M3 - MFPP: Plugins - [Jean] -- C:\Program Files\Mozilla FireFox\searchplugins\babylon.xml => Infection PUP (Toolbar.Babylon)* O2 - BHO: C:\Users\Jean\AppData\Roaming\2YourFace\bho.dll - {1185823F-F22F-4027-80E5-4F68ACD5DE5E} . (...) -- C:\Users\Jean\AppData\Roaming\2YourFace\bho.dll => Infection BT (Adware.2YourFace) O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} . (.Yontoo LLC - Yontoo Runtime.) -- C:\Program Files\Yontoo\YontooIEClient.dll => Infection PUP (Adware.Yontoo)* O16 - DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} ((no name)) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab => Infection BT (Adware.MetaStream) O40 - ASIC: Viewpoint Media Player - {03F998B2-0E00-11D3-A498-00104B6EB52E} . (...) -- C:\Program Files\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll => Infection PUP (Adware.MetaStream)* O42 - Logiciel: 2YourFace 1.0 - (.2YourFace.com.) [HKLM] -- 2YourFace => Infection BT (Adware.2YourFace) O42 - Logiciel: SweetIM for Messenger 3.6 - (.SweetIM Technologies Ltd..) [HKLM] -- {0D5BBB2B-F044-46C3-877B-6A6BE1E08D19} => Infection PUP (PUP.SweetIM)* O42 - Logiciel: Yontoo 1.12.02 - (.Yontoo LLC.) [HKLM] -- {889DF117-14D1-44EE-9F31-C5FB5D47F68B} => Infection PUP (Adware.Yontoo)* [HKCU\Software\2YourFace] => Infection BT (Adware.2YourFace) [HKCU\Software\AppDataLow\Software\PriceGong] => Infection PUP (Adware.PriceGong)* [HKCU\Software\AppDataLow\Software\SmartBar] => Infection PUP (Hijacker.SmartBar)* [HKCU\Software\BabylonToolbar] => Infection PUP (Toolbar.Babylon)* [HKCU\Software\DataMngr] => Infection PUP (PUP.BearShare)* [HKCU\Software\DataMngr_Toolbar] => Infection PUP (PUP.BearShare)* [HKCU\Software\SpeedMaxPc] => Infection PUP (PUP.SpeedMaxPc)* [HKLM\Software\Babylon] => Infection PUP (Toolbar.Babylon)* [HKLM\Software\DataMngr] => Infection PUP (PUP.BearShare)* [HKLM\Software\MetaStream] => Infection PUP (Adware.MetaStream) [HKLM\Software\SpeedMaxPc] => Infection PUP (PUP.SpeedMaxPc)* [HKLM\Software\Viewpoint] => Infection PUP (Adware.MetaStream)* O43 - CFD: 05/02/2013 - 14:32:19 - [0,049] ----D C:\Program Files\PriceGong => Infection PUP (Adware.PriceGong)* O43 - CFD: 05/02/2013 - 14:32:19 - [0,321] ----D C:\Program Files\Yontoo => Infection PUP (Adware.Yontoo)* O43 - CFD: 31/03/2013 - 14:38:50 - [0] ----D C:\ProgramData\Babylon => Infection PUP (Toolbar.Babylon)* O43 - CFD: 31/08/2012 - 22:29:51 - [0] ----D C:\ProgramData\SpeedMaxPc => Infection PUP (PUP.SpeedMaxPc)* O43 - CFD: 03/02/2013 - 18:38:58 - [0,003] ----D C:\ProgramData\Viewpoint => Infection PUP (Adware.MetaStream)* O43 - CFD: 05/02/2013 - 14:32:23 - [0,864] ----D C:\Users\Jean\AppData\Roaming\2YourFace => Infection BT (Adware.2YourFace) O43 - CFD: 31/03/2013 - 14:38:49 - [0,007] ----D C:\Users\Jean\AppData\Roaming\Babylon => Infection PUP (Toolbar.Babylon)* O43 - CFD: 02/03/2013 - 10:12:31 - [5,939] ----D C:\Users\Jean\AppData\Roaming\OpenCandy => Infection PUP (Adware.OpenCandy)* O43 - CFD: 31/08/2012 - 22:21:22 - [0] ----D C:\Users\Jean\AppData\Roaming\SpeedMaxPc => Infection PUP (PUP.SpeedMaxPc)* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("Smartbar.ConduitSearchEngineList", "Pokki Customized Web Search"); => Infection PUP (Hijacker.SmartBar)* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("browser.search.defaultthis.engineName", "Pokki Customized Web Search"); => Infection PUP (Adware.Bandoo) [MD5.36179B382A989075FF5FA282434F6892] [SPRF][21/03/2013] (.Babylon Ltd. - Uninstaller Application.) -- C:\Users\Jean\AppData\Local\Temp\uninst1.exe [394736] => Infection PUP (Toolbar.Babylon)* O87 - FAEL: "{5CB9E302-6CFF-4AA7-A957-3A18E6A5C4BB}" | In - Private - P6 - TRUE | .(...) -- C:\Users\Jean\AppData\Roaming\2YourFace\Updater.exe => Infection BT (Adware.2YourFace) O87 - FAEL: "{00FC476A-C666-4288-BB6C-AC72B747A778}" | In - Private - P17 - TRUE | .(...) -- C:\Users\Jean\AppData\Roaming\2YourFace\Updater.exe => Infection BT (Adware.2YourFace) [HKLM\Software\Classes\CLSID\{35b8892d-c3fb-4d88-990d-31db2ebd72bd}] => Infection PUP (Adware.RecordNRip) [HKLM\Software\Classes\Interface\{3f607e46-0d3c-4442-b1de-de7fa4768f5c}] => Infection PUP (Adware.RecordNRip) [HKLM\Software\Classes\TypeLib\{93e3d79c-0786-48ff-9329-93bc9f6dc2b3}] => Infection PUP (Adware.RecordNRip) [HKLM\Software\Classes\Interface\{fe0273d1-99df-4ac0-87d5-1371c6271785}] => Infection PUP (Adware.RecordNRip) [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}] => Infection BT (PUP.ClaroSearch) [HKLM\Software\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}] => Infection BT (Adware.Yontoo) [HKLM\Software\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}] => Infection BT (Adware.Yontoo) [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1185823F-F22F-4027-80E5-4F68ACD5DE5E}] => Infection BT (Toolbar.Babylon) [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1185823F-F22F-4027-80E5-4F68ACD5DE5E}] => Infection BT (Toolbar.Babylon) [HKLM\Software\Classes\CLSID\{1185823F-F22F-4027-80E5-4F68ACD5DE5E}] => Infection BT (Toolbar.Babylon) [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1185823F-F22F-4027-80E5-4F68ACD5DE5E}] => Infection BT (Toolbar.Babylon) [HKLM\Software\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}] => Infection BT (Adware.Yontoo) [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}] => Infection BT (Adware.MetaStream) [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}] => Infection BT (Adware.MetaStream) [HKLM\Software\Microsoft\Code Store Database\Distribution Units\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}] => Infection BT (Adware.MetaStream) [HKLM\Software\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}] => Infection PUP (PUP.WhiteSmoke) [HKLM\Software\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}] => Infection PUP (PUP.WhiteSmoke) [HKLM\Software\Classes\Interface\{7697BC38-D0FA-454B-AC75-968B4CCABFCE}] => Infection BT (Toolbar.Kiwee) [HKLM\Software\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}] => Infection BT (Adware.Yontoo) [HKLM\Software\Classes\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}] => Infection BT (Adware.Yontoo) [HKLM\Software\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}] => Infection BT (Adware.Yontoo) [HKLM\Software\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}] => Infection PUP (Toolbar.Babylon) [HKLM\Software\Classes\AppID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}] => Infection BT (Adware.PriceGong) [HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}] => Infection BT (Adware.Yontoo) [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}] => Infection BT (Adware.Yontoo) [HKLM\Software\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}] => Infection BT (Adware.Agent) [HKLM\Software\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}] => Infection BT (Adware.Yontoo) [HKLM\Software\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}] => Infection BT (Adware.Yontoo) [HKLM\Software\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}] => Infection BT (Adware.Yontoo) [HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}] => Infection BT (Adware.Yontoo) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635] => Infection PUP (PUP.SweetIM) [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}] => Infection BT (Adware.Yontoo) [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}] => Infection BT (Adware.Yontoo) [HKLM\Software\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}] => Infection BT (Adware.Yontoo) [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}] => Infection BT (Adware.Yontoo) [HKLM\Software\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}] => Infection BT (Adware.Yontoo) [HKLM\Software\Classes\AppID\PriceGongIE.DLL] => Infection PUP (Adware.PriceGong)* [HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\pricegong] => Infection PUP (Adware.PriceGong)* [HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ViewpointMediaPlayer] => Infection PUP (Adware.MetaStream)* [HKLM\Software\Classes\axmetastream.metastreamctl] => Infection PUP (Adware.MetaStream) [HKLM\Software\Classes\axmetastream.metastreamctl.1] => Infection PUP (Adware.MetaStream) [HKLM\Software\Classes\AxMetaStream.MetaStreamCtlSecondary] => Infection PUP (Adware.MetaStream) [HKLM\Software\Classes\AxMetaStream.MetaStreamCtlSecondary.1] => Infection PUP (Adware.MetaStream) [HKLM\Software\Google\Chrome\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok] => Infection BT (Adware.PriceGong) [HKLM\Software\Classes\Installer\Features\A6A9B7407E12FC548852A060E1FEB932] => Infection PUP (PUP.SweetIM) [HKLM\Software\Classes\Installer\Products\A6A9B7407E12FC548852A060E1FEB932] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A6A9B7407E12FC548852A060E1FEB932] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\CC94835868BCA58489B0D79DE655BCB1] => Infection BT (PUP.Dealio) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9] => Infection BT (Adware.MyWebSearch) [HKLM\Software\Classes\Installer\Features\B2BBB5D0440F3C6478B7A6B61E0ED891] => Infection PUP (PUP.SweetIM) [HKLM\Software\Classes\Installer\Products\B2BBB5D0440F3C6478B7A6B61E0ED891] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B2BBB5D0440F3C6478B7A6B61E0ED891] => Infection PUP (PUP.SweetIM) [HKCU\Software\2YourFace] => Infection BT (Adware.2YourFace) [HKCU\Software\BabylonToolbar] => Infection PUP (Toolbar.Babylon)* [HKCU\Software\DataMngr] => Infection PUP (PUP.BearShare)* [HKLM\Software\DataMngr] => Infection PUP (PUP.BearShare)* [HKLM\Software\MetaStream] => Infection PUP (Adware.MetaStream) [HKCU\Software\AppDataLow\Software\PriceGong] => Infection PUP (Adware.PriceGong)* [HKCU\Software\SpeedMaxPc] => Infection PUP (PUP.SpeedMaxPc)* [HKLM\Software\SpeedMaxPc] => Infection PUP (PUP.SpeedMaxPc)* [HKLM\Software\Viewpoint] => Infection PUP (Adware.MetaStream)* [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{047B9A6A-21E7-45CF-8825-0A061EEF9B23}] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0D5BBB2B-F044-46C3-877B-6A6BE1E08D19}] => Infection PUP (PUP.SweetIM) [HKLM\Software\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}] => Infection BT (Toolbar.Babylon) [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\2YourFace] => Infection BT (Adware.2YourFace) [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer] => Infection PUP (Adware.MetaStream)* [HKLM\Software\Classes\Prod.cap] => Infection PUP (Toolbar.Babylon) [HKLM\Software\Classes\AppID\secman.DLL] => Infection PUP (Toolbar.Babylon) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4318DF19719275242801CBE292063A4C] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75D5168E5E176C24981B4E5DBD991078] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8724E58E6C7D00C48A0D4F3345EB2C26] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB676B0E1B9EFA049B9F7DDDA9645734] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B31BBB0B825EDEF45AB0FE7099C68C81] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B471D8D7319336B4CA89374ED0D7B806] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC30043663AA2CA4DA1DAA9CA5FDCC75] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDC83385E6C239F4C876A77A37DF581D] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0] => Infection PUP (PUP.SweetIM) [HKLM\Software\Classes\MediaPlayer.GraphicsUtils.1] => Infection PUP (PUP.SweetIM) [HKLM\Software\Classes\MgMediaPlayer.GifAnimator.1] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F754C503375A13344B22388E18DFE87E] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420] => Infection PUP (PUP.SweetIM) [HKLM\Software\Classes\YontooIEClient.Api] => Infection PUP (Adware.Yontoo)* [HKLM\Software\Classes\YontooIEClient.Api.1] => Infection PUP (Adware.Yontoo)* [HKLM\Software\Classes\YontooIEClient.Layers] => Infection PUP (Adware.Yontoo)* [HKLM\Software\Classes\YontooIEClient.Layers.1] => Infection PUP (Adware.Yontoo)* [HKLM\Software\Classes\AppID\YontooIEClient.DLL] => Infection PUP (Adware.Yontoo)* [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399] => Infection PUP (PUP.SweetIM) [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156] => Infection PUP (PUP.SweetIM) C:\Program Files\yontoo => Infection PUP (Adware.Yontoo)* C:\Program Files\PriceGong => Infection PUP (Adware.PriceGong)* C:\ProgramData\Babylon => Infection PUP (Toolbar.Babylon)* C:\ProgramData\SpeedMaxPc => Infection PUP (PUP.SpeedMaxPc)* C:\ProgramData\Viewpoint => Infection PUP (Adware.MetaStream)* C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong => Infection PUP (Adware.PriceGong)* C:\Users\Jean\AppData\Roaming\2YourFace => Infection BT (Adware.2YourFace) C:\Users\Jean\AppData\Roaming\Babylon => Infection PUP (Toolbar.Babylon)* C:\Users\Jean\AppData\Roaming\OpenCandy => Infection PUP (Adware.OpenCandy)* C:\Users\Jean\AppData\Roaming\SpeedMaxPc => Infection PUP (PUP.SpeedMaxPc)* C:\Users\Jean\AppData\LocalLow\PriceGong => Infection PUP (Adware.PriceGong)* C:\Users\Jean\AppData\Roaming\Mozilla\Firefox\Profiles\h7ss5f6e.default\Smartbar => Infection PUP (Hijacker.SmartBar)* C:\Users\Jean\AppData\Roaming\Mozilla\Firefox\Profiles\h7ss5f6e.default\Extensions\ffxtlbr@babylon.com => Infection PUP (Toolbar.Babylon)* C:\Users\Jean\AppData\Local\Temp\uninst1.exe => Infection BT (Toolbar.Babylon) O90 - PUC: "A6A9B7407E12FC548852A060E1FEB932" . (.SweetIM Toolbar for Internet Explorer 4.3.) -- C:\Windows\Installer\{047B9A6A-21E7-45CF-8825-0A061EEF9B23}\ARPPRODUCTICON.exe => Infection PUP (PUP.SweetIM)* [HKCU\Software\d6dadab73fea44\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1125.80]:guid="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" => Infection PUP (Toolbar.Babylon) [HKCU\Software\d6dadab73fea44\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1125.80]:version="2.6.1125.80" => Infection PUP (Toolbar.Babylon) M3 - MFPP: Plugins - [Jean] -- C:\Users\Jean\AppData\Roaming\Mozilla\Firefox\Profiles\h7ss5f6e.default\searchplugins\conduit.xml => Toolbar.Conduit M3 - MFPP: Plugins - [Jean] -- C:\Users\Jean\AppData\Roaming\Mozilla\Firefox\Profiles\h7ss5f6e.default\searchplugins\delta.xml => Toolbar.DeltaSearch M0 - MFSP: prefs.js [Jean - h7ss5f6e.default] http://www.delta-search.com => Toolbar.DeltaSearch M2 - MFEP: prefs.js [Jean - h7ss5f6e.default\{e44a1809-4d10-4ab8-b343-3326b64c7cdd}] [] Pokki v10.14.65.43 (.Conduit Ltd..) => Toolbar.Conduit* R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-search.com => Toolbar.DeltaSearch O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM] -- {77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1} O42 - Logiciel: GoogleToolbar - (...) [HKLM] -- GoogleToolbar => Toolbar.Google [HKCU\Software\Alexa Internet] => Toolbar.Agent [HKCU\Software\AppDataLow\Software\ConduitSearchScopes] => Toolbar.Conduit [HKLM\Software\Tarma Installer] => Toolbar.Tarma O43 - CFD: 05/02/2013 - 14:31:49 - [2,391] ----D C:\ProgramData\Tarma Installer => Toolbar.Tarma O69 - SBI: C:\Users\Jean\AppData\Roaming\Mozilla\Firefox\Profiles\h7ss5f6e.default\searchplugins\conduit.xml => Toolbar.Conduit O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("CT3281675.SearchFromAddressBarUrl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT3281675&SearchSource=2&CUI=UN3225[...] => Toolbar.Conduit* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("CT3281675.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"http://search.conduit.com/?ctid=CT3281675&octid=CT3[...] => Toolbar.Conduit* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("Smartbar.ConduitHomepagesList", "http://search.conduit.com/?ctid=CT3281675&CUI=UN32250970163030094&UM=2&SearchSource=13[...] => Toolbar.Conduit* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("Smartbar.ConduitSearchUrlList", "http://search.conduit.com/ResultsExt.aspx?ctid=CT3281675&SearchSource=2&CUI=UN32250970[...] => Toolbar.Conduit* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("aol_toolbar.surf.date", "2"); => Toolbar.AOL* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("aol_toolbar.surf.lastDate", "20"); => Toolbar.AOL* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("aol_toolbar.surf.lastMonth", "1"); => Toolbar.AOL* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("aol_toolbar.surf.lastYear", "2013"); => Toolbar.AOL* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("aol_toolbar.surf.month", "3"); => Toolbar.AOL* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("aol_toolbar.surf.prevMonth", "35"); => Toolbar.AOL* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("aol_toolbar.surf.total", "166"); => Toolbar.AOL* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("aol_toolbar.surf.week", "2"); => Toolbar.AOL* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("aol_toolbar.surf.year", "3"); => Toolbar.AOL* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("browser.search.defaulturl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT3281675&CUI=UN32250970163030094&UM=2&Sear[...] => Toolbar.Conduit* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("smartbar.conduitHomepageList", "http://search.conduit.com/?ctid=CT3281675&CUI=UN32250970163030094&UM=2&SearchSource=13"[...] => Toolbar.Conduit* O69 - SBI: prefs.js [Jean - h7ss5f6e.default] user_pref("smartbar.conduitSearchAddressUrlList", "http://search.conduit.com/ResultsExt.aspx?ctid=CT3281675&SearchSource=2&CUI=UN3[...] => Toolbar.Conduit* O69 - SBI: SearchScopes [HKCU] {0BBF7067-8451-4396-B6BC-FCD6D3257324} - (Pokki Customized Web Search) - http://search.conduit.com => Toolbar.Conduit* O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} [DefaultScope] - (Delta Search) - http://www.delta-search.com => Toolbar.DeltaSearch* [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}] => Toolbar.SFR [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}] => Toolbar.SFR [HKLM\Software\Classes\CLSID\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}] => Toolbar.SFR [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}] => Toolbar.SFR [HKLM\Software\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}] => Toolbar.Agent [HKLM\Software\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}] => Toolbar.Conduit [HKLM\Software\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] => Toolbar.Skype [HKLM\Software\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] => Toolbar.Skype [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype [HKLM\Software\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] => Toolbar.Skype [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E] => Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0E9201899CF73FC4BA93F631631229A1] => Toolbar.Skype [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6] => Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7] => Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852] => Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96] => Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8] => Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01] => Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED] => Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472] => Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296] => Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888] => Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E] => Toolbar.Ask [HKCU\Software\AppDataLow\Software\ConduitSearchScopes] => Toolbar.Conduit [HKLM\Software\Tarma Installer] => Toolbar.Tarma [HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}] => Toolbar.Yahoo [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] => Toolbar.Bing [HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] => Toolbar.Bing [HKLM\Software\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}] => Toolbar.DeltaSearch [HKLM\Software\Classes\AOLTB.AOLToolBand.1] => Toolbar.Agent* [HKLM\Software\Classes\Toolbar.CT3281675] => Toolbar.Conduit* C:\Program Files\Conduit => Toolbar.Conduit C:\Users\Jean\AppData\Local\Conduit => Toolbar.Conduit C:\Users\Jean\AppData\LocalLow\Conduit => Toolbar.Conduit C:\Users\Jean\AppData\Roaming\Mozilla\Firefox\Profiles\h7ss5f6e.default\SearchPlugins\conduit.xml => Toolbar.Conduit O90 - PUC: "E17A8F77515323848B2BF2E1BD2D0E1F" . (.Bing Bar.) -- C:\Windows\Installer\{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}\icon_installer_ico O23 - Service: SBSD Security Center Service (SBSDWSCService) . (...) - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (.not file.) [MD5.00000000000000000000000000000000] [APT] [Ad-Aware Update (Weekly)] (...) -- C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{1E3475FE-F366-4925-9E32-975421800878}] (...) -- I:\AOLDNLD.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{79D0F547-7DC2-4572-A209-25747CA36B47}] (...) -- C:\Users\Jean\Desktop\AOLDNLD.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{A34E7DB7-45B9-426F-812E-5FBFA28B716A}] (...) -- C:\Users\Jean\Desktop\ToolBarSD.exe (.not file.) [0] = [MD5.A9886174C911F10229F3EDE83EF2C5A6] [APT] [{D919A0C4-063E-4A5D-B6C1-B25EDBE5F167}] (...) -- C:\Program Files\Uninstall Information\Ib\97\3867\ib_uninstall.exe [675616] [MD5.00000000000000000000000000000000] [APT] [{F64B3B7B-4B92-4B4D-BC3A-954AB8A4C699}] (...) -- H:\Autorun.exe (.not file.) [0] [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F02D7FF93A706B84299348C7E9A5B7D7] [HKLM\Software\Google\Chrome\Extensions\LMBLFNGOGNKLGEMAFEKEFCDJCNKDHMDM] O90 - PUC: "3E7A345BD349B9E429227D0B44746ED4" . (.Elevated Installer.) -- C:\Windows\Installer\{B543A7E3-943D-4E9B-9222-D7B04447E64D}\express.ico O90 - PUC: "609461C2F86EA264090107DD202232FE" . (.RemoteCapture Task 1.0.2.) -- C:\Windows\Installer\{2C164906-E68F-462A-9010-70DD022223EF}\ARPPRODUCTICON.exe O90 - PUC: "A6A9B7407E12FC548852A060E1FEB932" . (.SweetIM Toolbar for Internet Explorer 4.3.) -- C:\Windows\Installer\{047B9A6A-21E7-45CF-8825-0A061EEF9B23}\ARPPRODUCTICON.exe O90 - PUC: "CA661D043FEFBE94B8DF275838C9F372" . (.Meter Drivers for OneTouch Software.) -- C:\Windows\Installer\{40D166AC-FEF3-49EB-8BFD-7285839C3F27}\ARPPRODUCTICON.exe [HKCU\Software\d6dadab73fea44] [HKLM\Software\d6dadab73fea44] FirewallRaz EmptyFlash Emptytemp