Script ZHPFix R0 - HKCU\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 0 R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 O3 - Toolbar: avast! Online Security - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} . (...) -- (.not file.) O3 - Toolbar: (no name) - [HKLM]{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} Chiave orfano OPT:O4 - HKLM\..\Wow6432Node\Run: [PosService] . (.PLauncher - PLauncher.) -- C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe OPT:O23 - Service: Pos Service (PowerOffer Service) . (.PowerOfferService - PowerOfferService.) - C:\Users\DF\AppData\Local\PosService\Pos.exe [MD5.9EB925EDC8CF1C3D06E50E9348B54A0A] [APT] [FacebookUpdateTaskUserS-1-5-21-1286336489-1028466569-3393745925-1000Core] (.Facebook Inc..) -- C:\Users\DF\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [MD5.9EB925EDC8CF1C3D06E50E9348B54A0A] [APT] [FacebookUpdateTaskUserS-1-5-21-1286336489-1028466569-3393745925-1000UA] (.Facebook Inc..) -- C:\Users\DF\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [MD5.00000000000000000000000000000000] [APT] [PenWes] (...) -- C:\Program Files (x86)\PenWes\penwes.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{6B1BE8BC-71A0-48DE-973C-68B9A829824F}] (...) -- C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\uninstbb.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{8303A961-0F15-4B49-8C3B-22A1E6BD4332}] (...) -- C:\Users\DF\Desktop\file-repair-setup.exe (.not file.) [0] O39 - APT: FacebookUpdateTaskUserS-1-5-21-1286336489-1028466569-3393745925-1000Core - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1286336489-1028466569-3393745925-1000Core.job [1062] O39 - APT: FacebookUpdateTaskUserS-1-5-21-1286336489-1028466569-3393745925-1000Core - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1286336489-1028466569-3393745925-1000Core [1062] O39 - APT: FacebookUpdateTaskUserS-1-5-21-1286336489-1028466569-3393745925-1000UA - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1286336489-1028466569-3393745925-1000UA.job [1084] O39 - APT: FacebookUpdateTaskUserS-1-5-21-1286336489-1028466569-3393745925-1000UA - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1286336489-1028466569-3393745925-1000UA [1084] O42 - Logiciel: Adobe Flash Player 13 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX O42 - Logiciel: Adobe Flash Player 13 Plugin - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player Plugin O42 - Logiciel: Expresso - (...) [HKLM][64Bits] -- ZTEWireless-101_is1 O42 - Logiciel: Java 7 Update 45 - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83217045FF} O42 - Logiciel: babylon - (...) [HKLM][64Bits] -- Poker Club by Lottomatica O43 - CFD: 18/09/2012 - 11:50:24 - [] ----D C:\Program Files (x86)\Bing Bar Installer O43 - CFD: 17/04/2013 - 22:40:29 - [] ----D C:\Program Files (x86)\MyPcCleaner O43 - CFD: 29/05/2012 - 18:57:21 - [] ----D C:\Program Files (x86)\RegCleaner O43 - CFD: 02/07/2014 - 11:45:08 - [] ----D C:\Program Files (x86)\Spybot - Search & Destroy 2 O43 - CFD: 02/07/2014 - 11:44:00 - [] ----D C:\ProgramData\Spybot - Search & Destroy O51 - MPSK:{0d698062-91dc-11e1-bf91-001e101f8aaa}\AutoRun\command. (.No owner - AutoRun.) -- E:\AutoRun.exe O51 - MPSK:{1963c667-a64c-11e1-b83f-90004e96c305}\AutoRun\command. (.No owner - AutoRun.) -- E:\AutoRun.exe O51 - MPSK:{35aba244-00c4-11e4-972f-001e101f859f}\AutoRun\command. (.No owner - AutoRun.) -- E:\AutoRun.exe O51 - MPSK:{3de3ab39-bba6-11e2-a6bd-001e101fa1f5}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) O51 - MPSK:{84235574-9517-11e1-beb3-90004e96c305}\AutoRun\command. (.No owner - AutoRun.) -- E:\AutoRun.exe O51 - MPSK:{aa1cd3eb-98e8-11e1-b964-001e101f1838}\AutoRun\command. (.No owner - AutoRun.) -- E:\AutoRun.exe O51 - MPSK:{c60237e8-3575-11e2-a3ec-90004e96c305}\AutoRun\command. (.No owner - AutoRun.) -- E:\AutoRun.exe O51 - MPSK:{c6023811-3575-11e2-a3ec-90004e96c305}\AutoRun\command. (.No owner - AutoRun.) -- E:\AutoRun.exe O51 - MPSK:{d03a4939-02cf-11e4-a3d6-90004e96c305}\AutoRun\command. (.No owner - AutoRun.) -- E:\AutoRun.exe O51 - MPSK:{db757e4d-5a73-11e3-ba2e-90004e96c305}\AutoRun\command. (.No owner - AutoRun.) -- E:\AutoRun.exe O51 - MPSK:{e1b46963-92ad-11e1-be9b-001e101fabdd}\AutoRun\command. (.No owner - AutoRun.) -- E:\AutoRun.exe O51 - MPSK:{e6307c96-9225-11e1-ac33-90004e96c305}\AutoRun\command. (.No owner - AutoRun.) -- E:\AutoRun.exe O51 - MPSK:{f3b3a6b8-3a17-11e2-bb74-90004e96c305}\AutoRun\command. (.No owner - AutoRun.) -- E:\AutoRun.exe O51 - MPSK:{f3b3a6cc-3a17-11e2-bb74-90004e96c305}\AutoRun\command. (.No owner - AutoRun.) -- E:\AutoRun.exe O51 - MPSK:{ff6922b5-5d03-11e3-9e91-001e101f2b52}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\Browser Infrastructure Helper [Key] . (...) -- C:\Users\DF\AppData\Local\Smartbar\Application\QuickShare.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\IminentMessenger [Key] . (...) -- C:\Program Files (x86)\Iminent\Iminent.Messengers.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\WebCake Desktop [Key] . (...) -- C:\Users\DF\AppData\Roaming\WebCake\WebCakeDesktop.exe (.not file.) OPT:O53 - SMSR:HKLM\...\startupreg\QuickTime Task [Key] . (...) -- C:\Program Files (x86)\QuickTime\QTTask.exe (.not file.) O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1 O61 - LFC: 01/07/2014 - 20:52:57 ---A- . (.Safer-Networking Ltd..) -- C:\Users\DF\Downloads\spybot-2-2.exe [40658208] O61 - LFC: 02/07/2014 - 20:52:54 ---A- . (...) -- C:\Users\DF\AppData\Local\Temp\BackupSetup.exe [5464192] O61 - LFC: 03/07/2014 - 20:52:54 ---A- . (...) -- C:\Users\DF\AppData\Local\Temp\utt27CC.tmp.bat [53] [MD5.A672E4C77ED7CCC851575B10B46CC8AD] [WIS][29/09/2012] (.IMinent - IMinent Toolbar.) -- C:\Windows\Installer\73bc1b.msi [1019392] HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32 HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS HKLM\SOFTWARE\Microsoft\Tracing\PutLockerDownloader_RASAPI32 HKLM\SOFTWARE\Microsoft\Tracing\PutLockerDownloader_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\1ClickDownloader_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\1ClickDownloader_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\freeTVRadio-setup_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\freeTVRadio-setup_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\freetvradio_air_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\freetvradio_air_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\freeTVRadio_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\freeTVRadio_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\IminentSetup0208_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\IminentSetup0208_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\IminentSetup_2-KFRPtAWP-1__RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\IminentSetup_2-KFRPtAWP-1__RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SmartbarExeInstaller_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SmartbarExeInstaller_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateKozaka_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateKozaka_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\uTorrent_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\uTorrent_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\YontooSetup-S-15A0_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\YontooSetup-S-15A0_RASMANCS [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Poker Club by Lottomatica] [HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\Browser Infrastructure Helper] [HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\IminentMessenger] [HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\WebCake Desktop] [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D6533F74-218B-41BE-9D91-5BD471FECFFD}] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\482AA67AD25E6E74E9F48BD5FBE8533C] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\64B074831FB9EA045A886FDAD6C1D224] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9] [HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\HssSrv] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\DD88652BF1EEEB64B992F3561AF84F13] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\09540C6B8D1C56740B0E1E1861657AE0] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\15333F6466A3A1646B590E204B1C8794] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1B812BD0725DF36459D5BA985C9193C4] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2514EB7147619DA498D025C07B3421DD] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5FEF7DA1D0B6BAF4BA3AE8699FE83E55] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\73962F57F2FA32C43A431C9C05459330] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B63FC54A3B9D36449AD536B3C29D2A97] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C512D8DDA7F6553429ACE05EC3197DAB] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB8D24CD0A6EC784AA4C95D1CE0898C8] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E3B47C0B22C8D004B86CB646D46C357E] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2] C:\Program Files (x86)\Bing Bar Installer C:\Windows\Installer\73bc1b.msi ServiceStop:PowerOffer Service ServiceDisabled:PowerOffer Service ServiceDemand:ServUpdate EmptyTemp EmptyPrefetch EmptyFlash EmptyCLSID FirewallRAZ ProxyFix SysRestore