Script ZHPFix M3 - MFPP: Plugins - [DOS167] -- C:\Program Files\Mozilla FireFox\searchplugins\mystarttb.xml =>Spyware.VMNToolbar O3 - Toolbar: (no name) - [HKLM]{0BF43445-2F28-4351-9252-17FE6E806AA0} Clé orpheline O3 - Toolbar\WebBrowser: (no name) - [HKCU]{21FA44EF-376D-4D53-9B0F-8A89D3229068} Clé orpheline O23 - Service: (vToolbarUpdater17.2.0) . (...) - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe (.not file.) =>Toolbar.AVGSearch [MD5.00000000000000000000000000000000] [APT] [{6025CF64-5922-4CDC-B1E7-8F874F277E84}] (...) -- C:\Users\DOS167\Local Settings\Application Data\Bundled software uninstaller\biSetup61840.exe (.not file.) [0] =>Adware.MegaSearch [MD5.00000000000000000000000000000000] [APT] [{B16E4F35-D344-4E69-90C3-6751503502A9}] (...) -- C:\bureau\ZHPhep.exe (.not file.) [0] O69 - SBI: SearchScopes [HKCU] {9BB47C17-9C68-4BB3-B188-DD9AF0FD2412} - (Search Results) - http://dts.search-results.com =>PUP.SearchResults [MD5.4027E144748FD3463DCA96B83690D409] [SPRF][25/11/2013] (.Iminent - Iminent Setup.) -- C:\Users\DOS167\AppData\Local\Temp\0_Offer_1.exe [2092328] =>Adware.IMBooster [MD5.61CC93290064721BB856F89D00E156B4] [SPRF][25/11/2013] (.Iminent - Iminent Setup.) -- C:\Users\DOS167\AppData\Local\Temp\1_Offer_6.exe [2090816] =>Adware.IMBooster [MD5.2F5252E50745E47DB355B005725DAE05] [SPRF][25/11/2013] (.Somoto Ltd. - AppsHat Mobile Apps.) -- C:\Users\DOS167\AppData\Local\Temp\appshat-distribution.exe [327880] =>Adware.MegaSearch [MD5.B28C334C03CEE7C5E829C43AE75DAE5A] [SPRF][28/01/2013] (.Ask.com - AskIC Dynamic Link Library.) -- C:\Users\DOS167\AppData\Local\Temp\AskSLib.dll [248008] [MD5.E8C9FB54231A61068E8B154F00E0A4E5] [SPRF][09/08/2012] (.Boxore OU. - Setup.) -- C:\Users\DOS167\AppData\Local\Temp\boxore.exe [569768] =>Adware.Boxore [MD5.34E4DA7E4D32B4DC5153D1CEDB6E5F08] [SPRF][26/09/2012] (.Conduit - Pas de description.) -- C:\Users\DOS167\AppData\Local\Temp\conduitinstaller.exe [210816] =>Adware.Bloson [MD5.0BF369C8765A03092F0337D80BA519C6] [SPRF][29/03/2012] (.Babylon Ltd. - Babylon Client Setup.) -- C:\Users\DOS167\AppData\Local\Temp\MyBabylonTB.exe [862832] =>PUP.Babylon [MD5.C67BCF6441E378371F0D6EEFB7EF0861] [SPRF][31/10/2013] (.Conduit - SP Usage Sender.) -- C:\Users\DOS167\AppData\Local\Temp\nsaF07F.exe [167812] =>Toolbar.Conduit [MD5.C67BCF6441E378371F0D6EEFB7EF0861] [SPRF][31/10/2013] (.Conduit - SP Usage Sender.) -- C:\Users\DOS167\AppData\Local\Temp\nsaF3DA.exe [167812] =>Toolbar.Conduit [MD5.C67BCF6441E378371F0D6EEFB7EF0861] [SPRF][31/10/2013] (.Conduit - SP Usage Sender.) -- C:\Users\DOS167\AppData\Local\Temp\nsaF783.exe [167812] =>Toolbar.Conduit [MD5.C67BCF6441E378371F0D6EEFB7EF0861] [SPRF][31/10/2013] (.Conduit - SP Usage Sender.) -- C:\Users\DOS167\AppData\Local\Temp\nsc50F4.exe [167812] =>Toolbar.Conduit [MD5.C67BCF6441E378371F0D6EEFB7EF0861] [SPRF][31/10/2013] (.Conduit - SP Usage Sender.) -- C:\Users\DOS167\AppData\Local\Temp\nsf9CD1.exe [167812] =>Toolbar.Conduit [MD5.C67BCF6441E378371F0D6EEFB7EF0861] [SPRF][31/10/2013] (.Conduit - SP Usage Sender.) -- C:\Users\DOS167\AppData\Local\Temp\nsfA386.exe [167812] =>Toolbar.Conduit [MD5.C67BCF6441E378371F0D6EEFB7EF0861] [SPRF][31/10/2013] (.Conduit - SP Usage Sender.) -- C:\Users\DOS167\AppData\Local\Temp\nsvA78D.exe [167812] =>Toolbar.Conduit [MD5.BF37D51443D85CC77F14F9AC7B06917D] [SPRF][25/11/2013] (...) -- C:\Users\DOS167\AppData\Local\Temp\OptimizerPro.exe [6665808] =>PUP.OptimizerPro [MD5.9FB9D49C2DB7EDD1084AB765D619F5C6] [SPRF][21/10/2013] (.Conduit - Search Protect by conduit.) -- C:\Users\DOS167\AppData\Local\Temp\SearchProtectINT.exe [66368] =>Toolbar.Conduit [MD5.10B773A2DCC3CAC3C09CAFE38E7B9399] [SPRF][25/11/2013] (.Skytech Co., Ltd. - Skytech Downloader.) -- C:\Users\DOS167\AppData\Local\Temp\smt_do-search_201311131701.exe [454808] =>PUP.DoSearches [MD5.F3A10836603E03A28CAF404B29328F92] [SPRF][07/04/2013] (.Babylon Ltd. - Uninstaller Application.) -- C:\Users\DOS167\AppData\Local\Temp\uninst1.exe [394320] =>PUP.Babylon [MD5.EF7D1863F4980AB0C8BDA142FEE67F92] [SPRF][25/11/2013] (.Somoto Ltd. - FilesFrog Update Checker.) -- C:\Users\DOS167\AppData\Local\Temp\UpdateCheckerSetup.exe [200072] =>Adware.MegaSearch O87 - FAEL: "TCP Query User{6FCED5E8-271A-4DBF-BD04-8A271E151140}C:\users\dos167\appdata\roaming\cacaoweb\cacaoweb.exe" |In - Private - P6 - TRUE | .(...) -- C:\users\dos167\appdata\roaming\cacaoweb\cacaoweb.exe (.not file.) =>PUP.CacaoWeb O87 - FAEL: "UDP Query User{1A2F8085-2737-4E12-B066-F9BFE17D49F5}C:\users\dos167\appdata\roaming\cacaoweb\cacaoweb.exe" |In - Private - P17 - TRUE | .(...) -- C:\users\dos167\appdata\roaming\cacaoweb\cacaoweb.exe (.not file.) =>PUP.CacaoWeb O87 - FAEL: "UDP Query User{4E87506F-4E41-4CA7-BDC2-D9AEB1FF93B5}C:\program files\aresmod\aresmod.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files\aresmod\aresmod.exe (.not file.) O87 - FAEL: "TCP Query User{44D76985-25E3-465F-9560-D6364D6A6775}C:\users\dos167\appdata\roaming\cacaoweb\cacaoweb.exe" |In - Public - P6 - TRUE | .(...) -- C:\users\dos167\appdata\roaming\cacaoweb\cacaoweb.exe (.not file.) =>PUP.CacaoWeb O87 - FAEL: "UDP Query User{335ABA23-B17A-4EC5-8466-0873A45DB5BA}C:\users\dos167\appdata\roaming\cacaoweb\cacaoweb.exe" |In - Public - P17 - TRUE | .(...) -- C:\users\dos167\appdata\roaming\cacaoweb\cacaoweb.exe (.not file.) =>PUP.CacaoWeb O87 - FAEL: "{0E890323-1FD3-4633-A79A-294EFA13A1C4}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files\mystarttb\ToolbarCleaner.exe (.not file.) =>Spyware.VMNToolbar O87 - FAEL: "{A43D4768-A082-4540-9B85-7DAD5012AD83}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files\mystarttb\ToolbarCleaner.exe (.not file.) =>Spyware.VMNToolbar [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011441179}] =>PUP.CrossRider [HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2412}] =>Adware.Bandoo^ [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:fst_fr_35 =>PUA.FSTfr9^ C:\ProgramData\Software =>Adware.Boxore C:\Users\DOS167\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndkhncnongaclekkbelchmeafffimifj =>Adware.VidSaver C:\Users\DOS167\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp =>Toolbar.Wajam C:\Users\DOS167\AppData\Local\Temp\0_Offer_1.exe =>Adware.IMBooster^ C:\Users\DOS167\AppData\Local\Temp\1_Offer_6.exe =>Adware.IMBooster^ C:\Users\DOS167\AppData\Local\Temp\appshat-distribution.exe =>Adware.MegaSearch^ C:\Users\DOS167\AppData\Local\Temp\boxore.exe =>Adware.Boxore^ C:\Users\DOS167\AppData\Local\Temp\conduitinstaller.exe =>Adware.Bloson^ C:\Users\DOS167\AppData\Local\Temp\MyBabylonTB.exe =>PUP.Babylon^ C:\Users\DOS167\AppData\Local\Temp\nsaF07F.exe =>Toolbar.Conduit^ C:\Users\DOS167\AppData\Local\Temp\nsaF3DA.exe =>Toolbar.Conduit^ C:\Users\DOS167\AppData\Local\Temp\nsaF783.exe =>Toolbar.Conduit^ C:\Users\DOS167\AppData\Local\Temp\nsc50F4.exe =>Toolbar.Conduit^ C:\Users\DOS167\AppData\Local\Temp\nsf9CD1.exe =>Toolbar.Conduit^ C:\Users\DOS167\AppData\Local\Temp\nsfA386.exe =>Toolbar.Conduit^ C:\Users\DOS167\AppData\Local\Temp\nsvA78D.exe =>Toolbar.Conduit^ C:\Users\DOS167\AppData\Local\Temp\OptimizerPro.exe =>PUP.OptimizerPro^ C:\Users\DOS167\AppData\Local\Temp\SearchProtectINT.exe =>Toolbar.Conduit^ C:\Users\DOS167\AppData\Local\Temp\smt_do-search_201311131701.exe =>PUP.DoSearches^ C:\Users\DOS167\AppData\Local\Temp\uninst1.exe =>PUP.Babylon^ C:\Users\DOS167\AppData\Local\Temp\UpdateCheckerSetup.exe =>Adware.MegaSearch^ C:\Users\DOS167\AppData\Local\Temp\GoogleToolbarInstaller1.log =>PUP.Babylon C:\Users\DOS167\AppData\Local\Temp\GoogleToolbarInstaller2.log =>PUP.Babylon FirewallRaz EmptyFlash Emptytemp ShortcutFix