Auteur Sujet: "résolu"Suprimé Shearch protect  (Lu 24509 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23
"résolu"Suprimé Shearch protect
« le: octobre 28, 2013, 08:30:28 »
Bonjour, j'ai vue qu'il y avais déjà plusieurs sujet dans mon cas le problème c'est que je comprend pas grand choses il y a trop de mots pourriez vous m'aidé a le supprimé s'il vous plait
« Modifié: octobre 28, 2013, 17:34:41 par Anti-Virus59 »

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : Suprimé Shearch protect
« Réponse #1 le: octobre 28, 2013, 09:53:46 »
Bonjour Anti-Virus59,

Bienvenue sur Security-X,

Nous allons voir ensemble pour supprimer cet adware (logiciel publicitaire).
N'hésite à me demander avant d'effectuer une procédure si tu ne comprends pas une étape.


Télécharge Farbar Recovery Scan Tool (de Farbar) sur ton Bureau.

Attention: Tu dois lancer la version compatible avec votre système : 32 ou  64bits.

Sous IE9 ou IE10, le filtre SmartScreen déclenche une alerte. Cliquer sur Actions puis sur Exécuter quand même

  • Double-clique sur l'outil pour le lancer. Quand l'outil se lance, clique sur Yes pour accepter le disclamer.
  • Clique sur le bouton  Scan.
  • L'outil va créer un rapport nommé FRST.txt, enregistré dans le même dossier que l'outil.
  • A son premier lancement, l'outil va aussi créer un fichier nommé Addition.txt).
Poste les deux rapports générés.


Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23
Re : Suprimé Shearch protect
« Réponse #2 le: octobre 28, 2013, 10:07:17 »
d'accord je fait sa merci

Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23
Re : Suprimé Shearch protect
« Réponse #3 le: octobre 28, 2013, 10:14:06 »
Re , sa ma ouvert 2 bloc note

Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23
Re : Suprimé Shearch protect
« Réponse #4 le: octobre 28, 2013, 10:21:38 »
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-10-2013
Ran by Sam (administrator) on SAMY-PC on 28-10-2013 10:10:33
Running from C:\Users\Sam\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: French Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(CybelSoft) C:\Program Files\ma-config.com\MaConfigAgent.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\system32\AUDIODG.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968 2013-05-09] (AVAST Software)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-11-19] (Intel Corporation)
HKU\samy\...\Run: [Google Update] - C:\Users\samy\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-23] (Google Inc.)
HKU\samy\...\Run: [Facebook Update] - "C:\Users\samy\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://fr.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xDB1A1A5332B6CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr-FR
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.0.254

Chrome:
=======
CHR HomePage: hxxp://google.fr/
CHR RestoreOnStartup: "hxxp://search.conduit.com/?ctid=CT3310431&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP123754D7-6FAB-4B48-8629-D6E7B9FA51D0", "hxxp://www.google.com"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Extension: (Louis Vuitton Theme) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\ampkblmfophkabknplblgihaopmbcohf\1_0
CHR Extension: (Forge of Empires) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\anaphblkfplenhkephgneolhnmjminjg\1.2_0
CHR Extension: (Google Docs) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (The Simpsons) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\bboefnjcaohhhhlhomlmioccafmnknjm\1_0
CHR Extension: (American Racing 2 3D) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfpfdjclhabpjncikdngdoldjjjegnbe\2.1.2_0
CHR Extension: (YouTube) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Adblock Plus) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.6.1_0
CHR Extension: (Google Search) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (avast! Antivirus Theme) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\dppfpeoljbekcggiholmckbfccdgaeke\1.5_0
CHR Extension: (Infectonator 1) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\eclfcmjimeibidjckfnkpgbgijchepff\1.0.17.0_0
CHR Extension: (PanicButton) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\faminaibgiklngmfpfbhmokfmnglamcm\0.14.2.2_0
CHR Extension: (AdBlock) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.10_0
CHR Extension: (Apple Shooting) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjkgoneongcjgidecceapgdmibblfijp\1.0.1_0
CHR Extension: (avast! Online Security) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2005.45_0
CHR Extension: (Lord of Ultima) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdheeblenjmceeppomdgokgilmkonced\1.0.12_0
CHR Extension: (Green Farm) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbgdenhobifcbckaiohandoodkepleif\2.1.7.8_0
CHR Extension: (Grepolis) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkgkognjknhcgbgbeijjondlikfkgnog\2.11.14_0
CHR Extension: (Dragon Ball Z mmorpg game !) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\kljhjkncoceojjbadalclgdinmijjien\1.1_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (Google Quick Scroll) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\okanipcmceoeemlbjnmnbdibhgpbllgc\2.1.2_0
CHR Extension: (TV France - Regarder T\u00E9l\u00E9vision) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbchiajonfncphfgplcmdojihhlbffbd\2.2_0
CHR Extension: (Gmail) - C:\Users\Sam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
R2 MaConfigAgent; C:\Program Files\ma-config.com\MaConfigAgent.exe [2542416 2013-10-04] (CybelSoft)
S3 npggsvc; C:\Windows\SysWow64\GameMon.des [3975544 2012-05-09] (INCA Internet Co., Ltd.)

==================== Drivers (Whitelisted) ====================

R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-09] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-09] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-08-09] ()
S3 driverhardwarev2x64; C:\Program Files\ma-config.com\Drivers\driverhardwarev2x64.sys [16640 2011-07-21] (CybelSoft)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28216 2012-11-19] (Intel Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-10-28 10:09 - 2013-10-28 10:09 - 00000000 ____D C:\FRST
2013-10-28 10:06 - 2013-10-28 10:06 - 00359085 _____ (Farbar) C:\Users\Sam\Desktop\FSS.exe
2013-10-28 10:05 - 2013-10-28 10:07 - 01956538 _____ (Farbar) C:\Users\Sam\Desktop\FRST64.exe
2013-10-28 08:17 - 2013-10-28 08:17 - 00058016 _____ C:\Users\Sam\AppData\Local\GDIPFONTCACHEV1.DAT
2013-10-28 08:15 - 2013-10-28 08:15 - 00000056 _____ C:\Windows\setupact.log
2013-10-28 08:15 - 2013-10-28 08:15 - 00000000 _____ C:\Windows\setuperr.log
2013-10-28 08:14 - 2013-10-28 08:14 - 00275856 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-27 20:57 - 2013-10-27 21:05 - 00000000 ____D C:\3590F75ABA9E485486C100C1A9D4FF06ZZZZZ...ZZZZ..ZZ
2013-10-27 19:52 - 2013-10-27 20:06 - 00000000 ____D C:\AdwCleaner
2013-10-27 19:51 - 2013-10-27 19:52 - 01060070 _____ C:\Users\Sam\Downloads\adwcleaner.exe
2013-10-27 07:01 - 2013-10-27 07:02 - 00000000 ____D C:\Users\Sam\Desktop\Nouveau dossier
2013-10-22 10:57 - 2013-10-22 10:57 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2013-10-22 10:56 - 2013-10-22 10:56 - 00000000 ____D C:\Program Files\Synaptics
2013-10-22 10:34 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-22 10:34 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-22 10:34 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-22 10:34 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-22 10:34 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-22 10:34 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-10-22 10:34 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-22 09:58 - 2013-10-27 19:55 - 00000000 ____D C:\3590F75ABA9E485486C100C1A9D4FF06Z...ZZZZ.....ZZZ
2013-10-22 02:18 - 2013-10-24 06:36 - 00000008 _____ C:\Users\Sam\AppData\Roaming\DofusAppId0_6
2013-10-22 02:18 - 2013-10-22 02:18 - 00000000 ____D C:\Users\Sam\AppData\Roaming\Dofus-6
2013-10-20 19:05 - 2013-10-20 19:05 - 00003128 _____ C:\Windows\System32\Tasks\{B790A1AA-CB84-4B3E-BC2C-A29EC3F56261}
2013-10-19 12:47 - 2013-10-19 12:49 - 00000000 ____D C:\Users\Sam\AppData\Roaming\PhotoFiltre
2013-10-18 22:27 - 2013-10-18 22:27 - 01578974 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-10-18 22:27 - 2013-10-18 22:27 - 00000000 ____D C:\Users\Sam\AppData\Roaming\Intel Corporation
2013-10-18 22:22 - 2013-10-18 22:22 - 00014004 _____ C:\Windows\system32\results.xml
2013-10-18 22:16 - 2013-10-18 22:16 - 00003130 _____ C:\Windows\System32\Tasks\{C3CF9C3D-C954-4D34-A607-7F1A9B475C52}
2013-10-18 22:13 - 2013-10-18 22:13 - 00000000 ____D C:\Program Files (x86)\Cisco
2013-10-18 22:12 - 2013-10-18 22:13 - 00000000 ____D C:\Program Files (x86)\REALTEK PCIE Wireless LAN Driver
2013-10-18 22:12 - 2010-12-01 08:31 - 00451072 _____ C:\Windows\SysWOW64\ISSRemoveSP.exe
2013-10-18 22:11 - 2013-10-18 22:11 - 00000000 ____D C:\Windows\SysWOW64\sda
2013-10-18 22:11 - 2013-10-18 22:10 - 09889352 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RtsUStoricon.dll
2013-10-18 22:11 - 2013-10-18 22:10 - 00263896 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RtsUStor.sys
2013-10-18 22:09 - 2013-10-18 22:09 - 00000000 ____D C:\Users\Sam\AppData\Roaming\InstallShield
2013-10-18 22:09 - 2012-11-19 11:10 - 00652344 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorA.sys
2013-10-18 22:09 - 2012-11-19 11:10 - 00028216 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorF.sys
2013-10-18 22:07 - 2013-10-18 22:12 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-18 22:07 - 2013-10-18 22:11 - 00000000 ____D C:\Program Files (x86)\Realtek
2013-10-18 22:07 - 2013-10-18 22:06 - 00872152 _____ (Realtek                                            ) C:\Windows\system32\Drivers\Rt64win7.sys
2013-10-18 22:07 - 2013-10-18 22:06 - 00108760 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
2013-10-18 22:07 - 2013-10-18 22:06 - 00074456 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2013-10-18 22:06 - 2013-10-18 22:15 - 00000000 ____D C:\Program Files (x86)\Intel
2013-10-18 21:54 - 2013-10-18 22:04 - 00000000 ____D C:\Intel
2013-10-18 21:53 - 2013-10-18 21:53 - 00000000 ____D C:\ProgramData\ma-config.com
2013-10-18 21:53 - 2013-10-18 21:53 - 00000000 ____D C:\Program Files\ma-config.com
2013-10-18 07:01 - 2013-10-27 19:10 - 00000008 _____ C:\Users\Sam\AppData\Roaming\DofusAppId0_5
2013-10-18 07:01 - 2013-10-18 07:01 - 00000000 ____D C:\Users\Sam\AppData\Roaming\Dofus-5
2013-10-18 05:32 - 2013-10-18 05:32 - 00001066 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-10-18 05:26 - 2013-10-18 05:26 - 00002768 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-10-18 05:26 - 2013-10-18 05:26 - 00000000 ____D C:\Program Files\CCleaner
2013-10-18 05:07 - 2013-10-18 05:07 - 00000000 ____D C:\ProgramData\Oracle
2013-10-18 05:04 - 2013-10-08 06:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-18 05:04 - 2013-10-08 06:46 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-18 05:04 - 2013-10-08 06:46 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-18 05:04 - 2013-10-08 06:46 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-18 05:02 - 2013-10-18 05:04 - 00004869 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-18 03:54 - 2013-10-27 19:31 - 00000000 ____D C:\Users\Sam\AppData\Roaming\uTorrent
2013-10-11 14:36 - 2013-10-11 14:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2013-10-11 03:49 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-11 03:49 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-11 03:49 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-11 03:49 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-11 03:49 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-11 03:49 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-11 03:49 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-11 03:49 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-11 03:49 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-11 03:49 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-10-11 03:49 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-10-11 03:49 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-11 03:49 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-10-11 03:49 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-11 03:49 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-11 03:49 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-11 03:49 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-11 03:49 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-11 03:49 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-11 03:49 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-11 03:49 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-11 03:49 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-11 03:49 - 2013-09-22 23:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-11 03:49 - 2013-09-22 23:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-11 03:49 - 2013-09-22 23:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-11 03:49 - 2013-09-22 23:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-11 03:49 - 2013-09-22 23:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-11 03:49 - 2013-09-21 04:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-11 03:49 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-11 03:49 - 2013-09-21 03:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-11 03:49 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-10-10 22:00 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-10 22:00 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-10 22:00 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 22:00 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 22:00 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2013-10-10 22:00 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-10 22:00 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-10 22:00 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-10 22:00 - 2013-07-03 05:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2013-10-10 22:00 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-10 22:00 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-10 22:00 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-10 22:00 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-10 22:00 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-10 22:00 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-10 22:00 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-10 22:00 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-10 22:00 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-10 22:00 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-10 22:00 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-10 22:00 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-10 22:00 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-10 05:38 - 2013-08-09 04:49 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-10-10 05:38 - 2013-08-09 04:47 - 00000000 ____D C:\ProgramData\AVAST Software
2013-10-10 05:38 - 2013-05-09 09:58 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-10-10 05:38 - 2012-07-03 17:21 - 00227648 _____ (AVAST Software) C:\Windows\SysWOW64\aswBoot.exe
2013-10-07 21:01 - 2013-10-07 21:01 - 00000000 ____D C:\Users\samy\AppData\Local\Mozilla
2013-10-07 21:00 - 2013-10-07 21:00 - 00000000 ____D C:\ProgramData\Mozilla
2013-10-04 21:11 - 2013-10-04 23:34 - 00000000 ____D C:\Users\Sam\AppData\Roaming\Audacity
2013-10-04 20:17 - 2013-10-04 20:17 - 00000000 ____D C:\Users\Sam\AppData\Local\Macromedia
2013-10-04 12:53 - 2013-10-04 12:53 - 00000000 ____D C:\Users\samy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dofus2
2013-10-04 12:39 - 2013-10-04 12:45 - 00000008 _____ C:\Users\samy\AppData\Roaming\DofusAppId0_5
2013-10-04 12:39 - 2013-10-04 12:39 - 00000000 ____D C:\Users\samy\AppData\Roaming\Dofus-5.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
2013-10-01 14:09 - 2013-10-11 03:41 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

==================== One Month Modified Files and Folders =======

2013-10-28 10:11 - 2013-09-14 07:50 - 00001062 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-28 10:09 - 2013-10-28 10:09 - 00000000 ____D C:\FRST
2013-10-28 10:07 - 2013-10-28 10:05 - 01956538 _____ (Farbar) C:\Users\Sam\Desktop\FRST64.exe
2013-10-28 10:07 - 2013-09-11 10:50 - 00000008 _____ C:\Users\Sam\AppData\Roaming\DofusAppId0_1
2013-10-28 10:06 - 2013-10-28 10:06 - 00359085 _____ (Farbar) C:\Users\Sam\Desktop\FSS.exe
2013-10-28 09:53 - 2013-08-16 13:51 - 00001002 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-28 09:21 - 2012-07-23 22:17 - 00001074 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-894156157-116399700-3295306825-1000UA.job
2013-10-28 09:10 - 2013-09-11 10:50 - 00000000 ____D C:\Users\Sam\AppData\Roaming\Dofus2
2013-10-28 08:31 - 2013-09-11 10:50 - 00000109 _____ C:\Users\Sam\AppData\Roaming\D2Info0
2013-10-28 08:21 - 2009-07-14 16:24 - 00705768 _____ C:\Windows\system32\perfh00C.dat
2013-10-28 08:21 - 2009-07-14 16:24 - 00131540 _____ C:\Windows\system32\perfc00C.dat
2013-10-28 08:21 - 2009-07-14 06:13 - 01553430 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-28 08:19 - 2012-07-23 21:54 - 01621811 _____ C:\Windows\WindowsUpdate.log
2013-10-28 08:17 - 2013-10-28 08:17 - 00058016 _____ C:\Users\Sam\AppData\Local\GDIPFONTCACHEV1.DAT
2013-10-28 08:17 - 2013-08-09 04:49 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-10-28 08:15 - 2013-10-28 08:15 - 00000056 _____ C:\Windows\setupact.log
2013-10-28 08:15 - 2013-10-28 08:15 - 00000000 _____ C:\Windows\setuperr.log
2013-10-28 08:15 - 2013-09-14 07:50 - 00001058 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-28 08:15 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-28 08:14 - 2013-10-28 08:14 - 00275856 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-27 21:05 - 2013-10-27 20:57 - 00000000 ____D C:\3590F75ABA9E485486C100C1A9D4FF06ZZZZZ...ZZZZ..ZZ
2013-10-27 20:06 - 2013-10-27 19:52 - 00000000 ____D C:\AdwCleaner
2013-10-27 19:55 - 2013-10-22 09:58 - 00000000 ____D C:\3590F75ABA9E485486C100C1A9D4FF06Z...ZZZZ.....ZZZ
2013-10-27 19:52 - 2013-10-27 19:51 - 01060070 _____ C:\Users\Sam\Downloads\adwcleaner.exe
2013-10-27 19:31 - 2013-10-18 03:54 - 00000000 ____D C:\Users\Sam\AppData\Roaming\uTorrent
2013-10-27 19:10 - 2013-10-18 07:01 - 00000008 _____ C:\Users\Sam\AppData\Roaming\DofusAppId0_5
2013-10-27 17:59 - 2009-07-14 05:45 - 00023408 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-27 17:59 - 2009-07-14 05:45 - 00023408 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-27 10:20 - 2013-09-13 15:55 - 00000000 ____D C:\Users\Sam\AppData\Roaming\vlc
2013-10-27 07:02 - 2013-10-27 07:01 - 00000000 ____D C:\Users\Sam\Desktop\Nouveau dossier
2013-10-26 15:17 - 2013-09-11 16:07 - 00000008 _____ C:\Users\Sam\AppData\Roaming\DofusAppId0_2
2013-10-26 15:16 - 2013-09-21 12:15 - 00000008 _____ C:\Users\Sam\AppData\Roaming\DofusAppId0_4
2013-10-26 15:15 - 2013-09-13 15:03 - 00000008 _____ C:\Users\Sam\AppData\Roaming\DofusAppId0_3
2013-10-24 06:36 - 2013-10-22 02:18 - 00000008 _____ C:\Users\Sam\AppData\Roaming\DofusAppId0_6
2013-10-22 10:57 - 2013-10-22 10:57 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2013-10-22 10:56 - 2013-10-22 10:56 - 00000000 ____D C:\Program Files\Synaptics
2013-10-22 02:18 - 2013-10-22 02:18 - 00000000 ____D C:\Users\Sam\AppData\Roaming\Dofus-6
2013-10-21 23:21 - 2012-07-23 22:17 - 00001022 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-894156157-116399700-3295306825-1000Core.job
2013-10-20 19:05 - 2013-10-20 19:05 - 00003128 _____ C:\Windows\System32\Tasks\{B790A1AA-CB84-4B3E-BC2C-A29EC3F56261}
2013-10-19 12:49 - 2013-10-19 12:47 - 00000000 ____D C:\Users\Sam\AppData\Roaming\PhotoFiltre
2013-10-18 22:27 - 2013-10-18 22:27 - 01578974 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-10-18 22:27 - 2013-10-18 22:27 - 00000000 ____D C:\Users\Sam\AppData\Roaming\Intel Corporation
2013-10-18 22:22 - 2013-10-18 22:22 - 00014004 _____ C:\Windows\system32\results.xml
2013-10-18 22:16 - 2013-10-18 22:16 - 00003130 _____ C:\Windows\System32\Tasks\{C3CF9C3D-C954-4D34-A607-7F1A9B475C52}
2013-10-18 22:15 - 2013-10-18 22:06 - 00000000 ____D C:\Program Files (x86)\Intel
2013-10-18 22:13 - 2013-10-18 22:13 - 00000000 ____D C:\Program Files (x86)\Cisco
2013-10-18 22:13 - 2013-10-18 22:12 - 00000000 ____D C:\Program Files (x86)\REALTEK PCIE Wireless LAN Driver
2013-10-18 22:12 - 2013-10-18 22:07 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-18 22:12 - 2011-09-08 00:46 - 01226344 _____ (Realtek Semiconductor Corporation                           ) C:\Windows\system32\Drivers\rtl8192se.sys
2013-10-18 22:11 - 2013-10-18 22:11 - 00000000 ____D C:\Windows\SysWOW64\sda
2013-10-18 22:11 - 2013-10-18 22:07 - 00000000 ____D C:\Program Files (x86)\Realtek
2013-10-18 22:10 - 2013-10-18 22:11 - 09889352 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RtsUStoricon.dll
2013-10-18 22:10 - 2013-10-18 22:11 - 00263896 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RtsUStor.sys
2013-10-18 22:09 - 2013-10-18 22:09 - 00000000 ____D C:\Users\Sam\AppData\Roaming\InstallShield
2013-10-18 22:06 - 2013-10-18 22:07 - 00872152 _____ (Realtek                                            ) C:\Windows\system32\Drivers\Rt64win7.sys
2013-10-18 22:06 - 2013-10-18 22:07 - 00108760 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
2013-10-18 22:06 - 2013-10-18 22:07 - 00074456 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2013-10-18 22:04 - 2013-10-18 21:54 - 00000000 ____D C:\Intel
2013-10-18 21:53 - 2013-10-18 21:53 - 00000000 ____D C:\ProgramData\ma-config.com
2013-10-18 21:53 - 2013-10-18 21:53 - 00000000 ____D C:\Program Files\ma-config.com
2013-10-18 19:03 - 2012-07-26 04:47 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2013-10-18 19:03 - 2012-07-26 04:46 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2013-10-18 07:01 - 2013-10-18 07:01 - 00000000 ____D C:\Users\Sam\AppData\Roaming\Dofus-5
2013-10-18 05:32 - 2013-10-18 05:32 - 00001066 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-10-18 05:31 - 2012-08-15 15:50 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2013-10-18 05:27 - 2013-09-21 21:35 - 00000000 ____D C:\Users\Sam\AppData\Roaming\Azureus
2013-10-18 05:27 - 2013-08-08 20:18 - 00000000 ____D C:\Windows\Minidump
2013-10-18 05:27 - 2012-07-23 22:50 - 00000000 ____D C:\Windows\Panther
2013-10-18 05:26 - 2013-10-18 05:26 - 00002768 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-10-18 05:26 - 2013-10-18 05:26 - 00000000 ____D C:\Program Files\CCleaner
2013-10-18 05:07 - 2013-10-18 05:07 - 00000000 ____D C:\ProgramData\Oracle
2013-10-18 05:04 - 2013-10-18 05:02 - 00004869 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-18 05:04 - 2013-08-09 10:48 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-18 02:27 - 2013-09-14 07:51 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-17 04:06 - 2013-09-14 07:50 - 00004058 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-17 04:06 - 2013-09-14 07:50 - 00003806 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-13 00:11 - 2012-08-21 09:27 - 00000000 ____D C:\Users\samy\AppData\Local\Facebook
2013-10-11 14:36 - 2013-10-11 14:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2013-10-11 03:43 - 2013-08-15 02:03 - 00000000 ____D C:\Windows\system32\MRT
2013-10-11 03:41 - 2013-10-01 14:09 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-10 05:49 - 2012-07-24 06:08 - 00000008 _____ C:\Users\samy\AppData\Roaming\DofusAppId0_2
2013-10-10 02:38 - 2012-07-24 09:28 - 00000008 _____ C:\Users\samy\AppData\Roaming\DofusAppId0_3
2013-10-09 20:18 - 2012-07-28 00:22 - 00000008 _____ C:\Users\samy\AppData\Roaming\DofusAppId0_4
2013-10-09 04:47 - 2013-09-20 20:46 - 00000000 ____D C:\Program Files\WinRAR
2013-10-08 23:54 - 2013-08-16 13:51 - 00003940 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-08 23:53 - 2013-08-16 13:51 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-08 23:53 - 2013-08-16 13:51 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-08 18:48 - 2013-09-20 20:44 - 00000000 ____D C:\Program Files (x86)\WinRAR
2013-10-08 18:45 - 2013-09-20 21:11 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-10-08 18:40 - 2012-08-21 11:26 - 00000000 ____D C:\Windows\system32\appmgmt
2013-10-08 06:50 - 2013-10-18 05:04 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-08 06:46 - 2013-10-18 05:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-08 06:46 - 2013-10-18 05:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-08 06:46 - 2013-10-18 05:04 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-07 21:20 - 2012-07-23 22:18 - 00000000 ____D C:\ProgramData\Adobe
2013-10-07 21:01 - 2013-10-07 21:01 - 00000000 ____D C:\Users\samy\AppData\Local\Mozilla
2013-10-07 21:00 - 2013-10-07 21:00 - 00000000 ____D C:\ProgramData\Mozilla
2013-10-04 23:34 - 2013-10-04 21:11 - 00000000 ____D C:\Users\Sam\AppData\Roaming\Audacity
2013-10-04 20:17 - 2013-10-04 20:17 - 00000000 ____D C:\Users\Sam\AppData\Local\Macromedia
2013-10-04 12:53 - 2013-10-04 12:53 - 00000000 ____D C:\Users\samy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dofus2
2013-10-04 12:45 - 2013-10-04 12:39 - 00000008 _____ C:\Users\samy\AppData\Roaming\DofusAppId0_5
2013-10-04 12:39 - 2013-10-04 12:39 - 00000000 ____D C:\Users\samy\AppData\Roaming\Dofus-5.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
2013-10-02 10:30 - 2013-09-20 21:58 - 00000000 ____D C:\Users\Sam\Documents\Nouveau dossier
2013-10-02 09:33 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries

Some content of TEMP:
====================
C:\Users\Sam\AppData\Local\Temp\nscFFE8.exe
C:\Users\Sam\AppData\Local\Temp\nsrFB16.exe
C:\Users\Sam\AppData\Local\Temp\nst5A43.exe
C:\Users\Sam\AppData\Local\Temp\nsx4F9E.exe
C:\Users\Sam\AppData\Local\Temp\nsx5E8D.exe
C:\Users\Sam\AppData\Local\Temp\Quarantine.exe
C:\Users\Sam\AppData\Local\Temp\SHSetup.exe
C:\Users\Sam\AppData\Local\Temp\utt59E6.tmp.exe
C:\Users\samy\AppData\Local\Temp\AdobeAIRInstaller.exe
C:\Users\samy\AppData\Local\Temp\nsd91BB.exe
C:\Users\samy\AppData\Local\Temp\nsi46D.exe
C:\Users\samy\AppData\Local\Temp\nsn9506.exe
C:\Users\samy\AppData\Local\Temp\nsv2A12.exe
C:\Users\samy\AppData\Local\Temp\nsy86.exe
C:\Users\samy\AppData\Local\Temp\utt3A67.tmp.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-10-23 16:17

==================== End Of Log ============================

Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23
Re : Suprimé Shearch protect
« Réponse #5 le: octobre 28, 2013, 10:22:28 »
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-10-2013
Ran by Sam at 2013-10-28 10:12:53
Running from C:\Users\Sam\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

Adobe AIR (x32 Version: 3.9.0.1030)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Apple Application Support (x32 Version: 2.3.6)
avast! Free Antivirus (x32 Version: 8.0.1489.0)
CCleaner (Version: 4.06)
Cisco EAP-FAST Module (x32 Version: 2.2.14)
Cisco LEAP Module (x32 Version: 1.0.19)
Cisco PEAP Module (x32 Version: 1.1.6)
Google Chrome (x32 Version: 30.0.1599.101)
Google Update Helper (x32 Version: 1.3.21.165)
Intel(R) Graphics Media Accelerator Driver (x32 Version: 8.15.10.2869)
Intel(R) Rapid Storage Technology (x32 Version: 11.7.0.1013)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
Ma-Config.com (64 bits) (Version: 7.0.193)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile FRA Language Pack (Version: 4.0.30319)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Module linguistique Microsoft .NET Framework 4 Client Profile FRA (Version: 4.0.30319)
Realtek Card Reader (x32 Version: 6.2.9200.30164)
Realtek Ethernet Controller Driver (x32 Version: 7.73.618.2013)
REALTEK Wireless LAN Driver (x32 Version: 1.00.0180)
Synaptics Pointing Device Driver (Version: 15.3.29.0)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
VLC media player 2.1.0 (x32 Version: 2.1.0)

==================== Restore Points  =========================

18-10-2013 20:51:27 Installed Ma-Config.com (64 bits)
18-10-2013 21:07:20 Installé Realtek Ethernet Controller Driver
18-10-2013 21:11:07 Installé Realtek Card Reader
18-10-2013 21:18:54 Windows Update
22-10-2013 09:53:19 Windows Update

==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {25644090-B8F7-4583-A6F4-2614DBBFCA2D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-09-19] (Piriform Ltd)
Task: {5AAB946D-1552-42EB-8ABE-BBD532DEC157} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-14] (Google Inc.)
Task: {809244C3-6C67-477A-AFBB-48D0A0D0C374} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-894156157-116399700-3295306825-1000Core => C:\Users\samy\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-23] (Google Inc.)
Task: {94316AC7-640D-4C78-8AAD-4812312AB2C9} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software)
Task: {9C35CEE2-3599-4534-B4C1-8A77C2B29C47} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-14] (Google Inc.)
Task: {A3CFC2AD-7C37-46A8-BFCA-3DEBF045906C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-08] (Adobe Systems Incorporated)
Task: {A97108CA-DD36-4D7C-9928-19865FC7A6BD} - \EPUpdater No Task File
Task: {AEAFF0CE-1C61-4119-BF6A-F56A8773D224} - System32\Tasks\Games\UpdateCheck_S-1-5-21-894156157-116399700-3295306825-1000
Task: {B36AE296-F7C1-4A5C-AB1D-F72EC718803C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-894156157-116399700-3295306825-1000UA => C:\Users\samy\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-23] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-894156157-116399700-3295306825-1000Core.job => C:\Users\samy\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-894156157-116399700-3295306825-1000UA.job => C:\Users\samy\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-10-28 08:17 - 2013-10-27 22:39 - 02105856 _____ () C:\Program Files\AVAST Software\Avast\defs\13102701\algo.dll
2013-10-18 22:16 - 2013-10-18 22:16 - 00017408 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\PSIClient\cfebb500b0cfb12e0ba7ec9d9a57e46f\PSIClient.ni.dll
2013-10-18 02:27 - 2013-10-09 01:01 - 00698832 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libglesv2.dll
2013-10-18 02:27 - 2013-10-09 01:01 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libegl.dll
2013-10-18 02:27 - 2013-10-09 01:02 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll
2013-10-18 02:27 - 2013-10-09 01:02 - 00415184 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll
2013-10-18 02:27 - 2013-10-09 01:01 - 01604560 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ffmpegsumo.dll
2013-10-18 02:27 - 2013-10-09 01:02 - 13584336 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\3590F75ABA9E485486C100C1A9D4FF06Z...ZZZZ.....ZZZ:1
AlternateDataStreams: C:\3590F75ABA9E485486C100C1A9D4FF06ZZZZZ...ZZZZ..ZZ:1

==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/28/2013 08:15:04 AM) (Source: Winlogon) (User: )
Description: Échec de l’activation de la licence Windows. Erreur 0x80070005.


System errors:
=============
Error: (10/28/2013 08:18:35 AM) (Source: DCOM) (User: )
Description: C:\Windows\System32\slui.exe -Embedding5{F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}


Microsoft Office Sessions:
=========================
Error: (10/28/2013 08:15:04 AM) (Source: Winlogon)(User: )
Description: 0x800700050x00000000


==================== Memory info ===========================

Percentage of memory in use: 68%
Total physical RAM: 1978.93 MB
Available physical RAM: 615.86 MB
Total Pagefile: 3957.86 MB
Available Pagefile: 2038.58 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:101.93 GB) (Free:59.53 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: F5072B1C)
Partition 1: (Not Active) - (Size=10 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=102 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : Suprimé Shearch protect
« Réponse #6 le: octobre 28, 2013, 10:56:17 »
Re,

Cela aurait été bien de lire entièrement ma procédure, notamment :

Citer


C'est un Windows 7 Pro légal ?

Citer
Error: (10/28/2013 08:15:04 AM) (Source: Winlogon) (User: )
Description: Échec de l’activation de la licence Windows. Erreur 0x80070005.

Nous n'intervenons généralement pas sur les système crackés/illégaux, pour des risques lors des manipulation à cause de ces systèmes modifiés, et par éthique.


Tu as déjà passé Adwcleaner sur ce système ?

Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23
Re : Suprimé Shearch protect
« Réponse #7 le: octobre 28, 2013, 11:06:09 »
Re Oui je les utilisé hier apres le lecture d'un autre post 

Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23
Re : Suprimé Shearch protect
« Réponse #8 le: octobre 28, 2013, 11:06:56 »
Frst

Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23
Re : Suprimé Shearch protect
« Réponse #9 le: octobre 28, 2013, 11:07:42 »
et non je ne pense pas qu'il sois légal

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : Suprimé Shearch protect
« Réponse #10 le: octobre 28, 2013, 11:59:27 »
Re,

C'était pas en pièce jointe les rapport, mais hébergé, comme le montre le tutoriel donné ... mais bon ...

à faire :

Télécharge AdwCleaner (de Xplode) sur ton Bureau.


  • Double-clique sur adwcleaner.exe pour lancer le programme.
    (Utilisateur de Vista/Windows 7/8, clique-droit sur le fichier adwcleaner.exe -> Exécuter en tant qu'administrateur)

  • Dans la fenêtre principal, choisis l'option Scanner.
  • Attend la fin de la recherche puis clique sur l'option Rapport.
  • Un fichier texte apparaitra (sinon, il est situé ici C:\AdwCleaner[Rx].txt). Poste-le dans ta prochaine réponse.

Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23
Re : Suprimé Shearch protect
« Réponse #11 le: octobre 28, 2013, 12:15:30 »
Re dans la scan il m’affiche veuillez décoché les élément que vous ne voulez pas supprimé   et rien n'est affiché dans les case ou méme aucun fiche .txt qui ce nomme comme vous me lavez demandé   

Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23
Re : Suprimé Shearch protect
« Réponse #12 le: octobre 28, 2013, 12:17:15 »
C'bon désolé j'avais mal compris

Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23

Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23

Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23
Re : Suprimé Shearch protect
« Réponse #15 le: octobre 28, 2013, 12:20:47 »
j'ai eu du mal désolé

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : Suprimé Shearch protect
« Réponse #16 le: octobre 28, 2013, 14:01:11 »
Re,

Je vois cela ;)

Y'a-t-il encore le problème avec Search protect actuellement ?

Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23
Re : Suprimé Shearch protect
« Réponse #17 le: octobre 28, 2013, 14:24:54 »
Re , oui il et toujours la quand je le ferme dans les processus du gestionnaire de tache sa le quitte mes des que je redémarre le pc il reviens même dans les programmes et fonctionnalité il ni et plus j'ai chopé ce truc en téléchargent Utorrent avant il m’a-fiché un icone dans   les miniature sur le côté

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : Suprimé Shearch protect
« Réponse #18 le: octobre 28, 2013, 15:38:36 »
Re,

Il est là où exactement ? Dans un navigateur Internet, lequel ?
Tu parles de processus, lequel ?


Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23
Re : Suprimé Shearch protect
« Réponse #19 le: octobre 28, 2013, 16:22:43 »
alors , il et sur google chrome et le processus dans le gestionnaire de tâche s’appelle  protectshearch un truc du genre il s'ouvre et ce ferme tout seul la il était affiché j'ai naviguer jusqu’à venir sur le site  ré ouvre le gestionnaire et la je le vois plus 

Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23
Re : Suprimé Shearch protect
« Réponse #20 le: octobre 28, 2013, 16:31:01 »
esquille et possible de supprimé une session de l"ordinateur et tout sont contenue ? je pence que sa serais plus simple ?

Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23
Re : Suprimé Shearch protect
« Réponse #21 le: octobre 28, 2013, 16:40:53 »
je crois que c'bon j'ai redémarrer le pc 2 fois sans aucun problème sur chrome ni dans le gestionnaire merci beaucoup pour votre aide je trouve votre site vachement sympa et utile sa change de la vrais vie ou les gens ne ce bouscule pas pour aidé les autres merci :)

Hors ligne Anti-Virus59

  • Membres
  • Members
  • Messages: 23
Re : Suprimé Shearch protect
« Réponse #22 le: octobre 28, 2013, 16:44:13 »
je fait quoi de tout les logiciel ? :p

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : Suprimé Shearch protect
« Réponse #23 le: octobre 28, 2013, 17:14:09 »
Re,

Pour le nettoyage des logiciels :

Télécharge DelFix (de Xplode) sur ton bureau.

  • Ferme toutes tes fenêtres, puis double clique sur DelFix.exe pour le lancer.
    (Utilisateur de Vista/Windows 7 faites un clic droit -> "Exécuter en tant qu'administrateur")
  • Ne touche pas aux options cochées
  • Clique sur le bouton "Exécuter"
  • Laisse travailler l'outil.


Pour aller plus loin dans ta protection et éviter de te faire réinfecter voici quelques conseils supplémentaires :

  • Attention lors de l'installation de logiciel :
    Veiller à toujours lire les conditions d'utilisation (CLUF), afin de déceler la gestion des données personnelles, l'installation de sponsors publicitaires ou tout autre atteintes à la vie privée. Refuser les toolbars et autres addons proposés.
    A lire ! et à lire

  • Firefox et/ou Chrome offrent une meilleure sécurité par rapport à Internet Explorer, surtout si on les complète de quelques plugins très intéressant : Noscript et WOT par exemple. (pour Chrome : NoScript ; WOT )

  • Maintenir ses logiciels et son système à jour :
    De nombreuses infections sont dû à des failles de windows, mais aussi de logiciel tiers, comme Sun Java, Adobe Acrobat Reader, etc
    Tu peux faire un scan de vulnérabilité pour connaitre tes logiciels présentant des failles non corrigées ou à mettre à jour.
    Ou utiliser un outil comme SXCU pour vérifier occasionnellement.

    Enfin, le plus important reste ton comportement sur ton PC, tu restes la plus importante protection : Évites les comportement à risque : P2P, cracks, téléchargements et installations douteux via des pubs, les messageries instantanées, ou des sites inconnu, sites pornographiques.
    A lire !
    Ici aussi !



    Tu peux indiquer ton sujet "réglé" en cliquant sur le bouton "modifier" (en haut à droite)  dans ton tout premier message.
    -> Ajoute ensuite "résolu" à coté de ton titre et valide.

    A bientôt sur Security-X
     :AAN

Tags: FRST Addition