:OTL
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" =
http://startsear.ch/?aff=2&src=sp&cf=67 ... 5750d66&q={searchTerms} => Infection PUP (Adware.Bandoo)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://search.autocompletepro.com/?si=10203&bi=400 => Infection BT (Adware.PredictAd)
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
http://search.babylon.com/?q={searchTerms}&affID=113357&babsrc=SP_ss&mntrId=94828474000000000000002215750d66 => Infection PUP (PUP.ClaroSearch)
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" =
http://startsear.ch/?aff=2&src=sp&cf=67 ... 5750d66&q={searchTerms} => Infection PUP (Adware.Bandoo)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\crossriderapp1950@crossrider.com: C:\Documents and Settings\Propriétaire\Local Settings\Application Data\RewardsArcadeSuite\1950\Firefox [2012/01/20 20:42:10 | 000,000,000 | ---D | M] => Infection PUP (PUP.RewardsArcade)
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Program Files\AutocompletePro\AutocompletePro.dll File not found => Infection BT (Adware.PredictAd)
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll File not found => Infection BT (Toolbar.Babylon)
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll File not found => Infection BT (Toolbar.Babylon)
O3 - HKLM\..\Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - No CLSID value found. => Infection PUP (Adware.Bandoo)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
PRC - C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe () => Toolbar.AVGSearch
MOD - C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe () => Toolbar.AVGSearch
MOD - C:\Program Files\Fichiers communs\AVG Secure Search\SiteSafetyInstaller\14.0.1\SiteSafety.dll () => Toolbar.AVGSearch
SRV - (vToolbarUpdater14.0.1) -- C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe () => Toolbar.AVGSearch
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233} => Toolbar.AVGSearch
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" =
http://isearch.avg.com/search?cid={CAADB863-09E7-4FAA-8F45-888EEEF8AF75}&mid=fe8c3c46176f47d6a4a3d16b5391e495-c4230f7e3dfc0126527122a6456dd1b1cbf346a4&lang=fr&ds=AVG&pr=fr&d=2013-01 => Toolbar.AVGSearch
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050&SSPV=TB_IEOB28 => Toolbar.Conduit
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Fichiers communs\AVG Secure Search\SiteSafetyInstaller\14.0.1\\npsitesafety.dll () => Toolbar.AVGSearch
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\14.0.0.14\AVG Secure Search_toolbar.dll () => Toolbar.AVGSearch
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\14.0.0.14\AVG Secure Search_toolbar.dll () => Toolbar.AVGSearch
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Fichiers communs\AVG Secure Search\ViProtocolInstaller\14.0.1\ViProtocol.dll () => Toolbar.AVGSearch
[2013/01/23 09:47:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Local Settings\Application Data\AVG Secure Search => Toolbar.AVGSearch
[2013/01/23 09:47:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar => Toolbar.AVGSearch
[2013/01/23 09:47:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search => Toolbar.AVGSearch
[2013/01/23 09:47:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Propriétaire\Application Data\AVG Secure Search => Toolbar.AVGSearch
[2013/01/23 09:47:00 | 000,000,000 | ---D | C] -- C:\Program Files\Fichiers communs\AVG Secure Search => Toolbar.AVGSearch
[2013/01/23 09:46:59 | 000,000,000 | ---D | C] -- C:\Program Files\AVG Secure Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page =
http://search.autocompletepro.com/?si=10203&bi=400 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\FireFoxExt\14.0.0.14 [2013/01/23 09:47:13 | 000,000,000 | ---D | M]
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
http://dlm.tools.akamai.com/dlmanager/v ... .2.5.7.cab (DLM Control) => Akamai Download Manager ActiveX
[2013/01/25 13:00:00 | 000,001,068 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job => Google Update Task
[2013/01/25 09:03:32 | 000,001,064 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
O4 - HKLM\..\Run: [NPSStartup] File not found
O4 - HKLM\..\Run: [Tutorials] File not found
O4 - HKLM\..\RunOnceEx: [Flag] Reg Error: Invalid data type. File not found
MsConfig - StartUpFolder: C:^Documents and Settings^Propriétaire^Menu Démarrer^Programmes^Démarrage^Notification de cadeaux MSN.lnk - - File not found
MsConfig - StartUpReg:
PlusService - hkey= - key= - File not found
[2013/01/25 09:03:30 | 000,000,322 | ---- | M] () -- C:\WINDOWS\tasks\omqjrrk.job
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A29E7570
:Files
C:\WINDOWS\tasks\omqjrrk.job
:Commands
[emptytemp]
[createrestorepoint]