Voila le raport de short cut:
¤¤¤¤¤¤¤¤¤¤ | Shortcut_Module 26.01.2014.1 - g3n-h@ckm@n
20:36:52 - 26/01/2014
(1076) -- mfevtps.exe
(1144) -- mfefire.exe
(1192) -- McSvHost.exe
(1704) -- ctfmon.exe
(2752) -- McUICnt.exe
(1288) -- explorer.exe
(2332) -- chrome.exe
¤¤¤¤¤¤¤¤¤¤ | Hijack Links
Disinfected : C:\Users\Nicolas\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk : C:\Program Files\Internet Explorer\iexplore.exe (hxxp://
www.awesomehp.com/?type=scts=1390726479 ... XXZ1E5LAS6)
Disinfected : C:\Users\Nicolas\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk : C:\Program Files\Internet Explorer\iexplore.exe (hxxp://
www.awesomehp.com/?type=scts=1390726479 ... XXZ1E5LAS6)
Disinfected : C:\Users\Nicolas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk : C:\Program Files\Internet Explorer\iexplore.exe (hxxp://
www.awesomehp.com/?type=scts=1390726479 ... XXZ1E5LAS6)
¤¤¤¤¤¤¤¤¤¤ | Hijack Internet Explorer
Repaired : [HKU\S-1-5-21-592816680-2052944068-3555316804-1001\Software\Microsoft\Internet Explorer\Main]|[Search Bar] : Preserve -
http://www.google.com/
Repaired : [HKU\S-1-5-21-592816680-2052944068-3555316804-1001\Software\Microsoft\Internet Explorer\Main]|[Start Page] :
http://asus13.msn.com/?pc=ASJB -
http://www.google.com/
Repaired : [HKU\S-1-5-21-592816680-2052944068-3555316804-1001\Software\Microsoft\Internet Explorer\Main]|[Local Page] : C:\Windows\system32\blank.htm - C:\Windows\SysWOW64\blank.htm
Repaired : [HKU\S-1-5-21-592816680-2052944068-3555316804-1001\Software\Microsoft\Internet Explorer\Main]|[Search Page] :
http://www.bing.com/search?q={searchTerms} -
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Start Page] :
http://www.awesomehp.com/?type=hpts=139 ... XXZ1E5LAS6 -
http://go.microsoft.com/fwlink/?LinkId=69157
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Default_Search_URL] :
http://www.awesomehp.com/web/?type=dsts ... earchTerms} -
http://go.microsoft.com/fwlink/?LinkId=54896
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Default_Page_URL] :
http://www.awesomehp.com/?type=hpts=139 ... XXZ1E5LAS6 -
http://go.microsoft.com/fwlink/?LinkId=69157
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Search Page] :
http://www.awesomehp.com/web/?type=dsts ... earchTerms} -
http://go.microsoft.com/fwlink/?LinkId=54896
Repaired : [HKLM64\Software\Microsoft\Internet Explorer\Main]|[Start Page] :
http://www.awesomehp.com/?type=hpts=139 ... XXZ1E5LAS6 -
http://go.microsoft.com/fwlink/?LinkId=69157
Repaired : [HKLM64\Software\Microsoft\Internet Explorer\Main]|[Local Page] : C:\Windows\System32\blank.htm - C:\Windows\SysWOW64\blank.htm
Repaired : [HKLM64\Software\Microsoft\Internet Explorer\Main]|[Default_Search_URL] :
http://www.awesomehp.com/web/?type=dsts ... earchTerms} -
http://go.microsoft.com/fwlink/?LinkId=54896
Repaired : [HKLM64\Software\Microsoft\Internet Explorer\Main]|[Default_Page_URL] :
http://www.awesomehp.com/?type=hpts=139 ... XXZ1E5LAS6 -
http://go.microsoft.com/fwlink/?LinkId=69157
Repaired : [HKLM64\Software\Microsoft\Internet Explorer\Main]|[Search Page] :
http://www.awesomehp.com/web/?type=dsts ... earchTerms} -
http://go.microsoft.com/fwlink/?LinkId=54896
Repaired : [HKU\S-1-5-21-592816680-2052944068-3555316804-1001\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[ProxyOverride] : - *.local
Repaired : [HKU\S-1-5-21-592816680-2052944068-3555316804-1001\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[WarnonZoneCrossing] : 0 - 1
¤¤¤¤¤¤¤¤¤¤ | Hijack Google Chrome
[Nicolas] Reset Impossible : SearchURL !
[Nicolas] Successfull reset : Preferences
¤¤¤¤¤¤¤¤¤¤ | Hijack Firefox
¤¤¤¤¤¤¤¤¤¤ | Hijack StartMenuInternet
Repaired : [HKLM\Software\Clients\StartMenuInternet\IExplore.exe\shell\open\command] : C:\Program Files\Internet Explorer\iexplore.exe
http://www.awesomehp.com/?type=scts=139 ... XXZ1E5LAS6 - "C:\Program Files (x86)\Internet Explorer\iexplore.exe"
¤¤¤¤¤¤¤¤¤¤ | Hijack Jscript
Hijack Jscript Repaired !!! : HKCR\CLSID\{f414c262-6ac0-11cf-b6d1-00aa00bbbb58}\InProcServer32 : C:\Program Files\AVAST Software\Avast\AhAScr.dll - C:\Windows\SysWow64\Jscript.dll
¤¤¤¤¤¤¤¤¤¤ | TEMP Files
[All Users] TEMP Files deleted : 0 Ko
[Default User] TEMP Files deleted : 0 Ko
[Nicolas] TEMP Files deleted : 350 Ko
[Default] TEMP Files deleted : 0 Ko
[Public] TEMP Files deleted : 0 Ko
[UpdatusUser] TEMP Files deleted : 0 Ko
¤¤¤¤¤¤¤¤¤¤ |EOF| ¤¤¤¤¤¤¤¤¤¤