Script ZHPFix FirewallRaz EmptyPrefetch EmptyTemp EmptyFlash sysrestore [HKCU\Software\W3i] [HKLM\Software\Wow6432Node\W3i] KKCU\Software\ASKHomePageO2 - BHO: (no name) [64Bits] - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline OPT:O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation OPT:O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation O42 - Logiciel: Bing Rewards Client Installer - (.Microsoft Corporation.) [HKLM][64Bits] -- {61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17} [HKCU\Software\32850InstEnd] [HKCU\Software\ASKDefaultSearch] [HKCU\Software\ASKHomePage] O43 - CFD: 24/05/2015 - 19:59:45 - [] ----D C:\Program Files (x86)\GUMD01A.tmp O43 - CFD: 14/02/2011 - 20:05:43 - [] ----D C:\ProgramData\Norton O43 - CFD: 27/08/2010 - 10:23:32 - [] ----D C:\ProgramData\NortonInstaller O43 - CFD: 1/09/2013 - 22:29:33 - [] -SH-D C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} O43 - CFD: 30/10/2014 - 20:20:39 - [0] ----D C:\Users\Renata\AppData\Local\CRE O45 - LFCP:[MD5.6709BE9DE0BE4CA887DE770ADE4C6150] - 28/05/2015 - 12:58:40 ---A- - C:\Windows\Prefetch\CLOCKHAND.BOAS.EXE-BAA12CD4.pf =>PUP.ClockHand O45 - LFCP:[MD5.7FC8C58F5A201915B986A5899485A840] - 28/05/2015 - 13:01:16 ---A- - C:\Windows\Prefetch\CLOCKHAND.BOASHELPER.EXE-7D611CEC.pf =>PUP.ClockHand O45 - LFCP:[MD5.3655CE61432B54F3E96575D4A16ABF9B] - 28/05/2015 - 12:58:33 ---A- - C:\Windows\Prefetch\CLOCKHAND.BOASPRT.EXE-AA269AB2.pf =>PUP.ClockHand O45 - LFCP:[MD5.9E6072169A3333FF36E0F5E1257F26CB] - 28/05/2015 - 14:31:56 ---A- - C:\Windows\Prefetch\CLOCKHAND.BROWSERADAPTER.EXE-635DEB44.pf =>PUP.ClockHand O45 - LFCP:[MD5.F71A1A66ABB657F2FF389CA33B1ADE95] - 28/05/2015 - 14:32:27 ---A- - C:\Windows\Prefetch\CLOCKHAND.BROWSERADAPTER64.EX-99B28BE6.pf =>PUP.ClockHand O45 - LFCP:[MD5.729703F3F2FF9C1EA73BC3118378BCB1] - 28/05/2015 - 12:55:50 ---A- - C:\Windows\Prefetch\CLOCKHAND.EXPEXT.EXE-AD11A091.pf =>PUP.ClockHand O45 - LFCP:[MD5.5C92F615EB52ED740F4819C78EC0033F] - 11/04/2015 - 09:30:56 ---A- - C:\Windows\Prefetch\CLOCKHAND.OFSVC.EXE-97923940.pf =>PUP.ClockHand O45 - LFCP:[MD5.7CD064DE9309E2A2A004BD501BC84FA7] - 28/05/2015 - 13:08:30 ---A- - C:\Windows\Prefetch\CLOCKHAND.PURBROWSE64.EXE-0BFC8742.pf =>PUP.ClockHand O45 - LFCP:[MD5.8F4808EFB6256C9E4B1F63C5A1D0143C] - 28/05/2015 - 13:11:25 ---A- - C:\Windows\Prefetch\UPDATECLOCKHAND.EXE-432B94A3.pf =>PUP.ClockHand O45 - LFCP:[MD5.746616F2A0513FBDBF86A20C10899D74] - 28/05/2015 - 13:01:03 ---A- - C:\Windows\Prefetch\UTILCLOCKHAND.EXE-382DAA4B.pf =>PUP.ClockHand ServiceDeamand:WinDefend ServiceDemand:MBAMService [MD5.81F6DB10B1EDB693A1F2326790BE263F] - (.Google Inc. - Google Chrome Installer.) -- C:\Windows\TEMP\CR_53E00.tmp\setup.exe [986440] [PID.3460] O4 - HKCU\..\Run: [SpybotSD TeaTimer] . (.Safer Networking Limited - System settings protector.) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-21-3984910880-2758854699-675344059-1001\..\Run: [SpybotSD TeaTimer] . (.Safer Networking Limited - System settings protector.) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [HKCU\Software\Safer Networking Limited] [HKLM\Software\Wow6432Node\Safer Networking Limited] O43 - CFD: 24/05/2015 - 19:59:45 - [] ----D C:\Program Files (x86)\GUMD01A.tmp O43 - CFD: 24/01/2012 - 01:04:40 - [] ----D C:\Program Files (x86)\Spybot - Search & Destroy O43 - CFD: 24/01/2012 - 01:07:21 - [] ----D C:\ProgramData\Spybot - Search & Destroy O51 - MPSK:{3597a10a-0cbe-11e0-906d-806e6f6e6963}\AutoRun\command. (...) -- D:\K-PACS-Lite.exe (.not file.)