Script zhpfix [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowHelp: Modified =>PUA.StartShow O2 - BHO: (no name) [64Bits] - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} Clé orpheline O3 - Toolbar: (no name) - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Clé orpheline O3 - Toolbar: (no name) - [HKLM]{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} Clé orpheline O3 - Toolbar\WebBrowser: (no name) - [HKCU]{1017A80C-6F09-4548-A84D-EDD6AC9525F0} Clé orpheline O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. [MD5.00000000000000000000000000000000] [APT] [AllmyappsUpdateTask] (...) -- C:\Users\Utilisateur\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe (.not file.) [0] [MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-2680640916-4098147576-3932825530-1000Core] (.Facebook Inc..) -- C:\Users\Utilisateur\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-2680640916-4098147576-3932825530-1000UA] (.Facebook Inc..) -- C:\Users\Utilisateur\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [MD5.00000000000000000000000000000000] [APT] [Run RoboForm TaskBar Icon] (...) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{22781F17-3191-4CC6-AE30-FB4907EC6A16}] (...) -- C:\Users\Utilisateur\Downloads\wmp11-windowsxp-x86-FR-FR [1].exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{32754B74-4CE9-4FAD-A565-7EA8F856AFD8}] (...) -- C:\Users\Utilisateur\AppData\Roaming\istartsurf\UninstallManager.exe (.not file.) [0] =>PUP.IsStart [MD5.00000000000000000000000000000000] [APT] [{5CF3A257-CF41-420D-A6C7-DE698BE61262}] (...) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (.not file.) [0] O39 - APT: FacebookUpdateTaskUserS-1-5-21-2680640916-4098147576-3932825530-1000Core - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2680640916-4098147576-3932825530-1000Core.job [930] O39 - APT: FacebookUpdateTaskUserS-1-5-21-2680640916-4098147576-3932825530-1000Core - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2680640916-4098147576-3932825530-1000Core [930] O39 - APT: FacebookUpdateTaskUserS-1-5-21-2680640916-4098147576-3932825530-1000UA - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2680640916-4098147576-3932825530-1000UA.job [952] O39 - APT: FacebookUpdateTaskUserS-1-5-21-2680640916-4098147576-3932825530-1000UA - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2680640916-4098147576-3932825530-1000UA [952] [HKCU\Software\47718InstEnd] [HKCU\Software\Shareaza] [HKLM\Software\Wow6432Node\Avanquest] O43 - CFD: 25/03/2013 - 09:30:04 - [] ----D C:\Program Files (x86)\Lexmark Toolbar O43 - CFD: 02/01/2014 - 10:49:59 - [] ----D C:\Program Files (x86)\Shareaza O43 - CFD: 29/07/2013 - 17:58:03 - [] ----D C:\Program Files (x86)\Spybot - Search & Destroy O43 - CFD: 04/06/2014 - 17:50:51 - [] ----D C:\Program Files (x86)\Common Files\Avanquest Software O43 - CFD: 28/12/2013 - 08:43:49 - [] ----D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 O43 - CFD: 07/04/2013 - 17:53:29 - [] ----D C:\ProgramData\McAfee O43 - CFD: 29/07/2013 - 20:17:16 - [] ----D C:\ProgramData\Spybot - Search & Destroy O43 - CFD: 08/01/2014 - 21:01:51 - [] ----D C:\Users\Utilisateur\AppData\Roaming\1O1L1I1PtF1F1C1N O43 - CFD: 02/01/2014 - 12:59:43 - [] ----D C:\Users\Utilisateur\AppData\Roaming\Shareaza O43 - CFD: 01/01/2014 - 12:51:39 - [] ----D C:\Users\Utilisateur\AppData\Local\Shareaza O45 - LFCP:[MD5.CDDCE786DEA6F4E71D1D736CACDC4E2B] - 14/08/2014 - 15:41:10 ---A- - C:\Windows\Prefetch\ANYPROTECT.EXE-1996592C.pf =>PUP.AnyProtect O45 - LFCP:[MD5.B769D6D43774D29EF48C4DDF647A29BC] - 15/08/2014 - 10:08:15 ---A- - C:\Windows\Prefetch\SPEEDUPMYPC.EXE-F92E9673.pf =>PUP.SpeedUpMyPC O45 - LFCP:[MD5.6F1265C0594E63ABD4F4B82C2EBE7949] - 15/08/2014 - 10:07:47 ---A- - C:\Windows\Prefetch\VOPACKAGE.EXE-39435679.pf =>Adware.Downware O45 - LFCP:[MD5.277F27B41F81340EBC0FA5BFA01DF58A] - 15/08/2014 - 10:07:41 ---A- - C:\Windows\Prefetch\WAJAM_DOWNLOAD.EXE-2CFA87FC.pf =>PUP.Wajam O51 - MPSK:{359df182-a1b3-11e2-bc36-4487fcaa03d0}\AutoRun\command. (...) -- L:\AutoRun.exe (.not file.) O61 - LFC: 13/08/2014 - 19:07:21 ---A- . (...) -- C:\Users\Utilisateur\AppData\Local\Temp\386Dtmp\freesofttoday.exe [3310904] =>Adware.FreeSoftToday O61 - LFC: 13/08/2014 - 19:07:21 ---A- . (...) -- C:\Users\Utilisateur\AppData\Local\Temp\389Ctmp\vopackage.exe [291392] =>Adware.Downware O61 - LFC: 15/08/2014 - 19:07:21 ---A- . (...) -- C:\Users\Utilisateur\AppData\Local\Temp\6A02tmp\vopackage.exe [291083] =>Adware.Downware O61 - LFC: 15/08/2014 - 19:07:21 ---A- . (.Uniblue Systems Limited.) -- C:\Users\Utilisateur\AppData\Local\Temp\69D2tmp\speedupmypc.exe [1291312] =>PUP.SpeedUpMyPC O61 - LFC: 15/08/2014 - 19:07:21 ---A- . (.Uniblue Systems Limited.) -- C:\Users\Utilisateur\AppData\Local\Temp\is-BNUVN.tmp\SpeedUpMyPC-standalone-setup.exe [18478928] =>PUP.SpeedUpMyPC O69 - SBI: SearchScopes [HKCU] {20F5AB16-9F2E-4E92-93F2-ECB9ABB0EC42} - (Foxtab) - http://search.foxtab.com O69 - SBI: SearchScopes [HKCU] {9BB47C17-9C68-4BB3-B188-DD9AF0FD2516} - (default-search.net) - http://www.default-search.net =>Hijacker.Browsers [MD5.B67811645C5A3B8E4E4B1A1DB1EE271C] [WIS][03/04/2013] (.Boxore OU. - Software Update Helper.) -- C:\Windows\Installer\bf59a.msi [45056] =>Adware.Boxore HKLM\SOFTWARE\Microsoft\Tracing\MyPC Backup_RASAPI32 =>PUP.MyPCBackup HKLM\SOFTWARE\Microsoft\Tracing\MyPC Backup_RASMANCS =>PUP.MyPCBackup [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C9A6357B-25CC-4BCF-96C1-78736985D412}] =>Toolbar.Orange [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\1C875DDE39636004CA8CDAEC335B4160] =>Adware.PredictAd [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\BA086F2D38A8E1A47912955A68B3AD24] =>Adware.PredictAd [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\64A6E60055D801F4BB8AC269354B72B8] =>Adware.Boxore [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375] =>PUP.Tarma [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5] =>PUP.Tarma [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\464AA55239C100F32AF2D438EDDC0F47] =>Adware.IMBooster [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5652BA3D5FB98AE31B337BF0AF939856] =>Adware.IMBooster [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EB95E1AFCBABE3DB9ECCC669B99494] =>Adware.IMBooster [HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2516}] =>Adware.Bandoo^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BA71D41F6CC0B6247B05D473850A8AEA] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] =>Adware.Boxore^ [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowHelp: Modified =>PUA.StartShow^ C:\Windows\Installer\bf59a.msi =>Adware.Boxore^ C:\Users\Utilisateur\AppData\Local\Temp\GoogleToolbarInstaller1.log =>PUP.Babylon Emptytemp Emptyflash emptyPrefetch