Script ZHPFix O41 - Driver: (iSafeNetFilter) . (. - .) - C:\Program Files (x86)\iSafe\iSafeNetFilter.sys (.not file.) =>Trojan.Staser [HKCU\Software\AppDataLow\Software\toolbarcleaner] => Adware.ToolbarCleaner [HKCU\Software\ToolbarCleaner] => Adware.ToolbarCleaner [HKCU\Software\ToolbarCleaneroptions] => Adware.ToolbarCleaner [HKLM\Software\Wow6432Node\BearShareSRTB] =>PUP.BearShare [HKLM\Software\Wow6432Node\PopCap] =>Adware.PopCap [HKLM\Software\Wow6432Node\VBMZ] =>PUP.Duuqu [HKLM\Software\Wow6432Node\iSafe] =>Trojan.Staser O43 - CFD: 16/02/2013 - 14:46:08 - [0] ----D C:\Users\Alain.Alain-PC\AppData\Roaming\DSite =>Hijacker.DSite O43 - CFD: 3/05/2013 - 12:03:49 - [0,259] ----D C:\Users\Alain.Alain-PC\AppData\Roaming\holasearch =>Hijacker.HolaSearch O43 - CFD: 26/01/2014 - 13:15:34 - [0,057] ----D C:\Users\Alain.Alain-PC\AppData\Roaming\iSafe =>Trojan.Staser O43 - CFD: 31/08/2012 - 18:17:02 - [0,039] ----D C:\Users\Alain.Alain-PC\AppData\Roaming\WebPlayerBdd =>Adware.SocialSkinz O43 - CFD: 15/08/2013 - 17:57:53 - [103,043] ----D C:\Users\Alain.Alain-PC\AppData\Local\BearShare =>PUP.BearShare O43 - CFD: 13/10/2011 - 23:06:18 - [0,014] ----D C:\Users\Alain.Alain-PC\AppData\Local\Ilivid Player =>Adware.Bandoo O43 - CFD: 8/03/2013 - 09:50:58 - [12,359] ----D C:\Users\Alain.Alain-PC\AppData\Local\toolbarcleaner => Adware.ToolbarCleaner O43 - CFD: 24/09/2013 - 10:36:28 - [0] ----D C:\Users\Alain.Alain-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard =>PUP.BitGuard O43 - CFD: 7/01/2014 - 13:27:06 - [0] ----D C:\Users\Alain.Alain-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com =>Hijacker.TornTV O45 - LFCP:[MD5.8C73C2C3C9747327ED949AF1BE144923] - 27/01/2014 - 11:39:17 ---A- - C:\Windows\Prefetch\WISECUSTOMCALLA31.EXE-F79281E5.pf =>Crapware.SpyHunter O45 - LFCP:[MD5.460E60AE56D45D75B565C0F531E166DB] - 27/01/2014 - 11:39:35 ---A- - C:\Windows\Prefetch\WISECUSTOMCALLA37.EXE-6B94E103.pf =>Crapware.SpyHunter O53 - SMSR:HKLM\...\startupreg\Instant Savings App-repairJob [Key] . (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>Adware.InstantSavings O61 - LFC: 26/01/2014 - 14:38:49 ---A- . (.Enigma Software Group USA, LLC..) -- C:\Users\Alain.Alain-PC\Downloads\SpyHunter-Installer (1).exe [728960] =>Crapware.SpyHunter O61 - LFC: 26/01/2014 - 14:38:49 ---A- . (.Enigma Software Group USA, LLC..) -- C:\Users\Alain.Alain-PC\Downloads\SpyHunter-Installer (2).exe [728960] =>Crapware.SpyHunter O61 - LFC: 26/01/2014 - 14:38:49 ---A- . (.Enigma Software Group USA, LLC..) -- C:\Users\Alain.Alain-PC\Downloads\SpyHunter-Installer (3).exe [728960] =>Crapware.SpyHunter O61 - LFC: 26/01/2014 - 14:38:49 ---A- . (.Enigma Software Group USA, LLC..) -- C:\Users\Alain.Alain-PC\Downloads\SpyHunter-Installer (4).exe [728960] =>Crapware.SpyHunter O61 - LFC: 26/01/2014 - 14:38:49 ---A- . (.Enigma Software Group USA, LLC..) -- C:\Users\Alain.Alain-PC\Downloads\SpyHunter-Installer (5).exe [728960] =>Crapware.SpyHunter O61 - LFC: 26/01/2014 - 14:38:50 ---A- . (...) -- C:\Users\Alain.Alain-PC\Downloads\SpyHunter-Installer (6).exe [639671] =>Crapware.SpyHunter O61 - LFC: 26/01/2014 - 14:38:50 ---A- . (.Enigma Software Group USA, LLC..) -- C:\Users\Alain.Alain-PC\Downloads\SpyHunter-Installer.exe [728960] =>Crapware.SpyHunter O87 - FAEL: "TCP Query User{D672EC35-1270-4010-9500-7241D8D62701}C:\program files (x86)\torntv.com\torntv downloader.exe" |In - Private - P6 - TRUE | .(...) -- C:\program files (x86)\torntv.com\torntv downloader.exe (.not file.) =>Hijacker.TornTV O87 - FAEL: "UDP Query User{8AA581A3-0F91-4471-AE93-A39095226E10}C:\program files (x86)\torntv.com\torntv downloader.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files (x86)\torntv.com\torntv downloader.exe (.not file.) =>Hijacker.TornTV O87 - FAEL: "{5439CC34-D6F1-4F72-AFB6-43CD5A259EC6}" |In - Public - P6 - TRUE | .(...) -- C:\ProgramData\eSafe\eGdpSvc.exe (.not file.) =>PUP.eSafeSecurity [HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\Instant Savings App-repairJob] =>Adware.InstantSavings^ [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater] =>Hijacker.BabSolution [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F479A18A22A86E3429341589FF57D81A] =>PUP.SweetIM [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9] =>Adware.MyWebSearch [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632] =>PUP.SweetIM [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75D5168E5E176C24981B4E5DBD991078] =>PUP.SweetIM [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0] =>PUP.SweetIM [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F754C503375A13344B22388E18DFE87E] =>PUP.SweetIM [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FA20CB7A821113A4CB8FA1E38E303D3B] =>PUP.SweetIM [HKLM\Software\Microsoft\Tracing\updateBrowseFox_RASAPI32] =>Adware.BrowseFox [HKLM\Software\Microsoft\Tracing\updateBrowseFox_RASMANCS] =>Adware.BrowseFox [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyLiveUpdateTaskMachineCore] =>PUP.DealPly [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyLiveUpdateTaskMachineUA] =>PUP.DealPly [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094] =>PUP.SweetIM^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536] =>PUP.SweetIM^ C:\Users\Alain.Alain-PC\AppData\Roaming\DSite =>Hijacker.DSite^ C:\Users\Alain.Alain-PC\AppData\Roaming\holasearch =>Hijacker.HolaSearch^ C:\Users\Alain.Alain-PC\AppData\Roaming\iSafe =>Trojan.Staser^ C:\Users\Alain.Alain-PC\AppData\Roaming\WebPlayerBdd =>Adware.SocialSkinz^ C:\Users\Alain.Alain-PC\AppData\Local\BearShare =>PUP.BearShare^ C:\Users\Alain.Alain-PC\AppData\Local\Ilivid Player =>Adware.Bandoo^ C:\Users\Alain.Alain-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard =>PUP.BitGuard^ C:\Users\Alain.Alain-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com =>Hijacker.TornTV^ [HKLM\Software\Wow6432Node\BearShareSRTB] =>PUP.BearShare^ [HKLM\Software\Wow6432Node\PopCap] =>Adware.PopCap^ [HKLM\Software\Wow6432Node\iSafe] =>Trojan.Staser^ [HKCU\Software\Dashlane] =>Toolbar.Dashlane O43 - CFD: 13/09/2013 - 18:52:34 - [0] ----D C:\ProgramData\APN => Toolbar.Ask O43 - CFD: 15/11/2011 - 14:40:11 - [0,326] ----D C:\Users\Alain.Alain-PC\AppData\Local\APN => Toolbar.Ask O43 - CFD: 15/08/2013 - 12:24:04 - [2,778] ----D C:\Users\Alain.Alain-PC\AppData\Local\CRE => Toolbar.Conduit O43 - CFD: 16/09/2013 - 10:30:05 - [0,059] ----D C:\Users\Alain.Alain-PC\AppData\Local\SearchProtect =>Toolbar.Conduit O61 - LFC: 26/01/2014 - 14:36:31 ---A- . (...) -- C:\Users\Alain.Alain-PC\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.softonic.fr_0.localstorage [3072] =>Toolbar.Conduit O61 - LFC: 26/01/2014 - 14:36:31 ---A- . (...) -- C:\Users\Alain.Alain-PC\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.softonic.fr_0.localstorage-journal [512] =>Toolbar.Conduit [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7] =>Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8] =>Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01] =>Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED] =>Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472] =>Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296] =>Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888] =>Toolbar.Ask [HKLM\Software\Wow6432Node\VBMZ] =>Toolbar.Conduit [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2] =>Toolbar.Ask [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F999A48B-1950-4D81-9971-79018F807B4B}] =>Toolbar.Conduit C:\Users\Alain.Alain-PC\AppData\Local\SearchProtect =>Toolbar.Conduit^ C:\Users\Alain.Alain-PC\AppData\LocalLow\AskToolbar =>Toolbar.AskTBar C:\Users\Alain.Alain-PC\AppData\LocalLow\Conduit =>Toolbar.Conduit [HKCU\Software\Dashlane] =>Toolbar.Dashlane^ ShortcutFix FirewallRaz Emptytemp SysRestore