Script ZHPFix
[MD5.C53D9FC83CE7101E9589FCAEDF461F55] - (...) -- C:\Users\jonathan\AppData\Local\fst_fr_83\upfst_fr_83.exe [3153904] [PID.2008] =PUA.FSTfr9
M3 - MFPP: Plugins - [jonathan] -- C:\Program Files\Mozilla FireFox\searchplugins\awesomehp.xml =PUP.Awesomehp
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.awesomehp.com =PUP.Awesomehp
O4 - HKLM\..\Run: [fst_fr_83] Clé orpheline =PUA.FSTfr9
O4 - HKLM\..\RunOnce: [upfst_fr_83.exe] . (...) -- C:\Users\jonathan\AppData\Local\fst_fr_83\upfst_fr_83.exe =PUA.FSTfr9
[HKCU\Software\Tutorials] =Spyware.AgenceExclusive
[HKLM\Software\Tutorials] =Spyware.AgenceExclusive
[HKLM\Software\awesomehpSoftware] =PUP.Awesomehp
O43 - CFD: 09/02/2014 - 13:07:32 - [0] ----D C:\Program Files\Cling Clang =PUP.ClingClang
O43 - CFD: 01/03/2012 - 14:41:50 - [0] ----D C:\Program Files\WIA6EB~1 = Infection BT (Adware.Bandoo)
O43 - CFD: 07/06/2013 - 06:37:54 - [0,022] ----D C:\Users\jonathan\AppData\Roaming\dclogs = Stolen.Data
O43 - CFD: 09/02/2014 - 15:22:17 - [8,688] ----D C:\Users\jonathan\AppData\Local\fst_fr_83 =PUA.FSTfr9
O45 - LFCP:[MD5.A56A24AD102E01FBE6CADC98F4054739] - 06/02/2014 - 21:14:51 ---A- - C:\Windows\Prefetch\AZUREUS.EXE-D24891AB.pf =Azureus
O45 - LFCP:[MD5.E73491C3122DCE91895CDED0222F8F0C] - 09/02/2014 - 11:56:21 ---A- - C:\Windows\Prefetch\FORTUNITASSETUP.EXE-1268D02E.pf =PUP.Fortunitas
O45 - LFCP:[MD5.8D7007458BB7005FF17004CC01184A60] - 09/02/2014 - 11:56:25 ---A- - C:\Windows\Prefetch\TUGS_AWESOMEHP.EXE-E57D18AD.pf =PUP.Awesomehp
O45 - LFCP:[MD5.9D0B0A5A384202DC7BFF51039E0BA916] - 09/02/2014 - 11:56:27 ---A- - C:\Windows\Prefetch\FREESOFTTODAY.EXE-4AB645C9.pf =Adware.FreeSoftToday
O45 - LFCP:[MD5.91CE77AEAE6A183F69CCABAB09F91863] - 09/02/2014 - 11:56:27 ---A- - C:\Windows\Prefetch\FREESOFTTODAY.TMP-AE8B3B5A.pf =Adware.FreeSoftToday
O45 - LFCP:[MD5.5F08E6F9260B9777B5A6CCCF94669018] - 09/02/2014 - 11:56:37 ---A- - C:\Windows\Prefetch\FST_FR_83.EXE-F3668D02.pf =PUA.FSTfr9
O45 - LFCP:[MD5.8AB87F16E813232D0D8174CC63AD72BC] - 09/02/2014 - 11:57:09 ---A- - C:\Windows\Prefetch\OPTIMIZERPRO.EXE-81528A02.pf =PUP.OptimizerPro
O45 - LFCP:[MD5.9F58D902831D789F72AEE4F0278CF6D5] - 09/02/2014 - 11:57:39 ---A- - C:\Windows\Prefetch\OPTPROSTART.EXE-1D272174.pf = Infection PUP (PUP.OptimizerPro)
O45 - LFCP:[MD5.04CB44F593998650B885ACD19C9CB44F] - 09/02/2014 - 11:57:40 ---A- - C:\Windows\Prefetch\FORTUNITAS_SETUP.EXE-4E2A012A.pf =PUP.Fortunitas
O45 - LFCP:[MD5.2CB4DCC0C7C9B20AB3F87DA9C075C3DE] - 09/02/2014 - 11:57:49 ---A- - C:\Windows\Prefetch\OPTIMIZERPRO.EXE-95950FB6.pf =PUP.OptimizerPro
O45 - LFCP:[MD5.4C1A70EAA797C7ED72DE3F76111F188F] - 09/02/2014 - 11:58:01 ---A- - C:\Windows\Prefetch\FORTUNITAS.FIRSTRUN.EXE-4AD2F453.pf =PUP.Fortunitas
O45 - LFCP:[MD5.8A932B4338A0A2595D7A987528886524] - 09/02/2014 - 12:18:38 ---A- - C:\Windows\Prefetch\FORTUNITASUNINSTALL.EXE-2FD53516.pf =PUP.Fortunitas
O45 - LFCP:[MD5.A4F8FB7AC8789BD02E893D4013A4CB67] - 09/02/2014 - 12:47:45 ---A- - C:\Windows\Prefetch\WAJAM_VALIDATE.EXE-5D4F4F3B.pf =PUP.Wajam
O45 - LFCP:[MD5.9382CB8C9B5DB44B3D3E1A5A68B42468] - 09/02/2014 - 15:22:17 ---A- - C:\Windows\Prefetch\UPFST_FR_83.EXE-68798F97.pf =PUA.FSTfr9
O61 - LFC: 06/02/2014 - 15:33:37 ---A- . (...) -- C:\Users\jonathan\AppData\Local\fst_fr_83\upfst_fr_83.exe [3153904] =PUA.FSTfr9
O61 - LFC: 09/02/2014 - 15:33:37 ---A- . (...) -- C:\Users\jonathan\AppData\Local\fst_fr_83\upfst_fr_83.cyp [652] =PUA.FSTfr9
O61 - LFC: 09/02/2014 - 15:33:37 ---A- . (...) -- C:\Users\jonathan\AppData\Local\fst_fr_83\user_profil.cyp [1676] =PUA.FSTfr9
O61 - LFC: 09/02/2014 - 15:33:37 ---A- . (.FreeSoftToday.) -- C:\Users\jonathan\AppData\Local\fst_fr_83\Download\majfst.exe [5953648] =PUA.FSTfr9
O61 - LFC: 09/02/2014 - 15:33:38 ---A- . (...) -- C:\Users\jonathan\AppData\Local\Temp\toolbar_log.txt [30514] = Infection PUP (PUP.Babylon)
[MD5.EB34DF3DA0F2B2F21F256C51AB926F4A] [SPRF][06/05/2006] (...) -- C:\Users\jonathan\AppData\Roaming\logs.dat [223402] = Infection Diverse (Bifrose.Trace)
[HKCU\Software\Tutorials] =Spyware.AgenceExclusive
[HKLM\Software\Tutorials] =Spyware.AgenceExclusive
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:fst_fr_83 =PUA.FSTfr9^
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]:upfst_fr_83.exe =PUA.FSTfr9^
C:\Program Files\Cling Clang =PUP.ClingClang^
C:\Users\jonathan\AppData\Local\fst_fr_83 =PUA.FSTfr9^
C:\Users\jonathan\AppData\Local\fst_fr_83\upfst_fr_83.exe =PUA.FSTfr9^
[HKLM\Software\awesomehpSoftware] =PUP.Awesomehp^
O23 - Service: (vToolbarUpdater17.3.0) . (...) - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe (.not file.) =Toolbar.AVGSearch
O43 - CFD: 20/10/2013 - 16:27:36 - [2,791] ----D C:\Users\jonathan\AppData\Local\CRE = Toolbar.Conduit
O45 - LFCP:[MD5.D8F1470E4FDA2E04DF1D4B44BDDBAAA5] - 06/02/2014 - 15:33:08 ---A- - C:\Windows\Prefetch\VPROT.EXE-B916796C.pf = Toolbar.AVGSearch
SS - | Auto 10/07/1658 0 | (vToolbarUpdater17.3.0) . (...) - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe =Toolbar.AVGSearch
[HKLM\SYSTEM\CurrentControlSet\Services\vToolbarUpdater17.3.0] =Toolbar.AVGSearch^
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E30ED111-BD63-48C2-A6CB-AB3C9FFFB07C}] =Toolbar.Conduit
[HKLM\Software\Classes\CLSID\{BD5843ED-13C4-4EFF-ACE9-56CEE22BC087}] =Toolbar.AVGSearch
O4 - GS\Accessories [jonathan]: Run.lnk - Clé orpheline = Orphean Key not necessary
EmptyPrefetch
EmptyTemp
EmptyFlash
EmptyCLSID
SysRestore