Script ZHPFix [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: Modified =>Hijacker.Application G1 - GCS: Preference [User Data\Default] http://start.iminent.com =>Adware.IMBooster G0 - GCSP: Preference [User Data\Default][HomePage] http://start.iminent.com =>Adware.IMBooster G0 - GCSP: Preference [User Data\Default] http://start.iminent.com =>Adware.IMBooster M2 - MFEP: prefs.js [CAVERNE ANIMALIERE - uqpdnicw.default\ftdownloader3@ftdownloader.com] [] FTdownloader V3.0 v3.0 (..) =>Adware.Downware O2 - BHO: CrossriderApp0030137 [64Bits] - {11111111-1111-1111-1111-110311011137} . (...) -- C:\Program Files (x86)\Reduc.fr\Reduc.fr-bho64.dll (.not file.) =>PUP.CrossRider [MD5.00000000000000000000000000000000] [APT] [FGRun] (...) -- C:\Users\CAVERNE ANIMALIERE\AppData\Roaming\pack.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [Updater21810.exe] (...) -- C:\Users\CAVERNE ANIMALIERE\AppData\Local\Updater21810\Updater21810.exe (.not file.) [0] =>PUP.CrossRider [MD5.00000000000000000000000000000000] [APT] [{CD8A4800-4EA7-456A-976E-B19267F6DB20}] (...) -- D:\Welcome.exe (.not file.) [0] O42 - Logiciel: Iminent - (.Iminent.) [HKLM][64Bits] -- {973DD1DF-D51D-46BB-B6AC-D56617D133C1} =>Adware.IMBooster [HKCU\Software\UpToDown] =>PUP.UpToDown O87 - FAEL: "{6954F7D4-0269-4E96-97AF-6A0D3B62874D}" |In - Public - P6 - TRUE | .(...) -- C:\Users\CAVERNE ANIMALIERE\Downloads\SweetImSetup.exe (.not file.) =>PUP.SweetIM O87 - FAEL: "{5B611A2D-D826-47DA-BF72-C573931DE423}" |In - Public - P17 - TRUE | .(...) -- C:\Users\CAVERNE ANIMALIERE\Downloads\SweetImSetup.exe (.not file.) =>PUP.SweetIM O87 - FAEL: "{7B88CE88-BB6F-498E-B550-BFB65757648D}" |In - Public - P6 - TRUE | .(...) -- C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\dtUser.exe (.not file.) =>PUP.Datamngr O87 - FAEL: "{92D46D0B-F1A0-4D25-9B80-CF7AEBCDE414}" |In - Public - P17 - TRUE | .(...) -- C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\dtUser.exe (.not file.) =>PUP.Datamngr O87 - FAEL: "{24DCDFA1-D2C2-4C2A-BAEC-BC046D4F29C5}" |In - Public - P6 - TRUE | .(...) -- C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe (.not file.) =>Adware.RelevantKnowledge O87 - FAEL: "{53EE4A7E-7A43-4A88-A9EF-B8E58EDE738E}" |In - Public - P17 - TRUE | .(...) -- C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe (.not file.) =>Adware.RelevantKnowledge O87 - FAEL: "{32418DA8-6837-4721-AE4C-968DE101CA4C}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe (.not file.) =>Adware.RelevantKnowledge O87 - FAEL: "{2E643EDC-8D72-46DB-B917-CB08D5D128A3}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe (.not file.) =>Adware.RelevantKnowledge O87 - FAEL: "{DACB4224-0D60-4483-9F72-821083DAD1C6}" |In - None - P17 - TRUE | .(...) -- C:\Program Files (x86)\Iminent\Iminent.exe (.not file.) =>Adware.IMBooster O87 - FAEL: "{196A6CB2-0B36-4027-9314-E6FA6E0ACB1E}" |In - None - P17 - TRUE | .(...) -- C:\Program Files (x86)\Iminent\Iminent.Messengers.exe (.not file.) =>Adware.IMBooster O90 - PUC: "1EAD96AE2CB1DE84BAA9425A8CCA0817" . (.Boxore Client.) -- C:\Windows\Installer\{EA69DAE1-1BC2-48ED-AB9A-24A5C8AC8071}\boxore.ico =>Adware.Boxore O90 - PUC: "FD1DD379D15DBB646BCA5D66711D331C" . (.Iminent.) -- C:\Windows\Installer\{973DD1DF-D51D-46BB-B6AC-D56617D133C1}\imbooster.ico =>Adware.IMBooster [MD5.268B7B77A244DA029AD35FA8A82F0C7A] [WIS][25/10/2013] (.Iminent - Iminent.) -- C:\Windows\Installer\2264164.msi [1829888] =>Adware.IMBooster [MD5.CC23867AF6BCCE725BC7B957074EFE04] [WIS][06/02/2013] (.Boxore OU. - Software Update Helper.) -- C:\Windows\Installer\995fe.msi [24576] =>Adware.Boxore [MD5.E5E4443A230B8AC88E7B523ABBC5CDA9] [WIS][18/03/2013] (.Boxore OU - Boxore Client Installer.) -- C:\Windows\Installer\fd57e.msi [489984] =>Adware.Boxore [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311011137}] =>PUP.CrossRider^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{973DD1DF-D51D-46BB-B6AC-D56617D133C1}] =>Adware.IMBooster^ [HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{006E6A46-8D55-4F10-BBA8-2C9653B4278B}] =>Adware.Boxore [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9] =>Adware.MyWebSearch [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Associations]:bak_Application =>Hijacker.Agent [HKLM\Software\Classes\Installer\Features\64A6E60055D801F4BB8AC269354B72B8] =>Adware.Boxore [HKLM\Software\Classes\Installer\Products\64A6E60055D801F4BB8AC269354B72B8] =>Adware.Boxore [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\64A6E60055D801F4BB8AC269354B72B8] =>Adware.Boxore [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375] =>PUP.Tarma [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5] =>PUP.Tarma [HKLM\Software\Classes\Installer\Features\1EAD96AE2CB1DE84BAA9425A8CCA0817] =>Adware.Boxore [HKLM\Software\Classes\Installer\Products\1EAD96AE2CB1DE84BAA9425A8CCA0817] =>Adware.Boxore [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1EAD96AE2CB1DE84BAA9425A8CCA0817] =>Adware.Boxore [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F1057DD419AED0B468AD8888429E139A] =>Adware.IMBooster [HKLM\Software\Classes\CLSID\{11111111-1111-1111-1111-110311011137}] =>PUP.CrossRider [HKLM\Software\Classes\CLSID\{22222222-2222-2222-2222-220322012237}] =>PUP.CrossRider [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BA71D41F6CC0B6247B05D473850A8AEA] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] =>Adware.Boxore^ C:\Users\CAVERNE ANIMALIERE\AppData\Roaming\Mozilla\Firefox\Profiles\uqpdnicw.default\ftdownloader3@ftdownloader.com =>Adware.Downware^ [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: Modified =>Hijacker.Application^ [HKCU\Software\UpToDown] =>PUP.UpToDown^ C:\Windows\Installer\2264164.msi =>Adware.IMBooster^ C:\Windows\Installer\995fe.msi =>Adware.Boxore^ C:\Windows\Installer\fd57e.msi =>Adware.Boxore^ O4 - GS\Accessories [UpdatusUser]: Run.lnk - Clé orpheline O4 - GS\Accessories [CAVERNE ANIMALIERE]: Run.lnk - Clé orpheline O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] Clé orpheline O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] Clé orpheline [MD5.00000000000000000000000000000000] [APT] [Hoolapp For Android] (...) -- C:\Users\CAVERNE ANIMALIERE\AppData\Roaming\HOOLAP~1\UPDATE~1\UPDATE~1.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{22D6D81A-59E2-45D8-8C80-49B451BCEECF}] (...) -- C:\Users\CAVERNE ANIMALIERE\AppData\Local\Temp\wz539d\e-transactions-APIv6-Windows-ASP\E-TRANSACTIONS_600_ASP_W2003.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{45C2FF89-84B6-43AE-B02B-0A4FD0ADD6EB}] (...) -- C:\Users\CAVERNE ANIMALIERE\kit installation e transaction\e-transactions-APIv6-Windows-ASP\e-transactions-APIv6-Windows-ASP\E-TRANSACTIONS_600_ASP_W2003.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{BD58E255-4875-481B-BAF7-19E29B899751}] (...) -- C:\Users\CAVERNE ANIMALIERE\Desktop\npp.4.8.5.Installer.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{D56BC379-2642-4D43-B79E-604942B7B162}] (...) -- C:\Users\CAVERNE ANIMALIERE\Contacts\Documents\2012\site\02-2012\www\annuairess\animaleries\paiment en ligne\test a effacer\E-TRANSACTIONS_600_PLUGIN_W2003.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{39A24A95-DB2D-4BDE-9216-5AC462CF9BFD}] (...) -- D:\setup.exe (.not file.) [0] [HKLM\Software\Wow6432Node\AVAST Software] [HKCU\Software\Hoolapp] EmptyFlash FirewallRaz EmptyTemp ShortcutFix EMPTYCLSID