# AdwCleaner v6.046 - Rapport créé le 28/04/2017 à 11:08:14 # Mis à jour le 24/04/2017 par Malwarebytes # Base de données : 2017-04-25.1 [Serveur] # Système d'exploitation : Windows 10 Home (X64) # Nom d'utilisateur : ACER - ACER-PC-BIANCO # Exécuté depuis : C:\Users\ACER\Crav67_lucia\Desktop\adwcleaner_6.046.exe # Mode: Scan # Support : https://www.malwarebytes.com/support ***** [ Services ] ***** Aucun service malveillant trouvé. ***** [ Dossiers ] ***** Dossier trouvé: C:\ProgramData\cdoeikneejjepjflejogmjigffpkdpbi Dossier trouvé: C:\ProgramData\Application Data\cdoeikneejjepjflejogmjigffpkdpbi Dossier trouvé: C:\ProgramData\{c8559a9a-6dff-1d74-c855-59a9a6df6a69} Dossier trouvé: C:\Users\ACER\AppData\LocalLow\IObit\Advanced SystemCare Dossier trouvé: C:\Users\ACER\AppData\Roaming\IObit\Advanced SystemCare Dossier trouvé: C:\ProgramData\IObit\ASCDownloader Dossier trouvé: C:\ProgramData\IObit\Advanced SystemCare Dossier trouvé: C:\ProgramData\54F3DE4E-B7BA-4EBD-8B3B-385D272CC583 Dossier trouvé: C:\ProgramData\Application Data\IObit\ASCDownloader Dossier trouvé: C:\ProgramData\Application Data\IObit\Advanced SystemCare Dossier trouvé: C:\ProgramData\Application Data\54F3DE4E-B7BA-4EBD-8B3B-385D272CC583 Dossier trouvé: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec Dossier trouvé: C:\Program Files (x86)\goopad Dossier trouvé: C:\Program Files (x86)\myfree codec Dossier trouvé: C:\Program Files (x86)\RelevantKnowledge Dossier trouvé: C:\Program Files (x86)\Common Files\IObit\Advanced SystemCare ***** [ Fichiers ] ***** Fichier trouvé: C:\Users\ACER\AppData\Roaming\Mozilla\Firefox\Profiles\ysvmdu9w.default\extensions\{b64d9b05-48e1-4ceb-bf58-e0643994e900}.xpi ***** [ DLL ] ***** Aucune DLL patchée trouvée. ***** [ WMI ] ***** Aucune clé malveillante trouvée. ***** [ Raccourcis ] ***** Aucun raccourci infecté trouvé. ***** [ Tâches planifiées ] ***** Aucune tâche malveillante trouvée. ***** [ Registre ] ***** Valeur trouvée: HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [Plus-HD-2.3-bg.exe] Clé trouvée: HKLM\SOFTWARE\Classes\ASCExtMenu.CExtMenu Clé trouvée: HKLM\SOFTWARE\Classes\ASCExtMenu.CExtMenu.1 Clé trouvée: HKLM\SOFTWARE\Classes\protector_dll.Protector Clé trouvée: HKLM\SOFTWARE\Classes\protector_dll.Protector.1 Clé trouvée: HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib Clé trouvée: HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1 Clé trouvée: [x64] HKLM\SOFTWARE\Classes\ASCExtMenu.CExtMenu Clé trouvée: [x64] HKLM\SOFTWARE\Classes\ASCExtMenu.CExtMenu.1 Clé trouvée: [x64] HKLM\SOFTWARE\Classes\protector_dll.Protector Clé trouvée: [x64] HKLM\SOFTWARE\Classes\protector_dll.Protector.1 Clé trouvée: [x64] HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib Clé trouvée: [x64] HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1 Clé trouvée: HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36} Clé trouvée: HKU\.DEFAULT\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} Clé trouvée: HKU\S-1-5-21-2657179059-1983806374-3649987409-1000\Software\Myfree Codec Clé trouvée: HKU\S-1-5-21-2657179059-1983806374-3649987409-1000\Software\TeleCharger_v2 Clé trouvée: HKU\S-1-5-21-2657179059-1983806374-3649987409-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec Clé trouvée: HKU\S-1-5-18\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} Clé trouvée: HKCU\Software\Myfree Codec Clé trouvée: HKCU\Software\TeleCharger_v2 Clé trouvée: HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81} Clé trouvée: HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Clé trouvée: HKLM\SOFTWARE\Myfree Codec Clé trouvée: HKLM\SOFTWARE\IOBIT\ASC Clé trouvée: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec Clé trouvée: [x64] HKCU\Software\Myfree Codec Clé trouvée: [x64] HKCU\Software\TeleCharger_v2 Clé trouvée: [x64] HKLM\SOFTWARE\WISECLEANER Clé trouvée: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\case.trovit.it Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\fr.windfinder.com Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\case.trovit.it Clé trouvée: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\fr.windfinder.com Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\case.trovit.it Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\fr.windfinder.c Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\case.trovit.it Clé trouvée: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\fr.windfinder.com Clé trouvée: HKLM\SOFTWARE\CLASSES\DIRECTORY\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare Clé trouvée: HKLM\SOFTWARE\CLASSES\DRIVE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare Clé trouvée: HKLM\SOFTWARE\CLASSES\LNKFILE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare ***** [ Navigateurs web ] ***** Firefox préf trouvée: [C:\Users\ACER\AppData\Roaming\Mozilla\Firefox\Profiles\ysvmdu9w.default\prefs.js] - "extensions.BTwpPJKsD0iLKTw9.url" - "hxxp://filebestproffiguru.net/sync2/?q=hfZ9oeDOh7OMCyVUojr8rdaMg708BNmGWj8ykSh Firefox préf trouvée: [C:\Users\ACER\AppData\Roaming\Mozilla\Firefox\Profiles\ysvmdu9w.default\prefs.js] - "extensions.SIViTM6u44qN8Aeq.scode" - "(function(){try{if(window.location.href.indexOf(\"rjn6qjaEqTnHrTC7qTr6rdC7qd Aucune préférence Chromium malveillante trouvée. ************************* C:\AdwCleaner\AdwCleaner[S0].txt - [6800 octets] - [28/04/2017 11:08:14] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6874 octets] ##########