Script zhpfix [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified C:\Users\ludo\AppData\Roaming\Mozilla\Firefox\Profiles\{DefaultProfilesFolder}\prefs.js (.not file.) O3 - Toolbar\WebBrowser: (no name) - [HKCU]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} Clé orpheline O4 - HKLM\..\Run: [ETDCtrl] C:\Program Files (x86)\Elantech\ETDCtrl.exe (.not file.) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. [MD5.00000000000000000000000000000000] [APT] [Adobe Reader Speed Launcher] (...) -- C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [Norton WSC Integration] (...) -- C:\Program Files (x86)\Norton AntiVirus\Engine\19.8.0.14\WSCStub.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{D0197F1D-444A-42FB-BED2-FFAEE83A8F2A}] (...) -- C:\Users\ludo\Downloads\air3-7_win (2).exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{DA9403CE-AB34-407A-9259-94FEBF9F818E}] (...) -- C:\Users\ludo\Downloads\air3-8_win (1).exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [Norton Error Analyzer] (...) -- C:\Program Files (x86)\Norton AntiVirus\Engine\19.8.0.14\SymErr.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [Norton Error Processor] (...) -- C:\Program Files (x86)\Norton AntiVirus\Engine\19.8.0.14\SymErr.exe (.not file.) [0] [HKCU\Software\AskPartnerNetwork] [HKCU\Software\Symantec] [HKLM\Software\Wow6432Node\AskPartnerNetwork] [HKLM\Software\Wow6432Node\Symantec] O43 - CFD: 22/07/2013 - 11:05:18 - [] ----D C:\Program Files (x86)\AskPartnerNetwork O43 - CFD: 10/08/2014 - 10:44:07 - [] ----D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 O43 - CFD: 22/07/2013 - 11:05:18 - [] ----D C:\ProgramData\AskPartnerNetwork O43 - CFD: 13/02/2014 - 15:51:03 - [] ----D C:\ProgramData\Norton O51 - MPSK:{3241408a-5580-11e2-834c-ef327fc29716}\AutoRun\command. (...) -- F:\Startme.exe (.not file.) O51 - MPSK:{3ff93e9b-8967-11e2-8607-f84a24aa3814}\AutoRun\command - Clé orpheline O90 - PUC: "25946514D2147365007A7A857BC02020" . (.Avira SearchFree Toolbar plus Web Protection.) -- C:\Windows\Installer\{41564952-412D-5637-00A7-A758B70C0202}\ToolbarIcon.exe =>Toolbar.Avira [MD5.23823B6DD7133C17B6B30486257B61D8] [WIS][26/07/2013] (.Ask Partner Network - Avira SearchFree Toolbar plus Web Protection.) -- C:\Windows\Installer\1be24.msi [759296] =>Toolbar.Avira HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BetterInstaller_RASAPI32 =>Adware.MegaSearch HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BetterInstaller_RASMANCS =>Adware.MegaSearch HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BingBar_RASAPI32 =>Toolbar.Bing HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\LollipopInstaller_somoto_14693_RASAPI32 =>Adware.Lollipop HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\LollipopInstaller_somoto_14693_RASMANCS =>Adware.Lollipop HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\yontoo-C4-02D4_RASAPI32 =>Adware.Yontoo HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\yontoo-C4-02D4_RASMANCS =>Adware.Yontoo HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\yontoo-C4-12D4_RASAPI32 =>Adware.Yontoo HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\yontoo-C4-12D4_RASMANCS =>Adware.Yontoo HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\yontoo-C4-1348_RASAPI32 =>Adware.Yontoo HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\yontoo-C4-1348_RASMANCS =>Adware.Yontoo SS - | Disabled 10/07/1658 168400 | (APNMCP) . (...) - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}] =>Toolbar.Avira^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{41564952-412D-5637-00A7-A758B70C0202}] =>Toolbar.Avira^ [HKLM\Software\Wow6432Node\Microsoft\Tracing\BingBar_RASAPI32] =>Toolbar.Bing [HKCU\Software\AskPartnerNetwork] =>Toolbar.Ask [HKLM\Software\Wow6432Node\AskPartnerNetwork] =>Toolbar.Ask [HKLM\Software\Wow6432Node\Google\Chrome\Extensions\aaaaacalgebmfelllfiaoknifldpngjh] =>Toolbar.Avira [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094] =>PUP.SweetIM^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536] =>PUP.SweetIM^ C:\Program Files (x86)\AskPartnerNetwork =>Toolbar.Ask C:\ProgramData\AskPartnerNetwork =>Toolbar.Ask C:\Windows\Installer\1be24.msi =>Toolbar.Avira^ Emptytemp Emptyflash