Pub internet qui s'ouvre

Fermé
Alex - 16 mai 2015 à 18:20
 alex - 17 mai 2015 à 23:08
Bonjour,
depuis peu quand je fait une recherche sur google chrome des pub comme BUZZDOCK ADS, POWERED BY INTERNET PROGRAM s'ouvre en petite fenetre sur toutes mes pages internet je suis donc obligé de fermer chaque petite fenetre pour y voir plus claire. j'ai regarder dans les parametre de google chrome et rien n'est activer de plus que d'habitude. Et dans mes programes je n'est rien non plus. aidez moi svp


11 réponses

Paul.W Messages postés 71 Date d'inscription jeudi 8 mai 2014 Statut Membre Dernière intervention 30 juillet 2017 1
16 mai 2015 à 18:22
Hey , la solution est ici , télécharge AdwCleaner : https://toolslib.net/downloads/finish/1/ et fais une analyse , et puis c'est bon , apres dit moi si sa a marché.
1
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 805
16 mai 2015 à 18:30
+1 :)

nettoyer c'est bien aussi
0
Salut, PAUL W. j'ai deja telecharger adwclearner et rien a changer :(
0
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 805
17 mai 2015 à 16:17
▶ Télécharge ici : FRST (de Farbar)
!!! En fonction de ta version de Windows, prends la "32-Bit Version" ou la "64-Bit Version" !!!
Aide : va dans Démarrer > Panneau de configuration > Système pour savoir si tu es sous 32 bits ou 64 bits.

▶ Double-clique sur l'icône FRST.exe pour lancer le programme. (Sous Windows Vista, 7 et 8, il faut faire un clic droit dessus, puis exécuter en tant qu'administrateur.) Clique ensuite sur Oui lorsqu'un message d'avertissement (Disclaimer) s'affiche.

▶ Sur le menu principal, clique sur le bouton Scan et patiente le temps de l'analyse.

▶ A la fin du scan, deux rapports s'affichent, FRST.txt et Addition.txt Poste les rapports dans ta prochaine réponse.

Les rapport se trouvent ici : C:\FRST\Logs

▶ Envoie-les sur https://www.cjoint.com/ et poste les liens obtenus en échange.
0
Bnjour, je vient de clicker sur votre liens mais visiblement il est mort. la page s'ouvre, je clisk sur 64BITS et puis rien ne se passe
0
j'attend avec impatience ton aide. merci beaucoup
0
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 805
17 mai 2015 à 16:34
0
l'analse est en court et deux page de bloc notes se sont ouverte "FRST" et "ADDITION" on dirait que l'analyse est toujours en cours
0
FRST :

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-05-2015 02
Ran by proprietaire (administrator) on PROPRIETAIRE-PC on 17-05-2015 16:44:08
Running from C:\Users\proprietaire\Downloads
Loaded Profiles: proprietaire (Available profiles: proprietaire)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Français (France)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
() C:\Users\proprietaire\AppData\Roaming\722C1278-1431596933-E011-AB71-1C7508C6EF0F\nsk83E9.tmp
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\epson\MyEpson Portal\mepService.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
() C:\Users\proprietaire\AppData\Roaming\722C1278-1431596933-E011-AB71-1C7508C6EF0F\hnsr9B94.tmp
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\epson\MyEpson Portal\mep.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Users\proprietaire\AppData\Roaming\722C1278-1431596933-E011-AB71-1C7508C6EF0F\jnsr672A.tmp
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIILE.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpWareSE4.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(BitTorrent Inc.) C:\Users\proprietaire\AppData\Roaming\uTorrent\uTorrent.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11057768 2010-07-06] (Realtek Semiconductor)
HKLM\...\Run: [mwlDaemon] => C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-05-27] (Egis Technology Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated)
HKLM\...\Run: [OOTag] => C:\Program Files (x86)\Acer\OOBEOffer\ootag.exe [13856 2010-02-23] (Microsoft)
HKLM\...\Run: [3D BubbleSound] => "C:\Program Files\BubbleSound\3D BubbleSound.exe"
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-04-13] (Intel Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.)
HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-05-27] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-03-11] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-03-11] (Egis Technology Inc.)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [265984 2010-06-29] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [OOTag] => C:\Program Files (x86)\Acer\OOBEOffer\OOTag.exe [13856 2010-02-23] (Microsoft)
HKLM-x32\...\Run: [OpwareSE4] => C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpwareSE4.exe [79400 2007-02-04] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [tuto4pc_fr_30] => [X]
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227648 2015-03-30] (AVAST Software)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1058400 2011-10-31] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [gmsd_fr_524] => [X]
HKLM-x32\...\Run: [gmsd_fr_526] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2015-04-10] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4048187908-1995387496-4212406666-1000\...\Run: [msnmsgr] => "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background
HKU\S-1-5-21-4048187908-1995387496-4212406666-1000\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
HKU\S-1-5-21-4048187908-1995387496-4212406666-1000\...\Run: [] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
HKU\S-1-5-21-4048187908-1995387496-4212406666-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [31090792 2015-01-23] (Skype Technologies S.A.)
HKU\S-1-5-21-4048187908-1995387496-4212406666-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIILE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-4048187908-1995387496-4212406666-1000\...\Run: [uTorrent] => C:\Users\proprietaire\Downloads\uTorrent.exe [1998432 2015-05-16] (BitTorrent Inc.)
HKU\S-1-5-21-4048187908-1995387496-4212406666-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8202008 2015-04-08] (Piriform Ltd)
HKU\S-1-5-21-4048187908-1995387496-4212406666-1000\...\RunOnce: [Application Restart #2] => C:\Users\proprietaire\AppData\Local\Google\Chrome\Application\chrome.exe --flag-switches-begin --flag-switches-end --restore-last-session http://www.portaldosites.com/?utm_source=b&utm_medium=slbnew& (the data entry has 73 more characters).
HKU\S-1-5-21-4048187908-1995387496-4212406666-1000\...\MountPoints2: {05c0968b-2960-11e1-8308-1c7508c6ef0f} - F:\Autorun.exe
HKU\S-1-5-21-4048187908-1995387496-4212406666-1000\...\MountPoints2: {9a79f645-501a-11e2-8e23-1c7508c6ef0f} - E:\Autorun.exe
HKU\S-1-5-21-4048187908-1995387496-4212406666-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\System32\Acer.scr [453152 2009-12-24] ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2014-12-12] (AVAST Software)
ShellIconOverlayIdentifiers: [4SyncOverlay1] -> {2012DE06-50C0-48BD-ACDE-88F95D4CAD1F} => C:\Program Files (x86)\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers: [4SyncOverlay2] -> {C72C6188-BEF2-46E5-A89A-52F0ED75219E} => C:\Program Files (x86)\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers: [4SyncOverlay3] -> {C92F6BC2-AF61-4C0E-80E0-939B8282DDB7} => C:\Program Files (x86)\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll [2010-05-27] (Egis Technology Inc.)
ShellIconOverlayIdentifiers-x32: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x86\psdprotect.dll [2010-05-27] (Egis Technology Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-4048187908-1995387496-4212406666-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKU\S-1-5-21-4048187908-1995387496-4212406666-1000\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-4048187908-1995387496-4212406666-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
SearchScopes: HKLM -> {0AACB5B1-F935-709A-26C7-2DE77AA7A3FE} URL = http://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4048187908-1995387496-4212406666-1000 -> ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKU\S-1-5-21-4048187908-1995387496-4212406666-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: No Name -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> No File
BHO: coollncheAp -> {38bf0831-1cc6-45bc-8e5f-99fd6f860261} -> C:\Program Files (x86)\coollncheAp\pRIGAOIvLeJIbf.x64.dll No File
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-12-12] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2012-01-25] (SEIKO EPSON CORPORATION)
BHO: 4sharedExt -> {95525BD9-6136-4A26-8263-9CEE295D442D} -> No File
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems Incorporated)
BHO-x32: No Name -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2015-05-15] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-12-12] (AVAST Software)
BHO-x32: Programme d'aide de l'Assistant de connexion au compte Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2015-05-15] (Oracle Corporation)
BHO-x32: No Name -> {ff0021ad-2cc3-4e0d-8e3c-b4153a64a495} -> No File
Toolbar: HKLM - 4shared Toolbar - {95080B13-AA71-4EE8-B951-7E98221E1ED5} - No File
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2012-01-25] (SEIKO EPSON CORPORATION)
Toolbar: HKU\S-1-5-21-4048187908-1995387496-4212406666-1000 -> No Name - {BB1227AC-7A0D-4076-8C1A-51A1348F6FA8} - No File
Toolbar: HKU\S-1-5-21-4048187908-1995387496-4212406666-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.254

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-20] ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-20] ()
FF Plugin-x32: @java.com/DTPlugin,version=10.80.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2015-05-15] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.80.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2015-05-15] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2014-12-13] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2014-12-13] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-12-09] (VideoLAN)
FF HKLM-x32\...\Firefox\Extensions: [***@***] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-12-12]

Chrome:
=======
CHR HomePage: Default -> https://www.google.fr/
CHR StartupUrls: Default -> "https://www.google.fr/"
CHR DefaultSuggestURL: Default -> https://www.google.com/complete/search?client=chrome&q={searchTerms}
CHR Profile: C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-12]
CHR Extension: (Google Docs) - C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-12]
CHR Extension: (Google Drive) - C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-12]
CHR Extension: (YouTube) - C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-12]
CHR Extension: (Google Search) - C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-12]
CHR Extension: (Google Sheets) - C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-12]
CHR Extension: (Bookmark Manager) - C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-05-12]
CHR Extension: (Avast Online Security) - C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-05-12]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-13]
CHR Extension: (Google Wallet) - C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-15]
CHR Extension: (Gmail) - C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-12]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-12-12]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-12-12] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1254400 2015-04-27] (Microsoft Corporation)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
R2 fesefego; C:\Users\proprietaire\AppData\Roaming\722C1278-1431596933-E011-AB71-1C7508C6EF0F\nsk83E9.tmp [448512 2015-05-14] () [File not signed]
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [99936 2006-11-10] ()
S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2011-11-29] () [File not signed]
R2 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-27] (Egis Technology Inc.)
R2 MyEpson Portal Service; C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe [703984 2014-09-22] (SEIKO EPSON CORPORATION)
S3 Sbi_icefsm; C:\Windows\system32\drivers\wimmount.sys [22096 2009-07-14] (Microsoft Corporation)
S3 Sbi_icefsm; C:\Windows\SysWOW64\drivers\wimmount.sys [19008 2009-07-14] (Microsoft Corporation)
R2 soxocusy; C:\Users\proprietaire\AppData\Roaming\722C1278-1431596933-E011-AB71-1C7508C6EF0F\hnsr9B94.tmp [418304 2015-05-14] () [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 xiwezewy; C:\Users\proprietaire\AppData\Roaming\722C1278-1431596933-E011-AB71-1C7508C6EF0F\jnsr672A.tmp [231936 2015-05-14] () [File not signed]
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-12-12] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-12-12] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-12-12] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-12-12] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-12-12] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-12-12] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-12-12] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-12-12] ()
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [53760 2012-09-28] (Apple, Inc.) [File not signed]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-17 16:44 - 2015-05-17 16:44 - 00022597 _____ () C:\Users\proprietaire\Downloads\FRST.txt
2015-05-17 16:43 - 2015-05-17 16:44 - 00000000 ___DC () C:\FRST
2015-05-17 16:42 - 2015-05-17 16:43 - 02107392 _____ (Farbar) C:\Users\proprietaire\Downloads\FRST64.exe
2015-05-17 16:30 - 2015-05-17 16:30 - 00002818 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-05-17 16:30 - 2015-05-17 16:30 - 00000826 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-05-17 16:30 - 2015-05-17 16:30 - 00000000 ____D () C:\Program Files\CCleaner
2015-05-17 16:27 - 2015-05-17 16:29 - 06480808 _____ (Piriform Ltd) C:\Users\proprietaire\Downloads\ccsetup505-5.05.5176.exe
2015-05-17 16:23 - 2015-05-17 16:23 - 05170176 _____ () C:\Users\proprietaire\Downloads\WindowsDefender-1593.msi
2015-05-16 17:03 - 2015-05-16 17:03 - 01029429 _____ () C:\Users\proprietaire\Downloads\sims4.exe
2015-05-16 16:58 - 2015-05-16 16:58 - 00000000 ____D () C:\Users\proprietaire\Downloads\[R.G. Mechanics] The Sims 4
2015-05-16 16:57 - 2015-05-16 18:04 - 00000000 ____D () C:\Program Files\WaIEn
2015-05-16 16:57 - 2015-05-16 16:57 - 00000869 _____ () C:\Users\proprietaire\Desktop\µTorrent.lnk
2015-05-16 16:57 - 2015-05-16 16:57 - 00000849 _____ () C:\Users\proprietaire\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2015-05-16 16:57 - 2015-05-16 16:57 - 00000000 ____D () C:\Users\proprietaire\AppData\Roaming\OpenCandy
2015-05-16 16:56 - 2015-05-16 16:56 - 01998432 _____ (BitTorrent Inc.) C:\Users\proprietaire\Downloads\uTorrent.exe
2015-05-16 16:55 - 2015-05-16 16:55 - 00022132 _____ () C:\Users\proprietaire\Downloads\[rutor.org]R.G._Mechanics_The_Sims_4 (1).torrent
2015-05-16 16:53 - 2015-05-16 16:53 - 00022132 _____ () C:\Users\proprietaire\Downloads\[rutor.org]R.G._Mechanics_The_Sims_4.torrent
2015-05-15 11:53 - 2015-05-15 11:53 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2015-05-15 11:53 - 2015-05-15 11:53 - 00176040 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2015-05-15 11:53 - 2015-05-15 11:53 - 00176040 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2015-05-15 11:53 - 2015-05-15 11:53 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-05-15 11:53 - 2015-05-15 11:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-05-15 11:53 - 2015-05-15 11:53 - 00000000 ____D () C:\Program Files (x86)\Java
2015-05-15 11:27 - 2015-05-15 11:27 - 00002966 _____ () C:\Users\proprietaire\Desktop\Reimage2.lnk
2015-05-15 11:08 - 2015-05-15 11:24 - 00000000 ___DC () C:\AdwCleaner
2015-05-15 11:08 - 2015-05-15 11:08 - 02209792 _____ () C:\Users\proprietaire\Downloads\adwcleaner_4.204.exe
2015-05-14 22:58 - 2015-05-15 11:00 - 00003306 _____ () C:\Windows\System32\Tasks\avastBCLRestartS-1-5-21-4048187908-1995387496-4212406666-1000
2015-05-14 22:53 - 2015-05-16 17:07 - 00002132 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-14 18:06 - 2015-05-14 18:06 - 00003190 _____ () C:\Windows\System32\Tasks\{0C29B5AA-B952-4F48-97D6-B6248C14EC5C}
2015-05-14 14:35 - 2015-05-14 14:35 - 00613255 _____ (CMI Limited) C:\Users\proprietaire\AppData\Local\nst1B0D.tmp
2015-05-14 14:22 - 2015-05-14 17:48 - 00000000 ____D () C:\Program Files (x86)\Edu App
2015-05-14 13:04 - 2015-05-14 13:03 - 00628688 _____ (CMI Limited) C:\Users\proprietaire\AppData\Local\nsu7B21.tmp
2015-05-14 12:10 - 2015-05-15 12:10 - 00001030 _____ () C:\Windows\Tasks\6j5LlBMBdQwMvDW.job
2015-05-14 12:09 - 2015-05-15 10:41 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-05-14 12:09 - 2015-05-14 17:37 - 00000000 ____D () C:\Program Files (x86)\1c7846eb-e798-4a28-ab52-399816f1117a
2015-05-14 12:08 - 2015-05-15 13:43 - 00000000 ____D () C:\Program Files (x86)\CinemaPlus-3.2cV13.05
2015-05-14 11:53 - 2015-05-15 11:53 - 00001026 _____ () C:\Windows\Tasks\aOwUpoILful5W.job
2015-05-14 11:49 - 2013-04-25 20:50 - 00001108 _____ () C:\Windows\system32\Drivers\etc\hp.bak
2015-05-14 11:48 - 2015-05-16 17:42 - 00000000 ____D () C:\Users\proprietaire\AppData\Roaming\722C1278-1431596933-E011-AB71-1C7508C6EF0F
2015-05-14 11:28 - 2015-05-14 11:28 - 00003192 _____ () C:\Windows\System32\Tasks\{094E0025-3F0D-48BD-9B80-8EF2B476825D}
2015-05-14 11:06 - 2015-05-14 11:06 - 00001656 _____ () C:\Windows\SysWOW64\${LOGFILE}
2015-05-13 20:44 - 2015-05-13 20:44 - 00000290 __RSH () C:\ProgramData\ntuser.pol
2015-05-12 21:54 - 2015-05-01 15:17 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-12 21:54 - 2015-05-01 15:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-12 21:30 - 2015-04-22 04:28 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-12 21:30 - 2015-04-22 03:48 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-05-12 21:30 - 2015-04-21 19:14 - 24971776 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-12 21:30 - 2015-04-21 19:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-05-12 21:30 - 2015-04-21 19:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-05-12 21:30 - 2015-04-21 18:51 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-05-12 21:30 - 2015-04-21 18:50 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-12 21:30 - 2015-04-21 18:50 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-12 21:30 - 2015-04-21 18:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-05-12 21:30 - 2015-04-21 18:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-12 21:30 - 2015-04-21 18:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-05-12 21:30 - 2015-04-21 18:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-05-12 21:30 - 2015-04-21 18:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-05-12 21:30 - 2015-04-21 18:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-12 21:30 - 2015-04-21 18:35 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-12 21:30 - 2015-04-21 18:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-05-12 21:30 - 2015-04-21 18:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-05-12 21:30 - 2015-04-21 18:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-05-12 21:30 - 2015-04-21 18:31 - 06025728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-12 21:30 - 2015-04-21 18:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-05-12 21:30 - 2015-04-21 18:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-05-12 21:30 - 2015-04-21 18:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-05-12 21:30 - 2015-04-21 18:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-05-12 21:30 - 2015-04-21 18:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-05-12 21:30 - 2015-04-21 18:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-05-12 21:30 - 2015-04-21 18:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-05-12 21:30 - 2015-04-21 18:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-05-12 21:30 - 2015-04-21 18:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-05-12 21:30 - 2015-04-21 18:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-05-12 21:30 - 2015-04-21 18:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-12 21:30 - 2015-04-21 18:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-05-12 21:30 - 2015-04-21 18:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-12 21:30 - 2015-04-21 18:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-05-12 21:30 - 2015-04-21 18:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-05-12 21:30 - 2015-04-21 18:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-05-12 21:30 - 2015-04-21 18:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-05-12 21:30 - 2015-04-21 17:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-05-12 21:30 - 2015-04-21 17:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-05-12 21:30 - 2015-04-21 17:57 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-05-12 21:30 - 2015-04-21 17:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-12 21:30 - 2015-04-21 17:49 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-12 21:30 - 2015-04-21 17:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-05-12 21:30 - 2015-04-21 17:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-05-12 21:30 - 2015-04-21 17:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-12 21:30 - 2015-04-21 17:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-05-12 21:30 - 2015-04-21 17:40 - 14401536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-12 21:30 - 2015-04-21 17:39 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-05-12 21:30 - 2015-04-21 17:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-05-12 21:30 - 2015-04-21 17:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-05-12 21:30 - 2015-04-21 17:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-05-12 21:30 - 2015-04-21 17:27 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-12 21:30 - 2015-04-21 17:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-05-12 21:30 - 2015-04-21 17:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-05-12 21:30 - 2015-04-21 17:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-05-12 21:30 - 2015-04-21 17:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-05-12 21:30 - 2015-04-21 17:15 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-12 21:30 - 2015-04-21 17:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-12 21:30 - 2015-04-21 17:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-05-12 21:30 - 2015-04-21 16:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-05-12 21:30 - 2015-04-21 16:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-05-12 21:22 - 2015-05-14 22:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-05-12 21:17 - 2015-05-05 03:29 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-12 21:17 - 2015-05-05 03:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-05-12 21:17 - 2015-04-18 05:10 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-12 21:17 - 2015-04-18 04:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-05-12 21:14 - 2015-04-13 05:28 - 00328704 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-12 21:13 - 2015-04-27 21:28 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-05-12 21:13 - 2015-04-27 21:28 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-05-12 21:13 - 2015-04-27 21:28 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-05-12 21:13 - 2015-04-27 21:26 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 01254400 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-05-12 21:13 - 2015-04-27 21:23 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-05-12 21:13 - 2015-04-27 21:22 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-05-12 21:13 - 2015-04-27 21:22 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-05-12 21:13 - 2015-04-27 21:22 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-05-12 21:13 - 2015-04-27 21:22 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-05-12 21:13 - 2015-04-27 21:22 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-05-12 21:13 - 2015-04-27 21:22 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-05-12 21:13 - 2015-04-27 21:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-05-12 21:13 - 2015-04-27 21:22 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-05-12 21:13 - 2015-04-27 21:22 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-05-12 21:13 - 2015-04-27 21:21 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-05-12 21:13 - 2015-04-27 21:16 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 21:11 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-05-12 21:13 - 2015-04-27 21:11 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-05-12 21:13 - 2015-04-27 21:08 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-05-12 21:13 - 2015-04-27 21:05 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-05-12 21:13 - 2015-04-27 21:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-05-12 21:13 - 2015-04-27 21:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-05-12 21:13 - 2015-04-27 21:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-05-12 21:13 - 2015-04-27 21:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
2015-05-12 21:13 - 2015-04-27 21:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-05-12 21:13 - 2015-04-27 21:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-05-12 21:13 - 2015-04-27 21:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-05-12 21:13 - 2015-04-27 21:05 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-05-12 21:13 - 2015-04-27 21:04 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-05-12 21:13 - 2015-04-27 21:04 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-05-12 21:13 - 2015-04-27 21:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe
2015-05-12 21:13 - 2015-04-27 21:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe
2015-05-12 21:13 - 2015-04-27 21:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe
2015-05-12 21:13 - 2015-04-27 21:04 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe
2015-05-12 21:13 - 2015-04-27 21:04 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-05-12 21:13 - 2015-04-27 21:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-05-12 21:13 - 2015-04-27 21:03 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-05-12 21:13 - 2015-04-27 21:03 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-05-12 21:13 - 2015-04-27 21:03 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-05-12 21:13 - 2015-04-27 21:03 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-05-12 21:13 - 2015-04-27 21:03 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe
2015-05-12 21:13 - 2015-04-27 21:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-05-12 21:13 - 2015-04-27 20:06 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-05-12 21:13 - 2015-04-27 19:55 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-05-12 21:12 - 2015-04-27 21:18 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-05-12 21:12 - 2015-04-27 21:18 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-05-12 21:12 - 2015-04-27 21:16 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-05-12 21:12 - 2015-04-27 21:16 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-05-12 21:12 - 2015-04-27 21:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-12 21:12 - 2015-04-27 21:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-12 21:12 - 2015-04-27 21:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-05-12 21:12 - 2015-04-27 21:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-05-12 21:12 - 2015-04-27 20:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-05-12 21:12 - 2015-04-27 20:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-05-12 21:12 - 2015-04-27 20:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-05-12 21:12 - 2015-04-27 20:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-05-12 21:12 - 2015-04-27 20:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-05-12 21:12 - 2015-04-27 19:57 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-05-12 21:12 - 2015-04-27 19:57 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-05-12 21:12 - 2015-04-27 19:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-12 21:12 - 2015-04-27 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-05-12 21:12 - 2015-04-27 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-05-12 21:12 - 2015-04-20 05:17 - 01647104 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-12 21:12 - 2015-04-20 05:17 - 01179136 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-12 21:12 - 2015-04-20 04:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-05-12 21:12 - 2015-04-20 04:11 - 03204608 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-12 21:11 - 2015-04-08 05:29 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-05-12 21:11 - 2015-04-08 05:29 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-05-12 21:11 - 2015-04-08 05:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-05-12 21:11 - 2015-03-04 06:41 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-05-12 21:11 - 2015-03-04 06:41 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-05-12 21:11 - 2015-03-04 06:41 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-05-12 21:11 - 2015-03-04 06:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-05-12 21:11 - 2015-03-04 06:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2015-05-12 21:11 - 2015-03-04 06:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-05-12 21:11 - 2015-03-04 06:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-05-12 21:11 - 2015-02-18 09:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2015-05-12 21:11 - 2015-02-18 09:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-05-12 21:11 - 2015-01-29 05:19 - 02543104 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-05-12 21:11 - 2015-01-29 05:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
2015-05-01 11:08 - 2015-05-07 21:43 - 00016071 _____ () C:\Users\proprietaire\Desktop\course.ods
2015-04-24 03:17 - 2015-04-24 03:17 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-21 15:27 - 2015-03-25 05:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-21 15:27 - 2015-03-25 05:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-21 15:27 - 2015-03-25 05:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-21 15:27 - 2015-03-25 05:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-21 15:27 - 2015-03-25 05:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-21 15:27 - 2015-03-25 05:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-21 15:27 - 2015-03-25 05:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-21 15:27 - 2015-03-25 05:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-21 15:27 - 2015-03-25 05:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-21 15:27 - 2015-03-25 05:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-21 15:27 - 2015-03-25 05:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-21 15:27 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-04-21 15:27 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-04-21 15:27 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-04-21 15:27 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-04-21 15:27 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-04-21 15:27 - 2015-03-23 05:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-21 15:27 - 2015-03-23 05:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-21 15:27 - 2015-03-23 05:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-21 15:27 - 2015-03-23 05:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-21 15:27 - 2015-03-23 05:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-21 15:27 - 2015-03-23 05:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-21 15:27 - 2015-03-23 05:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-21 15:27 - 2015-03-23 05:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-21 15:27 - 2015-03-05 07:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-21 15:27 - 2015-03-05 06:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-04-21 15:27 - 2015-01-28 01:36 - 01239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2015-04-21 15:26 - 2015-03-10 05:25 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-21 15:26 - 2015-03-10 05:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-21 15:26 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-04-21 15:26 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-04-21 15:25 - 2015-02-25 05:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-21 15:20 - 2015-03-04 06:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-21 15:20 - 2015-03-04 06:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-21 15:20 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
2015-04-20 20:44 - 2015-04-20 20:44 - 00074384 _____ () C:\Users\proprietaire\Downloads\CV maman.zip
2015-04-19 14:20 - 2015-05-15 14:08 - 00000626 _____ () C:\Users\proprietaire\AppData\Roaming\aOwUpoILful5W
2015-04-19 14:20 - 2015-05-15 14:08 - 00000626 _____ () C:\Users\proprietaire\AppData\Roaming\6j5LlBMBdQwMvDW

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-17 16:44 - 2011-11-28 19:16 - 00000000 ____D () C:\Users\proprietaire\AppData\Roaming\uTorrent
2015-05-17 16:33 - 2013-04-25 20:46 - 00000000 ____D () C:\Users\proprietaire\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flvto Youtube Downloader
2015-05-17 16:33 - 2013-01-26 22:19 - 00000000 ____D () C:\Users\proprietaire\Tracing
2015-05-17 16:33 - 2012-12-01 12:38 - 00000000 ____D () C:\ProgramData\VSO
2015-05-17 16:33 - 2011-11-29 10:54 - 00000000 ____D () C:\Users\proprietaire\AppData\Roaming\DAEMON Tools Lite
2015-05-17 16:33 - 2011-11-21 14:04 - 00000000 ____D () C:\Users\proprietaire\AppData\Roaming\Skype
2015-05-17 16:33 - 2007-07-12 03:49 - 00000000 ____D () C:\Windows\Panther
2015-05-17 16:26 - 2012-04-01 17:28 - 00001070 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-17 16:26 - 2012-04-01 17:28 - 00001066 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-17 16:25 - 2009-07-14 06:45 - 00018736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-17 16:25 - 2009-07-14 06:45 - 00018736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-17 16:10 - 2012-05-23 20:30 - 00001002 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-17 15:58 - 2011-02-27 01:45 - 01855509 ____N () C:\Windows\WindowsUpdate.log
2015-05-17 15:50 - 2011-02-27 10:36 - 01604118 _____ () C:\Windows\system32\perfh00C.dat
2015-05-17 15:50 - 2011-02-27 10:36 - 00438558 _____ () C:\Windows\system32\perfc00C.dat
2015-05-17 15:50 - 2009-07-14 07:13 - 00006264 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-17 15:46 - 2014-12-12 11:20 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-05-17 15:46 - 2013-05-14 20:15 - 00000402 _____ () C:\Windows\Tasks\Happy Lyrics Update.job
2015-05-16 17:42 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-05-16 17:05 - 2015-04-05 10:54 - 00000000 ____D () C:\Program Files (x86)\Les Sims 4
2015-05-16 16:49 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-15 15:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2015-05-15 10:42 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2015-05-15 10:40 - 2011-05-09 17:59 - 00001363 _____ () C:\Users\proprietaire\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-05-14 17:59 - 2010-11-22 14:58 - 00000000 ____D () C:\Program Files (x86)\Acer
2015-05-14 17:37 - 2015-04-05 03:01 - 00000000 ___SD () C:\Windows\system32\GWX
2015-05-14 17:37 - 2015-02-01 16:36 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2015-05-14 17:37 - 2013-07-15 15:51 - 00000000 ____D () C:\Users\proprietaire\AppData\Roaming\vlc
2015-05-14 17:37 - 2011-05-09 17:56 - 00000000 ____D () C:\Users\proprietaire
2015-05-14 17:37 - 2010-11-22 15:02 - 00000000 ____D () C:\ProgramData\oem
2015-05-14 17:37 - 2009-07-14 09:45 - 00000000 ____D () C:\Windows\ShellNew
2015-05-14 17:37 - 2009-07-14 09:45 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-14 17:37 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2015-05-14 17:37 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2015-05-14 17:37 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-05-14 17:37 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-05-14 17:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2015-05-14 11:42 - 2012-12-27 00:14 - 00003251 _____ () C:\Windows\wininit.ini
2015-05-13 20:43 - 2009-07-14 06:45 - 00345944 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-12 22:08 - 2013-07-18 03:01 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-12 21:59 - 2011-11-23 09:39 - 140425016 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-05-12 21:22 - 2012-04-01 17:28 - 00000000 ____D () C:\Program Files (x86)\Google
2015-05-12 21:22 - 2011-11-08 20:35 - 00000000 ____D () C:\Users\proprietaire\AppData\Local\Google
2015-04-25 00:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat
2015-04-24 03:17 - 2014-05-17 22:20 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-20 19:15 - 2012-05-23 20:30 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-04-20 19:15 - 2012-05-23 20:30 - 00003940 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-04-20 19:15 - 2011-11-10 09:06 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

==================== Files in the root of some directories =======

2012-03-06 00:09 - 2012-10-07 20:47 - 0000006 _____ () C:\Program Files (x86)\Common Files\WPVersion.txt
2015-04-19 14:20 - 2015-05-15 14:08 - 0000626 _____ () C:\Users\proprietaire\AppData\Roaming\6j5LlBMBdQwMvDW
2015-04-19 14:20 - 2015-05-15 14:08 - 0000626 _____ () C:\Users\proprietaire\AppData\Roaming\aOwUpoILful5W
2015-02-21 05:38 - 2015-03-11 12:52 - 0000020 _____ () C:\Users\proprietaire\AppData\Roaming\appdataFr3.bin
2012-12-01 12:39 - 2012-12-04 13:10 - 0099384 _____ () C:\Users\proprietaire\AppData\Roaming\inst.exe
2012-03-07 16:37 - 2012-03-15 23:36 - 0000041 _____ () C:\Users\proprietaire\AppData\Roaming\Offre.ini
2012-12-01 12:39 - 2012-12-04 13:10 - 0007859 _____ () C:\Users\proprietaire\AppData\Roaming\pcouffin.cat
2012-12-01 12:39 - 2012-12-04 13:10 - 0001167 _____ () C:\Users\proprietaire\AppData\Roaming\pcouffin.inf
2012-12-01 12:39 - 2012-12-04 13:10 - 0000055 _____ () C:\Users\proprietaire\AppData\Roaming\pcouffin.log
2012-12-01 12:39 - 2012-12-04 13:10 - 0082816 _____ (VSO Software) C:\Users\proprietaire\AppData\Roaming\pcouffin.sys
2011-11-12 16:06 - 2013-08-08 17:04 - 0005120 _____ () C:\Users\proprietaire\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-05-14 14:35 - 2015-05-14 14:35 - 0613255 _____ (CMI Limited) C:\Users\proprietaire\AppData\Local\nst1B0D.tmp
2015-05-14 13:04 - 2015-05-14 13:03 - 0628688 _____ (CMI Limited) C:\Users\proprietaire\AppData\Local\nsu7B21.tmp
2010-11-22 14:49 - 2010-03-03 01:59 - 0131984 _____ () C:\ProgramData\FullRemove.exe
2012-05-15 20:30 - 2012-05-15 20:30 - 0000097 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc

Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.2524.dll
C:\Users\Public\AlexaNSISPlugin.4600.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-15 15:48

==================== End Of Log ============================
0
http://cjoint.com/?EErrjBG5EIW
http://cjoint.com/?EErrktYYSGb

voici les liens que tu m'as demandé. par contre est ce normal que l'analyse est toujours en court et ma encore ouvert les deux fenetre de bloc notes?
0
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 805
17 mai 2015 à 17:45
ZHPCleaner




Désactiver l'Anti-virus

Ton moteur de recherche va se fermer il faudra le réouvrir pour poster les rapports

téléchargement : https://nicolascoolman.eu




- Cet outil ne nécessite aucune installation, il est très rapide car basé sur l'éxécution de scripts.
- Clique droit sur le dossier téléchargé


- Clique sur Scanner :

- Savoir que tous les navigateurs ou onglets ouvert seront fermés et qu'il faudra les remettre

- En cas de présence d'un proxy, un message apparaît avec la question suivante
- Avez-vous installé ce proxy ? suivi de l'adresse IP du proxy
- Si vous n'avez pas installé de Proxy, cliquer sur "NON" pour accepter la réparation du proxy.

- En cas de présence d'un serveur inconnu, un message peut apparaître avec la question suivante
- Avez-vous installé ce serveur ? suivi du nom du serveur
- Si vous n'avez pas installé de serveur,, cliquer sur "NON" pour accepter la réparation



- Fournir le rapport
0
Le scanne est en cours
0
le scanne est terminé voici le rapport

~ ZHPCleaner v2015.5.17.241 by Nicolas Coolman (2015\05\17)
~ Run by proprietaire (Administrator) (17/05/2015 18:13:54)
~ Forum : http://forum.nicolascoolman.fr
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Scanner
~ Report : C:\Users\proprietaire\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\proprietaire\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
~ Windows 7, 64-bit Service Pack 1 (Build 7601)


---\\ Service. (1)
[S] TROUVÉ : KMService (Hijacker.Office)


---\\ Navigateur internet. (1)
TROUVÉ Chrome Preferences: hxxps://internetprogram-a.akamaihd.net/ (Adware.InternetProgram)


---\\ Fichier hôte. (1)
~ Le fichier hôte est légitime. (34)


---\\ Tâche planifiée. (1)
TROUVÉ tâche: [Happy Lyrics Update] [C:\Program Files (x86)\HappyLyrics\HLUpdater.exe (Not File) ] (Adware.AddLyrics)


---\\ Explorateur ( Dossiers, Fichiers ). (56)
TROUVÉ fichier: C:\Users\proprietaire\AppData\Roaming\inst.exe (Adware.Pirrit) [16E53BFC96CE14021C0E07EB1C198478]
TROUVÉ fichier: C:\Program Files (x86)\1c7846eb-e798-4a28-ab52-399816f1117a\0599d20f-b0bf-4b5a-aac7-ec15cc80f5f2.dll (Adware.CrossRider) [9D6E90994BEA886D7745D683C840C54E]
TROUVÉ fichier: C:\Program Files (x86)\1c7846eb-e798-4a28-ab52-399816f1117a\d5577a2e-882d-49d2-96d6-6da7e01cc234.dll (Adware.CrossRider) [DA4333A86DE461F90B00AC7E16854CBF]
TROUVÉ dossier: C:\Program Files (x86)\1c7846eb-e798-4a28-ab52-399816f1117a (Adware.CrossRider)
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\c46d3a53-af21-4b1c-a18b-6a878002189e-1-6.exe [Cinema PlusV13.05 - CinemaPlus-3.2cV13.05 exe] (Adware.CrossRider) [3C0A1EB2300490FF443C61F23699D9C0]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\c46d3a53-af21-4b1c-a18b-6a878002189e-1-7.exe [Cinema PlusV13.05 - CinemaPlus-3.2cV13.05 exe] (Adware.CrossRider) [EBB0AC7D602013A1117978572E5FF8DB]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\c46d3a53-af21-4b1c-a18b-6a878002189e-3.exe [Cinema PlusV13.05 - CinemaPlus-3.2cV13.05 exe] (Adware.CrossRider) [ECE0D3FA282B791150BF5855E34097EA]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\c46d3a53-af21-4b1c-a18b-6a878002189e-5.exe [Cinema PlusV13.05 - CinemaPlus-3.2cV13.05 exe] (Adware.CrossRider) [138258D303B89F82BFC3C9DB13F2895A]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\c46d3a53-af21-4b1c-a18b-6a878002189e-6.exe [Cinema PlusV13.05 - CinemaPlus-3.2cV13.05 exe] (Adware.CrossRider) [75981B73055B56A9CC25C21C4A1C81F4]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\c46d3a53-af21-4b1c-a18b-6a878002189e-64.exe [Cinema PlusV13.05 - CinemaPlus-3.2cV13.05 exe] (Adware.CrossRider) [15F80954E2BA995D9ED07E1ED725E354]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\c46d3a53-af21-4b1c-a18b-6a878002189e-7.exe [Cinema PlusV13.05 - CinemaPlus-3.2cV13.05 exe] (Adware.CrossRider) [EBB0AC7D602013A1117978572E5FF8DB]
TROUVÉ fichier: C:\Users\proprietaire\AppData\Roaming\inst.exe (Adware.GenericTask) [16E53BFC96CE14021C0E07EB1C198478]
TROUVÉ fichier: C:\Windows\Prefetch\WAJAM.EXE-EC79126F.pf (PUP.Wajam) [475F1526F5141DC8BF620232FDCFBFD8]
TROUVÉ fichier: C:\Windows\Prefetch\WAJAM_64.EXE-59CE3234.pf (PUP.Wajam) [EB52060AA5F17A699E7AC12A0699BB75]
TROUVÉ fichier: C:\Windows\Installer\1ff2355.msi [Kreapixel - Windows Installer](Adware.SocialSkinz) [15AC8E9AA19BC85222DAFAA57F672363]
TROUVÉ fichier: C:\ProgramData\InstallMate\{FDBB5335-8F9F-48C2-AA29-C7BD265871C3}\Setup.exe [Tarma Software Research Pty Ltd - InstallMate® Setup](PUP.Tarma) [E717F6CE3A7429BFA6D7F3CF66737A4B]
TROUVÉ fichier: C:\ProgramData\InstallMate\{55F5FD86-7FE0-4399-A172-37C28E16DF70}\Setup.exe [Tarma Software Research Pty Ltd - InstallMate® Setup](PUP.Tarma) [E717F6CE3A7429BFA6D7F3CF66737A4B]
TROUVÉ fichier: C:\ProgramData\InstallMate\{FDBB5335-8F9F-48C2-AA29-C7BD265871C3}\TsuDll.dll [Tarma Software Research Pty Ltd - InstallMate® Setup Library](PUP.Tarma) [AF7CE801C8471C5CD19B366333C153C4]
TROUVÉ fichier: C:\ProgramData\InstallMate\{55F5FD86-7FE0-4399-A172-37C28E16DF70}\TsuDll.dll [Tarma Software Research Pty Ltd - InstallMate® Setup Library](PUP.Tarma) [AF7CE801C8471C5CD19B366333C153C4]
TROUVÉ fichier: C:\Users\proprietaire\Desktop\Reimage2.lnk (PUP.ReimageRepair) [0710FA5104F0B14E0C48D7D47C9EBFC3]
TROUVÉ fichier: C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_internetprogram-a.akamaihd.net_0.localstorage (PUP.AkamaiHD) [B825AB583E66B31DCAA257EF314B4CDB]
TROUVÉ fichier: C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_internetprogram-a.akamaihd.net_0.localstorage-journal (PUP.AkamaiHD) [A5B056D6684A135BD31FDFE13E4371AF]
TROUVÉ fichier: C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage (PUP.BoostSaves) [0D8B3CCA3825A104B68F2F4A7AF254C0]
TROUVÉ fichier: C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage-journal (PUP.BoostSaves) [A4A9351E730209D8AFEECE1A27304A9A]
TROUVÉ fichier: C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage (Adware.PricePeep) [9FFC0F9F3524DC4BB8A654A46C14F053]
TROUVÉ fichier: C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage-journal (Adware.PricePeep) [7740F03ED8E715045573C5267EF35E51]
TROUVÉ fichier: C:\Users\proprietaire\AppData\Roaming\appdataFr3.bin (PUP.Optional) [EED8FDE6A39829728E56B6B59CA16C2F]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\66e8380a-c591-4057-a80a-6a242f0f0e7c.crx (Adware.CrossRider) [EB883038F770FDC03CB6DA597E5C2BFE]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\66e8380a-c591-4057-a80a-6a242f0f0e7c.dll (Adware.CrossRider) [DA4333A86DE461F90B00AC7E16854CBF]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\6e0c4982-8cf8-4522-a1dd-8bdc4333ab9b.dll (Adware.CrossRider) [9D6E90994BEA886D7745D683C840C54E]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\bgNova.html (Adware.CrossRider) [8910C06632E96352C2ED61FDCB9537B9]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\c46d3a53-af21-4b1c-a18b-6a878002189e-1-6.exe [Cinema PlusV13.05 - CinemaPlus-3.2cV13.05 exe](Adware.CrossRider) [3C0A1EB2300490FF443C61F23699D9C0]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\c46d3a53-af21-4b1c-a18b-6a878002189e-1-7.exe [Cinema PlusV13.05 - CinemaPlus-3.2cV13.05 exe](Adware.CrossRider) [EBB0AC7D602013A1117978572E5FF8DB]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\c46d3a53-af21-4b1c-a18b-6a878002189e-3.exe [Cinema PlusV13.05 - CinemaPlus-3.2cV13.05 exe](Adware.CrossRider) [ECE0D3FA282B791150BF5855E34097EA]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\c46d3a53-af21-4b1c-a18b-6a878002189e-5.exe [Cinema PlusV13.05 - CinemaPlus-3.2cV13.05 exe](Adware.CrossRider) [138258D303B89F82BFC3C9DB13F2895A]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\c46d3a53-af21-4b1c-a18b-6a878002189e-6.exe [Cinema PlusV13.05 - CinemaPlus-3.2cV13.05 exe](Adware.CrossRider) [75981B73055B56A9CC25C21C4A1C81F4]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\c46d3a53-af21-4b1c-a18b-6a878002189e-64.exe [Cinema PlusV13.05 - CinemaPlus-3.2cV13.05 exe](Adware.CrossRider) [15F80954E2BA995D9ED07E1ED725E354]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\c46d3a53-af21-4b1c-a18b-6a878002189e-7.exe [Cinema PlusV13.05 - CinemaPlus-3.2cV13.05 exe](Adware.CrossRider) [EBB0AC7D602013A1117978572E5FF8DB]
TROUVÉ fichier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05\Uninstall.exe (Adware.CrossRider) [A39B4036693015C4569A16FA6CB08947]
TROUVÉ dossier: C:\Program Files (x86)\CinemaPlus-3.2cV13.05 (Adware.CrossRider)
TROUVÉ dossier: C:\ProgramData\InstallMate\{55F5FD86-7FE0-4399-A172-37C28E16DF70} (PUP.Tarma)
TROUVÉ dossier: C:\ProgramData\InstallMate\{D79B2DE1-2C3F-415A-A3B1-641D0C780F17} (PUP.Tarma)
TROUVÉ dossier: C:\ProgramData\InstallMate\{FDBB5335-8F9F-48C2-AA29-C7BD265871C3} (PUP.Tarma)
TROUVÉ dossier: C:\ProgramData\InstallMate (PUP.Tarma)
TROUVÉ dossier: C:\Users\proprietaire\AppData\Roaming\OpenCandy\OpenCandy_87B4B23A26C74D3D87EC1805BADA7045 (Adware.OpenCandy)
TROUVÉ dossier: C:\Users\proprietaire\AppData\Roaming\OpenCandy (Adware.OpenCandy)
TROUVÉ dossier: C:\Program Files (x86)\Software (Adware.Boxore)
TROUVÉ dossier: C:\Windows\Installer\MSI2870.tmp- (Empty)
TROUVÉ dossier: C:\Windows\Installer\MSI3B12.tmp- (Empty)
TROUVÉ dossier: C:\Windows\Installer\MSI4417.tmp- (Empty)
TROUVÉ dossier: C:\Windows\Installer\MSI77B9.tmp- (Empty)
TROUVÉ dossier: C:\Windows\Installer\MSI89C6.tmp- (Empty)
TROUVÉ dossier: C:\Windows\Installer\MSIBFE5.tmp- (Empty)
TROUVÉ dossier: C:\Windows\Installer\MSIE576.tmp- (Empty)
TROUVÉ dossier: C:\Windows\Installer\MSIE62B.tmp- (Empty)
TROUVÉ dossier: C:\Windows\Installer\MSIFD63.tmp- (Empty)


---\\ Base de Registres ( Clés, Valeurs, Données ). (37)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{38bf0831-1cc6-45bc-8e5f-99fd6f860261} [coollncheAp] (Adware.Multiplug)
TROUVÉ clé: [X64] HKLM\Software\Classes\CLSID\{38bf0831-1cc6-45bc-8e5f-99fd6f860261} [coollncheAp] (Adware.Multiplug)
TROUVÉ clé: [X64] HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{38bf0831-1cc6-45bc-8e5f-99fd6f860261} [] (Adware.Multiplug)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ff0021ad-2cc3-4e0d-8e3c-b4153a64a495} [Internet Program] (Adware.InternetProgram)
TROUVÉ clé: HKLM\SYSTEM\CurrentControlSet\Services\KMService [C:\Windows\system32\srvany.exe (Not File)] (Hijacker.Office)
TROUVÉ clé: HKCU\Software\CinemaPlus-3.2cV13.05-nv [] (Heuristic.CrossRider)
TROUVÉ clé: HKCU\Software\CinemaPlus-3.2cV13.05-nv-ie [] (Heuristic.CrossRider)
TROUVÉ clé: HKCU\Software\CrossBrowse-1.4V13.05-nv-ie [] (Heuristic.CrossRider)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110211181110} [] (Adware.CrossRider)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\CinemaPlus-3.2cV13.05-nv [] (Heuristic.CrossRider)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\CinemaPlus-3.2cV13.05-nv-ie [] (Heuristic.CrossRider)
TROUVÉ valeur: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\3D BubbleSound ["C:\Program Files\BubbleSound\3D BubbleSound.exe"] (PUP.BubbleSound)
TROUVÉ valeur: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\\HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\\Application Restart #2 [C:\Users\proprietaire\AppData\Local\Google\Chrome\Application\chrome.exe --flag-switches-begin --flag-switches-end --restore-last-session http://www.portaldosites.com/?utm_source=b&utm_medium=slbnew&from=slbnew&uid=WDCXWD5000BEVT-22A0RT0_WD-WXF1EB03251032510&ts=1368556091] (Hijacker.PortaldoSites)
TROUVÉ valeur: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\HKLM64\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_524 [] (Adware.CrossRider)
TROUVÉ valeur: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\HKLM64\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_526 [] (Adware.CrossRider)
TROUVÉ clé: HKEY_USERS\S-1-5-21-4048187908-1995387496-4212406666-1000\Software\CinemaPlus-3.2cV13.05 [] (Adware.CrossRider)
TROUVÉ clé: HKEY_USERS\S-1-5-21-4048187908-1995387496-4212406666-1000\Software\CinemaPlus-3.2cV13.05-nv [] (Adware.CrossRider)
TROUVÉ clé: HKEY_USERS\S-1-5-21-4048187908-1995387496-4212406666-1000\Software\CinemaPlus-3.2cV13.05-nv-ie [] (Adware.CrossRider)
TROUVÉ clé: HKEY_USERS\S-1-5-21-4048187908-1995387496-4212406666-1000\Software\CrossBrowse-1.4V13.05-nv-ie [] (PUP.CrossBrowse)
TROUVÉ clé: HKEY_USERS\S-1-5-21-4048187908-1995387496-4212406666-1000\Software\Smartbar [] (PUP.QuickShare)
TROUVÉ clé: HKCU\Software\CinemaPlus-3.2cV13.05 [] (Adware.CrossRider)
TROUVÉ clé: HKCU\Software\CinemaPlus-3.2cV13.05-nv [] (Adware.CrossRider)
TROUVÉ clé: HKCU\Software\CinemaPlus-3.2cV13.05-nv-ie [] (Adware.CrossRider)
TROUVÉ clé: HKCU\Software\CrossBrowse-1.4V13.05-nv-ie [] (PUP.CrossBrowse)
TROUVÉ clé: HKCU\Software\Smartbar [] (PUP.QuickShare)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Classes\77zip.exe [] (Adware.InstallBrain)
TROUVÉ clé: [X64] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WebCakeUpdaterService [] (Adware.WebCake)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DuuquUpdate.exe [] (PUP.FrameFox)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\globalupdate.exe [] (PUP.GlobalUpdate)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\CinemaPlus-3.2cV13.05 [] (Adware.CrossRider)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\CinemaPlus-3.2cV13.05-nv [] (Adware.CrossRider)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\CinemaPlus-3.2cV13.05-nv-ie [] (Adware.CrossRider)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Infonaut_1.10.0.14 [] (PUP.Infonaut)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\InternetProgram [] (Adware.InternetProgram)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\CinemaPlus-3.2cV13.05 [Cinema PlusV13.05] (Adware.CrossRider)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage [] (Adware.Downware)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110211181110} [C:\Program Files (x86)\Giant Savings Extension (Not File)] (Adware.CrossRider)


---\\ Bilan de la réparation
~ Aucune réparation effectuée.
~ Ce navigateur est absent (Mozilla Firefox)
~ Ce navigateur est absent (Opera Software)


---\\ Statistiques
~ Items scannés : 64765
~ Items trouvés : 102
~ Items annulés : 0
~ Items réparés : 0


End of clean at 18:21:29
===================
ZHPCleaner-[S]-17052015-18_21_29.txt
0
est -ce que je dois faire nettoyer? ou je laisse tel quel?
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 805
17 mai 2015 à 18:27
Oui fais nettoyer
0
On me propose de redémarrer mon ordinateur. Et qu'un rapport s'affichera au démarrage du système
0
J'ai fait OK mais rien ne s'éteint est ce que je le fait manuellement?
0
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 805
17 mai 2015 à 18:36
oui tu peux
0
voici le rapport

~ ZHPCleaner v2015.5.17.241 by Nicolas Coolman (2015\05\17)
~ Run by proprietaire (Administrator) (17/05/2015 18:39:10)
~ Forum : http://forum.nicolascoolman.fr
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Netttoyer
~ Report : C:\Users\proprietaire\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\proprietaire\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
~ Windows 7, 64-bit Service Pack 1 (Build 7601)


---\\ Service. (0)
~ Aucun élément malicieux trouvé.


---\\ Navigateur internet. (0)
~ Aucun élément malicieux trouvé.


---\\ Fichier hôte. (1)
~ Le fichier hôte est légitime. (34)


---\\ Tâche planifiée. (0)
~ Aucun élément malicieux trouvé.


---\\ Explorateur ( Dossiers, Fichiers ). (6)
DEPLACÉ fichier*: C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_internetprogram-a.akamaihd.net_0.localstorage (PUP.AkamaiHD)
DEPLACÉ fichier*: C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_internetprogram-a.akamaihd.net_0.localstorage-journal (PUP.AkamaiHD)
DEPLACÉ fichier*: C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage (PUP.BoostSaves)
DEPLACÉ fichier*: C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage-journal (PUP.BoostSaves)
DEPLACÉ fichier*: C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage (Adware.PricePeep)
DEPLACÉ fichier*: C:\Users\proprietaire\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.pricepeep00.pricepeep.net_0.localstorage-journal (Adware.PricePeep)


---\\ Base de Registres ( Clés, Valeurs, Données ). (0)
~ Aucun élément malicieux trouvé.


---\\ Bilan de la réparation
~ Réparation réalisée avec succès.
~ Ce navigateur est absent (Mozilla Firefox)
~ Ce navigateur est absent (Opera Software)


---\\ Statistiques
~ Items scannés : 5591
~ Items trouvés : 0
~ Items annulés : 0
~ Items réparés : 6


End of clean at 18:39:21
===================
ZHPCleaner-[R]-17052015-18_30_24.txt
ZHPCleaner-[R]-17052015-18_39_21.txt
ZHPCleaner-[S]-17052015-18_21_29.txt
ZHPCleaner-[S]-17052015-18_38_50.txt
0
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 805
17 mai 2015 à 18:50
y a t-il du mieux?
0
Non pas de changement j'ai toujours plein de petite fenêtre qui s'ouvre avec comme signature "internet program ads" yen a 6
0
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 805
17 mai 2015 à 18:59
Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage,


0
Sayer mais rien n'y fait :(
Par contre quand j'utilise internet explorer pas de soucis.

Et j'ai ce soucis depuis que j'ai réinstaller Google Chrome peut être ai je pas prit un telechargement fiable
0
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 805
17 mai 2015 à 19:24
désinstalle le et réinstalle le
0
C'est que je vient de faire et tout va pour le mieux pour le moment mais bon merci. En tout cas je vous est monopolisé votre après midi c'est cool merci Beaucoup
0
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 805
17 mai 2015 à 19:53
refais frst
0
Je n'avais pas vu ton msg je le ferai demain vers 18h je mettrais le rapport :)
0
Pinguguss Messages postés 50 Date d'inscription samedi 16 mai 2015 Statut Membre Dernière intervention 3 juillet 2023 1
16 mai 2015 à 18:27
Bonjour,

Quelques hypothèses avec leurs solutions:
1 - Regarde dans tes modules complémentaires/extensions. Si tu trouves un nom bizarre, désactive l'extension, et supprime-la.
2 - Un logiciel espion (adware) peut s'être introduit dans ton PC. Utilise Windows Defender (gratuit) pour le déceler et l'exterminer.
3 - Un coup de Ccleaner pour nettoyer le registre et les fichiers superflus si nécessaire.
4 - Si tu sais ce que tu fais, regarde dans le dossier Programmes. Si tu tombes sur un dossier bizarre datant du moment où ces pubs sont apparues, c'est que c'est lui le fautif ! Supprime-le, et puis hop !
-1
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023 3 805
16 mai 2015 à 18:29
windows defender n'y fera rien du tout ni même ccleaner
0
Paul.W Messages postés 71 Date d'inscription jeudi 8 mai 2014 Statut Membre Dernière intervention 30 juillet 2017 1 > lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 18 septembre 2023
16 mai 2015 à 18:30
Par contre AdwCleaner si.
0
Pinguguss Messages postés 50 Date d'inscription samedi 16 mai 2015 Statut Membre Dernière intervention 3 juillet 2023 1
16 mai 2015 à 19:38
AdwCleaner, je l'avais utilisé il y a quelques temps, mais pour un autre problème de pub: sur certains sites, j'étais redirigé vers un site douteux qui me demandait de mettre à jour Flash Player.
J'aurais proposé ça, mais comme recours ultime.
0
Paul.W Messages postés 71 Date d'inscription jeudi 8 mai 2014 Statut Membre Dernière intervention 30 juillet 2017 1 > Pinguguss Messages postés 50 Date d'inscription samedi 16 mai 2015 Statut Membre Dernière intervention 3 juillet 2023
16 mai 2015 à 20:29
C'est normal si c'est sur certain site , car le createur du site le monetise.
0
Salut,
Pinguguss, j'ai supprimer tout programe bizarre mais rien a changer. Avast (mon antivirus ) n'a rien détécté :/
0