ZONE ANTIMALWARE

Le forum de Nicolas Coolman a pour objectif de détecter et d'informer sur les nouvelles menaces malwares présentes sur le web. 

Cette section concerne le système d'exploitation Windows. Quand votre système met beaucoup de temps à démarrer. Lorsque vous avez un message d'erreur Windows qui s'affiche sur votre ordinateur. Si vous constatez des dysfonctionnements dans l'affichage des fenêtres. Si votre disque dur se bloque souvent à 100% d'utilisation. Quand Windows vous signale une absence ou une erreur de pilote. Lorsque votre mémoire est saturée à 100% d'occupation. Ce sont autant de cas sur lesquels vous pouvez trouver une solution.
 #79725  par carolan
 
Fichier log de OTM :

All processes killed
========== REGISTRY ==========
Registry key HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\bitdefender.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\bitdefender.fr\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.bitdefender.com\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\SIGN.I not found.
Registry value HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\SIGN.I not found.
Registry value HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\SIGN.I not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrateur
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 315184 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default.migrated

User: Public
->Temp folder emptied: 0 bytes

User: Yoan
->Temp folder emptied: 22669 bytes
->Temporary Internet Files folder emptied: 255890 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 316208 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 606972 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1,00 mb


OTM by OldTimer - Version 3.1.21.0 log created on 05092018_133938

Files moved on Reboot...
C:\Users\Yoan\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Yoan\AppData\Local\Microsoft\Windows\INetCache\counters2.dat moved successfully.
File move failed. C:\WINDOWS\temp\NitroUpdateService.slog scheduled to be moved on reboot.

Registry entries deleted on Reboot...
 #79807  par carolan
 
Voici :

Farbar Recovery Scan Tool (x64) Version: 06.05.2018 01
Exécuté par Mouche (10-05-2018 10:50:14)
Exécuté depuis C:\Users\Yoan\Desktop
Mode d'amorçage: Normal

================== Chercher Registre: "bitdefender" ===========

[HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps\{C154ADC2-6C3D-43E7-A16C-5AE414A05EFC}\RecentItems\{7281D351-0A87-436D-A359-4D1296F9070F}]
"Path"="C:\gv\message maj windows bitdefender.jpg"
[HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps\{C154ADC2-6C3D-43E7-A16C-5AE414A05EFC}\RecentItems\{7281D351-0A87-436D-A359-4D1296F9070F}]
"DisplayName"="message maj windows bitdefender.jpg"
[HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]
"SIGN.IE=02F61A0 BitDefender_Uninstall_Tool.exe"="0x5341435001000000000000000700000028000000A0612F00048B2F0001000000000000000000010600010000E63F486B2AA0D20100000000000000000500000010000000000000000000000000000000800000000200000028000000000000008000004004000000000000000000000000000000262F0500000000000100000001000000"
[HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]
"SIGN.IE=02B60A0 The_New_Bitdefender_UninstallTool.exe"="0x5341435001000000000000000700000028000000A0602B00B5C82B0001000000000000000000010600010000E63F486B2AA0D201000000000000000005000000100000000000000000000000000000008000000002000000280000000000000080000040040000000000000000000000000000005FE70E00000000000100000001000000"
[HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]
"SIGN.IE=02F61A0 BitDefender_Uninstall_Tool (1).exe"="0x5341435001000000000000000700000028000000A0612F00048B2F0001000000000000000000010600010000E63F486B2AA0D20100000000000000000500000010000000000000000000000000000000800000000200000028000000000000008000004004000000000000000000000000000000C36A0600000000000100000001000000"
[HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\paint.net]
"File/MostRecent/Path7"="C:\gv\message maj windows bitdefender.jpg"
[HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByApp\{8E861EA8-BF4C-4364-80DC-385C1B52FCA2}]
"Metadata"="0 C:\gv\message maj windows bitdefender.jpg"
[HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByApp\{8E861EA8-BF4C-4364-80DC-385C1B52FCA2}]
"FilePath"="\\?\Volume{DF083428-1625-42C3-A16D-9276AAB6855B}\gv\message maj windows bitdefender.jpg"

====== Fin de Chercher ======
 #79908  par did80
 
salut carolan

c'est une impression ou il y en a plus?

refais un otm avec ces lignes
Contenu caché
Vous devez être inscrit et connecté sur ce forum pour voir le contenu caché.
didier
 #80058  par carolan
 
Salut Didier,

Ouais... me serais-je planté quelque part ?...

Résultat nouvel otm :
All processes killed
========== REGISTRY ==========
HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps\{C154ADC2-6C3D-43E7-A16C-5AE414A05EFC}\RecentItems\{7281D351-0A87-436D-A359-4D1296F9070F}\\"Path"|"" /E : value set successfully!
HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps\{C154ADC2-6C3D-43E7-A16C-5AE414A05EFC}\RecentItems\{7281D351-0A87-436D-A359-4D1296F9070F}\\"DisplayName"|"" /E : value set successfully!
HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\"SIGN.IE|"" /E : value set successfully!
HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\"SIGN.IE|"" /E : value set successfully!
HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\"SIGN.IE|"" /E : value set successfully!
HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\paint.net\\"File/MostRecent/Path7"|"" /E : value set successfully!
HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByApp\{8E861EA8-BF4C-4364-80DC-385C1B52FCA2}\\"Metadata"|"" /E : value set successfully!
HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.Windows.Photos_8wekyb3d8bbwe\PersistedStorageItemTable\ManagedByApp\{8E861EA8-BF4C-4364-80DC-385C1B52FCA2}\\"FilePath"|"" /E : value set successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrateur
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default.migrated

User: Public
->Temp folder emptied: 0 bytes

User: Yoan
->Temp folder emptied: 12570537 bytes
->Temporary Internet Files folder emptied: 39680668 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 2112 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 80210 bytes
RecycleBin emptied: 565624 bytes

Total Files Cleaned = 50,00 mb


OTM by OldTimer - Version 3.1.21.0 log created on 05122018_102712

Files moved on Reboot...
File move failed. C:\Users\Yoan\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot.
File move failed. C:\Users\Yoan\AppData\Local\Microsoft\Windows\INetCache\counters2.dat scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\NitroUpdateService.slog scheduled to be moved on reboot.

Registry entries deleted on Reboot...


Résultat nouveau farbar :

Farbar Recovery Scan Tool (x64) Version: 12.05.2018
Exécuté par Mouche (12-05-2018 10:45:17)
Exécuté depuis C:\Users\Yoan\Desktop
Mode d'amorçage: Normal

================== Chercher Registre: "bitdefender" ===========

[HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]
"SIGN.IE=02F61A0 BitDefender_Uninstall_Tool.exe"="0x5341435001000000000000000700000028000000A0612F00048B2F0001000000000000000000010600010000E63F486B2AA0D20100000000000000000500000010000000000000000000000000000000800000000200000028000000000000008000004004000000000000000000000000000000262F0500000000000100000001000000"
[HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]
"SIGN.IE=02B60A0 The_New_Bitdefender_UninstallTool.exe"="0x5341435001000000000000000700000028000000A0602B00B5C82B0001000000000000000000010600010000E63F486B2AA0D201000000000000000005000000100000000000000000000000000000008000000002000000280000000000000080000040040000000000000000000000000000005FE70E00000000000100000001000000"
[HKEY_USERS\S-1-5-21-3557671498-404040511-2280983113-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]
"SIGN.IE=02F61A0 BitDefender_Uninstall_Tool (1).exe"="0x5341435001000000000000000700000028000000A0612F00048B2F0001000000000000000000010600010000E63F486B2AA0D20100000000000000000500000010000000000000000000000000000000800000000200000028000000000000008000004004000000000000000000000000000000C36A0600000000000100000001000000"

====== Fin de Chercher ======



A te lire, si tu ne te décourages pas ?...
 #80074  par did80
 
salut carolan

Télécharger Zhpfix Script Manager

https://nicolascoolman.eu/download/zhpf ... t-manager/

sur votre bureau

Copier le correctif dans le cadre blanc
Contenu caché
Vous devez être inscrit et connecté sur ce forum pour voir le contenu caché.
Image


Puis Lancer l'outil en cliquant sur le balai

L'outil va fournir un fichier rapport zhpfix.txt sur votre bureau

redémarrer la machine

me copier le contenu de ce fichier

didier
Sujets similaires Statistiques Dernier message
problème windows , infection?
par lju  dans : Analyse de rapports et Désinfection.
22 Réponses
11020 Vues
par El Magnifico
Problème après extinction Windows
par Denys06  dans : Support Windows
8 Réponses
5720 Vues
par ab_web
résolu problème ouverture fichier c:/ progam
par nicogef  dans : Analyse de rapports et Désinfection.
16 Réponses
4303 Vues
par El Magnifico
[RESOLU]Problème redirection page internet
par Seb67  dans : Analyse de rapports et Désinfection.
12 Réponses
5247 Vues
par Seb67
problème de mise à jour W 10
par bonobono  dans : Support Windows
18 Réponses
10356 Vues
par bonobono