Script ZHPFix [MD5.5134FDA14EA5C8EB265DAA8136CC76C1] - (...) -- C:\Program Files (x86)\LyricsFolder Corp\LyricsFolder_wd.exe [77312] [PID.3964] =>Adware.AddLyrics [MD5.8B9C04225DBB4AF1F55F325FBE2BDDB2] - (.Smartbar - Smartbar.) -- C:\Users\andree\AppData\Local\Smartbar\Application\QuickShare.exe [20248] [PID.4464] =>PUP.QuickShare [MD5.AD3AAE7C22A571B99CFF5D23FD999C42] - (.Boxore OU - Boxore Client.) -- C:\Program Files (x86)\Boxore\BoxoreClient\boxore.exe [606520] [PID.4616] =>Adware.Boxore [MD5.CEDB27BACA286F063C3A11D44AF530AE] - (...) -- C:\Program Files\IB Updater\ExtensionUpdaterService.exe [188760] [PID.1808] =>Adware.InstallBrain [MD5.1776B5E8B7ED3F7FB0E97CC1F26B4849] - (...) -- C:\Program Files (x86)\LyricsFolder Corp\LyricsFolder158.exe [143360] [PID.2044] =>Adware.AddLyrics G0 - GCSP: Preference [User Data\Default][HomePage] http://mystart.incredibar.com =>Adware.IncrediBar G0 - GCSP: Preference [User Data\Default] http://mystart.incredibar.comtGyDzytAyDyDtAyC0F0BzytBzz2Q&cr=243426903&ir=" ] =>Adware.IncrediBar G2 - GCE: Preference [User Data\Default] [afjegdojkkoghnbiollpogeeimocanmk] SupraSavings v.5.0, (Désactivé) =>PUP.SupraSavings G2 - GCE: Preference [User Data\Default] [amfclgbdpgndipgoegfpkkgobahigbcl] QuickShare Widget v.1.4, (Désactivé) =>PUP.QuickShare G2 - GCE: Preference [User Data\Default] [lmgddjncmooacfihfmikfohkldcjjgml] LyricsFolder v.1.158.0.0 (Désactivé) =>Adware.AddLyrics G2 - GCE: Preference [User Data\Default] [pbpohikckhbcljgombipcdoinkaedlfa] Smart Display v.1.2 (Désactivé) =>Spyware.SmartDisplay R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do =>Hijacker.SmartBar R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com =>Hijacker.Qvo6 R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do =>Hijacker.SmartBar R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com =>Hijacker.Qvo6 R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do =>Hijacker.SmartBar R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do =>Hijacker.SmartBar R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com =>Hijacker.Qvo6 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:13828 =>Hijacker.Proxy O2 - BHO: 2rs3 [64Bits] - {10AD2C61-0898-4348-8600-14A342F22AC3} . (...) -- C:\Program Files (x86)\SupraSavings\2rs3.dll =>PUP.SupraSavings O2 - BHO: QuickShare WidgetEngine [64Bits] - {31ad400d-1b06-4e33-a59a-90c2c140cba0} . (...) -- mscoree.dll (.not file.) =>PUP.QuickShare O2 - BHO: IB Updater Helper [64Bits] - {336D0C35-8A85-403a-B9D2-65C292C39087} . (...) -- C:\Program Files\IB Updater\Extension32.dll =>Adware.InstallBrain O3 - Toolbar: QuickShare Widget - [HKLM]{ae07101b-46d4-4a98-af68-0333ea26e113} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>PUP.QuickShare O3 - Toolbar\WebBrowser: (no name) - [HKCU]{977AE9CC-AF83-45E8-9E03-E2798216E2D5} Clé orpheline => Adware.IMBooster O4 - GS\QuickLaunch [andree]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.qvo6.com =>Hijacker.Qvo6 O4 - GS\Program [andree]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com =>Hijacker.Qvo6 O4 - GS\SystemTools [andree]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com =>Hijacker.Qvo6 O4 - HKCU\..\Run: [Browser Infrastructure Helper] . (.Smartbar - Smartbar.) -- C:\Users\andree\AppData\Local\Smartbar\Application\QuickShare.exe =>PUP.QuickShare O4 - HKCU\..\Run: [Bubble Dock] C:\Users\andree\AppData\Roaming\Nosibay\Bubble Dock\LBubble Dock.exe (.not file.) =>PUP.BubbleDock O4 - HKLM\..\Wow6432Node\Run: [Boxore Client] . (.Boxore OU - Boxore Client.) -- C:\Program Files (x86)\Boxore\BoxoreClient\boxore.exe =>Adware.Boxore O4 - HKUS\S-1-5-21-241383120-1707648695-3901325165-1001\..\Run: [Browser Infrastructure Helper] . (.Smartbar - Smartbar.) -- C:\Users\andree\AppData\Local\Smartbar\Application\QuickShare.exe =>PUP.QuickShare O4 - HKUS\S-1-5-21-241383120-1707648695-3901325165-1001\..\Run: [Bubble Dock] C:\Users\andree\AppData\Roaming\Nosibay\Bubble Dock\LBubble Dock.exe (.not file.) =>PUP.BubbleDock O23 - Service: IB Updater (IB Updater) . (...) - C:\Program Files\IB Updater\ExtensionUpdaterService.exe =>Adware.InstallBrain O23 - Service: (IBUpdaterService) . (...) - C:\Windows\System32\dmwu.exe =>Adware.InstallBrain O23 - Service: LyricsFolder (LyricsFolder) . (...) - C:\Program Files (x86)\LyricsFolder Corp\LyricsFolder158.exe =>Adware.AddLyrics O23 - Service: Software Update Service (supdate) (supdate) . (.Boxore OU. - Programme d'installation de Software.) - C:\Program Files (x86)\Software\Update\SoftwareUpdate.exe =>Adware.Boxore O23 - Service: vxlsnyaiet64 (vxlsnyaiet64) . (...) - C:\Program Files\003\vxlsnyaiet64.exe =>PUP.AdPeak [MD5.311BCE25242D9D00CBD7BB9D8B6E1315] [APT] [Dealply] (...) -- C:\Users\andree\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.exe [102968] =>PUP.DealPly [MD5.00000000000000000000000000000000] [APT] [Desk 365 RunAsStdUser] (...) -- C:\Program Files (x86)\Desk 365\desk365.exe (.not file.) [0] =>Hijacker.22Find [MD5.8C9F79786D63E27BC9502252E933FAD8] [APT] [LyricsFolder Update] (...) -- C:\Program Files (x86)\LyricsFolder Corp\LrcsF.exe [383488] =>Adware.AddLyrics [MD5.5134FDA14EA5C8EB265DAA8136CC76C1] [APT] [LyricsFolder_wd] (...) -- C:\Program Files (x86)\LyricsFolder Corp\LyricsFolder_wd.exe [77312] =>Adware.AddLyrics [MD5.00000000000000000000000000000000] [APT] [MySearchDial] (...) -- C:\Users\andree\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.exe (.not file.) [0] =>Adware.MyWebSearch [MD5.00000000000000000000000000000000] [APT] [Omiga Plus RunAsStdUser] (...) -- C:\Program Files (x86)\Omiga Plus\omigaplus.exe (.not file.) [0] =>Hijacker.OmigaPlus [MD5.251A1AED2D4A26A47C0A4A3058AAE4A8] [APT] [SoftwareUpdateTaskMachineCore] (.Boxore OU..) -- C:\Program Files (x86)\Software\Update\SoftwareUpdate.exe [139576] =>Adware.Boxore [MD5.251A1AED2D4A26A47C0A4A3058AAE4A8] [APT] [SoftwareUpdateTaskMachineUA] (.Boxore OU..) -- C:\Program Files (x86)\Software\Update\SoftwareUpdate.exe [139576] =>Adware.Boxore [MD5.529F6B2DCCF4950BC01A4C86FFE1E658] [APT] [{EA068B39-D6D7-4292-8CF8-F2E3B86A2526}] (...) -- c:\users\andree\appdata\local\lollipop\lollipop.bat [336] =>Adware.Lollipop O39 - APT: Dealply - (...) -- C:\Windows\Tasks\Dealply.job [294] =>PUP.DealPly O39 - APT: Dealply - (...) -- C:\Windows\System32\Tasks\Dealply [294] =>PUP.DealPly O39 - APT: LyricsFolder Update - (...) -- C:\Windows\Tasks\LyricsFolder Update.job [406] =>Adware.AddLyrics O39 - APT: LyricsFolder Update - (...) -- C:\Windows\System32\Tasks\LyricsFolder Update [406] =>Adware.AddLyrics O39 - APT: LyricsFolder_wd - (...) -- C:\Windows\Tasks\LyricsFolder_wd.job [410] =>Adware.AddLyrics O39 - APT: LyricsFolder_wd - (...) -- C:\Windows\System32\Tasks\LyricsFolder_wd [410] =>Adware.AddLyrics O39 - APT: MySearchDial - (...) -- C:\Windows\Tasks\MySearchDial.job [296] =>Adware.MyWebSearch O39 - APT: MySearchDial - (...) -- C:\Windows\System32\Tasks\MySearchDial [296] =>Adware.MyWebSearch O39 - APT: SoftwareUpdateTaskMachineCore - (.Boxore OU..) -- C:\Windows\Tasks\SoftwareUpdateTaskMachineCore.job [1082] =>Adware.Boxore O39 - APT: SoftwareUpdateTaskMachineCore - (.Boxore OU..) -- C:\Windows\System32\Tasks\SoftwareUpdateTaskMachineCore [1082] =>Adware.Boxore O39 - APT: SoftwareUpdateTaskMachineUA - (.Boxore OU..) -- C:\Windows\Tasks\SoftwareUpdateTaskMachineUA.job [1086] =>Adware.Boxore O39 - APT: SoftwareUpdateTaskMachineUA - (.Boxore OU..) -- C:\Windows\System32\Tasks\SoftwareUpdateTaskMachineUA [1086] =>Adware.Boxore O42 - Logiciel: Boxore Client - (.Boxore OU.) [HKLM][64Bits] -- {9BF8BEF9-4DC6-45FC-9AA5-4B1311392CAD} =>Adware.Boxore O42 - Logiciel: BrowserDefender - (.Bit89 Inc.) [HKLM][64Bits] -- {15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693} =>Hijacker.Eazel O42 - Logiciel: IB Updater 2.0.0.574 - (.IncrediBar.) [HKLM][64Bits] -- {336D0C35-8A85-403a-B9D2-65C292C39087}_is1 =>Adware.InstallBrain O42 - Logiciel: IB Updater Service - (...) [HKLM][64Bits] -- WNLT =>Adware.InstallBrain O42 - Logiciel: Lollipop - (.Lollipop Network, S.L..) [HKCU][64Bits] -- lollipop =>Adware.Lollipop O42 - Logiciel: LyricsFolder - (.LormanSoftware.) [HKLM][64Bits] -- ad7f065d-88a6-4783-ab47-94da753f83eb =>Adware.AddLyrics O42 - Logiciel: QuickShare - (.Linkury Inc..) [HKLM][64Bits] -- {AF860F85-54A3-4A28-879B-BF9E6E325776} =>PUP.QuickShare O42 - Logiciel: Services-x87 - (.Corporate Inc.) [HKLM][64Bits] -- Services-x87 => Adware.Pricora O42 - Logiciel: SupraSavings - (.SupraSavings.) [HKLM][64Bits] -- {E6B105B8-1F65-4428-9397-1DFD8A03B94D} =>PUP.SupraSavings O42 - Logiciel: suprasavings - (.suprasavings.) [HKLM][64Bits] -- suprasavings =>PUP.SupraSavings [HKCU\Software\BabSolution] =>Hijacker.BabSolution [HKCU\Software\DataMngr] =>PUP.Datamngr [HKCU\Software\DataMngr_Toolbar] =>PUP.Datamngr [HKCU\Software\DealPlyLive] =>PUP.DealPly [HKCU\Software\Iminent] =>Adware.IMBooster [HKCU\Software\InstallCore] =>Adware.InstallCore [HKCU\Software\InstalledBrowserExtensions] =>Adware.VidSaver [HKCU\Software\SmartbarBackup] =>Hijacker.SmartBar [HKCU\Software\SmartbarLog] =>Hijacker.SmartBar [HKCU\Software\Smartbar] =>Hijacker.SmartBar [HKCU\Software\SupraSavings] =>PUP.SupraSavings [HKCU\Software\SweetIM] =>PUP.SweetIM [HKCU\Software\V9] => PUP.V9Software [HKCU\Software\WNLT] =>Adware.IncrediBar [HKLM\Software\IB Updater] =>Adware.InstallBrain [HKLM\Software\LevelQualityWatcher] =>PUP.LevelQualityWatcher [HKLM\Software\SweetIM] =>PUP.SweetIM [HKLM\Software\Tarma Installer] =>PUP.Tarma [HKLM\Software\WNLT] =>Adware.IncrediBar [HKLM\Software\Wow6432Node\Babylon] =>PUP.Babylon [HKLM\Software\Wow6432Node\Boxore] =>Adware.Boxore [HKLM\Software\Wow6432Node\DataMngr] =>PUP.Datamngr [HKLM\Software\Wow6432Node\DealPlyLive] =>PUP.DealPly [HKLM\Software\Wow6432Node\IB Updater] =>Adware.InstallBrain [HKLM\Software\Wow6432Node\Iminent] =>Adware.IMBooster [HKLM\Software\Wow6432Node\SweetIM] =>PUP.SweetIM [HKLM\Software\Wow6432Node\Tiger Savings] =>PUP.SpecialSavings [HKLM\Software\Wow6432Node\V9] => PUP.V9Software [HKLM\Software\Wow6432Node\VBMZ] =>PUP.Duuqu [HKLM\Software\Wow6432Node\deskSvc] => Infection PUP (Hijacker.22Find) [HKLM\Software\Wow6432Node\eSafeSecControl] =>PUP.eSafeSecurity [HKLM\Software\Wow6432Node\omigaplusSvc] =>Hijacker.OmigaPlus O43 - CFD: 21/01/2013 - 15:26:54 - [] ----D C:\Program Files (x86)\Boxore =>Adware.Boxore O43 - CFD: 25/10/2013 - 09:31:13 - [] ----D C:\Program Files (x86)\DealPly =>PUP.DealPly O43 - CFD: 25/10/2013 - 10:14:18 - [] ----D C:\Program Files (x86)\DealPlyLive =>PUP.DealPly O43 - CFD: 14/09/2013 - 13:41:45 - [] ----D C:\Program Files (x86)\Desk 365 =>Hijacker.22Find O43 - CFD: 23/01/2013 - 16:43:58 - [] ----D C:\Program Files (x86)\Iminent =>Adware.IMBooster O43 - CFD: 11/04/2014 - 14:51:06 - [0] ----D C:\Program Files (x86)\LyricsFolder =>Adware.AddLyrics O43 - CFD: 28/04/2014 - 12:55:20 - [] ----D C:\Program Files (x86)\LyricsFolder Corp =>Adware.AddLyrics O43 - CFD: 25/10/2013 - 09:28:02 - [] ----D C:\Program Files (x86)\Omiga Plus =>Hijacker.OmigaPlus O43 - CFD: 10/05/2014 - 08:31:54 - [] ----D C:\Program Files (x86)\Services-x87 => Adware.Pricora O43 - CFD: 28/04/2014 - 08:20:56 - [] ----D C:\Program Files (x86)\SupraSavings =>PUP.SupraSavings O43 - CFD: 03/09/2013 - 07:35:02 - [] ----D C:\Program Files (x86)\Common Files\337 =>Hijacker.22Find O43 - CFD: 25/05/2013 - 16:16:01 - [0] ----D C:\ProgramData\Babylon =>PUP.Babylon O43 - CFD: 20/06/2013 - 20:10:01 - [] ----D C:\ProgramData\BrowserDefender =>Hijacker.Eazel O43 - CFD: 20/06/2013 - 20:09:30 - [] ----D C:\ProgramData\DealPlyLive =>PUP.DealPly O43 - CFD: 21/07/2013 - 14:05:42 - [] ----D C:\ProgramData\eSafe =>PUP.eSafeSecurity O43 - CFD: 25/10/2013 - 09:34:29 - [] ----D C:\ProgramData\Tarma Installer =>PUP.Tarma O43 - CFD: 25/01/2013 - 21:23:25 - [] ----D C:\ProgramData\Trymedia =>Adware.Trymedia O43 - CFD: 14/09/2013 - 13:42:14 - [] ----D C:\Users\andree\AppData\Roaming\337 =>Hijacker.22Find O43 - CFD: 25/05/2013 - 16:16:01 - [] ----D C:\Users\andree\AppData\Roaming\Babylon =>PUP.Babylon O43 - CFD: 12/02/2013 - 15:50:55 - [] ----D C:\Users\andree\AppData\Roaming\DealPly =>PUP.DealPly O43 - CFD: 03/09/2013 - 07:34:39 - [] ----D C:\Users\andree\AppData\Roaming\Desk 365 =>Hijacker.22Find O43 - CFD: 20/06/2013 - 20:28:42 - [] ----D C:\Users\andree\AppData\Roaming\eIntaller => PUP.eSafeSecurity O43 - CFD: 28/04/2014 - 08:19:20 - [] ----D C:\Users\andree\AppData\Roaming\MySearchDial =>Adware.MyWebSearch O43 - CFD: 14/09/2013 - 13:50:00 - [] ----D C:\Users\andree\AppData\Roaming\Omiga Plus =>Hijacker.OmigaPlus O43 - CFD: 20/06/2013 - 20:09:30 - [] ----D C:\Users\andree\AppData\Local\DealPlyLive =>PUP.DealPly O43 - CFD: 30/05/2013 - 20:01:53 - [] ----D C:\Users\andree\AppData\Local\Lollipop =>Adware.Lollipop O43 - CFD: 13/05/2013 - 11:54:44 - [] ----D C:\Users\andree\AppData\Local\Smartbar =>Hijacker.SmartBar O43 - CFD: 20/06/2013 - 20:10:32 - [] ----D C:\Users\andree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender =>Hijacker.Eazel O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com =>Hijacker.Qvo6 O69 - SBI: SearchScopes [HKCU] {006ee092-9658-4fd6-bd8e-a21a348e59f5} - (Web Search) - http://feed.snap.do =>Hijacker.SmartBar O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} - (Search the web) - http://www.searchgol.com =>Adware.IMBooster O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} - (qvo6) - http://search.qvo6.com =>Hijacker.Qvo6 O69 - SBI: SearchScopes [HKCU] {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} - (MyStart Search) - http://mystart.incredibar.com =>Adware.IncrediBar O69 - SBI: SearchScopes [HKCU] {EAE59C1D-C131-4CFE-BB21-E7174E68CCA5} [DefaultScope] - (Mysearchdial) - http://start.mysearchdial.com =>Adware.MyWebSearch O90 - PUC: "8B501B6E56F182443979D1DFA8309BD4" . (.SupraSavings.) -- c:\Windows\Installer\{E6B105B8-1F65-4428-9397-1DFD8A03B94D}\icon64.ico =>PUP.SupraSavings O90 - PUC: "9FEB8FB96CD4CF54A95AB4311193C2DA" . (.Boxore Client.) -- C:\Windows\Installer\{9BF8BEF9-4DC6-45FC-9AA5-4B1311392CAD}\boxore.ico =>Adware.Boxore [MD5.D12E504B9C195A84A264A79388B55A88] [WIS][13/05/2013] (.Linkury Inc. - QuickShare Widget.) -- C:\Windows\Installer\130f1.msi [8495104] =>PUP.QuickShare [MD5.8AB6144FB5409A1A9277C54051EEEDC8] [WIS][17/01/2013] (.Boxore OU - Boxore Client Installer.) -- C:\Windows\Installer\1e4a96.msi [1511424] =>Adware.Boxore [MD5.B67811645C5A3B8E4E4B1A1DB1EE271C] [WIS][21/01/2013] (.Boxore OU. - Software Update Helper.) -- C:\Windows\Installer\1e4aa0.msi [45056] =>Adware.Boxore [MD5.9D0767859EE938C0C4FAC30693109843] [WIS][28/04/2014] (.SupraSavings - SupraSavings.) -- C:\Windows\Installer\45b7e.msi [3162112] =>PUP.SupraSavings HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32 =>PUP.MyPCBackup HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS =>PUP.MyPCBackup HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\boxore_RASAPI32 =>Adware.Boxore HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\boxore_RASMANCS =>Adware.Boxore HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\IminentSetup_RASAPI32 =>Adware.IMBooster HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\IminentSetup_RASMANCS =>Adware.IMBooster HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Iminent_RASAPI32 =>Adware.IMBooster HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Iminent_RASMANCS =>Adware.IMBooster HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\IncredibarToolbar_RASAPI32 =>Adware.IncrediBar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\IncredibarToolbar_RASMANCS =>Adware.IncrediBar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\incredibar_install_RASAPI32 =>Adware.IncrediBar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\incredibar_install_RASMANCS =>Adware.IncrediBar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\QuickShare_RASAPI32 =>PUP.QuickShare HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\QuickShare_RASMANCS =>PUP.QuickShare HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SmartbarExeInstaller_RASAPI32 =>Hijacker.SmartBar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SmartbarExeInstaller_RASMANCS =>Hijacker.SmartBar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\vbmz6_RASAPI32 =>PUP.Duuqu HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\vbmz6_RASMANCS =>PUP.Duuqu HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\VisualBeeSilent_RASAPI32 =>Adware.VisualBeeToolbar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\VisualBeeSilent_RASMANCS =>Adware.VisualBeeToolbar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WajamUpdater_RASAPI32 =>PUP.Wajam HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\WajamUpdater_RASMANCS =>PUP.Wajam HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\yontoo-c2-0CE8_RASAPI32 =>Adware.Yontoo HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\yontoo-c2-0CE8_RASMANCS =>Adware.Yontoo HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\YontooDesktop_RASAPI32 =>Adware.Yontoo HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\YontooDesktop_RASMANCS =>Adware.Yontoo [HKCR\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] (QuickShare WidgetEngine) =>PUP.QuickShare [HKCR\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}] (IB Updater) =>Adware.InstallBrain [HKCR\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}] (QuickShare Widget) =>PUP.QuickShare SS - | Auto 21/01/2013 139576 | (supdate) . (.Boxore OU..) - C:\Program Files (x86)\Software\Update\SoftwareUpdate.exe =>Adware.Boxore SR - | Auto 04/10/2012 188760 | (IB Updater) . (...) - C:\Program Files\IB Updater\ExtensionUpdaterService.exe =>Adware.InstallBrain SR - | Auto 07/04/2014 2276144 | (IBUpdaterService) . (...) - C:\Windows\System32\dmwu.exe =>Adware.InstallBrain SR - | Auto 11/04/2014 143360 | (LyricsFolder) . (...) - C:\Program Files (x86)\LyricsFolder Corp\LyricsFolder158.exe =>Adware.AddLyrics SR - | Auto 28/04/2014 706560 | (vxlsnyaiet64) . (...) - C:\Program Files\003\vxlsnyaiet64.exe =>PUP.AdPeak [HKLM\Software\Google\Chrome\Extensions\afjegdojkkoghnbiollpogeeimocanmk] =>PUP.SupraSavings^ [HKLM\Software\Google\Chrome\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl] =>PUP.QuickShare^ [HKLM\Software\Google\Chrome\Extensions\lmgddjncmooacfihfmikfohkldcjjgml] =>Adware.AddLyrics^ [HKLM\Software\Google\Chrome\Extensions\pbpohikckhbcljgombipcdoinkaedlfa] =>Spyware.SmartDisplay^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10AD2C61-0898-4348-8600-14A342F22AC3}] =>PUP.SupraSavings^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>PUP.QuickShare^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087}] =>Adware.InstallBrain^ [HKLM\SYSTEM\CurrentControlSet\Services\IB Updater] =>Adware.InstallBrain^ [HKLM\SYSTEM\CurrentControlSet\Services\IBUpdaterService] =>Adware.InstallBrain^ [HKLM\SYSTEM\CurrentControlSet\Services\LyricsFolder] =>Adware.AddLyrics^ [HKLM\SYSTEM\CurrentControlSet\Services\supdate) (supdate] =>Adware.Boxore^ [HKLM\SYSTEM\CurrentControlSet\Services\vxlsnyaiet64] =>PUP.AdPeak^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9BF8BEF9-4DC6-45FC-9AA5-4B1311392CAD}] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}] =>Hijacker.Eazel^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1] =>Adware.InstallBrain^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WNLT] =>Adware.InstallBrain^ [HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\lollipop] =>Adware.Lollipop^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ad7f065d-88a6-4783-ab47-94da753f83eb] =>Adware.AddLyrics^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AF860F85-54A3-4A28-879B-BF9E6E325776}] =>PUP.QuickShare^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E6B105B8-1F65-4428-9397-1DFD8A03B94D}] =>PUP.SupraSavings^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\suprasavings] =>PUP.SupraSavings^ [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{006E6A46-8D55-4F10-BBA8-2C9653B4278B}] =>Adware.Boxore [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}] =>Hijacker.SmartBar [HKLM\Software\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}] =>Adware.IMBooster [HKLM\Software\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}] =>Adware.IMBooster [HKLM\Software\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}] =>Adware.IMBooster [HKLM\Software\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}] =>Adware.IMBooster [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}] =>PUP.Babylon [HKLM\Software\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}] =>Adware.Yontoo [HKLM\Software\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}] =>Adware.Yontoo [HKLM\Software\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}] =>PUP.RewardsArcade [HKLM\Software\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}] =>PUP.RewardsArcade [HKLM\Software\Classes\AppID\{32451DFC-C23B-4E12-866C-FC7982238504}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{32451DFC-C23B-4E12-866C-FC7982238504}] =>PUP.Babylon [HKLM\Software\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}] =>PUP.RewardsArcade [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403a-B9D2-65C292C39087}] =>Adware.IncrediBar [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403a-B9D2-65C292C39087}] =>Adware.IncrediBar [HKLM\Software\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}] =>Adware.IncrediBar [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}] =>Adware.IncrediBar [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software [HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software [HKLM\Software\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}] =>PUP.RewardsArcade [HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\omigaplussvc] =>Hijacker.OmigaPlus [HKLM\Software\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}] =>PUP.RewardsArcade [HKLM\Software\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}] =>Hijacker.SmartBar [HKLM\Software\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}] =>Adware.Agent [HKLM\Software\Wow6432Node\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}] =>Adware.Agent [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}] =>Adware.SocialSkinz [HKLM\Software\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}] =>Adware.IMBooster [HKLM\Software\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}] =>Hijacker.SmartBar [HKLM\Software\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}] =>Hijacker.SmartBar [HKLM\Software\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}] =>Hijacker.SmartBar [HKLM\Software\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{736EF78E-5A04-46F9-893E-EDEC6EA5DF45}] =>Adware.Agent [HKLM\Software\Wow6432Node\Classes\Interface\{7A1BCE27-099C-4628-B63A-AEC00C6376B3}] =>Adware.Agent [HKLM\Software\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}] =>PUP.RewardsArcade [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ae07101b-46d4-4a98-af68-0333ea26e113}] =>Adware.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ae07101b-46d4-4a98-af68-0333ea26e113}] =>Adware.Agent [HKLM\Software\Classes\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}] =>Adware.Agent [HKLM\Software\Wow6432Node\Classes\Interface\{AF3AFF7C-B9E9-48DD-9002-212B6DEAAC02}] =>Adware.Agent [HKLM\Software\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}] =>PUP.RewardsArcade [HKLM\Software\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}] =>Hijacker.SmartBar [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}] =>Adware.IncrediBar [HKLM\Software\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}] =>PUP.RewardsArcade [HKLM\Software\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{DBE82879-914A-422F-BAE9-2ECC80BE536F}] =>Adware.Agent [HKLM\Software\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}] =>PUP.RewardsArcade [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}] =>Adware.Yontoo [HKLM\Software\Wow6432Node\Classes\Interface\{E12D7149-73EF-45E4-A1E9-99FD7DAE62D3}] =>Adware.Agent [HKLM\Software\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}] =>Adware.IMBooster [HKLM\Software\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{F2B184F1-547C-4EE9-BFC4-AC489C7077D9}] =>Adware.Agent [HKLM\Software\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}] =>PUP.RewardsArcade [HKLM\Software\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}] =>PUP.RewardsArcade [HKLM\Software\Classes\AppID\esrv.EXE] =>PUP.Babylon [HKLM\Software\Classes\Software.OneClickCtrl.8] =>Adware.Agent [HKLM\Software\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd] =>Adware.IncrediBar [HKLM\Software\Wow6432Node\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd] =>Adware.IncrediBar [HKLM\Software\Wow6432Node\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj] =>PUP.SweetIM [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\1C875DDE39636004CA8CDAEC335B4160] =>Adware.PredictAd [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\BA086F2D38A8E1A47912955A68B3AD24] =>Adware.PredictAd [HKLM\Software\Wow6432Node\Boxore] =>Adware.Boxore [HKCU\Software\DataMngr] =>Adware.Bandoo [HKLM\Software\Wow6432Node\DataMngr] =>Adware.Bandoo [HKCU\Software\lollipop] =>Adware.Lollipop [HKCU\Software\Iminent] =>Adware.IMBooster [HKLM\Software\Wow6432Node\Iminent] =>Adware.IMBooster [HKCU\Software\SmartbarBackup] =>Hijacker.SmartBar [HKCU\Software\SmartbarLog] =>Hijacker.SmartBar [HKCU\Software\SweetIM] =>PUP.SweetIM [HKLM\Software\SweetIM] =>PUP.SweetIM [HKLM\Software\Wow6432Node\SweetIM] =>PUP.SweetIM [HKLM\Software\Tarma Installer] =>PUP.Tarma [HKCU\Software\WNLT] =>Adware.IncrediBar [HKLM\Software\WNLT] =>Adware.IncrediBar [HKLM\Software\Wow6432Node\Microsoft\Tracing\Iminent_RASAPI32] =>Adware.Bandoo [HKLM\Software\Wow6432Node\Microsoft\Tracing\Iminent_RASMANCS] =>Adware.Bandoo [HKLM\Software\Wow6432Node\Microsoft\Tracing\incredibar_install_RASAPI32] =>Adware.IncrediBar [HKLM\Software\Wow6432Node\Microsoft\Tracing\incredibar_install_RASMANCS] =>Adware.IncrediBar [HKLM\Software\Wow6432Node\Microsoft\Tracing\IncredibarToolbar_RASAPI32] =>Adware.IncrediBar [HKLM\Software\Wow6432Node\Microsoft\Tracing\IncredibarToolbar_RASMANCS] =>Adware.IncrediBar [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WNLT] =>Adware.IncrediBar [HKLM\Software\Classes\Prod.cap] =>PUP.Babylon [HKLM\Software\Classes\Installer\Features\64A6E60055D801F4BB8AC269354B72B8] =>Adware.Boxore [HKLM\Software\Classes\Installer\Products\64A6E60055D801F4BB8AC269354B72B8] =>Adware.Boxore [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\64A6E60055D801F4BB8AC269354B72B8] =>Adware.Boxore [HKLM\Software\Wow6432Node\Classes\Installer\Features\64A6E60055D801F4BB8AC269354B72B8] =>Adware.Boxore [HKLM\Software\Wow6432Node\Classes\Installer\Products\64A6E60055D801F4BB8AC269354B72B8] =>Adware.Boxore [HKLM\Software\Classes\Installer\Features\9FEB8FB96CD4CF54A95AB4311193C2DA] =>Adware.Boxore [HKLM\Software\Classes\Installer\Products\9FEB8FB96CD4CF54A95AB4311193C2DA] =>Adware.Boxore [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9FEB8FB96CD4CF54A95AB4311193C2DA] =>Adware.Boxore [HKLM\Software\Wow6432Node\Classes\Installer\Features\9FEB8FB96CD4CF54A95AB4311193C2DA] =>Adware.Boxore [HKLM\Software\Wow6432Node\Classes\Installer\Products\9FEB8FB96CD4CF54A95AB4311193C2DA] =>Adware.Boxore [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9BF8BEF9-4DC6-45FC-9AA5-4B1311392CAD}] =>Adware.Boxore [HKCU\Software\InstallCore] =>Adware.InstallCore [HKLM\SYSTEM\CurrentControlSet\Services\supdate] =>Adware.Boxore [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375] =>PUP.Tarma [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5] =>PUP.Tarma [HKLM\Software\Wow6432Node\Microsoft\Tracing\QuickShare_RASAPI32] =>PUP.QuickShare [HKLM\Software\Wow6432Node\Microsoft\Tracing\QuickShare_RASMANCS] =>PUP.QuickShare [HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\desksvc] =>Hijacker.22find [HKLM\Software\Wow6432Node\qvo6Software] =>Hijacker.Qvo6 [HKLM\Software\Wow6432Node\eSafeSecControl] =>PUP.eSafeSecurity [HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider [HKCU\Software\InstalledBrowserExtensions\] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Microsoft\Tracing\boxore_RASAPI32] =>Adware.Boxore [HKLM\Software\Wow6432Node\Microsoft\Tracing\boxore_RASMANCS] =>Adware.Boxore [HKLM\Software\Wow6432Node\Google\Chrome\Extensions\pbpohikckhbcljgombipcdoinkaedlfa] =>Spyware.SmartDisplay [HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\eSafeSvc] =>PUP.eSafeSecurity [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF252F2C-0F44-47A7-89B9-3AFF5A17DEB2}] =>Adware.AddLyrics [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AF252F2C-0F44-47A7-89B9-3AFF5A17DEB2}] =>Adware.AddLyrics [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF252F2C-0F44-47A7-89B9-3AFF5A17DEB2}] =>Adware.AddLyrics [HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc] =>PUP.eSafeSecurity [HKLM\Software\Wow6432Node\omigaplusSvc] =>Hijacker.OmigaPlus [HKCU\Software\InstalledBrowserExtensions] =>PUP.CrossRider [HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro [HKLM\Software\Wow6432Node\{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro [HKLM\Software\Classes\CrossriderApp0034805.BHO] =>PUP.CrossRider [HKLM\Software\Classes\esrv.mysearchdialESrvc] =>Adware.MyWebSearch [HKLM\Software\Classes\esrv.mysearchdialESrvc.1] =>Adware.MyWebSearch [HKLM\Software\Wow6432Node\Classes\CrossriderApp0034805.BHO] =>PUP.CrossRider [HKLM\Software\Wow6432Node\Classes\esrv.mysearchdialESrvc] =>Adware.MyWebSearch [HKLM\Software\Wow6432Node\Classes\esrv.mysearchdialESrvc.1] =>Adware.MyWebSearch [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311481105}] =>PUP.CrossRider [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\38D5CDD0A851B3940A43CC50ABBA251C] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BA71D41F6CC0B6247B05D473850A8AEA] =>Adware.Boxore^ [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] =>Adware.Boxore^ [HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{ae07101b-46d4-4a98-af68-0333ea26e113} =>PUP.QuickShare^ [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:Browser Infrastructure Helper =>PUP.QuickShare^ [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:Boxore Client =>Adware.Boxore^ C:\Users\andree\AppData\Local\Google\Chrome\User Data\Default\Extensions\afjegdojkkoghnbiollpogeeimocanmk =>PUP.SupraSavings^ C:\Users\andree\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl =>PUP.QuickShare^ C:\Users\andree\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmgddjncmooacfihfmikfohkldcjjgml =>Adware.AddLyrics^ C:\Users\andree\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbpohikckhbcljgombipcdoinkaedlfa =>Spyware.SmartDisplay^ C:\Program Files (x86)\Boxore =>Adware.Boxore^ C:\Program Files (x86)\DealPly =>PUP.DealPly^ C:\Program Files (x86)\DealPlyLive =>PUP.DealPly^ C:\Program Files (x86)\Desk 365 =>Hijacker.22Find^ C:\Program Files (x86)\Iminent =>Adware.IMBooster^ C:\Program Files (x86)\LyricsFolder =>Adware.AddLyrics^ C:\Program Files (x86)\LyricsFolder Corp =>Adware.AddLyrics^ C:\Program Files (x86)\Omiga Plus =>Hijacker.OmigaPlus^ C:\Program Files (x86)\SupraSavings =>PUP.SupraSavings^ C:\Program Files (x86)\Common Files\337 =>Hijacker.22Find^ C:\ProgramData\Babylon =>PUP.Babylon^ C:\ProgramData\BrowserDefender =>Hijacker.Eazel^ C:\ProgramData\DealPlyLive =>PUP.DealPly^ C:\ProgramData\eSafe =>PUP.eSafeSecurity^ C:\ProgramData\Tarma Installer =>PUP.Tarma^ C:\ProgramData\Trymedia =>Adware.Trymedia^ C:\Users\andree\AppData\Roaming\337 =>Hijacker.22Find^ C:\Users\andree\AppData\Roaming\Babylon =>PUP.Babylon^ C:\Users\andree\AppData\Roaming\DealPly =>PUP.DealPly^ C:\Users\andree\AppData\Roaming\Desk 365 =>Hijacker.22Find^ C:\Users\andree\AppData\Roaming\MySearchDial =>Adware.MyWebSearch^ C:\Users\andree\AppData\Roaming\Omiga Plus =>Hijacker.OmigaPlus^ C:\Users\andree\AppData\Local\DealPlyLive =>PUP.DealPly^ C:\Users\andree\AppData\Local\Lollipop =>Adware.Lollipop^ C:\Users\andree\AppData\Local\Smartbar =>Hijacker.SmartBar^ C:\Users\andree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender =>Hijacker.Eazel^ C:\Program Files (x86)\Software =>Adware.Boxore C:\Program Files (x86)\HappyLyrics =>Adware.AddLyrics C:\Program Files (x86)\Services-x87 =>Adware.Pricora C:\Users\andree\AppData\Roaming\eIntaller =>PUP.eSafeSecurity C:\Users\andree\AppData\Local\Software =>Adware.Boxore C:\Users\andree\AppData\LocalLow\Incredibar.com =>Adware.IncrediBar C:\Users\andree\AppData\LocalLow\Smartbar =>Hijacker.SmartBar C:\Program Files (x86)\LyricsFolder Corp\LyricsFolder_wd.exe =>Adware.AddLyrics^ C:\Users\andree\AppData\Local\Smartbar\Application\QuickShare.exe =>PUP.QuickShare^ C:\Program Files (x86)\Boxore\BoxoreClient\boxore.exe =>Adware.Boxore^ C:\Program Files\IB Updater\ExtensionUpdaterService.exe =>Adware.InstallBrain^ C:\Program Files (x86)\LyricsFolder Corp\LyricsFolder158.exe =>Adware.AddLyrics^ C:\Users\andree\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.exe =>PUP.DealPly^ C:\Program Files (x86)\LyricsFolder Corp\LrcsF.exe =>Adware.AddLyrics^ C:\Program Files (x86)\Software\Update\SoftwareUpdate.exe =>Adware.Boxore^ c:\users\andree\appdata\local\lollipop\lollipop.bat =>Adware.Lollipop^ C:\Windows\Tasks\Dealply.job =>PUP.DealPly^ C:\Windows\System32\Tasks\Dealply =>PUP.DealPly^ C:\Windows\Tasks\LyricsFolder Update.job =>Adware.AddLyrics^ C:\Windows\System32\Tasks\LyricsFolder Update =>Adware.AddLyrics^ C:\Windows\Tasks\LyricsFolder_wd.job =>Adware.AddLyrics^ C:\Windows\System32\Tasks\LyricsFolder_wd =>Adware.AddLyrics^ C:\Windows\Tasks\MySearchDial.job =>Adware.MyWebSearch^ C:\Windows\System32\Tasks\MySearchDial =>Adware.MyWebSearch^ C:\Windows\Tasks\SoftwareUpdateTaskMachineCore.job =>Adware.Boxore^ C:\Windows\System32\Tasks\SoftwareUpdateTaskMachineCore =>Adware.Boxore^ C:\Windows\Tasks\SoftwareUpdateTaskMachineUA.job =>Adware.Boxore^ C:\Windows\System32\Tasks\SoftwareUpdateTaskMachineUA =>Adware.Boxore^ [HKCU\Software\BabSolution] =>Hijacker.BabSolution^ [HKCU\Software\DataMngr_Toolbar] =>PUP.Datamngr^ [HKCU\Software\DealPlyLive] =>PUP.DealPly^ [HKCU\Software\Smartbar] =>Hijacker.SmartBar^ [HKCU\Software\SupraSavings] =>PUP.SupraSavings^ [HKLM\Software\IB Updater] =>Adware.InstallBrain^ [HKLM\Software\LevelQualityWatcher] =>PUP.LevelQualityWatcher^ [HKLM\Software\Wow6432Node\Babylon] =>PUP.Babylon^ [HKLM\Software\Wow6432Node\DealPlyLive] =>PUP.DealPly^ [HKLM\Software\Wow6432Node\IB Updater] =>Adware.InstallBrain^ [HKLM\Software\Wow6432Node\Tiger Savings] =>PUP.SpecialSavings^ C:\Windows\Installer\130f1.msi =>PUP.QuickShare^ C:\Windows\Installer\1e4a96.msi =>Adware.Boxore^ C:\Windows\Installer\1e4aa0.msi =>Adware.Boxore^ C:\Windows\Installer\45b7e.msi =>PUP.SupraSavings^ [HKCR\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] (QuickShare WidgetEngine) =>PUP.QuickShare^ [HKCR\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}] (IB Updater) =>Adware.InstallBrain^ [HKCR\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}] (QuickShare Widget) =>PUP.QuickShare^ C:\Users\andree\AppData\Local\Temp\uninst1.exe =>PUP.Babylon [HKLM\Software\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}] =>Toolbar.Expresso [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>Toolbar.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>Toolbar.Agent [HKLM\Software\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{42AEFAF9-09D6-4185-87AE-DEDF6E955CB4}] =>Toolbar.Conduit [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{42AEFAF9-09D6-4185-87AE-DEDF6E955CB4}] =>Toolbar.Conduit [HKLM\Software\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}] =>Toolbar.Expresso [HKLM\Software\Wow6432Node\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}] =>Toolbar.Expresso [HKLM\Software\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}] =>Toolbar.Agent [HKLM\Software\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}] =>Toolbar.Wajam [HKLM\Software\Wow6432Node\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}] =>Toolbar.Wajam [HKLM\Software\Classes\AppID\Extension.DLL] =>Toolbar.Expresso [HKLM\Software\Classes\Extension.ExtensionHelperObject] =>Toolbar.Expresso [HKLM\Software\Classes\Extension.ExtensionHelperObject.1] =>Toolbar.Expresso [HKLM\Software\Wow6432Node\VBMZ] =>Toolbar.Conduit [HKLM\Software\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}] =>Toolbar.DeltaSearch [HKLM\Software\Wow6432Node\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}] =>Toolbar.DeltaSearch C:\Users\andree\AppData\LocalLow\Toolbar4 =>Toolbar.Conduit C:\Users\andree\AppData\Local\Temp\spidentifierimpl.exe =>Toolbar.Conduit ShortcutFix FirewallRaz Emptytemp SysRestore