[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] WarnOnHTTPSToHTTPRedirect: Modified =
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: Modified
[MD5.7A93E7D6377640A2338438D1C51E2D3E] - (...) -- C:\Users\Absynthe\AppData\Roaming\cacaoweb\cacaoweb.exe [436224] [PID.2852]
M2 - MFEP: prefs.js [Absynthe - 57mt929t.default\cacaoweb@cacaoweb.org] [] cacaoweb v1.0.30 (.
http://www.cacaoweb.org/.)
R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 195.220.151.50:8080
F3 - REG:win.ini: load=C:\Users\Absynthe\AppData\Local\Temp\mspnp1e7f.exe
O4 - HKCU\..\Run: [cacaoweb] . (...) -- C:\Users\Absynthe\AppData\Roaming\cacaoweb\cacaoweb.exe
O4 - HKUS\S-1-5-21-160373787-2642004010-3322628286-1001\..\Run: [cacaoweb] . (...) -- C:\Users\Absynthe\AppData\Roaming\cacaoweb\cacaoweb.exe
[MD5.8AB8A119714882679428D516F4EBE354] [APT] [reveil] (...) -- C:\Users\Absynthe\Music\gni\001---Culcha-Candela---Hamma.mp3
[MD5.8AB8A119714882679428D516F4EBE354] [APT] [reveil3] (...) -- C:\Users\Absynthe\Music\gni\001---Culcha-Candela---Hamma.mp3
[MD5.D41D8CD98F00B204E9800998ECF8427E] [APT] [r‚veil] (...) -- C:\Users\Absynthe\Music\gni\Beatsteaks-Jane Became Insane.mp3"
[HKCU\Software\AppDataLow\Software\Fun Web Products]
[HKCU\Software\AppDataLow\Software\FunWebProducts]
[HKCU\Software\AppDataLow\Software\MyWebSearch]
[HKCU\Software\OfferBox]
[HKCU\Software\Softonic]
[HKCU\Software\Spointer]
[HKCU\Software\YahooPartnerToolbar]
[HKCU\Software\cacaoweb]
[HKCU\Software\freeTVRadio]
[HKLM\Software\Wow6432Node\Trymedia Systems]
O43 - CFD: 04/07/2011 - 11:34:06 - [1,507] ----D C:\ProgramData\Trymedia
O43 - CFD: 10/07/2012 - 15:14:55 - [818,778] ----D C:\Users\Absynthe\AppData\Roaming\cacaoweb
O43 - CFD: 05/07/2010 - 09:27:54 - [0,001] ----D C:\Users\Absynthe\AppData\Roaming\freeTVRadio
O43 - CFD: 08/07/2010 - 10:02:31 - [0,000] ----D C:\Users\Absynthe\AppData\Roaming\OfferBox
O43 - CFD: 05/10/2010 - 16:21:53 - [0,313] ----D C:\Users\Absynthe\AppData\Local\freetvradio Air
O53 - SMSR:HKLM\...\startupreg\ajwpaonw [Key] . (...) -- C:\Users\Absynthe\AppData\Local\xquihanmc\bxhoccdtssd.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\wmiprves [Key] . (...) -- C:\Users\Absynthe\AppData\Local\Temp\k7j9cumk.exe (.not file.)
[MD5.E5A7FCCE2F5E854755E3A67329C96894] [SPRF][02/02/2011] (.?????????? ?????????? - ??????????? ??? Windows.) -- C:\Users\Absynthe\AppData\Local\Temp\mspnp1e7f.exe [153600]
[MD5.5B2DA96D90C95228239806D40B720BD2] [SPRF][18/08/2004] (...) -- C:\Users\Absynthe\AppData\Local\Temp\VP6.reg [340]
[MD5.1410ADCB69C267916EE702E2A443E93F] [SPRF][18/08/2004] (...) -- C:\Users\Absynthe\AppData\Local\Temp\VP6Install.exe [23040]
O87 - FAEL: "TCP Query User{421EC34E-8A9D-441C-AEC9-9B67CB4C6D1F}C:\program files (x86)\emule\emule.exe" |In - Private - P6 - TRUE | .(...) -- C:\program files (x86)\emule\emule.exe (.not file.)
O87 - FAEL: "UDP Query User{AA0AA198-BA6D-4ECB-9FA1-E17D7D23E6C1}C:\program files (x86)\emule\emule.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files (x86)\emule\emule.exe (.not file.)
O87 - FAEL: "TCP Query User{F30D2AA7-ACB8-4B6A-8C0C-0ED58771A9C6}C:\program files (x86)\freetvradio\freetvradio.exe" |In - Private - P6 - TRUE | .(...) -- C:\program files (x86)\freetvradio\freetvradio.exe (.not file.)
O87 - FAEL: "UDP Query User{057D4844-6A50-4A69-ACFA-D0DC0EC5E16C}C:\program files (x86)\freetvradio\freetvradio.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files (x86)\freetvradio\freetvradio.exe (.not file.)
O87 - FAEL: "{E473EF6B-F6BC-4028-956B-996109DDF368}" | In - Private - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O87 - FAEL: "{9C1BA828-02A3-4FE8-9B26-2F59A460B828}" | In - Private - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O87 - FAEL: "TCP Query User{7D91ED4E-153A-42E8-A1F4-B403DA4A3444}C:\users\absynthe\appdata\roaming\cacaoweb\cacaoweb.exe" | In - Private - P6 - TRUE | .(...) -- C:\users\absynthe\appdata\roaming\cacaoweb\cacaoweb.exe =
O87 - FAEL: "UDP Query User{2A2B3B21-C706-4B94-80C3-4144F6404B95}C:\users\absynthe\appdata\roaming\cacaoweb\cacaoweb.exe" | In - Private - P17 - TRUE | .(...) -- C:\users\absynthe\appdata\roaming\cacaoweb\cacaoweb.exe
O87 - FAEL: "TCP Query User{4EA54774-A5FC-4954-9C35-D6C5525FA58D}C:\users\absynthe\appdata\roaming\cacaoweb\cacaoweb.exe" | In - Public - P6 - TRUE | .(...) -- C:\users\absynthe\appdata\roaming\cacaoweb\cacaoweb.exe
O87 - FAEL: "UDP Query User{3B022468-DE89-480A-8EB6-615AE9492783}C:\users\absynthe\appdata\roaming\cacaoweb\cacaoweb.exe" | In - Public - P17 - TRUE | .(...) -- C:\users\absynthe\appdata\roaming\cacaoweb\cacaoweb.exe
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7}]
[HKCU\Software\Microsoft\Internet Explorer\MenuExt\&search]
[HKLM\Software\Wow6432Node\Microsoft\Tracing\offerbox_RASAPI32]
[HKLM\Software\Wow6432Node\Microsoft\Tracing\offerbox_RASMANCS]
C:\Users\Absynthe\AppData\LocalLow\FunWebProducts
C:\Users\Absynthe\AppData\LocalLow\MyWebSearch
C:\Users\Absynthe\AppData\Roaming\Mozilla\Firefox\Profiles\57mt929t.default\Extensions\cacaoweb@cacaoweb.org
FirewallRaz
EmptyFlash
Emptytemp