Script ZHPFix R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.yac.mx/?utm_source=b&utm_medium=iSafe&from=iSafe&uid=st750lm022xhn-m750mbb_s2y1j9ada00977 =>Trojan.Staser R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://search.yac.mx/?utm_source=b&utm_medium=iSafe&from=iSafe&uid=st750lm022xhn-m750mbb_s2y1j9ada00977 =>Trojan.Staser R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.yac.mx/?utm_source=b&utm_medium=isafe&from=isafe&uid=st750lm022xhn-m750mbb_s2y1j9ada00977 =>Trojan.Staser R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.yac.mx/?utm_source=b&utm_medium=isafe&from=isafe&uid=st750lm022xhn-m750mbb_s2y1j9ada00977 =>Trojan.Staser O4 - HKLM\..\Wow6432Node\Run: [fst_fr_135] Clé orpheline =>PUA.FSTfr9 [HKCU\Software\Reimage] =>Rogue.ReimageRepair [HKLM\Software\LevelQualityWatcher] =>PUP.LevelQualityWatcher [HKLM\Software\Reimage] =>Rogue.ReimageRepair O43 - CFD: 02/04/2014 - 17:26:34 - [0] ----D C:\Users\Lysie\AppData\Local\Software O44 - LFC:[MD5.ADB6D8FC167ADD268A63F2F3CF0E13BA] - 02/04/2014 - 19:47:38 ---A- . (...) -- C:\Windows\Reimage.ini [163] =>Rogue.ReimageRepair O45 - LFCP:[MD5.E2F4C2B1BD4F80580F3558C0C1B1EA16] - 02/04/2014 - 07:56:02 ---A- - C:\Windows\Prefetch\SPYHUNTER-INSTALLER (1).EXE-196FE677.pf =>Crapware.SpyHunter O45 - LFCP:[MD5.90A02D2FBF244726008B5F3D0C2347B8] - 02/04/2014 - 07:56:55 ---A- - C:\Windows\Prefetch\SPYHUNTER-INSTALLER.EXE-84675E35.pf =>Crapware.SpyHunter O45 - LFCP:[MD5.D756D2EBC5A35C7280EAD11493B6A8D4] - 02/04/2014 - 13:52:27 ---A- - C:\Windows\Prefetch\SPYHUNTER-INSTALLER (3).EXE-E454C8F1.pf =>Crapware.SpyHunter O45 - LFCP:[MD5.06092AAFEC1A5B06DFB5103610F19A1E] - 02/04/2014 - 13:54:25 ---A- - C:\Windows\Prefetch\PRICEPEEP_EN_0303-A419CB8D.EX-6983A024.pf =>Adware.PricePeep O45 - LFCP:[MD5.2CFF4D96B182B96C13A284E4E1915BFF] - 02/04/2014 - 18:48:15 ---A- - C:\Windows\Prefetch\REIMAGE.EXE-BEE43FC1.pf =>Rogue.ReimageRepair O45 - LFCP:[MD5.A90207FC49CEBEA0576971964DD42FAC] - 02/04/2014 - 19:47:49 ---A- - C:\Windows\Prefetch\REIMAGEREPAIR.EXE-2492A54D.pf =>Rogue.ReimageRepair O45 - LFCP:[MD5.E97C22776DD267495D4DB2732DE4D78C] - 03/04/2014 - 07:24:08 ---A- - C:\Windows\Prefetch\BU_.EXE-49DB8802.pf O45 - LFCP:[MD5.00DD8E5AE0B0806FCE0EDD3381CB1BE6] - 05/04/2014 - 14:49:35 ---A- - C:\Windows\Prefetch\ISAFESCAN.EXE-BEDBDBDC.pf =>Trojan.Staser O45 - LFCP:[MD5.26DB8B84A7F64A1739DF869077B58B13] - 05/04/2014 - 16:48:52 ---A- - C:\Windows\Prefetch\ISAFETRAY.EXE-F929161B.pf =>Trojan.Staser O45 - LFCP:[MD5.979B41FE42233AFB842A646B8148B60C] - 05/04/2014 - 17:11:22 ---A- - C:\Windows\Prefetch\ISAFE.EXE-A6C8B403.pf =>Trojan.Staser O61 - LFC: 08/04/2014 - 18:09:01 ---A- . (...) -- C:\Users\Lysie\AppData\Local\Temp\aa71bd8a-fbf8-4cad-a155-dfdd7831a107\bin\Fortunitas\info.html [3054] =>PUP.Fortunitas O61 - LFC: 08/04/2014 - 18:09:01 ---A- . (...) -- C:\Users\Lysie\AppData\Local\Temp\aa71bd8a-fbf8-4cad-a155-dfdd7831a107\temp\Fortunitasinfo.dfe [840] =>PUP.Fortunitas HKLM\\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32 =>PUP.AdvancedSystemProtector HKLM\\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS =>PUP.AdvancedSystemProtector [HKCU\Software\Reimage] =>Rogue.ReimageRepair [HKLM\Software\Reimage] =>Rogue.ReimageRepair [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] =>Adware.Boxore^ [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:fst_fr_135 =>PUA.FSTfr9^ C:\Users\Lysie\AppData\Local\Software =>Adware.Boxore [HKLM\Software\LevelQualityWatcher] =>PUP.LevelQualityWatcher^ C:\Windows\Reimage.ini =>Rogue.ReimageRepair FirewallRaz PROXYFix EmptyTemp EmptyFlash EmptyClsid