Script ZHPFix O2 - BHO: Windows Live ID Sign-in Helper [64Bits] - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Bing Bar Helper [64Bits] - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} . (...) -- "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (.not file.) O2 - BHO: SkypeIEPluginBHO [64Bits] - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Skype Technologies S.A. - Skype Click to Call for Internet Explorer.) -- C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O4 - GS\Desktop [Public]: iSafe.lnk . (...) -- C:\Program Files (x86)\iSafe\iStart.exe (.not file.) O4 - HKLM\..\Run: [SpywareTerminatorShield] C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe (.not file.) O4 - HKLM\..\Run: [SpywareTerminatorUpdater] C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe (.not file.) OPT:O4 - HKLM\..\Wow6432Node\Run: [LManager] . (.Dritek System Inc. - Launch Manager.) -- C:\Program Files (x86)\Launch Manager\LManager.exe OPT:O4 - HKLM\..\Wow6432Node\Run: [SSBkgdUpdate] . (.Nuance Communications, Inc. - SSBkgdUpdate.) -- C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe OPT:O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe OPT:O4 - HKLM\..\Wow6432Node\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- c:\program files (x86)\real\realplayer\Update\realsched.exe OPT:O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe OPT:O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe OPT:O4 - HKUS\S-1-5-21-4261990016-2609222765-3407180441-1000\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe OPT:O4 - HKUS\S-1-5-21-4261990016-2609222765-3407180441-1000\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\Katerina\AppData\Local\Facebook\Update\FacebookUpdate.exe [MD5.9EB925EDC8CF1C3D06E50E9348B54A0A] [APT] [FacebookUpdateTaskUserS-1-5-21-4261990016-2609222765-3407180441-1000Core] (.Facebook Inc..) -- C:\Users\Katerina\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [MD5.9EB925EDC8CF1C3D06E50E9348B54A0A] [APT] [FacebookUpdateTaskUserS-1-5-21-4261990016-2609222765-3407180441-1000UA] (.Facebook Inc..) -- C:\Users\Katerina\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [MD5.00000000000000000000000000000000] [APT] [Norton Security Scan for Katerina] (...) -- C:\Program Files (x86)\NORTON~2\Engine\372~1.5\Nss.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [RealDownloaderDownloaderScheduledTaskS-1-5-21-4261990016-2609222765-3407180441-1000] (...) -- C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe (.not file.) [0] [MD5.12E910B6B2FEB81F859EB62ED032DB8E] [APT] [RealPlayerRealUpgradeLogonTaskS-1-5-21-4261990016-2609222765-3407180441-1000] (.RealNetworks, Inc..) -- C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [140800] [MD5.12E910B6B2FEB81F859EB62ED032DB8E] [APT] [RealPlayerRealUpgradeScheduledTaskS-1-5-21-4261990016-2609222765-3407180441-1000] (.RealNetworks, Inc..) -- C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [140800] [MD5.12E910B6B2FEB81F859EB62ED032DB8E] [APT] [RealUpgradeLogonTaskS-1-5-21-4261990016-2609222765-3407180441-1000] (.RealNetworks, Inc..) -- C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [140800] [MD5.12E910B6B2FEB81F859EB62ED032DB8E] [APT] [RealUpgradeScheduledTaskS-1-5-21-4261990016-2609222765-3407180441-1000] (.RealNetworks, Inc..) -- C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [140800] O39 - APT: FacebookUpdateTaskUserS-1-5-21-4261990016-2609222765-3407180441-1000Core - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4261990016-2609222765-3407180441-1000Core.job [1086] O39 - APT: FacebookUpdateTaskUserS-1-5-21-4261990016-2609222765-3407180441-1000Core - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4261990016-2609222765-3407180441-1000Core [1086] O39 - APT: FacebookUpdateTaskUserS-1-5-21-4261990016-2609222765-3407180441-1000UA - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4261990016-2609222765-3407180441-1000UA.job [1108] O39 - APT: FacebookUpdateTaskUserS-1-5-21-4261990016-2609222765-3407180441-1000UA - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4261990016-2609222765-3407180441-1000UA [1108] O39 - APT: Norton Security Scan for Katerina - (...) -- C:\Windows\Tasks\Norton Security Scan for Katerina.job [454] O39 - APT: Norton Security Scan for Katerina - (...) -- C:\Windows\System32\Tasks\Norton Security Scan for Katerina [454] O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM][64Bits] -- {C28D96C0-6A90-459E-A077-A6706F4EC0FC} [HKLM\Software\BrowserChoice] O43 - CFD: 7/05/2014 - 15:17:29 - [0] ----D C:\Program Files (x86)\Spyware Terminator O43 - CFD: 2/04/2012 - 12:08:13 - [] ----D C:\Program Files (x86)\Common Files\mcafee O43 - CFD: 14/05/2012 - 09:38:34 - [] ----D C:\ProgramData\McAfee O44 - LFC:[MD5.CD81F6DF96AC72F4C76ED554041BC9D7] - 23/04/2014 - 11:19:45 ---A- . (.Elex do Brasil Participações Ltda - iSafe Kernel Boot Driver.) -- C:\Windows\System32\Drivers\iSafeKrnlBoot.sys [43520] O45 - LFCP:[MD5.CCA06FEA56AC6E7616B836F3E20DE724] - 7/05/2014 - 13:27:38 ---A- - C:\Windows\Prefetch\ISAFEUPDATE.EXE-0A36CED5.pf O58 - SDL:23/04/2014 - 11:19:45 ---A- . (.Elex do Brasil Participações Ltda - iSafe Kernel Boot Driver.) -- C:\Windows\System32\Drivers\iSafeKrnlBoot.sys [43520] O61 - LFC: 5/05/2014 - 22:37:41 ---A- . (...) -- C:\Users\Katerina\AppData\Local\Temp\Quarantine.exe [386201] O69 - SBI: SearchScopes [HKCU] {5AABE080-3A6E-4D96-B428-0E9929B0B4E3} - (Ask Search) - http://websearch.ask.com O90 - PUC: "0C69D82C09A6E9540A776A07F6E40CCF" . (.Bing Bar.) -- C:\Windows\Installer\{C28D96C0-6A90-459E-A077-A6706F4EC0FC}\icon_installer_ico [MD5.C3DC5C5ADD196CD88A3F2E525B7331F7] [WIS][7/06/2011] (.Microsoft Corporation - Bing Bar.) -- C:\Windows\Installer\11068.msi [4740608] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BingBar_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\GoogleToolbarInstaller_en32_signed_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\GoogleToolbarInstaller_en32_signed_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\GoogleToolbarInstaller_updater_signed_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\GoogleToolbarInstaller_updater_signed_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\GoogleToolbarNotifier_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\GoogleToolbarNotifier_RASMANCS HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\YontooSetup-S-191C_RASAPI32 HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\YontooSetup-S-191C_RASMANCS [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}] [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C28D96C0-6A90-459E-A077-A6706F4EC0FC}] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9] [HKLM\Software\Wow6432Node\Microsoft\Tracing\BingBar_RASAPI32] [HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks]:{00000000-6E41-4FD3-8538-502F5495E5FC} C:\Windows\Installer\11068.msi C:\Users\Katerina\AppData\Local\Temp\GoogleToolbarInstaller1.log ServiceDisabled:BBSvc ServiceDisabled:BBUpdate ServiceDemand:gupdate ServiceDemand:Bonjour Service ServiceDemand:DsiWMIService ServiceDemand:RealPlayerUpdateSvc EmptyTemp EmptyPrefetch EmptyFlash EmptyCLSID FirewallRAZ SysRestore