Script ZHPFix [MD5.44E5B5DC6A27EA109B8A234E640BB5FD] - (...) -- C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [3780064] [PID.1836] =>PUP.BitGuard [MD5.977EAD2A734AAD3218A9300A0824707A] - (.Smartbar - Smartbar.) -- C:\Users\Laura\AppData\Local\Smartbar\Application\SnapDo.exe [21536] [PID.4072] =>Hijacker.SmartBar [MD5.34AE0DFA3EE3B5B9975042D87332D0B7] - (...) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe [107520] [PID.1664] =>Adware.Bandoo G0 - GCSP: Preference [User Data\Default][HomePage] http://feed.snapdo.com =>Hijacker.SmartBar R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com =>Hijacker.SmartBar R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com =>Hijacker.SmartBar R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.com =>Hijacker.SmartBar R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.com =>Hijacker.SmartBar O2 - BHO: Babylon toolbar helper [64Bits] - {2EECD738-5844-4a99-B4B6-146BF802613B} . (.Babylon BHO - Pas de description.) -- C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.8.3.8\bh\BabylonToolbar.dll =>PUP.Babylon O2 - BHO: Snap.DoEngine [64Bits] - {31ad400d-1b06-4e33-a59a-90c2c140cba0} . (...) -- mscoree.dll (.not file.) =>Hijacker.SmartBar O2 - BHO: DefaultTabBHO [64Bits] - {7F6AFBF1-E065-4627-A2FD-810366367D01} . (.Search Results LLC. - Search Results.) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll =>Adware.Bandoo O2 - BHO: DealPly [64Bits] - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} . (.DealPly Technologies Ltd - DealPly for Internet Explorer.) -- C:\Program Files (x86)\DealPly\DealPlyIE.dll =>PUP.DealPly O2 - BHO: holasearch Helper Object [64Bits] - {DFF9B2DA-EF99-4B26-83CB-7058299999D8} . (.holasearch.com - Pas de description.) -- C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll =>Hijacker.HolaSearch O4 - GS\Desktop [Public]: PC Performer.lnk . (.PerformerSoft LLC - PC Performer.) -- C:\Program Files (x86)\PC Performer\PCPerformer.exe =>Rogue.PCPerformer O4 - GS\Program [Laura]: Search.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://feed.snapdo.com =>Hijacker.SmartBar O4 - GS\Desktop [Laura]: Search.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://feed.snapdo.com =>Hijacker.SmartBar O4 - HKCU\..\Run: [Browser Infrastructure Helper] . (.Smartbar - Smartbar.) -- C:\Users\Laura\AppData\Local\Smartbar\Application\SnapDo.exe =>Hijacker.SmartBar O4 - HKUS\S-1-5-21-1417406654-2775627020-3062465056-1000\..\Run: [Browser Infrastructure Helper] . (.Smartbar - Smartbar.) -- C:\Users\Laura\AppData\Local\Smartbar\Application\SnapDo.exe =>Hijacker.SmartBar O20 - AppInit_DLLs: . (...) - c:\progra~3\bitguard\271832~1.68\{c16c1~1\loader.dll =>PUP.BitGuard O23 - Service: BitGuard (BitGuard) . (...) - C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe =>PUP.BitGuard O23 - Service: DefaultTabUpdate (DefaultTabUpdate) . (...) - C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe =>Adware.Bandoo O39 - APT:Automatic Planified Task - C:\Windows\Tasks\PC Performer_DEFAULT.job [276] =>Rogue.PCPerformer O39 - APT:Automatic Planified Task - C:\Windows\Tasks\PC Performer_UPDATES.job [284] =>Rogue.PCPerformer [MD5.A6D24077E8D9D58FA63389A34ED1DEC7] [APT] [DealPly] (...) -- C:\Users\Laura\AppData\Roaming\DealPly\UPDATE~1\UPDATE~1.exe [93752] =>PUP.DealPly [MD5.4EE862402A5ECEE9A6F291E08B79F2C7] [APT] [DealPlyUpdate] (.DealPly.) -- C:\Program Files (x86)\DealPly\DealPlyUpdate.exe [78024] =>PUP.DealPly [MD5.3E8DCB18626B2D82E4010B3EAEAD4245] [APT] [DTReg] (.Search Results, LLC.) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\DTReg.exe [58976] =>Adware.Bandoo [MD5.71D490C463014E4FB88B8CBA700B111E] [APT] [EPUpdater] (...) -- C:\Users\Laura\AppData\Roaming\BabSolution\Shared\BabMaint.exe [4608] =>Hijacker.BabSolution [MD5.EB29B863B5F4FE6FDA0E01784709647E] [APT] [PC Performer] (.PerformerSoft LLC.) -- C:\Program Files (x86)\PC Performer\PCPerformer.exe [7343792] =>Rogue.PCPerformer [MD5.EB29B863B5F4FE6FDA0E01784709647E] [APT] [PC Performer_DEFAULT] (.PerformerSoft LLC.) -- C:\Program Files (x86)\PC Performer\PCPerformer.exe [7343792] =>Rogue.PCPerformer [MD5.EB29B863B5F4FE6FDA0E01784709647E] [APT] [PC Performer_UPDATES] (.PerformerSoft LLC.) -- C:\Program Files (x86)\PC Performer\PCPerformer.exe [7343792] =>Rogue.PCPerformer O42 - Logiciel: Babylon toolbar - (.BabylonToolbar.) [HKLM][64Bits] -- BabylonToolbar =>PUP.Babylon O42 - Logiciel: BitGuard - (.MediaTechSoft Inc..) [HKLM][64Bits] -- {15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693} =>PUP.BitGuard O42 - Logiciel: DealPly - (...) [HKCU][64Bits] -- DealPly =>PUP.DealPly O42 - Logiciel: DealPly - (.DealPly Technologies Ltd.) [HKLM][64Bits] -- DealPly =>PUP.DealPly O42 - Logiciel: DefaultTab - (.Search Results, LLC.) [HKLM][64Bits] -- DefaultTab =>Adware.Bandoo O42 - Logiciel: DefaultTab Chrome - (.Search Results, LLC.) [HKLM][64Bits] -- DefaultTab Chrome =>Adware.Bandoo O42 - Logiciel: PC Performer - (.PerformerSoft LLC.) [HKLM][64Bits] -- PC Performer_is1 =>Rogue.PCPerformer O42 - Logiciel: Snap.Do - (.ReSoft Ltd..) [HKLM][64Bits] -- {084B3661-F647-4E44-9018-D7DCDF538057} =>Hijacker.SmartBar O42 - Logiciel: Snap.Do Engine - (.ReSoft Ltd..) [HKCU][64Bits] -- {4552a266-4737-4a00-a7c4-647c67d09f43} =>Hijacker.SmartBar O42 - Logiciel: Vittalia Installer - (.fr.FILEWIN.com.) [HKLM][64Bits] -- Vittalia =>PUP.Vittalia O42 - Logiciel: hola Chrome Toolbar - (.hola.) [HKLM][64Bits] -- hola Chrome Toolbar =>Hijacker.HolaSearch O42 - Logiciel: holasearch toolbar - (.holasearch.) [HKLM][64Bits] -- holasearch =>Hijacker.HolaSearch [HKCU\Software\95788d9b03de443] =>Hijacker.Eazel [HKCU\Software\AppDataLow\Software\DefaultTab] =>Adware.Bandoo [HKCU\Software\AppDataLow\Software\PriceGong] =>Adware.PriceGong [HKCU\Software\AppDataLow\Software\Smartbar] =>Hijacker.SmartBar [HKCU\Software\BabSolution] =>Hijacker.BabSolution [HKCU\Software\BabylonToolbar] =>PUP.Babylon [HKCU\Software\DataMngr] =>PUP.Datamngr [HKCU\Software\DataMngr_Toolbar] =>PUP.Datamngr [HKCU\Software\Default Tab] =>Adware.Bandoo [HKCU\Software\DefaultTab] =>Adware.Bandoo [HKCU\Software\FileScout] =>PUP.FileScout [HKCU\Software\SmartbarBackup] =>Hijacker.SmartBar [HKCU\Software\SmartbarLog] =>Hijacker.SmartBar [HKCU\Software\Smartbar] =>Hijacker.SmartBar [HKCU\Software\holasearch] =>Hijacker.HolaSearch [HKLM\Software\Wow6432Node\95788d9b03de443] =>Hijacker.Eazel [HKLM\Software\Wow6432Node\Babylon] =>PUP.Babylon [HKLM\Software\Wow6432Node\DataMngr] =>PUP.Datamngr [HKLM\Software\Wow6432Node\Default Tab] =>Adware.Bandoo O43 - CFD: 29/10/2012 - 22:25:08 - [2,445] ----D C:\Program Files (x86)\BabylonToolbar =>PUP.Babylon O43 - CFD: 10/01/2014 - 15:28:07 - [0,939] ----D C:\Program Files (x86)\DealPly =>PUP.DealPly O43 - CFD: 19/11/2013 - 09:09:38 - [0,369] ----D C:\Program Files (x86)\DefaultTab =>Adware.Bandoo O43 - CFD: 18/06/2013 - 20:56:51 - [2,436] ----D C:\Program Files (x86)\holasearch =>Hijacker.HolaSearch O43 - CFD: 08/10/2013 - 22:11:09 - [11,876] ----D C:\Program Files (x86)\PC Performer =>Rogue.PCPerformer O43 - CFD: 08/10/2013 - 22:11:21 - [0,071] ----D C:\Program Files (x86)\Vittalia =>PUP.Vittalia O43 - CFD: 29/10/2012 - 22:24:52 - [0] ----D C:\ProgramData\Babylon =>PUP.Babylon O43 - CFD: 01/12/2013 - 16:27:46 - [12,737] ----D C:\ProgramData\BitGuard =>PUP.BitGuard O43 - CFD: 18/06/2013 - 20:56:12 - [0,002] ----D C:\ProgramData\IBUpdaterService =>Adware.InstallBrain O43 - CFD: 18/06/2013 - 20:56:50 - [1,311] ----D C:\Users\Laura\AppData\Roaming\BabSolution =>Hijacker.BabSolution O43 - CFD: 29/10/2012 - 22:24:52 - [0,024] ----D C:\Users\Laura\AppData\Roaming\Babylon =>PUP.Babylon O43 - CFD: 17/03/2013 - 13:31:36 - [0,090] ----D C:\Users\Laura\AppData\Roaming\DealPly =>PUP.DealPly O43 - CFD: 31/10/2012 - 15:28:17 - [3,275] ----D C:\Users\Laura\AppData\Roaming\DefaultTab =>Adware.Bandoo O43 - CFD: 08/10/2013 - 22:12:52 - [0,308] ----D C:\Users\Laura\AppData\Roaming\File Scout =>PUP.FileScout O43 - CFD: 08/10/2013 - 22:12:52 - [0,259] ----D C:\Users\Laura\AppData\Roaming\holasearch =>Hijacker.HolaSearch O43 - CFD: 31/10/2012 - 16:17:39 - [42,721] ----D C:\Users\Laura\AppData\Roaming\OpenCandy =>Adware.OpenCandy O43 - CFD: 31/10/2012 - 15:28:38 - [0] ----D C:\Users\Laura\AppData\Local\Lollipop =>Adware.Lollipop O43 - CFD: 10/11/2013 - 17:29:06 - [21,258] ----D C:\Users\Laura\AppData\Local\Smartbar =>Hijacker.SmartBar O43 - CFD: 22/11/2013 - 14:01:00 - [0,001] ----D C:\Users\Laura\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard =>PUP.BitGuard O61 - LFC: 16/01/2014 - 20:47:57 ---A- . (...) -- C:\Users\Laura\AppData\Local\Temp\smartbar\RadioTVIcons\1893260371.png [743] =>Hijacker.SmartBar O61 - LFC: 16/01/2014 - 20:47:57 ---A- . (...) -- C:\Users\Laura\AppData\Local\Temp\smartbar\RadioTVIcons\3823177572.png [709] =>Hijacker.SmartBar O61 - LFC: 16/01/2014 - 20:47:58 ---A- . (...) -- C:\Users\Laura\AppData\Local\Temp\smartbar\RadioTVIcons\3847014217.png [714] =>Hijacker.SmartBar O61 - LFC: 16/01/2014 - 20:47:58 ---A- . (...) -- C:\Users\Laura\AppData\Local\Temp\smartbar\RadioTVIcons\3887458186.png [693] =>Hijacker.SmartBar O61 - LFC: 16/01/2014 - 20:47:58 ---A- . (...) -- C:\Users\Laura\AppData\Local\Temp\smartbar\RadioTVIcons\876609851.png [701] =>Hijacker.SmartBar O61 - LFC: 16/01/2014 - 20:54:30 ---A- . (.Search Results, LLC.) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\DTReg.exe [58976] =>Adware.Bandoo O61 - LFC: 18/01/2014 - 20:46:21 ---A- . (...) -- C:\Users\Laura\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_amfclgbdpgndipgoegfpkkgobahigbcl_0.localstorage [5120] O61 - LFC: 18/01/2014 - 20:46:21 ---A- . (...) -- C:\Users\Laura\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_amfclgbdpgndipgoegfpkkgobahigbcl_0.localstorage-journal [5672] O61 - LFC: 18/01/2014 - 20:46:21 ---A- . (...) -- C:\Users\Laura\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gaiilaahiahdejapggenmdmafpmbipje_0.localstorage [3072] O61 - LFC: 18/01/2014 - 20:46:21 ---A- . (...) -- C:\Users\Laura\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gaiilaahiahdejapggenmdmafpmbipje_0.localstorage-journal [3608] O61 - LFC: 18/01/2014 - 20:46:21 ---A- . (...) -- C:\Users\Laura\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kdidombaedgpfiiedeimiebkmbilgmlc_0.localstorage [34816] O61 - LFC: 18/01/2014 - 20:46:21 ---A- . (...) -- C:\Users\Laura\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kdidombaedgpfiiedeimiebkmbilgmlc_0.localstorage-journal [16384] O61 - LFC: 18/01/2014 - 20:54:30 ---A- . (.Search Results LLC..) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll [472184] =>Adware.Bandoo O61 - LFC: 18/01/2014 - 20:54:30 ---A- . (.Search Results LLC..) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabStart.exe [50296] =>Adware.Bandoo O61 - LFC: 18/01/2014 - 20:54:30 ---A- . (.Search Results LLC..) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabStart64.exe [53880] =>Adware.Bandoo O61 - LFC: 18/01/2014 - 20:54:30 ---A- . (.Search Results LLC..) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabWrap.dll [444024] =>Adware.Bandoo O61 - LFC: 18/01/2014 - 20:54:30 ---A- . (.Search Results LLC..) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabWrap64.dll [529016] =>Adware.Bandoo O61 - LFC: 18/01/2014 - 20:54:34 ---A- . (.Search Results, LLC.) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\update.exe [878176] =>Adware.Bandoo O61 - LFC: 19/01/2014 - 20:46:07 ---A- . (...) -- C:\Users\Laura\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\publisherDefinitions.js [3292] O61 - LFC: 19/01/2014 - 20:46:08 ---A- . (...) -- C:\Users\Laura\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\redirect.js [244] O61 - LFC: 19/01/2014 - 20:47:34 ---A- . (...) -- C:\Users\Laura\AppData\Local\Smartbar\DistributionFiles\Configs\UserSettings.xml [4061] =>Hijacker.SmartBar O61 - LFC: 19/01/2014 - 20:47:55 ---A- . (...) -- C:\Users\Laura\AppData\Local\Temp\smartbar\0jtxq5am.k2h [492] =>Hijacker.SmartBar O61 - LFC: 19/01/2014 - 20:47:56 ---A- . (...) -- C:\Users\Laura\AppData\Local\Temp\smartbar\e14eltmh.pqb [630] =>Hijacker.SmartBar O61 - LFC: 19/01/2014 - 20:47:57 ---A- . (...) -- C:\Users\Laura\AppData\Local\Temp\smartbar\qyx4hg5z.yoi [777] =>Hijacker.SmartBar O61 - LFC: 19/01/2014 - 20:54:30 ---A- . (...) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.cfg [14957] =>Adware.Bandoo O61 - LFC: 19/01/2014 - 20:54:30 ---A- . (...) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\amazon_ie.ico [1150] =>Adware.Bandoo O61 - LFC: 19/01/2014 - 20:54:30 ---A- . (...) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\blocklist.json [176417] =>Adware.Bandoo O61 - LFC: 19/01/2014 - 20:54:30 ---A- . (...) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\ebay_ie.ico [1406] =>Adware.Bandoo O61 - LFC: 19/01/2014 - 20:54:30 ---A- . (...) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\facebook_ie.ico [1150] =>Adware.Bandoo O61 - LFC: 19/01/2014 - 20:54:30 ---A- . (...) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\search_here_ie.ico [1406] =>Adware.Bandoo O61 - LFC: 19/01/2014 - 20:54:30 ---A- . (...) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\twitter_ie.ico [1150] =>Adware.Bandoo O61 - LFC: 19/01/2014 - 20:54:34 ---A- . (...) -- C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\wikipedia_ie.ico [318] =>Adware.Bandoo O69 - SBI: SearchScopes [HKCU] {006ee092-9658-4fd6-bd8e-a21a348e59f5} [DefaultScope] - (Web Search) - http://feed.snapdo.com =>Hijacker.SmartBar O69 - SBI: SearchScopes [HKCU] {FE7A2F1C-66AC-4DDF-B180-FB5708A3DDE9} - (Search Here) - http://www.mysearchresults.com =>Adware.MyWebSearch [MD5.953F9AE5A36C5C281FB0A1A75727FD37] [SPRF][31/10/2012] (.DealPly - DealPly.) -- C:\Users\Laura\AppData\Local\Temp\dealply.exe [484624] =>PUP.DealPly [MD5.AC04843865032D4D1A258ED1774DE8CB] [SPRF][31/10/2012] (.Search Results - DefaultTabSetup.exe.) -- C:\Users\Laura\AppData\Local\Temp\DefaultTabSetup.exe [3182224] =>Adware.Bandoo [MD5.75E68C0C7910D38542792B1B5D0C179D] [SPRF][31/10/2012] (...) -- C:\Users\Laura\AppData\Local\Temp\instloffer.exe [61494] [MD5.77DFB27D68CE46659A3D5E93410C0B75] [SPRF][31/10/2012] (.Babylon Ltd. - Babylon Client Setup.) -- C:\Users\Laura\AppData\Local\Temp\tbbabylonv3.exe [899224] =>PUP.Babylon [HKCU\Software\95788d9b03de443\2.6.1519.190\upd]:="upd=1" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\2.6.1694.246\upd]:="upd=" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\2.7.1769.27\upd]:="upd=" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\2.7.1832.68\upd]:="upd=" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1339.144]:dllName="BrowserDefender.dll" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1339.144]:exeName="BrowserDefender.exe" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1339.144]:folderName="BrowserDefender" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1339.144]:guid="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1339.144]:serviceName="BrowserDefendert" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1339.144]:version="2.6.1339.144" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1519.190]:dllName="BrowserDefender.dll" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1519.190]:exeName="BrowserDefender.exe" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1519.190]:folderName="BrowserDefender" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1519.190]:guid="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1519.190]:serviceName="BrowserDefendert" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1519.190]:version="2.6.1519.190" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1694.246]:dllName="BitGuard.dll" =>PUP.BitGuard [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1694.246]:exeName="BitGuard.exe" =>PUP.BitGuard [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1694.246]:folderName="BitGuard" =>PUP.BitGuard [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1694.246]:guid="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1694.246]:serviceName="BitGuard" =>PUP.BitGuard [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1694.246]:version="2.6.1694.246" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.7.1769.27]:SERVICE_NAME="BitGuard" =>PUP.BitGuard [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.7.1769.27]:dllName="BitGuard.dll" =>PUP.BitGuard [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.7.1769.27]:exeName="BitGuard.exe" =>PUP.BitGuard [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.7.1769.27]:folderName="BitGuard" =>PUP.BitGuard [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.7.1769.27]:guid="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.7.1769.27]:version="2.7.1769.27" =>Hijacker.Eazel [HKCU\Software\95788d9b03de443]:version="2.7.1832.68" =>Hijacker.Eazel [HKLM\Software\Wow6432Node\95788d9b03de443]:version="2.7.1832.68" =>Hijacker.Eazel [MD5.5DD3CF37373872DC0F90EC1ABF466B99] [WIS][10/11/2013] (.ReSoft Ltd. - Snap.Do.) -- C:\Windows\Installer\bb3bd13.msi [9543680] =>Hijacker.SmartBar SR - | Auto 18/11/2013 3780064 | (BitGuard) . (...) - C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe =>PUP.BitGuard SR - | Auto 31/10/2012 107520 | (DefaultTabUpdate) . (...) - C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe =>Adware.Bandoo [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4A99-B4B6-146BF802613B}] =>PUP.Babylon^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>Hijacker.SmartBar^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}] =>Adware.Bandoo^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}] =>PUP.DealPly^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DFF9B2DA-EF99-4B26-83CB-7058299999D8}] =>Hijacker.HolaSearch^ [HKLM\SYSTEM\CurrentControlSet\Services\BitGuard] =>PUP.BitGuard^ [HKLM\SYSTEM\CurrentControlSet\Services\DefaultTabUpdate] =>Adware.Bandoo^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar] =>PUP.Babylon^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}] =>PUP.BitGuard^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DealPly] =>PUP.DealPly^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DealPly] =>PUP.DealPly^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab] =>Adware.Bandoo^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab Chrome] =>Adware.Bandoo^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\PC Performer_is1] =>Rogue.PCPerformer^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{084B3661-F647-4E44-9018-D7DCDF538057}] =>Hijacker.SmartBar^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4552a266-4737-4a00-a7c4-647c67d09f43}] =>Hijacker.SmartBar^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vittalia] =>PUP.Vittalia^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\hola Chrome Toolbar] =>Hijacker.HolaSearch^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\holasearch] =>Hijacker.HolaSearch^ [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}] =>Hijacker.SmartBar [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}] =>Hijacker.SmartBar [HKLM\Software\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}] =>PUP.Babylon [HKLM\Software\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}] =>PUP.Babylon [HKLM\Software\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}] =>PUP.Babylon [HKLM\Software\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}] =>PUP.Babylon [HKLM\Software\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}] =>PUP.Babylon [HKLM\Software\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] =>PUP.Babylon [HKLM\Software\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] =>PUP.Babylon [HKLM\Software\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}] =>Hijacker.SmartBar [HKLM\Software\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}] =>Hijacker.SmartBar [HKLM\Software\Wow6432Node\Microsoft\Tracing\SnapDo_RASAPI32] =>Hijacker.SmartBar [HKLM\Software\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}] =>Hijacker.SmartBar [HKLM\Software\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}] =>PUP.Babylon [HKLM\Software\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}] =>PUP.Babylon [HKLM\Software\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}] =>PUP.Babylon [HKLM\Software\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Microsoft\Tracing\SnapDo_RASMANCS] =>Hijacker.SmartBar [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}] =>PUP.DealPly [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}] =>PUP.DealPly [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}] =>PUP.DealPly [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ae07101b-46d4-4a98-af68-0333ea26e113}] =>Adware.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ae07101b-46d4-4a98-af68-0333ea26e113}] =>Adware.Agent [HKLM\Software\Classes\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}] =>Adware.Agent [HKLM\Software\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}] =>PUP.Babylon [HKLM\Software\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}] =>PUP.Babylon [HKLM\Software\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}] =>PUP.Babylon [HKLM\Software\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}] =>PUP.Babylon [HKLM\Software\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}] =>Adware.CDNHelper [HKLM\Software\Wow6432Node\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}] =>Adware.CDNHelper [HKLM\Software\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}] =>PUP.Babylon [HKLM\Software\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}] =>PUP.Babylon [HKLM\Software\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}] =>Hijacker.SmartBar [HKLM\Software\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] =>PUP.Babylon [HKLM\Software\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] =>PUP.Babylon [HKLM\Software\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}] =>PUP.Babylon [HKLM\Software\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}] =>PUP.Babylon [HKLM\Software\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}] =>PUP.Babylon [HKLM\Software\Classes\AppID\escort.dll] =>PUP.Babylon [HKLM\Software\Classes\AppID\escortapp.dll] =>PUP.Babylon [HKLM\Software\Classes\AppID\escorteng.dll] =>PUP.Babylon [HKLM\Software\Classes\AppID\esrv.EXE] =>PUP.Babylon [HKLM\Software\Classes\b] =>PUP.Babylon [HKLM\Software\Classes\Babylon.dskBnd] =>PUP.Babylon [HKLM\Software\Classes\Babylon.dskBnd.1] =>PUP.Babylon [HKLM\Software\Classes\bbylnApp.appCore] =>PUP.Babylon [HKLM\Software\Classes\bbylnApp.appCore.1] =>PUP.Babylon [HKLM\Software\Classes\escort.escortIEPane] =>PUP.Funmoods [HKLM\Software\Classes\escort.escortIEPane.1] =>PUP.Funmoods [HKLM\Software\Classes\esrv.BabylonESrvc] =>PUP.Babylon [HKLM\Software\Classes\esrv.BabylonESrvc.1] =>PUP.Babylon [HKLM\Software\Wow6432Node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje] =>PUP.DealPly [HKCU\Software\BabylonToolbar] =>PUP.Babylon [HKLM\Software\Wow6432Node\BabylonToolbar] =>PUP.Babylon [HKCU\Software\DataMngr] =>Adware.Bandoo [HKLM\Software\Wow6432Node\DataMngr] =>Adware.Bandoo [HKCU\Software\default tab] =>Adware.IMBooster [HKLM\Software\Wow6432Node\default tab] =>Adware.IMBooster [HKCU\Software\defaulttab] =>Adware.IMBooster [HKCU\Software\AppDataLow\Software\defaulttab] =>Adware.IMBooster [HKLM\Software\Wow6432Node\defaulttab] =>Adware.IMBooster [HKCU\Software\AppDataLow\Software\PriceGong] =>Adware.PriceGong [HKCU\Software\SmartbarBackup] =>Hijacker.SmartBar [HKCU\Software\SmartbarLog] =>Hijacker.SmartBar [HKCU\Software\DealPly] =>PUP.DealPly [HKLM\Software\Wow6432Node\DealPly] =>PUP.DealPly [HKLM\Software\Wow6432Node\Microsoft\Tracing\MyBabylontb_RASAPI32] =>PUP.Babylon [HKLM\Software\Wow6432Node\Microsoft\Tracing\MyBabylontb_RASMANCS] =>PUP.Babylon [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar] =>PUP.Babylon [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DealPly] =>PUP.DealPly [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab Chrome] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PC Performer_is1] =>Rogue.PCPerformer [HKLM\Software\Classes\Prod.cap] =>PUP.Babylon [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings] =>PUP.BProtector [HKCU\Software\holasearch] =>Hijacker.HolaSearch [HKLM\Software\Wow6432Node\holasearch] =>Hijacker.HolaSearch [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\holasearch] =>Hijacker.HolaSearch [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Hola Chrome Toolbar] =>Hijacker.HolaSearch [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C510DFFB-0AFE-484C-BA40-CED5B74C4EEF}] =>Hijacker.HolaSearch [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C510DFFB-0AFE-484C-BA40-CED5B74C4EEF}] =>Hijacker.HolaSearch [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DFF9B2DA-EF99-4B26-83CB-7058299999D8}] =>Hijacker.HolaSearch [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DFF9B2DA-EF99-4B26-83CB-7058299999D8}] =>Hijacker.HolaSearch [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DFF9B2DA-EF99-4B26-83CB-7058299999D8}] =>Hijacker.HolaSearch [HKLM\Software\Wow6432Node\Google\Chrome\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc] =>Adware.Bandoo [HKLM\Software\Wow6432Node\Google\Chrome\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla] =>Hijacker.HolaSearch [HKLM\Software\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}] =>PUP.Babylon [HKLM\Software\Classes\protector_dll.protectorbho] =>PUP.BProtector [HKLM\Software\Classes\protector_dll.protectorbho.1] =>PUP.BProtector [HKLM\Software\Classes\AppID\escorTlbr.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\escort.escortIEPane] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\escort.escortIEPane.1] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\escort.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\escortApp.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\escortEng.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\escorTlbr.DLL] =>PUP.Funmoods [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:Browser Infrastructure Helper =>Hijacker.SmartBar^ C:\Program Files (x86)\BabylonToolbar =>PUP.Babylon^ C:\Program Files (x86)\DealPly =>PUP.DealPly^ C:\Program Files (x86)\DefaultTab =>Adware.Bandoo^ C:\Program Files (x86)\holasearch =>Hijacker.HolaSearch^ C:\Program Files (x86)\PC Performer =>Rogue.PCPerformer^ C:\Program Files (x86)\Vittalia =>PUP.Vittalia^ C:\ProgramData\Babylon =>PUP.Babylon^ C:\ProgramData\BitGuard =>PUP.BitGuard^ C:\ProgramData\IBUpdaterService =>Adware.InstallBrain^ C:\Users\Laura\AppData\Roaming\BabSolution =>Hijacker.BabSolution^ C:\Users\Laura\AppData\Roaming\Babylon =>PUP.Babylon^ C:\Users\Laura\AppData\Roaming\DealPly =>PUP.DealPly^ C:\Users\Laura\AppData\Roaming\DefaultTab =>Adware.Bandoo^ C:\Users\Laura\AppData\Roaming\File Scout =>PUP.FileScout^ C:\Users\Laura\AppData\Roaming\holasearch =>Hijacker.HolaSearch^ C:\Users\Laura\AppData\Roaming\OpenCandy =>Adware.OpenCandy^ C:\Users\Laura\AppData\Local\Lollipop =>Adware.Lollipop^ C:\Users\Laura\AppData\Local\Smartbar =>Hijacker.SmartBar^ C:\Users\Laura\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard =>PUP.BitGuard^ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly =>PUP.DealPly C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Performer =>Rogue.PCPerformer C:\Users\Laura\AppData\LocalLow\BabylonToolbar =>PUP.Babylon C:\Users\Laura\AppData\LocalLow\PriceGong =>Adware.PriceGong C:\Users\Laura\AppData\LocalLow\Smartbar =>Hijacker.SmartBar C:\Users\Laura\AppData\LocalLow\holasearch =>Hijacker.HolaSearch C:\Users\Laura\AppData\Local\Temp\Smartbar =>Hijacker.SmartBar C:\Users\Laura\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc =>Adware.Bandoo C:\Users\Laura\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl =>PUP.QuickShare C:\Users\Laura\AppData\Local\Google\Chrome\User Data\Default\Extensions\fagpjgjmoaccgkkpjeoinehnoaimnbla =>Hijacker.HolaSearch C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe =>PUP.BitGuard^ C:\Users\Laura\AppData\Local\Smartbar\Application\SnapDo.exe =>Hijacker.SmartBar^ C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe =>Adware.Bandoo^ C:\Windows\Tasks\PC Performer_DEFAULT.job =>Rogue.PCPerformer^ C:\Windows\Tasks\PC Performer_UPDATES.job =>Rogue.PCPerformer^ C:\Users\Laura\AppData\Roaming\DealPly\UPDATE~1\UPDATE~1.exe =>PUP.DealPly^ C:\Program Files (x86)\DealPly\DealPlyUpdate.exe =>PUP.DealPly^ C:\Users\Laura\AppData\Roaming\DefaultTab\DefaultTab\DTReg.exe =>Adware.Bandoo^ C:\Users\Laura\AppData\Roaming\BabSolution\Shared\BabMaint.exe =>Hijacker.BabSolution^ C:\Program Files (x86)\PC Performer\PCPerformer.exe =>Rogue.PCPerformer^ [HKCU\Software\AppDataLow\Software\DefaultTab] =>Adware.Bandoo^ [HKCU\Software\AppDataLow\Software\Smartbar] =>Hijacker.SmartBar^ [HKCU\Software\BabSolution] =>Hijacker.BabSolution^ [HKCU\Software\DataMngr_Toolbar] =>PUP.Datamngr^ [HKCU\Software\Default Tab] =>Adware.Bandoo^ [HKCU\Software\DefaultTab] =>Adware.Bandoo^ [HKCU\Software\FileScout] =>PUP.FileScout^ [HKCU\Software\Smartbar] =>Hijacker.SmartBar^ [HKLM\Software\Wow6432Node\Babylon] =>PUP.Babylon^ [HKLM\Software\Wow6432Node\Default Tab] =>Adware.Bandoo^ C:\Users\Laura\AppData\Local\Temp\dealply.exe =>PUP.DealPly^ C:\Users\Laura\AppData\Local\Temp\DefaultTabSetup.exe =>Adware.Bandoo^ C:\Users\Laura\AppData\Local\Temp\tbbabylonv3.exe =>PUP.Babylon^ [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1339.144]:dllName="BrowserDefender.dll" =>Hijacker.Eazel^ [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1519.190]:dllName="BrowserDefender.dll" =>Hijacker.Eazel^ [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1694.246]:dllName="BitGuard.dll" =>PUP.BitGuard^ [HKCU\Software\95788d9b03de443\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.7.1769.27]:SERVICE_NAME="BitGuard" =>PUP.BitGuard^ C:\Windows\Installer\bb3bd13.msi =>Hijacker.SmartBar^ C:\Users\Laura\AppData\Local\Temp\instloffer.exe =>PUP.OfferBox C:\Users\Laura\AppData\Local\Temp\square_sweetim.bmp =>PUP.SweetIM C:\Users\Laura\AppData\Local\Temp\toolbar_sweetim.bmp =>PUP.SweetIM C:\Users\Laura\AppData\Local\Temp\square_babylon.bmp =>PUP.SweetIM C:\Users\Laura\AppData\Local\Temp\square_babylonv2.bmp =>PUP.SweetIM C:\Users\Laura\AppData\Local\Temp\square_babylonv3.bmp =>PUP.SweetIM C:\Users\Laura\AppData\Local\Temp\square_lollipop.bmp =>Adware.Lollipop C:\Users\Laura\AppData\Local\Temp\GoogleToolbarInstaller1.log =>PUP.Babylon C:\Users\Laura\AppData\Local\Temp\GoogleToolbarInstaller2.log =>PUP.Babylon C:\Users\Laura\AppData\Local\Temp\pricepeep_logo.bmp =>Adware.PricePeep C:\Users\Laura\AppData\Local\Temp\square_pricepeep.bmp =>Adware.PricePeep O43 - CFD: 15/09/2013 - 13:57:40 - [0,110] ----D C:\Users\Laura\AppData\Local\avgchrome O39 - APT:Automatic Planified Task - C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1417406654-2775627020-3062465056-1000Core.job [906] O39 - APT:Automatic Planified Task - C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1417406654-2775627020-3062465056-1000UA.job [928] [MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-1417406654-2775627020-3062465056-1000Core] (.Facebook Inc..) -- C:\Users\Laura\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-1417406654-2775627020-3062465056-1000UA] (.Facebook Inc..) -- C:\Users\Laura\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096] [HKCU\Software\PerformerSoft] [HKLM\Software\Wow6432Node\PerformerSoft] O43 - CFD: 15/12/2012 - 18:21:30 - [0] ----D C:\Users\Laura\AppData\Roaming\DVDVideoSoftIEHelpers O43 - CFD: 18/06/2013 - 20:56:28 - [0,565] ----D C:\Users\Laura\AppData\Roaming\PerformerSoft O45 - LFCP:[MD5.ACB282A370C8CE170A800850072AD9DB] - 02/01/2014 - 12:12:05 ---A- - C:\Windows\Prefetch\HKCMD.EXE-AE1DFF3B.pf O45 - LFCP:[MD5.A4D0E3685979E7241A77115B8AC1CB5F] - 10/01/2014 - 20:40:04 ---A- - C:\Windows\Prefetch\AgCx_S1_S-1-5-21-1417406654-2775627020-3062465056-1000.snp.db O45 - LFCP:[MD5.B28C38F491A41FE8B2D610A8D1AE278E] - 10/01/2014 - 20:41:52 ---A- - C:\Windows\Prefetch\AgCx_SC3_E4C1C658100467A8.db O45 - LFCP:[MD5.ED3B5D334DA3B121E8F9B042019B0183] - 13/01/2014 - 21:34:57 ---A- - C:\Windows\Prefetch\MCVSSHLD.EXE-D7F6620D.pf O45 - LFCP:[MD5.F4810EA807853C89E8F3F5E0A3939524] - 17/01/2014 - 11:24:33 ---A- - C:\Windows\Prefetch\NBAGENT.EXE-74069EAC.pf O45 - LFCP:[MD5.172C462D44D40725AC250EEE3BE10821] - 17/01/2014 - 20:55:37 ---A- - C:\Windows\Prefetch\NTOSBOOT-B00DFAAD.pf O45 - LFCP:[MD5.0652361306E64744927C7D20857AFF25] - 18/01/2014 - 18:59:15 ---A- - C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-1417406654-2775627020-3062465056-1000.db O45 - LFCP:[MD5.AF4C1F913E004B16A8896D3280C91B4E] - 18/01/2014 - 18:59:15 ---A- - C:\Windows\Prefetch\AgGlUAD_S-1-5-21-1417406654-2775627020-3062465056-1000.db O45 - LFCP:[MD5.0FBE73508697A0392254256CC80850BC] - 19/01/2014 - 20:30:43 ---A- - C:\Windows\Prefetch\HPWUCLI.EXE-C018277F.pf O45 - LFCP:[MD5.46EB1336A837658C2E045853F1658FD8] - 19/01/2014 - 20:32:01 ---A- - C:\Windows\Prefetch\MCAGENT.EXE-414BDE46.pf O45 - LFCP:[MD5.E4636727DA8844A8399E4555C8E6C5C1] - 19/01/2014 - 20:38:03 ---A- - C:\Windows\Prefetch\FACEBOOKUPDATE.EXE-13F846DA.pf O61 - LFC: 16/01/2014 - 20:47:36 ---A- . (...) -- C:\Users\Laura\AppData\Local\Temp\12232_3957\crl-set [7146] O61 - LFC: 16/01/2014 - 20:47:37 ---A- . (...) -- C:\Users\Laura\AppData\Local\Temp\12232_3957\manifest.fingerprint [12] O61 - LFC: 16/01/2014 - 20:47:37 ---A- . (...) -- C:\Users\Laura\AppData\Local\Temp\12232_3957\manifest.json [34] O61 - LFC: 16/01/2014 - 20:47:42 ---A- . (...) -- C:\Users\Laura\AppData\Local\Temp\9b608f74-50c9-4dae-80e3-ae837f392cad.dmp [91711] O61 - LFC: 16/01/2014 - 20:47:46 --HA- . (...) -- C:\Users\Laura\AppData\Local\Temp\etilqs_wcUfmPa3QlcevQo [0] O61 - LFC: 18/01/2014 - 20:47:39 ---A- . (...) -- C:\Users\Laura\AppData\Local\Temp\376dacb6-8bb8-4a33-8a44-332338ffb93d.dmp [83273] [MD5.A11BF073B9E79F9CCEC174696719C1F4] [SPRF][27/07/2013] (.Microsoft Corporation - DefaultPack.) -- C:\Users\Laura\AppData\Local\Temp\BingBarSetup-Partner.exe [2198672] [MD5.92BB4D06B78DCC7964D55BA14DDD9B3F] [SPRF][22/10/2012] (...) -- C:\Users\Laura\AppData\Local\Temp\defaultCache.reg [52594] [MD5.2888CCA1467272C8257632D523D71059] [SPRF][31/10/2012] (.Clasys Ltd. - Pas de description.) -- C:\Users\Laura\AppData\Local\Temp\searchresults.exe [291352] O3 - Toolbar: McAfee SiteAdvisor Toolbar - [HKLM]{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} . (.McAfee, Inc. - SiteAdvisor.) -- C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified G1 - GCS: Preference [User Data\Default] None R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLinkedConnections"=1 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 O61 - LFC: 16/01/2014 - 20:55:02 ---A- . (...) -- C:\Users\Laura\Downloads\autoliquidation TVA (1).pdf [80345] O61 - LFC: 16/01/2014 - 20:55:02 ---A- . (...) -- C:\Users\Laura\Downloads\autoliquidation TVA (2).pdf [80345] O61 - LFC: 16/01/2014 - 20:55:02 ---A- . (...) -- C:\Users\Laura\Downloads\autoliquidation TVA (3).pdf [80345] O61 - LFC: 16/01/2014 - 20:55:02 ---A- . (...) -- C:\Users\Laura\Downloads\autoliquidation TVA.pdf [80345] O61 - LFC: 16/01/2014 - 20:55:03 ---A- . (...) -- C:\Users\Laura\Downloads\Les feux de l'amour suite 20141.pps [7520256] O61 - LFC: 18/01/2014 - 20:46:06 ---A- . (...) -- C:\Users\Laura\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG.old [0] O61 - LFC: 19/01/2014 - 20:46:06 ---A- . (...) -- C:\Users\Laura\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG [0] O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Not Key.) R3 - URLSearchHook: DVDVideoSoftTB Toolbar [64Bits] - {872b5b88-9db5-4310-bdd0-ac189557e5f5} . (.Conduit Ltd. - Conduit Toolbar.) (6.4.0.0) -- C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll =>Toolbar.Conduit O2 - BHO: DVDVideoSoftTB [64Bits] - {872b5b88-9db5-4310-bdd0-ac189557e5f5} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll =>Toolbar.Conduit O2 - BHO: Google Toolbar Helper [64Bits] - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google O2 - BHO: Bing Bar Helper [64Bits] - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} . (.Microsoft Corporation. - Extensions du client Bing.) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll =>Toolbar.Bing O2 - BHO: (no name) [64Bits] - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Clé orpheline O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll =>Toolbar.Google O3 - Toolbar\WebBrowser: (no name) - [HKCU]{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Clé orpheline O4 - GS\Desktop [Public]: eBay.lnk . (.eBay Inc. - Browser Launcher.) -- C:\Program Files (x86)\eBay\eBay.exe http://rover.ebay.com =>Toolbar.eBay O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM][64Bits] -- {1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF} =>Toolbar.Bing O42 - Logiciel: DVDVideoSoftTB Toolbar - (.DVDVideoSoftTB.) [HKLM][64Bits] -- DVDVideoSoftTB Toolbar O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {18455581-E099-4BA8-BC6B-F34B2F06600C} =>Toolbar.Google O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {2318C2B1-4965-11d4-9B18-009027A5CD4F} =>Toolbar.Google O42 - Logiciel: eBay - (.eBay Inc..) [HKLM][64Bits] -- {FDE58148-57E7-43BF-879A-29CCE818C078} =>Toolbar.eBay [HKCU\Software\AppDataLow\Software\ConduitSearchScopes] [HKCU\Software\AppDataLow\Software\Conduit] =>Toolbar.Conduit [HKCU\Software\AppDataLow\Software\DVDVideoSoftTB] [HKCU\Software\AppDataLow\Toolbar] [HKCU\Software\Softonic] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Conduit] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\DVDVideoSoftTB] O43 - CFD: 04/09/2012 - 22:06:58 - [0,609] ----D C:\Program Files (x86)\Conduit O43 - CFD: 08/10/2013 - 22:09:57 - [4,849] ----D C:\Program Files (x86)\DVDVideoSoftTB O43 - CFD: 08/10/2013 - 22:09:57 - [0,211] ----D C:\Program Files (x86)\eBay =>Toolbar.eBay O43 - CFD: 08/10/2013 - 22:11:59 - [23,027] -SH-D C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} O43 - CFD: 04/09/2012 - 22:06:54 - [2,533] ----D C:\Users\Laura\AppData\Local\Conduit O61 - LFC: 19/01/2014 - 20:45:49 ---A- . (...) -- C:\Users\Laura\AppData\Local\avgchrome\avgp [115149] O90 - PUC: "84185EDF7E75FB3478A992CC8E810C87" . (.eBay.) -- C:\Windows\Installer\{FDE58148-57E7-43BF-879A-29CCE818C078}\_6FEFF9B68218417F98F549.exe =>Toolbar.eBay O90 - PUC: "90C64EA18BA25EE488BF80DCF07F2FFD" . (.Bing Bar.) -- C:\Windows\Installer\{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}\icon_installer_ico =>Toolbar.Bing [MD5.8C062F4F8973ABAB0F9B6AFA0080C592] [WIS][22/08/2012] (.Google Inc. - Google Toolbar for Internet Explorer.) -- C:\Windows\Installer\653bb.msi [28160] =>Toolbar.Google SS - | Auto 11/06/2012 193616 | (BBSvc) . (.Microsoft Corporation..) - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe SR - | Demand 11/06/2012 240208 | (BBUpdate) . (.Microsoft Corporation..) - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] =>Toolbar.Conduit^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4D91-8333-CF10577473F7}] =>Toolbar.Google^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}] =>Toolbar.Bing^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}] =>Toolbar.Bing^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}] =>Toolbar.Google^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}] =>Toolbar.Google^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FDE58148-57E7-43BF-879A-29CCE818C078}] =>Toolbar.eBay^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>Toolbar.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>Toolbar.Agent [HKLM\Software\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>Toolbar.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6AFBF1-E065-4627-A2FD-810366367D01}] =>Toolbar.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F6AFBF1-E065-4627-A2FD-810366367D01}] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01}] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}] =>Toolbar.TuneUp [HKLM\Software\Wow6432Node\Microsoft\Tracing\BingBar_RASMANCS] =>Toolbar.Bing [HKLM\Software\Classes\Installer\Features\90C64EA18BA25EE488BF80DCF07F2FFD] =>Toolbar.Agent [HKLM\Software\Classes\Installer\Products\90C64EA18BA25EE488BF80DCF07F2FFD] =>Toolbar.Agent [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\90C64EA18BA25EE488BF80DCF07F2FFD] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Classes\Installer\Features\90C64EA18BA25EE488BF80DCF07F2FFD] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Classes\Installer\Products\90C64EA18BA25EE488BF80DCF07F2FFD] =>Toolbar.Agent [HKCU\Software\AppDataLow\Software\ConduitSearchScopes] =>Toolbar.Conduit [HKCU\Software\Softonic] =>Toolbar.Conduit [HKCU\Software\AppDataLow\Toolbar] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FDE58148-57E7-43BF-879A-29CCE818C078}] =>Toolbar.eBay [HKLM\Software\Wow6432Node\Microsoft\Tracing\BingBar_RASAPI32] =>Toolbar.Bing [HKLM\Software\Classes\Installer\Features\84185EDF7E75FB3478A992CC8E810C87] =>Toolbar.eBay [HKLM\Software\Classes\Installer\Products\84185EDF7E75FB3478A992CC8E810C87] =>Toolbar.eBay [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\84185EDF7E75FB3478A992CC8E810C87] =>Toolbar.eBay [HKLM\Software\Wow6432Node\Classes\Installer\Features\84185EDF7E75FB3478A992CC8E810C87] =>Toolbar.eBay [HKLM\Software\Wow6432Node\Classes\Installer\Products\84185EDF7E75FB3478A992CC8E810C87] =>Toolbar.eBay [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] =>Toolbar.DVDVideoSoft [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] =>Toolbar.DVDVideoSoft [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] =>Toolbar.DVDVideoSoft [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}] =>Toolbar.DVDVideoSoft [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3F69D07-0AEE-47AF-87D0-1A67D4F70C68}] =>Toolbar.DVDVideoSoft [HKLM\Software\Wow6432Node\Microsoft\Tracing\ConduitInstaller_RASAPI32] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Microsoft\Tracing\ConduitInstaller_RASMANCS] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Microsoft\Tracing\AskInstallChecker_RASAPI32] =>Toolbar.Ask [HKLM\Software\Wow6432Node\Microsoft\Tracing\AskInstallChecker_RASMANCS] =>Toolbar.Ask [HKLM\Software\Classes\Toolbar.CT2269050] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Classes\Toolbar.CT2269050] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Classes\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1}] =>Toolbar.Conduit^ [HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks]:{872b5b88-9db5-4310-bdd0-ac189557e5f5} =>Toolbar.Conduit^ [HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{2318C2B1-4965-11d4-9B18-009027A5CD4F} =>Toolbar.Google^ C:\Program Files (x86)\eBay =>Toolbar.eBay^ C:\Program Files (x86)\Conduit =>Toolbar.Conduit C:\Program Files (x86)\DVDVideoSoftTB =>Toolbar.DVDVideoSoft C:\Users\Laura\AppData\Local\Conduit =>Toolbar.Conduit C:\Users\Laura\AppData\LocalLow\Conduit =>Toolbar.Conduit C:\Users\Laura\AppData\LocalLow\DVDVideoSoftTB =>Toolbar.DVDVideoSoft [HKCU\Software\AppDataLow\Software\Conduit] =>Toolbar.Conduit^ [HKLM\Software\Wow6432Node\Conduit] =>Toolbar.Conduit^ C:\Windows\Installer\653bb.msi =>Toolbar.Google^ FirewallRaz PROXYFix EmptyTemp EmptyFlash EmptyClsid