Supprimer PUP.Optional.PlusHD.A
Messages postés
Date d'inscription
mercredi 19 février 2014
Dernière intervention
19 février 2014
Modifié par Malekal_morte- le 19/02/2014 à 11:00
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 - 3 mars 2014 à 17:50
9 réponses
Messages postés
Date d'inscription
mercredi 17 mai 2006
Modérateur, Contributeur sécurité
Dernière intervention
15 décembre 2020
24 666
"Aucune action effectuée.
Sur le scan, clic droit puis cocher tout
puis bouton supprimer selection pour tout supprimer
ensuite :
Tu as installé des adwares et programmes parasites sur ton PC.
Voici la procédure à suivre pour les supprimer :
Un nettoyage AdwCleaner (environ 10/15min) :
Suis ce tutorial AdwCleaner ( d'Xplode ) sur ton bureau.
Vas sur le lien, télécharge AdwCleaner comme indiqué.
Lance AdwCleaner, clique sur [Scanner].
Le scan peux durer plusieurs minutes, patienter.
Une fois le scan terminé, clique sur [Nettoyer]
Une fois le nettoyage terminé, un rapport s'ouvrira. Copie/colle le contenu du rapport dans ta prochaine réponse par un copier/coller.
Si cela ne fonctionne pas, utilise le site pour héberger le rapport, donne le lien du rapport dans un nouveau message.
Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt
puis réinitialise tes navigateurs (5min):
Réinitialise tes navigateurs :
* Firefox :
* Google Chrome :
Faire un Scan OTL - Temps : Environ 40min
OTL permet de diagnostiquer les programmes qui tournent et déceler des infections - Le programme va générer deux rapports OTL.txt et Extras.txt
Fournir les deux rapports :
Tu peux suivre les indications de cette page pour t'aider :
* Télécharge sur ton bureau.
(Sous Vista/Win7, il faut cliquer droit sur OTL et choisir Exécuter en tant qu'administrateur)
Dans le cas d'Avast!, ne pas lancer le programme dans la Sandbox (voir lien d'aide ci-dessus).
* Lance OTL
* En haut à droite de Analyse rapide, coche "tous les utilisateurs"
* Clique sur le bouton Analyse.
**** Si durant le scan - OTL ne répond pas, ne touche à rien et laisse le scan se poursuivre ****
* Quand le scan est fini, utilise le site pour envoyer le rapport OTL.txt (et Extra.txt si présent).
Donne le ou les liens pjjoint qui pointent vers ces rapports ici dans une réponse.
Je répète : donne le lien du rapport pjjoint ici en réponse.
Messages postés
Date d'inscription
mercredi 19 février 2014
Dernière intervention
19 février 2014
19 févr. 2014 à 14:47
Désole, j'avais omis de nettoyer avant. voici le rapport de adware
# AdwCleaner v3.019 - Rapport créé le 19/02/2014 à 14:42:52
# Mis à jour le 17/02/2014 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : Audrey - AUDREY-HP
# Exécuté depuis : C:\Users\Audrey\Downloads\adwcleaner.exe
# Option : Scanner
***** [ Services ] *****
***** [ Fichiers / Dossiers ] *****
***** [ Raccourcis ] *****
***** [ Registre ] *****
***** [ Navigateurs ] *****
-\\ Internet Explorer v11.0.9600.16518
-\\ Google Chrome v
[ Fichier : C:\Users\Audrey\AppData\Local\Google\Chrome\User Data\Default\preferences ]
AdwCleaner[R0].txt - [15940 octets] - [19/02/2014 09:48:07]
AdwCleaner[R1].txt - [7866 octets] - [19/02/2014 11:09:37]
AdwCleaner[R2].txt - [973 octets] - [19/02/2014 12:33:57]
AdwCleaner[R3].txt - [834 octets] - [19/02/2014 14:42:52]
AdwCleaner[S0].txt - [7070 octets] - [19/02/2014 11:13:38]
########## EOF - C:\AdwCleaner\AdwCleaner[R3].txt - [953 octets] ##########
Messages postés
Date d'inscription
mercredi 19 février 2014
Dernière intervention
19 février 2014
19 févr. 2014 à 15:07
rapport de OTL, c'est du chinois pour moi§§§§
Merci de ton aide HFT
OTL logfile created on: 19/02/2014 14:51:37 - Run 1
OTL by OldTimer - Version Folder = C:\Users\Audrey\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16518)
Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy
3,75 Gb Total Physical Memory | 2,56 Gb Available Physical Memory | 68,40% Memory free
7,50 Gb Paging File | 5,78 Gb Available in Paging File | 77,16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 920,36 Gb Total Space | 817,10 Gb Free Space | 88,78% Space Free | Partition Type: NTFS
Drive D: | 11,05 Gb Total Space | 1,13 Gb Free Space | 10,20% Space Free | Partition Type: NTFS
Computer Name: AUDREY-HP | User Name: Audrey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========/color
PRC - [2014/02/19 14:50:19 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Audrey\Downloads\OTL.exe
PRC - [2014/02/14 03:01:55 | 003,767,096 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014/02/14 03:01:54 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2013/12/21 07:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2010/04/23 20:00:00 | 000,514,232 | ---- | M] (EasyBits Software AS) -- C:\Windows\SysWOW64\ezSharedSvcHost.exe
PRC - [2010/02/04 05:05:54 | 000,660,136 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe
PRC - [2010/02/04 05:05:52 | 000,025,256 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnmsdmon.exe
PRC - [2009/12/02 21:23:38 | 000,209,768 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2009/12/02 21:23:32 | 000,483,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2009/10/14 23:53:20 | 000,635,416 | ---- | M] (PDF Complete Inc) -- C:\Program Files (x86)\PDF Complete\pdfsvc.exe
PRC - [2008/11/20 18:47:28 | 000,062,768 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
[color=#E56717]========== Modules (No Company Name) ==========/color
MOD - [2014/02/14 03:30:46 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\8bc548587e91ecf0552a40e47bbf99cc\
MOD - [2014/02/14 03:30:41 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5c24d3b0041ebf4f48a93615b9fa3de9\
MOD - [2014/02/14 03:30:36 | 005,464,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\217ece46920546d718414291d463bb1c\
MOD - [2014/02/14 03:30:33 | 000,978,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\5b6ddf934128d538cd5cd77bf4209b93\
MOD - [2014/02/14 03:30:20 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\b3a78269847005365001c33870cd121f\
MOD - [2014/02/14 03:30:15 | 011,499,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ede2c6c842840e009f01bcc74fa4c457\
MOD - [2013/12/03 10:07:03 | 019,336,120 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2010/11/13 01:54:34 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\\mscorlib.resources.dll
MOD - [2010/02/04 05:05:54 | 000,660,136 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe
MOD - [2010/02/04 05:05:52 | 000,025,256 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnmsdmon.exe
MOD - [2010/02/03 06:21:47 | 000,036,864 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\app4r.monitor.core.dll
MOD - [2010/02/03 06:21:47 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\app4r.monitor.common.dll
MOD - [2010/02/03 06:20:51 | 000,065,536 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\app4r.devmons.mcmdevmon.dll
MOD - [2009/07/23 16:49:04 | 000,782,336 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdndrs.dll
MOD - [2009/07/23 16:48:28 | 000,380,928 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdnscw.dll
MOD - [2009/06/26 10:17:07 | 000,012,288 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\app4r.devmons.mcmdevmon.autoplayutil.dll
MOD - [2009/05/14 10:46:40 | 000,081,920 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdncaps.dll
MOD - [2007/10/02 11:51:09 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdncnv4.dll
MOD - [2007/05/29 04:39:08 | 000,589,824 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdndatr.dll
MOD - [2007/03/26 04:39:35 | 000,073,728 | ---- | M] () -- C:\Program Files (x86)\Lexmark 2600 Series\lxdncats.dll
[color=#E56717]========== Services (SafeList) ==========/color
SRV:[b]64bit:/b - [2014/02/14 03:01:54 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:[b]64bit:/b - [2014/02/06 11:48:45 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:/b - [2013/05/27 06:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV:[b]64bit:/b - [2010/02/02 00:17:12 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:[b]64bit:/b - [2009/04/28 06:58:52 | 000,029,184 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysNative\spool\DRIVERS\x64\3\\lxdnserv.exe -- (lxdnCATSCustConnectService)
SRV:[b]64bit:/b - [2007/11/28 11:51:42 | 001,039,872 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysNative\lxdncoms.exe -- (lxdn_device)
SRV - [2014/02/05 13:01:32 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/12/21 07:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/09/11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/06/20 18:24:18 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2010/04/04 00:01:24 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2009/12/02 21:23:38 | 000,209,768 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2009/12/02 21:23:32 | 000,483,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2009/10/14 23:53:20 | 000,635,416 | ---- | M] (PDF Complete Inc) [Auto | Running] -- C:\Program Files (x86)\PDF Complete\pdfsvc.exe -- (pdfcDispatcher)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/04/28 06:58:52 | 000,029,184 | ---- | M] () [Auto | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\\lxdnserv.exe -- (lxdnCATSCustConnectService)
SRV - [2007/11/28 11:12:40 | 000,589,824 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysWOW64\lxdncoms.exe -- (lxdn_device)
[color=#E56717]========== Driver Services (SafeList) ==========/color
DRV:[b]64bit:/b - [2014/02/14 03:02:00 | 000,080,184 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\aswstm.sys -- (aswStm)
DRV:[b]64bit:/b - [2014/02/14 03:01:59 | 001,038,072 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:[b]64bit:/b - [2014/02/14 03:01:59 | 000,421,704 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:[b]64bit:/b - [2014/02/14 03:01:59 | 000,078,648 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:[b]64bit:/b - [2013/12/27 15:11:22 | 000,207,904 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:[b]64bit:/b - [2013/12/03 10:07:05 | 000,092,544 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:[b]64bit:/b - [2013/12/03 10:07:05 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:[b]64bit:/b - [2013/04/04 14:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:[b]64bit:/b - [2012/08/23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:/b - [2012/08/23 15:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:/b - [2012/05/11 06:34:14 | 000,203,320 | ---- | M] (DEVGURU Co., LTD.( [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:[b]64bit:/b - [2012/05/11 06:34:12 | 000,099,384 | ---- | M] (DEVGURU Co., LTD.( [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:[b]64bit:/b - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:/b - [2010/11/20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:/b - [2010/07/08 14:18:38 | 000,694,888 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL8192su.sys -- (RTL8192su)
DRV:[b]64bit:/b - [2010/04/09 00:12:00 | 000,243,744 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:[b]64bit:/b - [2010/03/10 01:33:52 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie64.sys -- (AtiPcie)
DRV:[b]64bit:/b - [2010/03/04 14:43:00 | 000,346,144 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:[b]64bit:/b - [2010/02/02 00:55:20 | 006,366,720 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atipmdag.sys -- (amdkmdag)
DRV:[b]64bit:/b - [2010/02/01 23:24:00 | 000,186,880 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:[b]64bit:/b - [2009/12/21 19:26:36 | 000,038,456 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:[b]64bit:/b - [2009/12/02 21:23:38 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:[b]64bit:/b - [2009/12/02 21:23:34 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:[b]64bit:/b - [2009/12/02 21:23:32 | 000,269,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:[b]64bit:/b - [2009/12/02 21:23:26 | 000,721,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:[b]64bit:/b - [2009/10/23 09:26:14 | 000,046,592 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor)
DRV:[b]64bit:/b - [2009/10/08 01:13:34 | 000,070,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:/b - [2009/10/08 01:13:34 | 000,028,728 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:/b - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:/b - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:/b - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:/b - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:/b - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:/b - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:/b - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:[b]64bit:/b - [2007/05/14 16:06:18 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys -- (RimUsb)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
[color=#E56717]========== Standard Registry (SafeList) ==========/color
[color=#E56717]========== Internet Explorer ==========/color
IE:[b]64bit:/b - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE:[b]64bit:/b - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:[b]64bit:/b - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" ={searchTerms}&{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE:[b]64bit:/b - HKLM\..\SearchScopes\{83475DD4-638D-44B9-B8EB-6A8D30C6EED9}: "URL" ={searchTerms}
IE:[b]64bit:/b - HKLM\..\SearchScopes\{876B8792-1EAC-44E2-B35F-5CF241A6055D}: "URL" ={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CPDTDF
IE:[b]64bit:/b - HKLM\..\SearchScopes\{8DBCCA26-318D-4D80-97BB-0985D1CD084D}: "URL" ={searchTerms}&form=CPDTDF&pc=CPDTDF&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" ={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" ={searchTerms}&{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{83475DD4-638D-44B9-B8EB-6A8D30C6EED9}: "URL" ={searchTerms}
IE - HKLM\..\SearchScopes\{876B8792-1EAC-44E2-B35F-5CF241A6055D}: "URL" ={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CPDTDF
IE - HKLM\..\SearchScopes\{8DBCCA26-318D-4D80-97BB-0985D1CD084D}: "URL" ={searchTerms}&form=CPDTDF&pc=CPDTDF&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{acbd5593-e5ee-4c15-b48f-1823ce819dec}: "URL" =^ZU^xpt175^S05673^fr&si=CNGPgbzsuLcCFUfKtAodyyYAnQ&ptb=717EE340-C2D0-46C0-B7B1-36963BCD3C32&ind=2013052808&n=77fcbf88&psa=&st=sb&searchfor={searchTerms}
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page =
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\..\SearchScopes\{83475DD4-638D-44B9-B8EB-6A8D30C6EED9}: "URL" ={searchTerms}
IE - HKU\.DEFAULT\..\SearchScopes\{876B8792-1EAC-44E2-B35F-5CF241A6055D}: "URL" ={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CPDTDF
IE - HKU\.DEFAULT\..\SearchScopes\{8DBCCA26-318D-4D80-97BB-0985D1CD084D}: "URL" ={searchTerms}&form=CPDTDF&pc=CPDTDF&src=IE-SearchBox
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page =
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\..\SearchScopes\{83475DD4-638D-44B9-B8EB-6A8D30C6EED9}: "URL" ={searchTerms}
IE - HKU\S-1-5-18\..\SearchScopes\{876B8792-1EAC-44E2-B35F-5CF241A6055D}: "URL" ={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CPDTDF
IE - HKU\S-1-5-18\..\SearchScopes\{8DBCCA26-318D-4D80-97BB-0985D1CD084D}: "URL" ={searchTerms}&form=CPDTDF&pc=CPDTDF&src=IE-SearchBox
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2327108792-3824882524-3925735962-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
IE - HKU\S-1-5-21-2327108792-3824882524-3925735962-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-2327108792-3824882524-3925735962-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-2327108792-3824882524-3925735962-1000\..\SearchScopes,DefaultScope = {acbd5593-e5ee-4c15-b48f-1823ce819dec}
IE - HKU\S-1-5-21-2327108792-3824882524-3925735962-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" ={searchTerms}&{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_frFR461
IE - HKU\S-1-5-21-2327108792-3824882524-3925735962-1000\..\SearchScopes\{acbd5593-e5ee-4c15-b48f-1823ce819dec}: "URL" ={searchTerms}&a=tele1202&cd=2XzuyEtN2Y1L1QzuyBzz0A0C0CtD0Bzy0DtCyEzztByE0DtBtN0D0Tzu0SyBtByBtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=648652757&ir=
IE - HKU\S-1-5-21-2327108792-3824882524-3925735962-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========/color
FF:[b]64bit:/b - HKLM\Software\MozillaPlugins\ C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll File not found
FF:[b]64bit:/b - HKLM\Software\MozillaPlugins\ disabled File not found
FF:[b]64bit:/b - HKLM\Software\MozillaPlugins\,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\ C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF - HKLM\Software\MozillaPlugins\ disabled File not found
FF - HKLM\Software\MozillaPlugins\,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\ Update;version=3: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\ Update;version=9: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\,version=2.0.7: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013/06/26 19:21:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
[2013/06/26 19:22:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Audrey\AppData\Roaming\mozilla\Extensions
[2013/05/07 13:18:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[color=#E56717]========== Chrome ==========/color
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage:
CHR - Extension: No name found = C:\Users\Audrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: No name found = C:\Users\Audrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Audrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2005.45_0\
CHR - Extension: No name found = C:\Users\Audrey\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\\
O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:/b - BHO: (Plus-HD-3.5) - {11111111-1111-1111-1111-110311711180} - C:\Program Files (x86)\Plus-HD-3.5\Plus-HD-3.5-bho64.dll File not found
O2:[b]64bit:/b - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:[b]64bit:/b - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:[b]64bit:/b - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No CLSID value found.
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:[b]64bit:/b - HKLM\..\Toolbar: (no name) - !{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O3:[b]64bit:/b - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:[b]64bit:/b - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:[b]64bit:/b - HKLM\..\Toolbar: (avast! Online Security) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:[b]64bit:/b - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (avast! Online Security) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:[b]64bit:/b - HKU\S-1-5-21-2327108792-3824882524-3925735962-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:[b]64bit:/b - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4:[b]64bit:/b - HKLM..\Run: [lxdnamon] C:\Program Files (x86)\Lexmark 2600 Series\lxdnamon.exe ()
O4:[b]64bit:/b - HKLM..\Run: [lxdnmon.exe] C:\Program Files (x86)\Lexmark 2600 Series\lxdnmon.exe ()
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [FaxCenterServer] C:\Program Files (x86)\Lexmark Fax Solutions\fm3032.exe ()
O4 - HKLM..\Run: [Magic Desktop for HP notification] C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe (Easybits)
O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2327108792-3824882524-3925735962-1000..\Run: [CCleaner] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13[b]64bit:/b - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5268184B-D44A-4EDF-BDE9-392884FAE59C}: DhcpNameServer =
O18:[b]64bit:/b - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:/b - Protocol\Handler\msdaipp - No CLSID value found
O18:[b]64bit:/b - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:[b]64bit:/b - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:[b]64bit:/b - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:/b - Protocol\Handler\mso-offdap - No CLSID value found
O18:[b]64bit:/b - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:[b]64bit:/b - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:/b - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18:[b]64bit:/b - Protocol\Filter\text/xml - No CLSID value found
O20:[b]64bit:/b - AppInit_DLLs: (c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll) - File not found
O20:[b]64bit:/b - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:/b - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:/b - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:/b - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:/b - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:/b - HKLM\ [@ = comfile] -- "%1" %*
O37:[b]64bit:/b - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\ [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========/color
[2014/02/19 14:27:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
[2014/02/19 14:27:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ZHPDiag
[2014/02/19 14:27:37 | 000,000,000 | ---D | C] -- C:\Users\Audrey\AppData\Roaming\ZHP
[2014/02/19 09:08:09 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/02/19 09:08:01 | 000,000,000 | ---D | C] -- C:\Users\Audrey\AppData\Roaming\Malwarebytes
[2014/02/19 09:07:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2014/02/19 09:07:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/02/19 09:07:57 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014/02/19 09:07:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2014/02/14 03:02:15 | 000,548,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014/02/14 03:01:18 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014/02/14 03:01:17 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014/02/14 03:01:17 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014/02/14 03:01:16 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014/02/14 03:01:16 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014/02/14 03:01:16 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014/02/14 03:01:16 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014/02/14 03:01:15 | 000,627,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014/02/14 03:01:14 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014/02/14 03:01:14 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014/02/14 03:01:14 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014/02/14 03:01:14 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014/02/14 03:01:14 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014/02/14 03:01:13 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014/02/14 03:01:13 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014/02/14 03:01:13 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014/02/14 03:01:12 | 000,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014/02/14 03:01:12 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014/02/14 03:01:12 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014/02/14 03:01:11 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014/02/14 03:01:08 | 002,041,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014/02/14 03:01:08 | 001,964,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014/02/14 03:01:05 | 005,768,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014/02/13 07:41:32 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll
[2014/02/13 07:41:32 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll
[2014/02/13 07:41:24 | 000,658,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_isv.exe
[2014/02/13 07:41:24 | 000,626,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate.exe
[2014/02/13 07:41:24 | 000,594,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_isv.exe
[2014/02/13 07:41:24 | 000,572,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate.exe
[2014/02/13 07:41:24 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2014/02/13 07:41:24 | 000,508,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2014/02/13 07:41:23 | 000,553,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp.exe
[2014/02/13 07:41:23 | 000,528,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdrm.dll
[2014/02/13 07:41:23 | 000,510,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp.exe
[2014/02/13 07:41:23 | 000,488,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc.dll
[2014/02/13 07:41:23 | 000,485,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_isv.dll
[2014/02/13 07:41:23 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll
[2014/02/13 07:41:23 | 000,423,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_isv.dll
[2014/02/13 07:41:23 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp_isv.dll
[2014/02/13 07:41:23 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp.dll
[2014/02/13 07:41:23 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp_isv.dll
[2014/02/13 07:41:23 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp.dll
[2014/02/13 07:41:20 | 002,565,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2014/02/13 07:41:19 | 003,928,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2014/02/05 07:36:04 | 003,544,968 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2014/01/25 15:42:17 | 000,000,000 | ---D | C] -- C:\Users\Audrey\AppData\Local\Programs
[2012/06/22 16:47:50 | 004,734,976 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\vfp9r.dll
[2012/06/22 16:47:50 | 003,907,584 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\vfp9t.dll
[2012/06/22 16:47:50 | 001,228,800 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\vfp9rfra.dll
[2012/06/22 16:47:50 | 001,187,840 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\VFP9RENU.DLL
[2004/05/04 20:53:40 | 001,645,320 | R--- | C] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\gdiplus.dll
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========/color
[2014/02/19 14:33:28 | 000,018,736 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/02/19 14:33:28 | 000,018,736 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/02/19 14:31:00 | 000,000,512 | ---- | M] () -- C:\PhysicalDisk0_MBR.bin
[2014/02/19 14:28:00 | 000,001,068 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/02/19 14:27:39 | 000,001,997 | ---- | M] () -- C:\Users\Audrey\Desktop\ZHPFix.lnk
[2014/02/19 14:27:39 | 000,001,870 | ---- | M] () -- C:\Users\Audrey\Desktop\ZHPDiag.lnk
[2014/02/19 14:21:35 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/02/19 14:21:34 | 000,000,296 | ---- | M] () -- C:\Windows\tasks\Digital Sites.job
[2014/02/19 14:21:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/02/19 12:32:55 | 000,001,064 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/02/19 11:19:01 | 001,671,168 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/02/19 11:19:01 | 000,748,104 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat
[2014/02/19 11:19:01 | 000,654,714 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/02/19 11:19:01 | 000,150,370 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat
[2014/02/19 11:19:01 | 000,122,328 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/02/19 11:14:21 | 3019,333,632 | -HS- | M] () -- C:\hiberfil.sys
[2014/02/19 09:18:02 | 000,000,175 | ---- | M] () -- C:\Users\Audrey\AppData\Roaming\WB.CFG
[2014/02/19 09:07:59 | 000,001,119 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/02/14 03:03:58 | 001,645,300 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014/02/14 03:02:24 | 000,001,972 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2014/02/14 03:02:00 | 000,080,184 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswstm.sys
[2014/02/14 03:01:59 | 001,038,072 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2014/02/14 03:01:59 | 000,421,704 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2014/02/14 03:01:59 | 000,334,136 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2014/02/14 03:01:59 | 000,078,648 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2014/02/14 03:01:59 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2014/02/13 11:32:31 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForAUDREY-HP$.job
[2014/02/10 10:21:43 | 000,133,666 | ---- | M] () -- C:\Users\Audrey\Documents\Brochure_VAP_Officier.pdf
[2014/02/10 10:02:27 | 000,406,974 | ---- | M] () -- C:\Users\Audrey\Documents\2013-07-comment-devenir-officier-concours-interne.pdf
[2014/02/10 10:02:24 | 000,620,077 | ---- | M] () -- C:\Users\Audrey\Documents\2013-07-comment-devenir-officier-concours-externe.pdf
[2014/02/10 10:00:48 | 000,047,932 | ---- | M] () -- C:\Users\Audrey\Documents\2007-2013-annales-officier-int-dissertation-culture-genarale.pdf
[2014/02/10 10:00:42 | 003,732,501 | ---- | M] () -- C:\Users\Audrey\Documents\2012-annales-officier-int-note-synthese.pdf
[2014/02/10 10:00:36 | 003,375,432 | ---- | M] () -- C:\Users\Audrey\Documents\2013-annales-officier-int-note-synthese.pdf
[2014/02/10 10:00:25 | 000,118,929 | ---- | M] () -- C:\Users\Audrey\Documents\2012-etude-de-cas-vap-officier.pdf
[2014/02/10 10:00:19 | 000,107,899 | ---- | M] () -- C:\Users\Audrey\Documents\2013-etude-de-cas-vap-officier.pdf
[2014/02/10 09:59:34 | 000,054,999 | ---- | M] () -- C:\Users\Audrey\Documents\2013-annales-commissaire-vap-2006-2013.pdf
[2014/02/10 09:59:08 | 000,113,366 | ---- | M] () -- C:\Users\Audrey\Documents\2012-vap-officier1.pdf
[2014/02/10 09:58:42 | 000,300,287 | ---- | M] () -- C:\Users\Audrey\Documents\2013-officier-admis-internes.pdf
[2014/02/10 09:58:28 | 000,337,164 | ---- | M] () -- C:\Users\Audrey\Documents\2013-officier-admis-vap.pdf
[2014/02/06 12:30:12 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014/02/06 12:07:39 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014/02/06 12:06:47 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014/02/06 11:56:03 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014/02/06 11:52:11 | 000,574,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014/02/06 11:49:03 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014/02/06 11:48:45 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014/02/06 11:48:11 | 000,708,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014/02/06 11:32:49 | 000,218,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014/02/06 11:17:15 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014/02/06 11:11:37 | 005,768,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014/02/06 11:01:36 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014/02/06 11:00:46 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014/02/06 10:57:13 | 000,627,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014/02/06 10:52:21 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014/02/06 10:50:32 | 002,041,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014/02/06 10:49:22 | 000,440,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014/02/06 10:47:22 | 000,112,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014/02/06 10:46:27 | 000,553,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014/02/06 10:25:43 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014/02/06 10:09:30 | 001,964,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014/02/06 09:40:06 | 000,817,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014/02/06 09:34:31 | 000,703,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014/02/05 13:01:32 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014/02/05 13:01:31 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2014/02/05 13:01:30 | 003,544,968 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2014/01/30 14:46:40 | 000,000,005 | ---- | M] () -- C:\Users\Audrey\AppData\Roaming\WBPU-TTL.DAT
[2014/01/28 08:11:55 | 000,555,997 | ---- | M] () -- C:\Users\Audrey\Documents\50320004132043626211412511000574carrefour.pdf
[2014/01/26 18:59:22 | 000,000,336 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForAudrey.job
[2014/01/25 15:43:32 | 000,001,093 | ---- | M] () -- C:\Users\Audrey\Desktop\Video Performer.lnk
[2014/01/21 15:23:36 | 000,188,450 | ---- | M] () -- C:\Users\Audrey\Documents\recapitulatif_dossier_178929 journée de la femme ce clienteles.pdf
[2014/01/21 15:23:03 | 000,190,346 | ---- | M] () -- C:\Users\Audrey\Documents\DOSSIER_210114.032230 journée de la femme ce clienteles.pdf
[2014/01/21 15:15:34 | 000,117,255 | ---- | M] () -- C:\Users\Audrey\Documents\Ch1+NbRel.pdf
[2014/01/21 15:15:13 | 000,223,291 | ---- | M] () -- C:\Users\Audrey\Documents\Ch2+EgalPyth.pdf
[2014/01/21 15:14:49 | 000,109,187 | ---- | M] () -- C:\Users\Audrey\Documents\Ch3+EcritFract.pdf
[2014/01/21 15:14:11 | 000,198,124 | ---- | M] () -- C:\Users\Audrey\Documents\Ch4+TrRect.pdf
[2014/01/21 15:13:22 | 000,138,234 | ---- | M] () -- C:\Users\Audrey\Documents\Ch5+CalcLitt.pdf
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========/color
[2014/02/19 14:31:00 | 000,000,512 | ---- | C] () -- C:\PhysicalDisk0_MBR.bin
[2014/02/19 14:27:39 | 000,001,997 | ---- | C] () -- C:\Users\Audrey\Desktop\ZHPFix.lnk
[2014/02/19 14:27:39 | 000,001,870 | ---- | C] () -- C:\Users\Audrey\Desktop\ZHPDiag.lnk
[2014/02/19 09:07:59 | 000,001,119 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/02/14 03:00:34 | 000,000,296 | ---- | C] () -- C:\Windows\tasks\Digital Sites.job
[2014/02/10 10:21:43 | 000,133,666 | ---- | C] () -- C:\Users\Audrey\Documents\Brochure_VAP_Officier.pdf
[2014/02/10 10:02:17 | 000,406,974 | ---- | C] () -- C:\Users\Audrey\Documents\2013-07-comment-devenir-officier-concours-interne.pdf
[2014/02/10 10:02:08 | 000,620,077 | ---- | C] () -- C:\Users\Audrey\Documents\2013-07-comment-devenir-officier-concours-externe.pdf
[2014/02/10 10:00:48 | 000,047,932 | ---- | C] () -- C:\Users\Audrey\Documents\2007-2013-annales-officier-int-dissertation-culture-genarale.pdf
[2014/02/10 10:00:42 | 003,732,501 | ---- | C] () -- C:\Users\Audrey\Documents\2012-annales-officier-int-note-synthese.pdf
[2014/02/10 10:00:35 | 003,375,432 | ---- | C] () -- C:\Users\Audrey\Documents\2013-annales-officier-int-note-synthese.pdf
[2014/02/10 10:00:25 | 000,118,929 | ---- | C] () -- C:\Users\Audrey\Documents\2012-etude-de-cas-vap-officier.pdf
[2014/02/10 10:00:19 | 000,107,899 | ---- | C] () -- C:\Users\Audrey\Documents\2013-etude-de-cas-vap-officier.pdf
[2014/02/10 09:59:34 | 000,054,999 | ---- | C] () -- C:\Users\Audrey\Documents\2013-annales-commissaire-vap-2006-2013.pdf
[2014/02/10 09:59:08 | 000,113,366 | ---- | C] () -- C:\Users\Audrey\Documents\2012-vap-officier1.pdf
[2014/02/10 09:58:42 | 000,300,287 | ---- | C] () -- C:\Users\Audrey\Documents\2013-officier-admis-internes.pdf
[2014/02/10 09:58:28 | 000,337,164 | ---- | C] () -- C:\Users\Audrey\Documents\2013-officier-admis-vap.pdf
[2014/01/28 08:11:55 | 000,555,997 | ---- | C] () -- C:\Users\Audrey\Documents\50320004132043626211412511000574carrefour.pdf
[2014/01/25 15:43:32 | 000,001,093 | ---- | C] () -- C:\Users\Audrey\Desktop\Video Performer.lnk
[2014/01/21 15:23:36 | 000,188,450 | ---- | C] () -- C:\Users\Audrey\Documents\recapitulatif_dossier_178929 journée de la femme ce clienteles.pdf
[2014/01/21 15:23:03 | 000,190,346 | ---- | C] () -- C:\Users\Audrey\Documents\DOSSIER_210114.032230 journée de la femme ce clienteles.pdf
[2014/01/21 15:15:34 | 000,117,255 | ---- | C] () -- C:\Users\Audrey\Documents\Ch1+NbRel.pdf
[2014/01/21 15:15:13 | 000,223,291 | ---- | C] () -- C:\Users\Audrey\Documents\Ch2+EgalPyth.pdf
[2014/01/21 15:14:49 | 000,109,187 | ---- | C] () -- C:\Users\Audrey\Documents\Ch3+EcritFract.pdf
[2014/01/21 15:14:11 | 000,198,124 | ---- | C] () -- C:\Users\Audrey\Documents\Ch4+TrRect.pdf
[2014/01/21 15:13:22 | 000,138,234 | ---- | C] () -- C:\Users\Audrey\Documents\Ch5+CalcLitt.pdf
[2013/12/31 09:53:57 | 000,000,005 | ---- | C] () -- C:\Users\Audrey\AppData\Roaming\WBPU-Q5-TTL.DAT
[2013/09/23 06:22:10 | 000,000,175 | ---- | C] () -- C:\Users\Audrey\AppData\Roaming\WB.CFG
[2013/09/23 06:22:10 | 000,000,005 | ---- | C] () -- C:\Users\Audrey\AppData\Roaming\WBPU-TTL.DAT
[2013/06/25 21:40:43 | 000,038,449 | ---- | C] () -- C:\Users\Audrey\AppData\Roaming\Valeurs séparées par des virgules (Windows).ADR
[2012/08/03 07:42:31 | 000,000,023 | ---- | C] () -- C:\Users\Audrey\intlname.ols
[2012/02/10 11:36:57 | 000,003,584 | ---- | C] () -- C:\Users\Audrey\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/29 09:03:25 | 000,001,854 | ---- | C] () -- C:\Users\Audrey\AppData\Roaming\GhostObjGAFix.xml
[color=#E56717]========== ZeroAccess Check ==========/color
[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/07/26 03:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 02:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report >
[2014/02/06 10:09:30 | 001,964,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014/02/06 09:40:06 | 000,817,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014/02/06 09:34:31 | 000,703,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014/02/05 13:01:32 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014/02/05 13:01:31 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2014/02/05 13:01:30 | 003,544,968 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2014/01/30 14:46:40 | 000,000,005 | ---- | M] () -- C:\Users\Audrey\AppData\Roaming\WBPU-TTL.DAT
[2014/01/28 08:11:55 | 000,555,997 | ---- | M] () -- C:\Users\Audrey\Documents\50320004132043626211412511000574carrefour.pdf
[2014/01/26 18:59:22 | 000,000,336 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForAudrey.job
[2014/01/25 15:43:32 | 000,001,093 | ---- | M] () -- C:\Users\Audrey\Desktop\Video Performer.lnk
[2014/01/21 15:23:36 | 000,188,450 | ---- | M] () -- C:\Users\Audrey\Documents\recapitulatif_dossier_178929 journée de la femme ce clienteles.pdf
[2014/01/21 15:23:03 | 000,190,346 | ---- | M] () -- C:\Users\Audrey\Documents\DOSSIER_210114.032230 journée de la femme ce clienteles.pdf
[2014/01/21 15:15:34 | 000,117,255 | ---- | M] () -- C:\Users\Audrey\Documents\Ch1+NbRel.pdf
[2014/01/21 15:15:13 | 000,223,291 | ---- | M] () -- C:\Users\Audrey\Documents\Ch2+EgalPyth.pdf
[2014/01/21 15:14:49 | 000,109,187 | ---- | M] () -- C:\Users\Audrey\Documents\Ch3+EcritFract.pdf
[2014/01/21 15:14:11 | 000,198,124 | ---- | M] () -- C:\Users\Audrey\Documents\Ch4+TrRect.pdf
[2014/01/21 15:13:22 | 000,138,234 | ---- | M] () -- C:\Users\Audrey\Documents\Ch5+CalcLitt.pdf
[color=#E56717]========== Files Created - No Company Name ==========/color
[2014/02/19 14:31:00 | 000,000,512 | ---- | C] () -- C:\PhysicalDisk0_MBR.bin
[2014/02/19 14:27:39 | 000,001,997 | ---- | C] () -- C:\Users\Audrey\Desktop\ZHPFix.lnk
[2014/02/19 14:27:39 | 000,001,870 | ---- | C] () -- C:\Users\Audrey\Desktop\ZHPDiag.lnk
[2014/02/19 09:07:59 | 000,001,119 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/02/14 03:00:34 | 000,000,296 | ---- | C] () -- C:\Windows\tasks\Digital Sites.job
[2014/02/10 10:21:43 | 000,133,666 | ---- | C] () -- C:\Users\Audrey\Documents\Brochure_VAP_Officier.pdf
[2014/02/10 10:02:17 | 000,406,974 | ---- | C] () -- C:\Users\Audrey\Documents\2013-07-comment-devenir-officier-concours-interne.pdf
[2014/02/10 10:02:08 | 000,620,077 | ---- | C] () -- C:\Users\Audrey\Documents\2013-07-comment-devenir-officier-concours-externe.pdf
[2014/02/10 10:00:48 | 000,047,932 | ---- | C] () -- C:\Users\Audrey\Documents\2007-2013-annales-officier-int-dissertation-culture-genarale.pdf
[2014/02/10 10:00:42 | 003,732,501 | ---- | C] () -- C:\Users\Audrey\Documents\2012-annales-officier-int-note-synthese.pdf
[2014/02/10 10:00:35 | 003,375,432 | ---- | C] () -- C:\Users\Audrey\Documents\2013-annales-officier-int-note-synthese.pdf
[2014/02/10 10:00:25 | 000,118,929 | ---- | C] () -- C:\Users\Audrey\Documents\2012-etude-de-cas-vap-officier.pdf
[2014/02/10 10:00:19 | 000,107,899 | ---- | C] () -- C:\Users\Audrey\Documents\2013-etude-de-cas-vap-officier.pdf
[2014/02/10 09:59:34 | 000,054,999 | ---- | C] () -- C:\Users\Audrey\Documents\2013-annales-commissaire-vap-2006-2013.pdf
[2014/02/10 09:59:08 | 000,113,366 | ---- | C] () -- C:\Users\Audrey\Documents\2012-vap-officier1.pdf
[2014/02/10 09:58:42 | 000,300,287 | ---- | C] () -- C:\Users\Audrey\Documents\2013-officier-admis-internes.pdf
[2014/02/10 09:58:28 | 000,337,164 | ---- | C] () -- C:\Users\Audrey\Documents\2013-officier-admis-vap.pdf
[2014/01/28 08:11:55 | 000,555,997 | ---- | C] () -- C:\Users\Audrey\Documents\50320004132043626211412511000574carrefour.pdf
[2014/01/25 15:43:32 | 000,001,093 | ---- | C] () -- C:\Users\Audrey\Desktop\Video Performer.lnk
[2014/01/21 15:23:36 | 000,188,450 | ---- | C] () -- C:\Users\Audrey\Documents\recapitulatif_dossier_178929 journée de la femme ce clienteles.pdf
[2014/01/21 15:23:03 | 000,190,346 | ---- | C] () -- C:\Users\Audrey\Documents\DOSSIER_210114.032230 journée de la femme ce clienteles.pdf
[2014/01/21 15:15:34 | 000,117,255 | ---- | C] () -- C:\Users\Audrey\Documents\Ch1+NbRel.pdf
[2014/01/21 15:15:13 | 000,223,291 | ---- | C] () -- C:\Users\Audrey\Documents\Ch2+EgalPyth.pdf
[2014/01/21 15:14:49 | 000,109,187 | ---- | C] () -- C:\Users\Audrey\Documents\Ch3+EcritFract.pdf
[2014/01/21 15:14:11 | 000,198,124 | ---- | C] () -- C:\Users\Audrey\Documents\Ch4+TrRect.pdf
[2014/01/21 15:13:22 | 000,138,234 | ---- | C] () -- C:\Users\Audrey\Documents\Ch5+CalcLitt.pdf
[2013/12/31 09:53:57 | 000,000,005 | ---- | C] () -- C:\Users\Audrey\AppData\Roaming\WBPU-Q5-TTL.DAT
[2013/09/23 06:22:10 | 000,000,175 | ---- | C] () -- C:\Users\Audrey\AppData\Roaming\WB.CFG
[2013/09/23 06:22:10 | 000,000,005 | ---- | C] () -- C:\Users\Audrey\AppData\Roaming\WBPU-TTL.DAT
[2013/06/25 21:40:43 | 000,038,449 | ---- | C] () -- C:\Users\Audrey\AppData\Roaming\Valeurs séparées par des virgules (Windows).ADR
[2012/08/03 07:42:31 | 000,000,023 | ---- | C] () -- C:\Users\Audrey\intlname.ols
[2012/02/10 11:36:57 | 000,003,584 | ---- | C] () -- C:\Users\Audrey\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/29 09:03:25 | 000,001,854 | ---- | C] () -- C:\Users\Audrey\AppData\Roaming\GhostObjGAFix.xml
[color=#E56717]========== ZeroAccess Check ==========/color
[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/07/26 03:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 02:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report >
Messages postés
Date d'inscription
mercredi 19 février 2014
Dernière intervention
19 février 2014
19 févr. 2014 à 15:11
19 févr. 2014 à 15:11
Et le rapport Extra txt
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Messages postés
Date d'inscription
mercredi 17 mai 2006
Modérateur, Contributeur sécurité
Dernière intervention
15 décembre 2020
24 666
19 févr. 2014 à 16:08
19 févr. 2014 à 16:08
par pjjoint, le rapport OTL.
Voila le lien des Log OTL et Extra après adware
Merci à vous
Voila le lien des Log OTL et Extra après adware
Merci à vous
Messages postés
Date d'inscription
mercredi 17 mai 2006
Modérateur, Contributeur sécurité
Dernière intervention
15 décembre 2020
24 666
19 févr. 2014 à 17:17
19 févr. 2014 à 17:17
Plus de pubs ?
Messages postés
Date d'inscription
mercredi 17 mai 2006
Modérateur, Contributeur sécurité
Dernière intervention
15 décembre 2020
24 666
3 mars 2014 à 17:50
3 mars 2014 à 17:50
Installe Malwarebyte's Anti-Malware :
Fais des scans réguliers avec, il est efficace.
Pour ne plus te faire avoir.
A lire - Programmes parasites / PUPs :
Installe Malwarebyte's Anti-Malware :
Fais des scans réguliers avec, il est efficace.
Pour ne plus te faire avoir.
A lire - Programmes parasites / PUPs :
19 févr. 2014 à 11:10
je te laisse faire ;)
19 févr. 2014 à 14:48