¤¤¤¤¤¤¤¤ | Shortcut_Module 13.11.2013.2 - g3n-h@ckm@n
18:40:35 - 01/12/2013
(1572) -- spoolsv.exe
(1600) -- taskhost.exe
(1920) -- PhotoshopElementsFileAgent.exe
(1940) -- taskeng.exe
(1220) -- RAVCpl64.exe
(1380) -- igfxtray.exe
(1496) -- igfxsrvc.exe
(1444) -- hkcmd.exe
(1432) -- igfxpers.exe
(1260) -- SynTPEnh.exe
(1808) -- PLFSetI.exe
(2060) -- ePowerTray.exe
(2068) -- OrangeInside.exe
(2536) -- armsvc.exe
(2588) -- AppleMobileDeviceService.exe
(2720) -- ScanToPCActivationApp.exe
(2848) -- mDNSResponder.exe
(2896) -- SSScheduler.exe
(2904) -- rundll32.exe
(2916) -- notepad.exe
(2932) -- IAStorIcon.exe
(3024) -- dsiwmis.exe
(3052) -- LManager.exe
(3068) -- ePowerSvc.exe
(2300) -- BackupManagerTray.exe
(2308) -- GREGsvc.exe
(2384) -- VideoWebCamera.exe
(2556) -- iTunesHelper.exe
(2544) -- hpwuschd2.exe
(2572) -- IScheduleSvc.exe
(1936) -- MMDx64Fx.exe
(2756) -- realsched.exe
(3064) -- HPNetworkCommunicatorCom.exe
(2472) -- LMworker.exe
(3164) -- rndlresolversvc.exe
(3460) -- sftvsa.exe
(3616) -- UpdaterService.exe
(3652) -- WLIDSVC.EXE
(3696) -- sftlist.exe
(3744) -- WLIDSVCM.EXE
(3340) -- igfxext.exe
(4132) -- ePowerEvent.exe
(4424) -- CVHSVC.EXE
(4612) -- iPodService.exe
(4672) -- SearchIndexer.exe
(5076) -- SynTPHelper.exe
(4572) -- iexplore.exe
(1244) -- iexplore.exe
(2868) -- GoogleToolbarUser_32.exe
(2860) -- FlashUtil64_11_9_900_117_ActiveX.exe
(4856) -- IAStorDataMgrSvc.exe
(1500) -- MsSpellCheckingFacility.exe
(5660) -- explorer.exe
(3516) -- notepad.exe
(1028) -- iexplore.exe
(6116) -- SearchProtocolHost.exe
(4560) -- SearchFilterHost.exe
(4308) -- HPNetworkCommunicator.exe
¤¤¤¤¤¤¤¤¤¤ | Hijack Links
Disinfected : C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Packard Bell - Security Support\Contact.lnk : C:\Program Files\Internet Explorer\iexplore.exe (hxxp://do-search.com/?type=scts=1385638204from=airuid=WDCXWD5000BEVT-22A0RT0_WD-WXG1A50X3749X3749)
Disinfected : C:\Users\assunta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk : C:\Program Files (x86)\Internet Explorer\iexplore.exe (hxxp://do-search.com/?type=scts=1385638204from=airuid=WDCXWD5000BEVT-22A0RT0_WD-WXG1A50X3749X3749)
Disinfected : C:\Users\assunta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk : C:\Program Files\Internet Explorer\iexplore.exe (hxxp://do-search.com/?type=scts=1385638204from=airuid=WDCXWD5000BEVT-22A0RT0_WD-WXG1A50X3749X3749)
Disinfected : C:\Users\assunta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk : C:\Program Files\Internet Explorer\iexplore.exe (hxxp://do-search.com/?type=scts=1385638204from=airuid=WDCXWD5000BEVT-22A0RT0_WD-WXG1A50X3749X3749)
Disinfected : C:\Users\assunta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk : C:\Program Files\Internet Explorer\iexplore.exe (hxxp://do-search.com/?type=scts=1385638204from=airuid=WDCXWD5000BEVT-22A0RT0_WD-WXG1A50X3749X3749)
Disinfected : C:\Users\assunta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk : C:\Program Files\Internet Explorer\iexplore.exe (hxxp://do-search.com/?type=scts=1385638204from=airuid=WDCXWD5000BEVT-22A0RT0_WD-WXG1A50X3749X3749)
¤¤¤¤¤¤¤¤¤¤ | Hijack Internet Explorer
Repaired : [HKU\S-1-5-21-3833480701-174650934-3195008170-1000\Software\Microsoft\Internet Explorer\Main]|[Start Page] :
http://r.orange.fr/r/Ohome_portail?ref= ... ultPage_IE -
http://www.google.com/
Repaired : [HKU\S-1-5-21-3833480701-174650934-3195008170-1000\Software\Microsoft\Internet Explorer\Main]|[Local Page] : C:\Windows\system32\blank.htm - C:\Windows\SysWOW64\blank.htm
Repaired : [HKU\S-1-5-21-3833480701-174650934-3195008170-1000\Software\Microsoft\Internet Explorer\Main]|[Search Page] :
http://go.microsoft.com/fwlink/?LinkId=54896 -
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Start Page] :
http://do-search.com/?type=hpts=1385638 ... X3749X3749 -
http://go.microsoft.com/fwlink/?LinkId=69157
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Default_Search_URL] :
http://do-search.com/web/?type=dsts=138 ... earchTerms} -
http://go.microsoft.com/fwlink/?LinkId=54896
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Default_Page_URL] :
http://do-search.com/?type=hpts=1385638 ... X3749X3749 -
http://go.microsoft.com/fwlink/?LinkId=69157
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Search Page] :
http://do-search.com/web/?type=dsts=138 ... earchTerms} -
http://go.microsoft.com/fwlink/?LinkId=54896
Repaired : [HKU\S-1-5-21-3833480701-174650934-3195008170-1000\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[WarnonZoneCrossing] : 0 - 1
¤¤¤¤¤¤¤¤¤¤ | Hijack Google Chrome
[assunta] Successfull reset : SearchURL
[assunta] Successfull reset : Preferences
¤¤¤¤¤¤¤¤¤¤ | Hijack Firefox
¤¤¤¤¤¤¤¤¤¤ | Hijack StartMenuInternet
Repaired : [HKLM\Software\Clients\StartMenuInternet\IExplore.exe\shell\open\command] : "c:\program files\internet explorer\iexplore.exe" - "C:\Program Files (x86)\Internet Explorer\iexplore.exe"
¤¤¤¤¤¤¤¤¤¤ | TEMP Files
[All Users] TEMP Files deleted : 0 Ko
[Default User] TEMP Files deleted : 0 Ko
[Default] TEMP Files deleted : 0 Ko
[Public] TEMP Files deleted : 0 Ko
[assunta] TEMP Files deleted : 1237 Ko
[Hudson] TEMP Files deleted : 0 Ko
¤¤¤¤¤¤¤¤¤¤ |EOF| ¤¤¤¤¤¤¤¤¤¤