Ce correctif FRST à appliquer :
--------------------------------------------------------------------------------------------------------------
FRST - Correctif :
/!\ Crée un point de restauration manuel avant d'appliquer le correctif - Tutoriel en images /!\
- Ouvre le Bloc-notes (Démarrer => Tous les programmes => Accessoires => Bloc-notes)
- Copie/colle la totalité du contenu de la zone Code ci-dessous dans le Bloc-notes
start
CloseProcesses:
ProxyEnable: [S-1-5-21-996361165-524870672-62288233-1000] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-996361165-524870672-62288233-1000] => http=127.0.0.1:21010
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
R2 AddonAPIScreenshot; C:\Windows\system32\AddonAPIScreenshot\AddonAPIScreenshot.exe [68096 2014-11-26] () [File not signed]
R2 AppMotionODBC; C:\Windows\system32\AppMotionODBC\AppMotionODBC.exe [68096 2014-11-26] () [File not signed]
R2 BackupDashboardPath; C:\Windows\system32\BackupDashboardPath\BackupDashboardPath.exe [68096 2014-11-26] () [File not signed]
R2 CGICopyWinsock; C:\Windows\system32\CGICopyWinsock\CGICopyWinsock.exe [68096 2014-11-26] () [File not signed]
R2 ClipboardControlSchema; C:\Windows\system32\ClipboardControlSchema\ClipboardControlSchema.exe [68096 2014-11-26] () [File not signed]
R2 CompileEncondingWinsock; C:\Windows\system32\CompileEncondingWinsock\CompileEncondingWinsock.exe [68096 2014-11-26] () [File not signed]
R2 CompilerControlMotion; C:\Windows\system32\CompilerControlMotion\CompilerControlMotion.exe [68096 2014-11-26] () [File not signed]
R2 CompilerDesktopInterpreter; C:\Windows\system32\CompilerDesktopInterpreter\CompilerDesktopInterpreter.exe [68096 2014-11-26] () [File not signed]
R2 DashboardPathRaw; C:\Windows\system32\DashboardPathRaw\DashboardPathRaw.exe [68096 2014-11-26] () [File not signed]
R2 DebuggerMBRMemory; C:\Windows\system32\DebuggerMBRMemory\DebuggerMBRMemory.exe [68096 2014-11-26] () [File not signed]
R2 dimsjobmswsock32; C:\Windows\system32\dimsjobmswsock32\dimsjobmswsock32.exe [68096 2014-11-26] () [File not signed]
R2 dosehtracex64; C:\Windows\system32\dosehtracex64\dosehtracex64.exe [68096 2014-11-26] () [File not signed]
R2 DriverNativeSnapshot; C:\Windows\system32\DriverNativeSnapshot\DriverNativeSnapshot.exe [68096 2014-11-26] () [File not signed]
R2 FAT32MemoryRepository; C:\Windows\system32\FAT32MemoryRepository\FAT32MemoryRepository.exe [68096 2014-11-26] () [File not signed]
R2 FileGammaRuby; C:\Windows\system32\FileGammaRuby\FileGammaRuby.exe [68096 2014-11-26] () [File not signed]
R2 finderwdmaud32; C:\Windows\system32\finderwdmaud32\finderwdmaud32.exe [68096 2014-11-26] () [File not signed]
R2 FirmwareIconRoot; C:\Windows\system32\FirmwareIconRoot\FirmwareIconRoot.exe [68096 2014-11-26] () [File not signed]
R2 InterpreterMacroNet; C:\Windows\system32\InterpreterMacroNet\InterpreterMacroNet.exe [68096 2014-11-26] () [File not signed]
R2 interpretermotionBckp; C:\Windows\system32\interpretermotionBckp\interpretermotionBckp.exe [68096 2014-11-26] () [File not signed]
R2 MetafileTaskWizard; C:\Windows\system32\MetafileTaskWizard\MetafileTaskWizard.exe [68096 2014-11-26] () [File not signed]
R2 minimalrasplapProt; C:\Windows\system32\minimalrasplapProt\minimalrasplapProt.exe [68096 2014-11-26] () [File not signed]
R2 NativeSharewareUtility; C:\Windows\system32\NativeSharewareUtility\NativeSharewareUtility.exe [68096 2014-11-26] () [File not signed]
R2 ODBCOpenTrash; C:\Windows\system32\ODBCOpenTrash\ODBCOpenTrash.exe [67584 2014-11-12] () [File not signed]
R2 wdcregidleMonitor.exe; C:\Users\brodpers\AppData\Local\wdcregidleMonitor\wdcregidleMonitor.exe [208384 2014-11-26] () [File not signed]
S2 archivepku2uSched.exe; C:\Users\brodpers\AppData\Local\archivepku2uSched\archivepku2uSched.exe [X]
S2 FunctionNetRaw.exe; C:\Users\brodpers\AppData\Local\FunctionNetRaw\FunctionNetRaw.exe [X]
S2 kernelauthuiProvider.exe; C:\Users\brodpers\AppData\Local\kernelauthuiProvider\kernelauthuiProvider.exe [X]
S2 scrollingwdmaud32.exe; C:\Users\brodpers\AppData\Local\scrollingwdmaud32\scrollingwdmaud32.exe [X]
S2 wpcmiglocalsplTask.exe; C:\Users\brodpers\AppData\Local\wpcmiglocalsplTask\wpcmiglocalsplTask.exe [X]
S3 fdrawcmd; \??\C:\Windows\system32\drivers\fdrawcmd.sys [X]
S3 SPLITCAM; system32\DRIVERS\splitcam.sys [X]
S1 SydexFDD; system32\drives\sydexfdd.sys [X]
2014-11-26 14:19 - 2014-12-03 16:40 - 00000000 ____D () C:\Windows\system32\iexplore
C:\Users\brodpers\AppData\Local\wdcregidleMonitor
C:\Windows\system32\AddonAPIScreenshot
C:\Windows\system32\AppMotionODBC
C:\Windows\system32\BackupDashboardPath
C:\Windows\system32\CGICopyWinsock
C:\Windows\system32\ClipboardControlSchema
C:\Windows\system32\CompileEncondingWinsock
C:\Windows\system32\CompilerControlMotion
C:\Windows\system32\CompilerDesktopInterpreter
C:\Windows\system32\DashboardPathRaw
C:\Windows\system32\DebuggerMBRMemory
C:\Windows\system32\dimsjobmswsock32
C:\Windows\system32\dosehtracex64
C:\Windows\system32\DriverNativeSnapshot
C:\Windows\system32\FAT32MemoryRepository
C:\Windows\system32\FileGammaRuby
C:\Windows\system32\finderwdmaud32
C:\Windows\system32\FirmwareIconRoot
C:\Windows\system32\InterpreterMacroNet
C:\Windows\system32\interpretermotionBckp
C:\Windows\system32\MetafileTaskWizard
C:\Windows\system32\minimalrasplapProt
C:\Windows\system32\NativeSharewareUtility
C:\Windows\system32\ODBCOpenTrash
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{03C4C5F4-1893-444C-B8D8-002F0034DA92}\InprocServer32 -> C:\Users\brodpers\AppData\Local\LECLOU~1\bin\REDEMP~1.DLL No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{11E2BC0C-5D4F-4E0C-B438-501FFE05A382}\InprocServer32 -> C:\Users\brodpers\AppData\Local\LECLOU~1\bin\REDEMP~1.DLL No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{29AB7A12-B531-450E-8F7A-EA94C2F3C05F}\InprocServer32 -> C:\Users\brodpers\AppData\Local\LECLOU~1\bin\REDEMP~1.DLL No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{37587889-FC28-4507-B6D3-8557305F7511}\InprocServer32 -> C:\Users\brodpers\AppData\Local\LECLOU~1\bin\REDEMP~1.DLL No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{4A5E947E-C407-4DCC-A0B5-5658E457153B}\InprocServer32 -> C:\Users\brodpers\AppData\Local\LECLOU~1\bin\REDEMP~1.DLL No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{4FD5C4D3-6C15-4EA0-9EB9-EEE8FC74A91B}\InprocServer32 -> C:\Users\brodpers\AppData\Local\LECLOU~1\bin\REDEMP~1.DLL No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{5EEC505D-DD30-4B61-A46C-2E1D5F880897}\InprocServer32 -> C:\Users\brodpers\AppData\Local\Le Cloud Orange\addins\outlookAddin.dll No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{620D55B0-F2FB-464E-A278-B4308DB1DB2B}\InprocServer32 -> C:\Users\brodpers\AppData\Local\LECLOU~1\bin\REDEMP~1.DLL No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{741BEEFD-AEC0-4AFF-84AF-4F61D15F5526}\InprocServer32 -> C:\Users\brodpers\AppData\Local\LECLOU~1\bin\REDEMP~1.DLL No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{7A41359E-0407-470F-B3F7-7C6A0F7C449A}\InprocServer32 -> C:\Users\brodpers\AppData\Local\LECLOU~1\bin\REDEMP~1.DLL No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{7C4A630A-DE98-4E3E-8093-E8F5E159BB72}\InprocServer32 -> C:\Users\brodpers\AppData\Local\LECLOU~1\bin\REDEMP~1.DLL No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{7ED1E9B1-CB57-4FA0-84E8-FAE653FE8E6B}\InprocServer32 -> C:\Users\brodpers\AppData\Local\LECLOU~1\bin\REDEMP~1.DLL No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}\localserver32 -> "C:\Users\brodpers\AppData\Local\Vosteran\Application\31.0.1650.23\delegate_execute.exe" No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{A6931B16-90FA-4D69-A49F-3ABFA2C04060}\InprocServer32 -> C:\Users\brodpers\AppData\Local\LECLOU~1\bin\REDEMP~1.DLL No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{C5AA36A1-8BD1-47E0-90F8-47E7239C6EA1}\InprocServer32 -> C:\Users\brodpers\AppData\Local\LECLOU~1\bin\REDEMP~1.DLL No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{D46BA7B2-899F-4F60-85C7-4DF5713F6F18}\InprocServer32 -> C:\Users\brodpers\AppData\Local\LECLOU~1\bin\REDEMP~1.DLL No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{ED323630-B4FD-4628-BC6A-D4CC44AE3F00}\InprocServer32 -> C:\Users\brodpers\AppData\Local\LECLOU~1\bin\REDEMP~1.DLL No File
CustomCLSID: HKU\S-1-5-21-996361165-524870672-62288233-1000_Classes\CLSID\{FA2CBAFB-F7B1-4F41-9B7A-73329A6C1CB7}\InprocServer32 -> C:\Users\brodpers\AppData\Local\LECLOU~1\bin\REDEMP~1.DLL No File
EmptyTemp:
end - Enregistre le fichier sur ton Bureau (au même endroit que FRST) sous le nom fixlist.txt
- Ferme toutes les applications, y compris ton navigateur
- Double-clique sur FRST.exe
/!\ Sous Vista, Windows 7 et 8, il faut lancer le fichier par clic-droit -> Exécuter en tant qu'administrateur - Sur le menu principal, clique une seule fois sur Fix
et patiente le temps de la correction
- L'outil va créer un rapport de correction Fixlog.txt. Poste ce rapport dans ta réponse.
--------------------------------------------------------------------------------------------------------------
Est attendu le rapport Fixlog
@+