Script ZHPFix R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchUrl,Default = http://www.google.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = http://www.google.com R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = http://www.google.com R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - E-mail Naming Shim Provider.) -- C:\Windows\system32\napinsp.dll O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - PNRP Name Space Provider.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - PNRP Name Space Provider.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll D:\mohammed\programmes\WinRAR 5.11 Final.MaZiKa2daY.CoM.BY.KhaLid\WinRAR.4.00_keygen-FFF.rar =>.Crack,Keygen O17 - HKLM\System\CCS\Services\Tcpip\..\{B5CC5F48-B720-4523-B92F-32B33002AB72}: NameServer = 62.240.110.197,62.240.110.198 O17 - HKLM\System\CS1\Services\Tcpip\..\{B5CC5F48-B720-4523-B92F-32B33002AB72}: NameServer = 62.240.110.197,62.240.110.198 [HKCU\Software\UsbFix] O51 - MPSK:{7b8d141b-6e76-11e4-8253-b82a72aa281c}\AutoRun\command. (...) -- H:\Startme.exe (.not file.) O61 - LFC: 12/18/2014 - 11:25:10 PM ---A- . (...) -- C:\Users\Mohammed Helal\AppData\Local\Temp\KMP_3.2.0.0.exe [210] O63 - Logiciel: UsbFix - (.El Desaparecido - www.usbfix.net - www.sosvirus.net.) [HKLM] -- Usbfix O4 - GS\QuickLaunch [Mohammed Helal]: QQPlayer.lnk . (.Tencent Technology Company limited - QQ Player.) -- C:\Program Files (x86)\Tencent\QQPlayer\QQPlayer.exe =>Adware.TencentAddressBar O4 - GS\Desktop [Mohammed Helal]: QQPlayer.lnk . (.Tencent Technology Company limited - QQ Player.) -- C:\Program Files (x86)\Tencent\QQPlayer\QQPlayer.exe =>Adware.TencentAddressBar [HKCU\Software\Tencent] =>Adware.TencentAddressBar [HKLM\Software\Wow6432Node\Tencent] =>Adware.TencentAddressBar O43 - CFD: 10/31/2014 - 3:59:54 AM - [] ----D C:\Program Files (x86)\Tencent =>Adware.TencentAddressBar O43 - CFD: 11/28/2014 - 5:06:37 PM - [] ----D C:\ProgramData\Tencent =>Adware.TencentAddressBar O43 - CFD: 11/28/2014 - 5:06:37 PM - [] ----D C:\Users\Mohammed Helal\AppData\Roaming\Tencent =>Adware.TencentAddressBar O43 - CFD: 11/16/2014 - 6:21:37 PM - [] ----D C:\Users\Mohammed Helal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QQPlayer O43 - CFD: 10/31/2014 - 4:00:06 AM - [] ----D C:\Users\Mohammed Helal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tencent =>Adware.TencentAddressBar O87 - FAEL: "TCP Query User{46F99BE2-1F96-4C0A-9E7C-59DAF1A619FF}C:\program files (x86)\tencent\qqplayer\qqplayer.exe" | In - Private - P6 - TRUE | .(.Tencent Technology Company limited - QQ Player.) -- C:\program files (x86)\tencent\qqplayer\qqplayer.exe =>Adware.TencentAddressBar O87 - FAEL: "UDP Query User{27D5AFA4-9689-47C6-9D10-C9F0B0D1365B}C:\program files (x86)\tencent\qqplayer\qqplayer.exe" | In - Private - P17 - TRUE | .(.Tencent Technology Company limited - QQ Player.) -- C:\program files (x86)\tencent\qqplayer\qqplayer.exe =>Adware.TencentAddressBar [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9] =>Adware.MyWebSearch [HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks]:{00000000-6E41-4FD3-8538-502F5495E5FC} =>Adware.ShopperReports C:\Program Files (x86)\Tencent =>Adware.TencentAddressBar^ C:\ProgramData\Tencent =>Adware.TencentAddressBar^ C:\Users\Mohammed Helal\AppData\Roaming\Tencent =>Adware.TencentAddressBar^ C:\Users\Mohammed Helal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tencent =>Adware.TencentAddressBar^ [HKCU\Software\Tencent] =>Adware.TencentAddressBar^ [HKLM\Software\Wow6432Node\Tencent] =>Adware.TencentAddressBar^ R3 - URLSearchHook: UrlSearchHook Class [64Bits] - {00000000-6E41-4FD3-8538-502F5495E5FC} . (...) (No version) -- C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [MD5.00000000000000000000000000000000] [APT] [Scheduled Update for Ask Toolbar] (...) -- C:\Program Files (x86)\Ask.com\UpdateTask.exe (.not file.) [0] O42 - Logiciel: Ask Toolbar - (.Ask.com.) [HKLM][64Bits] -- {86D4B82A-ABED-442A-BE86-96357B70F4FE} [HKCU\Software\AppDataLow\Software\AskToolbar] O69 - SBI: SearchScopes [HKCU] {DA4A949B-EBC0-4927-953B-34BDD032E4DD} - (Ask Search) - http://websearch.ask.com [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}] [HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}] [HKLM\Software\Wow6432Node\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}] [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}] [HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}] [HKLM\Software\Wow6432Node\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}] [HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}] [HKLM\Software\Wow6432Node\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}] [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}] [HKLM\Software\Classes\AppID\GenericAskToolbar.DLL] [HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd] [HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd.1] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF] [HKCU\Software\AppDataLow\Software\AskToolbar] [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar]:{D4027C7F-154A-4066-A1AD-4243D8127440} ShortcutFix FirewallRaz EmptyTemp EmptyFlash Proxyfix Sysrestore