Se connecter / S'enregistrer
Votre question

suppression de nation zoom impossible

Tags :
  • Google
  • Nation-Zoom
  • Page d'accueil
  • Chrome
  • Moteur de recherche
  • Adware
  • Internet
  • Sécurité
Dernière réponse : dans Sécurité et virus
3 Février 2014 12:31:27

Bonjour comme indiqué dans le titre je n'arrive pas a supprimer nation zoom,
malgré la réinitialisation du moteur de recherche, changement de la page d'accueil par défaut , utilasation de adw cleaner, malwarebites ... pourriez vous m'indiquer la réel marche à suivre pour y parvenir s'il vous plait !!

Autres pages sur : suppression nation zoom impossible

a c 940 8 Sécurité
a c 267 2 Internet
a c 139 Ē Google Chrome
a b á Google
3 Février 2014 13:47:22

Bonjour,


Nous allons commencer par établir un diagnostic pour cibler les éléments néfastes avec cet outil :

---------------------------------------------------------------------------------------------

FRST :

  • Sur cette page, télécharge la version FRST de Farbar, compatible avec ton système et enregistre le fichier sur ton Bureau <-- Important
    Comment savoir quelle version 32 bits ou 64 bits est exécutée sur mon système ?
  • Ferme toutes les applications, y compris ton navigateur
  • Double-clique sur FRST.exe et clique sur Oui pour accepter le Disclaimer
    /!\ Sous Vista, Windows 7 et 8, il faut lancer le fichier par clic-droit -> Exécuter en tant qu'administrateur
  • Sur le menu principal, clique sur Scan et patiente le temps de l'analyse

  • A la fin du scan, les rapports FRST.txt et Addition.txt sont créés.
    Les rapports sont enregistrés au même emplacement que l'outil et sous C:\FRST\Logs


  • Sous IE9, IE10 ou IE11, le filtre SmartScreen déclenche une alerte. Cliquer sur Actions puis sur Exécuter quand même

    ---------------------------------------------------------------------------------------------

    Sont attendus les rapports FRST.txt et Addition.txt
    Poste aussi les rapports AdwCleaner et Malwarebytes, s'il te plaît.

    Tous les rapports doivent être hébergés sur ce site d'hébergement de fichiers et tu indiques les liens obtenus dans ta réponse -> Aide à l'utilisation

    @+
    m
    0
    l
    Contenus similaires
    a c 940 8 Sécurité
    a c 267 2 Internet
    a c 139 Ē Google Chrome
    a b á Google
    5 Février 2014 15:07:11

    Re,

    Pour AdwCleaner, je ne te demandais pas de relancer l'outil mais de poster le rapport que tu avais obtenu avant, lors de tes tentatives.

    Il faut être plus vigilant sur ce que tu valides lors de l'installation de logiciels gratuits, bien lire les conditions d'utilisation et ne pas accepter tout ce qui est proposé avec (cases pré-cochées).
    Stop la pub !
    Exemple sur l'Installation d'une application sponsorisée, les pièges à éviter !


    D'autre part, tu ne peux avoir 2 antivirus actifs sur ton système. Non seulement cela ne t'apportera aucune protection supplémentaire, mais c'est en plus une source de conflits et de dysfonctionnements.
    Il te faut donc choisir entre Trend Micro Titanium Internet Security et avast! Antivirusy et en désinstaller un par le Panneau de configuration.

    ---------------------------------------------------------------------------------------------

    Désinstalle via Panneau de configuration -> Désinstaller un programme (si présents) :

    ces adwares/hijackers/toolbars/programmes indésirables sponsorisés :
    easyToShop
    savernete
    SaveSense
    UpdaterEX
    YAC


    Si un programme ne veut pas se désinstaller, tu passes au suivant.

    ---------------------------------------------------------------------------------------------

    FRST - Correctif :

    /!\ Crée un point de restauration manuel avant d'appliquer le correctif - Tutoriel en images /!\

    • Ouvre le Bloc-notes (Démarrer => Tous les programmes => Accessoires => Bloc-notes)
    • Copie/colle la totalité du contenu de la zone Code ci-dessous dans le Bloc-notes

      start
      (Elex do Brasil Participações Ltda) C:\Program Files (x86)\iSafe\iSafeSvc.exe
      (Elex do Brasil Participações Ltda) C:\Program Files (x86)\iSafe\iSafeSvc2.exe
      (Elex do Brasil Participações Ltda) C:\Program Files (x86)\iSafe\iSafeTray.exe
      HKLM-x32\...\Run: [tuto4pc_fr_70] - [X]
      HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
      HKU\S-1-5-21-3965208469-1167969198-1018415534-1000\...\Run: [SpeedUpMyPC] - "C:\Program Files (x86)\Uniblue\SpeedUpMyPC\launcher.exe" -d 20000
      HKU\S-1-5-21-3965208469-1167969198-1018415534-1000\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\Cathy\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
      HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1389877876&from=air&uid=WDCXWD5000BPVT-80HXZT1_WD-WXE1A61U6021U6021&q={searchTerms}
      HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1389877876&from=air&uid=WDCXWD5000BPVT-80HXZT1_WD-WXE1A61U6021U6021
      HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1389877876&from=air&uid=WDCXWD5000BPVT-80HXZT1_WD-WXE1A61U6021U6021
      HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1389877876&from=air&uid=WDCXWD5000BPVT-80HXZT1_WD-WXE1A61U6021U6021&q={searchTerms}
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1389877876&from=air&uid=WDCXWD5000BPVT-80HXZT1_WD-WXE1A61U6021U6021&q={searchTerms}
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1389877876&from=air&uid=WDCXWD5000BPVT-80HXZT1_WD-WXE1A61U6021U6021
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1389877876&from=air&uid=WDCXWD5000BPVT-80HXZT1_WD-WXE1A61U6021U6021
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1389877876&from=air&uid=WDCXWD5000BPVT-80HXZT1_WD-WXE1A61U6021U6021&q={searchTerms}
      SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
      SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd103&cd=2XzuyEtN2Y1L1Qzu0EtD0Bzy0AyD0AzyyDyE0D0D0BtD0CyDtN0D0Tzu0CyCyCyCtN1L2XzutBtFtBtFyDtFtCtDyBtDtN1L1Czu1L1C1H1B1QtCtDtA&cr=1576231187&ir=
      SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
      SearchScopes: HKLM-x32 - {03144C01-E543-6EEE-7AAB-033E73F73F7F} URL =
      SearchScopes: HKLM-x32 - {acbd5593-e5ee-4c15-b48f-1823ce819dec} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZUxpt175YYfr&ptnrS=ZUxpt175YYfr&si=CLPEovae2LICFaTHtAodkRoA1g&ptb=49F65D60-5ED9-4205-AEAF-AA25B721219B&ind=2012092808&n=77ee1988&psa=&st=sb&searchfor={searchTerms}
      SearchScopes: HKLM-x32 - {D879CDAA-98F4-4A31-A0CB-D692F0A82E38 URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd103&cd=2XzuyEtN2Y1L1Qzu0EtD0Bzy0AyD0AzyyDyE0D0D0BtD0CyDtN0D0Tzu0CyCyCyCtN1L2XzutBtFtBtFyDtFtCtDyBtDtN1L1Czu1L1C1H1B1QtCtDtA&cr=1576231187&ir=
      SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
      SearchScopes: HKCU - {04D83FFC-FA35-3F80-C994-22DC0BC22CE0} URL =
      SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
      SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
      SearchScopes: HKCU - {D879CDAA-98F4-4A31-A0CB-D692F0A82E38} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=telemsd1103&cd=2XzuyEtN2Y1L1Qzu0EtD0Bzy0AyD0AzyyDyE0D0D0BtD0CyDtN0D0Tzu0SyBtDyBtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1208028233&ir=
      BHO: savernete - {98ED406B-F486-3AC0-7F8F-E6960330A7F7} - C:\ProgramData\savernete\s62nvxiqc.x64.dll ()
      BHO: easyToShop - {D645CAD1-2E6D-22DE-B162-F40AB56AE735} - C:\ProgramData\easyToShop\dXzNbGV.x64.dll ()
      BHO: PPTCheCker - {F7D8DA98-632F-418B-4482-ED8C2926E6BB} - C:\ProgramData\PPTCheCker\euYPhmzK.x64.dll ()
      BHO-x32: SaveSense - {0f21b1e5-5afc-43c9-9c66-515046e92ec2} - C:\Program Files (x86)\SaveSense\SaveSenseIE.dll (SaveSense)
      BHO-x32: savernete - {98ED406B-F486-3AC0-7F8F-E6960330A7F7} - C:\ProgramData\savernete\s62nvxiqc.dll ()
      BHO-x32: easyToShop - {D645CAD1-2E6D-22DE-B162-F40AB56AE735} - C:\ProgramData\easyToShop\dXzNbGV.dll ()
      BHO-x32: PPTCheCker - {F7D8DA98-632F-418B-4482-ED8C2926E6BB} - C:\ProgramData\PPTCheCker\euYPhmzK.dll ()
      CHR Extension: (PPTCheCker) - C:\Users\Cathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\cabnmeoaepanmhgpmclgdeipalhpgpfi [2014-01-31]
      CHR Extension: (easyToShop) - C:\Users\Cathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekmbomjcpkcipejbcoidagfhomfmlcha [2014-01-29]
      CHR Extension: (SaveSense) - C:\Users\Cathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\khcceooakamlehbimaepcldnnlnkcmfk [2014-01-16]
      CHR Extension: (savernete) - C:\ProgramData\lbbeijagjnfalngpbhmcjmapbnaffljn [2014-01-29]
      CHR HKLM-x32\...\Chrome\Extension: [khcceooakamlehbimaepcldnnlnkcmfk] - C:\Program Files (x86)\SaveSense\SaveSense.crx [2014-01-16]
      CHR HKLM\SOFTWARE\Policies\Google: Policy restriction
      R2 iSafeService; C:\Program Files (x86)\iSafe\iSafeSvc.exe [491688 2013-12-30] (Elex do Brasil Participações Ltda)
      S2 savesenselive; C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [146920 2014-01-16] (SaveSense)
      S3 savesenselivem; C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [146920 2014-01-16] (SaveSense)
      S2 70e6ca8c; "C:\Windows\system32\rundll32.exe" "c:\progra~2\optimi~1\OptProCrashSvc.dll",ServiceMain
      R3 iSafeKrnl; C:\Program Files (x86)\iSafe\iSafeKrnl.sys [219648 2013-12-30] (Elex do Brasil Participações Ltda)
      R1 iSafeNetFilter; C:\Program Files (x86)\iSafe\iSafeNetFilter.sys [44032 2013-12-30] (Elex do Brasil Participações Ltda)
      Task: {00E4AB70-EF81-4EE3-BA29-0DE0914D666B} - System32\Tasks\SaveSense => C:\Users\Cathy\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe [2013-04-12] ()
      Task: {1EB06047-4901-471A-BD30-71348D88708A} - \Desk 365 RunAsStdUser No Task File
      Task: {337E3028-7E25-4F85-9665-C51FF9590E77} - \RegClean Pro_DEFAULT No Task File
      Task: {3B528540-0514-4A17-876B-33AF2C1DAF18} - System32\Tasks\SaveSenseLiveUpdateTaskMachineUA => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [2014-01-16] (SaveSense)
      Task: {7395F749-5371-429A-BDE8-D4400890FD08} - System32\Tasks\BackgroundContainer Startup Task => Rundll32.exe "C:\Users\Cathy\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
      Task: {8947EA7B-8C04-46F2-98CF-6A6F26AF83E6} - \RegClean Pro_UPDATES No Task File
      Task: {AE03AD12-4D26-4E1B-BB19-6EEB28F8293D} - \RegClean Pro No Task File
      Task: {B102784A-15F0-420C-AA35-B90BCC14AAF6} - System32\Tasks\{A6D9CBA7-CBC8-40C2-A96E-774128829E7B} => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe
      Task: {BA4394CF-A059-4D22-8827-60665B832830} - \UpdaterEX No Task File
      Task: {BFE71BEB-2A49-419C-A774-BA35996CBC6E} - System32\Tasks\SaveSenseLiveUpdateTaskMachineCore => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [2014-01-16] (SaveSense)
      Task: {C5286D58-1B8B-4DBD-8514-FFFE0FD8C2D9} - \Dealply No Task File
      Task: {D8059B4F-D43D-44EC-9CF0-97FB3C220B34} - \SpeedUpMyPC No Task File
      Task: {FB54111E-180F-46A3-B62C-FA2E701D392E} - System32\Tasks\{6F544CC3-CC32-4141-A8FB-0C5D50BA1A98} => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe
      Task: C:\Windows\Tasks\SaveSense.job => C:\Users\Cathy\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE
      Task: C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe
      Task: C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe
      AlternateDataStreams: C:\ProgramData\Temp:D346F792
      2014-01-31 16:52 - 2014-02-04 09:23 - 00000000 ____D () C:\Program Files (x86)\iSafe
      2014-01-31 16:52 - 2014-01-31 17:46 - 00000000 ____D () C:\Users\Cathy\AppData\Roaming\iSafe
      2014-01-31 16:52 - 2014-01-31 16:52 - 00001786 _____ () C:\Users\Public\Desktop\YAC.lnk
      2014-01-31 16:52 - 2014-01-31 16:52 - 00000000 ____D () C:\Windows\system32\log
      2014-01-31 15:32 - 2014-01-31 15:32 - 00000290 __RSH () C:\ProgramData\ntuser.pol
      2014-01-31 15:32 - 2014-01-31 15:32 - 00000000 ____D () C:\ProgramData\PPTCheCker
      2014-01-31 15:31 - 2014-01-31 15:32 - 00000000 ____D () C:\ProgramData\cabnmeoaepanmhgpmclgdeipalhpgpfi
      2014-01-29 14:59 - 2014-01-31 15:32 - 00000000 ____D () C:\ProgramData\28f86fb3052de279
      2014-01-29 14:59 - 2014-01-29 14:59 - 00000000 ____D () C:\ProgramData\easyToShop
      2014-01-29 14:58 - 2014-01-29 14:59 - 00000000 ____D () C:\ProgramData\savernete
      2014-01-29 14:58 - 2014-01-29 14:58 - 00000000 ____D () C:\ProgramData\lbbeijagjnfalngpbhmcjmapbnaffljn
      2014-01-16 14:13 - 2014-02-05 10:59 - 00000292 _____ () C:\Windows\Tasks\SaveSense.job
      2014-01-16 14:13 - 2014-02-04 14:18 - 00000926 _____ () C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job
      2014-01-16 14:13 - 2014-02-03 09:59 - 00003232 _____ () C:\Windows\System32\Tasks\SaveSense
      2014-01-16 14:13 - 2014-01-16 14:13 - 00003926 _____ () C:\Windows\System32\Tasks\SaveSenseLiveUpdateTaskMachineUA
      2014-01-16 14:13 - 2014-01-16 14:13 - 00003674 _____ () C:\Windows\System32\Tasks\SaveSenseLiveUpdateTaskMachineCore
      2014-01-16 14:13 - 2014-01-16 14:13 - 00000000 ____D () C:\Users\Cathy\AppData\Roaming\SaveSense
      2014-01-16 14:13 - 2014-01-16 14:13 - 00000000 ____D () C:\Users\Cathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense
      2014-01-16 14:13 - 2014-01-16 14:13 - 00000000 ____D () C:\Users\Cathy\AppData\Local\SaveSenseLive
      2014-01-16 14:13 - 2014-01-16 14:13 - 00000000 ____D () C:\ProgramData\SaveSenseLive
      2014-01-16 14:13 - 2014-01-16 14:13 - 00000000 ____D () C:\Program Files (x86)\SaveSenseLive
      2014-01-16 14:13 - 2014-01-16 14:13 - 00000000 ____D () C:\Program Files (x86)\SaveSense
      2014-01-16 14:12 - 2014-01-23 14:50 - 00000000 ____D () C:\ProgramData\WPM
      2014-02-05 09:21 - 2014-01-03 12:16 - 00000000 ____D () C:\Users\Cathy\AppData\Roaming\newnext.me
      2014-02-03 11:26 - 2012-04-19 11:52 - 00000000 ____D () C:\Users\Cathy\AppData\Roaming\Uniblue
      2014-02-03 11:26 - 2012-04-19 11:52 - 00000000 ____D () C:\Program Files (x86)\Uniblue
      C:\Users\Cathy\AppData\Local\Conduit
      C:\Program Files (x86)\RegClean Pro
      C:\Program Files (x86)\Mobogenie
      C:\Users\Cathy\AppData\Local\Temp\air1038.exe
      C:\Users\Cathy\AppData\Local\Temp\air3F83.exe
      C:\Users\Cathy\AppData\Local\Temp\airCDCB.exe
      C:\Users\Cathy\AppData\Local\Temp\airFD03.exe
      C:\Users\Cathy\AppData\Local\Temp\FD14_HiDefMedia-1.1.12-win32.exe
      C:\Users\Cathy\AppData\Local\Temp\nsjDDC5.exe
      C:\Users\Cathy\AppData\Local\Temp\Quarantine.exe
      C:\Users\Cathy\AppData\Local\Temp\SPSetup.exe
      end


    • Enregistre le fichier sur ton Bureau (au même endroit que FRST) sous le nom fixlist.txt
    • Ferme toutes les applications, y compris ton navigateur
    • Double-clique sur FRST64.exe
      /!\ Sous Vista, Windows 7 et 8, il faut lancer le fichier par clic-droit -> Exécuter en tant qu'administrateur
    • Sur le menu principal, clique une seule fois sur Fix et patiente le temps de la correction

    • L'outil va créer un rapport de correction Fixlog.txt. Poste ce rapport dans ta réponse.


  • Note : Si l'outil t'indique qu'il faut télécharger une nouvelle version, tu valides par Oui et tu télécharges la dernière version proposée

    /!\ Ce script a été établi pour cet utilisateur, il ne doit, en aucun cas, être appliqué sur un autre système, au risque de provoquer de graves dysfonctionnement et endommager Windows /!\

    --------------------------------------------------------------------------------------------------------------

    Ensuite, tu relances AdwCleaner avec l'option Scanner et tu postes le nouveau rapport obtenu.

    --------------------------------------------------------------------------------------------------------------

    Sont attendus les rapports :
    Fixlog
    AdwCleaner


    @+
    m
    0
    l
    a c 940 8 Sécurité
    a c 267 2 Internet
    a c 139 Ē Google Chrome
    a b á Google
    11 Février 2014 15:08:22

    Bonjour,

    Des difficultés pour appliquer les procédures indiquées ?

    @+
    m
    0
    l
    18 Février 2014 15:19:04

    Merci beaucoup pour votre aide !!
    voici le rapport :
    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 16-02-2014
    Ran by Cathy at 2014-02-18 15:07:43 Run:1
    Running from C:\Users\Cathy\Desktop
    Boot Mode: Normal
    ==============================================

    Content of fixlist:
    *****************
    start

    (Elex do Brasil Participações Ltda) C:\Program Files (x86)\iSafe\iSafeSvc.exe

    (Elex do Brasil Participações Ltda) C:\Program Files (x86)\iSafe\iSafeSvc2.exe

    (Elex do Brasil Participações Ltda) C:\Program Files (x86)\iSafe\iSafeTray.exe

    HKLM-x32\...\Run: [tuto4pc_fr_70] - [X]

    HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe

    HKU\S-1-5-21-3965208469-1167969198-1018415534-1000\...\Run: [SpeedUpMyPC] - "C:\Program Files (x86)\Uniblue\SpeedUpMyPC\launcher.exe" -d 20000

    HKU\S-1-5-21-3965208469-1167969198-1018415534-1000\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\Cathy\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l

    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1389877876&fr...{searchTerms}

    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1389877876&from=a...

    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1389877876&from=a...

    HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1389877876&fr...{searchTerms}

    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1389877876&fr...{searchTerms}

    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1389877876&from=a...

    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1389877876&from=a...

    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1389877876&fr...{searchTerms}

    SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =

    SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd103&cd=2XzuyEtN2Y1L1Qzu0EtD0Bzy0AyD0AzyyDyE0D0D0BtD0CyDtN0D0Tzu0CyCyCyCtN1L2XzutBtFtBtFyDtFtCtDyBtDtN1L1Czu1L1C1H1B1QtCtDtA&cr=1576231187&ir=

    SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =

    SearchScopes: HKLM-x32 - {03144C01-E543-6EEE-7AAB-033E73F73F7F} URL =

    SearchScopes: HKLM-x32 - {acbd5593-e5ee-4c15-b48f-1823ce819dec} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?...{searchTerms}

    SearchScopes: HKLM-x32 - {D879CDAA-98F4-4A31-A0CB-D692F0A82E38 URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd103&cd=2XzuyEtN2Y1L1Qzu0EtD0Bzy0AyD0AzyyDyE0D0D0BtD0CyDtN0D0Tzu0CyCyCyCtN1L2XzutBtFtBtFyDtFtCtDyBtDtN1L1Czu1L1C1H1B1QtCtDtA&cr=1576231187&ir=

    SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =

    SearchScopes: HKCU - {04D83FFC-FA35-3F80-C994-22DC0BC22CE0} URL =

    SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

    SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =

    SearchScopes: HKCU - {D879CDAA-98F4-4A31-A0CB-D692F0A82E38} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=telemsd1103&cd=2XzuyEtN2Y1L1Qzu0EtD0Bzy0AyD0AzyyDyE0D0D0BtD0CyDtN0D0Tzu0SyBtDyBtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1208028233&ir=

    BHO: savernete - {98ED406B-F486-3AC0-7F8F-E6960330A7F7} - C:\ProgramData\savernete\s62nvxiqc.x64.dll ()

    BHO: easyToShop - {D645CAD1-2E6D-22DE-B162-F40AB56AE735} - C:\ProgramData\easyToShop\dXzNbGV.x64.dll ()

    BHO: PPTCheCker - {F7D8DA98-632F-418B-4482-ED8C2926E6BB} - C:\ProgramData\PPTCheCker\euYPhmzK.x64.dll ()

    BHO-x32: SaveSense - {0f21b1e5-5afc-43c9-9c66-515046e92ec2} - C:\Program Files (x86)\SaveSense\SaveSenseIE.dll (SaveSense)

    BHO-x32: savernete - {98ED406B-F486-3AC0-7F8F-E6960330A7F7} - C:\ProgramData\savernete\s62nvxiqc.dll ()

    BHO-x32: easyToShop - {D645CAD1-2E6D-22DE-B162-F40AB56AE735} - C:\ProgramData\easyToShop\dXzNbGV.dll ()

    BHO-x32: PPTCheCker - {F7D8DA98-632F-418B-4482-ED8C2926E6BB} - C:\ProgramData\PPTCheCker\euYPhmzK.dll ()

    CHR Extension: (PPTCheCker) - C:\Users\Cathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\cabnmeoaepanmhgpmclgdeipalhpgpfi [2014-01-31]

    CHR Extension: (easyToShop) - C:\Users\Cathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekmbomjcpkcipejbcoidagfhomfmlcha [2014-01-29]

    CHR Extension: (SaveSense) - C:\Users\Cathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\khcceooakamlehbimaepcldnnlnkcmfk [2014-01-16]

    CHR Extension: (savernete) - C:\ProgramData\lbbeijagjnfalngpbhmcjmapbnaffljn [2014-01-29]

    CHR HKLM-x32\...\Chrome\Extension: [khcceooakamlehbimaepcldnnlnkcmfk] - C:\Program Files (x86)\SaveSense\SaveSense.crx [2014-01-16]

    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction

    R2 iSafeService; C:\Program Files (x86)\iSafe\iSafeSvc.exe [491688 2013-12-30] (Elex do Brasil Participações Ltda)

    S2 savesenselive; C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [146920 2014-01-16] (SaveSense)

    S3 savesenselivem; C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [146920 2014-01-16] (SaveSense)

    S2 70e6ca8c; "C:\Windows\system32\rundll32.exe" "c:\progra~2\optimi~1\OptProCrashSvc.dll",ServiceMain

    R3 iSafeKrnl; C:\Program Files (x86)\iSafe\iSafeKrnl.sys [219648 2013-12-30] (Elex do Brasil Participações Ltda)

    R1 iSafeNetFilter; C:\Program Files (x86)\iSafe\iSafeNetFilter.sys [44032 2013-12-30] (Elex do Brasil Participações Ltda)

    Task: {00E4AB70-EF81-4EE3-BA29-0DE0914D666B} - System32\Tasks\SaveSense => C:\Users\Cathy\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe [2013-04-12] ()

    Task: {1EB06047-4901-471A-BD30-71348D88708A} - \Desk 365 RunAsStdUser No Task File

    Task: {337E3028-7E25-4F85-9665-C51FF9590E77} - \RegClean Pro_DEFAULT No Task File

    Task: {3B528540-0514-4A17-876B-33AF2C1DAF18} - System32\Tasks\SaveSenseLiveUpdateTaskMachineUA => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [2014-01-16] (SaveSense)

    Task: {7395F749-5371-429A-BDE8-D4400890FD08} - System32\Tasks\BackgroundContainer Startup Task => Rundll32.exe "C:\Users\Cathy\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun

    Task: {8947EA7B-8C04-46F2-98CF-6A6F26AF83E6} - \RegClean Pro_UPDATES No Task File

    Task: {AE03AD12-4D26-4E1B-BB19-6EEB28F8293D} - \RegClean Pro No Task File

    Task: {B102784A-15F0-420C-AA35-B90BCC14AAF6} - System32\Tasks\{A6D9CBA7-CBC8-40C2-A96E-774128829E7B} => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe

    Task: {BA4394CF-A059-4D22-8827-60665B832830} - \UpdaterEX No Task File

    Task: {BFE71BEB-2A49-419C-A774-BA35996CBC6E} - System32\Tasks\SaveSenseLiveUpdateTaskMachineCore => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [2014-01-16] (SaveSense)

    Task: {C5286D58-1B8B-4DBD-8514-FFFE0FD8C2D9} - \Dealply No Task File

    Task: {D8059B4F-D43D-44EC-9CF0-97FB3C220B34} - \SpeedUpMyPC No Task File

    Task: {FB54111E-180F-46A3-B62C-FA2E701D392E} - System32\Tasks\{6F544CC3-CC32-4141-A8FB-0C5D50BA1A98} => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe

    Task: C:\Windows\Tasks\SaveSense.job => C:\Users\Cathy\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE

    Task: C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe

    Task: C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe

    AlternateDataStreams: C:\ProgramData\Temp:D 346F792

    2014-01-31 16:52 - 2014-02-04 09:23 - 00000000 ____D () C:\Program Files (x86)\iSafe

    2014-01-31 16:52 - 2014-01-31 17:46 - 00000000 ____D () C:\Users\Cathy\AppData\Roaming\iSafe

    2014-01-31 16:52 - 2014-01-31 16:52 - 00001786 _____ () C:\Users\Public\Desktop\YAC.lnk

    2014-01-31 16:52 - 2014-01-31 16:52 - 00000000 ____D () C:\Windows\system32\log

    2014-01-31 15:32 - 2014-01-31 15:32 - 00000290 __RSH () C:\ProgramData\ntuser.pol

    2014-01-31 15:32 - 2014-01-31 15:32 - 00000000 ____D () C:\ProgramData\PPTCheCker

    2014-01-31 15:31 - 2014-01-31 15:32 - 00000000 ____D () C:\ProgramData\cabnmeoaepanmhgpmclgdeipalhpgpfi

    2014-01-29 14:59 - 2014-01-31 15:32 - 00000000 ____D () C:\ProgramData\28f86fb3052de279

    2014-01-29 14:59 - 2014-01-29 14:59 - 00000000 ____D () C:\ProgramData\easyToShop

    2014-01-29 14:58 - 2014-01-29 14:59 - 00000000 ____D () C:\ProgramData\savernete

    2014-01-29 14:58 - 2014-01-29 14:58 - 00000000 ____D () C:\ProgramData\lbbeijagjnfalngpbhmcjmapbnaffljn

    2014-01-16 14:13 - 2014-02-05 10:59 - 00000292 _____ () C:\Windows\Tasks\SaveSense.job

    2014-01-16 14:13 - 2014-02-04 14:18 - 00000926 _____ () C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job

    2014-01-16 14:13 - 2014-02-03 09:59 - 00003232 _____ () C:\Windows\System32\Tasks\SaveSense

    2014-01-16 14:13 - 2014-01-16 14:13 - 00003926 _____ () C:\Windows\System32\Tasks\SaveSenseLiveUpdateTaskMachineUA

    2014-01-16 14:13 - 2014-01-16 14:13 - 00003674 _____ () C:\Windows\System32\Tasks\SaveSenseLiveUpdateTaskMachineCore

    2014-01-16 14:13 - 2014-01-16 14:13 - 00000000 ____D () C:\Users\Cathy\AppData\Roaming\SaveSense

    2014-01-16 14:13 - 2014-01-16 14:13 - 00000000 ____D () C:\Users\Cathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense

    2014-01-16 14:13 - 2014-01-16 14:13 - 00000000 ____D () C:\Users\Cathy\AppData\Local\SaveSenseLive

    2014-01-16 14:13 - 2014-01-16 14:13 - 00000000 ____D () C:\ProgramData\SaveSenseLive

    2014-01-16 14:13 - 2014-01-16 14:13 - 00000000 ____D () C:\Program Files (x86)\SaveSenseLive

    2014-01-16 14:13 - 2014-01-16 14:13 - 00000000 ____D () C:\Program Files (x86)\SaveSense

    2014-01-16 14:12 - 2014-01-23 14:50 - 00000000 ____D () C:\ProgramData\WPM

    2014-02-05 09:21 - 2014-01-03 12:16 - 00000000 ____D () C:\Users\Cathy\AppData\Roaming\newnext.me

    2014-02-03 11:26 - 2012-04-19 11:52 - 00000000 ____D () C:\Users\Cathy\AppData\Roaming\Uniblue

    2014-02-03 11:26 - 2012-04-19 11:52 - 00000000 ____D () C:\Program Files (x86)\Uniblue

    C:\Users\Cathy\AppData\Local\Conduit

    C:\Program Files (x86)\RegClean Pro

    C:\Program Files (x86)\Mobogenie

    C:\Users\Cathy\AppData\Local\Temp\air1038.exe

    C:\Users\Cathy\AppData\Local\Temp\air3F83.exe

    C:\Users\Cathy\AppData\Local\Temp\airCDCB.exe

    C:\Users\Cathy\AppData\Local\Temp\airFD03.exe

    C:\Users\Cathy\AppData\Local\Temp\FD14_HiDefMedia-1.1.12-win32.exe

    C:\Users\Cathy\AppData\Local\Temp\nsjDDC5.exe

    C:\Users\Cathy\AppData\Local\Temp\Quarantine.exe

    C:\Users\Cathy\AppData\Local\Temp\SPSetup.exe

    end
    *****************

    C:\Program Files (x86)\iSafe\iSafeSvc.exe => No running process found
    C:\Program Files (x86)\iSafe\iSafeSvc2.exe => No running process found
    C:\Program Files (x86)\iSafe\iSafeTray.exe => No running process found
    HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\tuto4pc_fr_70 => Value deleted successfully.
    HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully.
    HKU\S-1-5-21-3965208469-1167969198-1018415534-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SpeedUpMyPC => Value deleted successfully.
    HKU\S-1-5-21-3965208469-1167969198-1018415534-1000\Software\Microsoft\Windows\CurrentVersion\Run\\NextLive => Value deleted successfully.
    HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
    HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
    HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
    HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
    HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{03144C01-E543-6EEE-7AAB-033E73F73F7F} => Key deleted successfully.
    HKCR\Wow6432Node\CLSID\{03144C01-E543-6EEE-7AAB-033E73F73F7F} => Key not found.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{acbd5593-e5ee-4c15-b48f-1823ce819dec} => Key deleted successfully.
    HKCR\Wow6432Node\CLSID\{acbd5593-e5ee-4c15-b48f-1823ce819dec} => Key not found.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{D879CDAA-98F4-4A31-A0CB-D692F0A82E38 => Key deleted successfully.
    HKCR\Wow6432Node\CLSID\{D879CDAA-98F4-4A31-A0CB-D692F0A82E38 => Key not found.
    HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
    HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{04D83FFC-FA35-3F80-C994-22DC0BC22CE0} => Key deleted successfully.
    HKCR\CLSID\{04D83FFC-FA35-3F80-C994-22DC0BC22CE0} => Key not found.
    HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
    HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
    HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key deleted successfully.
    HKCR\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => Key not found.
    HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D879CDAA-98F4-4A31-A0CB-D692F0A82E38} => Key deleted successfully.
    HKCR\CLSID\{D879CDAA-98F4-4A31-A0CB-D692F0A82E38} => Key not found.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{98ED406B-F486-3AC0-7F8F-E6960330A7F7} => Key deleted successfully.
    HKCR\CLSID\{98ED406B-F486-3AC0-7F8F-E6960330A7F7} => Key deleted successfully.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D645CAD1-2E6D-22DE-B162-F40AB56AE735} => Key deleted successfully.
    HKCR\CLSID\{D645CAD1-2E6D-22DE-B162-F40AB56AE735} => Key deleted successfully.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F7D8DA98-632F-418B-4482-ED8C2926E6BB} => Key deleted successfully.
    HKCR\CLSID\{F7D8DA98-632F-418B-4482-ED8C2926E6BB} => Key deleted successfully.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0f21b1e5-5afc-43c9-9c66-515046e92ec2} => Key not found.
    HKCR\Wow6432Node\CLSID\{0f21b1e5-5afc-43c9-9c66-515046e92ec2} => Key not found.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{98ED406B-F486-3AC0-7F8F-E6960330A7F7} => Key deleted successfully.
    HKCR\Wow6432Node\CLSID\{98ED406B-F486-3AC0-7F8F-E6960330A7F7} => Key deleted successfully.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D645CAD1-2E6D-22DE-B162-F40AB56AE735} => Key deleted successfully.
    HKCR\Wow6432Node\CLSID\{D645CAD1-2E6D-22DE-B162-F40AB56AE735} => Key deleted successfully.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F7D8DA98-632F-418B-4482-ED8C2926E6BB} => Key deleted successfully.
    HKCR\Wow6432Node\CLSID\{F7D8DA98-632F-418B-4482-ED8C2926E6BB} => Key deleted successfully.
    C:\Users\Cathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\cabnmeoaepanmhgpmclgdeipalhpgpfi => Moved successfully.
    C:\Users\Cathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekmbomjcpkcipejbcoidagfhomfmlcha => Moved successfully.
    C:\Users\Cathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\khcceooakamlehbimaepcldnnlnkcmfk directory not found.
    CHR Extension: (savernete) - C:\ProgramData\lbbeijagjnfalngpbhmcjmapbnaffljn [2014-01-29] directory not found.
    HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\khcceooakamlehbimaepcldnnlnkcmfk => Key deleted successfully.
    "C:\Program Files (x86)\SaveSense\SaveSense.crx" => File/Directory not found.
    HKLM\SOFTWARE\Policies\Google => Key deleted successfully.
    iSafeService => Service not found.
    savesenselive => Service not found.
    savesenselivem => Service not found.
    70e6ca8c => Service deleted successfully.
    iSafeKrnl => Service not found.
    iSafeNetFilter => Service not found.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{00E4AB70-EF81-4EE3-BA29-0DE0914D666B} => Key not found.
    C:\Windows\System32\Tasks\SaveSense not found.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSense => Key not found.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1EB06047-4901-471A-BD30-71348D88708A} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EB06047-4901-471A-BD30-71348D88708A} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Desk 365 RunAsStdUser => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{337E3028-7E25-4F85-9665-C51FF9590E77} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{337E3028-7E25-4F85-9665-C51FF9590E77} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_DEFAULT => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3B528540-0514-4A17-876B-33AF2C1DAF18} => Key not found.
    C:\Windows\System32\Tasks\SaveSenseLiveUpdateTaskMachineUA not found.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSenseLiveUpdateTaskMachineUA => Key not found.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7395F749-5371-429A-BDE8-D4400890FD08} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7395F749-5371-429A-BDE8-D4400890FD08} => Error deleting key
    C:\Windows\System32\Tasks\BackgroundContainer Startup Task => Moved successfully.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BackgroundContainer Startup Task => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8947EA7B-8C04-46F2-98CF-6A6F26AF83E6} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8947EA7B-8C04-46F2-98CF-6A6F26AF83E6} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro_UPDATES => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AE03AD12-4D26-4E1B-BB19-6EEB28F8293D} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AE03AD12-4D26-4E1B-BB19-6EEB28F8293D} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B102784A-15F0-420C-AA35-B90BCC14AAF6} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B102784A-15F0-420C-AA35-B90BCC14AAF6} => Error deleting key
    C:\Windows\System32\Tasks\{A6D9CBA7-CBC8-40C2-A96E-774128829E7B} => Moved successfully.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A6D9CBA7-CBC8-40C2-A96E-774128829E7B} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BA4394CF-A059-4D22-8827-60665B832830} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BA4394CF-A059-4D22-8827-60665B832830} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UpdaterEX => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFE71BEB-2A49-419C-A774-BA35996CBC6E} => Key not found.
    C:\Windows\System32\Tasks\SaveSenseLiveUpdateTaskMachineCore not found.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSenseLiveUpdateTaskMachineCore => Key not found.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C5286D58-1B8B-4DBD-8514-FFFE0FD8C2D9} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C5286D58-1B8B-4DBD-8514-FFFE0FD8C2D9} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dealply => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D8059B4F-D43D-44EC-9CF0-97FB3C220B34} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D8059B4F-D43D-44EC-9CF0-97FB3C220B34} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SpeedUpMyPC => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FB54111E-180F-46A3-B62C-FA2E701D392E} => Error deleting key
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FB54111E-180F-46A3-B62C-FA2E701D392E} => Error deleting key
    C:\Windows\System32\Tasks\{6F544CC3-CC32-4141-A8FB-0C5D50BA1A98} => Moved successfully.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6F544CC3-CC32-4141-A8FB-0C5D50BA1A98} => Error deleting key
    C:\Windows\Tasks\SaveSense.job not found.
    C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job not found.
    C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job not found.
    C:\ProgramData\Temp => ":D 346F792" ADS removed successfully.
    "C:\Program Files (x86)\iSafe" => File/Directory not found.
    C:\Users\Cathy\AppData\Roaming\iSafe => Moved successfully.
    "C:\Users\Public\Desktop\YAC.lnk" => File/Directory not found.
    C:\Windows\system32\log => Moved successfully.
    C:\ProgramData\ntuser.pol => Moved successfully.
    C:\ProgramData\PPTCheCker => Moved successfully.
    C:\ProgramData\cabnmeoaepanmhgpmclgdeipalhpgpfi => Moved successfully.
    C:\ProgramData\28f86fb3052de279 => Moved successfully.
    C:\ProgramData\easyToShop => Moved successfully.
    C:\ProgramData\savernete => Moved successfully.
    C:\ProgramData\lbbeijagjnfalngpbhmcjmapbnaffljn => Moved successfully.
    "C:\Windows\Tasks\SaveSense.job" => File/Directory not found.
    "C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job" => File/Directory not found.
    "C:\Windows\System32\Tasks\SaveSense" => File/Directory not found.
    "C:\Windows\System32\Tasks\SaveSenseLiveUpdateTaskMachineUA" => File/Directory not found.
    "C:\Windows\System32\Tasks\SaveSenseLiveUpdateTaskMachineCore" => File/Directory not found.
    C:\Users\Cathy\AppData\Roaming\SaveSense => Moved successfully.
    "C:\Users\Cathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense" => File/Directory not found.
    C:\Users\Cathy\AppData\Local\SaveSenseLive => Moved successfully.
    C:\ProgramData\SaveSenseLive => Moved successfully.
    C:\Program Files (x86)\SaveSenseLive => Moved successfully.
    "C:\Program Files (x86)\SaveSense" => File/Directory not found.
    C:\ProgramData\WPM => Moved successfully.
    C:\Users\Cathy\AppData\Roaming\newnext.me => Moved successfully.
    C:\Users\Cathy\AppData\Roaming\Uniblue => Moved successfully.
    C:\Program Files (x86)\Uniblue => Moved successfully.
    "C:\Users\Cathy\AppData\Local\Conduit" => File/Directory not found.
    "C:\Program Files (x86)\RegClean Pro" => File/Directory not found.
    "C:\Program Files (x86)\Mobogenie" => File/Directory not found.
    C:\Users\Cathy\AppData\Local\Temp\air1038.exe => Moved successfully.
    C:\Users\Cathy\AppData\Local\Temp\air3F83.exe => Moved successfully.
    C:\Users\Cathy\AppData\Local\Temp\airCDCB.exe => Moved successfully.
    C:\Users\Cathy\AppData\Local\Temp\airFD03.exe => Moved successfully.
    C:\Users\Cathy\AppData\Local\Temp\FD14_HiDefMedia-1.1.12-win32.exe => Moved successfully.
    C:\Users\Cathy\AppData\Local\Temp\nsjDDC5.exe => Moved successfully.
    "C:\Users\Cathy\AppData\Local\Temp\Quarantine.exe" => File/Directory not found.
    C:\Users\Cathy\AppData\Local\Temp\SPSetup.exe => Moved successfully.

    ==== End of Fixlog ====
    m
    0
    l
    18 Février 2014 15:22:20

    voici le rapport adw cleaner :

    # AdwCleaner v3.019 - Rapport créé le 18/02/2014 à 15:20:32
    # Mis à jour le 17/02/2014 par Xplode
    # Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Nom d'utilisateur : Cathy - CATHY-PC
    # Exécuté depuis : C:\Users\Cathy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HOQZQZHP\adwcleaner.exe
    # Option : Scanner

    ***** [ Services ] *****

    Service Présent : 70e6ca8c

    ***** [ Fichiers / Dossiers ] *****

    Dossier Présent C:\Program Files (x86)\predm
    Dossier Présent C:\ProgramData\Microsoft\Windows\Start Menu\Programs\uniblue
    Dossier Présent C:\Users\Cathy\AppData\Local\genienext
    Dossier Présent C:\Users\Cathy\AppData\Local\Mobogenie
    Dossier Présent C:\Users\Cathy\AppData\Local\NativeMessaging
    Dossier Présent C:\Users\Cathy\AppData\Local\WhiteListing
    Dossier Présent C:\Users\Cathy\AppData\Roaming\newnext.me
    Dossier Présent C:\Users\Cathy\Documents\Mobogenie
    Dossier Présent C:\Windows\System32\ljkb
    Fichier Présent : C:\Users\Cathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx
    Fichier Présent : C:\Users\Cathy\AppData\Local\mysearchdial-speeddial.crx

    ***** [ Raccourcis ] *****

    Raccourci Présent : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk ( hxxp://www.nationzoom.com/?type=sc&ts=1389877876&from=air&uid=... )
    Raccourci Présent : C:\Users\Cathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk ( hxxp://www.nationzoom.com/?type=sc&ts=1389877876&from=air&uid=... )
    Raccourci Présent : C:\Users\Cathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk ( hxxp://www.nationzoom.com/?type=sc&ts=1389877876&from=air&uid=... )
    Raccourci Présent : C:\Users\Cathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk ( hxxp://www.nationzoom.com/?type=sc&ts=1389877876&from=air&uid=... )
    Raccourci Présent : C:\Users\Cathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ( hxxp://www.nationzoom.com/?type=sc&ts=1389877876&from=air&uid=... )
    Raccourci Présent : C:\Users\Cathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk ( hxxp://www.nationzoom.com/?type=sc&ts=1389877876&from=air&uid=... )

    ***** [ Registre ] *****

    Clé Présente : HKCU\Software\FLEXnet
    Clé Présente : HKCU\Software\SaveSenseLive
    Clé Présente : HKCU\Software\SearchProtectINT
    Clé Présente : HKCU\Software\UpdaterEX
    Clé Présente : [x64] HKCU\Software\FLEXnet
    Clé Présente : [x64] HKCU\Software\SaveSenseLive
    Clé Présente : [x64] HKCU\Software\SearchProtectINT
    Clé Présente : [x64] HKCU\Software\UpdaterEX
    Clé Présente : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
    Clé Présente : HKLM\SOFTWARE\Classes\*\shell\filescout
    Clé Présente : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
    Clé Présente : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
    Clé Présente : HKLM\SOFTWARE\Classes\AppID\{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}
    Clé Présente : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
    Clé Présente : HKLM\SOFTWARE\Classes\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}
    Clé Présente : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
    Clé Présente : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
    Clé Présente : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
    Clé Présente : HKLM\SOFTWARE\Classes\TypeLib\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
    Clé Présente : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9}
    Clé Présente : HKLM\Software\hdcode
    Clé Présente : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
    Clé Présente : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\winzipper
    Clé Présente : HKLM\Software\nationzoomSoftware
    Clé Présente : HKLM\Software\SaveSenseLive
    Clé Présente : HKLM\Software\supWPM
    Clé Présente : HKLM\Software\Uniblue
    Clé Présente : HKLM\Software\winzipersvc
    Clé Présente : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
    Clé Présente : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
    Clé Présente : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
    Clé Présente : [x64] HKLM\SOFTWARE\Speedchecker Limited

    ***** [ Navigateurs ] *****

    -\\ Internet Explorer v11.0.9600.16518


    -\\ Google Chrome v32.0.1700.107

    [ Fichier : C:\Users\Cathy\AppData\Local\Google\Chrome\User Data\Default\preferences ]

    Trouvée : homepage

    *************************

    AdwCleaner[R0].txt - [43515 octets] - [03/02/2014 11:25:38]
    AdwCleaner[R1].txt - [3131 octets] - [03/02/2014 11:54:30]
    AdwCleaner[R2].txt - [1041 octets] - [05/02/2014 11:49:32]
    AdwCleaner[R3].txt - [5106 octets] - [18/02/2014 15:20:32]
    AdwCleaner[S0].txt - [41950 octets] - [03/02/2014 11:26:34]
    AdwCleaner[S1].txt - [2743 octets] - [03/02/2014 11:55:26]

    ########## EOF - C:\AdwCleaner\AdwCleaner[R3].txt - [5287 octets] ##########
    m
    0
    l
    18 Février 2014 15:25:01

    Est ce qu' après le nouveau scan sur adw cleaner je dois cliquer sur nettoyer ou non ?
    Merci vraiment pour votre aide !!
    m
    0
    l
    a c 940 8 Sécurité
    a c 267 2 Internet
    a c 139 Ē Google Chrome
    a b á Google
    18 Février 2014 17:12:10

    Bonjour,

    Oui, relance AdwCleaner avec l'option Nettoyer et poste le nouveau rapport obtenu.

    Rappel -> Tous les rapports doivent être hébergés sur ce site d'hébergement de fichiers et tu indiques les liens obtenus dans ta réponse -> Aide à l'utilisation

    @+
    m
    0
    l
    Tom's guide dans le monde
    • Allemagne
    • Italie
    • Irlande
    • Royaume Uni
    • Etats Unis
    Suivre Tom's Guide
    Inscrivez-vous à la Newsletter
    • ajouter à twitter
    • ajouter à facebook
    • ajouter un flux RSS