Script zhpfix [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified M0 - MFSP: prefs.js [Mellie - 1kh8nlow.default-1398591810859] http://www.bing.com [MD5.00000000000000000000000000000000] [APT] [wp_update] (...) -- C:\Users\Mellie\AppData\Roaming\~smaxxob.exe (.not file.) [0] =>PUP.WpManager [MD5.00000000000000000000000000000000] [APT] [{26E1F6DF-5E6A-465A-84D3-A6AFB06CA927}] (...) -- E:\setup.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{2D2972BA-EA5C-4EFA-BDCC-22DF724EC542}] (...) -- C:\Users\Mellie\Downloads\PVMsetup.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{355B6E47-49D5-496D-9A69-6F99139864EA}] (...) -- C:\Users\Mellie\Desktop\Guitar Pro 5\Logiciel\Guitar Pro_5.2.0&Add-Ons\Guitar Pro_5.2.0\setup.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{4BF5DD34-6DF2-47FB-B90B-3710F40D6C33}] (...) -- C:\Program Files (x86)\InstallShield Installation Information\{2FFE93F0-BB72-4E52-8761-354D1AAA9387}\ISAdmin.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{5485FBDF-4E23-41E2-A62A-C725C730E558}] (...) -- C:\Program Files (x86)\SOFTON~1\UNWISE.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{88E48C45-D0F4-4F54-AFF9-EF6523E4CB84}] (...) -- C:\Program Files (x86)\InstallShield Installation Information\{F0FDF9C9-1DDC-401F-B638-36F1CAE8A875}\setup.exe (.not file.) [0] O43 - CFD: 04/06/2013 - 21:21:22 - [0] ----D C:\ProgramData\Babylon =>PUP.Babylon O51 - MPSK:{9d983d8c-fb68-11e1-bd13-90e6ba5869fa}\AutoRun\command. (...) -- G:\unlock.exe (.not file.) O69 - SBI: SearchScopes [HKCU] ${searchCLSID} - (@ieframe.dll,-12512) - http://search.live.com O69 - SBI: SearchScopes [HKCU] {A5811EAF-6180-472B-80B3-BBEA4BE7B258} - (Yahoo!) - http://fr.search.yahoo.com [MD5.B67811645C5A3B8E4E4B1A1DB1EE271C] [WIS][20/09/2012] (.Boxore OU. - Software Update Helper.) -- C:\Windows\Installer\28dd4.msi [45056] =>Adware.Boxore HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FindRight_RASAPI32 =>Hijacker.FindrToolbar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FindRight_RASMANCS =>Hijacker.FindrToolbar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateFindRight_RASAPI32 =>Hijacker.FindrToolbar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateFindRight_RASMANCS =>Hijacker.FindrToolbar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\utilFindRight_RASAPI32 =>Hijacker.FindrToolbar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\utilFindRight_RASMANCS =>Hijacker.FindrToolbar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\widestream6_air_RASAPI32 =>Adware.SPointer HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\widestream6_air_RASMANCS =>Adware.SPointer [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\BA086F2D38A8E1A47912955A68B3AD24] =>Adware.PredictAd [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\64A6E60055D801F4BB8AC269354B72B8] =>Adware.Boxore [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] =>Adware.Boxore^ C:\ProgramData\Babylon =>PUP.Babylon^ C:\Windows\Installer\28dd4.msi =>Adware.Boxore^ C:\Users\Mellie\Downloads\cacaoweb.exe =>PUP.CacaoWeb Emptytemp Emptyflash