cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Script ZHPFix
FirewallRaz
EmptyPrefetch
EmptyTemp
EmptyFlash


[MD5.7172E394D61CE38BB4D862CBB2F28A74] - (.Baidu, Inc. - Baidu AndroidStore Helper.) -- C:\Program Files\Baidu Security\MoboMarket\1.2.8.4379\bas_helper.exe [2201632] [PID.516]
O2 - BHO: QQCycloneHelper - {00000000-12C9-4305-82F9-43058F20E8D2} . (...) -- C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll (.not file.) =>Adware.TencentAddressBar
O4 - HKUS\.DEFAULT\..\Run: [Bitdefender Wallet Agent] C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe (.not file.)
O4 - HKUS\.DEFAULT\..\Run: [Bitdefender Wallet] C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe (.not file.)
O4 - HKUS\.DEFAULT\..\Run: [Bitdefender Wallet Application Agent] C:\Program Files\Bitdefender\Bitdefender\bdapppassmgr.exe (.not file.)
O4 - HKUS\S-1-5-18\..\Run: [Bitdefender Wallet Agent] C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe (.not file.)
O4 - HKUS\S-1-5-18\..\Run: [Bitdefender Wallet] C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe (.not file.)
O4 - HKUS\S-1-5-18\..\Run: [Bitdefender Wallet Application Agent] C:\Program Files\Bitdefender\Bitdefender\bdapppassmgr.exe (.not file.)
O23 - Service: Baidu MoboMarket Service (BASSVC) . (.Baidu, Inc. - Baidu MoboMarket Service.) - C:\Program Files\Baidu Security\MoboMarket\1.2.8.4379\bassvc.exe
O23 - Service: Baidu Cleaner Service (BCleanerSvc) . (.Baidu Inc. - Baidu Cleaner Service.) - C:\Program Files\Baidu Cleaner\BCleanerSvc.exe
O23 - Service: ESET Service (ekrn) . (...) - C:\Program Files\ESET\ESET Smart Security\ekrn.exe (.not file.)
[MD5.4E8C983215115036C46841FFB51562A1] [APT] [AutoKMSCustom] (.CODYQX4.) -- C:\Windows\AutoKMS\AutoKMS.exe [2820608] =>HackTool.AutoKMS
[MD5.7428ECBD27D4AD75DCACC30AC5ABCA07] [APT] [AutoPico Daily Restart] (.@ByELDI.) -- C:\Program Files\KMSpico\AutoPico.exe [963264] =>PUA.KMSpico
[MD5.00000000000000000000000000000000] [APT] [avast! Emergency Update] (.@ByELDI.) -- C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [Baidu PC Faster Service] (.@ByELDI.) -- C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFasterSvc.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [Baidu PC Faster Update] (.@ByELDI.) -- C:\Program Files\Baidu Security\PC Faster\4.0.0.0\Updater.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [SparkUpdater] (.Google Inc..) -- C:\Program Files\baidu\Spark\SparkUpdate.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [TuneUpUtilities_Task_BkGndMaintenance2013] (.Google Inc..) -- C:\Program Files\TuneUp Utilities 2014\OneClick.exe (.not file.) [0]
O39 - APT: AutoKMSCustom - (.CODYQX4.) -- C:\Windows\System32\Tasks\AutoKMSCustom [3238] =>HackTool.AutoKMS
O39 - APT: AutoPico Daily Restart - (.@ByELDI.) -- C:\Windows\System32\Tasks\AutoPico Daily Restart [3356] =>PUA.KMSpico
O39 - APT: Baidu PC Faster Service - (.@ByELDI.) -- C:\Windows\System32\Tasks\Baidu PC Faster Service [3624]
O39 - APT: Baidu PC Faster Update - (.@ByELDI.) -- C:\Windows\System32\Tasks\Baidu PC Faster Update [3676]
O42 - Logiciel: Baidu Cleaner - (.Baidu Inc..) [HKLM] -- Baidu Cleaner
O42 - Logiciel: Baidu PC Faster - (.Baidu, Inc..) [HKLM] -- Baidu PC Faster 5.1.0.0
O42 - Logiciel: KMSpico v10 Beta 1 - (...) [HKLM] -- {8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1 =>PUA.KMSpico
O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKCU] -- uTorrent
HKLM\SOFTWARE\Baidu
HKLM\SOFTWARE\Baidu Cleaner
HKLM\SOFTWARE\Baidu Security
HKLM\SOFTWARE\Baidu_Drp_pos
HKLM\SOFTWARE\Bywifi =>Spyware.Bywifi
HKLM\SOFTWARE\EnigmaSoftwareGroup =>PUP.EnigmaSoftware
HKLM\SOFTWARE\Tencent =>Adware.TencentAddressBar
HKCU\SOFTWARE\Bywifi =>Spyware.Bywifi
HKCU\SOFTWARE\Baidu
HKCU\SOFTWARE\Baidu Cleaner
HKCU\SOFTWARE\Baidu Security
HKCU\SOFTWARE\BitTorrent
HKCU\SOFTWARE\Bywifi =>Spyware.Bywifi
HKCU\SOFTWARE\Tencent =>Adware.TencentAddressBar
O43 - CFD: 2015/07/08 00:53:49 - [] D -- C:\Program Files\Baidu Cleaner
O43 - CFD: 2014/10/31 15:53:53 - [] D -- C:\Program Files\Baidu Security
O43 - CFD: 2014/09/12 05:43:10 - [] D -- C:\Program Files\Baidu-Security-2014-4.4.4.80971
O43 - CFD: 2014/07/09 05:24:02 - [] D -- C:\Program Files\Enigma Software Group =>PUP.EnigmaSoftware
O43 - CFD: 2015/07/02 22:12:42 - [] D -- C:\Program Files\KMSpico =>PUA.KMSpico
O43 - CFD: 2015/05/16 09:16:57 - [] D -- C:\Program Files\KMSpicoPortable =>PUA.KMSpico
O43 - CFD: 2015/07/08 00:55:08 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baidu Browser
O43 - CFD: 2015/07/08 04:35:54 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baidu Cleaner
O43 - CFD: 2015/07/05 13:42:26 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster
O43 - CFD: 2015/07/02 22:12:42 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico =>PUA.KMSpico
O43 - CFD: 2015/02/04 01:19:40 - [] D -- C:\ProgramData\Baidu
O43 - CFD: 2015/05/28 20:27:33 - [] D -- C:\ProgramData\Baidu Cleaner
O43 - CFD: 2015/03/06 15:42:35 - [] D -- C:\ProgramData\Baidu Security
O43 - CFD: 2015/05/28 20:26:49 - [] D -- C:\Users\n\AppData\Roaming\Baidu Cleaner
O43 - CFD: 2015/03/06 15:42:35 - [] D -- C:\Users\n\AppData\Roaming\Baidu Security
O43 - CFD: 2015/06/13 17:41:33 - [] D -- C:\Users\n\AppData\Roaming\uTorrent
O43 - CFD: 2015/05/28 20:26:34 - [] D -- C:\Users\n\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Baidu Cleaner
O43 - CFD: 2015/03/06 15:44:06 - [] D -- C:\Users\n\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster

O58 - SDL:2015/03/31 08:14:18 A . (.Baidu, Inc. - Baidu Antivirus Hook Base.) -- C:\Windows\System32\drivers\Bhbase.sys [47408]
O58 - SDL:2015/04/09 14:02:04 A . (.Baidu, Inc. - Baidu Antivirus Minifilter Driver.) -- C:\Windows\System32\drivers\BProtectEx.sys [113992]
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\baidu\Spark\Spark.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Program Files\baidu\Spark\Spark.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Program Files\baidu\Spark\Spark.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Program Files\baidu\Spark\Spark.exe (.not file.)
SR - Auto [2014/12/17 14:15:28] [ 208928] Baidu MoboMarket Service (BASSVC) . (.Baidu, Inc..) - C:\Program Files\Baidu Security\MoboMarket\1.2.8.4379\bassvc.exe
SR - Auto [2015/05/25 11:05:08] [ 1697896] Baidu Cleaner Service (BCleanerSvc) . (.Baidu Inc..) - C:\Program Files\Baidu Cleaner\BCleanerSvc.exe
SS - Demand [2015/05/28 20:29:58] [ 3147624] Baidu System Repair Tool Service (BsrSvc) . (.Baidu, Inc..) - C:\Program Files\Baidu Cleaner\System Repair\BsrSvc.exe
SS - Demand [2015/05/13 10:05:47] [ 1714448] Baidu PC Faster Service 5.1.0.0 (PCFasterSvc_{PCFaster_5.1.0.0}) . (.Baidu, Inc..) - C:\Program Files\PC Faster\5.1.0.0\PCFasterSvc.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000000-12C9-4305-82F9-43058F20E8D2} =>Adware.TencentAddressBar
C:\Windows\AutoKMS\AutoKMS.exe =>HackTool.AutoKMS
C:\Program Files\KMSpico\AutoPico.exe =>PUA.KMSpico
C:\Windows\System32\Tasks\AutoKMSCustom =>HackTool.AutoKMS
C:\Windows\System32\Tasks\AutoPico Daily Restart =>PUA.KMSpico
HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1 =>PUA.KMSpico
HKLM\SOFTWARE\Bywifi =>Spyware.Bywifi
HKLM\SOFTWARE\EnigmaSoftwareGroup =>PUP.EnigmaSoftware
HKLM\SOFTWARE\Tencent =>Adware.TencentAddressBar
HKCU\SOFTWARE\Bywifi =>Spyware.Bywifi
HKCU\SOFTWARE\Tencent =>Adware.TencentAddressBar
C:\Program Files\Enigma Software Group =>PUP.EnigmaSoftware
C:\Program Files\KMSpico =>PUA.KMSpico
C:\Program Files\KMSpicoPortable =>PUA.KMSpico
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico =>PUA.KMSpico
C:\Program Files\KMSpico\KMSELDI.exe =>PUA.KMSpico
C:\Program Files\KMSpico\Service_KMS.exe =>PUA.KMSpico
HKLM\SYSTEM\CurrentControlSet\Services\Service KMSELDI =>PUA.KMSpico

Publicité


Signaler le contenu de ce document

Publicité