O44 - LFC:[MD5.C0EF0A87BF43950567FBAEC444359880] - 29/05/2011 - 21:06:02 ---A- . (...) -- C:\Windows\SysNative\perfc00C.dat [130754]
O44 - LFC:[MD5.1B7EAA786F994A36D306324CC6B009E8] - 29/05/2011 - 21:06:02 ---A- . (...) -- C:\Windows\SysNative\perfc009.dat [106388]
O44 - LFC:[MD5.25A12D9EE1B129EA4EB890EAFACCDDE6] - 29/05/2011 - 21:06:02 ---A- . (...) -- C:\Windows\SysNative\perfh00C.dat [704480]
O44 - LFC:[MD5.584EFF0CA5B0144392F9DFCEFAF8E158] - 29/05/2011 - 21:06:02 ---A- . (...) -- C:\Windows\SysNative\perfh009.dat [616008]
M2 - MFEP: prefs.js [marley - 01m7cd6b.default\@FissaPlugin] [] Fissa v1.0 (.Secure Digital Services.) => Infection PUP (PUP.OfferBox)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.fissa.comR0 - HKUS\S-1-5-21-2979984479-3032386748-1788732610-1001\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.fissa.comO42 - Logiciel: Fissa - (.Secure Digital Services.) [HKLM][64Bits] -- {4BD271AB-66E2-4D58-AF88-80FE3B0770C4}
[HKCU\Software\AppDataLow\Software\AskToolbar]
[HKCU\Software\Ask.com]
[HKCU\Software\FissaSearch]
[HKCU\Software\Spointer]
[HKCU\Software\freeTVRadio]
[HKLM\Software\FissaSearch]
O43 - CFD: 27/12/2010 - 00:36:38 - [25115] ----D- C:\Users\marley\AppData\Roaming\FissaSearch
O43 - CFD: 27/12/2010 - 01:24:28 - [677] ----D- C:\Users\marley\AppData\Roaming\freeTVRadio
O69 - SBI: SearchScopes [HKCU] {b41306c6-96d0-442a-bcc4-b0f621e82ce9} - (Fissa) -
http://www.fissa.com [HKLM\Software\Classes\AppID\SoftwareUpdate.exe]
[HKLM\Software\Wow6432Node\Classes\AppID\SoftwareUpdate.exe]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4BD271AB-66E2-4D58-AF88-80FE3B0770C4}]
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{b41306c6-96d0-442a-bcc4-b0f621e82ce9}]
[HKCR\Interface\{db885111-f39f-4d88-9ee5-c88460b6df7b}]
[HKLM\Software\Classes\Interface\{db885111-f39f-4d88-9ee5-c88460b6df7b}]
[HKCU\Software\Ask.com]
[HKCU\Software\Ask.com]
[HKCU\Software\AppDataLow\Software\AskToolbar]
[HKCU\Software\FissaSearch]
[HKLM\Software\FissaSearch]
[HKLM\Software\Wow6432Node\FissaSearch]
[HKCU\Software\freetvradio]
[HKCU\Software\AppDataLow\Software\AskToolbar]
[HKCU\Software\Spointer]
C:\Users\marley\AppData\Roaming\FissaSearch
C:\Users\marley\AppData\Roaming\freeTVRadio
O4 - Global Startup: C:\Users\marley\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PartyPoker.fr.lnk . (...) -- C:\Programs\PartyFrance\PartyFrance.exe
O8 - Extra context menu item: T?l?charger avec Mipony - (.not file.) - file:\\C:\Program Files (x86)\MiPony\Browser\IEContext.htm
O42 - Logiciel: PartyPoker.fr - (.PartyFrance.) [HKLM][64Bits] -- PartyPokerFr
[HKCU\Software\PartyFrance]
O43 - CFD: 17/12/2010 - 01:21:00 - [1252] ----D- C:\ProgramData\Partner
O43 - CFD: 18/02/2011 - 21:55:32 - [1717] ----D- C:\ProgramData\regid.1986-12.com.adobe
O51 - MPSK:{011dc706-0612-11e0-94a0-5442490efe8a}\AutoRun\command. (.Pas de propri?taire - Pas de description.) -- I:\RunWormsForts.exe (.not file.)
[HKCU\Software\PartyFrance]
O3 - Toolbar: DAEMON Tools Toolbar [64Bits] - {32099AAC-C132-4136-9E9A-4E364A424E17} . (.Pas de propri?taire - ToolBand Module.) -- C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll
O42 - Logiciel: DAEMON Tools Toolbar - (.DT Soft Ltd.) [HKLM][64Bits] -- DAEMON Tools Toolbar
[HKCU\Software\ReducBarre]
[HKLM\Software\Conduit]
O43 - CFD: 23/12/2010 - 19:29:12 - [3497393] ----D- C:\Program Files (x86)\DAEMON Tools Toolbar
O43 - CFD: 02/02/2011 - 20:10:24 - [593920] ----D- C:\Program Files (x86)\ReducBarre
[HKLM\Software\Conduit]
[HKLM\Software\Wow6432Node\Conduit]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\daemon tools toolbar]
[HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{32099aac-c132-4136-9e9a-4e364a424e17}
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{32099aac-c132-4136-9e9a-4e364a424e17}
C:\Program Files (x86)\DAEMON Tools Toolbar
C:\Program Files (x86)\ReducBarre
EmptyFlash
Emptytemp