Script ZHPFix O38 - TASK: {0350709F-5D5D-45F3-964F-357BB0435AD9} [64Bits][\{E19B3841-4A59-4602-97F2-1B450277427A}] - (...) -- C:\Program Files\Alwil Software\Avast5\aswRunDll.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan O38 - TASK: {03E76411-8AB0-4DE4-A3EB-2E8458635C52} [64Bits][\AVAST Software\Avast settings backup] - (...) -- C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan O38 - TASK: {0837D897-84CB-4E30-A8DD-807937A81DFC} [64Bits][\Microsoft\Windows\Media Center\mcupdate] - (...) -- C:\Windows\ehome\mcupdate (.not file.) [0] (.Orphan.) =>.SUP.Orphan O38 - TASK: {0B7A57A4-4061-4299-9C53-A8785E101A2D} [64Bits][\{772947B0-4C90-4BD0-AE26-1E1771B21AD4}] - (...) -- C:\Program Files (x86)\Skype\Phone\Skype.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan O38 - TASK: {11B6ECEC-2471-4B88-B874-B0082133B198} [64Bits][\avastBCLRestartS-1-5-21-3860743412-3194615298-1054303145-1000] - (...) -- C:\Users\jjosette\AppData\Local\Google\Chrome\Application\chrome.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan O38 - TASK: {13AF45CA-F4D3-4E2C-A8E7-D2F15F2A431D} [64Bits][\GoogleUpdateTaskUserS-1-5-21-3860743412-3194615298-1054303145-1000Core] - (...) -- C:\Users\jjosette\AppData\Local\Google\Update\GoogleUpdate.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan O38 - TASK: {1698EEB4-1E9C-4185-A863-DD9002684230} [64Bits][\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3860743412-3194615298-1054303145-1000] - (.Alcatel Lucent - .) -- C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan O38 - TASK: {1BAA195E-B936-4CD2-AD0D-EA6D4295F31D} [64Bits][\{07472856-CD51-47A0-BB71-349B05CBF2E9}] - (...) -- C:\Program Files (x86)\Skype\Phone\Skype.exe (.not file.) [0] (.Orphan.)ASUSTeK =>.SUP.Orphan O38 - TASK: {206F2F8D-D518-49A9-AEA7-104681C38A7D} [64Bits][\{EE3953DF-8F57-48B5-8875-7E22714C6523}] - (...) -- C:\Program Files (x86)\Skype\Phone\Skype.exe (.not file.) [0] (.Orphan.)ASUSTeK =>.SUP.Orphan O38 - TASK: {2213383F-56C3-42A1-826A-1F00576CB151} [64Bits][\{5645E34C-7DE6-4408-85B1-23198AD65D79}] - (...) -- C:\Program Files (x86)\Skype\Phone\Skype.exe (.not file.) [0] (.Orphan.)ASUSTeK =>.SUP.Orphan O38 - TASK: {2663EE71-3E4D-4E4E-8D1D-A25ECBE7492B} [64Bits][\Google Updater and Installer] - (...) -- C:\Users\jjosette\AppData\Local\Google\Update\GoogleUpdate.exe (.not file.) [0] (.Orphan.)ASUSTeK =>.SUP.Orphan O38 - TASK: {27DD0FAA-DCA3-434D-81A2-1EB65B56FC30} [64Bits][\{EA6F7536-4BB9-49FF-80F5-FDB9B92A57E8}] - (...) -- C:\Users\jjosette\AppData\Local\Google\Chrome\Application\chrome.exe (.not file.) [0] (.Orphan.)ASUSTeK =>.SUP.Orphan O38 - TASK: {3D6419B9-4859-4F38-A9A7-A3A955ED1482} [64Bits][\{2E3C8D56-AFA5-4F0A-A9F0-D02D23524D47}] - (...) -- E:\EPSETUP.EXE (.not file.) [0] (.Orphan.)ASUSTeK =>.SUP.Orphan O38 - TASK: {40F8CB1D-9FDC-4C7A-94E5-78D4B58ACB1B} [64Bits][\GoogleUpdateTaskUserS-1-5-21-3860743412-3194615298-1054303145-1000UA] - (...) -- C:\Users\jjosette\AppData\Local\Google\Update\GoogleUpdate.exe (.not file.) [0] (.Orphan.)ASUSTeK =>.SUP.Orphan O38 - TASK: {4A3A51C7-8611-4E4F-996F-5FB22618E0F8} [64Bits][\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3860743412-3194615298-1054303145-1000] - (.Alcatel Lucent - .) -- C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe (.not file.) [0] (.Orphan.)ASUSTeK =>.SUP.Orphan O38 - TASK: {F1AAEBC9-1E79-4278-A7DF-0B3D7A24425C} [64Bits][\{1D3CCC8B-78CB-4C03-85D1-01BAC8D741F2}] - (...) -- C:\Program Files (x86)\Skype\Phone\Skype.exe (.not file.) [0] (.Orphan.)ASUSTeK =>.SUP.Orphan O38 - TASK: {F33E2BB5-B8DB-4A16-B90B-6B2DC8763BFC} [64Bits][\RealPlayerRealUpgradeLogonTaskS-1-5-21-3860743412-3194615298-1054303145-1000] - (.Alcatel Lucent - .) -- C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe (.not file.) [0] (.Orphan.)ASUSTeK =>.SUP.Orphan O38 - TASK: {F4611864-F9ED-4FCB-81CE-44D5D66268B9} [64Bits][\{DD63CF49-B734-4B17-B1E0-754E860DEDDD}] - (...) -- C:\Users\jjosette\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CNFGYYI8\wlsetup-web[1].exe (.not file.) [0] (.Orphan.)ASUSTeK =>.SUP.Orphan O38 - TASK: {FC95AFFB-A506-46AC-A76E-BA95E0C80966} [64Bits][\{7F572418-D059-4A77-A0C7-737215FCCD54}] - (...) -- C:\Users\jjosette\Documents\Kelkoo_Fr_Toolbar\klkofrt.exe (.not file.) [0] (.Orphan.)ASUSTeK =>.SUP.Orphan O38 - TASK: {FD7B9720-B04A-4201-A6CD-6C7043703387} [64Bits][\Microsoft\Windows\Media Center\mcupdate_scheduled] - (...) -- C:\Windows\ehome\mcupdate (.not file.) [0] (.Orphan.)ASUSTeK =>.SUP.Orphan O38 - TASK: {DD548504-31EE-43FF-A573-1E9BCB56DC76} [64Bits][\Microsoft\Windows\Media Center\RecordingRestart] - (...) -- C:\Windows\ehome\ehrec (.not file.) [0] (.Orphan.)ASUSTeK =>.SUP.Orphan O38 - TASK: {E573638B-6FED-4ED9-90A8-2AD73D1CAEB4} [64Bits][\Programme de mise à jour en ligne de Adobe] - (...) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (.not file.) [0] (.Orphan.)ASUSTeK =>.SUP.Orphan O4 - HKCU\..\Run: [GoogleDriveSync] . (. - .) -- --restore-last-session =>.SUP.Orphan O4 - HKCU\..\RunOnce: [Uninstall C:\Users\jjosette\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64] . (. - .) -- C:\Users\jjosette\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64 (.Not File.) =>.SUP.Orphan O4 - HKCU\..\RunOnce: [Uninstall C:\Users\jjosette\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] . (. - .) -- C:\Users\jjosette\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64 (.Not File.) =>.SUP.Orphan 04 - HKUS\S-1-5-21-3860743412-3194615298-1054303145-1000\..\Run: [GoogleDriveSync] . (. - .) -- --restore-last-session =>.SUP.Orphan O4 - HKUS\S-1-5-21-3860743412-3194615298-1054303145-1000\..\RunOnce: [Uninstall C:\Users\jjosette\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64] . (. - .) -- C:\Users\jjosette\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64 (.Not File.) =>.SUP.Orphan O4 - HKUS\S-1-5-21-3860743412-3194615298-1054303145-1000\..\RunOnce: [Uninstall C:\Users\jjosette\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] . (. - .) -- C:\Users\jjosette\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64 (.Not File.) =>.SUP.Orphan G2 - GCE: Preference [jjosette][User Data\Default] [lameokaalbmnhgapanlloeichlbjloak] Search Manager =>.SUP.SearchManager O2 - BHO: Top Affaires [64Bits] - {2E5630C2-CF58-43c8-85E6-31BDE8300D9C} . (...) -- c:\NP\ie\64\TopAffairesTB.dll (.not file.) O3 - Toolbar: 0xE3EFEB7F196B494398D2FFB09D4B49CA00B7030000 - [HKCU]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} . (...) -- (.not file.) O3 - Toolbar: Kelkoo France Toolbar - [HKLM]{52DE91C6-8F53-4989-BE4A-90F1CAA0B48A} . (...) -- (.not file.) O42 - Logiciel: McAfee Security Scan Plus - (.McAfee, Inc..) [HKLM][64Bits] -- McAfee Security Scan =>.McAfee, Inc. O42 - Logiciel: PCSpeedUp - (.www.pcspeedup.com.) [HKCU][64Bits] -- 1229842944.www.pcspeedup.com HKLM\SOFTWARE\McAfee =>.McAfee Inc. HKLM\SOFTWARE\McAfee.com =>.McAfee Inc. HKLM\SOFTWARE\mcafeeupdater =>.McAfee Inc. HKLM\SOFTWARE\Symantec =>.Symantec HKLM\SOFTWARE\WOW6432Node\McAfee =>.McAfee Inc. HKLM\SOFTWARE\WOW6432Node\McAfee.com =>.McAfee Inc. HKLM\SOFTWARE\WOW6432Node\mcafeeupdater =>.McAfee Inc. HKLM\SOFTWARE\WOW6432Node\Symantec =>.Symantec HKCU\SOFTWARE\Chromium =>.Chromium HKCU\SOFTWARE\MCAFEE =>.McAfee Inc HKCU\SOFTWARE\Simple Star =>.SUP.SimpleStar HKCU\SOFTWARE\Smpv9 =>.SUP.SimpleMP HKCU\SOFTWARE\AppDataLow\Software\Smartbar =>Adware.QuickShare O43 - CFD: 08/03/2017 - [] D -- C:\ProgramData\McAfee =>.McAfee O43 - CFD: 20/07/2013 - [] D -- C:\ProgramData\Norton =>.Symantec Corporation O43 - CFD: 20/07/2013 - [] D -- C:\ProgramData\NortonInstaller =>.Symantec O43 - CFD: 20/07/2013 - [] D -- C:\ProgramData\Symantec =>.Symantec O43 - CFD: 20/07/2013 - [0] D -- C:\Program Files (x86)\Common Files\Symantec Shared =>.Symantec Corporation O43 - CFD: 13/11/2014 - [] D -- C:\Users\jjosette\AppData\Roaming\AdvancedSystemProtector =>PUP.Optional.AdvancedSystemProtector O43 - CFD: 16/03/2016 - [0] D -- C:\Users\jjosette\AppData\Roaming\Simple Star =>.SUP.SimpleStar O43 - CFD: 26/08/2017 - [] D -- C:\Users\jjosette\AppData\Local\chromium =>.Chromium O43 - CFD: 16/03/2013 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\McAfee =>.McAfee O53 - SMSR:HKLM\...\startupreg\Adobe Reader Speed Launcher [Key] [64Bits] . (...) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\ArcSoft Connection Service [Key] [64Bits] . (...) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\ExtraFilmHemmaAgent [Key] [64Bits] . (...) -- C:\Users\jjosette\Extrafilm FotoFacil\Agent.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\Google Update [Key] [64Bits] . (...) -- C:\Users\jjosette\AppData\Local\Google\Update\GoogleUpdate.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\MarineAquarium3Free_57 Browser Plugin Loader 64 [Key] [64Bits] . (...) -- C:\Program Files (x86)\MarineAquarium3Free_57\bar\1.bin\57brmon64.exe (.not file.) =>PUP.Optional.MarineAquarium O53 - SMSR:HKLM\...\startupreg\msnmsgr [Key] [64Bits] . (...) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (.not file.) O53 - SMSR:HKLM\...\startupreg\Setwallpaper [Key] [64Bits] . (...) -- c:\programdata\SetWallpaper.cmd (.not file.) O58 - SDL:2012/07/29 14:49:47 A . (.Kaspersky Lab, GERT - Kaspersky Lab Mini Driver.) -- C:\Windows\System32\drivers\10519704.sys [116016] =>.Kaspersky Lab® O58 - SDL:2012/07/31 21:54:40 A . (.Kaspersky Lab, GERT - Kaspersky Lab Mini Driver.) -- C:\Windows\System32\drivers\24978067.sys [116016] =>.Kaspersky Lab® O58 - SDL:2012/07/29 14:28:50 A . (.Kaspersky Lab, GERT - Kaspersky Lab Mini Driver.) -- C:\Windows\System32\drivers\92837947.sys [116016] =>.Kaspersky Lab® O87 - FAEL: "TCP Query User{E0039DA2-50E8-4FF2-BA86-503D2554173F}C:\users\jjosette\appdata\local\google\chrome\application\chrome.exe" [In-None-P6-TRUE] .(...) -- C:\users\jjosette\appdata\local\google\chrome\application\chrome.exe (.not file.) O87 - FAEL: "UDP Query User{F2AB86B2-EE52-44DA-87C8-3736AB6F23E8}C:\users\jjosette\appdata\local\google\chrome\application\chrome.exe" [In-None-P17-TRUE] .(...) -- C:\users\jjosette\appdata\local\google\chrome\application\chrome.exe (.not file.) O87 - FAEL: "TCP Query User{3DAB9C82-7EF4-45E2-8104-E190C883CD50}C:\users\jjosette\appdata\local\google\chrome\application\chrome.exe" [In-None-P6-TRUE] .(...) -- C:\users\jjosette\appdata\local\google\chrome\application\chrome.exe (.not file.) O87 - FAEL: "UDP Query User{72CAEAC9-EFAC-4DC2-8F7A-FE51360D6528}C:\users\jjosette\appdata\local\google\chrome\application\chrome.exe" [In-None-P17-TRUE] .(...) -- C:\users\jjosette\appdata\local\google\chrome\application\chrome.exe (.not file.) [MD5.6494BC85A3703C40528E66CDA37BF791] [WIS][2013/01/02 10:54:50] (.Advernet.) -- C:\Windows\Installer\2f9043.msi [1084928] =>PUP.Optional.Prox [MD5.A672E4C77ED7CCC851575B10B46CC8AD] [WIS][2012/07/27 15:53:53] (.IMinent - IMinent Toolbar.) -- C:\Windows\Installer\362170.msi [1019392] =>PUP.Optional.IMBooster [MD5.739F55C55A99F7923EB4E238012A517B] [WIS][2014/10/10 22:17:50] (.APN, LLC - Shopping App by Ask.) -- C:\Windows\Installer\9f43d.msi [512000] =>Adware.Bandoo HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32 =>PUP.Optional.MyPCBackup HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS =>PUP.Optional.MyPCBackup HKLM\SOFTWARE\Microsoft\Tracing\DriverReviver_RASAPI32 =>.SUP.DriverReviver HKLM\SOFTWARE\Microsoft\Tracing\DriverReviver_RASMANCS =>.SUP.DriverReviver HKLM\SOFTWARE\Microsoft\Tracing\DriverSupport_RASAPI32 =>PUP.Optional.DriverSupport HKLM\SOFTWARE\Microsoft\Tracing\DriverSupport_RASMANCS =>PUP.Optional.DriverSupport HKLM\SOFTWARE\Microsoft\Tracing\ReimageReminder_RASAPI32 =>.SUP.ReimageRepair HKLM\SOFTWARE\Microsoft\Tracing\ReimageReminder_RASMANCS =>.SUP.ReimageRepair HKLM\SOFTWARE\Microsoft\Tracing\Reimage_RASAPI32 =>.SUP.ReimageRepair HKLM\SOFTWARE\Microsoft\Tracing\Reimage_RASMANCS =>.SUP.ReimageRepair C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lameokaalbmnhgapanlloeichlbjloak =>.SUP.SearchManager C:\Program Files (x86)\Magentic =>Toolbar.Magentic C:\Users\jjosette\AppData\Roaming\AdvancedSystemProtector =>PUP.Optional.AdvancedSystemProtector C:\Users\jjosette\AppData\Roaming\Simple Star =>.SUP.SimpleStar C:\Users\jjosette\AppData\Local\Magentic =>Toolbar.Magentic HKLM\Software\WOW6432Node\Microsoft\Shared Tools\MSConfig\startupreg\MarineAquarium3Free_57 Browser Plugin Loader 64 =>PUP.Optional.MarineAquarium C:\Windows\Installer\2f9043.msi =>PUP.Optional.Proxy C:\Windows\Installer\362170.msi =>PUP.Optional.IMBooster C:\Windows\Installer\9f43d.msi =>Adware.Bandoo HKLM\Software\WOW6432Node\Microsoft\Tracing\BackupStack_RASAPI32 =>PUP.Optional.MyPCBackup HKLM\Software\WOW6432Node\Microsoft\Tracing\BackupStack_RASMANCS =>PUP.Optional.MyPCBackup HKLM\Software\WOW6432Node\Microsoft\Tracing\DriverReviver_RASAPI32 =>.SUP.DriverReviver HKLM\Software\WOW6432Node\Microsoft\Tracing\DriverReviver_RASMANCS =>.SUP.DriverReviver HKLM\Software\WOW6432Node\Microsoft\Tracing\DriverSupport_RASAPI32 =>PUP.Optional.DriverSupport HKLM\Software\WOW6432Node\Microsoft\Tracing\DriverSupport_RASMANCS =>PUP.Optional.DriverSupport HKLM\Software\WOW6432Node\Microsoft\Tracing\ReimageReminder_RASAPI32 =>.SUP.ReimageRepair HKLM\Software\WOW6432Node\Microsoft\Tracing\ReimageReminder_RASMANCS =>.SUP.ReimageRepair HKLM\Software\WOW6432Node\Microsoft\Tracing\Reimage_RASAPI32 =>.SUP.ReimageRepair HKLM\Software\WOW6432Node\Microsoft\Tracing\Reimage_RASMANCS =>.SUP.ReimageRepair C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d16fk4ms6rqz1v.cloudfront.net_0.localstorage =>.SUP.CloudfrontNet C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d16fk4ms6rqz1v.cloudfront.net_0.localstorage-journal =>.SUP.CloudfrontNet C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d22j4fzzszoii2.cloudfront.net_0.localstorage =>.SUP.CloudfrontNet C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d22j4fzzszoii2.cloudfront.net_0.localstorage-journal =>.SUP.CloudfrontNet C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_fr.bytefence.com_0.localstorage =>.SUP.ByteFence C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_fr.bytefence.com_0.localstorage-journal =>.SUP.ByteFence C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_fr.softonic.com_0.localstorage =>.SUP.Softonic C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_fr.softonic.com_0.localstorage-journal =>.SUP.Softonic C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ol.uk.at.atwola.com_0.localstorage =>.SUP.Atwola C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ol.uk.at.atwola.com_0.localstorage-journal =>.SUP.Atwola C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.audienceinsights.net_0.localstorage =>.SUP.AudienceInsights C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.audienceinsights.net_0.localstorage-journal =>.SUP.AudienceInsights C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage =>PUP.Optional.Generic C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal =>PUP.Optional.Generic C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_wix-instantsearchplus-ssl.akamaized.net_0.localstorage =>.SUP.AkamaiHD C:\Users\jjosette\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_wix-instantsearchplus-ssl.akamaized.net_0.localstorage-journal =>.SUP.AkamaiHD SysRestore FirewallRaz EmptyPrefetch EmptyCLSID EmptyFlash Emptytemp ShortcutFix