~ Report of ZHPDiag v2014.12.27.179 - Nicolas Coolman (27-12-2014) ~ Launched by admin (29-12-2014 12:48:28) ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ Web forum address : http://forum.nicolascoolman.fr ~ Translated by ~ Version State : New version available ~ White List : Activate by program ~ Elevation of privilege : OK ~ User Account Control : Deactivate by user ---\\ Internet browsers MSIE: Internet Explorer v11.0.9600.16663 MFIE: Mozilla Firefox 34.0.5 (Defaut) GCIE: Google Chrome ---\\ Windows product information ~ Langage: Anglais Windows 8.1 Pro with Media Center, 32-bit (Build 9600) Windows Server License Manager Script : OK ~ Windows(R) Operating System, RETAIL channel Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ System protection software Windows Defender W8 (Activate) ---\\ System optimization software CCleaner v5.01 ---\\ Sharing software PeerToPeer ---\\ Surveillance software Adobe Flash Player 16 NPAPI ---\\ Information on the system ~ Processor: x86 Family 15 Model 4 Stepping 3, GenuineIntel ~ Operating System: 32 Bits Boot mode: Normal (Normal boot) Total RAM: 1015.4 MB (42% free) System Restore: Activé (Enable) System drive C: has 25 GB (64%) free of 39 GB ---\\ Connection to the system mode ~ Computer Name: REDWAN ~ User Name: admin ~ All Users Names: Guest, Administrator, admin, ~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89 Logged in as Administrator ---\\ Environment variables ~ System Unit : C:\ ~ %AppZHP% : C:\Users\admin\AppData\Roaming\ZHP\ ~ %AppData% : C:\Users\admin\AppData\Roaming\ ~ %Desktop% : C:\Users\admin\Desktop\ ~ %Favorites% : C:\Users\admin\Favorites\ ~ %LocalAppData% : C:\Users\admin\AppData\Local\ ~ %StartMenu% : C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ Enumeration of the disk units A: Floppy drive, Flash card reader, USB Key (Not Inserted) C: Hard drive, Flash drive, Thumb drive (Free 25 Go of 39 Go) D: Hard drive, Flash drive, Thumb drive (Free 12 Go of 35 Go) E: CD-ROM drive (Not Inserted) H: Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go) ---\\ State of the Windows Security Center [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified ~ Security Center: 46 Legitimates Filtered in 00mn 00s ---\\ Search Generic System Files [MD5.2CA8E3C9335C3C8BAEB335345E48364D] - (.Microsoft Corporation - مستكشف Windows.) (.22-08-2013 - 5:25:34.) -- C:\Windows\Explorer.exe [2063408] [MD5.02BC073156B3097E94D63C4D609020DD] - (.Microsoft Corporation - ‎‎تطبيق بدء تشغيل Windows.) (.22-08-2013 - 2:49:55.) -- C:\Windows\System32\Wininit.exe [112640] [MD5.AAFEAB4FC9D70253F8C7E353E879E8A2] - (.Microsoft Corporation - ملحقات الإنترنت لـ Win32.) (.01-03-2014 - 2:32:16.) -- C:\Windows\System32\wininet.dll [1820160] [MD5.94385F95EF948FB274A70DE3EDE5696D] - (.Microsoft Corporation - تطبيق تسجيل دخول Windows.) (.22-08-2013 - 2:48:19.) -- C:\Windows\System32\Winlogon.exe [458752] [MD5.BFB9E1202225113991F981D29BFB9029] - (.Microsoft Corporation - مكتبة تراخيص البرامج.) (.21-12-2013 - 8:08:12.) -- C:\Windows\System32\sppcomapi.dll [438272] [MD5.2AF7DA157FFF947A507FCB4AB8BB4C7C] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.22-08-2013 - 6:13:54.) -- C:\Windows\system32\Drivers\AFD.sys [455168] [MD5.72FCAE2CE6DFEAB2AB072435017F3417] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.22-08-2013 - 5:33:25.) -- C:\Windows\system32\Drivers\atapi.sys [23392] [MD5.CE232BB0965C0C0B786C3F976CCBFB7D] - (.Microsoft Corporation - CD-ROM File System Driver.) (.22-08-2013 - 4:11:55.) -- C:\Windows\system32\Drivers\Cdfs.sys [73728] [MD5.E2FC132D48EA4E8B04432C33EFB77801] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.22-08-2013 - 1:59:12.) -- C:\Windows\system32\Drivers\Cdrom.sys [124928] [MD5.D4ADBFC2409EF883164F3AA49B22F366] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.22-08-2013 - 4:09:45.) -- C:\Windows\system32\Drivers\DfsC.sys [101376] [MD5.A31901DE6A22EA67AB83AAF7036F98CC] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.22-08-2013 - 4:10:12.) -- C:\Windows\system32\Drivers\HDAudBus.sys [69632] [MD5.5043E69532392A43549E5D41E22638AA] - (.Microsoft Corporation - i8042 Port Driver.) (.22-08-2013 - 4:10:59.) -- C:\Windows\system32\Drivers\i8042prt.sys [82944] [MD5.FA6C94C754A566EA8A61D658932F32DE] - (.Microsoft Corporation - IP Network Address Translator.) (.27-11-2013 - 11:03:35.) -- C:\Windows\system32\Drivers\IpNat.sys [126976] [MD5.9E030D5C03E68E0C78EA120212759D66] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.23-11-2013 - 6:09:50.) -- C:\Windows\system32\Drivers\MRxSmb.sys [332800] [MD5.BC242922B0D08F61CF7C87FD08FAFA8B] - (.Microsoft Corporation - MBT Transport driver.) (.22-08-2013 - 4:08:26.) -- C:\Windows\system32\Drivers\netBT.sys [218624] [MD5.D13D35452A5F452DCC1626AE1A7D9790] - (.Microsoft Corporation - NT File System Driver.) (.10-03-2014 - 8:43:52.) -- C:\Windows\system32\Drivers\ntfs.sys [1673048] [MD5.4F30970F15ADCC382544B31D5D7E368E] - (.Microsoft Corporation - Parallel Port Driver.) (.22-08-2013 - 4:11:49.) -- C:\Windows\system32\Drivers\Parport.sys [81408] [MD5.C51AB62AB41A2E8560D12472B204CC00] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.22-08-2013 - 4:07:36.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [81920] [MD5.67E91843B0344411820A012063E876B2] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.22-08-2013 - 14:39:05.) -- C:\Windows\system32\Drivers\rdpdr.sys [143872] [MD5.DB0C184142CF9FA1746F598A16EE92B2] - (.Microsoft Corporation - TDI Translation Driver.) (.22-08-2013 - 6:13:54.) -- C:\Windows\system32\Drivers\tdx.sys [87040] [MD5.CA3C52D981550DEA46576F9FFBA22C58] - (.Microsoft Corporation - Volume Shadow Copy Driver.) (.31-01-2014 - 14:04:24.) -- C:\Windows\system32\Drivers\volsnap.sys [265560] ~ Generic Processes: Scanned in 00mn 00s ---\\ Hidden files state (Hidden/Total) ~ Mes Favoris (My Favorites) : 1/4 ~ Mon Bureau (My Desktop) : 1/114 ~ Menu demarrer (Programs) : 1/31 ~ Hidden Files: Scanned in 00mn 00s ---\\ Process running [MD5.61A5597AB30F257BCC47A8E61711F039] - (.Microsoft Corporation - Host Process for Windows Tasks.) -- C:\WINDOWS\system32\taskhostex.exe [66632] [PID.796] [MD5.349AB4F70E2AC44970894E7F03E1576E] - (.Huawei Technologies Co., Ltd. - DataCardMonitor MFC Application.) -- C:\ProgramData\DatacardService\DCSHelper.exe [236384] [PID.1724] [MD5.C37C8414D1439EC22C1D1EA42185A94B] - (.Microsoft Corporation - SkyDrive Sync Engine Host.) -- C:\Windows\System32\skydrive.exe [460800] [PID.2448] [MD5.D78C53AC8418D9E5811D837103E594CE] - (.IObit - No Comment.) -- C:\Program Files\IObit\IObit Uninstaller\UninstallMonitor.exe [182048] [PID.3140] [MD5.07782C388EDDB13CB0A1040F7E1DDCDC] - (.No owner - Real-time Protector.) -- C:\Program Files\IObit\Advanced SystemCare 8\RealTimeProtector.exe [1106720] [PID.3180] [MD5.42433CDEC449D40F508752F2D487D8E4] - (.Microsoft Corporation - Host Process for Setting Synchronization.) -- C:\Windows\System32\SettingSyncHost.exe [478208] [PID.3292] [MD5.E47AC731D42B2452D4C0BF096DF3DD6E] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8145408] [PID.3660] ~ Processes Running: Scanned in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Line Analysis F0, F1, F2, F3 - IniFiles, Auto loading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s ---\\ Hosts file redirection (O1) ~ Le fichier hôte est sain (The hosts file is clean) (21) ~ Hosts File: Scanned in 00mn 00s ---\\ Auto loading programs from Registry and folders (O4) O4 - HKLM\..\Run: [UIExec] . (...) -- C:\Program Files\Internet Mobile+\UIexec.exe O4 - HKCU\..\Run: [Advanced SystemCare 8] . (.IObit - Advanced SystemCare 8.) -- C:\Program Files\IObit\Advanced SystemCare 8\ASCTray.exe O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd O4 - HKUS\S-1-5-21-559679301-2718928345-356766008-1001\..\Run: [Advanced SystemCare 8] . (.IObit - Advanced SystemCare 8.) -- C:\Program Files\IObit\Advanced SystemCare 8\ASCTray.exe O4 - HKUS\S-1-5-21-559679301-2718928345-356766008-1001\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe O4 - HKUS\S-1-5-21-559679301-2718928345-356766008-1001\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner.exe =>.Piriform Ltd ~ Application: Scanned in 00mn 00s ---\\ Lop.com/Domain Hijackers (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{D46A0BFF-9352-490A-A426-30E96F15665C}: NameServer = 8.8.8.8 41.214.140.5 O17 - HKLM\System\CS1\Services\Tcpip\..\{D46A0BFF-9352-490A-A426-30E96F15665C}: NameServer = 8.8.8.8 41.214.140.5 ~ Domain: Scanned in 00mn 00s ---\\ Extra protocols (O18) O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - عارض Microsoft (R) HTML.) -- C:\Windows\System32\mshtml.dll O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\System32\mscoree.dll =>.Microsoft Corporation ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Non Microsoft non disabled Windows XP/NT/2000 Services (O23) O23 - Service: HWDeviceService.exe (HWDeviceService.exe) . (.No owner - DCSHOST.) - C:\ProgramData\DatacardService\HWDeviceService.exe ~ Services: 5 Legitimates Filtered in 00mn 04s ---\\ Task Planned Automatically (039) [MD5.00000000000000000000000000000000] [APT] [{EC49A737-BF4C-49E3-B9D4-1951E2C302B9}] (...) -- F:\Setup.exe (.not file.) [0] O39 - APT: - (..) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [830] O39 - APT: - (..) -- C:\Windows\Tasks\ASC8_SkipUac_admin.job [244] O39 - APT: - (..) -- C:\Windows\System32\Tasks\ASC8_SkipUac_admin [244] ~ Scheduled Task: 7 Legitimates Filtered in 00mn 07s ---\\ Drivers launched at startup (O41) O41 - Driver: (HWiNFO32) . (.REALiX(tm) - HWiNFO x86 Kernel Driver.) - C:\WINDOWS\system32\drivers\HWiNFO32.sys ~ Drivers: 36 Legitimates Filtered in 00mn 00s ---\\ Software installed (O42) O42 - Logiciel: herdProtect Anti-Malware Scanner - (.Reason Company Software Inc..) [HKLM] -- herdProtectScan ~ Logic: 3 Legitimates Filtered in 00mn 00s ---\\ HKCU & HKLM Software Keys [HKCU\Software\AdsFix] [HKCU\Software\InCodeSolutions] [HKLM\Software\AdsFix] [HKLM\Software\SMR] ~ Key Software: 100 Legitimates Filtered in 00mn 00s ---\\ Contents of the Common Files folders (O43) O43 - CFD: 29-12-2014 - 2:23:40 - [] ----D C:\ProgramData\ProductData O43 - CFD: 19-12-2014 - 8:20:19 - [] ----D C:\ProgramData\SMR430 O43 - CFD: 12-12-2014 - 19:31:32 - [0] ----D C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0} O43 - CFD: 23-12-2014 - 6:19:15 - [] ----D C:\ProgramData\{D76294E6-03B8-4971-AF2E-3F846161A690} O43 - CFD: 23-12-2014 - 6:19:13 - [] ----D C:\ProgramData\{E1ED556E-3EA0-4F44-8BE7-CC5FB0F4B424} O43 - CFD: 27-12-2014 - 13:38:41 - [] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\herdProtect O43 - CFD: 22-08-2013 - 14:39:14 - [0] R-H-D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 24-12-2014 - 3:22:38 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WASEET303 O43 - CFD: 24-12-2014 - 3:25:51 - [] ----D C:\Users\admin\AppData\Roaming\InCode Solutions O43 - CFD: 14-12-2014 - 19:48:53 - [] ----D C:\Users\admin\AppData\Roaming\ProductData O43 - CFD: 16-12-2014 - 6:29:19 - [] ----D C:\Users\admin\AppData\Local\Smart_PC_Soft_&_Efam_Comp O43 - CFD: 19-12-2014 - 2:57:54 - [0] ----D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WASEET303 ~ Program Folder: 124 Legitimates Filtered in 00mn 00s ---\\ Last modified or created files under Windows and System32 (O44) O44 - LFC:[MD5.814231B961760C39A5807A43D8ED71E1] - 18-12-2014 - 7:38:28 ---A- . (...) -- C:\Windows\System32\Drivers\RTAIODAT.DAT [1443340] O44 - LFC:[MD5.11D34FC869F5BDA29949FE3858380894] - 19-12-2014 - 5:43:48 ---A- . (.The OpenVPN Project - TAP-Win32 Virtual Network Driver.) -- C:\Windows\System32\Drivers\tap0901.sys [26112] O44 - LFC:[MD5.6FFB351C9C9BB88E91785F4CD7396D31] - 20-12-2014 - 5:20:22 ---A- . (.REALiX(tm) - HWiNFO x86 Kernel Driver.) -- C:\Windows\System32\Drivers\HWiNFO32.SYS [23840] O44 - LFC:[MD5.24E455DD1CCE07253AAE04D9EAC5F725] - 24-12-2014 - 12:56:36 ---A- . (...) -- C:\Windows\System32\unrar.dll [217176] O44 - LFC:[MD5.2F237E41B9F198FBA75681CCB488DEBE] - 28-12-2014 - 9:30:51 ---A- . (...) -- C:\Windows\ProfessionalWMC.xml [17851] O44 - LFC:[MD5.4703C45615D8E349410B8F3FC165CE6A] - 29-12-2014 - 12:39:40 ---A- . (...) -- C:\AdsFix_29_12_2014_12_39_40.txt [20323] O44 - LFC:[MD5.58F56396C0FA068730A09B937D40B7A1] - 29-12-2014 - 12:48:28 ---A- . (...) -- C:\Windows\ntbtlog.txt [17936] ~ Files: 145 Legitimates Filtered in 00mn 07s ---\\ Local Security Authority-LSA Deny (O48) ~ LSA: 3 Legitimates Filtered in 00mn 00s ---\\ Safe Boot Control (O49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\CleanHlp.sys . (...) -- C:\Windows\System32\Drivers\CleanHlp.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\CleanHlp.sys . (...) -- C:\Windows\System32\Drivers\CleanHlp.sys (.not file.) ~ CSB: 24 Legitimates Filtered in 00mn 00s ---\\ MountPoints2 Shell Key (MPSK) (O51) O51 - MPSK:{26164089-8da5-11e4-9735-9f75d9fbf8ce}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) O51 - MPSK:{2f340925-822f-11e4-9712-806e6f6e6963}\AutoRun\command. (...) -- F:\Autorun.exe (.not file.) O51 - MPSK:{58d11287-8dc5-11e4-9736-e9ac36526ec3}\AutoRun\command. (...) -- F:\Autorun.exe (.not file.) O51 - MPSK:{58d11640-8dc5-11e4-9736-c16150d219d7}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) O51 - MPSK:{58d11688-8dc5-11e4-9736-c16150d219d7}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) O51 - MPSK:{b47738d8-8a2c-11e4-9720-a423e488e0b8}\AutoRun\command. (...) -- F:\Setup.exe (.not file.) O51 - MPSK:{e4e08ed8-8bf6-11e4-9732-ea06263e3c09}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) O51 - MPSK:{e4e08f33-8bf6-11e4-9732-ea06263e3c09}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) ~ Keys: Scanned in 00mn 00s ---\\ Microsoft Windows Policies System (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ MWPS: 17 Legitimates Filtered in 00mn 00s ---\\ System Drivers List (SDL) (O58) O58 - SDL:12-08-2013 - 23:25:32 ---A- . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\Drivers\bcmfn2.sys [16088] O58 - SDL:13-12-2012 - 15:41:10 ---A- . (.Windows (R) Win 7 DDK provider - Explore Systems Virtual Audio Device.) -- C:\Windows\System32\Drivers\dfx11_1.sys [24424] O58 - SDL:28-12-2014 - 1:23:51 ---A- . (.Huawei Tech. Co., Ltd. - HUAWEI USB Smart Card Driver.) -- C:\Windows\System32\Drivers\ewdcsc.sys [25856] O58 - SDL:20-12-2014 - 5:20:22 ---A- . (.REALiX(tm) - HWiNFO x86 Kernel Driver.) -- C:\Windows\System32\Drivers\HWiNFO32.SYS [23840] O58 - SDL:29-11-2014 - 0:37:06 ---A- . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\Drivers\idmwfp.sys [115752] O58 - SDL:02-03-2011 - 17:12:46 ---A- . (.MBB Incorporated - CDROM Filter.) -- C:\Windows\System32\Drivers\massfilter.sys [9216] O58 - SDL:28-12-2014 - 1:23:53 ---A- . (.DiBcom SA - DiBcom AVSTREAM BDA driver.) -- C:\Windows\System32\Drivers\mod7700.sys [861696] O58 - SDL:22-08-2013 - 5:32:57 ---A- . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x86.) -- C:\Windows\System32\Drivers\stexstor.sys [26976] O58 - SDL:21-08-2010 - 4:08:46 ---A- . (.The OpenVPN Project - TAP-Win32 Virtual Network Driver.) -- C:\Windows\System32\Drivers\tap0901.sys [26112] ~ Drivers: 53 Legitimates Filtered in 00mn 03s ---\\ List all tools cleaner (LATC) (O63) O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman ~ ADS: Scanned in 00mn 00s ---\\ Start Menu Internet (SMI) (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Keys: Scanned in 00mn 00s ---\\ Search Browser Infection (SBI) (O69) O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com ~ Keys: Scanned in 00mn 00s ---\\ Search Particular Root Folder (SPRF) (O84) [MD5.E8C9A28B66B8B56F319216FEFF2A8824] [SPRF][29-12-2014] (.No owner - AdsFix.) -- C:\Users\admin\Desktop\AdsFix.exe [2437632] [MD5.9A8336796A7C71E9F33DE848B8320ED3] [SPRF][29-12-2014] (...) -- C:\Users\admin\Desktop\wzgfklpt.exe [380416] ~ Files: 3 Legitimates Filtered in 00mn 00s ---\\ General States of Services not Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Demand 18-12-2014 267440 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe SS - | Auto 28-12-2014 655712 | (Internet Mobile. RunOuc) . (...) - C:\Program Files\Internet Mobile\UpdateDog\ouc.exe SS - | Demand 13-12-2014 114800 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe SS - | Demand 18-12-2014 252632 | (RtkAudioService) . (.Realtek Semiconductor.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe SS - | Demand 22-08-2013 31552 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 04-11-2014 815392 | (AdvancedSystemCareService8) . (.IObit.) - C:\Program Files\IObit\Advanced SystemCare 8\ASCService.exe SR - | Auto 14-03-2011 271712 | (HWDeviceService.exe) . (...) - C:\ProgramData\DatacardService\HWDeviceService.exe SR - | Auto 10-12-2014 2631456 | (LiveUpdateSvc) . (.IObit.) - C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe SR - | Auto 15-03-2011 261456 | (UI Assistant Service) . (...) - C:\Program Files\Internet Mobile+\AssistantServices.exe SR - | Auto 30-10-2013 22224 | (WinDefend) . (.Microsoft Corporation.) - C:\Program Files\Windows Defender\MsMpEng.exe ~ Services: Scanned in 00mn 17s ---\\ Scan Additionnel (O88) Database Version : 13026 - (27-12-2014) Clés trouvées (Keys found) : 0 Valeurs trouvées (Values found) : 0 Dossiers trouvés (Folders found) : 0 Fichiers trouvés (Files found) : 0 ~ Additionnel Scan: 168384 Items scanned in 00mn 39s ---\\ Additional information about modules ~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5) ~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Auto loading programs from Registry and folders (O4) ~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.MountPoints2 Shell Key (MPSK) (O51) ~ AMI: 3 Legitimates Filtered in 00mn 00s ~ 590 Legitimates filtered by white list End of the scan (347 lines in 01mn 44s)(0)