Desinstaller istartsurf

Résolu/Fermé
christianreba Messages postés 2 Date d'inscription mercredi 20 août 2014 Statut Membre Dernière intervention 20 août 2014 - 20 août 2014 à 11:01
 Mélissa - 11 sept. 2014 à 21:28
Bonjour,
je n'arrive pas à desinstaller ce logiciel, j ai telecharger adwcleaner, voici le rapport
Que faire ensuite ?
Le programme apparait tjrs dans le panneau de config

# AdwCleaner v3.307 - Rapport créé le 20/08/2014 à 10:50:45
# Mis à jour le 17/08/2014 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : christian - CHRISTIAN-HP
# Exécuté depuis : C:\Users\christian\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W8MCFRIA\adwcleaner_3.307.exe
# Option : Nettoyer

***** [ Services ] *****

[#] Service Supprimé : globalUpdate
[#] Service Supprimé : globalUpdatem
Service Supprimé : IePluginServices
Service Supprimé : servervo
Service Supprimé : WindowsMangerProtect

***** [ Fichiers / Dossiers ] *****

Dossier Supprimé : C:\ProgramData\IePluginServices
Dossier Supprimé : C:\ProgramData\Tarma Installer
Dossier Supprimé : C:\ProgramData\WindowsMangerProtect
Dossier Supprimé : C:\Program Files (x86)\Conduit
Dossier Supprimé : C:\Program Files (x86)\globalUpdate
Dossier Supprimé : C:\Program Files (x86)\SupTab
Dossier Supprimé : C:\Program Files (x86)\fst_fr_350
Dossier Supprimé : C:\Program Files (x86)\Browsers Apps
Dossier Supprimé : C:\Users\christian\AppData\Local\globalUpdate
Dossier Supprimé : C:\Users\christian\AppData\Local\fst_fr_350
Dossier Supprimé : C:\Users\christian\AppData\LocalLow\Conduit
Dossier Supprimé : C:\Users\christian\AppData\Roaming\istartsurf
Dossier Supprimé : C:\Users\christian\AppData\Roaming\OpenCandy
Dossier Supprimé : C:\Users\christian\AppData\Roaming\VOPackage
Dossier Supprimé : C:\Users\christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
Dossier Supprimé : C:\Users\christian\AppData\Roaming\Mozilla\Firefox\Profiles\4tqgmrvs.default\Extensions\herman.thorne45@outlook.com
Fichier Supprimé : C:\Users\christian\AppData\Local\CRE\ehdmaehkiiampolokajdcelladmnopgp.crx
Fichier Supprimé : C:\Users\Invité\Desktop\NewPlayer.lnk
Fichier Supprimé : C:\Users\christian\AppData\Roaming\Mozilla\Firefox\Profiles\4tqgmrvs.default\user.js
Fichier Supprimé : C:\Program Files (x86)\Mozilla Firefox\user.js
Fichier Supprimé : C:\Users\christian\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.betterdeals00.betterdeals.co_0.localstorage
Fichier Supprimé : C:\Users\christian\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.betterdeals00.betterdeals.co_0.localstorage-journal
Fichier Supprimé : C:\Users\christian\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal

***** [ Tâches planifiées ] *****

Tâche Supprimée : globalUpdateUpdateTaskMachineCore
Tâche Supprimée : globalUpdateUpdateTaskMachineUA
Tâche Supprimée : LaunchSignup
Tâche Supprimée : 1df86810-79ae-4103-8c9c-ad59d01a4a68
Tâche Supprimée : 476c72aa-295a-47d8-82d5-dba217406c47
Tâche Supprimée : 7bd54baa-3d74-4d74-b796-3db42a5a2f6f-1
Tâche Supprimée : 7bd54baa-3d74-4d74-b796-3db42a5a2f6f-11
Tâche Supprimée : 7bd54baa-3d74-4d74-b796-3db42a5a2f6f-2
Tâche Supprimée : 7bd54baa-3d74-4d74-b796-3db42a5a2f6f-3
Tâche Supprimée : 7bd54baa-3d74-4d74-b796-3db42a5a2f6f-4
Tâche Supprimée : 7bd54baa-3d74-4d74-b796-3db42a5a2f6f-5
Tâche Supprimée : 7bd54baa-3d74-4d74-b796-3db42a5a2f6f-5_user
Tâche Supprimée : 7bd54baa-3d74-4d74-b796-3db42a5a2f6f-6
Tâche Supprimée : 7bd54baa-3d74-4d74-b796-3db42a5a2f6f-7
Tâche Supprimée : 8901a572-5539-47f0-8345-541083ea4d05

***** [ Raccourcis ] *****

Raccourci Désinfecté : C:\Users\christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Raccourci Désinfecté : C:\Users\christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Raccourci Désinfecté : C:\Users\christian\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Raccourci Désinfecté : C:\Users\christian\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk
Raccourci Désinfecté : C:\Users\christian\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk

***** [ Registre ] *****

Clé Supprimée : HKCU\Software\Google\Chrome\Extensions\ehdmaehkiiampolokajdcelladmnopgp
Clé Supprimée : HKLM\SOFTWARE\Google\Chrome\Extensions\ehdmaehkiiampolokajdcelladmnopgp
Clé Supprimée : HKLM\SOFTWARE\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\Prod.cap
Clé Supprimée : HKLM\SOFTWARE\Classes\speedupmypc
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASAPI32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASMANCS
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasapi32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasmancs
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\sweetpacksupdatemanager_rasapi32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASMANCS
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\wajamupdater_rasapi32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\wajamupdater_rasmancs
Clé Supprimée : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Clé Supprimée : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Clé Supprimée : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Clé Supprimée : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [fst_fr_350]
Clé Supprimée : HKLM\SOFTWARE\Classes\CrossriderApp0061787.BHO
Clé Supprimée : HKLM\SOFTWARE\Classes\CrossriderApp0061787.BHO.1
Clé Supprimée : HKLM\SOFTWARE\Classes\CrossriderApp0061787.Sandbox
Clé Supprimée : HKLM\SOFTWARE\Classes\CrossriderApp0061787.Sandbox.1
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_pour_soulseek_RASAPI32
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_pour_soulseek_RASMANCS
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611171187}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622172287}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175587}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176687}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644174487}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171187}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611171187}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611171187}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Valeur Supprimée : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{8E5025C2-8EA3-430D-80B8-A14151068A6D}]
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611171187}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622172287}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175587}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176687}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171187}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Donnée Restaurée : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Clé Supprimée : HKCU\Software\Conduit
Clé Supprimée : HKCU\Software\GlobalUpdate
Clé Supprimée : HKCU\Software\InstalledBrowserExtensions
Clé Supprimée : HKCU\Software\Microsoft\Babylon
Clé Supprimée : HKCU\Software\Softonic
Clé Supprimée : HKCU\Software\SupHpUISoft
Clé Supprimée : HKCU\Software\Tutorials
Clé Supprimée : HKCU\Software\TutoTag
Clé Supprimée : HKCU\Software\AppDataLow\Software\Browsers Apps
Clé Supprimée : HKCU\Software\AppDataLow\Software\Conduit
Clé Supprimée : HKCU\Software\AppDataLow\Software\Crossrider
Clé Supprimée : HKCU\Software\AppDataLow\Software\SmartBar
Clé Supprimée : HKLM\SOFTWARE\Browsers Apps
Clé Supprimée : HKLM\SOFTWARE\Conduit
Clé Supprimée : HKLM\SOFTWARE\FreeSoftToday
Clé Supprimée : HKLM\SOFTWARE\GlobalUpdate
Clé Supprimée : HKLM\SOFTWARE\InstalledBrowserExtensions
Clé Supprimée : HKLM\SOFTWARE\SupDp
Clé Supprimée : HKLM\SOFTWARE\SupTab
Clé Supprimée : HKLM\SOFTWARE\supWindowsMangerProtect
Clé Supprimée : HKLM\SOFTWARE\supWPM
Clé Supprimée : HKLM\SOFTWARE\Tutorials
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Browsers Apps
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowsMangerProtect
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\fst_fr_350_is1
Clé Supprimée : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Clé Supprimée : [x64] HKLM\SOFTWARE\Tarma Installer
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B2468513CA2D6943A1A233CD3F88CE7
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3192AA38321C641458DBDAF83979D193

***** [ Navigateurs ] *****

-\\ Internet Explorer v11.0.9600.17239

Paramètre Restauré : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Paramètre Restauré : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Paramètre Restauré : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Paramètre Restauré : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Paramètre Restauré : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Paramètre Restauré : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Paramètre Restauré : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Paramètre Restauré : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Paramètre Restauré : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Paramètre Restauré : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]

-\\ Mozilla Firefox v

[ Fichier : C:\Users\christian\AppData\Roaming\Mozilla\Firefox\Profiles\4tqgmrvs.default\prefs.js ]


[ Fichier : C:\Users\Invité\AppData\Roaming\Mozilla\Firefox\Profiles\edaukgdk.default\prefs.js ]


-\\ Google Chrome v36.0.1985.143

[ Fichier : C:\Users\christian\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Supprimée [Search Provider] : hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010006.10028&barid={AFA062AD-1C7C-11E2-B2CA-E8393559BB8F}
Supprimée [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&ctid=CT3128284
Supprimée [Search Provider] : hxxp://search.babylon.com/?q={searchTerms}&affID=111020&tt=3212_7&babsrc=SP_ss&mntrId=4a30a6a80000000000000021917dcbc9
Supprimée [Search Provider] : hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPDTDF
Supprimée [Search Provider] : hxxp://websearch.ask.com/redirect?client=cr&src=kw&tb=ORJ&o=&locale=&apn_uid=C4777821-BF86-4EA1-8D69-7F8BA690995A&apn_ptnrs=U3&apn_sauid=3FCEAB72-A824-420C-AF84-3FFDF618B9F2&apn_dtid=OSJ000YYFR&q={searchTerms}
Supprimée [Search Provider] : hxxp://www.istartsurf.com/web/?type=ds&ts=1408478528&from=tugs&uid=ST3500413AS_Z2AT6TRE&q={searchTerms}
Supprimée [Search Provider] : hxxp://www.istartsurf.com/web/?type=ds&ts=1408478528&from=tugs&uid=ST3500413AS_Z2AT6TRE&q={searchTerms}
Supprimée [Search Provider] : hxxp://www.istartsurf.com/web/?type=ds&ts=1408478528&from=tugs&uid=ST3500413AS_Z2AT6TRE&q={searchTerms}
Supprimée [Startup_urls] : hxxp://search.conduit.com/?ctid=CT3128284&SearchSource=48
Supprimée [Startup_urls] : hxxp://www.istartsurf.com/?type=hp&ts=1408478528&from=tugs&uid=ST3500413AS_Z2AT6TRE
Supprimée [Homepage] : hxxp://search.conduit.com/?SearchSource=10&ctid=CT3128284
Supprimée [Extension] : ehdmaehkiiampolokajdcelladmnopgp

[ Fichier : C:\Users\Invité\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Supprimée [Search Provider] : hxxp://kogoa.com/?q={searchTerms}
Supprimée [Search Provider] : hxxp://isearch.avg.com/search?cid={054257E2-FBE8-41B9-915B-1E404CBD4ABE}&mid=66b00bc1d5b347d38fb9d147e0840740-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=fr&ds=lw011&pr=sa&d=2013-07-03 09:23:07&v=15.3.0.11&pid=avg&sg=0&sap=dsp&q={searchTerms}
Supprimée [Startup_urls] : hxxp://isearch.avg.com/?cid={054257E2-FBE8-41B9-915B-1E404CBD4ABE}&mid=66b00bc1d5b347d38fb9d147e0840740-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=fr&ds=lw011&pr=sa&d=2013-07-03 09:23:07&v=15.3.0.11&pid=avg&sg=0&sap=hp
Supprimée [Homepage] : hxxp://isearch.avg.com/?cid={054257E2-FBE8-41B9-915B-1E404CBD4ABE}&mid=66b00bc1d5b347d38fb9d147e0840740-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=fr&ds=lw011&pr=sa&d=2013-07-03 09:23:07&v=15.3.0.11&pid=avg&sg=0&sap=hp

*************************

AdwCleaner[R0].txt - [22242 octets] - [20/08/2014 10:48:02]
AdwCleaner[S0].txt - [20938 octets] - [20/08/2014 10:50:45]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [20999 octets] ##########



A voir également:

5 réponses

Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 628
Modifié par Malekal_morte- le 20/08/2014 à 11:18
Salut,


Réinitialise tes navigateurs:
==================================
Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :
* Internet Explorer et modules complémentaires / moteurs de recherche : https://forum.malekal.com/viewtopic.php?t=41399&start=
* Firefox : https://www.malekal.com/reparer-firefox/?t=36057&start=
* Google Chrome : https://www.malekal.com/reparer-google-chrome/?t=35837&start=


puis :



Faire un Scan OTL - Temps : Environ 40min
=====================
OTL permet de diagnostiquer les programmes qui tournent et déceler des infections - Le programme va générer deux rapports OTL.txt et Extras.txt
Fournir les deux rapports :

Tu peux suivre les indications de cette page pour t'aider : https://www.malekal.com/tutorial-otl/

* Faire un clic droit sur le lien suivant http://www.geekstogo.com/forum/files/file/398-otl-oldtimers-list-it/ puis enregistrer le lien sous.
* En haut à gauche, prendre bureau et enregistrer le fichier.
* Double-cliquez sur OTL
* En haut à droite de Analyse rapide, coche "tous les utilisateurs"
* Sur OTL, sous Personnalisation, copie-colle le script ci-dessous :



netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%ALLUSERSPROFILE%\Application Data\*.dll /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%temp%\*.exe /s
%SYSTEMDRIVE%\*.exe
%systemroot%\*. /mp /s
%systemroot%\system32\consrv.dll
%systemroot%\system32\*.dll /lockedfiles
%windir%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
/md5start
explorer.exe
winlogon.exe
services.exe
wininit.exe
/md5stop
HKEY_CLASSES_ROOT\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32 /s
HKEY_LOCAL_MACHINE\SYSTEM\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters /s
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems /s
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls /s
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList /s
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor /s
HKEY_CURRENT_USER\Software\Microsoft\Command Processor /s
CREATERESTOREPOINT
nslookup www.google.fr /c
ipconfig /all /c
ping www.google.fr /c
SAVEMBR:0
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs



* Clique sur le bouton Analyse.

**** Si durant le scan - OTL ne répond pas, ne touche à rien et laisse le scan se poursuivre ****

* Quand le scan est fini, utilise le site http://pjjoint.malekal.com/ pour envoyer le rapport OTL.txt (et Extra.txt si présent).
Donne le ou les liens pjjoint qui pointent vers ces rapports ici dans une réponse.
Je répète : donne le lien du rapport pjjoint ici en réponse.

NE PAS COPIER/COLLER LE RAPPORT ICI - DONNER LE LIEN PJJOINT DANS UN NOUVEAU MESSAGE





Like the angel you are, you laugh creating a lightness in my chest,
Your eyes they penetrate me,
(Your answer's always 'maybe')
That's when I got up and left
0
Bonsoir,

Désolée de vous déranger j'ai le même que " christianreba " .. J'ai fais tous ce que vous lui avait demandé de faire. Et je vous envois le rapport de OTL . Vous pouvez me donner la marche a suivre maintenant ?

Cordialement

OTL logfile created on: 11/09/2014 21:03:31 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Mélissa\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

3,25 Gb Total Physical Memory | 1,66 Gb Available Physical Memory | 51,21% Memory free
8,08 Gb Paging File | 6,36 Gb Available in Paging File | 78,76% Paging File free
Paging file location(s): c:\pagefile.sys 5000 6000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 71,28 Gb Total Space | 28,17 Gb Free Space | 39,52% Space Free | Partition Type: NTFS
Drive D: | 70,94 Gb Total Space | 49,02 Gb Free Space | 69,10% Space Free | Partition Type: NTFS

Computer Name: FAMILLE_NEVEU | User Name: Mélissa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2014/09/11 21:02:19 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Mélissa\Desktop\OTL.exe
PRC - [2014/09/11 18:00:56 | 000,715,656 | ---- | M] (Cherished Technololgy LIMITED) -- C:\ProgramData\IePluginServices\PluginService.exe
PRC - [2014/09/11 18:00:47 | 000,733,576 | ---- | M] () -- C:\Program Files\SupTab\HpUI.exe
PRC - [2014/09/10 05:32:33 | 000,854,344 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2014/09/09 13:41:46 | 004,823,040 | ---- | M] () -- C:\Windows\score.exe
PRC - [2014/09/02 21:55:28 | 000,487,483 | ---- | M] () -- C:\monitor.exe
PRC - [2014/09/01 20:26:50 | 001,317,096 | ---- | M] (MyOSCompany) -- C:\Program Files\PCTRunner\MyOSProtect.exe
PRC - [2014/08/22 12:44:44 | 000,022,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2014/08/22 12:44:40 | 000,288,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2014/08/22 12:41:00 | 000,974,432 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2014/07/16 11:16:28 | 000,064,000 | ---- | M] () -- C:\Program Files\SupTab\Loader32.exe
PRC - [2013/12/18 20:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/11/15 02:48:30 | 001,861,968 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2013/03/25 21:35:18 | 003,497,240 | ---- | M] (Piriform Ltd) -- C:\Program Files\CCleaner\CCleaner.exe
PRC - [2013/01/03 13:42:57 | 001,259,448 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2013/01/03 10:38:31 | 001,821,624 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
PRC - [2013/01/03 10:38:31 | 000,865,208 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2011/08/05 12:29:56 | 000,159,456 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Zune\ZuneLauncher.exe
PRC - [2009/04/10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/02/28 02:53:25 | 000,594,600 | ---- | M] ( ) -- C:\Windows\System32\lxdxcoms.exe
PRC - [2006/12/08 16:45:32 | 000,045,056 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
PRC - [2006/11/25 02:58:28 | 000,118,870 | ---- | M] () -- C:\Acer\Empowering Technology\eMode\PCM\Kernel\TV\CLSched.exe
PRC - [2006/11/25 02:58:26 | 000,274,520 | ---- | M] () -- C:\Acer\Empowering Technology\eMode\PCM\Kernel\TV\CLCapSvc.exe
PRC - [2006/11/12 22:35:08 | 000,024,576 | ---- | M] () -- C:\Acer\Empowering Technology\ePerformance\MemCheck.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2014/09/11 18:00:59 | 000,023,944 | ---- | M] () -- C:\Program Files\SupTab\WindowsSupportDll32.dll
MOD - [2014/09/11 18:00:47 | 000,733,576 | ---- | M] () -- C:\Program Files\SupTab\HpUI.exe
MOD - [2014/09/10 05:32:31 | 014,891,848 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\38.0.2125.58\PepperFlash\pepflashplayer.dll
MOD - [2014/09/10 05:32:28 | 008,910,664 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\38.0.2125.58\pdf.dll
MOD - [2014/09/10 05:32:19 | 001,681,224 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\38.0.2125.58\ffmpegsumo.dll
MOD - [2014/07/16 11:16:28 | 000,064,000 | ---- | M] () -- C:\Program Files\SupTab\Loader32.exe
MOD - [2014/02/10 13:44:24 | 004,592,128 | ---- | M] () -- C:\Users\Mélissa\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll
MOD - [2014/02/10 13:44:24 | 000,112,128 | ---- | M] () -- C:\Users\Mélissa\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll
MOD - [2013/11/15 02:49:56 | 000,100,688 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2013/11/15 02:48:30 | 001,861,968 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2013/03/26 01:37:52 | 000,053,248 | ---- | M] () -- C:\Program Files\CCleaner\lang\lang-1036.dll
MOD - [2012/11/28 15:13:52 | 000,087,952 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/11/28 15:13:30 | 001,242,512 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV - [2014/09/11 18:00:56 | 000,715,656 | ---- | M] (Cherished Technololgy LIMITED) [Auto | Running] -- C:\ProgramData\IePluginServices\PluginService.exe -- (IePluginServices)
SRV - [2014/09/10 11:16:50 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/09/09 13:41:46 | 004,823,040 | ---- | M] () [Auto | Running] -- C:\Windows\score.exe -- (scores)
SRV - [2014/09/02 21:55:26 | 000,034,244 | ---- | M] () [Auto | Stopped] -- C:\monitorsvc.exe -- (ProtectMonitor)
SRV - [2014/09/01 20:26:50 | 001,317,096 | ---- | M] (MyOSCompany) [On_Demand | Running] -- C:\Program Files\PCTRunner\MyOSProtect.exe -- (MyOSProtect)
SRV - [2014/08/22 12:44:44 | 000,022,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2014/08/22 12:44:40 | 000,288,120 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013/12/18 20:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/02/04 18:43:22 | 000,155,824 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion)
SRV - [2013/01/03 13:42:57 | 001,259,448 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2011/08/05 12:30:02 | 000,444,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc)
SRV - [2011/08/05 12:30:02 | 000,268,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\WMZuneComm.exe -- (WMZuneComm)
SRV - [2011/08/05 12:29:56 | 006,363,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneNss.exe -- (ZuneNetworkSvc)
SRV - [2008/02/28 02:53:25 | 000,594,600 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\lxdxcoms.exe -- (lxdx_device)
SRV - [2008/01/18 23:38:26 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2006/12/08 16:45:32 | 000,045,056 | ---- | M] (Acer Inc.) [Auto | Running] -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe -- (eRecoveryService)
SRV - [2006/11/25 02:58:28 | 000,118,870 | ---- | M] () [Auto | Running] -- C:\Acer\Empowering Technology\eMode\PCM\Kernel\TV\CLSched.exe -- (CLSched)
SRV - [2006/11/25 02:58:26 | 000,274,520 | ---- | M] () [Auto | Running] -- C:\Acer\Empowering Technology\eMode\PCM\Kernel\TV\CLCapSvc.exe -- (CLCapSvc)
SRV - [2006/11/12 22:35:08 | 000,024,576 | ---- | M] () [Auto | Running] -- C:\Acer\Empowering Technology\ePerformance\MemCheck.exe -- (AcerMemUsageCheckService)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\AMD\System Monitor\atillk64.sys -- (atillk64)
DRV - [2014/09/11 20:52:37 | 000,039,464 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D0C90679-4046-4D3F-A133-90B2EE034EC0}\MpKslde060fe0.sys -- (MpKslde060fe0)
DRV - [2014/09/01 20:29:16 | 000,019,840 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\pcwatch.sys -- (pcwatch)
DRV - [2014/08/06 03:20:56 | 000,055,224 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\Windows\System32\drivers\{6fcd6092-9615-4f7f-8898-8df53980e5d2}t.sys -- ({6fcd6092-9615-4f7f-8898-8df53980e5d2}t)
DRV - [2014/07/17 18:05:08 | 000,095,920 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2014/07/04 09:42:56 | 000,055,224 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\Windows\System32\drivers\{6fcd6092-9615-4f7f-8898-8df53980e5d2}Gt.sys -- ({6fcd6092-9615-4f7f-8898-8df53980e5d2}Gt)
DRV - [2013/09/17 22:42:17 | 000,023,456 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DrvAgent32.sys -- (DrvAgent32)
DRV - [2013/01/03 13:42:57 | 010,919,864 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2010/04/09 01:32:36 | 000,215,656 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\nvstor32.sys -- (nvstor32)
DRV - [2009/07/14 01:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (winusb)
DRV - [2008/02/22 16:33:02 | 000,114,304 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2008/02/22 16:33:02 | 000,014,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2008/02/22 16:33:00 | 000,087,936 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdbus.sys -- (sscdbus)
DRV - [2007/05/02 12:11:18 | 000,109,704 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_mdm.sys -- (ss_mdm)
DRV - [2007/05/02 12:11:18 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_mdfl.sys -- (ss_mdfl)
DRV - [2007/05/02 12:11:16 | 000,083,592 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bus.sys -- (ss_bus)
DRV - [2006/12/07 19:12:02 | 000,076,584 | ---- | M] () [Kernel | Auto | Running] -- C:\Acer\Empowering Technology\eRecovery\int15.sys -- (int15)
DRV - [2006/07/24 17:05:00 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1410451139&from=tugs&uid=395049983_397234_D85DBD5E
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds&ts=1410451139&from=tugs&uid=395049983_397234_D85DBD5E&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds&ts=1410451139&from=tugs&uid=395049983_397234_D85DBD5E&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1410451139&from=tugs&uid=395049983_397234_D85DBD5E
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.safefinder.com/...{searchTerms}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_tele_14_37_ch&cd=2XzuyEtN2Y1L1QzutDtDtCzytBtC0EyDyEyEtD0B0B0DyD0EtN0D0Tzu0SzyzzyEtN1L2XzutAtFtBtFyDtFtCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAyDtDtCtB0BtD0EtG0D0FyDzytG0B0DtByBtGtD0C0EtAtGtByE0DtBzytB0ByEtD0A0C0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0Ezz0FtCzyyDzyzztGzytD0B0EtGyEyEyB0FtG0AtBtCzytGtAyCzy0D0FyB0EtB0AyDzytA2Q&cr=583700836&ir=
IE - HKLM\..\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.istartsurf.com/web/?type=ds&ts=1410451139&from=tugs&uid=395049983_397234_D85DBD5E&q={searchTerms}


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1410451139&from=tugs&uid=395049983_397234_D85DBD5E
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.safefinder.com/...{searchTerms}
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SEARCH PAGE = http://feed.safefinder.com/...{searchTerms}
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.safefinder.com/...
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.safefinder.com/...{searchTerms}
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.safefinder.com/...{searchTerms}
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.safefinder.com/...{searchTerms}
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_tele_14_37_ch&cd=2XzuyEtN2Y1L1QzutDtDtCzytBtC0EyDyEyEtD0B0B0DyD0EtN0D0Tzu0SzyzzyEtN1L2XzutAtFtBtFyDtFtCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAyDtDtCtB0BtD0EtG0D0FyDzytG0B0DtByBtGtD0C0EtAtGtByE0DtBzytB0ByEtD0A0C0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0Ezz0FtCzyyDzyzztGzytD0B0EtGyEyEyB0FtG0AtBtCzytGtAyCzy0D0FyB0EtB0AyDzytA2Q&cr=583700836&ir=
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\..\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.istartsurf.com/web/?type=ds&ts=1410451139&from=tugs&uid=395049983_397234_D85DBD5E&q={searchTerms}
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.safefinder.com/...{searchTerms}
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.safefinder.com/...{searchTerms}
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.safefinder.com/...
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1004\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.safefinder.com/...{searchTerms}
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1004\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.safefinder.com/...{searchTerms}
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1004\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKU\S-1-5-21-2510554711-840524539-3490331217-1004\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.safefinder.com/...{searchTerms}

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:25.0.1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Web Player Plug-In,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.67.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

[2013/01/21 16:35:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mélissa\AppData\Roaming\mozilla\Extensions
[2014/09/11 18:02:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mélissa\AppData\Roaming\mozilla\Firefox\Profiles\dyuskqyc.default\extensions
[2014/09/11 18:02:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mélissa\AppData\Roaming\mozilla\Firefox\Profiles\dyuskqyc.default\extensions\***@***

[color=#E56717]========== Chrome ==========[/color]

CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\Mélissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.8_0\
CHR - Extension: No name found = C:\Users\Mélissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: No name found = C:\Users\Mélissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Mélissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: No name found = C:\Users\Mélissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\Mélissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\Mélissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.0_0\
CHR - Extension: No name found = C:\Users\Mélissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.7.13_0\
CHR - Extension: No name found = C:\Users\Mélissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\Mélissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfidkgnoidaeanioaeojmcmemhombjdg\2.0_0\
CHR - Extension: No name found = C:\Users\Mélissa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2006/09/18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Objet d'aide à la navigation SFR) - {0F6E720A-1A6B-40E1-A294-1D4D19F156C8} - C:\Program Files\SFR\Kit\SFRNavErrorHelper.dll (SFR)
O2 - BHO: (IETabPage Class) - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files\SupTab\SupTab.dll (Thinknice Co. Limited)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\System32\eDStoolbar.dll (HiTRUST)
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Windows\System32\eDStoolbar.dll (HiTRUST)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [mbot_fr_81] File not found
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-2510554711-840524539-3490331217-1004..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\gilles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\nicolas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\nicole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O7 - HKU\S-1-5-21-2510554711-840524539-3490331217-1000\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O7 - HKU\S-1-5-21-2510554711-840524539-3490331217-1004\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\MyOSProtect.dll (MyOSCompany)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\MyOSProtect.dll (MyOSCompany)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\MyOSProtect.dll (MyOSCompany)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\MyOSProtect.dll (MyOSCompany)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\System32\MyOSProtect.dll (MyOSCompany)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-2510554711-840524539-3490331217-1004\..Trusted Ranges: OrangeCP ([*] in )
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4A52B207-A4D2-4526-AA2E-0CC8A5CACFB2}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Mélissa\AppData\Roaming\Microsoft\Windows Photo Gallery\Papier peint de la Galerie de photos Windows.jpg
O24 - Desktop BackupWallPaper: C:\Users\Mélissa\AppData\Roaming\Microsoft\Windows Photo Gallery\Papier peint de la Galerie de photos Windows.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - Unable to obtain root file information for disk C:\
O33 - MountPoints2\{d44a62a5-7a48-11da-b66c-001921e5440b}\Shell - "" = AutoRun
O33 - MountPoints2\{d44a62a5-7a48-11da-b66c-001921e5440b}\Shell\AutoRun\command - "" = K:\Startme.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

MsConfig - StartUpReg: [b]Acer Empowering Technology Monitor[/b] - hkey= - key= - File not found
MsConfig - StartUpReg: [b]APSDaemon[/b] - hkey= - key= - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
MsConfig - StartUpReg: [b]ISUSPM Startup[/b] - hkey= - key= - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
MsConfig - StartUpReg: [b]iTunesHelper[/b] - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg: [b]OTB_util[/b] - hkey= - key= - File not found
MsConfig - StartUpReg: [b]RtHDVCpl[/b] - hkey= - key= - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
MsConfig - StartUpReg: [b]TkBellExe[/b] - hkey= - key= - File not found
MsConfig - StartUpReg: [b]Zune Launcher[/b] - hkey= - key= - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
MsConfig - State: "startup" - 2
MsConfig - State: "bootini" - 2

SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MsMpSvc - C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: pcwatch.sys - C:\Windows\System32\drivers\pcwatch.sys ()
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: MsMpSvc - C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SafeBootNet: MyOSProtect - C:\Program Files\PCTRunner\MyOSProtect.exe (MyOSCompany)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: pcwatch.sys - C:\Windows\System32\drivers\pcwatch.sys ()
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4903D172-DCCB-392F-93A3-34CA9D47FE3D} - .NET Framework
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files\Google\Chrome\Application\38.0.2125.58\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Shockwave Flash
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - File not found
Drivers32: msacm.mkdmp3enc - C:\Acer\EMPOWE~1\eMode\PCM\Kernel\Burner\MKDMP3Enc.ACM File not found
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2014/09/11 21:01:51 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Mélissa\Desktop\OTL.exe
[2014/09/11 18:48:42 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014/09/11 18:48:41 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2014/09/11 18:48:40 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2014/09/11 18:48:40 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2014/09/11 18:48:40 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2014/09/11 18:48:38 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2014/09/11 18:48:38 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2014/09/11 18:48:38 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2014/09/11 18:48:35 | 001,810,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2014/09/11 18:48:35 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2014/09/11 18:48:35 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2014/09/11 18:48:32 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2014/09/11 18:17:53 | 000,000,000 | ---D | C] -- C:\Program Files\predm
[2014/09/11 18:16:42 | 000,000,000 | ---D | C] -- C:\Users\Mélissa\AppData\Local\Software
[2014/09/11 18:16:42 | 000,000,000 | ---D | C] -- C:\Program Files\Software
[2014/09/11 18:13:51 | 000,000,000 | ---D | C] -- C:\Program Files\ver5BlockAndSurf
[2014/09/11 18:04:45 | 000,000,000 | ---D | C] -- C:\ProgramData\2308189059
[2014/09/11 18:02:36 | 000,304,776 | ---- | C] (MyOSCompany) -- C:\Windows\System32\MyOSProtect.dll
[2014/09/11 18:01:47 | 001,935,264 | ---- | C] (app) -- C:\Users\Mélissa\AppData\Roaming\HALQAPX.exe
[2014/09/11 18:01:37 | 000,000,000 | ---D | C] -- C:\Users\Mélissa\AppData\Local\globalUpdate
[2014/09/11 18:01:37 | 000,000,000 | ---D | C] -- C:\Program Files\globalUpdate
[2014/09/11 18:01:07 | 000,000,000 | ---D | C] -- C:\ProgramData\IePluginServices
[2014/09/11 18:00:43 | 000,000,000 | ---D | C] -- C:\ProgramData\WindowsMangerProtect
[2014/09/11 18:00:40 | 000,000,000 | ---D | C] -- C:\Program Files\SupTab
[2014/09/11 17:59:52 | 000,000,000 | ---D | C] -- C:\Users\Mélissa\Documents\Optimizer Pro
[2014/09/11 17:59:12 | 000,000,000 | ---D | C] -- C:\Program Files\Optimizer Pro
[2014/09/11 17:58:50 | 000,000,000 | ---D | C] -- C:\Program Files\PCTRunner
[2014/09/11 17:58:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip
[2014/09/11 17:58:24 | 000,000,000 | ---D | C] -- C:\Program Files\Smart Driver Updater
[2014/09/10 14:32:19 | 000,000,000 | ---D | C] -- C:\Users\Mélissa\AppData\Roaming\WSE_Astromenda
[2014/09/10 14:32:18 | 000,000,000 | ---D | C] -- C:\Program Files\WSE_Astromenda
[2014/09/04 17:41:34 | 000,000,000 | ---D | C] -- C:\Users\Mélissa\AppData\Local\Adobe
[2014/08/31 11:02:12 | 002,054,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2014/08/18 15:18:12 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2014/08/16 14:34:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2014/08/16 14:21:58 | 000,099,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\infocardapi.dll
[2014/08/16 14:21:56 | 000,619,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardagt.exe
[2014/08/16 14:21:55 | 000,008,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\icardres.dll
[2014/08/16 14:21:39 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsWpfWrp.exe
[2014/08/15 08:46:24 | 001,993,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\authui.dll
[2014/08/15 08:46:23 | 000,332,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msihnd.dll
[2014/08/15 08:46:23 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\consent.exe
[2014/08/15 08:46:14 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
[2014/08/15 08:46:08 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2014/09/11 21:05:51 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2014/09/11 21:02:19 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Mélissa\Desktop\OTL.exe
[2014/09/11 20:53:36 | 000,000,118 | -H-- | M] () -- C:\Users\Mélissa\Desktop\.~lock.maaf.PDF#
[2014/09/11 20:50:47 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/09/11 20:50:45 | 000,003,792 | ---- | M] () -- C:\Windows\tasks\4b192bb3-1425-4a85-afda-e3f7f36d7008-4.job
[2014/09/11 20:44:00 | 000,001,058 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/09/11 20:17:32 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2014/09/11 20:17:32 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2014/09/11 20:17:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/09/11 20:16:48 | 3489,157,120 | -HS- | M] () -- C:\hiberfil.sys
[2014/09/11 19:16:01 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/09/11 18:24:38 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2014/09/11 18:22:34 | 000,001,973 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/09/11 18:22:27 | 000,002,005 | ---- | M] () -- C:\Users\Mélissa\Application Data\Microsoft\Internet Explorer\Quick Launch\Search.lnk
[2014/09/11 18:22:27 | 000,001,997 | ---- | M] () -- C:\Users\Mélissa\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2014/09/11 18:22:27 | 000,000,947 | ---- | M] () -- C:\Users\Mélissa\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014/09/11 18:20:11 | 000,000,290 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2014/09/11 18:18:21 | 000,722,194 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2014/09/11 18:18:21 | 000,634,258 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/09/11 18:18:21 | 000,146,056 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2014/09/11 18:18:21 | 000,119,824 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014/09/11 18:14:14 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_webinstr_01009.Wdf
[2014/09/11 18:03:44 | 000,009,640 | ---- | M] () -- C:\Windows\System32\MyOSProtect.ini
[2014/09/11 18:03:44 | 000,002,272 | ---- | M] () -- C:\Windows\System32\MyOSProtectOff.ini
[2014/09/11 18:01:48 | 000,001,692 | ---- | M] () -- C:\Windows\tasks\HALQAPX.job
[2014/09/11 18:01:46 | 001,935,264 | ---- | M] (app) -- C:\Users\Mélissa\AppData\Roaming\HALQAPX.exe
[2014/09/10 11:16:49 | 000,701,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2014/09/10 11:16:49 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014/09/09 13:41:46 | 004,823,040 | ---- | M] () -- C:\Windows\score.exe
[2014/09/02 21:55:28 | 000,487,483 | ---- | M] () -- C:\monitor.exe
[2014/09/02 21:55:26 | 000,034,244 | ---- | M] () -- C:\monitorsvc.exe
[2014/09/02 20:16:10 | 000,634,880 | ---- | M] () -- C:\DirectControl.exe
[2014/09/01 20:29:16 | 000,019,840 | ---- | M] () -- C:\Windows\System32\drivers\pcwatch.sys
[2014/09/01 20:28:20 | 000,304,776 | ---- | M] (MyOSCompany) -- C:\Windows\System32\MyOSProtect.dll
[2014/09/01 10:18:44 | 000,001,248 | ---- | M] () -- C:\Users\Mélissa\AppData\Roaming\HALQAPX
[2014/08/31 11:05:33 | 000,260,888 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014/08/23 01:26:28 | 002,054,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2014/08/15 16:42:27 | 001,810,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2014/08/15 16:36:30 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2014/08/15 16:35:46 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2014/08/15 16:35:41 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2014/08/15 16:35:34 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2014/08/15 16:35:21 | 000,607,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2014/08/15 16:35:14 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2014/08/15 16:35:13 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2014/08/15 16:35:07 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2014/08/15 16:34:53 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2014/08/15 16:34:48 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2014/08/15 16:34:47 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2014/09/11 21:05:51 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2014/09/11 20:53:36 | 000,000,118 | -H-- | C] () -- C:\Users\Mélissa\Desktop\.~lock.maaf.PDF#
[2014/09/11 18:14:31 | 000,002,011 | ---- | C] () -- C:\Users\Mélissa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
[2014/09/11 18:14:31 | 000,002,005 | ---- | C] () -- C:\Users\Mélissa\Application Data\Microsoft\Internet Explorer\Quick Launch\Search.lnk
[2014/09/11 18:14:14 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_webinstr_01009.Wdf
[2014/09/11 18:13:51 | 000,000,290 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2014/09/11 18:02:59 | 000,019,840 | ---- | C] () -- C:\Windows\System32\drivers\pcwatch.sys
[2014/09/11 18:02:54 | 000,009,640 | ---- | C] () -- C:\Windows\System32\MyOSProtect.ini
[2014/09/11 18:02:54 | 000,002,272 | ---- | C] () -- C:\Windows\System32\MyOSProtectOff.ini
[2014/09/11 18:02:22 | 000,003,792 | ---- | C] () -- C:\Windows\tasks\4b192bb3-1425-4a85-afda-e3f7f36d7008-4.job
[2014/09/11 18:01:48 | 000,001,692 | ---- | C] () -- C:\Windows\tasks\HALQAPX.job
[2014/09/11 17:58:34 | 004,823,040 | ---- | C] () -- C:\Windows\score.exe
[2014/09/02 21:55:28 | 000,487,483 | ---- | C] () -- C:\monitor.exe
[2014/09/02 21:55:26 | 000,034,244 | ---- | C] () -- C:\monitorsvc.exe
[2014/09/02 20:16:10 | 000,634,880 | ---- | C] () -- C:\DirectControl.exe
[2014/09/01 10:18:44 | 000,001,248 | ---- | C] () -- C:\Users\Mélissa\AppData\Roaming\HALQAPX
[2014/08/16 14:34:49 | 000,001,997 | ---- | C] () -- C:\Users\Mélissa\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2014/08/16 14:34:49 | 000,001,973 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013/12/24 23:44:34 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt
[2013/12/24 23:37:59 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2013/09/17 15:33:17 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2013/09/17 15:31:43 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2013/09/17 15:31:43 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2013/02/07 12:43:27 | 000,360,448 | ---- | C] () -- C:\Windows\System32\lxdxcoin.dll
[2013/02/07 12:42:12 | 000,040,960 | ---- | C] () -- C:\Windows\System32\lxdxvs.dll
[2013/02/07 12:39:53 | 000,782,336 | ---- | C] () -- C:\Windows\System32\lxdxdrs.dll
[2013/02/07 12:39:53 | 000,081,920 | ---- | C] () -- C:\Windows\System32\lxdxcaps.dll
[2013/02/07 12:39:53 | 000,069,632 | ---- | C] () -- C:\Windows\System32\lxdxcnv4.dll
[2013/02/07 12:37:40 | 000,000,044 | ---- | C] () -- C:\Windows\System32\lxdxrwrd.ini
[2013/02/07 12:37:10 | 000,348,160 | ---- | C] () -- C:\Windows\System32\LXDXinst.dll
[2013/02/07 12:37:09 | 000,438,272 | ---- | C] ( ) -- C:\Windows\System32\LXDXhcp.dll
[2013/02/07 12:37:09 | 000,364,544 | ---- | C] ( ) -- C:\Windows\System32\lxdxinpa.dll
[2013/02/07 12:37:09 | 000,339,968 | ---- | C] ( ) -- C:\Windows\System32\lxdxiesc.dll
[2013/02/07 12:37:07 | 001,105,920 | ---- | C] ( ) -- C:\Windows\System32\lxdxserv.dll
[2013/02/07 12:37:07 | 000,843,776 | ---- | C] ( ) -- C:\Windows\System32\lxdxusb1.dll
[2013/02/07 12:37:07 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\lxdxprox.dll
[2013/02/07 12:37:06 | 000,647,168 | ---- | C] ( ) -- C:\Windows\System32\lxdxpmui.dll
[2013/02/07 12:37:06 | 000,569,344 | ---- | C] ( ) -- C:\Windows\System32\lxdxlmpm.dll
[2013/02/07 12:37:04 | 000,320,168 | ---- | C] ( ) -- C:\Windows\System32\lxdxih.exe
[2013/02/07 12:37:03 | 000,663,552 | ---- | C] ( ) -- C:\Windows\System32\lxdxhbn3.dll
[2013/02/07 12:37:03 | 000,208,896 | ---- | C] () -- C:\Windows\System32\lxdxgrd.dll
[2013/02/07 12:37:00 | 000,594,600 | ---- | C] ( ) -- C:\Windows\System32\lxdxcoms.exe
[2013/02/07 12:37:00 | 000,376,832 | ---- | C] ( ) -- C:\Windows\System32\lxdxcomm.dll
[2013/02/07 12:36:59 | 000,851,968 | ---- | C] ( ) -- C:\Windows\System32\lxdxcomc.dll
[2013/02/07 12:36:59 | 000,365,224 | ---- | C] ( ) -- C:\Windows\System32\lxdxcfg.exe
[2013/01/26 20:15:27 | 000,098,304 | ---- | C] () -- C:\Users\Mélissa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/01/21 17:37:23 | 000,032,768 | ---- | C] () -- C:\Windows\System32\LXF3FXPU.DLL
[2013/01/21 17:37:20 | 000,045,056 | ---- | C] () -- C:\Windows\System32\LXF3PMON.DLL
[2013/01/21 17:37:00 | 000,053,248 | ---- | C] () -- C:\Windows\System32\lxf3oem.dll
[2013/01/21 17:37:00 | 000,012,288 | ---- | C] () -- C:\Windows\System32\LXF3PMRC.DLL
[2013/01/21 16:22:13 | 000,000,042 | ---- | C] () -- C:\Windows\Acer(Wide).ini
[2013/01/21 16:22:12 | 000,000,044 | ---- | C] () -- C:\Windows\Acer(Normal).ini
[2013/01/21 16:15:22 | 000,016,384 | ---- | C] () -- C:\Windows\System32\LauncheRyAgentUser.exe
[2013/01/21 16:15:22 | 000,016,384 | ---- | C] ( ) -- C:\Windows\System32\ClearEvent.exe

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2006/11/02 14:51:16 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/03/25 15:26:04 | 011,587,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/10 23:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/10 23:28:26 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[color=#E56717]========== Custom Scans ==========[/color]

[color=#A23BEC]< %ALLUSERSPROFILE%\Application Data\*. >[/color]

[color=#A23BEC]< %ALLUSERSPROFILE%\Application Data\*.exe /s >[/color]

[color=#A23BEC]< %ALLUSERSPROFILE%\Application Data\*.dll /s >[/color]

[color=#A23BEC]< %APPDATA%\*. >[/color]
[2013/02/15 20:04:23 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\Adobe
[2013/03/17 21:14:28 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\Apple Computer
[2014/09/11 20:56:50 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\Azureus
[2013/01/21 17:57:40 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\CyberLink
[2013/11/28 11:25:38 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\DivX
[2013/05/02 15:39:06 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\eTeks
[2013/01/21 19:05:43 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\FaxCtr
[2013/01/21 16:05:38 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\Identities
[2013/10/03 11:38:01 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\Lexmark Productivity Studio
[2013/03/17 18:34:49 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\Macromedia
[2014/09/11 18:30:38 | 000,000,000 | --SD | M] -- C:\Users\Mélissa\AppData\Roaming\Microsoft
[2013/01/21 16:35:25 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\Mozilla
[2013/01/21 19:45:15 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\OpenOffice.org
[2013/02/15 21:01:30 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\OTB_util
[2013/03/08 00:20:51 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\PhotoFiltre
[2013/07/07 11:32:44 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\Real
[2013/12/24 23:58:19 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\Samsung
[2013/01/29 18:36:19 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\SFR
[2013/03/17 18:48:25 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\Skype
[2013/09/17 23:16:38 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\vlc
[2014/09/10 14:32:19 | 000,000,000 | ---D | M] -- C:\Users\Mélissa\AppData\Roaming\WSE_Astromenda

[color=#A23BEC]< %APPDATA%\*.exe /s >[/color]
[2014/09/11 18:01:46 | 001,935,264 | ---- | M] (app) -- C:\Users\Mélissa\AppData\Roaming\HALQAPX.exe
[2013/12/26 16:42:33 | 004,177,856 | ---- | M] () -- C:\Users\Mélissa\AppData\Roaming\Azureus\plugins\azemp\vuzeplayer.exe
[2013/01/21 19:43:56 | 000,310,208 | ---- | M] (Georgia Institute of Technology) -- C:\Users\Mélissa\AppData\Roaming\Azureus\plugins\mlab\ShaperProbeC.exe

[color=#A23BEC]< %temp%\*.exe /s >[/color]
[2014/09/11 17:58:52 | 005,601,864 | ---- | M] () -- C:\Users\MLISSA~1\AppData\Local\Temp\BackupSetup.exe
[2014/09/11 17:58:49 | 005,905,920 | ---- | M] (PC Utilities Software Limited ) -- C:\Users\MLISSA~1\AppData\Local\Temp\optprosetup.exe
[2014/09/11 18:13:35 | 000,408,576 | ---- | M] () -- C:\Users\MLISSA~1\AppData\Local\Temp\post1.exe
[2014/09/11 18:13:36 | 000,098,304 | ---- | M] () -- C:\Users\MLISSA~1\AppData\Local\Temp\post2.exe
[2014/09/11 18:16:36 | 000,620,656 | ---- | M] (The Software Group) -- C:\Users\MLISSA~1\AppData\Local\Temp\setup_326.exe
[2014/09/11 18:16:31 | 000,241,728 | ---- | M] () -- C:\Users\MLISSA~1\AppData\Local\Temp\setup_ra.exe
[43 C:\Users\MLISSA~1\AppData\Local\Temp\*.tmp files -> C:\Users\MLISSA~1\AppData\Local\Temp\*.tmp -> ]
[2011/02/03 11:07:40 | 000,881,128 | ---- | M] (Marvell) -- C:\Users\MLISSA~1\AppData\Local\Temp\~nsu.tmp\Au_.exe
[2014/09/11 17:58:23 | 002,246,832 | ---- | M] (Avanquest ) -- C:\Users\MLISSA~1\AppData\Local\Temp\7A56tmp\driver_updater.exe
[2014/09/11 17:57:56 | 000,073,816 | ---- | M] () -- C:\Users\MLISSA~1\AppData\Local\Temp\7A67tmp\cloud_backup_setup.exe
[2014/09/11 17:58:07 | 000,290,804 | ---- | M] ( ) -- C:\Users\MLISSA~1\AppData\Local\Temp\7A68tmp\vopackage.exe
[2014/09/11 17:58:41 | 006,084,600 | ---- | M] () -- C:\Users\MLISSA~1\AppData\Local\Temp\7A69tmp\optimizerpro.exe
[2014/09/11 17:59:04 | 011,624,368 | ---- | M] () -- C:\Users\MLISSA~1\AppData\Local\Temp\7A6Atmp\setup.exe
[2014/09/11 17:58:27 | 003,765,299 | ---- | M] () -- C:\Users\MLISSA~1\AppData\Local\Temp\7A6Btmp\setup.exe
[2014/09/11 17:58:02 | 000,665,976 | ---- | M] (File Syn) -- C:\Users\MLISSA~1\AppData\Local\Temp\7A6Ctmp\lly_istartsurf.exe
[2014/09/11 17:58:50 | 006,377,433 | ---- | M] () -- C:\Users\MLISSA~1\AppData\Local\Temp\7A7Ctmp\wp-dcollect-tgu.211.exe
[2014/09/11 17:58:38 | 003,324,728 | ---- | M] ( ) -- C:\Users\MLISSA~1\AppData\Local\Temp\7A7Dtmp\mybestofferstoday.exe
[2014/09/11 18:01:33 | 000,072,872 | ---- | M] (globalUpdate) -- C:\Users\MLISSA~1\AppData\Local\Temp\comh.188016\GoogleCrashHandler.exe
[2014/09/11 18:01:33 | 000,068,608 | ---- | M] (globalUpdate) -- C:\Users\MLISSA~1\AppData\Local\Temp\comh.188016\GoogleUpdate.exe
[2014/09/11 18:01:34 | 000,046,080 | ---- | M] (globalUpdate) -- C:\Users\MLISSA~1\AppData\Local\Temp\comh.188016\GoogleUpdateBroker.exe
[2014/09/11 18:01:34 | 000,046,080 | ---- | M] (globalUpdate) -- C:\Users\MLISSA~1\AppData\Local\Temp\comh.188016\GoogleUpdateOnDemand.exe
[2014/09/11 15:43:28 | 000,173,773 | ---- | M] () -- C:\Users\MLISSA~1\AppData\Local\Temp\is45637729\165574_stp\Generic_vo.exe
[2013/09/11 17:55:58 | 000,499,384 | ---- | M] (McAfee, Inc.) -- C:\Users\MLISSA~1\AppData\Local\Temp\MSS\3.8.150.1\McUICnt.exe
[2014/09/11 18:16:21 | 000,123,469 | ---- | M] () -- C:\Users\MLISSA~1\AppData\Local\Temp\nsi77AF.tmp\Mntz_Installer.exe
[2014/09/11 18:15:49 | 000,045,727 | ---- | M] () -- C:\Users\MLISSA~1\AppData\Local\Temp\nsi77AF.tmp\OurChecker.exe

[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >https://pjjoint.malekal.com/files.php?read=20140820_h13u12x8g11f8
0
christianreba
23 août 2014 à 23:28
merci tout semble etre redevenu normal seule la ligne itstartsur uninstall reste dans le panneau de config mais sans influence sur le fonctionnement .
encore merci
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 628
25 août 2014 à 14:01
oui, il faudrait juste que tu supprimes conduit en page de démarrage de Google Chrome
et supprimer l'extension 01net sur Firefox s'il est installé.

~~


Installe Malwarebyte's Anti-Malware : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
Fais des scans réguliers avec, il est efficace.


Pour prévenir les sites malicieux, tu peux installer Blockulicious : https://forum.malekal.com/viewtopic.php?t=46656&start=


Pour ne plus te faire avoir.
A lire - Programmes parasites / PUPs : https://www.malekal.com/adwares-pup-protection/


0
christianreba
27 août 2014 à 15:19
je n'ai pas conduit en page d'ouverture ni d'extensions parasites seule la ligne istartsurf uninstall reste dans le panneau de config, je ne clique pas dessus car je sais que ça ne desinstalle pas istartsurf bien au contraire. cependant merci pour la résolution du problème, je peux vivre avec cette petite ligne parasite dans le panneau.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
christianreba
25 août 2014 à 15:39
merci pour les programmes de protection, mais je n'ai pas compris l'expression dont tu me parles (supprimer conduit au demarrage de chrome ?) que signifie "conduit"
à bientôt
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 628
25 août 2014 à 20:03
Sur Google Chrome, tu dois avoir conduit.com en page de démarrage
si c'est le cas, supprime la.

Voir le paragraphe pour reconfigurer la page : https://www.malekal.com/reparer-google-chrome/?t=35837&start=
0

Newsletters

Newsletters