Script ZHPFix EmptyPrefetch FirewallRaz PROXYFix EmptyTemp EmptyFlash EmptyClsid SysRestore O17 - HKLM\System\CCS\Services\Tcpip\..\{E353C95E-1DC4-4630-AA7C-83915ED82F73}: DhcpDomain = mobile.lan O17 - HKLM\System\CS1\Services\Tcpip\..\{E353C95E-1DC4-4630-AA7C-83915ED82F73}: DhcpDomain = mobile.lan G0 - GCSP: Preference [User Data\Default][StartupURLs] http://www.google.fr/", "http://websearch.calcitapp.info/ =>PUP.CalcitApp [MD5.00000000000000000000000000000000] [APT] [{9A1E6970-FCF2-4188-9CA8-5DAB1D459E02}] (...) -- C:\Users\Mathilde\AppData\Local\WebPlayer\uninstall.exe (.not file.) [0] [HKLM\Software\Reimage] =>Rogue.ReimageRepair O43 - CFD: 07/08/2014 - 14:33:35 - [] ----D C:\Users\Mathilde\AppData\Local\com O43 - CFD: 31/08/2014 - 09:38:25 - [] ----D C:\Users\Mathilde\AppData\Local\somotoimeshmoviestoolbar =>PUP.iMesh O44 - LFC:[MD5.E6A74A350B513634748D2B38E7146AAE] - 11/09/2014 - 16:12:45 ---A- . (...) -- C:\Windows\Reimage.ini [137] =>Rogue.ReimageRepair O45 - LFCP:[MD5.30454D208485383FE620314EAD27443C] - 11/09/2014 - 16:12:58 ---A- - C:\Windows\Prefetch\REIMAGE.EXE-7B15761E.pf =>Rogue.ReimageRepair O45 - LFCP:[MD5.89C1E5731865C2B77E950FA88D3A1415] - 21/09/2014 - 06:13:09 ---A- - C:\Windows\Prefetch\SHSETUP.EXE-D980DFDC.pf =>Crapware.SpyHunter O45 - LFCP:[MD5.1B6CBB394D8543AAEDB68B772B14EFE1] - 21/09/2014 - 08:03:39 ---A- - C:\Windows\Prefetch\SPYHUNTER-INSTALLER.EXE-086FC764.pf =>Crapware.SpyHunter O45 - LFCP:[MD5.DCD56C0DB491FE1535B109D0CB7BB47D] - 25/09/2014 - 14:51:24 ---A- - C:\Windows\Prefetch\TOOLBAR CLEANER UNINSTALL.EXE-71520BB9.pf =>PUP.ToolbarCleaner O61 - LFC: 21/09/2014 - 10:49:55 ---A- . (.Enigma Software Group USA, LLC..) -- C:\Users\Mathilde\Downloads\SpyHunter-Installer.exe [728960] =>Crapware.SpyHunter O61 - LFC: 24/09/2014 - 10:49:55 ---A- . (.Enigma Software Group USA, LLC..) -- C:\Users\Mathilde\Downloads\SpyHunter-Installer (1).exe [728960] =>Crapware.SpyHunter HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32 =>PUP.MyPCBackup HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS =>PUP.MyPCBackup HKLM\SOFTWARE\Microsoft\Tracing\NewPlayerUpdater_RASAPI32 =>Adware.NewPlayer HKLM\SOFTWARE\Microsoft\Tracing\NewPlayerUpdater_RASMANCS =>Adware.NewPlayer [HKCR\CLSID\{D3A3949C-AD85-E0C5-67E5-2CFE65AE2A6A}] (dealsteR) =>PUP.DealSter [HKLM\Software\Reimage] =>Rogue.ReimageRepair C:\Users\Mathilde\AppData\Local\somotoimeshmoviestoolbar =>PUP.iMesh^ [HKCR\CLSID\{D3A3949C-AD85-E0C5-67E5-2CFE65AE2A6A}] (dealsteR) =>PUP.DealSter^ C:\Windows\Reimage.ini =>Rogue.ReimageRepair [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1 [HKCU\Software\AppDataLow\Software\adawaretb] O44 - LFC:[MD5.72561F19D9A072B9B78F2642E6E638EC] - 24/09/2014 - 14:18:32 ---A- . (...) -- C:\prefs.js [61] [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6c97a91e-4524-4019-86af-2aa2d567bf5c}] [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6c97a91e-4524-4019-86af-2aa2d567bf5c}] [HKLM\Software\Classes\CLSID\{6c97a91e-4524-4019-86af-2aa2d567bf5c}] [HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6c97a91e-4524-4019-86af-2aa2d567bf5c}] [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6c97a91e-4524-4019-86af-2aa2d567bf5c}] [HKCU\Software\AppDataLow\Software\adawaretb] Ad-Aware Antivirus v11.3.6321.0 Ad-Aware Browsing Protection v1.0.1.124 O4 - HKLM\..\Run: [AdAwareTray] . (...) -- C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareTray.exe O23 - Service: Ad-Aware Service 11 (LavasoftAdAwareService11) . (...) - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareService.exe Ad-Aware Antivirus v11.3.6321.0 Ad-Aware Browsing Protection v1.0.1.124 Spybot - Search & Destroy v2.4.40 O4 - HKLM\..\Run: [AdAwareTray] . (...) -- C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareTray.exe O23 - Service: McAfee Application Installer Cleanup (0039311411223654) (0039311411223654mcinstcleanup) . (...) - C:\Windows\TEMP\003931~1.exe (.not file.) O23 - Service: Ad-Aware Service 11 (LavasoftAdAwareService11) . (...) - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareService.exe O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) . (.Safer-Networking Ltd. - Spybot-S&D 2 Scanner Service.) - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) . (.Safer-Networking Ltd. - Spybot-S&D 2 Background update service.) - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) . (.Safer-Networking Ltd. - Windows Security Center integration..) - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [MD5.00000000000000000000000000000000] [APT] [temp_2992df36-0b37-4ab0-a71d-5e2740c5bb28-2] (...) -- C:\Users\Mathilde\AppData\Local\Temp\nsx6EDD.tmp\2992df36-0b37-4ab0-a71d-5e2740c5bb28-2.exe (.not file.) [0] [MD5.9CCE733E5262FB92C2331E8578512B49] [APT] [Check for updates] (.Safer-Networking Ltd..) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [4747720] [MD5.48FAE038F51676A795CEFAD780448D94] [APT] [Refresh immunization] (.Safer-Networking Ltd..) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [4460472] [MD5.280C014187E24860A7C860329513208F] [APT] [Scan the system] (.Safer-Networking Ltd..) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [4818848] O42 - Logiciel: Ad-Aware Antivirus - (.Lavasoft.) [HKLM][64Bits] -- {E39A80AE-0CC0-43EE-AB6B-BE11DC4F969F}_AdAwareUpdater O42 - Logiciel: AdAwareInstaller - (.Lavasoft.) [HKLM][64Bits] -- {0851BE65-294B-4BBA-8A0D-C1320DCBBCA3} O42 - Logiciel: AdAwareUpdater - (.Lavasoft.) [HKLM][64Bits] -- {E39A80AE-0CC0-43EE-AB6B-BE11DC4F969F} O42 - Logiciel: Spybot - Search & Destroy - (.Safer-Networking Ltd..) [HKLM][64Bits] -- {B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1 [HKCU\Software\AppDataLow\Software\adawarebp] [HKLM\Software\Wow6432Node\PCTools] O43 - CFD: 21/09/2014 - 04:52:50 - [] ----D C:\Program Files (x86)\Spybot - Search & Destroy 2 O43 - CFD: 21/09/2014 - 06:57:45 - [] ----D C:\ProgramData\Spybot - Search & Destroy O43 - CFD: 07/08/2014 - 14:50:26 - [0] ----D C:\Users\Mathilde\AppData\Local\PackageStaging O44 - LFC:[MD5.82446D358A9FB51CB9DA32A5C901D7A0] - 21/09/2014 - 03:43:47 ---A- . (.Safer Networking Limited - Pas de description.) -- C:\Windows\System32\sdnclean64.exe [21040] O44 - LFC:[MD5.FA8C639CB22DC7DDFA861372746A54F7] - 25/09/2014 - 14:16:03 ---A- . (...) -- C:\Ad-Report-SCAN[1].txt [1666] O47 - AAKE:Key Export SP - "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [Enabled] .(.Safer-Networking Ltd..) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe O47 - AAKE:Key Export SP - "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" [Enabled] .(.Safer-Networking Ltd..) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe O47 - AAKE:Key Export SP - "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" [Enabled] .(.Safer-Networking Ltd..) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe O47 - AAKE:Key Export SP - "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" [Enabled] .(.Safer-Networking Ltd..) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe O61 - LFC: 21/09/2014 - 10:49:52 ----- . (.Java Native Access (JNA).) -- C:\Users\Mathilde\AppData\Local\Temp\jna-366216204\jna3007672328284713491.dll [198144] O61 - LFC: 21/09/2014 - 10:49:52 ---A- . (...) -- C:\Users\Mathilde\AppData\Local\Temp\13055781037028086177.exe [773693] O61 - LFC: 21/09/2014 - 10:49:52 ---A- . (...) -- C:\Users\Mathilde\AppData\Local\Temp\PC Tools Download Manager\DownloadManagerAPI.dll [475136] O61 - LFC: 21/09/2014 - 10:49:52 ---A- . (...) -- C:\Users\Mathilde\AppData\Local\Temp\PC Tools Download Manager\DownloadManagerWrapper.dll [120832] O61 - LFC: 21/09/2014 - 10:49:52 ---A- . (.AppWork GmbH.) -- C:\Users\Mathilde\AppData\Local\Temp\130557810173661071.exe [79696] O61 - LFC: 21/09/2014 - 10:49:52 ---A- . (.Microsoft Corporation.) -- C:\Users\Mathilde\AppData\Local\Temp\is-15LFK.tmp\_isetup\_shfoldr.dll [23312] O61 - LFC: 21/09/2014 - 10:49:52 ---A- . (.Microsoft Corporation.) -- C:\Users\Mathilde\AppData\Local\Temp\is-GK7U2.tmp\_isetup\_shfoldr.dll [23312] O61 - LFC: 21/09/2014 - 10:49:53 ----- . (...) -- C:\Users\Mathilde\AppData\Local\Temp\proxy_vole7059243574688938428.dll [40448] O61 - LFC: 21/09/2014 - 10:49:53 ---A- . (...) -- C:\Users\Mathilde\AppData\Local\Temp\PC Tools Download Manager\InstallWrapper.dll [138240] O61 - LFC: 21/09/2014 - 10:49:53 ---A- . (...) -- C:\Users\Mathilde\AppData\Local\Temp\PC Tools Download Manager\PCTUI.dll [407040] O61 - LFC: 21/09/2014 - 10:49:53 ---A- . (...) -- C:\Users\Mathilde\AppData\Local\Temp\PC Tools Download Manager\pctcc.exe [154584] O61 - LFC: 21/09/2014 - 10:49:53 ---A- . (.PC Tools.) -- C:\Users\Mathilde\AppData\Local\Temp\PC Tools Download Manager\InnoHelpers.dll [1135944] O61 - LFC: 21/09/2014 - 10:49:53 ---A- . (.PC Tools.) -- C:\Users\Mathilde\AppData\Local\Temp\PC Tools Download Manager\InnoSelfProtect.dll [519128] O61 - LFC: 21/09/2014 - 10:49:53 ---A- . (.PC Tools.) -- C:\Users\Mathilde\AppData\Local\Temp\PC Tools Download Manager\lang\English.dll [345088] O61 - LFC: 21/09/2014 - 10:49:53 ---A- . (.PC Tools.) -- C:\Users\Mathilde\AppData\Local\Temp\PC Tools Download Manager\lang\FRENCH.dll [50688] O61 - LFC: 21/09/2014 - 10:49:53 ---A- . (.Terra Informatica Software, Inc., British C.) -- C:\Users\Mathilde\AppData\Local\Temp\PC Tools Download Manager\htmlayout.dll [915456] O61 - LFC: 21/09/2014 - 10:49:53 ---A- . (.Terra Informatica Software, Inc..) -- C:\Users\Mathilde\AppData\Local\Temp\PC Tools Download Manager\tiscript.dll [618496] O61 - LFC: 24/09/2014 - 10:49:52 ---A- . (...) -- C:\Users\Mathilde\AppData\Local\Temp\ded18f20-78c8-42be-b763-6464b5fd1c7c\AdAwareWebInstaller.exe [2808192] O61 - LFC: 24/09/2014 - 10:49:52 ---A- . (.Lavasoft.) -- C:\Users\Mathilde\AppData\Local\Temp\dce8ef71-6ac8-4ca5-bf86-8cd00467bea9.exe [4947328] O61 - LFC: 24/09/2014 - 10:49:52 ---A- . (.Microsoft Corporation.) -- C:\Users\Mathilde\AppData\Local\Temp\is-3FSQJ.tmp\_isetup\_shfoldr.dll [23312] O61 - LFC: 24/09/2014 - 10:49:52 ---A- . (.Microsoft Corporation.) -- C:\Users\Mathilde\AppData\Local\Temp\is-7F17O.tmp\_isetup\_shfoldr.dll [23312] O61 - LFC: 24/09/2014 - 10:49:52 ---A- . (.Microsoft Corporation.) -- C:\Users\Mathilde\AppData\Local\Temp\is-8EJGE.tmp\_isetup\_shfoldr.dll [23312] O61 - LFC: 24/09/2014 - 10:49:52 ---A- . (.Microsoft Corporation.) -- C:\Users\Mathilde\AppData\Local\Temp\is-Q897M.tmp\_isetup\_shfoldr.dll [23312] O61 - LFC: 24/09/2014 - 10:49:54 ---A- . (...) -- C:\Users\Mathilde\Downloads\ad-aware-free-antivirus_11-3_fr_12797.exe [1728896] SR - | Auto 27/08/2014 706864 | (LavasoftAdAwareService11) . (...) - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.3.6321.0\AdAwareService.exe SR - | Auto 24/06/2014 1738168 | (SDScannerService) . (.Safer-Networking Ltd..) - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe SR - | Auto 27/06/2014 2088408 | (SDUpdateService) . (.Safer-Networking Ltd..) - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe SR - | Auto 25/04/2014 171928 | (SDWSCService) . (.Safer-Networking Ltd..) - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe O61 - LFC: 22/09/2014 - 10:49:51 ---A- . (.GalaSoft Laurent Bugnion @ http://www.galas.) -- C:\Users\Mathilde\AppData\Local\Packages\M6Web.M6_ewak77gqn492e\AC\Microsoft\CLR_v4.0\NativeImages\GalaSoft.Mv2ad623d6#\231641e7b78d622bf93c012f339849b8\GalaSoft.MvvmLight.Win8.ni.dll [193536]