Script ZHPFix [MD5.50536335D8C6E7CFCE2F3E93FFF57E6E] - (.Bandoo Media Inc. - Datamngr Coordinator.) -- C:\Program Files\Movies Toolbar\Datamngr\DatamngrCoordinator.exe [3445248] [PID.2008] =>PUP.Datamngr [MD5.13AA3C457294711EC1484277759CF251] - (.Bandoo Media Inc. - Data Manager.) -- C:\Program Files\Movies Toolbar\Datamngr\DatamngrUI.exe [3605504] [PID.820] =>PUP.Datamngr O2 - BHO: Movies Toolbar (Dist. by Bandoo Media, Inc.) - {3d86a75b-cb6b-4764-885d-ca6336f04ba2} . (.No owner - dtx Dynamic Link Library.) -- C:\Program Files\Movies Toolbar\Datamngr\SRTOOL~2\IE\searchresultsDx.dll =>PUP.Datamngr O3 - Toolbar: Movies Toolbar (Dist. by Bandoo Media, Inc.) - [HKLM]{3d86a75b-cb6b-4764-885d-ca6336f04ba2} . (.No owner - dtx Dynamic Link Library.) -- C:\Program Files\Movies Toolbar\Datamngr\SRTOOL~2\IE\searchresultsDx.dll =>PUP.Datamngr O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -- Orphan key O14 - IERESET.INF: SAFESITE_VALUE=SAFESITE_VALUE="ie.search.msn.com" O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} . (.Microsoft Corporation - Shell Browser UI Library.) -- C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Browseui preloader - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Shell Browser UI Library.) -- C:\WINDOWS\system32\browseui.dll O24 - Desktop Component 0: الصفحة الرئيسية الحالية - file:About:Home O24 - Desktop General: BackupWallPaper - .(...) - C:\Documents and Settings\نائل\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop General: WallPaper - .(...) - C:\Documents and Settings\نائل\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O36 - AppCertDlls: (x64) . (...) -- c:\program files\movies toolbar\datamngr\x64\apcrtldr.dll =>PUP.Datamngr O36 - AppCertDlls: (x86) . (...) -- C:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll =>PUP.Datamngr [HKCU\Software\Datamngr] =>PUP.Datamngr [HKCU\Software\Softonic] =>Toolbar.Conduit [HKLM\Software\Datamngr] =>PUP.Datamngr O43 - CFD: 24/12/2013 - 12:50:55 م - [21.310] ----D C:\Program Files\Movies Toolbar =>PUP.MoviesToolbar O43 - CFD: 31/01/2014 - 12:59:44 م - [0] ----D C:\Documents and Settings\All Users\Application Data\Babylon =>PUP.Babylon O43 - CFD: 01/02/2014 - 09:47:10 م - [0.010] ----D C:\Documents and Settings\All Users\Application Data\Datamngr =>PUP.Datamngr O43 - CFD: 31/01/2014 - 12:59:44 م - [0.003] ----D C:\Documents and Settings\نائل\Application Data\Babylon =>PUP.Babylon O43 - CFD: 24/12/2013 - 01:38:05 م - [0] ----D C:\Documents and Settings\نائل\Application Data\searchresultstb =>PUP.SearchResults O43 - CFD: 31/01/2014 - 12:59:45 م - [0.004] ----D C:\Documents and Settings\نائل\Local Settings\Application Data\Babylon =>PUP.Babylon O43 - CFD: 24/12/2013 - 12:48:31 م - [0.003] ----D C:\Documents and Settings\نائل\Local Settings\Application Data\iLivid =>Adware.Bandoo O47 - AAKE:Key Export SP - "C:\Program Files\Movies Toolbar\Datamngr\SRTOOL~1\IE\dtUser.exe" [Enabled] .(.APN LLC.) -- C:\Program Files\Movies Toolbar\Datamngr\SRTOOL~1\IE\dtUser.exe =>PUP.Datamngr O47 - AAKE:Key Export SP - "C:\Program Files\Movies Toolbar\Datamngr\SRTOOL~2\IE\dtUser.exe" [Enabled] .(.APN LLC.) -- C:\Program Files\Movies Toolbar\Datamngr\SRTOOL~2\IE\dtUser.exe =>PUP.Datamngr O50 - IFEO:Image File Execution Options - bitguard.exe - tasklist.exe =>PUP.BitGuard O50 - IFEO:Image File Execution Options - browserdefender.exe - tasklist.exe =>Hijacker.Eazel O50 - IFEO:Image File Execution Options - browserprotect.exe - tasklist.exe =>Hijacker.Eazel O50 - IFEO:Image File Execution Options - browsersafeguard.exe - tasklist.exe =>PUP.BrowserSafeguard O50 - IFEO:Image File Execution Options - protectedsearch.exe - tasklist.exe =>Spyware.ProtectedSearch O51 - MPSK:{6a58e2a6-67fd-11e3-b4db-000e50eb09cb}\AutoRun\command. (...) -- I:\HWPcAssistant.exe (.not file.) O51 - MPSK:{6a58e2a7-67fd-11e3-b4db-000e50eb09cb}\AutoRun\command. (...) -- I:\HWPcAssistant.exe (.not file.) O64 - Services: CurCS - 05/12/2013 - C:\Program Files\Movies Toolbar\Datamngr\DatamngrCoordinator.exe (DatamngrCoordinator) .(.Bandoo Media Inc. - Datamngr Coordinator.) - LEGACY_DATAMNGRCOORDINATOR =>PUP.Datamngr O69 - SBI: SearchScopes [HKCU] {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} - (Ask.com) - http://dts.search.ask.com SR - | Auto 05/12/2013 3445248 | (DatamngrCoordinator) . (.Bandoo Media Inc..) - C:\Program Files\Movies Toolbar\Datamngr\DatamngrCoordinator.exe =>PUP.Datamngr [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3D86A75B-CB6B-4764-885D-CA6336F04BA2}] =>PUP.Datamngr^ [HKLM\SYSTEM\CurrentControlSet\Services\DatamngrCoordinator] =>PUP.Datamngr^ [HKLM\Software\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}] =>Adware.Bandoo [HKLM\Software\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}] =>Adware.Bandoo [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] =>Adware.Bandoo [HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}] =>Adware.Bandoo [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}] =>Adware.Bandoo [HKLM\Software\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}] =>Adware.Bandoo [HKLM\Software\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}] =>Adware.Bandoo [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}] =>Toolbar.Ask&Record [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}] =>Toolbar.Ask&Record [HKLM\Software\Classes\SearchQUIEHelper.DNSGuard] =>Adware.Bandoo [HKLM\Software\Classes\SearchQUIEHelper.DNSGuard.1] =>Adware.Bandoo [HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\HssSrv] =>Toolbar.Agent [HKCU\Software\APN DTX] =>Toolbar.Ask [HKCU\Software\DataMngr] =>Adware.Bandoo [HKLM\Software\DataMngr] =>Adware.Bandoo [HKCU\Software\Softonic] =>Toolbar.Conduit [HKLM\Software\Classes\Prod.cap] =>PUP.Babylon [HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{3d86a75b-cb6b-4764-885d-ca6336f04ba2} =>PUP.Datamngr^ C:\Program Files\Movies Toolbar =>PUP.MoviesToolbar^ C:\Documents and Settings\All Users\Application Data\Babylon =>PUP.Babylon^ C:\Documents and Settings\All Users\Application Data\Datamngr =>PUP.Datamngr^ C:\Documents and Settings\نائل\Application Data\Babylon =>PUP.Babylon^ C:\Documents and Settings\نائل\Application Data\searchresultstb =>PUP.SearchResults^ C:\Documents and Settings\نائل\Local Settings\Application Data\Babylon =>PUP.Babylon^ C:\Documents and Settings\نائل\Local Settings\Application Data\iLivid =>Adware.Bandoo^ C:\Program Files\Movies Toolbar\Datamngr\DatamngrCoordinator.exe =>PUP.Datamngr^ C:\Program Files\Movies Toolbar\Datamngr\DatamngrUI.exe =>PUP.Datamngr^ [HKCU\Software\Datamngr] =>PUP.Datamngr^ [HKLM\Software\Datamngr] =>PUP.Datamngr^ EmptyCLSID ShortcutFix FirewallRaz EmptyTemp EmptyFlash Proxyfix Sysrestore