Des pubs m'empèchent de naviguer tranquillement sur internet
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
8 mars 2015 à 21:17
Phil - 3 sept. 2015 à 10:10
Phil - 3 sept. 2015 à 10:10
A voir également:
- Des pubs m'empèchent de naviguer tranquillement sur internet
- Bloquer les pubs sur youtube - Accueil - Streaming
- Gps sans internet - Guide
- D'où peut venir un problème de connexion internet sur un ordinateur ? - Guide
- Vendre sur internet particulier - Guide
- Supprimer les pubs - Guide
18 réponses
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
9 mars 2015 à 17:58
9 mars 2015 à 17:58
Un logiciel permettant l'activation illégale soit de windows soit office
Télécharge et enregistre Zhpcleaner sur ton bureau :
[*] Fais un clique droit dessus, lance le en tant qu'administrateur !
[*] Accepte le contrat de licence d'utilisation finale (CLUF),
[*] Clique sur "réparation"
[*] Clique sur rapport (normalement le rapport s'affiche)
[*] Enregistre le rapport sur ton bureau
[*] Héberge son rapport de modification qui se trouve sur le Bureau : à lire =>
, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum </gras>
Note :
- Cet outil ne nécessite pas d'installation !
- Le rapport se trouve également dans ce répertoire "%AppData%".
Télécharge et enregistre Zhpcleaner sur ton bureau :
[*] Fais un clique droit dessus, lance le en tant qu'administrateur !
[*] Accepte le contrat de licence d'utilisation finale (CLUF),
[*] Clique sur "réparation"
[*] Clique sur rapport (normalement le rapport s'affiche)
[*] Enregistre le rapport sur ton bureau
[*] Héberge son rapport de modification qui se trouve sur le Bureau : à lire =>
, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum </gras>
Note :
- Cet outil ne nécessite pas d'installation !
- Le rapport se trouve également dans ce répertoire "%AppData%".
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
9 mars 2015 à 20:22
9 mars 2015 à 20:22
Redémarre et normalement plus de pub :)
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 20:24
9 mars 2015 à 20:24
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
8 mars 2015 à 21:22
8 mars 2015 à 21:22
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
8 mars 2015 à 21:31
8 mars 2015 à 21:31
Là ça n'a rien à voir avec les pubs de ccm
Il est infecté...
Tu as dû installer des logiciels potentiellement indésirables
Pour éviter ce genre de problème :
- Ne télécharge aucun programme proposé dans des publicités ou sur des sites suspects. A noter que certains sites connus comme Softronic, Tuto4PC, etc modifient parfois les programmes proposés au téléchargement pour y ajouter des logiciels publicitaires ==> Préfère toujours le téléchargement directement sur le site de l'éditeur.
- Au cours de l'installation d'un programme gratuit, lis bien attentivement et décoche tous les programmes additionnels qui sont proposés, en particulier les barres d'outils.
Pour ton information lis ces dossier sur les Programmes Potentiellement Indésirables et Les Barres d'Outils ce n'est pas obligatoires
Télécharge cet outil simple d'utilisation
Si problème avec le 1er lien prends le ici
Lance le (Sous vista/seven/8 clic droit dessus,et sur exécuter en tant qu'administrateur)si tu es sous xp double cliques dessus
Cliques sur scanner
Poste le rapport de recherche C:\Adwcleaner[R]
Note le rapport de recherche est également sauvegardé sous C:\Adwcleaner[R1]
Héberge le rapport sur cjoint
Pour t'aider
Il est infecté...
Tu as dû installer des logiciels potentiellement indésirables
Pour éviter ce genre de problème :
- Ne télécharge aucun programme proposé dans des publicités ou sur des sites suspects. A noter que certains sites connus comme Softronic, Tuto4PC, etc modifient parfois les programmes proposés au téléchargement pour y ajouter des logiciels publicitaires ==> Préfère toujours le téléchargement directement sur le site de l'éditeur.
- Au cours de l'installation d'un programme gratuit, lis bien attentivement et décoche tous les programmes additionnels qui sont proposés, en particulier les barres d'outils.
Pour ton information lis ces dossier sur les Programmes Potentiellement Indésirables et Les Barres d'Outils ce n'est pas obligatoires
Télécharge cet outil simple d'utilisation
Si problème avec le 1er lien prends le ici
Lance le (Sous vista/seven/8 clic droit dessus,et sur exécuter en tant qu'administrateur)si tu es sous xp double cliques dessus
Cliques sur scanner
Poste le rapport de recherche C:\Adwcleaner[R]
Note le rapport de recherche est également sauvegardé sous C:\Adwcleaner[R1]
Héberge le rapport sur cjoint
Pour t'aider
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
8 mars 2015 à 21:45
8 mars 2015 à 21:45
merci j'espère que ça fonctionnera,
je ferais plus attention après
je ferais plus attention après
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
8 mars 2015 à 22:01
8 mars 2015 à 22:01
il y a toujours les pubs "by cloudscout"
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
8 mars 2015 à 22:07
8 mars 2015 à 22:07
# AdwCleaner v4.111 - Rapport créé le 08/03/2015 à 22:02:05
# Mis à jour le 18/02/2015 par Xplode
# Base de données : 2015-03-05.1 [Serveur]
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (x64)
# Nom d'utilisateur : Tibo - TIBO-TOSH
# Exécuté depuis : F:\divers\les offices\autres\adwcleaner_4.111.exe
# Option : Scanner
Service Trouvé : vToolbarUpdater18.1.9
Dossier Trouvé : C:\Program Files (x86)\YoutubeAdBlocke
Dossier Trouvé : C:\Users\Tibo\AppData\Local\AVG SafeGuard toolbar
Dossier Trouvé : C:\Users\Tibo\AppData\Local\globalUpdate
Dossier Trouvé : C:\Users\Tibo\AppData\LocalLow\AVG SafeGuard toolbar
Fichier Trouvé : C:\Users\Tibo\AppData\Roaming\Mozilla\Firefox\Profiles\clfkm78y.default\user.js
Fichier Trouvé : C:\Users\Tibo\Desktop\Youtube.lnk
Fichier Trouvé : C:\windows\System32\ColorMediaOff.ini
Fichier Trouvé : C:\windows\SysWOW64\ColorMedia.dll
Fichier Trouvé : C:\windows\SysWOW64\ColorMediaOff.ini
-\\ Internet Explorer v11.0.9600.17631
-\\ Mozilla Firefox v36.0.1 (x86 fr)
AdwCleaner[R0].txt - [12301 octets] - [08/03/2015 21:46:11]
AdwCleaner[R1].txt - [1335 octets] - [08/03/2015 22:02:05]
AdwCleaner[S0].txt - [11971 octets] - [08/03/2015 21:51:37]
########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [1456 octets] ##########
# Mis à jour le 18/02/2015 par Xplode
# Base de données : 2015-03-05.1 [Serveur]
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (x64)
# Nom d'utilisateur : Tibo - TIBO-TOSH
# Exécuté depuis : F:\divers\les offices\autres\adwcleaner_4.111.exe
# Option : Scanner
- [ Services ] *****
Service Trouvé : vToolbarUpdater18.1.9
- [ Fichiers / Dossiers ] *****
Dossier Trouvé : C:\Program Files (x86)\YoutubeAdBlocke
Dossier Trouvé : C:\Users\Tibo\AppData\Local\AVG SafeGuard toolbar
Dossier Trouvé : C:\Users\Tibo\AppData\Local\globalUpdate
Dossier Trouvé : C:\Users\Tibo\AppData\LocalLow\AVG SafeGuard toolbar
Fichier Trouvé : C:\Users\Tibo\AppData\Roaming\Mozilla\Firefox\Profiles\clfkm78y.default\user.js
Fichier Trouvé : C:\Users\Tibo\Desktop\Youtube.lnk
Fichier Trouvé : C:\windows\System32\ColorMediaOff.ini
Fichier Trouvé : C:\windows\SysWOW64\ColorMedia.dll
Fichier Trouvé : C:\windows\SysWOW64\ColorMediaOff.ini
- [ Tâches planifiées ] *****
- [ Raccourcis ] *****
- [ Registre ] *****
- [ Navigateurs ] *****
-\\ Internet Explorer v11.0.9600.17631
-\\ Mozilla Firefox v36.0.1 (x86 fr)
AdwCleaner[R0].txt - [12301 octets] - [08/03/2015 21:46:11]
AdwCleaner[R1].txt - [1335 octets] - [08/03/2015 22:02:05]
AdwCleaner[S0].txt - [11971 octets] - [08/03/2015 21:51:37]
########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [1456 octets] ##########
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
8 mars 2015 à 22:12
8 mars 2015 à 22:12
Suite plus bas
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
Modifié par lilidurhone le 8/03/2015 à 22:09
Modifié par lilidurhone le 8/03/2015 à 22:09
Poste moi le rapport
Fais nettoyer puis
Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage,
Si problème il y a il existe toujours une solution
~~~~~~ Cs ~~~~~~
Fais nettoyer puis
Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage,
- Internet Explorer et modules complémentaires / moteurs de recherche :
- Firefox :
- Google Chrome :
Si problème il y a il existe toujours une solution
~~~~~~ Cs ~~~~~~
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
8 mars 2015 à 22:21
8 mars 2015 à 22:21
bizarre, ce type de pub est toujours là après tout ce que j'ai fait
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
8 mars 2015 à 22:29
8 mars 2015 à 22:29
▶ Télécharge ici : FRST (de Farbar)
!!! En fonction de ta version de Windows, prends la "32-Bit Version" ou la "64-Bit Version" !!!
Aide : va dans Démarrer > Panneau de configuration > Système pour savoir si tu es sous 32 bits ou 64 bits.
▶ Double-clique sur l'icône FRST.exe pour lancer le programme. (Sous Windows Vista, 7 et 8, il faut faire un clic droit dessus, puis exécuter en tant qu'administrateur.) Clique ensuite sur Oui lorsqu'un message d'avertissement (Disclaimer) s'affiche.
▶ Sur le menu principal, clique sur le bouton Scan et patiente le temps de l'analyse.
▶ A la fin du scan, deux rapports s'affichent, FRST.txt et Addition.txt Poste les rapports dans ta prochaine réponse.
Les rapport se trouvent ici : C:\FRST\Logs
▶ Envoie-les sur et poste les liens obtenus en échange.
la suite demain
!!! En fonction de ta version de Windows, prends la "32-Bit Version" ou la "64-Bit Version" !!!
Aide : va dans Démarrer > Panneau de configuration > Système pour savoir si tu es sous 32 bits ou 64 bits.
▶ Double-clique sur l'icône FRST.exe pour lancer le programme. (Sous Windows Vista, 7 et 8, il faut faire un clic droit dessus, puis exécuter en tant qu'administrateur.) Clique ensuite sur Oui lorsqu'un message d'avertissement (Disclaimer) s'affiche.
▶ Sur le menu principal, clique sur le bouton Scan et patiente le temps de l'analyse.
▶ A la fin du scan, deux rapports s'affichent, FRST.txt et Addition.txt Poste les rapports dans ta prochaine réponse.
Les rapport se trouvent ici : C:\FRST\Logs
▶ Envoie-les sur et poste les liens obtenus en échange.
la suite demain
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
8 mars 2015 à 22:45
8 mars 2015 à 22:45
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-03-2015 03
Ran by Tibo at 2015-03-08 22:43:18
Running from C:\Users\Tibo\Downloads
Boot Mode: Normal
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Bitdefender Antivirus (Enabled - Up to date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
AS: Bitdefender Antispyware (Enabled - Up to date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Pare-feu (Enabled) {A23392FD-84B9-F933-2C71-81E751F6EF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Abrosoft FantaMorph 5.1 (HKLM-x32\...\Abrosoft FantaMorph 5_is1) (Version: 5.1 - Abrosoft)
ACDSee Pro 4 (HKLM-x32\...\{88D4FE78-6EA6-4DFB-9FC2-8BC316F0C2FD}) (Version: 4.0.198 - ACD Systems International Inc.)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: - Adobe Systems Incorporated)
Adobe Reader X (10.1.13) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.13 - Adobe Systems Incorporated)
Agatha Christie - Death on the Nile (x32 Version: - WildTangent) Hidden
Aloha TriPeaks (x32 Version: - WildTangent) Hidden
Apple Software Update (HKLM-x32\...\{02DFF6B1-1654-411C-8D7B-FD6052EF016F}) (Version: - Apple Inc.)
Avira (HKLM-x32\...\{bd538030-07d4-4999-a525-7fafa2483f56}) (Version: - Avira Operations & Co. KG)
Avira (x32 Version: - Avira Operations & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: - Avira) (HKLM-x32\...\ (Version: - Blizzard Entertainment)
Bejeweled 3 (x32 Version: - WildTangent) Hidden
Bitdefender Total Security (HKLM\...\Bitdefender) (Version: - Bitdefender)
Cake Mania (x32 Version: - WildTangent) Hidden
Centre Souris et Claviers Microsoft (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: - Microsoft Corporation)
Centre Souris et Claviers Microsoft (Version: - Microsoft Corporation) Hidden
Chuzzle Deluxe (x32 Version: - WildTangent) Hidden
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
CPUID CPU-Z 1.71.1 (HKLM\...\CPUID CPU-Z_is1) (Version: - )
CyberLink PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.2013 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DiMAGE Viewer (HKLM-x32\...\{976EA7B1-7562-483D-88DA-4323D263B7CD}) (Version: - )
Foto?raf Galerisi (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Galeria de Fotografias (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Gmail Notifier (HKLM-x32\...\Gmail Notifier) (Version: - )
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
High-Definition Video Playback (x32 Version: 11.1.10500.2.65 - Nero AG) Hidden
Insaniquarium Deluxe (x32 Version: - WildTangent) Hidden
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{0EC7F9CC-4741-45AE-9F55-6E9343F726F5}) (Version: - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
Java 8 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418025F0}) (Version: 8.0.250 - Oracle Corporation)
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Java SE Development Kit 8 Update 5 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180050}) (Version: 8.0.50 - Oracle Corporation)
Jewel Quest Solitaire 2 (x32 Version: - WildTangent) Hidden
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Français) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1036) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Português) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 2070) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Türkçe) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1055) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Professionnel Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Module linguistique Microsoft Visual Studio 2010 Tools pour Office Runtime (x64) - FRA (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - FRA) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 36.0.1 (x86 fr) (HKLM-x32\...\Mozilla Firefox 36.0.1 (x86 fr)) (Version: 36.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla)
Mystery P.I. - The London Caper (x32 Version: - WildTangent) Hidden
Nero 11 Essentials (HKLM-x32\...\{F8635CF8-B797-4EFD-80BC-DE2D26C65D4F}) (Version: 11.0.00300 - Nero AG)
Nero Backup Drivers (HKLM\...\{D600D357-5CB9-4DE9-8FD4-14E208BD1970}) (Version: 1.0.11100.8.0 - Nero AG)
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
PC Wizard 2013.2.12 (HKLM-x32\...\PC Wizard 2013_is1) (Version: - CPUID)
Photorécit 3 pour Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.15 - Microsoft Corporation)
Plants vs. Zombies - Game of the Year (x32 Version: - WildTangent) Hidden
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Polar Bowler (x32 Version: - WildTangent) Hidden
Premium Sound HD (HKLM\...\{3007FF9F-5B2C-41FF-8BFC-08BF25DB2681}) (Version: 1.12.1800 - SRS Labs, Inc.)
Prey Anti-theft (x32 Version: 1.1.4 - Prey, Inc.) Hidden
QuickTime (HKLM-x32\...\{08CA9554-B5FE-4313-938F-D4A417B81175}) (Version: - Apple Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.370.70 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.86.508.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\...\InstallShield_{95F38874-065A-40AB-AFC1-B764B192FFE7}) (Version: 2.00.0002 - REALTEK Semiconductor Corp.)
REALTEK Wireless LAN Driver (x32 Version: 2.00.0002 - REALTEK Semiconductor Corp.) Hidden
Realtek WLAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4fed-B2B9-173001290E16}) (Version: 2.00.0016 - REALTEK Semiconductor Corp.)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden
Skype(TM) 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SlimDrivers (HKLM-x32\...\{A5457401-D56A-43F2-9524-78E54A7FC07A}) (Version: 2.2.32705 - SlimWare Utilities, Inc.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: - Synaptics Incorporated)
TOSHIBA Assist (HKLM-x32\...\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}) (Version: - TOSHIBA CORPORATION)
TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: for x64 - TOSHIBA Corporation)
TOSHIBA eco Utility (HKLM\...\{2C486987-D447-4E36-8D61-86E48E24199C}) (Version: - TOSHIBA Corporation)
TOSHIBA Hardware Setup (HKLM-x32\...\{2FD5D2C5-A7A1-4065-89BA-90542BF7CCD3}) (Version: 2.00.0020 - TOSHIBA)
TOSHIBA HDD/SSD Alert (HKLM\...\{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: - TOSHIBA Corporation)
Toshiba Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.04 - TOSHIBA)
TOSHIBA Media Controller (HKLM-x32\...\{C7A4F26F-F9B0-41B2-8659-99181108CDE3}) (Version: - TOSHIBA CORPORATION)
TOSHIBA Media Controller Plug-in (HKLM-x32\...\{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}) (Version: - TOSHIBA CORPORATION)
TOSHIBA Online Product Information (HKLM-x32\...\{2290A680-4083-410A-ADCC-7092C67FC052}) (Version: 4.01.0000 - TOSHIBA)
TOSHIBA PC Health Monitor (HKLM\...\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: - TOSHIBA Corporation)
TOSHIBA Places Icon Utility (HKLM-x32\...\{461F6F0D-7173-4902-9604-AB1A29108AF2}) (Version: - TOSHIBA Corporation)
TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: - TOSHIBA CORPORATION)
TOSHIBA Recovery Media Creator Reminder (HKLM-x32\...\InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}) (Version: 1.00.0019 - TOSHIBA)
TOSHIBA Resolution+ Plug-in for Windows Media Player (HKLM-x32\...\{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}) (Version: 1.1.2004 - TOSHIBA Corporation)
TOSHIBA Service Station (HKLM-x32\...\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.2.13 - TOSHIBA)
TOSHIBA Supervisor Password (HKLM-x32\...\{119826A8-4EF6-4BE5-A88B-D2D81FA7CEE2}) (Version: 2.00.0009 - TOSHIBA)
TOSHIBA TEMPRO (HKLM-x32\...\{F082CB11-4794-4259-99A1-D91BA762AD15}) (Version: 3.35 - Toshiba Europe GmbH)
TOSHIBA Value Added Package (HKLM-x32\...\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.6.0021.640203 - TOSHIBA Corporation)
TOSHIBA Web Camera Application (HKLM-x32\...\InstallShield_{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}) (Version: - TOSHIBA Corporation)
TuneUp Utilities 2014 (fr-FR) (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden
TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities) (Version: 14.0.1000.340 - TuneUp Software)
TuneUp Utilities 2014 (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
VideoDownloaderUltimate (HKU\S-1-5-21-1711470111-1547835389-10093087-1000\...\VideoDownloaderUltimateWinApp) (Version: - Link64)
Virtual Villagers 4 - The Tree of Life (x32 Version: - WildTangent) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
welcome (x32 Version: 11.0.22500.0.0 - Nero AG) Hidden
WildTangent Games (HKLM-x32\...\WildTangent toshiba Master Uninstall) (Version: - WildTangent)
WildTangent Games App (Toshiba Games) (x32 Version: - WildTangent) Hidden
Windows Live (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 5.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
XnView 2.13 (HKLM-x32\...\XnView_is1) (Version: 2.13 - Gougelet Pierre-e)
???? Windows Live (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
???? ????? (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-1711470111-1547835389-10093087-1000_Classes\CLSID\{00000001-0E3A-4123-8B32-4B68A91E104A}\InprocServer32 -> C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIBasePlace.dll (Toshiba Corporation)
==================== Restore Points =========================
25-01-2015 13:58:34 Supprimé Realtek USB 2.0 Card Reader
25-01-2015 13:59:23 Installé Realtek Card Reader
25-01-2015 14:16:01 SlimDrivers Installing Drivers
25-01-2015 14:16:42 Installé Realtek Card Reader
25-01-2015 21:44:50 Windows Update
26-01-2015 20:05:47 Windows Update
27-01-2015 21:56:11 Windows Update
28-01-2015 21:36:17 Windows Update
29-01-2015 22:05:01 Windows Update
30-01-2015 22:46:43 Windows Update
31-01-2015 12:17:51 Windows Update
01-02-2015 00:30:53 Windows Update
01-02-2015 22:30:15 Windows Update
02-02-2015 21:27:39 Windows Update
02-02-2015 22:13:06 Windows Update
03-02-2015 22:37:04 Windows Update
04-02-2015 21:52:13 Windows Update
05-02-2015 22:04:11 Windows Update
06-02-2015 18:22:08 Windows Update
07-02-2015 01:28:07 Windows Update
08-02-2015 01:29:35 Windows Update
08-02-2015 21:47:23 Windows Update
09-02-2015 22:03:24 Windows Update
10-02-2015 23:02:29 Windows Update
11-02-2015 22:23:25 Windows Update
12-02-2015 19:26:21 Removed BlueStacks Notification Center
12-02-2015 19:34:10 Removed BlueStacks Notification Center
12-02-2015 19:40:00 Removed BlueStacks Notification Center
12-02-2015 19:41:15 Removed BlueStacks Notification Center
12-02-2015 22:18:18 Windows Update
13-02-2015 17:52:54 Windows Update
14-02-2015 01:56:37 Windows Update
14-02-2015 14:55:55 Windows Update
16-02-2015 10:56:32 Windows Update
17-02-2015 02:29:21 Windows Update
17-02-2015 20:52:53 Windows Update
17-02-2015 21:05:24 Windows Update
17-02-2015 23:30:56 Removed BlueStacks Notification Center
18-02-2015 01:57:06 Windows Update
18-02-2015 21:06:38 DirectX est installé
18-02-2015 21:08:17 DirectX est installé
18-02-2015 21:11:44 DirectX est installé
18-02-2015 21:12:21 DirectX est installé
19-02-2015 02:39:20 Windows Update
20-02-2015 02:04:59 Windows Update
21-02-2015 03:00:31 Windows Update
21-02-2015 06:18:02 Windows Update
22-02-2015 03:00:31 Windows Update
22-02-2015 03:32:03 Windows Update
23-02-2015 01:48:41 Windows Update
28-02-2015 01:35:00 Windows Update
01-03-2015 01:42:30 Windows Update
01-03-2015 22:42:21 Windows Update
02-03-2015 23:21:21 Windows Update
03-03-2015 23:01:42 Windows Update
04-03-2015 18:49:36 Installed Minecraft
04-03-2015 18:51:01 Installed Minecraft
04-03-2015 23:02:15 Windows Update
05-03-2015 22:18:23 Windows Update
05-03-2015 23:05:23 Windows Update
07-03-2015 00:08:31 Windows Update
07-03-2015 22:53:27 Windows Update
08-03-2015 02:31:09 Windows Update
08-03-2015 21:46:40 Installed Minecraft
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0880F20F-B6EB-4B2E-9B6C-A2C298F0BAB7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {176F71A9-7304-4975-9313-510F29227E75} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {1E7E67F8-7B4C-4A93-A4EA-C0FDBFA92B8A} - System32\Tasks\SlimDrivers Startup => C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe [2013-09-24] (SlimWare Utilities, Inc.)
Task: {287B988F-DB1D-45C7-ABF6-69214C2DCB21} - System32\Tasks\TYTLPZ => C:\Users\Tibo\AppData\Roaming\TYTLPZ.exe <==== ATTENTION
Task: {315924DD-9A79-43B4-8B83-4AF7FDC13B78} - System32\Tasks\{FA5D6AEC-0BE0-45DB-9C52-9D02713EFDD1} => pcalua.exe -a E:\OutlookConnector.exe -d E:\
Task: {37BF5E99-848E-4814-B034-D019A9862CBE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-06] (Adobe Systems Incorporated)
Task: {3BAE25BF-1DEC-4901-9243-70567C6056B7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-29] (Google Inc.)
Task: {3DCC358B-7D9D-426A-B160-CC3B10093E55} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {4EFBE66E-7460-482A-93A4-985A06511AD7} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {4F68E788-8FD6-4D16-A4CB-F3CC84FDEF4F} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2014-07-16] (TuneUp Software)
Task: {56A392E8-9CF3-4C05-94D9-3BE9B857FF30} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: {5945923F-85FA-4242-8708-EF0B24E33DBA} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {63F3B89F-87EE-4479-97FC-AAB575D12BB2} - System32\Tasks\Microsoft Office 15 Sync Maintenance for Tibo-TOSH-Tibo Tibo-TOSH => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2015-01-21] (Microsoft Corporation)
Task: {6B309691-4401-41E1-A0C5-C58243224001} - System32\Tasks\{B6FDA11E-F672-4E2A-A4FF-B2C20F73F42C} => pcalua.exe -a "C:\Program Files (x86)\BlueStacks\HD-RuntimeUninstaller.exe"
Task: {7D794D2A-B048-4C37-8544-C9A20C4D6B26} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {8A9EB850-5593-4A7E-97CF-D8B0C058447B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {9E2B6002-8B70-47A9-AF02-7AD8C89FC719} - System32\Tasks\WQRHCI => C:\Users\Tibo\AppData\Roaming\WQRHCI.exe <==== ATTENTION
Task: {9F620F97-E1EE-40A7-9583-47D30FCDC051} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: {A0B36D62-13FA-40A7-B472-43CF7E146EF9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-29] (Google Inc.)
Task: {C8A367F9-D449-471C-8C41-A274A3E9A111} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {C9A05F71-DB56-427C-878A-708B5330302F} - \PurpleRain\PurpleRain3 No Task File <==== ATTENTION
Task: {D7DDCDEA-AA93-416F-BF73-C9DC6F2B1D27} - \f104d9b2-f4c1-4672-a978-27e82d116169-10_user No Task File <==== ATTENTION
Task: {E98DF101-4E91-486C-A82F-60AF9391B526} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {F4859A14-D9AC-4E78-A5AD-605CF75EE9BB} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\SlimDrivers Startup.job => C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
Task: C:\windows\Tasks\TYTLPZ.job => C:\Users\Tibo\AppData\Roaming\TYTLPZ.exe <==== ATTENTION
Task: C:\windows\Tasks\WQRHCI.job => C:\Users\Tibo\AppData\Roaming\WQRHCI.exe <==== ATTENTION
==================== Loaded Modules (whitelisted) ==============
2014-06-16 08:57 - 2014-11-11 14:02 - 00265080 _____ () C:\Program Files\Bitdefender\Bitdefender\txmlutil.dll
2014-10-04 23:13 - 2014-10-04 23:13 - 00003072 _____ () C:\Program Files\Bitdefender\Bitdefender\UI\accessl.ui
2014-06-16 08:57 - 2011-11-14 19:17 - 00153680 _____ () C:\Program Files\Bitdefender\Bitdefender\bdfwcore.dll
2014-10-04 23:13 - 2014-10-04 23:13 - 00005120 _____ () C:\Program Files\Bitdefender\Bitdefender\UI\IMSecurityAL.ui
2015-02-06 17:58 - 2015-02-06 17:58 - 00784712 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_00050_005\ashttpbr.mdl
2015-02-06 17:58 - 2015-02-06 17:58 - 00573544 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_00050_005\ashttpdsp.mdl
2015-02-06 17:58 - 2015-02-06 17:58 - 02657264 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_00050_005\ashttpph.mdl
2015-02-06 17:58 - 2015-02-06 17:58 - 01331648 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_00050_005\ashttprbl.mdl
2012-07-11 23:42 - 2010-09-10 01:26 - 00162824 _____ () C:\Windows\System32\GFNEXSrv.exe
2014-06-16 10:26 - 2010-11-18 16:26 - 00224176 _____ () C:\Program Files (x86)\Abrosoft\FantaMorph5\FantaUp.exe
2014-06-16 14:43 - 2014-06-16 14:43 - 00294912 _____ () C:\windows\KMSServerService\KMS Server Service.exe
2015-01-09 10:59 - 2009-04-17 18:01 - 00247152 ____N () C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
2014-07-16 10:24 - 2014-07-16 10:24 - 00699704 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll
2014-06-16 08:57 - 2013-03-25 15:16 - 01117920 _____ () C:\Program Files\Bitdefender\Bitdefender SafeBox\System.Data.SQLite.dll
2011-08-22 23:19 - 2011-08-22 23:19 - 11204992 _____ () C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll
2010-12-15 23:19 - 2010-12-15 23:19 - 00124320 _____ () C:\Program Files\TOSHIBA\TECO\MUIHelp.dll
2012-03-27 01:33 - 2012-03-27 01:33 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-06-16 08:57 - 2014-10-04 23:05 - 00190408 _____ () C:\Program Files\Bitdefender\Bitdefender\pwdmandb.dll
2014-05-15 16:49 - 2014-05-15 16:49 - 00016896 _____ () C:\Windows\Prey\versions\1.1.4\bin\windows\Cronsvclib.dll
2014-11-11 14:49 - 2014-11-11 14:49 - 00204280 _____ () C:\Program Files\Bitdefender\Bitdefender\antispam32\txmlutil.dll
2015-01-25 14:13 - 2000-01-01 01:00 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2015-02-06 17:52 - 2015-02-06 17:52 - 16852144 _____ () C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\windows\SysWOW64\ColorMedia.dll:BDU
AlternateDataStreams: C:\Users\Tibo\Downloads\avira_fr_av___ws.exe:BDU
AlternateDataStreams: C:\Users\Tibo\Downloads\FRST64.exe:BDU
AlternateDataStreams: C:\Users\Tibo\Downloads\Setup.exe:BDU
AlternateDataStreams: C:\Users\Tibo\Downloads\youtube_downloader_hd_setup.exe:BDU
AlternateDataStreams: C:\Users\Tibo\Documents\prey-0.6.3-win.exe:BDU
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1711470111-1547835389-10093087-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Tibo\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: -
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Toshiba Places Icon Utility.lnk => C:\windows\pss\Toshiba Places Icon Utility.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Tibo^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^TRDCReminder.lnk => C:\windows\pss\TRDCReminder.lnk.Startup
MSCONFIG\startupreg: Avira Systray => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
MSCONFIG\startupreg: NBAgent => "C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" /WinStart
MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
MSCONFIG\startupreg: Toshiba Registration => C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe
MSCONFIG\startupreg: Toshiba TEMPRO => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
MSCONFIG\startupreg: ToshibaServiceStation => "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
MSCONFIG\startupreg: TosSENotify => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
MSCONFIG\startupreg: UpdatePDRShortCut => "F:\Montage video\PowerDirector 8 Deluxe+serial\Logiciel\PowerDirector\MUITransfer\MUIStartMenu.exe" "F:\Montage video\PowerDirector 8 Deluxe+serial\Logiciel\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"
MSCONFIG\startupreg: vProt => "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
MSCONFIG\startupreg: WinCheck => C:\Users\Tibo\AppData\Local\wincheck\wincheck.exe
==================== Accounts: =============================
Administrateur (S-1-5-21-1711470111-1547835389-10093087-500 - Administrator - Disabled)
HomeGroupUser$ (S-1-5-21-1711470111-1547835389-10093087-1003 - Limited - Enabled)
Invité (S-1-5-21-1711470111-1547835389-10093087-501 - Limited - Enabled)
Remi ad (S-1-5-21-1711470111-1547835389-10093087-1001 - Administrator - Enabled)
Tibo (S-1-5-21-1711470111-1547835389-10093087-1000 - Administrator - Enabled) => C:\Users\Tibo
==================== Faulty Device Manager Devices =============
Class Guid:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
Error: (03/08/2015 09:57:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/08/2015 09:56:37 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 2176
Error: (03/08/2015 09:52:46 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 4948
Error: (03/08/2015 09:52:45 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 11832
Error: (03/08/2015 09:52:45 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 9080
Error: (03/08/2015 09:52:44 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 11972
Error: (03/08/2015 09:52:44 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 2736
Error: (03/08/2015 09:52:44 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 10952
Error: (03/08/2015 09:52:43 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 8724
Error: (03/08/2015 09:52:43 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 11660
System errors:
Error: (03/08/2015 09:56:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Le service vToolbarUpdater18.1.9 n'a pas pu démarrer en raison de l'erreur :
Error: (03/08/2015 09:56:36 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: AUTORITE NT)
Description: Le module d'extensibilité WLAN n'a pas pu démarrer.
Chemin d'accès du module : C:\windows\system32\Rtlihvs.dll
Code d'erreur : 126
Error: (03/08/2015 09:56:34 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Le service Bitdefender Virus Shield est en attente de démarrage.
Error: (03/08/2015 09:56:35 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x00000076 (0x0000000000000000, 0xfffffa8007a05060, 0x0000000000000007, 0x0000000000000000)C:\windows\MEMORY.DMP030815-64272-01
Error: (03/08/2015 09:52:50 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Le service Windows Search s'est terminé de manière inattendue. Ceci s'est produit 1 fois. L'action corrective suivante va être effectuée dans 30000 millisecondes : Redémarrer le service.
Error: (03/08/2015 09:52:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Le service Service Partage réseau du Lecteur Windows Media s'est terminé de manière inattendue. Ceci s'est produit 1 fois. L'action corrective suivante va être effectuée dans 30000 millisecondes : Redémarrer le service.
Error: (03/08/2015 09:52:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Le service TOSHIBA eco Utility Service s'est terminé de façon inattendue pour la 1ème fois.
Error: (03/08/2015 09:52:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Le service TPCH Service s'est terminé de façon inattendue pour la 1ème fois.
Error: (03/08/2015 09:52:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Le service Cron Service s'est terminé de façon inattendue pour la 1ème fois.
Error: (03/08/2015 09:52:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Le service Intel(R) Integrated Clock Controller Service - Intel(R) ICCS s'est terminé de façon inattendue pour la 1ème fois.
Microsoft Office Sessions:
Error: (03/08/2015 09:57:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/08/2015 09:56:37 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 2176
Error: (03/08/2015 09:52:46 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 4948
Error: (03/08/2015 09:52:45 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 11832
Error: (03/08/2015 09:52:45 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 9080
Error: (03/08/2015 09:52:44 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 11972
Error: (03/08/2015 09:52:44 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 2736
Error: (03/08/2015 09:52:44 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 10952
Error: (03/08/2015 09:52:43 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 8724
Error: (03/08/2015 09:52:43 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 11660
==================== Memory info ===========================
Processor: Intel(R) Celeron(R) CPU B820 @ 1.70GHz
Percentage of memory in use: 60%
Total physical RAM: 3985.8 MB
Available physical RAM: 1563.21 MB
Total Pagefile: 7969.8 MB
Available Pagefile: 4641 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: (Lecteur C) (Fixed) (Total:280.75 GB) (Free:101.82 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive f: (TIBO) (Fixed) (Total:1397.26 GB) (Free:1362.62 GB) NTFS
==================== MBR & Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298.1 GB) (Disk ID: 388C5D85)
Partition 1: (Active) - (Size=1.5 GB) - (Type=27)
Partition 2: (Not Active) - (Size=280.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=15.9 GB) - (Type=17)
Disk: 1 (Size: 1397.3 GB) (Disk ID: D54651C0)
Partition 1: (Active) - (Size=1397.3 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Ran by Tibo at 2015-03-08 22:43:18
Running from C:\Users\Tibo\Downloads
Boot Mode: Normal
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Bitdefender Antivirus (Enabled - Up to date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
AS: Bitdefender Antispyware (Enabled - Up to date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Pare-feu (Enabled) {A23392FD-84B9-F933-2C71-81E751F6EF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Abrosoft FantaMorph 5.1 (HKLM-x32\...\Abrosoft FantaMorph 5_is1) (Version: 5.1 - Abrosoft)
ACDSee Pro 4 (HKLM-x32\...\{88D4FE78-6EA6-4DFB-9FC2-8BC316F0C2FD}) (Version: 4.0.198 - ACD Systems International Inc.)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: - Adobe Systems Incorporated)
Adobe Reader X (10.1.13) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.13 - Adobe Systems Incorporated)
Agatha Christie - Death on the Nile (x32 Version: - WildTangent) Hidden
Aloha TriPeaks (x32 Version: - WildTangent) Hidden
Apple Software Update (HKLM-x32\...\{02DFF6B1-1654-411C-8D7B-FD6052EF016F}) (Version: - Apple Inc.)
Avira (HKLM-x32\...\{bd538030-07d4-4999-a525-7fafa2483f56}) (Version: - Avira Operations & Co. KG)
Avira (x32 Version: - Avira Operations & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: - Avira) (HKLM-x32\...\ (Version: - Blizzard Entertainment)
Bejeweled 3 (x32 Version: - WildTangent) Hidden
Bitdefender Total Security (HKLM\...\Bitdefender) (Version: - Bitdefender)
Cake Mania (x32 Version: - WildTangent) Hidden
Centre Souris et Claviers Microsoft (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: - Microsoft Corporation)
Centre Souris et Claviers Microsoft (Version: - Microsoft Corporation) Hidden
Chuzzle Deluxe (x32 Version: - WildTangent) Hidden
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
CPUID CPU-Z 1.71.1 (HKLM\...\CPUID CPU-Z_is1) (Version: - )
CyberLink PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.2013 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DiMAGE Viewer (HKLM-x32\...\{976EA7B1-7562-483D-88DA-4323D263B7CD}) (Version: - )
Foto?raf Galerisi (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Galeria de Fotografias (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Gmail Notifier (HKLM-x32\...\Gmail Notifier) (Version: - )
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
High-Definition Video Playback (x32 Version: 11.1.10500.2.65 - Nero AG) Hidden
Insaniquarium Deluxe (x32 Version: - WildTangent) Hidden
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{0EC7F9CC-4741-45AE-9F55-6E9343F726F5}) (Version: - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
Java 8 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418025F0}) (Version: 8.0.250 - Oracle Corporation)
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Java SE Development Kit 8 Update 5 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180050}) (Version: 8.0.50 - Oracle Corporation)
Jewel Quest Solitaire 2 (x32 Version: - WildTangent) Hidden
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Français) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1036) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Português) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 2070) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Türkçe) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1055) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Professionnel Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Module linguistique Microsoft Visual Studio 2010 Tools pour Office Runtime (x64) - FRA (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - FRA) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 36.0.1 (x86 fr) (HKLM-x32\...\Mozilla Firefox 36.0.1 (x86 fr)) (Version: 36.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla)
Mystery P.I. - The London Caper (x32 Version: - WildTangent) Hidden
Nero 11 Essentials (HKLM-x32\...\{F8635CF8-B797-4EFD-80BC-DE2D26C65D4F}) (Version: 11.0.00300 - Nero AG)
Nero Backup Drivers (HKLM\...\{D600D357-5CB9-4DE9-8FD4-14E208BD1970}) (Version: 1.0.11100.8.0 - Nero AG)
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
PC Wizard 2013.2.12 (HKLM-x32\...\PC Wizard 2013_is1) (Version: - CPUID)
Photorécit 3 pour Windows (HKLM-x32\...\{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}) (Version: 3.0.1115.15 - Microsoft Corporation)
Plants vs. Zombies - Game of the Year (x32 Version: - WildTangent) Hidden
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Polar Bowler (x32 Version: - WildTangent) Hidden
Premium Sound HD (HKLM\...\{3007FF9F-5B2C-41FF-8BFC-08BF25DB2681}) (Version: 1.12.1800 - SRS Labs, Inc.)
Prey Anti-theft (x32 Version: 1.1.4 - Prey, Inc.) Hidden
QuickTime (HKLM-x32\...\{08CA9554-B5FE-4313-938F-D4A417B81175}) (Version: - Apple Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.370.70 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.86.508.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\...\InstallShield_{95F38874-065A-40AB-AFC1-B764B192FFE7}) (Version: 2.00.0002 - REALTEK Semiconductor Corp.)
REALTEK Wireless LAN Driver (x32 Version: 2.00.0002 - REALTEK Semiconductor Corp.) Hidden
Realtek WLAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4fed-B2B9-173001290E16}) (Version: 2.00.0016 - REALTEK Semiconductor Corp.)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden
Skype(TM) 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SlimDrivers (HKLM-x32\...\{A5457401-D56A-43F2-9524-78E54A7FC07A}) (Version: 2.2.32705 - SlimWare Utilities, Inc.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: - Synaptics Incorporated)
TOSHIBA Assist (HKLM-x32\...\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}) (Version: - TOSHIBA CORPORATION)
TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: for x64 - TOSHIBA Corporation)
TOSHIBA eco Utility (HKLM\...\{2C486987-D447-4E36-8D61-86E48E24199C}) (Version: - TOSHIBA Corporation)
TOSHIBA Hardware Setup (HKLM-x32\...\{2FD5D2C5-A7A1-4065-89BA-90542BF7CCD3}) (Version: 2.00.0020 - TOSHIBA)
TOSHIBA HDD/SSD Alert (HKLM\...\{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: - TOSHIBA Corporation)
Toshiba Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.04 - TOSHIBA)
TOSHIBA Media Controller (HKLM-x32\...\{C7A4F26F-F9B0-41B2-8659-99181108CDE3}) (Version: - TOSHIBA CORPORATION)
TOSHIBA Media Controller Plug-in (HKLM-x32\...\{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}) (Version: - TOSHIBA CORPORATION)
TOSHIBA Online Product Information (HKLM-x32\...\{2290A680-4083-410A-ADCC-7092C67FC052}) (Version: 4.01.0000 - TOSHIBA)
TOSHIBA PC Health Monitor (HKLM\...\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: - TOSHIBA Corporation)
TOSHIBA Places Icon Utility (HKLM-x32\...\{461F6F0D-7173-4902-9604-AB1A29108AF2}) (Version: - TOSHIBA Corporation)
TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: - TOSHIBA CORPORATION)
TOSHIBA Recovery Media Creator Reminder (HKLM-x32\...\InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}) (Version: 1.00.0019 - TOSHIBA)
TOSHIBA Resolution+ Plug-in for Windows Media Player (HKLM-x32\...\{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}) (Version: 1.1.2004 - TOSHIBA Corporation)
TOSHIBA Service Station (HKLM-x32\...\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.2.13 - TOSHIBA)
TOSHIBA Supervisor Password (HKLM-x32\...\{119826A8-4EF6-4BE5-A88B-D2D81FA7CEE2}) (Version: 2.00.0009 - TOSHIBA)
TOSHIBA TEMPRO (HKLM-x32\...\{F082CB11-4794-4259-99A1-D91BA762AD15}) (Version: 3.35 - Toshiba Europe GmbH)
TOSHIBA Value Added Package (HKLM-x32\...\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.6.0021.640203 - TOSHIBA Corporation)
TOSHIBA Web Camera Application (HKLM-x32\...\InstallShield_{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}) (Version: - TOSHIBA Corporation)
TuneUp Utilities 2014 (fr-FR) (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden
TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities) (Version: 14.0.1000.340 - TuneUp Software)
TuneUp Utilities 2014 (x32 Version: 14.0.1000.340 - TuneUp Software) Hidden
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
VideoDownloaderUltimate (HKU\S-1-5-21-1711470111-1547835389-10093087-1000\...\VideoDownloaderUltimateWinApp) (Version: - Link64)
Virtual Villagers 4 - The Tree of Life (x32 Version: - WildTangent) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
welcome (x32 Version: 11.0.22500.0.0 - Nero AG) Hidden
WildTangent Games (HKLM-x32\...\WildTangent toshiba Master Uninstall) (Version: - WildTangent)
WildTangent Games App (Toshiba Games) (x32 Version: - WildTangent) Hidden
Windows Live (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 5.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
XnView 2.13 (HKLM-x32\...\XnView_is1) (Version: 2.13 - Gougelet Pierre-e)
???? Windows Live (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
???? ????? (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-1711470111-1547835389-10093087-1000_Classes\CLSID\{00000001-0E3A-4123-8B32-4B68A91E104A}\InprocServer32 -> C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIBasePlace.dll (Toshiba Corporation)
==================== Restore Points =========================
25-01-2015 13:58:34 Supprimé Realtek USB 2.0 Card Reader
25-01-2015 13:59:23 Installé Realtek Card Reader
25-01-2015 14:16:01 SlimDrivers Installing Drivers
25-01-2015 14:16:42 Installé Realtek Card Reader
25-01-2015 21:44:50 Windows Update
26-01-2015 20:05:47 Windows Update
27-01-2015 21:56:11 Windows Update
28-01-2015 21:36:17 Windows Update
29-01-2015 22:05:01 Windows Update
30-01-2015 22:46:43 Windows Update
31-01-2015 12:17:51 Windows Update
01-02-2015 00:30:53 Windows Update
01-02-2015 22:30:15 Windows Update
02-02-2015 21:27:39 Windows Update
02-02-2015 22:13:06 Windows Update
03-02-2015 22:37:04 Windows Update
04-02-2015 21:52:13 Windows Update
05-02-2015 22:04:11 Windows Update
06-02-2015 18:22:08 Windows Update
07-02-2015 01:28:07 Windows Update
08-02-2015 01:29:35 Windows Update
08-02-2015 21:47:23 Windows Update
09-02-2015 22:03:24 Windows Update
10-02-2015 23:02:29 Windows Update
11-02-2015 22:23:25 Windows Update
12-02-2015 19:26:21 Removed BlueStacks Notification Center
12-02-2015 19:34:10 Removed BlueStacks Notification Center
12-02-2015 19:40:00 Removed BlueStacks Notification Center
12-02-2015 19:41:15 Removed BlueStacks Notification Center
12-02-2015 22:18:18 Windows Update
13-02-2015 17:52:54 Windows Update
14-02-2015 01:56:37 Windows Update
14-02-2015 14:55:55 Windows Update
16-02-2015 10:56:32 Windows Update
17-02-2015 02:29:21 Windows Update
17-02-2015 20:52:53 Windows Update
17-02-2015 21:05:24 Windows Update
17-02-2015 23:30:56 Removed BlueStacks Notification Center
18-02-2015 01:57:06 Windows Update
18-02-2015 21:06:38 DirectX est installé
18-02-2015 21:08:17 DirectX est installé
18-02-2015 21:11:44 DirectX est installé
18-02-2015 21:12:21 DirectX est installé
19-02-2015 02:39:20 Windows Update
20-02-2015 02:04:59 Windows Update
21-02-2015 03:00:31 Windows Update
21-02-2015 06:18:02 Windows Update
22-02-2015 03:00:31 Windows Update
22-02-2015 03:32:03 Windows Update
23-02-2015 01:48:41 Windows Update
28-02-2015 01:35:00 Windows Update
01-03-2015 01:42:30 Windows Update
01-03-2015 22:42:21 Windows Update
02-03-2015 23:21:21 Windows Update
03-03-2015 23:01:42 Windows Update
04-03-2015 18:49:36 Installed Minecraft
04-03-2015 18:51:01 Installed Minecraft
04-03-2015 23:02:15 Windows Update
05-03-2015 22:18:23 Windows Update
05-03-2015 23:05:23 Windows Update
07-03-2015 00:08:31 Windows Update
07-03-2015 22:53:27 Windows Update
08-03-2015 02:31:09 Windows Update
08-03-2015 21:46:40 Installed Minecraft
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0880F20F-B6EB-4B2E-9B6C-A2C298F0BAB7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {176F71A9-7304-4975-9313-510F29227E75} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {1E7E67F8-7B4C-4A93-A4EA-C0FDBFA92B8A} - System32\Tasks\SlimDrivers Startup => C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe [2013-09-24] (SlimWare Utilities, Inc.)
Task: {287B988F-DB1D-45C7-ABF6-69214C2DCB21} - System32\Tasks\TYTLPZ => C:\Users\Tibo\AppData\Roaming\TYTLPZ.exe <==== ATTENTION
Task: {315924DD-9A79-43B4-8B83-4AF7FDC13B78} - System32\Tasks\{FA5D6AEC-0BE0-45DB-9C52-9D02713EFDD1} => pcalua.exe -a E:\OutlookConnector.exe -d E:\
Task: {37BF5E99-848E-4814-B034-D019A9862CBE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-06] (Adobe Systems Incorporated)
Task: {3BAE25BF-1DEC-4901-9243-70567C6056B7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-29] (Google Inc.)
Task: {3DCC358B-7D9D-426A-B160-CC3B10093E55} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {4EFBE66E-7460-482A-93A4-985A06511AD7} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {4F68E788-8FD6-4D16-A4CB-F3CC84FDEF4F} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2014-07-16] (TuneUp Software)
Task: {56A392E8-9CF3-4C05-94D9-3BE9B857FF30} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: {5945923F-85FA-4242-8708-EF0B24E33DBA} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {63F3B89F-87EE-4479-97FC-AAB575D12BB2} - System32\Tasks\Microsoft Office 15 Sync Maintenance for Tibo-TOSH-Tibo Tibo-TOSH => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2015-01-21] (Microsoft Corporation)
Task: {6B309691-4401-41E1-A0C5-C58243224001} - System32\Tasks\{B6FDA11E-F672-4E2A-A4FF-B2C20F73F42C} => pcalua.exe -a "C:\Program Files (x86)\BlueStacks\HD-RuntimeUninstaller.exe"
Task: {7D794D2A-B048-4C37-8544-C9A20C4D6B26} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {8A9EB850-5593-4A7E-97CF-D8B0C058447B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {9E2B6002-8B70-47A9-AF02-7AD8C89FC719} - System32\Tasks\WQRHCI => C:\Users\Tibo\AppData\Roaming\WQRHCI.exe <==== ATTENTION
Task: {9F620F97-E1EE-40A7-9583-47D30FCDC051} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: {A0B36D62-13FA-40A7-B472-43CF7E146EF9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-29] (Google Inc.)
Task: {C8A367F9-D449-471C-8C41-A274A3E9A111} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {C9A05F71-DB56-427C-878A-708B5330302F} - \PurpleRain\PurpleRain3 No Task File <==== ATTENTION
Task: {D7DDCDEA-AA93-416F-BF73-C9DC6F2B1D27} - \f104d9b2-f4c1-4672-a978-27e82d116169-10_user No Task File <==== ATTENTION
Task: {E98DF101-4E91-486C-A82F-60AF9391B526} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {F4859A14-D9AC-4E78-A5AD-605CF75EE9BB} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\SlimDrivers Startup.job => C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
Task: C:\windows\Tasks\TYTLPZ.job => C:\Users\Tibo\AppData\Roaming\TYTLPZ.exe <==== ATTENTION
Task: C:\windows\Tasks\WQRHCI.job => C:\Users\Tibo\AppData\Roaming\WQRHCI.exe <==== ATTENTION
==================== Loaded Modules (whitelisted) ==============
2014-06-16 08:57 - 2014-11-11 14:02 - 00265080 _____ () C:\Program Files\Bitdefender\Bitdefender\txmlutil.dll
2014-10-04 23:13 - 2014-10-04 23:13 - 00003072 _____ () C:\Program Files\Bitdefender\Bitdefender\UI\accessl.ui
2014-06-16 08:57 - 2011-11-14 19:17 - 00153680 _____ () C:\Program Files\Bitdefender\Bitdefender\bdfwcore.dll
2014-10-04 23:13 - 2014-10-04 23:13 - 00005120 _____ () C:\Program Files\Bitdefender\Bitdefender\UI\IMSecurityAL.ui
2015-02-06 17:58 - 2015-02-06 17:58 - 00784712 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_00050_005\ashttpbr.mdl
2015-02-06 17:58 - 2015-02-06 17:58 - 00573544 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_00050_005\ashttpdsp.mdl
2015-02-06 17:58 - 2015-02-06 17:58 - 02657264 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_00050_005\ashttpph.mdl
2015-02-06 17:58 - 2015-02-06 17:58 - 01331648 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_00050_005\ashttprbl.mdl
2012-07-11 23:42 - 2010-09-10 01:26 - 00162824 _____ () C:\Windows\System32\GFNEXSrv.exe
2014-06-16 10:26 - 2010-11-18 16:26 - 00224176 _____ () C:\Program Files (x86)\Abrosoft\FantaMorph5\FantaUp.exe
2014-06-16 14:43 - 2014-06-16 14:43 - 00294912 _____ () C:\windows\KMSServerService\KMS Server Service.exe
2015-01-09 10:59 - 2009-04-17 18:01 - 00247152 ____N () C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
2014-07-16 10:24 - 2014-07-16 10:24 - 00699704 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll
2014-06-16 08:57 - 2013-03-25 15:16 - 01117920 _____ () C:\Program Files\Bitdefender\Bitdefender SafeBox\System.Data.SQLite.dll
2011-08-22 23:19 - 2011-08-22 23:19 - 11204992 _____ () C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll
2010-12-15 23:19 - 2010-12-15 23:19 - 00124320 _____ () C:\Program Files\TOSHIBA\TECO\MUIHelp.dll
2012-03-27 01:33 - 2012-03-27 01:33 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-06-16 08:57 - 2014-10-04 23:05 - 00190408 _____ () C:\Program Files\Bitdefender\Bitdefender\pwdmandb.dll
2014-05-15 16:49 - 2014-05-15 16:49 - 00016896 _____ () C:\Windows\Prey\versions\1.1.4\bin\windows\Cronsvclib.dll
2014-11-11 14:49 - 2014-11-11 14:49 - 00204280 _____ () C:\Program Files\Bitdefender\Bitdefender\antispam32\txmlutil.dll
2015-01-25 14:13 - 2000-01-01 01:00 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2015-02-06 17:52 - 2015-02-06 17:52 - 16852144 _____ () C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\windows\SysWOW64\ColorMedia.dll:BDU
AlternateDataStreams: C:\Users\Tibo\Downloads\avira_fr_av___ws.exe:BDU
AlternateDataStreams: C:\Users\Tibo\Downloads\FRST64.exe:BDU
AlternateDataStreams: C:\Users\Tibo\Downloads\Setup.exe:BDU
AlternateDataStreams: C:\Users\Tibo\Downloads\youtube_downloader_hd_setup.exe:BDU
AlternateDataStreams: C:\Users\Tibo\Documents\prey-0.6.3-win.exe:BDU
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1711470111-1547835389-10093087-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Tibo\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: -
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Toshiba Places Icon Utility.lnk => C:\windows\pss\Toshiba Places Icon Utility.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Tibo^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^TRDCReminder.lnk => C:\windows\pss\TRDCReminder.lnk.Startup
MSCONFIG\startupreg: Avira Systray => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
MSCONFIG\startupreg: NBAgent => "C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe" /WinStart
MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
MSCONFIG\startupreg: Toshiba Registration => C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe
MSCONFIG\startupreg: Toshiba TEMPRO => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
MSCONFIG\startupreg: ToshibaServiceStation => "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
MSCONFIG\startupreg: TosSENotify => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
MSCONFIG\startupreg: UpdatePDRShortCut => "F:\Montage video\PowerDirector 8 Deluxe+serial\Logiciel\PowerDirector\MUITransfer\MUIStartMenu.exe" "F:\Montage video\PowerDirector 8 Deluxe+serial\Logiciel\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"
MSCONFIG\startupreg: vProt => "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
MSCONFIG\startupreg: WinCheck => C:\Users\Tibo\AppData\Local\wincheck\wincheck.exe
==================== Accounts: =============================
Administrateur (S-1-5-21-1711470111-1547835389-10093087-500 - Administrator - Disabled)
HomeGroupUser$ (S-1-5-21-1711470111-1547835389-10093087-1003 - Limited - Enabled)
Invité (S-1-5-21-1711470111-1547835389-10093087-501 - Limited - Enabled)
Remi ad (S-1-5-21-1711470111-1547835389-10093087-1001 - Administrator - Enabled)
Tibo (S-1-5-21-1711470111-1547835389-10093087-1000 - Administrator - Enabled) => C:\Users\Tibo
==================== Faulty Device Manager Devices =============
Class Guid:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
Error: (03/08/2015 09:57:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/08/2015 09:56:37 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 2176
Error: (03/08/2015 09:52:46 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 4948
Error: (03/08/2015 09:52:45 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 11832
Error: (03/08/2015 09:52:45 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 9080
Error: (03/08/2015 09:52:44 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 11972
Error: (03/08/2015 09:52:44 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 2736
Error: (03/08/2015 09:52:44 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 10952
Error: (03/08/2015 09:52:43 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 8724
Error: (03/08/2015 09:52:43 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 11660
System errors:
Error: (03/08/2015 09:56:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Le service vToolbarUpdater18.1.9 n'a pas pu démarrer en raison de l'erreur :
Error: (03/08/2015 09:56:36 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: AUTORITE NT)
Description: Le module d'extensibilité WLAN n'a pas pu démarrer.
Chemin d'accès du module : C:\windows\system32\Rtlihvs.dll
Code d'erreur : 126
Error: (03/08/2015 09:56:34 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Le service Bitdefender Virus Shield est en attente de démarrage.
Error: (03/08/2015 09:56:35 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x00000076 (0x0000000000000000, 0xfffffa8007a05060, 0x0000000000000007, 0x0000000000000000)C:\windows\MEMORY.DMP030815-64272-01
Error: (03/08/2015 09:52:50 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Le service Windows Search s'est terminé de manière inattendue. Ceci s'est produit 1 fois. L'action corrective suivante va être effectuée dans 30000 millisecondes : Redémarrer le service.
Error: (03/08/2015 09:52:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Le service Service Partage réseau du Lecteur Windows Media s'est terminé de manière inattendue. Ceci s'est produit 1 fois. L'action corrective suivante va être effectuée dans 30000 millisecondes : Redémarrer le service.
Error: (03/08/2015 09:52:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Le service TOSHIBA eco Utility Service s'est terminé de façon inattendue pour la 1ème fois.
Error: (03/08/2015 09:52:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Le service TPCH Service s'est terminé de façon inattendue pour la 1ème fois.
Error: (03/08/2015 09:52:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Le service Cron Service s'est terminé de façon inattendue pour la 1ème fois.
Error: (03/08/2015 09:52:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Le service Intel(R) Integrated Clock Controller Service - Intel(R) ICCS s'est terminé de façon inattendue pour la 1ème fois.
Microsoft Office Sessions:
Error: (03/08/2015 09:57:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/08/2015 09:56:37 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 2176
Error: (03/08/2015 09:52:46 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 4948
Error: (03/08/2015 09:52:45 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 11832
Error: (03/08/2015 09:52:45 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 9080
Error: (03/08/2015 09:52:44 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 11972
Error: (03/08/2015 09:52:44 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 2736
Error: (03/08/2015 09:52:44 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 10952
Error: (03/08/2015 09:52:43 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 8724
Error: (03/08/2015 09:52:43 PM) (Source: PreyCronService) (EventID: 0) (User: )
Description: Monitoring node process with id: 11660
==================== Memory info ===========================
Processor: Intel(R) Celeron(R) CPU B820 @ 1.70GHz
Percentage of memory in use: 60%
Total physical RAM: 3985.8 MB
Available physical RAM: 1563.21 MB
Total Pagefile: 7969.8 MB
Available Pagefile: 4641 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: (Lecteur C) (Fixed) (Total:280.75 GB) (Free:101.82 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive f: (TIBO) (Fixed) (Total:1397.26 GB) (Free:1362.62 GB) NTFS
==================== MBR & Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298.1 GB) (Disk ID: 388C5D85)
Partition 1: (Active) - (Size=1.5 GB) - (Type=27)
Partition 2: (Not Active) - (Size=280.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=15.9 GB) - (Type=17)
Disk: 1 (Size: 1397.3 GB) (Disk ID: D54651C0)
Partition 1: (Active) - (Size=1397.3 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
8 mars 2015 à 22:46
8 mars 2015 à 22:46
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\vsserv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Windows\System32\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
() C:\Program Files (x86)\Abrosoft\FantaMorph5\FantaUp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Fork Ltd.) C:\Windows\Prey\versions\1.1.4\bin\windows\cronsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Joyent, Inc) C:\Windows\Prey\versions\1.3.6\bin\node.exe
() C:\Windows\KMSServerService\KMS Server Service.exe
() C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(SlimWare Utilities, Inc.) C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
(Fork, Ltd.) C:\Windows\Prey\versions\1.3.6\node_modules\triggers\bin\lightevt.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Safebox\safeboxservice.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\bdagent.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [SRS Premium Sound HD] => C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe [2165120 2012-03-22] (SRS Labs, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2866960 2011-12-19] (Synaptics Incorporated)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [989056 2011-12-14] (TOSHIBA Corporation)
HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1548208 2011-11-24] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [712096 2011-12-14] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender\bdagent.exe [1757520 2015-01-21] (Bitdefender)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13774040 2000-01-01] (Realtek Semiconductor)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-11-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-20\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-21-1711470111-1547835389-10093087-1000\...\Run: [Bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [568400 2015-01-21] (Bitdefender)
HKU\S-1-5-21-1711470111-1547835389-10093087-1000\...\Run: [Bitdefender Agent de l'application Wallet] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [615256 2014-10-04] (Bitdefender)
HKU\S-1-5-21-1711470111-1547835389-10093087-1000\...\Run: [Bitdefender Wallet] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1002048 2014-10-04] (Bitdefender)
HKU\S-1-5-21-1711470111-1547835389-10093087-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30879328 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-1711470111-1547835389-10093087-1000\...\Run: [VideoDownloaderUltimate] => C:\ProgramData\VideoDownloaderUltimateWinApp\VideoDownloaderUltimate.exe [1025656 2015-02-11] (Link64 GmbH)
HKU\S-1-5-21-1711470111-1547835389-10093087-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\ssText3d.scr [333824 2010-11-21] (Microsoft Corporation)
HKU\S-1-5-18\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-18\...\Run: [Bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [568400 2015-01-21] (Bitdefender)
HKU\S-1-5-18\...\Run: [Bitdefender Wallet] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1002048 2014-10-04] (Bitdefender)
HKU\S-1-5-18\...\Run: [Bitdefender Agent de l'application Wallet] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [615256 2014-10-04] (Bitdefender)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: [__SafeBox1] -> {152C96EB-288E-4EDC-B7C6-D21F8250ADF3} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll (Bitdefender)
ShellIconOverlayIdentifiers: [__SafeBox2] -> {342DAA0B-D796-460D-8566-901E08A1CCAD} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll (Bitdefender)
ShellIconOverlayIdentifiers: [__SafeBox3] -> {57595DAE-1AE1-4D97-A49E-67CBB53B52DF} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll (Bitdefender)
ShellIconOverlayIdentifiers: [__SafeBox4] -> {33816773-98AE-4723-ADE0-EBE54C8B5A67} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll (Bitdefender)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1711470111-1547835389-10093087-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM-x32 -> {C603C399-7B22-441C-B766-65C810001115} URL ={searchTerms}&{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TEUA;
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1711470111-1547835389-10093087-1000 -> {BEB837C4-3C3B-4EAF-9F77-03A32F2CC930} URL ={searchTerms}
SearchScopes: HKU\S-1-5-21-1711470111-1547835389-10093087-1000 -> {C603C399-7B22-441C-B766-65C810001115} URL =
SearchScopes: HKU\S-1-5-21-1711470111-1547835389-10093087-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL =
SearchScopes: HKU\S-1-5-21-1711470111-1547835389-10093087-1000 -> {DF196509-5D72-4049-8C19-0D0A9CFF1211} URL ={searchTerms}
BHO: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll [2014-10-04] (Bitdefender)
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-01-21] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll [2014-12-14] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2014-06-03] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-14] (Oracle Corporation)
BHO: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll [2011-11-03] (<TOSHIBA>)
BHO-x32: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll [2014-10-04] (Bitdefender)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-10-22] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-14] (Oracle Corporation)
BHO-x32: Programme d'aide de l'Assistant de connexion au compte Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2014-06-03] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-22] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-14] (Oracle Corporation)
BHO-x32: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll [2011-11-03] (<TOSHIBA>)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2014-06-03] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2014-06-03] (Google Inc.)
Toolbar: HKU\S-1-5-21-1711470111-1547835389-10093087-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2014-06-03] (Google Inc.)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-04-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer]
Tcpip\..\Interfaces\{0ADFAFBB-0B96-462C-B8A6-49945EA0DAB7}: [NameServer],
Tcpip\..\Interfaces\{65EC1E92-D376-44A1-BB2A-81404865171F}: [NameServer],
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FF ProfilePath: C:\Users\Tibo\AppData\Roaming\Mozilla\Firefox\Profiles\tzp62kwl.default-1425849421151
FF Homepage:
FF Plugin: -> C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-06] ()
FF Plugin:,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-12-14] (Oracle Corporation)
FF Plugin:,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-12-14] (Oracle Corporation)
FF Plugin: -> disabled No File
FF Plugin:,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin:,version=14.0 -> C:\PROGRA~1\MICROS~4\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-06] ()
FF Plugin-x32: WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2000-01-01] (Intel Corporation)
FF Plugin-x32: WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2000-01-01] (Intel Corporation)
FF Plugin-x32:,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-12-14] (Oracle Corporation)
FF Plugin-x32: -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\new_plugin\npjp2.dll No File
FF Plugin-x32:,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-12-14] (Oracle Corporation)
FF Plugin-x32: -> disabled No File
FF Plugin-x32:,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2014-05-21] (Microsoft Corporation)
FF Plugin-x32:,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32:,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32:,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32:,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-01-13] (Nero AG)
FF Plugin-x32: Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2014-11-16] (Google Inc.)
FF Plugin-x32: Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2014-11-16] (Google Inc.)
FF Plugin-x32:,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32:,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32:,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2014-12-06] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2014-05-21] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2015-01-09] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2015-01-09] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2015-01-09] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2015-01-09] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2015-01-09] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll [2015-01-09] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll [2015-01-09] (Apple Inc.)
FF HKLM\...\Thunderbird\Extensions: [] - C:\Program Files\Bitdefender\Bitdefender\bdtbext
FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender\bdtbext [2014-06-16]
FF HKLM-x32\...\Firefox\Extensions: [] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman
FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman [2014-06-16]
FF HKLM-x32\...\Thunderbird\Extensions: [] - C:\Program Files\Bitdefender\Bitdefender\bdtbext
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] -
CHR HKLM-x32\...\Chrome\Extension: [ccahoghmggldkcdjiebjkidpfongdfbl] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxcr.crx [2014-06-16]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] -
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Abrosoft: Abrosoft FantaMorph update permissions manager. 12810.; C:\Program Files (x86)\Abrosoft\FantaMorph5\FantaUp.exe [224176 2010-11-18] ()
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG)
S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender\bdparentalservice.exe [77632 2014-10-04] (Bitdefender)
R2 CronService; C:\Windows\Prey\versions\1.1.4\bin\windows\cronsvc.exe [18432 2014-05-15] (Fork Ltd.) [File not signed]
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-12-06] (WildTangent)
R2 GFNEXSrv; C:\Windows\System32\GFNEXSrv.exe [162824 2010-09-10] ()
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2000-01-01] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2000-01-01] (Intel Corporation)
R2 KMSServerService; C:\windows\KMSServerService\KMS Server Service.exe [294912 2014-06-16] () [File not signed]
R2 RichVideo; C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [247152 2009-04-17] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [292568 2000-01-01] (Realtek Semiconductor)
R2 SafeBox; C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [94624 2013-07-08] (Bitdefender)
R2 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe [67320 2014-10-04] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender\vsserv.exe [1538672 2015-01-21] (Bitdefender)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1288472 2015-01-21] (BitDefender)
R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [263032 2015-01-21] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [647752 2014-10-04] (BitDefender)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-11-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-11-24] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-11-24] (Avira Operations GmbH & Co. KG)
R1 BdfNdisf; c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [93600 2014-06-17] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC)
S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL)
S3 BDSandBox; C:\windows\system32\drivers\bdsandbox.sys [82824 2013-11-04] (BitDefender SRL)
R1 BDVEDISK; C:\Windows\System32\DRIVERS\bdvedisk.sys [76944 2012-04-17] (BitDefender)
S3 cpuz137; C:\Program Files (x86)\CPUID\PC Wizard 2013\pcwiz_x64.sys [26856 2014-02-17] (CPUID)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-11-21] (Intel Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [100312 2000-01-01] (Intel Corporation)
U5 RTSPER; C:\Windows\System32\Drivers\RTSPER.sys [788696 2000-01-01] (Realsil Semiconductor Corporation)
R3 RTSUER; C:\Windows\System32\Drivers\RtsUer.sys [377560 2000-01-01] (Realsil Semiconductor Corporation)
R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [2974424 2013-08-07] (Realtek Semiconductor Corporation )
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2015-03-08] ()
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [452040 2015-01-21] (BitDefender S.R.L.)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2014-06-23] (TuneUp Software)
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X]
S3 TDEIO; \??\C:\Windows\SysWOW64\sysprep\BOOTPRIO\tdeio64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-08 22:41 - 2015-03-08 22:42 - 00027977 _____ () C:\Users\Tibo\Downloads\FRST.txt
2015-03-08 22:41 - 2015-03-08 22:41 - 00000000 ____D () C:\FRST
2015-03-08 22:40 - 2015-03-08 22:40 - 02095104 _____ (Farbar) C:\Users\Tibo\Downloads\FRST64.exe
2015-03-08 21:55 - 2015-03-08 21:56 - 00284552 _____ () C:\windows\Minidump\030815-64272-01.dmp
2015-03-08 21:46 - 2015-03-08 22:05 - 00000000 ____D () C:\AdwCleaner
2015-03-08 01:02 - 2015-03-08 01:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-04 18:59 - 2015-03-04 19:00 - 00284552 _____ () C:\windows\Minidump\030415-117858-01.dmp
2015-03-01 18:39 - 2015-03-01 18:39 - 00284496 _____ () C:\windows\Minidump\030115-106923-01.dmp
2015-02-28 20:24 - 2015-03-06 20:22 - 00002070 _____ () C:\Users\Tibo\Desktop\YouTube.lnk
2015-02-28 01:36 - 2015-01-09 00:44 - 00419936 _____ () C:\windows\SysWOW64\locale.nls
2015-02-28 01:36 - 2015-01-09 00:43 - 00419936 _____ () C:\windows\system32\locale.nls
2015-02-27 21:03 - 2015-01-09 04:14 - 00950272 _____ (Microsoft Corporation) C:\windows\system32\perftrack.dll
2015-02-27 21:03 - 2015-01-09 04:14 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\wdi.dll
2015-02-27 21:03 - 2015-01-09 04:14 - 00029696 _____ (Microsoft Corporation) C:\windows\system32\powertracker.dll
2015-02-27 21:03 - 2015-01-09 03:48 - 00076800 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdi.dll
2015-02-20 15:59 - 2015-02-20 15:59 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2015-02-20 02:09 - 2015-02-20 02:09 - 00284496 _____ () C:\windows\Minidump\022015-40981-01.dmp
2015-02-18 21:10 - 2015-02-18 21:10 - 00000000 ____D () C:\Users\Tibo\AppData\Roaming\Blockscape
2015-02-18 21:08 - 2015-02-18 21:08 - 00000000 ____D () C:\Program Files (x86)\Microsoft XNA
2015-02-18 21:07 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_6.dll
2015-02-18 21:07 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_6.dll
2015-02-18 21:07 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_4.dll
2015-02-18 21:07 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_7.dll
2015-02-18 21:07 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_41.dll
2015-02-18 21:07 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\windows\SysWOW64\xinput1_3.dll
2015-02-18 21:07 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_33.dll
2015-02-18 21:06 - 2015-02-18 21:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blockscape
2015-02-17 23:29 - 2015-02-17 23:29 - 00003116 _____ () C:\windows\System32\Tasks\{B6FDA11E-F672-4E2A-A4FF-B2C20F73F42C}
2015-02-17 23:24 - 2015-02-17 23:24 - 00284496 _____ () C:\windows\Minidump\021715-22105-01.dmp
2015-02-17 22:58 - 2015-02-17 22:58 - 00284496 _____ () C:\windows\Minidump\021715-41184-01.dmp
2015-02-17 22:53 - 2015-02-17 22:53 - 00284552 _____ () C:\windows\Minidump\021715-61433-01.dmp
2015-02-17 13:34 - 2015-02-17 13:34 - 00284496 _____ () C:\windows\Minidump\021715-30529-01.dmp
2015-02-17 13:28 - 2015-02-17 13:28 - 00284496 _____ () C:\windows\Minidump\021715-27627-01.dmp
2015-02-17 13:16 - 2015-02-17 13:16 - 00000000 ____D () C:\Users\Tibo\.android
2015-02-17 00:14 - 2015-02-17 00:14 - 00284496 _____ () C:\windows\Minidump\021715-32526-01.dmp
2015-02-16 21:47 - 2015-02-16 21:47 - 00284496 _____ () C:\windows\Minidump\021615-31247-01.dmp
2015-02-16 10:49 - 2015-02-16 10:49 - 00284496 _____ () C:\windows\Minidump\021615-28532-01.dmp
2015-02-14 12:18 - 2015-02-14 12:18 - 00284496 _____ () C:\windows\Minidump\021415-66706-01.dmp
2015-02-14 12:12 - 2015-02-14 12:12 - 00284496 _____ () C:\windows\Minidump\021415-69966-01.dmp
2015-02-13 23:06 - 2015-02-13 23:06 - 00000000 ____D () C:\Users\Tibo\Documents\Android
2015-02-13 23:06 - 2015-02-13 23:06 - 00000000 ____D () C:\Users\Public\Documents\Android
2015-02-13 19:56 - 2015-02-13 19:56 - 00284496 _____ () C:\windows\Minidump\021315-25350-01.dmp
2015-02-13 19:50 - 2015-02-13 19:51 - 00284496 _____ () C:\windows\Minidump\021315-27112-01.dmp
2015-02-13 19:42 - 2015-02-13 19:42 - 00284496 _____ () C:\windows\Minidump\021315-44694-01.dmp
2015-02-13 17:45 - 2015-02-13 17:45 - 00284496 _____ () C:\windows\Minidump\021315-32822-01.dmp
2015-02-12 19:56 - 2015-02-12 19:56 - 00284496 _____ () C:\windows\Minidump\021215-58859-01.dmp
2015-02-12 17:42 - 2015-01-23 05:42 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-02-12 17:42 - 2015-01-23 05:41 - 06041600 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-02-12 17:42 - 2015-01-23 04:43 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-02-12 17:42 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-02-11 20:32 - 2015-02-11 20:32 - 00000000 ____D () C:\ProgramData\VideoDownloaderUltimateWinApp
2015-02-11 16:33 - 2015-01-14 06:47 - 00389808 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-02-11 16:33 - 2015-01-14 06:09 - 00342712 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-02-11 16:33 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-02-11 16:33 - 2015-01-12 04:05 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-02-11 16:33 - 2015-01-12 04:05 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-02-11 16:33 - 2015-01-12 03:49 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-02-11 16:33 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-02-11 16:33 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-02-11 16:33 - 2015-01-12 03:48 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-02-11 16:33 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-02-11 16:33 - 2015-01-12 03:40 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-02-11 16:33 - 2015-01-12 03:39 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-02-11 16:33 - 2015-01-12 03:36 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-02-11 16:33 - 2015-01-12 03:34 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-02-11 16:33 - 2015-01-12 03:34 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-02-11 16:33 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-02-11 16:33 - 2015-01-12 03:25 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-02-11 16:33 - 2015-01-12 03:21 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-02-11 16:33 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-02-11 16:33 - 2015-01-12 03:13 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 16:33 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-02-11 16:33 - 2015-01-12 03:08 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-02-11 16:33 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-02-11 16:33 - 2015-01-12 03:07 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-02-11 16:33 - 2015-01-12 03:07 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-02-11 16:33 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-02-11 16:33 - 2015-01-12 03:04 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-02-11 16:33 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-02-11 16:33 - 2015-01-12 03:00 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-02-11 16:33 - 2015-01-12 02:59 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-02-11 16:33 - 2015-01-12 02:57 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-02-11 16:33 - 2015-01-12 02:55 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-02-11 16:33 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-02-11 16:33 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-02-11 16:33 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-02-11 16:33 - 2015-01-12 02:46 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-02-11 16:33 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-02-11 16:33 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-02-11 16:33 - 2015-01-12 02:40 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-02-11 16:33 - 2015-01-12 02:36 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-02-11 16:33 - 2015-01-12 02:35 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-02-11 16:33 - 2015-01-12 02:33 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-02-11 16:33 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-02-11 16:33 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-02-11 16:33 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-02-11 16:33 - 2015-01-12 02:22 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-02-11 16:33 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-02-11 16:33 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-02-11 16:33 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-02-11 16:33 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-02-11 16:33 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-02-11 16:33 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-02-11 16:25 - 2015-01-10 07:48 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-02-11 16:25 - 2015-01-10 07:48 - 00341504 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-02-11 16:25 - 2015-01-10 07:48 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-02-11 16:25 - 2015-01-10 07:48 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-02-11 16:25 - 2015-01-10 07:48 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-02-11 16:25 - 2015-01-10 07:48 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-02-11 16:25 - 2015-01-10 07:48 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-02-11 16:25 - 2015-01-10 07:27 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-02-11 16:25 - 2015-01-10 07:27 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-02-11 16:25 - 2015-01-10 07:27 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-02-11 16:25 - 2015-01-10 07:27 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-02-11 16:25 - 2015-01-10 07:27 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-02-11 16:25 - 2015-01-10 07:27 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-02-11 16:25 - 2015-01-10 07:27 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-02-11 16:20 - 2015-01-15 09:14 - 00155072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-02-11 16:20 - 2015-01-15 09:14 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-02-11 16:20 - 2015-01-15 09:09 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-02-11 16:20 - 2015-01-15 09:09 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-02-11 16:20 - 2015-01-15 09:09 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-02-11 16:20 - 2015-01-15 09:09 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-02-11 16:20 - 2015-01-15 09:09 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-02-11 16:20 - 2015-01-15 09:08 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-02-11 16:20 - 2015-01-15 09:06 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-02-11 16:20 - 2015-01-15 09:06 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-02-11 16:20 - 2015-01-15 09:04 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-02-11 16:20 - 2015-01-15 08:42 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-02-11 16:20 - 2015-01-15 08:42 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-02-11 16:20 - 2015-01-15 08:41 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-02-11 16:20 - 2015-01-15 08:39 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-02-11 16:20 - 2015-01-15 08:39 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-02-11 16:20 - 2015-01-15 08:37 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-02-11 16:20 - 2015-01-15 05:22 - 00458824 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-02-11 16:20 - 2015-01-13 04:10 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2015-02-11 16:20 - 2015-01-13 03:49 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2015-02-11 16:19 - 2014-12-12 06:31 - 01480192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2015-02-11 16:19 - 2014-12-12 06:07 - 01174528 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2015-02-11 16:19 - 2014-11-26 04:53 - 00861696 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2015-02-11 16:19 - 2014-11-26 04:32 - 00571904 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2015-02-11 16:19 - 2014-07-07 03:07 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2015-02-11 16:19 - 2014-07-07 03:06 - 00187904 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2015-02-11 16:19 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2015-02-11 16:19 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2015-02-11 16:18 - 2015-01-14 07:09 - 05554112 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-02-11 16:18 - 2015-01-14 07:05 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-02-11 16:18 - 2015-01-14 07:05 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-02-11 16:18 - 2015-01-14 07:04 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-02-11 16:18 - 2015-01-14 06:44 - 03972544 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-02-11 16:18 - 2015-01-14 06:44 - 03917760 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-02-11 16:18 - 2015-01-14 06:41 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-02-11 16:18 - 2014-12-08 04:09 - 00406528 _____ (Microsoft Corporation) C:\windows\system32\scesrv.dll
2015-02-11 16:18 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\windows\SysWOW64\scesrv.dll
2015-02-11 16:16 - 2015-01-09 03:03 - 03201536 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-02-09 20:11 - 2015-02-09 20:11 - 00001242 _____ () C:\Users\Tibo\Desktop\Paint.lnk
2015-02-09 20:11 - 2015-02-09 20:11 - 00000755 _____ () C:\Users\Tibo\.recently-used.xbel
2015-02-09 20:05 - 2015-02-09 20:05 - 00000000 ____D () C:\Users\Tibo\MyPaint
2015-02-09 17:51 - 2015-02-09 17:51 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2015-02-09 17:51 - 2015-02-09 17:51 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2015-02-09 17:50 - 2015-02-09 17:50 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Google
2015-02-09 17:50 - 2015-02-09 17:50 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe
2015-02-09 17:50 - 2015-02-09 17:50 - 00000000 ____D () C:\Users\Default\AppData\Local\Google
2015-02-09 17:50 - 2015-02-09 17:50 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Google
2015-02-09 17:50 - 2015-02-09 17:50 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe
2015-02-09 17:50 - 2015-02-09 17:50 - 00000000 ____D () C:\Users\Default User\AppData\Local\Google
2015-02-09 17:48 - 2015-02-09 17:48 - 00000000 ____D () C:\Users\Default\AppData\Local\SlimWare Utilities Inc
2015-02-09 17:48 - 2015-02-09 17:48 - 00000000 ____D () C:\Users\Default User\AppData\Local\SlimWare Utilities Inc
2015-02-06 18:36 - 2015-02-06 19:44 - 00002134 _____ () C:\Users\Tibo\Desktop\Google Traduction.lnk
2015-02-06 18:30 - 2015-02-06 18:30 - 00284496 _____ () C:\windows\Minidump\020615-115425-01.dmp
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-08 22:34 - 2014-06-03 11:31 - 00000000 ____D () C:\Users\Tibo\AppData\Roaming\Skype
2015-03-08 22:23 - 2012-05-11 04:18 - 00001070 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-08 22:21 - 2014-11-04 20:10 - 00005054 _____ () C:\windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Tibo-TOSH-Tibo Tibo-TOSH
2015-03-08 22:11 - 2012-07-11 23:22 - 02022333 _____ () C:\windows\WindowsUpdate.log
2015-03-08 22:06 - 2009-07-14 05:45 - 00024608 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-08 22:06 - 2009-07-14 05:45 - 00024608 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-08 22:04 - 2012-05-11 04:13 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-03-08 21:58 - 2015-01-25 11:33 - 00002832 _____ () C:\windows\System32\Tasks\SlimDrivers Startup
2015-03-08 21:58 - 2015-01-25 11:33 - 00000408 _____ () C:\windows\Tasks\SlimDrivers Startup.job
2015-03-08 21:57 - 2015-01-25 11:33 - 00016152 _____ () C:\windows\system32\Drivers\SWDUMon.sys
2015-03-08 21:56 - 2014-12-11 21:18 - 00001334 _____ () C:\windows\Tasks\WQRHCI.job
2015-03-08 21:56 - 2014-12-11 21:17 - 00001678 _____ () C:\windows\Tasks\TYTLPZ.job
2015-03-08 21:56 - 2012-05-11 04:18 - 00001066 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-08 21:56 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-03-08 21:56 - 2009-07-14 05:51 - 00079031 _____ () C:\windows\setupact.log
2015-03-08 21:55 - 2014-11-16 21:32 - 494228809 _____ () C:\windows\MEMORY.DMP
2015-03-08 21:55 - 2014-11-16 21:32 - 00000000 ____D () C:\windows\Minidump
2015-03-08 15:21 - 2014-06-03 12:32 - 00000000 ____D () C:\Users\Tibo\AppData\Roaming\vlc
2015-03-08 15:16 - 2011-07-05 15:04 - 00747570 _____ () C:\windows\system32\perfh00C.dat
2015-03-08 15:16 - 2011-07-05 15:04 - 00150062 _____ () C:\windows\system32\perfc00C.dat
2015-03-08 15:16 - 2009-07-14 06:13 - 01668256 _____ () C:\windows\system32\PerfStringBackup.INI
2015-03-08 09:54 - 2010-11-21 04:47 - 00627820 _____ () C:\windows\PFRO.log
2015-03-08 02:29 - 2015-01-27 16:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak
2015-03-08 02:29 - 2015-01-07 13:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-05 21:37 - 2014-12-11 21:13 - 00332448 _____ (Say Media Group LTD) C:\windows\SysWOW64\ColorMedia.dll
2015-03-02 23:19 - 2014-12-19 20:59 - 00000000 ____D () C:\Users\Tibo\AppData\Local\
2015-03-02 22:57 - 2015-01-09 22:20 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2015-03-02 22:53 - 2015-01-09 22:13 - 00000000 ____D () C:\Program Files (x86)\
2015-02-28 11:40 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\tracing
2015-02-18 01:56 - 2014-06-03 11:15 - 00000000 ____D () C:\Users\Tibo
2015-02-17 23:36 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2015-02-17 20:59 - 2014-06-16 14:27 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-02-17 20:57 - 2014-06-16 10:05 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-16 13:40 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache
2015-02-12 19:46 - 2014-06-25 19:11 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2015-02-12 17:25 - 2009-07-14 05:45 - 00444952 _____ () C:\windows\system32\FNTCACHE.DAT
2015-02-12 17:22 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\tr-TR
2015-02-12 17:22 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\tr-TR
2015-02-11 22:40 - 2009-07-14 03:34 - 00000612 _____ () C:\windows\win.ini
2015-02-11 22:34 - 2014-06-15 21:06 - 00000000 ____D () C:\windows\system32\MRT
2015-02-11 22:27 - 2014-06-15 21:06 - 116773704 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-02-09 20:06 - 2014-06-27 19:50 - 00000000 ____D () C:\Users\Tibo\AppData\Roaming\gtk-2.0
2015-02-09 18:19 - 2014-06-15 17:41 - 00018497 _____ () C:\windows\IE11_main.log
2015-02-09 17:58 - 2015-01-09 10:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-02-09 17:58 - 2015-01-09 10:32 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-02-09 17:58 - 2015-01-09 10:31 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-08 18:37 - 2012-07-11 23:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2015-02-08 14:40 - 2015-01-25 14:35 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2015-02-08 14:40 - 2014-06-30 12:27 - 00000000 ____D () C:\Users\Tibo\AppData\Local\Downloaded Installations
2015-02-08 14:40 - 2014-06-16 10:05 - 00000000 ____D () C:\Users\Tibo\AppData\Local\Microsoft Help
2015-02-06 18:05 - 2012-05-11 04:13 - 00701616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-02-06 18:05 - 2012-05-11 04:13 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-06 18:05 - 2012-05-11 04:13 - 00003768 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
==================== Files in the root of some directories =======
2014-09-03 22:36 - 2014-09-03 22:36 - 0001248 _____ () C:\Users\Tibo\AppData\Roaming\TYTLPZ
2014-12-27 01:23 - 2014-12-28 02:23 - 0000059 _____ () C:\Users\Tibo\AppData\Roaming\WB.CFG
2014-09-03 22:36 - 2014-09-03 22:36 - 0002086 _____ () C:\Users\Tibo\AppData\Roaming\WQRHCI
2014-07-02 17:50 - 2014-08-30 20:32 - 0043008 _____ () C:\Users\Tibo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-11 21:39 - 2014-12-11 21:38 - 0613057 _____ () C:\Users\Tibo\AppData\Local\nsw4FCA.tmp
2014-12-13 12:33 - 2014-12-13 12:32 - 0613057 _____ () C:\Users\Tibo\AppData\Local\nsxC13.tmp
2014-06-16 08:59 - 2014-06-16 08:59 - 0766457 _____ () C:\ProgramData\1402904772.bdinstall.bin
Some content of TEMP:
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-28 14:34
==================== End Of Log ============================
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\vsserv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Windows\System32\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
() C:\Program Files (x86)\Abrosoft\FantaMorph5\FantaUp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Fork Ltd.) C:\Windows\Prey\versions\1.1.4\bin\windows\cronsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Joyent, Inc) C:\Windows\Prey\versions\1.3.6\bin\node.exe
() C:\Windows\KMSServerService\KMS Server Service.exe
() C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(SlimWare Utilities, Inc.) C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
(Fork, Ltd.) C:\Windows\Prey\versions\1.3.6\node_modules\triggers\bin\lightevt.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Safebox\safeboxservice.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\bdagent.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [SRS Premium Sound HD] => C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe [2165120 2012-03-22] (SRS Labs, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2866960 2011-12-19] (Synaptics Incorporated)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [989056 2011-12-14] (TOSHIBA Corporation)
HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1548208 2011-11-24] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [712096 2011-12-14] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender\bdagent.exe [1757520 2015-01-21] (Bitdefender)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13774040 2000-01-01] (Realtek Semiconductor)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-11-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-20\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-21-1711470111-1547835389-10093087-1000\...\Run: [Bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [568400 2015-01-21] (Bitdefender)
HKU\S-1-5-21-1711470111-1547835389-10093087-1000\...\Run: [Bitdefender Agent de l'application Wallet] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [615256 2014-10-04] (Bitdefender)
HKU\S-1-5-21-1711470111-1547835389-10093087-1000\...\Run: [Bitdefender Wallet] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1002048 2014-10-04] (Bitdefender)
HKU\S-1-5-21-1711470111-1547835389-10093087-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30879328 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-1711470111-1547835389-10093087-1000\...\Run: [VideoDownloaderUltimate] => C:\ProgramData\VideoDownloaderUltimateWinApp\VideoDownloaderUltimate.exe [1025656 2015-02-11] (Link64 GmbH)
HKU\S-1-5-21-1711470111-1547835389-10093087-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\ssText3d.scr [333824 2010-11-21] (Microsoft Corporation)
HKU\S-1-5-18\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-18\...\Run: [Bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [568400 2015-01-21] (Bitdefender)
HKU\S-1-5-18\...\Run: [Bitdefender Wallet] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1002048 2014-10-04] (Bitdefender)
HKU\S-1-5-18\...\Run: [Bitdefender Agent de l'application Wallet] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [615256 2014-10-04] (Bitdefender)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: [__SafeBox1] -> {152C96EB-288E-4EDC-B7C6-D21F8250ADF3} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll (Bitdefender)
ShellIconOverlayIdentifiers: [__SafeBox2] -> {342DAA0B-D796-460D-8566-901E08A1CCAD} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll (Bitdefender)
ShellIconOverlayIdentifiers: [__SafeBox3] -> {57595DAE-1AE1-4D97-A49E-67CBB53B52DF} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll (Bitdefender)
ShellIconOverlayIdentifiers: [__SafeBox4] -> {33816773-98AE-4723-ADE0-EBE54C8B5A67} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll (Bitdefender)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1711470111-1547835389-10093087-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM-x32 -> {C603C399-7B22-441C-B766-65C810001115} URL ={searchTerms}&{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TEUA;
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1711470111-1547835389-10093087-1000 -> {BEB837C4-3C3B-4EAF-9F77-03A32F2CC930} URL ={searchTerms}
SearchScopes: HKU\S-1-5-21-1711470111-1547835389-10093087-1000 -> {C603C399-7B22-441C-B766-65C810001115} URL =
SearchScopes: HKU\S-1-5-21-1711470111-1547835389-10093087-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL =
SearchScopes: HKU\S-1-5-21-1711470111-1547835389-10093087-1000 -> {DF196509-5D72-4049-8C19-0D0A9CFF1211} URL ={searchTerms}
BHO: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll [2014-10-04] (Bitdefender)
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-01-21] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll [2014-12-14] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2014-06-03] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-14] (Oracle Corporation)
BHO: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll [2011-11-03] (<TOSHIBA>)
BHO-x32: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll [2014-10-04] (Bitdefender)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-10-22] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-14] (Oracle Corporation)
BHO-x32: Programme d'aide de l'Assistant de connexion au compte Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2014-06-03] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-22] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-14] (Oracle Corporation)
BHO-x32: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll [2011-11-03] (<TOSHIBA>)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2014-06-03] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2014-06-03] (Google Inc.)
Toolbar: HKU\S-1-5-21-1711470111-1547835389-10093087-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2014-06-03] (Google Inc.)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-04-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer]
Tcpip\..\Interfaces\{0ADFAFBB-0B96-462C-B8A6-49945EA0DAB7}: [NameServer],
Tcpip\..\Interfaces\{65EC1E92-D376-44A1-BB2A-81404865171F}: [NameServer],
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FF ProfilePath: C:\Users\Tibo\AppData\Roaming\Mozilla\Firefox\Profiles\tzp62kwl.default-1425849421151
FF Homepage:
FF Plugin: -> C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-06] ()
FF Plugin:,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-12-14] (Oracle Corporation)
FF Plugin:,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-12-14] (Oracle Corporation)
FF Plugin: -> disabled No File
FF Plugin:,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin:,version=14.0 -> C:\PROGRA~1\MICROS~4\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-06] ()
FF Plugin-x32: WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2000-01-01] (Intel Corporation)
FF Plugin-x32: WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2000-01-01] (Intel Corporation)
FF Plugin-x32:,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-12-14] (Oracle Corporation)
FF Plugin-x32: -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\new_plugin\npjp2.dll No File
FF Plugin-x32:,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-12-14] (Oracle Corporation)
FF Plugin-x32: -> disabled No File
FF Plugin-x32:,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2014-05-21] (Microsoft Corporation)
FF Plugin-x32:,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32:,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32:,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32:,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-01-13] (Nero AG)
FF Plugin-x32: Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2014-11-16] (Google Inc.)
FF Plugin-x32: Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2014-11-16] (Google Inc.)
FF Plugin-x32:,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32:,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32:,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2014-12-06] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2014-05-21] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2015-01-09] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2015-01-09] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2015-01-09] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2015-01-09] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2015-01-09] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll [2015-01-09] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll [2015-01-09] (Apple Inc.)
FF HKLM\...\Thunderbird\Extensions: [] - C:\Program Files\Bitdefender\Bitdefender\bdtbext
FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender\bdtbext [2014-06-16]
FF HKLM-x32\...\Firefox\Extensions: [] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman
FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman [2014-06-16]
FF HKLM-x32\...\Thunderbird\Extensions: [] - C:\Program Files\Bitdefender\Bitdefender\bdtbext
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] -
CHR HKLM-x32\...\Chrome\Extension: [ccahoghmggldkcdjiebjkidpfongdfbl] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxcr.crx [2014-06-16]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] -
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Abrosoft: Abrosoft FantaMorph update permissions manager. 12810.; C:\Program Files (x86)\Abrosoft\FantaMorph5\FantaUp.exe [224176 2010-11-18] ()
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG)
S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender\bdparentalservice.exe [77632 2014-10-04] (Bitdefender)
R2 CronService; C:\Windows\Prey\versions\1.1.4\bin\windows\cronsvc.exe [18432 2014-05-15] (Fork Ltd.) [File not signed]
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-12-06] (WildTangent)
R2 GFNEXSrv; C:\Windows\System32\GFNEXSrv.exe [162824 2010-09-10] ()
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2000-01-01] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2000-01-01] (Intel Corporation)
R2 KMSServerService; C:\windows\KMSServerService\KMS Server Service.exe [294912 2014-06-16] () [File not signed]
R2 RichVideo; C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [247152 2009-04-17] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [292568 2000-01-01] (Realtek Semiconductor)
R2 SafeBox; C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [94624 2013-07-08] (Bitdefender)
R2 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe [67320 2014-10-04] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender\vsserv.exe [1538672 2015-01-21] (Bitdefender)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 vToolbarUpdater18.1.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1288472 2015-01-21] (BitDefender)
R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [263032 2015-01-21] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [647752 2014-10-04] (BitDefender)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-11-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-11-24] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-11-24] (Avira Operations GmbH & Co. KG)
R1 BdfNdisf; c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [93600 2014-06-17] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC)
S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL)
S3 BDSandBox; C:\windows\system32\drivers\bdsandbox.sys [82824 2013-11-04] (BitDefender SRL)
R1 BDVEDISK; C:\Windows\System32\DRIVERS\bdvedisk.sys [76944 2012-04-17] (BitDefender)
S3 cpuz137; C:\Program Files (x86)\CPUID\PC Wizard 2013\pcwiz_x64.sys [26856 2014-02-17] (CPUID)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-11-21] (Intel Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [100312 2000-01-01] (Intel Corporation)
U5 RTSPER; C:\Windows\System32\Drivers\RTSPER.sys [788696 2000-01-01] (Realsil Semiconductor Corporation)
R3 RTSUER; C:\Windows\System32\Drivers\RtsUer.sys [377560 2000-01-01] (Realsil Semiconductor Corporation)
R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [2974424 2013-08-07] (Realtek Semiconductor Corporation )
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2015-03-08] ()
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [452040 2015-01-21] (BitDefender S.R.L.)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2014-06-23] (TuneUp Software)
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X]
S3 TDEIO; \??\C:\Windows\SysWOW64\sysprep\BOOTPRIO\tdeio64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-08 22:41 - 2015-03-08 22:42 - 00027977 _____ () C:\Users\Tibo\Downloads\FRST.txt
2015-03-08 22:41 - 2015-03-08 22:41 - 00000000 ____D () C:\FRST
2015-03-08 22:40 - 2015-03-08 22:40 - 02095104 _____ (Farbar) C:\Users\Tibo\Downloads\FRST64.exe
2015-03-08 21:55 - 2015-03-08 21:56 - 00284552 _____ () C:\windows\Minidump\030815-64272-01.dmp
2015-03-08 21:46 - 2015-03-08 22:05 - 00000000 ____D () C:\AdwCleaner
2015-03-08 01:02 - 2015-03-08 01:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-04 18:59 - 2015-03-04 19:00 - 00284552 _____ () C:\windows\Minidump\030415-117858-01.dmp
2015-03-01 18:39 - 2015-03-01 18:39 - 00284496 _____ () C:\windows\Minidump\030115-106923-01.dmp
2015-02-28 20:24 - 2015-03-06 20:22 - 00002070 _____ () C:\Users\Tibo\Desktop\YouTube.lnk
2015-02-28 01:36 - 2015-01-09 00:44 - 00419936 _____ () C:\windows\SysWOW64\locale.nls
2015-02-28 01:36 - 2015-01-09 00:43 - 00419936 _____ () C:\windows\system32\locale.nls
2015-02-27 21:03 - 2015-01-09 04:14 - 00950272 _____ (Microsoft Corporation) C:\windows\system32\perftrack.dll
2015-02-27 21:03 - 2015-01-09 04:14 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\wdi.dll
2015-02-27 21:03 - 2015-01-09 04:14 - 00029696 _____ (Microsoft Corporation) C:\windows\system32\powertracker.dll
2015-02-27 21:03 - 2015-01-09 03:48 - 00076800 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdi.dll
2015-02-20 15:59 - 2015-02-20 15:59 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2015-02-20 02:09 - 2015-02-20 02:09 - 00284496 _____ () C:\windows\Minidump\022015-40981-01.dmp
2015-02-18 21:10 - 2015-02-18 21:10 - 00000000 ____D () C:\Users\Tibo\AppData\Roaming\Blockscape
2015-02-18 21:08 - 2015-02-18 21:08 - 00000000 ____D () C:\Program Files (x86)\Microsoft XNA
2015-02-18 21:07 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAudio2_6.dll
2015-02-18 21:07 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\windows\SysWOW64\xactengine3_6.dll
2015-02-18 21:07 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\windows\SysWOW64\XAPOFX1_4.dll
2015-02-18 21:07 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\windows\SysWOW64\X3DAudio1_7.dll
2015-02-18 21:07 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_41.dll
2015-02-18 21:07 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\windows\SysWOW64\xinput1_3.dll
2015-02-18 21:07 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3dx9_33.dll
2015-02-18 21:06 - 2015-02-18 21:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blockscape
2015-02-17 23:29 - 2015-02-17 23:29 - 00003116 _____ () C:\windows\System32\Tasks\{B6FDA11E-F672-4E2A-A4FF-B2C20F73F42C}
2015-02-17 23:24 - 2015-02-17 23:24 - 00284496 _____ () C:\windows\Minidump\021715-22105-01.dmp
2015-02-17 22:58 - 2015-02-17 22:58 - 00284496 _____ () C:\windows\Minidump\021715-41184-01.dmp
2015-02-17 22:53 - 2015-02-17 22:53 - 00284552 _____ () C:\windows\Minidump\021715-61433-01.dmp
2015-02-17 13:34 - 2015-02-17 13:34 - 00284496 _____ () C:\windows\Minidump\021715-30529-01.dmp
2015-02-17 13:28 - 2015-02-17 13:28 - 00284496 _____ () C:\windows\Minidump\021715-27627-01.dmp
2015-02-17 13:16 - 2015-02-17 13:16 - 00000000 ____D () C:\Users\Tibo\.android
2015-02-17 00:14 - 2015-02-17 00:14 - 00284496 _____ () C:\windows\Minidump\021715-32526-01.dmp
2015-02-16 21:47 - 2015-02-16 21:47 - 00284496 _____ () C:\windows\Minidump\021615-31247-01.dmp
2015-02-16 10:49 - 2015-02-16 10:49 - 00284496 _____ () C:\windows\Minidump\021615-28532-01.dmp
2015-02-14 12:18 - 2015-02-14 12:18 - 00284496 _____ () C:\windows\Minidump\021415-66706-01.dmp
2015-02-14 12:12 - 2015-02-14 12:12 - 00284496 _____ () C:\windows\Minidump\021415-69966-01.dmp
2015-02-13 23:06 - 2015-02-13 23:06 - 00000000 ____D () C:\Users\Tibo\Documents\Android
2015-02-13 23:06 - 2015-02-13 23:06 - 00000000 ____D () C:\Users\Public\Documents\Android
2015-02-13 19:56 - 2015-02-13 19:56 - 00284496 _____ () C:\windows\Minidump\021315-25350-01.dmp
2015-02-13 19:50 - 2015-02-13 19:51 - 00284496 _____ () C:\windows\Minidump\021315-27112-01.dmp
2015-02-13 19:42 - 2015-02-13 19:42 - 00284496 _____ () C:\windows\Minidump\021315-44694-01.dmp
2015-02-13 17:45 - 2015-02-13 17:45 - 00284496 _____ () C:\windows\Minidump\021315-32822-01.dmp
2015-02-12 19:56 - 2015-02-12 19:56 - 00284496 _____ () C:\windows\Minidump\021215-58859-01.dmp
2015-02-12 17:42 - 2015-01-23 05:42 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-02-12 17:42 - 2015-01-23 05:41 - 06041600 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-02-12 17:42 - 2015-01-23 04:43 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-02-12 17:42 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-02-11 20:32 - 2015-02-11 20:32 - 00000000 ____D () C:\ProgramData\VideoDownloaderUltimateWinApp
2015-02-11 16:33 - 2015-01-14 06:47 - 00389808 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-02-11 16:33 - 2015-01-14 06:09 - 00342712 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-02-11 16:33 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-02-11 16:33 - 2015-01-12 04:05 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-02-11 16:33 - 2015-01-12 04:05 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-02-11 16:33 - 2015-01-12 03:49 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-02-11 16:33 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-02-11 16:33 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-02-11 16:33 - 2015-01-12 03:48 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-02-11 16:33 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-02-11 16:33 - 2015-01-12 03:40 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-02-11 16:33 - 2015-01-12 03:39 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-02-11 16:33 - 2015-01-12 03:36 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-02-11 16:33 - 2015-01-12 03:34 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-02-11 16:33 - 2015-01-12 03:34 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-02-11 16:33 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-02-11 16:33 - 2015-01-12 03:25 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-02-11 16:33 - 2015-01-12 03:21 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-02-11 16:33 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-02-11 16:33 - 2015-01-12 03:13 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 16:33 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-02-11 16:33 - 2015-01-12 03:08 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-02-11 16:33 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-02-11 16:33 - 2015-01-12 03:07 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-02-11 16:33 - 2015-01-12 03:07 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-02-11 16:33 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-02-11 16:33 - 2015-01-12 03:04 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-02-11 16:33 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-02-11 16:33 - 2015-01-12 03:00 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-02-11 16:33 - 2015-01-12 02:59 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-02-11 16:33 - 2015-01-12 02:57 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-02-11 16:33 - 2015-01-12 02:55 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-02-11 16:33 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-02-11 16:33 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-02-11 16:33 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-02-11 16:33 - 2015-01-12 02:46 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-02-11 16:33 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-02-11 16:33 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-02-11 16:33 - 2015-01-12 02:40 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-02-11 16:33 - 2015-01-12 02:36 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-02-11 16:33 - 2015-01-12 02:35 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-02-11 16:33 - 2015-01-12 02:33 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-02-11 16:33 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-02-11 16:33 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-02-11 16:33 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-02-11 16:33 - 2015-01-12 02:22 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-02-11 16:33 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-02-11 16:33 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-02-11 16:33 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-02-11 16:33 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-02-11 16:33 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-02-11 16:33 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-02-11 16:25 - 2015-01-10 07:48 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-02-11 16:25 - 2015-01-10 07:48 - 00341504 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-02-11 16:25 - 2015-01-10 07:48 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-02-11 16:25 - 2015-01-10 07:48 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-02-11 16:25 - 2015-01-10 07:48 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-02-11 16:25 - 2015-01-10 07:48 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-02-11 16:25 - 2015-01-10 07:48 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-02-11 16:25 - 2015-01-10 07:27 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-02-11 16:25 - 2015-01-10 07:27 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-02-11 16:25 - 2015-01-10 07:27 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-02-11 16:25 - 2015-01-10 07:27 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-02-11 16:25 - 2015-01-10 07:27 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-02-11 16:25 - 2015-01-10 07:27 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-02-11 16:25 - 2015-01-10 07:27 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-02-11 16:20 - 2015-01-15 09:14 - 00155072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-02-11 16:20 - 2015-01-15 09:14 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-02-11 16:20 - 2015-01-15 09:09 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-02-11 16:20 - 2015-01-15 09:09 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-02-11 16:20 - 2015-01-15 09:09 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-02-11 16:20 - 2015-01-15 09:09 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-02-11 16:20 - 2015-01-15 09:09 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-02-11 16:20 - 2015-01-15 09:08 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-02-11 16:20 - 2015-01-15 09:06 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-02-11 16:20 - 2015-01-15 09:06 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-02-11 16:20 - 2015-01-15 09:04 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-02-11 16:20 - 2015-01-15 08:42 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-02-11 16:20 - 2015-01-15 08:42 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-02-11 16:20 - 2015-01-15 08:41 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-02-11 16:20 - 2015-01-15 08:39 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-02-11 16:20 - 2015-01-15 08:39 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-02-11 16:20 - 2015-01-15 08:37 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-02-11 16:20 - 2015-01-15 05:22 - 00458824 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-02-11 16:20 - 2015-01-13 04:10 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2015-02-11 16:20 - 2015-01-13 03:49 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2015-02-11 16:19 - 2014-12-12 06:31 - 01480192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2015-02-11 16:19 - 2014-12-12 06:07 - 01174528 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2015-02-11 16:19 - 2014-11-26 04:53 - 00861696 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2015-02-11 16:19 - 2014-11-26 04:32 - 00571904 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2015-02-11 16:19 - 2014-07-07 03:07 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2015-02-11 16:19 - 2014-07-07 03:06 - 00187904 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2015-02-11 16:19 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2015-02-11 16:19 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2015-02-11 16:18 - 2015-01-14 07:09 - 05554112 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-02-11 16:18 - 2015-01-14 07:05 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-02-11 16:18 - 2015-01-14 07:05 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-02-11 16:18 - 2015-01-14 07:04 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-02-11 16:18 - 2015-01-14 06:44 - 03972544 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-02-11 16:18 - 2015-01-14 06:44 - 03917760 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-02-11 16:18 - 2015-01-14 06:41 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-02-11 16:18 - 2014-12-08 04:09 - 00406528 _____ (Microsoft Corporation) C:\windows\system32\scesrv.dll
2015-02-11 16:18 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\windows\SysWOW64\scesrv.dll
2015-02-11 16:16 - 2015-01-09 03:03 - 03201536 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-02-09 20:11 - 2015-02-09 20:11 - 00001242 _____ () C:\Users\Tibo\Desktop\Paint.lnk
2015-02-09 20:11 - 2015-02-09 20:11 - 00000755 _____ () C:\Users\Tibo\.recently-used.xbel
2015-02-09 20:05 - 2015-02-09 20:05 - 00000000 ____D () C:\Users\Tibo\MyPaint
2015-02-09 17:51 - 2015-02-09 17:51 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2015-02-09 17:51 - 2015-02-09 17:51 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2015-02-09 17:50 - 2015-02-09 17:50 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Google
2015-02-09 17:50 - 2015-02-09 17:50 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe
2015-02-09 17:50 - 2015-02-09 17:50 - 00000000 ____D () C:\Users\Default\AppData\Local\Google
2015-02-09 17:50 - 2015-02-09 17:50 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Google
2015-02-09 17:50 - 2015-02-09 17:50 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe
2015-02-09 17:50 - 2015-02-09 17:50 - 00000000 ____D () C:\Users\Default User\AppData\Local\Google
2015-02-09 17:48 - 2015-02-09 17:48 - 00000000 ____D () C:\Users\Default\AppData\Local\SlimWare Utilities Inc
2015-02-09 17:48 - 2015-02-09 17:48 - 00000000 ____D () C:\Users\Default User\AppData\Local\SlimWare Utilities Inc
2015-02-06 18:36 - 2015-02-06 19:44 - 00002134 _____ () C:\Users\Tibo\Desktop\Google Traduction.lnk
2015-02-06 18:30 - 2015-02-06 18:30 - 00284496 _____ () C:\windows\Minidump\020615-115425-01.dmp
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-08 22:34 - 2014-06-03 11:31 - 00000000 ____D () C:\Users\Tibo\AppData\Roaming\Skype
2015-03-08 22:23 - 2012-05-11 04:18 - 00001070 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-08 22:21 - 2014-11-04 20:10 - 00005054 _____ () C:\windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Tibo-TOSH-Tibo Tibo-TOSH
2015-03-08 22:11 - 2012-07-11 23:22 - 02022333 _____ () C:\windows\WindowsUpdate.log
2015-03-08 22:06 - 2009-07-14 05:45 - 00024608 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-08 22:06 - 2009-07-14 05:45 - 00024608 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-08 22:04 - 2012-05-11 04:13 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-03-08 21:58 - 2015-01-25 11:33 - 00002832 _____ () C:\windows\System32\Tasks\SlimDrivers Startup
2015-03-08 21:58 - 2015-01-25 11:33 - 00000408 _____ () C:\windows\Tasks\SlimDrivers Startup.job
2015-03-08 21:57 - 2015-01-25 11:33 - 00016152 _____ () C:\windows\system32\Drivers\SWDUMon.sys
2015-03-08 21:56 - 2014-12-11 21:18 - 00001334 _____ () C:\windows\Tasks\WQRHCI.job
2015-03-08 21:56 - 2014-12-11 21:17 - 00001678 _____ () C:\windows\Tasks\TYTLPZ.job
2015-03-08 21:56 - 2012-05-11 04:18 - 00001066 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-08 21:56 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-03-08 21:56 - 2009-07-14 05:51 - 00079031 _____ () C:\windows\setupact.log
2015-03-08 21:55 - 2014-11-16 21:32 - 494228809 _____ () C:\windows\MEMORY.DMP
2015-03-08 21:55 - 2014-11-16 21:32 - 00000000 ____D () C:\windows\Minidump
2015-03-08 15:21 - 2014-06-03 12:32 - 00000000 ____D () C:\Users\Tibo\AppData\Roaming\vlc
2015-03-08 15:16 - 2011-07-05 15:04 - 00747570 _____ () C:\windows\system32\perfh00C.dat
2015-03-08 15:16 - 2011-07-05 15:04 - 00150062 _____ () C:\windows\system32\perfc00C.dat
2015-03-08 15:16 - 2009-07-14 06:13 - 01668256 _____ () C:\windows\system32\PerfStringBackup.INI
2015-03-08 09:54 - 2010-11-21 04:47 - 00627820 _____ () C:\windows\PFRO.log
2015-03-08 02:29 - 2015-01-27 16:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak
2015-03-08 02:29 - 2015-01-07 13:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-05 21:37 - 2014-12-11 21:13 - 00332448 _____ (Say Media Group LTD) C:\windows\SysWOW64\ColorMedia.dll
2015-03-02 23:19 - 2014-12-19 20:59 - 00000000 ____D () C:\Users\Tibo\AppData\Local\
2015-03-02 22:57 - 2015-01-09 22:20 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2015-03-02 22:53 - 2015-01-09 22:13 - 00000000 ____D () C:\Program Files (x86)\
2015-02-28 11:40 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\tracing
2015-02-18 01:56 - 2014-06-03 11:15 - 00000000 ____D () C:\Users\Tibo
2015-02-17 23:36 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2015-02-17 20:59 - 2014-06-16 14:27 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-02-17 20:57 - 2014-06-16 10:05 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-16 13:40 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache
2015-02-12 19:46 - 2014-06-25 19:11 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2015-02-12 17:25 - 2009-07-14 05:45 - 00444952 _____ () C:\windows\system32\FNTCACHE.DAT
2015-02-12 17:22 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\tr-TR
2015-02-12 17:22 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\tr-TR
2015-02-11 22:40 - 2009-07-14 03:34 - 00000612 _____ () C:\windows\win.ini
2015-02-11 22:34 - 2014-06-15 21:06 - 00000000 ____D () C:\windows\system32\MRT
2015-02-11 22:27 - 2014-06-15 21:06 - 116773704 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-02-09 20:06 - 2014-06-27 19:50 - 00000000 ____D () C:\Users\Tibo\AppData\Roaming\gtk-2.0
2015-02-09 18:19 - 2014-06-15 17:41 - 00018497 _____ () C:\windows\IE11_main.log
2015-02-09 17:58 - 2015-01-09 10:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-02-09 17:58 - 2015-01-09 10:32 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-02-09 17:58 - 2015-01-09 10:31 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-08 18:37 - 2012-07-11 23:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2015-02-08 14:40 - 2015-01-25 14:35 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2015-02-08 14:40 - 2014-06-30 12:27 - 00000000 ____D () C:\Users\Tibo\AppData\Local\Downloaded Installations
2015-02-08 14:40 - 2014-06-16 10:05 - 00000000 ____D () C:\Users\Tibo\AppData\Local\Microsoft Help
2015-02-06 18:05 - 2012-05-11 04:13 - 00701616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-02-06 18:05 - 2012-05-11 04:13 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-06 18:05 - 2012-05-11 04:13 - 00003768 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
==================== Files in the root of some directories =======
2014-09-03 22:36 - 2014-09-03 22:36 - 0001248 _____ () C:\Users\Tibo\AppData\Roaming\TYTLPZ
2014-12-27 01:23 - 2014-12-28 02:23 - 0000059 _____ () C:\Users\Tibo\AppData\Roaming\WB.CFG
2014-09-03 22:36 - 2014-09-03 22:36 - 0002086 _____ () C:\Users\Tibo\AppData\Roaming\WQRHCI
2014-07-02 17:50 - 2014-08-30 20:32 - 0043008 _____ () C:\Users\Tibo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-11 21:39 - 2014-12-11 21:38 - 0613057 _____ () C:\Users\Tibo\AppData\Local\nsw4FCA.tmp
2014-12-13 12:33 - 2014-12-13 12:32 - 0613057 _____ () C:\Users\Tibo\AppData\Local\nsxC13.tmp
2014-06-16 08:59 - 2014-06-16 08:59 - 0766457 _____ () C:\ProgramData\1402904772.bdinstall.bin
Some content of TEMP:
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-28 14:34
==================== End Of Log ============================
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
8 mars 2015 à 22:48
8 mars 2015 à 22:48
(les rapports sont assez longs)
mais si c'est nécessaire.
merci de prendre le temps de m'aider.
à demain
mais si c'est nécessaire.
merci de prendre le temps de m'aider.
à demain
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
8 mars 2015 à 22:48
8 mars 2015 à 22:48
Héberge les rapports s'il te plaît
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
Modifié par Moicherchesolution le 9/03/2015 à 17:42
Modifié par Moicherchesolution le 9/03/2015 à 17:42
voilà les liens:
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 17:38
9 mars 2015 à 17:38
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 17:39
9 mars 2015 à 17:39
Par choix de son publicateur ou par opération de purge, ce document n'est plus hébergé par CJoint.
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 17:39
9 mars 2015 à 17:39
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 17:40
9 mars 2015 à 17:40
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
Modifié par lilidurhone le 9/03/2015 à 17:44
Modifié par lilidurhone le 9/03/2015 à 17:44
Plusieurs choses:
TuneUp Utilities 2014 à désinstaller
Avira ou bitdefender il te faudra choisir!
KMS Server Service.exe =>Office cracké?
Si problème il y a il existe toujours une solution
~~~~~~ Cs ~~~~~~
TuneUp Utilities 2014 à désinstaller
Avira ou bitdefender il te faudra choisir!
KMS Server Service.exe =>Office cracké?
Si problème il y a il existe toujours une solution
~~~~~~ Cs ~~~~~~
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 17:47
9 mars 2015 à 17:47
c'est bien mais ça ne règle pas mon problème
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 17:48
9 mars 2015 à 17:48
non rien je n'avais pas actualisé la page
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 17:49
9 mars 2015 à 17:49
qu'estce que kms server service?
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
9 mars 2015 à 18:08
9 mars 2015 à 18:08
oui passe le :)
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 18:09
9 mars 2015 à 18:09
attends svp
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 18:38
9 mars 2015 à 18:38
il me demande si j'ai installer des trucs j'ai mis non
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 18:39
9 mars 2015 à 18:39
~ ZHPCleaner v2015.3.9.114 by Nicolas Coolman (08/03/2015)
~ Run by Tibo (Administrator) (09/03/2015 18:20:37)
~ Forum :
~ Facebook :
~ State version : Version OK
~ Type : Scanner
~ Report : C:\Users\Tibo\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Tibo\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
~ Windows 7, 64-bit Service Pack 1 (Build 7601)
---\\ Service. (1)
[S] TROUVÉ : vToolbarUpdater18.1.9 (Toolbar.AVGSearch)
---\\ Navigateur internet. (2)
TROUVÉ Desktop: C:\Users\Tibo\Desktop\Google Traduction.lnk [Bad :] (Hijacker.Browser)
TROUVÉ Desktop: C:\Users\Tibo\Desktop\YouTube.lnk [Bad :] (Hijacker.Browser)
---\\ Fichier hôte. (1)
~ Le fichier hôte est légitime. (21)
---\\ Tâche planifiée. (4)
TROUVÉ tâche: [TYTLPZ] [C:\Users\Tibo\AppData\Roaming\TYTLPZ.exe (Not File) ] (Heuristic.Pirrit)
TROUVÉ tâche: [TYTLPZ] [C:\Users\Tibo\AppData\Roaming\TYTLPZ.exe (Not File) ] (Heuristic.Pirrit)
TROUVÉ tâche: [WQRHCI] [C:\Users\Tibo\AppData\Roaming\WQRHCI.exe (Not File) ] (Heuristic.Pirrit)
TROUVÉ tâche: [WQRHCI] [C:\Users\Tibo\AppData\Roaming\WQRHCI.exe (Not File) ] (Heuristic.Pirrit)
---\\ Explorateur ( Dossiers, Fichiers ). (23)
TROUVÉ fichier: C:\windows\Tasks\TYTLPZ.job [ - ] (Heuristic.Pirrit)
TROUVÉ fichier: C:\windows\Tasks\TYTLPZ.job [ - ] (Heuristic.Pirrit)
TROUVÉ fichier: C:\windows\Tasks\WQRHCI.job [ - ] (Heuristic.Pirrit)
TROUVÉ fichier: C:\windows\Tasks\WQRHCI.job [ - ] (Heuristic.Pirrit)
TROUVÉ fichier: C:\windows\System32\Tasks\TYTLPZ [ - ] (Heuristic.Pirrit)
TROUVÉ fichier: C:\windows\System32\Tasks\TYTLPZ [ - ] (Heuristic.Pirrit)
TROUVÉ fichier: C:\windows\System32\Tasks\WQRHCI [ - ] (Heuristic.Pirrit)
TROUVÉ fichier: C:\windows\System32\Tasks\WQRHCI [ - ] (Heuristic.Pirrit)
TROUVÉ fichier: C:\Program Files (x86)\YoutubeAdBlocke\YNNWcsRaabNTfH.dat [ - ](PUP.YouTubeAdBlock)
TROUVÉ fichier: C:\Program Files (x86)\YoutubeAdBlocke\YNNWcsRaabNTfH.exe [ - ](PUP.YouTubeAdBlock)
TROUVÉ fichier: C:\Program Files (x86)\YoutubeAdBlocke\YNNWcsRaabNTfH.tlb [ - ](PUP.YouTubeAdBlock)
TROUVÉ dossier: C:\Program Files (x86)\YoutubeAdBlocke (PUP.YouTubeAdBlock)
TROUVÉ fichier: C:\ProgramData\Microsoft Toolkit\Settings.xml [ - ](Trojan.AutoKMS)
TROUVÉ dossier: C:\ProgramData\Microsoft Toolkit (Trojan.AutoKMS)
TROUVÉ fichier: C:\windows\Prefetch\ [ - ](PUP.AnyProtect)
TROUVÉ fichier: C:\windows\Prefetch\ [ - ](PUP.CloudGuard)
TROUVÉ fichier: C:\windows\Prefetch\ [ - ](Adware.Pirrit)
TROUVÉ fichier: C:\windows\Prefetch\ [ - ](Adware.Downware)
TROUVÉ fichier: C:\ProgramData\SZZSfOcBwoD\dat\JbfcvFJPa.exe [Small Island Development - TVWizard](PUP.SmallIsland)
TROUVÉ fichier: C:\ProgramData\SZZSfOcBwoD\dat\LUjiHFSw.exe [Small Island Development - TVWizard](PUP.SmallIsland)
TROUVÉ dossier: C:\Rei (PUP.ReimageRepair)
TROUVÉ dossier: C:\Users\Tibo\AppData\Local\{B914BDC1-BAA5-4432-A33A-F9FFFE32138F} (Empty)
TROUVÉ dossier: C:\Users\Tibo\AppData\Local\{DF318D90-4A44-4EB4-93BC-7140AFCF05C6} (Empty)
---\\ Base de Registres ( Clés, Valeurs, Données ). (28)
TROUVÉ clé: [X64] HKLM\SYSTEM\CurrentControlSet\Services\vToolbarUpdater18.1.9 [C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe (Not File) ] (Toolbar.AVGSearch)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UpdatePDRShortCut ["F:\Montage video\PowerDirector 8 Deluxe+serial\Logiciel\PowerDirector\MUITransfer\MUIStartMenu.exe" "F:\Montage video\PowerDirector 8 Deluxe+serial\Logiciel\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"] (PUP.Istart)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\vProt ["C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"] (Toolbar.AVGSafeGuard)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinCheck [C:\Users\Tibo\AppData\Local\wincheck\wincheck.exe] (PUP.Wincheck)
TROUVÉ donnée: HKCR\JSFile\Shell\Open\Command\\Default [Bad : "C:\windows\System32\WScript.exe" "%1" %*] (Broken.OpenCommand)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Clients\StartMenuInternet\Vosteran.LUDSZ67YQ7ZZI6IG6MQMR42SJE ["C:\Users\Tibo\AppData\Local\Vosteran\Application\vosteran.exe"] (PUP.Vosteran)
TROUVÉ valeur: [X64] HKLM\Software\Classes\.htm\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
TROUVÉ valeur: [X64] HKLM\Software\Classes\.html\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
TROUVÉ valeur: [X64] HKLM\Software\Classes\.shtml\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
TROUVÉ valeur: [X64] HKLM\Software\Classes\.webp\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
TROUVÉ valeur: [X64] HKLM\Software\Classes\.xht\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
TROUVÉ clé: HKCU\Software\TYTLPZ [] (Heuristic.Pirrit)
TROUVÉ clé: HKCU\Software\TYTLPZ [] (Heuristic.Pirrit)
TROUVÉ clé: HKCU\Software\WQRHCI [] (Heuristic.Pirrit)
TROUVÉ clé: HKCU\Software\WQRHCI [] (Heuristic.Pirrit)
TROUVÉ clé: HKCU\Software\Media+PlayerVidEd2.0-nv [] (Heuristic.CrossRider)
TROUVÉ clé: HKLM\SOFTWARE\Wow6432Node\ac90a7f5-8436-484d-b4f4-1ffe5d750056 [] (PUP.CrossRider)
TROUVÉ clé: HKLM\SOFTWARE\Wow6432Node\Media+PlayerVidEd2.0-nv [] (Heuristic.CrossRider)
TROUVÉ clé: HKCU\Software\AppDataLow\Software\SpeedCheck [] (PUP.SpeedCheck)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Classes\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [Vosteran HTML Document] (PUP.Vosteran)
TROUVÉ donnée: [X64] HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0ADFAFBB-0B96-462C-B8A6-49945EA0DAB7}\\NameServer [, (Not File)][] (Hijacker.Browser)
TROUVÉ donnée: [X64] HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{65EC1E92-D376-44A1-BB2A-81404865171F}\\NameServer [, (Not File)][] (Hijacker.Browser)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\vProt ["C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"] (Toolbar.AVGSafeGuard)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinCheck [C:\Users\Tibo\AppData\Local\wincheck\wincheck.exe] (PUP.Wincheck)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A} [C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.1.9] (Toolbar.AVGSearch)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinCheck [] (PUP.Wincheck)
TROUVÉ clé: HKLM\SOFTWARE\Wow6432Node\Classes\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [Vosteran HTML Document] (PUP.Vosteran)
TROUVÉ clé: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A} [C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.1.9] (Toolbar.AVGSearch)
---\\ Bilan de la réparation
~ Aucune réparation effectuée.
~ Ce navigateur est absent (Google Chrome)
~ Ce navigateur est absent (Opera Software)
---\\ Statistiques
~ Items scannés : 82532
~ Items trouvés : 58
~ Items réparés : 0
End of clean at 18:38:42
~ Run by Tibo (Administrator) (09/03/2015 18:20:37)
~ Forum :
~ Facebook :
~ State version : Version OK
~ Type : Scanner
~ Report : C:\Users\Tibo\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Tibo\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
~ Windows 7, 64-bit Service Pack 1 (Build 7601)
---\\ Service. (1)
[S] TROUVÉ : vToolbarUpdater18.1.9 (Toolbar.AVGSearch)
---\\ Navigateur internet. (2)
TROUVÉ Desktop: C:\Users\Tibo\Desktop\Google Traduction.lnk [Bad :] (Hijacker.Browser)
TROUVÉ Desktop: C:\Users\Tibo\Desktop\YouTube.lnk [Bad :] (Hijacker.Browser)
---\\ Fichier hôte. (1)
~ Le fichier hôte est légitime. (21)
---\\ Tâche planifiée. (4)
TROUVÉ tâche: [TYTLPZ] [C:\Users\Tibo\AppData\Roaming\TYTLPZ.exe (Not File) ] (Heuristic.Pirrit)
TROUVÉ tâche: [TYTLPZ] [C:\Users\Tibo\AppData\Roaming\TYTLPZ.exe (Not File) ] (Heuristic.Pirrit)
TROUVÉ tâche: [WQRHCI] [C:\Users\Tibo\AppData\Roaming\WQRHCI.exe (Not File) ] (Heuristic.Pirrit)
TROUVÉ tâche: [WQRHCI] [C:\Users\Tibo\AppData\Roaming\WQRHCI.exe (Not File) ] (Heuristic.Pirrit)
---\\ Explorateur ( Dossiers, Fichiers ). (23)
TROUVÉ fichier: C:\windows\Tasks\TYTLPZ.job [ - ] (Heuristic.Pirrit)
TROUVÉ fichier: C:\windows\Tasks\TYTLPZ.job [ - ] (Heuristic.Pirrit)
TROUVÉ fichier: C:\windows\Tasks\WQRHCI.job [ - ] (Heuristic.Pirrit)
TROUVÉ fichier: C:\windows\Tasks\WQRHCI.job [ - ] (Heuristic.Pirrit)
TROUVÉ fichier: C:\windows\System32\Tasks\TYTLPZ [ - ] (Heuristic.Pirrit)
TROUVÉ fichier: C:\windows\System32\Tasks\TYTLPZ [ - ] (Heuristic.Pirrit)
TROUVÉ fichier: C:\windows\System32\Tasks\WQRHCI [ - ] (Heuristic.Pirrit)
TROUVÉ fichier: C:\windows\System32\Tasks\WQRHCI [ - ] (Heuristic.Pirrit)
TROUVÉ fichier: C:\Program Files (x86)\YoutubeAdBlocke\YNNWcsRaabNTfH.dat [ - ](PUP.YouTubeAdBlock)
TROUVÉ fichier: C:\Program Files (x86)\YoutubeAdBlocke\YNNWcsRaabNTfH.exe [ - ](PUP.YouTubeAdBlock)
TROUVÉ fichier: C:\Program Files (x86)\YoutubeAdBlocke\YNNWcsRaabNTfH.tlb [ - ](PUP.YouTubeAdBlock)
TROUVÉ dossier: C:\Program Files (x86)\YoutubeAdBlocke (PUP.YouTubeAdBlock)
TROUVÉ fichier: C:\ProgramData\Microsoft Toolkit\Settings.xml [ - ](Trojan.AutoKMS)
TROUVÉ dossier: C:\ProgramData\Microsoft Toolkit (Trojan.AutoKMS)
TROUVÉ fichier: C:\windows\Prefetch\ [ - ](PUP.AnyProtect)
TROUVÉ fichier: C:\windows\Prefetch\ [ - ](PUP.CloudGuard)
TROUVÉ fichier: C:\windows\Prefetch\ [ - ](Adware.Pirrit)
TROUVÉ fichier: C:\windows\Prefetch\ [ - ](Adware.Downware)
TROUVÉ fichier: C:\ProgramData\SZZSfOcBwoD\dat\JbfcvFJPa.exe [Small Island Development - TVWizard](PUP.SmallIsland)
TROUVÉ fichier: C:\ProgramData\SZZSfOcBwoD\dat\LUjiHFSw.exe [Small Island Development - TVWizard](PUP.SmallIsland)
TROUVÉ dossier: C:\Rei (PUP.ReimageRepair)
TROUVÉ dossier: C:\Users\Tibo\AppData\Local\{B914BDC1-BAA5-4432-A33A-F9FFFE32138F} (Empty)
TROUVÉ dossier: C:\Users\Tibo\AppData\Local\{DF318D90-4A44-4EB4-93BC-7140AFCF05C6} (Empty)
---\\ Base de Registres ( Clés, Valeurs, Données ). (28)
TROUVÉ clé: [X64] HKLM\SYSTEM\CurrentControlSet\Services\vToolbarUpdater18.1.9 [C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe (Not File) ] (Toolbar.AVGSearch)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UpdatePDRShortCut ["F:\Montage video\PowerDirector 8 Deluxe+serial\Logiciel\PowerDirector\MUITransfer\MUIStartMenu.exe" "F:\Montage video\PowerDirector 8 Deluxe+serial\Logiciel\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"] (PUP.Istart)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\vProt ["C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"] (Toolbar.AVGSafeGuard)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinCheck [C:\Users\Tibo\AppData\Local\wincheck\wincheck.exe] (PUP.Wincheck)
TROUVÉ donnée: HKCR\JSFile\Shell\Open\Command\\Default [Bad : "C:\windows\System32\WScript.exe" "%1" %*] (Broken.OpenCommand)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Clients\StartMenuInternet\Vosteran.LUDSZ67YQ7ZZI6IG6MQMR42SJE ["C:\Users\Tibo\AppData\Local\Vosteran\Application\vosteran.exe"] (PUP.Vosteran)
TROUVÉ valeur: [X64] HKLM\Software\Classes\.htm\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
TROUVÉ valeur: [X64] HKLM\Software\Classes\.html\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
TROUVÉ valeur: [X64] HKLM\Software\Classes\.shtml\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
TROUVÉ valeur: [X64] HKLM\Software\Classes\.webp\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
TROUVÉ valeur: [X64] HKLM\Software\Classes\.xht\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
TROUVÉ clé: HKCU\Software\TYTLPZ [] (Heuristic.Pirrit)
TROUVÉ clé: HKCU\Software\TYTLPZ [] (Heuristic.Pirrit)
TROUVÉ clé: HKCU\Software\WQRHCI [] (Heuristic.Pirrit)
TROUVÉ clé: HKCU\Software\WQRHCI [] (Heuristic.Pirrit)
TROUVÉ clé: HKCU\Software\Media+PlayerVidEd2.0-nv [] (Heuristic.CrossRider)
TROUVÉ clé: HKLM\SOFTWARE\Wow6432Node\ac90a7f5-8436-484d-b4f4-1ffe5d750056 [] (PUP.CrossRider)
TROUVÉ clé: HKLM\SOFTWARE\Wow6432Node\Media+PlayerVidEd2.0-nv [] (Heuristic.CrossRider)
TROUVÉ clé: HKCU\Software\AppDataLow\Software\SpeedCheck [] (PUP.SpeedCheck)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Classes\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [Vosteran HTML Document] (PUP.Vosteran)
TROUVÉ donnée: [X64] HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0ADFAFBB-0B96-462C-B8A6-49945EA0DAB7}\\NameServer [, (Not File)][] (Hijacker.Browser)
TROUVÉ donnée: [X64] HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{65EC1E92-D376-44A1-BB2A-81404865171F}\\NameServer [, (Not File)][] (Hijacker.Browser)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\vProt ["C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"] (Toolbar.AVGSafeGuard)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinCheck [C:\Users\Tibo\AppData\Local\wincheck\wincheck.exe] (PUP.Wincheck)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A} [C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.1.9] (Toolbar.AVGSearch)
TROUVÉ clé: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinCheck [] (PUP.Wincheck)
TROUVÉ clé: HKLM\SOFTWARE\Wow6432Node\Classes\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [Vosteran HTML Document] (PUP.Vosteran)
TROUVÉ clé: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A} [C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.1.9] (Toolbar.AVGSearch)
---\\ Bilan de la réparation
~ Aucune réparation effectuée.
~ Ce navigateur est absent (Google Chrome)
~ Ce navigateur est absent (Opera Software)
---\\ Statistiques
~ Items scannés : 82532
~ Items trouvés : 58
~ Items réparés : 0
End of clean at 18:38:42
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
9 mars 2015 à 18:54
9 mars 2015 à 18:54
Pour l'instant ne fais pas suppression il y a un faux positif
Je te tiens au courant
Je te tiens au courant
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 19:37
9 mars 2015 à 19:37
trop tard
~ ZHPCleaner v2015.3.9.114 by Nicolas Coolman (08/03/2015)
~ Run by Tibo (Administrator) (09/03/2015 18:39:25)
~ Forum :
~ Facebook :
~ State version : Version OK
~ Type : Réparer
~ Report : C:\Users\Tibo\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Tibo\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
~ Windows 7, 64-bit Service Pack 1 (Build 7601)
---\\ Service. (1)
---\\ Navigateur internet. (2)
REMPLACÉ Desktop: C:\Users\Tibo\Desktop\Google Traduction.lnk [Bad :] (Hijacker.Browser)
REMPLACÉ Desktop: C:\Users\Tibo\Desktop\YouTube.lnk [Bad :] (Hijacker.Browser)
---\\ Fichier hôte. (1)
~ Le fichier hôte est légitime. (21)
---\\ Tâche planifiée. (4)
SUPPRIMÉ tâche: [TYTLPZ] [C:\Users\Tibo\AppData\Roaming\TYTLPZ.exe (Not File) ] (Heuristic.Pirrit)
SUPPRIMÉ tâche: [TYTLPZ] [C:\Users\Tibo\AppData\Roaming\TYTLPZ.exe (Not File) ] (Heuristic.Pirrit)
SUPPRIMÉ tâche: [WQRHCI] [C:\Users\Tibo\AppData\Roaming\WQRHCI.exe (Not File) ] (Heuristic.Pirrit)
SUPPRIMÉ tâche: [WQRHCI] [C:\Users\Tibo\AppData\Roaming\WQRHCI.exe (Not File) ] (Heuristic.Pirrit)
---\\ Explorateur ( Dossiers, Fichiers ). (21)
DEPLACÉ fichier****: C:\windows\Tasks\TYTLPZ.job [ - ] (Heuristic.Pirrit)
DEPLACÉ fichier****: C:\windows\Tasks\TYTLPZ.job [ - ] (Heuristic.Pirrit)
DEPLACÉ fichier****: C:\windows\Tasks\WQRHCI.job [ - ] (Heuristic.Pirrit)
DEPLACÉ fichier****: C:\windows\Tasks\WQRHCI.job [ - ] (Heuristic.Pirrit)
DEPLACÉ fichier: C:\windows\System32\Tasks\TYTLPZ [ - ] (Heuristic.Pirrit)
DEPLACÉ fichier: C:\windows\System32\Tasks\WQRHCI [ - ] (Heuristic.Pirrit)
DEPLACÉ fichier: C:\Program Files (x86)\YoutubeAdBlocke\YNNWcsRaabNTfH.dat [ - ] (PUP.YouTubeAdBlock)
DEPLACÉ fichier: C:\Program Files (x86)\YoutubeAdBlocke\YNNWcsRaabNTfH.exe [ - ] (PUP.YouTubeAdBlock)
DEPLACÉ fichier: C:\Program Files (x86)\YoutubeAdBlocke\YNNWcsRaabNTfH.tlb [ - ] (PUP.YouTubeAdBlock)
DEPLACÉ dossier: C:\Program Files (x86)\YoutubeAdBlocke (PUP.YouTubeAdBlock)
DEPLACÉ fichier: C:\ProgramData\Microsoft Toolkit\Settings.xml [ - ] (Trojan.AutoKMS)
DEPLACÉ dossier: C:\ProgramData\Microsoft Toolkit (Trojan.AutoKMS)
DEPLACÉ fichier: C:\windows\Prefetch\ [ - ] (PUP.AnyProtect)
DEPLACÉ fichier: C:\windows\Prefetch\ [ - ] (PUP.CloudGuard)
DEPLACÉ fichier: C:\windows\Prefetch\ [ - ] (Adware.Pirrit)
DEPLACÉ fichier: C:\windows\Prefetch\ [ - ] (Adware.Downware)
DEPLACÉ fichier: C:\ProgramData\SZZSfOcBwoD\dat\JbfcvFJPa.exe [Small Island Development - TVWizard] (PUP.SmallIsland)
DEPLACÉ fichier: C:\ProgramData\SZZSfOcBwoD\dat\LUjiHFSw.exe [Small Island Development - TVWizard] (PUP.SmallIsland)
DEPLACÉ dossier: C:\Rei (PUP.ReimageRepair)
DEPLACÉ dossier: C:\Users\Tibo\AppData\Local\{B914BDC1-BAA5-4432-A33A-F9FFFE32138F} (Empty)
DEPLACÉ dossier: C:\Users\Tibo\AppData\Local\{DF318D90-4A44-4EB4-93BC-7140AFCF05C6} (Empty)
---\\ Base de Registres ( Clés, Valeurs, Données ). (24)
SUPPRIMÉ clé^: [X64] HKLM\SYSTEM\CurrentControlSet\Services\vToolbarUpdater18.1.9 [C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe (Not File) ] (Toolbar.AVGSearch)
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UpdatePDRShortCut ["F:\Montage video\PowerDirector 8 Deluxe+serial\Logiciel\PowerDirector\MUITransfer\MUIStartMenu.exe" "F:\Montage video\PowerDirector 8 Deluxe+serial\Logiciel\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"] (PUP.Istart)
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\vProt ["C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"] (Toolbar.AVGSafeGuard)
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinCheck [C:\Users\Tibo\AppData\Local\wincheck\wincheck.exe] (PUP.Wincheck)
SUPPRIMÉ donnée: HKCR\JSFile\Shell\Open\Command\\Default [Bad : "C:\windows\System32\WScript.exe" "%1" %*] (Broken.OpenCommand)
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Clients\StartMenuInternet\Vosteran.LUDSZ67YQ7ZZI6IG6MQMR42SJE ["C:\Users\Tibo\AppData\Local\Vosteran\Application\vosteran.exe"] (PUP.Vosteran)
SUPPRIMÉ valeur: [X64] HKLM\Software\Classes\.htm\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
SUPPRIMÉ valeur: [X64] HKLM\Software\Classes\.html\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
SUPPRIMÉ valeur: [X64] HKLM\Software\Classes\.shtml\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
SUPPRIMÉ valeur: [X64] HKLM\Software\Classes\.webp\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
SUPPRIMÉ valeur: [X64] HKLM\Software\Classes\.xht\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
SUPPRIMÉ clé*: HKCU\Software\TYTLPZ [] (Heuristic.Pirrit)
SUPPRIMÉ clé^: HKCU\Software\TYTLPZ [] (Heuristic.Pirrit)
SUPPRIMÉ clé*: HKCU\Software\WQRHCI [] (Heuristic.Pirrit)
SUPPRIMÉ clé^: HKCU\Software\WQRHCI [] (Heuristic.Pirrit)
SUPPRIMÉ clé*: HKCU\Software\Media+PlayerVidEd2.0-nv [] (Heuristic.CrossRider)
SUPPRIMÉ clé*: HKLM\SOFTWARE\Wow6432Node\ac90a7f5-8436-484d-b4f4-1ffe5d750056 [] (PUP.CrossRider)
SUPPRIMÉ clé*: HKLM\SOFTWARE\Wow6432Node\Media+PlayerVidEd2.0-nv [] (Heuristic.CrossRider)
SUPPRIMÉ clé*: HKCU\Software\AppDataLow\Software\SpeedCheck [] (PUP.SpeedCheck)
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [Vosteran HTML Document] (PUP.Vosteran)
REMPLACÉ donnée: [X64] HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0ADFAFBB-0B96-462C-B8A6-49945EA0DAB7}\\NameServer [, (Not File)][] (Hijacker.Browser)
REMPLACÉ donnée: [X64] HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{65EC1E92-D376-44A1-BB2A-81404865171F}\\NameServer [, (Not File)][] (Hijacker.Browser)
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A} [C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.1.9] (Toolbar.AVGSearch)
SUPPRIMÉ clé*: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A} [C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.1.9] (Toolbar.AVGSearch)
---\\ Bilan de la réparation
~ Réparation réalisée avec succès.
~ Ce navigateur est absent (Google Chrome)
~ Ce navigateur est absent (Opera Software)
~ Le système a été redémarré.
---\\ Statistiques
~ Items scannés : 82497
~ Items trouvés : 0
~ Items réparés : 43
End of clean at 18:53:40
~ ZHPCleaner v2015.3.9.114 by Nicolas Coolman (08/03/2015)
~ Run by Tibo (Administrator) (09/03/2015 18:39:25)
~ Forum :
~ Facebook :
~ State version : Version OK
~ Type : Réparer
~ Report : C:\Users\Tibo\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Tibo\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
~ Windows 7, 64-bit Service Pack 1 (Build 7601)
---\\ Service. (1)
---\\ Navigateur internet. (2)
REMPLACÉ Desktop: C:\Users\Tibo\Desktop\Google Traduction.lnk [Bad :] (Hijacker.Browser)
REMPLACÉ Desktop: C:\Users\Tibo\Desktop\YouTube.lnk [Bad :] (Hijacker.Browser)
---\\ Fichier hôte. (1)
~ Le fichier hôte est légitime. (21)
---\\ Tâche planifiée. (4)
SUPPRIMÉ tâche: [TYTLPZ] [C:\Users\Tibo\AppData\Roaming\TYTLPZ.exe (Not File) ] (Heuristic.Pirrit)
SUPPRIMÉ tâche: [TYTLPZ] [C:\Users\Tibo\AppData\Roaming\TYTLPZ.exe (Not File) ] (Heuristic.Pirrit)
SUPPRIMÉ tâche: [WQRHCI] [C:\Users\Tibo\AppData\Roaming\WQRHCI.exe (Not File) ] (Heuristic.Pirrit)
SUPPRIMÉ tâche: [WQRHCI] [C:\Users\Tibo\AppData\Roaming\WQRHCI.exe (Not File) ] (Heuristic.Pirrit)
---\\ Explorateur ( Dossiers, Fichiers ). (21)
DEPLACÉ fichier****: C:\windows\Tasks\TYTLPZ.job [ - ] (Heuristic.Pirrit)
DEPLACÉ fichier****: C:\windows\Tasks\TYTLPZ.job [ - ] (Heuristic.Pirrit)
DEPLACÉ fichier****: C:\windows\Tasks\WQRHCI.job [ - ] (Heuristic.Pirrit)
DEPLACÉ fichier****: C:\windows\Tasks\WQRHCI.job [ - ] (Heuristic.Pirrit)
DEPLACÉ fichier: C:\windows\System32\Tasks\TYTLPZ [ - ] (Heuristic.Pirrit)
DEPLACÉ fichier: C:\windows\System32\Tasks\WQRHCI [ - ] (Heuristic.Pirrit)
DEPLACÉ fichier: C:\Program Files (x86)\YoutubeAdBlocke\YNNWcsRaabNTfH.dat [ - ] (PUP.YouTubeAdBlock)
DEPLACÉ fichier: C:\Program Files (x86)\YoutubeAdBlocke\YNNWcsRaabNTfH.exe [ - ] (PUP.YouTubeAdBlock)
DEPLACÉ fichier: C:\Program Files (x86)\YoutubeAdBlocke\YNNWcsRaabNTfH.tlb [ - ] (PUP.YouTubeAdBlock)
DEPLACÉ dossier: C:\Program Files (x86)\YoutubeAdBlocke (PUP.YouTubeAdBlock)
DEPLACÉ fichier: C:\ProgramData\Microsoft Toolkit\Settings.xml [ - ] (Trojan.AutoKMS)
DEPLACÉ dossier: C:\ProgramData\Microsoft Toolkit (Trojan.AutoKMS)
DEPLACÉ fichier: C:\windows\Prefetch\ [ - ] (PUP.AnyProtect)
DEPLACÉ fichier: C:\windows\Prefetch\ [ - ] (PUP.CloudGuard)
DEPLACÉ fichier: C:\windows\Prefetch\ [ - ] (Adware.Pirrit)
DEPLACÉ fichier: C:\windows\Prefetch\ [ - ] (Adware.Downware)
DEPLACÉ fichier: C:\ProgramData\SZZSfOcBwoD\dat\JbfcvFJPa.exe [Small Island Development - TVWizard] (PUP.SmallIsland)
DEPLACÉ fichier: C:\ProgramData\SZZSfOcBwoD\dat\LUjiHFSw.exe [Small Island Development - TVWizard] (PUP.SmallIsland)
DEPLACÉ dossier: C:\Rei (PUP.ReimageRepair)
DEPLACÉ dossier: C:\Users\Tibo\AppData\Local\{B914BDC1-BAA5-4432-A33A-F9FFFE32138F} (Empty)
DEPLACÉ dossier: C:\Users\Tibo\AppData\Local\{DF318D90-4A44-4EB4-93BC-7140AFCF05C6} (Empty)
---\\ Base de Registres ( Clés, Valeurs, Données ). (24)
SUPPRIMÉ clé^: [X64] HKLM\SYSTEM\CurrentControlSet\Services\vToolbarUpdater18.1.9 [C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe (Not File) ] (Toolbar.AVGSearch)
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UpdatePDRShortCut ["F:\Montage video\PowerDirector 8 Deluxe+serial\Logiciel\PowerDirector\MUITransfer\MUIStartMenu.exe" "F:\Montage video\PowerDirector 8 Deluxe+serial\Logiciel\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"] (PUP.Istart)
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\vProt ["C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"] (Toolbar.AVGSafeGuard)
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinCheck [C:\Users\Tibo\AppData\Local\wincheck\wincheck.exe] (PUP.Wincheck)
SUPPRIMÉ donnée: HKCR\JSFile\Shell\Open\Command\\Default [Bad : "C:\windows\System32\WScript.exe" "%1" %*] (Broken.OpenCommand)
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Clients\StartMenuInternet\Vosteran.LUDSZ67YQ7ZZI6IG6MQMR42SJE ["C:\Users\Tibo\AppData\Local\Vosteran\Application\vosteran.exe"] (PUP.Vosteran)
SUPPRIMÉ valeur: [X64] HKLM\Software\Classes\.htm\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
SUPPRIMÉ valeur: [X64] HKLM\Software\Classes\.html\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
SUPPRIMÉ valeur: [X64] HKLM\Software\Classes\.shtml\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
SUPPRIMÉ valeur: [X64] HKLM\Software\Classes\.webp\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
SUPPRIMÉ valeur: [X64] HKLM\Software\Classes\.xht\OpenWithProgIDs\\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [] (PUP.Vosteran)
SUPPRIMÉ clé*: HKCU\Software\TYTLPZ [] (Heuristic.Pirrit)
SUPPRIMÉ clé^: HKCU\Software\TYTLPZ [] (Heuristic.Pirrit)
SUPPRIMÉ clé*: HKCU\Software\WQRHCI [] (Heuristic.Pirrit)
SUPPRIMÉ clé^: HKCU\Software\WQRHCI [] (Heuristic.Pirrit)
SUPPRIMÉ clé*: HKCU\Software\Media+PlayerVidEd2.0-nv [] (Heuristic.CrossRider)
SUPPRIMÉ clé*: HKLM\SOFTWARE\Wow6432Node\ac90a7f5-8436-484d-b4f4-1ffe5d750056 [] (PUP.CrossRider)
SUPPRIMÉ clé*: HKLM\SOFTWARE\Wow6432Node\Media+PlayerVidEd2.0-nv [] (Heuristic.CrossRider)
SUPPRIMÉ clé*: HKCU\Software\AppDataLow\Software\SpeedCheck [] (PUP.SpeedCheck)
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Classes\VosteranHTML.LUDSZ67YQ7ZZI6IG6MQMR42SJE [Vosteran HTML Document] (PUP.Vosteran)
REMPLACÉ donnée: [X64] HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0ADFAFBB-0B96-462C-B8A6-49945EA0DAB7}\\NameServer [, (Not File)][] (Hijacker.Browser)
REMPLACÉ donnée: [X64] HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{65EC1E92-D376-44A1-BB2A-81404865171F}\\NameServer [, (Not File)][] (Hijacker.Browser)
SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A} [C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.1.9] (Toolbar.AVGSearch)
SUPPRIMÉ clé*: HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A} [C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\18.1.9] (Toolbar.AVGSearch)
---\\ Bilan de la réparation
~ Réparation réalisée avec succès.
~ Ce navigateur est absent (Google Chrome)
~ Ce navigateur est absent (Opera Software)
~ Le système a été redémarré.
---\\ Statistiques
~ Items scannés : 82497
~ Items trouvés : 0
~ Items réparés : 43
End of clean at 18:53:40
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 19:38
9 mars 2015 à 19:38
mince, c'est quoi un faux positif?
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
9 mars 2015 à 19:40
9 mars 2015 à 19:40
Et pourtant je te l'avais dit de ne pas faire réparer car il t'a supprimé
" SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UpdatePDRShortCut ["F:\Montage video\PowerDirector 8 Deluxe+serial\Logiciel\PowerDirector\MUITransfer\MUIStartMenu.exe" "F:\Montage video\PowerDirector 8 Deluxe+serial\Logiciel\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"] (PUP.Istart) "
Vérifie que le logiciel fonctionne si il ne fonctionne pas fais une restauration à une date antérieure
" SUPPRIMÉ clé*: [X64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UpdatePDRShortCut ["F:\Montage video\PowerDirector 8 Deluxe+serial\Logiciel\PowerDirector\MUITransfer\MUIStartMenu.exe" "F:\Montage video\PowerDirector 8 Deluxe+serial\Logiciel\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"] (PUP.Istart) "
Vérifie que le logiciel fonctionne si il ne fonctionne pas fais une restauration à une date antérieure
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 19:48
9 mars 2015 à 19:48
ça fonctionne (pour faire des montages vidéos)
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 19:51
9 mars 2015 à 19:51
Ouf :)
Refais frst compte tenu de la suppression avec zhpcleaner
Refais frst compte tenu de la suppression avec zhpcleaner
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 19:51
9 mars 2015 à 19:51
ok ca scanne
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 19:44
9 mars 2015 à 19:44
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 19:45
9 mars 2015 à 19:45
et il n'y a pas que play now ou download
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
9 mars 2015 à 19:46
9 mars 2015 à 19:46
Refais FRST s'il te plaît
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 19:54
9 mars 2015 à 19:54
je mets les rapports sur clean?
Messages postés
Date d'inscription
dimanche 8 mars 2015
Dernière intervention
11 mars 2015
Modifié par AkaAmnesia le 9/03/2015 à 20:01
Modifié par AkaAmnesia le 9/03/2015 à 20:01
Hé bien!! J'admire les gens qui consacrent autant d'attention pour aider les gens ;)
Mais juste une question: ces pubs s'affichent que sur les sites?
Je veux pas dire mais imagine qu'il lui faut juste adblock
Mais juste une question: ces pubs s'affichent que sur les sites?
Je veux pas dire mais imagine qu'il lui faut juste adblock
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
Messages postés
Date d'inscription
dimanche 8 mars 2015
Dernière intervention
11 mars 2015
9 mars 2015 à 20:03
9 mars 2015 à 20:03
Non aka il est encore infecté
Ads by scoutclouds
Adblock ne sera pas utie
Oui sur cjoint ou pjoint
Ads by scoutclouds
Adblock ne sera pas utie
Oui sur cjoint ou pjoint
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 20:04
9 mars 2015 à 20:04
moi aussi j'admire ces gens là et je remercie Lilidurhone pour son aide.
ça affiche que dans les sites et je ne sait pas ce qu'est adblock
ça affiche que dans les sites et je ne sait pas ce qu'est adblock
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 20:05
9 mars 2015 à 20:05
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
9 mars 2015 à 20:12
9 mars 2015 à 20:12
▶ /!\ Crée un point de restauration manuel avant d'appliquer le correctif - Tutoriel en images/!\
▶ Ouvre le Bloc-notes (Démarrer => Tous les programmes => Accessoires => Bloc-notes)
▶ Copie/colle la totalité du contenu de la zone Code ci-dessous dans le Bloc-notes
▶ Enregistre le fichier sur ton Bureau (au même endroit que FRST) sous le nom fixlist.txt
▶ Ferme toutes les applications, y compris ton navigateur
▶ Double-clique sur FRST.exe
/!\ Sous Vista, Windows 7 et 8, il faut lancer le fichier par clic-droit -> Exécuter en tant qu'administrateur
▶ Sur le menu principal, clique une seule fois sur Fix et patiente le temps de la correction
▶ L'outil va créer un rapport de correction Fixlog.txt. Poste ce rapport dans ta réponse.
▶ /!\ Ce script a été établi pour cet utilisateur, il ne doit, en aucun cas, être appliqué sur un autre système, au risque de provoquer de graves dysfonctionnement et endommager Windows /!\
▶ Ouvre le Bloc-notes (Démarrer => Tous les programmes => Accessoires => Bloc-notes)
▶ Copie/colle la totalité du contenu de la zone Code ci-dessous dans le Bloc-notes
Task: {287B988F-DB1D-45C7-ABF6-69214C2DCB21} - \TYTLPZ No Task File <==== ATTENTION
Task: {9E2B6002-8B70-47A9-AF02-7AD8C89FC719} - \WQRHCI No Task File <==== ATTENTION
Task: {C9A05F71-DB56-427C-878A-708B5330302F} - \PurpleRain\PurpleRain3 No Task File <==== ATTENTION
Task: {D7DDCDEA-AA93-416F-BF73-C9DC6F2B1D27} - \f104d9b2-f4c1-4672-a978-27e82d116169-10_user No Task File <==== ATTENTION
Task: C:\windows\Tasks\TYTLPZ.job => C:\Users\Tibo\AppData\Roaming\TYTLPZ.exe <==== ATTENTION
Task: C:\windows\Tasks\WQRHCI.job => C:\Users\Tibo\AppData\Roaming\WQRHCI.exe <==== ATTENTION
2015-03-09 17:58 - 2014-12-11 21:18 - 00001334 _____ () C:\windows\Tasks\WQRHCI.job
2015-03-09 17:24 - 2014-12-11 21:17 - 00001678 _____ () C:\windows\Tasks\TYTLPZ.job
2014-09-03 22:36 - 2014-09-03 22:36 - 0001248 _____ () C:\Users\Tibo\AppData\Roaming\TYTLPZ
2014-09-03 22:36 - 2014-09-03 22:36 - 0002086 _____ () C:\Users\Tibo\AppData\Roaming\WQRHCI
▶ Enregistre le fichier sur ton Bureau (au même endroit que FRST) sous le nom fixlist.txt
▶ Ferme toutes les applications, y compris ton navigateur
▶ Double-clique sur FRST.exe
/!\ Sous Vista, Windows 7 et 8, il faut lancer le fichier par clic-droit -> Exécuter en tant qu'administrateur
▶ Sur le menu principal, clique une seule fois sur Fix et patiente le temps de la correction
▶ L'outil va créer un rapport de correction Fixlog.txt. Poste ce rapport dans ta réponse.
▶ /!\ Ce script a été établi pour cet utilisateur, il ne doit, en aucun cas, être appliqué sur un autre système, au risque de provoquer de graves dysfonctionnement et endommager Windows /!\
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 20:16
9 mars 2015 à 20:16
est-ce que mon pc peut "casser"
est-ce que mon pc peut "casser"
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 20:20
9 mars 2015 à 20:20
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-03-2015
Ran by Tibo at 2015-03-09 20:19:54 Run:1
Running from C:\Users\Tibo\Desktop
Loaded Profiles: Tibo (Available profiles: Tibo)
Boot Mode: Normal
Content of fixlist:
Task: {287B988F-DB1D-45C7-ABF6-69214C2DCB21} - \TYTLPZ No Task File <==== ATTENTION
Task: {9E2B6002-8B70-47A9-AF02-7AD8C89FC719} - \WQRHCI No Task File <==== ATTENTION
Task: {C9A05F71-DB56-427C-878A-708B5330302F} - \PurpleRain\PurpleRain3 No Task File <==== ATTENTION
Task: {D7DDCDEA-AA93-416F-BF73-C9DC6F2B1D27} - \f104d9b2-f4c1-4672-a978-27e82d116169-10_user No Task File <==== ATTENTION
Task: C:\windows\Tasks\TYTLPZ.job => C:\Users\Tibo\AppData\Roaming\TYTLPZ.exe <==== ATTENTION
Task: C:\windows\Tasks\WQRHCI.job => C:\Users\Tibo\AppData\Roaming\WQRHCI.exe <==== ATTENTION
2015-03-09 17:58 - 2014-12-11 21:18 - 00001334 _____ () C:\windows\Tasks\WQRHCI.job
2015-03-09 17:24 - 2014-12-11 21:17 - 00001678 _____ () C:\windows\Tasks\TYTLPZ.job
2014-09-03 22:36 - 2014-09-03 22:36 - 0001248 _____ () C:\Users\Tibo\AppData\Roaming\TYTLPZ
2014-09-03 22:36 - 2014-09-03 22:36 - 0002086 _____ () C:\Users\Tibo\AppData\Roaming\WQRHCI
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{287B988F-DB1D-45C7-ABF6-69214C2DCB21}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{287B988F-DB1D-45C7-ABF6-69214C2DCB21}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\TYTLPZ" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9E2B6002-8B70-47A9-AF02-7AD8C89FC719}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9E2B6002-8B70-47A9-AF02-7AD8C89FC719}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WQRHCI" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C9A05F71-DB56-427C-878A-708B5330302F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C9A05F71-DB56-427C-878A-708B5330302F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PurpleRain\PurpleRain3" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D7DDCDEA-AA93-416F-BF73-C9DC6F2B1D27}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D7DDCDEA-AA93-416F-BF73-C9DC6F2B1D27}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\f104d9b2-f4c1-4672-a978-27e82d116169-10_user" => Key deleted successfully.
C:\windows\Tasks\TYTLPZ.job => Moved successfully.
C:\windows\Tasks\WQRHCI.job => Moved successfully.
"C:\windows\Tasks\WQRHCI.job" => File/Directory not found.
"C:\windows\Tasks\TYTLPZ.job" => File/Directory not found.
C:\Users\Tibo\AppData\Roaming\TYTLPZ => Moved successfully.
C:\Users\Tibo\AppData\Roaming\WQRHCI => Moved successfully.
Ran by Tibo at 2015-03-09 20:19:54 Run:1
Running from C:\Users\Tibo\Desktop
Loaded Profiles: Tibo (Available profiles: Tibo)
Boot Mode: Normal
Content of fixlist:
Task: {287B988F-DB1D-45C7-ABF6-69214C2DCB21} - \TYTLPZ No Task File <==== ATTENTION
Task: {9E2B6002-8B70-47A9-AF02-7AD8C89FC719} - \WQRHCI No Task File <==== ATTENTION
Task: {C9A05F71-DB56-427C-878A-708B5330302F} - \PurpleRain\PurpleRain3 No Task File <==== ATTENTION
Task: {D7DDCDEA-AA93-416F-BF73-C9DC6F2B1D27} - \f104d9b2-f4c1-4672-a978-27e82d116169-10_user No Task File <==== ATTENTION
Task: C:\windows\Tasks\TYTLPZ.job => C:\Users\Tibo\AppData\Roaming\TYTLPZ.exe <==== ATTENTION
Task: C:\windows\Tasks\WQRHCI.job => C:\Users\Tibo\AppData\Roaming\WQRHCI.exe <==== ATTENTION
2015-03-09 17:58 - 2014-12-11 21:18 - 00001334 _____ () C:\windows\Tasks\WQRHCI.job
2015-03-09 17:24 - 2014-12-11 21:17 - 00001678 _____ () C:\windows\Tasks\TYTLPZ.job
2014-09-03 22:36 - 2014-09-03 22:36 - 0001248 _____ () C:\Users\Tibo\AppData\Roaming\TYTLPZ
2014-09-03 22:36 - 2014-09-03 22:36 - 0002086 _____ () C:\Users\Tibo\AppData\Roaming\WQRHCI
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{287B988F-DB1D-45C7-ABF6-69214C2DCB21}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{287B988F-DB1D-45C7-ABF6-69214C2DCB21}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\TYTLPZ" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9E2B6002-8B70-47A9-AF02-7AD8C89FC719}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9E2B6002-8B70-47A9-AF02-7AD8C89FC719}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WQRHCI" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C9A05F71-DB56-427C-878A-708B5330302F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C9A05F71-DB56-427C-878A-708B5330302F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PurpleRain\PurpleRain3" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D7DDCDEA-AA93-416F-BF73-C9DC6F2B1D27}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D7DDCDEA-AA93-416F-BF73-C9DC6F2B1D27}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\f104d9b2-f4c1-4672-a978-27e82d116169-10_user" => Key deleted successfully.
C:\windows\Tasks\TYTLPZ.job => Moved successfully.
C:\windows\Tasks\WQRHCI.job => Moved successfully.
"C:\windows\Tasks\WQRHCI.job" => File/Directory not found.
"C:\windows\Tasks\TYTLPZ.job" => File/Directory not found.
C:\Users\Tibo\AppData\Roaming\TYTLPZ => Moved successfully.
C:\Users\Tibo\AppData\Roaming\WQRHCI => Moved successfully.
End of Fixlog 20:19:55
Messages postés
Date d'inscription
dimanche 8 mars 2015
Dernière intervention
11 mars 2015
Modifié par AkaAmnesia le 9/03/2015 à 20:24
Modifié par AkaAmnesia le 9/03/2015 à 20:24
Pourras tu me résoudre un problème après s'il te plait?
C'est en rapport avec le fichier AppData
C'est en rapport avec le fichier AppData
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 20:32
9 mars 2015 à 20:32
madame ou monsieur, je vous/te remercie énormément!
je ferais plus attention avant de télécharger quoi que ce soit.
En tout cas vous êtes doué(e)
madame ou monsieur, je vous/te remercie énormément!
je ferais plus attention avant de télécharger quoi que ce soit.
En tout cas vous êtes doué(e)
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 20:33
9 mars 2015 à 20:33
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
9 mars 2015 à 20:34
9 mars 2015 à 20:34
Ps suis une fille ^^
Attends ce n'est pas fini le final
1)Désinstallation des outils de désinfection
Télécharges Delfix ici
Exécutes le en tant qu'administrateur(si tu es sous xp double clic sur le fichier téléchargé) puis une fois sur l'interface coches les cases suivantes
-supprimer les outils de désinfections
-purger la restauration du système
Cliques ensuite sur Exécuter puis patientes pendant le processus de suppression.
Le rapport sera enregistré dans le presse-papier et sur le disque dur (C:\DelFix.txt).
Poste le rapport
2)N'oublies pas de mettre à jour java adobe reader et flashplayer pour IE (chrome l'intègre déjà)
Un lien utile à lire
N'oublies pas aussi de maintenir Windows à jour via Windows update
3)Pour permettre de mettre à jour tes logiciels je te conseille d'utiliser Filehippo update checker
Tu peux le télécharger ici
Pour l'installation de filehippo décoches seulement mettre l'icône dans la barre de lancement rapide
4)Pour nettoyer les fichiers temporaires (attention pas de nettoyage registre ) tu peux utiliser Ccleaner avec tuto pour bien le configurer (
Lien du téléchargement
Tu peux aussi utiliser le nettoyeur de disque windows
N'oublies pas de défragmenter de temps en temps ton disque dur soit par le biais de l'utilitaire soit par le biais d'un logiciel tiers comme par exemple Deffagler ou auslogic Disk Defrag
Oublies les genres de nettoyeurs comme Tuneup ,Glary et autre nettoyeurs miracles ils ne te feront que ralentir ta machine et nettoyer plus blanc que blanc peut provoquer de graves dysfonctionnements
5)Sécurise tes navigateurs par exemple avec WOT et simple adblock pour Internet explorer
Pour télécharger WOT pour ie c'est par ici
Pour chrome(si tu possèdes Chrome)
Wot disponible ici
Adblock disponible ici
Lien du téléchargement pour wot sur firefox
Lien pour télécharger adblock +
6)Fais attention à ce que tu télécharges où et comment
Evites si possible de télécharger sur O1net,tom's guide,télé et Softonic et compagnie car ils repackent les logiciels avec des programmes potientellement indésirables
A lire
7)Pourquoi faut-il éviter de télécharger sur du p2p
Les risques sont gros la machine risque de devenir un pc zombie
Un peu de lecture concernant les dangers et le risque
8)Petit exercice pour éviter de se faire piéger
Ps suis une fille ^^
Attends ce n'est pas fini le final
1)Désinstallation des outils de désinfection
Télécharges Delfix ici
Exécutes le en tant qu'administrateur(si tu es sous xp double clic sur le fichier téléchargé) puis une fois sur l'interface coches les cases suivantes
-supprimer les outils de désinfections
-purger la restauration du système
Cliques ensuite sur Exécuter puis patientes pendant le processus de suppression.
Le rapport sera enregistré dans le presse-papier et sur le disque dur (C:\DelFix.txt).
Poste le rapport
2)N'oublies pas de mettre à jour java adobe reader et flashplayer pour IE (chrome l'intègre déjà)
Un lien utile à lire
N'oublies pas aussi de maintenir Windows à jour via Windows update
3)Pour permettre de mettre à jour tes logiciels je te conseille d'utiliser Filehippo update checker
Tu peux le télécharger ici
Pour l'installation de filehippo décoches seulement mettre l'icône dans la barre de lancement rapide
4)Pour nettoyer les fichiers temporaires (attention pas de nettoyage registre ) tu peux utiliser Ccleaner avec tuto pour bien le configurer (
Lien du téléchargement
Tu peux aussi utiliser le nettoyeur de disque windows
N'oublies pas de défragmenter de temps en temps ton disque dur soit par le biais de l'utilitaire soit par le biais d'un logiciel tiers comme par exemple Deffagler ou auslogic Disk Defrag
Oublies les genres de nettoyeurs comme Tuneup ,Glary et autre nettoyeurs miracles ils ne te feront que ralentir ta machine et nettoyer plus blanc que blanc peut provoquer de graves dysfonctionnements
5)Sécurise tes navigateurs par exemple avec WOT et simple adblock pour Internet explorer
Pour télécharger WOT pour ie c'est par ici
Pour chrome(si tu possèdes Chrome)
Wot disponible ici
Adblock disponible ici
Lien du téléchargement pour wot sur firefox
Lien pour télécharger adblock +
6)Fais attention à ce que tu télécharges où et comment
Evites si possible de télécharger sur O1net,tom's guide,télé et Softonic et compagnie car ils repackent les logiciels avec des programmes potientellement indésirables
A lire
7)Pourquoi faut-il éviter de télécharger sur du p2p
Les risques sont gros la machine risque de devenir un pc zombie
Un peu de lecture concernant les dangers et le risque
8)Petit exercice pour éviter de se faire piéger
Messages postés
Date d'inscription
dimanche 8 mars 2015
Dernière intervention
11 mars 2015
9 mars 2015 à 20:37
9 mars 2015 à 20:37
Tu fait support technique dans la vie?
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 20:39
9 mars 2015 à 20:39
OK merci pour toute ton aide qui m'a été précieuse.
je n'aurais pas pu y arriver seul comme j'ai 14 ans
je n'aurais pas pu y arriver seul comme j'ai 14 ans
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 20:52
9 mars 2015 à 20:52
# DelFix v10.9 - Rapport créé le 09/03/2015 à 20:42:25
# Mis à jour le 27/02/2015 par Xplode
# Nom d'utilisateur : Tibo - TIBO-TOSH
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
~ Suppression des outils de désinfection ...
Supprimé : C:\FRST
Supprimée : HKLM\SOFTWARE\AdwCleaner
~ Purge de la restauration système ...
Supprimé : RP #94 [Installé Realtek Card Reader | 01/25/2015 13:16:42]
Supprimé : RP #95 [Windows Update | 01/25/2015 20:44:50]
Supprimé : RP #96 [Windows Update | 01/26/2015 19:05:47]
Supprimé : RP #97 [Windows Update | 01/27/2015 20:56:11]
Supprimé : RP #98 [Windows Update | 01/28/2015 20:36:17]
Supprimé : RP #99 [Windows Update | 01/29/2015 21:05:01]
Supprimé : RP #100 [Windows Update | 01/30/2015 21:46:43]
Supprimé : RP #101 [Windows Update | 01/31/2015 11:17:51]
Supprimé : RP #102 [Windows Update | 01/31/2015 23:30:53]
Supprimé : RP #103 [Windows Update | 02/01/2015 21:30:15]
Supprimé : RP #104 [Windows Update | 02/02/2015 20:27:39]
Supprimé : RP #105 [Windows Update | 02/02/2015 21:13:06]
Supprimé : RP #106 [Windows Update | 02/03/2015 21:37:04]
Supprimé : RP #107 [Windows Update | 02/04/2015 20:52:13]
Supprimé : RP #108 [Windows Update | 02/05/2015 21:04:11]
Supprimé : RP #109 [Windows Update | 02/06/2015 17:22:08]
Supprimé : RP #110 [Windows Update | 02/07/2015 00:28:07]
Supprimé : RP #111 [Windows Update | 02/08/2015 00:29:35]
Supprimé : RP #112 [Windows Update | 02/08/2015 20:47:23]
Supprimé : RP #113 [Windows Update | 02/09/2015 21:03:24]
Supprimé : RP #114 [Windows Update | 02/10/2015 22:02:29]
Supprimé : RP #115 [Windows Update | 02/11/2015 21:23:25]
Supprimé : RP #116 [Removed BlueStacks Notification Center | 02/12/2015 18:26:21]
Supprimé : RP #117 [Removed BlueStacks Notification Center | 02/12/2015 18:34:10]
Supprimé : RP #118 [Removed BlueStacks Notification Center | 02/12/2015 18:40:00]
Supprimé : RP #119 [Removed BlueStacks Notification Center | 02/12/2015 18:41:15]
Supprimé : RP #120 [Windows Update | 02/12/2015 21:18:18]
Supprimé : RP #121 [Windows Update | 02/13/2015 16:52:54]
Supprimé : RP #122 [Windows Update | 02/14/2015 00:56:37]
Supprimé : RP #123 [Windows Update | 02/14/2015 13:55:55]
Supprimé : RP #124 [Windows Update | 02/16/2015 09:56:32]
Supprimé : RP #125 [Windows Update | 02/17/2015 01:29:21]
Supprimé : RP #126 [Windows Update | 02/17/2015 19:52:53]
Supprimé : RP #127 [Windows Update | 02/17/2015 20:05:24]
Supprimé : RP #128 [Removed BlueStacks Notification Center | 02/17/2015 22:30:56]
Supprimé : RP #129 [Windows Update | 02/18/2015 00:57:06]
Supprimé : RP #130 [DirectX est installé | 02/18/2015 20:06:38]
Supprimé : RP #131 [DirectX est installé | 02/18/2015 20:08:17]
Supprimé : RP #132 [DirectX est installé | 02/18/2015 20:11:44]
Supprimé : RP #133 [DirectX est installé | 02/18/2015 20:12:21]
Supprimé : RP #134 [Windows Update | 02/19/2015 01:39:20]
Supprimé : RP #135 [Windows Update | 02/20/2015 01:04:59]
Supprimé : RP #136 [Windows Update | 02/21/2015 02:00:31]
Supprimé : RP #137 [Windows Update | 02/21/2015 05:18:02]
Supprimé : RP #138 [Windows Update | 02/22/2015 02:00:31]
Supprimé : RP #139 [Windows Update | 02/22/2015 02:32:03]
Supprimé : RP #140 [Windows Update | 02/23/2015 00:48:41]
Supprimé : RP #141 [Windows Update | 02/28/2015 00:35:00]
Supprimé : RP #142 [Windows Update | 03/01/2015 00:42:30]
Supprimé : RP #143 [Windows Update | 03/01/2015 21:42:21]
Supprimé : RP #144 [Windows Update | 03/02/2015 22:21:21]
Supprimé : RP #145 [Windows Update | 03/03/2015 22:01:42]
Supprimé : RP #146 [Installed Minecraft | 03/04/2015 17:49:36]
Supprimé : RP #147 [Installed Minecraft | 03/04/2015 17:51:01]
Supprimé : RP #148 [Windows Update | 03/04/2015 22:02:15]
Supprimé : RP #149 [Windows Update | 03/05/2015 21:18:23]
Supprimé : RP #150 [Windows Update | 03/05/2015 22:05:23]
Supprimé : RP #151 [Windows Update | 03/06/2015 23:08:31]
Supprimé : RP #152 [Windows Update | 03/07/2015 21:53:27]
Supprimé : RP #153 [Windows Update | 03/08/2015 01:31:09]
Supprimé : RP #154 [Installed Minecraft | 03/08/2015 20:46:40]
Supprimé : RP #155 [Windows Update | 03/08/2015 21:49:24]
Supprimé : RP #156 [Supprimé TuneUp Utilities 2014 | 03/09/2015 17:09:20]
Supprimé : RP #157 [Supprimé TuneUp Utilities 2014 (fr-FR) | 03/09/2015 17:16:54]
Nouveau point de restauration créé !
########## - EOF - ##########
# Mis à jour le 27/02/2015 par Xplode
# Nom d'utilisateur : Tibo - TIBO-TOSH
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
~ Suppression des outils de désinfection ...
Supprimé : C:\FRST
Supprimée : HKLM\SOFTWARE\AdwCleaner
~ Purge de la restauration système ...
Supprimé : RP #94 [Installé Realtek Card Reader | 01/25/2015 13:16:42]
Supprimé : RP #95 [Windows Update | 01/25/2015 20:44:50]
Supprimé : RP #96 [Windows Update | 01/26/2015 19:05:47]
Supprimé : RP #97 [Windows Update | 01/27/2015 20:56:11]
Supprimé : RP #98 [Windows Update | 01/28/2015 20:36:17]
Supprimé : RP #99 [Windows Update | 01/29/2015 21:05:01]
Supprimé : RP #100 [Windows Update | 01/30/2015 21:46:43]
Supprimé : RP #101 [Windows Update | 01/31/2015 11:17:51]
Supprimé : RP #102 [Windows Update | 01/31/2015 23:30:53]
Supprimé : RP #103 [Windows Update | 02/01/2015 21:30:15]
Supprimé : RP #104 [Windows Update | 02/02/2015 20:27:39]
Supprimé : RP #105 [Windows Update | 02/02/2015 21:13:06]
Supprimé : RP #106 [Windows Update | 02/03/2015 21:37:04]
Supprimé : RP #107 [Windows Update | 02/04/2015 20:52:13]
Supprimé : RP #108 [Windows Update | 02/05/2015 21:04:11]
Supprimé : RP #109 [Windows Update | 02/06/2015 17:22:08]
Supprimé : RP #110 [Windows Update | 02/07/2015 00:28:07]
Supprimé : RP #111 [Windows Update | 02/08/2015 00:29:35]
Supprimé : RP #112 [Windows Update | 02/08/2015 20:47:23]
Supprimé : RP #113 [Windows Update | 02/09/2015 21:03:24]
Supprimé : RP #114 [Windows Update | 02/10/2015 22:02:29]
Supprimé : RP #115 [Windows Update | 02/11/2015 21:23:25]
Supprimé : RP #116 [Removed BlueStacks Notification Center | 02/12/2015 18:26:21]
Supprimé : RP #117 [Removed BlueStacks Notification Center | 02/12/2015 18:34:10]
Supprimé : RP #118 [Removed BlueStacks Notification Center | 02/12/2015 18:40:00]
Supprimé : RP #119 [Removed BlueStacks Notification Center | 02/12/2015 18:41:15]
Supprimé : RP #120 [Windows Update | 02/12/2015 21:18:18]
Supprimé : RP #121 [Windows Update | 02/13/2015 16:52:54]
Supprimé : RP #122 [Windows Update | 02/14/2015 00:56:37]
Supprimé : RP #123 [Windows Update | 02/14/2015 13:55:55]
Supprimé : RP #124 [Windows Update | 02/16/2015 09:56:32]
Supprimé : RP #125 [Windows Update | 02/17/2015 01:29:21]
Supprimé : RP #126 [Windows Update | 02/17/2015 19:52:53]
Supprimé : RP #127 [Windows Update | 02/17/2015 20:05:24]
Supprimé : RP #128 [Removed BlueStacks Notification Center | 02/17/2015 22:30:56]
Supprimé : RP #129 [Windows Update | 02/18/2015 00:57:06]
Supprimé : RP #130 [DirectX est installé | 02/18/2015 20:06:38]
Supprimé : RP #131 [DirectX est installé | 02/18/2015 20:08:17]
Supprimé : RP #132 [DirectX est installé | 02/18/2015 20:11:44]
Supprimé : RP #133 [DirectX est installé | 02/18/2015 20:12:21]
Supprimé : RP #134 [Windows Update | 02/19/2015 01:39:20]
Supprimé : RP #135 [Windows Update | 02/20/2015 01:04:59]
Supprimé : RP #136 [Windows Update | 02/21/2015 02:00:31]
Supprimé : RP #137 [Windows Update | 02/21/2015 05:18:02]
Supprimé : RP #138 [Windows Update | 02/22/2015 02:00:31]
Supprimé : RP #139 [Windows Update | 02/22/2015 02:32:03]
Supprimé : RP #140 [Windows Update | 02/23/2015 00:48:41]
Supprimé : RP #141 [Windows Update | 02/28/2015 00:35:00]
Supprimé : RP #142 [Windows Update | 03/01/2015 00:42:30]
Supprimé : RP #143 [Windows Update | 03/01/2015 21:42:21]
Supprimé : RP #144 [Windows Update | 03/02/2015 22:21:21]
Supprimé : RP #145 [Windows Update | 03/03/2015 22:01:42]
Supprimé : RP #146 [Installed Minecraft | 03/04/2015 17:49:36]
Supprimé : RP #147 [Installed Minecraft | 03/04/2015 17:51:01]
Supprimé : RP #148 [Windows Update | 03/04/2015 22:02:15]
Supprimé : RP #149 [Windows Update | 03/05/2015 21:18:23]
Supprimé : RP #150 [Windows Update | 03/05/2015 22:05:23]
Supprimé : RP #151 [Windows Update | 03/06/2015 23:08:31]
Supprimé : RP #152 [Windows Update | 03/07/2015 21:53:27]
Supprimé : RP #153 [Windows Update | 03/08/2015 01:31:09]
Supprimé : RP #154 [Installed Minecraft | 03/08/2015 20:46:40]
Supprimé : RP #155 [Windows Update | 03/08/2015 21:49:24]
Supprimé : RP #156 [Supprimé TuneUp Utilities 2014 | 03/09/2015 17:09:20]
Supprimé : RP #157 [Supprimé TuneUp Utilities 2014 (fr-FR) | 03/09/2015 17:16:54]
Nouveau point de restauration créé !
########## - EOF - ##########
Messages postés
Date d'inscription
dimanche 8 mars 2015
Dernière intervention
11 mars 2015
9 mars 2015 à 21:04
9 mars 2015 à 21:04
Ah oui elle fait partie du support .__.
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 20:58
9 mars 2015 à 20:58
Messages postés
Date d'inscription
dimanche 8 mars 2015
Dernière intervention
11 mars 2015
Modifié par AkaAmnesia le 9/03/2015 à 21:59
Modifié par AkaAmnesia le 9/03/2015 à 21:59
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
9 mars 2015 à 21:05
9 mars 2015 à 21:05
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 21:08
9 mars 2015 à 21:08
OK merci tu est très douée!
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 21:13
9 mars 2015 à 21:13
Si tu as un problème avec cette maj tu peux poster sur windows 7
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 21:14
9 mars 2015 à 21:14
à une prochaine fois!
Messages postés
Date d'inscription
lundi 25 avril 2011
Contributeur sécurité
Dernière intervention
31 octobre 2024
3 806
Messages postés
Date d'inscription
samedi 7 mars 2015
Dernière intervention
6 août 2015
9 mars 2015 à 21:16
9 mars 2015 à 21:16
merci :)
9 mars 2015 à 18:07