| |||||||||
Petit astucien | Bonjour, je viens d'être infesté par win32 agent qvo. non detecté par spybot adwcleaner est inefficace. malwarebytes n'arrive pas à la fin du scan, il se bloque puis l'ordi s'éteint. J'ai essayé en mode sans échec, il dure plus longtemps mais il se bloque encore, il en détecte 4 dans le registre. Comment faire s'il vous plait. C'est mon outil de travail. Merci de votre aide.
| ||||||||
Publicité | |||||||||
| |||||||||
Grand Maître astucien ![]() | Bonjour,
Fill | ||||||||
Petit astucien | Bonjour,
Merci pour votre réponse rapide. j'étais à l'affût. C'est le logiciel spybot qui l'a trouvé, cccleaner ne le voit pas, malwarebytes's le détecte mais ce bloque, je ne peux pas aller jusqu’à la mise en quarantaine. (au maximum 100000 fichier verifiés - 29 minutes). J'ai essayé également en mode sans echec : echec ! Je correspond aux critères pas de problème. On y va, si on peut résoudre cela dans la journée c'est super. Je lance les rapports. A tte à l'heure et merci
| ||||||||
Petit astucien | Fichier joint : AdwCleaner[R2].txt | ||||||||
Petit astucien | Fichier joint : ZHPDiag.txt | ||||||||
Petit astucien | Fichier joint : mbam-log-2014-06-03 (08-40-17).txt | ||||||||
Petit astucien | Re-bonjour,
Voilà les 3 rapports. Le dernier, de mbam est un rapport rapide. il ne détecte rien. C'est quand je lance l'analyse "complète" qu'il détecte les virus. Mais là ça se bloque. Je refais une tentative. | ||||||||
Petit astucien | Voilà au bout de 2 mn et 29 000 fichiers inspectés il se bloque : " ne répond pas". Il arque notamment : 4 éléments détectés en rouge. Que faire ? Merci pour ta réponse.
| ||||||||
![]() ![]() | Bonjour ! Tu devrais RELIRE les instructions de Fill. Ta version de Malwarebyte n'est pas à jour ! Désinstalle Malwarebyte et installe la nouvelle version préconisée dans le tuto de Fill. Il faut lire les instructions que l'on te donne !!! | ||||||||
Grand Maître astucien ![]() | Re, 1/ ZHPDiag n'est pas correctement configuré :
Dans la page suivante, cliquer sur "Parcourir" pour pointer vers le rapport ZHPDiag.txt qui devrait être sur votre bureau ou en C:
Cliquer maintenant sur "Envoyer" Les explications en détails
Remarque : Si le rapport est trop volumineux pour l'héberger de cette façon, passer par un hébergeur comme Cjoint par exemple en cochant 4 jours pour la durée d'hébergement. Communiquer le lien obtenu. 2/
3/
Fill | ||||||||
Petit astucien | C'est ok , je suis en train de faire le nécessaire. Merci
voici le premier rapport. | ||||||||
Petit astucien | Fichier joint : ZHPDiag.txt | ||||||||
Petit astucien | Voici le rapport de ROGUEKILLER Je passe au 3ème point :
RogueKiller V9.0.1.0 [Jun 2 2014] par Adlice Software Mail : http://www.adlice.com/contact/ Remontées : http://forum.adlice.com Site Web : http://www.adlice.com/softwares/roguekiller/ Blog : http://www.adlice.com
Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version Démarrage : Mode normal Utilisateur : Daniel [Droits d'admin] Mode : Recherche -- Date : 06/03/2014 17:11:15
¤¤¤ Processus malicieux : 0 ¤¤¤
¤¤¤ Entrées de registre : 4 ¤¤¤ [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> TROUVÉ [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> TROUVÉ [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> TROUVÉ [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> TROUVÉ
¤¤¤ Tâches planifiées : 0 ¤¤¤
¤¤¤ Fichiers : 0 ¤¤¤
¤¤¤ Fichier HOSTS : 0 [Too big!] ¤¤¤
¤¤¤ Antirootkit : 0 ¤¤¤
¤¤¤ Navigateurs web : 0 ¤¤¤
¤¤¤ MBR Verif : ¤¤¤ +++++ PhysicalDrive0: TOSHIBA MK7575GSX +++++ --- User --- [MBR] 0cc5fb16241d632903b1ad4355cb28d9 [BSP] a51a2462f98ba4902560c81a00c7a1e9 : Unknown MBR Code Partition table: 0 - [ACTIVE] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 1500 MB 1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 3074048 | Size: 698817 MB 2 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 1434251264 | Size: 15086 MB User = LL1 ... OK User = LL2 ... OK
+++++ PhysicalDrive1: G & T USB Flash Drive USB Device +++++ --- User --- [MBR] 552e525f27ba2a2e83cf15398939a31e [BSP] e75f2679424be588d79049db7be0b571 : Unknown MBR Code Partition table: 0 - [ACTIVE] FAT16 (0x6) [VISIBLE] Offset (sectors): 32 | Size: 1959 MB User = LL1 ... OK Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )
| ||||||||
Petit astucien | Fichier joint : FRST.txt | ||||||||
Petit astucien | Fichier joint : Addition.txt | ||||||||
Petit astucien | Voilà tous les rapports sont postés.
J'attends vos autres remarques.
Merci encore | ||||||||
PC Astuces a besoin de vous pour survivre. Nos conseils et astuces vous ont aidé ? Vous avez résolu un problème sur votre ordinateur ? Vous avez profité de nos bons plans ? Aidez-nous en retour avec un abonnement de soutien mensuel. 5 € par mois 10 € par mois 20 € par mois
| |||||||||
Petit astucien | Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-06-2014 Ran by Daniel (administrator) on DANIEL-TO on 03-06-2014 17:28:01 Running from C:\Users\Daniel\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: French Standard Internet Explorer Version 10 Boot Mode: Normal
The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Druide informatique inc.) C:\Program Files (x86)\Druide\Antidote 8\Programmes32\AgentAntidote.exe (Druide informatique inc.) C:\Program Files (x86)\Druide\Antidote 8\Programmes64\AgentAntidote.exe (TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Google Inc.) C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcagent.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TRCMan\TRCMan.exe () C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (CybelSoft) C:\Program Files\ma-config.com\MaConfigAgent.exe (Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe (Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (WDC) C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (Western Digital) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe (Western Digital ) C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe (Memeo) C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe () C:\Program Files (x86)\Belkin\F7D4101\V1\wlansrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe (Western Digital ) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [] => [X] HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [566696 2011-03-02] (TOSHIBA Corporation) HKLM\...\Run: [HSON] => C:\Program Files\TOSHIBA\TBS\HSON.exe [296824 2010-09-25] (TOSHIBA Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11775592 2011-01-26] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2188904 2011-01-18] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2679592 2011-02-04] (Synaptics Incorporated) HKLM\...\Run: [ThpSrv] => C:\windows\system32\thpsrv /logon HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [710040 2010-12-09] (TOSHIBA Corporation) HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation) HKLM\...\Run: [TosNC] => C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [597928 2011-03-03] (TOSHIBA Corporation) HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38304 2010-12-14] (TOSHIBA Corporation) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM\...\Run: [AgentAntidote32] => C:\Program Files (x86)\Druide\Antidote 8\Programmes32\AgentAntidote.exe [1144544 2013-11-12] (Druide informatique inc.) HKLM\...\Run: [AgentAntidote64] => C:\Program Files (x86)\Druide\Antidote 8\Programmes64\AgentAntidote.exe [1294560 2013-11-12] (Druide informatique inc.) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.) HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [1659976 2011-06-23] (McAfee, Inc.) HKLM-x32\...\Run: [SVPWUTIL] => C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe [532480 2010-11-09] (TOSHIBA) HKLM-x32\...\Run: [HWSetup] => C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [423936 2010-03-05] (TOSHIBA Electronics, Inc.) HKLM-x32\...\Run: [KeNotify] => C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [34160 2010-08-16] (TOSHIBA CORPORATION) HKLM-x32\...\Run: [TSleepSrv] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe [252792 2010-06-05] (TOSHIBA) HKLM-x32\...\Run: [TRCMan] => C:\Program Files (x86)\TOSHIBA\TRCMan\TRCMan.exe [714104 2010-11-02] (TOSHIBA Corporation) HKLM-x32\...\Run: [PPort12reminder] => C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe [328992 2010-02-09] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PDFHook] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PDF5 Registry Controller] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.) HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139264 2010-10-26] (Brother Industries, Ltd.) HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [WSHelperSetup.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1985824 2013-07-25] (Wondershare) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1985824 2013-07-25] (Wondershare) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [453736 2013-02-19] (CANON INC.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3888648 2014-06-02] (AVAST Software) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\.DEFAULT\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA) HKU\S-1-5-19\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA) HKU\S-1-5-20\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA) HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA) HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\Run: [Google Update] => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-19] (Google Inc.) HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22415552 2014-04-25] (Google) HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\Run: [WSHelperSetup.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1985824 2013-07-25] (Wondershare) HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\Run: [2D7856E7538B13D026A66639D73BA27D30F728D9._service_run] => C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe [860488 2014-05-14] (Google Inc.) HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [248208 2013-08-27] (TomTom) HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\MountPoints2: E - E:\LaunchU3.exe -a HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\MountPoints2: {32ada670-0d51-11e3-b748-b4749ff44d4a} - E:\AutoRun.exe HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\MountPoints2: {7d674823-c35a-11e0-8707-b870f4652d7b} - "F:\WD SmartWare.exe" autoplay=true HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\MountPoints2: {d7cebd86-8c0e-11e0-b1d2-806e6f6e6963} - D:\Autorun.exe AppInit_DLLs: C:\windows\system32\nvinitx.dll => C:\windows\system32\nvinitx.dll [226920 2011-03-02] (NVIDIA Corporation) AppInit_DLLs-x32: C:\windows\SysWOW64\nvinit.dll => C:\windows\SysWOW64\nvinit.dll [192616 2011-03-02] (NVIDIA Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dsites&cd=2XzuyEtN2Y1L1Qzu0DyCyByEzy0F0FyEyE0DyE0A0AtAtCyCtN0D0Tzu0CyBtDzytN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=65021605&ir= SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {2FDC286B-A4C9-4846-9BFE-EAE8D3B8B7F6} URL = SearchScopes: HKCU - {E5778874-C726-4E36-8E64-32D0AAF7C159} URL = BHO: No Name - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexbho.dll (CANON INC.) BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110817083024.dll (McAfee, Inc.) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) BHO-x32: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - C:\Program Files\mcafee\msk\mskapbho.dll () BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO-x32: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110817083024.dll (McAfee, Inc.) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>) Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexhlp.dll (CANON INC.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll () FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF Plugin-x32: @glowria.fr/FireVMGate - C:\Program Files (x86)\Common Files\Glowria\npFireVMGate.dll ( Glowria) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\progra~2\mcafee\msc\npmcsn~1.dll () FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\8\NP_wtapp.dll () FF Plugin-x32: @zylom.com/ZylomGamesPlayer - C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: LWAPlugin15.8 - C:\Users\Daniel\AppData\Roaming\Mozilla\Plugins\npLWAPlugin15.8.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Users\Daniel\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google) FF Plugin ProgramFiles/Appdata: C:\Users\Daniel\AppData\Roaming\mozilla\plugins\npLWAPlugin15.8.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Users\Daniel\AppData\Roaming\mozilla\plugins\npo1d.dll (Google) FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2011-04-15]
Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR StartupUrls: "https://news.google.fr/" CHR Plugin: (Shockwave Flash) - C:\Users\Daniel\AppData\Local\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Shockwave Flash) - C:\Users\Daniel\AppData\Local\Google\Chrome\Application\35.0.1916.114\gcswf32.dll No File CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Daniel\AppData\Local\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Daniel\AppData\Local\Google\Chrome\Application\35.0.1916.114\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Glowria Firefox Gateway for Video Manager) - C:\Program Files (x86)\Common Files\Glowria\npFireVMGate.dll ( Glowria) CHR Plugin: (Java(TM) Platform SE 7 U6) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.60.24) - C:\windows\SysWOW64\npDeployJava1.dll No File CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.) CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll () CHR Extension: (Google Drive) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-06] CHR Extension: (Azov Sea Theme) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\edlbggommlbjkfcfpclbcffgfkmkmega [2014-02-23] CHR Extension: (Feuilles de calcul Google ) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2013-01-13] CHR Extension: (SiteAdvisor) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2013-10-26] CHR Extension: (Antidote) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnhgdodmhnpmndnljbmafpgomahfal [2013-12-14] CHR Extension: (Google Wallet) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21] CHR HKLM\...\Chrome\Extension: [mjcnhgdodmhnpmndnljbmafpgomahfal] - C:\Program Files (x86)\Druide\Antidote 8\Texteurs\GoogleChrome\Installation.Antidote.GoogleChrome.crx [2013-11-12] CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Daniel\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-05-06] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2014-03-13] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-01-17] CHR HKLM-x32\...\Chrome\Extension: [mjcnhgdodmhnpmndnljbmafpgomahfal] - C:\Program Files (x86)\Druide\Antidote 8\Texteurs\GoogleChrome\Installation.Antidote.GoogleChrome.crx [2013-11-12] CHR StartMenuInternet: Google Chrome - C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-06-02] (AVAST Software) S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-03-29] (WildTangent) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] () R2 MaConfigAgent; C:\Program Files\ma-config.com\MaConfigAgent.exe [2542416 2013-10-04] (CybelSoft) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) S3 McAWFwk; C:\Program Files\mcafee\msc\McAWFwk.exe [220528 2010-08-09] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) U2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [501768 2011-06-23] (McAfee, Inc.) S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [197960 2011-03-13] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [208272 2011-03-13] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [158832 2011-03-13] (McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.) S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH) R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1157056 2012-09-19] (Western Digital ) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [248248 2012-09-19] (Western Digital) R2 WDRulesService; C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe [1177536 2012-09-19] (Western Digital ) R2 WLANBelkinService; C:\Program Files (x86)\Belkin\F7D4101\V1\wlansrv.exe [36864 2009-12-28] ()
==================== Drivers (Whitelisted) ====================
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-06-02] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-06-02] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-06-02] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-06-02] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-06-02] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-06-02] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-06-02] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-06-02] () R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [65128 2011-03-13] (McAfee, Inc.) S3 FsUsbExDisk; C:\windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-07-18] () R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-03] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [156792 2011-03-13] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [227856 2011-03-13] (McAfee, Inc.) U3 mfeavfk01; No ImagePath R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [481376 2011-03-13] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [639216 2011-03-13] (McAfee, Inc.) R1 mfenlfk; C:\Windows\System32\DRIVERS\mfenlfk.sys [75672 2011-03-13] (McAfee, Inc.) S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [98728 2011-03-13] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [281928 2011-03-13] (McAfee, Inc.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-03 17:27 - 2014-06-03 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2014-06-03 17:17 - 2014-06-03 17:29 - 00030693 _____ () C:\Users\Daniel\Desktop\FRST.txt 2014-06-03 17:17 - 2014-06-03 17:29 - 00000000 ____D () C:\FRST 2014-06-03 17:16 - 2014-06-03 17:16 - 02068992 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2014-06-03 17:01 - 2014-06-03 17:01 - 00000000 ____D () C:\ProgramData\RogueKiller 2014-06-03 17:00 - 2014-06-03 17:28 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-03 16:59 - 2014-06-03 16:59 - 00001073 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-06-03 16:59 - 2014-06-03 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-06-03 16:59 - 2014-06-03 16:59 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-06-03 16:59 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-06-03 16:59 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-06-03 16:59 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-06-03 16:44 - 2014-06-03 16:44 - 00044757 _____ () C:\Users\Daniel\Desktop\ZHPDiag.txt 2014-06-03 16:43 - 2014-06-03 16:43 - 00000512 _____ () C:\PhysicalDisk0_MBR.bin 2014-06-03 13:11 - 2014-06-03 13:11 - 00016596 _____ () C:\Users\Daniel\Downloads\Operation Littoral 2014 v2.xlsx 2014-06-03 08:13 - 2014-06-03 08:13 - 00001958 _____ () C:\Users\Daniel\Desktop\ZHPFix.lnk 2014-06-03 08:13 - 2014-06-03 08:13 - 00001831 _____ () C:\Users\Daniel\Desktop\ZHPDiag.lnk 2014-06-03 08:13 - 2014-06-03 08:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP 2014-06-03 08:12 - 2014-06-03 16:40 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\ZHP 2014-06-03 08:12 - 2014-06-03 08:13 - 00000000 ____D () C:\Program Files (x86)\ZHPDiag 2014-06-02 21:53 - 2014-06-03 16:48 - 00000672 _____ () C:\windows\PFRO.log 2014-06-02 14:18 - 2014-06-03 17:23 - 00002249 _____ () C:\windows\setupact.log 2014-06-02 14:18 - 2014-06-02 14:18 - 00000000 _____ () C:\windows\setuperr.log 2014-06-02 13:46 - 2014-06-02 13:46 - 00000000 ____D () C:\Intel 2014-06-02 10:03 - 2014-06-02 10:04 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Dropbox 2014-06-02 10:01 - 2014-06-02 10:01 - 36818984 _____ (Dropbox, Inc.) C:\Users\Public\Desktop\DropboxInstallerAvast.exe 2014-06-02 09:40 - 2014-06-02 09:40 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\AVAST Software 2014-06-02 09:33 - 2014-06-02 12:23 - 00085328 _____ (AVAST Software) C:\windows\system32\Drivers\aswstm.sys 2014-06-02 09:33 - 2014-06-02 09:33 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr 2014-06-02 09:33 - 2014-06-02 09:33 - 00029208 _____ () C:\windows\system32\Drivers\aswHwid.sys 2014-06-02 09:33 - 2014-06-02 09:33 - 00001977 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-06-01 08:20 - 2014-06-01 08:20 - 00010022 _____ () C:\Users\Daniel\Downloads\JWORG_Contacts_20140601062020.csv 2014-05-31 20:39 - 2014-05-31 20:39 - 00001938 _____ () C:\Users\Daniel\Downloads\google.csv 2014-05-31 19:17 - 2014-05-31 19:19 - 00000000 ___HD () C:\ProgramData\CanonIJScan 2014-05-26 16:50 - 2014-05-26 16:50 - 00055967 _____ () C:\Users\Daniel\Downloads\folder.zip 2014-05-20 06:15 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe 2014-05-20 06:14 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll 2014-05-20 06:14 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe 2014-05-20 06:14 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe 2014-05-20 06:13 - 2014-05-20 06:14 - 00004165 _____ () C:\windows\SysWOW64\jupdate-1.7.0_55-b14.log 2014-05-16 06:30 - 2014-05-16 06:30 - 00001990 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk 2014-05-12 16:44 - 2014-05-12 16:45 - 00000000 ____D () C:\Program Files\Microsoft Mouse and Keyboard Center 2014-05-12 16:40 - 2014-05-12 16:40 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_NuidFltr_01011.Wdf 2014-05-12 16:40 - 2014-05-12 16:40 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_dc3d_01011.Wdf 2014-05-10 08:00 - 2014-05-10 08:00 - 00019968 _____ () C:\Users\Daniel\Downloads\prog.sem.spéciale du 22 au 27 janv. 2014.wps 2014-05-05 10:13 - 2014-05-05 10:13 - 00000000 ___RD () C:\Users\Daniel\Desktop\Ludique 2014-05-05 10:11 - 2014-06-03 17:17 - 00000000 ____D () C:\Users\Daniel\Desktop\Logiciels nettoyage ordinateur 2014-05-05 10:04 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll 2014-05-05 10:03 - 2014-06-03 08:08 - 00000000 ____D () C:\AdwCleaner 2014-05-04 18:05 - 2014-05-04 18:05 - 00003158 _____ () C:\windows\System32\Tasks\{51C4114D-4751-41F8-992C-D8424DB00513} 2014-05-04 16:46 - 2014-05-04 16:46 - 01745872 _____ (AnyProtect.com) C:\Users\Daniel\AppData\Local\nsj80E0.tmp
==================== One Month Modified Files and Folders =======
2014-06-03 17:30 - 2011-08-10 16:00 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Temp 2014-06-03 17:29 - 2014-06-03 17:17 - 00030693 _____ () C:\Users\Daniel\Desktop\FRST.txt 2014-06-03 17:29 - 2014-06-03 17:17 - 00000000 ____D () C:\FRST 2014-06-03 17:28 - 2014-06-03 17:00 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-03 17:27 - 2014-06-03 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2014-06-03 17:27 - 2012-12-24 20:24 - 00000000 ___RD () C:\Users\Daniel\Google Drive 2014-06-03 17:26 - 2012-07-10 22:19 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update 2014-06-03 17:24 - 2013-01-28 08:52 - 00000356 _____ () C:\windows\Tasks\ROC_JAN2013_TB_rmv.job 2014-06-03 17:24 - 2012-12-24 20:19 - 00001064 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-03 17:23 - 2014-06-02 14:18 - 00002249 _____ () C:\windows\setupact.log 2014-06-03 17:23 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-06-03 17:20 - 2009-07-14 06:45 - 00025120 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-03 17:20 - 2009-07-14 06:45 - 00025120 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-03 17:17 - 2014-05-05 10:11 - 00000000 ____D () C:\Users\Daniel\Desktop\Logiciels nettoyage ordinateur 2014-06-03 17:16 - 2014-06-03 17:16 - 02068992 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2014-06-03 17:11 - 2011-06-01 07:12 - 01627982 _____ () C:\windows\WindowsUpdate.log 2014-06-03 17:10 - 2011-08-10 20:18 - 00003944 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{0E0E53BB-7B20-4E24-81E0-1F4D8DBD5061} 2014-06-03 17:01 - 2014-06-03 17:01 - 00000000 ____D () C:\ProgramData\RogueKiller 2014-06-03 16:59 - 2014-06-03 16:59 - 00001073 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-06-03 16:59 - 2014-06-03 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-06-03 16:59 - 2014-06-03 16:59 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-06-03 16:59 - 2012-07-19 17:32 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-03 16:48 - 2014-06-02 21:53 - 00000672 _____ () C:\windows\PFRO.log 2014-06-03 16:44 - 2014-06-03 16:44 - 00044757 _____ () C:\Users\Daniel\Desktop\ZHPDiag.txt 2014-06-03 16:43 - 2014-06-03 16:43 - 00000512 _____ () C:\PhysicalDisk0_MBR.bin 2014-06-03 16:41 - 2012-07-19 08:49 - 00001082 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1234134681-625734610-604210244-1001UA.job 2014-06-03 16:40 - 2014-06-03 08:12 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\ZHP 2014-06-03 13:11 - 2014-06-03 13:11 - 00016596 _____ () C:\Users\Daniel\Downloads\Operation Littoral 2014 v2.xlsx 2014-06-03 12:29 - 2012-12-24 20:19 - 00001068 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-03 11:44 - 2011-08-10 16:52 - 00000000 ____D () C:\Users\Daniel\Desktop\Surveillant circonscription 2014-06-03 10:55 - 2011-02-11 18:16 - 00062136 _____ () C:\windows\system32\perfh00C.dat 2014-06-03 10:55 - 2011-02-11 18:16 - 00026434 _____ () C:\windows\system32\perfc00C.dat 2014-06-03 10:55 - 2009-07-14 07:13 - 00852874 _____ () C:\windows\system32\PerfStringBackup.INI 2014-06-03 10:01 - 2011-06-01 07:16 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Temp 2014-06-03 08:13 - 2014-06-03 08:13 - 00001958 _____ () C:\Users\Daniel\Desktop\ZHPFix.lnk 2014-06-03 08:13 - 2014-06-03 08:13 - 00001831 _____ () C:\Users\Daniel\Desktop\ZHPDiag.lnk 2014-06-03 08:13 - 2014-06-03 08:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP 2014-06-03 08:13 - 2014-06-03 08:12 - 00000000 ____D () C:\Program Files (x86)\ZHPDiag 2014-06-03 08:08 - 2014-05-05 10:03 - 00000000 ____D () C:\AdwCleaner 2014-06-02 21:48 - 2014-04-10 17:14 - 00085504 ___SH () C:\Users\Daniel\Desktop\Thumbs.db 2014-06-02 15:16 - 2011-08-10 16:52 - 00000000 ____D () C:\Users\Daniel\Documents\Assemblée de District 2014-06-02 15:03 - 2011-08-10 20:02 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-06-02 14:18 - 2014-06-02 14:18 - 00000000 _____ () C:\windows\setuperr.log 2014-06-02 13:46 - 2014-06-02 13:46 - 00000000 ____D () C:\Intel 2014-06-02 12:23 - 2014-06-02 09:33 - 00085328 _____ (AVAST Software) C:\windows\system32\Drivers\aswstm.sys 2014-06-02 12:23 - 2011-08-10 22:03 - 01039096 _____ (AVAST Software) C:\windows\system32\Drivers\aswsnx.sys 2014-06-02 12:23 - 2011-08-10 22:03 - 00423240 _____ (AVAST Software) C:\windows\system32\Drivers\aswsp.sys 2014-06-02 10:04 - 2014-06-02 10:03 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Dropbox 2014-06-02 10:01 - 2014-06-02 10:01 - 36818984 _____ (Dropbox, Inc.) C:\Users\Public\Desktop\DropboxInstallerAvast.exe 2014-06-02 09:40 - 2014-06-02 09:40 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\AVAST Software 2014-06-02 09:33 - 2014-06-02 09:33 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr 2014-06-02 09:33 - 2014-06-02 09:33 - 00029208 _____ () C:\windows\system32\Drivers\aswHwid.sys 2014-06-02 09:33 - 2014-06-02 09:33 - 00001977 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-06-02 09:33 - 2013-04-07 15:31 - 00208416 _____ () C:\windows\system32\Drivers\aswVmm.sys 2014-06-02 09:33 - 2013-04-07 15:31 - 00065776 _____ () C:\windows\system32\Drivers\aswRvrt.sys 2014-06-02 09:33 - 2012-03-29 10:41 - 00093568 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys 2014-06-02 09:33 - 2011-08-10 22:03 - 01039096 _____ (AVAST Software) C:\windows\system32\Drivers\aswsnx.sys.1401704627312 2014-06-02 09:33 - 2011-08-10 22:03 - 00423240 _____ (AVAST Software) C:\windows\system32\Drivers\aswsp.sys.1401704627312 2014-06-02 09:33 - 2011-08-10 22:03 - 00334648 _____ (AVAST Software) C:\windows\system32\aswBoot.exe 2014-06-02 09:33 - 2011-08-10 22:03 - 00079184 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys 2014-06-02 09:31 - 2011-08-10 22:03 - 00000000 _____ () C:\windows\SysWOW64\config.nt 2014-06-02 09:31 - 2011-08-10 22:02 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-06-01 08:20 - 2014-06-01 08:20 - 00010022 _____ () C:\Users\Daniel\Downloads\JWORG_Contacts_20140601062020.csv 2014-06-01 07:41 - 2012-07-19 08:49 - 00001030 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1234134681-625734610-604210244-1001Core.job 2014-06-01 07:35 - 2014-02-23 19:57 - 00000000 ____D () C:\ProgramData\CanonIJPLM 2014-05-31 20:39 - 2014-05-31 20:39 - 00001938 _____ () C:\Users\Daniel\Downloads\google.csv 2014-05-31 19:19 - 2014-05-31 19:17 - 00000000 ___HD () C:\ProgramData\CanonIJScan 2014-05-31 19:17 - 2011-12-31 23:23 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Canon 2014-05-31 07:25 - 2013-05-20 11:54 - 11408384 ___SH () C:\Users\Daniel\Downloads\Thumbs.db 2014-05-26 20:35 - 2012-07-19 15:59 - 00000000 ____D () C:\Program Files\CCleaner 2014-05-26 16:50 - 2014-05-26 16:50 - 00055967 _____ () C:\Users\Daniel\Downloads\folder.zip 2014-05-23 11:14 - 2011-08-10 19:52 - 00025892 _____ () C:\Users\Daniel\Documents\finances personnelles.xlsx 2014-05-23 11:05 - 2011-12-12 19:09 - 00000000 ____D () C:\Users\Daniel\Documents\Publications en pdf 2014-05-22 06:34 - 2009-07-14 07:32 - 00000000 ____D () C:\windows\system32\FxsTmp 2014-05-21 22:08 - 2014-01-06 17:23 - 00000000 ____D () C:\Users\Daniel\Documents\Cycle 2014b 2014-05-20 06:15 - 2013-10-21 11:23 - 00000000 ____D () C:\ProgramData\Oracle 2014-05-20 06:14 - 2014-05-20 06:13 - 00004165 _____ () C:\windows\SysWOW64\jupdate-1.7.0_55-b14.log 2014-05-20 06:14 - 2011-04-14 23:34 - 00000000 ____D () C:\Program Files (x86)\Java 2014-05-19 13:10 - 2011-08-10 16:52 - 00000000 ____D () C:\Users\Daniel\Documents\Dossiers Divers 2014-05-16 06:30 - 2014-05-16 06:30 - 00001990 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk 2014-05-16 06:30 - 2011-04-14 23:40 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2014-05-12 22:14 - 2012-07-17 15:22 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Skype 2014-05-12 16:46 - 2013-10-22 09:53 - 00003118 _____ () C:\windows\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe 2014-05-12 16:46 - 2013-10-22 09:53 - 00003090 _____ () C:\windows\System32\Tasks\Microsoft_Hardware_Launch_itype_exe 2014-05-12 16:46 - 2013-10-22 09:53 - 00003062 _____ () C:\windows\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe 2014-05-12 16:46 - 2013-10-22 09:53 - 00003060 _____ () C:\windows\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe 2014-05-12 16:46 - 2011-08-10 23:00 - 00003092 _____ () C:\windows\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe 2014-05-12 16:45 - 2014-05-12 16:44 - 00000000 ____D () C:\Program Files\Microsoft Mouse and Keyboard Center 2014-05-12 16:40 - 2014-05-12 16:40 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_NuidFltr_01011.Wdf 2014-05-12 16:40 - 2014-05-12 16:40 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_dc3d_01011.Wdf 2014-05-12 07:26 - 2014-06-03 16:59 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:26 - 2014-06-03 16:59 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-06-03 16:59 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-05-10 08:00 - 2014-05-10 08:00 - 00019968 _____ () C:\Users\Daniel\Downloads\prog.sem.spéciale du 22 au 27 janv. 2014.wps 2014-05-10 07:36 - 2012-07-19 08:49 - 00004054 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1234134681-625734610-604210244-1001UA 2014-05-10 07:36 - 2012-07-19 08:49 - 00003658 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1234134681-625734610-604210244-1001Core 2014-05-09 16:35 - 2012-12-24 20:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2014-05-09 16:19 - 2013-03-15 23:29 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-05-09 16:19 - 2013-03-15 23:29 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-05-08 15:32 - 2013-03-15 23:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-05-08 07:24 - 2012-12-24 20:19 - 00004064 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-08 07:24 - 2012-12-24 20:19 - 00003812 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-05-06 07:30 - 2012-12-27 12:59 - 00001912 _____ () C:\windows\epplauncher.mif 2014-05-06 07:30 - 2012-12-27 12:58 - 00002128 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk 2014-05-06 07:29 - 2012-12-27 12:58 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2014-05-06 07:29 - 2012-12-27 12:58 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client 2014-05-05 10:13 - 2014-05-05 10:13 - 00000000 ___RD () C:\Users\Daniel\Desktop\Ludique 2014-05-04 18:06 - 2011-08-10 16:08 - 00001440 _____ () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-04 18:05 - 2014-05-04 18:05 - 00003158 _____ () C:\windows\System32\Tasks\{51C4114D-4751-41F8-992C-D8424DB00513} 2014-05-04 17:36 - 2013-07-23 16:45 - 00000556 _____ () C:\windows\wininit.ini 2014-05-04 17:07 - 2011-08-10 16:00 - 00000000 ___RD () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-04 16:46 - 2014-05-04 16:46 - 01745872 _____ (AnyProtect.com) C:\Users\Daniel\AppData\Local\nsj80E0.tmp 2014-05-04 16:35 - 2011-08-10 16:36 - 00000000 ___RD () C:\Users\Daniel\Desktop\Logiciels divers 2014-05-04 14:05 - 2009-07-14 07:08 - 00032496 _____ () C:\windows\Tasks\SCHEDLGU.TXT
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-24 07:18
==================== End Of Log ============================ | ||||||||
Petit astucien | Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-06-2014 Ran by Daniel (administrator) on DANIEL-TO on 03-06-2014 17:28:01 Running from C:\Users\Daniel\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: French Standard Internet Explorer Version 10 Boot Mode: Normal
The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Druide informatique inc.) C:\Program Files (x86)\Druide\Antidote 8\Programmes32\AgentAntidote.exe (Druide informatique inc.) C:\Program Files (x86)\Druide\Antidote 8\Programmes64\AgentAntidote.exe (TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Google Inc.) C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcagent.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TRCMan\TRCMan.exe () C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (CybelSoft) C:\Program Files\ma-config.com\MaConfigAgent.exe (Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe (Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (WDC) C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (Western Digital) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe (Western Digital ) C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe (Memeo) C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe () C:\Program Files (x86)\Belkin\F7D4101\V1\wlansrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe (Western Digital ) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [] => [X] HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [566696 2011-03-02] (TOSHIBA Corporation) HKLM\...\Run: [HSON] => C:\Program Files\TOSHIBA\TBS\HSON.exe [296824 2010-09-25] (TOSHIBA Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11775592 2011-01-26] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2188904 2011-01-18] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2679592 2011-02-04] (Synaptics Incorporated) HKLM\...\Run: [ThpSrv] => C:\windows\system32\thpsrv /logon HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [710040 2010-12-09] (TOSHIBA Corporation) HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation) HKLM\...\Run: [TosNC] => C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [597928 2011-03-03] (TOSHIBA Corporation) HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38304 2010-12-14] (TOSHIBA Corporation) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM\...\Run: [AgentAntidote32] => C:\Program Files (x86)\Druide\Antidote 8\Programmes32\AgentAntidote.exe [1144544 2013-11-12] (Druide informatique inc.) HKLM\...\Run: [AgentAntidote64] => C:\Program Files (x86)\Druide\Antidote 8\Programmes64\AgentAntidote.exe [1294560 2013-11-12] (Druide informatique inc.) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.) HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [1659976 2011-06-23] (McAfee, Inc.) HKLM-x32\...\Run: [SVPWUTIL] => C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe [532480 2010-11-09] (TOSHIBA) HKLM-x32\...\Run: [HWSetup] => C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [423936 2010-03-05] (TOSHIBA Electronics, Inc.) HKLM-x32\...\Run: [KeNotify] => C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [34160 2010-08-16] (TOSHIBA CORPORATION) HKLM-x32\...\Run: [TSleepSrv] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe [252792 2010-06-05] (TOSHIBA) HKLM-x32\...\Run: [TRCMan] => C:\Program Files (x86)\TOSHIBA\TRCMan\TRCMan.exe [714104 2010-11-02] (TOSHIBA Corporation) HKLM-x32\...\Run: [PPort12reminder] => C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe [328992 2010-02-09] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PDFHook] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PDF5 Registry Controller] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.) HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139264 2010-10-26] (Brother Industries, Ltd.) HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [WSHelperSetup.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1985824 2013-07-25] (Wondershare) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1985824 2013-07-25] (Wondershare) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [453736 2013-02-19] (CANON INC.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3888648 2014-06-02] (AVAST Software) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\.DEFAULT\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA) HKU\S-1-5-19\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA) HKU\S-1-5-20\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA) HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [845176 2011-02-18] (TOSHIBA) HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\Run: [Google Update] => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-19] (Google Inc.) HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22415552 2014-04-25] (Google) HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\Run: [WSHelperSetup.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1985824 2013-07-25] (Wondershare) HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\Run: [2D7856E7538B13D026A66639D73BA27D30F728D9._service_run] => C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe [860488 2014-05-14] (Google Inc.) HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [248208 2013-08-27] (TomTom) HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\MountPoints2: E - E:\LaunchU3.exe -a HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\MountPoints2: {32ada670-0d51-11e3-b748-b4749ff44d4a} - E:\AutoRun.exe HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\MountPoints2: {7d674823-c35a-11e0-8707-b870f4652d7b} - "F:\WD SmartWare.exe" autoplay=true HKU\S-1-5-21-1234134681-625734610-604210244-1001\...\MountPoints2: {d7cebd86-8c0e-11e0-b1d2-806e6f6e6963} - D:\Autorun.exe AppInit_DLLs: C:\windows\system32\nvinitx.dll => C:\windows\system32\nvinitx.dll [226920 2011-03-02] (NVIDIA Corporation) AppInit_DLLs-x32: C:\windows\SysWOW64\nvinit.dll => C:\windows\SysWOW64\nvinit.dll [192616 2011-03-02] (NVIDIA Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dsites&cd=2XzuyEtN2Y1L1Qzu0DyCyByEzy0F0FyEyE0DyE0A0AtAtCyCtN0D0Tzu0CyBtDzytN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=65021605&ir= SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {2FDC286B-A4C9-4846-9BFE-EAE8D3B8B7F6} URL = SearchScopes: HKCU - {E5778874-C726-4E36-8E64-32D0AAF7C159} URL = BHO: No Name - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexbho.dll (CANON INC.) BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110817083024.dll (McAfee, Inc.) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) BHO-x32: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - C:\Program Files\mcafee\msk\mskapbho.dll () BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO-x32: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110817083024.dll (McAfee, Inc.) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>) Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\addon64\ewpexhlp.dll (CANON INC.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll () FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF Plugin-x32: @glowria.fr/FireVMGate - C:\Program Files (x86)\Common Files\Glowria\npFireVMGate.dll ( Glowria) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\progra~2\mcafee\msc\npmcsn~1.dll () FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\8\NP_wtapp.dll () FF Plugin-x32: @zylom.com/ZylomGamesPlayer - C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll (Zylom) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: LWAPlugin15.8 - C:\Users\Daniel\AppData\Roaming\Mozilla\Plugins\npLWAPlugin15.8.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Users\Daniel\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google) FF Plugin ProgramFiles/Appdata: C:\Users\Daniel\AppData\Roaming\mozilla\plugins\npLWAPlugin15.8.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Users\Daniel\AppData\Roaming\mozilla\plugins\npo1d.dll (Google) FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2011-04-15]
Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR StartupUrls: "https://news.google.fr/" CHR Plugin: (Shockwave Flash) - C:\Users\Daniel\AppData\Local\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Shockwave Flash) - C:\Users\Daniel\AppData\Local\Google\Chrome\Application\35.0.1916.114\gcswf32.dll No File CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Daniel\AppData\Local\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Daniel\AppData\Local\Google\Chrome\Application\35.0.1916.114\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Glowria Firefox Gateway for Video Manager) - C:\Program Files (x86)\Common Files\Glowria\npFireVMGate.dll ( Glowria) CHR Plugin: (Java(TM) Platform SE 7 U6) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.60.24) - C:\windows\SysWOW64\npDeployJava1.dll No File CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.) CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll () CHR Extension: (Google Drive) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-06] CHR Extension: (Azov Sea Theme) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\edlbggommlbjkfcfpclbcffgfkmkmega [2014-02-23] CHR Extension: (Feuilles de calcul Google ) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2013-01-13] CHR Extension: (SiteAdvisor) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2013-10-26] CHR Extension: (Antidote) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnhgdodmhnpmndnljbmafpgomahfal [2013-12-14] CHR Extension: (Google Wallet) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21] CHR HKLM\...\Chrome\Extension: [mjcnhgdodmhnpmndnljbmafpgomahfal] - C:\Program Files (x86)\Druide\Antidote 8\Texteurs\GoogleChrome\Installation.Antidote.GoogleChrome.crx [2013-11-12] CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Daniel\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-05-06] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2014-03-13] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-01-17] CHR HKLM-x32\...\Chrome\Extension: [mjcnhgdodmhnpmndnljbmafpgomahfal] - C:\Program Files (x86)\Druide\Antidote 8\Texteurs\GoogleChrome\Installation.Antidote.GoogleChrome.crx [2013-11-12] CHR StartMenuInternet: Google Chrome - C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-06-02] (AVAST Software) S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-03-29] (WildTangent) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] () R2 MaConfigAgent; C:\Program Files\ma-config.com\MaConfigAgent.exe [2542416 2013-10-04] (CybelSoft) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) S3 McAWFwk; C:\Program Files\mcafee\msc\McAWFwk.exe [220528 2010-08-09] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) U2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [501768 2011-06-23] (McAfee, Inc.) S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [197960 2011-03-13] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [208272 2011-03-13] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [158832 2011-03-13] (McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.) S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH) R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1157056 2012-09-19] (Western Digital ) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [248248 2012-09-19] (Western Digital) R2 WDRulesService; C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe [1177536 2012-09-19] (Western Digital ) R2 WLANBelkinService; C:\Program Files (x86)\Belkin\F7D4101\V1\wlansrv.exe [36864 2009-12-28] ()
==================== Drivers (Whitelisted) ====================
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-06-02] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-06-02] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-06-02] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-06-02] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-06-02] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-06-02] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-06-02] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-06-02] () R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [65128 2011-03-13] (McAfee, Inc.) S3 FsUsbExDisk; C:\windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-07-18] () R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-03] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [156792 2011-03-13] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [227856 2011-03-13] (McAfee, Inc.) U3 mfeavfk01; No ImagePath R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [481376 2011-03-13] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [639216 2011-03-13] (McAfee, Inc.) R1 mfenlfk; C:\Windows\System32\DRIVERS\mfenlfk.sys [75672 2011-03-13] (McAfee, Inc.) S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [98728 2011-03-13] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [281928 2011-03-13] (McAfee, Inc.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-03 17:27 - 2014-06-03 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2014-06-03 17:17 - 2014-06-03 17:29 - 00030693 _____ () C:\Users\Daniel\Desktop\FRST.txt 2014-06-03 17:17 - 2014-06-03 17:29 - 00000000 ____D () C:\FRST 2014-06-03 17:16 - 2014-06-03 17:16 - 02068992 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2014-06-03 17:01 - 2014-06-03 17:01 - 00000000 ____D () C:\ProgramData\RogueKiller 2014-06-03 17:00 - 2014-06-03 17:28 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-03 16:59 - 2014-06-03 16:59 - 00001073 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-06-03 16:59 - 2014-06-03 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-06-03 16:59 - 2014-06-03 16:59 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-06-03 16:59 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-06-03 16:59 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-06-03 16:59 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-06-03 16:44 - 2014-06-03 16:44 - 00044757 _____ () C:\Users\Daniel\Desktop\ZHPDiag.txt 2014-06-03 16:43 - 2014-06-03 16:43 - 00000512 _____ () C:\PhysicalDisk0_MBR.bin 2014-06-03 13:11 - 2014-06-03 13:11 - 00016596 _____ () C:\Users\Daniel\Downloads\Operation Littoral 2014 v2.xlsx 2014-06-03 08:13 - 2014-06-03 08:13 - 00001958 _____ () C:\Users\Daniel\Desktop\ZHPFix.lnk 2014-06-03 08:13 - 2014-06-03 08:13 - 00001831 _____ () C:\Users\Daniel\Desktop\ZHPDiag.lnk 2014-06-03 08:13 - 2014-06-03 08:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP 2014-06-03 08:12 - 2014-06-03 16:40 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\ZHP 2014-06-03 08:12 - 2014-06-03 08:13 - 00000000 ____D () C:\Program Files (x86)\ZHPDiag 2014-06-02 21:53 - 2014-06-03 16:48 - 00000672 _____ () C:\windows\PFRO.log 2014-06-02 14:18 - 2014-06-03 17:23 - 00002249 _____ () C:\windows\setupact.log 2014-06-02 14:18 - 2014-06-02 14:18 - 00000000 _____ () C:\windows\setuperr.log 2014-06-02 13:46 - 2014-06-02 13:46 - 00000000 ____D () C:\Intel 2014-06-02 10:03 - 2014-06-02 10:04 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Dropbox 2014-06-02 10:01 - 2014-06-02 10:01 - 36818984 _____ (Dropbox, Inc.) C:\Users\Public\Desktop\DropboxInstallerAvast.exe 2014-06-02 09:40 - 2014-06-02 09:40 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\AVAST Software 2014-06-02 09:33 - 2014-06-02 12:23 - 00085328 _____ (AVAST Software) C:\windows\system32\Drivers\aswstm.sys 2014-06-02 09:33 - 2014-06-02 09:33 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr 2014-06-02 09:33 - 2014-06-02 09:33 - 00029208 _____ () C:\windows\system32\Drivers\aswHwid.sys 2014-06-02 09:33 - 2014-06-02 09:33 - 00001977 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-06-01 08:20 - 2014-06-01 08:20 - 00010022 _____ () C:\Users\Daniel\Downloads\JWORG_Contacts_20140601062020.csv 2014-05-31 20:39 - 2014-05-31 20:39 - 00001938 _____ () C:\Users\Daniel\Downloads\google.csv 2014-05-31 19:17 - 2014-05-31 19:19 - 00000000 ___HD () C:\ProgramData\CanonIJScan 2014-05-26 16:50 - 2014-05-26 16:50 - 00055967 _____ () C:\Users\Daniel\Downloads\folder.zip 2014-05-20 06:15 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe 2014-05-20 06:14 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll 2014-05-20 06:14 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe 2014-05-20 06:14 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe 2014-05-20 06:13 - 2014-05-20 06:14 - 00004165 _____ () C:\windows\SysWOW64\jupdate-1.7.0_55-b14.log 2014-05-16 06:30 - 2014-05-16 06:30 - 00001990 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk 2014-05-12 16:44 - 2014-05-12 16:45 - 00000000 ____D () C:\Program Files\Microsoft Mouse and Keyboard Center 2014-05-12 16:40 - 2014-05-12 16:40 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_NuidFltr_01011.Wdf 2014-05-12 16:40 - 2014-05-12 16:40 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_dc3d_01011.Wdf 2014-05-10 08:00 - 2014-05-10 08:00 - 00019968 _____ () C:\Users\Daniel\Downloads\prog.sem.spéciale du 22 au 27 janv. 2014.wps 2014-05-05 10:13 - 2014-05-05 10:13 - 00000000 ___RD () C:\Users\Daniel\Desktop\Ludique 2014-05-05 10:11 - 2014-06-03 17:17 - 00000000 ____D () C:\Users\Daniel\Desktop\Logiciels nettoyage ordinateur 2014-05-05 10:04 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll 2014-05-05 10:03 - 2014-06-03 08:08 - 00000000 ____D () C:\AdwCleaner 2014-05-04 18:05 - 2014-05-04 18:05 - 00003158 _____ () C:\windows\System32\Tasks\{51C4114D-4751-41F8-992C-D8424DB00513} 2014-05-04 16:46 - 2014-05-04 16:46 - 01745872 _____ (AnyProtect.com) C:\Users\Daniel\AppData\Local\nsj80E0.tmp
==================== One Month Modified Files and Folders =======
2014-06-03 17:30 - 2011-08-10 16:00 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Temp 2014-06-03 17:29 - 2014-06-03 17:17 - 00030693 _____ () C:\Users\Daniel\Desktop\FRST.txt 2014-06-03 17:29 - 2014-06-03 17:17 - 00000000 ____D () C:\FRST 2014-06-03 17:28 - 2014-06-03 17:00 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-03 17:27 - 2014-06-03 17:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2014-06-03 17:27 - 2012-12-24 20:24 - 00000000 ___RD () C:\Users\Daniel\Google Drive 2014-06-03 17:26 - 2012-07-10 22:19 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update 2014-06-03 17:24 - 2013-01-28 08:52 - 00000356 _____ () C:\windows\Tasks\ROC_JAN2013_TB_rmv.job 2014-06-03 17:24 - 2012-12-24 20:19 - 00001064 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-03 17:23 - 2014-06-02 14:18 - 00002249 _____ () C:\windows\setupact.log 2014-06-03 17:23 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-06-03 17:20 - 2009-07-14 06:45 - 00025120 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-03 17:20 - 2009-07-14 06:45 - 00025120 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-03 17:17 - 2014-05-05 10:11 - 00000000 ____D () C:\Users\Daniel\Desktop\Logiciels nettoyage ordinateur 2014-06-03 17:16 - 2014-06-03 17:16 - 02068992 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2014-06-03 17:11 - 2011-06-01 07:12 - 01627982 _____ () C:\windows\WindowsUpdate.log 2014-06-03 17:10 - 2011-08-10 20:18 - 00003944 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{0E0E53BB-7B20-4E24-81E0-1F4D8DBD5061} 2014-06-03 17:01 - 2014-06-03 17:01 - 00000000 ____D () C:\ProgramData\RogueKiller 2014-06-03 16:59 - 2014-06-03 16:59 - 00001073 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-06-03 16:59 - 2014-06-03 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-06-03 16:59 - 2014-06-03 16:59 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-06-03 16:59 - 2012-07-19 17:32 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-03 16:48 - 2014-06-02 21:53 - 00000672 _____ () C:\windows\PFRO.log 2014-06-03 16:44 - 2014-06-03 16:44 - 00044757 _____ () C:\Users\Daniel\Desktop\ZHPDiag.txt 2014-06-03 16:43 - 2014-06-03 16:43 - 00000512 _____ () C:\PhysicalDisk0_MBR.bin 2014-06-03 16:41 - 2012-07-19 08:49 - 00001082 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1234134681-625734610-604210244-1001UA.job 2014-06-03 16:40 - 2014-06-03 08:12 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\ZHP 2014-06-03 13:11 - 2014-06-03 13:11 - 00016596 _____ () C:\Users\Daniel\Downloads\Operation Littoral 2014 v2.xlsx 2014-06-03 12:29 - 2012-12-24 20:19 - 00001068 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-03 11:44 - 2011-08-10 16:52 - 00000000 ____D () C:\Users\Daniel\Desktop\Surveillant circonscription 2014-06-03 10:55 - 2011-02-11 18:16 - 00062136 _____ () C:\windows\system32\perfh00C.dat 2014-06-03 10:55 - 2011-02-11 18:16 - 00026434 _____ () C:\windows\system32\perfc00C.dat 2014-06-03 10:55 - 2009-07-14 07:13 - 00852874 _____ () C:\windows\system32\PerfStringBackup.INI 2014-06-03 10:01 - 2011-06-01 07:16 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Temp 2014-06-03 08:13 - 2014-06-03 08:13 - 00001958 _____ () C:\Users\Daniel\Desktop\ZHPFix.lnk 2014-06-03 08:13 - 2014-06-03 08:13 - 00001831 _____ () C:\Users\Daniel\Desktop\ZHPDiag.lnk 2014-06-03 08:13 - 2014-06-03 08:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP 2014-06-03 08:13 - 2014-06-03 08:12 - 00000000 ____D () C:\Program Files (x86)\ZHPDiag 2014-06-03 08:08 - 2014-05-05 10:03 - 00000000 ____D () C:\AdwCleaner 2014-06-02 21:48 - 2014-04-10 17:14 - 00085504 ___SH () C:\Users\Daniel\Desktop\Thumbs.db 2014-06-02 15:16 - 2011-08-10 16:52 - 00000000 ____D () C:\Users\Daniel\Documents\Assemblée de District 2014-06-02 15:03 - 2011-08-10 20:02 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-06-02 14:18 - 2014-06-02 14:18 - 00000000 _____ () C:\windows\setuperr.log 2014-06-02 13:46 - 2014-06-02 13:46 - 00000000 ____D () C:\Intel 2014-06-02 12:23 - 2014-06-02 09:33 - 00085328 _____ (AVAST Software) C:\windows\system32\Drivers\aswstm.sys 2014-06-02 12:23 - 2011-08-10 22:03 - 01039096 _____ (AVAST Software) C:\windows\system32\Drivers\aswsnx.sys 2014-06-02 12:23 - 2011-08-10 22:03 - 00423240 _____ (AVAST Software) C:\windows\system32\Drivers\aswsp.sys 2014-06-02 10:04 - 2014-06-02 10:03 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Dropbox 2014-06-02 10:01 - 2014-06-02 10:01 - 36818984 _____ (Dropbox, Inc.) C:\Users\Public\Desktop\DropboxInstallerAvast.exe 2014-06-02 09:40 - 2014-06-02 09:40 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\AVAST Software 2014-06-02 09:33 - 2014-06-02 09:33 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr 2014-06-02 09:33 - 2014-06-02 09:33 - 00029208 _____ () C:\windows\system32\Drivers\aswHwid.sys 2014-06-02 09:33 - 2014-06-02 09:33 - 00001977 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-06-02 09:33 - 2013-04-07 15:31 - 00208416 _____ () C:\windows\system32\Drivers\aswVmm.sys 2014-06-02 09:33 - 2013-04-07 15:31 - 00065776 _____ () C:\windows\system32\Drivers\aswRvrt.sys 2014-06-02 09:33 - 2012-03-29 10:41 - 00093568 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys 2014-06-02 09:33 - 2011-08-10 22:03 - 01039096 _____ (AVAST Software) C:\windows\system32\Drivers\aswsnx.sys.1401704627312 2014-06-02 09:33 - 2011-08-10 22:03 - 00423240 _____ (AVAST Software) C:\windows\system32\Drivers\aswsp.sys.1401704627312 2014-06-02 09:33 - 2011-08-10 22:03 - 00334648 _____ (AVAST Software) C:\windows\system32\aswBoot.exe 2014-06-02 09:33 - 2011-08-10 22:03 - 00079184 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys 2014-06-02 09:31 - 2011-08-10 22:03 - 00000000 _____ () C:\windows\SysWOW64\config.nt 2014-06-02 09:31 - 2011-08-10 22:02 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-06-01 08:20 - 2014-06-01 08:20 - 00010022 _____ () C:\Users\Daniel\Downloads\JWORG_Contacts_20140601062020.csv 2014-06-01 07:41 - 2012-07-19 08:49 - 00001030 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1234134681-625734610-604210244-1001Core.job 2014-06-01 07:35 - 2014-02-23 19:57 - 00000000 ____D () C:\ProgramData\CanonIJPLM 2014-05-31 20:39 - 2014-05-31 20:39 - 00001938 _____ () C:\Users\Daniel\Downloads\google.csv 2014-05-31 19:19 - 2014-05-31 19:17 - 00000000 ___HD () C:\ProgramData\CanonIJScan 2014-05-31 19:17 - 2011-12-31 23:23 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Canon 2014-05-31 07:25 - 2013-05-20 11:54 - 11408384 ___SH () C:\Users\Daniel\Downloads\Thumbs.db 2014-05-26 20:35 - 2012-07-19 15:59 - 00000000 ____D () C:\Program Files\CCleaner 2014-05-26 16:50 - 2014-05-26 16:50 - 00055967 _____ () C:\Users\Daniel\Downloads\folder.zip 2014-05-23 11:14 - 2011-08-10 19:52 - 00025892 _____ () C:\Users\Daniel\Documents\finances personnelles.xlsx 2014-05-23 11:05 - 2011-12-12 19:09 - 00000000 ____D () C:\Users\Daniel\Documents\Publications en pdf 2014-05-22 06:34 - 2009-07-14 07:32 - 00000000 ____D () C:\windows\system32\FxsTmp 2014-05-21 22:08 - 2014-01-06 17:23 - 00000000 ____D () C:\Users\Daniel\Documents\Cycle 2014b 2014-05-20 06:15 - 2013-10-21 11:23 - 00000000 ____D () C:\ProgramData\Oracle 2014-05-20 06:14 - 2014-05-20 06:13 - 00004165 _____ () C:\windows\SysWOW64\jupdate-1.7.0_55-b14.log 2014-05-20 06:14 - 2011-04-14 23:34 - 00000000 ____D () C:\Program Files (x86)\Java 2014-05-19 13:10 - 2011-08-10 16:52 - 00000000 ____D () C:\Users\Daniel\Documents\Dossiers Divers 2014-05-16 06:30 - 2014-05-16 06:30 - 00001990 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk 2014-05-16 06:30 - 2011-04-14 23:40 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2014-05-12 22:14 - 2012-07-17 15:22 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Skype 2014-05-12 16:46 - 2013-10-22 09:53 - 00003118 _____ () C:\windows\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe 2014-05-12 16:46 - 2013-10-22 09:53 - 00003090 _____ () C:\windows\System32\Tasks\Microsoft_Hardware_Launch_itype_exe 2014-05-12 16:46 - 2013-10-22 09:53 - 00003062 _____ () C:\windows\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe 2014-05-12 16:46 - 2013-10-22 09:53 - 00003060 _____ () C:\windows\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe 2014-05-12 16:46 - 2011-08-10 23:00 - 00003092 _____ () C:\windows\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe 2014-05-12 16:45 - 2014-05-12 16:44 - 00000000 ____D () C:\Program Files\Microsoft Mouse and Keyboard Center 2014-05-12 16:40 - 2014-05-12 16:40 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_NuidFltr_01011.Wdf 2014-05-12 16:40 - 2014-05-12 16:40 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_dc3d_01011.Wdf 2014-05-12 07:26 - 2014-06-03 16:59 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:26 - 2014-06-03 16:59 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-06-03 16:59 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-05-10 08:00 - 2014-05-10 08:00 - 00019968 _____ () C:\Users\Daniel\Downloads\prog.sem.spéciale du 22 au 27 janv. 2014.wps 2014-05-10 07:36 - 2012-07-19 08:49 - 00004054 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1234134681-625734610-604210244-1001UA 2014-05-10 07:36 - 2012-07-19 08:49 - 00003658 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1234134681-625734610-604210244-1001Core 2014-05-09 16:35 - 2012-12-24 20:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2014-05-09 16:19 - 2013-03-15 23:29 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-05-09 16:19 - 2013-03-15 23:29 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-05-08 15:32 - 2013-03-15 23:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-05-08 07:24 - 2012-12-24 20:19 - 00004064 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-08 07:24 - 2012-12-24 20:19 - 00003812 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-05-06 07:30 - 2012-12-27 12:59 - 00001912 _____ () C:\windows\epplauncher.mif 2014-05-06 07:30 - 2012-12-27 12:58 - 00002128 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk 2014-05-06 07:29 - 2012-12-27 12:58 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2014-05-06 07:29 - 2012-12-27 12:58 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client 2014-05-05 10:13 - 2014-05-05 10:13 - 00000000 ___RD () C:\Users\Daniel\Desktop\Ludique 2014-05-04 18:06 - 2011-08-10 16:08 - 00001440 _____ () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-04 18:05 - 2014-05-04 18:05 - 00003158 _____ () C:\windows\System32\Tasks\{51C4114D-4751-41F8-992C-D8424DB00513} 2014-05-04 17:36 - 2013-07-23 16:45 - 00000556 _____ () C:\windows\wininit.ini 2014-05-04 17:07 - 2011-08-10 16:00 - 00000000 ___RD () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-04 16:46 - 2014-05-04 16:46 - 01745872 _____ (AnyProtect.com) C:\Users\Daniel\AppData\Local\nsj80E0.tmp 2014-05-04 16:35 - 2011-08-10 16:36 - 00000000 ___RD () C:\Users\Daniel\Desktop\Logiciels divers 2014-05-04 14:05 - 2009-07-14 07:08 - 00032496 _____ () C:\windows\Tasks\SCHEDLGU.TXT
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-24 07:18
==================== End Of Log ============================ | ||||||||
Grand Maître astucien ![]() | Re, Il y a quelques traces d'infections mineures, mais rien d'important. Je pense toutefois que la cause majeure de dysfonctionnement est une surprotection qui nuit à l'ensemble et n'apporte rien en terme d'efficacité :
Tu as Microsoft security Essential, Mc Afee, Avast, De quoi mettre à genou une machine. Peux-tu me dire quelle est la protection que tu veux garder et on vire les autres pour commencer ? Fill | ||||||||
Petit astucien | AVAST m'a toujours satisfait | ||||||||
Petit astucien | A moins que tu me suggere de garder Microsoft essential. Il y a doublons ?? | ||||||||
Grand Maître astucien ![]() | Et même triplon avec Mc Afee 1/
2/ Désinstalle ceci et redémarre le pc :
3/
4/ Essaie de lancer l'analyse avec malwarebyte's maintenant. Fill Modifié par Fill le 03/06/2014 18:00 | ||||||||
Petit astucien | 1ère étape faite :
RogueKiller V9.0.1.0 [Jun 2 2014] par Adlice Software Mail : http://www.adlice.com/contact/ Remontées : http://forum.adlice.com Site Web : http://www.adlice.com/softwares/roguekiller/ Blog : http://www.adlice.com
Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version Démarrage : Mode normal Utilisateur : Daniel [Droits d'admin] Mode : Suppression -- Date : 06/03/2014 18:18:05
¤¤¤ Processus malicieux : 0 ¤¤¤
¤¤¤ Entrées de registre : 4 ¤¤¤ [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> REMPLACÉ (0) [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> REMPLACÉ (0) [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> REMPLACÉ (0) [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> REMPLACÉ (0)
¤¤¤ Tâches planifiées : 0 ¤¤¤
¤¤¤ Fichiers : 0 ¤¤¤
¤¤¤ Fichier HOSTS : 0 [Too big!] ¤¤¤
¤¤¤ Antirootkit : 0 ¤¤¤
¤¤¤ Navigateurs web : 0 ¤¤¤
¤¤¤ MBR Verif : ¤¤¤ +++++ PhysicalDrive0: TOSHIBA MK7575GSX +++++ --- User --- [MBR] 0cc5fb16241d632903b1ad4355cb28d9 [BSP] a51a2462f98ba4902560c81a00c7a1e9 : Unknown MBR Code Partition table: 0 - [ACTIVE] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 1500 MB 1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 3074048 | Size: 698817 MB 2 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 1434251264 | Size: 15086 MB User = LL1 ... OK User = LL2 ... OK
+++++ PhysicalDrive1: G & T USB Flash Drive USB Device +++++ --- User --- [MBR] 552e525f27ba2a2e83cf15398939a31e [BSP] e75f2679424be588d79049db7be0b571 : Unknown MBR Code Partition table: 0 - [ACTIVE] FAT16 (0x6) [VISIBLE] Offset (sectors): 32 | Size: 1959 MB User = LL1 ... OK Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )
============================================ RKreport_SCN_06032014_171115.log - RKreport_SCN_06032014_181710.log | ||||||||
Grand Maître astucien ![]() | Re, OK. Tu fais la suite ? Fill | ||||||||
Petit astucien | Oui, désolé j'ai du partir pour une réunion. J'ai supprimer Mc Afee et Microsoft. Je fais le reste. | ||||||||
Petit astucien | Voici les deux liens :
http://cjoint.com/?3FdwXMLOxxq
http://cjoint.com/?3Fdw1mMxTBK
Je lance malwarebytes | ||||||||
Petit astucien | Voilà c'est fait. Deux bricoles encore je crois jointe.
Cela va nettement mieux !!
Que faire ensuite ?
Pourrais-tu me donner un conseil ? Quelle protection devrais-je envisager ? Est-ce suffisant ce que j'ai ? Merci !
| ||||||||
Petit astucien | Fichier joint : resultat MAM.txt | ||||||||
Grand Maître astucien ![]() | Bonjour, Pour les conseils , on voit cela à la fin. 1/ Désinstalle spybot ; ça ne sert à rien. 2/
3/
4/ Fais une analyse en ligne avec Eset/Nod32 comme indiqué ici et édite le rapport. 5/ Tu n'as pas effectué la suppression des éléments trouvés dans malwarebyte's. Il faut reprendre. 6/ Comment se comporte le pc ? Fill Modifié par Fill le 04/06/2014 12:56 | ||||||||
Petit astucien | Bonsoir, je rentre juste pour poursuivre les différentes tâches :
- Spybot - supprimés : - Rapport OTL que voici : All processes killed Error: Unable to interpret <Instructions :> in the current context! ========== OTL ========== Service McAfee SiteAdvisor Service stopped successfully! Service McAfee SiteAdvisor Service deleted successfully! File C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe /McCoreSvc not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. File c:\progra~2\mcafee\msc\npmcsn~1.dll not found. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27B4851A-3207-45A2-B947-BE8AFE6163AB}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27B4851A-3207-45A2-B947-BE8AFE6163AB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{53707962-6F74-2D53-2644-206D7942484F}\ not found. File C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll not found. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_USERS\S-1-5-21-1234134681-625734610-604210244-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_USERS\S-1-5-21-1234134681-625734610-604210244-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SpybotSD TeaTimer deleted successfully. File C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartUpReg\SpybotSD TeaTimer\ not found. ========== FILES ========== C:\Windows\Installer\d5e8.msi moved successfully. ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Classes\Installer\Features\25BD30E1BC5D83343A835E62DDD4D41B\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\25BD30E1BC5D83343A835E62DDD4D41B\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\25BD30E1BC5D83343A835E62DDD4D41B\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\Installer\Features\25BD30E1BC5D83343A835E62DDD4D41B\ not found. Registry delete failed. HKEY_CLASSES_ROOT\CLSID\{58D052BC-A3DF-3508-AC95-FF297BDC9F0C}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58D052BC-A3DF-3508-AC95-FF297BDC9F0C}\ not found. Registry delete failed. HKEY_CLASSES_ROOT\CLSID\{6A01FDA0-30DF-11d0-B724-00AA006C1A01}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A01FDA0-30DF-11d0-B724-00AA006C1A01}\ not found. Registry delete failed. HKEY_CLASSES_ROOT\CLSID\{6B19643A-0CD7-4563-B710-BDC191FCAD3B}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6B19643A-0CD7-4563-B710-BDC191FCAD3B}\ not found. ========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Daniel ->Temp folder emptied: 903644613 bytes ->Temporary Internet Files folder emptied: 5964007 bytes ->Java cache emptied: 48338 bytes ->Google Chrome cache emptied: 44499682 bytes ->Flash cache emptied: 58259 bytes
User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33184 bytes ->Flash cache emptied: 57472 bytes
User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes
User: Public
User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56504 bytes
%systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 598892 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 68172 bytes RecycleBin emptied: 2537929 bytes
Total Files Cleaned = 913.00 mb
[EMPTYFLASH]
User: All Users
User: Daniel ->Flash cache emptied: 0 bytes
User: Default ->Flash cache emptied: 0 bytes
User: Default User ->Flash cache emptied: 0 bytes
User: Public
User: UpdatusUser ->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 06042014_192703
Files\Folders moved on Reboot... C:\Users\Daniel\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully. File move failed. C:\windows\temp\_avast_\AvastLock.txt scheduled to be moved on reboot. File\Folder C:\windows\temp\etilqs_aASzjUN6zC465Xw not found!
PendingFileRenameOperations files...
Registry entries deleted on Reboot... Registry delete failed. HKEY_CLASSES_ROOT\CLSID\{58D052BC-A3DF-3508-AC95-FF297BDC9F0C}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58D052BC-A3DF-3508-AC95-FF297BDC9F0C}\ not found. Registry delete failed. HKEY_CLASSES_ROOT\CLSID\{6A01FDA0-30DF-11d0-B724-00AA006C1A01}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A01FDA0-30DF-11d0-B724-00AA006C1A01}\ not found. Registry delete failed. HKEY_CLASSES_ROOT\CLSID\{6B19643A-0CD7-4563-B710-BDC191FCAD3B}\ scheduled to be deleted on reboot. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6B19643A-0CD7-4563-B710-BDC191FCAD3B}\ not found.
| ||||||||
Petit astucien | RE.. Selon malwarebyte's pas de fichiers malveillants ESET j'ai un problème, je n'arrive pas à éditer un rapport. Je lance à nouveau l'analyse. Le PC s'est nettement amélioré, rapidité au lancement incontestable et dnas la navigation. plus aucun blocage J'espère arriver à tirer le rapport.
| ||||||||
Petit astucien | ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7587 # api_version=3.0.2 # EOSSerial=d8045df527eb594284ec1c2125ccbbcd # engine=18552 # end=stopped # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-06-04 06:09:39 # local_time=2014-06-04 08:09:39 ) # country="France" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='avast! Antivirus' # compatibility_mode=783 16777213 100 97 197301 166329469 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 28428186 153535229 0 0 # scanned=81218 # found=2 # cleaned=0 # scan_time=1229 sh=67BFA0612192AD7A083BF992B4B5C19FB4805F6E ft=1 fh=5fc82f3fe42fb791 vn="a variant of Win32/Toolbar.CrossRider.AD potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MediaPlayerplus\6d220629-8407-4835-b552-653a16c17e38-4.exe.vir" sh=3BE999ADB884C591A1F84ABBBB6BADDFF538BDDA ft=1 fh=7eac532809e6e5ea vn="a variant of Win32/Toolbar.CrossRider.AC potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MediaPlayerplus\6d220629-8407-4835-b552-653a16c17e38-5.exe.vir" ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7587 # api_version=3.0.2 # EOSSerial=d8045df527eb594284ec1c2125ccbbcd # engine=18552 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-06-04 07:43:17 # local_time=2014-06-04 09:43:17 ) # country="France" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='avast! Antivirus' # compatibility_mode=783 16777213 100 97 202919 166335087 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 28433804 153540847 0 0 # scanned=196552 # found=5 # cleaned=5 # scan_time=4065 sh=67BFA0612192AD7A083BF992B4B5C19FB4805F6E ft=1 fh=5fc82f3fe42fb791 vn="a variant of Win32/Toolbar.CrossRider.AD potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MediaPlayerplus\6d220629-8407-4835-b552-653a16c17e38-4.exe.vir" sh=3BE999ADB884C591A1F84ABBBB6BADDFF538BDDA ft=1 fh=7eac532809e6e5ea vn="a variant of Win32/Toolbar.CrossRider.AC potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MediaPlayerplus\6d220629-8407-4835-b552-653a16c17e38-5.exe.vir" sh=2337A9C1B17E72F4C4B5807C1F7098661E49B980 ft=1 fh=abbd31e3ba80409a vn="Win32/AnyProtect.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\Daniel\AppData\Local\nsj80E0.tmp" sh=A2A43FBC39AF996DF7F842DCA3C6902BC9080A9F ft=1 fh=0ff7691adc261380 vn="a variant of Win32/DomaIQ.BB potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\File System\004\t\00\00000000" sh=A2A43FBC39AF996DF7F842DCA3C6902BC9080A9F ft=1 fh=0ff7691adc261380 vn="a variant of Win32/DomaIQ.BB potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\Daniel\Desktop\Logiciels divers\Java.exe" ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7587 # api_version=3.0.2 # EOSSerial=d8045df527eb594284ec1c2125ccbbcd # engine=18558 # end=stopped # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-06-04 08:22:37 # local_time=2014-06-04 10:22:37 ) # country="France" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='avast! Antivirus' # compatibility_mode=783 16777213 100 97 205279 166337447 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 28436164 153543207 0 0 # scanned=106180 # found=0 # cleaned=0 # scan_time=1975 ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7587 # api_version=3.0.2 # EOSSerial=d8045df527eb594284ec1c2125ccbbcd # engine=18558 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-06-04 10:30:58 # local_time=2014-06-05 12:30:58 ) # country="France" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='avast! Antivirus' # compatibility_mode=783 16777213 100 97 212980 166345148 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 28443865 153550908 0 0 # scanned=196692 # found=3 # cleaned=3 # scan_time=7197 sh=84380A1580B113FF870E9765E5BDB61DE8AD9B1C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MediaPlayerplus\360-54246.crx.vir" sh=360091E138E8E479A38347E9B98F6FACBA8AA36B ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MediaPlayerplus\54246.crx.vir" sh=35B9224FE503439EF1D91CD634CC0E66B0A04AF2 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MediaPlayerplus\54246.xpi.vir"
| ||||||||
Petit astucien | Voilà le dernier rapport, j'y suis enfin arriver..... | ||||||||
Grand Maître astucien ![]() | Bonjour, 1/
2/ Tu peux par contre, garderMalwarebytes'Anti-malware et CCleaner. Utilise CCleaner tous les soirs avant de couper le PC (ne prends que quelques secondes!).
N'oublie pas de vacicner tes clés USB, disques durs externes etc... Cela permet d'éviter un certain nombre d'infections utilisant ce moyen pour se propager. Tu peux lire cet article qui explique les risques d'infections par supports amovibles.
.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-. 3/
Il est fortement recommandé d'avoir tous ses logiciels de sécurité à jour, afin d'éviter les failles par lesquelles s'engouffrent les infections. Pour Java, il est possible d'utiliser Javara. Cela permet d'installer la dernière version De Java et d'effacer les anciennes versions. Pour le lecteur pdf, on peut utiliser des lecteurs alternatifs plus légers, comme Sumatra pdf, à la place de reader. Pour tester les vulnérabilités et les logiciels non à jour, il est possible de se rendre sur le site de Secunia et de faire une analyse de la machine.
.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-. 4/ Il est très important d'adopter un logiciel permettant de créer des images de son système. En cas de gros plantage, de défaillance matérielle, d'infection incurable, on peut ainsi en quelques minutes remettre sa machine sur pied à partir d'un CD de démarrage spécialement conçu à cet effet. On peut alors conserver une image disque sur sa machine et sur un support extérieur (Disque dur externe). Il existe des solutions commerciales payantes de qualité (Acronis true type, Ghost, Paragon), mais aussi des versions bridées gratuites de ces outils. Voici DiskWizard, qui est une version bridée gratuite du logiciel Acronis. Elle s'utilise pour les disques de marque Seagate.
Le programme Macrium permet lui aussi de créer des images disques. Un tuto présenté sur cette page.
Pour windows7, il y a l'outil natif intégré à cette architecture qui est décrit ici.
image disque sous windows8 : http://www.chantal11.com/2013/03/creer-une-image-systeme-sous-windows-8/
.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-. 5/ 90 % des infections sont facilement évitables si on est prudent ou vigilant. Les infections les plus répandues sont les PUP, souvent présentes dans de nombreux logiciels gratuits "repackés". Cela signifie que certains sites (01net, softonic notamment qui sont à proscrire) reconditionnent des programmes gratuits en y ajoutant des éléments indésirables (barres d'outils intrusives, nouvelle page d'accueil par défaut du navigateur, modification de réglgages dudit navigateur, pages de pubs etc...). Ce ne sont pas des infections à proprement parler, car elles sont installées avec le consentement de l'utilisateur qui n'a pas pris la peine de lire les éléments importants lors de l'installation, même si le procédé est plus que limite... C'est la raison pour laquelle il est préférable de télécharger un logiciel sur le site de l'éditeur. Cela évite le "repackage".
Voici par ailleurs une explication très complète sur la publicité et le profilage (très intéressant...et effrayant !) : http://assiste.free.fr/Assiste/Bloquer_la_publicite_sur_les_sites_Web.html
Certains programmes gratuits se payent en utilisant les mêmes méthodes de façon à avoir des retombées publicitaires. Si un programme impose des modifications sur le pc, en installant un nouveau moteur de recherche ou en modifiant certains paramètre de l'ordinateur, il faut renoncer au programme. De façon générale, il faut toujours décocher les cases cochées par défaut lors d'une installation. Voici une liste de logiciels utilisant cette politique : https://forum.pcastuces.com/toolbars_et_programmes-f31s64.htm
Enfin, certaines infections sont aussi spécialisées dans le vol de données confidentielles (mots de passe, données ou identifiants bancaires etc...). Il faut donc changer ses mots de passe après une telle infection et avoir une politique rigoureuse de mots de passes (mot de passe fort, différent pour chaque site utilisé).
Keepass est un logicel de gestion des mots de passe qui peut être intéressant.
Enfin, penser à garder son système à jour : windows, navigateur, Java, acrobat reader, flashplayer, suite bureautique etc... Les infections les plus graves s'installent à partir de failles non colmatées dans ces éléments du système informatique.
/!\ Pour améliorer la sécurité de ton PC, prends quelques instants pour lire...
Sécuriser son PC +WIFI (versions "hot" & "light") : https://forum.pcastuces.com/sujet.asp?f=25&s=25892
Prévention et protection - Comment vous prémunir : https://forum.pcastuces.com/sujet.asp?f=25&s=36131
Les risques sécuritaires du peer-to-peer en 10 points : http://www.libellules.ch/phpBB2/les-risques-securitaires-du-peer-to-peer-en-10-points-t28947.html
.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-. S'il te plait, note ton sujet [Résolu] en cliquant sur dans la barre de titre de ton sujet. Merci !
Prudence sur Internet et parle de PC Astuces autour de toi!
Bon surf et sois prudent ! Fill | ||||||||
Petit astucien | # DelFix v10.7 - Rapport créé le 05/06/2014 à 07:38:02 # Mis à jour le 27/04/2014 par Xplode # Nom d'utilisateur : Daniel - DANIEL-TO # Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
~ Suppression des outils de désinfection ...
Supprimé : C:\_OTL Supprimé : C:\FRST Supprimé : C:\AdwCleaner Supprimé : C:\Users\Daniel\AppData\Roaming\ZHP Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hijackthis Supprimé : C:\Program Files (x86)\ZHPDiag Supprimé : C:\Program Files (x86)\Trend Micro\Hijackthis Supprimé : C:\AdwCleaner[R1].txt Supprimé : C:\AdwCleaner[R2].txt Supprimé : C:\AdwCleaner[R3].txt Supprimé : C:\AdwCleaner[R4].txt Supprimé : C:\AdwCleaner[R5].txt Supprimé : C:\AdwCleaner[S1].txt Supprimé : C:\AdwCleaner[S2].txt Supprimé : C:\AdwCleaner[S3].txt Supprimé : C:\AdwCleaner[S4].txt Supprimé : C:\PhysicalDisk0_MBR.bin Supprimé : C:\Users\Daniel\Desktop\esetsmartinstaller_enu (1).exe Supprimé : C:\Users\Daniel\Desktop\esetsmartinstaller_enu.exe Supprimé : C:\Users\Daniel\Desktop\FRST64.exe Supprimé : C:\Users\Daniel\Desktop\OTL.exe Supprimé : C:\Users\Daniel\Desktop\ZHPDiag.lnk Supprimé : C:\Users\Daniel\Desktop\ZHPFix.lnk Supprimée : HKLM\SOFTWARE\OldTimer Tools Supprimée : HKLM\SOFTWARE\AdwCleaner Supprimée : HKLM\SOFTWARE\TrendMicro\Hijackthis Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hijackthis Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1 Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\HijackThis.exe
~ Purge de la restauration système ...
Supprimé : RP #458 [OTL Restore Point - 6/3/2014 10:19:30 PM | 06/03/2014 20:19:30]
Nouveau point de restauration créé !
########## - EOF - ##########
| ||||||||
Petit astucien | Merci beaucoup , c'est excellent. Je ne manquerai pas de parler du site; Tu m'a vraiment aidé. Je met en place ces logiciels.
Merci encore !!
| ||||||||
Grand Maître astucien ![]() | Re, Content d'avoir pu t'aider. Fill | ||||||||
|
Les bons plans du moment PC Astuces | Tous les Bons Plans | ||||||||||||||||||
|
Sujets relatifs |
|