Script ZHPFix G1 - GCS: Preference [User Data\Default] http://search.conduit.com G0 - GCSP: Preference [User Data\Default][HomePage] http://www2.delta-search.com =>Toolbar.DeltaSearch G0 - GCSP: Preference [User Data\Default] http://www2.delta-search.com =>Toolbar.DeltaSearch R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www2.delta-search.com =>Toolbar.DeltaSearch R3 - URLSearchHook: (no name) [64Bits] - {D8278076-BC68-4484-9233-6E7F1628B56C} . (...) (No version) -- (.not file.) O1 - Hosts: 0.0.0.0 boxore.com =>Adware.Boxore O1 - Hosts: 0.0.0.0 www.boxore.com =>Adware.Boxore O1 - Hosts: 0.0.0.0 boxore.org =>Adware.Boxore O1 - Hosts: 0.0.0.0 www.boxore.org =>Adware.Boxore O1 - Hosts: 0.0.0.0 boxore.net =>Adware.Boxore O1 - Hosts: 0.0.0.0 www.boxore.net =>Adware.Boxore O1 - Hosts: 0.0.0.0 dlmanager.com =>Adware.Boxore O1 - Hosts: 0.0.0.0 www.dlmanager.com =>Adware.Boxore O1 - Hosts: 0.0.0.0 dlmanager.org =>Adware.Boxore O1 - Hosts: 0.0.0.0 www.dlmanager.org =>Adware.Boxore O1 - Hosts: 0.0.0.0 dlmanager.net =>Adware.Boxore O1 - Hosts: 0.0.0.0 www.dlmanager.net =>Adware.Boxore O3 - Toolbar: (no name) [64Bits] - [HKLM]{ae07101b-46d4-4a98-af68-0333ea26e113} Clé orpheline O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Pricora 1.4-chromeinstaller.job [1908] =>Adware.Pricora O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Pricora 1.4-codedownloader.job [1202] =>Adware.Pricora O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Pricora 1.4-enabler.job [1100] =>Adware.Pricora O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Pricora 1.4-firefoxinstaller.job [1834] =>Adware.Pricora O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Pricora 1.4-updater.job [1290] =>Adware.Pricora [MD5.00000000000000000000000000000000] [APT] [Desk 365 RunAsStdUser] (...) -- C:\Program Files (x86)\Desk 365\desk365.exe (.not file.) [0] =>Hijacker.22Find [MD5.00000000000000000000000000000000] [APT] [GoforFilesUpdate] (...) -- C:\Program Files (x86)\GoforFiles\GFFUpdater.exe (.not file.) [0] =>P2P.GoforFiles [MD5.00000000000000000000000000000000] [APT] [Omiga Plus RunAsStdUser] (...) -- C:\Program Files (x86)\Omiga Plus\omigaplus.exe (.not file.) [0] =>Hijacker.OmigaPlus [MD5.00000000000000000000000000000000] [APT] [Pricora 1.4-chromeinstaller] (...) -- C:\Program Files (x86)\Pricora 1.4\Pricora 1.4-chromeinstaller.exe (.not file.) [0] =>Adware.Pricora [MD5.00000000000000000000000000000000] [APT] [Pricora 1.4-codedownloader] (...) -- C:\Program Files (x86)\Pricora 1.4\Pricora 1.4-codedownloader.exe (.not file.) [0] =>Adware.Pricora [MD5.00000000000000000000000000000000] [APT] [Pricora 1.4-enabler] (...) -- C:\Program Files (x86)\Pricora 1.4\Pricora 1.4-enabler.exe (.not file.) [0] =>Adware.Pricora [MD5.00000000000000000000000000000000] [APT] [Pricora 1.4-firefoxinstaller] (...) -- C:\Program Files (x86)\Pricora 1.4\Pricora 1.4-firefoxinstaller.exe (.not file.) [0] =>Adware.Pricora [MD5.00000000000000000000000000000000] [APT] [Pricora 1.4-updater] (...) -- C:\Program Files (x86)\Pricora 1.4\Pricora 1.4-updater.exe (.not file.) [0] =>Adware.Pricora O42 - Logiciel: ContinueToSave - (...) [HKLM][64Bits] -- {EE08A338-7070-4864-AA8F-385235EB81CE} =>PUP.OfferWare O42 - Logiciel: Search Protect by conduit - (.Conduit.) [HKLM][64Bits] -- SearchProtect =>Toolbar.Conduit [HKCU\Software\1ClickDownload] =>PUP.1ClickDownloader [HKCU\Software\BabSolution] =>Hijacker.BabSolution [HKCU\Software\Conduit] =>Toolbar.Conduit [HKCU\Software\InstallCore] =>Adware.InstallCore [HKCU\Software\InstalledBrowserExtensions] =>Adware.VidSaver [HKCU\Software\Softonic] =>Toolbar.Conduit [HKCU\Software\SweetIM] =>PUP.SweetIM [HKCU\Software\WEDLMNGR] =>PUP.weDownloadManager [HKLM\Software\Wow6432Node\Conduit] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\SweetIM] =>PUP.SweetIM [HKLM\Software\Wow6432Node\babylontoolbar] =>Toolbar.Babylon [HKLM\Software\Wow6432Node\omigaplusSvc] =>Hijacker.OmigaPlus O43 - CFD: 07/08/2013 - 22:05:04 - [0,274] ----D C:\Program Files (x86)\Conduit O43 - CFD: 01/09/2013 - 11:02:17 - [0] ----D C:\ProgramData\Babylon =>Toolbar.Babylon O43 - CFD: 12/09/2013 - 21:21:18 - [0,147] ----D C:\ProgramData\DSearchLink =>Toolbar.DeltaSearch O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} - (Delta Search) - http://www2.delta-search.com =>Toolbar.DeltaSearch O69 - SBI: SearchScopes [HKCU] {975384BD-D46E-4E75-B3E3-3F91987E59A3} [DefaultScope] - (01NET.com V1 Customized Web Search) - http://search.conduit.com O90 - PUC: "EE5B7A9BB7B990A4CBEA78832BF083AE" . (.Moovida.) -- C:\Windows\Installer\{B9A7B5EE-9B7B-4A09-BCAE-8738B20F38EA}\ARPPRODUCTICON.exe =>Adware.SPointer [MD5.3CD19859CD377AD00B30E4BEE49D374E] [WIS][05/01/2013] (.SweetIM Technologies Ltd. - Sweetpacks Communicator 1.1.) -- C:\Windows\Installer\10bee44.msi [2997248] =>PUP.SweetIM [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{EE08A338-7070-4864-AA8F-385235EB81CE}] =>PUP.OfferWare^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect] =>Toolbar.Conduit^ [HKLM\Software\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}] =>Toolbar.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}] =>Toolbar.Babylon [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}] =>Toolbar.Babylon [HKCU\Software\delta LTD] =>Toolbar.DeltaSearch [HKLM\Software\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}] =>Toolbar.Agent [HKLM\Software\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] =>Toolbar.Babylon [HKLM\Software\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] =>Toolbar.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] =>Toolbar.Babylon [HKLM\Software\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}] =>PUP.Whitesmoke [HKLM\Software\Wow6432Node\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}] =>PUP.Whitesmoke [HKLM\Software\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}] =>Toolbar.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}] =>Toolbar.Babylon [HKLM\Software\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] =>Toolbar.Babylon [HKLM\Software\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] =>Toolbar.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] =>Toolbar.Babylon [HKLM\Software\Classes\AppID\escort.dll] =>Toolbar.Babylon [HKLM\Software\Classes\AppID\escortapp.dll] =>Toolbar.Babylon [HKLM\Software\Classes\AppID\escorteng.dll] =>Toolbar.Babylon [HKLM\Software\Classes\AppID\esrv.EXE] =>Toolbar.Babylon [HKCU\Software\1ClickDownload] =>PUP.1ClickDownloader [HKLM\Software\Wow6432Node\BabylonToolbar] =>Toolbar.Babylon [HKCU\Software\AppDataLow\Software\ConduitSearchScopes] =>Toolbar.Conduit [HKCU\Software\Softonic] =>Toolbar.Conduit [HKCU\Software\SweetIM] =>PUP.SweetIM [HKLM\Software\Wow6432Node\SweetIM] =>PUP.SweetIM [HKLM\Software\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}] =>Toolbar.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}] =>Toolbar.Babylon [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect] =>Toolbar.Conduit [HKLM\Software\Classes\Prod.cap] =>Toolbar.Babylon [HKCU\Software\InstallCore] =>Adware.InstallCore [HKLM\Software\Classes\AppID\secman.DLL] =>Toolbar.Babylon [HKLM\Software\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}] =>Toolbar.DeltaSearch [HKLM\Software\Wow6432Node\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}] =>Toolbar.DeltaSearch [HKLM\Software\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}] =>Toolbar.DeltaSearch [HKLM\Software\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}] =>Toolbar.DeltaSearch [HKLM\Software\Wow6432Node\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}] =>Toolbar.DeltaSearch [HKLM\Software\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}] =>Toolbar.DeltaSearch [HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider [HKCU\Software\InstalledBrowserExtensions\] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Microsoft\Tracing\ConduitInstaller_RASAPI32] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Microsoft\Tracing\ConduitInstaller_RASMANCS] =>Toolbar.Conduit [HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\eSafeSvc] =>PUP.eSafeSecurity [HKCU\Software\BI] =>Adware.MegaSearch [HKLM\Software\Wow6432Node\Microsoft\Tracing\WebCakeDesktop_RASAPI32] =>Adware.WebCake [HKLM\Software\Wow6432Node\Microsoft\Tracing\WebCakeDesktop_RASMANCS] =>Adware.WebCake [HKLM\Software\Wow6432Node\omigaplusSvc] =>Hijacker.OmigaPlus [HKCU\Software\InstalledBrowserExtensions] =>PUP.CrossRider [HKLM\Software\Classes\IncrediSpooler.DeltaSync] =>Toolbar.DeltaSearch [HKLM\Software\Classes\IncrediSpooler.DeltaSync.1] =>Toolbar.DeltaSearch [HKLM\Software\Classes\AppID\escorTlbr.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\IncrediSpooler.DeltaSync] =>Toolbar.DeltaSearch [HKLM\Software\Wow6432Node\Classes\IncrediSpooler.DeltaSync.1] =>Toolbar.DeltaSearch [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110111991162}] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311341140}] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Classes\AppID\escort.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\escortApp.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\escortEng.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\escorTlbr.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110111991162}] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110111991162}] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{31111111-1111-1111-1111-110111991162}] =>PUP.CrossRider C:\ProgramData\Babylon =>Toolbar.Babylon^ C:\ProgramData\DSearchLink =>Toolbar.DeltaSearch^ C:\Users\Pierre\AppData\Roaming\Yahoo! =>Toolbar.Yahoo^ C:\Program Files (x86)\Conduit =>Toolbar.Conduit C:\Program Files (x86)\SearchProtect =>Toolbar.Conduit C:\Users\Pierre\AppData\Roaming\SearchProtect =>Toolbar.Conduit C:\Users\Pierre\AppData\LocalLow\Conduit =>Toolbar.Conduit C:\Users\Pierre\AppData\Local\Temp\Software =>Adware.Boxore C:\Users\Pierre\AppData\Local\Google\Chrome\User Data\Default\Extensions\jiofjbkodmcfkhmljgdmjcildliojoli =>Toolbar.DeltaSearch C:\Windows\Tasks\Pricora 1.4-chromeinstaller.job =>Adware.Pricora^ C:\Windows\Tasks\Pricora 1.4-codedownloader.job =>Adware.Pricora^ C:\Windows\Tasks\Pricora 1.4-enabler.job =>Adware.Pricora^ C:\Windows\Tasks\Pricora 1.4-firefoxinstaller.job =>Adware.Pricora^ C:\Windows\Tasks\Pricora 1.4-updater.job =>Adware.Pricora^ [HKCU\Software\BabSolution] =>Hijacker.BabSolution^ [HKCU\Software\Conduit] =>Toolbar.Conduit^ [HKCU\Software\WEDLMNGR] =>PUP.weDownloadManager^ [HKLM\Software\Wow6432Node\Conduit] =>Toolbar.Conduit^ [HKLM\Software\Wow6432Node\babylontoolbar] =>Toolbar.Babylon^ C:\Windows\Installer\{B9A7B5EE-9B7B-4A09-BCAE-8738B20F38EA}\ARPPRODUCTICON.exe =>Adware.SPointer^ C:\Windows\Installer\10bee44.msi =>PUP.SweetIM^ FirewallRaz EmptyFlash Emptytemp