs fois (avec des anti virus, etc...)
Mais pas de resultat donc je me suis tourné vers frst , pourriez vous m'aider?
(je vous fournis les liens pjjoint)
Frst: http://pjjoint.malekal.com/files.php?id=FRST_20170408_n8i11g15n9h7
additionnal : http://pjjoint.malekal.com/files.php?id=20170408_t9m12q8e8k5
shortcut: http://pjjoint.malekal.com/files.php?id=20170408_d14d11g5q5x8
A voir également:

3 réponses

Kuroki. Messages postés 20 Date d'inscription vendredi 7 avril 2017 Statut Membre Dernière intervention 9 avril 2017 4
8 avril 2017 à 01:59
Pour le supprimer, essaye d'aller dans :
Panneau de configuration -> Désinstaller un programme -> puis tu a toute la liste des programmes installés, tu fait clique gauche sur le/les programme(s) à désinstaller puis clique sur désinstaller, normalement ça marche.
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 636
8 avril 2017 à 10:41
Salut,

Je regarde les rapports.
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 636
8 avril 2017 à 10:50
Voici la correction à effectuer avec FRST. Tu peux t'aider de cette note explicative avec des captures d'écran.

Ouvre le bloc-notes : Touche Windows + R,
Dans le champs "Exécuter", saisir notepad et OK.
Copie/Colle dedans ce qui suit :

CreateRestorePoint:
CloseProcesses:
HKLM\...\Run: [gplyra] => C:\Users\C3Consultants\AppData\Roaming\gplyra\gplyra.exe [1538048 2017-02-05] () <===== ATTENTION
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-1821689846-2012740900-1950354591-1002\...\Run: [BingSvc] => C:\Users\C3Consultants\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-13] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-1821689846-2012740900-1950354591-1002\...\Run: [WahOO] => C:\Program Files (x86)\KowMedia\WahOO\WahOO.exe [5444416 2016-04-13] ()
HKU\S-1-5-21-1821689846-2012740900-1950354591-1002\...\Run: [sjcYAfa&ie.exe] => C:\Users\C3Consultants\AppData\Local\Temp\{c70-9a-c3-7d4a3-b0506-cdc0-bc67f}\sjcYAfa&ie.exe [687616 2017-02-19] (Sunday) <===== ATTENTION
HKU\S-1-5-21-1821689846-2012740900-1950354591-1002\...\Run: [I'aD3-kb3G.exe] => C:\Users\C3Consultants\AppData\Local\Temp\{c70-9a-c3-7d4a3-b0506-cdc0-bc67f}\I'aD3-kb3G.exe [891904 2017-02-19] (KApitale) <===== ATTENTION
HKU\S-1-5-21-1821689846-2012740900-1950354591-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27545048 2017-03-14] (Skype Technologies S.A.)
HKU\S-1-5-21-1821689846-2012740900-1950354591-1002\...\Run: [GameJoltClient] => C:\Users\C3Consultants\AppData\Local\GameJoltClient\GameJoltClient.exe [46705152 2016-12-20] ()
HKU\S-1-5-21-1821689846-2012740900-1950354591-1002\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3044848 2017-04-07] (Electronic Arts)
HKLM-x32\...\Run: [BtTray] => c:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe [364032 2012-08-16] (IVT Corporation)
HKLM-x32\...\Run: [HP HD Webcam Driver_Monitor] => C:\Program Files (x86)\HP HD Webcam Driver\monitor.exe [303480 2012-07-26] ()
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-24] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => c:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
R2 clean; C:\Users\C3Consultants\AppData\Local\clean\Kyubey.exe [114688 2017-04-06] () [Fichier non signé]
R2 GubedZL; C:\Program Files (x86)\Gubed\GubedZL.dll [118272 2017-02-04] () [Fichier non signé]
R2 Gubed_WMI; C:\Program Files (x86)\Gubed_WMI\Gubed_WMI.exe [110080 2016-12-26] () [Fichier non signé]
R2 Convxxxx; C:\Users\C3Consultants\AppData\Roaming\fibei\UvConverter.exe [396800 2016-12-26]
R3 iThemes5; C:\Program Files (x86)\Common Files\Services\iThemes.dll [526848 2017-02-04] () [Fichier non signé] <==== ATTENTION
S2 Kyubey; C:\Users\C3Consultants\AppData\Roaming\Kyubey\Kyubey.exe [236032 2017-04-01] () [Fichier non signé]
R2 Nettrans; C:\ProgramData\NetworkPacketManitor\Nettrans.exe [43520 2017-02-19] () [Fichier non signé]
R2 Themes; C:\WINDOWS\system32\themeservice.dll [59392 2014-10-29] (Microsoft Corporation) [DependOnService: iThemes5]<==== ATTENTION
R2 UncheckitSvc; C:\Program Files (x86)\Uncheckit\UncheckitSvc.exe [247552 2016-07-05] (evangel technology (hk) limited)
R2 WinSAPSvc; C:\Users\C3Consultants\AppData\Roaming\WinSAPSvc\WinSAP.dll [188416 2017-04-07] (Windows) [Fichier non signé]
R2 WINSNARE; C:\Users\C3Consultants\AppData\Roaming\WINSNARE\WinSnare.dll [1293312 2017-04-01] (InterSect Alliance Pty Ltd) [Fichier non signé] <==== ATTENTION
R2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [1094264 2016-08-25] (ExWzp Pvt Ltd.) [Fichier non signé] <==== ATTENTION
S2 Archer; C:\Program Files (x86)\WinArcher\Archer.dll [X]
S2 ed2kidle; "C:\Program Files (x86)\amuleC\ed2k.exe" -downloadwhenidle [X] <==== ATTENTION
S2 FirefoxDL; "C:\Users\C3CONS~1\AppData\Local\Temp\5\QQBrowser.exe" -isvc [X] <==== ATTENTION
S2 jIxmRfR_update; "C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe" [X]
S2 serverss; C:\WINDOWS\Temp\DCBC.tmp [X]
2017-04-07 00:57 - 2017-04-07 00:57 - 00000000 ____D C:\Program Files (x86)\{750416E0-9FE5-4AA5-AE94-95CA5C81C470}
2017-03-04 23:01 - 2017-04-08 01:06 - 00000000 ____D C:\Program Files (x86)\BikaQRss
2017-03-04 22:58 - 2017-03-04 22:58 - 00000000 ____D C:\Users\Public\Documents\CyberLink
2017-03-04 22:58 - 2017-03-04 22:58 - 00000000 ____D C:\Users\Public\CyberLink
2017-03-04 01:04 - 2017-04-07 00:21 - 00000000 _____ C:\WINDOWS\SysWOW64\4
2017-03-04 01:04 - 2017-04-01 17:28 - 00000000 _____ C:\WINDOWS\SysWOW64\3
2017-03-04 01:04 - 2017-03-04 01:04 - 00000000 ____D C:\Program Files (x86)\Firefox
2017-03-03 22:38 - 2017-03-03 22:38 - 00000000 ____D C:\Users\C3Consultants\AppData\Roaming\Kyubey
2017-02-23 14:25 - 2017-02-23 14:25 - 00000000 ____D C:\Users\C3Consultants\Desktop\M.S
2017-02-23 13:32 - 2017-02-23 13:32 - 69717250 _____ C:\Users\C3Consultants\Desktop\M.S.rar
2017-02-23 11:12 - 2017-02-23 11:12 - 00000000 ____D C:\Users\C3Consultants\Desktop\C.H_2
2017-02-23 11:11 - 2017-02-23 11:11 - 67033364 _____ C:\Users\C3Consultants\Desktop\C.H_2.rar
2017-02-23 11:09 - 2017-02-23 11:09 - 00000000 ____D C:\Users\C3Consultants\Desktop\Deadlock_1
2017-02-23 11:08 - 2017-02-23 11:08 - 48117867 _____ C:\Users\C3Consultants\Desktop\Deadlock_1.rar
2017-02-23 11:05 - 2017-02-23 11:05 - 00000000 ____D C:\Users\C3Consultants\Desktop\I.A_1
2017-02-23 11:04 - 2017-02-23 11:04 - 49390442 _____ C:\Users\C3Consultants\Desktop\I.A_1.rar
2017-02-23 10:54 - 2017-02-23 10:54 - 00000000 ____D C:\Users\C3Consultants\Desktop\Viewfinder_08
2017-02-22 14:03 - 2017-02-22 14:03 - 00000000 ____D C:\Users\C3Consultants\Downloads\B_F
2017-02-22 13:48 - 2017-04-07 12:31 - 00000000 ____D C:\Users\C3Consultants\AppData\Roaming\WinSAPSvc
2017-02-20 17:42 - 2017-02-20 17:42 - 00000772 _____ C:\WINDOWS\SysWOW64\ping.cfg
2017-02-20 17:42 - 2017-02-20 17:42 - 00000000 _____ C:\temp.dat
2017-02-20 09:57 - 2017-03-05 03:57 - 00003208 _____ C:\WINDOWS\System32\Tasks\BikaQ_FetchAndUpgrade_CanBeDel
2017-02-20 09:57 - 2017-03-04 23:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BikaQ
2017-02-20 03:37 - 2017-02-20 03:37 - 00002166 _____ C:\Users\Public\Desktop\Google Earth.lnk
2017-02-20 03:37 - 2017-02-20 03:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2017-02-20 02:34 - 2017-02-20 17:40 - 00000000 ____D C:\Users\C3Consultants\AppData\Local\BrowserAir
2017-02-20 02:34 - 2017-02-20 02:34 - 00004286 _____ C:\WINDOWS\System32\Tasks\SMW_UpdateTask_Time_323232353334383331372d2a55456c2d5a34575b413234
2017-02-19 21:45 - 2017-04-07 19:45 - 00000326 _____ C:\WINDOWS\Tasks\PC Clean Plus_DEFAULT.job
2017-02-19 21:45 - 2017-02-22 21:45 - 00000334 _____ C:\WINDOWS\Tasks\PC Clean Plus_UPDATES.job
2017-02-19 21:45 - 2017-02-19 21:45 - 00003260 _____ C:\WINDOWS\System32\Tasks\PC Clean Plus_DEFAULT
2017-02-19 21:45 - 2017-02-19 21:45 - 00003086 _____ C:\WINDOWS\System32\Tasks\PC Clean Plus_UPDATES
2017-02-19 21:44 - 2017-04-01 13:26 - 00003020 _____ C:\WINDOWS\System32\Tasks\RunAtStartup
2017-02-19 21:44 - 2017-04-01 13:26 - 00000000 ____D C:\Users\C3Consultants\AppData\Roaming\Event Monitor
2017-02-19 21:44 - 2017-02-19 21:44 - 00003122 _____ C:\WINDOWS\System32\Tasks\PC Clean Plus
2017-02-19 21:44 - 2017-02-19 21:44 - 00000000 ____D C:\Users\C3Consultants\AppData\Roaming\PC Clean Plus
2017-02-19 21:44 - 2017-02-19 21:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Clean Plus
2017-02-19 21:42 - 2017-02-19 21:42 - 00003154 _____ C:\WINDOWS\System32\Tasks\{352A360E-CECD-4C49-A977-4DB060F894C5}
2017-02-19 21:39 - 2017-02-19 21:39 - 00003602 _____ C:\WINDOWS\System32\Tasks\{7F1F24F0-550B-4900-BB8D-86231EE58D05}
2017-02-19 21:38 - 2017-02-19 21:38 - 00000000 ____D C:\ProgramData\Microleaves
2017-02-19 21:37 - 2017-02-19 21:37 - 00002398 _____ C:\WINDOWS\SysWOW64\findit.xml
2017-02-19 21:37 - 2017-02-19 21:37 - 00000000 ____D C:\ProgramData\Zaamlas
2017-02-19 21:35 - 2017-04-08 01:33 - 00000364 _____ C:\WINDOWS\Tasks\Traffic Exchange v209 - 3.job
2017-02-19 21:35 - 2017-04-08 01:33 - 00000364 _____ C:\WINDOWS\Tasks\Traffic Exchange v209 - 2.job
2017-02-19 21:35 - 2017-04-08 01:33 - 00000364 _____ C:\WINDOWS\Tasks\Traffic Exchange v209 - 1.job
2017-02-19 21:35 - 2017-04-08 01:33 - 00000354 _____ C:\WINDOWS\Tasks\Traffic Exchange v2 - 3.job
2017-02-19 21:35 - 2017-04-08 01:33 - 00000354 _____ C:\WINDOWS\Tasks\Traffic Exchange v2 - 2.job
2017-02-19 21:35 - 2017-04-08 01:33 - 00000354 _____ C:\WINDOWS\Tasks\Traffic Exchange v2 - 1.job
2017-02-19 21:35 - 2017-04-07 23:38 - 00000406 ____H C:\WINDOWS\Tasks\Traffic Exchange Updater.job
2017-02-19 21:35 - 2017-02-19 21:35 - 01938536 _____ C:\Users\C3Consultants\AppData\Roaming\Zumdox.bin
2017-02-19 21:35 - 2017-02-19 21:35 - 00003580 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange Guardian
2017-02-19 21:35 - 2017-02-19 21:35 - 00003580 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange Guard
2017-02-19 21:35 - 2017-02-19 21:35 - 00003580 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange
2017-02-19 21:35 - 2017-02-19 21:35 - 00003210 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange Updater
2017-02-19 21:35 - 2017-02-19 21:35 - 00003170 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v209 - 3
2017-02-19 21:35 - 2017-02-19 21:35 - 00003170 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v209 - 2
2017-02-19 21:35 - 2017-02-19 21:35 - 00003170 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v209 - 1
2017-02-19 21:35 - 2017-02-19 21:35 - 00003160 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v2 - 3
2017-02-19 21:35 - 2017-02-19 21:35 - 00003160 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v2 - 2
2017-02-19 21:35 - 2017-02-19 21:35 - 00003160 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v2 - 1
2017-02-19 21:35 - 2017-02-19 21:35 - 00000000 ____D C:\ProgramData\Logic Handler
2017-02-19 21:34 - 2017-03-03 22:21 - 00000000 ____D C:\ProgramData\NetworkPacketManitor
2017-02-19 21:34 - 2017-02-19 21:37 - 00000000 ____D C:\Users\C3Consultants\AppData\Roaming\Microleaves
2017-02-19 21:34 - 2017-02-19 21:36 - 00000000 ____D C:\Users\C3Consultants\AppData\Local\app
2017-02-19 21:34 - 2017-02-19 21:34 - 07319040 _____ C:\Users\C3Consultants\AppData\Roaming\agent.dat
2017-02-19 21:34 - 2017-02-19 21:34 - 01908111 _____ C:\Users\C3Consultants\AppData\Roaming\S-zap.tst
2017-02-19 21:34 - 2017-02-19 21:34 - 00278521 _____ C:\Users\C3Consultants\AppData\Roaming\Quadlam.bin
2017-02-19 21:34 - 2017-02-19 21:34 - 00126464 _____ C:\Users\C3Consultants\AppData\Roaming\noah.dat
2017-02-19 21:34 - 2017-02-19 21:34 - 00070752 _____ C:\Users\C3Consultants\AppData\Roaming\Config.xml
2017-02-19 21:34 - 2017-02-19 21:34 - 00018432 _____ C:\Users\C3Consultants\AppData\Roaming\Main.dat
2017-02-19 21:34 - 2017-02-19 21:34 - 00005568 _____ C:\Users\C3Consultants\AppData\Roaming\md.xml
2017-02-19 21:34 - 2017-02-19 21:34 - 00000000 ____D C:\Users\Default\AppData\Local\AdvinstAnalytics
2017-02-19 21:34 - 2017-02-19 21:34 - 00000000 ____D C:\Users\Default User\AppData\Local\AdvinstAnalytics
2017-02-19 21:33 - 2017-02-19 21:33 - 00005040 _____ C:\WINDOWS\System32\Tasks\Atowerpyplowat
2017-02-19 21:33 - 2017-02-19 21:33 - 00000000 ____D C:\Users\C3Consultants\AppData\Local\Bijlyirerge
2017-02-19 21:33 - 2017-02-19 21:33 - 00000000 ____D C:\ProgramData\SearchModule
2017-02-19 21:32 - 2017-02-19 21:41 - 00000000 ____D C:\Users\C3Consultants\AppData\Local\WikiThemes
2017-02-19 21:32 - 2017-02-19 21:36 - 00000000 ____D C:\Users\C3Consultants\AppData\Local\AppTrailers
2017-02-19 21:32 - 2017-02-19 21:32 - 00000000 ____D C:\Program Files\Common Files\Noobzo
2017-02-19 21:31 - 2017-02-19 21:34 - 00016224 _____ C:\Users\C3Consultants\AppData\Roaming\InstallationConfiguration.xml
2017-02-19 21:31 - 2017-02-19 21:32 - 00000000 ____D C:\Users\C3Consultants\AppData\Roaming\gplyra
2017-02-19 21:31 - 2017-02-19 21:31 - 00140288 _____ C:\Users\C3Consultants\AppData\Roaming\Installer.dat
2017-02-19 21:31 - 2017-02-19 21:31 - 00000000 _____ C:\TOSTACK
2017-02-19 21:28 - 2017-02-19 21:43 - 00000000 ____D C:\WINDOWS\system32\SSL
2011-09-26 21:45 - 2011-09-26 21:45 - 0001126 _____ () C:\Users\C3Consultants\AppData\Roaming\404-11.htm
2017-02-19 21:34 - 2017-02-19 21:34 - 7319040 _____ () C:\Users\C3Consultants\AppData\Roaming\agent.dat
2017-02-19 21:31 - 2017-02-19 21:31 - 0023622 _____ () C:\Users\C3Consultants\AppData\Roaming\aliexpress.ico
2017-02-19 21:31 - 2017-02-19 21:31 - 0099678 _____ () C:\Users\C3Consultants\AppData\Roaming\booking.ico
2017-02-19 21:34 - 2017-02-19 21:34 - 0070752 _____ () C:\Users\C3Consultants\AppData\Roaming\Config.xml
2013-10-02 04:54 - 2013-10-02 04:54 - 0000321 _____ () C:\Users\C3Consultants\AppData\Roaming\Eirunepe
2017-02-19 21:31 - 2017-02-19 21:34 - 0016224 _____ () C:\Users\C3Consultants\AppData\Roaming\InstallationConfiguration.xml
2017-02-19 21:31 - 2017-02-19 21:31 - 0140288 _____ () C:\Users\C3Consultants\AppData\Roaming\Installer.dat
2017-02-19 21:34 - 2017-02-19 21:34 - 0018432 _____ () C:\Users\C3Consultants\AppData\Roaming\Main.dat
2017-02-19 21:34 - 2017-02-19 21:34 - 0005568 _____ () C:\Users\C3Consultants\AppData\Roaming\md.xml
2016-04-17 17:27 - 2016-04-17 17:27 - 0052885 _____ () C:\Users\C3Consultants\AppData\Roaming\Nairobi
2017-02-19 21:34 - 2017-02-19 21:34 - 0126464 _____ () C:\Users\C3Consultants\AppData\Roaming\noah.dat
2013-10-02 04:54 - 2013-10-02 04:54 - 0001004 _____ () C:\Users\C3Consultants\AppData\Roaming\Petersburg
2017-02-19 21:34 - 2017-02-19 21:34 - 0278521 _____ () C:\Users\C3Consultants\AppData\Roaming\Quadlam.bin
2017-02-19 21:34 - 2017-02-19 21:34 - 1908111 _____ () C:\Users\C3Consultants\AppData\Roaming\S-zap.tst
2016-04-17 17:27 - 2016-04-17 17:27 - 0002205 _____ () C:\Users\C3Consultants\AppData\Roaming\SunbakeBerryInnuendo
2015-05-20 03:28 - 2015-05-20 03:28 - 0002670 _____ () C:\Users\C3Consultants\AppData\Roaming\system.xml
2013-10-02 04:56 - 2013-10-02 04:56 - 0003850 _____ () C:\Users\C3Consultants\AppData\Roaming\ua.js
2017-02-19 21:35 - 2017-02-19 21:35 - 0032038 _____ () C:\Users\C3Consultants\AppData\Roaming\uninstall_temp.ico
2013-10-02 04:59 - 2013-10-02 04:59 - 0001447 _____ () C:\Users\C3Consultants\AppData\Roaming\Xusage.txt
2017-02-19 21:35 - 2017-02-19 21:35 - 1938536 _____ () C:\Users\C3Consultants\AppData\Roaming\Zumdox.bin
2014-01-07 17:02 - 2014-01-07 17:02 - 0000057 _____ () C:\ProgramData\Ament.ini
ShortcutWithArgument: C:\Users\C3Consultants\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www%2dsearching.com/?prd=set_epf&s=h2jzftpbl0cshmobu,de825189-7290-48fd-8250-4bbf85316770,
ShortcutWithArgument: C:\Users\C3Consultants\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet-Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www%2dsearching.com/?prd=set_epf&s=h2jzftpbl0cshmobu,de825189-7290-48fd-8250-4bbf85316770,
ShortcutWithArgument: C:\Users\C3Consultants\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www%2dsearching.com/?prd=set_epf&s=h2jzftpbl0cshmobu,de825189-7290-48fd-8250-4bbf85316770,
ShortcutWithArgument: C:\Users\C3Consultants\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www-searching.com/?prd=set_epf&s=h2jzftpbl0cshmobu,de825189-7290-48fd-8250-4bbf85316770,
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www-searching.com/?prd=set_epf&s=h2jzftpbl0cshmobu,de825189-7290-48fd-8250-4bbf85316770,
ShortcutWithArgument: C:\Users\Public\Desktop\Formations Office 2010.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.nuesearch.com/?type=sc&ts=1466494450&z=a1111b41e8c4298291c38c5g9zcq4q7z3t5zfz9w7o&from=wpm0616&uid=ST9500423AS_S2V0E9RJ
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Firefox\Firefox.exe (Mozilla Corporation) -> hxxp://www-searching.com/?prd=set_epf&s=h2jzftpbl0cshmobu,de825189-7290-48fd-8250-4bbf85316770,
C:\Users\C3Consultants\AppData\Roaming\gplyra
Task: C:\WINDOWS\Tasks\PC Clean Plus_DEFAULT.job => C:\Program Files (x86)\PC Clean Plus\PCCleanPlus.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\PC Clean Plus_UPDATES.job => C:\Program Files (x86)\PC Clean Plus\PCCleanPlus.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Task: C:\WINDOWS\Tasks\Traffic Exchange Updater.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Traffic Exchange Updater.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v2 - 1.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v2 - 2.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v2 - 3.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v209 - 1.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v209 - 2.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Traffic Exchange v209 - 3.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: {6DFA2433-FA3C-4D09-9FFA-2F562B75BA09} - System32\Tasks\SMW_UpdateTask_Time_323232353334383331372d2a55456c2d5a34575b413234 => Wscript.exe //B "C:\ProgramData\SearchModule\smhe.js" smu.exe /invoke /f:check_services /l:0 <==== ATTENTION
Task: {4D05202B-04A0-4B5F-8E16-CBFC0E88B020} - System32\Tasks\jIxmRfRCheckTask => C:\Program Files (x86)\jIxmRfR\jIxmRfR\bin\jIxmRfR_server.exe <==== ATTENTION
Task: {57B61D8D-4C92-46F6-B078-E2AEA764673E} - System32\Tasks\UncheckitUpdateTaskDB => C:\Program Files (x86)\Uncheckit\UncheckitUpdate.exe [2016-07-05] (EVANGEL TECHNOLOGY (HK) LIMITED) <==== ATTENTION
Task: {9D0D9FE9-1514-4CDA-B677-484B10739520} - System32\Tasks\{7F1F24F0-550B-4900-BB8D-86231EE58D05} => pcalua.exe -a "C:\Program Files (x86)\Common Files\MoveBam\uninstall.exe" -c shuz -f "C:\Program Files (x86)\Common Files\MoveBam\uninstall.dat" -a uninstallme 748899DE-9C2F-4AFF-A463-921125FDEA4F DeviceId=3dc722f1-48ea-b2eb-ee3b-6f7236f78c8c BarcodeId=51107003 ChannelId=3 DistributerName=APSFClickMeIn
EmptyTemp:
RemoveProxy:
Reboot:


Une fois, le texte collé dans le Bloc-notes,
Menu "Fichier" puis "Enregistrer sous",
A gauche, place toi sur le Bureau,
Dans le champs en bas, nom du fichier mets : fixlist.txt
Clique sur "Enregistrer", cela va créer fixlist.txt sur le Bureau.

Relance FRST et clique sur le bouton "Corriger / Fix"
Un redémarrage sera peut-être nécessaire ( pas obligatoire )
Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.

Redémarre l'ordinateur.


2°)
Réinitialise/Répare les navigateurs WEB concernés par les problèmes :

3°)
Fais un nettoyage Malwarebytes - Tutoriel Malwarebytes Anti-Malware version gratuite

4°)
Refais un scan FRST et donne les nouveaux rapports via pjjoint


0