cjoint

Publicité


Publicité

Format du document : application/octet-stream

Prévisualisation

2019-09-29 14:30:34 : [Application] AdwCleaner 7 . 4 . 1 launched
2019-09-29 14:30:56 : [Button clicked] Survey closed
2019-09-29 14:30:56 : [Telemetry] Sending NPS Survey
2019-09-29 14:30:57 : [AdwUpgrade] Checking application updates
2019-09-29 14:30:57 : [Telemetry] Sending hello
2019-09-29 14:30:58 : [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-29 14:30:58 : [SslCert] Issued to ("*.malwarebytes.com")
2019-09-29 14:30:58 : [SslCert] Locality Name ("Santa Clara")
2019-09-29 14:30:58 : [SslCert] Organization ("Malwarebytes Inc")
2019-09-29 14:30:58 : [SslCert] Certificate EffectiveDate: "lun. oct. 2 00:00:00 2017 GMT"
2019-09-29 14:30:58 : [SslCert] Certificate ExpirationDate: "mar. oct. 6 12:00:00 2020 GMT"
2019-09-29 14:30:58 : [SslCert] ALPN: None
2019-09-29 14:30:58 : [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-29 14:30:58 : [SslCert] KXE: "ECDH"
2019-09-29 14:30:58 : [SslCert] Protocol: "TLSv1.2"
2019-09-29 14:30:58 : [Telemetry] Status code: QVariant(int, 200)
2019-09-29 14:30:59 : [SslCert] Issued by ("Let's Encrypt Authority X3")
2019-09-29 14:30:59 : [SslCert] Issued to ("telemetry-02.adwc.mb.fr33tux.org")
2019-09-29 14:30:59 : [SslCert] Locality Name ()
2019-09-29 14:30:59 : [SslCert] Organization ()
2019-09-29 14:30:59 : [SslCert] Certificate EffectiveDate: "dim. août 18 10:50:38 2019 GMT"
2019-09-29 14:30:59 : [SslCert] Certificate ExpirationDate: "sam. nov. 16 10:50:38 2019 GMT"
2019-09-29 14:30:59 : [SslCert] ALPN: Yes
2019-09-29 14:30:59 : [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-29 14:30:59 : [SslCert] KXE: "ECDH"
2019-09-29 14:30:59 : [SslCert] Protocol: "TLSv1.2"
2019-09-29 14:30:59 : [Telemetry] Status code: QVariant(int, 204)
2019-09-29 14:31:05 : [Button clicked] Dashboard menu item
2019-09-29 14:31:09 : [Button clicked] Scan
2019-09-29 14:31:09 : [Scan] Started
2019-09-29 14:31:09 : [Database] Downloading database
2019-09-29 14:31:11 : [Database] Checking integrity
2019-09-29 14:31:11 : [Database] Found 2601 families
2019-09-29 14:31:11 : [Database] Database v "2019-09-27.1"
2019-09-29 14:31:11 : [Loading paths] Local paths loaded
2019-09-29 14:31:11 : [Loading paths] Chrome paths loaded
2019-09-29 14:31:11 : [Loading paths] User Keys loaded
2019-09-29 14:31:11 : [Module initialized] "File"
2019-09-29 14:31:11 : [Module initialized] "Folder"
2019-09-29 14:31:11 : [Module initialized] "RegistryKey"
2019-09-29 14:31:11 : [Module initialized] "RegistryValue"
2019-09-29 14:31:11 : [Module initialized] "TaskName"
2019-09-29 14:31:12 : [Module initialized] "Service"
2019-09-29 14:31:12 : [Module initialized] "Winlogon"
2019-09-29 14:31:15 : [Module initialized] "URL"
2019-09-29 14:31:15 : [Module initialized] "RegAppInit"
2019-09-29 14:31:15 : [Module initialized] "RegClasses"
2019-09-29 14:31:15 : [Module initialized] "DNS"
2019-09-29 14:31:15 : [Module initialized] "RegFirewallPolicy"
2019-09-29 14:31:15 : [Module initialized] "RegGuid"
2019-09-29 14:31:15 : [Module initialized] "RegIEElevationPolicy"
2019-09-29 14:31:15 : [Module initialized] "RegOther"
2019-09-29 14:31:15 : [Module initialized] "RegProductID"
2019-09-29 14:31:15 : [Module initialized] "RegSoftware"
2019-09-29 14:31:15 : [Module initialized] "RegStartup"
2019-09-29 14:31:15 : [Module initialized] "WMI"
2019-09-29 14:31:15 : [Module initialized] "ChromiumExt"
2019-09-29 14:31:15 : [Module initialized] "FirefoxExt"
2019-09-29 14:31:15 : [Module initialize] Scan Browser
2019-09-29 14:31:15 : [Module initialize] Scan Browser FF
2019-09-29 14:31:15 : [Module initialize] FF start pages loaded
2019-09-29 14:31:15 : [Module initialize] FF search providers loaded
2019-09-29 14:31:15 : [Module initialize] FF plugin list loaded
2019-09-29 14:31:15 : [Scan] Exclusions loaded
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP CUSTOMER FEEDBACK" [ "Folder" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "C:\\Users\\Admin\\AppData\\Roaming\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "C:\\Users\\Admin\\AppData\\Local\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "C:\\Windows\\System32\\config\\systemprofile\\AppData\\Local\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "C:\\ProgramData\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP SUPPORT SOLUTIONS" [ "Folder" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "HKLM\\Software\\Classes\\CLSID\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "HKLM\\Software\\Wow6432Node\\\\Classes\\CLSID\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPCeement" , "C:\\Windows\\System32\\Tasks\\HPCEESCHEDULEFORADMIN" [ "Task" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPCeement" , "C:\\Windows\\Tasks\\HPCEESCHEDULEFORADMIN.JOB" [ "Task" ]
2019-09-29 14:31:25 : [Scan] Item detected: "localScan" , "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\HPCeeScheduleForAdmin" [ "Registry" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPCeement" , "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\HPCeeScheduleForAdmin" [ "Registry" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPCeement" , "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{67662A0F-28B5-4698-BB9B-2020E667F01D}\u0000" [ "Registry" ]
2019-09-29 14:31:25 : [Scan] Item detected: "Preinstalled.HPCeement" , "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Plain\\{67662A0F-28B5-4698-BB9B-2020E667F01D}\u0000" [ "Registry" ]
2019-09-29 14:31:25 : [Scan] Item detected: "PUP.Optional.TouchVPN" , "Touch VPN" [ "Chromium" ]
2019-09-29 14:31:26 : [Telemetry] Sending to Influx
2019-09-29 14:31:26 : [SslCert] Issued by ("Let's Encrypt Authority X3")
2019-09-29 14:31:26 : [SslCert] Issued to ("telemetry-02.adwc.mb.fr33tux.org")
2019-09-29 14:31:27 : [SslCert] Locality Name ()
2019-09-29 14:31:27 : [SslCert] Organization ()
2019-09-29 14:31:27 : [SslCert] Certificate EffectiveDate: "dim. août 18 10:50:38 2019 GMT"
2019-09-29 14:31:27 : [SslCert] Certificate ExpirationDate: "sam. nov. 16 10:50:38 2019 GMT"
2019-09-29 14:31:27 : [SslCert] ALPN: Yes
2019-09-29 14:31:27 : [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-29 14:31:27 : [SslCert] KXE: "ECDH"
2019-09-29 14:31:27 : [SslCert] Protocol: "TLSv1.2"
2019-09-29 14:31:27 : [Telemetry] Status code: QVariant(int, 204)
2019-09-29 14:31:27 : [Telemetry] Sending to DSE
2019-09-29 14:31:27 : [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-29 14:31:27 : [SslCert] Issued to ("*.malwarebytes.com")
2019-09-29 14:31:27 : [SslCert] Locality Name ("San Jose")
2019-09-29 14:31:27 : [SslCert] Organization ("Malwarebytes Inc.")
2019-09-29 14:31:27 : [SslCert] Certificate EffectiveDate: "jeu. févr. 22 00:00:00 2018 GMT"
2019-09-29 14:31:27 : [SslCert] Certificate ExpirationDate: "mer. avr. 22 12:00:00 2020 GMT"
2019-09-29 14:31:27 : [SslCert] ALPN: Yes
2019-09-29 14:31:27 : [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-29 14:31:27 : [SslCert] KXE: "ECDH"
2019-09-29 14:31:27 : [SslCert] Protocol: "TLSv1.2"
2019-09-29 14:31:27 : [Telemetry] Status code: QVariant(int, 201)
2019-09-29 14:31:27 : [Scan] Finished
2019-09-29 14:31:51 : [Button clicked] Next
2019-09-29 14:32:06 : [Button clicked] Bundleware found ok button
2019-09-29 14:32:25 : [Button clicked] Clean & repair
2019-09-29 14:32:35 : [Button clicked] Dialog button clicked [ 2 ]
2019-09-29 14:32:35 : [Cleaning] Started
2019-09-29 14:32:35 : [Cleaning] Unable to Open process - "[System Process]" 0
2019-09-29 14:32:35 : [Cleaning] Unable to Open process - "System" 0
2019-09-29 14:32:35 : [Cleaning] Unable to Open process - "Registry" 0
2019-09-29 14:32:35 : [Cleaning] Unable to Open process - "Memory Compression" 0
2019-09-29 14:32:35 : [Cleaning] Unable to Open process - "NisSrv.exe" 0
2019-09-29 14:32:35 : [Cleaning] Unable to Open process - "SecurityHealthService.exe" 0
2019-09-29 14:32:35 : [Cleaning] Unable to Open process - "SgrmBroker.exe" 0
2019-09-29 14:32:35 : [Quarantine] Session folder: "C:\\AdwCleaner\\Quarantine\\v1\\20190929.163235"
2019-09-29 14:32:36 : [Cleaning] Processing: "PUP.Optional.TouchVPN" , "Touch VPN" [ "Chromium" ]
2019-09-29 14:32:37 : Quarantined items list is empty
2019-09-29 14:32:37 : [Cleaning] Quarantined: "PUP.Optional.TouchVPN" , "Touch VPN" [ "Chromium" ]
2019-09-29 14:32:37 : [Engine Additional Action] "Delete Tracing Keys"
2019-09-29 14:32:39 : [Engine Additional Action] "Reset Winsock"
2019-09-29 14:32:39 : [Telemetry] Sending to Influx
2019-09-29 14:32:39 : [SslCert] Issued by ("Let's Encrypt Authority X3")
2019-09-29 14:32:39 : [SslCert] Issued to ("telemetry-02.adwc.mb.fr33tux.org")
2019-09-29 14:32:39 : [SslCert] Locality Name ()
2019-09-29 14:32:39 : [SslCert] Organization ()
2019-09-29 14:32:39 : [SslCert] Certificate EffectiveDate: "dim. août 18 10:50:38 2019 GMT"
2019-09-29 14:32:39 : [SslCert] Certificate ExpirationDate: "sam. nov. 16 10:50:38 2019 GMT"
2019-09-29 14:32:39 : [SslCert] ALPN: Yes
2019-09-29 14:32:39 : [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-29 14:32:39 : [SslCert] KXE: "ECDH"
2019-09-29 14:32:39 : [SslCert] Protocol: "TLSv1.2"
2019-09-29 14:32:39 : [Telemetry] Status code: QVariant(int, 204)
2019-09-29 14:32:39 : [Telemetry] Sending to DSE
2019-09-29 14:32:41 : [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-29 14:32:41 : [SslCert] Issued to ("*.malwarebytes.com")
2019-09-29 14:32:41 : [SslCert] Locality Name ("San Jose")
2019-09-29 14:32:41 : [SslCert] Organization ("Malwarebytes Inc.")
2019-09-29 14:32:41 : [SslCert] Certificate EffectiveDate: "jeu. févr. 22 00:00:00 2018 GMT"
2019-09-29 14:32:41 : [SslCert] Certificate ExpirationDate: "mer. avr. 22 12:00:00 2020 GMT"
2019-09-29 14:32:41 : [SslCert] ALPN: Yes
2019-09-29 14:32:41 : [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-29 14:32:41 : [SslCert] KXE: "ECDH"
2019-09-29 14:32:41 : [SslCert] Protocol: "TLSv1.2"
2019-09-29 14:32:41 : [Telemetry] Status code: QVariant(int, 201)
2019-09-29 14:32:41 : [Cleaning] Finished
2019-09-29 14:32:44 : [Button clicked] Dialog button clicked [ 6 ]
2019-09-29 14:32:45 : [Application] Closing AdwCleaner
2019-09-29 14:35:45 : [Application] AdwCleaner 7 . 4 . 1 launched
2019-09-29 14:36:30 : [MBBanner] Checking Iris
2019-09-29 14:36:30 : [IRIS] Making request
2019-09-29 14:36:30 : [AdwUpgrade] Checking application updates
2019-09-29 14:36:34 : [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-29 14:36:34 : [SslCert] Issued to ("*.malwarebytes.com")
2019-09-29 14:36:34 : [SslCert] Locality Name ("Santa Clara")
2019-09-29 14:36:34 : [SslCert] Organization ("Malwarebytes Inc")
2019-09-29 14:36:34 : [SslCert] Certificate EffectiveDate: "lun. oct. 2 00:00:00 2017 GMT"
2019-09-29 14:36:34 : [SslCert] Certificate ExpirationDate: "mar. oct. 6 12:00:00 2020 GMT"
2019-09-29 14:36:34 : [SslCert] ALPN: None
2019-09-29 14:36:34 : [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-29 14:36:34 : [SslCert] KXE: "ECDH"
2019-09-29 14:36:34 : [SslCert] Protocol: "TLSv1.2"
2019-09-29 14:36:34 : [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-29 14:36:34 : [SslCert] Issued to ("*.malwarebytes.com")
2019-09-29 14:36:34 : [SslCert] Locality Name ("Santa Clara")
2019-09-29 14:36:34 : [SslCert] Organization ("Malwarebytes Inc")
2019-09-29 14:36:34 : [SslCert] Certificate EffectiveDate: "lun. oct. 2 00:00:00 2017 GMT"
2019-09-29 14:36:34 : [SslCert] Certificate ExpirationDate: "mar. oct. 6 12:00:00 2020 GMT"
2019-09-29 14:36:34 : [SslCert] ALPN: None
2019-09-29 14:36:34 : [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-29 14:36:34 : [SslCert] KXE: "ECDH"
2019-09-29 14:36:34 : [SslCert] Protocol: "TLSv1.2"
2019-09-29 14:36:34 : [Telemetry] Status code: QVariant(int, 200)
2019-09-29 14:36:34 : [File Downloader] Error downloading ( QNetworkReply::NetworkError(ContentNotFoundError) )
2019-09-29 14:36:35 : [IRIS] Failed
2019-09-29 14:36:37 : [Button clicked] Quarantine menu item
2019-09-29 14:36:39 : [Button clicked] Log files menu item
2019-09-29 14:37:09 : [Button clicked] Dashboard menu item
2019-09-29 14:37:16 : [Button clicked] Scan
2019-09-29 14:37:16 : [Scan] Started
2019-09-29 14:37:16 : [Database] Downloading database
2019-09-29 14:37:17 : [Database] Checking integrity
2019-09-29 14:37:17 : [Database] Found 2601 families
2019-09-29 14:37:17 : [Database] Database v "2019-09-27.1"
2019-09-29 14:37:18 : [Loading paths] Local paths loaded
2019-09-29 14:37:20 : [Loading paths] Chrome paths loaded
2019-09-29 14:37:20 : [Loading paths] User Keys loaded
2019-09-29 14:37:20 : [Module initialized] "File"
2019-09-29 14:37:20 : [Module initialized] "Folder"
2019-09-29 14:37:20 : [Module initialized] "RegistryKey"
2019-09-29 14:37:20 : [Module initialized] "RegistryValue"
2019-09-29 14:37:21 : [Module initialized] "TaskName"
2019-09-29 14:37:21 : [Module initialized] "Service"
2019-09-29 14:37:21 : [Module initialized] "Winlogon"
2019-09-29 14:37:30 : [Module initialized] "URL"
2019-09-29 14:37:30 : [Module initialized] "RegAppInit"
2019-09-29 14:37:30 : [Module initialized] "RegClasses"
2019-09-29 14:37:30 : [Module initialized] "DNS"
2019-09-29 14:37:30 : [Module initialized] "RegFirewallPolicy"
2019-09-29 14:37:30 : [Module initialized] "RegGuid"
2019-09-29 14:37:30 : [Module initialized] "RegIEElevationPolicy"
2019-09-29 14:37:30 : [Module initialized] "RegOther"
2019-09-29 14:37:30 : [Module initialized] "RegProductID"
2019-09-29 14:37:30 : [Module initialized] "RegSoftware"
2019-09-29 14:37:30 : [Module initialized] "RegStartup"
2019-09-29 14:37:30 : [Module initialized] "WMI"
2019-09-29 14:37:30 : [Module initialized] "ChromiumExt"
2019-09-29 14:37:30 : [Module initialized] "FirefoxExt"
2019-09-29 14:37:30 : [Module initialize] Scan Browser
2019-09-29 14:37:30 : [Module initialize] Scan Browser FF
2019-09-29 14:37:30 : [Module initialize] FF start pages loaded
2019-09-29 14:37:30 : [Module initialize] FF search providers loaded
2019-09-29 14:37:30 : [Module initialize] FF plugin list loaded
2019-09-29 14:37:30 : [Scan] Exclusions loaded
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP CUSTOMER FEEDBACK" [ "Folder" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "C:\\Users\\Admin\\AppData\\Roaming\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "C:\\Users\\Admin\\AppData\\Local\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "C:\\Windows\\System32\\config\\systemprofile\\AppData\\Local\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "C:\\ProgramData\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP SUPPORT SOLUTIONS" [ "Folder" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "HKLM\\Software\\Classes\\CLSID\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "HKLM\\Software\\Wow6432Node\\\\Classes\\CLSID\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPSupportAssistant" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPCeement" , "C:\\Windows\\System32\\Tasks\\HPCEESCHEDULEFORADMIN" [ "Task" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPCeement" , "C:\\Windows\\Tasks\\HPCEESCHEDULEFORADMIN.JOB" [ "Task" ]
2019-09-29 14:37:55 : [Scan] Item detected: "localScan" , "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\HPCeeScheduleForAdmin" [ "Registry" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPCeement" , "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\HPCeeScheduleForAdmin" [ "Registry" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPCeement" , "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{67662A0F-28B5-4698-BB9B-2020E667F01D}\u0000" [ "Registry" ]
2019-09-29 14:37:55 : [Scan] Item detected: "Preinstalled.HPCeement" , "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Plain\\{67662A0F-28B5-4698-BB9B-2020E667F01D}\u0000" [ "Registry" ]
2019-09-29 14:37:55 : [Scan] Item detected: "PUP.Optional.TouchVPN" , "Touch VPN" [ "Chromium" ]
2019-09-29 14:37:56 : [Telemetry] Sending to Influx
2019-09-29 14:37:57 : [SslCert] Issued by ("Let's Encrypt Authority X3")
2019-09-29 14:37:57 : [SslCert] Issued to ("telemetry-02.adwc.mb.fr33tux.org")
2019-09-29 14:37:57 : [SslCert] Locality Name ()
2019-09-29 14:37:57 : [SslCert] Organization ()
2019-09-29 14:37:57 : [SslCert] Certificate EffectiveDate: "dim. août 18 10:50:38 2019 GMT"
2019-09-29 14:37:57 : [SslCert] Certificate ExpirationDate: "sam. nov. 16 10:50:38 2019 GMT"
2019-09-29 14:37:57 : [SslCert] ALPN: Yes
2019-09-29 14:37:57 : [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-29 14:37:57 : [SslCert] KXE: "ECDH"
2019-09-29 14:37:57 : [SslCert] Protocol: "TLSv1.2"
2019-09-29 14:37:58 : [Telemetry] Status code: QVariant(int, 204)
2019-09-29 14:37:58 : [Telemetry] Sending to DSE
2019-09-29 14:37:58 : [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-29 14:37:58 : [SslCert] Issued to ("*.malwarebytes.com")
2019-09-29 14:37:58 : [SslCert] Locality Name ("San Jose")
2019-09-29 14:37:58 : [SslCert] Organization ("Malwarebytes Inc.")
2019-09-29 14:37:58 : [SslCert] Certificate EffectiveDate: "jeu. févr. 22 00:00:00 2018 GMT"
2019-09-29 14:37:59 : [SslCert] Certificate ExpirationDate: "mer. avr. 22 12:00:00 2020 GMT"
2019-09-29 14:37:59 : [SslCert] ALPN: Yes
2019-09-29 14:37:59 : [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-29 14:37:59 : [SslCert] KXE: "ECDH"
2019-09-29 14:37:59 : [SslCert] Protocol: "TLSv1.2"
2019-09-29 14:37:59 : [Telemetry] Status code: QVariant(int, 201)
2019-09-29 14:37:59 : [Scan] Finished
2019-09-29 14:38:07 : [Button clicked] Next
2019-09-29 14:38:20 : [Button clicked] Clean & repair
2019-09-29 14:38:27 : [Button clicked] Dialog button clicked [ 2 ]
2019-09-29 14:38:33 : 0x1949fe8 "AdwCleaner_BeforeCleaning_29/09/2019_16:38:27" ]
2019-09-29 14:38:33 : [Cleaning] Started
2019-09-29 14:38:34 : [Cleaning] Unable to Open process - "[System Process]" 0
2019-09-29 14:38:34 : [Cleaning] Unable to Open process - "System" 0
2019-09-29 14:38:34 : [Cleaning] Unable to Open process - "Registry" 0
2019-09-29 14:38:34 : [Cleaning] Unable to Open process - "Memory Compression" 0
2019-09-29 14:38:34 : [Cleaning] Unable to Open process - "NisSrv.exe" 0
2019-09-29 14:38:34 : [Cleaning] Unable to Open process - "SecurityHealthService.exe" 0
2019-09-29 14:38:34 : [Cleaning] Unable to Open process - "SgrmBroker.exe" 0
2019-09-29 14:38:34 : [Cleaning] Unable to Open process - "sppsvc.exe" 0
2019-09-29 14:38:34 : [Quarantine] Session folder: "C:\\AdwCleaner\\Quarantine\\v1\\20190929.163834"
2019-09-29 14:38:34 : [Cleaning] Processing: "Preinstalled.HPSupportAssistant" , "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP CUSTOMER FEEDBACK" [ "Folder" ]
2019-09-29 14:38:34 : [Cleaning] Quarantined: "Preinstalled.HPSupportAssistant" , "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP CUSTOMER FEEDBACK" [ "Folder" ]
2019-09-29 14:38:34 : [Cleaning] Processing: "Preinstalled.HPSupportAssistant" , "C:\\Users\\Admin\\AppData\\Roaming\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:38:34 : [Cleaning] Quarantined: "Preinstalled.HPSupportAssistant" , "C:\\Users\\Admin\\AppData\\Roaming\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:38:34 : [Cleaning] Processing: "Preinstalled.HPSupportAssistant" , "C:\\Users\\Admin\\AppData\\Local\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:38:35 : [Cleaning] Quarantined: "Preinstalled.HPSupportAssistant" , "C:\\Users\\Admin\\AppData\\Local\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:38:35 : [Cleaning] Processing: "Preinstalled.HPSupportAssistant" , "C:\\Windows\\System32\\config\\systemprofile\\AppData\\Local\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:38:35 : [Cleaning] Quarantined: "Preinstalled.HPSupportAssistant" , "C:\\Windows\\System32\\config\\systemprofile\\AppData\\Local\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:38:35 : [Cleaning] Processing: "Preinstalled.HPSupportAssistant" , "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:38:47 : [Cleaning] Quarantined: "Preinstalled.HPSupportAssistant" , "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:38:47 : [Cleaning] Processing: "Preinstalled.HPSupportAssistant" , "C:\\ProgramData\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:38:47 : [Cleaning] Quarantined: "Preinstalled.HPSupportAssistant" , "C:\\ProgramData\\HEWLETT-PACKARD\\HP SUPPORT FRAMEWORK" [ "Folder" ]
2019-09-29 14:38:47 : [Cleaning] Processing: "Preinstalled.HPSupportAssistant" , "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP SUPPORT SOLUTIONS" [ "Folder" ]
2019-09-29 14:38:48 : [Cleaning] Quarantined: "Preinstalled.HPSupportAssistant" , "C:\\Program Files (x86)\\HEWLETT-PACKARD\\HP SUPPORT SOLUTIONS" [ "Folder" ]
2019-09-29 14:38:48 : [Cleaning] Processing: "Preinstalled.HPSupportAssistant" , "HKLM\\Software\\Classes\\CLSID\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:38:49 : [Cleaning] Quarantined: "Preinstalled.HPSupportAssistant" , "HKLM\\Software\\Classes\\CLSID\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:38:49 : [Cleaning] Processing: "Preinstalled.HPSupportAssistant" , "HKLM\\Software\\Wow6432Node\\\\Classes\\CLSID\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:38:49 : [Cleaning] Quarantined: "Preinstalled.HPSupportAssistant" , "HKLM\\Software\\Wow6432Node\\\\Classes\\CLSID\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:38:49 : [Cleaning] Processing: "Preinstalled.HPSupportAssistant" , "HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:38:49 : [Cleaning] Quarantined: "Preinstalled.HPSupportAssistant" , "HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:38:49 : [Cleaning] Processing: "Preinstalled.HPSupportAssistant" , "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:38:49 : [Cleaning] Quarantined: "Preinstalled.HPSupportAssistant" , "HKLM\\Software\\Wow6432Node\\\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:38:49 : [Cleaning] Processing: "Preinstalled.HPSupportAssistant" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:38:49 : [Cleaning] Quarantined: "Preinstalled.HPSupportAssistant" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:38:49 : [Cleaning] Processing: "Preinstalled.HPSupportAssistant" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:38:50 : [Cleaning] Quarantined: "Preinstalled.HPSupportAssistant" , "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}" [ "Registry" ]
2019-09-29 14:38:50 : [Cleaning] Processing: "Preinstalled.HPCeement" , "C:\\Windows\\System32\\Tasks\\HPCEESCHEDULEFORADMIN" [ "Task" ]
2019-09-29 14:38:50 : [Cleaning] Quarantined: "Preinstalled.HPCeement" , "C:\\Windows\\System32\\Tasks\\HPCEESCHEDULEFORADMIN" [ "Task" ]
2019-09-29 14:38:50 : [Cleaning] Processing: "Preinstalled.HPCeement" , "C:\\Windows\\Tasks\\HPCEESCHEDULEFORADMIN.JOB" [ "Task" ]
2019-09-29 14:38:50 : [Cleaning] Quarantined: "Preinstalled.HPCeement" , "C:\\Windows\\Tasks\\HPCEESCHEDULEFORADMIN.JOB" [ "Task" ]
2019-09-29 14:38:50 : [Cleaning] Processing: "Preinstalled.HPCeement" , "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\HPCeeScheduleForAdmin" [ "Registry" ]
2019-09-29 14:38:50 : [Cleaning] Quarantined: "Preinstalled.HPCeement" , "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\HPCeeScheduleForAdmin" [ "Registry" ]
2019-09-29 14:38:50 : [Cleaning] Processing: "Preinstalled.HPCeement" , "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{67662A0F-28B5-4698-BB9B-2020E667F01D}\u0000" [ "Registry" ]
2019-09-29 14:38:51 : [Cleaning] Quarantined: "Preinstalled.HPCeement" , "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{67662A0F-28B5-4698-BB9B-2020E667F01D}\u0000" [ "Registry" ]
2019-09-29 14:38:51 : [Cleaning] Processing: "Preinstalled.HPCeement" , "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Plain\\{67662A0F-28B5-4698-BB9B-2020E667F01D}\u0000" [ "Registry" ]
2019-09-29 14:38:51 : [Cleaning] Quarantined: "Preinstalled.HPCeement" , "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Plain\\{67662A0F-28B5-4698-BB9B-2020E667F01D}\u0000" [ "Registry" ]
2019-09-29 14:38:51 : [Cleaning] Processing: "PUP.Optional.TouchVPN" , "Touch VPN" [ "Chromium" ]
2019-09-29 14:38:52 : [Cleaning] Quarantined: "PUP.Optional.TouchVPN" , "Touch VPN" [ "Chromium" ]
2019-09-29 14:38:52 : [Engine Additional Action] "Delete Tracing Keys"
2019-09-29 14:38:53 : [Engine Additional Action] "Reset Winsock"
2019-09-29 14:38:53 : [Telemetry] Sending to Influx
2019-09-29 14:38:54 : [SslCert] Issued by ("Let's Encrypt Authority X3")
2019-09-29 14:38:54 : [SslCert] Issued to ("telemetry-02.adwc.mb.fr33tux.org")
2019-09-29 14:38:54 : [SslCert] Locality Name ()
2019-09-29 14:38:54 : [SslCert] Organization ()
2019-09-29 14:38:54 : [SslCert] Certificate EffectiveDate: "dim. août 18 10:50:38 2019 GMT"
2019-09-29 14:38:54 : [SslCert] Certificate ExpirationDate: "sam. nov. 16 10:50:38 2019 GMT"
2019-09-29 14:38:54 : [SslCert] ALPN: Yes
2019-09-29 14:38:54 : [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-29 14:38:54 : [SslCert] KXE: "ECDH"
2019-09-29 14:38:54 : [SslCert] Protocol: "TLSv1.2"
2019-09-29 14:38:54 : [Telemetry] Status code: QVariant(int, 204)
2019-09-29 14:38:54 : [Telemetry] Sending to DSE
2019-09-29 14:38:55 : [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-29 14:38:55 : [SslCert] Issued to ("*.malwarebytes.com")
2019-09-29 14:38:55 : [SslCert] Locality Name ("San Jose")
2019-09-29 14:38:55 : [SslCert] Organization ("Malwarebytes Inc.")
2019-09-29 14:38:55 : [SslCert] Certificate EffectiveDate: "jeu. févr. 22 00:00:00 2018 GMT"
2019-09-29 14:38:55 : [SslCert] Certificate ExpirationDate: "mer. avr. 22 12:00:00 2020 GMT"
2019-09-29 14:38:55 : [SslCert] ALPN: Yes
2019-09-29 14:38:55 : [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-29 14:38:55 : [SslCert] KXE: "ECDH"
2019-09-29 14:38:55 : [SslCert] Protocol: "TLSv1.2"
2019-09-29 14:38:55 : [Telemetry] Status code: QVariant(int, 201)
2019-09-29 14:38:55 : [Cleaning] Finished
2019-09-29 14:38:59 : [Button clicked] Dialog button clicked [ 6 ]
2019-09-29 14:38:59 : [Application] Closing AdwCleaner
2019-09-29 14:41:01 : [Application] AdwCleaner 7 . 4 . 1 launched
2019-09-29 14:41:57 : [MBBanner] Checking Iris
2019-09-29 14:41:57 : [IRIS] Making request
2019-09-29 14:41:57 : [Telemetry] Sending hello
ication updates
2019-09-29 14:41:59 : [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-29 14:41:59 : [SslCert] Issued to ("*.malwarebytes.com")
2019-09-29 14:41:59 : [SslCert] Locality Name ("Santa Clara")
2019-09-29 14:41:59 : [SslCert] Organization ("Malwarebytes Inc")
2019-09-29 14:41:59 : [SslCert] Certificate EffectiveDate: "lun. oct. 2 00:00:00 2017 GMT"
2019-09-29 14:41:59 : [SslCert] Certificate ExpirationDate: "mar. oct. 6 12:00:00 2020 GMT"
2019-09-29 14:41:59 : [SslCert] ALPN: None
2019-09-29 14:41:59 : [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-29 14:41:59 : [SslCert] KXE: "ECDH"
2019-09-29 14:41:59 : [SslCert] Protocol: "TLSv1.2"
2019-09-29 14:41:59 : [SslCert] Issued by ("DigiCert SHA2 High Assurance Server CA")
2019-09-29 14:41:59 : [SslCert] Issued to ("*.malwarebytes.com")
2019-09-29 14:41:59 : [SslCert] Locality Name ("Santa Clara")
2019-09-29 14:41:59 : [SslCert] Organization ("Malwarebytes Inc")
2019-09-29 14:41:59 : [SslCert] Certificate EffectiveDate: "lun. oct. 2 00:00:00 2017 GMT"
2019-09-29 14:41:59 : [SslCert] Certificate ExpirationDate: "mar. oct. 6 12:00:00 2020 GMT"
2019-09-29 14:41:59 : [SslCert] ALPN: None
2019-09-29 14:41:59 : [SslCert] Cipher: "ECDHE-RSA-AES256-GCM-SHA384"
2019-09-29 14:41:59 : [SslCert] KXE: "ECDH"
2019-09-29 14:41:59 : [SslCert] Protocol: "TLSv1.2"
2019-09-29 14:41:59 : [Telemetry] Status code: QVariant(int, 200)
2019-09-29 14:41:59 : [File Downloader] Error downloading ( QNetworkReply::NetworkError(ContentNotFoundError) )
2019-09-29 14:41:59 : [IRIS] Failed
2019-09-29 14:42:10 : [Button clicked] View Log

Publicité


Signaler le contenu de ce document

Publicité