~ Rapport de ZHPDiag v2014.4.13.25 - Nicolas Coolman (13/04/2014) ~ Lancé par sheitan (13/04/2014 23:24:03) ~ Adresse du Site Web http://nicolascoolman.webs.com ~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/ ~ Traduit par Nicolas Coolman ~ Etat de la version : ~ Liste blanche : Activée par le programme ~ Elévation des Privilèges : OK ~ User Account Control (UAC): Deactivate by user ---\\ Navigateurs Internet MSIE: Internet Explorer v11.0.9600.16659 MFIE: Mozilla Firefox 28.0 GCIE: Google Chrome v34.0.1847.116 (Defaut) OPIE: Opera vStable 19.0.1326.63 OBIE: Safari v5.34.57.2 ---\\ Informations sur les produits Windows ~ Langage: Français Windows Vista (TM) Ultimate, 64-bit Service Pack 1 (Build 6000) Windows Server License Manager Script : OK ~ Windows Operating System - Windows(R) 7, RETAIL channel Windows ID Activation : OK ~ Windows Partial Key : RYDKP Windows License : OK ~ Windows Remaining Initializations Number : 3 Software Protection Service (Protection logicielle) : OK Key Management Service client information : KO Windows Automatic Updates : OK ---\\ Logiciels de protection du système avast! Internet Security v8.0.1489.0 ---\\ Logiciels d'optimisation du système CCleaner v4.12 =>.Piriform Ltd ---\\ Logiciels de partage PeerToPeer ---\\ Surveillance de Logiciels Adobe Flash Player 12 Plugin Adobe Reader XI Java 7 Update 7 Java 7 Update 51 ---\\ Informations sur le système ~ Processor: Intel64 Family 6 Model 42 Stepping 7, GenuineIntel ~ Operating System: 64 Bits Boot mode: Normal (Normal boot) Total RAM: 12264 MB (56% free) System Restore: Activé (Enable) System drive C: has 84 GB (9%) free of 931 GB ---\\ Mode de connexion au système ~ Computer Name: ADONIS ~ User Name: sheitan ~ All Users Names: UpdatusUser, sheitan, HomeGroupUser$, Administrateur, 91867046729449C4A2F4, ~ Unselected Option: None Logged in as Administrator ---\\ Variables d'environnement ~ System Unit : C:\ ~ %AppZHP% : C:\Users\sheitan\AppData\Roaming\ZHP\ ~ %AppData% : C:\Users\sheitan\AppData\Roaming\ ~ %Desktop% : C:\Users\sheitan\Desktop\ ~ %Favorites% : C:\Users\sheitan\Favorites\ ~ %LocalAppData% : C:\Users\sheitan\AppData\Local\ ~ %StartMenu% : C:\Users\sheitan\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ Enumération des unités disques C: Hard drive, Flash drive, Thumb drive (Free 84 Go of 931 Go) D: CD-ROM drive (Not Inserted) E: Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go) F: Hard drive, Flash drive, Thumb drive (Free 629 Go of 932 Go) G: CD-ROM drive (Free 0 Go of 25 Go) ---\\ Etat du Centre de Sécurité Windows [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified ~ Security Center: 46 Legitimates Filtered in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808] [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024] [MD5.DF79CE9B950C62677D232154E93A81C7] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.01/03/2014 - 04:10:28.) -- C:\Windows\System32\wininet.dll [2334208] [MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.21/11/2010 - 04:24:29.) -- C:\Windows\System32\Winlogon.exe [390656] [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.21/11/2010 - 04:24:16.) -- C:\Windows\System32\sppcomapi.dll [232448] [MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/09/2013 - 02:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152] [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128] [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160] [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456] [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.21/11/2010 - 04:24:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400] [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368] [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472] [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224] [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208] [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.21/11/2010 - 04:23:51.) -- C:\Windows\system32\Drivers\netBT.sys [261632] [MD5.1A29A59A4C5BA6F8C85062A613B7E2B2] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/01/2014 - 03:37:55.) -- C:\Windows\system32\Drivers\ntfs.sys [1684928] [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280] [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.21/11/2010 - 04:24:33.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536] [MD5.1B6163C503398B23FF8B939C67747683] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.21/11/2010 - 04:25:07.) -- C:\Windows\system32\Drivers\rdpdr.sys [165888] [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184] [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.21/11/2010 - 04:24:32.) -- C:\Windows\system32\Drivers\tdx.sys [119296] [MD5.DF8126BD41180351A093A3AD2FC8903B] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.25/02/2011 - 07:25:38.) -- C:\Windows\system32\Drivers\volsnap.sys [296320] ~ Generic Processes: Scanned in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 3/377 ~ Mes musiques (My Musics) : 8/1203 ~ Mes Videos (My Videos) : 2/1554 ~ Mes Favoris (My Favorites) : 1/28 ~ Mes Documents (My Documents) : 3/225790 ~ Mon Bureau (My Desktop) : 3/51416 ~ Menu demarrer (Programs) : 1/78 ~ Hidden Files: Scanned in 00mn 33s ---\\ Processus lancés [MD5.70F81D6EEFCA1E1943828306F57EA55C] - (.Akamai Technologies, Inc. - Akamai NetSession Client.) -- C:\Users\sheitan\AppData\Local\Akamai\netsession_win.exe [4672920] [PID.2520] [MD5.8772A605542D8487F4C08FF9F89F2AB7] - (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe [815512] [PID.4716] [MD5.BEE1B9329506308987E9DBB38D7BD477] - (.DeviceVM, Inc. - Browser Configuration Utility.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe [375000] [PID.4748] [MD5.5B6E8E09BE6401A7E022F52FDFCB2FF8] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336] [PID.4776] [MD5.D1AE8E020CF000C334E905273190A96F] - (.Corsair Components Inc - Corsair Vengeance Headset.) -- C:\Program Files (x86)\Corsair\Corsair Headset Software\HeadsetControlPanel.exe [3161088] [PID.4784] [MD5.8F0E03F50968FF73E36310EA8F0DEF79] - (.Boxore OU - Boxore Client.) -- C:\Program Files (x86)\Boxore\BoxoreClient\boxore.exe [973088] [PID.4800] =>Adware.Boxore [MD5.B3F7965A9CE79C26AEEEC8D3F8329C34] - (.Bitvise - Bitvise SSH Client.) -- C:\Program Files (x86)\Bitvise SSH Client\BvSsh.exe [6358720] [PID.5324] [MD5.D450312A8C61D642482066376B51BB1E] - (...) -- C:\ProgramData\BOINC\projects\boinc.bakerlab.org_rosetta\minirosetta_3.48_windows_x86_64.exe [25803776] [PID.3988] [MD5.2EBBBFC120593C683796092F2DDA0EFC] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [841032] [PID.5712] [MD5.08FECDE82830FA31E186E071D87CE86A] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8212992] [PID.3668] [MD5.5A19667A580B1CE886EAF968B9743F45] - (.NVIDIA Corporation - Stereo Vision Control Panel API Server.) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [383264] [PID.1008] [MD5.C2009C6A452BD07B30D773349589B762] - (.AVAST Software - avast! firewall service.) -- C:\Program Files\AVAST Software\Avast\afwServ.exe [137960] [PID.1716] [MD5.251A1AED2D4A26A47C0A4A3058AAE4A8] - (.Boxore OU. - Programme d'installation de Software.) -- C:\Program Files (x86)\Software\Update\SoftwareUpdate.exe [139576] [PID.2056] =>Adware.Boxore [MD5.B362181ED3771DC03B4141927C80F801] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65432] [PID.2176] [MD5.6E3F4538B33BC19259E99BE1826286A3] - (...) -- C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe [922240] [PID.2200] [MD5.A63173897EA1A73A75D0E65036DE5B15] - (...) -- C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [915584] [PID.2388] [MD5.5C31DFB196CB3A488A041881634D86D2] - (...) -- C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [586880] [PID.2472] [MD5.7ED4E1D2E124AD4E6A287CF49DBC9BBA] - (.DeviceVM, Inc. - Browser Configuration Utility Auto-recovery.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [223464] [PID.2580] [MD5.673E36852E2F9FA778D5D3DDCEFA591B] - (.PACE Anti-Piracy, Inc. - PACE License Support Service.) -- C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe [2938880] [PID.2764] [MD5.205E1B699FD3F2F9B036EEA2EC30C620] - (...) -- C:\Windows\SysWOW64\PnkBstrA.exe [76888] [PID.2820] [MD5.80F8944EA183004D6EDCBBDCEC166404] - (.Western Digital - WD Drive Service.) -- C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [248248] [PID.2964] [MD5.FD2D1C60CDBDFAB63EF182539D8FFC2D] - (.Western Digital - WD Rules Engine.) -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe [1177536] [PID.3024] [MD5.96C4C98FE4866C16FC64E4578A0AA975] - (.Western Digital - WD Backup Engine.) -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1157056] [PID.792] [MD5.B3009DCDBCC5EFA49FA52562E9860E3C] - (.MAGIX AG - Verzeichnisüberwachung und Hilfsaufgaben fü.) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1840128] [PID.2184] [MD5.2C24DC448DBE8DB9BE1441B824C57E79] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [277824] [PID.3852] ~ Processes Running: Scanned in 00mn 00s ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2) C:\Users\sheitan\AppData\Local\Google\Chrome\User Data\Default\Preferences G0 - GCSP: Preference [User Data\Default][HomePage] http://search.conduit.com G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Drive v.6.3 (Activé) G2 - GCE: Preference [User Data\Default] [bbjciahceamgodcoidkjpchnokgfpphh] Funmoods Chat v.2.3.8 (Désactivé) =>PUP.Funmoods G2 - GCE: Preference [User Data\Default] [bebdghdpchfhbbmfeddkijldlpnkbjkk] LyricsTube v.1.111 (Désactivé) =>Adware.AddLyrics G2 - GCE: Preference [User Data\Default] [cjpglkicenollcignonpgiafdgfeehoj] Funmoods v.9.4.15, (Désactivé) =>PUP.Funmoods G2 - GCE: Preference [User Data\Default] [geelfhphabnejjhdalkjhgipohgpdnoc] Ripple Emulator (Beta) v.0.9.15, (Désactivé) G2 - GCE: Preference [User Data\Default] [gobmeekldnjpoafibilnjbnnhlaadhlp] websiave v.3.7 (Désactivé) =>PUP.Websave G2 - GCE: Preference [User Data\Default] [indebdooekgjhkncmgbkeopjebofdoid] jquery-injector v.0.5.1 (Désactivé) G2 - GCE: Preference [User Data\Default] [neajdppkdcdipfabeoofebfddakdcjhd] Google Network Speech v.1.0 (Activé) G2 - GCE: Preference [User Data\Default] [nkeimhogjdpnpccoofpliimaahmaaome] Hangout Services v.1.0 (Activé) G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Wallet v.0.0.6.1 (Activé) G2 - GCE: Preference [User Data\Default] [pbaohildkhbcljgoabiecdoinkaedlca] Smart Display v.1.7, (Activé) =>Spyware.SmartDisplay G2 - GCE: Preference [User Data\Default] [pbpohikckhbcljgombipcdoinkaedlfa] Smart Display v.1.8, (Activé) =>Spyware.SmartDisplay ---\\ Liste des dossiers d'extension Google Chrome ~ Google Lines Browser: 30 Legitimates Filtered in 00mn 05s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) C:\Users\sheitan\AppData\Roaming\Mozilla\Firefox\Profiles\0v7vsx8w.default\prefs.js C:\Users\sheitan\AppData\Roaming\Mozilla\Firefox\Profiles\g02zqukx.default\prefs.js (.not file.) M3 - MFPP: Plugins - [sheitan] -- C:\Users\sheitan\AppData\Roaming\Mozilla\Firefox\Profiles\0v7vsx8w.default\searchplugins\conduit-search.xml =>Toolbar.Conduit M3 - MFPP: Plugins - [sheitan] -- C:\Users\sheitan\AppData\Roaming\Mozilla\Firefox\Profiles\0v7vsx8w.default\searchplugins\WebSearch.xml M0 - MFSP: prefs.js [sheitan - 0v7vsx8w.default] http://websearch.searchsun.info M2 - MFEP: prefs.js [sheitan - 0v7vsx8w.default\ee_cioe@fsiuuoo-.net] [] websiave v3.7 (..) =>PUP.Websave M2 - MFEP: prefs.js [sheitan - 0v7vsx8w.default\ioea1oh@cksaqzdva.org] [] SSearuch-NewTab v2.1 (..) =>Adware.FastSaveApp M2 - MFEP: prefs.js [sheitan - 0v7vsx8w.default\oaee@ueuy.org] [] weebsAvee v3.7 (..) =>PUP.Websave ~ Firefox Browser: 15 Legitimates Filtered in 00mn 00s ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com =>PUP.HelperBar R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com =>PUP.HelperBar R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com =>PUP.HelperBar ~ IE Browser: 19 Legitimates Filtered in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local; R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s ---\\ Hosts file redirection (O1) ~ Le fichier hosts est sain (The hosts file is clean). ~ Hosts File: Scanned in 00mn 00s ~ Nombre de lignes (Lines number): 58 ---\\ Browser Helper Objects de navigateur (O2) O2 - BHO: BBrowsye2savve [64Bits] - {C2088AC3-609F-6B40-7BC7-7564D892CEFA} . (...) -- C:\ProgramData\BBrowsye2savve\516f0f7a511e4.dll =>Adware.Browse2Save O2 - BHO: Browse2save [64Bits] - {DCFDAE13-0A87-8387-7415-9A45D26A03D5} . (...) -- C:\ProgramData\Browse2save\510c0e5b2409a.dll =>Adware.Browse2Save ~ BHO: 20 Legitimates Filtered in 00mn 00s ---\\ Internet Explorer Toolbars (O3) O3 - Toolbar: avast! Online Security - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll O3 - Toolbar: (no name) - [HKLM]{ae07101b-46d4-4a98-af68-0333ea26e113} Clé orpheline O3 - Toolbar\WebBrowser: (no name) - [HKCU]{724D43A0-0D85-11D4-9908-00400523E39A} Clé orpheline O3 - Toolbar\WebBrowser: (no name) - [HKCU]{47833539-D0C5-4125-9FA8-0819E2EAAC93} Clé orpheline ~ Toolbar: Scanned in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - GS\Desktop [Public]: Assassins Creed IV Black Flag.lnk . (...) -- C:\Program Files (x86)\Assassins Creed IV Black Flag\AC4BFSP.exe O4 - GS\Desktop [Public]: FINAL FANTASY VII.lnk . (...) -- C:\Program Files (x86)\Square Enix\FINAL FANTASY VII\FF7_Launcher.exe O4 - GS\Desktop [Public]: FreeMi UPnP Media Server.lnk . (...) -- C:\Program Files (x86)\FreeMi UPnP Media Server\FreeMi UPnP Media Server.exe (.not file.) O4 - GS\Desktop [Public]: L.A. Noire.lnk . (.Rockstar Games - LANLauncher.) -- C:\LA_noire\LANLauncher.exe O4 - GS\Desktop [Public]: METAL GEAR RISING REVENGEANCE.lnk . (...) -- C:\Program Files (x86)\METAL GEAR RISING REVENGEANCE\METAL GEAR RISING REVENGEANCE.exe O4 - GS\Desktop [Public]: Speccy.lnk . (...) -- C:\Program Files (x86)\Speccy\Speccy64.exe (.not file.) O4 - GS\Desktop [Public]: WRC 4 FIA World Rally Championship.lnk . (.Milestone S.r.l. - WRC 4.) -- C:\Program Files (x86)\WRC 4 FIA World Rally Championship\WRC4.exe O4 - GS\Program [Public]: Acrobat_com.lnk . (...) -- C:\Program Files (x86)\Adobe\Acrobat_com\Acrobat_com.exe O4 - GS\Program [Public]: Assassins Creed IV Black Flag.lnk . (...) -- C:\Program Files (x86)\Assassins Creed IV Black Flag\AC4BFSP.exe O4 - GS\Program [Public]: METAL GEAR RISING REVENGEANCE.lnk . (...) -- C:\Program Files (x86)\METAL GEAR RISING REVENGEANCE\METAL GEAR RISING REVENGEANCE.exe O4 - GS\Program [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O4 - GS\Program [Public]: Opera.lnk . (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\launcher.exe O4 - GS\Program [Public]: Safari.lnk . (...) -- C:\Windows\Installer\{C779648B-410E-4BBA-B75B-5815BCEFE71D}\SafariIco.exe O4 - GS\Program [Public]: Sublime Text 2.lnk . (...) -- C:\Program Files\Sublime Text 2\sublime_text.exe O4 - GS\Program [Public]: WRC 4 FIA World Rally Championship.lnk . (.Milestone S.r.l. - WRC 4.) -- C:\Program Files (x86)\WRC 4 FIA World Rally Championship\WRC4.exe O4 - GS\Desktop [UpdatusUser]: EVEREST Home Edition.lnk . (...) -- C:\Program Files (x86)\Lavalys\EVEREST Home Edition\everest.exe O4 - GS\Desktop [UpdatusUser]: HomePlayer.lnk . (...) -- C:\Program Files (x86)\HomePlayer\HomePlayer.exe O4 - GS\Desktop [UpdatusUser]: Supra ASCII Art.lnk . (.NGSoft-fr.com - Pas de description.) -- C:\Program Files\SupraASCIIArt\SAA.exe O4 - GS\QuickLaunch [sheitan]: Apple Safari.lnk . (...) -- C:\Windows\Installer\{C779648B-410E-4BBA-B75B-5815BCEFE71D}\SafariIco.exe O4 - GS\QuickLaunch [sheitan]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O4 - GS\QuickLaunch [sheitan]: Komodo Edit 8.lnk . (.ActiveState - ActiveState Komodo.) -- C:\Program Files (x86)\ActiveState Komodo Edit 8\komodo.exe O4 - GS\QuickLaunch [sheitan]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\QuickLaunch [sheitan]: Media converter.lnk . (...) -- C:\Program Files (x86)\Media converter\MediaConverter.exe O4 - GS\TaskBar [sheitan]: Bitvise SSH Client.lnk . (.Bitvise - Bitvise SSH Client.) -- C:\Program Files (x86)\Bitvise SSH Client\BvSsh.exe O4 - GS\TaskBar [sheitan]: FileZilla Client.lnk . (.FileZilla Project - FileZilla FTP Client.) -- C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe O4 - GS\TaskBar [sheitan]: FreeMi UPnP Media Server.lnk . (...) -- C:\Program Files\FreeMi UPnP Media Server\FreeMi UPnP Media Server.exe O4 - GS\TaskBar [sheitan]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O4 - GS\TaskBar [sheitan]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\TaskBar [sheitan]: Max Payne 3.lnk . (.Rockstar Games - PlayMaxPayne3.) -- C:\Program Files (x86)\Rockstar Games\Max Payne 3\PlayMaxPayne3.exe O4 - GS\TaskBar [sheitan]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O4 - GS\TaskBar [sheitan]: Safari.lnk . (...) -- C:\Windows\Installer\{C779648B-410E-4BBA-B75B-5815BCEFE71D}\SafariIco.exe O4 - GS\TaskBar [sheitan]: SecurityKISS Tunnel.lnk . (...) -- C:\Program Files\SecurityKISS Tunnel\SecurityKISSTunnel.exe O4 - GS\TaskBar [sheitan]: Sublime Text 2.lnk . (...) -- C:\Program Files (x86)\Sublime Text 2\sublime_text.exe (.not file.) O4 - GS\TaskBar [sheitan]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe =>P2P.BitTorrent O4 - GS\Program [sheitan]: freenas - FreeNAS-8.3.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://192.168.1.54:4430/ =>Hijacker.Browsers O4 - GS\Program [sheitan]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\Program [sheitan]: Social Games.lnk - Clé orpheline O4 - GS\Program [sheitan]: Traitement de texte Atlantis.lnk . (...) -- C:\Program Files (x86)\Atlantis\Atlantis.exe O4 - GS\SystemTools [sheitan]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\Desktop [sheitan]: Amnesia.lnk . (...) -- C:\Program Files (x86)\Amnesia - The Dark Descent\redist\Launcher.exe O4 - GS\Desktop [sheitan]: IAmAlive_Launcher.exe - Raccourci.lnk . (.Ubisoft - Autopatch system.) -- C:\Program Files (x86)\Ubisoft\I Am Alive\IAmAlive_Launcher.exe O4 - GS\Desktop [sheitan]: Magic DVD Ripper.lnk . (...) -- C:\Program Files (x86)\MagicDVDRipper\MagicDVDRipper.exe O4 - GS\Desktop [sheitan]: Max Payne 3.lnk . (.Rockstar Games - PlayMaxPayne3.) -- C:\Program Files (x86)\Rockstar Games\Max Payne 3\PlayMaxPayne3.exe O4 - GS\Desktop [sheitan]: prototypef.exe - Raccourci.lnk . (.Activision - Prototype.) -- C:\Program Files (x86)\Activision\Prototype\prototypef.exe ~ Global Startup: 127 Legitimates Filtered in 00mn 00s ---\\ Applications lancées au démarrage du système (O4) O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp O4 - HKLM\..\Run: [BCSSync] . (.Microsoft Corporation - Microsoft Office 2010 component.) -- C:\Program Files\Microsoft Office\Office14\BCSSync.exe =>.Microsoft Corporation O4 - HKLM\..\Run: [boinctray] . (.Space Sciences Laboratory - BOINC System Tray for Windows.) -- C:\Program Files\BOINC\boinctray.exe O4 - HKCU\..\Run: [Akamai NetSession Interface] . (.Akamai Technologies, Inc. - Akamai NetSession Client.) -- C:\Users\sheitan\AppData\Local\Akamai\netsession_win.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] . (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe =>.DT Soft Ltd O4 - HKCU\..\Run: [boincmgr] . (.Space Sciences Laboratory - BOINC Manager for Windows.) -- C:\Program Files\BOINC\boincmgr.exe O4 - HKLM\..\Wow6432Node\Run: [Acrobat Assistant 8.0] . (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe O4 - HKLM\..\Wow6432Node\Run: [SwitchBoard] . (.Adobe Systems Incorporated - SwitchBoard Server (32 bit).) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe O4 - HKLM\..\Wow6432Node\Run: [JMB36X IDE Setup] . (...) -- C:\Windows\RaidTool\xInsIDE.exe O4 - HKLM\..\Wow6432Node\Run: [BCU] . (.DeviceVM, Inc. - Browser Configuration Utility.) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle Corporation O4 - HKLM\..\Wow6432Node\Run: [Corsair Headset Software] . (.Corsair Components Inc - Corsair Vengeance Headset.) -- C:\Program Files (x86)\Corsair\Corsair Headset Software\HeadsetControlPanel.exe O4 - HKLM\..\Wow6432Node\Run: [Boxore Client] . (.Boxore OU - Boxore Client.) -- C:\Program Files (x86)\Boxore\BoxoreClient\boxore.exe =>Adware.Boxore O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O4 - HKUS\S-1-5-21-3421522004-3679920147-533480818-1000\..\Run: [Akamai NetSession Interface] . (.Akamai Technologies, Inc. - Akamai NetSession Client.) -- C:\Users\sheitan\AppData\Local\Akamai\netsession_win.exe O4 - HKUS\S-1-5-21-3421522004-3679920147-533480818-1000\..\Run: [DAEMON Tools Lite] . (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe =>.DT Soft Ltd O4 - HKUS\S-1-5-21-3421522004-3679920147-533480818-1000\..\Run: [boincmgr] . (.Space Sciences Laboratory - BOINC Manager for Windows.) -- C:\Program Files\BOINC\boincmgr.exe ~ Application: Scanned in 00mn 00s ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: &Envoyer à OneNote [64Bits] - {2670000A-7350-4f3c-8081-5663EE0C6C49} -- C:\Program Files (x86)\MICROS~3\Office14\ONBttnIE.dll (.not file.) O9 - Extra button: &KeyScrambler Options [64Bits] - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} -- Clé orpheline O9 - Extra button: Send by Bluetooth to [64Bits] - {7815BE26-237D-41A8-A98F-F7BD75F71086} -- Clé orpheline O9 - Extra button: Notes &liées OneNote [64Bits] - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} -- C:\Program Files (x86)\MICROS~3\Office14\ONBTTN~1.dll (.not file.) ~ IE Extra Buttons: Scanned in 00mn 00s ---\\ Site dans la Zone de confiance d'Internet Explorer (O15) O15 - Trusted Zone: [HKCU\...\Domains] http.ma-config.com O15 - Trusted Zone: [HKCU\...\Domains] http.touslesdrivers.com ~ IE Zone Confiance: Scanned in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{0B81E8EC-1481-43A0-87D1-44DAAAE432DD}: DhcpNameServer = 10.10.0.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{18511CB2-5570-42C3-A170-D9B64AB53AFC}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CCS\Services\Tcpip\..\{6A6A2D50-4D5C-449E-B48F-8BC1BB37C580}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{D49B27BF-1509-47E3-B660-0619F2E5986A}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CCS\Services\Tcpip\..\{D4E97DF3-D78B-46DA-B447-E9A5E77BA835}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CCS\Services\Tcpip\..\{EB32C56F-2D77-449B-9A0A-38CA0962A829}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CS1\Services\Tcpip\..\{0B81E8EC-1481-43A0-87D1-44DAAAE432DD}: DhcpNameServer = 10.10.0.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{18511CB2-5570-42C3-A170-D9B64AB53AFC}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CS1\Services\Tcpip\..\{6A6A2D50-4D5C-449E-B48F-8BC1BB37C580}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{D49B27BF-1509-47E3-B660-0619F2E5986A}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CS1\Services\Tcpip\..\{D4E97DF3-D78B-46DA-B447-E9A5E77BA835}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CS1\Services\Tcpip\..\{EB32C56F-2D77-449B-9A0A-38CA0962A829}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CS2\Services\Tcpip\..\{0B81E8EC-1481-43A0-87D1-44DAAAE432DD}: DhcpNameServer = 10.10.0.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{18511CB2-5570-42C3-A170-D9B64AB53AFC}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CS2\Services\Tcpip\..\{6A6A2D50-4D5C-449E-B48F-8BC1BB37C580}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{D49B27BF-1509-47E3-B660-0619F2E5986A}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CS2\Services\Tcpip\..\{D4E97DF3-D78B-46DA-B447-E9A5E77BA835}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CS2\Services\Tcpip\..\{EB32C56F-2D77-449B-9A0A-38CA0962A829}: DhcpNameServer = 212.27.40.240 212.27.40.241 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.240 212.27.40.241 ~ Domain: Scanned in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) -- O18 - Filter: text/xml [64Bits] - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.dll =>.Microsoft Corporation ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: KMService (KMService) . (...) - C:\Windows\SysWOW64\srvany.exe =>Hijacker.Office ~ Services: 25 Legitimates Filtered in 00mn 09s ---\\ Tâches planifiées en automatique (O39) O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Digital Sites.job [300] O39 - APT:Automatic Planified Task - C:\Windows\Tasks\DigitalSite.job [300] =>Hijacker.DSite O39 - APT:Automatic Planified Task - C:\Windows\Tasks\SoftwareUpdateTaskMachineCore.job [1084] O39 - APT:Automatic Planified Task - C:\Windows\Tasks\SoftwareUpdateTaskMachineUA.job [1088] [MD5.1D915D5E8E564B00C2AC53BE2805EB0B] [APT] [Digital Sites] (...) -- C:\Users\sheitan\AppData\Roaming\DIGITA~2\UPDATE~1\UPDATE~1.exe [113152] [MD5.C7ACCBE7E79C17F230B44367A8A3CCD2] [APT] [DigitalSite] (...) -- C:\Users\sheitan\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.exe [101376] =>Hijacker.DSite [MD5.00000000000000000000000000000000] [APT] [Run RoboForm TaskBar Icon] (...) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (.not file.) [0] [MD5.251A1AED2D4A26A47C0A4A3058AAE4A8] [APT] [SoftwareUpdateTaskMachineCore] (.Boxore OU..) -- C:\Program Files (x86)\Software\Update\SoftwareUpdate.exe [139576] =>Adware.Boxore [MD5.251A1AED2D4A26A47C0A4A3058AAE4A8] [APT] [SoftwareUpdateTaskMachineUA] (.Boxore OU..) -- C:\Program Files (x86)\Software\Update\SoftwareUpdate.exe [139576] =>Adware.Boxore [MD5.00000000000000000000000000000000] [APT] [{178F065C-ED55-4191-A7C6-38F8879A5295}] (...) -- C:\Program Files (x86)\Rockstar Games\L.A. Noire\LANLauncher.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{25603B9A-416D-46E0-B8DE-688B3B94BCD8}] (...) -- D:\Setup.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{2C1FA0A6-81A5-48D5-8240-F5D93450EF93}] (...) -- C:\Program Files (x86)\Rockstar Games\Max Payne 2\MaxPayne2.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{4AFB6321-5095-4ED5-B252-23008E9158AA}] (...) -- D:\FR_Fallout_3_DLC.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{6614B2DC-934C-4C98-95A2-E403E8F90D19}] (...) -- D:\Install.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{7F1615F7-72F0-4666-9E42-A5F68333556E}] (...) -- D:\Setup.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{80226650-F477-47CE-8A06-7EC471EE2D62}] (...) -- D:\Install.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{81DA949B-C018-4C4F-8F27-9934A5B9B016}] (...) -- C:\Program Files (x86)\Rockstar Games\L.A. Noire\LANLauncher.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{89C40967-26A7-439A-9B4F-BB144D8E3138}] (...) -- D:\Install.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{8C7B35EC-8186-423B-820C-E4D64542B648}] (...) -- D:\Setup.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{8EF15DCC-6BD3-41C8-B858-ADFA02D363F7}] (...) -- D:\Install.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{96488E12-AFE9-465F-8DBB-1E6FCE5CC183}] (...) -- D:\Install.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{B434C67E-37C0-4F72-8C1C-107EE1064A22}] (...) -- C:\Users\sheitan\Downloads\L12V2-FR.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{B65F8CD2-3D14-458D-B2F0-2C0C5244907C}] (...) -- D:\Setup.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{BA212B17-5FA3-4382-8ED9-99099E1FEF5E}] (...) -- C:\Users\sheitan\Desktop\freeNAS\physdiskwrite.exe (.not file.) [0] [MD5.01C551508D00D3479A5D9171E05F4A4A] [APT] [{BD1C699C-5508-47D0-87AA-1A36B8F3C4A9}] (.Bitvise.) -- C:\Program Files (x86)\Bitvise SSH Client\uninst.exe [357984] [MD5.00000000000000000000000000000000] [APT] [{C990163E-C45C-423B-9C3E-9F2FBDAA32E6}] (...) -- D:\Install.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{F01A2DC6-CD1E-49F1-AB9C-FBBC8A486EDC}] (...) -- C:\Users\sheitan\Documents\asus_Update\Setup.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{F4C8E2AC-D1D3-43BC-A14B-BDF9FF95347C}] (...) -- C:\Program Files (x86)\Rockstar Games\Max Payne 2\MaxPayne2.exe (.not file.) [0] ~ Scheduled Task: 50 Legitimates Filtered in 00mn 04s ---\\ Logiciels installés (O42) O42 - Logiciel: Boxore Client - (.Boxore OU.) [HKLM][64Bits] -- {0E365FDA-909F-4939-838A-261DD468D862} =>Adware.Boxore O42 - Logiciel: BrowseToSave - (...) [HKLM][64Bits] -- {F3DA0622-A699-4551-A7BA-EEBB283924D4} =>Adware.Browse2Save O42 - Logiciel: DomaIQ - (.Tuguu SLU.) [HKLM][64Bits] -- DomaIQ Uninstaller =>PUP.VAFPlayer O42 - Logiciel: EAX(tm) Unified (SHELL) - (...) [HKLM][64Bits] -- EAX(tm) Unified (SHELL) O42 - Logiciel: LyricsTube - (.Hansen & Destar Apps.) [HKLM][64Bits] -- lrcsTube@hansanddeta.com =>Adware.AddLyrics O42 - Logiciel: My Lockbox 2.8.7 - (...) [HKLM][64Bits] -- My Lockbox_is1 O42 - Logiciel: Search Assistant WebSearch 1.74 - (...) [HKLM][64Bits] -- SP_4e24eecb O42 - Logiciel: Supreme Savings - (.215 Apps.) [HKLM][64Bits] -- Supreme Savings =>PUP.RewardsArcade O42 - Logiciel: Update for Funmoods Chat - (.Update for Funmoods Chat.) [HKCU][64Bits] -- Funmoods Chat =>PUP.Funmoods O42 - Logiciel: Update for Video Converter - (...) [HKCU][64Bits] -- DigitalSite =>Hijacker.DSite O42 - Logiciel: Updater Service - (...) [HKLM][64Bits] -- Updater Service =>Adware.IncrediBar O42 - Logiciel: YoutubeAdblocker - (.YoutubeAdblocker.) [HKLM][64Bits] -- {4820778D-AB0D-6D18-C316-52A6A0E1D507} =>PUP.TubeAdBlocker O42 - Logiciel: YoutubeAdblocker - (.YoutubeAdblocker.) [HKLM][64Bits] -- {CF830981-8F31-C561-C7A0-FE2CE1878B40} =>PUP.TubeAdBlocker O42 - Logiciel: websiave - (.websave.) [HKLM][64Bits] -- {476D78C4-1DB0-2D88-7FCC-AA6559F59A8D} =>PUP.Websave ~ Logic: 45 Legitimates Filtered in 00mn 00s ---\\ HKCU & HKLM Software Keys [HKCU\Software\1ClickDownload] =>PUP.1ClickDownloader [HKCU\Software\5e6dd88b46aba43] =>PUP.Babylon [HKCU\Software\BabSolution] =>Hijacker.BabSolution [HKCU\Software\BabylonToolbar] =>PUP.Babylon [HKCU\Software\Boxore] =>Adware.Boxore [HKCU\Software\Conduit] =>Toolbar.Conduit [HKCU\Software\CrystalBP] [HKCU\Software\DataMngr] =>PUP.Datamngr [HKCU\Software\DataMngr_Toolbar] =>PUP.Datamngr [HKCU\Software\Dreampainters] [HKCU\Software\FMChat] [HKCU\Software\FTPRush] [HKCU\Software\Faux] [HKCU\Software\FileScout] =>PUP.FileScout [HKCU\Software\FindMySoft] [HKCU\Software\Funmoods] =>PUP.Funmoods [HKCU\Software\Iminent] =>Adware.IMBooster [HKCU\Software\InstallCore] =>Adware.InstallCore [HKCU\Software\InstalledBrowserExtensions] =>Adware.VidSaver [HKCU\Software\Smartbar] =>Hijacker.SmartBar [HKCU\Software\Softonic] =>Toolbar.Conduit [HKLM\Software\DomaIQ] =>Adware.DomaIQ [HKLM\Software\Tarma Installer] =>PUP.Tarma [HKLM\Software\Wow6432Node\5e6dd88b46aba43] =>PUP.Babylon [HKLM\Software\Wow6432Node\Babylon] =>PUP.Babylon [HKLM\Software\Wow6432Node\Boxore] =>Adware.Boxore [HKLM\Software\Wow6432Node\DataMngr] =>PUP.Datamngr [HKLM\Software\Wow6432Node\Debian] [HKLM\Software\Wow6432Node\Iminent] =>Adware.IMBooster [HKLM\Software\Wow6432Node\SP Global] =>PUP.AdvancedSystemProtector [HKLM\Software\Wow6432Node\SProtector] =>PUP.Mocaflix [HKLM\Software\Wow6432Node\TheChineseRoom] [HKLM\Software\Wow6432Node\mdr] ~ Key Software: 638 Legitimates Filtered in 00mn 00s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 10/04/2014 - 13:11:44 - [2,999] ----D C:\Program Files (x86)\Boxore =>Adware.Boxore O43 - CFD: 17/04/2013 - 22:31:48 - [1,473] ----D C:\Program Files (x86)\BrowseToSave =>Adware.Browse2Save O43 - CFD: 28/06/2013 - 00:01:08 - [0,269] ----D C:\Program Files (x86)\LyricsTube =>Adware.AddLyrics O43 - CFD: 22/11/2012 - 22:35:06 - [17,198] ----D C:\Program Files (x86)\MagicDVDRipper O43 - CFD: 22/11/2012 - 22:35:36 - [0,313] ----D C:\Program Files (x86)\Red Sky =>Adware.DownTango O43 - CFD: 28/04/2013 - 22:51:39 - [0] ----D C:\Program Files (x86)\SingAlong =>Adware.Singalng O43 - CFD: 17/02/2014 - 00:51:19 - [0] ----D C:\Program Files (x86)\SSearuch-NewTab =>Adware.FastSaveApp O43 - CFD: 28/06/2013 - 00:01:05 - [3,240] ----D C:\Program Files (x86)\Supreme Savings =>PUP.RewardsArcade O43 - CFD: 22/11/2012 - 22:36:08 - [0,665] ----D C:\Program Files (x86)\thechineseroom O43 - CFD: 17/04/2013 - 22:33:09 - [1,470] ----D C:\Program Files (x86)\WebSearch O43 - CFD: 10/03/2014 - 05:13:55 - [0] ----D C:\Program Files (x86)\websiave =>PUP.Websave O43 - CFD: 17/02/2014 - 00:45:33 - [0] ----D C:\Program Files (x86)\weebsAvee =>PUP.Websave O43 - CFD: 16/03/2014 - 19:10:28 - [0] ----D C:\Program Files (x86)\WS-Booster O43 - CFD: 17/02/2014 - 00:45:57 - [0] ----D C:\Program Files (x86)\YoutubeAdblocker =>PUP.TubeAdBlocker O43 - CFD: 10/03/2014 - 05:13:55 - [0,253] ----D C:\ProgramData\787c65387cd1d2e1 O43 - CFD: 05/10/2012 - 14:51:13 - [0] ----D C:\ProgramData\Babylon =>PUP.Babylon O43 - CFD: 20/05/2013 - 17:40:18 - [0,322] ----D C:\ProgramData\BBrowsye2savve =>Adware.Browse2Save O43 - CFD: 12/03/2014 - 19:32:06 - [0] ----D C:\ProgramData\BoxUpdChk =>Adware.Boxore O43 - CFD: 03/02/2013 - 17:31:48 - [0,309] ----D C:\ProgramData\Browse2save =>Adware.Browse2Save O43 - CFD: 17/02/2014 - 00:51:14 - [0] ----D C:\ProgramData\GreatSoft O43 - CFD: 28/03/2013 - 07:18:13 - [0,584] ----D C:\ProgramData\IBUpdaterService =>Adware.InstallBrain O43 - CFD: 10/03/2014 - 05:12:25 - [7,511] ----D C:\ProgramData\InstallMate =>PUP.Tarma O43 - CFD: 17/02/2013 - 13:36:36 - [0] ----D C:\ProgramData\MasterTools O43 - CFD: 25/02/2014 - 04:24:36 - [0] ----D C:\ProgramData\SSearuch-NewTab =>Adware.FastSaveApp O43 - CFD: 22/11/2012 - 22:38:31 - [2,483] ----D C:\ProgramData\Tarma Installer =>PUP.Tarma O43 - CFD: 10/03/2014 - 05:13:55 - [0,446] ----D C:\ProgramData\websiave =>PUP.Websave O43 - CFD: 17/02/2014 - 00:45:33 - [0,408] ----D C:\ProgramData\weebsAvee =>PUP.Websave O43 - CFD: 17/02/2014 - 00:46:39 - [0,821] ----D C:\ProgramData\YoutubeAdblocker =>PUP.TubeAdBlocker O43 - CFD: 22/11/2012 - 22:56:11 - [0,014] ----D C:\Users\sheitan\AppData\Roaming\Babylon =>PUP.Babylon O43 - CFD: 28/03/2013 - 07:18:15 - [0,308] ----D C:\Users\sheitan\AppData\Roaming\File Scout =>PUP.FileScout O43 - CFD: 04/02/2013 - 23:57:56 - [0,144] ----D C:\Users\sheitan\AppData\Roaming\FTPRush O43 - CFD: 02/02/2014 - 01:00:37 - [0] ----D C:\Users\sheitan\AppData\Roaming\Funmoods =>PUP.Funmoods O43 - CFD: 06/02/2014 - 01:40:21 - [0] ----D C:\Users\sheitan\AppData\Roaming\FunmoodsChat =>PUP.Funmoods O43 - CFD: 22/11/2012 - 22:56:20 - [31,236] ----D C:\Users\sheitan\AppData\Roaming\OpenCandy =>Adware.OpenCandy O43 - CFD: 27/12/2012 - 14:43:28 - [14,130] ----D C:\Users\sheitan\AppData\Roaming\{287f1079-8b80-4988-ad74-bc713a00863b} O43 - CFD: 27/12/2012 - 14:51:31 - [14,130] ----D C:\Users\sheitan\AppData\Roaming\{6fc7e593-b058-4c9e-892e-4e4402337b23} O43 - CFD: 28/12/2012 - 12:49:16 - [14,130] ----D C:\Users\sheitan\AppData\Roaming\{860300b9-5e1a-4c88-a089-48ff8d48e346} O43 - CFD: 27/12/2012 - 15:01:56 - [14,130] ----D C:\Users\sheitan\AppData\Roaming\{9775825f-e4c4-41f8-aff7-9507b34ac7bd} O43 - CFD: 27/12/2012 - 16:53:40 - [14,130] ----D C:\Users\sheitan\AppData\Roaming\{cb6820b2-6882-424a-8872-42ad29d17259} O43 - CFD: 16/01/2013 - 03:20:07 - [0,042] ----D C:\Users\sheitan\AppData\Local\76561198064861272 O43 - CFD: 28/09/2013 - 18:54:43 - [0] ----D C:\Users\sheitan\AppData\Local\paginaEpubChecker O43 - CFD: 17/03/2013 - 13:48:24 - [0,063] ----D C:\Users\sheitan\AppData\Local\Supreme Savings =>PUP.RewardsArcade O43 - CFD: 25/06/2013 - 00:48:16 - [0] ----D C:\Users\sheitan\AppData\Local\Updater19962 =>PUP.CrossRider O43 - CFD: 03/09/2012 - 23:54:54 - [0] --HAD C:\Users\sheitan\AppData\Local\wAYZT6vLuntM O43 - CFD: 22/11/2012 - 22:56:19 - [0,004] ----D C:\Users\sheitan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My Lockbox ~ 8 Dossier CLSID vide (CLSID Empty Folder) ~ Program Folder: 395 Legitimates Filtered in 00mn 06s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.EEEA1767126F89308ADA93E78CB3C728] - 13/04/2014 - 01:34:14 ---A- . (...) -- C:\colorbox.log [451] O44 - LFC:[MD5.323D1732C6483A9BD97A3A6D45A6AC45] - 13/04/2014 - 13:02:41 ---A- . (...) -- C:\Windows\AutoKMS.log [2373] ~ Files: 37 Legitimates Filtered in 00mn 01s ---\\ Derniers fichiers créés dans Windows Prefetcher (O45) O45 - LFCP:[MD5.253292BDEF21CFFF3F039D288366E0CA] - 13/04/2014 - 18:09:21 ---A- - C:\Windows\Prefetch\SUBLIME_TEXT.EXE-5E61774C.pf O45 - LFCP:[MD5.DD1F8ECA1DCF65D5E273CF83F87ACF62] - 13/04/2014 - 21:56:12 ---A- - C:\Windows\Prefetch\MINIROSETTA_3.48_WINDOWS_X86_-B14E99C2.pf O45 - LFCP:[MD5.9B154EBAED7B7E79EFD5E7A18BD45DCB] - 13/04/2014 - 22:01:00 ---A- - C:\Windows\Prefetch\UPDATE~1.EXE-AD5B06A0.pf ~ Prefetcher: 3 Legitimates Filtered in 00mn 00s ---\\ Opérations et fonctions au démarrage de Windows Explorer (O46) O46 - SEH:ShellExecuteHooks - Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL O46 - SEH:ShellExecuteHooks - Groove GFS Stub Execution Hook [64Bits] - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL ~ ShellExecuteHooks: Scanned in 00mn 00s ---\\ Clé de registre Shell MountPoints2 (MPKS) (O51) O51 - MPSK:{80bed94c-3664-11e2-a59e-002683331f95}\AutoRun\command. (.Pas de propriétaire - METAL GEAR RISING: REVENGEANCE (c) Konami Digital Entertainm.) -- G:\setup.exe O51 - MPSK:{b50c5a4a-0913-11e3-a21e-806e6f6e6963}\AutoRun\command. (...) -- D:\.\Bin\ASSETUP.exe (.not file.) ~ Keys: Scanned in 00mn 00s ---\\ Enumération des clés de registre StartupReg (SMSR) (O53) O53 - SMSR:HKLM\...\startupreg\SYMPHONYSound [Key] . (...) -- C:\Program Files\Corsair VENGEANCE 2000\CPL\CAHS2.exe (.not file.) ~ SMSR Keys: 30 Legitimates Filtered in 00mn 00s ---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ MWPS: 16 Legitimates Filtered in 00mn 00s ---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56) O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 ~ MWPE Keys: 4 Legitimates Filtered in 00mn 00s ---\\ Liste des pilotes du système (SDL) (O58) O58 - SDL:[MD5.518B8D447A1975AB46DA093A2E743256] - 27/06/2012 - 21:33:54 ---A- . (.ALWIL Software - avast! Filtering NDIS driver.) -- C:\Windows\System32\Drivers\aswNdis.sys [12368] O58 - SDL:[MD5.5573AA70993A2BB81525B1C704B88763] - 09/05/2013 - 09:59:07 ---A- . (...) -- C:\Windows\System32\Drivers\aswRvrt.sys [65336] O58 - SDL:[MD5.2E83D2621E87C493AB45DC6655BA77D4] - 11/08/2013 - 17:04:25 ---A- . (...) -- C:\Windows\System32\Drivers\aswSnx.sys.sum [175] O58 - SDL:[MD5.A5F29AC2F0ADE8B995B49D7350CE3AC0] - 11/08/2013 - 17:04:26 ---A- . (...) -- C:\Windows\System32\Drivers\aswSP.sys.sum [175] O58 - SDL:[MD5.22F521108881DC59837F6FC614E0568F] - 11/08/2013 - 17:04:26 ---A- . (...) -- C:\Windows\System32\Drivers\aswVmm.sys [189936] O58 - SDL:[MD5.E86C64478D9A90D62255FE9EB0150C6E] - 11/08/2013 - 17:04:27 ---A- . (...) -- C:\Windows\System32\Drivers\aswvmm.sys.sum [175] O58 - SDL:[MD5.4119870B90E1B5E7797D6433D21F9216] - 13/03/2011 - 09:58:42 ---A- . (.Windows (R) Win 7 DDK provider - BulkUsb Driver.) -- C:\Windows\System32\Drivers\AthDfu.sys [51872] O58 - SDL:[MD5.46571ED73AE84469DCA53081D33CF3C8] - 24/11/2012 - 20:16:20 ---A- . (.DT Soft Ltd - DAEMON Tools Virtual Bus Driver.) -- C:\Windows\System32\Drivers\dtsoftbus01.sys [283200] O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496] O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232] O58 - SDL:[MD5.748EEDBB095FE6535C7E3616AEBC533F] - 16/05/2012 - 10:15:12 ---A- . (.Pas de propriétaire - iLok Kernel Driver.) -- C:\Windows\System32\Drivers\iLokDrvr.sys [25752] O58 - SDL:[MD5.D6AB7C13FCDD2E4CAC35244D2C172D9A] - 21/11/2012 - 19:17:52 ---A- . (.Duplex Secure Ltd. - SCSI Pass Through Direct Host.) -- C:\Windows\System32\Drivers\sptd.sys [564824] O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656] O58 - SDL:[MD5.F0B9D3ED88E56D3CD713DFF21E42AAF0] - 01/07/2011 - 10:46:40 ---A- . (.The OpenVPN Project - TAP-Win32 Virtual Network Driver.) -- C:\Windows\System32\Drivers\tap0901.sys [31232] O58 - SDL:[MD5.FEF9DD9EA587F8886ADE43C1BEFBDAFE] - 24/08/2010 - 15:16:40 ---A- . (...) -- C:\Windows\SysWOW64\drivers\AsIO.sys [13440] O58 - SDL:[MD5.1392B92179B07B672720763D9B1028A5] - 03/08/2010 - 13:21:24 ---A- . (...) -- C:\Windows\SysWOW64\drivers\AsUpIO.sys [14464] O58 - SDL:[MD5.19166026A93206F9C6A8CD3A1F010AE4] - 02/04/2009 - 13:30:14 ---A- . (...) -- C:\Windows\SysWOW64\drivers\ASUSHWIO.SYS [10296] ~ Drivers: 16 Legitimates Filtered in 00mn 00s ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) O61 - LFC: 10/04/2014 - 23:25:20 ---A- . (...) -- C:\Users\sheitan\AppData\Roaming\Opera Software\Opera Stable\History [94208] O61 - LFC: 10/04/2014 - 23:26:24 -SHA- . (...) -- C:\Users\sheitan\Videos\TheProdigy-GreatestHits2009320\Thumbs.db [13824] O61 - LFC: 11/04/2014 - 23:25:15 ---A- . (...) -- C:\Users\sheitan\.lexpersona\log\lpauth.log.1 [1748] O61 - LFC: 11/04/2014 - 23:25:15 ---A- . (...) -- C:\Users\sheitan\.lexpersona\log\lpauth.log.1.lck [0] O61 - LFC: 11/04/2014 - 23:25:15 ---A- . (...) -- C:\Users\sheitan\.lexpersona\log\lpauth.log.lck [0] O61 - LFC: 11/04/2014 - 23:25:17 ---A- . (...) -- C:\Users\sheitan\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.2.464\_platform_specific\win_x86\CdmAdapterVersion [13] O61 - LFC: 11/04/2014 - 23:26:22 ---A- . (.Tim Kosse.) -- C:\Users\sheitan\Downloads\FileZilla_3.8.0_win32-setup.exe [4968079] O61 - LFC: 11/04/2014 - 23:26:23 ---A- . (...) -- C:\Users\sheitan\Downloads\shiroi.zip [485668] O61 - LFC: 12/04/2014 - 23:25:20 ---A- . (...) -- C:\Users\sheitan\AppData\Roaming\DigitalSite\UpdateProc\info.dat [56] =>Hijacker.DSite O61 - LFC: 12/04/2014 - 23:25:20 ---A- . (...) -- C:\Users\sheitan\AppData\Roaming\DigitalSites\UpdateProc\info.dat [67] =>Hijacker.DSite O61 - LFC: 12/04/2014 - 23:25:21 ---A- . (...) -- C:\Users\sheitan\AppData\Roaming\Sublime Text 2\Packages\User\Package Control.cache\9d19c4dd6192810c18ab5785c55e208d [3028] O61 - LFC: 12/04/2014 - 23:25:21 ---A- . (...) -- C:\Users\sheitan\AppData\Roaming\Sublime Text 2\Packages\User\Package Control.cache\9d19c4dd6192810c18ab5785c55e208d.info [109] O61 - LFC: 12/04/2014 - 23:25:21 ---A- . (...) -- C:\Users\sheitan\AppData\Roaming\Sublime Text 2\Packages\User\Package Control.cache\ecf295d4fbe2115040f7d0eb5ab8ead4 [12797] O61 - LFC: 12/04/2014 - 23:25:21 ---A- . (...) -- C:\Users\sheitan\AppData\Roaming\Sublime Text 2\Packages\User\Package Control.cache\ecf295d4fbe2115040f7d0eb5ab8ead4.info [109] O61 - LFC: 12/04/2014 - 23:25:21 ---A- . (...) -- C:\Users\sheitan\AppData\Roaming\WB.CFG [256] O61 - LFC: 12/04/2014 - 23:26:20 -SHA- . (...) -- C:\Users\sheitan\Documents\ecrits\Thumbs.db [52224] O61 - LFC: 12/04/2014 - 23:26:23 ---A- . (...) -- C:\Users\sheitan\Downloads\Tarifs_So_Colissimo.pdf [549840] O61 - LFC: 12/04/2014 - 23:26:23 ---A- . (...) -- C:\Users\sheitan\Downloads\sitemap.xml [3182] O61 - LFC: 13/04/2014 - 23:25:17 ---A- . (...) -- C:\Users\sheitan\AppData\Local\Google\Chrome\User Data\Certificate Revocation Lists [292498] O61 - LFC: 13/04/2014 - 23:25:17 ---A- . (...) -- C:\Users\sheitan\AppData\Local\Google\Chrome\User Data\Local State [72144] O61 - LFC: 13/04/2014 - 23:25:21 ---A- . (...) -- C:\Users\sheitan\AppData\Roaming\Sublime Text 2\Packages\User\Package Control.cache\ad7758d143e99a76034aad71ae2a1f3b [1425489] O61 - LFC: 13/04/2014 - 23:25:21 ---A- . (...) -- C:\Users\sheitan\AppData\Roaming\Sublime Text 2\Packages\User\Package Control.cache\ad7758d143e99a76034aad71ae2a1f3b.info [75] O61 - LFC: 13/04/2014 - 23:25:21 ---A- . (...) -- C:\Users\sheitan\AppData\Roaming\Sublime Text 2\Packages\User\Package Control.last-run [10] O61 - LFC: 13/04/2014 - 23:25:21 ---A- . (...) -- C:\Users\sheitan\AppData\Roaming\Sublime Text 2\Settings\Auto Save Session.sublime_session [40680] O61 - LFC: 13/04/2014 - 23:25:21 ---A- . (...) -- C:\Users\sheitan\AppData\Roaming\Sublime Text 2\Settings\Session.sublime_session [40694] O61 - LFC: 13/04/2014 - 23:26:22 ---A- . (...) -- C:\Users\sheitan\Downloads\INVOICE_2141802565_29917440.pdf [197362] ~ 2 Fichiers cookies (Cookies files) ~ Files: 356 Legitimates Filtered in 01mn 09s ---\\ Fichiers Alternate Data Stream (ADS) (O62) O62 - ADS:Alternate Data Stream File - C:\Windows\System32\D3DX9_43.dll:Zone.Identifier ~ ADS: Scanned in 00mn 00s ---\\ Liste des outils de désinfection (LATC) (O63) O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman ~ ADS: Scanned in 00mn 00s ---\\ Associations Shell Spawning (O67) O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Not Key.) ~ FASS Keys: 11 Legitimates Filtered in 00mn 00s ---\\ Menu de démarrage Internet (SMI) (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Opera Software - Opera Internet Browser.) -- C:\Program Files (x86)\Opera\Launcher.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Apple Inc. - Safari.) -- C:\Program Files (x86)\Safari\Safari.exe ~ Keys: Scanned in 00mn 00s ---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69) O69 - SBI: prefs.js [sheitan - 0v7vsx8w.default] user_pref("browser.newtab.url", "http://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=EB_SSP[...] O69 - SBI: SearchScopes [HKCU] {006ee092-9658-4fd6-bd8e-a21a348e59f5} - (Web Search) - http://feed.helperbar.com =>PUP.HelperBar O69 - SBI: SearchScopes [HKCU] {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} - (Conduit Search) - http://search.conduit.com O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} - (Delta Search) - http://www.delta-search.com =>Toolbar.DeltaSearch O69 - SBI: SearchScopes [HKCU] {12014BBA-BA04-4def-94F5-DF924CF23995} - (Google) - http://www.google.com O69 - SBI: SearchScopes [HKCU] {1ED8E307-00AD-436d-A5D0-6A4B42836B9F} [DefaultScope] - (Yahoo) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {67F5AE55-B8C9-F0BF-21F4-49B9957B632F} - (Web Search) - http://feed.helperbar.com =>PUP.HelperBar O69 - SBI: SearchScopes [HKCU] {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} - (WebSearch) - http://websearch.searchsun.info ~ Keys: Scanned in 00mn 00s ---\\ Enumère les fichiers Crack & Keygen (CKF) (O82) C:\Users\sheitan\Downloads\activateur\Resources\KMSKG\Keygen.exe =>.Crack,Keygen C:\Users\sheitan\Downloads\activateur\Resources\KMSKG\Keygen.exe =>.Crack,Keygen ~ Files: Scanned in 08mn 32s ---\\ Liste des exceptions du parefeu (FirewallRules) (O87) O87 - FAEL: "UDP Query User{FC166497-9989-4A8F-86FC-54A06F8389F5}G:\jeux_pc\american mcgee's alice\alice.exe" |In - Public - P17 - TRUE | .(...) -- G:\jeux_pc\american mcgee's alice\alice.exe (.not file.) O87 - FAEL: "TCP Query User{0FC7B0BC-0072-4446-943E-735D7A986C24}G:\jeux_pc\american mcgee's alice\alice.exe" |In - Public - P6 - TRUE | .(...) -- G:\jeux_pc\american mcgee's alice\alice.exe (.not file.) O87 - FAEL: "UDP Query User{527133D6-E9D7-4D64-B6EB-2D5D1AA7E64C}C:\program files (x86)\thechineseroom\dear esther\dearesther.exe" |In - Public - P17 - TRUE | .(...) -- C:\program files (x86)\thechineseroom\dear esther\dearesther.exe (.not file.) O87 - FAEL: "TCP Query User{408D15F8-2814-4E0E-81EE-CDBE38AE95E4}C:\program files (x86)\thechineseroom\dear esther\dearesther.exe" |In - Public - P6 - TRUE | .(...) -- C:\program files (x86)\thechineseroom\dear esther\dearesther.exe (.not file.) O87 - FAEL: "UDP Query User{E9A43461-F0A7-45F6-A208-D8A24825480B}C:\program files\i am alive\src\system\iamalive_game.exe" |In - Public - P17 - TRUE | .(...) -- C:\program files\i am alive\src\system\iamalive_game.exe (.not file.) O87 - FAEL: "TCP Query User{997C1E11-22F6-454F-9BD1-27DEC975A63E}C:\program files\i am alive\src\system\iamalive_game.exe" |In - Public - P6 - TRUE | .(...) -- C:\program files\i am alive\src\system\iamalive_game.exe (.not file.) O87 - FAEL: "UDP Query User{B115D7FE-7B5E-4A1C-8276-92776BDE202E}G:\r.g. catalyst\dear esther\dearesther.exe" |In - Public - P17 - TRUE | .(...) -- G:\r.g. catalyst\dear esther\dearesther.exe (.not file.) O87 - FAEL: "TCP Query User{EE07F9BA-3C2B-4249-9C5E-165B1D4036BD}G:\r.g. catalyst\dear esther\dearesther.exe" |In - Public - P6 - TRUE | .(...) -- G:\r.g. catalyst\dear esther\dearesther.exe (.not file.) O87 - FAEL: "UDP Query User{FA7232B0-8970-45D0-9B1A-21CFF51FD5D4}C:\program files (x86)\bethesda softworks\dishonored\binaries\win32\dishonored.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files (x86)\bethesda softworks\dishonored\binaries\win32\dishonored.exe (.not file.) O87 - FAEL: "TCP Query User{1784CDEF-78F0-4A1F-AE98-98E9706B2A3D}C:\program files (x86)\bethesda softworks\dishonored\binaries\win32\dishonored.exe" |In - Private - P6 - TRUE | .(...) -- C:\program files (x86)\bethesda softworks\dishonored\binaries\win32\dishonored.exe (.not file.) O87 - FAEL: "UDP Query User{55567E3C-06AD-48B4-BF6B-8296209FB305}C:\program files (x86)\bethesda softworks\dishonored\binaries\win32\dishonored.exe" |In - Public - P17 - TRUE | .(...) -- C:\program files (x86)\bethesda softworks\dishonored\binaries\win32\dishonored.exe (.not file.) O87 - FAEL: "TCP Query User{1FEF7A23-4907-4A12-92DB-EAC105977B61}C:\program files (x86)\bethesda softworks\dishonored\binaries\win32\dishonored.exe" |In - Public - P6 - TRUE | .(...) -- C:\program files (x86)\bethesda softworks\dishonored\binaries\win32\dishonored.exe (.not file.) O87 - FAEL: "UDP Query User{13CF097D-560C-4E76-B827-C33183FE6A2D}C:\windows\keygen.exe" |In - Public - P17 - TRUE | .(...) -- C:\windows\keygen.exe (.not file.) O87 - FAEL: "TCP Query User{BF1C4B1A-7EE2-47E2-9D94-D1A0BCD29B1E}C:\windows\keygen.exe" |In - Public - P6 - TRUE | .(...) -- C:\windows\keygen.exe (.not file.) O87 - FAEL: "{BE9D70DE-F876-4B78-A76E-97BE973C47B6}" |In - Public - P6 - TRUE | .(...) -- C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\iPhone Simulator\pnSvc.exe (.not file.) O87 - FAEL: "TCP Query User{A29E5617-CEB1-4ADD-8A3D-59488FEEFBE5}C:\program files (x86)\xming\xming.exe" |In - Private - P6 - TRUE | .(...) -- C:\program files (x86)\xming\xming.exe (.not file.) O87 - FAEL: "UDP Query User{21D5B67A-D1AF-4083-AE6B-107217483610}C:\program files (x86)\xming\xming.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files (x86)\xming\xming.exe (.not file.) O87 - FAEL: "{1A73BC9B-8A1E-40CB-BA9A-9A34516B8FC0}" |In - Public - P17 - TRUE | .(...) -- C:\program files (x86)\xming\xming.exe (.not file.) O87 - FAEL: "{2228DBD9-BAD1-4BED-902B-F893BA64580E}" |In - Public - P6 - TRUE | .(...) -- C:\program files (x86)\xming\xming.exe (.not file.) O87 - FAEL: "TCP Query User{1A00CCA3-9B27-4D0D-9D77-278A0218BACB}C:\program files (x86)\bethesda softworks\fallout 3\fallout3.exe" |In - Private - P6 - TRUE | .(...) -- C:\program files (x86)\bethesda softworks\fallout 3\fallout3.exe (.not file.) O87 - FAEL: "UDP Query User{C84090FE-711C-446E-879F-6BD92D45130E}C:\program files (x86)\bethesda softworks\fallout 3\fallout3.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files (x86)\bethesda softworks\fallout 3\fallout3.exe (.not file.) O87 - FAEL: "{5E322EF6-DDA8-4EDC-A4DD-3AA607CB939F}" |In - Public - P17 - TRUE | .(...) -- C:\program files (x86)\bethesda softworks\fallout 3\fallout3.exe (.not file.) O87 - FAEL: "{9E5182D9-309F-4D97-A4AD-7A702AAB000A}" |In - Public - P6 - TRUE | .(...) -- C:\program files (x86)\bethesda softworks\fallout 3\fallout3.exe (.not file.) ~ Firewall: 416 Legitimates Filtered in 00mn 04s ---\\ Enumère les codes produits des logiciels (PUC) (O90) O90 - PUC: "058A22391909E0D42B25E328DE3A9DA4" . (.Prototype(TM).) -- C:\Windows\Installer\{9322A850-9091-4D0E-B252-3E82EDA3D94A}\ARPPRODUCTICON.exe O90 - PUC: "A81E737A17150D040843D72D34240018" . (.Software Updater.) -- C:\Windows\Installer\{A737E18A-5171-40D0-8034-7DD243420081}\icon.ico O90 - PUC: "ADF563E0F909939438A862D14D868D26" . (.Boxore Client.) -- C:\Windows\Installer\{0E365FDA-909F-4939-838A-261DD468D862}\boxore.ico =>Adware.Boxore O90 - PUC: "EE79CCCB261EC84488749517F82FB940" . (..) -- C:\Windows\Installer\{BCCC97EE-E162-448C-8847-59718FF29B04}\ARPPRODUCTICON.exe ~ Update Products: 178 Legitimates Filtered in 00mn 00s ---\\ Export de clés de registre aléatoires (O91) [HKCU\Software\5e6dd88b46aba43\2.6.1339.144\upd]:="upd=1" =>PUP.Babylon [HKCU\Software\5e6dd88b46aba43\2.6.1519.190\upd]:="upd=1" =>PUP.Babylon [HKCU\Software\5e6dd88b46aba43\history\{16cdff19-861d-48e3-a751-d99a27784753}2.3.762.17]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =>PUP.Babylon [HKCU\Software\5e6dd88b46aba43\history\{16cdff19-861d-48e3-a751-d99a27784753}2.3.762.17]:version="2.3.762.17" =>PUP.Babylon [HKCU\Software\5e6dd88b46aba43\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1123.78]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =>PUP.Babylon [HKCU\Software\5e6dd88b46aba43\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1123.78]:version="2.6.1123.78" =>PUP.Babylon [HKCU\Software\5e6dd88b46aba43\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1125.80]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =>PUP.Babylon [HKCU\Software\5e6dd88b46aba43\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1125.80]:version="2.6.1125.80" =>PUP.Babylon [HKCU\Software\5e6dd88b46aba43\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1249.132]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =>PUP.Babylon [HKCU\Software\5e6dd88b46aba43\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1249.132]:version="2.6.1249.132" =>PUP.Babylon [HKCU\Software\5e6dd88b46aba43\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1339.144]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =>PUP.Babylon [HKCU\Software\5e6dd88b46aba43\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1339.144]:version="2.6.1339.144" =>PUP.Babylon [HKCU\Software\5e6dd88b46aba43] =>PUP.Babylon^ [HKLM\Software\Wow6432Node\5e6dd88b46aba43] => Clé orpheline => Clé orpheline => Clé orpheline => Clé orpheline ~ Export Key Software: Scanned in 00mn 00s ---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS) [MD5.79BBAAC753ABDA50DF19030265F7D1A6] [WIS][10/04/2014] (.Boxore OU - Boxore Client Installer.) -- C:\Windows\Installer\2240b.msi [2473984] =>Adware.Boxore [MD5.F02BF56DFA8CC5953CB50F383A061F7A] [WIS][21/07/2009] (.CAPCOM CO., LTD. - RESIDENT EVIL 5.) -- C:\Windows\Installer\4a7d30f.msi [8012288] [MD5.B67811645C5A3B8E4E4B1A1DB1EE271C] [WIS][01/05/2013] (.Boxore OU. - Software Update Helper.) -- C:\Windows\Installer\8a9b4f.msi [45056] =>Adware.Boxore ~ WIS: 184 Legitimates Filtered in 00mn 23s ---\\ Recherche de clés de registre Tracing (O100) HKLM\SOFTWARE\Microsoft\Tracing\Azureus_RASAPI32 =>P2P.Azureus HKLM\SOFTWARE\Microsoft\Tracing\DomaIQ10_RASAPI32 =>Adware.DomaIQ HKLM\SOFTWARE\Microsoft\Tracing\DomaIQ10_RASMANCS =>Adware.DomaIQ HKLM\SOFTWARE\Microsoft\Tracing\PC Speed Master64_RASAPI32 =>Rogue.PCSpeedMaster HKLM\SOFTWARE\Microsoft\Tracing\PC Speed Master64_RASMANCS =>Rogue.PCSpeedMaster HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32 =>PUP.AdvancedSystemProtector HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS =>PUP.AdvancedSystemProtector HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\boxore_RASAPI32 =>Adware.Boxore HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\boxore_RASMANCS =>Adware.Boxore HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FunmoodsLatest_RASAPI32 =>PUP.Funmoods HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FunmoodsLatest_RASMANCS =>PUP.Funmoods HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\HAL7600_v1_RASAPI32 =>Hijacker.Windows7 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\HAL7600_v1_RASMANCS =>Hijacker.Windows7 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Iminent_RASAPI32 =>Adware.IMBooster HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Iminent_RASMANCS =>Adware.IMBooster HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MyBabylonTB_RASAPI32 =>PUP.Babylon HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MyBabylonTB_RASMANCS =>PUP.Babylon HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SingAlong_RASAPI32 =>Adware.Singalng HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SingAlong_RASMANCS =>Adware.Singalng HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\supreme savings-bg_RASAPI32 =>PUP.RewardsArcade HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\supreme savings-bg_RASMANCS =>PUP.RewardsArcade HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Supreme Savings_RASAPI32 =>PUP.RewardsArcade HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Supreme Savings_RASMANCS =>PUP.RewardsArcade HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\uTorrent_RASAPI32 =>P2P.µTorrent HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\uTorrent_RASMANCS =>P2P.µTorrent HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\VAFPlayer_RASAPI32 =>PUP.VAFPlayer HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\VAFPlayer_RASMANCS =>PUP.VAFPlayer HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\VuzeInstaller_RASAPI32 =>P2P.Azureus ~ BTK: 367 Legitimates Filtered in 00mn 00s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Demand 12/03/2014 257928 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe SS - | Demand 26/04/2011 2702848 | (FirebirdServerMAGIXInstance) . (.MAGIX®.) - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe SS - | Auto 01/11/2013 116648 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 01/11/2013 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Auto 17/10/2011 13592 | (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe SS - | Demand 03/04/2005 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe SS - | Demand 15/05/2013 641352 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe SS - | Auto 10/07/1658 0 | (KMService) . (...) - C:\Windows\system32\srvany.exe =>Hijacker.Office SS - | Auto 04/08/2013 2650960 | (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe SS - | Demand 18/03/2014 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe SS - | Auto 13/07/2012 769432 | (NAUpdate) . (.Nero AG.) - C:\Program Files (x86)\Nero\Update\NASvc.exe SS - | Auto 29/12/2012 1260472 | (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe SS - | Auto 21/06/2013 162408 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe SS - | Demand 15/03/2013 543656 | (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe SS - | Demand 19/02/2010 517096 | (SwitchBoard) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe SS - | Demand 13/05/2012 22016 | (wampapache) . (.Apache Software Foundation.) - c:\wamp\bin\apache\apache2.2.22\bin\httpd.exe SS - | Demand 19/04/2012 9693696 | (wampmysqld) . (...) - c:\wamp\bin\mysql\mysql5.5.24\bin\mysqld.exe SR - | Auto 21/12/2013 65432 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe SR - | Auto 07/10/2011 922240 | (asComSvc) . (...) - C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe SR - | Auto 07/10/2011 915584 | (asHmComSvc) . (...) - C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe SR - | Auto 07/10/2011 586880 | (AsSysCtrlService) . (...) - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe SR - | Auto 13/03/2011 74912 | (AtherosSvc) . (.Atheros Commnucations.) - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe SR - | Auto 26/10/2009 223464 | (BCUService) . (.DeviceVM, Inc..) - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe SR - | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe SR - | Auto 11/12/2011 135824 | (EpsonScanSvc) . (.Seiko Epson Corporation.) - C:\Windows\system32\EscSvc64.exe SR - | Auto 24/05/2011 1840128 | (Fabs) . (.MAGIX AG.) - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe SR - | Auto 12/08/2010 133800 | (Intel® PROSet Monitoring Service) . (.Intel Corporation.) - C:\Windows\system32\IProsetMonitor.exe SR - | Auto 17/07/2012 277824 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe SR - | Auto 18/01/2013 884512 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe SR - | Auto 18/05/2012 2938880 | (PaceLicenseDServices) . (.PACE Anti-Piracy, Inc..) - C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe SR - | Auto 10/07/1658 0 | (PnkBstrA) . (...) - C:\Windows\system32\PnkBstrA.exe SR - | Auto 18/01/2013 383264 | (Stereo Service) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe SR - | Auto 19/09/2012 1157056 | (WDBackup) . (.Western Digital.) - C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe SR - | Auto 19/09/2012 248248 | (WDDriveService) . (.Western Digital.) - C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe SR - | Auto 19/09/2012 1177536 | (WDRulesService) . (.Western Digital.) - C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation SR - | Auto 14/07/2009 27136 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Services: Scanned in 00mn 15s ---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80) Run by sheitan at 13/04/2014 23:35:45 ~ OS 64 not supported by MBR tool ~ MBR: 0 Legitimates Filtered in 00mn 00s ---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by sheitan at 13/04/2014 23:35:47 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 02s ---\\ Liste des émulateurs de CD/DVD (MBR Hook) O58 - SDL:[MD5.D6AB7C13FCDD2E4CAC35244D2C172D9A] - 21/11/2012 - 19:17:52 ---A- . (.Duplex Secure Ltd. - SCSI Pass Through Direct Host.) -- C:\Windows\System32\Drivers\sptd.sys [564824] ~ Emulateurs: Scanned in 00mn 02s ---\\ Scan Additionnel (O88) Database Version : 13044 - (13/04/2014) Clés trouvées (Keys found) : 292 Valeurs trouvées (Values found) : 3 Dossiers trouvés (Folders found) : 43 Fichiers trouvés (Files found) : 20 [HKLM\Software\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh] =>PUP.Funmoods^ [HKLM\Software\Google\Chrome\Extensions\bebdghdpchfhbbmfeddkijldlpnkbjkk] =>Adware.AddLyrics^ [HKLM\Software\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj] =>PUP.Funmoods^ [HKLM\Software\Google\Chrome\Extensions\gobmeekldnjpoafibilnjbnnhlaadhlp] =>PUP.Websave^ [HKLM\Software\Google\Chrome\Extensions\pbaohildkhbcljgoabiecdoinkaedlca] =>Spyware.SmartDisplay^ [HKLM\Software\Google\Chrome\Extensions\pbpohikckhbcljgombipcdoinkaedlfa] =>Spyware.SmartDisplay^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2088AC3-609F-6B40-7BC7-7564D892CEFA}] =>Adware.Browse2Save^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DCFDAE13-0A87-8387-7415-9A45D26A03D5}] =>Adware.Browse2Save^ [HKLM\SYSTEM\CurrentControlSet\Services\KMService] =>Hijacker.Office^ [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DigitalSite] =>Hijacker.DSite^ [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SoftwareUpdateTaskMachineCore] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SoftwareUpdateTaskMachineUA] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0E365FDA-909F-4939-838A-261DD468D862}] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F3DA0622-A699-4551-A7BA-EEBB283924D4}] =>Adware.Browse2Save^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DomaIQ Uninstaller] =>PUP.VAFPlayer^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\lrcsTube@hansanddeta.com] =>Adware.AddLyrics^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Supreme Savings] =>PUP.RewardsArcade^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Funmoods Chat] =>PUP.Funmoods^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DigitalSite] =>Hijacker.DSite^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service] =>Adware.IncrediBar^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}] =>PUP.TubeAdBlocker^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CF830981-8F31-C561-C7A0-FE2CE1878B40}] =>PUP.TubeAdBlocker^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{476D78C4-1DB0-2D88-7FCC-AA6559F59A8D}] =>PUP.Websave^ [HKLM\Software\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{006E6A46-8D55-4F10-BBA8-2C9653B4278B}] =>Adware.Boxore [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}] =>Hijacker.SmartBar [HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}] =>Hijacker.SmartBar [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}] =>Hijacker.SmartBar [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}] =>PUP.Babylon [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}] =>Toolbar.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110011501160}] =>PUP.SpecialSavings [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>Toolbar.Agent [HKLM\Software\Classes\AppID\{32451DFC-C23B-4E12-866C-FC7982238504}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{32451DFC-C23B-4E12-866C-FC7982238504}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{42AEFAF9-09D6-4185-87AE-DEDF6E955CB4}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{42AEFAF9-09D6-4185-87AE-DEDF6E955CB4}] =>Toolbar.Conduit [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6492E171-2427-4932-B414-33574A089F5E}] =>Adware.Singalng [HKLM\Software\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}] =>PUP.Whitesmoke [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\Interface\{736EF78E-5A04-46F9-893E-EDEC6EA5DF45}] =>Adware.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}] =>PUP.Funmoods [HKLM\Software\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}] =>Toolbar.Ask [HKLM\Software\Wow6432Node\Classes\Interface\{7A1BCE27-099C-4628-B63A-AEC00C6376B3}] =>Adware.Agent [HKLM\Software\Classes\AppID\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}] =>PUP.Funmoods [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}] =>PUP.Funmoods [HKLM\Software\Classes\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}] =>Adware.Agent [HKLM\Software\Wow6432Node\Classes\Interface\{AF3AFF7C-B9E9-48DD-9002-212B6DEAAC02}] =>Adware.Agent [HKLM\Software\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}] =>Adware.CDNHelper [HKLM\Software\Wow6432Node\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}] =>Adware.CDNHelper [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C87FC351-A80D-43E9-9A86-CF1E29DC443A}] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\Interface\{DBE82879-914A-422F-BAE9-2ECC80BE536F}] =>Adware.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}] =>Adware.Yontoo [HKLM\Software\Wow6432Node\Classes\Interface\{E12D7149-73EF-45E4-A1E9-99FD7DAE62D3}] =>Adware.Agent [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\Interface\{F2B184F1-547C-4EE9-BFC4-AC489C7077D9}] =>Adware.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}] =>Adware.PricePeep [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}] =>Adware.Yontoo [HKLM\Software\Classes\Software.OneClickCtrl.8] =>Adware.Agent [HKLM\Software\Wow6432Node\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj] =>Adware.SearchYa [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\1C875DDE39636004CA8CDAEC335B4160] =>Adware.PredictAd [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\BA086F2D38A8E1A47912955A68B3AD24] =>Adware.PredictAd [HKCU\Software\1ClickDownload] =>PUP.1ClickDownloader [HKCU\Software\BabylonToolbar] =>PUP.Babylon [HKCU\Software\Boxore] =>Adware.Boxore [HKLM\Software\Wow6432Node\Boxore] =>Adware.Boxore [HKCU\Software\DataMngr] =>Adware.Bandoo [HKLM\Software\Wow6432Node\DataMngr] =>Adware.Bandoo [HKCU\Software\DataMngr_Toolbar] =>Toolbar.Agent [HKCU\Software\funmoods] =>PUP.Funmoods [HKCU\Software\Iminent] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Iminent] =>Adware.IMBooster [HKCU\Software\AppDataLow\Software\PriceGong] =>Adware.PriceGong [HKCU\Software\Softonic] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\SP Global] =>PUP.AdvancedSystemProtector [HKCU\Software\AppDataLow\SProtector] =>PUP.AdvancedSystemProtector [HKLM\Software\Wow6432Node\SProtector] =>PUP.AdvancedSystemProtector [HKLM\Software\Tarma Installer] =>PUP.Tarma [HKLM\Software\Wow6432Node\Microsoft\Tracing\Iminent_RASAPI32] =>Adware.Bandoo [HKLM\Software\Wow6432Node\Microsoft\Tracing\Iminent_RASMANCS] =>Adware.Bandoo [HKLM\Software\Wow6432Node\Microsoft\Tracing\MyBabylontb_RASAPI32] =>PUP.Babylon [HKLM\Software\Wow6432Node\Microsoft\Tracing\MyBabylontb_RASMANCS] =>PUP.Babylon [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service] =>Adware.IncrediBar [HKLM\Software\Classes\Prod.cap] =>PUP.Babylon [HKLM\Software\Classes\Installer\Features\64A6E60055D801F4BB8AC269354B72B8] =>Adware.Boxore [HKLM\Software\Classes\Installer\Products\64A6E60055D801F4BB8AC269354B72B8] =>Adware.Boxore [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\64A6E60055D801F4BB8AC269354B72B8] =>Adware.Boxore [HKLM\Software\Wow6432Node\Classes\Installer\Features\64A6E60055D801F4BB8AC269354B72B8] =>Adware.Boxore [HKLM\Software\Wow6432Node\Classes\Installer\Products\64A6E60055D801F4BB8AC269354B72B8] =>Adware.Boxore [HKCU\Software\InstallCore] =>Adware.InstallCore [HKLM\Software\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}] =>Adware.Agent [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375] =>PUP.Tarma [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5] =>PUP.Tarma [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C3F3165C-74D3-6FDB-3274-14FDA8698CFA}] =>Adware.Browse2Save [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}] =>Adware.Browse2Save [HKLM\Software\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}] =>Toolbar.DeltaSearch [HKLM\Software\Wow6432Node\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}] =>Toolbar.DeltaSearch [HKLM\Software\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}] =>Adware.MagniPic [HKLM\Software\Wow6432Node\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}] =>Adware.MagniPic [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SP_f2a323db] =>Adware.Browse2Save [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OpenCandyHelperRunOnce] =>Adware.OpenCandy [HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider [HKCU\Software\InstalledBrowserExtensions\] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Microsoft\Tracing\boxore_RASAPI32] =>Adware.Boxore [HKLM\Software\Wow6432Node\Microsoft\Tracing\boxore_RASMANCS] =>Adware.Boxore [HKLM\Software\Wow6432Node\Google\Chrome\Extensions\bebdghdpchfhbbmfeddkijldlpnkbjkk] =>Adware.AddLyrics [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B399EDE8-1525-458C-8DD9-31EADF632D06}] =>Adware.AddLyrics [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B399EDE8-1525-458C-8DD9-31EADF632D06}] =>Adware.AddLyrics [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lrcsTube@hansanddeta.com] =>Adware.AddLyrics [HKCU\Software\InstalledBrowserExtensions] =>PUP.CrossRider [HKLM\Software\Classes\CrossriderApp0019962.BHO] =>PUP.CrossRider [HKLM\Software\Classes\CrossriderApp0019962.BHO.1] =>PUP.CrossRider [HKLM\Software\Classes\CrossriderApp0019962.Sandbox] =>PUP.CrossRider [HKLM\Software\Classes\CrossriderApp0019962.Sandbox.1] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Classes\CrossriderApp0019962.BHO] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Classes\CrossriderApp0019962.BHO.1] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Classes\CrossriderApp0019962.Sandbox] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Classes\CrossriderApp0019962.Sandbox.1] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011501160}] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Classes\CLSID\{11111111-1111-1111-1111-110111991162}] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Classes\CLSID\{22222222-2222-2222-2222-220122992262}] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011501160}] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110111991162}] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110111991162}] =>PUP.CrossRider [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0124B064795BB484FA494FC7CF204C0C] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\01F8E7504D2D2644AB1185234D2AD5AC] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\04CDEDFDD6EF25443B78A49D1FE5B4F2] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\058911EBC07BAAE42B102E3F4B0D070D] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\05CE306CC244D284D8D8090E404CD7D3] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\089527E77AD22E345B0066D226E44F46] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0BD0B15D6F0C2BF428B339B2D2D732C9] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0C1AAA506D92B2D44BD6FEF6CDFB71E1] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CAEC9AFF1716FF4DBACEED82F88C702] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0DD4444CBC682774C8E573CC73C5BC46] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0F68250201451D64EA71E91BA19832DC] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\126FFC99A0F214F41AE2D6C7A0FC09BF] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12F72EF2521177A4BB467FF35A881382] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\14873772FE3926F4195C9280D52D3486] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\14CF11D787D40BF458A3B5CB123733CE] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\163A5460E4FB18343B4C0B781B27E813] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1705977FCB2F22F4D8A9AB847C3FB9CE] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\19F133B6A0BA9B14493CE47703DF4CF3] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1C735C7A54F53574CA5AEA93D0D1F01E] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1CE2260B068265A488410CA171D93778] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DF1DD2609A2135479C19D72E41B64AA] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F72D9058D0863E4F8EB9FE6E980C385] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2217D47FAFB0AC547820199B3A026CFB] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22C5FD2815F5C7C4DB5F34F504BF9D96] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\26CF57FC035624845B9005289DFA1448] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2719056FB4CDD294887140382819FFF7] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2956CB28F45AAF746998774B3C9FF012] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2AD5E582EBA9ED54989A134D9250922B] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2BB672F8D2CA64146B6688371E75C986] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2EA450B923F9C4D4BBEB203648FBFFDC] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2ECA942EFDBD22B4EBB7FE3AB9EDDBDD] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2F055C41FDCA50A43BE42A96D243AD47] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2F4EE319A22490145BC4AEBC53B616CA] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\31E430E345D85D54CA33BC88AEFDB9D8] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\358096DA35E67B5479C2E880DF0C10C1] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\37345F678B330594E9E4AC16908F78CF] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\38641BF101151094F86DD62B534BDEC4] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\38762340C83E6764B87807B67154F5A4] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3984BAF27BDA0DC4D8AED19FCB64BD7D] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3D82200490995CE42AB754DCD90AC44D] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E9F0E4315A35D741873885200C6A454] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3F261C3E5AD56E54598E24B106813C7E] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\40D753328E77EE842A82631EED62CEC5] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\40FDEFB25883CF140B9B5F89CB7E2871] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\412179CD2126BB34CAE51691856A3D68] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43218F63264345445A73071C174FEEE8] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\439E8A02B7736CA488EECE28D7EE961A] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\456D8CED0106E1649AE5CBD8082AC705] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\459277E8A0EE8894F9D7F807DF90506A] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\463372A470C576443AE8802B1AC61D89] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\48F13E425ECD5F243A8A82AA2B65336D] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B6F3AD0EE690D2478C7D0528AADF8C4] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4BB9D431259E08A499469636383B9935] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4D3B0714BC82B2340AB18C031262573D] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4D5809867D6C1D14180511D3AAD03F79] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4DB13DED48DC4494C90DE800D31B086C] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\52C608FC2A61CCE479768A9719CABF7B] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\56861F0CE995D0E45835F5D31E105D54] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\58E44D082625757499995F9516313A9C] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5A52F724764B00747A637F14FBBBB830] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5B19839CB98BB914BA43E863BBE11B4E] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\613DCE6E373581A40B6C88D4F7C09096] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6292C097F9759424BAFA3E32CD3DD562] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\62C171206461ED34885A4AE095F4A7AC] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\63E9F48D88AA940498502E29E3747471] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\64747EAAAE2BA5141AEBCF4F6651A144] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6494B0B34076D6248B6E5F42E3252AD0] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6495111F730311440BBC3AAAF3B8C7AC] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\65273BD75ADFA9146A0950469941299A] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6543EA2E8E729CF4789BCD7361D58C03] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\658DABBCADB609E429A6769C46FAADD0] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\67A614CC45D7C5845BE2184211CC8F9C] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B6581D2CF6BB444D8ACBF79E3AF425B] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C0DB201BFD71284CB8CA279446863E8] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EA4E994723ECC940AE01A2507673199] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F2331E07AF9B414DB15E2E7BAB7F880] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F3E6739E6CECC64D9B7E5D24CF60746] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\73268B3F6C2206C4BAF14E3C5B4BC494] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\73D229597C7281E409FDEB3079E30E5A] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75A49DF39158638428A0F7797D4CD1E6] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75D223AE12684124794DD7D3FB067886] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76937F723CDCAB547A9791D60867A5B5] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\78AD011E92C0B7D4A86E41451EC7A0F0] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\79080E81959ECB54E9E7B3C67AE5781A] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7A8B37070412F4D47895AA40EFC2E39A] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7F84DAA817EC0AB409DFE802184D5B09] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\82F14F44AA63A5945A2E960EF018794E] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\831071FAC16E2DA4682F55E0B0DE6979] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\83D0F8F1641145A42B26F71D534E9A34] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\84072C174C7F25148BFB33ADE8C704E1] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\872C7B3D2887D4E4EBF645D7AB9374D1] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8C00987A23C36B145AB60EE274936EB3] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8D736B12592E2E94094267BC5B7AA7EB] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F3E0221A8351144BB04AEF5266143CB] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\90E77522D1656DA4DABC673942243B44] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\920219BD6C542544893D7ECFCB5E2B6B] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\939840D09446FFF459FA6CB4F03C38BE] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9459BDD3A7C686345A9B7A1AD1CC6BE4] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\95AC1A94BAFFE3D41B23B2097BA8B190] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\983EBB458AA802846BBC74D26C3209C8] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98A0180804723E24AAA941C0B046363D] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\990A25796B2949842BACA56514B7316A] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\999D63C685BF046489CA3126029FE837] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9AC4C1465926D52478BEC6D3DB946DD7] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9CF7625ADC5FCFE43AD003DCC16B49CB] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A2D54AC8D24E8F94ABBB993A69EF13EC] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A357C02D064283D41978AFEEE1A48E0F] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A4022CA9531268145AD6F8FD7F4F01DC] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5CDCC279604D6746A7DA9ED701BF41F] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6F4FE9AC6F165A4EAA8F90CE891C0DA] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A960AC53CA238044A820A3B63D4536CA] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA3077BB9E4617440AF467D91146A8C4] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AAC05EAA51DC78A41A1DCE3B31038584] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD7957C966A13904EA466152B29EA9AF] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B13C910C1D6376A4BB2BDB9585253923] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B1B5689BAD89AFD448923B5051E5BB50] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B2CE0F97DFABDE446811F33E7273BFE2] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B445461D74829AF4C8EF6C00B2861EF0] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B4D011D14FD2DB74A9090EA633C0B98E] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B551BEBCA0334AA40978C2137FD21AB2] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B877893A942DC524580C7B45547FCBC8] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BA71D41F6CC0B6247B05D473850A8AEA] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC651C0803618C44DA6F1DDD51AF35BF] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BDE5B9F2A520B674BBB1BEAE5F5D51B8] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BEE85C3D8F4816D4A9E5F4EAA4D80A2A] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BFD48F71CCCEC97489147D4E852D3F6F] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C05694CDCD2DD724F90F13A20E67EC7C] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C42065D3060DD4648A38882BEA92941E] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C5F606FB1152E344981B09071C472211] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C77B53875F388AA4AA076F6F9D099011] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C85EA06E73FF0A240B4C287EE0D9521D] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA30DE5A0DE293D4AA3BF5E13322823A] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA9ADF25A98C8074FA4CBBA3ED29FEFA] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCE886225BDEB6C43868B0AEDB036B02] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CDD11BF4B1CAA584695EFBC611438213] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE1CCF5CABA1395409D54586592B319E] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE7392F9B9A81FA4EA952625BD5534FE] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D12B7976E5CA7C34D932C1A8A1BF61C8] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D91D500D43BD91A44B02BDBE41E0523F] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DA2710A9158C6584C9677EB954F3AC97] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DCF07B57C9DC38E419CF122EA180585E] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD2E1A561C7F1294BB3996EE77F6BBEE] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DF14E9E130504B745A2AC47EF6145D24] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DF7A4CDE9ED9CD7479FF74F35FA4149E] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DFE39849AF921D045B613CD5852C76A6] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E03EC5B80A22A7D4C92AB528A3D323E8] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E1B9E95AA2730744AB926911484F8AD5] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E3436415FB2833843B9EE970079A87C0] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E3BBB86ACE9686A4281227D5F7EE95AE] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E6B40E8EBBC3CD445BD2FC7D8FDCCFEC] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E77C3F952C1F0354FAFADB6B080ACCF7] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E84382A588F214C4C89C3DB758EA6AD6] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E89B10C102BBEF941A920EE2269747C0] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E9D73D5153C19FD48B6E10CB7E8572CE] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EBAFF392ACA75ED4CA30BF821C1AE267] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ECFC746582988774684DB5D8D95F674D] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EECC799BFA63E6146A81EAAA53540EDE] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F1547261AA1C98C48B0ECDBC767C76CE] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F1BDB464DE2D33547BB31C1B35D9C337] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F29CFDBF9B20AB8448A1BD73A3FE863F] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F5F8D8368E8CAE84188DE44DAF8C10F9] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FAB510A06C6F4B24AAD055CE6EEA27CD] =>Adware.Boxore^ [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:Boxore Client =>Adware.Boxore^ C:\Users\sheitan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh =>PUP.Funmoods^ C:\Users\sheitan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bebdghdpchfhbbmfeddkijldlpnkbjkk =>Adware.AddLyrics^ C:\Users\sheitan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj =>PUP.Funmoods^ C:\Users\sheitan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gobmeekldnjpoafibilnjbnnhlaadhlp =>PUP.Websave^ C:\Users\sheitan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbaohildkhbcljgoabiecdoinkaedlca =>Spyware.SmartDisplay^ C:\Users\sheitan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbpohikckhbcljgombipcdoinkaedlfa =>Spyware.SmartDisplay^ C:\Users\sheitan\AppData\Roaming\Mozilla\Firefox\Profiles\0v7vsx8w.default\extensions\ee_cioe@fsiuuoo-.net =>PUP.Websave^ C:\Users\sheitan\AppData\Roaming\Mozilla\Firefox\Profiles\0v7vsx8w.default\extensions\ioea1oh@cksaqzdva.org =>Adware.FastSaveApp^ C:\Users\sheitan\AppData\Roaming\Mozilla\Firefox\Profiles\0v7vsx8w.default\extensions\oaee@ueuy.org =>PUP.Websave^ C:\Program Files (x86)\Boxore =>Adware.Boxore^ C:\Program Files (x86)\BrowseToSave =>Adware.Browse2Save^ C:\Program Files (x86)\LyricsTube =>Adware.AddLyrics^ C:\Program Files (x86)\Red Sky =>Adware.DownTango^ C:\Program Files (x86)\SingAlong =>Adware.Singalng^ C:\Program Files (x86)\SSearuch-NewTab =>Adware.FastSaveApp^ C:\Program Files (x86)\Supreme Savings =>PUP.RewardsArcade^ C:\Program Files (x86)\websiave =>PUP.Websave^ C:\Program Files (x86)\weebsAvee =>PUP.Websave^ C:\Program Files (x86)\YoutubeAdblocker =>PUP.TubeAdBlocker^ C:\ProgramData\Babylon =>PUP.Babylon^ C:\ProgramData\BBrowsye2savve =>Adware.Browse2Save^ C:\ProgramData\BoxUpdChk =>Adware.Boxore^ C:\ProgramData\Browse2save =>Adware.Browse2Save^ C:\ProgramData\IBUpdaterService =>Adware.InstallBrain^ C:\ProgramData\InstallMate =>PUP.Tarma^ C:\ProgramData\SSearuch-NewTab =>Adware.FastSaveApp^ C:\ProgramData\Tarma Installer =>PUP.Tarma^ C:\ProgramData\websiave =>PUP.Websave^ C:\ProgramData\weebsAvee =>PUP.Websave^ C:\ProgramData\YoutubeAdblocker =>PUP.TubeAdBlocker^ C:\Users\sheitan\AppData\Roaming\Babylon =>PUP.Babylon^ C:\Users\sheitan\AppData\Roaming\File Scout =>PUP.FileScout^ C:\Users\sheitan\AppData\Roaming\Funmoods =>PUP.Funmoods^ C:\Users\sheitan\AppData\Roaming\FunmoodsChat =>PUP.Funmoods^ C:\Users\sheitan\AppData\Roaming\OpenCandy =>Adware.OpenCandy^ C:\Users\sheitan\AppData\Local\Supreme Savings =>PUP.RewardsArcade^ C:\Users\sheitan\AppData\Local\Updater19962 =>PUP.CrossRider^ C:\Program Files (x86)\Software =>Adware.Boxore C:\Program Files (x86)\WebSearch =>Hijacker.LookForiThere C:\Program Files (x86)\DeviceVM =>Toolbar.Splashtop C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browse2Save =>Adware.Browse2Save C:\Users\sheitan\AppData\Local\SearchProtect =>Toolbar.Conduit C:\Users\sheitan\AppData\Local\Software =>Adware.Boxore C:\Program Files (x86)\Boxore\BoxoreClient\boxore.exe =>Adware.Boxore^ C:\Program Files (x86)\Software\Update\SoftwareUpdate.exe =>Adware.Boxore^ C:\Windows\Tasks\DigitalSite.job =>Hijacker.DSite^ C:\Users\sheitan\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.exe =>Hijacker.DSite^ [HKCU\Software\BabSolution] =>Hijacker.BabSolution^ [HKCU\Software\Conduit] =>Toolbar.Conduit^ [HKCU\Software\FileScout] =>PUP.FileScout^ [HKCU\Software\Funmoods] =>PUP.Funmoods^ [HKCU\Software\Smartbar] =>Hijacker.SmartBar^ [HKLM\Software\DomaIQ] =>Adware.DomaIQ^ [HKLM\Software\Wow6432Node\Babylon] =>PUP.Babylon^ [HKCU\Software\5e6dd88b46aba43\history\{16cdff19-861d-48e3-a751-d99a27784753}2.3.762.17]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =>PUP.Babylon^ [HKCU\Software\5e6dd88b46aba43\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1123.78]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =>PUP.Babylon^ [HKCU\Software\5e6dd88b46aba43\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1125.80]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =>PUP.Babylon^ [HKCU\Software\5e6dd88b46aba43\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1249.132]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =>PUP.Babylon^ [HKCU\Software\5e6dd88b46aba43\history\{16cdff19-861d-48e3-a751-d99a27784753}2.6.1339.144]:guid="{16cdff19-861d-48e3-a751-d99a27784753}" =>PUP.Babylon^ [HKCU\Software\5e6dd88b46aba43] =>PUP.Babylon^^ C:\Windows\Installer\2240b.msi =>Adware.Boxore^ C:\Windows\Installer\8a9b4f.msi =>Adware.Boxore^ C:\Windows\AutoKMS.exe =>Trojan.Keygen ~ Additionnel Scan: 629049 Items scanned in 00mn 47s ---\\ Récapitulatif des détections trouvées sur votre station http://nicolascoolman.webs.com/apps/blog/show/26626977-adware-boxore =>Adware.Boxore http://nicolascoolman.webs.com/apps/blog/show/27630986-pup-funmoods =>PUP.Funmoods http://nicolascoolman.webs.com/apps/blog/show/26601058-adware-addlyrics =>Adware.AddLyrics http://nicolascoolman.webs.com/apps/blog/show/41475428-pup-websave =>PUP.Websave http://nicolascoolman.webs.com/apps/blog/show/32662245-spyware-smartdisplay =>Spyware.SmartDisplay http://nicolascoolman.webs.com/apps/blog/show/29507721-toolbar-conduit =>Toolbar.Conduit http://nicolascoolman.webs.com/apps/blog/show/26801402-adware-fastsaveapp =>Adware.FastSaveApp http://nicolascoolman.webs.com/apps/blog/show/26627530-adware-browse2save =>Adware.Browse2Save http://nicolascoolman.webs.com/apps/blog/show/33263878-hijacker-browser =>Hijacker.Browsers http://nicolascoolman.webs.com/apps/blog/show/29626487-hijacker-office =>Hijacker.Office http://nicolascoolman.webs.com/apps/blog/show/35170315-hijacker-dsite =>Hijacker.DSite http://nicolascoolman.webs.com/apps/blog/show/30392620-pup-vafplayer =>PUP.VAFPlayer http://nicolascoolman.webs.com/apps/blog/show/28000037-pup-rewardsarcade =>PUP.RewardsArcade http://nicolascoolman.webs.com/apps/blog/show/26898222-adware-incredibar =>Adware.IncrediBar http://nicolascoolman.webs.com/apps/blog/show/26607014-pup-1clickdownloader =>PUP.1ClickDownloader http://nicolascoolman.webs.com/apps/blog/show/26627369-toolbar-babylon =>PUP.Babylon http://nicolascoolman.webs.com/apps/blog/show/26678994-hijacker-babsolution =>Hijacker.BabSolution http://nicolascoolman.webs.com/apps/blog/show/27583992-pup-datamngr =>PUP.Datamngr http://nicolascoolman.webs.com/apps/blog/show/34311830-pup-filescout =>PUP.FileScout http://nicolascoolman.webs.com/apps/blog/show/26684723-adware-imbooster =>Adware.IMBooster http://nicolascoolman.webs.com/apps/blog/show/29790567-adware-installcore =>Adware.InstallCore http://nicolascoolman.webs.com/apps/blog/show/27557062-adware-vidsaver =>Adware.VidSaver http://nicolascoolman.webs.com/apps/blog/show/26990375-hijacker-smartbar =>Hijacker.SmartBar http://nicolascoolman.webs.com/apps/blog/show/30393137-adware-domaiq =>Adware.DomaIQ http://nicolascoolman.webs.com/apps/blog/show/29637859-toolbar-tarma =>PUP.Tarma http://nicolascoolman.webs.com/apps/blog/show/26630283-pup-advancedsystemprotector =>PUP.AdvancedSystemProtector http://nicolascoolman.webs.com/apps/blog/show/28486577-pup-mocaflix =>PUP.Mocaflix http://nicolascoolman.webs.com/apps/blog/show/27659036-adware-downtango =>Adware.DownTango http://nicolascoolman.webs.com/apps/blog/show/27423721-adware-singalng =>Adware.Singalng http://nicolascoolman.webs.com/apps/blog/show/26907365-adware-installbrain =>Adware.InstallBrain http://nicolascoolman.webs.com/apps/blog/show/26770694-adware-opencandy =>Adware.OpenCandy http://nicolascoolman.webs.com/apps/blog/show/27583526-pup-crossrider =>PUP.CrossRider http://nicolascoolman.webs.com/apps/blog/show/27875657-toolbar-deltasearch =>Toolbar.DeltaSearch http://nicolascoolman.webs.com/apps/blog/show/26686441-pup-specialsavings =>PUP.SpecialSavings http://nicolascoolman.webs.com/apps/blog/show/27636417-pup-whitesmoke =>PUP.Whitesmoke http://nicolascoolman.webs.com/apps/blog/show/28927746-toolbar-ask =>Toolbar.Ask http://nicolascoolman.webs.com/apps/blog/show/26811836-adware-yontoo =>Adware.Yontoo http://nicolascoolman.webs.com/apps/blog/show/27529784-adware-searchya =>Adware.SearchYa http://nicolascoolman.webs.com/apps/blog/show/27229962-adware-predictad =>Adware.PredictAd http://nicolascoolman.webs.com/apps/blog/show/26611092-adware-bandoo =>Adware.Bandoo http://nicolascoolman.webs.com/apps/blog/show/26666995-adware-pricegong =>Adware.PriceGong http://nicolascoolman.webs.com/apps/blog/show/26632189-adware-magnipic =>Adware.MagniPic http://nicolascoolman.webs.com/apps/blog/show/29285781-hijacker-lookforithere =>Hijacker.LookForiThere ~ MSI: 43 link(s) detected in 00mn 00s ~ 2293 Legitimates filtered by white list End of the scan (1247 lines in 12mn 34s)(2)