~ Report of ZHPDiag v2014.9.10.132 - Nicolas Coolman (9/10/2014) ~ Launched by Mo'ath (9/12/2014 10:42:14 AM) ~ Web site address : http://nicolascoolman.fr ~ Web forum address : http://forum.nicolascoolman.fr ~ Translated by ~ Version State : Updated version. ~ White List : Activate by program ~ Elevation of privilege : OK ~ User Account Control : Deactivate by user ---\\ Internet browsers MSIE: Internet Explorer v11.0.9600.17239 GCIE: Google Chrome v37.0.2062.103 (Defaut) ---\\ Windows product information ~ Langage: Anglais Windows 8.1 Pro, 64-bit (Build 9600) Windows Server License Manager Script : OK ~ Windows(R) Operating System, VOLUME_KMSCLIENT channel Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ System protection software Malwarebytes Anti-Malware version 2.0.2.1012 Windows Defender W8 (Deactivate) ---\\ System optimization software ---\\ Sharing software PeerToPeer ---\\ Surveillance software ---\\ Information on the system ~ Processor: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel ~ Operating System: 64 Bits Boot mode: Normal (Normal boot) Total RAM: 3994.4 MB (59% free) System Restore: Activé (Enable) System drive C: has 232 GB (85%) free of 270 GB ---\\ Connection to the system mode ~ Computer Name: MOATH ~ User Name: Mo'ath ~ All Users Names: Mo'ath, Guest, Administrator, ~ Unselected Option: O45,O61 Logged in as Administrator ---\\ Environment variables ~ System Unit : C:\ ~ %AppZHP% : C:\Users\Mo'ath\AppData\Roaming\ZHP\ ~ %AppData% : C:\Users\Mo'ath\AppData\Roaming\ ~ %Desktop% : C:\Users\Mo'ath\Desktop\ ~ %Favorites% : C:\Users\Mo'ath\Favorites\ ~ %LocalAppData% : C:\Users\Mo'ath\AppData\Local\ ~ %StartMenu% : C:\Users\Mo'ath\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ Enumeration of the disk units C: Hard drive, Flash drive, Thumb drive (Free 232 Go of 270 Go) D: Hard drive, Flash drive, Thumb drive (Free 182 Go of 195 Go) G: CD-ROM drive (Not Inserted) ---\\ State of the Windows Security Center [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified ~ Security Center: 40 Legitimates Filtered in 00mn AMs ---\\ Search Generic System Files [MD5.4CE0C733CDCF1D2F78532BBD9CE3441D] - (.Microsoft Corporation - Windows Explorer.) (.2/22/2014 - 6:50:32 PM.) -- C:\Windows\Explorer.exe [2373784] [MD5.48CFA7BE561A7BE144C29BB912055016] - (.Microsoft Corporation - Windows Start-Up Application.) (.8/22/2013 - 12:58:29 PM.) -- C:\Windows\System32\Wininit.exe [144384] [MD5.8E71A5CB5312B8392D4DA4CA37BB5868] - (.Microsoft Corporation - Internet Extensions for Win32.) (.7/25/2014 - 1:52:06 PM.) -- C:\Windows\System32\wininet.dll [2266624] [MD5.306EB21E5B480AE9065EA55AC8C35936] - (.Microsoft Corporation - Windows Logon Application.) (.2/22/2014 - 12:45:48 PM.) -- C:\Windows\System32\Winlogon.exe [562176] [MD5.AFCAB4DC692CCE37E283B00E2D7B438F] - (.Microsoft Corporation - Software Licensing Library.) (.12/21/2013 - 11:54:07 AM.) -- C:\Windows\System32\sppcomapi.dll [447488] [MD5.374E27295F0A9DCAA8FC96370F9BEEA5] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.5/30/2014 - 6:03:03 AM.) -- C:\Windows\system32\Drivers\AFD.sys [563200] [MD5.74B14192CF79A72F7536B27CB8814FBD] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.8/22/2013 - 3:43:41 PM.) -- C:\Windows\system32\Drivers\atapi.sys [26464] [MD5.2FA6510E33F7DEFEC03658B74101A9B9] - (.Microsoft Corporation - CD-ROM File System Driver.) (.8/22/2013 - 2:40:15 PM.) -- C:\Windows\system32\Drivers\Cdfs.sys [88576] [MD5.C6796EA22B513E3457514D92DCDB1A3D] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.8/22/2013 - 11:46:35 AM.) -- C:\Windows\system32\Drivers\Cdrom.sys [164352] [MD5.414686EF104910BA41DF66E83BDCD495] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.1/16/2014 - 10:32:01 AM.) -- C:\Windows\system32\Drivers\DfsC.sys [134656] [MD5.03909BDBFF0DCACCABF2B2D4ADEE44DC] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.8/22/2013 - 2:38:38 PM.) -- C:\Windows\system32\Drivers\HDAudBus.sys [78336] [MD5.84CFC5EFA97D0C965EDE1D56F116A541] - (.Microsoft Corporation - i8042 Port Driver.) (.8/22/2013 - 2:39:15 PM.) -- C:\Windows\system32\Drivers\i8042prt.sys [107520] [MD5.B7342B3C58E91107F6E946A93D9D4EFD] - (.Microsoft Corporation - IP Network Address Translator.) (.11/27/2013 - 3:02:29 PM.) -- C:\Windows\system32\Drivers\IpNat.sys [142848] [MD5.16FFC07D36FD83ACA189A641385168B3] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.2/2/2014 - 3:19:07 PM.) -- C:\Windows\system32\Drivers\MRxSmb.sys [402944] [MD5.0217532E19A748F0E5D569307363D5FD] - (.Microsoft Corporation - MBT Transport driver.) (.8/22/2013 - 2:37:02 PM.) -- C:\Windows\system32\Drivers\netBT.sys [282624] [MD5.9AEB38B451A7B84ACB7CD3D664F87BF0] - (.Microsoft Corporation - NT File System Driver.) (.2/22/2014 - 6:44:11 PM.) -- C:\Windows\system32\Drivers\ntfs.sys [2013016] [MD5.764B1121867B2D9B31C491668AC72B2B] - (.Microsoft Corporation - Parallel Port Driver.) (.8/22/2013 - 2:40:02 PM.) -- C:\Windows\system32\Drivers\Parport.sys [94208] [MD5.BBB6272B7F46C4640A8CDB8A70C3450F] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.8/22/2013 - 2:35:51 PM.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [120832] [MD5.680C1DAE268B6FB67FA21B389A8B79EF] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.8/22/2013 - 10:11:17 PM.) -- C:\Windows\system32\Drivers\rdpdr.sys [195584] [MD5.FFF28F9F6823EB1756C60F1649560BBF] - (.Microsoft Corporation - TDI Translation Driver.) (.8/22/2013 - 4:25:35 PM.) -- C:\Windows\system32\Drivers\tdx.sys [107520] [MD5.3595FBDF25F8BA6256072D103937D7D6] - (.Microsoft Corporation - Volume Shadow Copy Driver.) (.2/22/2014 - 6:44:13 PM.) -- C:\Windows\system32\Drivers\volsnap.sys [311640] ~ Generic Processes: Scanned in 00mn AMs ---\\ Hidden files state (Hidden/Total) ~ Mes images (My Pictures) : 1/1741 ~ Mes Videos (My Videos) : 1/5 ~ Mes Favoris (My Favorites) : 1/3 ~ Mes Documents (My Documents) : 1/700 ~ Mon Bureau (My Desktop) : 1/389 ~ Menu demarrer (Programs) : 1/38 ~ Hidden Files: Scanned in 02mn AMs ---\\ Process running [MD5.4FBC630768570E6AC35C3DE8F6EC79F5] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe [6970168] [PID.2252] [MD5.349AB4F70E2AC44970894E7F03E1576E] - (.Huawei Technologies Co., Ltd. - DataCardMonitor MFC Application.) -- C:\ProgramData\DatacardService\DCSHelper.exe [236384] [PID.2484] [MD5.87C93C18DDEF79BAE09EB12D1106B902] - (...) -- C:\Program Files (x86)\Zain Broadband\Zain Broadband.exe [514048] [PID.684] [MD5.0706DDBD4EA0D122CA069FF2552E20FD] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [852808] [PID.4156] [MD5.80B582A109C0E361408409183D18FDEB] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8102400] [PID.4788] ~ Processes Running: Scanned in 00mn AMs ---\\ Google Chrome, Start,Search,Extensions (G0,G1,G2) C:\Users\Mo'ath\AppData\Local\Google\Chrome\User Data\Default\Preferences G0 - GCSP: Preference [User Data\Default][StartupURLs] http://google.jo/ G2 - GCE: Preference [User Data\Default] [eehpibjfkijipalplliffcgkhhmecjgi] ط¨ط·ظˆظ„ط§طھ ظƒط±ط© ط§ظ„ظ‚ط¯ظ… v.0.56 (Activé) G2 - GCE: Preference [User Data\Default] [hlhbmnfdcklajeaeikfinieljfegamko] ط§ط®طھط¨ط§ط± ط³ط±ط¹ط© v.2.2 (Activé) G2 - GCE: Preference [User Data\Default] [jpfbieopdmepaolggioebjmedmclkbap] Cache Killer v. () G2 - GCE: Preference [User Data\Default] [kmendfapggjehodndflmmgagdbamhnfd] CryptoTokenExtension v.0.0.1 (Activé) G2 - GCE: Preference [User Data\Default] [mfffpogegjflfpflabcdkioaeobkgjik] GaiaAuthExtension v.0.0.1, (Activé) G2 - GCE: Preference [User Data\Default] [nccllfnllopfpcbjdgjdlfmomnfgnnbk] MultiLogin v.0.1620 (Activé) G2 - GCE: Preference [User Data\Default] [neajdppkdcdipfabeoofebfddakdcjhd] Google Network Speech v.1.0 (Activé) G2 - GCE: Preference [User Data\Default] [pafkbggdmjlpgkdkcbjmhmfcdpncadgh] Google Now v.1.2.0.1 (Activé) G2 - GCE: Preference [User Data\Default] [pfpeapihoiogbcmdmnibeplnikfnhoge] Outlook.com v.1.0.2 (Activé) G2 - GCE: Preference [User Data\Default] [pinjeagflheledfiihhbilplepebhhcn] Facebook Covers v.3.888 (Activé) ---\\ Google Chrome Extension Folder ~ Google Lines Browser: 28 Legitimates Filtered in 04mn AMs ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn AMs ---\\ Line Analysis F0, F1, F2, F3 - IniFiles, Auto loading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn AMs ---\\ Hosts file redirection (O1) ~ Le fichier hôte est sain (The hosts file is clean) (21) ~ Hosts File: Scanned in 00mn AMs ---\\ Auto loading programs from Registry and folders (O4) O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Realtek HD Audio Manager.) -- C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe =>.Adobe Systems Incorporated O4 - HKLM\..\Run: [Andy] . (...) -- C:\Program Files\Andy\HandyAndy.exe O4 - HKCU\..\Run: [Mobile Partner] . (...) -- C:\Program Files (x86)\Zain Broadband\Zain Broadband.exe O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Facebook Installer.) -- C:\Users\Mo'ath\AppData\Local\Facebook\Update\FacebookUpdate.exe O4 - HKLM\..\Wow6432Node\Run: [BlueStacks Agent] . (.BlueStack Systems, Inc. - BlueStacks Agent.) -- C:\Program Files (x86)\BlueStacks\HD-Agent.exe O4 - HKLM\..\Wow6432Node\Run: [Adobe Creative Cloud] . (.Adobe Systems Incorporated - Adobe Creative Cloud.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe O4 - HKLM\..\Wow6432Node\Run: [QHSafeTray] . (.Qihu Software Co. Limited - 360 Total Security.) -- C:\Program Files (x86)\360\Total Security\safemon\360Tray.exe O4 - HKUS\S-1-5-21-1780214637-3531778011-2012122408-1001\..\Run: [Mobile Partner] . (...) -- C:\Program Files (x86)\Zain Broadband\Zain Broadband.exe O4 - HKUS\S-1-5-21-1780214637-3531778011-2012122408-1001\..\Run: [Facebook Update] . (.Facebook Inc. - Facebook Installer.) -- C:\Users\Mo'ath\AppData\Local\Facebook\Update\FacebookUpdate.exe ~ Application: Scanned in 00mn AMs ---\\ Lop.com/Domain Hijackers (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{D69BE18D-E5BE-4B77-A601-6B2AAAAF79B6}: NameServer = 188.247.86.10 188.247.86.11 O17 - HKLM\System\CCS\Services\Tcpip\..\{E77ED4B4-E610-4B2E-8E07-EC4BB9BF2C1F}: NameServer = 188.247.86.10 188.247.86.11 O17 - HKLM\System\CCS\Services\Tcpip\..\{F5AC5FE7-7611-47DE-9489-39820C5595A7}: NameServer = 188.247.86.10 188.247.86.11 O17 - HKLM\System\CCS\Services\Tcpip\..\{F2E20604-E1D1-480B-A727-63C2AD8BC39D}: DhcpNameServer = 192.168.43.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{D69BE18D-E5BE-4B77-A601-6B2AAAAF79B6}: NameServer = 188.247.86.10 188.247.86.11 O17 - HKLM\System\CS1\Services\Tcpip\..\{E77ED4B4-E610-4B2E-8E07-EC4BB9BF2C1F}: NameServer = 188.247.86.10 188.247.86.11 O17 - HKLM\System\CS1\Services\Tcpip\..\{F5AC5FE7-7611-47DE-9489-39820C5595A7}: NameServer = 188.247.86.10 188.247.86.11 O17 - HKLM\System\CS1\Services\Tcpip\..\{F2E20604-E1D1-480B-A727-63C2AD8BC39D}: DhcpNameServer = 192.168.43.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.43.1 ~ Domain: Scanned in 00mn AMs ---\\ Extra protocols (O18) O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation ~ Protocole Additionnel: Scanned in 00mn AMs ---\\ Non Microsoft non disabled Windows XP/NT/2000 Services (O23) O23 - Service: HWDeviceService64.exe (HWDeviceService64.exe) . (.No owner - DCSHOST.) - C:\ProgramData\DatacardService\HWDeviceService64.exe O23 - Service: 360 Total Security (QHActiveDefense) . (.No owner - 360 Total Security.) - C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe O23 - Service: Zain Broadband. OUC (Zain Broadband. RunOuc) . (...) - C:\Program Files (x86)\Zain Broadband\UpdateDog\ouc.exe ~ Services: 13 Legitimates Filtered in 03mn AMs ---\\ Task Planned Automatically (039) O39 - APT: - (..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1780214637-3531778011-2012122408-1001Core [922] O39 - APT: - (..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1780214637-3531778011-2012122408-1001UA [944] ~ Scheduled Task: 11 Legitimates Filtered in 01mn AMs ---\\ Drivers launched at startup (O41) O41 - Driver: (360Box64) . (.360.cn - 360Box64.) - C:\Windows\System32\DRIVERS\360Box64.sys O41 - Driver: (360Camera) . (.360.cn - 360安全卫士 木马防火墙模块.) - C:\Windows\System32\Drivers\360Camera64.sys O41 - Driver: (360FsFlt) . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Proactive Defense.) - C:\Windows\System32\DRIVERS\360FsFlt.sys O41 - Driver: (BAPIDRV) . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Cloud Security.) - C:\Windows\System32\DRIVERS\BAPIDRV64.sys ~ Drivers: 48 Legitimates Filtered in 00mn AMs ---\\ Software installed (O42) O42 - Logiciel: ANDY OS - (.andyroid.net.) [HKLM][64Bits] -- ANDY OS ~ Logic: 25 Legitimates Filtered in 00mn AMs ---\\ HKCU & HKLM Software Keys [HKCU\Software\360] [HKCU\Software\AdsFix] [HKCU\Software\Andy] [HKCU\Software\Project07] [HKLM\Software\AdsFix] [HKLM\Software\Wow6432Node\360Safe] [HKLM\Software\Wow6432Node\360TotalSecurity] [HKLM\Software\Wow6432Node\360softmgr] [HKLM\Software\Wow6432Node\AdsFix] [HKLM\Software\Wow6432Node\ND] [HKLM\Software\Wow6432Node\SOSVirus] ~ Key Software: 182 Legitimates Filtered in 00mn AMs ---\\ Contents of the Common Files folders (O43) O43 - CFD: 9/4/2014 - 10:47:06 PM - [] ----D C:\Program Files (x86)\360 O43 - CFD: 8/11/2014 - 3:31:51 AM - [] ----D C:\Program Files (x86)\Remove Logo Now! O43 - CFD: 8/6/2014 - 5:28:16 AM - [] ----D C:\Program Files (x86)\Zain Broadband O43 - CFD: 9/12/2014 - 3:04:43 AM - [] ----D C:\ProgramData\360safe O43 - CFD: 8/19/2014 - 8:02:29 PM - [] ----D C:\ProgramData\KMSAutoS =>Trojan.AutoKMS O43 - CFD: 8/6/2014 - 5:28:16 AM - [] ----D C:\ProgramData\Zain Broadband O43 - CFD: 9/12/2014 - 10:38:39 AM - [] ----D C:\Users\Mo'ath\AppData\Roaming\360safe O43 - CFD: 8/20/2014 - 12:40:10 AM - [] ----D C:\Users\Mo'ath\AppData\Roaming\rmi O43 - CFD: 9/8/2014 - 12:11:57 AM - [] ----D C:\Users\Mo'ath\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Andy ~ Program Folder: 119 Legitimates Filtered in 00mn AMs ---\\ Last modified or created files under Windows and System32 (O44) O44 - LFC:[MD5.09FA608B4845F4EB06A77636602800E5] - 9/12/2014 - 2:16:03 AM ---A- . (...) -- C:\AdsFix_12_09_2014_02_16_06.txt [30199] O44 - LFC:[MD5.4D3CECDF094C65D999E6CFDF8DED2339] - 9/12/2014 - 3:03:50 AM ---A- . (...) -- C:\AdsFix_12_09_2014_03_03_51.txt [22015] O44 - LFC:[MD5.A583F4DAAA4DB87BF92FD033966ABC4B] - 9/4/2014 - 10:47:30 PM ---A- . (.360.cn - 360Box64.) -- C:\Windows\System32\Drivers\360Box64.sys [305736] O44 - LFC:[MD5.15FE196A71357AC9FF6E5A4B360BDB20] - 9/4/2014 - 10:47:32 PM ---A- . (.360.cn - 360安全卫士 网络防黑模块.) -- C:\Windows\System32\Drivers\360AntiHacker64.sys [100424] O44 - LFC:[MD5.D33811D3113C05B8485BF497B6CB50A9] - 9/4/2014 - 10:47:32 PM ---A- . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Cloud Security.) -- C:\Windows\System32\Drivers\BAPIDRV64.SYS [180816] O44 - LFC:[MD5.D31541708A595BCA380105D44C2C2AD5] - 9/4/2014 - 10:47:33 PM ---A- . (.360.cn - 360安全卫士 木马防火墙模块.) -- C:\Windows\System32\Drivers\360Camera64.sys [40520] O44 - LFC:[MD5.3AA0D07082BF4B4EFF8BAE9F4EDF783B] - 9/4/2014 - 10:47:37 PM ---A- . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Proactive Defense.) -- C:\Windows\System32\Drivers\360fsflt.sys [311888] O44 - LFC:[MD5.0AABA03736666B85AC37C01467E89578] - 9/4/2014 - 10:47:48 PM ---A- . (.360.cn - 360杀毒 文件监控驱动.) -- C:\Windows\System32\Drivers\360AvFlt.sys [77896] O44 - LFC:[MD5.1EE5F9F327D19074DA82B58D8252A749] - 9/4/2014 - 10:47:50 PM ---A- . (.360安全中心 - 360Efimon Driver.) -- C:\Windows\System32\Drivers\efimon.sys [23752] ~ Files: 82 Legitimates Filtered in 04mn AMs ---\\ Local Security Authority-LSA Deny (O48) ~ LSA: 3 Legitimates Filtered in 00mn AMs ---\\ MountPoints2 Shell Key (MPKS) (O51) O51 - MPSK:{bad66ca3-1cf2-11e4-824c-806e6f6e6963}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) O51 - MPSK:{ccd4ac93-2868-11e4-8254-a02bb8210ac1}\AutoRun\command. (...) -- E:\AutoRun.exe (.not file.) O51 - MPSK:{d8f965ce-1d10-11e4-824f-9cd21e1f66bd}\AutoRun\command. (...) -- E:\AutoRun.exe (.not file.) O51 - MPSK:{f43a79bd-1d55-11e4-8251-001e101f9689}\AutoRun\command. (...) -- E:\AutoRun.exe (.not file.) ~ Keys: Scanned in 00mn AMs ---\\ Microsoft Windows Policies System (MWPS) (O55) O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ MWPS: 17 Legitimates Filtered in 00mn AMs ---\\ Microsoft Windows Policies Explorer (MWPE) (O56) O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 ~ MWPE Keys: 3 Legitimates Filtered in 00mn AMs ---\\ System Drivers List (SDL) (O58) O58 - SDL:8/21/2014 - 4:22:35 PM ---A- . (.360.cn - 360安全卫士 网络防黑模块.) -- C:\Windows\System32\Drivers\360AntiHacker64.sys [100424] O58 - SDL:8/21/2014 - 4:22:35 PM ---A- . (.360.cn - 360杀毒 文件监控驱动.) -- C:\Windows\System32\Drivers\360AvFlt.sys [77896] O58 - SDL:8/21/2014 - 4:22:35 PM ---A- . (.360.cn - 360Box64.) -- C:\Windows\System32\Drivers\360Box64.sys [305736] O58 - SDL:8/21/2014 - 4:22:35 PM ---A- . (.360.cn - 360安全卫士 木马防火墙模块.) -- C:\Windows\System32\Drivers\360Camera64.sys [40520] O58 - SDL:8/21/2014 - 4:22:35 PM ---A- . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Proactive Defense.) -- C:\Windows\System32\Drivers\360fsflt.sys [311888] O58 - SDL:8/21/2014 - 4:22:35 PM ---A- . (.Qihu 360 Software Co., Ltd. - 360 Internet Security Cloud Security.) -- C:\Windows\System32\Drivers\BAPIDRV64.SYS [180816] O58 - SDL:8/13/2013 - 2:25:46 AM ---A- . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\Drivers\bcmfn2.sys [17624] O58 - SDL:8/21/2014 - 4:22:35 PM ---A- . (.360安全中心 - 360Efimon Driver.) -- C:\Windows\System32\Drivers\efimon.sys [23752] O58 - SDL:8/6/2014 - 5:27:43 AM ---A- . (.Huawei Tech. Co., Ltd. - HUAWEI USB Smart Card Driver.) -- C:\Windows\System32\Drivers\ewdcsc.sys [32768] O58 - SDL:6/9/2014 - 11:41:00 AM ---A- . (.Tonec Inc. - Internet Download Manager WFP Driver.) -- C:\Windows\System32\Drivers\idmwfp.sys [180136] O58 - SDL:8/6/2014 - 5:27:43 AM ---A- . (.DiBcom SA - DiBcom AVSTREAM BDA driver.) -- C:\Windows\System32\Drivers\mod7700.sys [1001472] O58 - SDL:1/22/2014 - 6:52:10 PM ---A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudbus.sys [108800] O58 - SDL:1/22/2014 - 6:52:10 PM ---A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudmdm.sys [206080] O58 - SDL:1/22/2014 - 6:52:12 PM ---A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Mobile Logging Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudserd.sys [206080] O58 - SDL:8/22/2013 - 3:43:32 PM ---A- . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x64.) -- C:\Windows\System32\Drivers\stexstor.sys [31072] O58 - SDL:8/13/2014 - 3:07:22 AM ---A- . (.StdLib - StdLib.) -- C:\Windows\System32\Drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}Gw64.sys [61584] =>PUP.LinkiDoo O58 - SDL:7/31/2014 - 4:56:44 PM ---A- . (...) -- C:\Windows\SysWOW64\drivers\MoborobAssDriver64.sys [13304] ~ Drivers: 73 Legitimates Filtered in 04mn AMs ---\\ Alternate Data Stream File (ADS) (O62) O62 - ADS:Alternate Data Stream File - C:\Windows\System32\ig7icd32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igd10iumd32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igdail32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igdbcl32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igdde32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igdfcl32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igdmd32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igdrcl32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igdumdim32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igdusc32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igfx11cmrt32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igfxcmjit32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igfxcmrt32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\igfxexps32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\iglhcp32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\iglhsip32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\IntelCpHeciSvc.exe:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\IntelOpenCL32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\Intel_OpenCL_ICD32.dll:Zone.Identifier O62 - ADS:Alternate Data Stream File - C:\Windows\System32\OpenCL.DLL:Zone.Identifier ~ ADS: Scanned in 01mn AMs ---\\ List all tools cleaner (LATC) (O63) O63 - Logiciel: UsbFix - (.El Desaparecido - www.usbfix.net - www.sosvirus.net.) [HKLM] -- Usbfix O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman ~ ADS: Scanned in 00mn AMs ---\\ File Associations Shell Spawning (O67) O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Not Key.) ~ FASS Keys: 11 Legitimates Filtered in 00mn AMs ---\\ Start Menu Internet (SMI) (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Keys: Scanned in 00mn AMs ---\\ Search Browser Infection (SBI) (O69) O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com ~ Keys: Scanned in 00mn AMs ---\\ Search Particular Root Folder (SPRF) (O84) [MD5.B67230A0FC91A977F9E398C609FEC10B] [SPRF][8/22/2014] (...) -- C:\Users\Mo'ath\AppData\Roaming\AndyCleanupTool.exe [1177208] [MD5.8D05C7AF64CF79A366C1844C39A8FC1D] [SPRF][8/22/2014] (...) -- C:\Users\Mo'ath\AppData\Roaming\AndyCleanVM.exe [1176696] [MD5.388DE0500C3375F3FC2B2D49A33AA58E] [SPRF][9/12/2014] (.No owner - AdsFix.) -- C:\Users\Mo'ath\Desktop\AdsFix.exe [2696192] [MD5.E8F746CD86EFBCD5AB43F01A59CFE49D] [SPRF][10/8/2013] (.No owner - CPU temperature and system information utility.) -- C:\Users\Mo'ath\Desktop\Core Temp.exe [890016] ~ Files: 4 Legitimates Filtered in 00mn AMs ---\\ MyComputer Name Space (MNS) (O92) O92 - MNS: - {1CF1260C-4DD0-4ebb-811F-33C572699FDE} O92 - MNS: - {374DE290-123F-4565-9164-39C4925E467B} O92 - MNS: - {3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA} O92 - MNS: - {A0953C92-50DC-43bf-BE83-3742FED03C9C} O92 - MNS: - {A8CDFF1C-4878-43be-B5FD-F8091C1C60D0} O92 - MNS: - {B4BFCC3A-DB2C-424C-B029-7FE99A87C641} ~ MNS: 6 Legitimates Filtered in 00mn AMs ---\\ General States of Services not Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Auto 5/1/2014 402192 | (BstHdAndroidSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-Service.exe SS - | Demand 5/23/2014 279024 | (cphs) . (.Intel Corporation.) - C:\Windows\SysWow64\IntelCpHeciSvc.exe SS - | Demand 8/6/2014 116648 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 8/6/2014 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 4/25/2012 169752 | (ICCS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe SS - | Demand 7/11/1658 0 | (IePluginServices) . (...) - C:\ProgramData\IePluginServices\PluginService.exe =>PUP.IePluginService SS - | Demand 7/11/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation SS - | Auto 8/6/2014 246112 | (Zain Broadband. RunOuc) . (...) - C:\Program Files (x86)\Zain Broadband\UpdateDog\ouc.exe SR - | Auto 8/6/2014 98208 | (AERTFilters) . (.Andrea Electronics Corporation.) - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe SR - | Auto 8/31/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe SR - | Auto 5/1/2014 385808 | (BstHdLogRotatorSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe SR - | Auto 5/1/2014 774928 | (BstHdUpdaterSvc) . (.BlueStack Systems, Inc..) - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe SR - | Auto 8/26/2014 78088 | (HPSupportSolutionsFrameworkService) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe SR - | Auto 3/14/2011 346976 | (HWDeviceService64.exe) . (...) - C:\ProgramData\DatacardService\HWDeviceService64.exe SR - | Auto 5/23/2014 282096 | (igfxCUIService1.0.0.0) . (.Intel Corporation.) - C:\Windows\System32\igfxCUIService.exe SR - | Auto 5/12/2014 1809720 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe SR - | Auto 5/12/2014 860472 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe SR - | Auto 8/21/2014 707184 | (QHActiveDefense) . (...) - C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe SR - | Auto 8/6/2014 290520 | (RtkAudioService) . (.Realtek Semiconductor.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe SR - | Demand 7/11/1658 0 | (WdNisSvc) . (...) - C:\Program Files (x86)\Windows Defender\NisSrv.exe SR - | Demand 7/11/1658 0 | (WinDefend) . (...) - C:\Program Files (x86)\Windows Defender\MsMpEng.exe SR - | Demand 8/22/2013 37768 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Services: Scanned in 07mn AMs ---\\ Search Master Boot Record Infection (MBR)(O80) Run by Mo'ath at 9/12/2014 10:43:34 AM ~ OS 64 not supported by MBR tool ~ MBR: 0 Legitimates Filtered in 00mn AMs ---\\ Search Master Boot Record Infection (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by Mo'ath at 9/12/2014 10:43:36 AM ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 02mn AMs ---\\ Scan Additionnel (O88) Database Version : 13026 - (9/10/2014) Clés trouvées (Keys found) : 1 Valeurs trouvées (Values found) : 0 Dossiers trouvés (Folders found) : 1 Fichiers trouvés (Files found) : 0 [HKLM\Software\Wow6432Node\360Safe] =>Trojan.Lozavita C:\ProgramData\KMSAutoS =>Trojan.AutoKMS^ ~ Additionnel Scan: 169590 Items scanned in 11mn AMs ---\\ Additional information about modules ~ http://nicolascoolman.fr/g0-page-de-demarrage-google-chrome/ =>.Google Chrome, Start,Search,Extensions (G0,G1,G2) ~ http://nicolascoolman.fr/g2-google-chrome-extensions/ =>.Google Chrome, Start,Search,Extensions (G0,G1,G2) ~ http://nicolascoolman.fr/r5-internet-explorer-proxy-management-iepm/ =>.Internet Explorer, Proxy Management (R5) ~ http://nicolascoolman.fr/o4-applications-demarrees-par-le-registre/ =>.Auto loading programs from Registry and folders (O4) ~ http://nicolascoolman.fr/o51-mountpoints2-shell-key-mpsk/ =>.MountPoints2 Shell Key (MPKS) (O51) ~ AMI: 5 Legitimates Filtered in 00mn AMs ---\\ Summary of the detections found on your workstation http://nicolascoolman.fr/trojan-autokms =>Trojan.AutoKMS http://nicolascoolman.fr/pup-linkidoo =>PUP.LinkiDoo http://nicolascoolman.fr/trojan-lozavita =>Trojan.Lozavita ~ MSI: 3 link(s) detected in 00mn AMs ~ 620 Legitimates filtered by white list End of the scan (472 lines in 34mn AMs)(0)