Script ZHPFix [MD5.14D133377D80BB4F28B71C2BFDC4D41B] - (...) -- C:\Program Files (x86)\PenWes\penwes.exe [1426432] [PID.2928] =>PUP.Penwes [MD5.DEABB07BC9B0009D826D2CA04C43F90F] - (.Conduit - Search Protect by Conduit.) -- C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe [4693792] [PID.3364] =>Toolbar.Conduit [MD5.EFAAE131121B7AD73CBA0FECC0B5A277] - (.Conduit - Search Protect by Conduit.) -- C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe [3037472] [PID.1812] =>Toolbar.Conduit [MD5.AA3B0D91CBD9D30303C848AEBC9836DA] - (.Aztec Media Inc - Systemk Service.) -- C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe [3543056] [PID.3464] =>PUP.SystemK [MD5.CF8DDE5A58FFB4131FC2E95D0A0BB9E9] - (.Aztec Media Inc - SystemK Module.) -- C:\Program Files (x86)\Settings Manager\systemk\systemku.exe [3582992] [PID.3580] =>PUP.SystemK [MD5.F31EAD497B8CBE16895A3B7B201C4EAE] - (.Conduit - Search Protect by Conduit.) -- C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [2470688] [PID.6812] =>Toolbar.Conduit G0 - GCSP: Preference [User Data\Default][HomePage] http://start.iminent.com =>Adware.IMBooster G2 - GCE: Preference [User Data\Default] [afjegdojkkoghnbiollpogeeimocanmk] SupraSavings v.5.0, (Activé) =>PUP.SupraSavings G2 - GCE: Preference [User Data\Default] [flpcjncodpafbgdpnkljologafpionhb] Managera v.0.1 (Activé) =>PUP.Manager M3 - MFPP: Plugins - [ACMimi] -- C:\Users\ACMimi\AppData\Roaming\Mozilla\Firefox\Profiles\9xnxg92z.default\searchplugins\iminent.xml =>Adware.IMBooster M2 - MFEP: prefs.js [ACMimi - 9xnxg92z.default\addon@freecorder.com] [] Freecorder v7.0.0.13 (..) =>Riskware.Movly M2 - MFEP: prefs.js [ACMimi - 9xnxg92z.default\extension@linkeyproject.com] [] Linkey for Firefox v1.0 (..) =>PUP.LinkeySearch M2 - MFEP: prefs.js [ACMimi - 9xnxg92z.default\ffxtlbr@iminent.com] [] Iminent Toolbar v1.6.0 (..) =>Adware.IMBooster M2 - MFEP: prefs.js [ACMimi - 9xnxg92z.default\SupraSavings@jetpack] [] SupraSavings v5.0 (..) =>PUP.SupraSavings M2 - MFEP: prefs.js [ACMimi - 9xnxg92z.default\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7}] [] Settings Manager v5.0.0.12521 (..) =>PUP.SystemK O3 - Toolbar\WebBrowser: (no name) - [HKCU]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} Clé orpheline O3 - Toolbar\WebBrowser: (no name) - [HKCU]{724D43A0-0D85-11D4-9908-00400523E39A} Clé orpheline O23 - Service: Search Protect by Conduit Service (CltMngSvc) . (.Conduit - Search Protect by Conduit.) - C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe =>Toolbar.Conduit O23 - Service: SProtection (SProtection) . (...) - C:\Program Files (x86)\Common Files\Umbrella\Umbrella235.exe (.not file.) O23 - Service: xmkysecqun64 (xmkysecqun64) . (...) - C:\Program Files\003\xmkysecqun64.exe (.not file.) =>PUP.AdPeak O23 - Service: yewimmxqbs64 (yewimmxqbs64) . (...) - C:\Program Files\002\yewimmxqbs64.exe =>PUP.AdPeak O36 - AppCertDlls: (x86) . (...) -- C:\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll =>PUP.SystemK O36 - AppCertDlls: (x64) . (...) -- C:\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll =>PUP.SystemK [MD5.14D133377D80BB4F28B71C2BFDC4D41B] [APT] [PenWes] (...) -- C:\Program Files (x86)\PenWes\penwes.exe [1426432] =>PUP.Penwes O41 - Driver: ({9e891144-6b11-4b15-831d-1fc05f439ef4}w64) . (.StdLib - StdLib.) - C:\Windows\System32\drivers\{9e891144-6b11-4b15-831d-1fc05f439ef4}w64.sys =>PUP.LinkiDoo O42 - Logiciel: Advanced System Protector - (.Systweak Software.) [HKLM][64Bits] -- 00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1 =>PUP.AdvancedSystemProtector O42 - Logiciel: Iminent - (.Iminent.) [HKLM][64Bits] -- IMBoosterARP =>Adware.IMBooster O42 - Logiciel: PenWes [6225] - (...) [HKLM][64Bits] -- Penwes =>PUP.Penwes O42 - Logiciel: Search Protect - (.Conduit.) [HKLM][64Bits] -- SearchProtect =>Toolbar.Conduit O42 - Logiciel: Sing Along - (.Xenophesoft.) [HKLM][64Bits] -- singalong@xenophesoft.com =>Adware.Singalng O42 - Logiciel: SupraSavings - (.SupraSavings.) [HKLM][64Bits] -- {E6B105B8-1F65-4428-9397-1DFD8A03B94D} =>PUP.SupraSavings O42 - Logiciel: System Speedup - (.systemspeedup.com.) [HKLM][64Bits] -- System Speedup_is1 =>PUP.SystemSpeedup O42 - Logiciel: VO Package - (...) [HKLM][64Bits] -- VOPackage =>Adware.Downware O42 - Logiciel: rrsavings - (.rrsavings.) [HKLM][64Bits] -- rrsavings =>PUP.SupraSavings O42 - Logiciel: suprasavings - (.suprasavings.) [HKLM][64Bits] -- suprasavings =>PUP.SupraSavings [HKCU\Software\SystemK] =>PUP.SystemK [HKLM\Software\LevelQualityWatcher] =>PUP.LevelQualityWatcher [HKLM\Software\Linkey] =>PUP.LinkeySearch [HKLM\Software\Wow6432Node\IminentToolbar] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Iminent] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Jump Flip] =>PUP.JumpFlip [HKLM\Software\Wow6432Node\Linkey] =>PUP.LinkeySearch [HKLM\Software\Wow6432Node\System Speedup] =>PUP.SystemSpeedup [HKLM\Software\Wow6432Node\SystemK] =>PUP.SystemK O43 - CFD: 02/05/2014 - 19:26:25 - [] ----D C:\Program Files (x86)\Advanced System Protector =>PUP.AdvancedSystemProtector O43 - CFD: 02/05/2014 - 19:26:25 - [] ---AD C:\Program Files (x86)\Iminent =>Adware.IMBooster O43 - CFD: 07/04/2014 - 09:14:29 - [] ----D C:\Program Files (x86)\Jump Flip =>PUP.JumpFlip O43 - CFD: 02/05/2014 - 17:44:19 - [] ----D C:\Program Files (x86)\Linkey =>PUP.LinkeySearch O43 - CFD: 12/04/2012 - 10:37:37 - [] ----D C:\Program Files (x86)\PenWes =>PUP.Penwes O43 - CFD: 02/05/2014 - 17:36:07 - [] ----D C:\Program Files (x86)\Settings Manager =>PUP.SystemK O43 - CFD: 02/05/2014 - 19:26:25 - [] ----D C:\Program Files (x86)\SupraSavings =>PUP.SupraSavings O43 - CFD: 02/05/2014 - 19:26:25 - [] ----D C:\Program Files (x86)\System Speedup =>PUP.SystemSpeedup O43 - CFD: 07/05/2014 - 03:00:32 - [] ----D C:\ProgramData\systemk =>PUP.SystemK O43 - CFD: 02/05/2014 - 19:26:25 - [] ----D C:\Program Files (x86)\System Speedup =>PUP.SystemSpeedup O43 - CFD: 07/05/2014 - 03:00:32 - [] ----D C:\ProgramData\systemk =>PUP.SystemK O43 - CFD: 02/05/2014 - 19:26:24 - [] ----D C:\Users\ACMimi\AppData\Roaming\System Speedup =>PUP.SystemSpeedup O44 - LFC:[MD5.4FF990D6249A5EFB2A6774E223748FD7] - 24/04/2014 - 11:26:34 ---A- . (.StdLib - StdLib.) -- C:\Windows\System32\Drivers\{9e891144-6b11-4b15-831d-1fc05f439ef4}w64.sys [61112] =>PUP.LinkiDoo O50 - IFEO:Image File Execution Options - bitguard.exe - tasklist.exe =>PUP.BitGuard O50 - IFEO:Image File Execution Options - browserdefender.exe - tasklist.exe =>Hijacker.Eazel O50 - IFEO:Image File Execution Options - browserprotect.exe - tasklist.exe =>Hijacker.Eazel O50 - IFEO:Image File Execution Options - browsersafeguard.exe - tasklist.exe =>PUP.BrowserSafeguard O50 - IFEO:Image File Execution Options - DatamngrCoordinator.exe - tasklist.exe =>PUP.Datamngr O50 - IFEO:Image File Execution Options - dprotectsvc.exe - tasklist.exe =>Trojan.Staser O50 - IFEO:Image File Execution Options - jumpflip - tasklist.exe =>PUP.JumpFlip O50 - IFEO:Image File Execution Options - protectedsearch.exe - tasklist.exe =>Spyware.ProtectedSearch O50 - IFEO:Image File Execution Options - searchinstaller.exe - tasklist.exe O50 - IFEO:Image File Execution Options - searchprotection.exe - tasklist.exe =>Toolbar.Conduit O50 - IFEO:Image File Execution Options - searchprotector.exe - tasklist.exe =>Toolbar.Conduit O50 - IFEO:Image File Execution Options - searchsettings.exe - tasklist.exe =>Adware.SearchSettings O50 - IFEO:Image File Execution Options - searchsettings64.exe - tasklist.exe =>Adware.SearchSettings O50 - IFEO:Image File Execution Options - snapdo.exe - tasklist.exe =>Hijacker.SmartBar O50 - IFEO:Image File Execution Options - stinst32.exe - tasklist.exe O50 - IFEO:Image File Execution Options - stinst64.exe - tasklist.exe O50 - IFEO:Image File Execution Options - umbrella.exe - tasklist.exe =>Adware.IMBooster O50 - IFEO:Image File Execution Options - utiljumpflip.exe - tasklist.exe =>PUP.JumpFlip O50 - IFEO:Image File Execution Options - volaro - tasklist.exe =>Trojan.Vonteera O50 - IFEO:Image File Execution Options - vonteera - tasklist.exe =>Trojan.Vonteera O50 - IFEO:Image File Execution Options - websteroids.exe - tasklist.exe =>PUP.TubeDimmer O50 - IFEO:Image File Execution Options - websteroidsservice.exe - tasklist.exe =>PUP.TubeDimmer O58 - SDL:24/04/2014 - 11:26:34 ---A- . (.StdLib - StdLib.) -- C:\Windows\System32\Drivers\{9e891144-6b11-4b15-831d-1fc05f439ef4}w64.sys [61112] =>PUP.LinkiDoo O64 - Services: CurCS - 24/04/2014 - C:\Windows\System32\drivers\{9e891144-6b11-4b15-831d-1fc05f439ef4}w64.sys ({9e891144-6b11-4b15-831d-1fc05f439ef4}w64) .(.StdLib - StdLib.) - LEGACY_{9E891144-6B11-4B15-831D-1FC05F439EF4}W64 =>PUP.LinkiDoo O69 - SBI: SearchScopes [HKCU] {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} - (default-search.net) - http://www.default-search.net =>Hijacker.SearchNet O90 - PUC: "8B501B6E56F182443979D1DFA8309BD4" . (.SupraSavings.) -- c:\Windows\Installer\{E6B105B8-1F65-4428-9397-1DFD8A03B94D}\icon64.ico =>PUP.SupraSavings HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32 =>PUP.MyPCBackup HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS =>PUP.MyPCBackup HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32 =>PUP.AdvancedSystemProtector HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS =>PUP.AdvancedSystemProtector HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BabMaint_RASAPI32 =>Hijacker.BabSolution HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BabMaint_RASMANCS =>Hijacker.BabSolution HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\penwes_RASAPI32 =>PUP.Penwes HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\penwes_RASDLG =>PUP.Penwes HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\penwes_RASMANCS =>PUP.Penwes HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SetupPenWes_RASAPI32 =>PUP.Penwes HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SetupPenWes_RASMANCS =>PUP.Penwes HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateJumpFlip_RASAPI32 =>PUP.JumpFlip HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateJumpFlip_RASMANCS =>PUP.JumpFlip HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\utilJumpFlip_RASAPI32 =>PUP.JumpFlip HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\utilJumpFlip_RASMANCS =>PUP.JumpFlip [HKCR\CLSID\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}] (Linkey) =>PUP.LinkeySearch [HKCR\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}] (SystemK Module) =>PUP.SystemK [HKCR\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] (IMinent WebBooster (BHO)) =>Adware.IMBooster SS - | Auto 10/07/1658 0 | (xmkysecqun64) . (...) - C:\Program Files\003\xmkysecqun64.exe =>PUP.AdPeak SR - | Auto 08/04/2014 2470688 | (CltMngSvc) . (.Conduit.) - C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe =>Toolbar.Conduit SR - | System 28/04/2014 36240 | (F06DEFF2-5B9C-490D-910F-35D3A91196222) . (.Aztec Media Inc.) - C:\Program Files (x86)\Settings Manager\systemk\x64\systemkmgrc1.cfg =>PUP.SystemK SR - | Auto 02/05/2014 706560 | (yewimmxqbs64) . (...) - C:\Program Files\002\yewimmxqbs64.exe =>PUP.AdPeak [HKLM\Software\Google\Chrome\Extensions\afjegdojkkoghnbiollpogeeimocanmk] =>PUP.SupraSavings^ [HKLM\Software\Google\Chrome\Extensions\flpcjncodpafbgdpnkljologafpionhb] =>PUP.Manager^ [HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc] =>Toolbar.Conduit^ [HKLM\SYSTEM\CurrentControlSet\Services\xmkysecqun64] =>PUP.AdPeak^ [HKLM\SYSTEM\CurrentControlSet\Services\yewimmxqbs64] =>PUP.AdPeak^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1] =>PUP.AdvancedSystemProtector^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP] =>Adware.IMBooster^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Penwes] =>PUP.Penwes^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect] =>Toolbar.Conduit^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\singalong@xenophesoft.com] =>Adware.Singalng^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E6B105B8-1F65-4428-9397-1DFD8A03B94D}] =>PUP.SupraSavings^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\System Speedup_is1] =>PUP.SystemSpeedup^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage] =>Adware.Downware^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\rrsavings] =>PUP.SupraSavings^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\suprasavings] =>PUP.SupraSavings^ [HKLM\Software\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11}] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11}] =>Adware.IMBooster [HKLM\Software\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}] =>PUP.Babylon [HKLM\Software\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] =>PUP.Babylon [HKLM\Software\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] =>PUP.Babylon [HKLM\Software\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\singalong@xenophesoft.com] =>Adware.Singalng [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] =>Adware.IMBooster [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] =>Adware.IMBooster [HKLM\Software\Classes\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] =>Adware.IMBooster [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] =>Adware.IMBooster [HKLM\Software\Classes\TypeLib\{A9CAF365-EA35-45DA-BD8B-2EFA09D374AC}] =>Adware.IMBooster [HKLM\Software\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}] =>Adware.IMBooster [HKLM\Software\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}] =>Adware.IMBooster [HKLM\Software\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}] =>Adware.IMBooster [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CFCB809C-3A22-4616-A916-6C007BD9D920}] =>Toolbar.Agent [HKLM\Software\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] =>PUP.Babylon [HKLM\Software\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}] =>Adware.IMBooster [HKLM\Software\Classes\AppID\escort.dll] =>PUP.Babylon [HKLM\Software\Classes\AppID\escortapp.dll] =>PUP.Babylon [HKLM\Software\Classes\AppID\escorteng.dll] =>PUP.Babylon [HKLM\Software\Classes\AppID\esrv.EXE] =>PUP.Babylon [HKLM\Software\Classes\I] =>Adware.IncrediBar [HKLM\Software\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}] =>Adware.Adkubru [HKLM\Software\Wow6432Node\Google\Chrome\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl] =>Adware.IMBooster [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E] =>Toolbar.Ask [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9] =>Adware.MyWebSearch [HKLM\Software\Iminent] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Iminent] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Penwes] =>PUP.Penwes [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect] =>Toolbar.Conduit [HKCU\Software\AppDataLow\Software\SingAlong] =>Adware.Singalng [HKLM\Software\Classes\AppID\RegistryHelper.DLL] =>Toolbar.Freecorder [HKLM\Software\Classes\AppID\{544C2426-48FD-4C40-AE3B-31257FF334D0}] =>Toolbar.Freecorder [HKLM\Software\Wow6432Node\Classes\AppID\{544C2426-48FD-4C40-AE3B-31257FF334D0}] =>Toolbar.Freecorder [HKLM\Software\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}] =>Toolbar.Freecorder [HKLM\Software\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}] =>Toolbar.Freecorder [HKLM\Software\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}] =>Toolbar.Freecorder [HKLM\Software\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}] =>Toolbar.Freecorder [HKLM\Software\Classes\Interface\{93CF54F5-CFAA-4440-B588-8ED0DFAD5C21}] =>Toolbar.Freecorder [HKLM\Software\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}] =>Toolbar.Freecorder [HKLM\Software\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}] =>Toolbar.Freecorder [HKLM\Software\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}] =>Toolbar.Freecorder [HKLM\Software\Classes\Interface\{B887CA3B-D82B-4A01-AD29-E97444D01CE6}] =>Toolbar.Freecorder [HKLM\Software\Wow6432Node\Classes\Interface\{B887CA3B-D82B-4A01-AD29-E97444D01CE6}] =>Toolbar.Freecorder [HKLM\Software\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}] =>Toolbar.Freecorder [HKLM\Software\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}] =>Toolbar.Freecorder [HKLM\Software\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}] =>Toolbar.Freecorder [HKLM\Software\Classes\Interface\{D3BC53E7-0437-4C97-90EE-2CD6FF47FB14}] =>Toolbar.Freecorder [HKLM\Software\Classes\protector_dll.protectorbho] =>PUP.BProtector [HKLM\Software\Classes\protector_dll.protectorbho.1] =>PUP.BProtector [HKLM\Software\Classes\esrv.iminentESrvc] =>Adware.IMBooster [HKLM\Software\Classes\esrv.iminentESrvc.1] =>Adware.IMBooster [HKLM\Software\Classes\Iminent] =>Adware.IMBooster [HKLM\Software\Classes\iminent.iminentappCore] =>Adware.IMBooster [HKLM\Software\Classes\iminent.iminentappCore.1] =>Adware.IMBooster [HKLM\Software\Classes\iminent.iminentdskBnd] =>Adware.IMBooster [HKLM\Software\Classes\iminent.iminentdskBnd.1] =>Adware.IMBooster [HKLM\Software\Classes\iminent.iminentHlpr] =>Adware.IMBooster [HKLM\Software\Classes\iminent.iminentHlpr.1] =>Adware.IMBooster [HKLM\Software\Classes\IminentWebBooster.BrowserHelperObject] =>Adware.IMBooster [HKLM\Software\Classes\IminentWebBooster.BrowserHelperObject.1] =>Adware.IMBooster [HKLM\Software\Classes\IminentWebBooster.ScriptExtender] =>Adware.IMBooster [HKLM\Software\Classes\IminentWebBooster.ScriptExtender.1] =>Adware.IMBooster [HKLM\Software\Classes\AppID\escorTlbr.DLL] =>PUP.Funmoods [HKLM\Software\Classes\AppID\Iminent.WebBooster.InternetExplorer.DLL] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\esrv.iminentESrvc] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\esrv.iminentESrvc.1] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\Iminent] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\iminent.iminentappCore] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\iminent.iminentappCore.1] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\iminent.iminentdskBnd] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\iminent.iminentdskBnd.1] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\iminent.iminentHlpr] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\iminent.iminentHlpr.1] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\IminentWebBooster.BrowserHelperObject] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\IminentWebBooster.BrowserHelperObject.1] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\IminentWebBooster.ScriptExtender] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\IminentWebBooster.ScriptExtender.1] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\AppID\escort.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\escortApp.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\escortEng.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\escorTlbr.DLL] =>PUP.Funmoods [HKLM\Software\Wow6432Node\Classes\AppID\Iminent.WebBooster.InternetExplorer.DLL] =>Adware.IMBooster [HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}] =>Adware.Bandoo C:\Users\ACMimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\afjegdojkkoghnbiollpogeeimocanmk =>PUP.SupraSavings^ C:\Users\ACMimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\flpcjncodpafbgdpnkljologafpionhb =>PUP.Manager^ C:\Users\ACMimi\AppData\Roaming\Mozilla\Firefox\Profiles\9xnxg92z.default\extensions\addon@freecorder.com =>Riskware.Movly^ C:\Users\ACMimi\AppData\Roaming\Mozilla\Firefox\Profiles\9xnxg92z.default\extensions\extension@linkeyproject.com =>PUP.LinkeySearch^ C:\Users\ACMimi\AppData\Roaming\Mozilla\Firefox\Profiles\9xnxg92z.default\extensions\ffxtlbr@iminent.com =>Adware.IMBooster^ C:\Users\ACMimi\AppData\Roaming\Mozilla\Firefox\Profiles\9xnxg92z.default\extensions\SupraSavings@jetpack =>PUP.SupraSavings^ C:\Users\ACMimi\AppData\Roaming\Mozilla\Firefox\Profiles\9xnxg92z.default\extensions\{1ED03F15-1006-1C66-CCA5-15A00B80A7B7} =>PUP.SystemK^ C:\Program Files (x86)\Advanced System Protector =>PUP.AdvancedSystemProtector^ C:\Program Files (x86)\Iminent =>Adware.IMBooster^ C:\Program Files (x86)\Jump Flip =>PUP.JumpFlip^ C:\Program Files (x86)\Linkey =>PUP.LinkeySearch^ C:\Program Files (x86)\PenWes =>PUP.Penwes^ C:\Program Files (x86)\Settings Manager =>PUP.SystemK^ C:\Program Files (x86)\SupraSavings =>PUP.SupraSavings^ C:\Program Files (x86)\System Speedup =>PUP.SystemSpeedup^ C:\ProgramData\systemk =>PUP.SystemK^ C:\Users\ACMimi\AppData\Roaming\System Speedup =>PUP.SystemSpeedup^ C:\Program Files (x86)\iMesh Applications =>PUP.iMesh C:\Program Files (x86)\SearchProtect =>Toolbar.Conduit C:\ProgramData\Software =>Adware.Boxore C:\Users\ACMimi\AppData\Local\SearchProtect =>Toolbar.Conduit C:\Users\ACMimi\AppData\Local\Software =>Adware.Boxore C:\Users\ACMimi\AppData\Local\Temp\Iminent =>Adware.IMBooster C:\Program Files (x86)\PenWes\penwes.exe =>PUP.Penwes^ C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe =>Toolbar.Conduit^ C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe =>Toolbar.Conduit^ C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe =>PUP.SystemK^ C:\Program Files (x86)\Settings Manager\systemk\systemku.exe =>PUP.SystemK^ C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe =>Toolbar.Conduit^ [HKCU\Software\SystemK] =>PUP.SystemK^ [HKLM\Software\LevelQualityWatcher] =>PUP.LevelQualityWatcher^ [HKLM\Software\Linkey] =>PUP.LinkeySearch^ [HKLM\Software\Wow6432Node\IminentToolbar] =>Adware.IMBooster^ [HKLM\Software\Wow6432Node\Jump Flip] =>PUP.JumpFlip^ [HKLM\Software\Wow6432Node\Linkey] =>PUP.LinkeySearch^ [HKLM\Software\Wow6432Node\System Speedup] =>PUP.SystemSpeedup^ [HKLM\Software\Wow6432Node\SystemK] =>PUP.SystemK^ [HKCR\CLSID\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}] (Linkey) =>PUP.LinkeySearch^ [HKCR\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1}] (SystemK Module) =>PUP.SystemK^ [HKCR\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] (IMinent WebBooster (BHO)) =>Adware.IMBooster^ [HKCR\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}] (Google Toolbar Helper) =>Toolbar.Google^ C:\Users\ACMimi\AppData\Local\Temp\GoogleToolbarInstaller1.log =>PUP.Babylon C:\Users\ACMimi\AppData\Local\Temp\GoogleToolbarInstaller2.log =>PUP.Babylon C:\Users\ACMimi\AppData\Local\Temp\nsb4B49.exe =>Toolbar.Conduit C:\Users\ACMimi\AppData\Local\Temp\nsb7815.exe =>Toolbar.Conduit C:\Users\ACMimi\AppData\Local\Temp\nsbAF3F.exe =>Toolbar.Conduit C:\Users\ACMimi\AppData\Local\Temp\nsbB3D2.exe =>Toolbar.Conduit C:\Users\ACMimi\AppData\Local\Temp\nsg680C.exe =>Toolbar.Conduit C:\Users\ACMimi\AppData\Local\Temp\nsm52D9.exe =>Toolbar.Conduit C:\Users\ACMimi\AppData\Local\Temp\nsmB8A4.exe =>Toolbar.Conduit C:\Users\ACMimi\AppData\Local\Temp\nsmC040.exe =>Toolbar.Conduit C:\Users\ACMimi\AppData\Local\Temp\nsmCA02.exe =>Toolbar.Conduit C:\Users\ACMimi\AppData\Local\Temp\nsr59FB.exe =>Toolbar.Conduit C:\Users\ACMimi\AppData\Local\Temp\nsw71DD.exe =>Toolbar.Conduit C:\Users\ACMimi\AppData\Local\Temp\nswC511.exe =>Toolbar.Conduit FirewallRaz EmptyFlash Emptytemp ShortcutFix