Script zhpfix O4 - HKCU\..\Run: [Akamai NetSession Interface] . (.Akamai Technologies, Inc. - Akamai NetSession Client.) -- C:\Users\wail\AppData\Local\Akamai\netsession_win.exe O4 - HKUS\S-1-5-21-2661446304-2415482568-1118987131-1000\..\Run: [Akamai NetSession Interface] . (.Akamai Technologies, Inc. - Akamai NetSession Client.) -- C:\Users\wail\AppData\Local\Akamai\netsession_win.exe O42 - Logiciel: Akamai NetSession Interface - (.Akamai Technologies, Inc.) [HKCU][64Bits] -- Akamai O23 - Service: COMODO Dragon Update Service (DragonUpdater) . (...) - C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe O42 - Logiciel: Comodo Dragon - (.COMODO.) [HKLM][64Bits] -- Comodo Dragon [HKCU\Software\AppDataLow\COMODO] [HKLM\Software\COMODO] [HKLM\Software\Wow6432Node\ComodoGroup] O43 - CFD: 13/04/2013 - 22:52:34 - [] ----D C:\Program Files (x86)\Comodo O43 - CFD: 13/04/2013 - 22:52:48 - [] ----D C:\Users\wail\AppData\Local\Comodo O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Comodo - Comodo Dragon.) -- C:\Program Files (x86)\Comodo\Dragon\dragon.exe SS - | Auto 24/12/2012 1868432 | (DragonUpdater) . (...) - C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified G1 - GCS: Preference [User Data\Default] http://mysearch.avg.com G2 - GCE: Preference [User Data\Default] [aaaapoomnboffjcgcebabolakmhbblbk] Ask Toolbar v.7.15.1.0 (Désactivé) =>Toolbar.Ask G2 - EXT: C:\Users\wail\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaapoomnboffjcgcebabolakmhbblbk [Ask Toolbar] =>Toolbar.Ask R0 - HKCU\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.rpidity.com =>Adware.Boxore R3 - URLSearchHook: (no name) [64Bits] - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} . (.Skype Limited - Facebook Video Calling Plugin.) (No version) -- (.not file.) O3 - Toolbar\WebBrowser: (no name) - [HKCU]{37483B40-C254-4A72-BDA4-22EE90182C1E} Clé orpheline O4 - HKLM\..\Wow6432Node\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (.not file.) O23 - Service: (vToolbarUpdater18.1.9) . (...) - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe (.not file.) =>Toolbar.AVGSearch O39 - APT: - (..) -- C:\Windows\Tasks\AVG-Secure-Search-Update_0214b_rel.job [372] =>Toolbar.AVGSearch O39 - APT: - (..) -- C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0214b_rel [372] =>Toolbar.AVGSearch O39 - APT: - (..) -- C:\Windows\Tasks\AVG-Secure-Search-Update_0214b_rmv.job [374] =>Toolbar.AVGSearch O39 - APT: - (..) -- C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0214b_rmv [374] =>Toolbar.AVGSearch O39 - APT: - (..) -- C:\Windows\Tasks\DuuquUpdateTaskMachineCore.job [880] =>PUP.Duuqu O39 - APT: - (..) -- C:\Windows\System32\Tasks\DuuquUpdateTaskMachineCore [880] =>PUP.Duuqu O39 - APT: - (..) -- C:\Windows\Tasks\DuuquUpdateTaskMachineUA.job [884] =>PUP.Duuqu O39 - APT: - (..) -- C:\Windows\System32\Tasks\DuuquUpdateTaskMachineUA [884] =>PUP.Duuqu O39 - APT: - (..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2661446304-2415482568-1118987131-1000Core.job [1070] O39 - APT: - (..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2661446304-2415482568-1118987131-1000Core [1070] O39 - APT: - (..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2661446304-2415482568-1118987131-1000UA.job [1092] O39 - APT: - (..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2661446304-2415482568-1118987131-1000UA [1092] O41 - Driver: (avgtp) . (.AVG Technologies - Pas de description.) - C:\Windows\system32\drivers\avgtpx64.sys O42 - Logiciel: Iminent - (.Iminent.) [HKLM][64Bits] -- {E931F892-098A-4C81-8DED-4013DB9E3B69} =>Adware.IMBooster O42 - Logiciel: Outil de notification de cadeaux MSN - (.Microsoft Corporation.) [HKCU][64Bits] -- {CAD9C0EB-457D-49BB-A6AD-389304C38B2A} O42 - Logiciel: searchweb - (.searchweb.) [HKLM][64Bits] -- searchweb =>Adware.SocialSkinz [HKCU\Software\AppDataLow\Software\Unity] [HKCU\Software\Avg Secure Update] [HKCU\Software\Norton] [HKCU\Software\SoulSeek] =>P2P.SoulSeek [HKCU\Software\Soulseek2] =>P2P.SoulSeek [HKCU\Software\Unity] [HKLM\Software\Symantec] [HKLM\Software\Wow6432Node\ALWIL Software] [HKLM\Software\Wow6432Node\Avg Secure Update] [HKLM\Software\Wow6432Node\Bunndle] [HKLM\Software\Wow6432Node\Norton] [HKLM\Software\Wow6432Node\Symantec] [HKLM\Software\Wow6432Node\mcafeeupdater] O43 - CFD: 28/11/2010 - 14:57:34 - [] --H-D C:\Program Files (x86)\Soulseek =>P2P.SoulSeek O43 - CFD: 28/11/2010 - 14:55:55 - [] --H-D C:\Program Files (x86)\SoulseekNS =>P2P.SoulSeek O43 - CFD: 09/03/2013 - 23:46:31 - [0] --H-D C:\Program Files (x86)\Common Files\Symantec Shared O43 - CFD: 22/01/2014 - 19:02:29 - [] ----D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 O43 - CFD: 11/03/2011 - 23:09:24 - [0] ----D C:\ProgramData\Alwil Software O43 - CFD: 28/09/2009 - 22:09:11 - [] ----D C:\ProgramData\McAfee O43 - CFD: 09/03/2013 - 23:47:13 - [] ----D C:\ProgramData\Norton O43 - CFD: 09/05/2009 - 08:37:01 - [] ----D C:\ProgramData\NortonInstaller O43 - CFD: 28/11/2010 - 14:56:28 - [0] ----D C:\ProgramData\Soulseek =>P2P.SoulSeek O43 - CFD: 23/09/2009 - 08:59:39 - [] ----D C:\ProgramData\Symantec O43 - CFD: 04/01/2012 - 18:36:50 - [] ----D C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001} O43 - CFD: 08/08/2013 - 22:22:38 - [] ----D C:\Users\wail\AppData\Roaming\WebPlayerBdd =>Adware.SocialSkinz O43 - CFD: 21/04/2014 - 20:49:01 - [] ----D C:\Users\wail\AppData\Local\AVG SafeGuard toolbar O43 - CFD: 14/06/2014 - 04:53:45 - [] ----D C:\Users\wail\AppData\Local\Conduit O43 - CFD: 22/10/2013 - 03:09:53 - [] ----D C:\Users\wail\AppData\Local\Duuqu =>PUP.Duuqu O43 - CFD: 03/02/2013 - 13:52:50 - [] ----D C:\Users\wail\AppData\Local\Symantec O43 - CFD: 04/08/2013 - 15:57:57 - [0] ----D C:\Users\wail\AppData\Local\Unity O43 - CFD: 28/11/2010 - 14:57:34 - [0] ----D C:\Users\wail\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Soulseek =>P2P.SoulSeek O43 - CFD: 28/11/2010 - 14:55:55 - [0] ----D C:\Users\wail\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Soulseek NS =>P2P.SoulSeek O44 - LFC:[MD5.68430AD3FB0FADBFA5D1677617D1E1F5] - 11/08/2014 - 23:51:35 ---A- . (.AVG Technologies - Pas de description.) -- C:\Windows\System32\Drivers\avgtpx64.sys [50976] O45 - LFCP:[MD5.64342A53D133A525C19B57442FE890EE] - 23/08/2014 - 03:28:52 ---A- - C:\Windows\Prefetch\AVG-SECURE-SEARCH-UPDATE_0214-BEFD6CB1.pf =>Toolbar.AVGSearch O45 - LFCP:[MD5.791372D0BFDC5705FD02221CC0F04D61] - 23/08/2014 - 06:11:51 ---A- - C:\Windows\Prefetch\DUUQUCRASHHANDLER.EXE-CA3B5323.pf =>PUP.Duuqu O45 - LFCP:[MD5.51CE4A4C929CF8BB64E785A937E63CA2] - 23/08/2014 - 06:14:00 ---A- - C:\Windows\Prefetch\DUUQUUPDATE.EXE-AAA01EF3.pf =>PUP.Duuqu O45 - LFCP:[MD5.3857ED591E8D1B2231D252DDC568B6B5] - 17/08/2014 - 21:39:34 ---A- - C:\Windows\Prefetch\IMINENT.EXE-239E2AD1.pf =>Adware.IMBooster O45 - LFCP:[MD5.8E929A71C92CCB1751ACED1575A6E573] - 13/08/2014 - 04:49:28 ---A- - C:\Windows\Prefetch\IMINENT.MESSENGERS.EXE-C7B6CC1B.pf =>Adware.IMBooster O53 - SMSR:HKLM\...\startupreg\Ask and Record FLV Service [Key] . (.Applian Technologies, Inc. - FLV Service for Ask and Record Toolbar.) -- C:\Program Files (x86)\Replay Media Catcher\FLVSrvc.exe O53 - SMSR:HKLM\...\startupreg\avgnt [Key] . (...) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\BlackBerryAutoUpdate [Key] . (...) -- C:\Program Files (x86)\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\ISUSPM [Key] . (...) -- C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\msnmsgr [Key] . (...) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\RoxWatchTray [Key] . (...) -- C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\SearchSettings [Key] . (...) -- C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (.not file.) =>PUP.Dealio O53 - SMSR:HKLM\...\startupreg\Setresolution [Key] . (...) -- C:\ACER\config\1366x768.cmd (.not file.) O53 - SMSR:HKLM\...\startupreg\T1358844TT4 [Key] . (...) -- C:\Windows\system32\78405478316l.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\tsnp2uvc [Key] . (...) -- C:\Windows\tsnp2uvc.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\Windows Defender [Key] . (...) -- C:\Program Files (x86)\Windows Defender\MSASCui.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\WMPNSCFG [Key] . (...) -- C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe (.not file.) =>.Microsoft Corporation O58 - SDL:11/08/2014 - 23:51:35 ---A- . (.AVG Technologies - Pas de description.) -- C:\Windows\System32\Drivers\avgtpx64.sys [50976] [MD5.C7B2DD2C0712BD5B5CFE18DC689AF81D] [SPRF][07/08/2010] (...) -- C:\Users\wail\Desktop\Softonic_France.exe [2695680] =>Toolbar.Conduit O90 - PUC: "098CCE33084C42149BB5AB630E521B02" . (.FrameFox Extensions 1.0.7.0.) -- C:\Windows\Installer\{33ECC890-C480-4124-B95B-BA36E025B120}\FrameFox.ico =>PUP.FrameFox O90 - PUC: "298F139EA89018C4D8DE0431BDE9B396" . (.Iminent.) -- C:\Windows\Installer\{E931F892-098A-4C81-8DED-4013DB9E3B69}\imbooster.ico =>Adware.IMBooster O90 - PUC: "9EE58E3C298524145B73CBBED3CAC4D3" . (.Internet Explorer Toolbar 4.6 by SweetPacks.) -- C:\Windows\Installer\{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}\ARPPRODUCTICON.exe =>PUP.SweetIM [MD5.95136A2B060F8684722435ED5C65009A] [WIS][22/10/2013] (.QwertyBox Team - FrameFox Extensions 1.0.7.0 Setup.) -- C:\Windows\Installer\25a7d11.msi [219136] =>PUP.FrameFox [MD5.7ADF6DD6FEB60B47AD4746A148F3D186] [WIS][18/08/2013] (.Iminent - Iminent.) -- C:\Windows\Installer\6b56cd.msi [1797120] =>Adware.IMBooster [HKCR\CLSID\{024BA55C-DA05-4FA5-AD24-5EA6D3C7C153}] (DuuquUpdate Update3Web) =>PUP.Duuqu [HKCR\CLSID\{486E4A9A-50F4-4DA4-9F50-363FC9F72939}] (Duuqu Update Core Class) =>PUP.Duuqu [HKCR\CLSID\{7D79AC47-48F6-40F8-BA34-17677EAEA37C}] (Duuqu.OneClickProcessLauncher) =>PUP.Duuqu [HKCR\CLSID\{9EBB6A38-FB41-458F-AC93-B5B4AEEE2C41}] (Duuqu Update Broker Class Factory) =>PUP.Duuqu [HKCR\CLSID\{B03E3833-2BAE-439D-A3E6-1AC654BECEDB}] (DuuquUpdate Update3Web) =>PUP.Duuqu [HKCR\CLSID\{B6E89C52-A6C8-4839-A5D1-28A7A5EA46D9}] (Duuqu Update Core Class) =>PUP.Duuqu [HKCR\CLSID\{B8669E7E-2C40-42DC-8BA0-314D860F5200}] (Duuqu Update Legacy On Demand) =>PUP.Duuqu [HKCR\CLSID\{D4B7651E-076D-4BB2-A021-26F6E7A59A48}] (DuuquUpdate CredentialDialog) =>PUP.Duuqu [HKCR\CLSID\{D7BEC320-B746-4A47-B289-509214980E2B}] (Duuqu Update Legacy On Demand) =>PUP.Duuqu [HKCR\CLSID\{E555444B-4EA6-4B30-A314-49C2D1BE413D}] (Duuqu Update Process Launcher Class) =>PUP.Duuqu [HKCR\CLSID\{EF0AC81C-F34C-4B2E-B85D-91E4DB1E3E9D}] (Duuqu Update Broker Class Factory) =>PUP.Duuqu SS - | Auto 10/07/1658 0 | (vToolbarUpdater18.1.9) . (...) - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.9\ToolbarUpdater.exe =>Toolbar.AVGSearch [HKLM\Software\Google\Chrome\Extensions\aaaapoomnboffjcgcebabolakmhbblbk] =>Toolbar.Ask^ [HKLM\SYSTEM\CurrentControlSet\Services\vToolbarUpdater18.1.9] =>Toolbar.AVGSearch^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E931F892-098A-4C81-8DED-4013DB9E3B69}] =>Adware.IMBooster^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Soulseek2] =>P2P.SoulSeek^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Soulseek] =>P2P.SoulSeek^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\searchweb] =>Adware.SocialSkinz^ [HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\SearchSettings] =>PUP.Dealio^ [HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{7A387452-4D16-4EB9-9E74-76CA65534E45}] =>PUP.Dealio [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Iminent] =>Adware.IMBooster [HKLM\Software\Classes\Installer\Features\EB6AF8AEEB922FA4392548F13812E50B] =>PUP.SweetIM [HKLM\Software\Classes\Installer\Products\EB6AF8AEEB922FA4392548F13812E50B] =>PUP.SweetIM [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\searchweb] =>Adware.SocialSkinz [HKLM\Software\Classes\Installer\Features\9EE58E3C298524145B73CBBED3CAC4D3] =>PUP.SweetIM [HKLM\Software\Classes\Installer\Products\9EE58E3C298524145B73CBBED3CAC4D3] =>PUP.SweetIM [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{51073A91-D8F4-4A97-8D08-CACF6E88D5B5}] =>Adware.Razoss C:\Users\wail\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaapoomnboffjcgcebabolakmhbblbk =>Toolbar.Ask^ C:\Program Files (x86)\Soulseek =>P2P.SoulSeek^ C:\Program Files (x86)\SoulseekNS =>P2P.SoulSeek^ C:\ProgramData\Soulseek =>P2P.SoulSeek^ C:\Users\wail\AppData\Roaming\WebPlayerBdd =>Adware.SocialSkinz^ C:\Users\wail\AppData\Local\Duuqu =>PUP.Duuqu^ C:\Users\wail\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Soulseek =>P2P.SoulSeek^ C:\Users\wail\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Soulseek NS =>P2P.SoulSeek^ C:\Users\wail\AppData\Local\Conduit =>Toolbar.Conduit C:\Users\wail\AppData\LocalLow\uTorrentBar_FR =>Toolbar.Conduit C:\Users\wail\AppData\LocalLow\holasearch =>Hijacker.HolaSearch C:\Users\wail\AppData\Local\Temp\uTorrentBar_FR =>Toolbar.Conduit C:\Windows\Tasks\AVG-Secure-Search-Update_0214b_rel.job =>Toolbar.AVGSearch^ C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0214b_rel =>Toolbar.AVGSearch^ C:\Windows\Tasks\AVG-Secure-Search-Update_0214b_rmv.job =>Toolbar.AVGSearch^ C:\Windows\System32\Tasks\AVG-Secure-Search-Update_0214b_rmv =>Toolbar.AVGSearch^ C:\Windows\Tasks\DuuquUpdateTaskMachineCore.job =>PUP.Duuqu^ C:\Windows\System32\Tasks\DuuquUpdateTaskMachineCore =>PUP.Duuqu^ C:\Windows\Tasks\DuuquUpdateTaskMachineUA.job =>PUP.Duuqu^ C:\Windows\System32\Tasks\DuuquUpdateTaskMachineUA =>PUP.Duuqu^ [HKCU\Software\SoulSeek] =>P2P.SoulSeek^ [HKCU\Software\Soulseek2] =>P2P.SoulSeek^ C:\Users\wail\Desktop\Softonic_France.exe =>Toolbar.Conduit^ C:\Windows\Installer\25a7d11.msi =>PUP.FrameFox^ C:\Windows\Installer\6b56cd.msi =>Adware.IMBooster^ [HKCR\CLSID\{024BA55C-DA05-4FA5-AD24-5EA6D3C7C153}] (DuuquUpdate Update3Web) =>PUP.Duuqu^ [HKCR\CLSID\{486E4A9A-50F4-4DA4-9F50-363FC9F72939}] (Duuqu Update Core Class) =>PUP.Duuqu^ [HKCR\CLSID\{7D79AC47-48F6-40F8-BA34-17677EAEA37C}] (Duuqu.OneClickProcessLauncher) =>PUP.Duuqu^ [HKCR\CLSID\{9EBB6A38-FB41-458F-AC93-B5B4AEEE2C41}] (Duuqu Update Broker Class Factory) =>PUP.Duuqu^ [HKCR\CLSID\{B03E3833-2BAE-439D-A3E6-1AC654BECEDB}] (DuuquUpdate Update3Web) =>PUP.Duuqu^ [HKCR\CLSID\{B6E89C52-A6C8-4839-A5D1-28A7A5EA46D9}] (Duuqu Update Core Class) =>PUP.Duuqu^ [HKCR\CLSID\{B8669E7E-2C40-42DC-8BA0-314D860F5200}] (Duuqu Update Legacy On Demand) =>PUP.Duuqu^ [HKCR\CLSID\{D4B7651E-076D-4BB2-A021-26F6E7A59A48}] (DuuquUpdate CredentialDialog) =>PUP.Duuqu^ [HKCR\CLSID\{D7BEC320-B746-4A47-B289-509214980E2B}] (Duuqu Update Legacy On Demand) =>PUP.Duuqu^ [HKCR\CLSID\{E555444B-4EA6-4B30-A314-49C2D1BE413D}] (Duuqu Update Process Launcher Class) =>PUP.Duuqu^ [HKCR\CLSID\{EF0AC81C-F34C-4B2E-B85D-91E4DB1E3E9D}] (Duuqu Update Broker Class Factory) =>PUP.Duuqu^ Emptytemp Emptyflash Emptyprefetch EmptyCLSID