

patrickgsxr
Membres-
Compteur de contenus
37 -
Inscription
-
Dernière visite
Type de contenu
Profils
Forums
Blogs
Tout ce qui a été posté par patrickgsxr
-
[Résolu] Virus BlackLed, ReduLed, Epictory
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
ok c'est noté et merci pour votre aide -
[Résolu] Virus BlackLed, ReduLed, Epictory
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
Je vais faire tout ça. En revanche, pour l'instant Avast se manifeste toujours 5 ou 6 fois à chaque démmarrage ou à chaque redémmarrage suite à une mise en veille. Il indique toujours Blackledinfo, Epictory .... -
[Résolu] Virus BlackLed, ReduLed, Epictory
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
En plus des deux précédents voici le rapport SFTGC http://cjoint.com/?EBfvF6cSzeG -
[Résolu] Virus BlackLed, ReduLed, Epictory
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
lien ZHPFix : http://cjoint.com/?EBfvs0AmBel lien ZHP Cleaner : http://cjoint.com/?EBfvuRHL9ND -
[Résolu] Virus BlackLed, ReduLed, Epictory
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
Rapport adwcleaner : http://cjoint.com/?EBewHvJeEId Rapport Junkware Removal Tool: http://cjoint.com/?EBewI6yPgEg Rapport Shortcut cleaner : http://cjoint.com/?EBewLj9Ms6w Rapport ZHPDiag : http://cjoint.com/?EBewKmVhIY3 Rapport Malwarebytes Malwarebytes Anti-Malware www.malwarebytes.org Date de l'examen: 04/02/2015 Heure de l'examen: 21:30:40 Fichier journal: Administrateur: Oui Version: 2.00.4.1028 Base de données Malveillants: v2015.02.04.10 Base de données Rootkits: v2015.02.03.01 Licence: Gratuit Protection contre les malveillants: Désactivé(e) Protection contre les sites Web malveillants: Désactivé(e) Auto-protection: Désactivé(e) Système d'exploitation: Windows 8.1 Processeur: x64 Système de fichiers: NTFS Utilisateur: patrick Type d'examen: Examen "Menaces" Résultat: Terminé Objets analysés: 371576 Temps écoulé: 11 min, 6 sec Mémoire: Activé(e) Démarrage: Activé(e) Système de fichiers: Activé(e) Archives: Activé(e) Rootkits: Activé(e) Heuristique: Activé(e) PUP: Activé(e) PUM: Activé(e) Processus: 0 (Aucun élément malicieux detecté) Modules: 0 (Aucun élément malicieux detecté) Clés du Registre: 17 PUP.Optional.Vosteran, HKLM\SOFTWARE\CLASSES\APPID\{4CB3598A-82E8-4D1F-983F-061238AE696E}, Mis en quarantaine, [b06244d6e0aa1b1b2730fafff909f30d], PUP.Optional.Vosteran, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{4CB3598A-82E8-4D1F-983F-061238AE696E}, Mis en quarantaine, [b06244d6e0aa1b1b2730fafff909f30d], PUP.Optional.iGraal.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{240373D3-4199-4F41-BB4D-15D5B830C82D}, Mis en quarantaine, [be5419011d6d6dc933fc70cbcf3422de], PUP.Optional.iGraal.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{D5552947-6DFE-4278-9312-B763A59B4073}, Mis en quarantaine, [be5419011d6d6dc933fc70cbcf3422de], PUP.Optional.iGraal.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{62319ABC-B371-49D1-BDCC-F85826DB4AB9}, Mis en quarantaine, [be5419011d6d6dc933fc70cbcf3422de], PUP.Optional.iGraal.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{62319ABC-B371-49D1-BDCC-F85826DB4AB9}, Mis en quarantaine, [be5419011d6d6dc933fc70cbcf3422de], PUP.Optional.iGraal.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{D5552947-6DFE-4278-9312-B763A59B4073}, Mis en quarantaine, [be5419011d6d6dc933fc70cbcf3422de], PUP.Optional.iGraal.A, HKLM\SOFTWARE\CLASSES\iGraalBHO.IGraalBHOComponent, Mis en quarantaine, [be5419011d6d6dc933fc70cbcf3422de], PUP.Optional.iGraal.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\iGraalBHO.IGraalBHOComponent, Mis en quarantaine, [be5419011d6d6dc933fc70cbcf3422de], PUP.Optional.iGraal.A, HKLM\SOFTWARE\CLASSES\iGraalBHO.IGraalBHOComponent.1, Mis en quarantaine, [be5419011d6d6dc933fc70cbcf3422de], PUP.Optional.iGraal.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\iGraalBHO.IGraalBHOComponent.1, Mis en quarantaine, [be5419011d6d6dc933fc70cbcf3422de], PUP.Optional.iGraal.A, HKU\S-1-5-21-3091567084-3210032472-3026869250-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{240373D3-4199-4F41-BB4D-15D5B830C82D}, Mis en quarantaine, [be5419011d6d6dc933fc70cbcf3422de], PUP.Optional.iGraal.A, HKU\S-1-5-21-3091567084-3210032472-3026869250-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{240373D3-4199-4F41-BB4D-15D5B830C82D}, Mis en quarantaine, [be5419011d6d6dc933fc70cbcf3422de], PUP.Optional.RapidyWeb.A, HKLM\SOFTWARE\CLASSES\SimpleAdblock.SimpleAdblock, Mis en quarantaine, [29e98b8f92f8fb3b83db05f5986a659b], PUP.Optional.RapidyWeb.A, HKLM\SOFTWARE\CLASSES\SimpleAdblock.SimpleAdblock.1, Mis en quarantaine, [bf5326f45733df57fc62a9519072d42c], PUP.Optional.RapidyWeb.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SimpleAdblock.SimpleAdblock, Mis en quarantaine, [bf5326f45733df57fc62a9519072d42c], PUP.Optional.RapidyWeb.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SimpleAdblock.SimpleAdblock.1, Mis en quarantaine, [bf5326f45733df57fc62a9519072d42c], Valeurs du Registre: 3 PUP.Optional.Vosteran, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\WSE_Vosteran\\, Mis en quarantaine, [72a041d95f2b270f4e09c843f01558a8] PUP.Optional.GamesDesktop.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|gmsd_fr_60, Mis en quarantaine, [fe140e0c6b1fea4c3a0f2a6155ae9769], PUP.Optional.Vosteran, HKU\S-1-5-21-3091567084-3210032472-3026869250-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, Vosteran, Mis en quarantaine, [f41ef624aedc280e6d4ed8333acb34cc] Données du Registre: 0 (Aucun élément malicieux detecté) Dossiers: 1 Rogue.Multiple, C:\ProgramData\1887373585, Mis en quarantaine, [9e7464b61476e353c8c957e453b0c63a], Fichiers: 6 PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{df47b99d-26f5-45f4-85c5-97b4da365f21}Gw64.sys, Supprimé-au-redémarrage, [1ecc2f31440353e354f8184edd539b85], PUP.Optional.Iminent.A, C:\Users\patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ehhlaekjfiiojlddgndcnefflngfmhen_0.localstorage, Mis en quarantaine, [51c172a86921b4829e685f3d30d3f30d], PUP.Optional.Iminent.A, C:\Users\patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nbljechdpodpbchbmjcoamidppmpnmlc_0.localstorage, Mis en quarantaine, [1200f52531593afcb7505547e0237888], PUP.Optional.Iminent.A, C:\Users\patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jdkokpcldhneihjdhigfjmoeojkdcbmg_0.localstorage, Mis en quarantaine, [a2702af0ef9b0333d34e376dbd46946c], Rogue.Multiple, C:\ProgramData\1887373585\BIT2DD5.tmp, Mis en quarantaine, [9e7464b61476e353c8c957e453b0c63a], PUP.Optional.Trovi.A, C:\Users\patrick\AppData\Local\Google\Chrome\User Data\Default\Preferences, Bon: (), Mauvais: ({"apps":{"shortcuts_have_been_created":true},"browser":{"last_known_google_url":"https://www.google.fr/","last_prompted_google_url":"https://www.google.fr/","show_home_button":true,"window_placement":{"bottom":1030,"left":10,"maximized":false,"right":955,"top":10,"work_area_bottom":1040,"work_area_left":0,"work_area_right":1920,"work_area_top":0}},"countryid_at_install":18002,"default_apps_install_state":2,"default_search_provider":null,"default_search_provider_data":null,"extensions":{"alerts":{"initialized":true},"autoupdate":{"next_check":"13042823630137224"},"chrome_url_overrides":{"bookmarks":["chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html"]},"known_disabled":["gomekmidlodglbbmalcneegieacbdmki"],"last_chrome_version":"34.0.1847.116","settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"13039559111525176":"location","5":"manifest","C:\\Program Files (x86)\\Google\\Chrome\\Application\\33.0.1750.154\\resources\\web_store":"preferences","active_permissions":{"api":["management","webstorePrivate"],"manifest_permissions":"app_launcher_ordinal"},"creation_flags":1,"events":"from_bookmark","false":"bepbmhgboaologfdajaanbcjmnhjmhfn","incognito_preferences":"install_time","n":"path","regular_only_preferences":"was_installed_by_default","t":"content_settings","{\"app\":{\"launch\":{\"web_url\":\"https://chrome.google.com/webstore\"},\"urls\":[\"https://chrome.google.com/webstore\"]},\"description\":\"Chrome Web Store\",\"icons\":{\"128\":\"webstore_icon_128.png\",\"16\":\"webstore_icon_16.png\"},\"key\":\"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB\",\"name\":\"Google Store\",\"permissions\":[\"webstorePrivate\",\"management\"],\"version\":\"0.2\"}":"page_ordinal"},"plugins":{"migrated_to_pepper_flash":true,"plugins_list":"removed_old_component_pepper_flash_settings","true":"profile"},"{\"accept_languages\":\"fr-FR,fr,en-US,en\"}":"invalidator","{\"active_permissions\":{\"api\":[\"bookmarks\",\"bookmarkManagerPrivate\",\"metricsPrivate\",\"systemPrivate\",\"tabs\"],\"explicit_host\":[\"chrome://favicon/*\",\"chrome://resources/*\"],\"manifest_permissions\":\"content_settings\"},\"creation_flags\":1,\"events\":\"from_bookmark\",\"false\":\"incognito_content_settings\",\"incognito_preferences\":\"initial_keybindings_set\",\"true\":\"install_time\",\"13039559111525176\":\"location\",\"5\":\"manifest\",\"{\\\"chrome_url_overrides\\\":{\\\"bookmarks\\\":\\\"main.html\\\"},\\\"content_security_policy\\\":\\\"object-src 'none'; script-src chrome:\\\/\\\/resources 'self'\\\",\\\"description\\\":\\\"Bookmark Manager\\\",\\\"icons\\\":\\\"incognito\\\",\\\"split\\\":\\\"key\\\",\\\"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQcByy+eN9jzazWF\\\/DPn7NW47sW7lgmpk6eKc0BQM18q8hvEM3zNm2n7HkJv\\\/R6fU+X5mtqkDuKvq5skF6qqUF4oEyaleWDFhd1xFwV7JV+\\\/DU7bZ00w2+6gzqsabkerFpoP33ZRIw7OviJenP0c0uWqDWF8EGSyMhB3txqhOtiQIDAQAB\\\":\\\"manifest_version\\\",\\\"2\\\":\\\"name\\\",\\\"Bookmark Manager\\\":\\\"permissions\\\",\\\"[\\\\\\\"bookmarks\\\\\\\",\\\\\\\"bookmarkManagerPrivate\\\\\\\",\\\\\\\"metricsPrivate\\\\\\\",\\\\\\\"systemPrivate\\\\\\\",\\\\\\\"tabs\\\\\\\",\\\\\\\"chrome:\\\\\\\\\\\/\\\\\\\\\\\/favicon\\\\\\\\\\\/\\\\\\\",\\\\\\\"chrome:\\\\\\\\\\\/\\\\\\\\\\\/resources\\\\\\\\\\\/\\\\\\\"]\\\":\\\"version\\\",\\\"0.1\\\":\\\"path\\\"}\":\"C:\\\\Program Files (x86)\\\\Google\\\\Chrome\\\\Application\\\\33.0.1750.154\\\\resources\\\\bookmark_manager\",\"preferences\":\"regular_only_preferences\",\"was_installed_by_default\":false,\"ennkphjdgehloodpbhlhldgbnhmacadg\":{\"active_permissions\":{\"api\":\"explicit_host\",\"[\\\"chrome:\\\/\\\/settings-frame\\\/*\\\"]\":\"manifest_permissions\"},\"content_settings\":\"creation_flags\",\"1\":\"events\",\"[\\\"app.runtime.onLaunched\\\"]\":\"from_bookmark\",\"incognito_preferences\":\"initial_keybindings_set\",\"13039559111529176\":\"location\",\"5\":\"manifest\",\"{\\\"app\\\":{\\\"background\\\":{\\\"scripts\\\":[\\\"settings_app.js\\\"]}},\\\"description\\\":\\\"Settings\\\",\\\"display_in_launcher\\\":false,\\\"icons\\\":{\\\"128\\\":\\\"settings_app_icon_128.png\\\",\\\"16\\\":\\\"settings_app_icon_16.png\\\",\\\"32\\\":\\\"settings_app_icon_32.png\\\",\\\"48\\\":\\\"settings_app_icon_48.png\\\"},\\\"key\\\":\\\"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDoVDPGX6fvKPVVgc+gnkYlGqHuuapgFDyKhsy4z7UzRLO\\\/95zXPv8h8e5EacqbAQJLUbP6DERH5jowyNEYVxq9GJyntJMwP1ejvoz\\\/52hnY3CCGGCmttmKzzpp5zwLuq3iZf8bslwywfflNUYtaCFSDa0TtrBZz0aOPrAAd\\\/AhNwIDAQAB\\\",\\\"manifest_version\\\":2,\\\"name\\\":\\\"Settings\\\",\\\"permissions\\\":[\\\"chrome:\\\/\\\/settings-frame\\\/\\\"],\\\"version\\\":\\\"0.2\\\"}\":\"path\",\"C:\\\\Program Files (x86)\\\\Google\\\\Chrome\\\\Application\\\\33.0.1750.154\\\\resources\\\\settings_app\":\"preferences\",\"regular_only_preferences\":\"running\",\"true\":\"was_installed_by_default\",\"false\":\"gfdkimpbcpahaombhbimeihdjnejgicl\"}}":{"active_permissions":{"api":["feedbackPrivate"],"explicit_host":["chrome://resources/*"],"manifest_permissions":"content_settings"},"creation_flags":1,"events":["feedbackPrivate.onFeedbackRequested"],"from_bookmark":false,"from_webstore":false,"gomekmidlodglbbmalcneegieacbdmki":{"0":"was_installed_by_default","13042796392171886":"location","13042823091070886":"lastpingday","3":"manifest","ack_external":true,"active_permissions":{"api":["cookies","tabs","webNavigation","webRequest","webRequestBlocking","webRequestInternal"],"explicit_host":["*://*.avast.com/*","http://*/*","https://*/*"],"manifest_permissions":"content_settings"},"creation_flags":1,"disable_reasons":1,"events":"external_first_run","false":"mfehgcgbbipciphmccgaenjidiccnmng","gomekmidlodglbbmalcneegieacbdmki\\9.0.2016.82_0":"preferences","incognito_preferences":"initial_keybindings_set","regular_only_preferences":"state","true":"install_time","{\"background\":{\"scripts\":[\"common/libs/protobuf.js\",\"common/libs/wrc_gpb.js\",\"common/libs/lodash.js\",\"common/libs/jquery-1.5.2.js\",\"common/libs/query.js\",\"common/libs/avastwrc.js\",\"scripts/aos.js\",\"common/scripts/bal.js\",\"scripts/background.js\"]},\"browser_action\":{\"default_icon\":\"common/skin/img/icn_extensiontop.png\",\"default_title\":\"avast! Online Security\"},\"current_locale\":\"fr\",\"default_locale\":\"en\",\"description\":\"Avast Browser Security and Web Reputation Plugin.\",\"icons\":{\"128\":\"common/skin/img/icon128.png\",\"256\":\"common/skin/img/icon256.png\",\"48\":\"common/skin/img/icon48.png\",\"64\":\"common/skin/img/icon64.png\"},\"key\":\"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDWStseB5KE8Vqukt6RkFc3NirSBRmBTKvNolNhsOo5Q/kUlJs1pajaMckUR5rJXlpzvxfvesfNlASR/QnHKdlGBxPlyi5dxN+nohCclJYf5dXVq2ndj2ykgd++rs1qD35tw3R2v5BaeTmLgP2G/Jd53BaJXDNTGIusbkGEhvZ2rQIDAQAB\",\"manifest_version\":2,\"name\":\"avast! Online Security\",\"options_page\":\"options.html\",\"permissions\":[\"cookies\",\"*://*.avast.com/*\",\"http://*/*\",\"https://*/*\",\"tabs\",\"webNavigation\",\"webRequest\",\"webRequestBlocking\"],\"update_url\":\"https://clients2.google.com/service/update2/crx\",\"version\":\"9.0.2016.82\",\"web_accessible_resources\":[\"common/skin/*\",\"common/skin/img/*\",\"common/skin/css/*\",\"common/mocks/*\"]}":"path"},"incognito_content_settings":"incognito_preferences","initial_keybindings_set":true,"install_time":"13039559111529176","location":5,"manifest":{"app":{"background":{"scripts":["js/event_handler.js"]},"content_security_policy":"default-src 'none'; script-src 'self' chrome://resources; style-src 'unsafe-inline' *; img-src *; media-src 'self'"},"description":"User feedback extension","display_in_launcher":false,"display_in_new_tab_page":false,"icons":{"32":"images/icon32.png","64":"images/icon64.png"},"incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMZElzFX2J1g1nRQ/8S3rg/1CjFyDltWOxQg+9M8aVgNVxbutEWFQz+oQzIP9BB67mJifULgiv12ToFKsae4NpEUR8sPZjiKDIHumc6pUdixOm8SJ5Rs16SMR6+VYxFUjlVW+5CA3IILptmNBxgpfyqoK0qRpBDIhGk1KDEZ4zqQIDAQAB","manifest_version":2,"name":"Feedback","permissions":["feedbackPrivate","chrome://resources/"],"version":"1.0"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\33.0.1750.154\\resources\\feedback","preferences":"regular_only_preferences","running":true,"was_installed_by_default":false},"{\"active_permissions\":{\"api\":[\"cloudPrintPrivate\"],\"manifest_permissions\":\"content_settings\"},\"creation_flags\":1,\"events\":\"from_bookmark\",\"false\":\"incognito_content_settings\",\"incognito_preferences\":\"install_time\",\"13039559111525176\":\"location\",\"5\":\"manifest\",\"{\\\"app\\\":{\\\"launch\\\":{\\\"web_url\\\":\\\"https:\\\/\\\/www.google.com\\\/cloudprint\\\"},\\\"urls\\\":[\\\"https:\\\/\\\/www.google.com\\\/cloudprint\\\/enable_chrome_connector\\\"]},\\\"description\\\":\\\"Cloud Print\\\",\\\"display_in_launcher\\\":false,\\\"icons\\\":\\\"key\\\",\\\"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqOhnwk4+HXVfGyaNsAQdU\\\/js1Na56diW08oF1MhZiwzSnJsEaeuMN9od9q9N4ZdK3o1xXOSARrYdE+syV7Dl31nf6qz3A6K+D5NHe6sSB9yvYlIiN37jdWdrfxxE0pRYEVYZNTe3bzq3NkcYJlOdt1UPcpJB+isXpAGUKUvt7EQIDAQAB\\\":\\\"name\\\",\\\"Cloud Print\\\":\\\"permissions\\\",\\\"[\\\\\\\"cloudPrintPrivate\\\\\\\"]\\\":\\\"version\\\",\\\"0.1\\\":\\\"path\\\"}\":\"C:\\\\Program Files (x86)\\\\Google\\\\Chrome\\\\Application\\\\33.0.1750.154\\\\resources\\\\cloud_print\",\"preferences\":\"regular_only_preferences\",\"was_installed_by_default\":false,\"mgndgikekgjfcpckkfioiadnlibdjbkf\":{\"active_permissions\":{\"api\":\"manifest_permissions\"},\"app_launcher_ordinal\":\"n\",\"content_settings\":\"creation_flags\",\"1\":\"events\",\"from_bookmark\":false,\"from_webstore\":false,\"incognito_content_settings\":\"incognito_preferences\",\"install_time\":\"13039559111529176\",\"location\":5,\"manifest\":{\"app\":{\"launch\":{\"web_url\":\"http://THIS-WILL-BE-REPLACED\"}},\"description\":\"Chrome as an app\",\"display_in_launcher\":true,\"display_in_new_tab_page\":false,\"icons\":{\"128\":\"product_logo_128.png\",\"16\":\"product_logo_16.png\"},\"key\":\"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNuYLEQ1QPMcc5HfWI/9jiEf6FdJWqEtgRmIeI7qtjPLBM5oje+Ny2E2mTAhou5qdJiO2CHWdU1DQXY2F7Zu2gZaKZgHLfK4WimHxUT5Xd9/aro/R9PCzjguM1BLusiWYc9xlj1IsZpyiN1hcjU7SCnBhv1feQlv2WSB5KRiXwhQIDAQAB\",\"name\":\"Chrome\",\"version\":\"0.1\"},\"page_ordinal\":\"n\",\"path\":\"C:\\\\Program Files (x86)\\\\Google\\\\Chrome\\\\Application\\\\33.0.1750.154\\\\resources\\\\chrome_app\",\"preferences\":\"regular_only_preferences\",\"was_installed_by_default\":false}}":"neajdppkdcdipfabeoofebfddakdcjhd","{\"active_permissions\":{\"api\":[\"systemPrivate\",\"ttsEngine\"],\"explicit_host\":[\"https://www.google.com/*\"],\"manifest_permissions\":\"content_settings\"},\"creation_flags\":1,\"events\":[\"ttsEngine.onPause\",\"ttsEngine.onResume\",\"ttsEngine.onSpeak\",\"ttsEngine.onStop\"],\"from_bookmark\":false,\"from_webstore\":false,\"incognito_content_settings\":\"incognito_preferences\",\"initial_keybindings_set\":true,\"install_time\":\"13039559111529176\",\"location\":5,\"manifest\":{\"background\":{\"persistent\":false,\"scripts\":[\"tts_extension.js\"]},\"description\":\"Component extension providing speech via the Google network text-to-speech service.\",\"key\":\"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8GSbNUMGygqQTNDMFGIjZNcwXsHLzkNkHjWbuY37PbNdSDZ4VqlVjzbWqODSe+MjELdv5Keb51IdytnoGYXBMyqKmWpUrg+RnKvQ5ibWr4MW9pyIceOIdp9GrzC1WZGgTmZismYR3AjaIpufZ7xDdQQv+XrghPWCkdVqLN+qZDA1HU+DURznkMICiDDSH2sU0egm9UbWfS218bZqzKeQDiC3OnTPlaxcbJtKUuupIm5knjze3Wo9Ae9poTDMzKgchg0VlFCv3uqox+wlD8sjXBoyBCCK9HpImdVAF1a7jpdgiUHpPeV/26oYzM9/grltwNR3bzECQgSpyXp0eyoegwIDAQAB\",\"manifest_version\":2,\"name\":\"Google Network Speech\",\"permissions\":[\"systemPrivate\",\"ttsEngine\",\"https://www.google.com/\"],\"tts_engine\":{\"voices\":[{\"event_types\":[\"start\",\"end\",\"error\"],\"gender\":\"female\",\"lang\":\"en-US\",\"remote\":true,\"voice_name\":\"Google US English\"},{\"event_types\":[\"start\",\"end\",\"error\"],\"gender\":\"male\",\"lang\":\"en-GB\",\"remote\":true,\"voice_name\":\"Google UK English Male\"},{\"event_types\":[\"start\",\"end\",\"error\"],\"gender\":\"female\",\"lang\":\"en-GB\",\"remote\":true,\"voice_name\":\"Google UK English Female\"},{\"event_types\":[\"start\",\"end\",\"error\"],\"gender\":\"female\",\"lang\":\"es-ES\",\"remote\":true,\"voice_name\":\"Google Español\"},{\"event_types\":[\"start\",\"end\",\"error\"],\"gender\":\"female\",\"lang\":\"fr-FR\",\"remote\":true,\"voice_name\":\"Google Français\"},{\"event_types\":[\"start\",\"end\",\"error\"],\"gender\":\"female\",\"lang\":\"it-IT\",\"remote\":true,\"voice_name\":\"Google Italiano\"},{\"event_types\":[\"start\",\"end\",\"error\"],\"gender\":\"female\",\"lang\":\"de-DE\",\"remote\":true,\"voice_name\":\"Google Deutsch\"},{\"event_types\":[\"start\",\"end\",\"error\"],\"gender\":\"female\",\"lang\":\"ja-JP\",\"remote\":true,\"voice_name\":\"Google \\u65e5\\u672c\\u4eba\"},{\"event_types\":[\"start\",\"end\",\"error\"],\"gender\":\"female\",\"lang\":\"ko-KR\",\"remote\":true,\"voice_name\":\"Google \\ud55c\\uad6d\\uc758\"},{\"event_types\":[\"start\",\"end\",\"error\"],\"gender\":\"female\",\"lang\":\"zh-CN\",\"remote\":true,\"voice_name\":\"Google \\u4e2d\\u56fd\的\"}]},\"version\":\"1.0\"},\"path\":\"C:\\\\Program Files (x86)\\\\Google\\\\Chrome\\\\Application\\\\33.0.1750.154\\\\resources\\\\network_speech_synthesis\",\"preferences\":\"regular_only_preferences\",\"was_installed_by_default\":false,\"nkeimhogjdpnpccoofpliimaahmaaome\":{\"active_permissions\":{\"api\":[\"alarms\",\"desktopCapture\",\"webConnectable\",\"webrtcAudioPrivate\",\"webrtcLoggingPrivate\",\"system.cpu\"],\"manifest_permissions\":\"content_settings\"},\"creation_flags\":1,\"events\":[\"alarms.onAlarm\",\"runtime.onStartup\"],\"from_bookmark\":false,\"from_webstore\":false,\"incognito_content_settings\":\"incognito_preferences\",\"initial_keybindings_set\":true,\"install_time\":\"13039559111529176\",\"location\":5,\"manifest\":{\"background\":{\"page\":\"background.html\",\"persistent\":false},\"externally_connectable\":{\"matches\":[\"https://*.google.com/hangouts*\",\"*://localhost/*\"]},\"key\":\"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDAQt2ZDdPfoSe/JI6ID5bgLHRCnCu9T36aYczmhw/tnv6QZB2I6WnOCMZXJZlRdqWc7w9jo4BWhYS50Vb4weMfh/I0On7VcRwJUgfAxW2cHB+EkmtI1v4v/OU24OqIa1Nmv9uRVeX0GjhQukdLNhAE6ACWooaf5kqKlCeK+1GOkQIDAQAB\",\"manifest_version\":2,\"name\":\"Hangout Services\",\"permissions\":[\"alarms\",\"desktopCapture\",\"system.cpu\",\"webrtcAudioPrivate\",\"webrtcLoggingPrivate\"],\"version\":\"1.0\"},\"path\":\"C:\\\\Program Files (x86)\\\\Google\\\\Chrome\\\\Application\\\\33.0.1750.154\\\\resources\\\\hangout_services\",\"preferences\":\"regular_only_preferences\",\"was_installed_by_default\":false,\"nmmhkkegccagdldgiimedpiccmgmieda\":{\"ack_external\":true,\"active_permissions\":{\"api\":[\"identity\",\"webRequestInternal\",\"webview\"],\"explicit_host\":[\"https://checkout.google.com/*\",\"https://sandbox.google.com/*\",\"https://www.google.com/*\",\"https://www.googleapis.com/*\"],\"manifest_permissions\":\"content_settings\"},\"creation_flags\":137,\"events\":[\"app.runtime.onLaunched\"],\"from_bookmark\":false,\"from_webstore\":true,\"incognito_content_settings\":\"incognito_preferences\",\"initial_keybindings_set\":true,\"install_time\":\"13042823090823886\",\"lastpingday\":\"13042796392171886\",\"location\":10,\"manifest\":{\"app\":{\"background\":{\"scripts\":[\"craw_background.js\"]}},\"current_locale\":\"fr\",\"default_locale\":\"en\",\"description\":\"Google Wallet pour le contenu numérique\",\"display_in_launcher\":false,\"display_in_new_tab_page\":false,\"icons\":{\"128\":\"images/icon_128.png\",\"16\":\"images/icon_16.png\"},\"key\":\"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCrKfMnLqViEyokd1wk57FxJtW2XXpGXzIHBzv9vQI/01UsuP0IV5/lj0wx7zJ/xcibUgDeIxobvv9XD+zO1MdjMWuqJFcKuSS4Suqkje6u+pMrTSGOSHq1bmBVh0kpToN8YoJs/P/yrRd7FEtAXTaFTGxQL4C385MeXSjaQfiRiQIDAQAB\",\"manifest_version\":2,\"minimum_chrome_version\":\"29\",\"name\":\"Google Wallet\",\"oauth2\":{\"auto_approve\":true,\"client_id\":\"203784468217.apps.googleusercontent.com\",\"scopes\":[\"https://www.googleapis.com/auth/sierra\",\"https://www.googleapis.com/auth/sierrasandbox\",\"https://www.googleapis.com/auth/chromewebstore\",\"https://www.googleapis.com/auth/chromewebstore.readonly\"]},\"permissions\":[\"identity\",\"webview\",\"https://checkout.google.com/\",\"https://sandbox.google.com/checkout/\",\"https://www.google.com/\",\"https://www.googleapis.com/*\"],\"update_url\":\"https://clients2.google.com/service/update2/crx\",\"version\":\"0.0.6.1\"},\"path\":\"nmmhkkegccagdldgiimedpiccmgmieda\\\\0.0.6.1_1\",\"preferences\":\"regular_only_preferences\",\"running\":true,\"state\":1,\"was_installed_by_default\":true,\"google\":{\"services\":{\"signin\":{\"LSID\":\"\",\"SID\":\"\"}}}}}}":"intl","{\"avatar_index\":0,\"content_settings\":{\"clear_on_exit_migrated\":true,\"pattern_pairs\":\"pref_version\",\"1\":\"exit_type\"},\"Normal\":\"exited_cleanly\",\"true\":\"icon_version\",\"2\":\"managed_user_id\",\"\":\"name\",\"Premier utilisateur\":\"session\"}":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13039559111473176"},"{\"client_id\":\"Dx8iHiT2KHqR6ez3OXiRNQ==\"}":"media","{\"device_id_salt\":\"J0kVxPQ4qUeVFBzonDOSlQ==\"}":"net","{\"disable_reasons\":1,\"state\":0}":"eemcgdkfndhakfknompkggombfjjjeno","{\"http_server_properties\":{\"servers\":{\"clients2.google.com:443\":{\"alternate_protocol\":{\"port\":443,\"protocol_str\":\"quic\"},\"supports_spdy\":true},\"clients2.googleusercontent.com:443\":{\"alternate_protocol\":{\"port\":443,\"protocol_str\":\"quic\"},\"supports_spdy\":true},\"www.google.com:443\":{\"alternate_protocol\":{\"port\":443,\"protocol_str\":\"quic\"},\"settings\":{\"4\":100,\"5\":32,\"6\":0},\"supports_spdy\":true}},\"version\":2}}":"pinned_tabs"}},"homepage":"http://www.trovi.com/?gd=&ctid=CT3324803&octid=EB_ORIGINAL_CTID&ISID=M7BA5ADCC-2437-4E5F-927D-D5F1FCEC58FB&SearchSource=55&CUI=&UM=8&UP=SP942EB53A-A852-48F6-BC36-3E439BB43AF1&SSPV=","homepage_is_newtabpage":false,"null":null,"profile":null,"session":{"restore_on_startup":4,"startup_urls":[],"urls_to_restore_on_startup":null},"translate_blocked_languages":["fr"],"translate_whitelists":null}), Remplacé,[49c99684e9a15ed865314e9e15f030d0] Secteurs physiques: 0 (Aucun élément malicieux detecté) (end) -
[Résolu] Virus BlackLed, ReduLed, Epictory
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
Pouvez vous me renvoyer ce message avec les liens de chargement actifs: exemple 3)Téléchargez Malwarebytes Anti-Malware Ici ou là: les liens ne sont pas actifs pour télécharger -
[Résolu] Virus BlackLed, ReduLed, Epictory
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
Voici le rapport txt http://cjoint.com/?EBdv0t9Ze72 -
[Résolu] Virus BlackLed, ReduLed, Epictory
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
Merci, je fais cela dès que je rentre du bureau -
[Résolu] Virus BlackLed, ReduLed, Epictory
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
Erreur ce n'est pas Norton mais Avast qui bloque ces virus -
[Résolu] Virus BlackLed, ReduLed, Epictory
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
J'ai 3 rapports à votre disposition : - FRST.txt -addition.txt - shortcut.txt les souhaitez vous et comment vous les transmettre ? -
[Résolu] Virus BlackLed, ReduLed, Epictory
patrickgsxr a posté un sujet dans Analyses et éradication malwares
Bonjour, à chaque démarrage Norton bloque ses différents virus. comment les supprimer -
[Résolu] Fenêtre intempestive Adsrvmedia
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
Tout d'abord un grand merci pour votre aide et votree patience. Je clotûre le dossier selon le protocole décrit ci dessus merci encore -
[Résolu] Fenêtre intempestive Adsrvmedia
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
Je n'arrive pas à charger SFTGC Pour désactiver les protections résidentes on me dit de faire un clic droit sur l'icone a coté de l'horloge et je ne le trouve pas HELP!!! -
[Résolu] Fenêtre intempestive Adsrvmedia
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
le rapport ZHPFIX http://cjoint.com/?DLctdTRj2Vw -
[Résolu] Fenêtre intempestive Adsrvmedia
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
le rapport sc http://cjoint.com/?DLbvmDeBLEE le rapport zhpdiag http://cjoint.com/?DLbvi4q51nw -
[Résolu] Fenêtre intempestive Adsrvmedia
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
rapport adw http://cjoint.com/?DLbuQ4Qwh38 Rapport jrt http://cjoint.com/?DLbuSCkrswE rapport mbam Malwarebytes Anti-Malware www.malwarebytes.org Date de l'examen: 01/12/2014 Heure de l'examen: 19:51:44 Fichier journal: Administrateur: Oui Version: 2.00.3.1025 Base de données Malveillants: v2014.12.01.06 Base de données Rootkits: v2014.12.01.02 Licence: Gratuit Protection contre les malveillants: Désactivé(e) Protection contre les sites Web malveillants: Désactivé(e) Auto-protection: Désactivé(e) Système d'exploitation: Windows 8.1 Processeur: x64 Système de fichiers: NTFS Utilisateur: patrick Type d'examen: Examen "Menaces" Résultat: Terminé Objets analysés: 357514 Temps écoulé: 8 min, 6 sec Mémoire: Activé(e) Démarrage: Activé(e) Système de fichiers: Activé(e) Archives: Activé(e) Rootkits: Activé(e) Heuristique: Activé(e) PUP: Activé(e) PUM: Activé(e) Processus: 7 PUP.Optional.StormAlert.A, C:\ProgramData\QVXsvlJuyce\NDtfPElj.exe, 2596, Supprimé-au-redémarrage, [3d6c93caa8d4a591b498539b06fb2cd4] PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\updateHoldPage.exe, 2388, Supprimé-au-redémarrage, [b9f09fbebcc0e1554c2c599245bca060] PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\utilHoldPage.exe, 4832, Supprimé-au-redémarrage, [1d8c5b021a62181e27519b50f20fea16] PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.BrowserAdapter.exe, 3740, Supprimé-au-redémarrage, [f1b826373844f640a71b95abcd3617e9] PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.BrowserAdapter64.exe, 6080, Supprimé-au-redémarrage, [f1b826373844f640a71b95abcd3617e9] PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.expext.exe, 5276, Supprimé-au-redémarrage, [f1b826373844f640a71b95abcd3617e9] PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.PurBrowse64.exe, 3056, Supprimé-au-redémarrage, [f1b826373844f640a71b95abcd3617e9] Modules: 2 PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.expextdll.dll, Supprimé-au-redémarrage, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\{df47b99d-26f5-45f4-85c5-97b4da365f21}.dll, Supprimé-au-redémarrage, [f1b826373844f640a71b95abcd3617e9], Clés du Registre: 31 PUP.Optional.StormAlert.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NDtfPElj, Mis en quarantaine, [3d6c93caa8d4a591b498539b06fb2cd4], PUP.Optional.HoldPage.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Hold Page, Mis en quarantaine, [b9f09fbebcc0e1554c2c599245bca060], PUP.Optional.HoldPage.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util Hold Page, Mis en quarantaine, [1d8c5b021a62181e27519b50f20fea16], PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, Mis en quarantaine, [06a32637601ccb6b5c8178855aa828d8], PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, Mis en quarantaine, [06a32637601ccb6b5c8178855aa828d8], PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6c14185e-4de6-4a79-985b-19f23fd1e638}, Mis en quarantaine, [bced1c419ae256e0550d8e3342c0f709], PUP.Optional.HoldPage.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{180BD92C-7EC0-4CF9-9329-7CEA0405B796}, Mis en quarantaine, [bced1c419ae256e0550d8e3342c0f709], PUP.Optional.HoldPage.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9B0B3C08-2AC3-43AD-AC78-3DB45181A1E1}, Mis en quarantaine, [bced1c419ae256e0550d8e3342c0f709], PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9B0B3C08-2AC3-43AD-AC78-3DB45181A1E1}, Mis en quarantaine, [bced1c419ae256e0550d8e3342c0f709], PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{180BD92C-7EC0-4CF9-9329-7CEA0405B796}, Mis en quarantaine, [bced1c419ae256e0550d8e3342c0f709], PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{6C14185E-4DE6-4A79-985B-19F23FD1E638}, Mis en quarantaine, [bced1c419ae256e0550d8e3342c0f709], PUP.Optional.HoldPage.A, HKU\S-1-5-21-3091567084-3210032472-3026869250-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{6C14185E-4DE6-4A79-985B-19F23FD1E638}, Mis en quarantaine, [bced1c419ae256e0550d8e3342c0f709], PUP.Optional.HoldPage.A, HKU\S-1-5-21-3091567084-3210032472-3026869250-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{6C14185E-4DE6-4A79-985B-19F23FD1E638}, Mis en quarantaine, [bced1c419ae256e0550d8e3342c0f709], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\TYPELIB\{157B1AA6-3E5C-404A-9118-C1D91F537040}, Mis en quarantaine, [02a705584d2f84b2be7723a021e1629e], PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{157B1AA6-3E5C-404A-9118-C1D91F537040}, Mis en quarantaine, [02a705584d2f84b2be7723a021e1629e], PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{df47b99d-26f5-45f4-85c5-97b4da365f21}Gw64, Mis en quarantaine, [c6e30b520d6f171f0d64c98ff50eb749], PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\Hold Page, Mis en quarantaine, [9a0ff26bc4b82511ed5ba3a0df240ef2], PUP.Optional.InstallCore.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLCORE\WSE_Vosteran, Mis en quarantaine, [b3f666f73f3d2610511b0545af54f808], PUP.Optional.HoldPage.A, HKU\S-1-5-21-3091567084-3210032472-3026869250-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Hold Page, Mis en quarantaine, [b0f985d806761224c87fbf84d92ab44c], PUP.Optional.Vosteran.A, HKU\S-1-5-21-3091567084-3210032472-3026869250-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\wse_vosteran, Mis en quarantaine, [1d8c86d715670f278b3f0bb555af1be5], PUP.Optional.InstallCore.A, HKU\S-1-5-21-3091567084-3210032472-3026869250-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Mis en quarantaine, [4d5c4b12cdafa690299e8ff2897a58a8], PUP.Optional.InstallCore.A, HKU\S-1-5-21-3091567084-3210032472-3026869250-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Mis en quarantaine, [6742a3baa7d5e2540ce2286f04007789], PUP.Optional.HoldPage.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Hold Page, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, HKLM\SOFTWARE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], Valeurs du Registre: 1 PUP.Optional.InstallCore.A, HKU\S-1-5-21-3091567084-3210032472-3026869250-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0Z1B1L2Z1S, Mis en quarantaine, [6742a3baa7d5e2540ce2286f04007789] Données du Registre: 0 (Aucun élément malicieux detecté) Dossiers: 8 PUP.Optional.StormAlert.A, C:\Users\patrick\AppData\Local\StormAlert, Mis en quarantaine, [7336134a1963d75fee3091b6b053b050], Rogue.Multiple, C:\ProgramData\600440862, Mis en quarantaine, [4d5c332a2854280eaa39a35ee51edf21], PUP.Optional.Vosteran.A, C:\Users\patrick\AppData\Roaming\WSE_Vosteran, Supprimé-au-redémarrage, [8128c7969ddf5ed8eb66a59bab58946c], PUP.Optional.Vosteran.A, C:\Users\patrick\AppData\Roaming\WSE_Vosteran\UpdateProc, Supprimé-au-redémarrage, [8128c7969ddf5ed8eb66a59bab58946c], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page, Supprimé-au-redémarrage, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin, Supprimé-au-redémarrage, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\TEMP, Supprimé-au-redémarrage, [f1b826373844f640a71b95abcd3617e9], Fichiers: 45 PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{df47b99d-26f5-45f4-85c5-97b4da365f21}Gw64.sys, Remplacé-au-redémarrage, , PUP.Optional.StormAlert.A, C:\ProgramData\QVXsvlJuyce\NDtfPElj.exe, Supprimé-au-redémarrage, [3d6c93caa8d4a591b498539b06fb2cd4], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\updateHoldPage.exe, Supprimé-au-redémarrage, [b9f09fbebcc0e1554c2c599245bca060], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\utilHoldPage.exe, Supprimé-au-redémarrage, [1d8c5b021a62181e27519b50f20fea16], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\HoldPagebho.dll, Mis en quarantaine, [bced1c419ae256e0550d8e3342c0f709], PUP.Optional.StormAlert.A, C:\ProgramData\QVXsvlJuyce\dat\FpIvnnavfP.exe, Supprimé-au-redémarrage, [54555d00e49843f3e06c22cc4fb204fc], PUP.Optional.StormAlert.A, C:\ProgramData\QVXsvlJuyce\dat\PeTbHH.exe, Supprimé-au-redémarrage, [abfe9ac3483448eebf8d3db18b76ca36], PUP.Optional.HealthAlert.A, C:\ProgramData\QVXsvlJuyce\dat\UDuLPqrLSU.dll, Supprimé-au-redémarrage, [2c7d66f7d2aa181ea32a95b749bc1ce4], PUP.Optional.BPlug, C:\Users\patrick\AppData\Local\Temp\is765589038\1FBF57E8_stp.EXE, Mis en quarantaine, [bdec88d54c302214f62306c0728f5aa6], PUP.Optional.BundleInstaller.A, C:\Users\patrick\AppData\Local\Temp\is765589038\30E4230C_stp.EXE, Mis en quarantaine, [a20763faef8d8aac2eb820f9ed188c74], PUP.Optional.StormAlert.A, C:\Users\patrick\AppData\Local\StormAlert\data2.dat, Mis en quarantaine, [7336134a1963d75fee3091b6b053b050], PUP.Optional.Vosteran.A, C:\Windows\Tasks\WSE_Vosteran.job, Mis en quarantaine, [7a2fe8752e4e5fd74d7a5b657e8615eb], PUP.Optional.Vosteran.A, C:\Windows\System32\Tasks\WSE_Vosteran, Mis en quarantaine, [2089223b8eee1a1cccfc843c8c786e92], PUP.Optional.Vosteran.A, C:\Users\patrick\AppData\Roaming\Mozilla\Firefox\Profiles\zktu6d2j.default\searchplugins\Vosteran.xml, Mis en quarantaine, [3376bda06c102d09c00dfec20bf99d63], Rogue.Multiple, C:\ProgramData\600440862\BITAAC9.tmp, Mis en quarantaine, [4d5c332a2854280eaa39a35ee51edf21], PUP.Optional.Vosteran.A, C:\Users\patrick\AppData\Roaming\WSE_Vosteran\UpdateProc\UpdateTask.exe, Supprimé-au-redémarrage, [8128c7969ddf5ed8eb66a59bab58946c], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\0, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\HoldPage.ico, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\HoldPageUninstall.exe, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\updateHoldPage.InstallState, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\4zmac3ar.4rx, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\7za.exe, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\BrowserAdapter.7z, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\df47b99d26f545f485c5.dll, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\df47b99d26f545f485c564.dll, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.BrowserAdapter.exe, Supprimé-au-redémarrage, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.BrowserAdapter64.exe, Supprimé-au-redémarrage, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.expext.exe, Supprimé-au-redémarrage, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.expext.zip, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.expextdll.dll, Supprimé-au-redémarrage, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.PurBrowse64.exe, Supprimé-au-redémarrage, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.PurBrowseG.zip, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\m1xio0o4.r0c, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\sqlite3.dll, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\utilHoldPage.InstallState, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\{df47b99d-26f5-45f4-85c5-97b4da365f21}.dll, Supprimé-au-redémarrage, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\{df47b99d-26f5-45f4-85c5-97b4da365f21}64.dll, Supprimé-au-redémarrage, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.Bromon.dll, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.BroStats.dll, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.BrowserAdapter.dll, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.CompatibilityChecker.dll, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.ExpExt.dll, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.FFUpdate.dll, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.GCUpdate.dll, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.IEUpdate.dll, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.PurBrowseG.dll, Mis en quarantaine, [f1b826373844f640a71b95abcd3617e9], Secteurs physiques: 0 (Aucun élément malicieux detecté) (end) -
[Résolu] Fenêtre intempestive Adsrvmedia
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
C'est noté je vous fait tout ça dès 17H30 quand je rentre à la maison -
[Résolu] Fenêtre intempestive Adsrvmedia
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
pouvez vous exploiter ce lien ? -
[Résolu] Fenêtre intempestive Adsrvmedia
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
voici le lien "tapé" http://cjoint.com/?DKEtrHu7JgU -
[Résolu] Fenêtre intempestive Adsrvmedia
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
Je suis confus il n'y a pas moyen de coller ni avec la fonction coller ni avec ctrl+c est-ce que je peux "taper le lien" -
[Résolu] Fenêtre intempestive Adsrvmedia
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
Tout d'abord un grand merci la génération du lien s'est bien faite, je l'ai copié pais je n'arrive pas à la coller dans le message Quand je suis sur le message la fonction collée n'est pas possible (je suis sous ie) que dois je faire -
[Résolu] Fenêtre intempestive Adsrvmedia
patrickgsxr a posté un sujet dans Analyses et éradication malwares
Bonjour, sous ie dès le début de la navigation, des fenêtres s'affichent. Elles sont du type "astuces PC" ... et souvent apparaît "adsvrmedia" merci de votre aide -
PC lent ayant besoin d'un nettoyage
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
Bonjour, je vais réinitialiser le navigateur comme tu me le préconises Je dispose d'office 2003 et j'ai l'intantion de l'installer en remplacement d'office 2000 Cela mettra fin à mes problèmes de mise à jour d'office 2000 Question : est-il préférable que je désinstalle office 2000 avant d'installer la version 2003 ou bien je l'installe directement ? -
PC lent ayant besoin d'un nettoyage
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
Bonjour ok je vais voir sur le forum SOFTWARE Pour les redirections il y a du mieux. J'utilise généralement ie -
PC lent ayant besoin d'un nettoyage
patrickgsxr a répondu à un(e) sujet de patrickgsxr dans Analyses et éradication malwares
Apo, tout d'abord je n'ai pas réussi à faire les mises à jour.word2000, excel2000, powerpointt2000 .... Concernant KVRTool, le sacn a duré environ 5 heures et a détecté 2 anomalie ("cheval de troie") qu'il a supprimé Voici le rapport : Etat : Supprimés (évênements : 2) 26/08/2013 19:44:57 Supprimés cheval de Troie Trojan.Win32.Agentb.ini C:\AdwCleaner\Quarantine\C\Program Files\Webplayer setup\LollipopInstaller_kreapixel_14650.exe.vir Elevées 26/08/2013 21:59:06 Supprimés cheval de Troie Trojan.Win32.Agentb.ini C:\System Volume Information\_restore{1B8DF5D8-75BF-4FA8-97A2-C390E88B5891}\RP732\A0152070.exe Elevées