ÿþ <?xml version="1.0" encoding="UTF-16"?> @namespace html url(http://www.w3.org/1999/xhtml); :root { font:small Verdana; font-weight: bold; padding: 2em; padding-left:4em; } * { display: block; padding-left: 2em; } html|style { display: none; } html|span, html|a { display: inline; padding: 0; font-weight: normal; text-decoration: none; } html|span.block { display: block; } *[html|hidden], span.block[html|hidden] { display: none; } .expand { display: block; } .expand:before { content: '+'; color: red; position: absolute; left: -1em; } .collapse { display: block; } .collapse:before { content: '-'; color: red; position: absolute; left:-1em; } <mbam-log> <header> <date>2016/10/01 09:14:38 +0200</date> <logfile>mbam-log-2016-10-01 (09-14-34).xml</logfile> <isadmin>yes</isadmin> </header> <engine> <version>2.2.1.1043</version> <malware-database>v2016.10.01.02</malware-database> <rootkit-database>v2016.09.26.02</rootkit-database> <license>free</license> <file-protection>disabled</file-protection> <web-protection>disabled</web-protection> <self-protection>disabled</self-protection> </engine> <system> <hostname>DOMINIQUEVEY-PC</hostname> <ip>192.168.0.14</ip> <osversion>Windows 10</osversion> <arch>x64</arch> <username>Dominique VEY</username> <filesys>NTFS</filesys> </system> <summary> <type>threat</type> <result>completed</result> <objects>515959</objects> <time>2520</time> <processes>0</processes> <modules>0</modules> <keys>23</keys> <values>13</values> <datas>5</datas> <folders>69</folders> <files>135</files> <sectors>0</sectors> </summary> <options> <memory>enabled</memory> <startup>enabled</startup> <filesystem>enabled</filesystem> <archives>enabled</archives> <rootkits>disabled</rootkits> <deeprootkit>disabled</deeprootkit> <heuristics>enabled</heuristics> <pup>enabled</pup> <pum>enabled</pum> </options> <items> <key> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1004\SOFTWARE\MICROSOFT\INTERNETw EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}</path> <vendor>PUP.Optional.SnapDo</vendor> <action/> <hash>f313e7ad009aa78fcb7a4b43d42ece32</hash> </key> <key> <path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{08AE5E13-70CC-4FBB-AD00-EF4B90A44451}</path> <vendor>PUP.Optional.Bandoo.AppFlsh</vendor> <action/> <hash>90765d3756444ee8c47b0492ad55cd33</hash> </key> <key> <path>HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pilplloabdedfmialnfchjomjmpjcoej</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>5babe1b3831786b0deac4caeb152946c</hash> </key> <key> <path>HKLM\SOFTWARE\MICROSOFT\TRACING\winwb_RASAPI32</path> <vendor>PUP.Optional.WebBar</vendor> <action/> <hash>23e3c8ccadedba7cbfcd19e61ee5768a</hash> </key> <key> <path>HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\OpenCandyHelperRunAsStandardUser5413020B00114BDE8ABF1818F3FF6E32</path> <vendor>PUP.Optional.OpenCandy</vendor> <action/> <hash>bc4ab8dcff9b2a0c32193c72fe05e31d</hash> </key> <key> <path>HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\OpenCandyHelperRunOnce46A6E4AEFCDA48FD9FDA0AD4437E19FF</path> <vendor>PUP.Optional.OpenCandy</vendor> <action/> <hash>d3331c784357162058f3733bf70c33cd</hash> </key> <key> <path>HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\pilplloabdedfmialnfchjomjmpjcoej</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>0afc2b69b4e668ce5e2c6496c93a867a</hash> </key> <key> <path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\WinZipMalwareProtector_RASAPI32</path> <vendor>PUP.Optional.WinZipMalwareProtector</vendor> <action/> <hash>2adc5b395c3e72c48f607173699a4fb1</hash> </key> <key> <path>HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WinZip Malware Protector</path> <vendor>PUP.Optional.WinZipMalwareProtector</vendor> <action/> <hash>fa0c90048d0d7eb8ed05eff57291b24e</hash> </key> <key> <path>HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\FP1.1</path> <vendor>PUP.Optional.Feven</vendor> <action/> <hash>27df078deeac04329092b7eb51b2eb15</hash> </key> <key> <path>HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\Fre_Ven_s Pro 23</path> <vendor>PUP.Optional.Feven</vendor> <action/> <hash>6f971b795941e1552403237fb64d22de</hash> </key> <key> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1001\SOFTWARE\csastats</path> <vendor>PUP.Optional.InstallCore</vendor> <action/> <hash>32d4bbd9bedc37ffdda8a55560a3cf31</hash> </key> <key> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1001\SOFTWARE\GoldenGate</path> <vendor>PUP.Optional.Gameo</vendor> <action/> <hash>52b4593befab4aec3007439029d9cb35</hash> </key> <key> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1001\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pilplloabdedfmialnfchjomjmpjcoej</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>b353eba9465460d625834487a35fc33d</hash> </key> <key> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1001\SOFTWARE\MICROSOFT\INTERNET1 EXPLORER\DOMSTORAGE\piroga.space</path> <vendor>PUP.Optional.InstallMonster</vendor> <action/> <hash>8f77b4e00a906ec857e77f4f9c68e41c</hash> </key> <key> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1001\SOFTWARE\MICROSOFT\INTERNET1 EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{53BF6D6C-EF52-4BD5-A8AD-FDB9F8C245A0}</path> <vendor>PUP.Optional.CrossRider</vendor> <action/> <hash>24e2d4c04a50af87c62cc7d76a9932ce</hash> </key> <key> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1001\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\gaiilaahiahdejapggenmdmafpmbipje</path> <vendor>PUP.Optional.DealPly</vendor> <action/> <hash>699d54400f8b8da94d2b2b74eb1823dd</hash> </key> <key> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1004\SOFTWARE\Wajam</path> <vendor>PUP.Optional.Wajam</vendor> <action/> <hash>5da9ccc8b9e1da5c09f1c6f4f50ea35d</hash> </key> <key> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1004\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}</path> <vendor>PUP.Optional.SuperOptimizer</vendor> <action/> <hash>9e688e069dfd270fc5502e89e81bc13f</hash> </key> <key> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1004\SOFTWARE\SYSTEM HEALER</path> <vendor>PUP.Optional.SystemHealer</vendor> <action/> <hash>26e0395b41595fd7efdd8a50b64d8c74</hash> </key> <key> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-501\SOFTWARE\Datamngr</path> <vendor>PUP.Optional.DataMngr.AppFlsh</vendor> <action/> <hash>33d304908911fc3ad00e00dd32d19a66</hash> </key> <key> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-501\SOFTWARE\APPDATALOW\SOFTWARE\IncrediMail_MediaBar_2</path> <vendor>PUP.Optional.IncrediMediaBar</vendor> <action/> <hash>08fe009483176bcb81f69e40a55d59a7</hash> </key> <key> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-501\SOFTWARE\SYSTEM HEALER</path> <vendor>PUP.Optional.SystemHealer</vendor> <action/> <hash>54b2dfb591099a9cc408fbdfe51ede22</hash> </key> <value> <path>HKLM\SOFTWARE\CLASSES\SDP\SHELL\OPEN\COMMAND</path> <valuename/> <vendor>PUP.Optional.FilesFrog</vendor> <action/> <valuedata>"C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe" /protocol %1</valuedata> <hash>e521d8bc11892d09143f1dd32ad9b14f</hash> </value> <value> <path>HKLM\SOFTWARE\CLASSES\WOW6432NODE\SDP\SHELL\OPEN\COMMAND</path> <valuename/> <vendor>PUP.Optional.FilesFrog</vendor> <action/> <valuedata>"C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe" /protocol %1</valuedata> <hash>f0167a1a4852fc3a2a29945c788bc937</hash> </value> <value> <path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\SDP\SHELL\OPEN\COMMAND</path> <valuename/> <vendor>PUP.Optional.FilesFrog</vendor> <action/> <valuedata>"C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe" /protocol %1</valuedata> <hash>1cea286c4e4cbd79f95a767a36cd9868</hash> </value> <value> <path>HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NLASVC\PARAMETERS\INTERNET\MANUALPROXIES</path> <valuename/> <vendor>Hijack.AutoConfigURL.PrxySvrRST</vendor> <action/> <valuedata>0http://un-blocking.org/wpad.dat?c17ab0bef4bd9cdc68426744d2bb430317456883</valuedata> <hash>7690b7dd6f2bec4a61feae4aa262f10f</hash> </value> <value> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1001\SOFTWARE\MICROSOFT\INTERNET/ EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{53BF6D6C-EF52-4BD5-A8AD-FDB9F8C245A0}</path> <valuename>AppName</valuename> <vendor>PUP.Optional.CrossRider</vendor> <action/> <valuedata>e7bcb6de-d3bb-4e81-b635-9168b3a1d35e-2.exe-buttonutil.exe</valuedata> <hash>24e2d4c04a50af87c62cc7d76a9932ce</hash> </value> <value> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1001\SOFTWARE\MICROSOFT\INTERNETe EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION</path> <valuename>winwb.exe</valuename> <vendor>PUP.Optional.WebBar</vendor> <action/> <valuedata>11000</valuedata> <hash>a363abe90e8c0b2bf2235e9e43c0b947</hash> </value> <value> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNETn SETTINGS</path> <valuename>AutoConfigUrl</valuename> <vendor>Hijack.AutoConfigURL.PrxySvrRST</vendor> <action/> <valuedata>http://un-blocking.org/wpad.dat?c17ab0bef4bd9cdc68426744d2bb430317456883</valuedata> <hash>d432ace8bedc9f9793c4ae4ab54f6a96</hash> </value> <value> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1004\SOFTWARE\SYSTEM HEALER</path> <valuename>HomePage</valuename> <vendor>PUP.Optional.SystemHealer</vendor> <action/> <valuedata>http://systemhealer.com/</valuedata> <hash>26e0395b41595fd7efdd8a50b64d8c74</hash> </value> <value> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1004\SOFTWARE\SYSTEM HEALER</path> <valuename>CartURL</valuename> <vendor>PUP.Optional.SystemHealer</vendor> <action/> <valuedata>http://gen.securedshopgate.com/?t=01&b=35&tid=351002282-IL-318_1C8377A1-3194-40B9-A9AB-BFD118C4DE51&clb=1</valuedata> <hash>a561bdd7bedcfe3881243ac332d16d93</hash> </value> <value> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1004\SOFTWARE\SYSTEM HEALER</path> <valuename>SupportPage</valuename> <vendor>PUP.Optional.SystemHealer</vendor> <action/> <valuedata>http://systemhealer.com/support/#contact</valuedata> <hash>6c9ac0d4b6e44fe76a62f1e983809f61</hash> </value> <value> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-501\SOFTWARE\SYSTEM HEALER</path> <valuename>HomePage</valuename> <vendor>PUP.Optional.SystemHealer</vendor> <action/> <valuedata>http://systemhealer.com/</valuedata> <hash>54b2dfb591099a9cc408fbdfe51ede22</hash> </value> <value> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-501\SOFTWARE\SYSTEM HEALER</path> <valuename>CartURL</valuename> <vendor>PUP.Optional.SystemHealer</vendor> <action/> <valuedata>http://gen.securedshopgate.com/?t=01&b=35&tid=351002282-IL-318_1C8377A1-3194-40B9-A9AB-BFD118C4DE51&clb=1</valuedata> <hash>bb4bc2d2cfcb171f9a0b7588f70ccb35</hash> </value> <value> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-501\SOFTWARE\SYSTEM HEALER</path> <valuename>SupportPage</valuename> <vendor>PUP.Optional.SystemHealer</vendor> <action/> <valuedata>http://systemhealer.com/support/#contact</valuedata> <hash>db2bc8cc0c8e60d6f0dcb723e81bff01</hash> </value> <data> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1004\SOFTWARE\MICROSOFT\INTERNET0 EXPLORER\MAIN</path> <valuename>Search Bar</valuename> <vendor>PUP.Optional.HelperBar</vendor> <action/> <valuedata>http://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK2q0U14moCf-ET1EM4uw4GigvFB13oDdKkPmeiaEounjkyvBmjdrDok9HgOibCTpvjDaljl7BA1AkJ9yBbepxixQN6rmyqJ0vLQEcnPIKyRvBwxYMBu3ayPSZYbIqbpUC8vqkBoq5ueDRvqlieE8WLJSfgdpQFvFgSXC6gmIH8sFfNgGoL1DoXPYPZuyTN7e0cL2bL3buJy95Q,,&q={searchTerms}</valuedata> <baddata>http://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK2q0U14moCf-ET1EM4uw4GigvFB13oDdKkPmeiaEounjkyvBmjdrDok9HgOibCTpvjDaljl7BA1AkJ9yBbepxixQN6rmyqJ0vLQEcnPIKyRvBwxYMBu3ayPSZYbIqbpUC8vqkBoq5ueDRvqlieE8WLJSfgdpQFvFgSXC6gmIH8sFfNgGoL1DoXPYPZuyTN7e0cL2bL3buJy95Q,,&q={searchTerms}</baddata> <gooddata>www.google.com</gooddata> <hash>778fc5cf7228092ddbf0db9c2cd83dc3</hash> </data> <data> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1004\SOFTWARE\MICROSOFT\INTERNET< EXPLORER\MAIN</path> <valuename>First Home Page</valuename> <vendor>PUP.Optional.HelperBar</vendor> <action/> <valuedata>http://go.microsoft.com/fwlink/?LinkID=226786&Mkt=fr-FR&Src=MSE&Tid=0003446E&OHP=about%3Ablank&OSP=http%3A%2F%2Ffeed.helperbar.com%2F%3Fp%3DmKO%5FAwFzXIpYRbkHo3StK2q0U14moCf%2DET1EM4uw4GigvFB13oDdKkPmeiaEounjkyvBmjdrDok9HgOibCTpvjDaljl7BA1AkJ9yBbepxixQN6rmyqJ0vLQEcnPIKyRvBwxYMBu3ayPSZYbIqbpUC8vqkBoq5ueDRvqlieE8WLJSfgdpQFvFgSXC6gmIH8sFfNgGoL1DoXPYPZuyTN7e0cL2bL3buJy95Q%2C%2C%26q%3D%7BsearchTerms%7D</valuedata> <baddata>http://go.microsoft.com/fwlink/?LinkID=226786&Mkt=fr-FR&Src=MSE&Tid=0003446E&OHP=about%3Ablank&OSP=http%3A%2F%2Ffeed.helperbar.com%2F%3Fp%3DmKO%5FAwFzXIpYRbkHo3StK2q0U14moCf%2DET1EM4uw4GigvFB13oDdKkPmeiaEounjkyvBmjdrDok9HgOibCTpvjDaljl7BA1AkJ9yBbepxixQN6rmyqJ0vLQEcnPIKyRvBwxYMBu3ayPSZYbIqbpUC8vqkBoq5ueDRvqlieE8WLJSfgdpQFvFgSXC6gmIH8sFfNgGoL1DoXPYPZuyTN7e0cL2bL3buJy95Q%2C%2C%26q%3D%7BsearchTerms%7D</baddata> <gooddata>www.google.com</gooddata> <hash>3acc2f658515290dae1d482f5aaa47b9</hash> </data> <data> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1004\SOFTWARE\MICROSOFT\INTERNET. EXPLORER\SEARCH</path> <valuename>Default_Search_URL</valuename> <vendor>PUP.Optional.HelperBar</vendor> <action/> <valuedata>http://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK2q0U14moCf-ET1EM4uw4GigvFB13oDdKkPmeiaEounjkyvBmjdrDok9HgOibCTpvjDaljl7BA1AkJ9yBbepxixQN6rmyqJ0vLQEcnPIKyRvBwxYMBu3ayPSZYbIqbpUC8vqkBoq5ueDRvqlieE8WLJSfgdpQFvFgSXC6gmIH8sFfNgGoL1DoXPYPZuyTN7e0cL2bL3buJy95Q,,&q={searchTerms}</valuedata> <baddata>http://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK2q0U14moCf-ET1EM4uw4GigvFB13oDdKkPmeiaEounjkyvBmjdrDok9HgOibCTpvjDaljl7BA1AkJ9yBbepxixQN6rmyqJ0vLQEcnPIKyRvBwxYMBu3ayPSZYbIqbpUC8vqkBoq5ueDRvqlieE8WLJSfgdpQFvFgSXC6gmIH8sFfNgGoL1DoXPYPZuyTN7e0cL2bL3buJy95Q,,&q={searchTerms}</baddata> <gooddata>www.google.com</gooddata> <hash>1aeccec611895dd9418b81f6a163a759</hash> </data> <data> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1004\SOFTWARE\MICROSOFT\INTERNET5 EXPLORER\SEARCH</path> <valuename>SearchAssistant</valuename> <vendor>PUP.Optional.HelperBar</vendor> <action/> <valuedata>http://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK2q0U14moCf-ET1EM4uw4GigvFB13oDdKkPmeiaEounjkyvBmjdrDok9HgOibCTpvjDaljl7BA1AkJ9yBbepxixQN6rmyqJ0vLQEcnPIKyRvBwxYMBu3ayPSZYbIqbpUC8vqkBoq5ueDRvqlieE8WLJSfgdpQFvFgSXC6gmIH8sFfNgGoL1DoXPYPZuyTN7e0cL2bL3buJy95Q,,&q={searchTerms}</valuedata> <baddata>http://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK2q0U14moCf-ET1EM4uw4GigvFB13oDdKkPmeiaEounjkyvBmjdrDok9HgOibCTpvjDaljl7BA1AkJ9yBbepxixQN6rmyqJ0vLQEcnPIKyRvBwxYMBu3ayPSZYbIqbpUC8vqkBoq5ueDRvqlieE8WLJSfgdpQFvFgSXC6gmIH8sFfNgGoL1DoXPYPZuyTN7e0cL2bL3buJy95Q,,&q={searchTerms}</baddata> <gooddata>www.google.com</gooddata> <hash>b6508212267465d1e0ecaacd54b09a66</hash> </data> <data> <path>HKU\S-1-5-21-2950831876-2088724787-3088863540-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL</path> <valuename>Default</valuename> <vendor>PUP.Optional.HelperBar</vendor> <action/> <valuedata>http://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK2q0U14moCf-ET1EM4uw4GigvFB13oDdKkPmeiaEounjkyvBmjdrDok9HgOibCTpvjDaljl7BA1AkJ9yBbepxixQN6rmyqJ0vLQEcnPIKyRvBwxYMBu3ayPSZYbIqbpUC8vqkBoq5ueDRvqlieE8WLJSfgdpQFvFgSXC6gmIH8sFfNgGoL1DoXPYPZuyTN7e0cL2bL3buJy95Q,,&q={searchTerms}</valuedata> <baddata>http://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StK2q0U14moCf-ET1EM4uw4GigvFB13oDdKkPmeiaEounjkyvBmjdrDok9HgOibCTpvjDaljl7BA1AkJ9yBbepxixQN6rmyqJ0vLQEcnPIKyRvBwxYMBu3ayPSZYbIqbpUC8vqkBoq5ueDRvqlieE8WLJSfgdpQFvFgSXC6gmIH8sFfNgGoL1DoXPYPZuyTN7e0cL2bL3buJy95Q,,&q={searchTerms}</baddata> <gooddata>www.google.com</gooddata> <hash>df27efa55149ab8b933a1265a55f6997</hash> </data> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\GoldenGate</path> <vendor>PUP.Optional.Gameo</vendor> <action/> <hash>a75f603428726dc9a2932fa4d929cf31</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\HowToRemove</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\l7nze82d.default-1413910788947\DownSpeedTest_dq</path> <vendor>PUP.Optional.MindSpark</vendor> <action/> <hash>0afcd5bf495124126c841297a55ecf31</hash> </folder> <folder> <path>C:\Windows\System32\config\systemprofile\AppData\Local\WebBar</path> <vendor>PUP.Optional.WebBar</vendor> <action/> <hash>a165bbd96a3093a3b99ef4c7649f5ca4</hash> </folder> <folder> <path>C:\ProgramData\374311380</path> <vendor>Rogue.Multiple</vendor> <action/> <hash>1cea761ed4c602346b918215c9399e62</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}</path> <vendor>PUP.Optional.IncrediMediaBar</vendor> <action/> <hash>c046850ffaa087af9d72bdedd131e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\Chrome</path> <vendor>PUP.Optional.IncrediMediaBar</vendor> <action/> <hash>c046850ffaa087af9d72bdedd131e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\Chrome\CT2724386</path> <vendor>PUP.Optional.IncrediMediaBar</vendor> <action/> <hash>c046850ffaa087af9d72bdedd131e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\Chrome\CT2724386\content</path> <vendor>PUP.Optional.IncrediMediaBar</vendor> <action/> <hash>c046850ffaa087af9d72bdedd131e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\Chrome\CT2724386\content\tb</path> <vendor>PUP.Optional.IncrediMediaBar</vendor> <action/> <hash>c046850ffaa087af9d72bdedd131e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\Chrome\CT2724386\content\tb\al</path> <vendor>PUP.Optional.IncrediMediaBar</vendor> <action/> <hash>c046850ffaa087af9d72bdedd131e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\Chrome\CT2724386\content\tb\al\wa</path> <vendor>PUP.Optional.IncrediMediaBar</vendor> <action/> <hash>c046850ffaa087af9d72bdedd131e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\Chrome\CT2724386\content\tb\al\wa\APPLICATION_BUTTON</path> <vendor>PUP.Optional.IncrediMediaBar</vendor> <action/> <hash>c046850ffaa087af9d72bdedd131e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\components</path> <vendor>PUP.Optional.IncrediMediaBar</vendor> <action/> <hash>c046850ffaa087af9d72bdedd131e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\bymgo2mi.default-1401686432357\extensions\cacaoweb@cacaoweb.org</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c343efa5752586b030b97935dd25e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\bymgo2mi.default-1401686432357\extensions\cacaoweb@cacaoweb.org\chrome</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c343efa5752586b030b97935dd25e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\bymgo2mi.default-1401686432357\extensions\cacaoweb@cacaoweb.org\chrome\content</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c343efa5752586b030b97935dd25e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\bymgo2mi.default-1401686432357\extensions\cacaoweb@cacaoweb.org\chrome\locale</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c343efa5752586b030b97935dd25e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\bymgo2mi.default-1401686432357\extensions\cacaoweb@cacaoweb.org\chrome\locale\de-DE</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c343efa5752586b030b97935dd25e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\bymgo2mi.default-1401686432357\extensions\cacaoweb@cacaoweb.org\chrome\locale\en-US</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c343efa5752586b030b97935dd25e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\bymgo2mi.default-1401686432357\extensions\cacaoweb@cacaoweb.org\chrome\locale\es-ES</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c343efa5752586b030b97935dd25e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\bymgo2mi.default-1401686432357\extensions\cacaoweb@cacaoweb.org\chrome\locale\fr-FR</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c343efa5752586b030b97935dd25e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\bymgo2mi.default-1401686432357\extensions\cacaoweb@cacaoweb.org\chrome\skin</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c343efa5752586b030b97935dd25e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\bymgo2mi.default-1401686432357\extensions\cacaoweb@cacaoweb.org\defaults</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c343efa5752586b030b97935dd25e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\bymgo2mi.default-1401686432357\extensions\cacaoweb@cacaoweb.org\defaults\preferences</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c343efa5752586b030b97935dd25e11f</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\lfy6m5ts.default-1413825442581\extensions\cacaoweb@cacaoweb.org</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>b155a7ed1b7f38fef8f14569c83ade22</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\lfy6m5ts.default-1413825442581\extensions\cacaoweb@cacaoweb.org\chrome</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>b155a7ed1b7f38fef8f14569c83ade22</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\lfy6m5ts.default-1413825442581\extensions\cacaoweb@cacaoweb.org\chrome\content</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>b155a7ed1b7f38fef8f14569c83ade22</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\lfy6m5ts.default-1413825442581\extensions\cacaoweb@cacaoweb.org\chrome\locale</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>b155a7ed1b7f38fef8f14569c83ade22</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\lfy6m5ts.default-1413825442581\extensions\cacaoweb@cacaoweb.org\chrome\locale\de-DE</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>b155a7ed1b7f38fef8f14569c83ade22</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\lfy6m5ts.default-1413825442581\extensions\cacaoweb@cacaoweb.org\chrome\locale\en-US</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>b155a7ed1b7f38fef8f14569c83ade22</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\lfy6m5ts.default-1413825442581\extensions\cacaoweb@cacaoweb.org\chrome\locale\es-ES</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>b155a7ed1b7f38fef8f14569c83ade22</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\lfy6m5ts.default-1413825442581\extensions\cacaoweb@cacaoweb.org\chrome\locale\fr-FR</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>b155a7ed1b7f38fef8f14569c83ade22</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\lfy6m5ts.default-1413825442581\extensions\cacaoweb@cacaoweb.org\chrome\skin</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>b155a7ed1b7f38fef8f14569c83ade22</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\lfy6m5ts.default-1413825442581\extensions\cacaoweb@cacaoweb.org\defaults</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>b155a7ed1b7f38fef8f14569c83ade22</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\lfy6m5ts.default-1413825442581\extensions\cacaoweb@cacaoweb.org\defaults\preferences</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>b155a7ed1b7f38fef8f14569c83ade22</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\cacaoweb@cacaoweb.org</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c0462a6a72284ee88b5e149a19e9cf31</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\cacaoweb@cacaoweb.org\chrome</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c0462a6a72284ee88b5e149a19e9cf31</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\cacaoweb@cacaoweb.org\chrome\content</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c0462a6a72284ee88b5e149a19e9cf31</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\cacaoweb@cacaoweb.org\chrome\locale</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c0462a6a72284ee88b5e149a19e9cf31</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\cacaoweb@cacaoweb.org\chrome\locale\de-DE</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c0462a6a72284ee88b5e149a19e9cf31</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\cacaoweb@cacaoweb.org\chrome\locale\en-US</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c0462a6a72284ee88b5e149a19e9cf31</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\cacaoweb@cacaoweb.org\chrome\locale\es-ES</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c0462a6a72284ee88b5e149a19e9cf31</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\cacaoweb@cacaoweb.org\chrome\locale\fr-FR</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c0462a6a72284ee88b5e149a19e9cf31</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\cacaoweb@cacaoweb.org\chrome\skin</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c0462a6a72284ee88b5e149a19e9cf31</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\cacaoweb@cacaoweb.org\defaults</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c0462a6a72284ee88b5e149a19e9cf31</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\cacaoweb@cacaoweb.org\defaults\preferences</path> <vendor>PUP.Optional.CacaoWeb</vendor> <action/> <hash>c0462a6a72284ee88b5e149a19e9cf31</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}</path> <vendor>PUP.Optional.DealPly</vendor> <action/> <hash>ee18b9db27739e982dbb179a38ca16ea</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}\chrome</path> <vendor>PUP.Optional.DealPly</vendor> <action/> <hash>ee18b9db27739e982dbb179a38ca16ea</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}\chrome\content</path> <vendor>PUP.Optional.DealPly</vendor> <action/> <hash>ee18b9db27739e982dbb179a38ca16ea</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\lfy6m5ts.default-1413825442581\extensions\{08ae5e13-70cc-4fbb-ad00-ef4b90a44451}</path> <vendor>PUP.Optional.Bandoo.AppFlsh</vendor> <action/> <hash>57af553f7921aa8c46e51ba9867cb44c</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\lfy6m5ts.default-1413825442581\extensions\{08ae5e13-70cc-4fbb-ad00-ef4b90a44451}\chrome</path> <vendor>PUP.Optional.Bandoo.AppFlsh</vendor> <action/> <hash>57af553f7921aa8c46e51ba9867cb44c</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\lfy6m5ts.default-1413825442581\extensions\{08ae5e13-70cc-4fbb-ad00-ef4b90a44451}\chrome\data</path> <vendor>PUP.Optional.Bandoo.AppFlsh</vendor> <action/> <hash>57af553f7921aa8c46e51ba9867cb44c</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\chrome</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\common</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\external</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\search</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\css</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\external</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\fonts</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </folder> <folder> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\_metadata</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </folder> <file> <path>C:\Users\Dominique VEY\AppData\Roaming\ZHP\Quarantine\FlashPlayerSDM.exe</path> <vendor>PUP.Optional.SweetIM</vendor> <action/> <hash>9571a7edfe9ce65099f92e5ba0647888</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Roaming\ZHP\Quarantine\~wunflrq.exe</path> <vendor>Trojan.KreaPixel</vendor> <action/> <hash>df27d3c1f7a3033307bab3ed57aa03fd</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Roaming\ZHP\Quarantine\FromDocToPDF.e9e7cfe54e46414faaf8ee6d637b0f2d.exe</path> <vendor>PUP.Optional.MindSpark</vendor> <action/> <hash>8c7a9afadebc0f273fef12855fa536ca</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Roaming\ZHP\Quarantine\SoftonicDownloader_pour_aimp.exe</path> <vendor>PUP.Optional.SofTonic</vendor> <action/> <hash>0ff7078decae03334965d05db1504ab6</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Roaming\ZHP\Quarantine\sweetimsetup.exe</path> <vendor>PUP.Optional.SweetIM</vendor> <action/> <hash>52b46d27a5f560d6dfb3ec9dba4aad53</hash> </file> <file> <path>C:\Users\Dominique VEY\Downloads\install_flashplayer11x64_mssd_aih.exe</path> <vendor>PUP.Optional.InstallCore</vendor> <action/> <hash>bc4aaee6089234027efb14f7629ee818</hash> </file> <file> <path>C:\Users\Dominique VEY\Downloads\Player_Setup.exe</path> <vendor>PUP.Optional.DomaIQ</vendor> <action/> <hash>24e26430297145f1a952fcad649c5fa1</hash> </file> <file> <path>C:\Users\Dominique VEY\Downloads\FlashPlayerPro.exe</path> <vendor>PUP.Optional.InstallCore</vendor> <action/> <hash>7393ddb70c8e60d6ca2201399170df21</hash> </file> <file> <path>C:\Users\Dominique VEY\Downloads\VLCMediaPlayerSetup.exe</path> <vendor>PUP.Optional.Somoto</vendor> <action/> <hash>27dff79df4a641f51b04a47ee31d8c74</hash> </file> <file> <path>C:\Users\Dominique VEY\Downloads\SoftwareUpdate.exe</path> <vendor>PUP.Optional.AirAd</vendor> <action/> <hash>2adc3c586e2cb482a2306bb7827eca36</hash> </file> <file> <path>C:\Users\Dominique VEY\Downloads\WiseConvert_1_5.exe</path> <vendor>PUP.Optional.Conduit</vendor> <action/> <hash>55b1cdc7dfbb1c1a7ca77f36f40db848</hash> </file> <file> <path>C:\Users\Dominique VEY\Downloads\setup.exe</path> <vendor>PUP.Optional.DomaIQ</vendor> <action/> <hash>808603915347c4725f81329ce31d9070</hash> </file> <file> <path>C:\Users\Dominique VEY\Downloads\PDFCreator-1_7_0_setup.exe</path> <vendor>PUP.Optional.InstallCore</vendor> <action/> <hash>986ed7bdafebc472f2873dceba46926e</hash> </file> <file> <path>C:\Users\Dominique VEY\Downloads\Media_Player_Setup.exe</path> <vendor>PUP.Optional.OptimumInstaller</vendor> <action/> <hash>10f63a5a9406e6507b51929aa06128d8</hash> </file> <file> <path>C:\Users\Dominique VEY\Downloads\free-music-converter.exe</path> <vendor>PUP.Optional.InstallCore</vendor> <action/> <hash>729491036e2c85b1327c54e8b64ed030</hash> </file> <file> <path>C:\Users\Dominique VEY\Downloads\FileConverter_1_5.exe</path> <vendor>PUP.Optional.Conduit</vendor> <action/> <hash>41c5583cb8e2f24431f2a70ee21f619f</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\nsn6D2A.tmp</path> <vendor>PUP.Optional.AnyProtect</vendor> <action/> <hash>15f11b792d6df93dbe48711e5ea610f0</hash> </file> <file> <path>C:\Windows\Installer\a8bf9d.msi</path> <vendor>PUP.Optional.SweetIM</vendor> <action/> <hash>42c4f89cb3e76accdcb62a5f42c245bb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Roaming\GoldenGate\3a6b9503a0a8026e8e765e39fa7e95f7.logic.db</path> <vendor>PUP.Optional.Gameo</vendor> <action/> <hash>a75f603428726dc9a2932fa4d929cf31</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\extensions\boost@boost.net.xpi</path> <vendor>PUP.Optional.Boost</vendor> <action/> <hash>31d5e1b38e0c191d5987752390738a76</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\lero</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\bapi_ff.dat</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\bapi_ie.dat</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\didi</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\faro</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\install.log</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\naci.dat</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\raco.cfg</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\Sqlite3.dll</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\tido.exe</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\uninst.dat</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\uninst.exe</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\HowToRemove\chromium-min.jpg</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\HowToRemove\control panel-min-min.JPG</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\HowToRemove\down.png</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\HowToRemove\ff menu.JPG</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\HowToRemove\ff search engine-min.png</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\HowToRemove\HowToRemove.html</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\HowToRemove\hp-min ff.png</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\HowToRemove\hp-min ie.png</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\HowToRemove\search engine.gif</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\HowToRemove\setup pages.gif</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\HowToRemove\sp-min.png</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\HowToRemove\start-min.jpg</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\{477D7121-63D5-1D99-0E4D-38712A25C4E9}\HowToRemove\up.png</path> <vendor>PUP.Optional.Dregol</vendor> <action/> <hash>63a3fe963c5e14221b7b782830d315eb</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\l7nze82d.default-1413910788947\DownSpeedTest_dq\69DE1ED5-17EF-408D-AE4D-BD87B25E4625.sqlite</path> <vendor>PUP.Optional.MindSpark</vendor> <action/> <hash>0afcd5bf495124126c841297a55ecf31</hash> </file> <file> <path>C:\Windows\System32\config\systemprofile\AppData\Local\WebBar\wb.log</path> <vendor>PUP.Optional.WebBar</vendor> <action/> <hash>a165bbd96a3093a3b99ef4c7649f5ca4</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\searchplugins\Web Search.xml</path> <vendor>PUP.Optional.WebSearch</vendor> <action/> <hash>32d4e0b4702a53e309aca714c93acf31</hash> </file> <file> <path>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HowToRemove.html.lnk</path> <vendor>PUP.Optional.WinYahoo</vendor> <action/> <hash>cc3a93012d6d2511b1ff7b65a95a3cc4</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Local Storage\chrome-extension_pilplloabdedfmialnfchjomjmpjcoej_0.localstorage</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>3fc795ffcdcd5cda48408f6b48bb38c8</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\manifest.json</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\background.html</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\favicon.ico</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\newtab.html</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\chrome\common.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\chrome\lifecycle.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\chrome\settings.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\chrome\setup.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\chrome\utils.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\common\abtest.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\common\conf-sys.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\common\conf.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\common\nt_ptr.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\common\prefs-sys.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\common\prefs.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\common\settings-dev.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\common\udata.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\external\jquery-2.1.1.min.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\external\md5.min.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\external\progressbar.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\external\string.min.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\external\underscore-min.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\search\AutoSuggest.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\search\contentscript.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\search\newtab-base.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\search\newtab-msg.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\search\search-engines.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\search\search-form.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\content\search\search-redirect.js</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\css\newtab.css</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\css\search.css</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\css\search2.css</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\css\styles.css</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\css\white_bg.css</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\external\normalize.css</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\fonts\HelveticaNeue-Thin.otf</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\fonts\neue-bold.woff</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\fonts\neue.woff</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\128.png</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\16.png</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\48.png</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\close.png</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\01d.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\01n.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\02d.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\02n.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\03d.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\03n.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\04d.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\04n.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\09d.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\09n.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\10d.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\10n.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\11d.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\11n.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\13d.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\13n.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\50d.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\icons\weather\50n.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images\bg.jpg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images\bing.png</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images\bluesky-bg.jpg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images\brush.png</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images\clock.png</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images\cloud.png</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images\cupcake-bg.jpg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images\desk-bg.jpg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images\doodle.png</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images\down.png</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images\google.png</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images\just-the-box.png</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images\mountain-bg.jpg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images\sea-bg.jpg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images\yahoo.png</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\skin\images\yahoo.svg</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Chromium\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\1.0.9.1_0\_metadata\verified_contents.json</path> <vendor>PUP.Optional.SearchManager</vendor> <action/> <hash>9a6c2074376371c536ad359281819f61</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Local\Microsoft\Windows\INetCookies\Low\VLBY2WBN.txt</path> <vendor>PUP.Optional.TerraClicks.ShrtCln</vendor> <action/> <hash>7591553fc4d6d363363fd2ca08fc6b95</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\bymgo2mi.default-1401686432357\prefs.js</path> <vendor>PUP.Optional.WinYahoo</vendor> <action/> <baddata>user_pref("browser.startup.homepage", "https://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_39_ssg08&param1=1&param2=f%3D1%26b%3DFirefox%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzuyC0C0F0D0Bzy0CyEyByCtC0FtCzy0DyBtN0D0Tzu0StCyBtAyEtN1L2XzutAtFtByEtFyCtFyDtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyByCyCyBtD0CtBzytGtDyC0BtAtGyCzyyBtDtGtB0CtBtDtG0A0CyC0FtCzytD0DtC0EtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0EtA0AtD0AtC0D0CtGtD0DtByBtGyEtAyDzytGzytByByCtGyEyBtAyD0Fzy0ByByCyB0Azz2QtN0A0LzutBtN1B2Z1V1T1S1NzutCtDyEtCtC%26cr%3D1928225444%26a%3Dwbf_popjar_16_39_ssg08%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome");</baddata> <gooddata>user_pref("browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/</gooddata> <hash>09fd692b247657df416618854cb8e719</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\bymgo2mi.default-1401686432357\searchplugins\yahoo!t powered.xml</path> <vendor>PUP.Optional.WinYahoo</vendor> <action/> <hash>52b4890bff9b8ea8aeae1c810ff58d73</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\l7nze82d.default-1413910788947\searchplugins\yahoo!D powered.xml</path> <vendor>PUP.Optional.WinYahoo</vendor> <action/> <hash>ad59355f227823133f1ddebf0ef606fa</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\lfy6m5ts.default-1413825442581\prefs.js</path> <vendor>PUP.Optional.WinYahoo</vendor> <action/> <baddata>user_pref("browser.startup.homepage", "https://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_39_ssg08&param1=1&param2=f%3D1%26b%3DFirefox%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzuyC0C0F0D0Bzy0CyEyByCtC0FtCzy0DyBtN0D0Tzu0StCyBtAyEtN1L2XzutAtFtByEtFyCtFyDtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyByCyCyBtD0CtBzytGtDyC0BtAtGyCzyyBtDtGtB0CtBtDtG0A0CyC0FtCzytD0DtC0EtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0EtA0AtD0AtC0D0CtGtD0DtByBtGyEtAyDzytGzytByByCtGyEyBtAyD0Fzy0ByByCyB0Azz2QtN0A0LzutBtN1B2Z1V1T1S1NzutCtDyEtCtC%26cr%3D1928225444%26a%3Dwbf_popjar_16_39_ssg08%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome");</baddata> <gooddata>user_pref("browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/</gooddata> <hash>e42243515f3bb77f4661dcc1fd0716ea</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\lfy6m5ts.default-1413825442581\searchplugins\yahoo!B powered.xml</path> <vendor>PUP.Optional.WinYahoo</vendor> <action/> <hash>dc2ad4c0a9f14de9aeaee6b71de725db</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\prefs.js</path> <vendor>PUP.Optional.WinYahoo</vendor> <action/> <baddata>user_pref("browser.startup.homepage", "https://fr.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_39_ssg08&param1=1&param2=f%3D1%26b%3DFirefox%26cc%3Dfr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzuyC0C0F0D0Bzy0CyEyByCtC0FtCzy0DyBtN0D0Tzu0StCyBtAyEtN1L2XzutAtFtByEtFyCtFyDtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyByCyCyBtD0CtBzytGtDyC0BtAtGyCzyyBtDtGtB0CtBtDtG0A0CyC0FtCzytD0DtC0EtAtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0EtA0AtD0AtC0D0CtGtD0DtByBtGyEtAyDzytGzytByByCtGyEyBtAyD0Fzy0ByByCyB0Azz2QtN0A0LzutBtN1B2Z1V1T1S1NzutCtDyEtCtC%26cr%3D1928225444%26a%3Dwbf_popjar_16_39_ssg08%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome");</baddata> <gooddata>user_pref("browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/</gooddata> <hash>a165f79d297170c6c7e03469719352ae</hash> </file> <file> <path>C:\Users\Dominique VEY\AppData\Roaming\Mozilla\Firefox\Profiles\qb4zxzd2.default\searchplugins\yahoo!o powered.xml</path> <vendor>PUP.Optional.WinYahoo</vendor> <action/> <hash>b551f3a1bfdbb185d3891a83b25215eb</hash> </file> </items> </mbam-log>