Script ZHPFix [MD5.A9C71D2C838DDCE573888D82B3E17A8B] - (.Spigot, Inc. - Search Protection.) -- C:\Users\khoja\AppData\Roaming\Search Protection\SearchProtection.exe [832360] [PID.2232] =>PUP.Dealio [MD5.CC514A238A2993138AC84F345A40D0F7] - (.APN - Ask Toolbar Notifier.) -- C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1707472] [PID.2708] =>Toolbar.Ask [MD5.A043F2DCB3DE6A01317FD7DDDAA53736] - (.APN LLC. - Virtual New Tab Loader.) -- C:\Users\khoja\AppData\Local\VNT\vntldr.exe [202192] [PID.2836] =>Toolbar.Ask [MD5.BEF294FFE5F40BE768BDCBE1837DFABE] - (.APN LLC. - APN Updater.) -- C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352] [PID.1900] =>Toolbar.Ask [MD5.F422BB58E93A0451A5ADE8BC34E1FAEA] - (.LemurLeap - LemurLeap.) -- C:\Program Files (x86)\LemurLeap\bin\utilLemurLeap.exe [65312] [PID.2596] =>PUP.LemurLeap G1 - GCS: Preference [User Data\Default] http://www.search.ask.com G0 - GCSP: Preference [User Data\Default][HomePage] http://www.qvo6.com =>Hijacker.Qvo6 G0 - GCSP: Preference [User Data\Default] http://www.search.ask.com G2 - GCE: Preference [User Data\Default] [aaaajepdnhoaepmhbcinpphpaiennofj] Ask Toolbar v.30.1, (Désactivé) =>Toolbar.Ask G2 - GCE: Preference [User Data\Default] [hehijbfgiekmjfkfjpbkbammjbdenadd] IE Tab v.6.1.7.1, (Activé) G2 - GCE: Preference [User Data\Default] [ifohbjbgfchkkfhphahclmkpgejiplfo] Lightning Newtab v.1.1.5.2, (Désactivé) =>PUP.Elex G2 - GCE: Preference [User Data\Default] [jlnfdbbladgcmhhamgkioifhbobjaoof] LemurLeap v.1.0.0 (Désactivé) =>PUP.LemurLeap P2 - FPN:Firefox Plugin Navigator . (.BitComet - BitCometAgent v1.30 for Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npBitCometAgent.dll =>P2P.BitComet P2 - FPN: [HKCU] [@bittorrent.com/BitTorrentDNA] - (.BitTorrent, Inc. - Delivery Network Acceleration by BitTorrent™.) -- C:\Users\khoja\Program Files (x86)\DNA\plugins\npbtdna.dll =>P2P.BitTorrent R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com =>Hijacker.Qvo6 R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com =>Hijacker.Qvo6 R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com =>Hijacker.Qvo6 R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.b1.org R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com =>Hijacker.Qvo6 R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com =>Hijacker.Qvo6 R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = http://search.babylon.com =>PUP.Babylon R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com =>Hijacker.Qvo6 O2 - BHO: LemurLeap [64Bits] - {415419c3-dad0-4df1-ac37-22c72ad81878} . (.LemurLeap - LemurLeap.) -- C:\Program Files (x86)\LemurLeap\LemurLeapbho.dll =>PUP.LemurLeap O2 - BHO: Softonic Helper Object [64Bits] - {E87806B5-E908-45FD-AF5E-957D83E58E68} . (.Softonic.com - Pas de description.) -- C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\bh\Softonic.dll =>Toolbar.Conduit O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll =>Toolbar.Google O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline O3 - Toolbar\WebBrowser: (no name) - [HKCU]{D4027C7F-154A-4066-A1AD-4243D8127440} Clé orpheline O3 - Toolbar\WebBrowser: (no name) - [HKCU]{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} Clé orpheline O4 - GS\Desktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.qvo6.com =>Hijacker.Qvo6 O4 - GS\QuickLaunch [khoja]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.qvo6.com =>Hijacker.Qvo6 O4 - GS\QuickLaunch [khoja]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.qvo6.com =>Hijacker.Qvo6 O4 - GS\QuickLaunch [khoja]: QQPlayer.lnk . (.Tencent Technology Company limited - QQ Player.) -- C:\Program Files (x86)\Tencent\QQPlayer\QQPlayer.exe =>Adware.TencentAddressBar O4 - GS\QuickLaunch [khoja]: Upgrade to Paltalk Extreme.lnk - Clé orpheline O4 - GS\TaskBar [khoja]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.qvo6.com =>Hijacker.Qvo6 O4 - GS\Program [khoja]: Internet Explorer (64-bit).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com =>Hijacker.Qvo6 O4 - GS\Program [khoja]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.qvo6.com =>Hijacker.Qvo6 O4 - GS\SystemTools [khoja]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.qvo6.com =>Hijacker.Qvo6 O4 - GS\Desktop [khoja]: QQPlayer.lnk . (.Tencent Technology Company limited - QQ Player.) -- C:\Program Files (x86)\Tencent\QQPlayer\QQPlayer.exe =>Adware.TencentAddressBar O4 - HKCU\..\Run: [SearchProtection] . (.Spigot, Inc. - Search Protection.) -- C:\Users\khoja\AppData\Roaming\Search Protection\SearchProtection.exe =>PUP.Dealio O4 - HKCU\..\Run: [Software updater] . (...) -- C:\Users\khoja\AppData\Roaming\FreeSoftwareUpdater\updater.exe =>PUP.Eorezo O4 - HKLM\..\Wow6432Node\Run: [ApnTBMon] . (.APN - Ask Toolbar Notifier.) -- C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe =>Toolbar.Ask O4 - HKLM\..\Wow6432Node\Run: [VNT] . (.APN LLC. - Virtual New Tab Loader.) -- C:\Program Files (x86)\VNT\vntldr.exe =>Toolbar.Ask O4 - HKLM\..\policies\Explorer\Run: [Policies] C:\Windows\system32\install2016\ver.exe (.not file.) O4 - HKCU\..\policies\Explorer\Run: [Policies] C:\Windows\system32\install2016\ver.exe (.not file.) O4 - HKUS\S-1-5-21-2492572214-1095162767-3787251965-1000\..\Run: [SearchProtection] . (.Spigot, Inc. - Search Protection.) -- C:\Users\khoja\AppData\Roaming\Search Protection\SearchProtection.exe =>PUP.Dealio O4 - HKUS\S-1-5-21-2492572214-1095162767-3787251965-1000\..\Run: [Software updater] . (...) -- C:\Users\khoja\AppData\Roaming\FreeSoftwareUpdater\updater.exe =>PUP.Eorezo O23 - Service: Service de mise à jour Ask (APNMCP) . (.APN LLC. - APN Updater.) - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe =>Toolbar.Ask O23 - Service: Update LemurLeap (Update LemurLeap) . (.LemurLeap - LemurLeap.) - C:\Program Files (x86)\LemurLeap\updateLemurLeap.exe =>PUP.LemurLeap O23 - Service: Util LemurLeap (Util LemurLeap) . (.LemurLeap - LemurLeap.) - C:\Program Files (x86)\LemurLeap\bin\utilLemurLeap.exe =>PUP.LemurLeap [MD5.3FE83108CDDD427C6965A743654D0B9B] [APT] [Volaro Update] (.Volaro.) -- C:\Program Files (x86)\Volaro\Updater\Updater.exe [281368] =>Trojan.Vonteera [MD5.B763782BEB7D4BE135B493A66AE2C841] [APT] [{85DA86F6-25CE-4E40-B2D7-E44D73347072}] (.Ask Partner Network.) -- C:\Program Files (x86)\AskPartnerNetwork\Toolbar\APNSetup.exe [509872] O42 - Logiciel: LemurLeap 3.0.0 - (.LemurLeap.) [HKLM][64Bits] -- LemurLeap =>PUP.LemurLeap O42 - Logiciel: Volaro Updater - (.Volaro.) [HKLM][64Bits] -- Volaro Updater =>Trojan.Vonteera O42 - Logiciel: Vonteera - (.Vonteera.) [HKLM][64Bits] -- Vonteera =>Trojan.Vonteera [HKCU\Software\BitComet] =>P2P.BitComet [HKCU\Software\Conduit] =>Toolbar.Conduit [HKCU\Software\LemurLeap] =>PUP.LemurLeap [HKCU\Software\Softonic] =>Toolbar.Conduit [HKCU\Software\Tencent] =>Adware.TencentAddressBar [HKCU\Software\Volaro] =>Trojan.Vonteera [HKCU\Software\Vonteera] =>Trojan.Vonteera [HKLM\Software\Wow6432Node\AskPartnerNetwork] [HKLM\Software\Wow6432Node\BabylonToolbar] =>PUP.Babylon [HKLM\Software\Wow6432Node\Babylon] =>PUP.Babylon [HKLM\Software\Wow6432Node\Conduit] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\LemurLeap] =>PUP.LemurLeap [HKLM\Software\Wow6432Node\Tencent] =>Adware.TencentAddressBar [HKLM\Software\Wow6432Node\eSafeSecControl] =>PUP.eSafeSecurity O43 - CFD: 15/12/2013 - 19:07:01 - [8,590] ----D C:\Program Files (x86)\AskPartnerNetwork O43 - CFD: 31/08/2013 - 20:57:37 - [0,609] ----D C:\Program Files (x86)\Conduit O43 - CFD: 03/10/2013 - 08:10:10 - [2,750] ----D C:\Program Files (x86)\LemurLeap =>PUP.LemurLeap O43 - CFD: 07/07/2013 - 10:20:56 - [2,258] ----D C:\Program Files (x86)\Softonic =>Toolbar.Conduit O43 - CFD: 07/07/2013 - 18:18:45 - [89,065] ----D C:\Program Files (x86)\Tencent =>Adware.TencentAddressBar O43 - CFD: 08/07/2013 - 21:14:34 - [0,334] ----D C:\Program Files (x86)\Volaro =>Trojan.Vonteera O43 - CFD: 15/08/2013 - 14:40:22 - [0,130] ----D C:\Program Files (x86)\VonteeraAddon =>Trojan.Vonteera O43 - CFD: 09/07/2013 - 12:21:24 - [0] ----D C:\ProgramData\Babylon =>PUP.Babylon O43 - CFD: 17/09/2013 - 07:41:45 - [0,052] ----D C:\ProgramData\eSafe =>PUP.eSafeSecurity O43 - CFD: 08/07/2013 - 21:15:13 - [0,001] ----D C:\ProgramData\IBUpdaterService =>Adware.InstallBrain O43 - CFD: 07/07/2013 - 18:20:05 - [0] ----D C:\ProgramData\Tencent =>Adware.TencentAddressBar O43 - CFD: 01/08/2013 - 14:26:32 - [0,457] ----D C:\Users\khoja\AppData\Roaming\B1Toolbar =>Hijacker.SearchB1org O43 - CFD: 09/07/2013 - 12:21:24 - [0,007] ----D C:\Users\khoja\AppData\Roaming\Babylon =>PUP.Babylon O43 - CFD: 15/12/2013 - 20:22:26 - [0,338] ----D C:\Users\khoja\AppData\Roaming\BitComet =>P2P.BitComet O43 - CFD: 07/07/2013 - 10:20:54 - [0,259] ----D C:\Users\khoja\AppData\Roaming\Softonic =>Toolbar.Conduit O43 - CFD: 07/07/2013 - 18:20:05 - [0,973] ----D C:\Users\khoja\AppData\Roaming\Tencent =>Adware.TencentAddressBar O43 - CFD: 09/07/2013 - 12:21:25 - [4,529] ----D C:\Users\khoja\AppData\Local\Babylon =>PUP.Babylon O43 - CFD: 31/08/2013 - 21:38:40 - [0] ----D C:\Users\khoja\AppData\Local\Conduit O43 - CFD: 07/07/2013 - 18:18:49 - [0,004] ----D C:\Users\khoja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tencent =>Adware.TencentAddressBar O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.qvo6.com =>Hijacker.Qvo6 O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Users\khoja\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" http://www.qvo6.com =>Hijacker.Qvo6 O69 - SBI: SearchScopes [HKCU] D48DE57265A04DB09BC33E733051BADE [DefaultScope] - (Yahoo! Search) - http://search.yahoo.com O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} - (Search the web (Babylon)) - http://search.babylon.com =>Adware.IMBooster O69 - SBI: SearchScopes [HKCU] {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} - (Ask Search) - http://websearch.ask.com =>Toolbar.Ask O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} - (qvo6) - http://search.qvo6.com =>Hijacker.Qvo6 O69 - SBI: SearchScopes [HKCU] {756D1D40-E491-4E1D-9BC6-5B37CEDE646E} - (VenteeRo) - http://www.arabyonline.com O69 - SBI: SearchScopes [HKCU] {8ADF7C14-0437-43F4-AC13-21629FE379C1} - (Web Search) - http://search.conduit.com O69 - SBI: SearchScopes [HKCU] {9125F83C-0B73-475F-B1C4-3D977CC948BD} - (Search the web (Softonic)) - http://search.softonic.com =>Adware.IMBooster O87 - FAEL: "TCP Query User{27616A4A-EA65-4883-ACC6-F605AF5F8FFC}C:\program files (x86)\tencent\qqplayer\qqplayer.exe" | In - Public - P6 - TRUE | .(.Tencent Technology Company limited - QQ Player.) -- C:\program files (x86)\tencent\qqplayer\qqplayer.exe =>Adware.TencentAddressBar O87 - FAEL: "UDP Query User{C75CA3C2-3F67-4235-B8D1-0F2FA1F53236}C:\program files (x86)\tencent\qqplayer\qqplayer.exe" | In - Public - P17 - TRUE | .(.Tencent Technology Company limited - QQ Player.) -- C:\program files (x86)\tencent\qqplayer\qqplayer.exe =>Adware.TencentAddressBar SS - | Auto 07/07/2013 116648 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 07/07/2013 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 07/07/2013 194032 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe SS - | Auto 03/10/2013 65312 | (Update LemurLeap) . (.LemurLeap.) - C:\Program Files (x86)\LemurLeap\updateLemurLeap.exe =>PUP.LemurLeap SR - | Auto 07/11/2013 166352 | (APNMCP) . (.APN LLC..) - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe =>Toolbar.Ask [HKLM\Software\Google\Chrome\Extensions\aaaajepdnhoaepmhbcinpphpaiennofj] =>Toolbar.Ask^ [HKLM\Software\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo] =>PUP.Elex^ [HKLM\Software\Google\Chrome\Extensions\jlnfdbbladgcmhhamgkioifhbobjaoof] =>PUP.LemurLeap^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{415419C3-DAD0-4DF1-AC37-22C72AD81878}] =>PUP.LemurLeap^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E87806B5-E908-45FD-AF5E-957D83E58E68}] =>Toolbar.Conduit^ [HKLM\SYSTEM\CurrentControlSet\Services\APNMCP] =>Toolbar.Ask^ [HKLM\SYSTEM\CurrentControlSet\Services\Update LemurLeap] =>PUP.LemurLeap^ [HKLM\SYSTEM\CurrentControlSet\Services\Util LemurLeap] =>PUP.LemurLeap^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\BitTorrent DNA] =>P2P.BitTorrent^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\LemurLeap] =>PUP.LemurLeap^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Volaro Updater] =>Trojan.Vonteera^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vonteera] =>Trojan.Vonteera^ [HKLM\Software\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}] =>PUP.Babylon [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}] =>PUP.Babylon [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}] =>Toolbar.Ask [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software [HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software [HKLM\Software\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] =>PUP.Babylon [HKLM\Software\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}] =>Toolbar.Ask [HKLM\Software\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06}] =>PUP.Babylon [HKLM\Software\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}] =>PUP.Babylon [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}] =>Toolbar.Avira [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}] =>Toolbar.Avira [HKLM\Software\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] =>PUP.Babylon [HKLM\Software\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] =>PUP.Babylon [HKLM\Software\Classes\AppID\BHO.DLL] =>Toolbar.Agent [HKLM\Software\Classes\AppID\escort.dll] =>PUP.Babylon [HKLM\Software\Classes\AppID\escortapp.dll] =>PUP.Babylon [HKLM\Software\Classes\AppID\escorteng.dll] =>PUP.Babylon [HKLM\Software\Classes\AppID\esrv.EXE] =>PUP.Babylon [HKLM\Software\Classes\escort.escortIEPane] =>PUP.Funmoods [HKLM\Software\Classes\escort.escortIEPane.1] =>PUP.Funmoods [HKLM\Software\Classes\S] =>Toolbar.Agent [HKCU\Software\APN PIP] =>Toolbar.Ask [HKLM\Software\Wow6432Node\BabylonToolbar] =>PUP.Babylon [HKCU\Software\AppDataLow\Software\ConduitSearchScopes] =>Toolbar.Conduit [HKCU\Software\Softonic] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Softonic] =>Toolbar.Conduit [HKLM\Software\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492}] =>Toolbar.Conduit [HKLM\Software\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F}] =>Toolbar.Conduit [HKLM\Software\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9}] =>Toolbar.Conduit [HKLM\Software\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A}] =>Toolbar.Conduit [HKLM\Software\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6}] =>Toolbar.Conduit [HKLM\Software\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6}] =>Toolbar.Conduit [HKLM\Software\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D}] =>Toolbar.Conduit [HKLM\Software\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE}] =>Toolbar.Conduit [HKLM\Software\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79}] =>Toolbar.Conduit [HKLM\Software\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496}] =>Toolbar.Conduit [HKLM\Software\Classes\AppID\{B15F118E-AF21-45E8-A809-29FDD7362565}] =>PUP.Funmoods [HKLM\Software\Classes\TypeLib\{B15F118E-AF21-45E8-A809-29FDD7362565}] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\{B15F118E-AF21-45E8-A809-29FDD7362565}] =>PUP.Funmoods [HKLM\Software\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}] =>PUP.Funmoods [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}] =>Toolbar.Conduit [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CF034EA-7B46-48D3-8895-8A14B32AE445}] =>Toolbar.Conduit [HKLM\Software\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3}] =>Toolbar.Conduit [HKLM\Software\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA}] =>Toolbar.Conduit [HKLM\Software\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94}] =>Toolbar.Conduit [HKLM\Software\Classes\TypeLib\{11D9E165-B8C1-4734-A56C-BC4FCACA966B}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\softonic] =>Toolbar.Conduit [HKLM\Software\Classes\AppID\VONTEERA.DLL] =>Trojan.Vonteera [HKLM\Software\Classes\Prod.cap] =>PUP.Babylon [HKLM\Software\Wow6432Node\qvo6Software] =>Hijacker.Qvo6 [HKLM\Software\Wow6432Node\eSafeSecControl] =>PUP.eSafeSecurity [HKLM\Software\Wow6432Node\Microsoft\Tracing\ConduitInstaller_RASAPI32] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Microsoft\Tracing\ConduitInstaller_RASMANCS] =>Toolbar.Conduit [HKCU\Software\AskPartnerNetwork] =>Toolbar.Ask [HKLM\Software\Wow6432Node\AskPartnerNetwork] =>Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\464AA55239C100F32AF2D438EDDC0F47] =>Adware.IMBooster [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5652BA3D5FB98AE31B337BF0AF939856] =>Adware.IMBooster [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EB95E1AFCBABE3DB9ECCC669B99494] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo] =>PUP.Elex [HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc] =>PUP.eSafeSecurity [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D5FEC983-01DB-414A-9456-AF95AC9ED7B5}] =>Toolbar.YandexFastDial [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D5FEC983-01DB-414A-9456-AF95AC9ED7B5}] =>Toolbar.YandexFastDial [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5FEC983-01DB-414A-9456-AF95AC9ED7B5}] =>Toolbar.YandexFastDial [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{91397D20-1446-11D4-8AF4-0040CA1127B6}] =>Toolbar.YandexFastDial [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{91397D20-1446-11D4-8AF4-0040CA1127B6}] =>Toolbar.YandexFastDial [HKLM\Software\Wow6432Node\Google\Chrome\Extensions\jlnfdbbladgcmhhamgkioifhbobjaoof] =>PUP.LemurLeap [HKLM\Software\Wow6432Node\Microsoft\Tracing\apnstub_RASAPI32] =>Toolbar.Ask [HKLM\Software\Wow6432Node\Microsoft\Tracing\apnstub_RASMANCS] =>Toolbar.Ask [HKLM\Software\Wow6432Node\Microsoft\Tracing\askpartnercobrandingtool_rasapi32] =>Toolbar.Ask [HKLM\Software\Wow6432Node\Microsoft\Tracing\askpartnercobrandingtool_rasmancs] =>Toolbar.Ask [HKLM\Software\Classes\protector_dll.protectorbho] =>PUP.BProtector [HKLM\Software\Classes\protector_dll.protectorbho.1] =>PUP.BProtector [HKLM\Software\Classes\AppID\escorTlbr.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\escort.escortIEPane] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\escort.escortIEPane.1] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\escort.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\escortApp.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\escortEng.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\escorTlbr.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1}] =>Toolbar.Conduit^ [HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{2318C2B1-4965-11d4-9B18-009027A5CD4F} =>Toolbar.Google^ [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:uTorrent =>P2P.BitTorrent^ [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:ApnTBMon =>Toolbar.Ask^ [HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{D4027C7F-154A-4066-A1AD-4243D8127440} =>Toolbar.Avira C:\Users\khoja\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaajepdnhoaepmhbcinpphpaiennofj =>Toolbar.Ask^ C:\Users\khoja\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo =>PUP.Elex^ C:\Users\khoja\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlnfdbbladgcmhhamgkioifhbobjaoof =>PUP.LemurLeap^ C:\Program Files (x86)\LemurLeap =>PUP.LemurLeap^ C:\Program Files (x86)\Softonic =>Toolbar.Conduit^ C:\Program Files (x86)\Tencent =>Adware.TencentAddressBar^ C:\Program Files (x86)\Volaro =>Trojan.Vonteera^ C:\Program Files (x86)\VonteeraAddon =>Trojan.Vonteera^ C:\ProgramData\Babylon =>PUP.Babylon^ C:\ProgramData\eSafe =>PUP.eSafeSecurity^ C:\ProgramData\IBUpdaterService =>Adware.InstallBrain^ C:\ProgramData\Tencent =>Adware.TencentAddressBar^ C:\Users\khoja\AppData\Roaming\B1Toolbar =>Hijacker.SearchB1org^ C:\Users\khoja\AppData\Roaming\Babylon =>PUP.Babylon^ C:\Users\khoja\AppData\Roaming\BitComet =>P2P.BitComet^ C:\Users\khoja\AppData\Roaming\Softonic =>Toolbar.Conduit^ C:\Users\khoja\AppData\Roaming\Tencent =>Adware.TencentAddressBar^ C:\Users\khoja\AppData\Local\Babylon =>PUP.Babylon^ C:\Users\khoja\AppData\Local\DProtect =>Trojan.Staser^ C:\Users\khoja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tencent =>Adware.TencentAddressBar^ C:\Program Files (x86)\Conduit =>Toolbar.Conduit C:\Program Files (x86)\AskPartnerNetwork =>Toolbar.Ask C:\ProgramData\AskPartnerNetwork =>Toolbar.Ask C:\Users\khoja\AppData\Local\Conduit =>Toolbar.Conduit C:\Users\khoja\AppData\Local\B1E =>Toolbar.BrotherSoft C:\Users\khoja\AppData\LocalLow\Conduit =>Toolbar.Conduit C:\Users\khoja\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent^ C:\Users\khoja\AppData\Roaming\Search Protection\SearchProtection.exe =>PUP.Dealio^ C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe =>Toolbar.Ask^ C:\Users\khoja\AppData\Local\VNT\vntldr.exe =>Toolbar.Ask^ C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe =>Toolbar.Ask^ C:\Program Files (x86)\LemurLeap\bin\utilLemurLeap.exe =>PUP.LemurLeap^ C:\Program Files (x86)\Volaro\Updater\Updater.exe =>Trojan.Vonteera^ [HKCU\Software\BitComet] =>P2P.BitComet^ [HKCU\Software\Conduit] =>Toolbar.Conduit^ [HKCU\Software\LemurLeap] =>PUP.LemurLeap^ [HKCU\Software\Tencent] =>Adware.TencentAddressBar^ [HKCU\Software\Volaro] =>Trojan.Vonteera^ [HKCU\Software\Vonteera] =>Trojan.Vonteera^ [HKLM\Software\Wow6432Node\Babylon] =>PUP.Babylon^ [HKLM\Software\Wow6432Node\Conduit] =>Toolbar.Conduit^ [HKLM\Software\Wow6432Node\LemurLeap] =>PUP.LemurLeap^ [HKLM\Software\Wow6432Node\Tencent] =>Adware.TencentAddressBar^ EmptyFlash EmptyTemp EmptyClsid FirewallRaz Proxyfix SysRestore