[MD5.34AE0DFA3EE3B5B9975042D87332D0B7] - (...) -- C:\Users\ramzi\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe [107520] [PID.1944] => Infection PUP (Adware.IMBooster) G1 - GCS: Preference [User Data\Default] http://search.rpidity.com => Infection PUP (Adware.Boxore)* M3 - MFPP: Plugins - [ramzi] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\babylon.xml => Infection PUP (Toolbar.Babylon)* M0 - MFSP: prefs.js [ramzi - zsoobouo.default] http://allssearch.com => ZHPHosts Black List R0 - HKCU\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.rpidity.com => Infection PUP (Adware.Boxore)* R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://search.rpidity.com => Infection PUP (Adware.Boxore)* R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = http://search.rpidity.com => Infection PUP (Adware.Boxore)* O2 - BHO: CrossriderApp0004637 [64Bits] - {11111111-1111-1111-1111-110011461137} . (.215 Apps - Deals Plugin BHO.) -- C:\Program Files (x86)\Deals Plugin\Deals Plugin.dll => Infection PUP (Adware.VidSaver)* O23 - Service: DefaultTabUpdate (DefaultTabUpdate) . (...) - C:\Users\ramzi\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe => Infection PUP (Adware.IMBooster) O39 - APT:Automatic Planified Task - C:\Windows\Tasks\AutoKMS.job => Infection Diverse (Trojan.Keygen) O39 - APT:Automatic Planified Task - C:\Windows\Tasks\AutoKMSDaily.job => Infection Diverse (Trojan.Keygen) [MD5.00000000000000000000000000000000] [APT] [AutoKMS] (...) -- C:\Windows\AutoKMS\AutoKMS.exe (.not file.) => Infection Diverse (Trojan.Keygen) [MD5.00000000000000000000000000000000] [APT] [AutoKMSDaily] (...) -- C:\Windows\AutoKMS\AutoKMS.exe (.not file.) => Infection Diverse (Trojan.Keygen) O42 - Logiciel: DefaultTab - (.Search Results, LLC.) [HKLM][64Bits] -- DefaultTab => Infection PUP (Adware.IMBooster)* O42 - Logiciel: rpidity - (.rpidity.) [HKLM][64Bits] -- rpidity => Infection PUP (Adware.Boxore)* [HKCU\Software\AppDataLow\Software\Crossrider] => Infection PUP (Adware.VidSaver)* [HKCU\Software\AppDataLow\Software\DefaultTab] => Infection PUP (Adware.IMBooster) [HKCU\Software\AppDataLow\Software\PriceGong] => Infection PUP (Adware.PriceGong)* [HKCU\Software\Cr_Installer] => Infection PUP (Adware.VidSaver) [HKCU\Software\Default Tab] => Infection PUP (Adware.IMBooster) [HKCU\Software\InstalledBrowserExtensions] => Infection PUP (Adware.VidSaver) [HKLM\Software\Wow6432Node\Babylon] => Infection PUP (Toolbar.Babylon)* [HKLM\Software\Wow6432Node\Default Tab] => Infection PUP (Adware.IMBooster) O43 - CFD: 10/10/2012 - 20:12:07 - [3,587] ----D C:\Program Files (x86)\rpidity => Infection PUP (Adware.Boxore)* O43 - CFD: 01/02/2013 - 21:39:36 - [0] ----D C:\ProgramData\Babylon => Infection PUP (Toolbar.Babylon)* O43 - CFD: 01/02/2013 - 21:39:36 - [0,006] ----D C:\Users\ramzi\AppData\Roaming\Babylon => Infection PUP (Toolbar.Babylon)* O43 - CFD: 15/10/2012 - 20:40:36 - [1,830] ----D C:\Users\ramzi\AppData\Roaming\DefaultTab => Infection PUP (Adware.IMBooster) O43 - CFD: 05/02/2013 - 08:29:19 - [28,325] ----D C:\Users\ramzi\AppData\Roaming\OpenCandy => Infection PUP (Adware.OpenCandy)* O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("extensions.BabylonToolbar_i.newTab", true); => Infection PUP (Toolbar.Babylon)* O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("extensions.crossrider.bic", "139b7421c0127c20e8f5f7072ce0038f"); => Infection PUP (Adware.VidSaver)* O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} - (Delta Search) - http://www.delta-search.com => Infection PUP (PUP.ClaroSearch) O69 - SBI: SearchScopes [HKCU] {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} - (Rpidity) - http://search.rpidity.com => Infection PUP (Adware.Boxore)* O69 - SBI: SearchScopes [HKCU] {FC5FF74D-CF71-42D9-BD43-4768349182EE} - (Search Here) - http://www.mysearchresults.com => Infection BT (Adware.MyWebSearch)* [MD5.F39FD431BE6629896D4FA4B575CAEF2C] [SPRF][15/10/2012] (.Search Results - DefaultTabSetup.exe.) -- C:\Users\ramzi\AppData\Local\Temp\DefaultTabSetup2.exe [3182736] => Infection PUP (Adware.IMBooster)* [MD5.AF7F1FE5EC4F48EF3856FB712F23FE99] [SPRF][23/08/2012] (...) -- C:\Users\ramzi\AppData\Local\Temp\rpidity.exe [1605760] => Infection PUP (Adware.Boxore)* [HKLM\Software\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}] => Infection PUP (Toolbar.Babylon) [HKLM\Software\Wow6432Node\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}] => Infection PUP (Toolbar.Babylon) [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}] => Infection BT (PUP.ClaroSearch) [HKLM\Software\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\Interface\{4897bba6-48d9-468c-8efa-846275d7701b}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\Interface\{4897bba6-48d9-468c-8efa-846275d7701b}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] => Infection BT (Adware.IncrediBar) [HKLM\Software\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] => Infection BT (Adware.IncrediBar) [HKLM\Software\Wow6432Node\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] => Infection BT (Adware.IncrediBar) [HKLM\Software\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}] => Infection BT (Adware.BHO) [HKLM\Software\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}] => Infection BT (Adware.SocialSkinz) [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ae07101b-46d4-4a98-af68-0333ea26e113}] => Infection BT (Adware.SEOToolbar) [HKLM\Software\Classes\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}] => Infection BT (Adware.SEOToolbar) [HKLM\Software\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}] => Infection PUP (Adware.Funmoods) [HKLM\Software\Wow6432Node\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}] => Infection PUP (Adware.Funmoods) [HKLM\Software\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}] => Infection BT (Hijacker.Seeearch) [HKLM\Software\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}] => Infection BT (Adware.SocialSkinz) [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C0924543-15FD-4F3D-889C-0B4562A9CB45}] => Infection BT (Adware.SocialSkinz) [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C0924543-15FD-4F3D-889C-0B4562A9CB45}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0924543-15FD-4F3D-889C-0B4562A9CB45}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}] => Infection BT (Hijacker.Seeearch) [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}] => Infection BT (Adware.SocialSkinz) [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\extensions\{CDB982ED-F9D6-4E3B-B94B-96F705D35AD1}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] => Infection PUP (Adware.Funmoods) [HKLM\Software\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] => Infection PUP (Adware.Funmoods) [HKLM\Software\Wow6432Node\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] => Infection PUP (Adware.Funmoods) [HKLM\Software\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}] => Infection BT (Adware. BullseyeToolbar) [HKLM\Software\Wow6432Node\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}] => Infection BT (Adware. BullseyeToolbar) [HKLM\Software\Classes\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Wow6432Node\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}] => Infection BT (Adware.SocialSkinz) [HKLM\Software\Classes\AppID\escort.dll] => Infection PUP (PUP.Funmoods)* [HKLM\Software\Classes\AppID\escortapp.dll] => Infection PUP (PUP.Funmoods)* [HKLM\Software\Classes\AppID\escorteng.dll] => Infection PUP (PUP.Funmoods)* [HKLM\Software\Classes\AppID\esrv.EXE] => Infection PUP (PUP.Funmoods) [HKLM\Software\Classes\escort.escortIEPane] => Infection PUP (PUP.Funmoods)* [HKLM\Software\Classes\escort.escortIEPane.1] => Infection PUP (PUP.Funmoods)* [HKCU\Software\Cr_Installer] => Infection PUP (Adware.VidSaver) [HKCU\Software\default tab] => Infection PUP (Adware.IMBooster) [HKLM\Software\Wow6432Node\default tab] => Infection PUP (Adware.IMBooster) [HKCU\Software\AppDataLow\Software\defaulttab] => Infection PUP (Adware.IMBooster) [HKCU\Software\AppDataLow\Software\PriceGong] => Infection PUP (Adware.PriceGong)* [HKLM\Software\Wow6432Node\Microsoft\Tracing\MyBabylontb_RASAPI32] => Infection PUP (Toolbar.Babylon)* [HKLM\Software\Wow6432Node\Microsoft\Tracing\MyBabylontb_RASMANCS] => Infection PUP (Toolbar.Babylon)* [HKLM\Software\Wow6432Node\Microsoft\Tracing\rpidity_RASAPI32] => Infection PUP (Adware.Boxore)* [HKLM\Software\Wow6432Node\Microsoft\Tracing\rpidity_RASMANCS] => Infection PUP (Adware.Boxore)* [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab] => Infection PUP (Adware.IMBooster) [HKCU\Software\InstalledBrowserExtensions\215 Apps] => Infection PUP (PUP.CrossFire) [HKLM\Software\Classes\Prod.cap] => Infection PUP (Adware.Bandoo) [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\rpidity] => Infection PUP (Adware.Boxore)* [HKLM\Software\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}] => Infection PUP (PUP.ClaroSearch) [HKLM\Software\Wow6432Node\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}] => Infection PUP (PUP.ClaroSearch) [HKLM\Software\Classes\CrossriderApp0004637.BHO] => Infection PUP (Adware.VidSaver)* [HKLM\Software\Classes\CrossriderApp0004637.BHO.1] => Infection PUP (Adware.VidSaver)* [HKLM\Software\Classes\CrossriderApp0004637.Sandbox] => Infection PUP (Adware.VidSaver)* [HKLM\Software\Classes\CrossriderApp0004637.Sandbox.1] => Infection PUP (Adware.VidSaver)* [HKLM\Software\Wow6432Node\Classes\CrossriderApp0004637.BHO] => Infection PUP (Adware.VidSaver)* [HKLM\Software\Wow6432Node\Classes\CrossriderApp0004637.BHO.1] => Infection PUP (Adware.VidSaver)* [HKLM\Software\Wow6432Node\Classes\CrossriderApp0004637.Sandbox] => Infection PUP (Adware.VidSaver)* [HKLM\Software\Wow6432Node\Classes\CrossriderApp0004637.Sandbox.1] => Infection PUP (Adware.VidSaver)* [HKLM\Software\Wow6432Node\Classes\escort.escortIEPane] => Infection PUP (PUP.Funmoods)* [HKLM\Software\Wow6432Node\Classes\escort.escortIEPane.1] => Infection PUP (PUP.Funmoods)* [HKLM\Software\Classes\AppID\escort.DLL] => Infection PUP (PUP.Funmoods)* [HKLM\Software\Classes\AppID\escortApp.DLL] => Infection PUP (PUP.Funmoods)* [HKLM\Software\Classes\AppID\escortEng.DLL] => Infection PUP (PUP.Funmoods)* [HKLM\Software\Classes\AppID\escorTlbr.DLL] => Infection PUP (PUP.Funmoods)* C:\ProgramData\Babylon => Infection PUP (Toolbar.Babylon)* C:\Users\ramzi\AppData\Roaming\Babylon => Infection PUP (Toolbar.Babylon)* C:\Users\ramzi\AppData\Roaming\defaulttab => Infection PUP (Adware.IMBooster) C:\Users\ramzi\AppData\Roaming\OpenCandy => Infection PUP (Adware.OpenCandy)* C:\Users\ramzi\AppData\LocalLow\PriceGong => Infection PUP (Adware.PriceGong)* C:\Users\ramzi\AppData\LocalLow\Toolbar4 => Infection BT (Adware.SocialSkinz) SR - | Auto 107520 | (DefaultTabUpdate) . (...) - C:\Users\ramzi\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe => Infection PUP (Adware.IMBooster) O4 - Global Startup: C:\Users\ramzi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk . (.Nullsoft, Inc..) -- C:\Program Files (x86)\Winamp\winamp.exe => Unknown owner%. G2 - GCE: Preference [User Data\Default] [paoponfhfdfnjgddpnpjkambkcgdaaib] uTorrentBar_FR v.2.3.15.10 (Désactivé) => P2P.µTorrent* O2 - BHO: QuickShare WidgetEngine [64Bits] - {31ad400d-1b06-4e33-a59a-90c2c140cba0} . (...) -- mscoree.dll (.not file.) => Fichier absent O4 - Global Startup: C:\Users\ramzi\Desktop\.lnk . (...) -- C:\Users\ramzi\AppData\Local\Temp\ICReinstall_mysql-gui-tools-5-0-r17-es-en-win-setup.exe => Temporary file not necessary O4 - Global Startup: C:\Users\ramzi\Desktop\Ordinateur - Raccourci.lnk - Orphean Key => Orphean Key not necessary O4 - Global Startup: C:\Users\ramzi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk . (.BitTorrent, Inc..) -- C:\Program Files (x86)\uTorrent\uTorrent.exe => P2P.BitTorrent* O42 - Logiciel: uTorrentBar_FR Toolbar - (.uTorrentBar_FR.) [HKLM][64Bits] -- uTorrentBar_FR Toolbar => P2P.µTorrent* O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKLM][64Bits] -- uTorrent => P2P.BitTorrent* [HKCU\Software\AppDataLow\Software\uTorrentBar_FR] => P2P.µTorrent* [HKCU\Software\BitTorrent] => P2P.BitTorrent* [HKLM\Software\Wow6432Node\uTorrentBar_FR] => P2P.µTorrent* O43 - CFD: 26/01/2013 - 00:38:41 - [0,924] ----D C:\Program Files (x86)\uTorrent => P2P.µTorrent* O43 - CFD: 14/10/2012 - 15:31:31 - [4,849] ----D C:\Program Files (x86)\uTorrentBar_FR => P2P.µTorrent* O43 - CFD: 08/02/2013 - 07:02:57 - [2,026] ----D C:\Users\ramzi\AppData\Roaming\uTorrent => P2P.µTorrent* O51 - MPSK:{6901f364-6e0a-11e2-aba7-005056c00008}\AutoRun\command. (...) -- F:\.\Setup.exe (.not file.) => Fichier absent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.scriptSource", "http://127.0.0.1:10000/gui/"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"http://uTorrent[...] => P2P.µTorrent* O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"uTorrentBar_FR\[...] => P2P.µTorrent* O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.smartbar.toolbarName", "uTorrentBar_FR "); => P2P.µTorrent* O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.url_history0001", "http://www.fanpop.com/spots/hyuna-kim/images/25401870/title/hyuna-wallpaper-photo:::clickh[...] => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT3128284.installType", "ConduitNSISIntegration"); => Toolbar.Agent [MD5.D41D8CD98F00B204E9800998ECF8427E] [SPRF][05/02/2013] (...) -- C:\Users\ramzi\AppData\Local\Temp\.exe [0] => Temporary file not necessary [MD5.885E9EB42889CA547F4E3515DCDE5D3D] [SPRF][14/05/2006] (...) -- C:\Users\ramzi\AppData\Local\Temp\7za.exe [476672] => Temporary file not necessary [MD5.509842CCC1F9E1DCBE3A0E7A4D7D3CDF] [SPRF][26/10/2012] (.Microsoft Corporation - BingBarSetup-Partner.) -- C:\Users\ramzi\AppData\Local\Temp\BingBarSetup-Partner.exe [7850088] => Temporary file not necessary [MD5.2DD6603BE9B20768DA6084628A529F2C] [SPRF][11/09/2012] (.215 Apps - Deals Plugin Installer.) -- C:\Users\ramzi\AppData\Local\Temp\DealsPluginROW.exe [1965176] => Temporary file not necessary [MD5.D41D8CD98F00B204E9800998ECF8427E] [SPRF][05/02/2013] (...) -- C:\Users\ramzi\AppData\Local\Temp\default.exe [0] => Temporary file not necessary [MD5.B919F915239E373275D4836A019166C2] [SPRF][26/10/2012] (...) -- C:\Users\ramzi\AppData\Local\Temp\defaultCache.reg [1469030] => Temporary file not necessary [MD5.3D7CDC3E67A97110321BF7453C649B1F] [SPRF][24/01/2013] (...) -- C:\Users\ramzi\AppData\Local\Temp\DeltaTB.exe [775664] => Temporary file not necessary [MD5.2CE6EEF84B7F306858C23000F017E2A0] [SPRF][19/03/2012] (...) -- C:\Users\ramzi\AppData\Local\Temp\Extract.bat [80] => Temporary file not necessary [MD5.4123BAC3CD56A2D27B5DAE37BDF92E4D] [SPRF][02/01/2013] (...) -- C:\Users\ramzi\AppData\Local\Temp\ICReinstall_mysql-gui-tools-5-0-r17-es-en-win-setup.exe [1202720] => Temporary file not necessary [MD5.D41D8CD98F00B204E9800998ECF8427E] [SPRF][06/02/2013] (...) -- C:\Users\ramzi\AppData\Local\Temp\jcogyk7m.dll [0] => Temporary file not necessary [MD5.75F1D82EFC00ED50097E2032D043F8B5] [SPRF][01/09/2012] (...) -- C:\Users\ramzi\AppData\Local\Temp\pyl3A61.tmp.exe [49152] => Temporary file not necessary [MD5.D190911614D682369192C40D909F4E66] [SPRF][14/10/2012] (...) -- C:\Users\ramzi\AppData\Local\Temp\utt823C.tmp.exe [6040064] => Temporary file not necessary [MD5.3AB5B019B47350A07B286B87231EC2A6] [SPRF][25/01/2013] (...) -- C:\Users\ramzi\AppData\Local\Temp\utt97F1.tmp.bat [95] => Temporary file not necessary [MD5.3AB5B019B47350A07B286B87231EC2A6] [SPRF][25/01/2013] (...) -- C:\Users\ramzi\AppData\Local\Temp\utt9F22.tmp.bat [95] => Temporary file not necessary O87 - FAEL: "{D448AD41-96A0-4BB6-A344-1A56FFCC41B6}" | In - None - P6 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe => P2P.BitTorrent* O87 - FAEL: "{E98DA92B-36F8-4477-B492-1EE1869C322C}" | In - None - P17 - TRUE | .(.BitTorrent, Inc. - µTorrent.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe => P2P.BitTorrent* [HKCU\Software\AppDataLow\Software\uTorrentBar_FR] => P2P.µTorrent* [HKLM\Software\Wow6432Node\uTorrentBar_FR] => P2P.µTorrent* [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentBar_FR Toolbar] => P2P.µTorrent* C:\Program Files (x86)\uTorrentBar_FR => P2P.µTorrent* C:\Users\ramzi\AppData\LocalLow\uTorrentBar_FR => P2P.µTorrent* C:\Users\ramzi\AppData\Local\Temp\01NET.com.exe => Temporary file not necessary G0 - GCSP: Preference [User Data\Default][HomePage] http://www.delta-search.com => Toolbar.DeltaSearch G0 - GCSP: Preference [User Data\Default] http://www.delta-search.com => Toolbar.DeltaSearch M3 - MFPP: Plugins - [ramzi] -- C:\Users\ramzi\AppData\Roaming\Mozilla\Firefox\Profiles\zsoobouo.default\searchplugins\conduit.xml => Toolbar.Conduit M3 - MFPP: Plugins - [ramzi] -- C:\Users\ramzi\AppData\Roaming\Mozilla\Firefox\Profiles\zsoobouo.default\searchplugins\delta.xml => Toolbar.DeltaSearch M3 - MFPP: Plugins - [ramzi] -- C:\Users\ramzi\AppData\Roaming\Mozilla\Firefox\Profiles\zsoobouo.default\searchplugins\search-here.xml => Toolbar.MySearchResults M2 - MFEP: prefs.js [ramzi - zsoobouo.default\ffxtlbr@delta.com] [] Delta Toolbar v1.5.0 (.delta-search.com.) => Toolbar.DeltaSearch M2 - MFEP: prefs.js [ramzi - zsoobouo.default\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}] [] uTorrentBar_FR v10.14.42.7 (.Conduit Ltd..) => Toolbar.Conduit* R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-search.com => Toolbar.DeltaSearch R3 - URLSearchHook: 01NET.com Toolbar [64Bits] - {8e5025c2-8ea3-430d-80b8-a14151068a6d} . (.Conduit Ltd. - Conduit Toolbar.) (6.4.0.0) -- C:\Program Files (x86)\01NET.com\prxtb01NE.dll => Toolbar.Conduit* R3 - URLSearchHook: ToolbarURLSearchHook Class [64Bits] - {CA3EB689-8F09-4026-AA10-B9534C691CE0} . (.Unknown owner - IE Toolbar Helper Module.) (4.2.0.87) -- C:\Program Files (x86)\rpidity\tbunsrE6EB.tmp\tbhelper.dll => Toolbar.Agent* R3 - URLSearchHook: uTorrentBar_FR Toolbar [64Bits] - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} . (.Conduit Ltd. - Conduit Toolbar.) (6.4.0.0) -- C:\Program Files (x86)\uTorrentBar_FR\prxtbuTor.dll => Toolbar.Conduit* O2 - BHO: uTorrentBar_FR [64Bits] - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files (x86)\uTorrentBar_FR\prxtbuTor.dll => Toolbar.Conduit* O2 - BHO: 01NET.com [64Bits] - {8e5025c2-8ea3-430d-80b8-a14151068a6d} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files (x86)\01NET.com\prxtb01NE.dll => Toolbar.Conduit* O2 - BHO: TBSB02609 [64Bits] - {C0924543-15FD-4F3D-889C-0B4562A9CB45} . (.Unknown owner - IE Toolbar Engine.) -- C:\Program Files (x86)\rpidity\tbunsrE6EB.tmp\tbcore3.dll => Toolbar.Agent* O2 - BHO: delta Helper Object [64Bits] - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} . (.Delta-search.com - No comment.) -- C:\Program Files (x86)\Delta\delta\1.8.10.0\bh\delta.dll => Toolbar.DeltaSearch O4 - HKCU\..\Run: [Browser Infrastructure Helper] . (.Smartbar - Smartbar.) -- C:\Users\ramzi\AppData\Local\Smartbar\Application\QuickShare.exe => Toolbar.Smartbar* O4 - HKUS\S-1-5-21-1914605606-2867671001-3639964001-1001\..\Run: [Browser Infrastructure Helper] . (.Smartbar - Smartbar.) -- C:\Users\ramzi\AppData\Local\Smartbar\Application\QuickShare.exe => Toolbar.Smartbar* [MD5.F0876747D83C1067BD71DAAF9F59325F] [APT] [ROC_REG_JAN_DELETE] (...) -- C:\ProgramData\AVG January 2013 Campaign\ROC.exe => Toolbar.AVGSearch O42 - Logiciel: 01NET.com Toolbar - (.01NET.com.) [HKLM][64Bits] -- 01NET.com Toolbar => Toolbar.Agent O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM][64Bits] -- {1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF} O42 - Logiciel: Delta Chrome Toolbar - (.DeltaInstaller.) [HKLM][64Bits] -- {177586E7-E42E-4F38-83D1-D15B4AF5B714} => Toolbar.DeltaSearch O42 - Logiciel: Delta toolbar - (.Delta.) [HKLM][64Bits] -- delta => Toolbar.DeltaSearch [HKCU\Software\AppDataLow\Software\01NET.com] => Toolbar.Agent [HKCU\Software\AppDataLow\Software\ConduitSearchScopes] => Toolbar.Conduit [HKCU\Software\AppDataLow\Software\Conduit] => Toolbar.Conduit [HKCU\Software\AppDataLow\Software\Smartbar] => Toolbar.Smartbar* [HKCU\Software\AppDataLow\Toolbar] => Toolbar.Conduit [HKCU\Software\Conduit] => Toolbar.Conduit [HKCU\Software\SmartbarBackup] => Toolbar.Smartbar* [HKCU\Software\SmartbarLog] => Toolbar.Smartbar* [HKCU\Software\Smartbar] => Toolbar.Smartbar* [HKCU\Software\Softonic] => Toolbar.Conduit* [HKLM\Software\Wow6432Node\01NET.com] => Toolbar.Agent [HKLM\Software\Wow6432Node\AVG Secure Search] => Toolbar.AVGSearch [HKLM\Software\Wow6432Node\Conduit] => Toolbar.Conduit O43 - CFD: 11/09/2012 - 22:28:40 - [4,795] ----D C:\Program Files (x86)\01NET.com => Toolbar.Agent O43 - CFD: 11/09/2012 - 22:28:41 - [0,609] ----D C:\Program Files (x86)\Conduit => Toolbar.Conduit O43 - CFD: 20/01/2013 - 17:50:02 - [8,430] ----D C:\ProgramData\AVG January 2013 Campaign => Toolbar.AVGSearch O43 - CFD: 14/10/2012 - 15:31:30 - [1,808] ----D C:\Users\ramzi\AppData\Local\Conduit => Toolbar.Conduit O43 - CFD: 01/02/2013 - 21:39:41 - [17,033] ----D C:\Users\ramzi\AppData\Local\Smartbar => Toolbar.Smartbar* O69 - SBI: C:\Users\ramzi\AppData\Roaming\Mozilla\Firefox\Profiles\zsoobouo.default\searchplugins\conduit.xml => Toolbar.Conduit O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.1000234.TWC_TMP_city", "TUNIS"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.1000234.TWC_TMP_country", "TN"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.1000234.TWC_locId", "TSXX0010"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.1000234.TWC_location", "Tunis, Tunisia"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.1000234.TWC_region", "OT"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.1000234.TWC_temp_dis", "c"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.1000234.TWC_wind_dis", "kmh"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.1000234.weatherData", "{\"icon\":\"29.png\",\"temperature\":\"20°C\",\"temperatureClear\":\"20°C\",\"highTe[...] => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.FirstTime", "true"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.FirstTimeFF3", "true"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.LoginRevertSettingsEnabled", true); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.RevertSettingsEnabled", true); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.UserID", "UN22563032473246902"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.addressBarTakeOverEnabledInHidden", "true"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.autoDisableScopes", -1); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.cbcountry_001", "TN"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.cbfirsttime", "Sun Oct 14 2012 15:32:03 GMT+0100"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.defaultSearch", "FALSE"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.enableAlerts", "always"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.enableFix404ByUser", "FALSE"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.enableSearchFromAddressBar", "FALSE"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.firstTimeDialogOpened", "true"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.fixPageNotFoundError", "true"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.fixPageNotFoundErrorByUser", "true"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.fixPageNotFoundErrorInHidden", "true"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.fixUrls", true); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.installId", "fft6C1C.tmp.exe"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.installType", "XPE"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.isCheckedStartAsHidden", true); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.isFirstTimeToolbarLoading", "false"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.isNewTabEnabled", true); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.isPerformedSmartBarTransition", "true"); => Toolbar.Smartbar* O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"http://search.conduit.com/?ctid=CT2851639&octid=CT2[...] => Toolbar.Conduit* O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.lastVersion", "10.14.42.7"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.migrateAppsAndComponents", true); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"\",\"EB_MAIN_FRAME_TITLE\":\"\",\"EB_SEARCH_TERM\":\"\",\"E[...] => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.openThankYouPage", "true"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.openUninstallPage", "FALSE"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.search.searchAppId", "129351529700743801"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.search.searchCount", "0"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.searchInNewTabEnabledByUser", "true"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.searchInNewTabEnabledInHidden", "true"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT2851639\"}"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"1\"}"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1350225110635"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_services_appsMetadata_lastUpdate", "1350225110247"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1350225110643"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_services_login_10.10.27.6_lastUpdate", "1353619037084"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_services_login_10.13.40.15_lastUpdate", "1358339476697"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_services_login_10.14.40.128_lastUpdate", "1359721218579"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_services_login_10.14.42.7_lastUpdate", "1360301188642"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1350225111606"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_services_searchAPI_lastUpdate", "1350225109893"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_services_serviceMap_lastUpdate", "1360301188109"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_services_toolbarContextMenu_lastUpdate", "1350225110695"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_services_toolbarSettings_lastUpdate", "1360301188578"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.serviceLayer_services_translation_lastUpdate", "1360301189269"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.settingsINI", true); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.shouldFirstTimeDialog", "false"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.smartbar.CTID", "CT2851639"); => Toolbar.Smartbar* O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.smartbar.Uninstall", "0"); => Toolbar.Smartbar* O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.smartbar.isHidden", true); => Toolbar.Smartbar* O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.startPage", "userChanged"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.toolbarBornServerTime", "14-10-2012"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.toolbarCurrentServerTime", "8-2-2013"); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639.upgradeFromClearSBVersion", true); => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT2851639_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1360320950802,\"isWithState\"[...] => Toolbar.Agent O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT3128284.RSS_Pub_Config", "{\"settings\":{\"icon\":\"http://storage.conduit.com/bankimages/iconsGallery/24/46693806336[...] => Toolbar.Conduit* O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("CT3128284.SearchFromAddressBarUrl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT3128284&SearchSource=2&q="); => Toolbar.Conduit* O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("Smartbar.ConduitHomepagesList", ""); => Toolbar.Smartbar* O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("Smartbar.ConduitSearchEngineList", ""); => Toolbar.Smartbar* O69 - SBI: prefs.js [ramzi - zsoobouo.default] user_pref("Smartbar.ConduitSearchUrlList", ""); => Toolbar.Smartbar* O69 - SBI: SearchScopes [HKCU] {2682E22D-2E29-49E9-9D99-2E36287A97D0} - (uTorrentBar_FR Customized Web Search) - http://search.conduit.com => Toolbar.Conduit* [MD5.9B0355C4EB74CB09D844B3E4B3F1CEB7] [SPRF][30/08/2012] (.Conduit - 01NET.com Toolbar.) -- C:\Users\ramzi\AppData\Local\Temp\01NET.com.exe [2154904] [MD5.C36923084822C017F69396418A999D39] [SPRF][05/02/2013] (.Ask.com - AskStub Application.) -- C:\Users\ramzi\AppData\Local\Temp\ApnStub.exe [143240] [MD5.B28C334C03CEE7C5E829C43AE75DAE5A] [SPRF][28/01/2013] (.Ask.com - AskIC Dynamic Link Library.) -- C:\Users\ramzi\AppData\Local\Temp\AskSLib.dll [248008] [MD5.132E1C3A27E824EB6B120226AC368593] [SPRF][12/03/2012] (.Conduit - No comment.) -- C:\Users\ramzi\AppData\Local\Temp\conduitinstaller.exe [211032] [MD5.9497C6912ECEA28D5C2918F30D10B5D7] [SPRF][31/12/2012] (.Unknown owner - Linkury.Installer.MsiWrapper.) -- C:\Users\ramzi\AppData\Local\Temp\SmartbarExeInstaller.exe [8036776] => Toolbar.Smartbar* [MD5.73406FA9287B36CA4163797C73A2CD04] [SPRF][16/07/2012] (.Conduit Ltd. - Conduit Toolbar.) -- C:\Users\ramzi\AppData\Local\Temp\tbedrs.dll [4451144] => Toolbar.Conduit* [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E}] => Toolbar.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E}] => Toolbar.Agent [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E}] => Toolbar.Agent [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{177586E7-E42E-4F38-83D1-D15B4AF5B714}] => Toolbar.DeltaSearch [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{151867D5-7359-40AF-8764-66E58D06283C}] => Toolbar.01NET [HKLM\Software\Classes\Interface\{2a42d13c-d427-4787-821b-cf6973855778}] => Toolbar.Agent [HKLM\Software\Wow6432Node\Classes\Interface\{2a42d13c-d427-4787-821b-cf6973855778}] => Toolbar.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] => Toolbar.Agent [HKLM\Software\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] => Toolbar.Agent [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] => Toolbar.Agent [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] => Toolbar.Agent [HKLM\Software\Classes\Interface\{3d8478aa-7b88-48a9-8bcb-b85d594411ec}] => Toolbar.Agent [HKLM\Software\Wow6432Node\Classes\Interface\{3d8478aa-7b88-48a9-8bcb-b85d594411ec}] => Toolbar.Agent [HKLM\Software\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}] => Toolbar.Conduit [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01}] => Toolbar.SearchResults [HKLM\Software\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] => Toolbar.Skype [HKLM\Software\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] => Toolbar.Skype [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] => Toolbar.Skype [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}] => Toolbar.Agent [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E}] => Toolbar.CheatEngine [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype [HKLM\Software\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D6533F74-218B-41BE-9D91-5BD471FECFFD}] => Toolbar.Conduit [HKLM\Software\Classes\AppID\TbCommonUtils.DLL] => Toolbar.Agent [HKLM\Software\Classes\AppID\TbHelper.EXE] => Toolbar.Agent* [HKLM\Software\Classes\comobject.deskbarenabler] => Toolbar.Ant.com [HKLM\Software\Classes\comobject.deskbarenabler.1] => Toolbar.Ant.com [HKLM\Software\Classes\TbCommonUtils.CommonUtils] => Toolbar.Agent [HKLM\Software\Classes\TbCommonUtils.CommonUtils.1] => Toolbar.Agent [HKLM\Software\Classes\URLSearchHook.ToolbarURLSearchHook] => Adware.Agent [HKLM\Software\Classes\urlsearchhook.toolbarurlsearchhook] => Adware.Agent [HKLM\Software\Classes\urlsearchhook.toolbarurlsearchhook.1] => Adware.Agent [HKLM\Software\Wow6432Node\Google\Chrome\Extensions\ehdmaehkiiampolokajdcelladmnopgp] => Toolbar.01NET.com [HKLM\Software\Wow6432Node\Google\Chrome\Extensions\paoponfhfdfnjgddpnpjkambkcgdaaib] => Toolbar.uTorrentBar [HKLM\Software\Classes\Installer\Features\90C64EA18BA25EE488BF80DCF07F2FFD] => Toolbar.Bing [HKLM\Software\Classes\Installer\Products\90C64EA18BA25EE488BF80DCF07F2FFD] => Toolbar.Bing [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\90C64EA18BA25EE488BF80DCF07F2FFD] => Toolbar.Bing [HKLM\Software\Wow6432Node\Classes\Installer\Features\90C64EA18BA25EE488BF80DCF07F2FFD] => Toolbar.Bing [HKLM\Software\Wow6432Node\Classes\Installer\Products\90C64EA18BA25EE488BF80DCF07F2FFD] => Toolbar.Bing [HKCU\Software\AppDataLow\Software\01NET.com] => Toolbar.Agent [HKLM\Software\Wow6432Node\01NET.com] => Toolbar.Agent [HKCU\Software\AppDataLow\Software\ConduitSearchScopes] => Toolbar.Conduit [HKCU\Software\SmartbarBackup] => Toolbar.Smartbar* [HKCU\Software\SmartbarLog] => Toolbar.Smartbar* [HKCU\Software\Softonic] => Toolbar.Conduit* [HKCU\Software\AppDataLow\Toolbar] => Toolbar.Conduit [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}] => Toolbar.Bing [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\01NET.com Toolbar] => Toolbar.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}] => Toolbar.DeltaSearch [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}] => Toolbar.DeltaSearch [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}] => Toolbar.DeltaSearch [HKLM\Software\Classes\Installer\Features\7E685771E24E83F4381D1DB5A45F7B41] => Toolbar.DeltaSearch [HKLM\Software\Classes\Installer\Products\7E685771E24E83F4381D1DB5A45F7B41] => Toolbar.DeltaSearch [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7E685771E24E83F4381D1DB5A45F7B41] => Toolbar.DeltaSearch [HKLM\Software\Wow6432Node\Classes\Installer\Features\7E685771E24E83F4381D1DB5A45F7B41] => Toolbar.DeltaSearch [HKLM\Software\Wow6432Node\Classes\Installer\Products\7E685771E24E83F4381D1DB5A45F7B41] => Toolbar.DeltaSearch [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3}] => Toolbar.DeltaSearch [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3}] => Toolbar.DeltaSearch [HKLM\Software\Classes\TbHelper.TbDownloadManager] => Toolbar.Agent* [HKLM\Software\Classes\TbHelper.TbDownloadManager.1] => Toolbar.Agent* [HKLM\Software\Classes\TbHelper.TbPropertyManager] => Toolbar.Agent* [HKLM\Software\Classes\TbHelper.TbPropertyManager.1] => Toolbar.Agent* [HKLM\Software\Classes\TbHelper.TbRequest] => Toolbar.Agent* [HKLM\Software\Classes\TbHelper.TbRequest.1] => Toolbar.Agent* [HKLM\Software\Classes\TbHelper.TbTask] => Toolbar.Agent* [HKLM\Software\Classes\TbHelper.TbTask.1] => Toolbar.Agent* [HKLM\Software\Classes\TbHelper.ToolbarHelper] => Toolbar.Agent* [HKLM\Software\Classes\TbHelper.ToolbarHelper.1] => Toolbar.Agent* [HKLM\Software\Classes\TBSB02609.IEToolbar] => Toolbar.Agent* [HKLM\Software\Classes\TBSB02609.IEToolbar.1] => Toolbar.Agent* [HKLM\Software\Classes\TBSB02609.TBSB02609] => Toolbar.Agent* [HKLM\Software\Classes\TBSB02609.TBSB02609.3] => Toolbar.Agent* [HKLM\Software\Classes\Toolbar3.TBSB02609] => Toolbar.Agent* [HKLM\Software\Classes\Toolbar3.TBSB02609.1] => Toolbar.Agent* [HKLM\Software\Classes\Toolbar.CT2851639] => Toolbar.Conduit* [HKLM\Software\Classes\Toolbar.CT3128284] => Toolbar.Conduit* [HKLM\Software\Classes\Toolbar3.ContextMenuNotifier] => Toolbar.Agent* [HKLM\Software\Classes\Toolbar3.ContextMenuNotifier.1] => Toolbar.Agent* [HKLM\Software\Classes\Toolbar3.CustomInternetSecurityImpl] => Toolbar.Agent* [HKLM\Software\Classes\Toolbar3.CustomInternetSecurityImpl.1] => Toolbar.Agent* [HKLM\Software\Classes\Toolbar3.SearchProviderManager] => Toolbar.Agent* [HKLM\Software\Classes\Toolbar3.SearchProviderManager.1] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\TbHelper.TbDownloadManager] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\TbHelper.TbDownloadManager.1] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\TbHelper.TbPropertyManager] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\TbHelper.TbPropertyManager.1] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\TbHelper.TbRequest] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\TbHelper.TbRequest.1] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\TbHelper.TbTask] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\TbHelper.TbTask.1] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\TbHelper.ToolbarHelper] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\TbHelper.ToolbarHelper.1] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\TBSB02609.IEToolbar] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\TBSB02609.IEToolbar.1] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\TBSB02609.TBSB02609] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\TBSB02609.TBSB02609.3] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\Toolbar3.TBSB02609] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\Toolbar3.TBSB02609.1] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\Toolbar.CT2851639] => Toolbar.Conduit* [HKLM\Software\Wow6432Node\Classes\Toolbar.CT3128284] => Toolbar.Conduit* [HKLM\Software\Wow6432Node\Classes\Toolbar3.ContextMenuNotifier] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\Toolbar3.ContextMenuNotifier.1] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\Toolbar3.CustomInternetSecurityImpl] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\Toolbar3.CustomInternetSecurityImpl.1] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\Toolbar3.SearchProviderManager] => Toolbar.Agent* [HKLM\Software\Wow6432Node\Classes\Toolbar3.SearchProviderManager.1] => Toolbar.Agent* [HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{8E5025C2-8EA3-430D-80B8-A14151068A6D} => Toolbar.01NET.com [HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks]:{8E5025C2-8EA3-430D-80B8-A14151068A6D} => Toolbar.01NET.com [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar]:{8E5025C2-8EA3-430D-80B8-A14151068A6D} => Toolbar.01NET.com C:\Program Files (x86)\Conduit => Toolbar.Conduit C:\ProgramData\AVG January 2013 Campaign => Toolbar.AVGSearch C:\Users\ramzi\AppData\Local\Conduit => Toolbar.Conduit C:\Users\ramzi\AppData\Local\Smartbar => Toolbar.Smartbar* C:\Users\ramzi\AppData\LocalLow\Conduit => Toolbar.Conduit C:\Users\ramzi\AppData\LocalLow\Smartbar => Toolbar.Smartbar* C:\Users\ramzi\AppData\Local\Temp\Smartbar => Toolbar.Smartbar* C:\Users\ramzi\AppData\Roaming\Mozilla\Firefox\Profiles\zsoobouo.default\Smartbar => Toolbar.Smartbar* C:\Users\ramzi\AppData\Roaming\Mozilla\Firefox\Profiles\zsoobouo.default\SearchPlugins\conduit.xml => Toolbar.Conduit C:\Users\ramzi\AppData\Local\Temp\conduitinstaller.exe => Toolbar.Conduit C:\Users\ramzi\AppData\Local\Temp\tbedrs.dll => Toolbar.Conduit O90 - PUC: "7E685771E24E83F4381D1DB5A45F7B41" . (.Delta Chrome Toolbar.) -- C:\Windows\Installer\{177586E7-E42E-4F38-83D1-D15B4AF5B714}\Delta.ico O90 - PUC: "90C64EA18BA25EE488BF80DCF07F2FFD" . (.Bing Bar.) -- C:\Windows\Installer\{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}\icon_installer_ico