Script ZHPFix [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowPrinters: Modified R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <-loopback> R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 O3 - Toolbar: Acer eDataSecurity Management - [HKLM]{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} . (.Egis Incorporated. - Acer eDataSecurity Management Explorer Tool.) -- C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline OPT:O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] Clé orpheline O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] Clé orpheline [MD5.00000000000000000000000000000000] [APT] [4964] (...) -- C:\Users\PascKath\AppData\Local\Temp\launchie.vbs \\B (.not file.) [0] O39 - APT: FacebookUpdateTaskUserS-1-5-21-3861729339-4169080700-1581058186-1000Core - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3861729339-4169080700-1581058186-1000Core.job [918] O39 - APT: FacebookUpdateTaskUserS-1-5-21-3861729339-4169080700-1581058186-1000Core - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3861729339-4169080700-1581058186-1000Core [918] O42 - Logiciel: Java 6 Update 3 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160030} [HKCU\Software\AppDataLow\Software\LyricSing] [HKCU\Software\Condut] [HKCU\Software\Mixi.DJ] [HKCU\Software\SpottyFiles] [HKCU\Software\USyndication] [HKCU\Software\usyndication.com] [HKLM\Software\McAfee.com] [HKLM\Software\McAfee] [HKLM\Software\SpottyFiles] [HKLM\Software\VBMZ] [HKLM\Software\mamverifier] O43 - CFD: 2013-08-21 - 05:57:31 - [0] ----D C:\Program Files\SaveShare O43 - CFD: 2014-01-29 - 18:05:54 - [] ----D C:\Program Files\uTorrent O43 - CFD: 2012-09-21 - 13:03:30 - [0] ----D C:\Users\PascKath\AppData\Roaming\SpottyFiles O43 - CFD: 2014-06-23 - 08:07:18 - [] ----D C:\Users\PascKath\AppData\Roaming\uTorrent O43 - CFD: 2013-09-15 - 14:33:43 - [] ----D C:\Users\PascKath\AppData\Local\CRE O43 - CFD: 2013-09-15 - 14:34:41 - [0] ----D C:\Users\PascKath\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits O45 - LFCP:[MD5.836C6DD39803685BFC737DCCBEB04CB8] - 2014-06-22 - 18:10:30 ---A- - C:\Windows\Prefetch\BROWSERSAFEGUARD.EXE-AEA3426D.pf O45 - LFCP:[MD5.197BE37E87C4227ADE59B59B680D11E5] - 2014-06-22 - 18:11:22 ---A- - C:\Windows\Prefetch\VOPACKAGE.EXE-A1CE3512.pf O45 - LFCP:[MD5.B12D3ADA556BDD366B91E78DFC53B0BE] - 2014-06-22 - 18:29:28 ---A- - C:\Windows\Prefetch\WAJAMHTTPSERVER.EXE-A02165B9.pf O45 - LFCP:[MD5.70CC5432FB8CA61F8DBBBD570BA00B8C] - 2014-06-22 - 18:29:30 ---A- - C:\Windows\Prefetch\WAJAMINTERNETENHANCER.EXE-B842ACA7.pf O51 - MPSK:{53822bc3-a4da-11e3-9c39-00218570fde8}\AutoRun\command. (...) -- K:\start.exe (.not file.) O51 - MPSK:{bff32a33-eacc-11e2-b074-00218570fde8}\AutoRun\command. (...) -- K:\SETUP.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\AnyProtect [Key] . (...) -- C:\Program Files\AnyProtectEx\AnyProtect.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\AnyProtect Tray [Key] . (...) -- C:\Program Files\AnyProtectEx\AnyProtectTray.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\mobilegeni daemon [Key] . (...) -- C:\Program Files\Mobogenie\DaemonProcess.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\Updater [Key] . (...) -- C:\ProgramData\Updater\Updater.exe (.not file.) O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O61 - LFC: 2014-06-22 - 06:03:03 ---A- . (...) -- C:\Users\PascKath\AppData\Local\Temp\Nex66EF\VOPackage.exe [287182] O69 - SBI: SearchScopes [HKCU] {96677A36-DCF1-4198-9F87-2985A3843DA0} - (Mysearchdial) - http://start.mysearchdial.com C:\Users\PascKath\Desktop\musique kath\Downloads\Bigfish Games - Slingo Supreme + Adnan_Boy 2008 + Precracked\Slingo Supreme.exe C:\Users\PascKath\Desktop\musique kath\Downloads\Bigfish Games - Slingo Supreme + Adnan_Boy 2008 + Precracked\Torrent downloaded from Demonoid.com.txt C:\Users\PascKath\Desktop\musique kath\Downloads\Slingo Quest Amazon - Full PreCracked\Slingo Quest Amazon - Full PreCracked.exe C:\Users\PascKath\Desktop\musique kath\Downloads\Bigfish Games - Slingo Supreme + Adnan_Boy 2008 + Precracked\Slingo Supreme.exe C:\Users\PascKath\Desktop\musique kath\Downloads\Bigfish Games - Slingo Supreme + Adnan_Boy 2008 + Precracked\Torrent downloaded from Demonoid.com.txt C:\Users\PascKath\Desktop\musique kath\Downloads\Slingo Quest Amazon - Full PreCracked\Slingo Quest Amazon - Full PreCracked.exe ServiceDemand:Bonjour Service ServiceStop:Bonjour Service [HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\AnyProtect] [HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\AnyProtect Tray] [HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon] [HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\Updater] [HKLM\Software\Classes\.bk1] [HKLM\Software\Classes\.bk2] [HKLM\Software\VBMZ] [HKCU\Software\Classes\MF] [HKCU\Software\Mixi.DJ] [HKCU\Software\USyndication] [HKCU\Software\usyndication.com] [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5CBE3B7C-1E47-477E-A7DD-396DB0476E29}] [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5CBE3B7C-1E47-477E-A7DD-396DB0476E29}] [HKLM\Software\Classes\CLSID\{5CBE3B7C-1E47-477E-A7DD-396DB0476E29}] [HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011441179}] [HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110111251155}] [HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110111271147}] [HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211971101}] [HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011441179}] [HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110111251155}] [HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110111271147}] [HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211971101}] [HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110111251155}] [HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110111271147}] [HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110211971101}] [HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{31111111-1111-1111-1111-110111251155}] [HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{31111111-1111-1111-1111-110211971101}] [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011441179}] [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110111251155}] [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110111271147}] [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110111281132}] [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211971101}] C:\Program Files\SaveShare C:\Program Files\uTorrent C:\Users\PascKath\AppData\Roaming\uTorrent C:\Users\PascKath\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits [HKCU\Software\AppDataLow\Software\LyricSing] EmptyTemp EmptyPrefetch EmptyFlash EmptyCLSID FirewallRAZ ProxyFix SysRestore