Script ZHPFix O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} (.Orphan.) O4 - GS\Quicklaunch [Administrateur]: BS.Player FREE.lnk . (.AB Team - BS.Player.) C:\Program Files\Webteh\BSplayer\bsplayer.exe O4 - GS\Quicklaunch [michel]: BS.Player FREE.lnk . (.AB Team - BS.Player.) C:\Program Files\Webteh\BSplayer\bsplayer.exe HKU\S-1-5-21-2008996643-3335521316-3605118564-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com HKCU\Software\Lavasoft\Web Companion HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2008996643-3335521316-3605118564-1001\Software\SweetIM HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com HKLM\SOFTWARE\Lavasoft\Web Companion HKLM\SOFTWARE\Classes\TypeLib\{ED62BC6E-64F1-46BE-866F-4C8DC0DF7057} HKLM\SOFTWARE\Webteh HKCU\SOFTWARE\Conduit HKU\S-1-5-21-2008996643-3335521316-3605118564-1001\SOFTWARE\Conduit O40 - ASIC: Google Chrome - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (...) -- C:\Program Files\Google\Chrome\Application\57.0.2987.110\Installer\chrmstp.exe (.not file.) =>.SUP.Various O69 - SBI: prefs.js [michel - 6c06nk15.default-1416932462540] user_pref("extensions.{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.install-event-fired", true); HKLM\SOFTWARE\Microsoft\Tracing\AkamaiDownloadManagerInstaller_RASMANCS C:\Users\michel\AppData\Roaming\Mozilla\Firefox\Profiles\6c06nk15.default-1416932462540\extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB} HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5C255C8A-E604-49b4-9D64-90988571CECB} HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96} HKLM\SOFTWARE\AviraSpeedup =>.Avira Software HKLM\SOFTWARE\Lavasoft =>.Lavasoft HKU\.DEFAULT\SOFTWARE\Avira =>.Avira HKU\.DEFAULT\SOFTWARE\AviraSpeedup =>.Avira Software HKU\.DEFAULT\SOFTWARE\Safer Networking Limited =>.Safer Networking Limited HKU\S-1-5-21-2008996643-3335521316-3605118564-1001\SOFTWARE\Lavasoft =>.Lavasoft HKU\S-1-5-21-2008996643-3335521316-3605118564-1001\SOFTWARE\MCAFEE =>.McAfee Inc. HKU\S-1-5-21-2008996643-3335521316-3605118564-1001\SOFTWARE\Safer Networking Limited =>.Safer Networking Limited O43 - CFD: 24/07/2018 - [] D -- C:\Program Files\RogueKiller =>.Adlice Software O43 - CFD: 01/04/2017 - [] D -- C:\Program Files\Spybot - Search & Destroy 2 =>.SaferNetworking O43 - CFD: 24/07/2018 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller =>.Adlice Software O43 - CFD: 06/08/2012 - [] D -- C:\ProgramData\backup =>.Symantec O43 - CFD: 15/04/2011 - [] D -- C:\ProgramData\McAfee =>.McAfee O43 - CFD: 30/05/2015 - [] D -- C:\ProgramData\RogueKiller =>.Adlice Software O43 - CFD: 01/04/2017 - [] D -- C:\ProgramData\Spybot - Search & Destroy =>.SaferNetworking O43 - CFD: 26/04/2010 - [] D -- C:\ProgramData\Trend Micro =>.Trend Micro O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Program Files\Google\Chrome\Application\chrome.exe (.not file.) C:\Program Files\Webteh C:\Windows\Installer\11441c0.msp C:\Windows\Installer\18c245e.msp C:\Windows\Installer\18e2ff0.msp C:\Windows\Installer\18e6036.msp C:\Windows\Installer\24d1f48.msp C:\Windows\Installer\24e9fe8.msp C:\Windows\Installer\3107b39.msp C:\Windows\Installer\c9d9c.msp C:\Windows\Installer\ccef21.msp C:\Windows\Installer\cd15e0.msp C:\Windows\Installer\cd4fe.msp C:\Windows\Installer\cd6367.msp C:\Windows\Installer\d9686.msp C:\Windows\Installer\ef675.msp C:\Windows\Installer\fd52f.msp HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AkamaiDownloadManagerInstaller_RASMANCS [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID]:{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} HKU\S-1-5-21-2008996643-3335521316-3605118564-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com HKCU\Software\Lavasoft\Web Companion HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2008996643-3335521316-3605118564-1001\Software\SweetIM HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com HKLM\SOFTWARE\Lavasoft\Web Companion HKLM\SOFTWARE\Classes\TypeLib\{ED62BC6E-64F1-46BE-866F-4C8DC0DF7057} EmptyPrefetch Emptytemp EmptyClsid SysRestore FirewallRaz EmptyPrefetch EmptyCLSID EmptyFlash Emptytemp ShortcutFix