Auteur Sujet: fichiers corrompus suite virus ? RESOLU  (Lu 20763 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne caribou

  • Membres
  • Members
  • Messages: 11
fichiers corrompus suite virus ? RESOLU
« le: septembre 23, 2012, 18:10:05 »
Bonjour à tous ! Suite au virus "Gendarmerie" je n'arrive plus à ouvrir des photos. La taille et le nom des fichiers n'ont pas changé. Quand je veux les ouvrir, selon le programme j'ai plusieurs messages :" Il se peut que le fichier soit endommagé, corrompu ou non pris en charge" ou encore "image non valide, le format de fichier n'est pas pris en charge ou n'est pas valide ".   Les photos enregistrées après sur le PC sont visualisables.
Comment puis-je ouvrir ces fichiers de photos ? Merci!
« Modifié: septembre 25, 2012, 17:50:21 par caribou »

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : fichiers corrompus suite virus ?
« Réponse #1 le: septembre 23, 2012, 23:14:24 »
Bonsoir,

Nous allons regarder cela en deux temps :
- Vérifier qu'il ne reste rien de l'infection
- Vérifier quelle variante de cette infection a crypté tes fichiers ... attention, selon la variante, il n'existera peut-être aucune solution pour récupérer les fichiers !

Télécharge OTL (de Old Timer) sur ton bureau.

  • Ferme toutes tes fenêtres, puis double clique sur OTL.exe pour le lancer.
    (Utilisateur de Vista/Windows 7 faites un clic droit -> "Exécuter en tant qu'administrateur")
  • Coche en haut la case devant "Tous les utilisateurs"
  • Sous Personnalisation, copie-colle l'ensemble du texte ci-dessous, laisse les autres options par défaut.

netsvcs
msconfig
activex
/md5start
explorer.exe
wininit.exe
winlogon.exe
userinit.exe
kernel32.dll
services.exe
/md5stop
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\syswow64\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\syswow64\drivers\*.sys /lockedfiles
CREATERESTOREPOINT

  • Clique sur le bouton Analyse en haut à gauche puis patiente quelques instants.
  • A la fin du scan, deux rapports s'ouvriront OTL.Txt et Extras.Txt.

  • Pour les rapports, merci d'utiliser ce service de rapport en ligne : dépose le fichier via "parcourir" et poste simplement le lien obtenu dans ta réponse.
Une aide à l'utilisation ici

Note : Les rapports sont aussi enregistrés sur le bureau

Hors ligne caribou

  • Membres
  • Members
  • Messages: 11
Re : fichiers corrompus suite virus ?
« Réponse #2 le: septembre 24, 2012, 12:37:19 »
Merci de votre aide !
Voici le lien du rapport otl        http://pjjoint.malekal.com/files.php?id=20120924_x9e5n13q15g5

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : fichiers corrompus suite virus ?
« Réponse #3 le: septembre 24, 2012, 14:08:04 »
Re,

Peux-tu me donner un exemple de forme exact du nom d'un fichier encrypté ?

Image d'écran ou transcris-moi le nom :
http://forum.security-x.fr/cours-et-tutoriels-322/(tutoriel)-impression-d%27ecran-et-hebergement-de-rapport

Hors ligne caribou

  • Membres
  • Members
  • Messages: 11
Re : fichiers corrompus suite virus ?
« Réponse #4 le: septembre 24, 2012, 21:14:09 »
Bonsoir ! Voici le lien d'une photo que je n'arrive pas à ouvrir :  http://pjjoint.malekal.com/files.php?id=20120924_m12e13f11z15k10
et voici le lien de la même photo retransférée sur l'ordi et que je peux ouvrir :  http://pjjoint.malekal.com/files.php?id=20120924_q15j7t13x15c11

J'ai remarqué qu'avec une visionneuse "Ma galerie photo" (de HP ?) je peux ouvrir les fichiers corrompus mais la qualité est très altérée (Gros pixels) voici l'exemple avec la même photo :  http://pjjoint.malekal.com/files.php?id=20120924_l13i8w6d8n11
 Y aurait-il un autre moyen de les lires ?
Merci de votre réponse !

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : fichiers corrompus suite virus ?
« Réponse #5 le: septembre 24, 2012, 21:47:21 »
Re,

Alors que nous soyons sur la même longueur, c'est bien une capture de l’icône et du nom d'une image que tu ne parviens pas à ouvrir, ce n'est pas l'image elle-même ?

Celle transférée, c'est prise tel quel du pc infecté vers un pc sain, sans modif ?

Si oui, alors c'est ta visionneuse windows qui a un souci ... ce ne sont pas des fichiers cryptés ou endommagés si tu peux les ouvrir sur un autre pc. On regardera.

Déjà on va compléter une chose :

1) Télécharge AdwCleaner (de Xplode) sur ton Bureau.

/!\ Ferme toutes les applications en cours (notamment ton navigateur)/!\

  • Double-clique sur adwcleaner0.exe pour lancer le programme.
    (Utilisateur de Vista/Windows 7, clique-droit sur le fichier adwcleaner0.exe -> Exécuter en tant qu'administrateur)

  • Dans la fenêtre principal, choisis l'option Suppression.
  • Valide l'avertissement.
  • Si le pc demande à redémarrer, accepte.
  • Un rapport apparaitra (sinon, il est situé ici C:\AdwCleaner[Sx].txt). Poste-le dans ta prochaine réponse.


    2) Relance  OTL.exe

    • Ferme toutes tes fenêtres, puis double clique sur OTL.exe pour le lancer.
    (Utilisateur de Vista/Windows 7 faites un clic droit -> "Exécuter en tant qu'administrateur")

    /!\ Attention, utilisateur d'Avast! ou d'autres antivirus, ne lancez pas OTL en mode sandbox /!\

    • Copie-colle l'ensemble du texte ci-dessous dans le cadre Personnalisation d'OTL en bas à gauche.


    :OTL
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000.10011&barid={E4040182-03E8-11E2-80E0-6C626DC96B90}
    IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
    IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10011&barid={E4040182-03E8-11E2-80E0-6C626DC96B90}
    IE - HKU\S-1-5-21-609408362-640983105-3706714562-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000.10011&barid={E4040182-03E8-11E2-80E0-6C626DC96B90}
    IE - HKU\S-1-5-21-609408362-640983105-3706714562-1001\..\URLSearchHook: {8e5025c2-8ea3-430d-80b8-a14151068a6d} - No CLSID value found
    IE - HKU\S-1-5-21-609408362-640983105-3706714562-1001\..\URLSearchHook: {AEEC3B59-CA98-4EBA-A140-57B94E283583} - No CLSID value found
    IE - HKU\S-1-5-21-609408362-640983105-3706714562-1001\..\SearchScopes\{26C6DB5D-9642-420F-BFCA-DA102F57E28F}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3128284
    IE - HKU\S-1-5-21-609408362-640983105-3706714562-1001\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10011&barid={E4040182-03E8-11E2-80E0-6C626DC96B90}
    [2012/09/18 21:31:40 | 000,000,000 | ---D | M] (01NET.com) -- C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}
    [2012/09/21 14:33:43 | 000,000,000 | ---D | M] (OneClickDownloader) -- C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com
    CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\Christophe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehdmaehkiiampolokajdcelladmnopgp\10.11.21.503_0\plugins/ConduitChromeApiPlugin.dll
    CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\Christophe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehdmaehkiiampolokajdcelladmnopgp\10.11.21.503_0\plugins/np-cwmp.dll
    CHR - Extension: 01NET.com = C:\Users\Christophe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehdmaehkiiampolokajdcelladmnopgp\10.11.21.503_0\
    O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo LLC)
    O8:64bit: - Extra context menu item: ajouter cette page à vos favoris Orange - C:\Users\CHRIST~1\AppData\Local\Temp\cceCCE6.html File not found
    O8:64bit: - Extra context menu item: traduire le texte sélectionné - C:\Users\CHRIST~1\AppData\Local\Temp\cceCCE5.html File not found
    O8 - Extra context menu item: ajouter cette page à vos favoris Orange - C:\Users\CHRIST~1\AppData\Local\Temp\cceCCE6.html File not found
    O8 - Extra context menu item: traduire la page - C:\Users\CHRIST~1\AppData\Local\Temp\cceCCD4.html File not found
    O8 - Extra context menu item: traduire le texte sélectionné - C:\Users\CHRIST~1\AppData\Local\Temp\cceCCE5.html File not found
    [2012/09/21 14:36:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Yontoo
    [2012/09/21 14:36:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer
    [2012/09/21 14:35:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SweetIM
    [2012/09/21 14:32:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\1ClickDownload
    [2012/09/17 20:19:32 | 000,082,869 | ---- | M] () -- C:\ProgramData\xjdfkuscypvsoms
    [2012/09/18 21:31:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
    [2012/09/18 21:31:36 | 000,000,000 | ---D | C] -- C:\Users\Christophe\AppData\Local\Conduit
    [2012/09/17 20:19:32 | 000,000,000 | ---D | C] -- C:\ProgramData\yjbyfpurgwcbzjo

    :Commands
    [emptytemp]


    • Puis clique sur le bouton Correction en haut à gauche
    • Le pc va redémarrer. (si ce n'est pas le cas, fais-le manuellement)
    • Poste le rapport de suppression s'il apparait.

    Note : le rapport est enregistré sous format ".log", il convient de changer cette extension en ".txt" si tu veux le déposer sur des sites en ligne. S'il n'apparait pas, il se trouve ici : C:\_OTL, sous la forme xxxxxxxx_xxxx.log où x sont la date et l'heure

    /!\ Ce script est exclusivement réservé à l'utilisateur actuel du sujet, vous ne devez en aucun cas l'utiliser de votre propre chef sur un autre pc, sous risque d'endommager le système /!\

Hors ligne caribou

  • Membres
  • Members
  • Messages: 11
Re : fichiers corrompus suite virus ?
« Réponse #6 le: septembre 24, 2012, 22:48:19 »
La première image est une capture de l'icône et du nom de l'image que je n'arrive pas à ouvrir,  la deuxième image est une capture de l'icône  et du nom de l'image (après avoir été retransférée  sur le pc ) et que j'arrive à ouvrir, la troisième image est la capture de la photo soit disant "corrompue" que je n'arrive à lire qu'avec la visionneuse "Ma galerie photo" mais dans une qualité médiocre et que je n'arrive pas à ouvrir avec les autres programmes.


Voici les rapports demandés  adwcleaner :

 # AdwCleaner v2.003 - Rapport créé le 24/09/2012 à 22:05:11
# Mis à jour le 23/09/2012 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : Christophe - HP-BUREAU
# Mode de démarrage : Normal
# Exécuté depuis : C:\Users\Christophe\Downloads\adwcleaner.exe
# Option [Suppression]


***** [Services] *****


***** [Fichiers / Dossiers] *****

Dossier Supprimé : C:\Program Files (x86)\Conduit
Dossier Supprimé : C:\Program Files (x86)\DAEMON Tools Toolbar
Dossier Supprimé : C:\Program Files (x86)\SweetIM
Dossier Supprimé : C:\Program Files (x86)\Yontoo
Dossier Supprimé : C:\ProgramData\Tarma Installer
Dossier Supprimé : C:\Users\Christophe\AppData\Local\Conduit
Dossier Supprimé : C:\Users\Christophe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehdmaehkiiampolokajdcelladmnopgp
Dossier Supprimé : C:\Users\Christophe\AppData\LocalLow\Conduit
Dossier Supprimé : C:\Users\Christophe\AppData\Roaming\Nosibay
Supprimé au redémarrage : C:\Users\Christophe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehdmaehkiiampolokajdcelladmnopgp

***** [Registre] *****

Clé Supprimée : HKCU\Software\AppDataLow\Software\Conduit
Clé Supprimée : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Clé Supprimée : HKCU\Software\AppDataLow\Software\SmartBar
Clé Supprimée : HKCU\Software\Conduit
Clé Supprimée : HKCU\Software\Google\Chrome\Extensions\ehdmaehkiiampolokajdcelladmnopgp
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Clé Supprimée : HKCU\Software\Nosibay
Clé Supprimée : HKCU\Software\SweetIm
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Clé Supprimée : HKLM\SOFTWARE\Classes\SearchBar.Client
Clé Supprimée : HKLM\SOFTWARE\Classes\Toolbar.CT3128284
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Clé Supprimée : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Clé Supprimée : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Clé Supprimée : HKLM\SOFTWARE\Classes\YontooIEClient.Layers
Clé Supprimée : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1
Clé Supprimée : HKLM\Software\Conduit
Clé Supprimée : HKLM\Software\Iminent
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Clé Supprimée : HKLM\Software\SweetIm
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3BF72F68-72D8-461D-A884-329D936C5581}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{78E9D883-93CD-4072-BEF3-38EE581E2839}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{83AC1413-FCE4-4A46-9DD5-4F31F306E71F}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ehdmaehkiiampolokajdcelladmnopgp
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2F603A45-D956-496B-81B5-50D782424976}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Clé Supprimée : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B85C4CB2-B352-4BD8-818C-BCE353599107}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2F603A45-D956-496B-81B5-50D782424976}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B85C4CB2-B352-4BD8-818C-BCE353599107}
Clé Supprimée : HKLM\SOFTWARE\Tarma Installer
Valeur Supprimée : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Valeur Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Bubble Dock]

***** [Navigateurs] *****

-\\ Internet Explorer v9.0.8112.16421

Restauré : [HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restauré : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restauré : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restauré : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restauré : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restauré : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restauré : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Remplacé : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://home.sweetim.com/?crg=3.1010000.10011&barid={E4040182-03E8-11E2-80E0-6C626DC96B90} --> hxxp://www.google.com

-\\ Google Chrome v [Impossible d'obtenir la version]

Fichier : C:\Users\Christophe\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Le fichier ne contient aucune entrée illégitime.

*************************

AdwCleaner[S1].txt - [7372 octets] - [24/09/2012 22:05:11]

########## EOF - C:\AdwCleaner[S1].txt - [7432 octets] ##########


et voici le rapport de otl :


All processes killed
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847}\ not found.
HKU\S-1-5-21-609408362-640983105-3706714562-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-609408362-640983105-3706714562-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{8e5025c2-8ea3-430d-80b8-a14151068a6d} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\ not found.
Registry value HKEY_USERS\S-1-5-21-609408362-640983105-3706714562-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{AEEC3B59-CA98-4EBA-A140-57B94E283583} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEEC3B59-CA98-4EBA-A140-57B94E283583}\ not found.
Registry key HKEY_USERS\S-1-5-21-609408362-640983105-3706714562-1001\Software\Microsoft\Internet Explorer\SearchScopes\{26C6DB5D-9642-420F-BFCA-DA102F57E28F}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26C6DB5D-9642-420F-BFCA-DA102F57E28F}\ not found.
Registry key HKEY_USERS\S-1-5-21-609408362-640983105-3706714562-1001\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C360-6118-11DC-9C72-001320C79847}\ not found.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\NOTIFICATION\images\light folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\NOTIFICATION\images\dark folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\NOTIFICATION\images folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\NOTIFICATION\css folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\NOTIFICATION folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\MULTI_RSS\js\resources folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\MULTI_RSS\js folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\MULTI_RSS\img folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\MULTI_RSS\css folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\MULTI_RSS folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\HIGHLIGHTER\js folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\HIGHLIGHTER\css folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\HIGHLIGHTER folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\EMAIL_NOTIFIER\js\plugins folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\EMAIL_NOTIFIER\js folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\EMAIL_NOTIFIER\css folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\EMAIL_NOTIFIER folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\APPLICATION_BUTTON\resources folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\APPLICATION_BUTTON\Js folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\APPLICATION_BUTTON folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa\404 folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\wa folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\ui\menu\js folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\ui\menu\img folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\ui\menu\css folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\ui\menu folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\ui\gf\img folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\ui\gf\css folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\ui\gf folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\ui\gadgetFrame folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\ui\dlg\ftd\images folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\ui\dlg\ftd folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\ui\dlg folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\ui folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\searchProtector\searchProtectorSettingsDialog\images folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\searchProtector\searchProtectorSettingsDialog folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\searchProtector\SearchProtectorBubbleDialog\images folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\searchProtector\SearchProtectorBubbleDialog folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\searchProtector\js folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\searchProtector folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\options\js\resources folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\options\js folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\options\images folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\options\css folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\options folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\myStuffDialogs folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\features\js\resources folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\features\js folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\features folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\api folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\ac\res folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\ac\img folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\ac\css folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\ac folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\aboutBox\js folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\aboutBox\images folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al\aboutBox folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb\al folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content\tb folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284\content folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome\CT3128284 folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d}\chrome folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\extensions\{8e5025c2-8ea3-430d-80b8-a14151068a6d} folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\oneclickdownloader\tests folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\oneclickdownloader\lib folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\oneclickdownloader\data folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\oneclickdownloader folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\api-utils\lib\windows folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\api-utils\lib\window folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\api-utils\lib\utils folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\api-utils\lib\traits folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\api-utils\lib\tabs folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\api-utils\lib\events folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\api-utils\lib\event folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\api-utils\lib\dom folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\api-utils\lib\content folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\api-utils\lib folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\api-utils\data folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\api-utils folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\addon-kit\lib folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\addon-kit\data folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources\addon-kit folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\resources folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\locale folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\defaults\preferences folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com\defaults folder moved successfully.
C:\Users\Christophe\AppData\Roaming\mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com folder moved successfully.
File C:\Users\Christophe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehdmaehkiiampolokajdcelladmnopgp\10.11.21.503_0\plugins/ConduitChromeApiPlugin.dll not found.
File C:\Users\Christophe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehdmaehkiiampolokajdcelladmnopgp\10.11.21.503_0\plugins/np-cwmp.dll not found.
File C:\Users\Christophe\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehdmaehkiiampolokajdcelladmnopgp\10.11.21.503_0 not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\ not found.
File C:\Program Files (x86)\Yontoo\YontooIEClient.dll not found.
64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ajouter cette page à vos favoris Orange\ deleted successfully.
64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\traduire le texte sélectionné\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ajouter cette page à vos favoris Orange\ not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\traduire la page\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\traduire le texte sélectionné\ not found.
Folder C:\Program Files (x86)\Yontoo\ not found.
Folder C:\ProgramData\Tarma Installer\ not found.
Folder C:\Program Files (x86)\SweetIM\ not found.
C:\Program Files (x86)\1ClickDownload folder moved successfully.
C:\ProgramData\xjdfkuscypvsoms moved successfully.
Folder C:\Program Files (x86)\Conduit\ not found.
Folder C:\Users\Christophe\AppData\Local\Conduit\ not found.
C:\ProgramData\yjbyfpurgwcbzjo folder moved successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Christophe
->Temp folder emptied: 8435303890 bytes
->Temporary Internet Files folder emptied: 42989095 bytes
->Java cache emptied: 1718074 bytes
->Google Chrome cache emptied: 49299825 bytes
->Flash cache emptied: 506 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Marie-Laure
->Temp folder emptied: 763577 bytes
->Temporary Internet Files folder emptied: 30396032 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 754 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 413709200 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 68044 bytes
RecycleBin emptied: 7600669207 bytes
 
Total Files Cleaned = 15,807.00 mb
 
 
OTL by OldTimer - Version 3.2.65.1 log created on 09242012_221931

Files\Folders moved on Reboot...
C:\Users\Christophe\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : fichiers corrompus suite virus ?
« Réponse #7 le: septembre 25, 2012, 10:26:47 »
Re,

Ok, maintenant le pc est propre, on va travailler sur les fichiers.

J'ai vu que tu avais utilisé RannohDecryptor, est-ce qu'il avait trouvé et décrypté des fichiers ? est-ce que cette photo en faisait partie ?

Hors ligne caribou

  • Membres
  • Members
  • Messages: 11
Re : fichiers corrompus suite virus ?
« Réponse #8 le: septembre 25, 2012, 10:51:29 »
Rannohdecryptor n'avait pas trouvé ni décrypté aucun fichier.

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : fichiers corrompus suite virus ?
« Réponse #9 le: septembre 25, 2012, 11:10:50 »
Re,

Si ni la taille, ni le nom des photos et autres fichiers n'ont été modifié par l'infection, et qu'aucun décrypteur n'a été utilisé ou a décrypté quelque chose, et que ces même fichiers simplement déplacé sur un autre pc sont fonctionnels, c'est que les fichiers n'ont pas été crypté.

Le problème vient donc d'autre chose.

Peux-tu ouvrir normalement ton image sans problème apparent dans Paint ?
(démarrer -> tous les programmes -> accessoires -> Paint )

Hors ligne caribou

  • Membres
  • Members
  • Messages: 11
Re : fichiers corrompus suite virus ?
« Réponse #10 le: septembre 25, 2012, 11:24:04 »
voici la réponse quand j'ouvre avec paint : http://pjjoint.malekal.com/files.php?id=20120925_v14m6v5x13o10
  alors que la même photos retransférée sur le même pc mais après infection s'ouvre normalement avec toutes les visionneuses.

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : fichiers corrompus suite virus ?
« Réponse #11 le: septembre 25, 2012, 12:45:06 »
Re,

On va tester ceci pour voir :

Télécharge ExtSigChecker (de  Tigzy) sur ton Bureau.

Attention il est très important de bien enregistrer le fichier sur ton bureau

  • Clique sur "Démarrer" -> "Exécuter" (s'il n'apparait pas, il est dans "tous les programmes" -> "accessoires")
  • Tape exactement ceci : (ou copie-colle pour plus de sécurité)
"%userprofile%\bureau\extsigchecker.exe" c: -f
  • Valide avec la touche "Entrée"
  • Le scan va commencer, attends qu'il se termine.



Regarde s'il y a du mieux ensuite, ou indique-moi si le scan a mis des erreurs ou qu'il n'a rien trouvé.

Hors ligne caribou

  • Membres
  • Members
  • Messages: 11
Re : fichiers corrompus suite virus ?
« Réponse #12 le: septembre 25, 2012, 14:15:17 »
Je n'arrive pas à lancer le scan. Est-ce que je dois insérer le texte dans cette fenêtre ?http://pjjoint.malekal.com/files.php?id=20120925_t13j12o9v9v15

J'ai essayé, la fenêtre se ferme et plus rien ne se passe.

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : fichiers corrompus suite virus ?
« Réponse #13 le: septembre 25, 2012, 14:30:56 »
Re,

L'outil se lance bien, par contre il doit manquer un paramètre quand tu as copié dans "exécuter"

Tu as bien copié le c: et -f qui suivait ?

Tu as appuyer sur une touche pour continuer le lancement ?
Tu n'as rien à copier une fois la fenêtre noire d'invite de commande lancée normalement.


Hors ligne caribou

  • Membres
  • Members
  • Messages: 11
Re : fichiers corrompus suite virus ?
« Réponse #14 le: septembre 25, 2012, 14:47:24 »
désolé, j'ai dû raté une étape ! Le programme est bien sur le bureau mais je ne le trouve pas dans  démarrer ou accessoires. Je ne vois pas ou copier le texte.

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : fichiers corrompus suite virus ?
« Réponse #15 le: septembre 25, 2012, 15:02:30 »
Re,

On recommence  ;D
Tu ne dois pas lancer le programme, il se lancera grâce à la commande que je te demande de taper, celle-ci dois être taper dans l'interface "exécuter" de ton Windows :



Citer

Télécharge ExtSigChecker (de  Tigzy) sur ton Bureau.

Attention il est très important de bien enregistrer le fichier sur ton bureau

  • Clique sur "Démarrer" -> "Exécuter" (s'il n'apparait pas, il est dans "tous les programmes" -> "accessoires")

  • Tape exactement ceci : (ou copie-colle pour plus de sécurité)
"%userprofile%\bureau\extsigchecker.exe" c: -f
  • Valide avec la touche "Entrée"
  • Le scan va commencer, attends qu'il se termine.



Regarde s'il y a du mieux ensuite, ou indique-moi si le scan a mis des erreurs ou qu'il n'a rien trouvé.

Hors ligne caribou

  • Membres
  • Members
  • Messages: 11
Re : fichiers corrompus suite virus ?
« Réponse #16 le: septembre 25, 2012, 15:25:44 »
J'avais effectivement essayé mais voici le message : http://pjjoint.malekal.com/files.php?id=20120925_w12i5t8h9b9
Le programme est bien copié sur le bureau.

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : fichiers corrompus suite virus ?
« Réponse #17 le: septembre 25, 2012, 15:30:21 »
Re,

Alors tape ceci plutôt :
"%userprofile%\desktop\extsigchecker.exe" c: -f

Hors ligne caribou

  • Membres
  • Members
  • Messages: 11
Re : fichiers corrompus suite virus ?
« Réponse #18 le: septembre 25, 2012, 15:49:07 »
 :AAC Magnifique ! Et comment qu'il y a du mieux ! En un bref apercu je pense pouvoir de nouveau lire toutes les photos. Encore un grand MERCI et bravo ! Pendant le scan, ce message apparaissait à plusieurs reprises " Invalid file handle for filter 001DD710. Error is 5 ".
Quelle était la cause de ces soucis ?

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : fichiers corrompus suite virus ?
« Réponse #19 le: septembre 25, 2012, 16:02:41 »
Re,

l'Erreur 5 indique un fichier inaccessible. ça arrive, ce n'est pas grave.

Tu avais donc bien un ransomware qui avait crypté les fichiers, mais c'était une variante assez rare.
On va conclure et mettre à jour le pc afin d'éviter une nouvelle infection !


1) Désinstalle AdwCleaner :

  • Relance-le le programme adwcleaner0.exe situé sur ton Bureau.
    (Utilisateur de Vista/Windows 7, clique-droit sur le fichier -> Exécuter en tant qu'administrateur)
  • Dans la fenêtre principal, choisis l'option Désinstallation, et valide avec "Oui"

  • Supprime ensuite le fichier adwcleaner0.exe sur ton bureau.


    2) Relance  OTL.exe[/color]
    (Utilisateur de Vista/Windows 7 faites un clic droit -> "Exécuter en tant qu'administrateur")

  • Clique sur "Purge d'outils"
  • Valide l'avertissement par "ok" et laisse le pc redémarrer.

    Tu peux supprimer manuellement ExtSigChecker.exe



    Mise à jour du système et des logiciels :

    Télécharge SX Check&Update (de Igor51 ) sur ton bureau.

  • Lance SXCU.exe en double-cliquant dessus.
    (Utilisateur de Vista/Windows 7 faites un clic droit -> "Exécuter en tant qu'administrateur")

  • Clique sur Update Java à droite. Le chargement et l'exécution de la mise à jour vont se faire, suis les instructions. Si rien ne se passe, fais manuellement la mise à jour ici : http://www.java.com/fr/download/
    Vérifie que les anciennes version sont supprimées dans ta liste des programmes, sinon fait-le manuellement : Java 6 Update 35

  • Clique sur Update Adobe Reader à droite. Si besoin, le chargement et l'exécution de la mise à jour vont se faire, suis les instructions. Si rien ne se passe, fais manuellement la mise à jour ici : http://get.adobe.com/reader/

  • Clique sur Update Flash à droite. Si besoin et selon le cas, soit Internet Explorer, soit ton ou tes autres navigateurs vont s'ouvrir, suis pour chacun d'eux les instructions à l'écran pour la mise à jour.
    (pense à ne pas accepter les offres comme McAfee security scan ou Chrome)   

    Ferme le programme via "Quit"
    Tu peux supprimer SXCU.exe.


    Pour aller plus loin dans ta protection et éviter de te faire réinfecter voici quelques conseils supplémentaires :

  • Attention lors de l'installation de logiciel :
    Veiller à toujours lire les conditions d'utilisation (CLUF), afin de déceler la gestion des données personnelles, l'installation de sponsors publicitaires ou tout autre atteintes à la vie privée. Refuser les toolbars et autres addons proposés.
    A lire !

  • Firefox et/ou Chrome offrent une meilleure sécurité par rapport à Internet Explorer, surtout si on les complète de quelques plugins très intéressant : Noscript et WOT par exemple. (pour Chrome : NoScript ; WOT )

  • Maintenir ses logiciels et son système à jour :
    De nombreuses infections sont dû à des failles de windows, mais aussi de logiciel tiers, comme Sun Java, Adobe Acrobat Reader, etc
    Tu peux faire un scan de vulnérabilité pour connaitre tes logiciels présentant des failles non corrigées ou à mettre à jour.

    Enfin, le plus important reste ton comportement sur ton PC, tu restes la plus importante protection : Évites les comportement à risque : P2P, cracks, téléchargements et installations douteux via des pubs, les messageries instantanées, ou des sites inconnu, sites pornographiques.
    A lire !
    Ici aussi !



    Tu peux indiquer ton sujet "réglé" en cliquant sur le bouton "modifier" (en haut à droite)  dans ton tout premier message.
    -> Ajoute ensuite "résolu" à coté de ton titre et valide.

    A bientôt sur Security-X
     :AAN

Hors ligne caribou

  • Membres
  • Members
  • Messages: 11
Re : fichiers corrompus suite virus ?
« Réponse #20 le: septembre 25, 2012, 17:48:30 »
Encore un grand merci !  :)

Tags: