script ZHPFix M3 - MFPP: Plugins - [user] -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\y0h9qatq.default-1397195214921\searchplugins\VenteeRo.xml M3 - MFPP: Plugins - [user] -- C:\Program Files\Mozilla FireFox\searchplugins\do-search.xml =>PUP.DoSearches M0 - MFSP: prefs.js [user - y0h9qatq.default-1397195214921] http://www.arabyonline.com M0 - MFSP: user.js [user - y0h9qatq.default-1397195214921] http://www.arabyonline.com R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.arabyonline.com R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.arabyonline.com O2 - BHO: AdSafe - {598AC71E-BE58-3981-B78A-5C138F423AD6} . (...) -- C:\Documents and Settings\user\Application Data\VolIE\Adsafe_32.dll O4 - HKCU\..\Run: [LiveSupport] C:\Program Files\LiveSupport\LiveSupport.exe (.not file.) =>PUP.LiveSupport O9 - Extra button: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -- Clé orpheline O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job [232] =>Toolbar.Ask [MD5.6B773BA457B813850A76493B3425AB35] [APT] [Scheduled Update for Ask Toolbar] (...) -- C:\Program Files\Ask.com\UpdateTask.exe [131976] =>Toolbar.Ask [HKCU\Software\BuzzSearch] =>PUP.BuzzSearch [HKCU\Software\Conduit] =>Toolbar.Conduit [HKCU\Software\Default Tab] =>Adware.Bandoo [HKCU\Software\InstallCore] =>Adware.InstallCore [HKCU\Software\Smartbar] =>Hijacker.SmartBar [HKCU\Software\Softonic] =>Toolbar.Conduit [HKCU\Software\Vonteera Safe ads] =>Trojan.Vonteera [HKCU\Software\YourFileDownloader] =>PUP.YourFileDownloader [HKLM\Software\BuzzSearch] =>PUP.BuzzSearch [HKLM\Software\Conduit] =>Toolbar.Conduit [HKLM\Software\Default Tab] =>Adware.Bandoo [HKLM\Software\YourFileDownloader] =>PUP.YourFileDownloader [HKLM\Software\babylontoolbar] =>PUP.Babylon O43 - CFD: 01/12/2013 - 23:03:49 - [0,294] ----D C:\Program Files\FTdownloader V6.0 =>Adware.Downware O43 - CFD: 03/01/2014 - 23:28:52 - [0] ----D C:\Program Files\greatsoaver =>PUP.GreatSaver O43 - CFD: 09/03/2014 - 00:56:51 - [0] ----D C:\Program Files\NExtCCouup =>PUP.NetCoupon O43 - CFD: 01/12/2013 - 23:18:21 - [0,008] ----D C:\Program Files\SecretSauce =>Adware.SecretSauce O43 - CFD: 07/03/2014 - 13:41:31 - [0] ----D C:\Program Files\Weibsave =>PUP.Websave O43 - CFD: 23/11/2013 - 22:17:59 - [4,560] ----D C:\Program Files\YourFileDownloader =>PUP.YourFileDownloader O43 - CFD: 23/11/2013 - 22:17:59 - [0] ----D C:\Documents and Settings\All Users\Application Data\Babylon =>PUP.Babylon O43 - CFD: 04/01/2014 - 19:57:22 - [0] ----D C:\Documents and Settings\All Users\Application Data\greatsoaver =>PUP.GreatSaver O43 - CFD: 09/03/2014 - 00:58:11 - [0] ----D C:\Documents and Settings\All Users\Application Data\NExtCCouup =>PUP.NetCoupon O43 - CFD: 07/03/2014 - 13:44:33 - [0] ----D C:\Documents and Settings\All Users\Application Data\Weibsave =>PUP.Websave O43 - CFD: 04/01/2014 - 19:57:22 - [0] ----D C:\Documents and Settings\All Users\Application Data\YoutubeAdblocker =>PUP.TubeAdBlocker O43 - CFD: 24/11/2013 - 15:12:52 - [0] ----D C:\Documents and Settings\user\Application Data\defaulttab =>Adware.Bandoo O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - () - http://search.live.com O69 - SBI: SearchScopes [HKCU] {756D1D40-E491-4E1D-9BC6-5B37CEDE646E} [DefaultScope] - (VenteeRo) - http://www.arabyonline.com O69 - SBI: SearchScopes [HKCU] {afdbddaa-5d3f-42ee-b79c-185a7020515b} - (Newwara Customized Web Search) - http://search.conduit.com [HKCR\CLSID\{460CCE08-552E-CC5A-E5B9-0ECB0A76143A}] (YoutubeAdblocker) =>PUP.Multiplug [HKCU\Software\delta LTD] =>Toolbar.DeltaSearch [HKLM\Software\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}] =>Adware.iWinArcade [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}] =>Toolbar.Conduit [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}] =>Toolbar.Ask&Record [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}] =>Toolbar.Ask&Record [HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\HssSrv] =>Toolbar.Agent [HKLM\Software\BabylonToolbar] =>PUP.Babylon [HKCU\Software\default tab] =>Adware.IMBooster [HKLM\Software\default tab] =>Adware.IMBooster [HKCU\Software\Softonic] =>Toolbar.Conduit [HKLM\Software\Classes\Prod.cap] =>PUP.Babylon [HKCU\Software\InstallCore] =>Adware.InstallCore [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}] =>Toolbar.Yahoo [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}] =>Toolbar.Yahoo [HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}] =>Toolbar.Yahoo [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}] =>Adware.Browse2Save [HKLM\Software\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}] =>Toolbar.DeltaSearch [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}] =>Toolbar.Yahoo [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}] =>Toolbar.Yahoo [HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}] =>Toolbar.Yahoo [HKLM\Software\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}] =>Adware.BrowseFox [HKLM\Software\Classes\Toolbar.CT2458743] =>Toolbar.Conduit [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:LiveSupport =>PUP.LiveSupport^ C:\Program Files\FTdownloader V6.0 =>Adware.Downware^ C:\Program Files\greatsoaver =>PUP.GreatSaver^ C:\Program Files\NExtCCouup =>PUP.NetCoupon^ C:\Program Files\SecretSauce =>Adware.SecretSauce^ C:\Program Files\Weibsave =>PUP.Websave^ C:\Program Files\YourFileDownloader =>PUP.YourFileDownloader^ C:\Documents and Settings\All Users\Application Data\Babylon =>PUP.Babylon^ C:\Documents and Settings\All Users\Application Data\greatsoaver =>PUP.GreatSaver^ C:\Documents and Settings\All Users\Application Data\NExtCCouup =>PUP.NetCoupon^ C:\Documents and Settings\All Users\Application Data\Weibsave =>PUP.Websave^ C:\Documents and Settings\All Users\Application Data\YoutubeAdblocker =>PUP.TubeAdBlocker^ C:\Documents and Settings\user\Application Data\defaulttab =>Adware.Bandoo^ C:\Documents and Settings\user\Application Data\YourFileDownloader =>PUP.YourFileDownloader^ C:\Program Files\Ask.com =>Toolbar.AskBar C:\Program Files\Conduit =>Toolbar.Conduit C:\Program Files\Webplayer setup =>Adware.SocialSkinz C:\Program Files\SimilarSites =>Adware.SimilarSites C:\Program Files\Optimizer Pro =>PUP.OptimizerPro C:\Documents and Settings\All Users\Application Data\InstallMate =>PUP.Tarma C:\Documents and Settings\user\Application Data\SimilarSites =>Adware.SimilarSites C:\Documents and Settings\user\Local Settings\Application Data\AskToolbar =>Toolbar.AskTBar C:\Documents and Settings\user\Local Settings\Application Data\Conduit =>Toolbar.Conduit C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job =>Toolbar.Ask^ C:\Program Files\Ask.com\UpdateTask.exe =>Toolbar.Ask^ [HKCU\Software\BuzzSearch] =>PUP.BuzzSearch^ [HKCU\Software\Conduit] =>Toolbar.Conduit^ [HKCU\Software\Default Tab] =>Adware.Bandoo^ [HKCU\Software\Smartbar] =>Hijacker.SmartBar^ [HKCU\Software\Vonteera Safe ads] =>Trojan.Vonteera^ [HKCU\Software\YourFileDownloader] =>PUP.YourFileDownloader^ [HKLM\Software\BuzzSearch] =>PUP.BuzzSearch^ [HKLM\Software\Conduit] =>Toolbar.Conduit^ [HKLM\Software\Default Tab] =>Adware.Bandoo^ [HKLM\Software\YourFileDownloader] =>PUP.YourFileDownloader^ [HKLM\Software\babylontoolbar] =>PUP.Babylon^ [HKCR\CLSID\{460CCE08-552E-CC5A-E5B9-0ECB0A76143A}] (YoutubeAdblocker) =>PUP.Multiplug^ EmptyCLSID ShortcutFix FirewallRaz EmptyTemp EmptyFlash Proxyfix Sysrestore