Script ZHPFix [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified P2 - FPN:Firefox Plugin Navigator . (.BitComet - BitCometAgent v1.30 for Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npBitCometAgent.dll O2 - BHO: MSS+ Identifier [64Bits] - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} . (.McAfee, Inc. - Quick Browser Identifier for MSS+ Tool.) -- C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll O2 - BHO: Windows Live Messenger Companion Helper [64Bits] - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} . (.Microsoft Corporation - Windows Live Messenger Companion Core.) -- C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O2 - BHO: (no name) [64Bits] - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} Clé orpheline O3 - Toolbar: McAfee SiteAdvisor Toolbar - [HKLM]{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} . (...) -- C:\Program Files (x86)\mcafee\SITEAD~1\x64\mcieplg.dll O3 - Toolbar: avast! Online Security - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} . (...) -- (.not file.) O4 - HKCU\..\Run: [BitComet] C:\Program Files (x86)\BitComet\BitComet.exe (.not file.) O4 - HKLM\..\Wow6432Node\Run: [HF_G_Jul] C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe (.not file.) O4 - HKLM\..\Wow6432Node\Run: [ROC_ROC_JULY_P1] C:\Program Files (x86)\AVG Secure Search\ROC_ROC_JULY_P1.exe (.not file.) O4 - HKLM\..\Wow6432Node\Run: [ROC_ROC_NT] C:\Program Files (x86)\AVG Secure Search\ROC_ROC_NT.exe (.not file.) OPT:O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe OPT:O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe OPT:O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe O4 - HKUS\S-1-5-21-3838763673-1115839168-2840729140-1000\..\Run: [BitComet] C:\Program Files (x86)\BitComet\BitComet.exe (.not file.) O23 - Service: (vToolbarUpdater) . (...) - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe (.not file.) [MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-3838763673-1115839168-2840729140-1000Core] (.Facebook Inc..) -- C:\Users\UTILISATEUR\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-3838763673-1115839168-2840729140-1000UA] (.Facebook Inc..) -- C:\Users\UTILISATEUR\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [MD5.00000000000000000000000000000000] [APT] [Launch HTC Sync Loader] (...) -- C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{435AA3D5-CF93-4F49-83C2-BC9B7B2F93AA}] (...) -- C:\Program Files\DomaIQ Uninstaller\DomaIQUninstall.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{CC9931A6-0C89-4975-8BAB-ABE72DCCDF6C}] (...) -- C:\Users\UTILISATEUR\Local Settings\Application Data\Bundled software uninstaller\biclient.exe (.not file.) [0] O39 - APT: FacebookUpdateTaskUserS-1-5-21-3838763673-1115839168-2840729140-1000Core - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3838763673-1115839168-2840729140-1000Core.job [930] O39 - APT: FacebookUpdateTaskUserS-1-5-21-3838763673-1115839168-2840729140-1000Core - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3838763673-1115839168-2840729140-1000Core [930] O39 - APT: FacebookUpdateTaskUserS-1-5-21-3838763673-1115839168-2840729140-1000UA - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3838763673-1115839168-2840729140-1000UA.job [952] O39 - APT: FacebookUpdateTaskUserS-1-5-21-3838763673-1115839168-2840729140-1000UA - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3838763673-1115839168-2840729140-1000UA [952] O42 - Logiciel: Java 6 Update 37 - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83216035FF} [HKCU\Software\BitComet] [HKCU\Software\IncrediMail] [HKCU\Software\MCAFEE] [HKCU\Software\Pando Networks] [HKLM\Software\ASK] [HKLM\Software\Wow6432Node\IncrediMail] [HKLM\Software\Wow6432Node\McAfee.com] [HKLM\Software\Wow6432Node\McAfeeInstaller] [HKLM\Software\Wow6432Node\McAfee] [HKLM\Software\Wow6432Node\Pando Networks] [HKLM\Software\Wow6432Node\Symantec] O43 - CFD: 03/10/2012 - 19:38:46 - [] ----D C:\Program Files (x86)\AVG O43 - CFD: 02/05/2013 - 11:08:46 - [0] ----D C:\Program Files (x86)\Pando Networks O43 - CFD: 21/05/2013 - 21:06:07 - [] ----D C:\Program Files (x86)\Software O43 - CFD: 24/04/2012 - 14:24:33 - [0] ----D C:\Program Files (x86)\Common Files\Symantec Shared O43 - CFD: 06/04/2013 - 12:38:11 - [] ----D C:\ProgramData\boost_interprocess O43 - CFD: 27/02/2013 - 13:15:16 - [] ----D C:\ProgramData\McAfee O43 - CFD: 27/02/2013 - 13:15:17 - [] ----D C:\ProgramData\McAfee Security Scan O43 - CFD: 25/04/2012 - 07:26:20 - [] ----D C:\ProgramData\Norton O43 - CFD: 22/04/2012 - 21:00:16 - [] ----D C:\ProgramData\NortonInstaller O43 - CFD: 25/04/2012 - 07:26:16 - [0] ----D C:\ProgramData\Symantec O43 - CFD: 30/03/2013 - 10:40:45 - [] ----D C:\Users\UTILISATEUR\AppData\Roaming\BitComet O43 - CFD: 03/10/2012 - 19:51:59 - [] ----D C:\Users\UTILISATEUR\AppData\Roaming\TuneUp Software O43 - CFD: 15/10/2014 - 15:54:33 - [0] ----D C:\Users\UTILISATEUR\AppData\Local\CRE O43 - CFD: 21/05/2013 - 18:01:11 - [] ----D C:\Users\UTILISATEUR\AppData\Local\Software O51 - MPSK:{0370c609-0ad1-11e2-b6b2-e811323f655e}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) O51 - MPSK:{0370c639-0ad1-11e2-b6b2-e811323f655e}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) O51 - MPSK:{78bc1707-bf0d-11e2-860f-e811323f655e}\AutoRun\command. (...) -- G:\Startme.exe (.not file.) O51 - MPSK:{d609d338-74a6-11e3-8ed3-ea55f9470159}\AutoRun\command. (...) -- F:\CMADownloader.exe (.not file.) O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 [MD5.4893D70913B2F286E9E920FC9B0455E3] [WIS][04/12/2013] (.Kreapixel - Webplayer.) -- C:\Windows\Installer\154a1d4.msi [21504] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\01net_BitComet_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\01net_BitComet_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BitComet_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BitComet_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Deeal_fr 0_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Deeal_fr 0_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ExtensionUpdaterService_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\ExtensionUpdaterService_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\KREAPIXEL_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\KREAPIXEL_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SmartbarExeInstaller_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SmartbarExeInstaller_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\VAFPlayer_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\VAFPlayer_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WAJAM_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WAJAM_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\wp_update_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\wp_update_RASMANCS [HKLM\SYSTEM\CurrentControlSet\Services\vToolbarUpdater] [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:BitComet [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:HF_G_Jul C:\Users\UTILISATEUR\AppData\Roaming\BitComet C:\Program Files (x86)\Software C:\Users\UTILISATEUR\AppData\Local\Software C:\Users\UTILISATEUR\AppData\Local\Temp\avg@toolbar [HKCU\Software\BitComet] C:\Windows\Installer\154a1d4.msi C:\Users\UTILISATEUR\AppData\Local\Temp\instloffer.exe C:\Users\UTILISATEUR\AppData\Local\Temp\uninst1.exe C:\Users\UTILISATEUR\AppData\Local\Temp\incredibar_installer.exe C:\Users\UTILISATEUR\AppData\Local\Temp\square_babylonv2.bmp C:\Users\UTILISATEUR\AppData\Local\Temp\square_babylonv3.bmp C:\Users\UTILISATEUR\AppData\Local\Temp\BoxoreInstaller.exe C:\Users\UTILISATEUR\AppData\Local\Temp\square_lollipop.bmp C:\Users\UTILISATEUR\AppData\Local\Temp\ToolbarInstaller.exe C:\Users\UTILISATEUR\AppData\Local\Temp\SearchHelper.exe C:\Users\UTILISATEUR\AppData\Local\Temp\tb01NE.dll ServiceDisabled:McComponentHostService ServiceDisabled:vToolbarUpdater ServiceDemand:Bonjour Service ProxyFix EmptyTemp EmptyPrefetch EmptyFlash EmptyCLSID FirewallRAZ SysRestore