¤¤¤¤¤¤¤¤¤¤ | Shortcut_Module 13.11.2013.2 - g3n-h@ckm@n
17:15:53 - 21/11/2013
(920) -- atiesrxx.exe
(1296) -- atieclxx.exe
(1572) -- explorer.exe
(1640) -- spoolsv.exe
(1796) -- taskhost.exe
(1896) -- armsvc.exe
(1932) -- AppleMobileDeviceService.exe
(1968) -- mDNSResponder.exe
(2028) -- msseces.exe
(820) -- soffice.exe
(2256) -- soffice.bin
(2308) -- SearchIndexer.exe
(2620) -- WUDFHost.exe
(2808) -- iexplore.exe
(2860) -- iexplore.exe
(3044) -- iexplore.exe
(3808) -- MsSpellCheckingFacility.exe
(736) -- iexplore.exe
(1488) -- SearchProtocolHost.exe
(3504) -- SearchFilterHost.exe
(2420) -- SearchProtocolHost.exe
¤¤¤¤¤¤¤¤¤¤ | Hijack Links
Disinfected : C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk : C:\Program Files\Mozilla Firefox\firefox.exe (hxxp://do-search.com/?type=scts=1384815339from=tugsuid=WDCXWD3200JS-60PDB0_WD-WCAPD208879888798)
Disinfected : C:\Users\Public\Desktop\Mozilla Firefox.lnk : C:\Program Files\Mozilla Firefox\firefox.exe (hxxp://do-search.com/?type=scts=1384815339from=tugsuid=WDCXWD3200JS-60PDB0_WD-WCAPD208879888798)
Disinfected : C:\Users\Utilisateur\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk : C:\Program Files\Internet Explorer\iexplore.exe (hxxp://do-search.com/?type=scts=1384815339from=tugsuid=WDCXWD3200JS-60PDB0_WD-WCAPD208879888798)
Disinfected : C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk : C:\Program Files\Internet Explorer\iexplore.exe (hxxp://do-search.com/?type=scts=1384815339from=tugsuid=WDCXWD3200JS-60PDB0_WD-WCAPD208879888798)
Disinfected : C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk : C:\Program Files\Internet Explorer\iexplore.exe (hxxp://do-search.com/?type=scts=1384815339from=tugsuid=WDCXWD3200JS-60PDB0_WD-WCAPD208879888798)
Disinfected : C:\Users\Utilisateur\Desktop\Internet Explorer.lnk : C:\Program Files\Internet Explorer\iexplore.exe (hxxp://do-search.com/?type=scts=1384815339from=tugsuid=WDCXWD3200JS-60PDB0_WD-WCAPD208879888798)
¤¤¤¤¤¤¤¤¤¤ | Hijack Internet Explorer
Repaired : [HKU\S-1-5-21-1181802946-1865005556-1823128663-1000\Software\Microsoft\Internet Explorer\Main]|[Start Page] :
https://www.google.fr/ -
http://www.google.com/
Repaired : [HKU\S-1-5-21-1181802946-1865005556-1823128663-1000\Software\Microsoft\Internet Explorer\Main]|[Search Page] :
http://go.microsoft.com/fwlink/?LinkId=54896 -
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Start Page] :
http://go.microsoft.com/fwlink/p/?LinkId=255141 -
http://go.microsoft.com/fwlink/?LinkId=69157
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Default_Search_URL] :
http://do-search.com/web/?type=dsts=138 ... earchTerms} -
http://go.microsoft.com/fwlink/?LinkId=54896
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Default_Page_URL] :
http://go.microsoft.com/fwlink/p/?LinkId=255141 -
http://go.microsoft.com/fwlink/?LinkId=69157
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Search Page] :
http://do-search.com/web/?type=dsts=138 ... earchTerms} -
http://go.microsoft.com/fwlink/?LinkId=54896
Repaired : [HKU\S-1-5-21-1181802946-1865005556-1823128663-1000\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[WarnonZoneCrossing] : 0 - 1
¤¤¤¤¤¤¤¤¤¤ | Hijack Google Chrome
¤¤¤¤¤¤¤¤¤¤ | Hijack Firefox
[Utilisateur] Replaced : user_pref("browser.search.defaultenginename", "do-search"); - user_pref("browser.search.defaultenginename", "google");
¤¤¤¤¤¤¤¤¤¤ | Hijack StartMenuInternet
Repaired : [HKLM\Software\Clients\StartMenuInternet\Firefox.exe\shell\open\command] : C:\Program Files\Mozilla Firefox\firefox.exe
http://do-search.com/?type=scts=1384815 ... 8879888798 - "C:\Program Files\Mozilla Firefox\Firefox.exe"
Repaired : [HKLM\Software\Clients\StartMenuInternet\IExplore.exe\shell\open\command] : C:\Program Files\Internet Explorer\iexplore.exe
http://do-search.com/?type=scts=1384815 ... 8879888798 - "C:\Program Files\Internet Explorer\iexplore.exe"
¤¤¤¤¤¤¤¤¤¤ | TEMP Files
[All Users] TEMP Files deleted : 0 Ko
[Default User] TEMP Files deleted : 0 Ko
[Public] TEMP Files deleted : 0 Ko
[Default] TEMP Files deleted : 0 Ko
[Utilisateur] TEMP Files deleted : 355636 Ko
¤¤¤¤¤¤¤¤¤¤ |EOF| ¤¤¤¤¤¤¤¤¤¤