Impossible d'enlever start qone8

Fermé
gweromemierw - 25 sept. 2013 à 22:45
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 - 29 avril 2014 à 16:02
Bonjour,




bonsoir à tous
je n'arrive as a enlever qone8 de mon ordinateur , j'ai essayer de désinstaller les programmes , je suis aller remettre Google dans propriétés internet , j'ai essayer adwcleaner mais ... ce fichu QONE8 revient chaque fois que je vais sur internet
je n'arrive pas a l'enlever
si vous pouviez m'aider merci ....

9 réponses

Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 628
25 sept. 2013 à 22:46
Salut,

Tu as des adwares sur ton PC.
Passe ces deux programmes dans l'ordre.
Lis bien les instructions, clics sur les liens et lis bien aussi.
Prends ton temps.

Télécharge et installe Malwarebyte : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
Mets le à jour, fais un scan rapide, supprime tout et poste le rapport ici.
!!! Malwarebyte doit être à jour avant de faire le scan !!!
Coche tout ce qui est détecté - puis bouton supprimer sélection pour tout supprimer.

puis :

Télécharge https://www.malekal.com/adwcleaner-supprimer-virus-adwares-pup/?t=33839&start= AdwCleaner ( d'Xplode ) sur ton bureau.
Sur la page d'AdwCleaner, à droite, clic sur la disquette grise avec la flèche verte pour lancer le téléchargement.
Lance AdwCleaner, clique sur [Scanner].
Le scan peux durer plusieurs minutes, patienter.
Une fois le scan terminé, clique sur [Nettoyer]

Une fois le nettoyage terminéi, un rapport s'ouvrira. Copie/colle le contenu du rapport dans ta prochaine réponse par un copier/coller.
Si cela ne fonctionne pas, utilise le site http://pjjoint.malekal.com pour héberger le rapport, donne le lien du rapport dans un nouveau message.

Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt



0
gweromemierw
25 sept. 2013 à 23:08
merci
voila pour le premier lien
Malwarebytes Anti-Malware (Essai) 1.75.0.1300
www.malwarebytes.org

Version de la base de données: v2013.09.25.07

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16686
Laniesse :: TOSHIBA-M01 [administrateur]

Protection: Activé

25/09/2013 22:56:47
mbam-log-2013-09-25 (22-56-47).txt

Type d'examen: Examen rapide
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d'examen désactivées: P2P
Elément(s) analysé(s): 185360
Temps écoulé: 9 minute(s), 44 seconde(s)

Processus mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Clé(s) du Registre détectée(s): 1
HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} (PUP.Optional.OptimzerPro.A) -> Mis en quarantaine et supprimé avec succès.

Valeur(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)

Elément(s) de données du Registre détecté(s): 0
(Aucun élément nuisible détecté)

Dossier(s) détecté(s): 1
C:\Users\Laniesse\Documents\Optimizer Pro (PUP.Optional.OptimizerPro.A) -> Mis en quarantaine et supprimé avec succès.

Fichier(s) détecté(s): 12
C:\Users\Laniesse\AppData\Local\Temp\Optimizer_Pro.exe (PUP.Optional.1ClickDownload.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\Laniesse\AppData\Local\Temp\eIntaller\1D67C69EF54B433b95857637AD45D5BB\eGdpSvc.exe (PUP.Optional.DProtect.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\Laniesse\AppData\Local\Temp\eIntaller\1D67C69EF54B433b95857637AD45D5BB\eXQ.exe (PUP.Optional.DProtect.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\Laniesse\AppData\Local\Temp\openoffice.exe\6e81bfa0b8e84edfaeb0c8588b17dabf\installer.exe (PUP.Optional.BundleInstaller.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\Laniesse\AppData\Local\Temp\openoffice.exe\6e81bfa0b8e84edfaeb0c8588b17dabf\openoffice.exe (PUP.Optional.BundleInstaller.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\Laniesse\AppData\Local\Temp\openoffice.exe\6e81bfa0b8e84edfaeb0c8588b17dabf\software\OptimizerPro.exe (PUP.Optional.OptimizePro.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\Laniesse\AppData\Local\Temp\openoffice.exe\6e81bfa0b8e84edfaeb0c8588b17dabf\software\Qone8.exe (PUP.Optional.Elex) -> Mis en quarantaine et supprimé avec succès.
C:\Users\Laniesse\AppData\Local\Temp\openoffice.exe\6e81bfa0b8e84edfaeb0c8588b17dabf\software\Superlyrics.exe (PUP.Optional.Adtool) -> Mis en quarantaine et supprimé avec succès.
C:\Users\Laniesse\Local Settings\Temporary Internet Files\Content.IE5\R1BNIEIB\AdwCleaner.exe (PUP.Optional.Firseria) -> Mis en quarantaine et supprimé avec succès.
C:\Users\Laniesse\Local Settings\Temporary Internet Files\Content.IE5\R1BNIEIB\openoffice.exe (PUP.Optional.BundleInstaller.A) -> Mis en quarantaine et supprimé avec succès.
C:\Users\Laniesse\Documents\Optimizer Pro\CookiesException.txt (PUP.Optional.OptimizerPro.A) -> Mis en quarantaine et supprimé avec succès.
C:\User Data\Default\Extensions\newtab.crx (PUP.Optional.Elex.A) -> Mis en quarantaine et supprimé avec succès.

(fin)
0
gweromemierw
25 sept. 2013 à 23:17
voila pour le deuxieme lien j'ai tout fait comme vous me disiez , l'ordi a redemarrer mais qone8 est toujours la :-(

# AdwCleaner v3.005 - Rapport créé le 25/09/2013 à 23:12:56
# Mis à jour le 22/09/2013 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (32 bits)
# Nom d'utilisateur : Laniesse - TOSHIBA-M01
# Exécuté depuis : C:\Users\Laniesse\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MD0JNM4J\adwcleaner.exe
# Option : Nettoyer

***** [ Services ] *****


***** [ Fichiers / Dossiers ] *****

Dossier Supprimé : C:\ProgramData\eSafe
Dossier Supprimé : C:\Users\Laniesse\AppData\Local\lollipop
Dossier Supprimé : C:\Users\Laniesse\AppData\Local\Temp\eIntaller
Dossier Supprimé : C:\Users\Laniesse\AppData\Roaming\pdfforge

***** [ Raccourcis ] *****


***** [ Registre ] *****


***** [ Navigateurs ] *****

-\\ Internet Explorer v10.0.9200.16686


*************************

AdwCleaner[R0].txt - [1672 octets] - [25/09/2013 21:58:11]
AdwCleaner[R1].txt - [1091 octets] - [25/09/2013 23:12:06]
AdwCleaner[S0].txt - [1756 octets] - [25/09/2013 21:59:40]
AdwCleaner[S1].txt - [1025 octets] - [25/09/2013 23:12:56]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1085 octets] ##########
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 628
25 sept. 2013 à 23:23
Sur ton raccourci de lancement de ton navigateur que tu utilises pour lancer :

Clic droit, dans cible, à la fin, y a une adresse http ?

~~


Faire un scan OTL pour diagnostiquer les programmes qui tournent et déceler des infections - Le programme va générer deux rapports OTL.txt et Extras.txt
Fournir les deux rapports :

Tu peux suivre les indications de cette page pour t'aider : https://www.malekal.com/tutorial-otl/

* Télécharge http://www.geekstogo.com/forum/files/file/398-otl-oldtimers-list-it/ sur ton bureau.
(Sous Vista/Win7, il faut cliquer droit sur OTL et choisir Exécuter en tant qu'administrateur)

Dans le cas d'Avast!, ne pas lancer le programme dans la Sandbox (voir lien d'aide ci-dessus).

* Lance OTL
* En haut à droite de Analyse rapide, coche "tous les utilisateurs"
* Sur OTL, sous Personnalisation, copie-colle le script ci-dessous :



netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%temp%\*.exe /s
%SYSTEMDRIVE%\*.exe
%systemroot%\*. /mp /s
%systemroot%\system32\consrv.dll
%systemroot%\system32\*.dll /lockedfiles
%windir%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
/md5start
explorer.exe
winlogon.exe
services.exe
wininit.exe
/md5stop
HKEY_CLASSES_ROOT\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32 /s
HKEY_LOCAL_MACHINE\SYSTEM\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters /s
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems /s
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls /s
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList /s
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor /s
HKEY_CURRENT_USER\Software\Microsoft\Command Processor /s
CREATERESTOREPOINT
nslookup https://www.google.fr/?gws_rd=ssl /c
SAVEMBR:0
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs



* Clique sur le bouton Analyse.

* Quand le scan est fini, utilise le site http://pjjoint.malekal.com/ pour envoyer le rapport OTL.txt (et Extra.txt si présent).
Donne le ou les liens pjjoint qui pointent vers ces rapports ici dans une réponse.
Je répète : donne le lien du rapport pjjoint ici en réponse.

NE PAS COPIER/COLLER LE RAPPORT ICI - DONNER LE LIEN PJJOINT DANS UN NOUVEAU MESSAGE
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
gweromemierw
25 sept. 2013 à 23:25
oui il y a http mais c tres long et ca commence par "C:
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 628
25 sept. 2013 à 23:31
0
J'ai une question (peut-être stupide, désolée). Quel est le but de copier le rapport sur le forum ?
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 628
29 avril 2014 à 08:50
pour le lire et voir ce qui est présent, et virer les restes.
0
Merci pour la réponse :)

Ayant le même problème avec qone8, j'ai suivi la procédure ci-dessus.
Je poste donc mon rapport de scan, si quelqu'un peut le déchiffrer... pour moi c'est du martien !

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 29/04/2014
Scan Time: 07:49:01
Logfile: rapport malwarebytes.txt
Administrator: Yes

Version: 2.00.1.1004
Malware Database: v2014.04.29.01
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled

OS: Windows Vista Service Pack 2
CPU: x86
File System: NTFS
User: Lalou

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 226421
Time Elapsed: 21 min, 36 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled

Processes: 3
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, 1936, , [f223fb350e6dc175a71f480ade23fb05]
Trojan.Agent.SVR, C:\Program Files\003\nuttkoqiez32.exe, 3092, , [3bdac26e56250c2a70922a3fb44d827e]
PUP.Optional.AdPeak.A, C:\Program Files\003\nuttkoqiez32.exe, 3092, , [1203f739621940f6d0ddfc774ab8db25]

Modules: 1
PUP.Optional.SupTab.A, C:\Program Files\SupTab\DpInterface32.dll, , [b2633df3285350e6580e1c68b34fe21e],

Registry Keys: 24
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginService, , [f223fb350e6dc175a71f480ade23fb05],
Trojan.Agent.SVR, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\nuttkoqiez32, , [3bdac26e56250c2a70922a3fb44d827e],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [f223ec44a1dab284da7380b5817fc739],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, , [f223ec44a1dab284da7380b5817fc739],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, , [f223ec44a1dab284da7380b5817fc739],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [f223ec44a1dab284da7380b5817fc739],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [f223ec44a1dab284da7380b5817fc739],
PUP.Optional.SupTab.A, HKU\S-1-5-21-891053039-1990247307-3841707916-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [f223ec44a1dab284da7380b5817fc739],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [f223ec44a1dab284da7380b5817fc739],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [f223ec44a1dab284da7380b5817fc739],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\INPROCSERVER32, , [f223ec44a1dab284da7380b5817fc739],
PUP.Optional.AdPeak.A, HKU\S-1-5-21-891053039-1990247307-3841707916-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{10AD2C61-0898-4348-8600-14A342F22AC3}, , [b65f042c354649ed40d3b6655fa344bc],
PUP.Optional.AdPeak.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{10AD2C61-0898-4348-8600-14A342F22AC3}, , [b65f042c354649ed40d3b6655fa344bc],
PUP.Optional.Qone8.A, HKLM\SOFTWARE\qone8Software, , [f61f3bf5de9d46f0d9762a7e4bb8ea16],
PUP.Optional.SupraSavings.A, HKLM\SOFTWARE\suprasavings, , [50c5a789116a221451c5d9a0db277f81],
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pelmeidfhdlhlbjimpabfcbnnojbboma, , [a5701b155b20b284194fd1aaea188c74],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [20f5260a5f1c989ec7dd8920bb48fa06],
PUP.Optional.AdPeak.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\nuttkoqiez32, , [1203f739621940f6d0ddfc774ab8db25],
PUP.Optional.TornTV.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Torntv V9.0, , [a471bf71b3c8e65064ac6f13768c14ec],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-891053039-1990247307-3841707916-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, , [ab6a151b2a51fd398da5aaf5d52e05fb],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-891053039-1990247307-3841707916-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, , [b85d6ec2176475c13f2d981a11f24bb5],
PUP.Optional.SupraSavings.A, HKU\S-1-5-21-891053039-1990247307-3841707916-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Supra Savings, , [4cc9b7791962b482c73af781ac56966a],
PUP.Optional.Qone8, HKU\S-1-5-21-891053039-1990247307-3841707916-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [d93cd45c7407072f673c872256ad53ad],
PUP.Optional.BubbleDock.A, HKU\S-1-5-21-891053039-1990247307-3841707916-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\NOSIBAY\Bubble Dock Tag, , [53c2ac847efd43f37cea65244eb4d030],

Registry Values: 1
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|***@***, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***, , [23f242eeee8d5ed8c0a9b3c881817a86]

Registry Data: 6
PUP.Optional.Qone8, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Mozilla Firefox\firefox.exe http://start.qone8.com/?type=sc&ts=1398714290&from=ild&uid=HitachiXHTS541616J9SA00_SB2441SJE0BKJEE0BKJEX, Good: (firefox.exe), Bad: (C:\Program Files\Mozilla Firefox\firefox.exe http://start.qone8.com/?type=sc&ts=1398714290&from=ild&uid=HitachiXHTS541616J9SA00_SB2441SJE0BKJEE0BKJEX),,[8f8661cf1566a98d452356dd848051af]
PUP.Optional.Qone8, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1398714290&from=ild&uid=HitachiXHTS541616J9SA00_SB2441SJE0BKJEE0BKJEX, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1398714290&from=ild&uid=HitachiXHTS541616J9SA00_SB2441SJE0BKJEE0BKJEX),,[f61f29070774261083e6a291f80ced13]
Hijack.StartPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://start.qone8.com/?type=hp&ts=1398714290&from=ild&uid=HitachiXHTS541616J9SA00_SB2441SJE0BKJEE0BKJEX, Good: (http://www.google.com), Bad: (http://start.qone8.com/?type=hp&ts=1398714290&from=ild&uid=HitachiXHTS541616J9SA00_SB2441SJE0BKJEE0BKJEX),,[070e47e9b9c2092d676640e9dd27a15f]
Hijack.StartPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://start.qone8.com/?type=hp&ts=1398714290&from=ild&uid=HitachiXHTS541616J9SA00_SB2441SJE0BKJEE0BKJEX, Good: (http://www.google.com), Bad: (http://start.qone8.com/?type=hp&ts=1398714290&from=ild&uid=HitachiXHTS541616J9SA00_SB2441SJE0BKJEE0BKJEX),,[e035c26ed2a94aecf4dbcb5e18ec7987]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[1df8f0408bf0de583c2e979c82825ca4]
Hijack.StartPage, HKU\S-1-5-21-891053039-1990247307-3841707916-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://start.qone8.com/?type=hp&ts=1398714290&from=ild&uid=HitachiXHTS541616J9SA00_SB2441SJE0BKJEE0BKJEX, Good: (http://www.google.com), Bad: (http://start.qone8.com/?type=hp&ts=1398714290&from=ild&uid=HitachiXHTS541616J9SA00_SB2441SJE0BKJEE0BKJEX),,[b362cd63ea912a0c0cc4a683907418e8]

Folders: 64
PUP.Optional.SupTab.A, C:\Program Files\SupTab, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\weather, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\en-US, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\es-419, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\es-ES, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-BE, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-CA, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-CH, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-FR, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-LU, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\it-CH, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\it-IT, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pl, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pt, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pt-BR, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\ru, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\ru-MO, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\tr-TR, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\vi-VI, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\zh-CN, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\zh-TW, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService, , [0a0b2d033744eb4b8fe2283f9a6849b7],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update, , [0a0b2d033744eb4b8fe2283f9a6849b7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\include, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\include\tools, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\en, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\en-US, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\es, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\es-419, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\fr, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\fr-BE, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\fr-CA, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\fr-CH, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\fr-LU, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\it, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\it-CH, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\pl, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\pt-BR, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\ru, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\ru-MO, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\tr, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\vi, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\zh-CN, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\zh-TW, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\skin, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\skin\weather, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\defaults, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\defaults\preferences, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\modules, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.PriceMeter.A, C:\Users\Lalou\AppData\Roaming\PriceMeterUpdater, , [e82d79b7196266d0f0df4e1d6a980bf5],
PUP.Optional.PriceMeter.A, C:\Users\Lalou\AppData\Roaming\PriceMeterUpdater\UpdateProc, , [e82d79b7196266d0f0df4e1d6a980bf5],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\CrashReports, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0, , [74a186aa285360d6dff1ef7cda28cf31],

Files: 200
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, , [f223fb350e6dc175a71f480ade23fb05],
Trojan.Agent.SVR, C:\Program Files\003\nuttkoqiez32.exe, , [3bdac26e56250c2a70922a3fb44d827e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\SupTab.dll, , [f223ec44a1dab284da7380b5817fc739],
PUP.Optional.SupTab.A, C:\Users\Lalou\AppData\Roaming\SupTab\SupTab.dll, , [68ada48c2358d95d4d0060d52fd14cb4],
PUP.Optional.AdPeak.A, C:\Temp\InstallFilter32.msi, , [a17470c0ff7c3bfb9bdbe6570ef29d63],
PUP.Optional.SupraSavings.A, C:\Temp\t.msi, , [93821d13562573c3919b58ce7d87946c],
Adware.Hotbar, C:\Temp\xvid-win32.exe, , [44d10030f784082e28f39af3b749b24e],
PUP.Optional.BubbleDock.A, C:\Users\Lalou\AppData\Local\Temp\2842014223142\Uninstall Bubble Dock.exe, , [888d161af38886b0816a9c9aa8597789],
PUP.Optional.SkyTech.A, C:\Users\Lalou\AppData\Local\Temp\fullpackage_temp1398714240\alilog.dll, , [8a8bda56e89377bf68ad2c0652ae817f],
PUP.Optional.IePluginService.A, C:\Users\Lalou\AppData\Local\Temp\fullpackage_temp1398714240\tmp\SupTab.exe, , [60b5042c67146acc586ed1814ab7c53b],
PUP.Optional.WpManager, C:\Users\Lalou\AppData\Local\Temp\fullpackage_temp1398714240\tmp\wpm.exe, , [819471bfb9c2bc7a45d58ecf4db434cc],
PUP.Optional.OneClickDownloader.A, C:\Users\Lalou\Downloads\Game_of_Thrones_S03E08_HDTV_x264-EVOLVE(ettv).exe, , [da3baf81f18a63d30264fe1042bf857b],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx, , [c550e947740774c20b7757226e9441bf],
PUP.Optional.PriceMeter.A, C:\Windows\Tasks\PriceMeterUpdater.job, , [5abba58bcdaea98d69cd780233cf5da3],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\install.data, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\DpInterface32.dll, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\DpInterface64.dll, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\DpInterfacef32.dll, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\ient.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\RSHP.exe, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\SearchProtect32.dll, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\SearchProtect64.dll, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\SpAPPSv32.dll, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\SpAPPSv64.dll, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\uninstall.exe, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\WebDataJs, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\data.html, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\indexIE.html, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\indexIE8.html, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\main.css, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\ver.txt, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\arrow.png, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\default_add_logo.png, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\default_add_logo_hover.png, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\default_logo.png, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\googlelogo.png, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\googlelogo2.png, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\google_trends.png, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\icon128.png, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\icon16.png, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\icon48.png, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\loading.gif, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\logo32.ico, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\weather\0.png, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\common.js, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\ga.js, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\ie8.js, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\jquery-1.11.0.min.js, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\jquery.autocomplete.js, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\js.js, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\library.js, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\xagainit.js, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\en-US\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\es-419\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\es-ES\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-BE\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-CA\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-CH\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-FR\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-LU\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\it-CH\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\it-IT\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pl\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pt\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pt-BR\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\ru\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\ru-MO\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\tr-TR\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\vi-VI\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\zh-CN\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\zh-TW\messages.json, , [b2633df3285350e6580e1c68b34fe21e],
PUP.Optional.Bubbledock.A, C:\Users\Lalou\AppData\Roaming\Bubble Dock.boostrap.log, , [33e250e03e3d013565b3a5e2f210cd33],
PUP.Optional.Qone8, C:\Program Files\Mozilla Firefox\searchplugins\qone8.xml, , [1df8c16f463561d5455d1990e61d40c0],
PUP.Optional.AdPeak.A, C:\Program Files\003\nuttkoqiez32.exe, , [1203f739621940f6d0ddfc774ab8db25],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update\conf, , [0a0b2d033744eb4b8fe2283f9a6849b7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome.manifest, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\install.rdf, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\index.html, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\quick_start.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\quick_start.xul, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\include\speed_dial.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\include\tools\about_blank_hook.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\include\tools\misc.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\include\tools\popup_image_helper.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\include\tools\urlrequestor.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\js\common.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\js\doT.min.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\js\ga.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\js\jquery-2.1.0.min.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\js\jquery.autocomplete.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\js\js.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\content\js\xagainit.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\en\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\en-US\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\es\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\es-419\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\fr\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\fr-BE\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\fr-CA\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\fr-CH\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\fr-LU\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\it\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\it-CH\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\pl\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\pt-BR\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\ru\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\ru-MO\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\tr\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\vi\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\zh-CN\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\locale\zh-TW\locale.properties, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\skin\arrow.png, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\skin\default_add_logo.png, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\skin\default_add_logo_hover.png, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\skin\default_logo.png, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\skin\googlelogo.png, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\skin\googlelogo2.png, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\skin\google_trends.png, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\skin\icon.png, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\skin\loading.gif, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\skin\logo.ico, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\skin\logo.png, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\skin\logo32.ico, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\skin\style.css, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\chrome\skin\weather\0.png, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\defaults\preferences\fvd.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\modules\addonmanager.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\modules\aes.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\modules\config.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\modules\dialogs.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\modules\last_tab.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\modules\misc.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\modules\properties.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\modules\remoterequest.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\modules\restoreprefs.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.QuickStart.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\extensions\***@***\modules\settings.js, , [789dff3133483006ae9485e6649e19e7],
PUP.Optional.PriceMeter.A, C:\Users\Lalou\AppData\Roaming\PriceMeterUpdater\UpdateProc\config.dat, , [e82d79b7196266d0f0df4e1d6a980bf5],
PUP.Optional.PriceMeter.A, C:\Users\Lalou\AppData\Roaming\PriceMeterUpdater\UpdateProc\info.dat, , [e82d79b7196266d0f0df4e1d6a980bf5],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_de.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_el.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_en-GB.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_en.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_es-419.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_es.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_et.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_fa.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_fi.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_fil.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_fr.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_gu.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_hi.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_hr.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_hu.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_id.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_it.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_iw.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ja.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_kn.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ko.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_lt.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_lv.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ml.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_mr.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ms.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_nl.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_no.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_pl.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_pt-BR.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_pt-PT.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ro.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdate.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_am.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ar.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_bg.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_bn.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ca.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_cs.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sk.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sl.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sr.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sv.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sw.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ta.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_te.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_th.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_tr.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_uk.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ur.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_vi.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_zh-CN.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_zh-TW.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdate.exe, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdateHandler.exe, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdateHelper.msi, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\psmachine.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\psuser.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_da.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_is.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.PriceMeter.A, C:\Program Files\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ru.dll, , [74a186aa285360d6dff1ef7cda28cf31],
PUP.Optional.Qone8.A, C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\prefs.js, Good: (), Bad: (user_pref("browser.newtab.url", "http://start.qone8.com/newtab/?type=nt&ts=1398714290&from=ild&uid=HitachiXHTS541616J9SA00_SB2441SJE0BKJEE0BKJEX");), ,[a1740d230d6e2115f68c9dc109fb53ad]

Physical Sectors: 0
(No malicious items detected)


(end)


AdwCleaner est en cours.
0
Et voici le rapport de scan après avoir utilisé AdwCleaner (je ne sais pas si tout est ok, mais qone8 n'est plus là, alors déjà, merci pour ça !!)

# AdwCleaner v3.205 - Rapport créé le 29/04/2014 à 15:25:39
# Mis à jour le 28/04/2014 par Xplode
# Système d'exploitation : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Nom d'utilisateur : Lalou - PC-DE-LALWETTE
# Exécuté depuis : C:\Users\Lalou\Downloads\AdwCleaner.exe
# Option : Nettoyer

***** [ Services ] *****


***** [ Fichiers / Dossiers ] *****

Dossier Supprimé : C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\Extensions\***@***
Fichier Supprimé : C:\Program Files\Mozilla Firefox\.autoreg
Fichier Supprimé : C:\Windows\System32\Tasks\pricemeterdownloader
Fichier Supprimé : C:\Windows\System32\Tasks\PriceMeterUpdater

***** [ Raccourcis ] *****

Raccourci Désinfecté : C:\Users\Public\Desktop\Google Chrome.lnk
Raccourci Désinfecté : C:\Users\Public\Desktop\Mozilla Firefox.lnk
Raccourci Désinfecté : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox\Mozilla Firefox (Mode sans échec).lnk
Raccourci Désinfecté : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox\Mozilla Firefox.lnk
Raccourci Désinfecté : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Raccourci Désinfecté : C:\Users\Lalou\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Raccourci Désinfecté : C:\Users\Lalou\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Raccourci Désinfecté : C:\Users\Lalou\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Raccourci Désinfecté : C:\Users\Lalou\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Raccourci Désinfecté : C:\Users\Lalou\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk

***** [ Registre ] *****

[#] Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6440BA5A-EE36-420E-893A-E04D5B5C231B}
[#] Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6440BA5A-EE36-420E-893A-E04D5B5C231B}
[#] Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B903D08F-B81B-43BF-B505-0DD4D4B59394}
[#] Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B903D08F-B81B-43BF-B505-0DD4D4B59394}
Valeur Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [PriceMeterW]
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\NCTAudioCompress3.DLL
Clé Supprimée : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
Clé Supprimée : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{F54A0D21-6A53-460C-8301-C694EC9E1033}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{03F14321-8FED-4CBC-B01A-4B57FC199062}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{4C58EB04-7B72-4D3D-A36E-66167A99BC31}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{84B9B044-17C0-48FB-A300-C9747D5DF29C}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{9DBB28C1-1925-11D3-A498-00104B6EB52E}
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Valeur Supprimée : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{08C06D61-F1F3-4799-86F8-BE1A89362C85}]
Clé Supprimée : HKCU\Software\Nosibay
Clé Supprimée : HKCU\Software\YahooPartnerToolbar
Clé Supprimée : HKLM\Software\GamesBarSetup
Clé Supprimée : HKLM\Software\LevelQualityWatcher
Clé Supprimée : HKLM\Software\MetaStream
Clé Supprimée : HKLM\Software\supTab
Clé Supprimée : HKLM\Software\supWPM
Clé Supprimée : HKLM\Software\Viewpoint
Clé Supprimée : HKLM\Software\Wpm
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ViewpointMediaPlayer
Clé Supprimée : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\464AA55239C100F32AF2D438EDDC0F47
Clé Supprimée : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5652BA3D5FB98AE31B337BF0AF939856
Clé Supprimée : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EB95E1AFCBABE3DB9ECCC669B99494

***** [ Navigateurs ] *****

-\\ Internet Explorer v9.0.8112.16545

Paramètre Restauré : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Paramètre Restauré : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Mozilla Firefox v3.6.27 (fr)

[ Fichier : C:\Users\Lalou\AppData\Roaming\Mozilla\Firefox\Profiles\xbwosq1s.default\prefs.js ]

Ligne Supprimée : user_pref("browser.search.defaultenginename", "qone8");
Ligne Supprimée : user_pref("browser.search.selectedEngine", "qone8");

-\\ Google Chrome v34.0.1847.116

[ Fichier : C:\Users\Lalou\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Supprimée [Search Provider] : hxxp://www.maisonsdumonde.com/v2/FR/fr/search/?searchQuery={searchTerms}&search_category=0¤tPage=0&rawQuery=true
Supprimée [Search Provider] : hxxp://www.vidohe.com/video-search-results.php?q={searchTerms}&cx=005536796155304041479%3Ahbixpuuu7l8&cof=FORID%3A11&from=os-family
Supprimée [Extension] : pelmeidfhdlhlbjimpabfcbnnojbboma

*************************

AdwCleaner[R0].txt - [7667 octets] - [29/04/2014 13:48:58]
AdwCleaner[R1].txt - [7533 octets] - [29/04/2014 14:13:23]
AdwCleaner[R2].txt - [7652 octets] - [29/04/2014 14:30:31]
AdwCleaner[R3].txt - [7771 octets] - [29/04/2014 14:36:32]
AdwCleaner[R4].txt - [7890 octets] - [29/04/2014 14:53:38]
AdwCleaner[R5].txt - [8009 octets] - [29/04/2014 15:14:20]
AdwCleaner[S0].txt - [956 octets] - [29/04/2014 14:02:49]
AdwCleaner[S1].txt - [383 octets] - [29/04/2014 14:16:56]
AdwCleaner[S2].txt - [383 octets] - [29/04/2014 14:35:49]
AdwCleaner[S3].txt - [383 octets] - [29/04/2014 14:42:46]
AdwCleaner[S4].txt - [383 octets] - [29/04/2014 14:56:58]
AdwCleaner[S5].txt - [6688 octets] - [29/04/2014 15:25:39]

########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [6748 octets] ##########
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 628
29 avril 2014 à 16:02
Réinitialise :
* Firefox : https://www.malekal.com/reparer-firefox/?t=36057&start=
* Google Chrome : https://www.malekal.com/reparer-google-chrome/?t=35837&start=


Regarde si tu as encore des pubs etc.
0