Security-X

Forum Security-X => Désinfections => Discussion démarrée par: c3g le janvier 08, 2014, 12:12:49

Titre: Infection Nationzoom [Résolu]
Posté par: c3g le janvier 08, 2014, 12:12:49
Bonjour

Mon fils n'a pas surveillé une mise à jour qui semble fausse et résultat : pc infecté par un spyware/malware appelé "Nationzoom"
Merci d'avance de votre aide pour nettoyage complet

Config : Asus R700V - I5 3210 - W7 64
Titre: Re : Infection Nationzoom
Posté par: itsinthehead le janvier 08, 2014, 13:51:01
salut c3g :)

Je vais te prendre en charge pour ce sujet :)




FRST - version 64 bits :

Titre: Re : Infection Nationzoom
Posté par: c3g le janvier 08, 2014, 14:13:17
Bonjour à toi et merci pour ton aide par avance.

http://up.security-x.fr/file.php?h=R39b6d9a48b18d5a566b30217c95dacf4

http://up.security-x.fr/file.php?h=R78c7c359968aafd1e0a90911f4e0926e

A plus
Titre: Re : Infection Nationzoom
Posté par: itsinthehead le janvier 08, 2014, 16:50:13
 :AAC




(si un de ces programme ne peut être désinstallé passe au suivant et signale-le dans ton prochain message)






FRST - Correctif :

/!\ Crée un point de restauration manuel avant d'appliquer le correctif - Tutoriel en images (http://forum.security-x.fr/windows-7/%28tutoriel%29-creer-un-point-de-restauration-sous-windows-7/) /!\

start
(Cherished Technololgy LIMITED) C:\ProgramData\WPM\wprotectmanager.exe
C:\ProgramData\WPM
() C:\Users\Florent\AppData\Local\fst_fr_35\upfst_fr_35.exe
C:\Users\Florent\AppData\Local\fst_fr_35
() C:\Program Files (x86)\fst_fr_35\fst_fr_35.exe
C:\Program Files (x86)\fst_fr_35
() C:\Program Files (x86)\fst_fr_35\fst_fr_35.exe
HKLM-x32\...\Run: [fst_fr_35] - C:\Program Files (x86)\fst_fr_35\fst_fr_35.exe [3992488 2013-12-19] ()
HKLM-x32\...\RunOnce: [upfst_fr_35.exe] - C:\Users\Florent\AppData\Local\fst_fr_35\upfst_fr_35.exe -runonce [3154344 2013-12-18] ()
Startup: C:\Users\Florent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.nationzoom.com/?type=sc&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
BHO: Feven 1.7 - {11111111-1111-1111-1111-110411051194} - C:\Program Files (x86)\Feven 1.7\Feven 1.7-bho64.dll (Feven)
C:\Program Files (x86)\Feven 1.7
BHO-x32: Feven 1.7 - {11111111-1111-1111-1111-110411051194} - C:\Program Files (x86)\Feven 1.7\Feven 1.7-bho.dll (Feven)
FF NewTab: hxxp://www.nationzoom.com/newtab/?type=nt&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
FF DefaultSearchEngine: nationzoom
FF SelectedSearchEngine: nationzoom
FF Homepage: hxxp://www.nationzoom.com/?type=hp&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\nationzoom.xml
C:\Program Files (x86)\mozilla firefox\browser\searchplugins\nationzoom.xml
M101MBB_S2TTJ9HC500924&q={searchTerms}
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [38440 2013-09-19] (Just Develop It)
C:\Program Files (x86)\MyPC Backup
R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [499856 2013-12-21] (Cherished Technololgy LIMITED)
C:\ProgramData\WPM
Task: {0189868C-AE05-4D1F-9521-6DF03651EC67} - System32\Tasks\Feven 1.7-updater => C:\Program Files (x86)\Feven 1.7\Feven 1.7-updater.exe [2013-12-21] (Feven) <==== ATTENTION
Task: {19EDA4B9-930B-4E2D-9D45-04944994624A} - System32\Tasks\Feven 1.7-enabler => C:\Program Files (x86)\Feven 1.7\Feven 1.7-enabler.exe [2013-12-21] (Feven) <==== ATTENTION
Task: {1BBCD050-2121-4CF5-A8BF-47D9193F08FF} - System32\Tasks\Feven 1.7-codedownloader => C:\Program Files (x86)\Feven 1.7\Feven 1.7-codedownloader.exe [2013-12-21] (Feven) <==== ATTENTION
Task: {48E334F0-0348-4A1A-8FC3-B70A2182A25A} - System32\Tasks\Feven 1.7-chromeinstaller => C:\Program Files (x86)\Feven 1.7\Feven 1.7-chromeinstaller.exe [2013-12-21] (Feven) <==== ATTENTION
Task: {96806986-6643-4114-8759-87F1C2C0C7DD} - System32\Tasks\Feven 1.7-firefoxinstaller => C:\Program Files (x86)\Feven 1.7\Feven 1.7-firefoxinstaller.exe [2013-12-21] (Feven) <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.7-chromeinstaller.job => C:\Program Files (x86)\Feven 1.7\Feven 1.7-chromeinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.7-codedownloader.job => C:\Program Files (x86)\Feven 1.7\Feven 1.7-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.7-enabler.job => C:\Program Files (x86)\Feven 1.7\Feven 1.7-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.7-firefoxinstaller.job => C:\Program Files (x86)\Feven 1.7\Feven 1.7-firefoxinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.7-updater.job => C:\Program Files (x86)\Feven 1.7\Feven 1.7-updater.exe <==== ATTENTION
2013-12-21 00:46 - 2014-01-08 14:01 - 00002022 _____ C:\Windows\Tasks\Feven 1.7-firefoxinstaller.job
2013-12-21 00:46 - 2014-01-08 13:56 - 00001338 _____ C:\Windows\Tasks\Feven 1.7-updater.job
2013-12-21 00:46 - 2014-01-08 13:56 - 00001240 _____ C:\Windows\Tasks\Feven 1.7-codedownloader.job
2013-12-21 00:46 - 2014-01-08 13:56 - 00001140 _____ C:\Windows\Tasks\Feven 1.7-enabler.job
2013-12-21 00:46 - 2013-12-21 00:46 - 00004368 _____ C:\Windows\System32\Tasks\Feven 1.7-updater
2013-12-21 00:46 - 2013-12-21 00:46 - 00004270 _____ C:\Windows\System32\Tasks\Feven 1.7-codedownloader
2013-12-21 00:46 - 2013-12-21 00:46 - 00004170 _____ C:\Windows\System32\Tasks\Feven 1.7-enabler
2013-12-21 00:45 - 2014-01-08 13:56 - 00001980 _____ C:\Windows\Tasks\Feven 1.7-chromeinstaller.job 
2013-12-21 00:45 - 2013-12-21 00:45 - 00001089 _____ C:\Users\Florent\Desktop\MyPC Backup.lnk
2013-12-21 00:45 - 2013-12-21 00:45 - 00000000 ____D C:\Users\Florent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup 
2014-01-08 13:56 - 2013-12-21 00:45 - 00001980 _____ C:\Windows\Tasks\Feven 1.7-chromeinstaller.job   
2013-12-21 00:45 - 2013-12-21 00:45 - 00001089 _____ C:\Users\Florent\Desktop\MyPC Backup.lnk
C:\Users\Florent\AppData\Local\Temp\BackupSetup.exe
end
/!\ Ce script a été établi pour cet utilisateur, il ne doit, en aucun cas, être appliqué sur un autre système, au risque de provoquer de graves dysfonctionnement et endommager Windows /!\




AdwCleaner - Recherche :



**Reposte moi le rapport Addition.txt du scan que tu as fait avec FRST, le rapport n'était pas complet**


Titre: Re : Infection Nationzoom
Posté par: c3g le janvier 08, 2014, 17:41:17
Re-

4 programmes supprimés
Impossible accéder Windows Live Messenger pour suppression

Fichier fixlog.txt contient seulement la mention : "end of fixlog"

Rapport AdwCleaner

# AdwCleaner v3.016 - Rapport créé le 08/01/2014 à 17:31:20
# Mis à jour le 23/12/2013 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : Florent - FLORENT-PC
# Exécuté depuis : C:\Users\Florent\Desktop\AdwCleaner.exe
# Option : Scanner

***** [ Services ] *****

Service Présent : PirritUpdater
Service Présent : Update Cling Clang

***** [ Fichiers / Dossiers ] *****

Dossier Présent : C:\Users\Florent\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml
Dossier Présent : C:\Users\Florent\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo
Dossier Présent C:\Program Files (x86)\Bench
Dossier Présent C:\Program Files (x86)\NCH Software
Dossier Présent C:\Program Files (x86)\Pirrit
Dossier Présent C:\Program Files (x86)\Uniblue\SpeedUpMyPC
Dossier Présent C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue\SpeedUpMyPC
Dossier Présent C:\ProgramData\NCH Software
Dossier Présent C:\Users\Florent\AppData\Local\Pirrit Suggestor
Dossier Présent C:\Users\Florent\AppData\Roaming\NCH Software
Dossier Présent C:\Users\Florent\AppData\Roaming\Pirrit
Dossier Présent C:\Users\Florent\AppData\Roaming\Uniblue\SpeedUpMyPC
Fichier Présent : C:\Users\Florent\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx
Fichier Présent : C:\Users\Florent\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ifohbjbgfchkkfhphahclmkpgejiplfo_0.localstorage
Fichier Présent : C:\Users\Florent\AppData\Roaming\Mozilla\Firefox\Profiles\3i68bmie.default\Extensions\suggestor@suggestor.pirrit.com.xpi
Fichier Présent : C:\Users\Public\Desktop\speedupmypc.lnk
Fichier Présent : C:\Windows\System32\Tasks\NCH Software

***** [ Raccourcis ] *****

Raccourci Présent : C:\Users\Public\Desktop\Google Chrome.lnk ( hxxp://www.nationzoom.com/?type=sc&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924 )
Raccourci Présent : C:\Users\Public\Desktop\Mozilla Firefox.lnk ( hxxp://www.nationzoom.com/?type=sc&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924 )
Raccourci Présent : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk ( hxxp://www.nationzoom.com/?type=sc&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924 )
Raccourci Présent : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk ( hxxp://www.nationzoom.com/?type=sc&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924 )
Raccourci Présent : C:\Users\Florent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk ( hxxp://www.nationzoom.com/?type=sc&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924 )
Raccourci Présent : C:\Users\Florent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk ( hxxp://www.nationzoom.com/?type=sc&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924 )
Raccourci Présent : C:\Users\Florent\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk ( hxxp://www.nationzoom.com/?type=sc&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924 )
Raccourci Présent : C:\Users\Florent\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ( hxxp://www.nationzoom.com/?type=sc&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924 )
Raccourci Présent : C:\Users\Florent\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk ( hxxp://www.nationzoom.com/?type=sc&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924 )
Raccourci Présent : C:\Users\Florent\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk ( hxxp://www.nationzoom.com/?type=sc&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924 )

***** [ Registre ] *****

Clé Présente : HKCU\Software\AppDataLow\Software\Crossrider
Clé Présente : HKCU\Software\Conduit
Clé Présente : HKCU\Software\FreeSoftToday
Clé Présente : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
Clé Présente : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
Clé Présente : HKCU\Software\NCH Software
Clé Présente : HKCU\Software\TutoTag
Clé Présente : [x64] HKCU\Software\Conduit
Clé Présente : [x64] HKCU\Software\FreeSoftToday
Clé Présente : [x64] HKCU\Software\NCH Software
Clé Présente : [x64] HKCU\Software\TutoTag
Clé Présente : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Clé Présente : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Clé Présente : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Clé Présente : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Clé Présente : HKLM\SOFTWARE\Classes\CLSID\{AA9AA36B-5B7B-4996-B083-83EF84D53B19}
Clé Présente : HKLM\SOFTWARE\Classes\CLSID\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
Clé Présente : HKLM\SOFTWARE\Classes\speedupmypc
Clé Présente : HKLM\Software\Conduit
Clé Présente : HKLM\Software\FreeSoftToday
Clé Présente : HKLM\SOFTWARE\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo
Clé Présente : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Clé Présente : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Clé Présente : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32
Clé Présente : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS
Clé Présente : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Clé Présente : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Clé Présente : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Clé Présente : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Clé Présente : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Clé Présente : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA9AA36B-5B7B-4996-B083-83EF84D53B19}
Clé Présente : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D40C654D-7C51-4EB3-95B2-1E23905C2A2D}
Clé Présente : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1
Clé Présente : HKLM\Software\nationzoomSoftware
Clé Présente : HKLM\Software\NCH Software
Clé Présente : HKLM\Software\Pirrit
Clé Présente : HKLM\Software\supWPM
Clé Présente : HKLM\Software\Tutorials
Clé Présente : HKLM\Software\Uniblue
Clé Présente : HKLM\Software\Uniblue\SpeedUpMyPC
Clé Présente : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Clé Présente : [x64] HKLM\SOFTWARE\DomaIQ

***** [ Navigateurs ] *****

-\\ Internet Explorer v11.0.9600.16428


-\\ Mozilla Firefox v26.0 (fr)

[ Fichier : C:\Users\Florent\AppData\Roaming\Mozilla\Firefox\Profiles\3i68bmie.default\prefs.js ]

Ligne Trouvée : user_pref("extensions.crossrider.bic", "14312678cc9c98fa8509e98678ac7d4b");

-\\ Google Chrome v32.0.1700.41

[ Fichier : C:\Users\Florent\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Trouvée : search_url
Trouvée : keyword

*************************

AdwCleaner[R0].txt - [7334 octets] - [08/01/2014 17:31:20]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [7394 octets] ##########

Rapport addition.txt

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-01-2014
Ran by Florent at 2014-01-08 14:06:42
Running from C:\Users\Florent\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: avast! Antivirus (Disabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AS: avast! Antivirus (Disabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.05) - Français (x32 Version: 11.0.05 - Adobe Systems Incorporated)
Apple Application Support (x32 Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (x32 Version: 2.1.3.127 - Apple Inc.)
ASUS AI Recovery (x32 Version: 1.0.24 - ASUS)
ASUS FaceLogon (x32 Version: 1.0.0014 - ASUS)
ASUS K45_K75_K95_Screensaver (x32 Version: 1.0.0001 - ASUS)
ASUS LifeFrame3 (x32 Version: 3.1.1 - ASUS)
ASUS Live Update (x32 Version: 3.1.7 - ASUS)
ASUS Power4Gear Hybrid (Version: 1.2.1 - ASUS)
ASUS Splendid Video Enhancement Technology (x32 Version: 1.02.0041 - ASUS)
ASUS USB Charger Plus (x32 Version: 2.0.9 - ASUS)
ASUS Virtual Camera (x32 Version: 1.0.25 - ASUS)
ASUS Virtual Touch (x32 Version: 1.0.11 - ASUS)
ASUS WebStorage (x32 Version: 3.0.108.222 - eCareme Technologies, Inc.)
ASUSDVD (x32 Version: 10.0.3622.52 - CyberLink Corp.)
ASUSDVD (x32 Version: 10.0.3622.52 - CyberLink Corp.) Hidden
AsusVibe2.0 (x32 Version: 2.0.9.157 - ASUSTEK)
ATK Package (x32 Version: 1.0.0016 - ASUS)
AutoCAD 2012 - French (Version: 18.2.51.0 - Autodesk)
AutoCAD 2012 - French (Version: 18.2.51.0 - Autodesk) Hidden
AutoCAD 2012 Language Pack - French (Version: 18.2.51.0 - Autodesk) Hidden
Autodesk Content Service (x32 Version: 2.0.90 - Autodesk)
Autodesk Material Library 2012 (x32 Version: 2.5.0.8 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2012 (x32 Version: 2.5.0.8 - Autodesk)
avast! Free Antivirus (x32 Version: 9.0.2011 - Avast Software)
Bing Bar (x32 Version: 7.2.241.0 - Microsoft Corporation)
Bonjour (Version: 3.0.0.10 - Apple Inc.)
Bubbletown (x32 Version:  - Oberon Media)
Control ActiveX de Windows Live Mesh para conexiones remotas (x32 Version: 15.4.5722.2 - Microsoft Corporation)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (x32 Version: 15.4.5722.2 - Microsoft Corporation)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (x32 Version: 15.4.5722.2 - Microsoft Corporation)
CyberLink LabelPrint (x32 Version: 2.5.3624 - CyberLink Corp.)
CyberLink LabelPrint (x32 Version: 2.5.3624 - CyberLink Corp.) Hidden
CyberLink Media Suite (x32 Version: 8.0.2926 - CyberLink Corp.)
CyberLink Media Suite (x32 Version: 8.0.2926 - CyberLink Corp.) Hidden
CyberLink Power2Go (x32 Version: 7.0.0.1126 - CyberLink Corp.)
CyberLink Power2Go (x32 Version: 7.0.0.1126 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (x32 Version: 4.46.1.0327 - DT Soft Ltd)
Deadtime Stories (x32 Version:  - Oberon Media)
Dream Day First Home (x32 Version:  - Oberon Media)
Dream Vacation Solitaire (x32 Version:  - Oberon Media)
ETDWare PS/2-X64 10.5.9.0 (Version: 10.5.9.0 - ELAN Microelectronic Corp.)
Facebook Video Calling 1.2.0.287 (x32 Version: 1.2.287 - Skype Limited)
Farm Frenzy 3 - Madagascar (x32 Version:  - Oberon Media)
FARO LS 1.1.406.58 (x32 Version: 4.6.58.2 - FARO Scanner Production)
Fast Boot (Version: 1.0.10 - ASUS)
Feven 1.7 (x32 Version: 1.32.153.0 - Feven) <==== ATTENTION
fst_fr_35 (x32 Version:  - FREESOFTTODAY) <==== ATTENTION
Galapago (x32 Version:  - Oberon Media)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Game Park Console (x32 Version: 1.2.4.431 - Oberon Media Inc.)
Go Go Gourmet Chef of the Year (x32 Version:  - Oberon Media)
Google Chrome (x32 Version: 32.0.1700.41 - Google Inc.)
Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden
InstantOn for NB (x32 Version: 2.3.1 - ASUS)
Intel PROSet Wireless (Version:  - ) Hidden
Intel(R) Manageability Engine Firmware Recovery Agent (x32 Version: 1.0.0.35342 - Intel Corporation)
Intel(R) Management Engine Components (x32 Version: 8.0.3.1427 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (x32 Version:  - Intel Corporation)
Intel(R) Processor Graphics (x32 Version: 8.15.10.2669 - Intel Corporation)
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (Version: 15.0.0.0083 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 2.1.0.0140 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.4.220 - Intel Corporation)
Intel(R) WiDi (x32 Version: 3.0.13.0 - Intel Corporation)
Intel(R) Wireless Display (Version:  - )
Intel® PROSet/Wireless WiFi Software (Version: 15.00.0000.0708 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.23.605.1 - Intel Corporation)
iTunes (Version: 11.1.0.126 - Apple Inc.)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Logitole V5 (x32 Version: 5.15.00 - DEMLOG PROfirst Group)
Logitrace V12 (x32 Version: 12.0.13 - Demlog  PROfirst Group)
Mahjong Memoirs (x32 Version:  - Oberon Media)
Malwarebytes Anti-Malware version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile FRA Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended FRA Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Access MUI (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Arabic) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Dutch) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (French) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Mise à jour Microsoft Office Excel 2007 Help  (KB963678) (x32 Version:  - Microsoft)
Mise à jour Microsoft Office Outlook 2007 Help  (KB963677) (x32 Version:  - Microsoft)
Mise à jour Microsoft Office Powerpoint 2007 Help  (KB963669) (x32 Version:  - Microsoft)
Mise à jour Microsoft Office Word 2007 Help  (KB963665) (x32 Version:  - Microsoft)
Module linguistique Microsoft .NET Framework 4 Client Profile FRA (Version: 4.0.30319 - Microsoft Corporation)
Module linguistique Microsoft .NET Framework 4 Extended FRA (Version: 4.0.30319 - Microsoft Corporation)
Mozilla Firefox 26.0 (x86 fr) (x32 Version: 26.0 - Mozilla)
Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla)
Mozilla Thunderbird 24.2.0 (x86 fr) (x32 Version: 24.2.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MyPC Backup  (Version:  - MyPC Backup) <==== ATTENTION
Nexon Game Manager (x32 Version:  - )
NVIDIA Control Panel 290.81 (Version: 290.81 - NVIDIA Corporation) Hidden
NVIDIA Graphics Driver 290.81 (Version: 290.81 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.48.259 - NVIDIA Corporation) Hidden
NVIDIA Optimus 1.6.24 (Version: 1.6.24 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.11.1111 - NVIDIA Corporation)
NVIDIA Update 1.6.24 (Version: 1.6.24 - NVIDIA Corporation)
NVIDIA Update Components (Version: 1.6.24 - NVIDIA Corporation) Hidden
PhotoFiltre 7 (HKCU Version:  - )
Plants vs Zombies (x32 Version:  - Oberon Media)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (x32 Version: 7.49.927.2011 - Realtek)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6537 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.7601.30130 - Realtek Semiconductor Corp.)
SceneSwitch (x32 Version: 1.0.12 - ASUS)
Skype™ 6.3 (x32 Version: 6.3.107 - Skype Technologies S.A.)
SpeedUpMyPC (x32 Version: 6.0.0.0 - Uniblue Systems Limited)
Switch Sound File Converter (x32 Version:  - NCH Software)
Turbo Fiesta (x32 Version:  - Oberon Media)
Update for 2007 Microsoft Office System (KB967642) (x32 Version:  - Microsoft)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition (x32 Version:  - Microsoft)
VirtualDJ PRO Full (x32 Version: 7.3 - Atomix Productions)
WarRock (x32 Version:  - )
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Family Safety (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (x32 Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
WinFlash (x32 Version: 2.41.0 - ASUS)
WinRAR 4.20 (64-bit) (Version: 4.20.0 - win.rar GmbH)
Wireless Console 3 (x32 Version: 3.0.27 - ASUS)
World of Goo (x32 Version:  - Oberon Media)
World of Tanks (x32 Version:  - Wargaming.net)
WPM17.8.0.3159 (x32 Version: 17.8.0.3159 - Cherished Technololgy LIMITED) <==== ATTENTION
Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (x32 Version: 15.4.5722.2 - Microsoft Corporation)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Элемент управления Windows Live Mesh ActiveX для удаленных подключений (x32 Version: 15.4.5722.2 - Microsoft Corporation)
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (x32 Version: 15.4.5722.2 - Microsoft Corporation)
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (x32 Version: 15.4.5722.2 - Microsoft Corporation)
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
適用遠端連線的 Windows Live Mesh ActiveX 控制項 (x32 Version: 15.4.5722.2 - Microsoft Corporation)

==================== Restore Points  =========================

12-12-2013 09:50:32 Windows Update
17-12-2013 18:34:15 Windows Update
20-12-2013 21:47:58 Windows Update
20-12-2013 23:45:40 Uniblue SpeedUpMyPC installation
24-12-2013 23:15:58 Windows Update
28-12-2013 00:38:46 Windows Update
31-12-2013 22:47:52 Windows Update
08-01-2014 08:13:23 Windows Update
08-01-2014 12:58:58 avast! antivirus system restore point

==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {0189868C-AE05-4D1F-9521-6DF03651EC67} - System32\Tasks\Feven 1.7-updater => C:\Program Files (x86)\Feven 1.7\Feven 1.7-updater.exe [2013-12-21] (Feven) <==== ATTENTION
Task: {0556BB97-06C5-4ACC-A60D-0FF832E97355} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {0CC8D11D-AAFF-44E9-AEB5-18713C214A91} - System32\Tasks\ASUS Quick Gesture (x64) => C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe [2012-04-11] (ASUSTeK Computer Inc.)
Task: {11E55748-3893-4CC5-819C-2617F4D1BC75} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-02-16] (ASUSTek Computer Inc.)
Task: {19EDA4B9-930B-4E2D-9D45-04944994624A} - System32\Tasks\Feven 1.7-enabler => C:\Program Files (x86)\Feven 1.7\Feven 1.7-enabler.exe [2013-12-21] (Feven) <==== ATTENTION
Task: {1BBCD050-2121-4CF5-A8BF-47D9193F08FF} - System32\Tasks\Feven 1.7-codedownloader => C:\Program Files (x86)\Feven 1.7\Feven 1.7-codedownloader.exe [2013-12-21] (Feven) <==== ATTENTION
Task: {20E0D677-F256-4582-95CD-1F4F40663AEB} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
Task: {28810C30-2BCC-4037-9212-AFD57F0D475D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10] (Adobe Systems Incorporated)
Task: {344CD121-7B79-45D4-B2ED-7FF3B81EDF96} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe [2012-02-17] (ASUSTek Computer Inc.)
Task: {40E539F3-7DB5-44C6-B9FC-01EA0F8DF67D} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-02-16] (ASUS)
Task: {46060FE9-249A-48E2-AA96-D64D19217323} - System32\Tasks\ASUS Quick Gesture => C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe [2012-04-11] (ASUSTeK Computer Inc.)
Task: {48E334F0-0348-4A1A-8FC3-B70A2182A25A} - System32\Tasks\Feven 1.7-chromeinstaller => C:\Program Files (x86)\Feven 1.7\Feven 1.7-chromeinstaller.exe [2013-12-21] (Feven) <==== ATTENTION
Task: {552FAC02-A5BC-45C8-82AE-8AD5D4867511} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-01-08] (AVAST Software)
Task: {87B7B454-ECFC-451F-B4DA-81E6A9556C1B} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation)
Task: {8BC49669-EA4C-4BD5-9A17-C6E431C973E2} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-02-29] (ASUSTek Computer Inc.)
Task: {96806986-6643-4114-8759-87F1C2C0C7DD} - System32\Tasks\Feven 1.7-firefoxinstaller => C:\Program Files (x86)\Feven 1.7\Feven 1.7-firefoxinstaller.exe [2013-12-21] (Feven) <==== ATTENTION
Task: {9BC7762B-0EEA-46B5-9007-BDCF34A37EC6} - System32\Tasks\SpeedUpMyPC Startup => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe [2013-12-12] (Uniblue Systems Limited)
Task: {B4D1DB95-2B14-4514-874C-F39565F93267} - System32\Tasks\SpeedUpMyPC Maintenance => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe [2013-12-12] (Uniblue Systems Limited)
Task: {BD58853E-B4A0-4955-9735-CDB80607587B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-04] (Google Inc.)
Task: {C5A99C18-2A53-495A-88A3-67BA53873FE5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-04] (Google Inc.)
Task: {C6A507C3-9BEF-425B-B600-FCDB4DC04D02} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3453522075-146108178-2956732179-1001Core => C:\Users\Florent\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-07] (Facebook Inc.)
Task: {D25124C1-7E7D-441E-BBDF-5C1139667F55} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3453522075-146108178-2956732179-1001UA => C:\Users\Florent\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-07] (Facebook Inc.)
Task: {FF69F923-4338-4209-A1A9-99739673F53A} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3453522075-146108178-2956732179-1001Core.job => C:\Users\Florent\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3453522075-146108178-2956732179-1001UA.job => C:\Users\Florent\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\Feven 1.7-chromeinstaller.job => C:\Program Files (x86)\Feven 1.7\Feven 1.7-chromeinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.7-codedownloader.job => C:\Program Files (x86)\Feven 1.7\Feven 1.7-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.7-enabler.job => C:\Program Files (x86)\Feven 1.7\Feven 1.7-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.7-firefoxinstaller.job => C:\Program Files (x86)\Feven 1.7\Feven 1.7-firefoxinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.7-updater.job => C:\Program Files (x86)\Feven 1.7\Feven 1.7-updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\Windows\Tasks\SpeedUpMyPC Maintenance.job => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe
Task: C:\Windows\Tasks\SpeedUpMyPC Startup.job => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe

==================== Loaded Modules (whitelisted) =============

2010-07-15 00:11 - 2010-07-15 00:11 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
2013-09-19 23:37 - 2013-09-19 23:37 - 00012288 _____ () C:\Program Files (x86)\MyPC Backup\GetText.dll
2013-09-19 23:32 - 2013-09-19 23:32 - 01102336 _____ () C:\Program Files (x86)\MyPC Backup\x64\System.Data.SQLite.dll
2014-01-07 22:14 - 2014-01-07 20:01 - 02244608 _____ () C:\Program Files\AVAST Software\Avast\defs\14010701\algo.dll
2013-09-13 18:51 - 2013-09-13 18:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2013-09-13 18:51 - 2013-09-13 18:51 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2012-02-21 22:49 - 2012-02-21 22:49 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2010-08-20 17:57 - 2010-08-20 17:57 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2010-08-20 17:57 - 2010-08-20 17:57 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2012-01-31 17:25 - 2012-01-31 17:25 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
2012-06-21 10:47 - 2012-02-21 05:09 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2011-08-16 04:12 - 2011-08-16 04:12 - 02603520 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtCore4.dll
2011-08-16 04:15 - 2011-08-16 04:15 - 00382464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtXml4.dll
2011-08-18 00:41 - 2011-08-18 00:41 - 00400384 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\sqlite3.dll
2011-08-18 00:48 - 2011-08-18 00:48 - 00322048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\log4cplus.dll
2011-11-25 21:29 - 2011-11-25 21:29 - 00015872 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\featureController.dll
2011-08-16 04:12 - 2011-08-16 04:12 - 01006592 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtNetwork4.dll
2011-08-18 00:48 - 2011-08-18 00:48 - 00195584 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\libgsoap.dll
2011-08-16 03:23 - 2011-08-16 03:23 - 00062464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\zlib1.dll
2011-11-25 21:28 - 2011-11-25 21:28 - 00484352 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\DeviceProfile.dll
2011-11-25 21:42 - 2011-11-25 21:42 - 00499976 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\plugin\PServerPlugin.dll
2011-11-25 21:26 - 2011-11-25 21:26 - 00013824 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\eventsSender.dll
2011-07-20 00:05 - 2011-07-20 00:05 - 14978048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtWebKit4.dll
2011-07-20 00:04 - 2011-07-20 00:04 - 00317952 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\phonon4.dll
2011-08-16 04:17 - 2011-08-16 04:17 - 09224704 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtGui4.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/08/2014 00:14:03 PM) (Source: Application Error) (User: )
Description: Nom de l’application défaillante ETDCtrl.exe, version : 10.0.0.13, horodatage : 0x4f3b4b12
Nom du module défaillant : KERNELBASE.dll, version : 6.1.7601.18229, horodatage : 0x51fb1677
Code d’exception : 0xc00000fd
Décalage d’erreur : 0x0000000000012f5d
ID du processus défaillant : 0xea4
Heure de début de l’application défaillante : 0xETDCtrl.exe0
Chemin d’accès de l’application défaillante : ETDCtrl.exe1
Chemin d’accès du module défaillant: ETDCtrl.exe2
ID de rapport : ETDCtrl.exe3

Error: (01/08/2014 00:11:13 PM) (Source: Application Error) (User: )
Description: Nom de l’application défaillante Explorer.EXE, version : 6.1.7601.17567, horodatage : 0x4d672ee4
Nom du module défaillant : KERNELBASE.dll, version : 6.1.7601.18229, horodatage : 0x51fb1677
Code d’exception : 0xc00000fd
Décalage d’erreur : 0x0000000000012f5d
ID du processus défaillant : 0x%9
Heure de début de l’application défaillante : 0xExplorer.EXE0
Chemin d’accès de l’application défaillante : Explorer.EXE1
Chemin d’accès du module défaillant: Explorer.EXE2
ID de rapport : Explorer.EXE3

Error: (01/07/2014 10:13:37 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 29656383

Error: (01/07/2014 10:13:37 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 29656383

Error: (01/07/2014 10:13:37 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/07/2014 01:59:23 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2247

Error: (01/07/2014 01:59:23 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2247

Error: (01/07/2014 01:59:23 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/07/2014 01:59:22 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1186

Error: (01/07/2014 01:59:22 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1186


System errors:
=============
Error: (01/06/2014 10:41:26 PM) (Source: Service Control Manager) (User: )
Description: Le service PirritUpdater est marqué comme étant interactif. Cependant, le système est configuré pour ne pas autoriser les services interactifs. Ce service peut ne pas fonctionner correctement.

Error: (12/23/2013 02:38:05 AM) (Source: Service Control Manager) (User: )
Description: Le service Computer Backup (MyPC Backup) n’a pas pu démarrer en raison de l’erreur :
%%1053

Error: (12/23/2013 02:38:05 AM) (Source: Service Control Manager) (User: )
Description: Le dépassement de délai (30000 millisecondes) a été atteint lors de l’attente de la connexion du service Computer Backup (MyPC Backup).

Error: (12/04/2013 10:52:42 AM) (Source: Service Control Manager) (User: )
Description: Le service ASLDR Service s’est terminé de façon inattendue pour la 1ème fois.

Error: (12/04/2013 09:04:02 AM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (12/04/2013 00:18:38 AM) (Source: DCOM) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}

Error: (12/02/2013 09:04:50 PM) (Source: DCOM) (User: )
Description: {4EB61BAC-A3B6-4760-9581-655041EF4D69}

Error: (12/01/2013 06:05:33 PM) (Source: Disk) (User: )
Description: Le pilote a détecté une erreur du contrôleur sur \Device\Harddisk1\DR1.

Error: (12/01/2013 06:05:32 PM) (Source: Disk) (User: )
Description: Le pilote a détecté une erreur du contrôleur sur \Device\Harddisk1\DR1.

Error: (12/01/2013 06:05:32 PM) (Source: Disk) (User: )
Description: Le pilote a détecté une erreur du contrôleur sur \Device\Harddisk1\DR1.


Microsoft Office Sessions:
=========================


A plus
Titre: Re : Infection Nationzoom
Posté par: itsinthehead le janvier 08, 2014, 18:58:22
 :)


Citer
4 programmes supprimés
Impossible accéder Windows Live Messenger pour suppression

Réessaye ,regarde ==>ici<== (http://support.microsoft.com/kb/938275/fr) pour t'aider



Citer
Fichier fixlog.txt contient seulement la mention : "end of fixlog"

Y'a une erreur quelque part ...  ::)

Recommence la procédure ,STP :)

FRST - Correctif :

/!\ Crée un point de restauration manuel avant d'appliquer le correctif - Tutoriel en images (http://forum.security-x.fr/windows-7/%28tutoriel%29-creer-un-point-de-restauration-sous-windows-7/) /!\

start
(Cherished Technololgy LIMITED) C:\ProgramData\WPM\wprotectmanager.exe
C:\ProgramData\WPM
() C:\Users\Florent\AppData\Local\fst_fr_35\upfst_fr_35.exe
C:\Users\Florent\AppData\Local\fst_fr_35
() C:\Program Files (x86)\fst_fr_35\fst_fr_35.exe
C:\Program Files (x86)\fst_fr_35
() C:\Program Files (x86)\fst_fr_35\fst_fr_35.exe
HKLM-x32\...\Run: [fst_fr_35] - C:\Program Files (x86)\fst_fr_35\fst_fr_35.exe [3992488 2013-12-19] ()
HKLM-x32\...\RunOnce: [upfst_fr_35.exe] - C:\Users\Florent\AppData\Local\fst_fr_35\upfst_fr_35.exe -runonce [3154344 2013-12-18] ()
Startup: C:\Users\Florent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.nationzoom.com/?type=sc&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.nationzoom.com/web/?type=ds&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924&q={searchTerms}
BHO: Feven 1.7 - {11111111-1111-1111-1111-110411051194} - C:\Program Files (x86)\Feven 1.7\Feven 1.7-bho64.dll (Feven)
C:\Program Files (x86)\Feven 1.7
BHO-x32: Feven 1.7 - {11111111-1111-1111-1111-110411051194} - C:\Program Files (x86)\Feven 1.7\Feven 1.7-bho.dll (Feven)
FF NewTab: hxxp://www.nationzoom.com/newtab/?type=nt&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
FF DefaultSearchEngine: nationzoom
FF SelectedSearchEngine: nationzoom
FF Homepage: hxxp://www.nationzoom.com/?type=hp&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\nationzoom.xml
C:\Program Files (x86)\mozilla firefox\browser\searchplugins\nationzoom.xml
M101MBB_S2TTJ9HC500924&q={searchTerms}
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [38440 2013-09-19] (Just Develop It)
C:\Program Files (x86)\MyPC Backup
R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [499856 2013-12-21] (Cherished Technololgy LIMITED)
C:\ProgramData\WPM
Task: {0189868C-AE05-4D1F-9521-6DF03651EC67} - System32\Tasks\Feven 1.7-updater => C:\Program Files (x86)\Feven 1.7\Feven 1.7-updater.exe [2013-12-21] (Feven) <==== ATTENTION
Task: {19EDA4B9-930B-4E2D-9D45-04944994624A} - System32\Tasks\Feven 1.7-enabler => C:\Program Files (x86)\Feven 1.7\Feven 1.7-enabler.exe [2013-12-21] (Feven) <==== ATTENTION
Task: {1BBCD050-2121-4CF5-A8BF-47D9193F08FF} - System32\Tasks\Feven 1.7-codedownloader => C:\Program Files (x86)\Feven 1.7\Feven 1.7-codedownloader.exe [2013-12-21] (Feven) <==== ATTENTION
Task: {48E334F0-0348-4A1A-8FC3-B70A2182A25A} - System32\Tasks\Feven 1.7-chromeinstaller => C:\Program Files (x86)\Feven 1.7\Feven 1.7-chromeinstaller.exe [2013-12-21] (Feven) <==== ATTENTION
Task: {96806986-6643-4114-8759-87F1C2C0C7DD} - System32\Tasks\Feven 1.7-firefoxinstaller => C:\Program Files (x86)\Feven 1.7\Feven 1.7-firefoxinstaller.exe [2013-12-21] (Feven) <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.7-chromeinstaller.job => C:\Program Files (x86)\Feven 1.7\Feven 1.7-chromeinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.7-codedownloader.job => C:\Program Files (x86)\Feven 1.7\Feven 1.7-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.7-enabler.job => C:\Program Files (x86)\Feven 1.7\Feven 1.7-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.7-firefoxinstaller.job => C:\Program Files (x86)\Feven 1.7\Feven 1.7-firefoxinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Feven 1.7-updater.job => C:\Program Files (x86)\Feven 1.7\Feven 1.7-updater.exe <==== ATTENTION
2013-12-21 00:46 - 2014-01-08 14:01 - 00002022 _____ C:\Windows\Tasks\Feven 1.7-firefoxinstaller.job
2013-12-21 00:46 - 2014-01-08 13:56 - 00001338 _____ C:\Windows\Tasks\Feven 1.7-updater.job
2013-12-21 00:46 - 2014-01-08 13:56 - 00001240 _____ C:\Windows\Tasks\Feven 1.7-codedownloader.job
2013-12-21 00:46 - 2014-01-08 13:56 - 00001140 _____ C:\Windows\Tasks\Feven 1.7-enabler.job
2013-12-21 00:46 - 2013-12-21 00:46 - 00004368 _____ C:\Windows\System32\Tasks\Feven 1.7-updater
2013-12-21 00:46 - 2013-12-21 00:46 - 00004270 _____ C:\Windows\System32\Tasks\Feven 1.7-codedownloader
2013-12-21 00:46 - 2013-12-21 00:46 - 00004170 _____ C:\Windows\System32\Tasks\Feven 1.7-enabler
2013-12-21 00:45 - 2014-01-08 13:56 - 00001980 _____ C:\Windows\Tasks\Feven 1.7-chromeinstaller.job 
2013-12-21 00:45 - 2013-12-21 00:45 - 00001089 _____ C:\Users\Florent\Desktop\MyPC Backup.lnk
2013-12-21 00:45 - 2013-12-21 00:45 - 00000000 ____D C:\Users\Florent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup 
2014-01-08 13:56 - 2013-12-21 00:45 - 00001980 _____ C:\Windows\Tasks\Feven 1.7-chromeinstaller.job   
2013-12-21 00:45 - 2013-12-21 00:45 - 00001089 _____ C:\Users\Florent\Desktop\MyPC Backup.lnk
C:\Users\Florent\AppData\Local\Temp\BackupSetup.exe
end
Titre: Re : Infection Nationzoom
Posté par: c3g le janvier 09, 2014, 09:55:58
Bonjour

Windows Live Messenger supprimé avec succès

A priori, l'appli FRST n'existe plus......
J'ai voulu double clic sur l'icone, il me dit que le FRST.exe n'existe plus.
J'ai voulu desinstal/réinstal FRST, mais pas trouvé dans liste des appli
Impossible supprimer l'icône FRST du bureau : "n'existe plus dans C:\utilisateurs\........"

Que fais-je ?
Titre: Re : Re : Infection Nationzoom
Posté par: itsinthehead le janvier 09, 2014, 10:58:38
Salut c3g  :)

Citation de: c3g

A priori, l'appli FRST n'existe plus......
J'ai voulu double clic sur l'icone, il me dit que le FRST.exe n'existe plus.
J'ai voulu desinstal/réinstal FRST, mais pas trouvé dans liste des appli
Impossible supprimer l'icône FRST du bureau : "n'existe plus dans C:\utilisateurs\........"

Que fais-je ?

???  ::) Tu as utilisé d'autre outils ??




Re-télécharge FRST , sur ton bureau .

Titre: Re : Infection Nationzoom
Posté par: c3g le janvier 09, 2014, 11:26:55
Bonjour intsinthehead

Non je n'ai absolument pas fait de manip entretemps ; ni utilisé d'outils quelconque.

Fichier fixlog :

http://up.security-x.fr/file.php?h=R250c798fdddb68725ec4df5c67f62ea8

A plus
Titre: Re : Infection Nationzoom
Posté par: itsinthehead le janvier 09, 2014, 12:44:31
 :)

Nickel, refait un scan avec ADWCleaner et poste le rapport.

Je te remets la procédure, mais si tu as gardé ADWCleaner ne le re-télécharge pas .

AdwCleaner - Recherche :

Titre: Re : Infection Nationzoom
Posté par: c3g le janvier 09, 2014, 16:05:54
re bonjour

rapport ADW Cleaner :

http://up.security-x.fr/file.php?h=Rece7bf7bf1442ee56cd3f818f808f679

A plus
Titre: Re : Infection Nationzoom
Posté par: itsinthehead le janvier 09, 2014, 18:14:10
Titre: Re : Infection Nationzoom
Posté par: c3g le janvier 09, 2014, 18:32:48
Re-

Rapport ADW Cleaner :

http://up.security-x.fr/file.php?h=Rae83a38c4d9a0ca1b7d0e84bd0886578

Par contre, Nationzoom apparait toujours à l'ouverture de Firefox et (gros soucis !) un tas d'icônes et de photos ont disparu du bureau

A plus
Titre: Re : Infection Nationzoom
Posté par: itsinthehead le janvier 09, 2014, 21:30:45
Citer
Par contre, Nationzoom apparait toujours à l'ouverture de Firefox


Re,  :)

On va nettoyer tes raccourcis manuellement:

Clique sur:

"C:\Program Files\Mozilla Firefox\firefox.exe" hxxp://www.nationzoom.com/?type=sc&ts=1387583142&from=tugs&uid=ST1000LM024XHN-M101MBB_S2TTJ9HC500924

(https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fsecurity-x.fr%2Fimg%2Fpublic%2FNettoyer_raccourcis_navigateurs%2FNettoyer_raccourcis-navigateurs-3.jpg&hash=b2cdecf5db6e38cdb1dd50b9e835d279fb7a1b49)






Citer
et (gros soucis !) un tas d'icônes et de photos ont disparu du bureau


C'est à dire , peux tu être + précis , parce que ces fichiers n'apparaissent pas dans le rapport ADWCleaner


Photo personnels ??

Les icônes ??

Fais ceci :


Clique sur:

Titre: Re : Infection Nationzoom
Posté par: c3g le janvier 09, 2014, 21:51:11
Re-

Appli Speed up my pc désinstallée

A priori Nationzoom disparu

Concernant le "nettoyage" du bureau, ont disparu a priori seulement des fichiers (dossiers et photos perso)

Fichier quarantine :

http://up.security-x.fr/file.php?h=R629f278c6e7001361de30672e1cd4810

A plus
Titre: Re : Infection Nationzoom
Posté par: itsinthehead le janvier 09, 2014, 22:31:21
ok

Titre: Re : Infection Nationzoom
Posté par: itsinthehead le janvier 09, 2014, 23:08:17
 :)

Y'a eu un bug de l'outils sur ton système .  ::)

Pourquoi sur ton pc ... je ne sais pas  ::)

Tu peux récupérer tes dossiers perso que tu identifies et tes fichiers perso .jpg, .pdf, .docx, .avi

Aucun .exe, ni .dll



Va dans la quarantaine de l'outil:




Fais le moi savoir quand ça sera fait ou si tu rencontre un problème .

 :)


Titre: Re : Infection Nationzoom
Posté par: c3g le janvier 10, 2014, 07:51:44
Bonjour

Contenu du dossier "Quarantine" copié dans "Mes documents" (on triera plus tard... :) )

A plus
Titre: Re : Infection Nationzoom
Posté par: itsinthehead le janvier 10, 2014, 13:56:36
Salut c3g :)

Ok pour ton dossier déplacé, mais tu feras bien attention à récupérer uniquement tes dossiers perso que tu identifies et tes fichiers perso avec des extensios .jpg, .pdf, .docx, .avi

Ne récupère aucun fichiers avec les extensions .exe ou  .dll

J'ai oublié de te préciser de ne pas récupérer les raccourcis (.lnk)  navigateurs (Chrome , Firefox, Internet explorer )



Passons à la suite , tu as déjà Malwarebyte Anti-Malware sur ton système. (Sinon télécharge le ==>Malwarebyte Anti-Malware<== (http://www.malwarebytes.org/mwb-download/)) Aide en images (http://forum.security-x.fr/tutoriels-317/%28tutoriel%29-malwarebyte%27s-anti-malware/)


--Actions pour les  Programmes potentiellement indésirables (PUP) ==> sélectionne : Afficher dans les résultats, pré-coché pour suppression

--Actions pour les Modifications potentiellement indésirables (PUM) ==> sélectionne : Afficher dans les résultats, pré-coché pour suppression

Titre: Re : Infection Nationzoom
Posté par: c3g le janvier 10, 2014, 15:11:26
Re-

Rapport MAM :

http://up.security-x.fr/file.php?h=Rd256c51f3fce4f8fb662ddf4e72e5374

A plus
Titre: Re : Infection Nationzoom
Posté par: itsinthehead le janvier 10, 2014, 16:22:20
 :)

Avant de finaliser:


Comment se comporte ton système ?

D'autre soucis ?

 :)
Titre: Re : Infection Nationzoom
Posté par: c3g le janvier 10, 2014, 16:33:55

Négatif !

Plus de souci visible.... (pour l'instant .... ;) )

Dans l'attente de tes consignes pour le coup de balai final !
Titre: Re : Re : Infection Nationzoom
Posté par: itsinthehead le janvier 10, 2014, 17:49:59
:)

Citation de: c3g

Négatif !

Plus de souci visible.... (pour l'instant .... ;) )

Normalement.... ::) ,j'ai vu que tu était un peu habitué à SX , et tu as déjà eu des discours de prévention en fin de désinfection ,non ?

Donc...  ;D

Citer
Dans l'attente de tes consignes pour le coup de balai final !

C'est parti  ;)


***********************************************************************************************


Télécharge ==>DelFix<== (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/9-delfix) (de Xplode) sur ton bureau.

Titre: Re : Infection Nationzoom
Posté par: c3g le janvier 10, 2014, 18:19:06
Re-

Euhhh, en fait toutes mes demandes sur Security x ne me concernent pas !! J'ai réparé une fois mon PC infecté, mais dans tous les autres cas (comme ici) je ne suis que le réparateur sur des machines de tiers.....
Autrement dit, moi le message de prévention, je l'ai bien reçu. Mais mon beau père ou mes fils, j'ai l'impression qu'ils s'en f.... un peu ! D'autant plus qu'ils savent qu'ils peuvent compter sur moi et sur Security X bien sûr ! Jusqu'au jour où ça sera bien planté, et là..........

Revenons à nos moutons.... :)

J'ai appliqué TFC et redémarré. Au redémarrage, le PC m'a signalé que l'appli Discount Dragon était endommagée et que le système la réparait automatiquement.
Or j'ai bien l'impression que c'est encore une saleté ce truc non ?

A te lire

Edit :

J'ai supprimé Discount Dragon avec ajout/suppression de pgm

Rapport Delfix :

# DelFix v10.6 - Rapport créé le 10/01/2014 à 18:23:25
# Mis à jour le 11/11/2013 par Xplode
# Nom d'utilisateur : Florent - FLORENT-PC
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Suppression des outils de désinfection ...

Supprimé : C:\FRST
Supprimé : C:\AdwCleaner
Supprimé : C:\Users\Florent\Desktop\AdwCleaner.exe
Supprimé : C:\Users\Florent\Desktop\Fixlog.txt
Supprimé : C:\Users\Florent\Desktop\FRST64.exe
Supprimé : C:\Users\Florent\Desktop\TFC.exe
Supprimé : C:\Users\Florent\Downloads\SXCU.exe
Supprimée : HKLM\SOFTWARE\OldTimer Tools
Supprimée : HKLM\SOFTWARE\AdwCleaner

~ Purge de la restauration système ...

Supprimé : RP #136 [Windows Update | 12/17/2013 18:34:15]
Supprimé : RP #137 [Windows Update | 12/20/2013 21:47:58]
Supprimé : RP #138 [Uniblue SpeedUpMyPC installation | 12/20/2013 23:45:40]
Supprimé : RP #139 [Windows Update | 12/24/2013 23:15:58]
Supprimé : RP #140 [Windows Update | 12/28/2013 00:38:46]
Supprimé : RP #141 [Windows Update | 12/31/2013 22:47:52]
Supprimé : RP #142 [Windows Update | 01/08/2014 08:13:23]
Supprimé : RP #143 [avast! antivirus system restore point | 01/08/2014 12:58:58]
Supprimé : RP #144 [Pt restau security x | 01/08/2014 16:18:41]
Supprimé : RP #145 [Windows Live Essentials | 01/09/2014 08:46:16]
Supprimé : RP #146 [WLSetup | 01/09/2014 08:46:41]
Supprimé : RP #147 [point de restau security x | 01/09/2014 10:19:41]

Nouveau point de restauration créé !

########## - EOF - ##########

A plus
Titre: Re : Re : Infection Nationzoom
Posté par: itsinthehead le janvier 10, 2014, 19:13:34
Citation de: c3g
Re-

Euhhh, en fait toutes mes demandes sur Security x ne me concernent pas !! J'ai réparé une fois mon PC infecté, mais dans tous les autres cas (comme ici) je ne suis que le réparateur sur des machines de tiers.....
Autrement dit, moi le message de prévention, je l'ai bien reçu. Mais mon beau père ou mes fils, j'ai l'impression qu'ils s'en f.... un peu ! D'autant plus qu'ils savent qu'ils peuvent compter sur moi et sur Security X bien sûr ! Jusqu'au jour où ça sera bien planté, et là..........

Laisse les venir désinfecter leur pc sur SX  ;D

Y'a qu'avec l'expérience qu'il comprendront  ;)

Citer
Revenons à nos moutons.... :

Comme tu dis  :)

Citer
J'ai appliqué TFC et redémarré. Au redémarrage, le PC m'a signalé que l'appli Discount Dragon était endommagée et que le système la réparait automatiquement.
Or j'ai bien l'impression que c'est encore une saleté ce truc non ?

 ::) quand même bizarre qu'y'a des trucs comme ça.

Mais c'est bien une saleté et des fois même difficile à éradiquer.

On va refaire un scan avec FRST.

Je te remets la procédure:

Au cas où, vérifie bien que la case Addition.txt soit cochée.

FRST - version 64 bits :

:)
Titre: Re : Infection Nationzoom
Posté par: c3g le janvier 10, 2014, 19:26:03
Bonsoir

Rapport addition :

http://up.security-x.fr/file.php?h=R6845292d5cc7c71dff7de39795903941



Rapport FRST :

http://up.security-x.fr/file.php?h=Rb4968659dc8ae9bdb6afbd463ec988bf


A plus
Titre: Re : Infection Nationzoom
Posté par: itsinthehead le janvier 10, 2014, 22:42:30
re, :)

désinstalle ce programme via ajout/suppression de programmes:

Titre: Re : Infection Nationzoom
Posté par: c3g le janvier 11, 2014, 09:43:02
Bonjour à toi itsinthehead

Cling Clang désinstallé

Rapport fixlog :

http://up.security-x.fr/file.php?h=Rf842758c130389e1ade5f4fdd912ffe7

A plus
Titre: Re : Infection Nationzoom
Posté par: itsinthehead le janvier 11, 2014, 11:22:04
Salu c3g  :D

C'est tout bon  ;)

As-tu eu des soucis au cours de cette désinfection, pour appliquer les procédures par exemple ?

Si tu as quelques commentaires à faire n'hésite pas ;)




On va donc passer au discours final  ;D


Quelques conseils avant l'installation d'un programme,et sur les dangers du net:

Titre: Re : Infection Nationzoom
Posté par: c3g le janvier 11, 2014, 14:14:51
Re-

Non, pas de souci particulier, sauf ceux que je t'ai signalé au fur et à mesure des différents nettoyages, et auxquels tu as répondu.

Merci pour ton aide efficace.

A une prochaine ! (.....mais le plus tard sera le mieux !)
Titre: Re : Infection Nationzoom
Posté par: itsinthehead le janvier 11, 2014, 14:43:41
 :D

Passe ton sujet en résolu.

Bye  :AAN