Demande d'analyse rapport ZHPDiag
Résolu/Fermé
ismai2003
Messages postés
9
Date d'inscription
mercredi 6 juin 2012
Statut
Membre
Dernière intervention
7 juin 2012
-
6 juin 2012 à 19:50
ismai2003 Messages postés 9 Date d'inscription mercredi 6 juin 2012 Statut Membre Dernière intervention 7 juin 2012 - 7 juin 2012 à 19:09
ismai2003 Messages postés 9 Date d'inscription mercredi 6 juin 2012 Statut Membre Dernière intervention 7 juin 2012 - 7 juin 2012 à 19:09
A voir également:
- Demande d'analyse rapport ZHPDiag
- Zhpdiag - Télécharger - Informations & Diagnostic
- Analyse disque dur - Télécharger - Informations & Diagnostic
- Analyse performance pc - Guide
- Plan rapport de stage - Guide
- Analyse et reparation du lecteur c ✓ - Forum Windows 10
14 réponses
Utilisateur anonyme
6 juin 2012 à 19:56
6 juin 2012 à 19:56
salut
▶ Téléchargez UsbFix (créé par El Desaparecido) sur votre Bureau.
▶ Si votre antivirus affiche une alerte, ignorez-la et désactivez l'antivirus temporairement.
▶ Branchez toutes vos sources de données externes à votre PC (clé USB, disque dur externe, etc...) sans les ouvrir.
▶ Double cliquez sur UsbFix.exe.
▶ Cliquez sur Suppression.
▶ Laissez travailler l'outil.
▶ À la fin du scan, un rapport va s'afficher, postez-le dans votre prochaine réponse sur le forum.
▶ Le rapport est aussi sauvegardé à la racine du disque système ( C:\UsbFix.txt ).
▶ Tutoriel vidéo
▶ Téléchargez UsbFix (créé par El Desaparecido) sur votre Bureau.
▶ Si votre antivirus affiche une alerte, ignorez-la et désactivez l'antivirus temporairement.
▶ Branchez toutes vos sources de données externes à votre PC (clé USB, disque dur externe, etc...) sans les ouvrir.
▶ Double cliquez sur UsbFix.exe.
▶ Cliquez sur Suppression.
▶ Laissez travailler l'outil.
▶ À la fin du scan, un rapport va s'afficher, postez-le dans votre prochaine réponse sur le forum.
▶ Le rapport est aussi sauvegardé à la racine du disque système ( C:\UsbFix.txt ).
▶ Tutoriel vidéo
ismai2003
Messages postés
9
Date d'inscription
mercredi 6 juin 2012
Statut
Membre
Dernière intervention
7 juin 2012
6 juin 2012 à 23:35
6 juin 2012 à 23:35
bonsoir,
voici le rapport Usb fix:
############################## | UsbFix V 7.088 | [Research]
User: Hinda (Administrator) # HINDA-PC
Updated 16/05/2012 by El Desaparecido
Started at 23:29:51 | 06/06/2012
Website: https://www.sosvirus.net/
Forum: http://forum.eldesaparecido.com
Suspicious file ? : http://eldesaparecido.com/upload.php
Contact: contact@eldesaparecido.com
PC: Dell Inc. (Inspiron N7010) (x64-based PC) # Notebook
CPU: Intel(R) Core(TM) i5 CPU M 460 @ 2.53GHz (2534)
RAM -> [ Total : 5941 | Free : 4346 ]
BIOS: Ver 1.00 BIOS A09 PARTTBL
BOOT: Normal boot
OS: Microsoft Windows 7 Home Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 8.0.7601.17514
SC: Security Center Service [ Enabled ]
WU: Windows Update Service [ Enabled ]
AV: avast! Antivirus [ Enabled | Updated ]
FW: Windows FireWall Service [ Enabled ]
C:\ (%systemdrive%) -> Fixed drive # 581 Gb (498 Mb free - 86%) [OS] # NTFS
D:\ -> CD-ROM
################## | Active Processes |
C:\Windows\system32\csrss.exe (488)
C:\Windows\system32\wininit.exe (568)
C:\Windows\system32\csrss.exe (592)
C:\Windows\system32\services.exe (628)
C:\Windows\system32\lsass.exe (656)
C:\Windows\system32\lsm.exe (664)
C:\Windows\system32\svchost.exe (764)
C:\Windows\system32\svchost.exe (852)
C:\Windows\System32\svchost.exe (916)
C:\Windows\System32\svchost.exe (948)
C:\Windows\system32\svchost.exe (976)
C:\Windows\system32\winlogon.exe (508)
C:\Windows\system32\svchost.exe (836)
C:\Windows\system32\svchost.exe (1084)
C:\Windows\system32\WLANExt.exe (1268)
C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE (1284)
C:\Windows\system32\conhost.exe (1308)
C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe (1332)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1340)
C:\Windows\System32\spoolsv.exe (1968)
C:\Windows\system32\svchost.exe (2004)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1172)
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (1700)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1676)
C:\Program Files (x86)\Bonjour\mDNSResponder.exe (1520)
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (1876)
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (2308)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (2332)
C:\Windows\system32\svchost.exe (2396)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2452)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (2548)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (2768)
C:\Windows\system32\taskhost.exe (3064)
C:\Windows\system32\Dwm.exe (2836)
C:\Windows\Explorer.EXE (2448)
C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE (3208)
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE (3248)
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe (3492)
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (3552)
C:\Windows\System32\alg.exe (3860)
C:\Windows\system32\svchost.exe (4092)
C:\Windows\system32\svchost.exe (3392)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (4120)
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (4404)
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (4504)
C:\Windows\System32\igfxtray.exe (4564)
C:\Windows\System32\hkcmd.exe (4636)
C:\Windows\System32\igfxpers.exe (4672)
C:\Program Files\Dell\QuickSet\quickset.exe (4712)
C:\Windows\system32\wbem\wmiprvse.exe (4760)
C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (4780)
C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe (4832)
C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe (4980)
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (4996)
C:\Windows\system32\SearchIndexer.exe (4400)
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe (1276)
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (4220)
C:\Program Files\AVAST Software\Avast\AvastUI.exe (4184)
C:\Program Files (x86)\iTunes\iTunesHelper.exe (4768)
C:\Program Files (x86)\Athan\Athan.exe (4212)
C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe (5128)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (5176)
C:\Program Files (x86)\Ask.com\Updater\Updater.exe (5268)
C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe (5308)
C:\Program Files\iPod\bin\iPodService.exe (6136)
C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe (5740)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (6784)
C:\Windows\System32\svchost.exe (6912)
C:\Program Files\Windows Media Player\wmpnetwk.exe (6932)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (7004)
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (864)
C:\Program Files (x86)\Mozilla Firefox\firefox.exe (6808)
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (6996)
C:\Windows\system32\wbem\wmiprvse.exe (6712)
c:\program files\windows defender\MpCmdRun.exe (8176)
C:\UsbFix\Go.exe (2984)
################## | Files # Infected Folders |
Found ! C:\Users\Hinda\AppData\Local\Temp\EpsonInkjetDriverDownloader.EXE
Found ! C:\Users\Hinda\AppData\Local\Temp\7za.exe
################## | Registry |
################## | Mountpoints2 |
################## | Vaccin |
(!) This computer is not vaccinated!
################## | E.O.F |
voici le rapport Usb fix:
############################## | UsbFix V 7.088 | [Research]
User: Hinda (Administrator) # HINDA-PC
Updated 16/05/2012 by El Desaparecido
Started at 23:29:51 | 06/06/2012
Website: https://www.sosvirus.net/
Forum: http://forum.eldesaparecido.com
Suspicious file ? : http://eldesaparecido.com/upload.php
Contact: contact@eldesaparecido.com
PC: Dell Inc. (Inspiron N7010) (x64-based PC) # Notebook
CPU: Intel(R) Core(TM) i5 CPU M 460 @ 2.53GHz (2534)
RAM -> [ Total : 5941 | Free : 4346 ]
BIOS: Ver 1.00 BIOS A09 PARTTBL
BOOT: Normal boot
OS: Microsoft Windows 7 Home Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 8.0.7601.17514
SC: Security Center Service [ Enabled ]
WU: Windows Update Service [ Enabled ]
AV: avast! Antivirus [ Enabled | Updated ]
FW: Windows FireWall Service [ Enabled ]
C:\ (%systemdrive%) -> Fixed drive # 581 Gb (498 Mb free - 86%) [OS] # NTFS
D:\ -> CD-ROM
################## | Active Processes |
C:\Windows\system32\csrss.exe (488)
C:\Windows\system32\wininit.exe (568)
C:\Windows\system32\csrss.exe (592)
C:\Windows\system32\services.exe (628)
C:\Windows\system32\lsass.exe (656)
C:\Windows\system32\lsm.exe (664)
C:\Windows\system32\svchost.exe (764)
C:\Windows\system32\svchost.exe (852)
C:\Windows\System32\svchost.exe (916)
C:\Windows\System32\svchost.exe (948)
C:\Windows\system32\svchost.exe (976)
C:\Windows\system32\winlogon.exe (508)
C:\Windows\system32\svchost.exe (836)
C:\Windows\system32\svchost.exe (1084)
C:\Windows\system32\WLANExt.exe (1268)
C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE (1284)
C:\Windows\system32\conhost.exe (1308)
C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe (1332)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1340)
C:\Windows\System32\spoolsv.exe (1968)
C:\Windows\system32\svchost.exe (2004)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1172)
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (1700)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1676)
C:\Program Files (x86)\Bonjour\mDNSResponder.exe (1520)
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (1876)
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (2308)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (2332)
C:\Windows\system32\svchost.exe (2396)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2452)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (2548)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (2768)
C:\Windows\system32\taskhost.exe (3064)
C:\Windows\system32\Dwm.exe (2836)
C:\Windows\Explorer.EXE (2448)
C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE (3208)
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE (3248)
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe (3492)
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (3552)
C:\Windows\System32\alg.exe (3860)
C:\Windows\system32\svchost.exe (4092)
C:\Windows\system32\svchost.exe (3392)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (4120)
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (4404)
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (4504)
C:\Windows\System32\igfxtray.exe (4564)
C:\Windows\System32\hkcmd.exe (4636)
C:\Windows\System32\igfxpers.exe (4672)
C:\Program Files\Dell\QuickSet\quickset.exe (4712)
C:\Windows\system32\wbem\wmiprvse.exe (4760)
C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (4780)
C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe (4832)
C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe (4980)
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (4996)
C:\Windows\system32\SearchIndexer.exe (4400)
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe (1276)
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (4220)
C:\Program Files\AVAST Software\Avast\AvastUI.exe (4184)
C:\Program Files (x86)\iTunes\iTunesHelper.exe (4768)
C:\Program Files (x86)\Athan\Athan.exe (4212)
C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe (5128)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (5176)
C:\Program Files (x86)\Ask.com\Updater\Updater.exe (5268)
C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe (5308)
C:\Program Files\iPod\bin\iPodService.exe (6136)
C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe (5740)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (6784)
C:\Windows\System32\svchost.exe (6912)
C:\Program Files\Windows Media Player\wmpnetwk.exe (6932)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (7004)
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (864)
C:\Program Files (x86)\Mozilla Firefox\firefox.exe (6808)
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (6996)
C:\Windows\system32\wbem\wmiprvse.exe (6712)
c:\program files\windows defender\MpCmdRun.exe (8176)
C:\UsbFix\Go.exe (2984)
################## | Files # Infected Folders |
Found ! C:\Users\Hinda\AppData\Local\Temp\EpsonInkjetDriverDownloader.EXE
Found ! C:\Users\Hinda\AppData\Local\Temp\7za.exe
################## | Registry |
################## | Mountpoints2 |
################## | Vaccin |
(!) This computer is not vaccinated!
################## | E.O.F |
ismai2003
Messages postés
9
Date d'inscription
mercredi 6 juin 2012
Statut
Membre
Dernière intervention
7 juin 2012
6 juin 2012 à 23:43
6 juin 2012 à 23:43
??? cet a dire?
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
ismai2003
Messages postés
9
Date d'inscription
mercredi 6 juin 2012
Statut
Membre
Dernière intervention
7 juin 2012
7 juin 2012 à 00:00
7 juin 2012 à 00:00
ok c'est bon:
############################## | UsbFix V 7.088 | [Deletion]
User: Hinda (Administrator) # HINDA-PC
Updated 16/05/2012 by El Desaparecido
Started at 23:52:31 | 06/06/2012
Website: https://www.sosvirus.net/
Forum: http://forum.eldesaparecido.com
Suspicious file ? : http://eldesaparecido.com/upload.php
Contact: contact@eldesaparecido.com
PC: Dell Inc. (Inspiron N7010) (x64-based PC) # Notebook
CPU: Intel(R) Core(TM) i5 CPU M 460 @ 2.53GHz (2534)
RAM -> [ Total : 5941 | Free : 4225 ]
BIOS: Ver 1.00 BIOS A09 PARTTBL
BOOT: Normal boot
OS: Microsoft Windows 7 Home Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 8.0.7601.17514
SC: Security Center Service [ Enabled ]
WU: Windows Update Service [ Enabled ]
AV: avast! Antivirus [ Enabled | Updated ]
FW: Windows FireWall Service [ Enabled ]
C:\ (%systemdrive%) -> Fixed drive # 581 Gb (498 Mb free - 86%) [OS] # NTFS
D:\ -> CD-ROM
################## | Active Processes |
C:\Windows\system32\csrss.exe (488)
C:\Windows\system32\wininit.exe (568)
C:\Windows\system32\csrss.exe (592)
C:\Windows\system32\services.exe (628)
C:\Windows\system32\lsass.exe (656)
C:\Windows\system32\lsm.exe (664)
C:\Windows\system32\svchost.exe (764)
C:\Windows\system32\svchost.exe (852)
C:\Windows\System32\svchost.exe (916)
C:\Windows\System32\svchost.exe (948)
C:\Windows\system32\svchost.exe (976)
C:\Windows\system32\winlogon.exe (508)
C:\Windows\system32\svchost.exe (836)
C:\Windows\system32\svchost.exe (1084)
C:\Windows\system32\WLANExt.exe (1268)
C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE (1284)
C:\Windows\system32\conhost.exe (1308)
C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe (1332)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1340)
C:\Windows\System32\spoolsv.exe (1968)
C:\Windows\system32\svchost.exe (2004)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1172)
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (1700)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1676)
C:\Program Files (x86)\Bonjour\mDNSResponder.exe (1520)
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (1876)
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (2308)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (2332)
C:\Windows\system32\svchost.exe (2396)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2452)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (2548)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (2768)
C:\Windows\system32\taskhost.exe (3064)
C:\Windows\system32\Dwm.exe (2836)
C:\Windows\Explorer.EXE (2448)
C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE (3208)
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE (3248)
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe (3492)
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (3552)
C:\Windows\System32\alg.exe (3860)
C:\Windows\system32\svchost.exe (4092)
C:\Windows\system32\svchost.exe (3392)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (4120)
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (4404)
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (4504)
C:\Windows\System32\igfxtray.exe (4564)
C:\Windows\System32\hkcmd.exe (4636)
C:\Windows\System32\igfxpers.exe (4672)
C:\Program Files\Dell\QuickSet\quickset.exe (4712)
C:\Windows\system32\wbem\wmiprvse.exe (4760)
C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (4780)
C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe (4832)
C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe (4980)
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (4996)
C:\Windows\system32\SearchIndexer.exe (4400)
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe (1276)
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (4220)
C:\Program Files\AVAST Software\Avast\AvastUI.exe (4184)
C:\Program Files (x86)\iTunes\iTunesHelper.exe (4768)
C:\Program Files (x86)\Athan\Athan.exe (4212)
C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe (5128)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (5176)
C:\Program Files (x86)\Ask.com\Updater\Updater.exe (5268)
C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe (5308)
C:\Program Files\iPod\bin\iPodService.exe (6136)
C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe (5740)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (6784)
C:\Windows\System32\svchost.exe (6912)
C:\Program Files\Windows Media Player\wmpnetwk.exe (6932)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (7004)
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (864)
C:\Program Files (x86)\Mozilla Firefox\firefox.exe (6808)
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (6996)
C:\Windows\system32\taskeng.exe (2192)
C:\Windows\system32\SearchProtocolHost.exe (4156)
C:\Windows\system32\SearchFilterHost.exe (7444)
C:\UsbFix\Go.exe (7500)
C:\Windows\system32\wbem\wmiprvse.exe (7424)
################## | Stopped processes |
Stopped! C:\Windows\system32\WLANExt.exe (1268)
Stopped! C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE (1284)
Stopped! C:\Windows\system32\conhost.exe (1308)
Stopped! C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe (1332)
Stopped! C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1340)
Stopped! C:\Windows\System32\spoolsv.exe (1968)
Stopped! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1172)
Stopped! C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (1700)
Stopped! C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1676)
Stopped! C:\Program Files (x86)\Bonjour\mDNSResponder.exe (1520)
Stopped! C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (1876)
Stopped! C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (2308)
Stopped! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (2332)
Stopped! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2452)
Stopped! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (2548)
Stopped! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (2768)
Stopped! C:\Windows\system32\taskhost.exe (3064)
Stopped! C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE (3208)
Stopped! C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE (3248)
Stopped! C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe (3492)
Stopped! C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (3552)
Stopped! C:\Windows\System32\alg.exe (3860)
Stopped! C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (4120)
Stopped! C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (4404)
Stopped! C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (4504)
Stopped! C:\Windows\System32\igfxtray.exe (4564)
Stopped! C:\Windows\System32\hkcmd.exe (4636)
Stopped! C:\Windows\System32\igfxpers.exe (4672)
Stopped! C:\Program Files\Dell\QuickSet\quickset.exe (4712)
Stopped! C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (4780)
Stopped! C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe (4832)
Stopped! C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe (4980)
Stopped! C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (4996)
Stopped! C:\Windows\system32\SearchIndexer.exe (4400)
Stopped! C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe (1276)
Stopped! C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (4220)
Stopped! C:\Program Files\AVAST Software\Avast\AvastUI.exe (4184)
Stopped! C:\Program Files (x86)\iTunes\iTunesHelper.exe (4768)
Stopped! C:\Program Files (x86)\Athan\Athan.exe (4212)
Stopped! C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe (5128)
Stopped! C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (5176)
Stopped! C:\Program Files (x86)\Ask.com\Updater\Updater.exe (5268)
Stopped! C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe (5308)
Stopped! C:\Program Files\iPod\bin\iPodService.exe (6136)
Stopped! C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe (5740)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (6784)
Stopped! C:\Program Files\Windows Media Player\wmpnetwk.exe (6932)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (7004)
Stopped! C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (864)
Stopped! C:\Program Files (x86)\Mozilla Firefox\firefox.exe (6808)
Stopped! C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (6996)
Stopped! C:\Windows\system32\taskeng.exe (2192)
Stopped! c:\program files\windows defender\MpCmdRun.exe (3668)
################## | Files # Infected Folders |
Deleted ! C:\Users\Hinda\AppData\Local\Temp\EpsonInkjetDriverDownloader.EXE
Deleted ! C:\Users\Hinda\AppData\Local\Temp\7za.exe
Deleted ! C:\$RECYCLE.BIN\S-1-5-20
Deleted ! C:\$RECYCLE.BIN\S-1-5-21-2647959408-2079287883-1907983367-1000
Deleted ! C:\$RECYCLE.BIN\S-1-5-21-2647959408-2079287883-1907983367-500
(!) Temporary files deleted.
################## | Registry |
################## | Mountpoints2 |
################## | Listing |
[06/06/2012 - 23:56:33 | SHD ] C:\$Recycle.Bin
[11/10/2011 - 07:29:36 | D ] C:\677420aa8d24365805e09ad3640bfa7a
[21/05/2011 - 16:03:12 | D ] C:\8b2331a490933910dc0db3e4
[02/03/2011 - 13:25:56 | D ] C:\Apps
[11/10/2011 - 07:19:35 | D ] C:\b9211b024fe978971616
[12/10/2011 - 13:17:35 | D ] C:\c787aa7d247d004c4392ba5ad4df6267
[09/05/2011 - 15:53:48 | D ] C:\DELL
[25/02/2011 - 20:11:30 | N | 3855] C:\dell.sdr
[14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings
[02/03/2011 - 14:59:45 | D ] C:\Drivers
[11/04/2008 - 10:07:18 | N | 3820] C:\eula.1028.txt
[11/04/2008 - 10:07:18 | N | 15428] C:\eula.1031.txt
[11/04/2008 - 10:07:18 | N | 10058] C:\eula.1033.txt
[11/04/2008 - 10:07:18 | N | 12246] C:\eula.1036.txt
[11/04/2008 - 10:07:18 | N | 13912] C:\eula.1040.txt
[11/04/2008 - 10:07:18 | N | 5868] C:\eula.1041.txt
[11/04/2008 - 10:07:18 | N | 5970] C:\eula.1042.txt
[11/04/2008 - 10:07:18 | N | 10134] C:\eula.1049.txt
[11/04/2008 - 10:07:18 | N | 3814] C:\eula.2052.txt
[11/04/2008 - 10:07:18 | N | 12936] C:\eula.3082.txt
[18/11/2011 - 11:25:09 | D ] C:\FIND_EULA_PATH
[11/04/2008 - 10:07:18 | N | 1110] C:\globdata.ini
[05/06/2012 - 23:46:41 | ASH | 4671815680] C:\hiberfil.sys
[11/04/2008 - 08:03:48 | N | 562688] C:\install.exe
[11/04/2008 - 10:07:18 | N | 843] C:\install.ini
[11/04/2008 - 08:03:48 | N | 76304] C:\install.res.1028.dll
[11/04/2008 - 08:03:48 | N | 96272] C:\install.res.1031.dll
[11/04/2008 - 08:03:48 | N | 91152] C:\install.res.1033.dll
[11/04/2008 - 08:03:48 | N | 97296] C:\install.res.1036.dll
[11/04/2008 - 08:03:48 | N | 95248] C:\install.res.1040.dll
[11/04/2008 - 08:03:48 | N | 81424] C:\install.res.1041.dll
[11/04/2008 - 08:03:48 | N | 79888] C:\install.res.1042.dll
[11/04/2008 - 10:09:24 | N | 93200] C:\install.res.1049.dll
[11/04/2008 - 08:03:48 | N | 75792] C:\install.res.2052.dll
[11/04/2008 - 08:03:48 | N | 96272] C:\install.res.3082.dll
[02/03/2011 - 15:01:57 | D ] C:\Intel
[08/08/2011 - 22:32:28 | RHD ] C:\MSOCache
[05/06/2012 - 23:46:44 | ASH | 6229090304] C:\pagefile.sys
[14/07/2009 - 05:20:08 | D ] C:\PerfLogs
[23/01/2012 - 15:26:42 | D ] C:\Program Files
[05/06/2012 - 10:23:15 | D ] C:\Program Files (x86)
[20/05/2012 - 09:31:41 | HD ] C:\ProgramData
[09/05/2011 - 16:04:39 | SHD ] C:\System Recovery
[05/06/2012 - 14:12:24 | SHD ] C:\System Volume Information
[02/03/2011 - 13:47:44 | D ] C:\Temp
[06/06/2012 - 23:56:33 | D ] C:\UsbFix
[06/06/2012 - 23:55:15 | A | 12209] C:\UsbFix.txt
[03/05/2011 - 04:04:56 | D ] C:\Users
[07/11/2007 - 09:00:40 | N | 5686] C:\vcredist.bmp
[11/04/2008 - 10:09:38 | N | 3797292] C:\VC_RED.cab
[11/04/2008 - 10:11:40 | N | 233472] C:\VC_RED.MSI
[20/05/2012 - 20:26:14 | D ] C:\Windows
[06/06/2012 - 19:30:39 | D ] C:\ZHP
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | Upload |
Please send the file: C:\UsbFix_Upload_Me_HINDA-PC.zip
http://eldesaparecido.com/upload.php
Thank you for your contribution.
################## | E.O.F |
############################## | UsbFix V 7.088 | [Deletion]
User: Hinda (Administrator) # HINDA-PC
Updated 16/05/2012 by El Desaparecido
Started at 23:52:31 | 06/06/2012
Website: https://www.sosvirus.net/
Forum: http://forum.eldesaparecido.com
Suspicious file ? : http://eldesaparecido.com/upload.php
Contact: contact@eldesaparecido.com
PC: Dell Inc. (Inspiron N7010) (x64-based PC) # Notebook
CPU: Intel(R) Core(TM) i5 CPU M 460 @ 2.53GHz (2534)
RAM -> [ Total : 5941 | Free : 4225 ]
BIOS: Ver 1.00 BIOS A09 PARTTBL
BOOT: Normal boot
OS: Microsoft Windows 7 Home Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 8.0.7601.17514
SC: Security Center Service [ Enabled ]
WU: Windows Update Service [ Enabled ]
AV: avast! Antivirus [ Enabled | Updated ]
FW: Windows FireWall Service [ Enabled ]
C:\ (%systemdrive%) -> Fixed drive # 581 Gb (498 Mb free - 86%) [OS] # NTFS
D:\ -> CD-ROM
################## | Active Processes |
C:\Windows\system32\csrss.exe (488)
C:\Windows\system32\wininit.exe (568)
C:\Windows\system32\csrss.exe (592)
C:\Windows\system32\services.exe (628)
C:\Windows\system32\lsass.exe (656)
C:\Windows\system32\lsm.exe (664)
C:\Windows\system32\svchost.exe (764)
C:\Windows\system32\svchost.exe (852)
C:\Windows\System32\svchost.exe (916)
C:\Windows\System32\svchost.exe (948)
C:\Windows\system32\svchost.exe (976)
C:\Windows\system32\winlogon.exe (508)
C:\Windows\system32\svchost.exe (836)
C:\Windows\system32\svchost.exe (1084)
C:\Windows\system32\WLANExt.exe (1268)
C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE (1284)
C:\Windows\system32\conhost.exe (1308)
C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe (1332)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1340)
C:\Windows\System32\spoolsv.exe (1968)
C:\Windows\system32\svchost.exe (2004)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1172)
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (1700)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1676)
C:\Program Files (x86)\Bonjour\mDNSResponder.exe (1520)
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (1876)
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (2308)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (2332)
C:\Windows\system32\svchost.exe (2396)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2452)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (2548)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (2768)
C:\Windows\system32\taskhost.exe (3064)
C:\Windows\system32\Dwm.exe (2836)
C:\Windows\Explorer.EXE (2448)
C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE (3208)
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE (3248)
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe (3492)
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (3552)
C:\Windows\System32\alg.exe (3860)
C:\Windows\system32\svchost.exe (4092)
C:\Windows\system32\svchost.exe (3392)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (4120)
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (4404)
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (4504)
C:\Windows\System32\igfxtray.exe (4564)
C:\Windows\System32\hkcmd.exe (4636)
C:\Windows\System32\igfxpers.exe (4672)
C:\Program Files\Dell\QuickSet\quickset.exe (4712)
C:\Windows\system32\wbem\wmiprvse.exe (4760)
C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (4780)
C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe (4832)
C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe (4980)
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (4996)
C:\Windows\system32\SearchIndexer.exe (4400)
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe (1276)
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (4220)
C:\Program Files\AVAST Software\Avast\AvastUI.exe (4184)
C:\Program Files (x86)\iTunes\iTunesHelper.exe (4768)
C:\Program Files (x86)\Athan\Athan.exe (4212)
C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe (5128)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (5176)
C:\Program Files (x86)\Ask.com\Updater\Updater.exe (5268)
C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe (5308)
C:\Program Files\iPod\bin\iPodService.exe (6136)
C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe (5740)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (6784)
C:\Windows\System32\svchost.exe (6912)
C:\Program Files\Windows Media Player\wmpnetwk.exe (6932)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (7004)
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (864)
C:\Program Files (x86)\Mozilla Firefox\firefox.exe (6808)
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (6996)
C:\Windows\system32\taskeng.exe (2192)
C:\Windows\system32\SearchProtocolHost.exe (4156)
C:\Windows\system32\SearchFilterHost.exe (7444)
C:\UsbFix\Go.exe (7500)
C:\Windows\system32\wbem\wmiprvse.exe (7424)
################## | Stopped processes |
Stopped! C:\Windows\system32\WLANExt.exe (1268)
Stopped! C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE (1284)
Stopped! C:\Windows\system32\conhost.exe (1308)
Stopped! C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe (1332)
Stopped! C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1340)
Stopped! C:\Windows\System32\spoolsv.exe (1968)
Stopped! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1172)
Stopped! C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (1700)
Stopped! C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1676)
Stopped! C:\Program Files (x86)\Bonjour\mDNSResponder.exe (1520)
Stopped! C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (1876)
Stopped! C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (2308)
Stopped! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (2332)
Stopped! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2452)
Stopped! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (2548)
Stopped! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (2768)
Stopped! C:\Windows\system32\taskhost.exe (3064)
Stopped! C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE (3208)
Stopped! C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE (3248)
Stopped! C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe (3492)
Stopped! C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (3552)
Stopped! C:\Windows\System32\alg.exe (3860)
Stopped! C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (4120)
Stopped! C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (4404)
Stopped! C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (4504)
Stopped! C:\Windows\System32\igfxtray.exe (4564)
Stopped! C:\Windows\System32\hkcmd.exe (4636)
Stopped! C:\Windows\System32\igfxpers.exe (4672)
Stopped! C:\Program Files\Dell\QuickSet\quickset.exe (4712)
Stopped! C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (4780)
Stopped! C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe (4832)
Stopped! C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe (4980)
Stopped! C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (4996)
Stopped! C:\Windows\system32\SearchIndexer.exe (4400)
Stopped! C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe (1276)
Stopped! C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (4220)
Stopped! C:\Program Files\AVAST Software\Avast\AvastUI.exe (4184)
Stopped! C:\Program Files (x86)\iTunes\iTunesHelper.exe (4768)
Stopped! C:\Program Files (x86)\Athan\Athan.exe (4212)
Stopped! C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe (5128)
Stopped! C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (5176)
Stopped! C:\Program Files (x86)\Ask.com\Updater\Updater.exe (5268)
Stopped! C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe (5308)
Stopped! C:\Program Files\iPod\bin\iPodService.exe (6136)
Stopped! C:\Program Files (x86)\Dell Stage\Dell Stage\stage_secondary.exe (5740)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (6784)
Stopped! C:\Program Files\Windows Media Player\wmpnetwk.exe (6932)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (7004)
Stopped! C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (864)
Stopped! C:\Program Files (x86)\Mozilla Firefox\firefox.exe (6808)
Stopped! C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (6996)
Stopped! C:\Windows\system32\taskeng.exe (2192)
Stopped! c:\program files\windows defender\MpCmdRun.exe (3668)
################## | Files # Infected Folders |
Deleted ! C:\Users\Hinda\AppData\Local\Temp\EpsonInkjetDriverDownloader.EXE
Deleted ! C:\Users\Hinda\AppData\Local\Temp\7za.exe
Deleted ! C:\$RECYCLE.BIN\S-1-5-20
Deleted ! C:\$RECYCLE.BIN\S-1-5-21-2647959408-2079287883-1907983367-1000
Deleted ! C:\$RECYCLE.BIN\S-1-5-21-2647959408-2079287883-1907983367-500
(!) Temporary files deleted.
################## | Registry |
################## | Mountpoints2 |
################## | Listing |
[06/06/2012 - 23:56:33 | SHD ] C:\$Recycle.Bin
[11/10/2011 - 07:29:36 | D ] C:\677420aa8d24365805e09ad3640bfa7a
[21/05/2011 - 16:03:12 | D ] C:\8b2331a490933910dc0db3e4
[02/03/2011 - 13:25:56 | D ] C:\Apps
[11/10/2011 - 07:19:35 | D ] C:\b9211b024fe978971616
[12/10/2011 - 13:17:35 | D ] C:\c787aa7d247d004c4392ba5ad4df6267
[09/05/2011 - 15:53:48 | D ] C:\DELL
[25/02/2011 - 20:11:30 | N | 3855] C:\dell.sdr
[14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings
[02/03/2011 - 14:59:45 | D ] C:\Drivers
[11/04/2008 - 10:07:18 | N | 3820] C:\eula.1028.txt
[11/04/2008 - 10:07:18 | N | 15428] C:\eula.1031.txt
[11/04/2008 - 10:07:18 | N | 10058] C:\eula.1033.txt
[11/04/2008 - 10:07:18 | N | 12246] C:\eula.1036.txt
[11/04/2008 - 10:07:18 | N | 13912] C:\eula.1040.txt
[11/04/2008 - 10:07:18 | N | 5868] C:\eula.1041.txt
[11/04/2008 - 10:07:18 | N | 5970] C:\eula.1042.txt
[11/04/2008 - 10:07:18 | N | 10134] C:\eula.1049.txt
[11/04/2008 - 10:07:18 | N | 3814] C:\eula.2052.txt
[11/04/2008 - 10:07:18 | N | 12936] C:\eula.3082.txt
[18/11/2011 - 11:25:09 | D ] C:\FIND_EULA_PATH
[11/04/2008 - 10:07:18 | N | 1110] C:\globdata.ini
[05/06/2012 - 23:46:41 | ASH | 4671815680] C:\hiberfil.sys
[11/04/2008 - 08:03:48 | N | 562688] C:\install.exe
[11/04/2008 - 10:07:18 | N | 843] C:\install.ini
[11/04/2008 - 08:03:48 | N | 76304] C:\install.res.1028.dll
[11/04/2008 - 08:03:48 | N | 96272] C:\install.res.1031.dll
[11/04/2008 - 08:03:48 | N | 91152] C:\install.res.1033.dll
[11/04/2008 - 08:03:48 | N | 97296] C:\install.res.1036.dll
[11/04/2008 - 08:03:48 | N | 95248] C:\install.res.1040.dll
[11/04/2008 - 08:03:48 | N | 81424] C:\install.res.1041.dll
[11/04/2008 - 08:03:48 | N | 79888] C:\install.res.1042.dll
[11/04/2008 - 10:09:24 | N | 93200] C:\install.res.1049.dll
[11/04/2008 - 08:03:48 | N | 75792] C:\install.res.2052.dll
[11/04/2008 - 08:03:48 | N | 96272] C:\install.res.3082.dll
[02/03/2011 - 15:01:57 | D ] C:\Intel
[08/08/2011 - 22:32:28 | RHD ] C:\MSOCache
[05/06/2012 - 23:46:44 | ASH | 6229090304] C:\pagefile.sys
[14/07/2009 - 05:20:08 | D ] C:\PerfLogs
[23/01/2012 - 15:26:42 | D ] C:\Program Files
[05/06/2012 - 10:23:15 | D ] C:\Program Files (x86)
[20/05/2012 - 09:31:41 | HD ] C:\ProgramData
[09/05/2011 - 16:04:39 | SHD ] C:\System Recovery
[05/06/2012 - 14:12:24 | SHD ] C:\System Volume Information
[02/03/2011 - 13:47:44 | D ] C:\Temp
[06/06/2012 - 23:56:33 | D ] C:\UsbFix
[06/06/2012 - 23:55:15 | A | 12209] C:\UsbFix.txt
[03/05/2011 - 04:04:56 | D ] C:\Users
[07/11/2007 - 09:00:40 | N | 5686] C:\vcredist.bmp
[11/04/2008 - 10:09:38 | N | 3797292] C:\VC_RED.cab
[11/04/2008 - 10:11:40 | N | 233472] C:\VC_RED.MSI
[20/05/2012 - 20:26:14 | D ] C:\Windows
[06/06/2012 - 19:30:39 | D ] C:\ZHP
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | Upload |
Please send the file: C:\UsbFix_Upload_Me_HINDA-PC.zip
http://eldesaparecido.com/upload.php
Thank you for your contribution.
################## | E.O.F |
Utilisateur anonyme
7 juin 2012 à 00:12
7 juin 2012 à 00:12
Désactive toutes tes protections si possible , antivirus , sandbox , etc....
telecharge et enregistre Pre_Scan sur ton bureau :
http://forums-fec.be/gen-hackman/Pre_Scan.exe
http://general-changelog-team.fr/fr/downloads/viewdownload/41-outils-de-gen-hackman/52-pre-scan
Avertissement :Il y aura une extinction du bureau pendant le scan --> pas de panique.
une fois telechargé lance-le , laisse faire le scan jusqu'à l'apparition de "Pre_scan_la_date_et_l'heure.txt" sur le bureau.
si l'outil est relancé plusieurs fois , il te proposera un menu et qu'aucune option n'est demandée, lance l'option "Kill"
si l'outil est bloqué par l'infection utilise cette version avec extension .pif :
http://forums-fec.be/gen-hackman/Pre_Scan.pif
ou cette version renommée winlogon.exe :
http://forums-fec.be/gen-hackman/winlogon.exe
si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"
Il se peut qu'une multitude de fenêtres noires clignotent , laisse-le travailler
Poste Pre_Scan_la_date_et_l'heure.txt qui apparaitra sur le bureau en fin de scan
NE LE POSTE PAS SUR LE FORUM !!! (il est trop long)
Heberge le rapport sur http://pjjoint.malekal.com puis donne le lien obtenu en echange sur le forum où tu te fais aider
telecharge et enregistre Pre_Scan sur ton bureau :
http://forums-fec.be/gen-hackman/Pre_Scan.exe
http://general-changelog-team.fr/fr/downloads/viewdownload/41-outils-de-gen-hackman/52-pre-scan
Avertissement :Il y aura une extinction du bureau pendant le scan --> pas de panique.
une fois telechargé lance-le , laisse faire le scan jusqu'à l'apparition de "Pre_scan_la_date_et_l'heure.txt" sur le bureau.
si l'outil est relancé plusieurs fois , il te proposera un menu et qu'aucune option n'est demandée, lance l'option "Kill"
si l'outil est bloqué par l'infection utilise cette version avec extension .pif :
http://forums-fec.be/gen-hackman/Pre_Scan.pif
ou cette version renommée winlogon.exe :
http://forums-fec.be/gen-hackman/winlogon.exe
si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"
Il se peut qu'une multitude de fenêtres noires clignotent , laisse-le travailler
Poste Pre_Scan_la_date_et_l'heure.txt qui apparaitra sur le bureau en fin de scan
NE LE POSTE PAS SUR LE FORUM !!! (il est trop long)
Heberge le rapport sur http://pjjoint.malekal.com puis donne le lien obtenu en echange sur le forum où tu te fais aider
ismai2003
Messages postés
9
Date d'inscription
mercredi 6 juin 2012
Statut
Membre
Dernière intervention
7 juin 2012
7 juin 2012 à 00:52
7 juin 2012 à 00:52
Utilisateur anonyme
Modifié par g3n-h@ckm@n le 7/06/2012 à 01:43
Modifié par g3n-h@ckm@n le 7/06/2012 à 01:43
mets internet explorer à jour
mets mozilla à jour
========
ne telecharge plus sur 01net , ils refourguent des toolbars pourries avec les installeurs de programmes , ils les repackent à leur sauce !
========
desinstalle 4shared toolbar
desinstalle complitly
desinstalle Ask.com/Ask.Toolbar
desinstalle searchweb
desinstalle tout Java
========
Selectionne tout le texte en gras ci-dessous sans les lignes de dessus-dessous, puis (clic droit/copier ou ctrl+c) :
___________________________________________________
Kill::
Registry::
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\Microsoft\Internet Explorer\SearchScopes\{12995981-2FD6-4BEE-9FB0-B1674E8E5E7E}]
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\Microsoft\Internet Explorer\SearchScopes\{A63FB974-580C-4D15-96A1-A783DCFC7CD1}]
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}]
[-HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6}]
[-HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6}]
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6}]
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000_Classes\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6}]
[-HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6}]
[-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}]
[-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
""=-
"QuickTime Task"=-
"ApnUpdater"=-
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
""=-
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]
"Locked"=-
"{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}"=-
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
"{95080B13-AA71-4EE8-B951-7E98221E1ED5}"=-
[HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\Microsoft\Internet Explorer\Toolbar]
"Locked"=-
[-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}]
[-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95525BD9-6136-4A26-8263-9CEE295D442D}]
[-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0924543-15FD-4F3D-889C-0B4562A9CB45}]
[-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[-HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
[-HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}]
[-HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\4shared Toolbar]
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\APN]
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\Ask.com]
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\Complitly]
[-HKLM\Software\APN]
[-HKLM\Software\AskToolbar]
File::
C:\Users\Guillaume\Downloads\SweetImSetup.exe
C:\Program Files (x86)\Mozilla Firefox\searchplugins\4shared.xml
C:\Windows\,÷e
C:\Users\Hinda\Downloads\avast_free6_01Net.exe
C:\Users\Hinda\AppData\Roaming\Mozilla\Firefox\Profiles\xzmb5539.default\extensions\4sharedToolbar.xpi
Folder::
C:\Program Files (x86)\searchweb
C:\Program Files (x86)\Ask.com
C:\Users\Hinda\AppData\Roaming\Mozilla\Firefox\Profiles\xzmb5539.default\extensions\toolbar@ask.com
C:\Users\Hinda\AppData\Roaming\Complitly
C:\Program Files (x86)\4shared Toolbar
C:\677420aa8d24365805e09ad3640bfa7a
C:\8b2331a490933910dc0db3e4
C:\b9211b024fe978971616
C:\c787aa7d247d004c4392ba5ad4df6267
C:\Users\Hinda\AppData\Local\APN
C:\Program Files (x86)\Complitly
MBR::
clean::
Reboot::
___________________________________________________
Relance Pre_scan puis choisis l'option "Script"
une page va s'ouvrir
logiquement le texte que tu as sélectionné s'y trouve déjà , donc tu fermes et le programme va travailler.
sinon colle-le (clic droit/coller ou ctrl+V) dans la page vierge.
puis onglet fichier => enregistrer (pas enregistrer sous...) , puis ferme le texte
des fenetres noires risquent de clignoter , c'est normal , c'est le programme qui travaille
poste Pre_Script.txt qui apparaitra sur le bureau en fin de travail
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Scan_Concept ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
mets mozilla à jour
========
ne telecharge plus sur 01net , ils refourguent des toolbars pourries avec les installeurs de programmes , ils les repackent à leur sauce !
========
desinstalle 4shared toolbar
desinstalle complitly
desinstalle Ask.com/Ask.Toolbar
desinstalle searchweb
desinstalle tout Java
========
Selectionne tout le texte en gras ci-dessous sans les lignes de dessus-dessous, puis (clic droit/copier ou ctrl+c) :
___________________________________________________
Kill::
Registry::
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\Microsoft\Internet Explorer\SearchScopes\{12995981-2FD6-4BEE-9FB0-B1674E8E5E7E}]
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\Microsoft\Internet Explorer\SearchScopes\{A63FB974-580C-4D15-96A1-A783DCFC7CD1}]
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}]
[-HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6}]
[-HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6}]
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6}]
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000_Classes\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6}]
[-HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6}]
[-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}]
[-HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}]
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
""=-
"QuickTime Task"=-
"ApnUpdater"=-
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
""=-
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]
"Locked"=-
"{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}"=-
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
"{95080B13-AA71-4EE8-B951-7E98221E1ED5}"=-
[HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\Microsoft\Internet Explorer\Toolbar]
"Locked"=-
[-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}]
[-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95525BD9-6136-4A26-8263-9CEE295D442D}]
[-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0924543-15FD-4F3D-889C-0B4562A9CB45}]
[-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[-HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
[-HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}]
[-HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\4shared Toolbar]
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\APN]
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\Ask.com]
[-HKU\S-1-5-21-2647959408-2079287883-1907983367-1000\Software\Complitly]
[-HKLM\Software\APN]
[-HKLM\Software\AskToolbar]
File::
C:\Users\Guillaume\Downloads\SweetImSetup.exe
C:\Program Files (x86)\Mozilla Firefox\searchplugins\4shared.xml
C:\Windows\,÷e
C:\Users\Hinda\Downloads\avast_free6_01Net.exe
C:\Users\Hinda\AppData\Roaming\Mozilla\Firefox\Profiles\xzmb5539.default\extensions\4sharedToolbar.xpi
Folder::
C:\Program Files (x86)\searchweb
C:\Program Files (x86)\Ask.com
C:\Users\Hinda\AppData\Roaming\Mozilla\Firefox\Profiles\xzmb5539.default\extensions\toolbar@ask.com
C:\Users\Hinda\AppData\Roaming\Complitly
C:\Program Files (x86)\4shared Toolbar
C:\677420aa8d24365805e09ad3640bfa7a
C:\8b2331a490933910dc0db3e4
C:\b9211b024fe978971616
C:\c787aa7d247d004c4392ba5ad4df6267
C:\Users\Hinda\AppData\Local\APN
C:\Program Files (x86)\Complitly
MBR::
clean::
Reboot::
___________________________________________________
Relance Pre_scan puis choisis l'option "Script"
une page va s'ouvrir
logiquement le texte que tu as sélectionné s'y trouve déjà , donc tu fermes et le programme va travailler.
sinon colle-le (clic droit/coller ou ctrl+V) dans la page vierge.
puis onglet fichier => enregistrer (pas enregistrer sous...) , puis ferme le texte
des fenetres noires risquent de clignoter , c'est normal , c'est le programme qui travaille
poste Pre_Script.txt qui apparaitra sur le bureau en fin de travail
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Scan_Concept ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
ismai2003
Messages postés
9
Date d'inscription
mercredi 6 juin 2012
Statut
Membre
Dernière intervention
7 juin 2012
7 juin 2012 à 11:41
7 juin 2012 à 11:41
merci beaucoup de ton aide!
voici le rapport:
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Script | 2.606 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Hinda : Windows 7 Home Premium (64 bits)
Switchs : https://gen-hackman.kanak.fr/
Script : 11:40:04
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Absent : C:\Users\Guillaume\Downloads\SweetImSetup.exe
Supprimé : C:\Program Files (x86)\Mozilla Firefox\searchplugins\4shared.xml
Supprimé : C:\Windows\,÷e
Supprimé : C:\Users\Hinda\Downloads\avast_free6_01Net.exe
Supprimé : C:\Users\Hinda\AppData\Roaming\Mozilla\Firefox\Profiles\xzmb5539.default\extensions\4sharedToolbar.xpi
¤
Supprimé : C:\Program Files (x86)\searchweb
Absent : C:\Program Files (x86)\Ask.com
Absent : C:\Users\Hinda\AppData\Roaming\Mozilla\Firefox\Profiles\xzmb5539.default\extensions\toolbar@ask.com
Absent : C:\Users\Hinda\AppData\Roaming\Complitly
Supprimé : C:\Program Files (x86)\4shared Toolbar
Supprimé : C:\677420aa8d24365805e09ad3640bfa7a
Supprimé : C:\8b2331a490933910dc0db3e4
Supprimé : C:\b9211b024fe978971616
non Supprimé : C:\c787aa7d247d004c4392ba5ad4df6267
Supprimé : C:\Users\Hinda\AppData\Local\APN
Absent : C:\Program Files (x86)\Complitly
¤
Fin : 11:40:06
¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤
voici le rapport:
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Script | 2.606 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Hinda : Windows 7 Home Premium (64 bits)
Switchs : https://gen-hackman.kanak.fr/
Script : 11:40:04
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Absent : C:\Users\Guillaume\Downloads\SweetImSetup.exe
Supprimé : C:\Program Files (x86)\Mozilla Firefox\searchplugins\4shared.xml
Supprimé : C:\Windows\,÷e
Supprimé : C:\Users\Hinda\Downloads\avast_free6_01Net.exe
Supprimé : C:\Users\Hinda\AppData\Roaming\Mozilla\Firefox\Profiles\xzmb5539.default\extensions\4sharedToolbar.xpi
¤
Supprimé : C:\Program Files (x86)\searchweb
Absent : C:\Program Files (x86)\Ask.com
Absent : C:\Users\Hinda\AppData\Roaming\Mozilla\Firefox\Profiles\xzmb5539.default\extensions\toolbar@ask.com
Absent : C:\Users\Hinda\AppData\Roaming\Complitly
Supprimé : C:\Program Files (x86)\4shared Toolbar
Supprimé : C:\677420aa8d24365805e09ad3640bfa7a
Supprimé : C:\8b2331a490933910dc0db3e4
Supprimé : C:\b9211b024fe978971616
non Supprimé : C:\c787aa7d247d004c4392ba5ad4df6267
Supprimé : C:\Users\Hinda\AppData\Local\APN
Absent : C:\Program Files (x86)\Complitly
¤
Fin : 11:40:06
¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤
ismai2003
Messages postés
9
Date d'inscription
mercredi 6 juin 2012
Statut
Membre
Dernière intervention
7 juin 2012
7 juin 2012 à 13:48
7 juin 2012 à 13:48
voila de nouveau
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Script | 2.606 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Hinda : Windows 7 Home Premium (64 bits)
Switchs : https://gen-hackman.kanak.fr/
Script : 13:42:33
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Modification du registre effectuée
¤
Absent : C:\Users\Guillaume\Downloads\SweetImSetup.exe
Absent : C:\Program Files (x86)\Mozilla Firefox\searchplugins\4shared.xml
Absent : C:\Windows\,÷e
Absent : C:\Users\Hinda\Downloads\avast_free6_01Net.exe
Absent : C:\Users\Hinda\AppData\Roaming\Mozilla\Firefox\Profiles\xzmb5539.default\extensions\4sharedToolbar.xpi
¤
Absent : C:\Program Files (x86)\searchweb
Absent : C:\Program Files (x86)\Ask.com
Absent : C:\Users\Hinda\AppData\Roaming\Mozilla\Firefox\Profiles\xzmb5539.default\extensions\toolbar@ask.com
Absent : C:\Users\Hinda\AppData\Roaming\Complitly
Absent : C:\Program Files (x86)\4shared Toolbar
Absent : C:\677420aa8d24365805e09ad3640bfa7a
Absent : C:\8b2331a490933910dc0db3e4
Absent : C:\b9211b024fe978971616
non Supprimé : C:\c787aa7d247d004c4392ba5ad4df6267
Absent : C:\Users\Hinda\AppData\Local\APN
Absent : C:\Program Files (x86)\Complitly
¤
¤¤¤¤¤¤¤¤¤¤ | MBR
Windows Version: Windows 7 Home Premium Edition
Windows Information: Service Pack 1 (build 7601), 64-bit
Base Board Manufacturer: Dell Inc.
BIOS Manufacturer: Dell Inc.
System Manufacturer: Dell Inc.
System Product Name: Inspiron N7010
Logical Drives Mask: 0x0001000c
Analysis of file "C:\Pre_Scan\MBR.bin":
Windows 2008 MBR code detected
¤
¤¤¤¤¤¤¤¤¤¤ | Nettoyage disque
Nettoyage du disque effectué
¤
explorer.exe -> Processus redémarré
Fin : 13:43:06
¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Script | 2.606 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Hinda : Windows 7 Home Premium (64 bits)
Switchs : https://gen-hackman.kanak.fr/
Script : 13:42:33
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Modification du registre effectuée
¤
Absent : C:\Users\Guillaume\Downloads\SweetImSetup.exe
Absent : C:\Program Files (x86)\Mozilla Firefox\searchplugins\4shared.xml
Absent : C:\Windows\,÷e
Absent : C:\Users\Hinda\Downloads\avast_free6_01Net.exe
Absent : C:\Users\Hinda\AppData\Roaming\Mozilla\Firefox\Profiles\xzmb5539.default\extensions\4sharedToolbar.xpi
¤
Absent : C:\Program Files (x86)\searchweb
Absent : C:\Program Files (x86)\Ask.com
Absent : C:\Users\Hinda\AppData\Roaming\Mozilla\Firefox\Profiles\xzmb5539.default\extensions\toolbar@ask.com
Absent : C:\Users\Hinda\AppData\Roaming\Complitly
Absent : C:\Program Files (x86)\4shared Toolbar
Absent : C:\677420aa8d24365805e09ad3640bfa7a
Absent : C:\8b2331a490933910dc0db3e4
Absent : C:\b9211b024fe978971616
non Supprimé : C:\c787aa7d247d004c4392ba5ad4df6267
Absent : C:\Users\Hinda\AppData\Local\APN
Absent : C:\Program Files (x86)\Complitly
¤
¤¤¤¤¤¤¤¤¤¤ | MBR
Windows Version: Windows 7 Home Premium Edition
Windows Information: Service Pack 1 (build 7601), 64-bit
Base Board Manufacturer: Dell Inc.
BIOS Manufacturer: Dell Inc.
System Manufacturer: Dell Inc.
System Product Name: Inspiron N7010
Logical Drives Mask: 0x0001000c
Analysis of file "C:\Pre_Scan\MBR.bin":
Windows 2008 MBR code detected
¤
¤¤¤¤¤¤¤¤¤¤ | Nettoyage disque
Nettoyage du disque effectué
¤
explorer.exe -> Processus redémarré
Fin : 13:43:06
¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤
Utilisateur anonyme
7 juin 2012 à 14:28
7 juin 2012 à 14:28
Télécharge et enregistre ADWcleaner sur ton bureau :
ADWCleaner (Merci à Xplode)
Lance le,
clique sur suppression et poste son rapport.
ADWCleaner (Merci à Xplode)
Lance le,
clique sur suppression et poste son rapport.
ismai2003
Messages postés
9
Date d'inscription
mercredi 6 juin 2012
Statut
Membre
Dernière intervention
7 juin 2012
7 juin 2012 à 19:09
7 juin 2012 à 19:09
voila
# AdwCleaner v1.608 - Logfile created 06/07/2012 at 19:02:34
# Updated 27/05/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Hinda - HINDA-PC
# Running from : C:\Users\Hinda\Downloads\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
Folder Deleted : C:\Users\Hinda\AppData\Local\Temp\AskSearch
Folder Deleted : C:\Users\Hinda\AppData\LocalLow\Toolbar4
File Deleted : C:\Users\Hinda\AppData\Roaming\Mozilla\Firefox\Profiles\xzmb5539.default\searchplugins\Askcom.xml
File Deleted : C:\Users\Public\Desktop\eBay.lnk
***** [Registry] *****
[*] Key Deleted : HKLM\SOFTWARE\Classes\TBSB02609.IEToolbar
[*] Key Deleted : HKLM\SOFTWARE\Classes\TBSB02609.IEToolbar.1
[*] Key Deleted : HKLM\SOFTWARE\Classes\TBSB02609.TBSB02609
[*] Key Deleted : HKLM\SOFTWARE\Classes\TBSB02609.TBSB02609.3
[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.TBSB02609
[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.TBSB02609.1
Key Deleted : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler
Key Deleted : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler.1
Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils
Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager.1
Key Deleted : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook
Key Deleted : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
Key Deleted : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
***** [Registre - GUID] *****
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C0924543-15FD-4F3D-889C-0B4562A9CB45}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D433A9D0-8267-40CB-8AD5-24F22FA5373F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EC4085F2-8DB3-45A6-AD0B-CA289F3C5D7E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0924543-15FD-4F3D-889C-0B4562A9CB45}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C0924543-15FD-4F3D-889C-0B4562A9CB45}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C0924543-15FD-4F3D-889C-0B4562A9CB45}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{CA3EB689-8F09-4026-AA10-B9534C691CE0}]
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
[OK] Registry is clean.
-\\ Mozilla Firefox v12.0 (fr)
Profile name : default
File : C:\Users\Hinda\AppData\Roaming\Mozilla\Firefox\Profiles\xzmb5539.default\prefs.js
[OK] File is clean.
-\\ Google Chrome v19.0.1084.52
File : C:\Users\Hinda\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [12531 octets] - [07/06/2012 19:01:03]
AdwCleaner[S1].txt - [270 octets] - [07/06/2012 19:01:19]
AdwCleaner[R2].txt - [12651 octets] - [07/06/2012 19:02:08]
AdwCleaner[R3].txt - [12712 octets] - [07/06/2012 19:02:26]
AdwCleaner[S2].txt - [9528 octets] - [07/06/2012 19:02:34]
########## EOF - C:\AdwCleaner[S2].txt - [9656 octets] ##########
# AdwCleaner v1.608 - Logfile created 06/07/2012 at 19:02:34
# Updated 27/05/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Hinda - HINDA-PC
# Running from : C:\Users\Hinda\Downloads\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
Folder Deleted : C:\Users\Hinda\AppData\Local\Temp\AskSearch
Folder Deleted : C:\Users\Hinda\AppData\LocalLow\Toolbar4
File Deleted : C:\Users\Hinda\AppData\Roaming\Mozilla\Firefox\Profiles\xzmb5539.default\searchplugins\Askcom.xml
File Deleted : C:\Users\Public\Desktop\eBay.lnk
***** [Registry] *****
[*] Key Deleted : HKLM\SOFTWARE\Classes\TBSB02609.IEToolbar
[*] Key Deleted : HKLM\SOFTWARE\Classes\TBSB02609.IEToolbar.1
[*] Key Deleted : HKLM\SOFTWARE\Classes\TBSB02609.TBSB02609
[*] Key Deleted : HKLM\SOFTWARE\Classes\TBSB02609.TBSB02609.3
[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.TBSB02609
[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.TBSB02609.1
Key Deleted : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler
Key Deleted : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler.1
Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils
Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager.1
Key Deleted : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook
Key Deleted : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
Key Deleted : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
***** [Registre - GUID] *****
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C0924543-15FD-4F3D-889C-0B4562A9CB45}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D433A9D0-8267-40CB-8AD5-24F22FA5373F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EC4085F2-8DB3-45A6-AD0B-CA289F3C5D7E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0924543-15FD-4F3D-889C-0B4562A9CB45}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C0924543-15FD-4F3D-889C-0B4562A9CB45}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C0924543-15FD-4F3D-889C-0B4562A9CB45}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{CA3EB689-8F09-4026-AA10-B9534C691CE0}]
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
[OK] Registry is clean.
-\\ Mozilla Firefox v12.0 (fr)
Profile name : default
File : C:\Users\Hinda\AppData\Roaming\Mozilla\Firefox\Profiles\xzmb5539.default\prefs.js
[OK] File is clean.
-\\ Google Chrome v19.0.1084.52
File : C:\Users\Hinda\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [12531 octets] - [07/06/2012 19:01:03]
AdwCleaner[S1].txt - [270 octets] - [07/06/2012 19:01:19]
AdwCleaner[R2].txt - [12651 octets] - [07/06/2012 19:02:08]
AdwCleaner[R3].txt - [12712 octets] - [07/06/2012 19:02:26]
AdwCleaner[S2].txt - [9528 octets] - [07/06/2012 19:02:34]
########## EOF - C:\AdwCleaner[S2].txt - [9656 octets] ##########