Script ZHPFix [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified O2 - BHO: Browser Guard BHO [64Bits] - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} . (.Threat Expert Ltd. - Browser Defender Toolbar.) -- C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll O2 - BHO: (no name) [64Bits] - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline O2 - BHO: avast! Online Security [64Bits] - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} Clé orpheline O3 - Toolbar: avast! Online Security - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} . (...) -- (.not file.) O3 - Toolbar\WebBrowser: (no name) - [HKCU]{21FA44EF-376D-4D53-9B0F-8A89D3229068} Clé orpheline O3 - Toolbar\WebBrowser: (no name) - [HKCU]{D3028143-6145-4318-99D3-3EDCE54A95A9} Clé orpheline [MD5.00000000000000000000000000000000] [APT] [avast! Emergency Update] (...) -- C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{467883C8-37B4-43DC-AAB4-A580DEF326CA}] (...) -- C:\Program Files\Alwil Software\Avast5\aswRundll.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{F948E23E-801A-4995-875A-9FEBB7372A36}] (...) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe (.not file.) [0] O41 - Driver: ({9edd0ea8-2819-47c2-8320-b007d5996f8a}w64) . (.StdLib - StdLib.) - C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}w64.sys O42 - Logiciel: Tube Dimmer - (.Creative Island Media, LLC.) [HKLM][64Bits] -- TubeDimmer O42 - Logiciel: VisualBee for Microsoft PowerPoint - (.VisualBee.com.) [HKCU][64Bits] -- VisualBee for Microsoft PowerPoint [HKCU\Software\BearShare] [HKCU\Software\Iminent Browser] [HKCU\Software\MCAFEE] [HKLM\Software\Wow6432Node\BearShare] [HKLM\Software\Wow6432Node\PCTools] [HKLM\Software\Wow6432Node\VBMZ] O43 - CFD: 03/06/2014 - 21:25:10 - [] ----D C:\Program Files (x86)\GetNowUpdater O43 - CFD: 24/12/2013 - 20:31:44 - [] ----D C:\Program Files (x86)\PC Tools O43 - CFD: 19/01/2014 - 17:15:12 - [] ----D C:\Program Files (x86)\Common Files\PC Tools O44 - LFC:[MD5.5545FB5B49268C903F311849DB1942ED] - 04/06/2014 - 18:55:37 ---A- . (.AVAST Software - avast! self protection module.) -- C:\Windows\System32\Drivers\obfozrtk.sys [423240] O45 - LFCP:[MD5.D878B59643C7F5038FCB365EED341DA6] - 03/06/2014 - 20:40:04 ---A- - C:\Windows\Prefetch\DATAMNGRCOORDINATOR.EXE-953D8A61.pf O45 - LFCP:[MD5.B9D73A21375AF309115B054E4F3955F5] - 06/06/2014 - 06:34:42 ---A- - C:\Windows\Prefetch\DATAMNGRUI.EXE-D6BCB7D3.pf O53 - SMSR:HKLM\...\startupreg\mobilegeni daemon [Key] . (...) -- C:\Program Files (x86)\Mobogenie\DaemonProcess.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\Setwallpaper [Key] . (...) -- c:\programdata\SetWallpaper.cmd (.not file.) O53 - SMSR:HKLM\...\startupreg\Updater [Key] . (...) -- C:\ProgramData\Updater\Updater.exe (.not file.) O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 O58 - SDL:16/05/2014 - 12:49:41 ---A- . (...) -- C:\Windows\System32\Drivers\aswHwid.sys [29208] O58 - SDL:24/04/2014 - 13:06:26 ---A- . (.StdLib - StdLib.) -- C:\Windows\System32\Drivers\wStLibG64.sys [61120] O58 - SDL:12/05/2014 - 15:40:58 ---A- . (.StdLib - StdLib.) -- C:\Windows\System32\Drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}w64.sys [61112] O58 - SDL:24/04/2014 - 11:25:04 ---A- . (.StdLib - StdLib.) -- C:\Windows\System32\Drivers\{b99c8534-7800-48fa-bd71-519a46cdc7e1}w64.sys [61120] O61 - LFC: 05/06/2014 - 12:53:03 ---A- . (...) -- C:\Users\annick\AppData\Local\Temp\Quarantine.exe [384139] O64 - Services: CurCS - 12/05/2014 - C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}w64.sys ({9edd0ea8-2819-47c2-8320-b007d5996f8a}w64) .(.StdLib - StdLib.) - LEGACY_{9EDD0EA8-2819-47C2-8320-B007D5996F8A}W64 [MD5.90E1D86D979B92738A47D7072CB22DA8] [SPRF][07/07/2010] (...) -- C:\ProgramData\FullRemove.exe [131472] HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32 HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BetterInstaller_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BetterInstaller_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BingBar_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BingBar_RASDLG HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\GoogleToolbarNotifier_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateFindRight_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateFindRight_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\vbmz10_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\vbmz10_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\VisualBeeSilent_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\VisualBeeSilent_RASMANCS [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}] [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\TubeDimmer] [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\VisualBee for Microsoft PowerPoint] [HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\mobilegeni daemon] [HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\Updater] [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C9A6357B-25CC-4BCF-96C1-78736985D412}] [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C9A6357B-25CC-4BCF-96C1-78736985D412}] [HKLM\Software\Wow6432Node\Microsoft\Tracing\BingBar_RASAPI32] [HKLM\Software\Wow6432Node\VBMZ] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\464AA55239C100F32AF2D438EDDC0F47] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5652BA3D5FB98AE31B337BF0AF939856] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EB95E1AFCBABE3DB9ECCC669B99494] C:\Program Files (x86)\GetNowUpdater [HKCU\Software\BearShare] [HKCU\Software\Iminent Browser] [HKLM\Software\Wow6432Node\BearShare] C:\Users\annick\AppData\Local\Temp\OB.exe EmptyTemp EmptyPrefetch EmptyFlash EmptyCLSID FirewallRAZ ProxyFix IFEOFix SysRestore