[MD5.981794879E8FD26CDD6ABCFF3F3F65EF] - (...) -- C:\ProgramData\BrowserProtect\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [3085264] [PID.2536] =>Hijacker.Eazel
M3 - MFPP: Plugins - [Adrien Gasnier] -- C:\Users\Adrien Gasnier\AppData\Roaming\Mozilla\Firefox\Profiles\1dbgeibv.default\searchplugins\babylon.xml =>Toolbar.Babylon
M3 - MFPP: Plugins - [Adrien Gasnier] -- C:\Users\Adrien Gasnier\AppData\Roaming\Mozilla\Firefox\Profiles\1dbgeibv.default\searchplugins\BrowserProtect.xml =>Hijacker.Eazel
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.babylon.com =>Toolbar.Babylon
O2 - BHO: CrossriderApp0012765 [64Bits] - {11111111-1111-1111-1111-110111271165} . (.Innovative Apps - Savings Wave BHO.) -- C:\Program Files (x86)\Savings Wave\Savings Wave.dll =>PUP.CrossRider
O2 - BHO: holasearch Helper Object [64Bits] - {DFF9B2DA-EF99-4B26-83CB-7058299999D8} . (.holasearch.com - Pas de description.) -- C:\Program Files (x86)\holasearch\holasearch\1.8.16.16\bh\holasearch.dll =>Hijacker.HolaSearch
O23 - Service: BrowserProtect (BrowserProtect) . (...) - C:\ProgramData\BrowserProtect\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe =>Hijacker.Eazel
[MD5.F1B6B19AA752DEA83BCE4DFEF3D4C5BA] [APT] [EPUpdater] (...) -- C:\Users\Adrien Gasnier\AppData\Roaming\BabSolution\Shared\BabMaint.exe [9808] =>Hijacker.BabSolution
[MD5.79EBD77C22501221AB73A4549C9FDBF2] [APT] [Express FilesUpdate] (...) -- C:\Program Files (x86)\ExpressFiles\EFUpdater.exe [249440] =>Adware.ExpressFiles
[MD5.108C6E4777A679FE0AD3DB7476FA9D04] [APT] [Updater12765.exe] (.Innovative Apps.) -- C:\Users\Adrien Gasnier\AppData\Local\Updater12765\Updater12765.exe [210312] =>PUP.CrossRider
O42 - Logiciel: BrowserProtect - (...) [HKLM][64Bits] -- {15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693} =>Hijacker.Eazel
O42 - Logiciel: ExpressFiles - (.
http://www.express-files.com/.) [HKCU][64Bits] -- ExpressFiles =>Adware.ExpressFiles
O42 - Logiciel: Savings Wave - (.Innovative Apps.) [HKLM][64Bits] -- Savings Wave =>PUP.CrossRider
O42 - Logiciel: Yontoo 2.051 - (.Yontoo LLC.) [HKLM][64Bits] -- {889DF117-14D1-44EE-9F31-C5FB5D47F68B} =>Adware.Yontoo
O42 - Logiciel: holasearch toolbar - (.holasearch.) [HKLM][64Bits] -- holasearch =>Hijacker.HolaSearch
[HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider
[HKCU\Software\AppDataLow\Software\Savings Wave] =>PUP.CrossRider
[HKCU\Software\BabSolution] =>Hijacker.BabSolution
[HKCU\Software\Cr_Installer] =>PUP.CrossRider
[HKCU\Software\DataMngr] =>PUP.Datamngr
[HKCU\Software\DataMngr_Toolbar] =>PUP.Datamngr
[HKCU\Software\Iminent] =>Adware.IMBooster
[HKCU\Software\InstallCore] =>PUP.InstallCore
[HKCU\Software\InstalledBrowserExtensions] =>Adware.VidSaver
[HKCU\Software\e558cdeb534e841] => Infection PUP (Toolbar.Babylon)
[HKCU\Software\holasearch LTD] =>Hijacker.HolaSearch
[HKCU\Software\holasearch] =>Hijacker.HolaSearch
[HKLM\Software\Wow6432Node\Babylon] =>Toolbar.Babylon
[HKLM\Software\Wow6432Node\DataMngr] =>PUP.Datamngr
[HKLM\Software\Wow6432Node\ExpressFiles] =>Adware.ExpressFiles
[HKLM\Software\Wow6432Node\Iminent] =>Adware.IMBooster
[HKLM\Software\Wow6432Node\Supreme Savings] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\e558cdeb534e841] => Infection PUP (Toolbar.Babylon)
O43 - CFD: 29/05/2013 - 21:46:23 - [9,328] ----D C:\Program Files (x86)\ExpressFiles =>Adware.ExpressFiles
O43 - CFD: 24/04/2013 - 14:19:24 - [2,813] ----D C:\Program Files (x86)\holasearch =>Hijacker.HolaSearch
O43 - CFD: 30/05/2013 - 22:33:22 - [0,695] ----D C:\Program Files (x86)\Iminent =>Adware.IMBooster
O43 - CFD: 24/04/2013 - 14:21:59 - [5,759] ----D C:\Program Files (x86)\Savings Wave =>PUP.CrossRider
O43 - CFD: 19/04/2013 - 13:03:44 - [0,444] ----D C:\Program Files (x86)\Yontoo =>Adware.Yontoo
O43 - CFD: 19/04/2013 - 16:02:49 - [0] ----D C:\ProgramData\Babylon =>Toolbar.Babylon
O43 - CFD: 07/06/2013 - 17:16:30 - [8,375] ----D C:\ProgramData\BrowserProtect =>Hijacker.Eazel
O43 - CFD: 24/04/2013 - 14:19:08 - [0,002] ----D C:\ProgramData\IBUpdaterService =>Adware.InstallBrain
O43 - CFD: 29/05/2013 - 21:46:46 - [1,573] ----D C:\Users\Adrien Gasnier\AppData\Roaming\BabSolution =>Hijacker.BabSolution
O43 - CFD: 19/04/2013 - 16:02:48 - [0,027] ----D C:\Users\Adrien Gasnier\AppData\Roaming\Babylon =>Toolbar.Babylon
O43 - CFD: 22/05/2013 - 10:33:05 - [0,079] ----D C:\Users\Adrien Gasnier\AppData\Roaming\ExpressFiles =>Adware.ExpressFiles
O43 - CFD: 19/04/2013 - 13:03:45 - [0,098] ----D C:\Users\Adrien Gasnier\AppData\Roaming\Yontoo =>Adware.Yontoo
O43 - CFD: 20/04/2013 - 13:10:05 - [0,021] ----D C:\Users\Adrien Gasnier\AppData\Local\Lollipop =>Adware.Lollipop
O43 - CFD: 24/04/2013 - 14:21:59 - [0,010] ----D C:\Users\Adrien Gasnier\AppData\Local\Savings Wave =>PUP.CrossRider
O43 - CFD: 20/04/2013 - 13:08:49 - [0,011] ----D C:\Users\Adrien Gasnier\AppData\Local\Supreme Savings =>PUP.RewardsArcade
O43 - CFD: 24/04/2013 - 14:21:49 - [0,201] ----D C:\Users\Adrien Gasnier\AppData\Local\Updater12765 =>PUP.CrossRider
O87 - FAEL: "{83C94FE2-D19F-4BB5-9668-D9A4E94E35FA}" | In - Public - P6 - TRUE | .(.
http://www.express-files.com/ - ExpressDL Application.) -- C:\Program Files (x86)\ExpressFiles\expressdl.exe =>Adware.ExpressFiles
O87 - FAEL: "{15187947-9692-4523-B196-0E643D5C4DFE}" | In - Public - P17 - TRUE | .(.
http://www.express-files.com/ - ExpressDL Application.) -- C:\Program Files (x86)\ExpressFiles\expressdl.exe =>Adware.ExpressFiles
O87 - FAEL: "{C1CA970A-B705-4F1F-8FE4-0039117FA59C}" | In - Public - P6 - TRUE | .(.
http://www.express-files.com/ - ExpressFiles Application.) -- C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe =>Adware.ExpressFiles
O87 - FAEL: "{8D5D4EE8-A160-4EB1-9B15-B414462B2FE3}" | In - Public - P17 - TRUE | .(.
http://www.express-files.com/ - ExpressFiles Application.) -- C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe =>Adware.ExpressFiles
[HKLM\Software\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}] =>Adware.IMBooster
[HKLM\Software\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}] =>Adware.IMBooster
[HKLM\Software\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}] =>Adware.IMBooster
[HKLM\Software\Wow6432Node\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}] =>Adware.IMBooster
[HKLM\Software\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}] =>Adware.IMBooster
[HKLM\Software\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}] =>Adware.IMBooster
[HKLM\Software\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}] =>Toolbar.Babylon
[HKLM\Software\Wow6432Node\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}] =>Toolbar.Babylon
[HKLM\Software\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}] =>Adware.IMBooster
[HKLM\Software\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}] =>Adware.IMBooster
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}] =>Toolbar.Babylon
[HKLM\Software\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}] =>Adware.Yontoo
[HKLM\Software\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}] =>Adware.Yontoo
[HKLM\Software\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}] =>PUP.RewardsArcade
[HKLM\Software\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}] =>PUP.RewardsArcade
[HKLM\Software\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] =>Toolbar.Babylon
[HKLM\Software\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] =>Toolbar.Babylon
[HKLM\Software\Wow6432Node\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] =>Toolbar.Babylon
[HKLM\Software\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}] =>Adware.IMBooster
[HKLM\Software\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}] =>PUP.RewardsArcade
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}] =>Adware.Yontoo
[HKLM\Software\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}] =>PUP.RewardsArcade
[HKLM\Software\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}] =>Toolbar.Babylon
[HKLM\Software\Wow6432Node\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}] =>Toolbar.Babylon
[HKLM\Software\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}] =>PUP.RewardsArcade
[HKLM\Software\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] =>Toolbar.Babylon
[HKLM\Software\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] =>Toolbar.Babylon
[HKLM\Software\Wow6432Node\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] =>Toolbar.Babylon
[HKLM\Software\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}] =>PUP.RewardsArcade
[HKLM\Software\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}] =>PUP.RewardsArcade
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}] =>Adware.Yontoo
[HKLM\Software\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}] =>Adware.IMBooster
[HKLM\Software\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}] =>PUP.RewardsArcade
[HKLM\Software\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}] =>PUP.RewardsArcade
[HKLM\Software\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}] =>PUP.RewardsArcade
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}] =>Adware.Yontoo
[HKLM\Software\Classes\AppID\escort.dll] =>Toolbar.Babylon
[HKLM\Software\Classes\AppID\escortapp.dll] =>Toolbar.Babylon
[HKLM\Software\Classes\AppID\escorteng.dll] =>Toolbar.Babylon
[HKLM\Software\Classes\AppID\esrv.EXE] =>Toolbar.Babylon
[HKLM\Software\Classes\escort.escortIEPane] =>PUP.Funmoods
[HKLM\Software\Classes\escort.escortIEPane.1] =>PUP.Funmoods
[HKCU\Software\Cr_Installer] =>PUP.CrossRider
[HKCU\Software\DataMngr] =>Adware.Bandoo
[HKLM\Software\Wow6432Node\DataMngr] =>Adware.Bandoo
[HKCU\Software\lollipop] =>Adware.Lollipop
[HKCU\Software\Iminent] =>Adware.IMBooster
[HKLM\Software\Wow6432Node\Iminent] =>Adware.IMBooster
[HKLM\Software\Wow6432Node\Microsoft\Tracing\Iminent_RASAPI32] =>Adware.Bandoo
[HKLM\Software\Wow6432Node\Microsoft\Tracing\Iminent_RASMANCS] =>Adware.Bandoo
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}] =>Toolbar.Babylon
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\lollipop] =>Adware.Lollipop
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP] =>Adware.IMBooster
[HKLM\Software\Classes\Prod.cap] =>Toolbar.Babylon
[HKCU\Software\InstallCore] =>Adware.InstallCore
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings] =>PUP.BProtector
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}] =>PUP.BProtector
[HKLM\Software\Classes\delta.deltaappCore] =>PUP.Funmoods
[HKLM\Software\Classes\delta.deltaappCore.1] =>PUP.Funmoods
[HKLM\Software\Classes\delta.deltadskBnd] =>PUP.Funmoods
[HKLM\Software\Classes\delta.deltadskBnd.1] =>PUP.Funmoods
[HKLM\Software\Classes\AppID\ESRV.EXE] =>Adware.Facemoods
[HKCU\Software\AppDataLow\Software\Savings Wave] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Savings Wave] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Savings Wave] =>PUP.CrossRider
[HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider
[HKCU\Software\InstalledBrowserExtensions\] =>PUP.CrossRider
[HKCU\Software\holasearch] =>Hijacker.HolaSearch
[HKLM\Software\Wow6432Node\holasearch] =>Hijacker.HolaSearch
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\holasearch] =>Hijacker.HolaSearch
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Hola Chrome Toolbar] =>Hijacker.HolaSearch
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C510DFFB-0AFE-484C-BA40-CED5B74C4EEF}] =>Hijacker.HolaSearch
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C510DFFB-0AFE-484C-BA40-CED5B74C4EEF}] =>Hijacker.HolaSearch
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DFF9B2DA-EF99-4B26-83CB-7058299999D8}] =>Hijacker.HolaSearch
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DFF9B2DA-EF99-4B26-83CB-7058299999D8}] =>Hijacker.HolaSearch
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DFF9B2DA-EF99-4B26-83CB-7058299999D8}] =>Hijacker.HolaSearch
[HKLM\Software\Wow6432Node\SoftwareUpdater] =>Hijacker.Eazel
[HKLM\Software\Classes\CrossriderApp0012765.BHO] =>PUP.CrossRider
[HKLM\Software\Classes\CrossriderApp0012765.BHO.1] =>PUP.CrossRider
[HKLM\Software\Classes\CrossriderApp0012765.Sandbox] =>PUP.CrossRider
[HKLM\Software\Classes\CrossriderApp0012765.Sandbox.1] =>PUP.CrossRider
[HKLM\Software\Classes\AppID\escort.DLL] =>PUP.Funmoods
[HKLM\Software\Classes\AppID\escortApp.DLL] =>PUP.Funmoods
[HKLM\Software\Classes\AppID\escortEng.DLL] =>PUP.Funmoods
[HKLM\Software\Classes\AppID\escorTlbr.DLL] =>PUP.Funmoods
[HKLM\Software\Wow6432Node\Classes\CrossriderApp0012765.BHO] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Classes\CrossriderApp0012765.BHO.1] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Classes\CrossriderApp0012765.Sandbox] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Classes\CrossriderApp0012765.Sandbox.1] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Classes\escort.escortIEPane] =>PUP.Funmoods
[HKLM\Software\Wow6432Node\Classes\escort.escortIEPane.1] =>PUP.Funmoods
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110111271165}] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110111991162}] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Classes\CLSID\{11111111-1111-1111-1111-110111271165}] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Classes\CLSID\{22222222-2222-2222-2222-220122272265}] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Classes\AppID\escort.DLL] =>PUP.Funmoods
[HKLM\Software\Wow6432Node\Classes\AppID\escortApp.DLL] =>PUP.Funmoods
[HKLM\Software\Wow6432Node\Classes\AppID\escortEng.DLL] =>PUP.Funmoods
[HKLM\Software\Wow6432Node\Classes\AppID\escorTlbr.DLL] =>PUP.Funmoods
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110111271165}] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110111991162}] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110111271165}] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110111991162}] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{31111111-1111-1111-1111-110111271165}] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{31111111-1111-1111-1111-110111991162}] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110111271165}] =>PUP.CrossRider
[HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{D4027C7F-154A-4066-A1AD-4243D8127440} =>Adware.AskSBAR
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]:Bubble Dock =>Adware.SPointer
C:\Program Files (x86)\yontoo =>Adware.Yontoo
C:\Program Files (x86)\Iminent =>Adware.IMBooster
C:\Program Files (x86)\Savings Wave =>PUP.CrossRider
C:\Program Files (x86)\holasearch =>Hijacker.HolaSearch
C:\Program Files (x86)\Mozilla Firefox\Extensions\ffxtlbr@babylon.com =>Toolbar.Babylon
C:\ProgramData\Babylon =>Toolbar.Babylon
C:\ProgramData\IBUpdaterService =>Adware.IncrediBar
C:\ProgramData\BrowserProtect =>Hijacker.Eazel
C:\Users\Adrien Gasnier\AppData\Roaming\yontoo =>Adware.Yontoo
C:\Users\Adrien Gasnier\AppData\Roaming\Babylon =>Toolbar.Babylon
C:\Users\Adrien Gasnier\AppData\Roaming\BabSolution =>Hijacker.BabSolution
C:\Users\Adrien Gasnier\AppData\Local\lollipop =>Adware.Lollipop
C:\Users\Adrien Gasnier\AppData\Local\Supreme Savings =>PUP.RewardsArcade
C:\Users\Adrien Gasnier\AppData\Local\Savings Wave =>PUP.CrossRider
C:\Users\Adrien Gasnier\AppData\LocalLow\holasearch =>Hijacker.HolaSearch
[HKCU\Software\e558cdeb534e841\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1125.80]:guid="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" => Infection PUP (Toolbar.Babylon)
[HKCU\Software\e558cdeb534e841\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1125.80]:version="2.6.1125.80" => Infection PUP (Toolbar.Babylon)
[HKCU\Software\e558cdeb534e841\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1249.132]:guid="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" => Infection PUP (Toolbar.Babylon)
[HKCU\Software\e558cdeb534e841\history\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}2.6.1249.132]:version="2.6.1249.132" => Infection PUP (Toolbar.Babylon)
[HKCU\Software\e558cdeb534e841] =>Toolbar.Babylon^
[HKCU\Software\e558cdeb534e841]:GUID="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" => Infection PUP (Toolbar.Babylon)
[HKCU\Software\e558cdeb534e841]:version="2.6.1339.144" => Infection PUP (Toolbar.Babylon)
[HKLM\Software\Wow6432Node\e558cdeb534e841] =>Toolbar.Babylon^
[HKLM\Software\Wow6432Node\e558cdeb534e841]:GUID="{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}" => Infection PUP (Toolbar.Babylon)
[HKLM\Software\Wow6432Node\e558cdeb534e841]:version="2.6.1339.144" => Infection PUP (Toolbar.Babylon)
SR - | Auto 3085264 | (BrowserProtect) . (...) - C:\ProgramData\BrowserProtect\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe =>Hijacker.Eazel
M3 - MFPP: Plugins - [Adrien Gasnier] -- C:\Users\Adrien Gasnier\AppData\Roaming\Mozilla\Firefox\Profiles\1dbgeibv.default\searchplugins\delta.xml => Toolbar.DeltaSearch
O2 - BHO: delta Helper Object [64Bits] - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} . (.Delta-search.com - Pas de description.) -- C:\Program Files (x86)\Delta\delta\1.8.21.5\bh\delta.dll =>Toolbar.DeltaSearch
O42 - Logiciel: Delta toolbar - (.Delta.) [HKLM][64Bits] -- delta => Toolbar.DeltaSearch
[HKCU\Software\APN PIP] => Toolbar.Ask
[HKCU\Software\Softonic] => Toolbar.Conduit*
[HKLM\Software\DomaIQ] =>Toolbar.DomaIQ
[HKLM\Software\Tarma Installer] =>Toolbar.Tarma
[HKLM\Software\Wow6432Node\PIP] => Toolbar.Ask
O43 - CFD: 30/04/2013 - 19:49:06 - [0] ----D C:\ProgramData\APN => Toolbar.Ask
O43 - CFD: 16/04/2013 - 20:23:10 - [2,592] ----D C:\ProgramData\Tarma Installer =>Toolbar.Tarma
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.admin", false); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.aflt", "babsst"); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.autoRvrt", "false"); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.dfltLng", "en"); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.excTlbr", false); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.ffxUnstlRst", true); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.id", "ecb71840000000000000caf733948bb3"); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.instlDay", "15854"); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.instlRef", "sst"); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.newTab", false); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.prdct", "delta"); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.prtnrId", "delta"); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.rvrt", "false"); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.smplGrp", "none"); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.tlbrId", "base"); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.tlbrSrchUrl", ""); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.vrsn", "1.8.21.5"); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.vrsnTs", "1.8.21.521:46:41"); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta.vrsni", "1.8.21.5"); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta_i.babExt", ""); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta_i.babTrack", "affID=122310&tt=gc_"); => Toolbar.DeltaSearch)*
O69 - SBI: prefs.js [Adrien Gasnier - 1dbgeibv.default] user_pref("extensions.delta_i.srcExt", "ss"); => Toolbar.DeltaSearch)*
O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} - (Delta Search) -
http://www.delta-search.com =>Toolbar.DeltaSearch
[HKLM\Software\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}] =>Toolbar.Wajam
[HKLM\Software\Wow6432Node\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}] =>Toolbar.Wajam
[HKCU\Software\APN PIP] =>Toolbar.Ask
[HKLM\Software\Wow6432Node\PIP] =>Toolbar.Ask
[HKCU\Software\Softonic] =>Toolbar.Conduit
[HKLM\Software\Tarma Installer] =>Toolbar.Tarma
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}] =>Toolbar.DeltaSearch
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375] =>Toolbar.Agent
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5] =>Toolbar.Agent
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}] =>Toolbar.DeltaSearch
[HKLM\Software\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}] =>Toolbar.DeltaSearch
[HKLM\Software\Wow6432Node\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}] =>Toolbar.DeltaSearch
[HKLM\Software\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}] =>Toolbar.DeltaSearch
[HKLM\Software\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}] =>Toolbar.DeltaSearch
[HKLM\Software\Wow6432Node\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}] =>Toolbar.DeltaSearch
[HKLM\Software\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}] =>Toolbar.DeltaSearch
[HKLM\Software\Classes\delta.deltaHlpr] =>toolbar.DeltaSearch
[HKLM\Software\Classes\delta.deltaHlpr.1] =>toolbar.DeltaSearch
[HKLM\Software\Classes\esrv.deltaESrvc] =>toolbar.DeltaSearch
[HKLM\Software\Classes\esrv.deltaESrvc.1] =>toolbar.DeltaSearch
[HKLM\Software\Wow6432Node\Classes\delta.deltaappCore] =>toolbar.DeltaSearch
[HKLM\Software\Wow6432Node\Classes\delta.deltaappCore.1] =>toolbar.DeltaSearch
[HKLM\Software\Wow6432Node\Classes\delta.deltadskBnd] =>toolbar.DeltaSearch
[HKLM\Software\Wow6432Node\Classes\delta.deltadskBnd.1] =>toolbar.DeltaSearch
[HKLM\Software\Wow6432Node\Classes\delta.deltaHlpr] =>toolbar.DeltaSearch
[HKLM\Software\Wow6432Node\Classes\delta.deltaHlpr.1] =>toolbar.DeltaSearch
[HKLM\Software\Wow6432Node\Classes\esrv.deltaESrvc] =>toolbar.DeltaSearch
[HKLM\Software\Wow6432Node\Classes\esrv.deltaESrvc.1] =>toolbar.DeltaSearch
FirewallRaz
EmptyFlash
Emptytemp
SysRestore