Comment se débarasser de Start.qone8

Résolu/Fermé
Romuxl Messages postés 3 Date d'inscription samedi 19 octobre 2013 Statut Membre Dernière intervention 19 octobre 2013 - Modifié par Jeff le 8/11/2013 à 16:39
 nucetta - 6 juin 2014 à 11:22
Bonjour,

Je n'arrive pas a me dépêtrer de ce satané virus qone8 , j'ai essayé spyhunter , spybot, awcleaner etc..
Rien n'y fait , quand j'ouvrer ie j'ai toujours cette page qui s"ouvre .
J'ai tout tenté mais je n'y arrive pas ..

HELP!!!HELP!!!

J'ai fait un rapport sous zhpdiag , vous pouvez le trouvez à l'adresse :
http://cjoint.com/data/0JtqM6VA8hb.htm

Si une charitable arrivé à me sortir de cette impasse je lui serai éternellement reconnaissant.

Merci par avance de toute l'aide que vous pourrez m'apporter.

Merci.

10 réponses

Utilisateur anonyme
19 oct. 2013 à 17:08
Bonjour

Reparamètres tes navigateurs WEB (page de démarrage, moteur de recherche, etc...) mais aussi supprimer/désactiver les extensions inutiles/parasites :
* Internet Explorer et modules complémentaires / moteurs de recherche : https://forum.malekal.com/viewtopic.php?t=41399&start=

* Firefox : https://www.malekal.com/reparer-firefox/?t=36057&start=

* Google Chrome : https://www.malekal.com/reparer-google-chrome/?t=35837&start=


Attention - il faut nettoyer les raccourcis (icones) de lancement des navigateurs WEB.
Faire un clic droit sur les icones de raccourcis de lancement des navigateurs puis propriétés.
Dans cible, à la fin, une adresse http a été ajoutée (exemple https://www.malekal.com/fichiers/forum/malavida_22find_7.png ) pour que le site s'ouvre au démarrage du navigateur, supprimer cette adresse http ET SEULEMENT cette adresse http.


puis :

Sur Firefox : Menu Outils / Modules complémentaires
Onglet Extension.
Donne la liste.

Sur Google Chrome : Menu en haut à droite puis Outils / Extensions
Donne la liste.

@+
22
Genial ça fonctionne!
Merci
0
Le coup du raccourcis infecté sa m' a laissé sur le postérieur.
0
Pour les gens qui ne s'y connaissent pas en informatique o pourrait traduire les marchés à suivre s'il vous plait ? ^^
0
ça explique qu'il faut désinstaller manuellement mais rien n'apparaît sous le nom de Qone8 ni dans mes extensions google chrome ni dans "Ajouter / Supprimer des programmes" de mon WinXP

J'utilise un cleaner à ce moment là ? ça ne peut pas marcher en supprimant juste mon google chrome + réinstallation ? Mon ordinateur est inutilisable depuis plus d'une semaine à cause de sa lenteur =/

Merci !
0
Merci beaucoup! C'était finalement très simple de supprimer ce qone8.
Je suis ravie de retrouver ma page d'accueil :o))
0
Romuxl Messages postés 3 Date d'inscription samedi 19 octobre 2013 Statut Membre Dernière intervention 19 octobre 2013 2
19 oct. 2013 à 17:18
En reconfigurant mon IE et les raccourcis chrome et IE.

Ca marche , je ne suis plus embeté !!!

merci a toi.
2
bonjour je ne trouve pas regedit sous Windows
0
Utilisateur anonyme
19 oct. 2013 à 17:21
Re

On finalise.
Télécharge DelFix de Xplode

Lance le.
Tu as 5 choix :

Réactiver l'UAC
Supprimer les outils de désinfection (cocher par défaut)

Effectuer une sauvegarde du registre
Purger la restauration de système
Réinitialisation des paramètres usine

Tu coches ceux qui sont en gras
et tu exécutes
Le rapport se trouve ici généralement
C:\DelFix.txt



Le reste de la sécurité : http://forum.malekal.com/comment-securiser-son-ordinateur.html

Mets à jour tes programmes:
Pour vérifier les mises à jour logiciels à appliquer sur ton PC
https://www.flexera.com/products/operations/software-vulnerability-management.html
Divers liens te seront proposés pour les logiciels non à jour.


@+
0
Merci ! Merci ! Merci !
0
Romuxl Messages postés 3 Date d'inscription samedi 19 octobre 2013 Statut Membre Dernière intervention 19 octobre 2013 2
19 oct. 2013 à 17:31
Fait...

Merci à toi.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Bonjour,
Super ca a marché, merci
0
Merci pour l'aide c'est un vrai soulagement ça commençait vraiment à me souler ! MERCIIIIIIII ^^
0
Je ne sais pas si ça marche encore mais normalement oui donc au cas où.

"Tester avec Shortcut_Module sa répare les raccourcie endommagée et Qone8 intervient quelque fois sur les raccourcie donc bon. C'est testé et sa fonctionne.

Vous pouvez le télécharger ici: http://www.security-helpzone.com/blog/shortcut_module_supprimer_les_raccourcis_infectes_du_bureau-news-18.html"
0
soso2102 Messages postés 2 Date d'inscription mercredi 30 avril 2014 Statut Membre Dernière intervention 2 mai 2014
30 avril 2014 à 22:38
Rapport de ZHPFix 2014.4.7.2 par Nicolas Coolman, Update du 07/04/2014
Fichier d'export Registre :
Run by geant at 30/04/2014 20:52:09
High Elevated Privileges : OK
Windows 8 Home Premium Edition, 64-bit (Build 9200)

Corbeille vidée (00mn 07s)

========== Valeurs du Registre ==========
Aucune Valeur Standard Profile: FirewallRaz :
Aucune Valeur Domain Profile: FirewallRaz :
SUPPRIMÉ: FirewallRaz (Domain) : {808F1451-4108-46FD-ADBB-F17324B5F0BD}
SUPPRIMÉ: FirewallRaz (Domain) : {E7985E1D-C36F-4787-80A8-6350D07E9266}
SUPPRIMÉ: FirewallRaz (Domain) : NetPres-In-TCP-NoScope
SUPPRIMÉ: FirewallRaz (Domain) : NetPres-Out-TCP-NoScope
SUPPRIMÉ: FirewallRaz (None) : NetPres-WSD-In-UDP
SUPPRIMÉ: FirewallRaz (None) : NetPres-WSD-Out-UDP
SUPPRIMÉ: FirewallRaz (Public) : NetPres-In-TCP
SUPPRIMÉ: FirewallRaz (Public) : NetPres-Out-TCP
SUPPRIMÉ: FirewallRaz (None) : MCX-Prov-Out-TCP
SUPPRIMÉ: FirewallRaz (None) : MCX-McrMgr-Out-TCP

========== Dossiers ==========
Aucun dossiers CLSID Local utilisateur vide
SUPPRIMÉS Temporaires Windows (0)
SUPPRIMÉS Flash Cookies (0)

========== Fichiers ==========
SUPPRIMÉ: c:\users\public\desktop\google chrome.lnk (http://start.qone8.com)
CRÉÉ: C:\Users\Public\Desktop\Google Chrome.lnk
SUPPRIMÉ: c:\users\geant\appdata\roaming\microsoft\internet explorer\quick launch\google chrome.lnk (http://start.qone8.com)
CRÉÉ: C:\Users\geant\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
SUPPRIMÉ: c:\users\geant\appdata\roaming\microsoft\internet explorer\quick launch\launch internet explorer browser.lnk (http://start.qone8.com)
CRÉÉ: C:\Users\geant\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
SUPPRIMÉ: c:\users\geant\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\google chrome.lnk (http://start.qone8.com)
CRÉÉ: C:\Users\geant\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
CRÉÉ: C:\Users\geant\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
SUPPRIMÉ: c:\users\geant\appdata\roaming\microsoft\windows\start menu\programs\internet explorer.lnk (http://start.qone8.com)
CRÉÉ: C:\Users\geant\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
CRÉÉ: C:\Users\geant\Desktop\Internet Explorer.lnk
SUPPRIMÉ: c:\windows\prefetch\spyhunter4.exe-3b4e3201.pf
SUPPRIMÉS Temporaires Windows (0) (0 octets)
SUPPRIMÉS Flash Cookies (0) (0 octets)

========== Restauration Système ==========
Point de restauration du système créé avec succès


========== Récapitulatif ==========
12 : Valeurs du Registre
3 : Dossiers
15 : Fichiers
1 : Restauration Système


End of clean in 00mn 41s

========== Chemin de fichier rapport ==========
C:\Users\geant\AppData\Roaming\ZHP\ZHPFix[R1].txt - 30/04/2014 20:52:17 [2849]
0
soso2102 Messages postés 2 Date d'inscription mercredi 30 avril 2014 Statut Membre Dernière intervention 2 mai 2014
2 mai 2014 à 12:11
# Nom d'utilisateur : Sofia - SOFIA
# Exécuté depuis : C:\Users\Sofia\Downloads\adwcleaner.exe
# Option : Nettoyer

***** [ Services ] *****


***** [ Fichiers / Dossiers ] *****


***** [ Raccourcis ] *****


***** [ Registre ] *****


***** [ Navigateurs ] *****

-\\ Internet Explorer v10.0.9200.16519


-\\ Google Chrome v34.0.1847.131

[ Fichier : C:\Users\Sofia\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Supprimée [Startup_urls] : hxxp://start.qone8.com/?type=hp&ts=1398877501&from=smt&uid=HGSTXHTS541010A9E680_JB1000131B0JUB1B0JUBX
Supprimée [Startup_urls] : hxxp://start.mysearchdial.com/?f=1&a=tele_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DzzyDtD0EyCtDtBtCzz0A0ByCtBtD0FtN0D0Tzu0SzzyDtCtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0AyBtBzztAyDzztG0C0DzzyEtGtA0CtCtDtGtByC0A0CtGtAyEzytAtCtC0C0F0C0DtCtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0EtDyC0E0ByEyDtGtB0ByE0DtGtAzzzzzytGyDyC0E0BtGyEzzyEtByD0ByC0B0B0F0AyC2Q&cr=1953962745&ir=
Supprimée [Startup_urls] : hxxp://start.qone8.com/?type=hppp&ts=1398877826&from=smt&uid=HGSTXHTS541010A9E680_JB1000131B0JUB1B0JUBX
Supprimée [Startup_urls] : hxxp://start.mysearchdial.com/?f=1&a=ir_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DzzyDtD0EyCtDtBtCzz0A0ByCtBtD0FtN0D0Tzu0SzzyDtCtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyC0BtC0DtAyCyCyDtGtC0D0AyDtG0CyDzy0DtGtBtAtByEtGyEtA0Dzy0CyEzz0ByEzy0F0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtDyC0C0EyB0B0BtGtByC0FtBtG0A0B0A0AtG0DyEyE0DtGyEyC0DtA0CyDtCtDzytDzyyB2Q&cr=1118770080&ir=
Supprimée [Startup_urls] : hxxp://start.iminent.com/?appId=8577FF01-CCCB-4C5E-9A74-553C93F45683

*************************

AdwCleaner[R0].txt - [1934 octets] - [02/05/2014 12:05:28]
AdwCleaner[S0].txt - [1865 octets] - [02/05/2014 12:06:54]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1925 octets] ##########
0
Bonjour,
j'ai eu moi aussi le même pb . Je pense que c'est résolu .
Merci
0
krissouille Messages postés 1 Date d'inscription mardi 6 mai 2014 Statut Membre Dernière intervention 6 mai 2014
6 mai 2014 à 00:36
# AdwCleaner v3.207 - Rapport créé le 06/05/2014 à 00:25:52
# Mis à jour le 05/05/2014 par Xplode
# Système d'exploitation : Windows 8 (64 bits)
# Nom d'utilisateur : christian - CHRIS
# Exécuté depuis : C:\Users\christian\Downloads\adwcleaner (3).exe
# Option : Nettoyer

***** [ Services ] *****


***** [ Fichiers / Dossiers ] *****

Fichier Supprimé : C:\Users\christian\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.iminent.com_0.localstorage
Fichier Supprimé : C:\Users\christian\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.iminent.com_0.localstorage-journal

***** [ Raccourcis ] *****


***** [ Registre ] *****


***** [ Navigateurs ] *****

-\\ Internet Explorer v10.0.9200.16537


-\\ Google Chrome v34.0.1847.131

[ Fichier : C:\Users\christian\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Supprimée [Startup_urls] : hxxp://search.conduit.com/?ctid=CT3317933&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SPC0E28738-37F1-4E79-A562-6E1FBAECF156&SSPV=
Supprimée [Startup_urls] : hxxp://www.dosearches.com/?utm_source=b&utm_medium=tugs&utm_campaign=rg&utm_content=hp&from=tugs&uid=TOSHIBAXMQ01ABD075_Z289C7I8TXXZ289C7I8T&ts=1383689931
Supprimée [Startup_urls] : hxxp://start.iminent.com/?appId=79E0B8ED-A32C-4277-A6CD-A4BA878024F1
Supprimée [Startup_urls] : hxxp://search.iminent.com/?appId=79E0B8ED-A32C-4277-A6CD-A4BA878024F1
Supprimée [Startup_urls] : hxxp://start.qone8.com/?type=hp&ts=1396790831&from=ild&uid=TOSHIBAXMQ01ABD075_Z289C7I8TXXZ289C7I8T
Supprimée [Startup_urls] : hxxp://www.trovigo.com/?gd=&ctid=CT3317933&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPC0E28738-37F1-4E79-A562-6E1FBAECF156&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=&SSPV=%22,%22hxxp=//www.dosearches.com/?utm_source=b
Supprimée [Homepage] : hxxp://www.trovigo.com/?gd=&ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPC0E28738-37F1-4E79-A562-6E1FBAECF156&SSPV=

*************************

AdwCleaner[R0].txt - [17467 octets] - [05/05/2014 23:57:11]
AdwCleaner[R1].txt - [2379 octets] - [06/05/2014 00:07:05]
AdwCleaner[R2].txt - [2499 octets] - [06/05/2014 00:24:39]
AdwCleaner[S0].txt - [15382 octets] - [05/05/2014 23:58:22]
AdwCleaner[S1].txt - [2456 octets] - [06/05/2014 00:07:51]
AdwCleaner[S2].txt - [2436 octets] - [06/05/2014 00:25:52]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2496 octets] ##########
0
Bourguignoul
8 mai 2014 à 11:33
J'ai trouvé une autre méthode radicale fonctionnant sous Windows 7.
1 - Démarrer/tous les programmes/internet explorer
2 - Clic droit/envoyer vers/bureau
3 - Depuis là, cliquer sur le nouvel icône Internet-explorer et faire propriétés
4 - Dans la fenêtre qui s'ouvre regarder " Cible ".
5 - Vous lirez : "C:\Program Files\Internet Explorer\iexplore.exe"XXXxxxXXXxxxXXX
6 - Supprimez tout ce qui est écrit après le guillemet (") de iexplore.exe
7 - C'est tout.
8 - Vous pouvez aller vérifier dans la liste des programmes si certains d'entre eux on été installés avec votre consentement ou non.
0
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 10/05/2014
Scan Time: 18:38:10
Logfile:
Administrator: Yes

Version: 2.00.1.1004
Malware Database: v2014.05.10.07
Rootkit Database: v2014.03.27.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled

OS: Windows XP Service Pack 3
CPU: x86
File System: NTFS
User: cdelanghe

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 371626
Time Elapsed: 22 min, 10 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled

Processes: 3
Trojan.Agent.SVR, C:\Program Files\003\xmkysecqun32.exe, 1348, , [6f50e16e9be01323f3543c2f9f624bb5]
PUP.Optional.OptimizerPro, C:\Program Files\Optimizer Pro\OptProSmartScan.exe, 2764, , [af105af5314a04329fe0e93dc53c50b0]
PUP.Optional.AdPeak.A, C:\Program Files\003\xmkysecqun32.exe, 1348, , [7d42a0af0378dd59f37f1d63b74b6a96]

Modules: 0
(No malicious items detected)

Registry Keys: 49
Trojan.Agent.SVR, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\xmkysecqun32, , [6f50e16e9be01323f3543c2f9f624bb5],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [a41bb39cf2895fd766e867ce9967b54b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, , [a41bb39cf2895fd766e867ce9967b54b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, , [a41bb39cf2895fd766e867ce9967b54b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [a41bb39cf2895fd766e867ce9967b54b],
PUP.Optional.SupTab.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [a41bb39cf2895fd766e867ce9967b54b],
PUP.Optional.SupTab.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [a41bb39cf2895fd766e867ce9967b54b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}\INPROCSERVER32, , [a41bb39cf2895fd766e867ce9967b54b],
PUP.Optional.SearchQu, HKLM\SOFTWARE\CLASSES\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}, , [ffc062ed91ea3501953a022416ec22de],
PUP.Optional.SearchQu, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{99079A25-328F-4BD4-BE04-00955ACAA0A7}, , [ffc062ed91ea3501953a022416ec22de],
PUP.Optional.SearchQu, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{99079A25-328F-4BD4-BE04-00955ACAA0A7}, , [ffc062ed91ea3501953a022416ec22de],
PUP.Optional.SearchQu, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{99079A25-328F-4BD4-BE04-00955ACAA0A7}, , [ffc062ed91ea3501953a022416ec22de],
Adware.QuestScan, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{4B8C28A7-A9BC-45F8-990D-21499EED643C}, , [7946e16e5823da5c7a185add6c96e21e],
PUP.Optional.Iminent.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{112BA211-334C-4A90-90EC-2AD1CDAB287C}, , [209f76d9ef8cda5ca3a60e4b2ad83fc1],
PUP.Optional.Iminent.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{112BA211-334C-4A90-90EC-2AD1CDAB287C}, , [209f76d9ef8cda5ca3a60e4b2ad83fc1],
PUP.Optional.Iminent.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{1FAFD711-ABF9-4F6A-8130-5166C7371427}, , [7e417ad5b5c6d26494b6a0b9fd0558a8],
PUP.Optional.Iminent.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{1FAFD711-ABF9-4F6A-8130-5166C7371427}, , [7e417ad5b5c6d26494b6a0b9fd0558a8],
PUP.Optional.Iminent.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}, , [338c3619b8c349edf4e6e37526dc748c],
PUP.Optional.Iminent.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}, , [338c3619b8c349edf4e6e37526dc748c],
PUP.Optional.ScanTack.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D332CFF8-358E-4C9E-8AF3-A08872EF22C1}, , [417e5df20e6de155b9072bf88082a65a],
PUP.Optional.ScanTack.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D332CFF8-358E-4C9E-8AF3-A08872EF22C1}, , [417e5df20e6de155b9072bf88082a65a],
PUP.Optional.CouponDownloader.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{10AD2C61-0898-4348-8600-14A342F22AC3}, , [6e5194bb4a3174c292d41a0705fdaf51],
PUP.Optional.CouponDownloader.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{10AD2C61-0898-4348-8600-14A342F22AC3}, , [6e5194bb4a3174c292d41a0705fdaf51],
PUP.Optional.Iminent.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}, , [fcc3133c740752e479cfd8815ba7dc24],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}, , [fcc3133c740752e479cfd8815ba7dc24],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, , [06b982cd5724bf7753606beec240be42],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, , [cbf4e16e04779f977d374514a85a3ac6],
PUP.Optional.AdPeak.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\xmkysecqun32, , [7d42a0af0378dd59f37f1d63b74b6a96],
Adware.Boxore, HKLM\SOFTWARE\Boxore, , [ccf3222ded8eb482b5be680dc43ffa06],
Adware.EoRezo, HKLM\SOFTWARE\freeSoftToday, , [f2cdd07f295290a6fb8b506007fce21e],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\Iminent, , [a817c98683f8c86e143f3c598f738779],
PUP.Optional.Qone8.A, HKLM\SOFTWARE\qone8Software, , [1da29eb1502bed4951a031832cd729d7],
PUP.Optional.SupraSavings.A, HKLM\SOFTWARE\suprasavings, , [f7c81e31592200368a45d0b5b250ca36],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent, , [3c8393bc99e2fc3a7c4519a62dd6ea16],
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pelmeidfhdlhlbjimpabfcbnnojbboma, , [b20d9ab5d8a375c122f99fe9be44f60a],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [59661a356f0c4beba99d3c7a45be4eb2],
Adware.QuestScan, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\QUESTSCAN, , [15aa46097803a98da77b2e7b3dc55ea2],
Adware.QuestScan, HKLM\SOFTWARE\QUESTSCAN, , [4a75b19e403bfb3ba4b8595e40c245bb],
Adware.QuestScan, HKLM\SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_QUESTSCAN_SERVICE, , [d2eda9a6a4d7ae887c0e6f4806fcb64a],
Adware.QuestScan, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\QuestScan Service, , [dde2c48b1d5e85b14b40d2e5c9390af6],
PUP.Optional.Deeal.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Deeal_fr 0.2, , [cbf474db6516bd7979f2c7c748baf60a],
PUP.Optional.Deeal.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Deeal_fr 0.2, , [536c62eddd9e290d006bd9b535cd6898],
Adware.GibMedia, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Winsudate, , [279894bb9fdc1a1cf2b4b15d798ad828],
PUP.Optional.RRSavings.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Rr Savings, , [3a8587c8f289072faf05354b48ba639d],
PUP.Optional.SupraSavings.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Supra Savings, , [5768c887cfaca195b00a1f65b94940c0],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CROSSRIDER, , [8e31c28d4f2c88ae39302c7fdc271ae6],
PUP.Optional.Qone8, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [5c63262919620c2ad86d5a5cee15c937],
PUP.Optional.BubbleDock.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\NOSIBAY\Bubble Dock Tag, , [10afea65c3b850e62fe2633361a1d729],
PUP.Optional.Softonic.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [6e5181ce6219f640d6c8552dce3421df],

Registry Values: 9
PUP.Optional.SearchQu, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{99079A25-328F-4BD4-BE04-00955ACAA0A7}, Searchqu Toolbar, , [ffc062ed91ea3501953a022416ec22de]
PUP.Optional.Iminent.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{84FF7BD6-B47F-46F8-9130-01B2696B36CB}, , [fcc3133c740752e479cfd8815ba7dc24],
PUP.Optional.Iminent.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}, , [19a6c58a7ffc201626224e0bc2400af6],
PUP.Optional.SearchQu, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{99079a25-328f-4bd4-be04-00955acaa0a7}, , [a71849060b7071c5339cae78d13153ad],
PUP.Optional.FirstSeenToday.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|fst_fr_177, , [d1eeb6998af13cfaea42ef91c33f837d],
Adware.EoRezo, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|upfst_fr_177.exe, C:\Documents and Settings\cdelanghe\Local Settings\Application Data\fst_fr_177\upfst_fr_177.exe -runhelper, , [a01f5ef1780347ef8afdc304649f37c9]
Adware.QuestScan, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\QUESTSCAN|DisplayName, QuestScan 1.0 build 193, , [15aa46097803a98da77b2e7b3dc55ea2]
Adware.QuestScan, HKLM\SOFTWARE\QUESTSCAN|DllPath, C:\Program Files\QuestScan\questscan.dll, , [4a75b19e403bfb3ba4b8595e40c245bb]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CROSSRIDER|Verifier, 2ddb96fb5153558b6abef59de34348d2, , [8e31c28d4f2c88ae39302c7fdc271ae6]

Registry Data: 5
PUP.Optional.Qone8, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1399717268&from=nsbfr&uid=HitachiXHTS543225L9A300_081014FB0E00LKHPWA7AX, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1399717268&from=nsbfr&uid=HitachiXHTS543225L9A300_081014FB0E00LKHPWA7AX),,[467952fd2f4cd85e20064bf7af5543bd]
Hijack.StartPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://start.qone8.com/?type=hp&ts=1399717268&from=nsbfr&uid=HitachiXHTS543225L9A300_081014FB0E00LKHPWA7AX, Good: (http://www.google.com), Bad: (http://start.qone8.com/?type=hp&ts=1399717268&from=nsbfr&uid=HitachiXHTS543225L9A300_081014FB0E00LKHPWA7AX),,[1da2df7096e54fe7e7a745f3f113eb15]
Hijack.StartPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://start.qone8.com/?type=hp&ts=1399717268&from=nsbfr&uid=HitachiXHTS543225L9A300_081014FB0E00LKHPWA7AX, Good: (http://www.google.com), Bad: (http://start.qone8.com/?type=hp&ts=1399717268&from=nsbfr&uid=HitachiXHTS543225L9A300_081014FB0E00LKHPWA7AX),,[239c3e116c0f8fa78705013706fed828]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[03bc92bdb5c6e84e9592360c53b16f91]
Hijack.StartPage, HKU\S-1-5-21-321500761-4242303157-171814982-1149-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://start.qone8.com/?type=hp&ts=1399717268&from=nsbfr&uid=HitachiXHTS543225L9A300_081014FB0E00LKHPWA7AX, Good: (http://www.google.com), Bad: (http://start.qone8.com/?type=hp&ts=1399717268&from=nsbfr&uid=HitachiXHTS543225L9A300_081014FB0E00LKHPWA7AX),,[9f20a8a7f18a76c0246b340455aff50b]

Folders: 35
PUP.Optional.SupTab.A, C:\Program Files\SupTab, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\weather, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\en-US, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\es-419, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\es-ES, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-BE, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-CA, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-CH, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-FR, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-LU, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\it-CH, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\it-IT, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pl, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pt, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pt-BR, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\ru, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\ru-MO, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\tr-TR, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\vi-VI, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\zh-CN, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\zh-TW, , [dde2371857245dd916fbfb961fe3c23e],
Adware.InstallBrain, C:\Documents and Settings\All Users\Application Data\IBUpdaterService, , [1fa05af5d9a266d0b099f391f70cc43c],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Documents and Settings\cdelanghe\Application Data\PerformerSoft\PC Performer, , [ccf3331c5f1cfa3c85a86448ed1640c0],
PUP.Optional.PCPerformer.A, C:\Documents and Settings\cdelanghe\Application Data\PerformerSoft\PC Performer\Partial Backups, , [ccf3331c5f1cfa3c85a86448ed1640c0],
PUP.Optional.Iminent.A, C:\Program Files\IminentToolbar, , [bb042c23106b38feda854f1d9b67c53b],
PUP.Optional.FileScout.A, C:\Documents and Settings\cdelanghe\Application Data\File Scout, , [af100a45c7b4e1557c04214b23df46ba],
PUP.Optional.Iminent.A, C:\Documents and Settings\cdelanghe\Local Settings\Temp\Iminent, , [e7d8054a53286accdba6d8949072669a],
PUP.Optional.Iminent.A, C:\Documents and Settings\cdelanghe\Application Data\IminentToolbar, , [9d22f55a7605f244cb69df8f4db5629e],
PUP.Optional.Iminent.A, C:\Documents and Settings\cdelanghe\Application Data\IminentToolbar\iminent, , [9d22f55a7605f244cb69df8f4db5629e],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-2.6, , [2c939fb0611ab77fceb6462d3dc5dd23],

Files: 140
Trojan.Agent.SVR, C:\Program Files\003\xmkysecqun32.exe, , [6f50e16e9be01323f3543c2f9f624bb5],
PUP.Optional.OptimizerPro, C:\Program Files\Optimizer Pro\OptProSmartScan.exe, , [af105af5314a04329fe0e93dc53c50b0],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\SupTab.dll, , [a41bb39cf2895fd766e867ce9967b54b],
Trojan.Banker.Kreapixel, C:\Documents and Settings\cdelanghe\Application Data\~setmgat.exe, , [417e4a055c1f9d99f7314fecbe438a76],
PUP.Optional.SupTab.A, C:\Documents and Settings\cdelanghe\Application Data\SupTab\SupTab.dll, , [b00f2f206219280e3e100f26897709f7],
PUP.Optional.Softonic, C:\Documents and Settings\cdelanghe\Bureau\SoftonicDownloader_pour_avs-audio-converter.exe, , [ccf358f7abd0d75fa4982bd830d1aa56],
PUP.Optional.OptimizerPro, C:\RECYCLER\S-1-5-21-321500761-4242303157-171814982-1149\Dc18.exe, , [0bb4242b5e1ddc5aceaf2105f20f3fc1],
PUP.Optional.AdPeak.A, C:\temp\InstallFilter32.msi, , [09b689c6413a83b36512211c837d47b9],
PUP.Optional.SupraSavings.A, C:\temp\t.msi, , [4d724f002457ae88222971c27193bf41],
PUP.Optional.PCPerformer.A, C:\WINDOWS\system32\roboot.exe, , [f0cf212e275459dd418d5ac6ff01e818],
PUP.Optional.AdPeak.A, C:\WINDOWS\system32\SecureAssist.dll, , [9f20321d5d1ea690e88f2a13df216a96],
PUP.Optional.BubbleDock.A, C:\Documents and Settings\cdelanghe\Local Settings\Temp\n6304\BubbleDock_FR_0210-6f5bb19e.exe, , [f2cd6de2bfbcd95d3cd61d1c05fc28d8],
PUP.Optional.Iminent.A, C:\Documents and Settings\cdelanghe\Local Settings\Temp\n6304\Iminent_1712-b2fcad5e.exe, , [9f2074db5427a195b4e1b88a26db40c0],
PUP.Optional.SupraSavings.A, C:\Documents and Settings\cdelanghe\Local Settings\Temp\n6304\suprasavings_2703-e3e04064.exe, , [d9e6c48b0a71e1557e829d84cc36b34d],
PUP.Optional.BubbleDock.A, C:\Documents and Settings\cdelanghe\Local Settings\Temp\1052014121620\Uninstall Bubble Dock.exe, , [12ad5bf426555adc43cf87b22cd518e8],
PUP.Optional.SkyTech.A, C:\Documents and Settings\cdelanghe\Local Settings\Temp\fullpackage_temp1399717242\alilog.dll, , [229dda75a4d7fe3817ffca68748c26da],
PUP.Optional.IePluginService.A, C:\Documents and Settings\cdelanghe\Local Settings\Temp\fullpackage_temp1399717242\tmp\SupTab.exe, , [9f20dd72d1aa57dff3f8d87c2ad737c9],
PUP.Optional.WpManager, C:\Documents and Settings\cdelanghe\Local Settings\Temp\fullpackage_temp1399717242\tmp\wpm.exe, , [c6f9d877a6d5e74f47026cf3c43da060],
PUP.Optional.GenericExt.A, C:\Documents and Settings\cdelanghe\Local Settings\Temp\igdhbblpcellaljokkpfhcjlagemhgjl70aac\minibarchrome.exe, , [02bd65ea0675c76f98a18cb14db3cd33],
PUP.Optional.AppsInstaller, C:\Documents and Settings\cdelanghe\Local Settings\Temporary Internet Files\Content.IE5\G5V2D3EQ\Setup[1].exe, , [15aa420d1764ce68844050e714f044bc],
PUP.Optional.AdPeak.A, C:\Program Files\003\xmkysecqun32.exe, , [7d42a0af0378dd59f37f1d63b74b6a96],
PUP.Optional.PlusHD.A, C:\WINDOWS\Tasks\Plus-HD-2.6-codedownloader.job, , [fac5be912a51de58ee66651e43bfd729],
PUP.Optional.PlusHD.A, C:\WINDOWS\Tasks\Plus-HD-2.6-enabler.job, , [6e51eb647b00d85e6ce812712cd67b85],
PUP.Optional.PlusHD.A, C:\WINDOWS\Tasks\Plus-HD-2.6-updater.job, , [f7c867e82259e05675df4e35aa5833cd],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\install.data, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\BHOEnabler.exe, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\DpInterface32.dll, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\DpInterface64.dll, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\DpInterfacef32.dll, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\ient.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\RSHP.exe, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\SearchProtect32.dll, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\SearchProtect64.dll, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\SpAPPSv32.dll, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\SpAPPSv64.dll, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\uninstall.exe, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\WebDataJs, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\data.html, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\indexIE.html, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\indexIE8.html, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\main.css, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\ver.txt, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\arrow.png, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\default_add_logo.png, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\default_add_logo_hover.png, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\default_logo.png, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\googlelogo.png, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\googlelogo2.png, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\google_trends.png, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\icon128.png, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\icon16.png, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\icon48.png, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\loading.gif, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\logo32.ico, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\weather\0.png, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\common.js, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\ga.js, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\ie8.js, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\jquery-1.11.0.min.js, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\jquery.autocomplete.js, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\js.js, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\library.js, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\xagainit.js, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\en-US\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\es-419\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\es-ES\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-BE\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-CA\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-CH\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-FR\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-LU\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\it-CH\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\it-IT\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pl\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pt\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pt-BR\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\ru\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\ru-MO\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\tr-TR\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\vi-VI\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\zh-CN\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\zh-TW\messages.json, , [dde2371857245dd916fbfb961fe3c23e],
PUP.Optional.Bubbledock.A, C:\Documents and Settings\cdelanghe\Application Data\Bubble Dock.boostrap.log, , [0fb09ab53f3cfc3a8c37e7acc83abc44],
Adware.InstallBrain, C:\Documents and Settings\All Users\Application Data\IBUpdaterService\repository.xml, , [1fa05af5d9a266d0b099f391f70cc43c],
PUP.Optional.BrowserDefender.A, C:\WINDOWS\Tasks\BrowserDefendert.job, , [26997ad5037851e5a934bceb04ff8080],
PUP.Optional.Babylon.A, C:\WINDOWS\Tasks\EPUpdater.job, , [9629f15eb6c5ad8951fd1a8e5ea59b65],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\xmllite.dll, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\Italian_rcp.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\Chinese_rcp.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\CleanSchedule.exe, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\Danish_rcp.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\Dutch_rcp.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\eng_rcp.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\Finnish_rcp_fi.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\French_rcp.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\German_rcp.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\greek_rcp_el.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\install_left_image.bmp, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\isxdl.dll, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\Japanese_rcp.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\korean_rcp_ko.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\Norwegian_rcp.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\PCPerformer.dll, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\PCPerformer.exe, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\polish_rcp_pl.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\portugese_rcp_pt.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\Portuguese_rcp.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\russian_rcp_ru.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\Spanish_rcp.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\Swedish_rcp.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\TraditionalCn_rcp_zh-tw.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\turkish_rcp_tr.ini, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\unins000.dat, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\unins000.exe, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\Program Files\PC Performer\unins000.msg, , [6e51e768710ae353c0d29018b3506c94],
PUP.Optional.PCPerformer.A, C:\WINDOWS\Tasks\PC Performer_DEFAULT.job, , [b00fa2ad8bf067cf6d271e8aa95aa25e],
PUP.Optional.PCPerformer.A, C:\WINDOWS\Tasks\PC Performer_UPDATES.job, , [378884cbd4a71e18f689bceeef1438c8],
PUP.Optional.PCPerformer.A, C:\Documents and Settings\cdelanghe\Application Data\PerformerSoft\PC Performer\log_06-05-2013.log, , [ccf3331c5f1cfa3c85a86448ed1640c0],
PUP.Optional.PCPerformer.A, C:\Documents and Settings\cdelanghe\Application Data\PerformerSoft\PC Performer\ExcludeList.rcp, , [ccf3331c5f1cfa3c85a86448ed1640c0],
PUP.Optional.PCPerformer.A, C:\Documents and Settings\cdelanghe\Application Data\PerformerSoft\PC Performer\French_rcp.dat, , [ccf3331c5f1cfa3c85a86448ed1640c0],
PUP.Optional.PCPerformer.A, C:\Documents and Settings\cdelanghe\Application Data\PerformerSoft\PC Performer\results.rcp, , [ccf3331c5f1cfa3c85a86448ed1640c0],
PUP.Optional.PCPerformer.A, C:\Documents and Settings\cdelanghe\Application Data\PerformerSoft\PC Performer\TempHLList.rcp, , [ccf3331c5f1cfa3c85a86448ed1640c0],
PUP.Optional.PCPerformer.A, C:\Documents and Settings\cdelanghe\Application Data\PerformerSoft\PC Performer\Partial Backups\00000001.rmx, , [ccf3331c5f1cfa3c85a86448ed1640c0],
PUP.Optional.PCPerformer.A, C:\Documents and Settings\cdelanghe\Application Data\PerformerSoft\PC Performer\Partial Backups\00000001.rxb, , [ccf3331c5f1cfa3c85a86448ed1640c0],
PUP.Optional.FileScout.A, C:\Documents and Settings\cdelanghe\Application Data\File Scout\uninst.exe, , [af100a45c7b4e1557c04214b23df46ba],
PUP.Optional.Iminent.A, C:\Documents and Settings\cdelanghe\Application Data\IminentToolbar\sqlite3.dll, , [9d22f55a7605f244cb69df8f4db5629e],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-2.6\background.html, , [2c939fb0611ab77fceb6462d3dc5dd23],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-2.6\Installer.log, , [2c939fb0611ab77fceb6462d3dc5dd23],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-bg.exe, , [2c939fb0611ab77fceb6462d3dc5dd23],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-bho.dll, , [2c939fb0611ab77fceb6462d3dc5dd23],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-buttonutil.dll, , [2c939fb0611ab77fceb6462d3dc5dd23],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-buttonutil.exe, , [2c939fb0611ab77fceb6462d3dc5dd23],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-buttonutil64.dll, , [2c939fb0611ab77fceb6462d3dc5dd23],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-buttonutil64.exe, , [2c939fb0611ab77fceb6462d3dc5dd23],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-codedownloader.exe, , [2c939fb0611ab77fceb6462d3dc5dd23],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-enabler.exe, , [2c939fb0611ab77fceb6462d3dc5dd23],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-helper.exe, , [2c939fb0611ab77fceb6462d3dc5dd23],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-2.6\Plus-HD-2.6-updater.exe, , [2c939fb0611ab77fceb6462d3dc5dd23],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-2.6\Plus-HD-2.6.ico, , [2c939fb0611ab77fceb6462d3dc5dd23],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-2.6\Uninstall.exe, , [2c939fb0611ab77fceb6462d3dc5dd23],

Physical Sectors: 0
(No malicious items detected)


(end)
0