PC infecté, publicités intempestives : FlashBeat, Xtab, SmartWeb
Résolu
girfred
Messages postés
17
Date d'inscription
Statut
Membre
Dernière intervention
-
Malekal_morte- Messages postés 180304 Date d'inscription Statut Modérateur, Contributeur sécurité Dernière intervention -
Malekal_morte- Messages postés 180304 Date d'inscription Statut Modérateur, Contributeur sécurité Dernière intervention -
Bonjour à tous,
Le Pc portable de mes beaux parents est infecté par un truc que je n'arrive pas à supprimer. Je pense que c'est FlashBeat mais je n'en suis pas certain. La naviguation sur le net est infernale.
Merci à ceux voudront bien m'aider.
Le Pc portable de mes beaux parents est infecté par un truc que je n'arrive pas à supprimer. Je pense que c'est FlashBeat mais je n'en suis pas certain. La naviguation sur le net est infernale.
Merci à ceux voudront bien m'aider.
A voir également:
- PC infecté, publicités intempestives : FlashBeat, Xtab, SmartWeb
- Reinitialiser pc - Guide
- Test performance pc - Guide
- Pc lent - Guide
- Downloader for pc - Télécharger - Téléchargement & Transfert
- Supprimer les publicités - Guide
21 réponses
Salut,
Suis ce tutoriel FRST: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/
(et bien prendre le temps de lire afin d'appliquer correctement - tout y est expliqué).
Télécharge et lance le scan FRST, cela va générer trois rapports FRST :
Envoie, comme expliqué, ces trois rapports sur le site http://pjjoint.malekal.com et en retour donne les trois liens pjjoint qui mènent à ses rapports ici dans une nouvelle réponse afin que l'on puisse les consulter.
Suis ce tutoriel FRST: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/
(et bien prendre le temps de lire afin d'appliquer correctement - tout y est expliqué).
Télécharge et lance le scan FRST, cela va générer trois rapports FRST :
- FRST.txt
- Shortcut.txt
- Additionnal.txt
Envoie, comme expliqué, ces trois rapports sur le site http://pjjoint.malekal.com et en retour donne les trois liens pjjoint qui mènent à ses rapports ici dans une nouvelle réponse afin que l'on puisse les consulter.
Salut,
Merci pour ton aide.
Ci-dessous les trois
https://pjjoint.malekal.com/files.php?id=20150404_y6m8o13m9t5
https://pjjoint.malekal.com/files.php?id=20150404_h7w9q1214c8
https://pjjoint.malekal.com/files.php?id=FRST_20150404_l13g11g10b11g10
Merci pour ton aide.
Ci-dessous les trois
https://pjjoint.malekal.com/files.php?id=20150404_y6m8o13m9t5
https://pjjoint.malekal.com/files.php?id=20150404_h7w9q1214c8
https://pjjoint.malekal.com/files.php?id=FRST_20150404_l13g11g10b11g10
Tu as installé des adwares et programmes parasites sur ton PC qui ouvrent des publicités et ralentissent l'ordinateur et les navigateurs WEB.
Voici la procédure à suivre pour les supprimer :
Commence par ceci :
Suis le tutorial AdwCleaner https://www.malekal.com/adwcleaner-supprimer-virus-adwares-pup/?t=33839&start= ( d'Xplode )
Télécharge le sur ton bureau ou dossier de téléchargement.
Lance AdwCleaner, clique sur [Scanner].
L'analyse peux durer plusieurs minutes, patiente.
Une fois le scan terminé, ne décoche rien, clique sur [Nettoyer]
Une fois le nettoyage terminé, un rapport s'ouvrira. Copie/colle le contenu du rapport dans ta prochaine réponse par un copier/coller.
Si cela ne fonctionne pas, utilise le site http://pjjoint.malekal.com pour héberger le rapport, donne le lien du rapport dans un nouveau message.
Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt
Voici la procédure à suivre pour les supprimer :
Commence par ceci :
Suis le tutorial AdwCleaner https://www.malekal.com/adwcleaner-supprimer-virus-adwares-pup/?t=33839&start= ( d'Xplode )
Télécharge le sur ton bureau ou dossier de téléchargement.
Lance AdwCleaner, clique sur [Scanner].
L'analyse peux durer plusieurs minutes, patiente.
Une fois le scan terminé, ne décoche rien, clique sur [Nettoyer]
Une fois le nettoyage terminé, un rapport s'ouvrira. Copie/colle le contenu du rapport dans ta prochaine réponse par un copier/coller.
Si cela ne fonctionne pas, utilise le site http://pjjoint.malekal.com pour héberger le rapport, donne le lien du rapport dans un nouveau message.
Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt
Bien enfin c'est fait, la navigation est vraiment pénible! Ci-dessous le rapport.
# AdwCleaner v4.200 - Rapport créé le 04/04/2015 à 22:50:23
# Mis à jour le 29/03/2015 par Xplode
# Base de données : 2015-03-29.1 [Serveur]
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (x64)
# Nom d'utilisateur : Françoise - FRANÇOISE-HP
# Exécuté depuis : C:\Users\Françoise\Downloads\adwcleaner_4.200.exe
# Option : Nettoyer
Service Supprimé : CltMngSvc
[#] Service Supprimé : Gambali
[#] Service Supprimé : globalUpdate
[#] Service Supprimé : globalUpdatem
Service Supprimé : netfilter64
Service Supprimé : Orbiter
Service Supprimé : ServiceEverything
[#] Service Supprimé : pfnfd_1_10_0_9
[#] Service Supprimé : qrnfd_1_10_0_9
Dossier Supprimé : C:\TVWizard
Dossier Supprimé : C:\HealthAlert
Dossier Supprimé : C:\ProgramData\Browser
Dossier Supprimé : C:\ProgramData\ParetoLogic
Dossier Supprimé : C:\ProgramData\PicRec
Dossier Supprimé : C:\ProgramData\PriceMeterLiveUpdate
Dossier Supprimé : C:\ProgramData\systemk
Dossier Supprimé : C:\ProgramData\WindowsMangerProtect
Dossier Supprimé : C:\ProgramData\WPM
Dossier Supprimé : C:\ProgramData\YTAHelper
Dossier Supprimé : C:\ProgramData\IHProtectUpDate
Dossier Supprimé : C:\ProgramData\FlashBeat
Dossier Supprimé : C:\ProgramData\CoolSaleCuouppoon
Dossier Supprimé : C:\ProgramData\dEalpeaak
Dossier Supprimé : C:\ProgramData\WOwCouponn
Dossier Supprimé : C:\ProgramData\6eb9994600007367
Dossier Supprimé : C:\ProgramData\a06c590c1f809607
Dossier Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flash Player Pro
Dossier Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverRestore
Dossier Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
Dossier Supprimé : C:\Program Files (x86)\AnyProtectEx
Dossier Supprimé : C:\Program Files (x86)\Boxore
Dossier Supprimé : C:\Program Files (x86)\Easy Speed Check
Dossier Supprimé : C:\Program Files (x86)\Flash Player Pro
Dossier Supprimé : C:\Program Files (x86)\globalUpdate
Dossier Supprimé : C:\Program Files (x86)\ParetoLogic
Dossier Supprimé : C:\Program Files (x86)\PC Speed Maximizer
Dossier Supprimé : C:\Program Files (x86)\PicRec
Dossier Supprimé : C:\Program Files (x86)\predm
Dossier Supprimé : C:\Program Files (x86)\Probit Software
Dossier Supprimé : C:\Program Files (x86)\SearchProtect
Dossier Supprimé : C:\Program Files (x86)\Settings Manager
Dossier Supprimé : C:\Program Files (x86)\Smart Driver Updater
Dossier Supprimé : C:\Program Files (x86)\WinZipper
Dossier Supprimé : C:\Program Files (x86)\DriverRestore
Dossier Supprimé : C:\Program Files (x86)\ORBTR
Dossier Supprimé : C:\Program Files (x86)\EZ Software Updater
Dossier Supprimé : C:\Program Files (x86)\XTab
Dossier Supprimé : C:\Program Files (x86)\igs
Dossier Supprimé : C:\Program Files (x86)\QuickRef_1.10.0.9
Dossier Supprimé : C:\Program Files (x86)\CoolSaleCuouppoon
Dossier Supprimé : C:\Program Files (x86)\dEalpeaak
Dossier Supprimé : C:\Program Files (x86)\WOwCouponn
Dossier Supprimé : C:\Program Files (x86)\gmsd_fr_373
Dossier Supprimé : C:\Program Files (x86)\gmsd_fr_379
Dossier Supprimé : C:\Program Files (x86)\Common Files\ParetoLogic
Dossier Supprimé : C:\Windows\Microsoft\sogr
Dossier Supprimé : C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Infigo
Dossier Supprimé : C:\Program Files\002
Dossier Supprimé : C:\Program Files\003
Dossier Supprimé : C:\Program Files\shopperz
Dossier Supprimé : C:\Users\Françoise\AppData\Local\Boxore
Dossier Supprimé : C:\Users\Françoise\AppData\Local\Genesis
Dossier Supprimé : C:\Users\Françoise\AppData\Local\globalUpdate
Dossier Supprimé : C:\Users\Françoise\AppData\Local\Mobogenie
Dossier Supprimé : C:\Users\Françoise\AppData\Local\SearchProtect
Dossier Supprimé : C:\Users\Françoise\AppData\Local\TVWizard
Dossier Supprimé : C:\Users\Françoise\AppData\Local\SmartWeb
Dossier Supprimé : C:\Users\Françoise\AppData\Local\Doctor_PC
Dossier Supprimé : C:\Users\Françoise\AppData\Local\Pro_PC_Cleaner
Dossier Supprimé : C:\Users\Françoise\AppData\Local\Microsoft\WinU
Dossier Supprimé : C:\Users\Françoise\AppData\Local\Binkiland
Dossier Supprimé : C:\Users\Françoise\AppData\Local\gmsd_fr_373
Dossier Supprimé : C:\Users\Françoise\AppData\Local\gmsd_fr_379
Dossier Supprimé : C:\Users\Françoise\AppData\LocalLow\iac
Dossier Supprimé : C:\Users\Françoise\AppData\LocalLow\IminentToolbar
Dossier Supprimé : C:\Users\Françoise\AppData\LocalLow\mystarttb
Dossier Supprimé : C:\Users\Françoise\AppData\LocalLow\SmartWeb
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\AnyProtectEx
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\DriverCure
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Gameo
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\istartsurf
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Nosibay
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\ParetoLogic
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Probit Software
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\qone8
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\sweet-page
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Systweak
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\webplayer
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\wp_update
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Advanced Cleaner Pro
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Infigo
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Company Name
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Binkiland
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\7r64_lvf@hcvkzbuyoi.com
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\jzju0h@uydys.org
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\rbfm1xa@iyy-gzmh.edu
Fichier Supprimé : C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\{E77F341C-F32E-40AA-8829-AA785C7D9316}.xpi
Fichier Supprimé : C:\crossbrowse.lnk
Fichier Supprimé : C:\Windows\apppatch\apppatch64\vcldr64.dll
Fichier Supprimé : C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
Fichier Supprimé : C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb
Fichier Supprimé : C:\Windows\AppPatch\nbin\VC32Loader.dll
Fichier Supprimé : C:\Windows\efix.ini
Fichier Supprimé : C:\Windows\patsearch.bin
Fichier Supprimé : C:\Windows\Reimage.ini
Fichier Supprimé : C:\Windows\SysWOW64\Gambali.dll
Fichier Supprimé : C:\Windows\SysWOW64\GambaliOff.ini
Fichier Supprimé : C:\Users\FRANOI~1\AppData\Local\Temp\Uninstall.exe
Fichier Supprimé : C:\Windows\System32\Gambali64.dll
Fichier Supprimé : C:\Windows\System32\GambaliOff.ini
Fichier Supprimé : C:\Windows\System32\roboot64.exe
Fichier Supprimé : C:\Windows\System32\drivers\netfilter64.sys
Fichier Supprimé : C:\Windows\System32\drivers\qrnfd_1_10_0_9.sys
Fichier Supprimé : C:\Users\Françoise\daemonprocess.txt
Fichier Supprimé : C:\Users\Françoise\AppData\Roaming\aps.uninstall.scan.results
Fichier Supprimé : C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk
Fichier Supprimé : C:\Users\Françoise\Desktop\AnyProtect.lnk
Fichier Supprimé : C:\Users\Françoise\Desktop\eBay.lnk
Fichier Supprimé : C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\searchplugins\MyOnlineSearch.xml
Fichier Supprimé : C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\searchplugins\mysearchskms.xml
Fichier Supprimé : C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\user.js
Tâche Supprimée : APSnotifierPP1
Tâche Supprimée : APSnotifierPP2
Tâche Supprimée : APSnotifierPP3
Tâche Supprimée : Binkiland
Tâche Supprimée : DoctorPC_Start
Tâche Supprimée : globalUpdateUpdateTaskMachineCore
Tâche Supprimée : globalUpdateUpdateTaskMachineUA
Tâche Supprimée : InfiniteCrisis TW1
Tâche Supprimée : InfiniteCrisis TW2
Tâche Supprimée : LaunchSignup
Tâche Supprimée : Optimizer Pro Schedule
Tâche Supprimée : pricemeterdownloader
Tâche Supprimée : PriceMeterLiveUpdateUpdateTaskMachineCore
Tâche Supprimée : PriceMeterLiveUpdateUpdateTaskMachineUA
Tâche Supprimée : PriceMeterUpdater
Tâche Supprimée : ProPCCleaner_Start
Tâche Supprimée : SmartWeb Upgrade Trigger Task
Tâche Supprimée : TaskUserUpdate_wp
Tâche Supprimée : 7afd764a-e7cd-4246-be3e-541cc5aa9a66-10_user
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\speedupmypc
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Clé Supprimée : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Clé Supprimée : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Clé Supprimée : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Valeur Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [EasySpeedCheck]
Clé Supprimée : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm
Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SmartWeb]
Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [gmsd_fr_373]
Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [gmsd_fr_379]
Clé Supprimée : HKLM\SOFTWARE\69c797b1-4ba6-2a3b-d356-5d276df4c3ea
Clé Supprimée : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{126C78A0-36E7-4697-A3AB-32706144398B}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{00A154AE-6C33-4F1E-9057-242350540936}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{126C78A0-36E7-4697-A3AB-32706144398B}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{5B60D1C0-453A-485D-AE91-61FAC9203719}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{03771AEF-400D-4A13-B712-25878EC4A3F5}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Clé Supprimée : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Clé Supprimée : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}
Clé Supprimée : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Clé Supprimée : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Clé Supprimée : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CC865B26-C31D-4D23-B17B-96548EEF03F6}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{a0892e19-6051-4ae6-9a5f-91542a166b2b}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0b4d26f6-61a8-4463-99dd-5f2fe0400fa6}
Clé Supprimée : HKCU\Software\AnyProtect
Clé Supprimée : HKCU\Software\Boost
Clé Supprimée : HKCU\Software\BRS
Clé Supprimée : HKCU\Software\eSupport.com
Clé Supprimée : HKCU\Software\genesis
Clé Supprimée : HKCU\Software\GlobalUpdate
Clé Supprimée : HKCU\Software\Goobzo
Clé Supprimée : HKCU\Software\IM
Clé Supprimée : HKCU\Software\ImInstaller
Clé Supprimée : HKCU\Software\InstallCore
Clé Supprimée : HKCU\Software\Nosibay
Clé Supprimée : HKCU\Software\Optimizer Pro
Clé Supprimée : HKCU\Software\simplytech
Clé Supprimée : HKCU\Software\Store
Clé Supprimée : HKCU\Software\systweak
Clé Supprimée : HKCU\Software\Tutorials
Clé Supprimée : HKCU\Software\TutoTag
Clé Supprimée : HKCU\Software\Vittalia
Clé Supprimée : HKCU\Software\DriverRestore
Clé Supprimée : HKCU\Software\UpdateFiles
Clé Supprimée : HKCU\Software\Easy Speed Check
Clé Supprimée : HKCU\Software\Advanced Cleaner Pro
Clé Supprimée : HKCU\Software\gameo
Clé Supprimée : HKCU\Software\GAMESDESKTOP
Clé Supprimée : HKCU\Software\TNT2
Clé Supprimée : HKCU\Software\Super Optimizer
Clé Supprimée : HKCU\Software\ProPCCleanerLanguage
Clé Supprimée : HKCU\Software\ProPCCleanerConfig
Clé Supprimée : HKCU\Software\Binkiland Browser
Clé Supprimée : HKCU\Software\SearchProtectWS
Clé Supprimée : HKCU\Software\Kreapixel
Clé Supprimée : HKCU\Software\Crossbrowse
Clé Supprimée : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Clé Supprimée : HKCU\Software\AppDataLow\Software\BlockAndSurf
Clé Supprimée : HKCU\Software\AppDataLow\Software\Crossrider
Clé Supprimée : HKCU\Software\AppDataLow\Software\DynConIE
Clé Supprimée : HKCU\Software\AppDataLow\Software\SmartWeb
Clé Supprimée : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Clé Supprimée : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Clé Supprimée : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Clé Supprimée : HKLM\SOFTWARE\Boost
Clé Supprimée : HKLM\SOFTWARE\EZ Software Updater
Clé Supprimée : HKLM\SOFTWARE\GlobalUpdate
Clé Supprimée : HKLM\SOFTWARE\Goobzo
Clé Supprimée : HKLM\SOFTWARE\hdcode
Clé Supprimée : HKLM\SOFTWARE\ImInstaller
Clé Supprimée : HKLM\SOFTWARE\istartsurfSoftware
Clé Supprimée : HKLM\SOFTWARE\SearchProtect
Clé Supprimée : HKLM\SOFTWARE\SupDp
Clé Supprimée : HKLM\SOFTWARE\SupTab
Clé Supprimée : HKLM\SOFTWARE\sweet-pageSoftware
Clé Supprimée : HKLM\SOFTWARE\systweak
Clé Supprimée : HKLM\SOFTWARE\Tutorials
Clé Supprimée : HKLM\SOFTWARE\winzipersvc
Clé Supprimée : HKLM\SOFTWARE\SpeedBrowser
Clé Supprimée : HKLM\SOFTWARE\mystartsearchSoftware
Clé Supprimée : HKLM\SOFTWARE\ORBTR
Clé Supprimée : HKLM\SOFTWARE\GAMESDESKTOP
Clé Supprimée : HKLM\SOFTWARE\IHProtect
Clé Supprimée : HKLM\SOFTWARE\SPPDCOM
Clé Supprimée : HKLM\SOFTWARE\IGS
Clé Supprimée : HKLM\SOFTWARE\FlashBeat
Clé Supprimée : HKLM\SOFTWARE\QuickRef_1.10.0.9
Clé Supprimée : HKLM\SOFTWARE\Crossbrowse
Clé Supprimée : HKLM\SOFTWARE\doctor pc
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\WajIntEnhance
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran.com
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1B8A71D1-31D4-EE6A-C32F-836E0BFFA6D3}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C60D3D4E-3B20-5AB3-7F2C-9C946AD4080F}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AnyProtect
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SmartWeb
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBeat
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WajIntEnhance
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran.com
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gmsd_fr_379_is1
Clé Supprimée : [x64] HKLM\SOFTWARE\ShopperPro
Clé Supprimée : [x64] HKLM\SOFTWARE\FlashBeat
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Donnée Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll
Donnée Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PriceMeterLiveUpdate.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftwareUpdate.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
Donnée Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>
-\\ Internet Explorer v11.0.9600.17689
Paramètre Restauré : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Paramètre Restauré : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Paramètre Restauré : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Paramètre Restauré : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Paramètre Restauré : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v
[4xlmdvpw.default\prefs.js] - Ligne Supprimée : user_pref("browser.search.order.1", "default-search.net");
[4xlmdvpw.default\prefs.js] - Ligne Supprimée : user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C%22amazon.co.uk%22%2C%22a[...]
[4xlmdvpw.default\prefs.js] - Ligne Supprimée : user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__fifty_test_rules.value", "%7B%22DE%22%3A%7B%22ALL%22%3A%5B%22anastasiadate.com%22%2C%22op[...]
[4xlmdvpw.default\prefs.js] - Ligne Supprimée : user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D[...]
[4xlmdvpw.default\prefs.js] - Ligne Supprimée : user_pref("extensions.ataylorralstonhotmailcom64755.64755.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C%22amazon.co.uk%22%2C%22amazon.com%22%2C%22anthropologi[...]
[4xlmdvpw.default\prefs.js] - Ligne Supprimée : user_pref("extensions.ataylorralstonhotmailcom64755.64755.internaldb.__ICM_LITE__fifty_test_rules.value", "%7B%22DE%22%3A%7B%22ALL%22%3A%5B%22anastasiadate.com%22%2C%22optionweb.com%22%2C%22pctools.co[...]
-\\ Opera v0.0.0.0
AdwCleaner[R0].txt - [31293 octets] - [04/04/2015 22:34:19]
AdwCleaner[S0].txt - [28672 octets] - [04/04/2015 22:50:23]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [28733 octets] ##########
A+
# AdwCleaner v4.200 - Rapport créé le 04/04/2015 à 22:50:23
# Mis à jour le 29/03/2015 par Xplode
# Base de données : 2015-03-29.1 [Serveur]
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (x64)
# Nom d'utilisateur : Françoise - FRANÇOISE-HP
# Exécuté depuis : C:\Users\Françoise\Downloads\adwcleaner_4.200.exe
# Option : Nettoyer
- [ Services ] *****
Service Supprimé : CltMngSvc
[#] Service Supprimé : Gambali
[#] Service Supprimé : globalUpdate
[#] Service Supprimé : globalUpdatem
Service Supprimé : netfilter64
Service Supprimé : Orbiter
Service Supprimé : ServiceEverything
[#] Service Supprimé : pfnfd_1_10_0_9
[#] Service Supprimé : qrnfd_1_10_0_9
- [ Fichiers / Dossiers ] *****
Dossier Supprimé : C:\TVWizard
Dossier Supprimé : C:\HealthAlert
Dossier Supprimé : C:\ProgramData\Browser
Dossier Supprimé : C:\ProgramData\ParetoLogic
Dossier Supprimé : C:\ProgramData\PicRec
Dossier Supprimé : C:\ProgramData\PriceMeterLiveUpdate
Dossier Supprimé : C:\ProgramData\systemk
Dossier Supprimé : C:\ProgramData\WindowsMangerProtect
Dossier Supprimé : C:\ProgramData\WPM
Dossier Supprimé : C:\ProgramData\YTAHelper
Dossier Supprimé : C:\ProgramData\IHProtectUpDate
Dossier Supprimé : C:\ProgramData\FlashBeat
Dossier Supprimé : C:\ProgramData\CoolSaleCuouppoon
Dossier Supprimé : C:\ProgramData\dEalpeaak
Dossier Supprimé : C:\ProgramData\WOwCouponn
Dossier Supprimé : C:\ProgramData\6eb9994600007367
Dossier Supprimé : C:\ProgramData\a06c590c1f809607
Dossier Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flash Player Pro
Dossier Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverRestore
Dossier Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
Dossier Supprimé : C:\Program Files (x86)\AnyProtectEx
Dossier Supprimé : C:\Program Files (x86)\Boxore
Dossier Supprimé : C:\Program Files (x86)\Easy Speed Check
Dossier Supprimé : C:\Program Files (x86)\Flash Player Pro
Dossier Supprimé : C:\Program Files (x86)\globalUpdate
Dossier Supprimé : C:\Program Files (x86)\ParetoLogic
Dossier Supprimé : C:\Program Files (x86)\PC Speed Maximizer
Dossier Supprimé : C:\Program Files (x86)\PicRec
Dossier Supprimé : C:\Program Files (x86)\predm
Dossier Supprimé : C:\Program Files (x86)\Probit Software
Dossier Supprimé : C:\Program Files (x86)\SearchProtect
Dossier Supprimé : C:\Program Files (x86)\Settings Manager
Dossier Supprimé : C:\Program Files (x86)\Smart Driver Updater
Dossier Supprimé : C:\Program Files (x86)\WinZipper
Dossier Supprimé : C:\Program Files (x86)\DriverRestore
Dossier Supprimé : C:\Program Files (x86)\ORBTR
Dossier Supprimé : C:\Program Files (x86)\EZ Software Updater
Dossier Supprimé : C:\Program Files (x86)\XTab
Dossier Supprimé : C:\Program Files (x86)\igs
Dossier Supprimé : C:\Program Files (x86)\QuickRef_1.10.0.9
Dossier Supprimé : C:\Program Files (x86)\CoolSaleCuouppoon
Dossier Supprimé : C:\Program Files (x86)\dEalpeaak
Dossier Supprimé : C:\Program Files (x86)\WOwCouponn
Dossier Supprimé : C:\Program Files (x86)\gmsd_fr_373
Dossier Supprimé : C:\Program Files (x86)\gmsd_fr_379
Dossier Supprimé : C:\Program Files (x86)\Common Files\ParetoLogic
Dossier Supprimé : C:\Windows\Microsoft\sogr
Dossier Supprimé : C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Infigo
Dossier Supprimé : C:\Program Files\002
Dossier Supprimé : C:\Program Files\003
Dossier Supprimé : C:\Program Files\shopperz
Dossier Supprimé : C:\Users\Françoise\AppData\Local\Boxore
Dossier Supprimé : C:\Users\Françoise\AppData\Local\Genesis
Dossier Supprimé : C:\Users\Françoise\AppData\Local\globalUpdate
Dossier Supprimé : C:\Users\Françoise\AppData\Local\Mobogenie
Dossier Supprimé : C:\Users\Françoise\AppData\Local\SearchProtect
Dossier Supprimé : C:\Users\Françoise\AppData\Local\TVWizard
Dossier Supprimé : C:\Users\Françoise\AppData\Local\SmartWeb
Dossier Supprimé : C:\Users\Françoise\AppData\Local\Doctor_PC
Dossier Supprimé : C:\Users\Françoise\AppData\Local\Pro_PC_Cleaner
Dossier Supprimé : C:\Users\Françoise\AppData\Local\Microsoft\WinU
Dossier Supprimé : C:\Users\Françoise\AppData\Local\Binkiland
Dossier Supprimé : C:\Users\Françoise\AppData\Local\gmsd_fr_373
Dossier Supprimé : C:\Users\Françoise\AppData\Local\gmsd_fr_379
Dossier Supprimé : C:\Users\Françoise\AppData\LocalLow\iac
Dossier Supprimé : C:\Users\Françoise\AppData\LocalLow\IminentToolbar
Dossier Supprimé : C:\Users\Françoise\AppData\LocalLow\mystarttb
Dossier Supprimé : C:\Users\Françoise\AppData\LocalLow\SmartWeb
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\AnyProtectEx
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\DriverCure
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Gameo
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\istartsurf
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Nosibay
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\ParetoLogic
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Probit Software
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\qone8
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\sweet-page
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Systweak
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\webplayer
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\wp_update
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Advanced Cleaner Pro
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Infigo
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Company Name
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Binkiland
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\7r64_lvf@hcvkzbuyoi.com
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\jzju0h@uydys.org
Dossier Supprimé : C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\rbfm1xa@iyy-gzmh.edu
Fichier Supprimé : C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\{E77F341C-F32E-40AA-8829-AA785C7D9316}.xpi
Fichier Supprimé : C:\crossbrowse.lnk
Fichier Supprimé : C:\Windows\apppatch\apppatch64\vcldr64.dll
Fichier Supprimé : C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
Fichier Supprimé : C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb
Fichier Supprimé : C:\Windows\AppPatch\nbin\VC32Loader.dll
Fichier Supprimé : C:\Windows\efix.ini
Fichier Supprimé : C:\Windows\patsearch.bin
Fichier Supprimé : C:\Windows\Reimage.ini
Fichier Supprimé : C:\Windows\SysWOW64\Gambali.dll
Fichier Supprimé : C:\Windows\SysWOW64\GambaliOff.ini
Fichier Supprimé : C:\Users\FRANOI~1\AppData\Local\Temp\Uninstall.exe
Fichier Supprimé : C:\Windows\System32\Gambali64.dll
Fichier Supprimé : C:\Windows\System32\GambaliOff.ini
Fichier Supprimé : C:\Windows\System32\roboot64.exe
Fichier Supprimé : C:\Windows\System32\drivers\netfilter64.sys
Fichier Supprimé : C:\Windows\System32\drivers\qrnfd_1_10_0_9.sys
Fichier Supprimé : C:\Users\Françoise\daemonprocess.txt
Fichier Supprimé : C:\Users\Françoise\AppData\Roaming\aps.uninstall.scan.results
Fichier Supprimé : C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk
Fichier Supprimé : C:\Users\Françoise\Desktop\AnyProtect.lnk
Fichier Supprimé : C:\Users\Françoise\Desktop\eBay.lnk
Fichier Supprimé : C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\searchplugins\MyOnlineSearch.xml
Fichier Supprimé : C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\searchplugins\mysearchskms.xml
Fichier Supprimé : C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\user.js
- [ Tâches planifiées ] *****
Tâche Supprimée : APSnotifierPP1
Tâche Supprimée : APSnotifierPP2
Tâche Supprimée : APSnotifierPP3
Tâche Supprimée : Binkiland
Tâche Supprimée : DoctorPC_Start
Tâche Supprimée : globalUpdateUpdateTaskMachineCore
Tâche Supprimée : globalUpdateUpdateTaskMachineUA
Tâche Supprimée : InfiniteCrisis TW1
Tâche Supprimée : InfiniteCrisis TW2
Tâche Supprimée : LaunchSignup
Tâche Supprimée : Optimizer Pro Schedule
Tâche Supprimée : pricemeterdownloader
Tâche Supprimée : PriceMeterLiveUpdateUpdateTaskMachineCore
Tâche Supprimée : PriceMeterLiveUpdateUpdateTaskMachineUA
Tâche Supprimée : PriceMeterUpdater
Tâche Supprimée : ProPCCleaner_Start
Tâche Supprimée : SmartWeb Upgrade Trigger Task
Tâche Supprimée : TaskUserUpdate_wp
Tâche Supprimée : 7afd764a-e7cd-4246-be3e-541cc5aa9a66-10_user
- [ Raccourcis ] *****
- [ Registre ] *****
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Clé Supprimée : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Clé Supprimée : HKLM\SOFTWARE\Classes\speedupmypc
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Clé Supprimée : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Clé Supprimée : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Clé Supprimée : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Valeur Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [EasySpeedCheck]
Clé Supprimée : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm
Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SmartWeb]
Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [gmsd_fr_373]
Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [gmsd_fr_379]
Clé Supprimée : HKLM\SOFTWARE\69c797b1-4ba6-2a3b-d356-5d276df4c3ea
Clé Supprimée : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{126C78A0-36E7-4697-A3AB-32706144398B}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{00A154AE-6C33-4F1E-9057-242350540936}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{126C78A0-36E7-4697-A3AB-32706144398B}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{5B60D1C0-453A-485D-AE91-61FAC9203719}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Clé Supprimée : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{03771AEF-400D-4A13-B712-25878EC4A3F5}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Clé Supprimée : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Clé Supprimée : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Clé Supprimée : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Clé Supprimée : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}
Clé Supprimée : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Clé Supprimée : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Clé Supprimée : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CC865B26-C31D-4D23-B17B-96548EEF03F6}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{a0892e19-6051-4ae6-9a5f-91542a166b2b}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0b4d26f6-61a8-4463-99dd-5f2fe0400fa6}
Clé Supprimée : HKCU\Software\AnyProtect
Clé Supprimée : HKCU\Software\Boost
Clé Supprimée : HKCU\Software\BRS
Clé Supprimée : HKCU\Software\eSupport.com
Clé Supprimée : HKCU\Software\genesis
Clé Supprimée : HKCU\Software\GlobalUpdate
Clé Supprimée : HKCU\Software\Goobzo
Clé Supprimée : HKCU\Software\IM
Clé Supprimée : HKCU\Software\ImInstaller
Clé Supprimée : HKCU\Software\InstallCore
Clé Supprimée : HKCU\Software\Nosibay
Clé Supprimée : HKCU\Software\Optimizer Pro
Clé Supprimée : HKCU\Software\simplytech
Clé Supprimée : HKCU\Software\Store
Clé Supprimée : HKCU\Software\systweak
Clé Supprimée : HKCU\Software\Tutorials
Clé Supprimée : HKCU\Software\TutoTag
Clé Supprimée : HKCU\Software\Vittalia
Clé Supprimée : HKCU\Software\DriverRestore
Clé Supprimée : HKCU\Software\UpdateFiles
Clé Supprimée : HKCU\Software\Easy Speed Check
Clé Supprimée : HKCU\Software\Advanced Cleaner Pro
Clé Supprimée : HKCU\Software\gameo
Clé Supprimée : HKCU\Software\GAMESDESKTOP
Clé Supprimée : HKCU\Software\TNT2
Clé Supprimée : HKCU\Software\Super Optimizer
Clé Supprimée : HKCU\Software\ProPCCleanerLanguage
Clé Supprimée : HKCU\Software\ProPCCleanerConfig
Clé Supprimée : HKCU\Software\Binkiland Browser
Clé Supprimée : HKCU\Software\SearchProtectWS
Clé Supprimée : HKCU\Software\Kreapixel
Clé Supprimée : HKCU\Software\Crossbrowse
Clé Supprimée : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Clé Supprimée : HKCU\Software\AppDataLow\Software\BlockAndSurf
Clé Supprimée : HKCU\Software\AppDataLow\Software\Crossrider
Clé Supprimée : HKCU\Software\AppDataLow\Software\DynConIE
Clé Supprimée : HKCU\Software\AppDataLow\Software\SmartWeb
Clé Supprimée : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Clé Supprimée : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Clé Supprimée : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Clé Supprimée : HKLM\SOFTWARE\Boost
Clé Supprimée : HKLM\SOFTWARE\EZ Software Updater
Clé Supprimée : HKLM\SOFTWARE\GlobalUpdate
Clé Supprimée : HKLM\SOFTWARE\Goobzo
Clé Supprimée : HKLM\SOFTWARE\hdcode
Clé Supprimée : HKLM\SOFTWARE\ImInstaller
Clé Supprimée : HKLM\SOFTWARE\istartsurfSoftware
Clé Supprimée : HKLM\SOFTWARE\SearchProtect
Clé Supprimée : HKLM\SOFTWARE\SupDp
Clé Supprimée : HKLM\SOFTWARE\SupTab
Clé Supprimée : HKLM\SOFTWARE\sweet-pageSoftware
Clé Supprimée : HKLM\SOFTWARE\systweak
Clé Supprimée : HKLM\SOFTWARE\Tutorials
Clé Supprimée : HKLM\SOFTWARE\winzipersvc
Clé Supprimée : HKLM\SOFTWARE\SpeedBrowser
Clé Supprimée : HKLM\SOFTWARE\mystartsearchSoftware
Clé Supprimée : HKLM\SOFTWARE\ORBTR
Clé Supprimée : HKLM\SOFTWARE\GAMESDESKTOP
Clé Supprimée : HKLM\SOFTWARE\IHProtect
Clé Supprimée : HKLM\SOFTWARE\SPPDCOM
Clé Supprimée : HKLM\SOFTWARE\IGS
Clé Supprimée : HKLM\SOFTWARE\FlashBeat
Clé Supprimée : HKLM\SOFTWARE\QuickRef_1.10.0.9
Clé Supprimée : HKLM\SOFTWARE\Crossbrowse
Clé Supprimée : HKLM\SOFTWARE\doctor pc
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\WajIntEnhance
Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran.com
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1B8A71D1-31D4-EE6A-C32F-836E0BFFA6D3}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C60D3D4E-3B20-5AB3-7F2C-9C946AD4080F}
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AnyProtect
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SmartWeb
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBeat
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WajIntEnhance
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran.com
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gmsd_fr_379_is1
Clé Supprimée : [x64] HKLM\SOFTWARE\ShopperPro
Clé Supprimée : [x64] HKLM\SOFTWARE\FlashBeat
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Donnée Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll
Donnée Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Clé Supprimée : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PriceMeterLiveUpdate.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SoftwareUpdate.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
Donnée Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>
- [ Navigateurs ] *****
-\\ Internet Explorer v11.0.9600.17689
Paramètre Restauré : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Paramètre Restauré : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Paramètre Restauré : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Paramètre Restauré : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Paramètre Restauré : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v
[4xlmdvpw.default\prefs.js] - Ligne Supprimée : user_pref("browser.search.order.1", "default-search.net");
[4xlmdvpw.default\prefs.js] - Ligne Supprimée : user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C%22amazon.co.uk%22%2C%22a[...]
[4xlmdvpw.default\prefs.js] - Ligne Supprimée : user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__fifty_test_rules.value", "%7B%22DE%22%3A%7B%22ALL%22%3A%5B%22anastasiadate.com%22%2C%22op[...]
[4xlmdvpw.default\prefs.js] - Ligne Supprimée : user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D[...]
[4xlmdvpw.default\prefs.js] - Ligne Supprimée : user_pref("extensions.ataylorralstonhotmailcom64755.64755.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C%22amazon.co.uk%22%2C%22amazon.com%22%2C%22anthropologi[...]
[4xlmdvpw.default\prefs.js] - Ligne Supprimée : user_pref("extensions.ataylorralstonhotmailcom64755.64755.internaldb.__ICM_LITE__fifty_test_rules.value", "%7B%22DE%22%3A%7B%22ALL%22%3A%5B%22anastasiadate.com%22%2C%22optionweb.com%22%2C%22pctools.co[...]
-\\ Opera v0.0.0.0
AdwCleaner[R0].txt - [31293 octets] - [04/04/2015 22:34:19]
AdwCleaner[S0].txt - [28672 octets] - [04/04/2015 22:50:23]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [28733 octets] ##########
A+
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
ok, voici la suite :
Scan Malwarebytes (temps : environ 40min de scan):
==================================================
Télécharge et installe Malwarebyte : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
Mets le à jour puis lance un examen.
A la fin du scan, clic sur "Mettre tout en quarantaine" en bas à gauche.
Redémarre l'ordinateur si besoin.
Après redémarrage, relance Malwarebytes.
Vas chercher le rapport dans l'onglet Historique.
A gauche Journal des examens.
Doube-clic sur l'examen dans la liste.
Puis en bas Copier dans le presse papier
Vas sur http://pjjoint.malekal.com et en bas, clic droit / coller pour coller le rapport du scan Malwarebytes.
Clic sur envoyer.
Dans un nouveau message ici en réponse, donne le lien pjjoint afin de pouvoir consulter le rapport.
Scan Malwarebytes (temps : environ 40min de scan):
==================================================
Télécharge et installe Malwarebyte : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
Mets le à jour puis lance un examen.
A la fin du scan, clic sur "Mettre tout en quarantaine" en bas à gauche.
Redémarre l'ordinateur si besoin.
Après redémarrage, relance Malwarebytes.
Vas chercher le rapport dans l'onglet Historique.
A gauche Journal des examens.
Doube-clic sur l'examen dans la liste.
Puis en bas Copier dans le presse papier
Vas sur http://pjjoint.malekal.com et en bas, clic droit / coller pour coller le rapport du scan Malwarebytes.
Clic sur envoyer.
Dans un nouveau message ici en réponse, donne le lien pjjoint afin de pouvoir consulter le rapport.
Bonjour,
J'ai mis deux liens pour le journal de protection et pour le rapport
http://pjjoint.malekal.com/files.php?id=20150405_f15i9v7t8o5
http://pjjoint.malekal.com/files.php?id=20150405_p7l106f15y5
J'espère que tu vas arriver à en faire quelque chose car j'ai eu des difficultés à tous trouver.
A+ et encore merci pour ton aide.
J'ai mis deux liens pour le journal de protection et pour le rapport
http://pjjoint.malekal.com/files.php?id=20150405_f15i9v7t8o5
http://pjjoint.malekal.com/files.php?id=20150405_p7l106f15y5
J'espère que tu vas arriver à en faire quelque chose car j'ai eu des difficultés à tous trouver.
A+ et encore merci pour ton aide.
La navigation est polluée par des demandes de mise à jour d'adobe flash Player et des pages s'ouvrent de façon intempestives. Rien que pour t'écrire là c'est galère.
Je relance un scan FRST et je t'envoie le résultat.
Je relance un scan FRST et je t'envoie le résultat.
Voilà les rapports FRST
https://pjjoint.malekal.com/files.php?id=20150405_l511c13y15y5
https://pjjoint.malekal.com/files.php?id=20150405_b7p15y7u10p5
https://pjjoint.malekal.com/files.php?id=20150405_i12l6r7v7o11
Ca reste encore galère! Faut-il supprimer ce qui est mis en quarantaine dans Mbam ?
https://pjjoint.malekal.com/files.php?id=20150405_l511c13y15y5
https://pjjoint.malekal.com/files.php?id=20150405_b7p15y7u10p5
https://pjjoint.malekal.com/files.php?id=20150405_i12l6r7v7o11
Ca reste encore galère! Faut-il supprimer ce qui est mis en quarantaine dans Mbam ?
bon y a du boulot =)
Voici la correction à effectuer avec FRST.
Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix
Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
Copie/colle dedans ce qui suit :
HKLM-x32\...\Run: [gmsd_fr_340] => [X]
HKLM-x32\...\Run: [gmsd_fr_349] => [X]
HKLM-x32\...\Run: [gmsd_fr_362] => [X]
HKLM-x32\...\Run: [gmsd_fr_364] => C:\Program Files (x86)\gmsd_fr_364\gmsd_fr_364.exe [3983504 2015-03-30] ()
HKLM-x32\...\Run: [gmsd_fr_379] => C:\Program Files (x86)\gmsd_fr_379\gmsd_fr_379.exe [3984016 2015-04-04] ()
HKLM-x32\...\Run: [SmartWeb] => C:\Users\Françoise\AppData\Local\SmartWeb\SmartWebHelper.exe [270368 2015-02-17] (SoftBrain Technologies Ltd.)
HKLM-x32\...\RunOnce: [Ridigefekuke] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\FRANOI~1\AppData\Local\61BF73~1\Cuba.dat"
HKLM-x32\...\RunOnce: [upgmsd_fr_364.exe] => C:\Users\Françoise\AppData\Local\gmsd_fr_364\upgmsd_fr_364.exe [3308688 2015-03-30] ()
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro 3.75\OptProLauncher.exe [148008 2015-03-31] ()
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\...\MountPoints2: {a9835061-5c33-11e4-9a00-80c16e586cac} - G:\LaunchU3.exe
HKU\S-1-5-18\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_16_0_0_287_Plugin.exe -update plugin
AppInit_DLLs-x32: c:/progra~3/{4884a~1/192~1.1/rari.dll => "c:\progra~3\{4884a~1\192~1.1\rari.dll" File Not Found
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
Startup: C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk
ShortcutTarget: hqghumeaylnlf.lnk -> C:\ProgramData\{b24c03f5-2214-6cba-b24c-c03f52210fd4}\hqghumeaylnlf.exe (PC Utilities Software Limited)
Startup: C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk
ShortcutTarget: SmartWeb.lnk -> C:\Users\Françoise\AppData\Local\SmartWeb\SmartWebHelper.exe (SoftBrain Technologies Ltd.)
roxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:57266;https=127.0.0.1:57266
R2 542bb8ed; c:\Program Files (x86)\Optimizer Pro 3.75\OptProMon.dll [2292264 2015-04-04] ()
R2 cicifiso; C:\Users\Françoise\AppData\Roaming\32444335-1427214172-3535-4C39-80C16E586CAC\nsz8ACC.tmp [208384 2015-04-04] () [File not signed]
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158816 2015-03-16] (XTab system)
R2 toqukozi; C:\Users\Françoise\AppData\Roaming\32444335-1424508927-3535-4C39-80C16E586CAC\jnsxBEAE.tmp [90624 2015-02-21] () [File not signed]
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [493712 2015-04-04] (SysTool PasSame LIMITED)
R2 xuhejygu; C:\Users\Françoise\AppData\Roaming\32444335-1427214172-3535-4C39-80C16E586CAC\jnsu55B1.tmp [131584 2015-03-24] () [File not signed]
S2 FlashBeat; C:\ProgramData\FlashBeat\FlashBeat.exe [X]
R2 gusomybu; C:\Users\Françoise\AppData\Roaming\32444335-1424508927-3535-4C39-80C16E586CAC\nsr900.tmpfs [X]
S2 qrsvc_1.10.0.9; "C:\Program Files (x86)\QuickRef_1.10.0.9\Service\qrsvc.exe" [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
FF Extension: linkygemaldk - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\linky@gemal.dk [2014-08-31]
FF Extension: Settings Manager - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7} [2014-05-18]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\boost@boost.net.xpi [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\{8299d9bc-4fe2-4889-9adf-025a0769d461}.xpi [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\idmsq@idmsq.com [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\taylorralston@hotmail.com [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.com [Not Found]
2015-04-05 09:14 - 2015-04-05 09:19 - 00002836 _____ () C:\Windows\System32\Tasks\APSnotifierPP1
2015-04-05 09:14 - 2015-04-05 09:19 - 00002834 _____ () C:\Windows\System32\Tasks\APSnotifierPP3
2015-04-05 09:14 - 2015-04-05 09:19 - 00002834 _____ () C:\Windows\System32\Tasks\APSnotifierPP2
2015-04-05 09:14 - 2015-04-05 09:14 - 00001045 _____ () C:\Users\Françoise\Desktop\AnyProtect.lnk
2015-04-05 09:14 - 2015-04-05 09:14 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
2015-04-05 09:13 - 2015-04-05 11:27 - 00000000 ____D () C:\Program Files (x86)\AnyProtectEx
2015-04-05 09:13 - 2015-04-05 09:13 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsjC83D.tmp
2015-04-05 09:13 - 2015-04-05 09:13 - 00000000 __SHD () C:\Users\Françoise\AppData\Roaming\AnyProtectEx
2015-04-05 09:08 - 2015-04-05 11:27 - 00000000 ____D () C:\Users\Françoise\AppData\Local\SmartWeb
2015-04-05 09:08 - 2015-04-05 09:08 - 00004058 _____ () C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task
2015-04-05 09:07 - 2015-04-05 11:27 - 00000000 ____D () C:\Users\Françoise\AppData\Local\gmsd_fr_379
2015-04-05 09:07 - 2015-04-05 09:11 - 00000000 ____D () C:\Program Files (x86)\gmsd_fr_379
2015-04-04 23:44 - 2015-04-04 23:44 - 00000000 ____D () C:\Users\Françoise\SupTab
2015-04-04 23:29 - 2015-04-05 11:10 - 00000000 ____D () C:\Users\Françoise\AppData\Local\gmsd_fr_364
2015-04-04 23:29 - 2015-04-05 08:53 - 00003278 _____ () C:\Windows\System32\Tasks\Optimizer Pro Schedule
2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\Users\Françoise\Documents\Optimizer Pro
2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\Optimizer Pro
2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\Program Files (x86)\gmsd_fr_364
2015-04-04 23:28 - 2015-04-05 08:36 - 00000000 ____D () C:\ProgramData\{b24c03f5-2214-6cba-b24c-c03f52210fd4}
2015-04-04 23:28 - 2015-04-04 23:28 - 00001099 _____ () C:\Users\Françoise\Desktop\Optimizer Pro.lnk
2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro 3.75
2015-04-04 23:27 - 2015-04-05 11:05 - 00000000 ____D () C:\Program Files (x86)\XTab
2015-04-04 23:27 - 2015-04-04 23:27 - 00001101 _____ () C:\Users\Françoise\Desktop\Continue Live Installation.lnk
2015-04-04 23:27 - 2015-04-04 23:27 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2015-04-04 23:27 - 2015-04-04 23:27 - 00000000 ____D () C:\ProgramData\IHProtectUpDate
2015-04-04 23:26 - 2015-04-04 23:26 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\mystartsearch
2015-04-04 20:07 - 2015-04-04 20:07 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl19A7.tmp
2015-04-04 20:06 - 2015-04-05 11:40 - 00026874 _____ () C:\Users\Françoise\Desktop\FRST.txt
2015-04-04 20:06 - 2015-04-04 20:06 - 00000306 _____ () C:\Windows\Tasks\avaavaxvyy.job
2015-04-04 20:05 - 2015-04-05 11:39 - 00000000 ____D () C:\FRST
2015-04-04 20:05 - 2015-04-04 20:05 - 00000000 ____D () C:\Users\Françoise\AppData\Local\avaavaxvyy
2015-04-04 20:01 - 2015-04-04 20:01 - 02095616 _____ (Farbar) C:\Users\Françoise\Desktop\FRST64.exe
2015-04-04 19:02 - 2015-04-04 19:02 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsoEDD6.tmp
2015-04-04 18:59 - 2015-04-04 18:59 - 00000000 ____D () C:\Users\Françoise\AppData\Local\Software
2015-04-04 18:58 - 2015-04-04 18:58 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsxDBAD.tmp
2015-04-04 18:24 - 2015-04-04 23:26 - 00001615 _____ () C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-04 18:24 - 2015-04-04 18:24 - 00000300 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{F3D00496-1512-4FEF-A011-C2925A21559B}.job
2015-04-04 18:24 - 2015-04-04 18:24 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-04 16:27 - 2015-04-04 16:27 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsgEBB7.tmp
2015-04-04 06:55 - 2015-04-04 06:55 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsbFDBE.tmp
2015-04-04 06:54 - 2015-04-04 06:54 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl570A.tmp
2015-04-04 06:52 - 2015-04-04 06:54 - 01950208 _____ () C:\Users\Françoise\AppData\Roaming\GWEXI.exe
2015-04-04 06:52 - 2015-04-04 06:54 - 00001352 _____ () C:\Windows\Tasks\GWEXI.job
2015-04-03 09:32 - 2015-04-03 09:32 - 00000000 ___HD () C:\Users\Françoise\AppData\Local\61bf73677f83230a
2015-04-02 18:09 - 2015-04-02 18:09 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsdFDF0.tmp
2015-03-31 12:01 - 2015-04-05 03:42 - 00000000 ____D () C:\Program Files (x86)\Mountain Bike
2015-03-31 05:19 - 2015-03-31 05:19 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsiDF85.tmp
2015-03-30 10:33 - 2015-03-30 10:33 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsm5819.tmp
2015-03-30 07:23 - 2015-04-05 11:10 - 00000348 _____ () C:\Windows\Tasks\HPCeeScheduleForFrançoise.job
2015-03-30 07:17 - 2015-03-30 07:17 - 00000000 _____ () C:\Windows\SysWOW64\sho148F.tmp
2015-03-29 12:11 - 2015-03-29 12:11 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nso16B3.tmp
2015-03-29 11:57 - 2015-03-29 11:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\1 Media Player
2015-03-29 11:57 - 2015-03-29 11:57 - 00000000 ____D () C:\Program Files (x86)\1 Media Player
2015-03-29 07:38 - 2015-03-29 07:39 - 00914436 _____ () C:\Users\Françoise\Downloads\widget-1-6.zip
2015-03-28 16:36 - 2015-03-28 16:35 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsn2300.tmp
2015-03-28 16:34 - 2015-04-05 03:43 - 00000000 ____D () C:\Program Files (x86)\GoHDV28.03
2015-03-28 16:34 - 2015-03-28 16:34 - 01971200 _____ () C:\Users\Françoise\AppData\Roaming\FDEDZBML.exe
2015-03-28 16:34 - 2015-03-28 16:34 - 00001702 _____ () C:\Windows\Tasks\FDEDZBML.job
2015-03-27 17:05 - 2015-03-27 17:05 - 02250712 _____ (Company Name) C:\Users\Françoise\Downloads\adsl-tv-fm_setup.exe
2015-03-27 10:46 - 2015-03-27 10:46 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsnC48.tmp
2015-03-27 07:30 - 2015-03-27 07:30 - 00003176 _____ () C:\Windows\System32\Tasks\{29DAE379-E7E9-4211-98F1-3C0DF9E21230}
2015-03-26 21:14 - 2015-03-26 21:14 - 00005542 _____ () C:\Users\Françoise\AppData\Roaming\GWEXI
2015-03-26 21:14 - 2015-03-26 21:14 - 00005542 _____ () C:\Users\Françoise\AppData\Roaming\FDEDZBML
2015-03-26 20:50 - 2015-03-26 20:50 - 00000000 ____D () C:\ZombieNews
2015-03-26 20:43 - 2015-03-26 20:43 - 01940992 _____ () C:\Users\Françoise\AppData\Roaming\THULJOON.exe
2015-03-26 20:43 - 2015-03-26 20:43 - 00001702 _____ () C:\Windows\Tasks\THULJOON.job
2015-03-26 20:42 - 2015-03-26 20:42 - 00000000 ____D () C:\Users\Public\Documents\YTAHelper
2015-03-26 20:40 - 2015-03-26 20:40 - 00000000 ____D () C:\Users\Françoise\AppData\Local\CrashRpt
2015-03-26 20:39 - 2015-03-26 20:39 - 01978840 _____ () C:\Users\Françoise\AppData\Roaming\PWKN.exe
2015-03-26 20:39 - 2015-03-26 20:39 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsuC72D.tmp
2015-03-26 20:39 - 2015-03-26 20:39 - 00001350 _____ () C:\Windows\Tasks\PWKN.job
2015-03-26 20:36 - 2015-03-26 20:36 - 01940992 _____ () C:\Users\Françoise\AppData\Roaming\TJYHKE.exe
2015-03-26 20:36 - 2015-03-26 20:36 - 00001354 _____ () C:\Windows\Tasks\TJYHKE.job
2015-03-26 08:24 - 2015-03-26 08:24 - 00000000 _____ () C:\Users\Françoise\AppData\Local\.w852.db
2015-03-25 08:52 - 2015-03-25 08:52 - 00001103 _____ () C:\Users\Françoise\Downloads\Download-setup.website
2015-03-24 18:38 - 2015-03-24 18:38 - 00001700 _____ () C:\Windows\Tasks\LQNCBDR.job
2015-03-24 18:37 - 2015-03-24 18:37 - 01933824 _____ () C:\Users\Françoise\AppData\Roaming\LQNCBDR.exe
2015-03-24 18:35 - 2015-04-05 03:50 - 00000000 ____D () C:\Users\Françoise\AppData\Local\avaavxvyex
2015-03-24 18:27 - 2015-04-05 11:27 - 00000000 ____D () C:\Users\Françoise\AppData\Local\32444335-1427218036-3535-4C39-80C16E586CAC
2015-03-24 18:26 - 2015-03-24 18:26 - 00003582 _____ () C:\Windows\System32\Tasks\OKKFODDR
2015-03-24 18:26 - 2015-03-24 18:26 - 00001702 _____ () C:\Windows\Tasks\OKPPBAAR.job
2015-03-24 18:26 - 2015-03-24 18:26 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webTinstMKTN_01009.Wdf
2015-03-24 18:26 - 2015-03-24 18:25 - 01933824 _____ () C:\Users\Françoise\AppData\Roaming\OKPPBAAR.exe
2015-03-24 18:25 - 2015-04-05 11:26 - 00000000 ____D () C:\ProgramData\e551e40cdd5e4104afe48d92c795a590
2015-03-24 18:25 - 2015-03-24 18:25 - 00000000 ____D () C:\ProgramData\7fbb4485eae14230b10d76d5ce7f1c83
2015-03-24 18:24 - 2015-03-24 18:24 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\WebplayerRemote
2015-03-24 18:22 - 2015-04-05 10:35 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\32444335-1427214172-3535-4C39-80C16E586CAC
2015-03-24 18:20 - 2015-04-04 18:22 - 00000000 ____D () C:\Program Files (x86)\CloudScout Parental Control
2015-03-24 18:19 - 2015-03-24 18:19 - 00000000 ____D () C:\d05e7453-6a9e-4756-b897-37340347d5ca
2015-03-23 18:55 - 2015-04-04 15:42 - 00000978 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-03-23 18:55 - 2015-04-04 14:34 - 00000982 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-04-04 15:55 - 2015-03-02 09:55 - 00000306 _____ () C:\Windows\Tasks\Binkiland.job
2015-04-04 15:40 - 2015-01-19 11:23 - 00000000 ____D () C:\Users\Françoise\AppData\Everything
2015-04-04 12:10 - 2014-04-07 20:04 - 00000451 _____ () C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Yahoo!.website
2015-04-05 09:59 - 2014-05-05 06:27 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2015-03-26 21:14 - 2015-03-26 21:14 - 0005542 _____ () C:\Users\Françoise\AppData\Roaming\FDEDZBML
2015-03-28 16:34 - 2015-03-28 16:34 - 1971200 _____ () C:\Users\Françoise\AppData\Roaming\FDEDZBML.exe
2015-03-26 21:14 - 2015-03-26 21:14 - 0005542 _____ () C:\Users\Françoise\AppData\Roaming\GWEXI
2015-04-04 06:52 - 2015-04-04 06:54 - 1950208 _____ () C:\Users\Françoise\AppData\Roaming\GWEXI.exe
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\Françoise\AppData\Roaming\LQNCBDR
2015-03-24 18:37 - 2015-03-24 18:37 - 1933824 _____ () C:\Users\Françoise\AppData\Roaming\LQNCBDR.exe
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\Françoise\AppData\Roaming\OKPPBAAR
2015-03-24 18:26 - 2015-03-24 18:25 - 1933824 _____ () C:\Users\Françoise\AppData\Roaming\OKPPBAAR.exe
2014-09-01 10:18 - 2014-09-01 10:18 - 0001248 _____ () C:\Users\Françoise\AppData\Roaming\ONLLP
2015-01-25 18:12 - 2015-01-25 18:12 - 0001248 _____ () C:\Users\Françoise\AppData\Roaming\PWKN
2015-03-26 20:39 - 2015-03-26 20:39 - 1978840 _____ () C:\Users\Françoise\AppData\Roaming\PWKN.exe
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\Françoise\AppData\Roaming\THULJOON
2015-03-26 20:43 - 2015-03-26 20:43 - 1940992 _____ () C:\Users\Françoise\AppData\Roaming\THULJOON.exe
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\Françoise\AppData\Roaming\TJYHKE
2015-03-26 20:36 - 2015-03-26 20:36 - 1940992 _____ () C:\Users\Françoise\AppData\Roaming\TJYHKE.exe
2014-09-01 10:18 - 2014-09-01 10:18 - 0002086 _____ () C:\Users\Françoise\AppData\Roaming\UFQUWS
2014-12-17 12:12 - 2014-12-17 12:12 - 0022528 _____ () C:\Users\Françoise\AppData\Local\dsisetup13768332.exe
2015-02-23 12:38 - 2015-02-23 12:38 - 0613057 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsb2586.tmp
2015-04-04 06:55 - 2015-04-04 06:55 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsbFDBE.tmp
2015-04-02 18:09 - 2015-04-02 18:09 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsdFDF0.tmp
2015-04-04 16:27 - 2015-04-04 16:27 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsgEBB7.tmp
2014-05-09 18:31 - 2014-05-09 18:31 - 0301488 _____ (VuuPC Limited) C:\Users\Françoise\AppData\Local\nsi1680.tmp
2015-03-31 05:19 - 2015-03-31 05:19 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsiDF85.tmp
2015-04-05 09:13 - 2015-04-05 09:13 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsjC83D.tmp
2015-04-04 20:07 - 2015-04-04 20:07 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl19A7.tmp
2015-04-04 06:54 - 2015-04-04 06:54 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl570A.tmp
2015-02-21 10:49 - 2015-02-21 10:49 - 0613057 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl76E0.tmp
2015-03-30 10:33 - 2015-03-30 10:33 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsm5819.tmp
2015-03-28 16:36 - 2015-03-28 16:35 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsn2300.tmp
2015-03-27 10:46 - 2015-03-27 10:46 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsnC48.tmp
2015-03-29 12:11 - 2015-03-29 12:11 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nso16B3.tmp
2015-04-04 19:02 - 2015-04-04 19:02 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsoEDD6.tmp
2015-03-26 20:39 - 2015-03-26 20:39 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsuC72D.tmp
2015-04-04 18:58 - 2015-04-04 18:58 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsxDBAD.tmp
2014-11-14 08:12 - 2014-11-14 08:12 - 0301608 _____ (VuuPC Limited) C:\Users\Françoise\AppData\Local\nsy3999.tmp
2015-04-04 15:14 - 2015-03-01 15:52 - 0196504 _____ () C:\Program Files (x86)\9tres.dll
2015-04-04 15:14 - 2015-03-01 15:52 - 1037896 _____ () C:\Program Files (x86)\9tUninstall Internet Speed Tracker.dll
Task: {0C399515-1567-4D57-81CD-079D99FFF752} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {12FFAF24-CD9C-44A8-87F3-40B7BD32B842} - System32\Tasks\t4h2IDlcVS2y0Sr => C:\Users\Françoise\AppData\Roaming\jDuSLEf\6O1gHkb.exe
Task: {26E4C186-E388-4729-B0DC-40672FC139FB} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {2A377C54-9448-48C7-81BC-4F827718F323} - System32\Tasks\{0072C348-C0F5-4690-B9C5-C8B850EAAA95} => pcalua.exe -a C:\Users\Françoise\AppData\Roaming\sweet-page\UninstallManager.exe -c -ptid=cor
Task: {2A83656A-D193-4CDE-AFD1-3D0F5462B76A} - System32\Tasks\S7qLnZDxEjVnWif => C:\Users\Françoise\AppData\Roaming\FXOoNoy\eSAjdhI.exe [2015-02-27] ( )
Task: {2F74EA80-3F09-42F5-BB56-FD6D23201531} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {70D31263-C8AA-4F72-94CD-B847C475C5B0} - \8c6736a2-0446-4148-8f02-ca63eff37ec5-12 No Task File <==== ATTENTION
Task: {70EB7038-801D-4629-B59A-F2B52526ACD8} - System32\Tasks\{1393E89C-3D33-423C-BECB-D5548128FBC0} => pcalua.exe -a C:\Users\Françoise\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=adks <==== ATTENTION
Task: {7904E1AC-513E-4EB8-A318-65389D155BFD} - System32\Tasks\{E3E303C7-214A-4246-8966-F0426841A603} => Iexplore.exe http://ui.skype.com/ui/0/5.6.0.110.161/fr/abandoninstall?page=tsDownload&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled
Task: {8255801E-C819-4A83-A3BD-006338DEBEF6} - System32\Tasks\ULNtEsDPMKLzji9 => C:\Users\Françoise\AppData\Roaming\Cpap4wF\gn5Vm4r.exe
Task: {828CA497-D5EC-40F1-82B1-D94654F80D64} - System32\Tasks\SmartWeb Upgrade Trigger Task => C:\Users\Françoise\AppData\Local\SmartWeb\SmartWebHelper.exe [2015-02-17] (SoftBrain Technologies Ltd.) <==== ATTENTION
Task: {89431725-61A5-43B7-B149-4F68602D645C} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {8B7A841B-A394-44EA-A832-C8834484C0C3} - \8c6736a2-0446-4148-8f02-ca63eff37ec5-1-7 No Task File <==== ATTENTION
Task: {8CCE1C4E-E6A6-4004-B556-526E9C1DD61F} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files (x86)\Optimizer Pro 3.75\OptProLauncher.exe [2015-03-31] () <==== ATTENTION
Task: {924D639B-824C-4387-85D8-6B8F305DD4CD} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {94907B4A-CFE9-4508-B069-BDF1D85BEE81} - System32\Tasks\WIN-statsAdmin => C:\Users\Françoise\AppData\Local\Microsoft\WinU\~pqrhxft.exe <==== ATTENTION
Task: {A269C044-F854-4A64-A9C0-E84F64848B15} - System32\Tasks\{9687AFBA-FA57-48A3-90A8-3D61C414676A} => pcalua.exe -a C:\Users\Françoise\AppData\Roaming\qone8\UninstallManager.exe -c -ptid=adks
Task: {A832BAFF-4526-4A32-A841-37226B978D64} - System32\Tasks\{29DAE379-E7E9-4211-98F1-3C0DF9E21230} => pcalua.exe -a C:\Users\Françoise\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=smt
Task: {AE872F99-D435-474D-B58A-D4D2145EF8A9} - System32\Tasks\WIN-statsSystem => C:\Users\Françoise\AppData\Local\Microsoft\WinU\~frodbro.exe
Task: {B4F88351-D346-47F7-BF79-FFEA82521039} - System32\Tasks\9XGQKw3LInouXt0 => C:\Users\Françoise\AppData\Roaming\xmfTvyu\yUAoRwK.exe [2015-02-24] ( )
Task: {C2AF11FA-199C-49F3-8234-A42D3EF9F64A} - System32\Tasks\{1ED12CDA-49C0-49C3-876E-45DFAE76E072} => Firefox.exe
Task: {C3A564F3-F565-444F-B9B9-2C7BE983C80C} - System32\Tasks\WIN-GGfIfEGCfEGbGffIfCfEGC => C:\Users\Françoise\AppData\Roaming\~lbehxzl.exe
Task: {CE821C2E-F472-4C86-B298-9539C29181B5} - System32\Tasks\OKKFODDR => C:\ProgramData\e551e40cdd5e4104afe48d92c795a590\e551e40cdd5e4104afe48d92c795a590.exe
Task: {E5FBFE04-9BCE-47A6-AB45-41896307775D} - System32\Tasks\{6C6A1B19-AC17-40B1-81FA-F846708DC1B4} => Iexplore.exe http://ui.skype.com/ui/0/5.6.0.110.161/fr/abandoninstall?page=tsDownload&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled
Task: {F08FCB6F-1C7C-4618-897D-DCA0C185FF9C} - System32\Tasks\{A9DA2D5F-CB04-4000-BA22-B132226837FD} => Iexplore.exe http://ui.skype.com/ui/0/5.6.0.110.161/fr/abandoninstall?page=tsDownload&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled
Task: {F486969F-6FE3-4F2B-9DE6-EF16AAA97E54} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-04] (Google Inc.)
Task: {F9283F80-A3F8-43C6-BE94-75A3471EFCC1} - \8c6736a2-0446-4148-8f02-ca63eff37ec5-1-6 No Task File <==== ATTENTION
Task: {FAEBBC22-5575-45A7-B295-A53013F7C389} - \8c6736a2-0446-4148-8f02-ca63eff37ec5-5 No Task File <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\avaavaxvyy.job => C:\Users\Françoise\AppData\Local\avaavaxvyy\avaavaxvyy.exe
Task: C:\Windows\Tasks\Binkiland.job => C:\Users\FRANOI~1\AppData\Roaming\BINKIL~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\FDEDZBML.job => C:\Users\Franýÿoise\AppData\Roaming\FDEDZBML.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GWEXI.job => C:\Users\Franýÿoise\AppData\Roaming\GWEXI.exe <==== ATTENTION
Task: C:\Windows\Tasks\LQNCBDR.job => C:\Users\Franýÿoise\AppData\Roaming\LQNCBDR.exe <==== ATTENTION
Task: C:\Windows\Tasks\OKPPBAAR.job => C:\Users\Franýÿoise\AppData\Roaming\OKPPBAAR.exe <==== ATTENTION
Task: C:\Windows\Tasks\ONLLP.job => C:\Users\Franýÿoise\AppData\Roaming\ONLLP.exe <==== ATTENTION
Task: C:\Windows\Tasks\PWKN.job => C:\Users\Franýÿoise\AppData\Roaming\PWKN.exe <==== ATTENTION
Task: C:\Windows\Tasks\THULJOON.job => C:\Users\Franýÿoise\AppData\Roaming\THULJOON.exe <==== ATTENTION
Task: C:\Windows\Tasks\TJYHKE.job => C:\Users\Franýÿoise\AppData\Roaming\TJYHKE.exe <==== ATTENTION
Task: C:\Windows\Tasks\UFQUWS.job => C:\Users\Franýÿoise\AppData\Roaming\UFQUWS.exe <==== ATTENTION
Task: C:\Windows\Tasks\User_Feed_Synchronization-{F3D00496-1512-4FEF-A011-C2925A21559B}.job => C:\Windows\system32\msfeedssync.exe
Une fois, le texte coller dans le bloc-note.
Menu Fichier puis Enregistrer sous.
A gauche, place toi sur le bureau.
Dans le champs en bas, nom du fichier mets : fixlist.txt
Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.
Relance FRST et clic sur le bouton Fix
Selon comment un redémarrage est nécessaire (pas obligatoire).
Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.
Redémarre l'ordinateur
Supprime les PUM.DNS avec RogueKiller en suivant ce tutorial : https://forum.malekal.com/viewtopic.php?t=48312&start=
Donne le rapport de suppression de RogueKiller.
puis :
puis réinitialise tes navigateurs:
==================================
Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :
Voici la correction à effectuer avec FRST.
Tu peux t'inspirer de cette note explicative avec des captures d'écran pour t'aider: https://www.malekal.com/tutoriel-farbar-recovery-scan-tool-frst/#fix
Ouvre le bloc-notes : Touche Windows + R, dans le champs executer, tape notepad et OK.
Copie/colle dedans ce qui suit :
HKLM-x32\...\Run: [gmsd_fr_340] => [X]
HKLM-x32\...\Run: [gmsd_fr_349] => [X]
HKLM-x32\...\Run: [gmsd_fr_362] => [X]
HKLM-x32\...\Run: [gmsd_fr_364] => C:\Program Files (x86)\gmsd_fr_364\gmsd_fr_364.exe [3983504 2015-03-30] ()
HKLM-x32\...\Run: [gmsd_fr_379] => C:\Program Files (x86)\gmsd_fr_379\gmsd_fr_379.exe [3984016 2015-04-04] ()
HKLM-x32\...\Run: [SmartWeb] => C:\Users\Françoise\AppData\Local\SmartWeb\SmartWebHelper.exe [270368 2015-02-17] (SoftBrain Technologies Ltd.)
HKLM-x32\...\RunOnce: [Ridigefekuke] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\FRANOI~1\AppData\Local\61BF73~1\Cuba.dat"
HKLM-x32\...\RunOnce: [upgmsd_fr_364.exe] => C:\Users\Françoise\AppData\Local\gmsd_fr_364\upgmsd_fr_364.exe [3308688 2015-03-30] ()
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro 3.75\OptProLauncher.exe [148008 2015-03-31] ()
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\...\MountPoints2: {a9835061-5c33-11e4-9a00-80c16e586cac} - G:\LaunchU3.exe
HKU\S-1-5-18\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_16_0_0_287_Plugin.exe -update plugin
AppInit_DLLs-x32: c:/progra~3/{4884a~1/192~1.1/rari.dll => "c:\progra~3\{4884a~1\192~1.1\rari.dll" File Not Found
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
Startup: C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk
ShortcutTarget: hqghumeaylnlf.lnk -> C:\ProgramData\{b24c03f5-2214-6cba-b24c-c03f52210fd4}\hqghumeaylnlf.exe (PC Utilities Software Limited)
Startup: C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk
ShortcutTarget: SmartWeb.lnk -> C:\Users\Françoise\AppData\Local\SmartWeb\SmartWebHelper.exe (SoftBrain Technologies Ltd.)
roxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:57266;https=127.0.0.1:57266
R2 542bb8ed; c:\Program Files (x86)\Optimizer Pro 3.75\OptProMon.dll [2292264 2015-04-04] ()
R2 cicifiso; C:\Users\Françoise\AppData\Roaming\32444335-1427214172-3535-4C39-80C16E586CAC\nsz8ACC.tmp [208384 2015-04-04] () [File not signed]
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158816 2015-03-16] (XTab system)
R2 toqukozi; C:\Users\Françoise\AppData\Roaming\32444335-1424508927-3535-4C39-80C16E586CAC\jnsxBEAE.tmp [90624 2015-02-21] () [File not signed]
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [493712 2015-04-04] (SysTool PasSame LIMITED)
R2 xuhejygu; C:\Users\Françoise\AppData\Roaming\32444335-1427214172-3535-4C39-80C16E586CAC\jnsu55B1.tmp [131584 2015-03-24] () [File not signed]
S2 FlashBeat; C:\ProgramData\FlashBeat\FlashBeat.exe [X]
R2 gusomybu; C:\Users\Françoise\AppData\Roaming\32444335-1424508927-3535-4C39-80C16E586CAC\nsr900.tmpfs [X]
S2 qrsvc_1.10.0.9; "C:\Program Files (x86)\QuickRef_1.10.0.9\Service\qrsvc.exe" [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
FF Extension: linkygemaldk - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\linky@gemal.dk [2014-08-31]
FF Extension: Settings Manager - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7} [2014-05-18]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\boost@boost.net.xpi [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\{8299d9bc-4fe2-4889-9adf-025a0769d461}.xpi [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\idmsq@idmsq.com [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\taylorralston@hotmail.com [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.com [Not Found]
2015-04-05 09:14 - 2015-04-05 09:19 - 00002836 _____ () C:\Windows\System32\Tasks\APSnotifierPP1
2015-04-05 09:14 - 2015-04-05 09:19 - 00002834 _____ () C:\Windows\System32\Tasks\APSnotifierPP3
2015-04-05 09:14 - 2015-04-05 09:19 - 00002834 _____ () C:\Windows\System32\Tasks\APSnotifierPP2
2015-04-05 09:14 - 2015-04-05 09:14 - 00001045 _____ () C:\Users\Françoise\Desktop\AnyProtect.lnk
2015-04-05 09:14 - 2015-04-05 09:14 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
2015-04-05 09:13 - 2015-04-05 11:27 - 00000000 ____D () C:\Program Files (x86)\AnyProtectEx
2015-04-05 09:13 - 2015-04-05 09:13 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsjC83D.tmp
2015-04-05 09:13 - 2015-04-05 09:13 - 00000000 __SHD () C:\Users\Françoise\AppData\Roaming\AnyProtectEx
2015-04-05 09:08 - 2015-04-05 11:27 - 00000000 ____D () C:\Users\Françoise\AppData\Local\SmartWeb
2015-04-05 09:08 - 2015-04-05 09:08 - 00004058 _____ () C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task
2015-04-05 09:07 - 2015-04-05 11:27 - 00000000 ____D () C:\Users\Françoise\AppData\Local\gmsd_fr_379
2015-04-05 09:07 - 2015-04-05 09:11 - 00000000 ____D () C:\Program Files (x86)\gmsd_fr_379
2015-04-04 23:44 - 2015-04-04 23:44 - 00000000 ____D () C:\Users\Françoise\SupTab
2015-04-04 23:29 - 2015-04-05 11:10 - 00000000 ____D () C:\Users\Françoise\AppData\Local\gmsd_fr_364
2015-04-04 23:29 - 2015-04-05 08:53 - 00003278 _____ () C:\Windows\System32\Tasks\Optimizer Pro Schedule
2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\Users\Françoise\Documents\Optimizer Pro
2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\Optimizer Pro
2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\Program Files (x86)\gmsd_fr_364
2015-04-04 23:28 - 2015-04-05 08:36 - 00000000 ____D () C:\ProgramData\{b24c03f5-2214-6cba-b24c-c03f52210fd4}
2015-04-04 23:28 - 2015-04-04 23:28 - 00001099 _____ () C:\Users\Françoise\Desktop\Optimizer Pro.lnk
2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro 3.75
2015-04-04 23:27 - 2015-04-05 11:05 - 00000000 ____D () C:\Program Files (x86)\XTab
2015-04-04 23:27 - 2015-04-04 23:27 - 00001101 _____ () C:\Users\Françoise\Desktop\Continue Live Installation.lnk
2015-04-04 23:27 - 2015-04-04 23:27 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2015-04-04 23:27 - 2015-04-04 23:27 - 00000000 ____D () C:\ProgramData\IHProtectUpDate
2015-04-04 23:26 - 2015-04-04 23:26 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\mystartsearch
2015-04-04 20:07 - 2015-04-04 20:07 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl19A7.tmp
2015-04-04 20:06 - 2015-04-05 11:40 - 00026874 _____ () C:\Users\Françoise\Desktop\FRST.txt
2015-04-04 20:06 - 2015-04-04 20:06 - 00000306 _____ () C:\Windows\Tasks\avaavaxvyy.job
2015-04-04 20:05 - 2015-04-05 11:39 - 00000000 ____D () C:\FRST
2015-04-04 20:05 - 2015-04-04 20:05 - 00000000 ____D () C:\Users\Françoise\AppData\Local\avaavaxvyy
2015-04-04 20:01 - 2015-04-04 20:01 - 02095616 _____ (Farbar) C:\Users\Françoise\Desktop\FRST64.exe
2015-04-04 19:02 - 2015-04-04 19:02 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsoEDD6.tmp
2015-04-04 18:59 - 2015-04-04 18:59 - 00000000 ____D () C:\Users\Françoise\AppData\Local\Software
2015-04-04 18:58 - 2015-04-04 18:58 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsxDBAD.tmp
2015-04-04 18:24 - 2015-04-04 23:26 - 00001615 _____ () C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-04 18:24 - 2015-04-04 18:24 - 00000300 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{F3D00496-1512-4FEF-A011-C2925A21559B}.job
2015-04-04 18:24 - 2015-04-04 18:24 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-04 16:27 - 2015-04-04 16:27 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsgEBB7.tmp
2015-04-04 06:55 - 2015-04-04 06:55 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsbFDBE.tmp
2015-04-04 06:54 - 2015-04-04 06:54 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl570A.tmp
2015-04-04 06:52 - 2015-04-04 06:54 - 01950208 _____ () C:\Users\Françoise\AppData\Roaming\GWEXI.exe
2015-04-04 06:52 - 2015-04-04 06:54 - 00001352 _____ () C:\Windows\Tasks\GWEXI.job
2015-04-03 09:32 - 2015-04-03 09:32 - 00000000 ___HD () C:\Users\Françoise\AppData\Local\61bf73677f83230a
2015-04-02 18:09 - 2015-04-02 18:09 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsdFDF0.tmp
2015-03-31 12:01 - 2015-04-05 03:42 - 00000000 ____D () C:\Program Files (x86)\Mountain Bike
2015-03-31 05:19 - 2015-03-31 05:19 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsiDF85.tmp
2015-03-30 10:33 - 2015-03-30 10:33 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsm5819.tmp
2015-03-30 07:23 - 2015-04-05 11:10 - 00000348 _____ () C:\Windows\Tasks\HPCeeScheduleForFrançoise.job
2015-03-30 07:17 - 2015-03-30 07:17 - 00000000 _____ () C:\Windows\SysWOW64\sho148F.tmp
2015-03-29 12:11 - 2015-03-29 12:11 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nso16B3.tmp
2015-03-29 11:57 - 2015-03-29 11:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\1 Media Player
2015-03-29 11:57 - 2015-03-29 11:57 - 00000000 ____D () C:\Program Files (x86)\1 Media Player
2015-03-29 07:38 - 2015-03-29 07:39 - 00914436 _____ () C:\Users\Françoise\Downloads\widget-1-6.zip
2015-03-28 16:36 - 2015-03-28 16:35 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsn2300.tmp
2015-03-28 16:34 - 2015-04-05 03:43 - 00000000 ____D () C:\Program Files (x86)\GoHDV28.03
2015-03-28 16:34 - 2015-03-28 16:34 - 01971200 _____ () C:\Users\Françoise\AppData\Roaming\FDEDZBML.exe
2015-03-28 16:34 - 2015-03-28 16:34 - 00001702 _____ () C:\Windows\Tasks\FDEDZBML.job
2015-03-27 17:05 - 2015-03-27 17:05 - 02250712 _____ (Company Name) C:\Users\Françoise\Downloads\adsl-tv-fm_setup.exe
2015-03-27 10:46 - 2015-03-27 10:46 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsnC48.tmp
2015-03-27 07:30 - 2015-03-27 07:30 - 00003176 _____ () C:\Windows\System32\Tasks\{29DAE379-E7E9-4211-98F1-3C0DF9E21230}
2015-03-26 21:14 - 2015-03-26 21:14 - 00005542 _____ () C:\Users\Françoise\AppData\Roaming\GWEXI
2015-03-26 21:14 - 2015-03-26 21:14 - 00005542 _____ () C:\Users\Françoise\AppData\Roaming\FDEDZBML
2015-03-26 20:50 - 2015-03-26 20:50 - 00000000 ____D () C:\ZombieNews
2015-03-26 20:43 - 2015-03-26 20:43 - 01940992 _____ () C:\Users\Françoise\AppData\Roaming\THULJOON.exe
2015-03-26 20:43 - 2015-03-26 20:43 - 00001702 _____ () C:\Windows\Tasks\THULJOON.job
2015-03-26 20:42 - 2015-03-26 20:42 - 00000000 ____D () C:\Users\Public\Documents\YTAHelper
2015-03-26 20:40 - 2015-03-26 20:40 - 00000000 ____D () C:\Users\Françoise\AppData\Local\CrashRpt
2015-03-26 20:39 - 2015-03-26 20:39 - 01978840 _____ () C:\Users\Françoise\AppData\Roaming\PWKN.exe
2015-03-26 20:39 - 2015-03-26 20:39 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsuC72D.tmp
2015-03-26 20:39 - 2015-03-26 20:39 - 00001350 _____ () C:\Windows\Tasks\PWKN.job
2015-03-26 20:36 - 2015-03-26 20:36 - 01940992 _____ () C:\Users\Françoise\AppData\Roaming\TJYHKE.exe
2015-03-26 20:36 - 2015-03-26 20:36 - 00001354 _____ () C:\Windows\Tasks\TJYHKE.job
2015-03-26 08:24 - 2015-03-26 08:24 - 00000000 _____ () C:\Users\Françoise\AppData\Local\.w852.db
2015-03-25 08:52 - 2015-03-25 08:52 - 00001103 _____ () C:\Users\Françoise\Downloads\Download-setup.website
2015-03-24 18:38 - 2015-03-24 18:38 - 00001700 _____ () C:\Windows\Tasks\LQNCBDR.job
2015-03-24 18:37 - 2015-03-24 18:37 - 01933824 _____ () C:\Users\Françoise\AppData\Roaming\LQNCBDR.exe
2015-03-24 18:35 - 2015-04-05 03:50 - 00000000 ____D () C:\Users\Françoise\AppData\Local\avaavxvyex
2015-03-24 18:27 - 2015-04-05 11:27 - 00000000 ____D () C:\Users\Françoise\AppData\Local\32444335-1427218036-3535-4C39-80C16E586CAC
2015-03-24 18:26 - 2015-03-24 18:26 - 00003582 _____ () C:\Windows\System32\Tasks\OKKFODDR
2015-03-24 18:26 - 2015-03-24 18:26 - 00001702 _____ () C:\Windows\Tasks\OKPPBAAR.job
2015-03-24 18:26 - 2015-03-24 18:26 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webTinstMKTN_01009.Wdf
2015-03-24 18:26 - 2015-03-24 18:25 - 01933824 _____ () C:\Users\Françoise\AppData\Roaming\OKPPBAAR.exe
2015-03-24 18:25 - 2015-04-05 11:26 - 00000000 ____D () C:\ProgramData\e551e40cdd5e4104afe48d92c795a590
2015-03-24 18:25 - 2015-03-24 18:25 - 00000000 ____D () C:\ProgramData\7fbb4485eae14230b10d76d5ce7f1c83
2015-03-24 18:24 - 2015-03-24 18:24 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\WebplayerRemote
2015-03-24 18:22 - 2015-04-05 10:35 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\32444335-1427214172-3535-4C39-80C16E586CAC
2015-03-24 18:20 - 2015-04-04 18:22 - 00000000 ____D () C:\Program Files (x86)\CloudScout Parental Control
2015-03-24 18:19 - 2015-03-24 18:19 - 00000000 ____D () C:\d05e7453-6a9e-4756-b897-37340347d5ca
2015-03-23 18:55 - 2015-04-04 15:42 - 00000978 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-03-23 18:55 - 2015-04-04 14:34 - 00000982 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-04-04 15:55 - 2015-03-02 09:55 - 00000306 _____ () C:\Windows\Tasks\Binkiland.job
2015-04-04 15:40 - 2015-01-19 11:23 - 00000000 ____D () C:\Users\Françoise\AppData\Everything
2015-04-04 12:10 - 2014-04-07 20:04 - 00000451 _____ () C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Yahoo!.website
2015-04-05 09:59 - 2014-05-05 06:27 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2015-03-26 21:14 - 2015-03-26 21:14 - 0005542 _____ () C:\Users\Françoise\AppData\Roaming\FDEDZBML
2015-03-28 16:34 - 2015-03-28 16:34 - 1971200 _____ () C:\Users\Françoise\AppData\Roaming\FDEDZBML.exe
2015-03-26 21:14 - 2015-03-26 21:14 - 0005542 _____ () C:\Users\Françoise\AppData\Roaming\GWEXI
2015-04-04 06:52 - 2015-04-04 06:54 - 1950208 _____ () C:\Users\Françoise\AppData\Roaming\GWEXI.exe
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\Françoise\AppData\Roaming\LQNCBDR
2015-03-24 18:37 - 2015-03-24 18:37 - 1933824 _____ () C:\Users\Françoise\AppData\Roaming\LQNCBDR.exe
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\Françoise\AppData\Roaming\OKPPBAAR
2015-03-24 18:26 - 2015-03-24 18:25 - 1933824 _____ () C:\Users\Françoise\AppData\Roaming\OKPPBAAR.exe
2014-09-01 10:18 - 2014-09-01 10:18 - 0001248 _____ () C:\Users\Françoise\AppData\Roaming\ONLLP
2015-01-25 18:12 - 2015-01-25 18:12 - 0001248 _____ () C:\Users\Françoise\AppData\Roaming\PWKN
2015-03-26 20:39 - 2015-03-26 20:39 - 1978840 _____ () C:\Users\Françoise\AppData\Roaming\PWKN.exe
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\Françoise\AppData\Roaming\THULJOON
2015-03-26 20:43 - 2015-03-26 20:43 - 1940992 _____ () C:\Users\Françoise\AppData\Roaming\THULJOON.exe
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\Françoise\AppData\Roaming\TJYHKE
2015-03-26 20:36 - 2015-03-26 20:36 - 1940992 _____ () C:\Users\Françoise\AppData\Roaming\TJYHKE.exe
2014-09-01 10:18 - 2014-09-01 10:18 - 0002086 _____ () C:\Users\Françoise\AppData\Roaming\UFQUWS
2014-12-17 12:12 - 2014-12-17 12:12 - 0022528 _____ () C:\Users\Françoise\AppData\Local\dsisetup13768332.exe
2015-02-23 12:38 - 2015-02-23 12:38 - 0613057 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsb2586.tmp
2015-04-04 06:55 - 2015-04-04 06:55 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsbFDBE.tmp
2015-04-02 18:09 - 2015-04-02 18:09 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsdFDF0.tmp
2015-04-04 16:27 - 2015-04-04 16:27 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsgEBB7.tmp
2014-05-09 18:31 - 2014-05-09 18:31 - 0301488 _____ (VuuPC Limited) C:\Users\Françoise\AppData\Local\nsi1680.tmp
2015-03-31 05:19 - 2015-03-31 05:19 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsiDF85.tmp
2015-04-05 09:13 - 2015-04-05 09:13 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsjC83D.tmp
2015-04-04 20:07 - 2015-04-04 20:07 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl19A7.tmp
2015-04-04 06:54 - 2015-04-04 06:54 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl570A.tmp
2015-02-21 10:49 - 2015-02-21 10:49 - 0613057 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl76E0.tmp
2015-03-30 10:33 - 2015-03-30 10:33 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsm5819.tmp
2015-03-28 16:36 - 2015-03-28 16:35 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsn2300.tmp
2015-03-27 10:46 - 2015-03-27 10:46 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsnC48.tmp
2015-03-29 12:11 - 2015-03-29 12:11 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nso16B3.tmp
2015-04-04 19:02 - 2015-04-04 19:02 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsoEDD6.tmp
2015-03-26 20:39 - 2015-03-26 20:39 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsuC72D.tmp
2015-04-04 18:58 - 2015-04-04 18:58 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsxDBAD.tmp
2014-11-14 08:12 - 2014-11-14 08:12 - 0301608 _____ (VuuPC Limited) C:\Users\Françoise\AppData\Local\nsy3999.tmp
2015-04-04 15:14 - 2015-03-01 15:52 - 0196504 _____ () C:\Program Files (x86)\9tres.dll
2015-04-04 15:14 - 2015-03-01 15:52 - 1037896 _____ () C:\Program Files (x86)\9tUninstall Internet Speed Tracker.dll
Task: {0C399515-1567-4D57-81CD-079D99FFF752} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {12FFAF24-CD9C-44A8-87F3-40B7BD32B842} - System32\Tasks\t4h2IDlcVS2y0Sr => C:\Users\Françoise\AppData\Roaming\jDuSLEf\6O1gHkb.exe
Task: {26E4C186-E388-4729-B0DC-40672FC139FB} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {2A377C54-9448-48C7-81BC-4F827718F323} - System32\Tasks\{0072C348-C0F5-4690-B9C5-C8B850EAAA95} => pcalua.exe -a C:\Users\Françoise\AppData\Roaming\sweet-page\UninstallManager.exe -c -ptid=cor
Task: {2A83656A-D193-4CDE-AFD1-3D0F5462B76A} - System32\Tasks\S7qLnZDxEjVnWif => C:\Users\Françoise\AppData\Roaming\FXOoNoy\eSAjdhI.exe [2015-02-27] ( )
Task: {2F74EA80-3F09-42F5-BB56-FD6D23201531} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {70D31263-C8AA-4F72-94CD-B847C475C5B0} - \8c6736a2-0446-4148-8f02-ca63eff37ec5-12 No Task File <==== ATTENTION
Task: {70EB7038-801D-4629-B59A-F2B52526ACD8} - System32\Tasks\{1393E89C-3D33-423C-BECB-D5548128FBC0} => pcalua.exe -a C:\Users\Françoise\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=adks <==== ATTENTION
Task: {7904E1AC-513E-4EB8-A318-65389D155BFD} - System32\Tasks\{E3E303C7-214A-4246-8966-F0426841A603} => Iexplore.exe http://ui.skype.com/ui/0/5.6.0.110.161/fr/abandoninstall?page=tsDownload&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled
Task: {8255801E-C819-4A83-A3BD-006338DEBEF6} - System32\Tasks\ULNtEsDPMKLzji9 => C:\Users\Françoise\AppData\Roaming\Cpap4wF\gn5Vm4r.exe
Task: {828CA497-D5EC-40F1-82B1-D94654F80D64} - System32\Tasks\SmartWeb Upgrade Trigger Task => C:\Users\Françoise\AppData\Local\SmartWeb\SmartWebHelper.exe [2015-02-17] (SoftBrain Technologies Ltd.) <==== ATTENTION
Task: {89431725-61A5-43B7-B149-4F68602D645C} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {8B7A841B-A394-44EA-A832-C8834484C0C3} - \8c6736a2-0446-4148-8f02-ca63eff37ec5-1-7 No Task File <==== ATTENTION
Task: {8CCE1C4E-E6A6-4004-B556-526E9C1DD61F} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files (x86)\Optimizer Pro 3.75\OptProLauncher.exe [2015-03-31] () <==== ATTENTION
Task: {924D639B-824C-4387-85D8-6B8F305DD4CD} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {94907B4A-CFE9-4508-B069-BDF1D85BEE81} - System32\Tasks\WIN-statsAdmin => C:\Users\Françoise\AppData\Local\Microsoft\WinU\~pqrhxft.exe <==== ATTENTION
Task: {A269C044-F854-4A64-A9C0-E84F64848B15} - System32\Tasks\{9687AFBA-FA57-48A3-90A8-3D61C414676A} => pcalua.exe -a C:\Users\Françoise\AppData\Roaming\qone8\UninstallManager.exe -c -ptid=adks
Task: {A832BAFF-4526-4A32-A841-37226B978D64} - System32\Tasks\{29DAE379-E7E9-4211-98F1-3C0DF9E21230} => pcalua.exe -a C:\Users\Françoise\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=smt
Task: {AE872F99-D435-474D-B58A-D4D2145EF8A9} - System32\Tasks\WIN-statsSystem => C:\Users\Françoise\AppData\Local\Microsoft\WinU\~frodbro.exe
Task: {B4F88351-D346-47F7-BF79-FFEA82521039} - System32\Tasks\9XGQKw3LInouXt0 => C:\Users\Françoise\AppData\Roaming\xmfTvyu\yUAoRwK.exe [2015-02-24] ( )
Task: {C2AF11FA-199C-49F3-8234-A42D3EF9F64A} - System32\Tasks\{1ED12CDA-49C0-49C3-876E-45DFAE76E072} => Firefox.exe
Task: {C3A564F3-F565-444F-B9B9-2C7BE983C80C} - System32\Tasks\WIN-GGfIfEGCfEGbGffIfCfEGC => C:\Users\Françoise\AppData\Roaming\~lbehxzl.exe
Task: {CE821C2E-F472-4C86-B298-9539C29181B5} - System32\Tasks\OKKFODDR => C:\ProgramData\e551e40cdd5e4104afe48d92c795a590\e551e40cdd5e4104afe48d92c795a590.exe
Task: {E5FBFE04-9BCE-47A6-AB45-41896307775D} - System32\Tasks\{6C6A1B19-AC17-40B1-81FA-F846708DC1B4} => Iexplore.exe http://ui.skype.com/ui/0/5.6.0.110.161/fr/abandoninstall?page=tsDownload&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled
Task: {F08FCB6F-1C7C-4618-897D-DCA0C185FF9C} - System32\Tasks\{A9DA2D5F-CB04-4000-BA22-B132226837FD} => Iexplore.exe http://ui.skype.com/ui/0/5.6.0.110.161/fr/abandoninstall?page=tsDownload&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled
Task: {F486969F-6FE3-4F2B-9DE6-EF16AAA97E54} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-04] (Google Inc.)
Task: {F9283F80-A3F8-43C6-BE94-75A3471EFCC1} - \8c6736a2-0446-4148-8f02-ca63eff37ec5-1-6 No Task File <==== ATTENTION
Task: {FAEBBC22-5575-45A7-B295-A53013F7C389} - \8c6736a2-0446-4148-8f02-ca63eff37ec5-5 No Task File <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\avaavaxvyy.job => C:\Users\Françoise\AppData\Local\avaavaxvyy\avaavaxvyy.exe
Task: C:\Windows\Tasks\Binkiland.job => C:\Users\FRANOI~1\AppData\Roaming\BINKIL~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\FDEDZBML.job => C:\Users\Franýÿoise\AppData\Roaming\FDEDZBML.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GWEXI.job => C:\Users\Franýÿoise\AppData\Roaming\GWEXI.exe <==== ATTENTION
Task: C:\Windows\Tasks\LQNCBDR.job => C:\Users\Franýÿoise\AppData\Roaming\LQNCBDR.exe <==== ATTENTION
Task: C:\Windows\Tasks\OKPPBAAR.job => C:\Users\Franýÿoise\AppData\Roaming\OKPPBAAR.exe <==== ATTENTION
Task: C:\Windows\Tasks\ONLLP.job => C:\Users\Franýÿoise\AppData\Roaming\ONLLP.exe <==== ATTENTION
Task: C:\Windows\Tasks\PWKN.job => C:\Users\Franýÿoise\AppData\Roaming\PWKN.exe <==== ATTENTION
Task: C:\Windows\Tasks\THULJOON.job => C:\Users\Franýÿoise\AppData\Roaming\THULJOON.exe <==== ATTENTION
Task: C:\Windows\Tasks\TJYHKE.job => C:\Users\Franýÿoise\AppData\Roaming\TJYHKE.exe <==== ATTENTION
Task: C:\Windows\Tasks\UFQUWS.job => C:\Users\Franýÿoise\AppData\Roaming\UFQUWS.exe <==== ATTENTION
Task: C:\Windows\Tasks\User_Feed_Synchronization-{F3D00496-1512-4FEF-A011-C2925A21559B}.job => C:\Windows\system32\msfeedssync.exe
Une fois, le texte coller dans le bloc-note.
Menu Fichier puis Enregistrer sous.
A gauche, place toi sur le bureau.
Dans le champs en bas, nom du fichier mets : fixlist.txt
Clic sur Enregistrer - cela va créer un fichier fixlist.txt sur le bureau.
Relance FRST et clic sur le bouton Fix
Selon comment un redémarrage est nécessaire (pas obligatoire).
Un fichier texte apparaît, copie/colle le contenu ici dans un nouveau message.
Redémarre l'ordinateur
Supprime les PUM.DNS avec RogueKiller en suivant ce tutorial : https://forum.malekal.com/viewtopic.php?t=48312&start=
Donne le rapport de suppression de RogueKiller.
puis :
puis réinitialise tes navigateurs:
==================================
Réinitialise tes navigateurs et ou manuellement reparamètre tes navigateurs WEB (page de démarrage, moteur de recherche etc) mais aussi supprimer/désactiver les extensions inutiles/parasites :
- Firefox : https://www.malekal.com/reparer-firefox/?t=36057&start=
- Google Chrome : https://www.malekal.com/reparer-google-chrome/?t=35837&start=
- Internet Explorer et modules complémentaires / moteurs de recherche : https://forum.malekal.com/viewtopic.php?t=41399&start=
Bien enfin ,c'est vraiment galère.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
Ran by Françoise at 2015-04-05 13:43:53 Run:1
Running from C:\Users\Françoise\Desktop
Loaded Profiles: Françoise (Available profiles: Françoise)
Boot Mode: Normal
==============================================
Content of fixlist:
HKLM-x32\...\Run: [gmsd_fr_340] => [X]
HKLM-x32\...\Run: [gmsd_fr_349] => [X]
HKLM-x32\...\Run: [gmsd_fr_362] => [X]
HKLM-x32\...\Run: [gmsd_fr_364] => C:\Program Files (x86)\gmsd_fr_364\gmsd_fr_364.exe [3983504 2015-03-30] ()
HKLM-x32\...\Run: [gmsd_fr_379] => C:\Program Files (x86)\gmsd_fr_379\gmsd_fr_379.exe [3984016 2015-04-04] ()
HKLM-x32\...\Run: [SmartWeb] => C:\Users\Françoise\AppData\Local\SmartWeb\SmartWebHelper.exe [270368 2015-02-17] (SoftBrain Technologies Ltd.)
HKLM-x32\...\RunOnce: [Ridigefekuke] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\FRANOI~1\AppData\Local\61BF73~1\Cuba.dat"
HKLM-x32\...\RunOnce: [upgmsd_fr_364.exe] => C:\Users\Françoise\AppData\Local\gmsd_fr_364\upgmsd_fr_364.exe [3308688 2015-03-30] ()
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro 3.75\OptProLauncher.exe [148008 2015-03-31] ()
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\...\MountPoints2: {a9835061-5c33-11e4-9a00-80c16e586cac} - G:\LaunchU3.exe
HKU\S-1-5-18\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_16_0_0_287_Plugin.exe -update plugin
AppInit_DLLs-x32: c:/progra~3/{4884a~1/192~1.1/rari.dll => "c:\progra~3\{4884a~1\192~1.1\rari.dll" File Not Found
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
Startup: C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk
ShortcutTarget: hqghumeaylnlf.lnk -> C:\ProgramData\{b24c03f5-2214-6cba-b24c-c03f52210fd4}\hqghumeaylnlf.exe (PC Utilities Software Limited)
Startup: C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk
ShortcutTarget: SmartWeb.lnk -> C:\Users\Françoise\AppData\Local\SmartWeb\SmartWebHelper.exe (SoftBrain Technologies Ltd.)
roxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:57266;https=127.0.0.1:57266
R2 542bb8ed; c:\Program Files (x86)\Optimizer Pro 3.75\OptProMon.dll [2292264 2015-04-04] ()
R2 cicifiso; C:\Users\Françoise\AppData\Roaming\32444335-1427214172-3535-4C39-80C16E586CAC\nsz8ACC.tmp [208384 2015-04-04] () [File not signed]
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158816 2015-03-16] (XTab system)
R2 toqukozi; C:\Users\Françoise\AppData\Roaming\32444335-1424508927-3535-4C39-80C16E586CAC\jnsxBEAE.tmp [90624 2015-02-21] () [File not signed]
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [493712 2015-04-04] (SysTool PasSame LIMITED)
R2 xuhejygu; C:\Users\Françoise\AppData\Roaming\32444335-1427214172-3535-4C39-80C16E586CAC\jnsu55B1.tmp [131584 2015-03-24] () [File not signed]
S2 FlashBeat; C:\ProgramData\FlashBeat\FlashBeat.exe [X]
R2 gusomybu; C:\Users\Françoise\AppData\Roaming\32444335-1424508927-3535-4C39-80C16E586CAC\nsr900.tmpfs [X]
S2 qrsvc_1.10.0.9; "C:\Program Files (x86)\QuickRef_1.10.0.9\Service\qrsvc.exe" [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
FF Extension: linkygemaldk - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\linky@gemal.dk [2014-08-31]
FF Extension: Settings Manager - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7} [2014-05-18]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\boost@boost.net.xpi [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\{8299d9bc-4fe2-4889-9adf-025a0769d461}.xpi [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\idmsq@idmsq.com [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\taylorralston@hotmail.com [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.com [Not Found]
2015-04-05 09:14 - 2015-04-05 09:19 - 00002836 _____ () C:\Windows\System32\Tasks\APSnotifierPP1
2015-04-05 09:14 - 2015-04-05 09:19 - 00002834 _____ () C:\Windows\System32\Tasks\APSnotifierPP3
2015-04-05 09:14 - 2015-04-05 09:19 - 00002834 _____ () C:\Windows\System32\Tasks\APSnotifierPP2
2015-04-05 09:14 - 2015-04-05 09:14 - 00001045 _____ () C:\Users\Françoise\Desktop\AnyProtect.lnk
2015-04-05 09:14 - 2015-04-05 09:14 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
2015-04-05 09:13 - 2015-04-05 11:27 - 00000000 ____D () C:\Program Files (x86)\AnyProtectEx
2015-04-05 09:13 - 2015-04-05 09:13 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsjC83D.tmp
2015-04-05 09:13 - 2015-04-05 09:13 - 00000000 __SHD () C:\Users\Françoise\AppData\Roaming\AnyProtectEx
2015-04-05 09:08 - 2015-04-05 11:27 - 00000000 ____D () C:\Users\Françoise\AppData\Local\SmartWeb
2015-04-05 09:08 - 2015-04-05 09:08 - 00004058 _____ () C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task
2015-04-05 09:07 - 2015-04-05 11:27 - 00000000 ____D () C:\Users\Françoise\AppData\Local\gmsd_fr_379
2015-04-05 09:07 - 2015-04-05 09:11 - 00000000 ____D () C:\Program Files (x86)\gmsd_fr_379
2015-04-04 23:44 - 2015-04-04 23:44 - 00000000 ____D () C:\Users\Françoise\SupTab
2015-04-04 23:29 - 2015-04-05 11:10 - 00000000 ____D () C:\Users\Françoise\AppData\Local\gmsd_fr_364
2015-04-04 23:29 - 2015-04-05 08:53 - 00003278 _____ () C:\Windows\System32\Tasks\Optimizer Pro Schedule
2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\Users\Françoise\Documents\Optimizer Pro
2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\Optimizer Pro
2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\Program Files (x86)\gmsd_fr_364
2015-04-04 23:28 - 2015-04-05 08:36 - 00000000 ____D () C:\ProgramData\{b24c03f5-2214-6cba-b24c-c03f52210fd4}
2015-04-04 23:28 - 2015-04-04 23:28 - 00001099 _____ () C:\Users\Françoise\Desktop\Optimizer Pro.lnk
2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro 3.75
2015-04-04 23:27 - 2015-04-05 11:05 - 00000000 ____D () C:\Program Files (x86)\XTab
2015-04-04 23:27 - 2015-04-04 23:27 - 00001101 _____ () C:\Users\Françoise\Desktop\Continue Live Installation.lnk
2015-04-04 23:27 - 2015-04-04 23:27 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2015-04-04 23:27 - 2015-04-04 23:27 - 00000000 ____D () C:\ProgramData\IHProtectUpDate
2015-04-04 23:26 - 2015-04-04 23:26 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\mystartsearch
2015-04-04 20:07 - 2015-04-04 20:07 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl19A7.tmp
2015-04-04 20:06 - 2015-04-05 11:40 - 00026874 _____ () C:\Users\Françoise\Desktop\FRST.txt
2015-04-04 20:06 - 2015-04-04 20:06 - 00000306 _____ () C:\Windows\Tasks\avaavaxvyy.job
2015-04-04 20:05 - 2015-04-05 11:39 - 00000000 ____D () C:\FRST
2015-04-04 20:05 - 2015-04-04 20:05 - 00000000 ____D () C:\Users\Françoise\AppData\Local\avaavaxvyy
2015-04-04 20:01 - 2015-04-04 20:01 - 02095616 _____ (Farbar) C:\Users\Françoise\Desktop\FRST64.exe
2015-04-04 19:02 - 2015-04-04 19:02 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsoEDD6.tmp
2015-04-04 18:59 - 2015-04-04 18:59 - 00000000 ____D () C:\Users\Françoise\AppData\Local\Software
2015-04-04 18:58 - 2015-04-04 18:58 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsxDBAD.tmp
2015-04-04 18:24 - 2015-04-04 23:26 - 00001615 _____ () C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-04 18:24 - 2015-04-04 18:24 - 00000300 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{F3D00496-1512-4FEF-A011-C2925A21559B}.job
2015-04-04 18:24 - 2015-04-04 18:24 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-04 16:27 - 2015-04-04 16:27 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsgEBB7.tmp
2015-04-04 06:55 - 2015-04-04 06:55 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsbFDBE.tmp
2015-04-04 06:54 - 2015-04-04 06:54 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl570A.tmp
2015-04-04 06:52 - 2015-04-04 06:54 - 01950208 _____ () C:\Users\Françoise\AppData\Roaming\GWEXI.exe
2015-04-04 06:52 - 2015-04-04 06:54 - 00001352 _____ () C:\Windows\Tasks\GWEXI.job
2015-04-03 09:32 - 2015-04-03 09:32 - 00000000 ___HD () C:\Users\Françoise\AppData\Local\61bf73677f83230a
2015-04-02 18:09 - 2015-04-02 18:09 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsdFDF0.tmp
2015-03-31 12:01 - 2015-04-05 03:42 - 00000000 ____D () C:\Program Files (x86)\Mountain Bike
2015-03-31 05:19 - 2015-03-31 05:19 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsiDF85.tmp
2015-03-30 10:33 - 2015-03-30 10:33 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsm5819.tmp
2015-03-30 07:23 - 2015-04-05 11:10 - 00000348 _____ () C:\Windows\Tasks\HPCeeScheduleForFrançoise.job
2015-03-30 07:17 - 2015-03-30 07:17 - 00000000 _____ () C:\Windows\SysWOW64\sho148F.tmp
2015-03-29 12:11 - 2015-03-29 12:11 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nso16B3.tmp
2015-03-29 11:57 - 2015-03-29 11:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\1 Media Player
2015-03-29 11:57 - 2015-03-29 11:57 - 00000000 ____D () C:\Program Files (x86)\1 Media Player
2015-03-29 07:38 - 2015-03-29 07:39 - 00914436 _____ () C:\Users\Françoise\Downloads\widget-1-6.zip
2015-03-28 16:36 - 2015-03-28 16:35 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsn2300.tmp
2015-03-28 16:34 - 2015-04-05 03:43 - 00000000 ____D () C:\Program Files (x86)\GoHDV28.03
2015-03-28 16:34 - 2015-03-28 16:34 - 01971200 _____ () C:\Users\Françoise\AppData\Roaming\FDEDZBML.exe
2015-03-28 16:34 - 2015-03-28 16:34 - 00001702 _____ () C:\Windows\Tasks\FDEDZBML.job
2015-03-27 17:05 - 2015-03-27 17:05 - 02250712 _____ (Company Name) C:\Users\Françoise\Downloads\adsl-tv-fm_setup.exe
2015-03-27 10:46 - 2015-03-27 10:46 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsnC48.tmp
2015-03-27 07:30 - 2015-03-27 07:30 - 00003176 _____ () C:\Windows\System32\Tasks\{29DAE379-E7E9-4211-98F1-3C0DF9E21230}
2015-03-26 21:14 - 2015-03-26 21:14 - 00005542 _____ () C:\Users\Françoise\AppData\Roaming\GWEXI
2015-03-26 21:14 - 2015-03-26 21:14 - 00005542 _____ () C:\Users\Françoise\AppData\Roaming\FDEDZBML
2015-03-26 20:50 - 2015-03-26 20:50 - 00000000 ____D () C:\ZombieNews
2015-03-26 20:43 - 2015-03-26 20:43 - 01940992 _____ () C:\Users\Françoise\AppData\Roaming\THULJOON.exe
2015-03-26 20:43 - 2015-03-26 20:43 - 00001702 _____ () C:\Windows\Tasks\THULJOON.job
2015-03-26 20:42 - 2015-03-26 20:42 - 00000000 ____D () C:\Users\Public\Documents\YTAHelper
2015-03-26 20:40 - 2015-03-26 20:40 - 00000000 ____D () C:\Users\Françoise\AppData\Local\CrashRpt
2015-03-26 20:39 - 2015-03-26 20:39 - 01978840 _____ () C:\Users\Françoise\AppData\Roaming\PWKN.exe
2015-03-26 20:39 - 2015-03-26 20:39 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsuC72D.tmp
2015-03-26 20:39 - 2015-03-26 20:39 - 00001350 _____ () C:\Windows\Tasks\PWKN.job
2015-03-26 20:36 - 2015-03-26 20:36 - 01940992 _____ () C:\Users\Françoise\AppData\Roaming\TJYHKE.exe
2015-03-26 20:36 - 2015-03-26 20:36 - 00001354 _____ () C:\Windows\Tasks\TJYHKE.job
2015-03-26 08:24 - 2015-03-26 08:24 - 00000000 _____ () C:\Users\Françoise\AppData\Local\.w852.db
2015-03-25 08:52 - 2015-03-25 08:52 - 00001103 _____ () C:\Users\Françoise\Downloads\Download-setup.website
2015-03-24 18:38 - 2015-03-24 18:38 - 00001700 _____ () C:\Windows\Tasks\LQNCBDR.job
2015-03-24 18:37 - 2015-03-24 18:37 - 01933824 _____ () C:\Users\Françoise\AppData\Roaming\LQNCBDR.exe
2015-03-24 18:35 - 2015-04-05 03:50 - 00000000 ____D () C:\Users\Françoise\AppData\Local\avaavxvyex
2015-03-24 18:27 - 2015-04-05 11:27 - 00000000 ____D () C:\Users\Françoise\AppData\Local\32444335-1427218036-3535-4C39-80C16E586CAC
2015-03-24 18:26 - 2015-03-24 18:26 - 00003582 _____ () C:\Windows\System32\Tasks\OKKFODDR
2015-03-24 18:26 - 2015-03-24 18:26 - 00001702 _____ () C:\Windows\Tasks\OKPPBAAR.job
2015-03-24 18:26 - 2015-03-24 18:26 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webTinstMKTN_01009.Wdf
2015-03-24 18:26 - 2015-03-24 18:25 - 01933824 _____ () C:\Users\Françoise\AppData\Roaming\OKPPBAAR.exe
2015-03-24 18:25 - 2015-04-05 11:26 - 00000000 ____D () C:\ProgramData\e551e40cdd5e4104afe48d92c795a590
2015-03-24 18:25 - 2015-03-24 18:25 - 00000000 ____D () C:\ProgramData\7fbb4485eae14230b10d76d5ce7f1c83
2015-03-24 18:24 - 2015-03-24 18:24 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\WebplayerRemote
2015-03-24 18:22 - 2015-04-05 10:35 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\32444335-1427214172-3535-4C39-80C16E586CAC
2015-03-24 18:20 - 2015-04-04 18:22 - 00000000 ____D () C:\Program Files (x86)\CloudScout Parental Control
2015-03-24 18:19 - 2015-03-24 18:19 - 00000000 ____D () C:\d05e7453-6a9e-4756-b897-37340347d5ca
2015-03-23 18:55 - 2015-04-04 15:42 - 00000978 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-03-23 18:55 - 2015-04-04 14:34 - 00000982 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-04-04 15:55 - 2015-03-02 09:55 - 00000306 _____ () C:\Windows\Tasks\Binkiland.job
2015-04-04 15:40 - 2015-01-19 11:23 - 00000000 ____D () C:\Users\Françoise\AppData\Everything
2015-04-04 12:10 - 2014-04-07 20:04 - 00000451 _____ () C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Yahoo!.website
2015-04-05 09:59 - 2014-05-05 06:27 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2015-03-26 21:14 - 2015-03-26 21:14 - 0005542 _____ () C:\Users\Françoise\AppData\Roaming\FDEDZBML
2015-03-28 16:34 - 2015-03-28 16:34 - 1971200 _____ () C:\Users\Françoise\AppData\Roaming\FDEDZBML.exe
2015-03-26 21:14 - 2015-03-26 21:14 - 0005542 _____ () C:\Users\Françoise\AppData\Roaming\GWEXI
2015-04-04 06:52 - 2015-04-04 06:54 - 1950208 _____ () C:\Users\Françoise\AppData\Roaming\GWEXI.exe
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\Françoise\AppData\Roaming\LQNCBDR
2015-03-24 18:37 - 2015-03-24 18:37 - 1933824 _____ () C:\Users\Françoise\AppData\Roaming\LQNCBDR.exe
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\Françoise\AppData\Roaming\OKPPBAAR
2015-03-24 18:26 - 2015-03-24 18:25 - 1933824 _____ () C:\Users\Françoise\AppData\Roaming\OKPPBAAR.exe
2014-09-01 10:18 - 2014-09-01 10:18 - 0001248 _____ () C:\Users\Françoise\AppData\Roaming\ONLLP
2015-01-25 18:12 - 2015-01-25 18:12 - 0001248 _____ () C:\Users\Françoise\AppData\Roaming\PWKN
2015-03-26 20:39 - 2015-03-26 20:39 - 1978840 _____ () C:\Users\Françoise\AppData\Roaming\PWKN.exe
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\Françoise\AppData\Roaming\THULJOON
2015-03-26 20:43 - 2015-03-26 20:43 - 1940992 _____ () C:\Users\Françoise\AppData\Roaming\THULJOON.exe
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\Françoise\AppData\Roaming\TJYHKE
2015-03-26 20:36 - 2015-03-26 20:36 - 1940992 _____ () C:\Users\Françoise\AppData\Roaming\TJYHKE.exe
2014-09-01 10:18 - 2014-09-01 10:18 - 0002086 _____ () C:\Users\Françoise\AppData\Roaming\UFQUWS
2014-12-17 12:12 - 2014-12-17 12:12 - 0022528 _____ () C:\Users\Françoise\AppData\Local\dsisetup13768332.exe
2015-02-23 12:38 - 2015-02-23 12:38 - 0613057 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsb2586.tmp
2015-04-04 06:55 - 2015-04-04 06:55 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsbFDBE.tmp
2015-04-02 18:09 - 2015-04-02 18:09 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsdFDF0.tmp
2015-04-04 16:27 - 2015-04-04 16:27 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsgEBB7.tmp
2014-05-09 18:31 - 2014-05-09 18:31 - 0301488 _____ (VuuPC Limited) C:\Users\Françoise\AppData\Local\nsi1680.tmp
2015-03-31 05:19 - 2015-03-31 05:19 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsiDF85.tmp
2015-04-05 09:13 - 2015-04-05 09:13 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsjC83D.tmp
2015-04-04 20:07 - 2015-04-04 20:07 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl19A7.tmp
2015-04-04 06:54 - 2015-04-04 06:54 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl570A.tmp
2015-02-21 10:49 - 2015-02-21 10:49 - 0613057 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl76E0.tmp
2015-03-30 10:33 - 2015-03-30 10:33 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsm5819.tmp
2015-03-28 16:36 - 2015-03-28 16:35 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsn2300.tmp
2015-03-27 10:46 - 2015-03-27 10:46 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsnC48.tmp
2015-03-29 12:11 - 2015-03-29 12:11 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nso16B3.tmp
2015-04-04 19:02 - 2015-04-04 19:02 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsoEDD6.tmp
2015-03-26 20:39 - 2015-03-26 20:39 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsuC72D.tmp
2015-04-04 18:58 - 2015-04-04 18:58 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsxDBAD.tmp
2014-11-14 08:12 - 2014-11-14 08:12 - 0301608 _____ (VuuPC Limited) C:\Users\Françoise\AppData\Local\nsy3999.tmp
2015-04-04 15:14 - 2015-03-01 15:52 - 0196504 _____ () C:\Program Files (x86)\9tres.dll
2015-04-04 15:14 - 2015-03-01 15:52 - 1037896 _____ () C:\Program Files (x86)\9tUninstall Internet Speed Tracker.dll
Task: {0C399515-1567-4D57-81CD-079D99FFF752} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {12FFAF24-CD9C-44A8-87F3-40B7BD32B842} - System32\Tasks\t4h2IDlcVS2y0Sr => C:\Users\Françoise\AppData\Roaming\jDuSLEf\6O1gHkb.exe
Task: {26E4C186-E388-4729-B0DC-40672FC139FB} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {2A377C54-9448-48C7-81BC-4F827718F323} - System32\Tasks\{0072C348-C0F5-4690-B9C5-C8B850EAAA95} => pcalua.exe -a C:\Users\Françoise\AppData\Roaming\sweet-page\UninstallManager.exe -c -ptid=cor
Task: {2A83656A-D193-4CDE-AFD1-3D0F5462B76A} - System32\Tasks\S7qLnZDxEjVnWif => C:\Users\Françoise\AppData\Roaming\FXOoNoy\eSAjdhI.exe [2015-02-27] ( )
Task: {2F74EA80-3F09-42F5-BB56-FD6D23201531} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {70D31263-C8AA-4F72-94CD-B847C475C5B0} - \8c6736a2-0446-4148-8f02-ca63eff37ec5-12 No Task File <==== ATTENTION
Task: {70EB7038-801D-4629-B59A-F2B52526ACD8} - System32\Tasks\{1393E89C-3D33-423C-BECB-D5548128FBC0} => pcalua.exe -a C:\Users\Françoise\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=adks <==== ATTENTION
Task: {7904E1AC-513E-4EB8-A318-65389D155BFD} - System32\Tasks\{E3E303C7-214A-4246-8966-F0426841A603} => Iexplore.exe http://ui.skype.com/ui/0/5.6.0.110.161/fr/abandoninstall?page=tsDownload&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled
Task: {8255801E-C819-4A83-A3BD-006338DEBEF6} - System32\Tasks\ULNtEsDPMKLzji9 => C:\Users\Françoise\AppData\Roaming\Cpap4wF\gn5Vm4r.exe
Task: {828CA497-D5EC-40F1-82B1-D94654F80D64} - System32\Tasks\SmartWeb Upgrade Trigger Task => C:\Users\Françoise\AppData\Local\SmartWeb\SmartWebHelper.exe [2015-02-17] (SoftBrain Technologies Ltd.) <==== ATTENTION
Task: {89431725-61A5-43B7-B149-4F68602D645C} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {8B7A841B-A394-44EA-A832-C8834484C0C3} - \8c6736a2-0446-4148-8f02-ca63eff37ec5-1-7 No Task File <==== ATTENTION
Task: {8CCE1C4E-E6A6-4004-B556-526E9C1DD61F} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files (x86)\Optimizer Pro 3.75\OptProLauncher.exe [2015-03-31] () <==== ATTENTION
Task: {924D639B-824C-4387-85D8-6B8F305DD4CD} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {94907B4A-CFE9-4508-B069-BDF1D85BEE81} - System32\Tasks\WIN-statsAdmin => C:\Users\Françoise\AppData\Local\Microsoft\WinU\~pqrhxft.exe <==== ATTENTION
Task: {A269C044-F854-4A64-A9C0-E84F64848B15} - System32\Tasks\{9687AFBA-FA57-48A3-90A8-3D61C414676A} => pcalua.exe -a C:\Users\Françoise\AppData\Roaming\qone8\UninstallManager.exe -c -ptid=adks
Task: {A832BAFF-4526-4A32-A841-37226B978D64} - System32\Tasks\{29DAE379-E7E9-4211-98F1-3C0DF9E21230} => pcalua.exe -a C:\Users\Françoise\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=smt
Task: {AE872F99-D435-474D-B58A-D4D2145EF8A9} - System32\Tasks\WIN-statsSystem => C:\Users\Françoise\AppData\Local\Microsoft\WinU\~frodbro.exe
Task: {B4F88351-D346-47F7-BF79-FFEA82521039} - System32\Tasks\9XGQKw3LInouXt0 => C:\Users\Françoise\AppData\Roaming\xmfTvyu\yUAoRwK.exe [2015-02-24] ( )
Task: {C2AF11FA-199C-49F3-8234-A42D3EF9F64A} - System32\Tasks\{1ED12CDA-49C0-49C3-876E-45DFAE76E072} => Firefox.exe
Task: {C3A564F3-F565-444F-B9B9-2C7BE983C80C} - System32\Tasks\WIN-GGfIfEGCfEGbGffIfCfEGC => C:\Users\Françoise\AppData\Roaming\~lbehxzl.exe
Task: {CE821C2E-F472-4C86-B298-9539C29181B5} - System32\Tasks\OKKFODDR => C:\ProgramData\e551e40cdd5e4104afe48d92c795a590\e551e40cdd5e4104afe48d92c795a590.exe
Task: {E5FBFE04-9BCE-47A6-AB45-41896307775D} - System32\Tasks\{6C6A1B19-AC17-40B1-81FA-F846708DC1B4} => Iexplore.exe http://ui.skype.com/ui/0/5.6.0.110.161/fr/abandoninstall?page=tsDownload&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled
Task: {F08FCB6F-1C7C-4618-897D-DCA0C185FF9C} - System32\Tasks\{A9DA2D5F-CB04-4000-BA22-B132226837FD} => Iexplore.exe http://ui.skype.com/ui/0/5.6.0.110.161/fr/abandoninstall?page=tsDownload&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled
Task: {F486969F-6FE3-4F2B-9DE6-EF16AAA97E54} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-04] (Google Inc.)
Task: {F9283F80-A3F8-43C6-BE94-75A3471EFCC1} - \8c6736a2-0446-4148-8f02-ca63eff37ec5-1-6 No Task File <==== ATTENTION
Task: {FAEBBC22-5575-45A7-B295-A53013F7C389} - \8c6736a2-0446-4148-8f02-ca63eff37ec5-5 No Task File <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\avaavaxvyy.job => C:\Users\Françoise\AppData\Local\avaavaxvyy\avaavaxvyy.exe
Task: C:\Windows\Tasks\Binkiland.job => C:\Users\FRANOI~1\AppData\Roaming\BINKIL~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\FDEDZBML.job => C:\Users\Franýÿoise\AppData\Roaming\FDEDZBML.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GWEXI.job => C:\Users\Franýÿoise\AppData\Roaming\GWEXI.exe <==== ATTENTION
Task: C:\Windows\Tasks\LQNCBDR.job => C:\Users\Franýÿoise\AppData\Roaming\LQNCBDR.exe <==== ATTENTION
Task: C:\Windows\Tasks\OKPPBAAR.job => C:\Users\Franýÿoise\AppData\Roaming\OKPPBAAR.exe <==== ATTENTION
Task: C:\Windows\Tasks\ONLLP.job => C:\Users\Franýÿoise\AppData\Roaming\ONLLP.exe <==== ATTENTION
Task: C:\Windows\Tasks\PWKN.job => C:\Users\Franýÿoise\AppData\Roaming\PWKN.exe <==== ATTENTION
Task: C:\Windows\Tasks\THULJOON.job => C:\Users\Franýÿoise\AppData\Roaming\THULJOON.exe <==== ATTENTION
Task: C:\Windows\Tasks\TJYHKE.job => C:\Users\Franýÿoise\AppData\Roaming\TJYHKE.exe <==== ATTENTION
Task: C:\Windows\Tasks\UFQUWS.job => C:\Users\Franýÿoise\AppData\Roaming\UFQUWS.exe <==== ATTENTION
Task: C:\Windows\Tasks\User_Feed_Synchronization-{F3D00496-1512-4FEF-A011-C2925A21559B}.job => C:\Windows\system32\msfeedssync.exe
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_340 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_349 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_362 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_364 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_379 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SmartWeb => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\Ridigefekuke => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\upgmsd_fr_364.exe => value deleted successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui" => Key deleted successfully.
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Optimizer Pro => value deleted successfully.
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableLockWorkstation => value deleted successfully.
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableChangePassword => value deleted successfully.
"HKU\S-1-5-21-805902893-1657446439-1934957100-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a9835061-5c33-11e4-9a00-80c16e586cac}" => Key deleted successfully.
HKCR\CLSID\{a9835061-5c33-11e4-9a00-80c16e586cac} => Key not found.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\FlashPlayerUpdate => value deleted successfully.
"c:/progra~3/{4884a~1/192~1.1/rari.dll" => Value Data removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\jumpflip" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\volaro" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vonteera" => Key deleted successfully.
C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk => Moved successfully.
C:\ProgramData\{b24c03f5-2214-6cba-b24c-c03f52210fd4}\hqghumeaylnlf.exe => Moved successfully.
C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk => Moved successfully.
C:\Users\Françoise\AppData\Local\SmartWeb\SmartWebHelper.exe => Moved successfully.
roxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. => Error: No automatic fix found for this entry.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully.
542bb8ed => Service deleted successfully.
cicifiso => Service stopped successfully.
cicifiso => Service deleted successfully.
IHProtect Service => Service stopped successfully.
IHProtect Service => Service deleted successfully.
toqukozi => Service stopped successfully.
toqukozi => Service deleted successfully.
WindowsMangerProtect => Service stopped successfully.
WindowsMangerProtect => Service deleted successfully.
xuhejygu => Service stopped successfully.
xuhejygu => Service deleted successfully.
FlashBeat => Service deleted successfully.
gusomybu => Service stopped successfully.
gusomybu => Service deleted successfully.
qrsvc_1.10.0.9 => Service deleted successfully.
clwvd => Service deleted successfully.
C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\linky@gemal.dk => Moved successfully.
C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7} => Moved successfully.
C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\boost@boost.net.xpi not found.
C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\{8299d9bc-4fe2-4889-9adf-025a0769d461}.xpi not found.
C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\idmsq@idmsq.com not found.
C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} not found.
C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\taylorralston@hotmail.com not found.
C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.com not found.
C:\Windows\System32\Tasks\APSnotifierPP1 => Moved successfully.
C:\Windows\System32\Tasks\APSnotifierPP3 => Moved successfully.
C:\Windows\System32\Tasks\APSnotifierPP2 => Moved successfully.
C:\Users\Françoise\Desktop\AnyProtect.lnk => Moved successfully.
C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup => Moved successfully.
C:\Program Files (x86)\AnyProtectEx => Moved successfully.
C:\Users\Françoise\AppData\Local\nsjC83D.tmp => Moved successfully.
C:\Users\Françoise\AppData\Roaming\AnyProtectEx => Moved successfully.
C:\Users\Françoise\AppData\Local\SmartWeb => Moved successfully.
C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task => Moved successfully.
C:\Users\Françoise\AppData\Local\gmsd_fr_379 => Moved successfully.
C:\Program Files (x86)\gmsd_fr_379 => Moved successfully.
C:\Users\Françoise\SupTab => Moved successfully.
C:\Users\Françoise\AppData\Local\gmsd_fr_364 => Moved successfully.
C:\Windows\System32\Tasks\Optimizer Pro Schedule => Moved successfully.
C:\Users\Françoise\Documents\Optimizer Pro => Moved successfully.
C:\Users\Françoise\AppData\Roaming\Optimizer Pro => Moved successfully.
C:\Program Files (x86)\gmsd_fr_364 => Moved successfully.
C:\ProgramData\{b24c03f5-2214-6cba-b24c-c03f52210fd4} => Moved successfully.
C:\Users\Françoise\Desktop\Optimizer Pro.lnk => Moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 => Moved successfully.
C:\Program Files (x86)\Optimizer Pro 3.75 => Moved successfully.
C:\Program Files (x86)\XTab => Moved successfully.
C:\Users\Françoise\Desktop\Continue Live Installation.lnk => Moved successfully.
C:\ProgramData\WindowsMangerProtect => Moved successfully.
C:\ProgramData\IHProtectUpDate => Moved successfully.
C:\Users\Françoise\AppData\Roaming\mystartsearch => Moved successfully.
C:\Users\Françoise\AppData\Local\nsl19A7.tmp => Moved successfully.
C:\Users\Françoise\Desktop\FRST.txt => Moved successfully.
C:\Windows\Tasks\avaavaxvyy.job => Moved successfully.
"C:\FRST" directory move:
Could not move "C:\FRST" directory. => Scheduled to move on reboot.
C:\Users\Françoise\AppData\Local\avaavaxvyy => Moved successfully.
C:\Users\Françoise\Desktop\FRST64.exe => Moved successfully.
C:\Users\Françoise\AppData\Local\nsoEDD6.tmp => Moved successfully.
C:\Users\Françoise\AppData\Local\Software => Moved successfully.
C:\Users\Françoise\AppData\Local\nsxDBAD.tmp => Moved successfully.
C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Moved successfully.
C:\Windows\Tasks\User_Feed_Synchronization-{F3D00496-1512-4FEF-A011-C2925A21559B}.job => Moved successfully.
C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories => Moved successfully.
C:\Users\Françoise\AppData\Local\nsgEBB7.tmp => Moved successfully.
C:\Users\Françoise\AppData\Local\nsbFDBE.tmp => Moved successfully.
C:\Users\Françoise\AppData\Local\nsl570A.tmp => Moved successfully.
C:\Users\Françoise\AppData\Roaming\GWEXI.exe => Moved successfully.
C:\Windows\Tasks\GWEXI.job => Moved successfully.
C:\Users\Françoise\AppData\Local\61bf73677f83230a => Moved successfully.
C:\Users\Françoise\AppData\Local\nsdFDF0.tmp => Moved successfully.
C:\Program Files (x86)\Mountain Bike => Moved successfully.
C:\Users\Françoise\AppData\Local\nsiDF85.tmp => Moved successfully.
C:\Users\Françoise\AppData\Local\nsm5819.tmp => Moved successfully.
C:\Windows\Tasks\HPCeeScheduleForFrançoise.job => Moved successfully.
C:\Windows\SysWOW64\sho148F.tmp => Moved successfully.
C:\Users\Françoise\AppData\Local\nso16B3.tmp => Moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\1 Media Player => Moved successfully.
C:\Program Files (x86)\1 Media Player => Moved successfully.
C:\Users\Françoise\Downloads\widget-1-6.zip => Moved successfully.
C:\Users\Françoise\AppData\Local\nsn2300.tmp => Moved successfully.
C:\Program Files (x86)\GoHDV28.03 => Moved successfully.
C:\Users\Françoise\AppData\Roaming\FDEDZBML.exe => Moved successfully.
C:\Windows\Tasks\FDEDZBML.job => Moved successfully.
C:\Users\Françoise\Downloads\adsl-tv-fm_setup.exe => Moved successfully.
C:\Users\Françoise\AppData\Local\nsnC48.tmp => Moved successfully.
C:\Windows\System32\Tasks\{29DAE379-E7E9-4211-98F1-3C0DF9E21230} => Moved successfully.
C:\Users\Françoise\AppData\Roaming\GWEXI => Moved successfully.
C:\Users\Françoise\AppData\Roaming\FDEDZBML => Moved successfully.
C:\ZombieNews => Moved successfully.
C:\Users\Françoise\AppData\Roaming\THULJOON.exe => Moved successfully.
C:\Windows\Tasks\THULJOON.job => Moved successfully.
C:\Users\Public\Documents\YTAHelper => Moved successfully.
C:\Users\Françoise\AppData\Local\CrashRpt => Moved successfully.
C:\Users\Françoise\AppData\Roaming\PWKN.exe => Moved successfully.
C:\Users\Françoise\AppData\Local\nsuC72D.tmp => Moved successfully.
C:\Windows\Tasks\PWKN.job => Moved successfully.
C:\Users\Françoise\AppData\Roaming\TJYHKE.exe => Moved successfully.
C:\Windows\Tasks\TJYHKE.job => Moved successfully.
C:\Users\Françoise\AppData\Local\.w852.db => Moved successfully.
C:\Users\Françoise\Downloads\Download-setup.website => Moved successfully.
C:\Windows\Tasks\LQNCBDR.job => Moved successfully.
C:\Users\Françoise\AppData\Roaming\LQNCBDR.exe => Moved successfully.
C:\Users\Françoise\AppData\Local\avaavxvyex => Moved successfully.
C:\Users\Françoise\AppData\Local\32444335-1427218036-3535-4C39-80C16E586CAC => Moved successfully.
C:\Windows\System32\Tasks\OKKFODDR => Moved successfully.
C:\Windows\Tasks\OKPPBAAR.job => Moved successfully.
C:\Windows\system32\Drivers\Msft_Kernel_webTinstMKTN_01009.Wdf => Moved successfully.
C:\Users\Françoise\AppData\Roaming\OKPPBAAR.exe => Moved successfully.
C:\ProgramData\e551e40cdd5e4104afe48d92c795a590 => Moved successfully.
C:\ProgramData\7fbb4485eae14230b10d76d5ce7f1c83 => Moved successfully.
C:\Users\Françoise\AppData\Roaming\WebplayerRemote => Moved successfully.
C:\Users\Françoise\AppData\Roaming\32444335-1427214172-3535-4C39-80C16E586CAC => Moved successfully.
C:\Program Files (x86)\CloudScout Parental Control => Moved successfully.
C:\d05e7453-6a9e-4756-b897-37340347d5ca => Moved successfully.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\Binkiland.job => Moved successfully.
C:\Users\Françoise\AppData\Everything => Moved successfully.
C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Yahoo!.website => Moved successfully.
C:\Windows\Tasks\APSnotifierPP1.job => Moved successfully.
"C:\Users\Françoise\AppData\Roaming\FDEDZBML" => File/Directory not found.
"C:\Users\Françoise\AppData\Roaming\FDEDZBML.exe" => File/Directory not found.
"C:\Users\Françoise\AppData\Roaming\GWEXI" => File/Directory not found.
"C:\Users\Françoise\AppData\Roaming\GWEXI.exe" => File/Directory not found.
C:\Users\Françoise\AppData\Roaming\LQNCBDR => Moved successfully.
"C:\Users\Françoise\AppData\Roaming\LQNCBDR.exe" => File/Directory not found.
C:\Users\Françoise\AppData\Roaming\OKPPBAAR => Moved successfully.
"C:\Users\Françoise\AppData\Roaming\OKPPBAAR.exe" => File/Directory not found.
C:\Users\Françoise\AppData\Roaming\ONLLP => Moved successfully.
C:\Users\Françoise\AppData\Roaming\PWKN => Moved successfully.
"C:\Users\Françoise\AppData\Roaming\PWKN.exe" => File/Directory not found.
C:\Users\Françoise\AppData\Roaming\THULJOON => Moved successfully.
"C:\Users\Françoise\AppData\Roaming\THULJOON.exe" => File/Directory not found.
C:\Users\Françoise\AppData\Roaming\TJYHKE => Moved successfully.
"C:\Users\Françoise\AppData\Roaming\TJYHKE.exe" => File/Directory not found.
C:\Users\Françoise\AppData\Roaming\UFQUWS => Moved successfully.
C:\Users\Françoise\AppData\Local\dsisetup13768332.exe => Moved successfully.
C:\Users\Françoise\AppData\Local\nsb2586.tmp => Moved successfully.
"C:\Users\Françoise\AppData\Local\nsbFDBE.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsdFDF0.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsgEBB7.tmp" => File/Directory not found.
C:\Users\Françoise\AppData\Local\nsi1680.tmp => Moved successfully.
"C:\Users\Françoise\AppData\Local\nsiDF85.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsjC83D.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsl19A7.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsl570A.tmp" => File/Directory not found.
C:\Users\Françoise\AppData\Local\nsl76E0.tmp => Moved successfully.
"C:\Users\Françoise\AppData\Local\nsm5819.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsn2300.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsnC48.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nso16B3.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsoEDD6.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsuC72D.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsxDBAD.tmp" => File/Directory not found.
C:\Users\Françoise\AppData\Local\nsy3999.tmp => Moved successfully.
C:\Program Files (x86)\9tres.dll => Moved successfully.
C:\Program Files (x86)\9tUninstall Internet Speed Tracker.dll => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0C399515-1567-4D57-81CD-079D99FFF752}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0C399515-1567-4D57-81CD-079D99FFF752}" => Key deleted successfully.
C:\Windows\System32\Tasks\APSnotifierPP1 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP1" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{12FFAF24-CD9C-44A8-87F3-40B7BD32B842}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{12FFAF24-CD9C-44A8-87F3-40B7BD32B842}" => Key deleted successfully.
C:\Windows\System32\Tasks\t4h2IDlcVS2y0Sr => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\t4h2IDlcVS2y0Sr" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{26E4C186-E388-4729-B0DC-40672FC139FB}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{26E4C186-E388-4729-B0DC-40672FC139FB}" => Key deleted successfully.
C:\Windows\System32\Tasks\APSnotifierPP3 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP3" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2A377C54-9448-48C7-81BC-4F827718F323}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A377C54-9448-48C7-81BC-4F827718F323}" => Key deleted successfully.
C:\Windows\System32\Tasks\{0072C348-C0F5-4690-B9C5-C8B850EAAA95} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0072C348-C0F5-4690-B9C5-C8B850EAAA95}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2A83656A-D193-4CDE-AFD1-3D0F5462B76A}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A83656A-D193-4CDE-AFD1-3D0F5462B76A}" => Key deleted successfully.
C:\Windows\System32\Tasks\S7qLnZDxEjVnWif => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\S7qLnZDxEjVnWif" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2F74EA80-3F09-42F5-BB56-FD6D23201531}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F74EA80-3F09-42F5-BB56-FD6D23201531}" => Key deleted successfully.
C:\Windows\System32\Tasks\APSnotifierPP2 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP2" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{70D31263-C8AA-4F72-94CD-B847C475C5B0}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70D31263-C8AA-4F72-94CD-B847C475C5B0}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\8c6736a2-0446-4148-8f02-ca63eff37ec5-12" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{70EB7038-801D-4629-B59A-F2B52526ACD8}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70EB7038-801D-4629-B59A-F2B52526ACD8}" => Key deleted successfully.
C:\Windows\System32\Tasks\{1393E89C-3D33-423C-BECB-D5548128FBC0} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1393E89C-3D33-423C-BECB-D5548128FBC0}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7904E1AC-513E-4EB8-A318-65389D155BFD}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7904E1AC-513E-4EB8-A318-65389D155BFD}" => Key deleted successfully.
C:\Windows\System32\Tasks\{E3E303C7-214A-4246-8966-F0426841A603} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E3E303C7-214A-4246-8966-F0426841A603}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8255801E-C819-4A83-A3BD-006338DEBEF6}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8255801E-C819-4A83-A3BD-006338DEBEF6}" => Key deleted successfully.
C:\Windows\System32\Tasks\ULNtEsDPMKLzji9 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ULNtEsDPMKLzji9" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{828CA497-D5EC-40F1-82B1-D94654F80D64}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{828CA497-D5EC-40F1-82B1-D94654F80D64}" => Key deleted successfully.
C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SmartWeb Upgrade Trigger Task" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{89431725-61A5-43B7-B149-4F68602D645C}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89431725-61A5-43B7-B149-4F68602D645C}" => Key deleted successfully.
C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSoftwareProtectionPlatform\SvcRestartTask" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8B7A841B-A394-44EA-A832-C8834484C0C3}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8B7A841B-A394-44EA-A832-C8834484C0C3}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\8c6736a2-0446-4148-8f02-ca63eff37ec5-1-7" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8CCE1C4E-E6A6-4004-B556-526E9C1DD61F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8CCE1C4E-E6A6-4004-B556-526E9C1DD61F}" => Key deleted successfully.
C:\Windows\System32\Tasks\Optimizer Pro Schedule not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimizer Pro Schedule" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{924D639B-824C-4387-85D8-6B8F305DD4CD}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{924D639B-824C-4387-85D8-6B8F305DD4CD}" => Key deleted successfully.
C:\Windows\System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{94907B4A-CFE9-4508-B069-BDF1D85BEE81}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{94907B4A-CFE9-4508-B069-BDF1D85BEE81}" => Key deleted successfully.
C:\Windows\System32\Tasks\WIN-statsAdmin => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WIN-statsAdmin" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A269C044-F854-4A64-A9C0-E84F64848B15}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A269C044-F854-4A64-A9C0-E84F64848B15}" => Key deleted successfully.
C:\Windows\System32\Tasks\{9687AFBA-FA57-48A3-90A8-3D61C414676A} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{9687AFBA-FA57-48A3-90A8-3D61C414676A}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A832BAFF-4526-4A32-A841-37226B978D64}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A832BAFF-4526-4A32-A841-37226B978D64}" => Key deleted successfully.
C:\Windows\System32\Tasks\{29DAE379-E7E9-4211-98F1-3C0DF9E21230} not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{29DAE379-E7E9-4211-98F1-3C0DF9E21230}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AE872F99-D435-474D-B58A-D4D2145EF8A9}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AE872F99-D435-474D-B58A-D4D2145EF8A9}" => Key deleted successfully.
C:\Windows\System32\Tasks\WIN-statsSystem => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WIN-statsSystem" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B4F88351-D346-47F7-BF79-FFEA82521039}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B4F88351-D346-47F7-BF79-FFEA82521039}" => Key deleted successfully.
C:\Windows\System32\Tasks\9XGQKw3LInouXt0 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\9XGQKw3LInouXt0" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C2AF11FA-199C-49F3-8234-A42D3EF9F64A}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2AF11FA-199C-49F3-8234-A42D3EF9F64A}" => Key deleted successfully.
C:\Windows\System32\Tasks\{1ED12CDA-49C0-49C3-876E-45DFAE76E072} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1ED12CDA-49C0-49C3-876E-45DFAE76E072}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C3A564F3-F565-444F-B9B9-2C7BE983C80C}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C3A564F3-F565-444F-B9B9-2C7BE983C80C}" => Key deleted successfully.
C:\Windows\System32\Tasks\WIN-GGfIfEGCfEGbGffIfCfEGC => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WIN-GGfIfEGCfEGbGffIfCfEGC" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CE821C2E-F472-4C86-B298-9539C29181B5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE821C2E-F472-4C86-B298-9539C29181B5}" => Key deleted successfully.
C:\Windows\System32\Tasks\OKKFODDR not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OKKFODDR" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E5FBFE04-9BCE-47A6-AB45-41896307775D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E5FBFE04-9BCE-47A6-AB45-41896307775D}" => Key deleted successfully.
C:\Windows\System32\Tasks\{6C6A1B19-AC17-40B1-81FA-F846708DC1B4} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6C6A1B19-AC17-40B1-81FA-F846708DC1B4}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F08FCB6F-1C7C-4618-897D-DCA0C185FF9C}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F08FCB6F-1C7C-4618-897D-DCA0C185FF9C}" => Key deleted successfully.
C:\Windows\System32\Tasks\{A9DA2D5F-CB04-4000-BA22-B132226837FD} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A9DA2D5F-CB04-4000-BA22-B132226837FD}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F486969F-6FE3-4F2B-9DE6-EF16AAA97E54}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F486969F-6FE3-4F2B-9DE6-EF16AAA97E54}" => Key deleted successfully.
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F9283F80-A3F8-43C6-BE94-75A3471EFCC1}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F9283F80-A3F8-43C6-BE94-75A3471EFCC1}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\8c6736a2-0446-4148-8f02-ca63eff37ec5-1-6" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FAEBBC22-5575-45A7-B295-A53013F7C389}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FAEBBC22-5575-45A7-B295-A53013F7C389}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\8c6736a2-0446-4148-8f02-ca63eff37ec5-5" => Key deleted successfully.
C:\Windows\Tasks\APSnotifierPP1.job not found.
C:\Windows\Tasks\APSnotifierPP2.job => Moved successfully.
C:\Windows\Tasks\APSnotifierPP3.job => Moved successfully.
C:\Windows\Tasks\avaavaxvyy.job not found.
C:\Windows\Tasks\Binkiland.job not found.
C:\Windows\Tasks\FDEDZBML.job not found.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job not found.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job not found.
C:\Windows\Tasks\GWEXI.job not found.
C:\Windows\Tasks\LQNCBDR.job not found.
C:\Windows\Tasks\OKPPBAAR.job not found.
C:\Windows\Tasks\ONLLP.job => Moved successfully.
C:\Windows\Tasks\PWKN.job not found.
C:\Windows\Tasks\THULJOON.job not found.
C:\Windows\Tasks\TJYHKE.job not found.
C:\Windows\Tasks\UFQUWS.job => Moved successfully.
C:\Windows\Tasks\User_Feed_Synchronization-{F3D00496-1512-4FEF-A011-C2925A21559B}.job not found.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
Ran by Françoise at 2015-04-05 13:43:53 Run:1
Running from C:\Users\Françoise\Desktop
Loaded Profiles: Françoise (Available profiles: Françoise)
Boot Mode: Normal
==============================================
Content of fixlist:
HKLM-x32\...\Run: [gmsd_fr_340] => [X]
HKLM-x32\...\Run: [gmsd_fr_349] => [X]
HKLM-x32\...\Run: [gmsd_fr_362] => [X]
HKLM-x32\...\Run: [gmsd_fr_364] => C:\Program Files (x86)\gmsd_fr_364\gmsd_fr_364.exe [3983504 2015-03-30] ()
HKLM-x32\...\Run: [gmsd_fr_379] => C:\Program Files (x86)\gmsd_fr_379\gmsd_fr_379.exe [3984016 2015-04-04] ()
HKLM-x32\...\Run: [SmartWeb] => C:\Users\Françoise\AppData\Local\SmartWeb\SmartWebHelper.exe [270368 2015-02-17] (SoftBrain Technologies Ltd.)
HKLM-x32\...\RunOnce: [Ridigefekuke] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\FRANOI~1\AppData\Local\61BF73~1\Cuba.dat"
HKLM-x32\...\RunOnce: [upgmsd_fr_364.exe] => C:\Users\Françoise\AppData\Local\gmsd_fr_364\upgmsd_fr_364.exe [3308688 2015-03-30] ()
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro 3.75\OptProLauncher.exe [148008 2015-03-31] ()
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\...\MountPoints2: {a9835061-5c33-11e4-9a00-80c16e586cac} - G:\LaunchU3.exe
HKU\S-1-5-18\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_16_0_0_287_Plugin.exe -update plugin
AppInit_DLLs-x32: c:/progra~3/{4884a~1/192~1.1/rari.dll => "c:\progra~3\{4884a~1\192~1.1\rari.dll" File Not Found
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
Startup: C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk
ShortcutTarget: hqghumeaylnlf.lnk -> C:\ProgramData\{b24c03f5-2214-6cba-b24c-c03f52210fd4}\hqghumeaylnlf.exe (PC Utilities Software Limited)
Startup: C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk
ShortcutTarget: SmartWeb.lnk -> C:\Users\Françoise\AppData\Local\SmartWeb\SmartWebHelper.exe (SoftBrain Technologies Ltd.)
roxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:57266;https=127.0.0.1:57266
R2 542bb8ed; c:\Program Files (x86)\Optimizer Pro 3.75\OptProMon.dll [2292264 2015-04-04] ()
R2 cicifiso; C:\Users\Françoise\AppData\Roaming\32444335-1427214172-3535-4C39-80C16E586CAC\nsz8ACC.tmp [208384 2015-04-04] () [File not signed]
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158816 2015-03-16] (XTab system)
R2 toqukozi; C:\Users\Françoise\AppData\Roaming\32444335-1424508927-3535-4C39-80C16E586CAC\jnsxBEAE.tmp [90624 2015-02-21] () [File not signed]
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [493712 2015-04-04] (SysTool PasSame LIMITED)
R2 xuhejygu; C:\Users\Françoise\AppData\Roaming\32444335-1427214172-3535-4C39-80C16E586CAC\jnsu55B1.tmp [131584 2015-03-24] () [File not signed]
S2 FlashBeat; C:\ProgramData\FlashBeat\FlashBeat.exe [X]
R2 gusomybu; C:\Users\Françoise\AppData\Roaming\32444335-1424508927-3535-4C39-80C16E586CAC\nsr900.tmpfs [X]
S2 qrsvc_1.10.0.9; "C:\Program Files (x86)\QuickRef_1.10.0.9\Service\qrsvc.exe" [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
FF Extension: linkygemaldk - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\linky@gemal.dk [2014-08-31]
FF Extension: Settings Manager - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7} [2014-05-18]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\boost@boost.net.xpi [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\{8299d9bc-4fe2-4889-9adf-025a0769d461}.xpi [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\idmsq@idmsq.com [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\taylorralston@hotmail.com [Not Found]
FF Extension: No Name - C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.com [Not Found]
2015-04-05 09:14 - 2015-04-05 09:19 - 00002836 _____ () C:\Windows\System32\Tasks\APSnotifierPP1
2015-04-05 09:14 - 2015-04-05 09:19 - 00002834 _____ () C:\Windows\System32\Tasks\APSnotifierPP3
2015-04-05 09:14 - 2015-04-05 09:19 - 00002834 _____ () C:\Windows\System32\Tasks\APSnotifierPP2
2015-04-05 09:14 - 2015-04-05 09:14 - 00001045 _____ () C:\Users\Françoise\Desktop\AnyProtect.lnk
2015-04-05 09:14 - 2015-04-05 09:14 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
2015-04-05 09:13 - 2015-04-05 11:27 - 00000000 ____D () C:\Program Files (x86)\AnyProtectEx
2015-04-05 09:13 - 2015-04-05 09:13 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsjC83D.tmp
2015-04-05 09:13 - 2015-04-05 09:13 - 00000000 __SHD () C:\Users\Françoise\AppData\Roaming\AnyProtectEx
2015-04-05 09:08 - 2015-04-05 11:27 - 00000000 ____D () C:\Users\Françoise\AppData\Local\SmartWeb
2015-04-05 09:08 - 2015-04-05 09:08 - 00004058 _____ () C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task
2015-04-05 09:07 - 2015-04-05 11:27 - 00000000 ____D () C:\Users\Françoise\AppData\Local\gmsd_fr_379
2015-04-05 09:07 - 2015-04-05 09:11 - 00000000 ____D () C:\Program Files (x86)\gmsd_fr_379
2015-04-04 23:44 - 2015-04-04 23:44 - 00000000 ____D () C:\Users\Françoise\SupTab
2015-04-04 23:29 - 2015-04-05 11:10 - 00000000 ____D () C:\Users\Françoise\AppData\Local\gmsd_fr_364
2015-04-04 23:29 - 2015-04-05 08:53 - 00003278 _____ () C:\Windows\System32\Tasks\Optimizer Pro Schedule
2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\Users\Françoise\Documents\Optimizer Pro
2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\Optimizer Pro
2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\Program Files (x86)\gmsd_fr_364
2015-04-04 23:28 - 2015-04-05 08:36 - 00000000 ____D () C:\ProgramData\{b24c03f5-2214-6cba-b24c-c03f52210fd4}
2015-04-04 23:28 - 2015-04-04 23:28 - 00001099 _____ () C:\Users\Françoise\Desktop\Optimizer Pro.lnk
2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro 3.75
2015-04-04 23:27 - 2015-04-05 11:05 - 00000000 ____D () C:\Program Files (x86)\XTab
2015-04-04 23:27 - 2015-04-04 23:27 - 00001101 _____ () C:\Users\Françoise\Desktop\Continue Live Installation.lnk
2015-04-04 23:27 - 2015-04-04 23:27 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2015-04-04 23:27 - 2015-04-04 23:27 - 00000000 ____D () C:\ProgramData\IHProtectUpDate
2015-04-04 23:26 - 2015-04-04 23:26 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\mystartsearch
2015-04-04 20:07 - 2015-04-04 20:07 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl19A7.tmp
2015-04-04 20:06 - 2015-04-05 11:40 - 00026874 _____ () C:\Users\Françoise\Desktop\FRST.txt
2015-04-04 20:06 - 2015-04-04 20:06 - 00000306 _____ () C:\Windows\Tasks\avaavaxvyy.job
2015-04-04 20:05 - 2015-04-05 11:39 - 00000000 ____D () C:\FRST
2015-04-04 20:05 - 2015-04-04 20:05 - 00000000 ____D () C:\Users\Françoise\AppData\Local\avaavaxvyy
2015-04-04 20:01 - 2015-04-04 20:01 - 02095616 _____ (Farbar) C:\Users\Françoise\Desktop\FRST64.exe
2015-04-04 19:02 - 2015-04-04 19:02 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsoEDD6.tmp
2015-04-04 18:59 - 2015-04-04 18:59 - 00000000 ____D () C:\Users\Françoise\AppData\Local\Software
2015-04-04 18:58 - 2015-04-04 18:58 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsxDBAD.tmp
2015-04-04 18:24 - 2015-04-04 23:26 - 00001615 _____ () C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-04 18:24 - 2015-04-04 18:24 - 00000300 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{F3D00496-1512-4FEF-A011-C2925A21559B}.job
2015-04-04 18:24 - 2015-04-04 18:24 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-04 16:27 - 2015-04-04 16:27 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsgEBB7.tmp
2015-04-04 06:55 - 2015-04-04 06:55 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsbFDBE.tmp
2015-04-04 06:54 - 2015-04-04 06:54 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl570A.tmp
2015-04-04 06:52 - 2015-04-04 06:54 - 01950208 _____ () C:\Users\Françoise\AppData\Roaming\GWEXI.exe
2015-04-04 06:52 - 2015-04-04 06:54 - 00001352 _____ () C:\Windows\Tasks\GWEXI.job
2015-04-03 09:32 - 2015-04-03 09:32 - 00000000 ___HD () C:\Users\Françoise\AppData\Local\61bf73677f83230a
2015-04-02 18:09 - 2015-04-02 18:09 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsdFDF0.tmp
2015-03-31 12:01 - 2015-04-05 03:42 - 00000000 ____D () C:\Program Files (x86)\Mountain Bike
2015-03-31 05:19 - 2015-03-31 05:19 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsiDF85.tmp
2015-03-30 10:33 - 2015-03-30 10:33 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsm5819.tmp
2015-03-30 07:23 - 2015-04-05 11:10 - 00000348 _____ () C:\Windows\Tasks\HPCeeScheduleForFrançoise.job
2015-03-30 07:17 - 2015-03-30 07:17 - 00000000 _____ () C:\Windows\SysWOW64\sho148F.tmp
2015-03-29 12:11 - 2015-03-29 12:11 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nso16B3.tmp
2015-03-29 11:57 - 2015-03-29 11:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\1 Media Player
2015-03-29 11:57 - 2015-03-29 11:57 - 00000000 ____D () C:\Program Files (x86)\1 Media Player
2015-03-29 07:38 - 2015-03-29 07:39 - 00914436 _____ () C:\Users\Françoise\Downloads\widget-1-6.zip
2015-03-28 16:36 - 2015-03-28 16:35 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsn2300.tmp
2015-03-28 16:34 - 2015-04-05 03:43 - 00000000 ____D () C:\Program Files (x86)\GoHDV28.03
2015-03-28 16:34 - 2015-03-28 16:34 - 01971200 _____ () C:\Users\Françoise\AppData\Roaming\FDEDZBML.exe
2015-03-28 16:34 - 2015-03-28 16:34 - 00001702 _____ () C:\Windows\Tasks\FDEDZBML.job
2015-03-27 17:05 - 2015-03-27 17:05 - 02250712 _____ (Company Name) C:\Users\Françoise\Downloads\adsl-tv-fm_setup.exe
2015-03-27 10:46 - 2015-03-27 10:46 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsnC48.tmp
2015-03-27 07:30 - 2015-03-27 07:30 - 00003176 _____ () C:\Windows\System32\Tasks\{29DAE379-E7E9-4211-98F1-3C0DF9E21230}
2015-03-26 21:14 - 2015-03-26 21:14 - 00005542 _____ () C:\Users\Françoise\AppData\Roaming\GWEXI
2015-03-26 21:14 - 2015-03-26 21:14 - 00005542 _____ () C:\Users\Françoise\AppData\Roaming\FDEDZBML
2015-03-26 20:50 - 2015-03-26 20:50 - 00000000 ____D () C:\ZombieNews
2015-03-26 20:43 - 2015-03-26 20:43 - 01940992 _____ () C:\Users\Françoise\AppData\Roaming\THULJOON.exe
2015-03-26 20:43 - 2015-03-26 20:43 - 00001702 _____ () C:\Windows\Tasks\THULJOON.job
2015-03-26 20:42 - 2015-03-26 20:42 - 00000000 ____D () C:\Users\Public\Documents\YTAHelper
2015-03-26 20:40 - 2015-03-26 20:40 - 00000000 ____D () C:\Users\Françoise\AppData\Local\CrashRpt
2015-03-26 20:39 - 2015-03-26 20:39 - 01978840 _____ () C:\Users\Françoise\AppData\Roaming\PWKN.exe
2015-03-26 20:39 - 2015-03-26 20:39 - 00613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsuC72D.tmp
2015-03-26 20:39 - 2015-03-26 20:39 - 00001350 _____ () C:\Windows\Tasks\PWKN.job
2015-03-26 20:36 - 2015-03-26 20:36 - 01940992 _____ () C:\Users\Françoise\AppData\Roaming\TJYHKE.exe
2015-03-26 20:36 - 2015-03-26 20:36 - 00001354 _____ () C:\Windows\Tasks\TJYHKE.job
2015-03-26 08:24 - 2015-03-26 08:24 - 00000000 _____ () C:\Users\Françoise\AppData\Local\.w852.db
2015-03-25 08:52 - 2015-03-25 08:52 - 00001103 _____ () C:\Users\Françoise\Downloads\Download-setup.website
2015-03-24 18:38 - 2015-03-24 18:38 - 00001700 _____ () C:\Windows\Tasks\LQNCBDR.job
2015-03-24 18:37 - 2015-03-24 18:37 - 01933824 _____ () C:\Users\Françoise\AppData\Roaming\LQNCBDR.exe
2015-03-24 18:35 - 2015-04-05 03:50 - 00000000 ____D () C:\Users\Françoise\AppData\Local\avaavxvyex
2015-03-24 18:27 - 2015-04-05 11:27 - 00000000 ____D () C:\Users\Françoise\AppData\Local\32444335-1427218036-3535-4C39-80C16E586CAC
2015-03-24 18:26 - 2015-03-24 18:26 - 00003582 _____ () C:\Windows\System32\Tasks\OKKFODDR
2015-03-24 18:26 - 2015-03-24 18:26 - 00001702 _____ () C:\Windows\Tasks\OKPPBAAR.job
2015-03-24 18:26 - 2015-03-24 18:26 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webTinstMKTN_01009.Wdf
2015-03-24 18:26 - 2015-03-24 18:25 - 01933824 _____ () C:\Users\Françoise\AppData\Roaming\OKPPBAAR.exe
2015-03-24 18:25 - 2015-04-05 11:26 - 00000000 ____D () C:\ProgramData\e551e40cdd5e4104afe48d92c795a590
2015-03-24 18:25 - 2015-03-24 18:25 - 00000000 ____D () C:\ProgramData\7fbb4485eae14230b10d76d5ce7f1c83
2015-03-24 18:24 - 2015-03-24 18:24 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\WebplayerRemote
2015-03-24 18:22 - 2015-04-05 10:35 - 00000000 ____D () C:\Users\Françoise\AppData\Roaming\32444335-1427214172-3535-4C39-80C16E586CAC
2015-03-24 18:20 - 2015-04-04 18:22 - 00000000 ____D () C:\Program Files (x86)\CloudScout Parental Control
2015-03-24 18:19 - 2015-03-24 18:19 - 00000000 ____D () C:\d05e7453-6a9e-4756-b897-37340347d5ca
2015-03-23 18:55 - 2015-04-04 15:42 - 00000978 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-03-23 18:55 - 2015-04-04 14:34 - 00000982 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-04-04 15:55 - 2015-03-02 09:55 - 00000306 _____ () C:\Windows\Tasks\Binkiland.job
2015-04-04 15:40 - 2015-01-19 11:23 - 00000000 ____D () C:\Users\Françoise\AppData\Everything
2015-04-04 12:10 - 2014-04-07 20:04 - 00000451 _____ () C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Yahoo!.website
2015-04-05 09:59 - 2014-05-05 06:27 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2015-03-26 21:14 - 2015-03-26 21:14 - 0005542 _____ () C:\Users\Françoise\AppData\Roaming\FDEDZBML
2015-03-28 16:34 - 2015-03-28 16:34 - 1971200 _____ () C:\Users\Françoise\AppData\Roaming\FDEDZBML.exe
2015-03-26 21:14 - 2015-03-26 21:14 - 0005542 _____ () C:\Users\Françoise\AppData\Roaming\GWEXI
2015-04-04 06:52 - 2015-04-04 06:54 - 1950208 _____ () C:\Users\Françoise\AppData\Roaming\GWEXI.exe
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\Françoise\AppData\Roaming\LQNCBDR
2015-03-24 18:37 - 2015-03-24 18:37 - 1933824 _____ () C:\Users\Françoise\AppData\Roaming\LQNCBDR.exe
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\Françoise\AppData\Roaming\OKPPBAAR
2015-03-24 18:26 - 2015-03-24 18:25 - 1933824 _____ () C:\Users\Françoise\AppData\Roaming\OKPPBAAR.exe
2014-09-01 10:18 - 2014-09-01 10:18 - 0001248 _____ () C:\Users\Françoise\AppData\Roaming\ONLLP
2015-01-25 18:12 - 2015-01-25 18:12 - 0001248 _____ () C:\Users\Françoise\AppData\Roaming\PWKN
2015-03-26 20:39 - 2015-03-26 20:39 - 1978840 _____ () C:\Users\Françoise\AppData\Roaming\PWKN.exe
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\Françoise\AppData\Roaming\THULJOON
2015-03-26 20:43 - 2015-03-26 20:43 - 1940992 _____ () C:\Users\Françoise\AppData\Roaming\THULJOON.exe
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\Françoise\AppData\Roaming\TJYHKE
2015-03-26 20:36 - 2015-03-26 20:36 - 1940992 _____ () C:\Users\Françoise\AppData\Roaming\TJYHKE.exe
2014-09-01 10:18 - 2014-09-01 10:18 - 0002086 _____ () C:\Users\Françoise\AppData\Roaming\UFQUWS
2014-12-17 12:12 - 2014-12-17 12:12 - 0022528 _____ () C:\Users\Françoise\AppData\Local\dsisetup13768332.exe
2015-02-23 12:38 - 2015-02-23 12:38 - 0613057 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsb2586.tmp
2015-04-04 06:55 - 2015-04-04 06:55 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsbFDBE.tmp
2015-04-02 18:09 - 2015-04-02 18:09 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsdFDF0.tmp
2015-04-04 16:27 - 2015-04-04 16:27 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsgEBB7.tmp
2014-05-09 18:31 - 2014-05-09 18:31 - 0301488 _____ (VuuPC Limited) C:\Users\Françoise\AppData\Local\nsi1680.tmp
2015-03-31 05:19 - 2015-03-31 05:19 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsiDF85.tmp
2015-04-05 09:13 - 2015-04-05 09:13 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsjC83D.tmp
2015-04-04 20:07 - 2015-04-04 20:07 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl19A7.tmp
2015-04-04 06:54 - 2015-04-04 06:54 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl570A.tmp
2015-02-21 10:49 - 2015-02-21 10:49 - 0613057 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsl76E0.tmp
2015-03-30 10:33 - 2015-03-30 10:33 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsm5819.tmp
2015-03-28 16:36 - 2015-03-28 16:35 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsn2300.tmp
2015-03-27 10:46 - 2015-03-27 10:46 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsnC48.tmp
2015-03-29 12:11 - 2015-03-29 12:11 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nso16B3.tmp
2015-04-04 19:02 - 2015-04-04 19:02 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsoEDD6.tmp
2015-03-26 20:39 - 2015-03-26 20:39 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsuC72D.tmp
2015-04-04 18:58 - 2015-04-04 18:58 - 0613255 _____ (CMI Limited) C:\Users\Françoise\AppData\Local\nsxDBAD.tmp
2014-11-14 08:12 - 2014-11-14 08:12 - 0301608 _____ (VuuPC Limited) C:\Users\Françoise\AppData\Local\nsy3999.tmp
2015-04-04 15:14 - 2015-03-01 15:52 - 0196504 _____ () C:\Program Files (x86)\9tres.dll
2015-04-04 15:14 - 2015-03-01 15:52 - 1037896 _____ () C:\Program Files (x86)\9tUninstall Internet Speed Tracker.dll
Task: {0C399515-1567-4D57-81CD-079D99FFF752} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {12FFAF24-CD9C-44A8-87F3-40B7BD32B842} - System32\Tasks\t4h2IDlcVS2y0Sr => C:\Users\Françoise\AppData\Roaming\jDuSLEf\6O1gHkb.exe
Task: {26E4C186-E388-4729-B0DC-40672FC139FB} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {2A377C54-9448-48C7-81BC-4F827718F323} - System32\Tasks\{0072C348-C0F5-4690-B9C5-C8B850EAAA95} => pcalua.exe -a C:\Users\Françoise\AppData\Roaming\sweet-page\UninstallManager.exe -c -ptid=cor
Task: {2A83656A-D193-4CDE-AFD1-3D0F5462B76A} - System32\Tasks\S7qLnZDxEjVnWif => C:\Users\Françoise\AppData\Roaming\FXOoNoy\eSAjdhI.exe [2015-02-27] ( )
Task: {2F74EA80-3F09-42F5-BB56-FD6D23201531} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {70D31263-C8AA-4F72-94CD-B847C475C5B0} - \8c6736a2-0446-4148-8f02-ca63eff37ec5-12 No Task File <==== ATTENTION
Task: {70EB7038-801D-4629-B59A-F2B52526ACD8} - System32\Tasks\{1393E89C-3D33-423C-BECB-D5548128FBC0} => pcalua.exe -a C:\Users\Françoise\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=adks <==== ATTENTION
Task: {7904E1AC-513E-4EB8-A318-65389D155BFD} - System32\Tasks\{E3E303C7-214A-4246-8966-F0426841A603} => Iexplore.exe http://ui.skype.com/ui/0/5.6.0.110.161/fr/abandoninstall?page=tsDownload&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled
Task: {8255801E-C819-4A83-A3BD-006338DEBEF6} - System32\Tasks\ULNtEsDPMKLzji9 => C:\Users\Françoise\AppData\Roaming\Cpap4wF\gn5Vm4r.exe
Task: {828CA497-D5EC-40F1-82B1-D94654F80D64} - System32\Tasks\SmartWeb Upgrade Trigger Task => C:\Users\Françoise\AppData\Local\SmartWeb\SmartWebHelper.exe [2015-02-17] (SoftBrain Technologies Ltd.) <==== ATTENTION
Task: {89431725-61A5-43B7-B149-4F68602D645C} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {8B7A841B-A394-44EA-A832-C8834484C0C3} - \8c6736a2-0446-4148-8f02-ca63eff37ec5-1-7 No Task File <==== ATTENTION
Task: {8CCE1C4E-E6A6-4004-B556-526E9C1DD61F} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files (x86)\Optimizer Pro 3.75\OptProLauncher.exe [2015-03-31] () <==== ATTENTION
Task: {924D639B-824C-4387-85D8-6B8F305DD4CD} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {94907B4A-CFE9-4508-B069-BDF1D85BEE81} - System32\Tasks\WIN-statsAdmin => C:\Users\Françoise\AppData\Local\Microsoft\WinU\~pqrhxft.exe <==== ATTENTION
Task: {A269C044-F854-4A64-A9C0-E84F64848B15} - System32\Tasks\{9687AFBA-FA57-48A3-90A8-3D61C414676A} => pcalua.exe -a C:\Users\Françoise\AppData\Roaming\qone8\UninstallManager.exe -c -ptid=adks
Task: {A832BAFF-4526-4A32-A841-37226B978D64} - System32\Tasks\{29DAE379-E7E9-4211-98F1-3C0DF9E21230} => pcalua.exe -a C:\Users\Françoise\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=smt
Task: {AE872F99-D435-474D-B58A-D4D2145EF8A9} - System32\Tasks\WIN-statsSystem => C:\Users\Françoise\AppData\Local\Microsoft\WinU\~frodbro.exe
Task: {B4F88351-D346-47F7-BF79-FFEA82521039} - System32\Tasks\9XGQKw3LInouXt0 => C:\Users\Françoise\AppData\Roaming\xmfTvyu\yUAoRwK.exe [2015-02-24] ( )
Task: {C2AF11FA-199C-49F3-8234-A42D3EF9F64A} - System32\Tasks\{1ED12CDA-49C0-49C3-876E-45DFAE76E072} => Firefox.exe
Task: {C3A564F3-F565-444F-B9B9-2C7BE983C80C} - System32\Tasks\WIN-GGfIfEGCfEGbGffIfCfEGC => C:\Users\Françoise\AppData\Roaming\~lbehxzl.exe
Task: {CE821C2E-F472-4C86-B298-9539C29181B5} - System32\Tasks\OKKFODDR => C:\ProgramData\e551e40cdd5e4104afe48d92c795a590\e551e40cdd5e4104afe48d92c795a590.exe
Task: {E5FBFE04-9BCE-47A6-AB45-41896307775D} - System32\Tasks\{6C6A1B19-AC17-40B1-81FA-F846708DC1B4} => Iexplore.exe http://ui.skype.com/ui/0/5.6.0.110.161/fr/abandoninstall?page=tsDownload&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled
Task: {F08FCB6F-1C7C-4618-897D-DCA0C185FF9C} - System32\Tasks\{A9DA2D5F-CB04-4000-BA22-B132226837FD} => Iexplore.exe http://ui.skype.com/ui/0/5.6.0.110.161/fr/abandoninstall?page=tsDownload&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled
Task: {F486969F-6FE3-4F2B-9DE6-EF16AAA97E54} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-04] (Google Inc.)
Task: {F9283F80-A3F8-43C6-BE94-75A3471EFCC1} - \8c6736a2-0446-4148-8f02-ca63eff37ec5-1-6 No Task File <==== ATTENTION
Task: {FAEBBC22-5575-45A7-B295-A53013F7C389} - \8c6736a2-0446-4148-8f02-ca63eff37ec5-5 No Task File <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\avaavaxvyy.job => C:\Users\Françoise\AppData\Local\avaavaxvyy\avaavaxvyy.exe
Task: C:\Windows\Tasks\Binkiland.job => C:\Users\FRANOI~1\AppData\Roaming\BINKIL~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\FDEDZBML.job => C:\Users\Franýÿoise\AppData\Roaming\FDEDZBML.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GWEXI.job => C:\Users\Franýÿoise\AppData\Roaming\GWEXI.exe <==== ATTENTION
Task: C:\Windows\Tasks\LQNCBDR.job => C:\Users\Franýÿoise\AppData\Roaming\LQNCBDR.exe <==== ATTENTION
Task: C:\Windows\Tasks\OKPPBAAR.job => C:\Users\Franýÿoise\AppData\Roaming\OKPPBAAR.exe <==== ATTENTION
Task: C:\Windows\Tasks\ONLLP.job => C:\Users\Franýÿoise\AppData\Roaming\ONLLP.exe <==== ATTENTION
Task: C:\Windows\Tasks\PWKN.job => C:\Users\Franýÿoise\AppData\Roaming\PWKN.exe <==== ATTENTION
Task: C:\Windows\Tasks\THULJOON.job => C:\Users\Franýÿoise\AppData\Roaming\THULJOON.exe <==== ATTENTION
Task: C:\Windows\Tasks\TJYHKE.job => C:\Users\Franýÿoise\AppData\Roaming\TJYHKE.exe <==== ATTENTION
Task: C:\Windows\Tasks\UFQUWS.job => C:\Users\Franýÿoise\AppData\Roaming\UFQUWS.exe <==== ATTENTION
Task: C:\Windows\Tasks\User_Feed_Synchronization-{F3D00496-1512-4FEF-A011-C2925A21559B}.job => C:\Windows\system32\msfeedssync.exe
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_340 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_349 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_362 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_364 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_fr_379 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SmartWeb => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\Ridigefekuke => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\upgmsd_fr_364.exe => value deleted successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui" => Key deleted successfully.
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Optimizer Pro => value deleted successfully.
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableLockWorkstation => value deleted successfully.
HKU\S-1-5-21-805902893-1657446439-1934957100-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableChangePassword => value deleted successfully.
"HKU\S-1-5-21-805902893-1657446439-1934957100-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a9835061-5c33-11e4-9a00-80c16e586cac}" => Key deleted successfully.
HKCR\CLSID\{a9835061-5c33-11e4-9a00-80c16e586cac} => Key not found.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\FlashPlayerUpdate => value deleted successfully.
"c:/progra~3/{4884a~1/192~1.1/rari.dll" => Value Data removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\jumpflip" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\volaro" => Key deleted successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vonteera" => Key deleted successfully.
C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk => Moved successfully.
C:\ProgramData\{b24c03f5-2214-6cba-b24c-c03f52210fd4}\hqghumeaylnlf.exe => Moved successfully.
C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk => Moved successfully.
C:\Users\Françoise\AppData\Local\SmartWeb\SmartWebHelper.exe => Moved successfully.
roxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. => Error: No automatic fix found for this entry.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully.
542bb8ed => Service deleted successfully.
cicifiso => Service stopped successfully.
cicifiso => Service deleted successfully.
IHProtect Service => Service stopped successfully.
IHProtect Service => Service deleted successfully.
toqukozi => Service stopped successfully.
toqukozi => Service deleted successfully.
WindowsMangerProtect => Service stopped successfully.
WindowsMangerProtect => Service deleted successfully.
xuhejygu => Service stopped successfully.
xuhejygu => Service deleted successfully.
FlashBeat => Service deleted successfully.
gusomybu => Service stopped successfully.
gusomybu => Service deleted successfully.
qrsvc_1.10.0.9 => Service deleted successfully.
clwvd => Service deleted successfully.
C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\linky@gemal.dk => Moved successfully.
C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\Extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7} => Moved successfully.
C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\boost@boost.net.xpi not found.
C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\{8299d9bc-4fe2-4889-9adf-025a0769d461}.xpi not found.
C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\idmsq@idmsq.com not found.
C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} not found.
C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\taylorralston@hotmail.com not found.
C:\Users\Françoise\AppData\Roaming\Mozilla\Firefox\Profiles\4xlmdvpw.default\extensions\0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.com not found.
C:\Windows\System32\Tasks\APSnotifierPP1 => Moved successfully.
C:\Windows\System32\Tasks\APSnotifierPP3 => Moved successfully.
C:\Windows\System32\Tasks\APSnotifierPP2 => Moved successfully.
C:\Users\Françoise\Desktop\AnyProtect.lnk => Moved successfully.
C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup => Moved successfully.
C:\Program Files (x86)\AnyProtectEx => Moved successfully.
C:\Users\Françoise\AppData\Local\nsjC83D.tmp => Moved successfully.
C:\Users\Françoise\AppData\Roaming\AnyProtectEx => Moved successfully.
C:\Users\Françoise\AppData\Local\SmartWeb => Moved successfully.
C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task => Moved successfully.
C:\Users\Françoise\AppData\Local\gmsd_fr_379 => Moved successfully.
C:\Program Files (x86)\gmsd_fr_379 => Moved successfully.
C:\Users\Françoise\SupTab => Moved successfully.
C:\Users\Françoise\AppData\Local\gmsd_fr_364 => Moved successfully.
C:\Windows\System32\Tasks\Optimizer Pro Schedule => Moved successfully.
C:\Users\Françoise\Documents\Optimizer Pro => Moved successfully.
C:\Users\Françoise\AppData\Roaming\Optimizer Pro => Moved successfully.
C:\Program Files (x86)\gmsd_fr_364 => Moved successfully.
C:\ProgramData\{b24c03f5-2214-6cba-b24c-c03f52210fd4} => Moved successfully.
C:\Users\Françoise\Desktop\Optimizer Pro.lnk => Moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 => Moved successfully.
C:\Program Files (x86)\Optimizer Pro 3.75 => Moved successfully.
C:\Program Files (x86)\XTab => Moved successfully.
C:\Users\Françoise\Desktop\Continue Live Installation.lnk => Moved successfully.
C:\ProgramData\WindowsMangerProtect => Moved successfully.
C:\ProgramData\IHProtectUpDate => Moved successfully.
C:\Users\Françoise\AppData\Roaming\mystartsearch => Moved successfully.
C:\Users\Françoise\AppData\Local\nsl19A7.tmp => Moved successfully.
C:\Users\Françoise\Desktop\FRST.txt => Moved successfully.
C:\Windows\Tasks\avaavaxvyy.job => Moved successfully.
"C:\FRST" directory move:
Could not move "C:\FRST" directory. => Scheduled to move on reboot.
C:\Users\Françoise\AppData\Local\avaavaxvyy => Moved successfully.
C:\Users\Françoise\Desktop\FRST64.exe => Moved successfully.
C:\Users\Françoise\AppData\Local\nsoEDD6.tmp => Moved successfully.
C:\Users\Françoise\AppData\Local\Software => Moved successfully.
C:\Users\Françoise\AppData\Local\nsxDBAD.tmp => Moved successfully.
C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => Moved successfully.
C:\Windows\Tasks\User_Feed_Synchronization-{F3D00496-1512-4FEF-A011-C2925A21559B}.job => Moved successfully.
C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories => Moved successfully.
C:\Users\Françoise\AppData\Local\nsgEBB7.tmp => Moved successfully.
C:\Users\Françoise\AppData\Local\nsbFDBE.tmp => Moved successfully.
C:\Users\Françoise\AppData\Local\nsl570A.tmp => Moved successfully.
C:\Users\Françoise\AppData\Roaming\GWEXI.exe => Moved successfully.
C:\Windows\Tasks\GWEXI.job => Moved successfully.
C:\Users\Françoise\AppData\Local\61bf73677f83230a => Moved successfully.
C:\Users\Françoise\AppData\Local\nsdFDF0.tmp => Moved successfully.
C:\Program Files (x86)\Mountain Bike => Moved successfully.
C:\Users\Françoise\AppData\Local\nsiDF85.tmp => Moved successfully.
C:\Users\Françoise\AppData\Local\nsm5819.tmp => Moved successfully.
C:\Windows\Tasks\HPCeeScheduleForFrançoise.job => Moved successfully.
C:\Windows\SysWOW64\sho148F.tmp => Moved successfully.
C:\Users\Françoise\AppData\Local\nso16B3.tmp => Moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\1 Media Player => Moved successfully.
C:\Program Files (x86)\1 Media Player => Moved successfully.
C:\Users\Françoise\Downloads\widget-1-6.zip => Moved successfully.
C:\Users\Françoise\AppData\Local\nsn2300.tmp => Moved successfully.
C:\Program Files (x86)\GoHDV28.03 => Moved successfully.
C:\Users\Françoise\AppData\Roaming\FDEDZBML.exe => Moved successfully.
C:\Windows\Tasks\FDEDZBML.job => Moved successfully.
C:\Users\Françoise\Downloads\adsl-tv-fm_setup.exe => Moved successfully.
C:\Users\Françoise\AppData\Local\nsnC48.tmp => Moved successfully.
C:\Windows\System32\Tasks\{29DAE379-E7E9-4211-98F1-3C0DF9E21230} => Moved successfully.
C:\Users\Françoise\AppData\Roaming\GWEXI => Moved successfully.
C:\Users\Françoise\AppData\Roaming\FDEDZBML => Moved successfully.
C:\ZombieNews => Moved successfully.
C:\Users\Françoise\AppData\Roaming\THULJOON.exe => Moved successfully.
C:\Windows\Tasks\THULJOON.job => Moved successfully.
C:\Users\Public\Documents\YTAHelper => Moved successfully.
C:\Users\Françoise\AppData\Local\CrashRpt => Moved successfully.
C:\Users\Françoise\AppData\Roaming\PWKN.exe => Moved successfully.
C:\Users\Françoise\AppData\Local\nsuC72D.tmp => Moved successfully.
C:\Windows\Tasks\PWKN.job => Moved successfully.
C:\Users\Françoise\AppData\Roaming\TJYHKE.exe => Moved successfully.
C:\Windows\Tasks\TJYHKE.job => Moved successfully.
C:\Users\Françoise\AppData\Local\.w852.db => Moved successfully.
C:\Users\Françoise\Downloads\Download-setup.website => Moved successfully.
C:\Windows\Tasks\LQNCBDR.job => Moved successfully.
C:\Users\Françoise\AppData\Roaming\LQNCBDR.exe => Moved successfully.
C:\Users\Françoise\AppData\Local\avaavxvyex => Moved successfully.
C:\Users\Françoise\AppData\Local\32444335-1427218036-3535-4C39-80C16E586CAC => Moved successfully.
C:\Windows\System32\Tasks\OKKFODDR => Moved successfully.
C:\Windows\Tasks\OKPPBAAR.job => Moved successfully.
C:\Windows\system32\Drivers\Msft_Kernel_webTinstMKTN_01009.Wdf => Moved successfully.
C:\Users\Françoise\AppData\Roaming\OKPPBAAR.exe => Moved successfully.
C:\ProgramData\e551e40cdd5e4104afe48d92c795a590 => Moved successfully.
C:\ProgramData\7fbb4485eae14230b10d76d5ce7f1c83 => Moved successfully.
C:\Users\Françoise\AppData\Roaming\WebplayerRemote => Moved successfully.
C:\Users\Françoise\AppData\Roaming\32444335-1427214172-3535-4C39-80C16E586CAC => Moved successfully.
C:\Program Files (x86)\CloudScout Parental Control => Moved successfully.
C:\d05e7453-6a9e-4756-b897-37340347d5ca => Moved successfully.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\Binkiland.job => Moved successfully.
C:\Users\Françoise\AppData\Everything => Moved successfully.
C:\Users\Françoise\AppData\Roaming\Microsoft\Windows\Start Menu\Yahoo!.website => Moved successfully.
C:\Windows\Tasks\APSnotifierPP1.job => Moved successfully.
"C:\Users\Françoise\AppData\Roaming\FDEDZBML" => File/Directory not found.
"C:\Users\Françoise\AppData\Roaming\FDEDZBML.exe" => File/Directory not found.
"C:\Users\Françoise\AppData\Roaming\GWEXI" => File/Directory not found.
"C:\Users\Françoise\AppData\Roaming\GWEXI.exe" => File/Directory not found.
C:\Users\Françoise\AppData\Roaming\LQNCBDR => Moved successfully.
"C:\Users\Françoise\AppData\Roaming\LQNCBDR.exe" => File/Directory not found.
C:\Users\Françoise\AppData\Roaming\OKPPBAAR => Moved successfully.
"C:\Users\Françoise\AppData\Roaming\OKPPBAAR.exe" => File/Directory not found.
C:\Users\Françoise\AppData\Roaming\ONLLP => Moved successfully.
C:\Users\Françoise\AppData\Roaming\PWKN => Moved successfully.
"C:\Users\Françoise\AppData\Roaming\PWKN.exe" => File/Directory not found.
C:\Users\Françoise\AppData\Roaming\THULJOON => Moved successfully.
"C:\Users\Françoise\AppData\Roaming\THULJOON.exe" => File/Directory not found.
C:\Users\Françoise\AppData\Roaming\TJYHKE => Moved successfully.
"C:\Users\Françoise\AppData\Roaming\TJYHKE.exe" => File/Directory not found.
C:\Users\Françoise\AppData\Roaming\UFQUWS => Moved successfully.
C:\Users\Françoise\AppData\Local\dsisetup13768332.exe => Moved successfully.
C:\Users\Françoise\AppData\Local\nsb2586.tmp => Moved successfully.
"C:\Users\Françoise\AppData\Local\nsbFDBE.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsdFDF0.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsgEBB7.tmp" => File/Directory not found.
C:\Users\Françoise\AppData\Local\nsi1680.tmp => Moved successfully.
"C:\Users\Françoise\AppData\Local\nsiDF85.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsjC83D.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsl19A7.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsl570A.tmp" => File/Directory not found.
C:\Users\Françoise\AppData\Local\nsl76E0.tmp => Moved successfully.
"C:\Users\Françoise\AppData\Local\nsm5819.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsn2300.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsnC48.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nso16B3.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsoEDD6.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsuC72D.tmp" => File/Directory not found.
"C:\Users\Françoise\AppData\Local\nsxDBAD.tmp" => File/Directory not found.
C:\Users\Françoise\AppData\Local\nsy3999.tmp => Moved successfully.
C:\Program Files (x86)\9tres.dll => Moved successfully.
C:\Program Files (x86)\9tUninstall Internet Speed Tracker.dll => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0C399515-1567-4D57-81CD-079D99FFF752}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0C399515-1567-4D57-81CD-079D99FFF752}" => Key deleted successfully.
C:\Windows\System32\Tasks\APSnotifierPP1 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP1" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{12FFAF24-CD9C-44A8-87F3-40B7BD32B842}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{12FFAF24-CD9C-44A8-87F3-40B7BD32B842}" => Key deleted successfully.
C:\Windows\System32\Tasks\t4h2IDlcVS2y0Sr => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\t4h2IDlcVS2y0Sr" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{26E4C186-E388-4729-B0DC-40672FC139FB}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{26E4C186-E388-4729-B0DC-40672FC139FB}" => Key deleted successfully.
C:\Windows\System32\Tasks\APSnotifierPP3 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP3" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2A377C54-9448-48C7-81BC-4F827718F323}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A377C54-9448-48C7-81BC-4F827718F323}" => Key deleted successfully.
C:\Windows\System32\Tasks\{0072C348-C0F5-4690-B9C5-C8B850EAAA95} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0072C348-C0F5-4690-B9C5-C8B850EAAA95}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2A83656A-D193-4CDE-AFD1-3D0F5462B76A}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A83656A-D193-4CDE-AFD1-3D0F5462B76A}" => Key deleted successfully.
C:\Windows\System32\Tasks\S7qLnZDxEjVnWif => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\S7qLnZDxEjVnWif" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2F74EA80-3F09-42F5-BB56-FD6D23201531}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F74EA80-3F09-42F5-BB56-FD6D23201531}" => Key deleted successfully.
C:\Windows\System32\Tasks\APSnotifierPP2 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP2" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{70D31263-C8AA-4F72-94CD-B847C475C5B0}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70D31263-C8AA-4F72-94CD-B847C475C5B0}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\8c6736a2-0446-4148-8f02-ca63eff37ec5-12" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{70EB7038-801D-4629-B59A-F2B52526ACD8}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70EB7038-801D-4629-B59A-F2B52526ACD8}" => Key deleted successfully.
C:\Windows\System32\Tasks\{1393E89C-3D33-423C-BECB-D5548128FBC0} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1393E89C-3D33-423C-BECB-D5548128FBC0}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7904E1AC-513E-4EB8-A318-65389D155BFD}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7904E1AC-513E-4EB8-A318-65389D155BFD}" => Key deleted successfully.
C:\Windows\System32\Tasks\{E3E303C7-214A-4246-8966-F0426841A603} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E3E303C7-214A-4246-8966-F0426841A603}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8255801E-C819-4A83-A3BD-006338DEBEF6}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8255801E-C819-4A83-A3BD-006338DEBEF6}" => Key deleted successfully.
C:\Windows\System32\Tasks\ULNtEsDPMKLzji9 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ULNtEsDPMKLzji9" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{828CA497-D5EC-40F1-82B1-D94654F80D64}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{828CA497-D5EC-40F1-82B1-D94654F80D64}" => Key deleted successfully.
C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SmartWeb Upgrade Trigger Task" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{89431725-61A5-43B7-B149-4F68602D645C}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89431725-61A5-43B7-B149-4F68602D645C}" => Key deleted successfully.
C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSoftwareProtectionPlatform\SvcRestartTask" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8B7A841B-A394-44EA-A832-C8834484C0C3}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8B7A841B-A394-44EA-A832-C8834484C0C3}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\8c6736a2-0446-4148-8f02-ca63eff37ec5-1-7" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8CCE1C4E-E6A6-4004-B556-526E9C1DD61F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8CCE1C4E-E6A6-4004-B556-526E9C1DD61F}" => Key deleted successfully.
C:\Windows\System32\Tasks\Optimizer Pro Schedule not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimizer Pro Schedule" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{924D639B-824C-4387-85D8-6B8F305DD4CD}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{924D639B-824C-4387-85D8-6B8F305DD4CD}" => Key deleted successfully.
C:\Windows\System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{94907B4A-CFE9-4508-B069-BDF1D85BEE81}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{94907B4A-CFE9-4508-B069-BDF1D85BEE81}" => Key deleted successfully.
C:\Windows\System32\Tasks\WIN-statsAdmin => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WIN-statsAdmin" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A269C044-F854-4A64-A9C0-E84F64848B15}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A269C044-F854-4A64-A9C0-E84F64848B15}" => Key deleted successfully.
C:\Windows\System32\Tasks\{9687AFBA-FA57-48A3-90A8-3D61C414676A} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{9687AFBA-FA57-48A3-90A8-3D61C414676A}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A832BAFF-4526-4A32-A841-37226B978D64}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A832BAFF-4526-4A32-A841-37226B978D64}" => Key deleted successfully.
C:\Windows\System32\Tasks\{29DAE379-E7E9-4211-98F1-3C0DF9E21230} not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{29DAE379-E7E9-4211-98F1-3C0DF9E21230}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AE872F99-D435-474D-B58A-D4D2145EF8A9}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AE872F99-D435-474D-B58A-D4D2145EF8A9}" => Key deleted successfully.
C:\Windows\System32\Tasks\WIN-statsSystem => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WIN-statsSystem" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B4F88351-D346-47F7-BF79-FFEA82521039}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B4F88351-D346-47F7-BF79-FFEA82521039}" => Key deleted successfully.
C:\Windows\System32\Tasks\9XGQKw3LInouXt0 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\9XGQKw3LInouXt0" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C2AF11FA-199C-49F3-8234-A42D3EF9F64A}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2AF11FA-199C-49F3-8234-A42D3EF9F64A}" => Key deleted successfully.
C:\Windows\System32\Tasks\{1ED12CDA-49C0-49C3-876E-45DFAE76E072} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1ED12CDA-49C0-49C3-876E-45DFAE76E072}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C3A564F3-F565-444F-B9B9-2C7BE983C80C}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C3A564F3-F565-444F-B9B9-2C7BE983C80C}" => Key deleted successfully.
C:\Windows\System32\Tasks\WIN-GGfIfEGCfEGbGffIfCfEGC => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WIN-GGfIfEGCfEGbGffIfCfEGC" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CE821C2E-F472-4C86-B298-9539C29181B5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CE821C2E-F472-4C86-B298-9539C29181B5}" => Key deleted successfully.
C:\Windows\System32\Tasks\OKKFODDR not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OKKFODDR" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E5FBFE04-9BCE-47A6-AB45-41896307775D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E5FBFE04-9BCE-47A6-AB45-41896307775D}" => Key deleted successfully.
C:\Windows\System32\Tasks\{6C6A1B19-AC17-40B1-81FA-F846708DC1B4} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6C6A1B19-AC17-40B1-81FA-F846708DC1B4}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F08FCB6F-1C7C-4618-897D-DCA0C185FF9C}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F08FCB6F-1C7C-4618-897D-DCA0C185FF9C}" => Key deleted successfully.
C:\Windows\System32\Tasks\{A9DA2D5F-CB04-4000-BA22-B132226837FD} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A9DA2D5F-CB04-4000-BA22-B132226837FD}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F486969F-6FE3-4F2B-9DE6-EF16AAA97E54}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F486969F-6FE3-4F2B-9DE6-EF16AAA97E54}" => Key deleted successfully.
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F9283F80-A3F8-43C6-BE94-75A3471EFCC1}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F9283F80-A3F8-43C6-BE94-75A3471EFCC1}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\8c6736a2-0446-4148-8f02-ca63eff37ec5-1-6" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FAEBBC22-5575-45A7-B295-A53013F7C389}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FAEBBC22-5575-45A7-B295-A53013F7C389}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\8c6736a2-0446-4148-8f02-ca63eff37ec5-5" => Key deleted successfully.
C:\Windows\Tasks\APSnotifierPP1.job not found.
C:\Windows\Tasks\APSnotifierPP2.job => Moved successfully.
C:\Windows\Tasks\APSnotifierPP3.job => Moved successfully.
C:\Windows\Tasks\avaavaxvyy.job not found.
C:\Windows\Tasks\Binkiland.job not found.
C:\Windows\Tasks\FDEDZBML.job not found.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job not found.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job not found.
C:\Windows\Tasks\GWEXI.job not found.
C:\Windows\Tasks\LQNCBDR.job not found.
C:\Windows\Tasks\OKPPBAAR.job not found.
C:\Windows\Tasks\ONLLP.job => Moved successfully.
C:\Windows\Tasks\PWKN.job not found.
C:\Windows\Tasks\THULJOON.job not found.
C:\Windows\Tasks\TJYHKE.job not found.
C:\Windows\Tasks\UFQUWS.job => Moved successfully.
C:\Windows\Tasks\User_Feed_Synchronization-{F3D00496-1512-4FEF-A011-C2925A21559B}.job not found.
Ouf!! Ci-dessous le lien du rapport roguekiller
http://pjjoint.malekal.com/files.php?id=20150405_m12s9q10s1113
http://pjjoint.malekal.com/files.php?id=20150405_m12s9q10s1113
On a fait un grand pas en avant, il reste deux raccourcis qui à l'ouverture de la page internet annonce qu'un site web veut ouvrir un contenu web en utilisant ce programme sur l'ordi : AcroRd32.exe, éditeur adobe système. Je ne sais pas si il faut autoriser ou pas ?
Un grand merci, déjà pour tout le temps que tu m'as accordé.
Mes beaux parents vont être contents. Après je ne sais pas pour combien de temps le PC va rester dans cet état!
Un grand merci, déjà pour tout le temps que tu m'as accordé.
Mes beaux parents vont être contents. Après je ne sais pas pour combien de temps le PC va rester dans cet état!
Super, un très grand merci. Pour finir quelues conseils pour protéger la navigation : mes beaux parents arrivent dans les 70 ans et ils ont le clique facile!
Mets leur blockulicious et imprime leur le dossier.
Ca devrait limiter la casse =)
Quelques conseils :
Pour prévenir les sites malicieux, tu peux installer Blockulicious : https://forum.malekal.com/viewtopic.php?t=46656&start=
Pour ne plus te faire avoir.
A lire - Programmes parasites / PUPs : https://www.malekal.com/adwares-pup-protection/
Le reste de la sécurité : http://forum.malekal.com/comment-securiser-son-ordinateur.html
Ca devrait limiter la casse =)
Quelques conseils :
Pour prévenir les sites malicieux, tu peux installer Blockulicious : https://forum.malekal.com/viewtopic.php?t=46656&start=
Pour ne plus te faire avoir.
A lire - Programmes parasites / PUPs : https://www.malekal.com/adwares-pup-protection/
Le reste de la sécurité : http://forum.malekal.com/comment-securiser-son-ordinateur.html