cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Script ZHPFix
[MD5.EFD1839F21CEBB26D4A815ACDA85E3A1] - (.KalityWeb - WebAdSystem.) -- C:\Program Files\WebAdSystem\WebAdSystem.exe [822640] [PID.3268] =>Adware.WebAdSystem
G0 - GCSP: Preference [User Data\Default][HomePage] http://istart.webssearches.com =>Hijacker.WebsSearches
G2 - GCE: Preference [User Data\Default] [opldoklbgkdpfmogjpheabmldkcdkokn] WebAdSystem v.1.4.15.0 (D�sactiv�) =>Adware.WebAdSystem
G2 - EXT: C:\Documents and Settings\BOUHAFA\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\opldoklbgkdpfmogjpheabmldkcdkokn [WebAdSystem] =>Adware.WebAdSystem
M3 - MFPP: Plugins - [BOUHAFA] -- C:\Documents and Settings\BOUHAFA\Application Data\Mozilla\Firefox\Profiles\n9e00o1n.default\searchplugins\buenosearch.xml =>PUP.BuenoSearch
M0 - MFSP: prefs.js [BOUHAFA - n9e00o1n.default] http://istart.webssearches.com =>Hijacker.WebsSearches
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com =>Hijacker.WebsSearches
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com =>Hijacker.WebsSearches
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com =>Hijacker.WebsSearches
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com =>Hijacker.WebsSearches
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com =>Hijacker.WebsSearches
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com =>Hijacker.WebsSearches
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com =>Hijacker.WebsSearches
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com =>Hijacker.WebsSearches
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://istart.webssearches.com =>Hijacker.WebsSearches
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://istart.webssearches.com =>Hijacker.WebsSearches
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <-loopback> =>Hijacker.Proxy
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} . (.Thinknice Co. Limited - SupTab setup package.) -- C:\Program Files\SupTab\SupTab.dll =>PUP.SupTab
O2 - BHO: WebAdSystemBho - {EC8FCB46-9F27-476E-B26A-93989316D2FB} . (.KalityWeb - WebAdSystemBho.) -- C:\Program Files\WebAdSystem\BrowserExtensions\internetexplorer\WebAdSystemBho.dll =>Adware.WebAdSystem
O4 - GS\Program [AllUsers]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe http://istart.webssearches.com =>Hijacker.WebsSearches
O4 - GS\Program [AllUsers]: WebAdSystem.lnk . (.KalityWeb - WebAdSystem.) -- C:\Program Files\WebAdSystem\WebAdSystem.exe =>Adware.WebAdSystem
O4 - GS\Program [BOUHAFA]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe http://istart.webssearches.com =>Hijacker.WebsSearches
O4 - HKLM\..\Run: [YourFile DownloaderInstaller Starter] C:\DOCUME~1\BOUHAFA\LOCALS~1\Temp\install2120926.exe (.not file.) =>PUP.YourFileDownloader
O4 - HKLM\..\Run: [WebAdSystem] . (.KalityWeb - WebAdSystem.) -- C:\Program Files\WebAdSystem\WebAdSystem.exe =>Adware.WebAdSystem
O23 - Service: IePlugin Services (IePluginServices) . (.Cherished Technololgy LIMITED - IePlugin Service.) - C:\Documents and Settings\All Users\Application Data\IePluginServices\PluginService.exe =>Trojan.SProtector
O23 - Service: WindowsProtectManger Service (WindowsProtectManger) . (.Fuyu LIMITED - WindowsProtectManger Service.) - C:\Documents and Settings\All Users\Application Data\WindowsProtectManger\wprotectmanager.exe =>Trojan.Fuyu
[MD5.00000000000000000000000000000000] [APT] [YourFile DownloaderUpdate] (...) -- C:\Program Files\YourFileDownloader Updater\YourFileUpdater.exe (.not file.) [0] =>PUP.YourFileDownloader
O39 - APT: YourFile DownloaderUpdate - (...) -- C:\WINDOWS\Tasks\YourFile DownloaderUpdate.job [340] =>PUP.YourFileDownloader
O41 - Driver: ({587cb346-a3d8-4884-b39b-f0ed918b6f96}Gt) . (.StdLib - StdLib.) - C:\WINDOWS\system32\drivers\{587cb346-a3d8-4884-b39b-f0ed918b6f96}Gt.sys =>PUP.LinkiDoo
O42 - Logiciel: WebAdSystem - (.KalityWeb.) [HKLM] -- {4b693ee6-6ab3-41b6-956e-6290548ad66d} =>Adware.WebAdSystem
O42 - Logiciel: WebAdSystem - (.KalityWeb.) [HKLM] -- {AF59773E-3245-46A3-B418-DD84AB6C3C50} =>Adware.WebAdSystem
O42 - Logiciel: WindowsProtectManger20.0.0.339 - (.Fuyu LIMITED.) [HKLM] -- WindowsProtectManger =>Trojan.Fuyu
O42 - Logiciel: webssearches uninstaller - (.webssearches.) [HKLM] -- webssearches uninstaller =>Hijacker.WebsSearches
[HKCU\Software\Boxore] =>Adware.Boxore
[HKCU\Software\KalityWeb] =>Adware.WebAdSystem
[HKCU\Software\YourFileDownloader]
[HKLM\Software\Boxore] =>Adware.Boxore
[HKLM\Software\KalityWeb] =>Adware.WebAdSystem
[HKLM\Software\SupDp] =>PUP.SupTab
[HKLM\Software\Wpm] =>PUP.WpManager
[HKLM\Software\YourFileDownloader]
[HKLM\Software\supTab] =>PUP.SupTab
[HKLM\Software\supWindowsProtectManger] =>Trojan.Fuyu
[HKLM\Software\webssearchesSoftware] =>Hijacker.WebsSearches
O43 - CFD: 06/06/2014 - 15:52:16 - [] ----D C:\Program Files\Software
O43 - CFD: 06/06/2014 - 13:51:03 - [] ----D C:\Program Files\SupTab =>PUP.SupTab
O43 - CFD: 06/06/2014 - 13:51:46 - [] ----D C:\Program Files\WebAdSystem =>Adware.WebAdSystem
O43 - CFD: 06/06/2014 - 13:51:02 - [] ----D C:\Documents and Settings\All Users\Application Data\IePluginServices =>Trojan.SProtector
O43 - CFD: 06/06/2014 - 13:51:01 - [] ----D C:\Documents and Settings\All Users\Application Data\WindowsProtectManger =>Trojan.Fuyu
O43 - CFD: 06/06/2014 - 13:51:00 - [0] ----D C:\Documents and Settings\BOUHAFA\Application Data\SupTab =>PUP.SupTab
O43 - CFD: 06/06/2014 - 16:24:16 - [] ----D C:\Documents and Settings\BOUHAFA\Application Data\webssearches =>Hijacker.WebsSearches
O43 - CFD: 24/05/2014 - 19:40:21 - [0] ----D C:\Documents and Settings\BOUHAFA\Application Data\YourFileDownloader
O43 - CFD: 06/06/2014 - 13:51:45 - [] ----D C:\Documents and Settings\BOUHAFA\Local Settings\Application Data\KalityWeb =>Adware.WebAdSystem
O43 - CFD: 06/06/2014 - 13:47:47 - [] ----D C:\Documents and Settings\BOUHAFA\Local Settings\Application Data\Software =>Adware.Boxore
O44 - LFC:[MD5.4AF54BC8B22ADFE155BDCC6C622E4408] - 24/05/2014 - 20:15:18 ---A- . (.StdLib - StdLib.) -- C:\WINDOWS\system32\Drivers\{587cb346-a3d8-4884-b39b-f0ed918b6f96}Gt.sys [55232] =>PUP.LinkiDoo
O45 - LFCP:[MD5.3D78B7DC2ED7B4C5773F0677FCDF7206] - 06/06/2014 - 12:48:41 ---A- - C:\WINDOWS\Prefetch\BOXORE.EXE-2493A27E.pf =>Adware.Boxore
O45 - LFCP:[MD5.50A7F0EF7C56782E84A5B58D22CC5C6C] - 06/06/2014 - 15:13:37 ---A- - C:\WINDOWS\Prefetch\WAJAMHTTPSERVER.EXE-114088E6.pf =>PUP.Wajam
O45 - LFCP:[MD5.BB619295666C8504F5131C1CD15EF2D5] - 06/06/2014 - 15:16:01 ---A- - C:\WINDOWS\Prefetch\WAJAMINTERNETENHANCER.EXE-065605A0.pf =>PUP.Wajam
O45 - LFCP:[MD5.A05155BF6EF5FFC30C263225375917B7] - 06/06/2014 - 15:21:36 ---A- - C:\WINDOWS\Prefetch\WAJAMINTERNETENHANCERSERVICE.-09DCC0FA.pf =>PUP.Wajam
O45 - LFCP:[MD5.450B95C265E04E89450ADB2AD27FB386] - 08/06/2014 - 12:38:02 ---A- - C:\WINDOWS\Prefetch\WEBADSYSTEM.EXE-17B61E7B.pf =>Adware.WebAdSystem
O58 - SDL:22/05/2014 - 17:22:32 ---A- . (.StdLib - StdLib.) -- C:\WINDOWS\system32\Drivers\{587cb346-a3d8-4884-b39b-f0ed918b6f96}Gt.sys [55232] =>PUP.LinkiDoo
O64 - Services: CurCS - 22/05/2014 - C:\WINDOWS\system32\drivers\{587cb346-a3d8-4884-b39b-f0ed918b6f96}Gt.sys ({587cb346-a3d8-4884-b39b-f0ed918b6f96}Gt) .(.StdLib - StdLib.) - LEGACY_{587CB346-A3D8-4884-B39B-F0ED918B6F96}GT =>PUP.LinkiDoo
O68 - StartMenuInternet: <>[HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Google\Chrome\Application\chrome.exe" http://istart.webssearches.com =>Hijacker.WebsSearches
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Internet Explorer\iexplore.exe" http://istart.webssearches.com =>Hijacker.WebsSearches
O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} - (Bueno Search) - http://www.buenosearch.com =>PUP.BuenoSearch
O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} [DefaultScope] - (webssearches) - http://istart.webssearches.com =>Hijacker.WebsSearches
[MD5.B6C9DF2816FC7F6BD151CA3C1F009373] [WIS][06/06/2014] (.KalityWeb - WebAdSystem.) -- C:\Windows\Installer\21e83d.msi [176128] =>Adware.WebAdSystem
[HKCR\CLSID\{EC8FCB46-9F27-476E-B26A-93989316D2FB}] (WebAdSystem) =>Adware.WebAdSystem
SS - | Auto 08/05/2014 704112 | (IePluginServices) . (.Cherished Technololgy LIMITED.) - C:\Documents and Settings\All Users\Application Data\IePluginServices\PluginService.exe =>Trojan.SProtector
SS - | Auto 06/06/2014 573344 | (WindowsProtectManger) . (.Fuyu LIMITED.) - C:\Documents and Settings\All Users\Application Data\WindowsProtectManger\wprotectmanager.exe =>Trojan.Fuyu
[HKLM\Software\Google\Chrome\Extensions\opldoklbgkdpfmogjpheabmldkcdkokn] =>Adware.WebAdSystem^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}] =>PUP.SupTab^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EC8FCB46-9F27-476E-B26A-93989316D2FB}] =>Adware.WebAdSystem^
[HKLM\SYSTEM\CurrentControlSet\Services\IePluginServices] =>Trojan.SProtector^
[HKLM\SYSTEM\CurrentControlSet\Services\WindowsProtectManger] =>Trojan.Fuyu^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4b693ee6-6ab3-41b6-956e-6290548ad66d}] =>Adware.WebAdSystem^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AF59773E-3245-46A3-B418-DD84AB6C3C50}] =>Adware.WebAdSystem^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WindowsProtectManger] =>Trojan.Fuyu^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\webssearches uninstaller] =>Hijacker.WebsSearches^
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}] =>PUP.Babylon
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software
[HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software
[HKCU\Software\Boxore] =>Adware.Boxore
[HKLM\Software\Boxore] =>Adware.Boxore
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EC8FCB46-9F27-476E-B26A-93989316D2FB}] =>Adware.WebAdSystem
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EC8FCB46-9F27-476E-B26A-93989316D2FB}] =>Adware.WebAdSystem
[HKLM\Software\Classes\CLSID\{EC8FCB46-9F27-476E-B26A-93989316D2FB}] =>Adware.WebAdSystem
[HKLM\Software\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}] =>Adware.BrowseFox
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] =>Adware.Boxore^
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:YourFile DownloaderInstaller Starter =>PUP.YourFileDownloader^
C:\Documents and Settings\BOUHAFA\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\opldoklbgkdpfmogjpheabmldkcdkokn =>Adware.WebAdSystem^
C:\Program Files\SupTab =>PUP.SupTab^
C:\Program Files\WebAdSystem =>Adware.WebAdSystem^
C:\Documents and Settings\All Users\Application Data\IePluginServices =>Trojan.SProtector^
C:\Documents and Settings\All Users\Application Data\WindowsProtectManger =>Trojan.Fuyu^
C:\Documents and Settings\BOUHAFA\Application Data\SupTab =>PUP.SupTab^
C:\Documents and Settings\BOUHAFA\Application Data\webssearches =>Hijacker.WebsSearches^
C:\Documents and Settings\BOUHAFA\Local Settings\Application Data\KalityWeb =>Adware.WebAdSystem^
C:\Documents and Settings\BOUHAFA\Local Settings\Application Data\Software =>Adware.Boxore^
C:\Program Files\Software =>Adware.Boxore
C:\Documents and Settings\BOUHAFA\Application Data\yourfiledownloader =>PUP.YourFileDownloader
C:\Program Files\WebAdSystem\WebAdSystem.exe =>Adware.WebAdSystem^
C:\WINDOWS\Tasks\YourFile DownloaderUpdate.job =>PUP.YourFileDownloader^
[HKLM\Software\SupDp] =>PUP.SupTab^
[HKLM\Software\Wpm] =>PUP.WpManager^
[HKLM\Software\supTab] =>PUP.SupTab^
[HKLM\Software\supWindowsProtectManger] =>Trojan.Fuyu^
[HKLM\Software\webssearchesSoftware] =>Hijacker.WebsSearches^
C:\Windows\Installer\21e83d.msi =>Adware.WebAdSystem^
[HKCR\CLSID\{EC8FCB46-9F27-476E-B26A-93989316D2FB}] (WebAdSystem) =>Adware.WebAdSystem^
[HKCU\Software\KalityWeb] =>Toolbar.Agent
[HKLM\Software\KalityWeb] =>Toolbar.Agent
EmptyPrefetch
FirewallRaz
PROXYFix
EmptyTemp
EmptyFlash
EmptyClsid
SysRestore

Publicité


Signaler le contenu de ce document

Publicité