:OTL
SRV - [2012/04/06 07:34:23 | 000,055,808 | ---- | M] () [Auto] -- C:\Windows\TEMP\kpgiaa\setup.exe -- (AMService)
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://home.sweetim.com/?barid={5D62140A-07FE-11E1-8C16-001D7D44D9DF}
IE - HKLM\..\URLSearchHook: {53903846-3fb3-467b-a1bb-f3049e1a89a9} - C:\Program Files\BMFTV_bar\prxtbBMFT.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {9b53772a-8259-495d-a6b2-fa5966fe52e1} - C:\Program Files\Video_Clip_Grab\prxtbVide.dll (Conduit Ltd.)
IE - HKU\ilyes_ON_C\Software\Microsoft\Internet Explorer\Main,Search Page =
http://cloud-search.linkury.com/results ... ORID:11&q={searchTerms}&sa=Search&siteurl=search.linkury.com
IE - HKU\ilyes_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://search.linkury.com/newtab.html IE - HKU\ilyes_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr-FR
IE - HKU\ilyes_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D3 9D D9 36 B9 8D CC 01 [binary data]
IE - HKU\ilyes_ON_C\Software\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://cloud-search.linkury.com/results ... ORID:11&q={searchTerms}&sa=Search&siteurl=search.linkury.com
IE - HKU\ilyes_ON_C\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://cloud-search.linkury.com/results ... ORID:11&q={searchTerms}&sa=Search&siteurl=search.linkury.com
IE - HKU\ilyes_ON_C\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..keyword.URL: "http://cloud-search.linkury.com/results.htm?cx=partner-pub-7890126930977991:7317400059&cof=FORID:11&sa=Search&siteurl=search.linkury.com&q="
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "Linkury Smartbar Search"
FF - prefs.js..browser.startup.homepage: "http://search.linkury.com"
FF - prefs.js..browser.startup.homepage: "http://search.linkury.com"
FF - prefs.js..browser.search.selectedEngine: "Linkury Smartbar Search"
FF - prefs.js..browser.search.defaultenginename: "Search"
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{9CD2384C-143B-4790-A075-E7FEFE2A554B}: C:\Program Files\Boxore\BoxoreClient\BoxoreExtension\MozillaFirefox\
[2012/03/17 16:41:44 | 000,000,000 | ---D | M] (PriceGong) -- C:\Users\ilyes\AppData\Roaming\Mozilla\Firefox\Profiles\2p8ct26w.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
[2011/11/21 03:52:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ilyes\AppData\Roaming\Mozilla\Firefox\Profiles\h94yteeq.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
[2011/11/21 03:53:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ilyes\AppData\Roaming\Mozilla\Firefox\Profiles\h94yteeq.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2012/04/11 09:08:22 | 000,001,798 | ---- | M] () -- C:\Users\ilyes\AppData\Roaming\Mozilla\Firefox\Profiles\2p8ct26w.default\searchplugins\funmoods.xml
[2012/04/22 05:42:37 | 000,002,412 | ---- | M] () -- C:\Users\ilyes\AppData\Roaming\Mozilla\Firefox\Profiles\2p8ct26w.default\searchplugins\Linkury Smartbar Search.xml
[2012/03/17 16:42:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\ffxtlbr@babylon.com
File not found (No name found) --
[2012/04/09 06:15:03 | 000,002,353 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
O2 - BHO: (Complitly) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\ilyes\AppData\Roaming\Complitly\Complitly.dll (SimplyGen)
O2 - BHO: (2YourFace Addon) - {1185823F-F22F-4027-80E5-4F68ACD5DE5E} - C:\Program Files\2YourFace\bho.dll ()
O2 - BHO: (Shopping Assistant Plugin) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files\PriceGong\2.6.2\PriceGongIE.dll (PriceGong)
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO)
O2 - BHO: (extrafind) - {4be0986a-b9ed-d1f1-30da-43ef8389dde5} - C:\Windows\System32\4d60b17c.dll ()
O2 - BHO: (BMFTV bar Toolbar) - {53903846-3fb3-467b-a1bb-f3049e1a89a9} - C:\Program Files\BMFTV_bar\prxtbBMFT.dll (Conduit Ltd.)
O2 - BHO: (TBSB01620 Class) - {58124A0B-DC32-4180-9BFF-E0E21AE34026} - C:\Program Files\IMinent Toolbar\tbcore3.dll ()
O2 - BHO: (no name) - {66D8FBA6-D90F-40A9-AC55-84896F79CA69} - No CLSID value found.
O2 - BHO: (no name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No CLSID value found.
O2 - BHO: (no name) - {9193fbaf-bdaf-4751-a99a-1f5ef255c35b} - No CLSID value found.
O2 - BHO: (Video Clip Grab Toolbar) - {9b53772a-8259-495d-a6b2-fa5966fe52e1} - C:\Program Files\Video_Clip_Grab\prxtbVide.dll (Conduit Ltd.)
O2 - BHO: (IMinent WebBooster (BHO)) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files\Iminent\Iminent.WebBooster.InternetExplorer.dll (Iminent)
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files\Wajam\IE\priam_bho.dll (Wajam)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) => Ask.com Toolbar
O3 - HKLM\..\Toolbar: (BMFTV bar Toolbar) - {53903846-3fb3-467b-a1bb-f3049e1a89a9} - C:\Program Files\BMFTV_bar\prxtbBMFT.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) => Microsoft Corporation - BingBar
O3 - HKLM\..\Toolbar: (IMinent Toolbar) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - C:\Program Files\IMinent Toolbar\tbcore3.dll () => Infection PUP (Adware.IMBooster)
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.) => Infection BT (Toolbar.Babylon)
O3 - HKLM\..\Toolbar: (Video Clip Grab Toolbar) - {9b53772a-8259-495d-a6b2-fa5966fe52e1} - C:\Program Files\Video_Clip_Grab\prxtbVide.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) => Ask.com Toolbar
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (BMFTV bar Toolbar) - {53903846-3FB3-467B-A1BB-F3049E1A89A9} - C:\Program Files\BMFTV_bar\prxtbBMFT.dll (Conduit Ltd.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (IMinent Toolbar) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - C:\Program Files\IMinent Toolbar\tbcore3.dll () => Infection PUP (Adware.IMBooster)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Video Clip Grab Toolbar) - {9B53772A-8259-495D-A6B2-FA5966FE52E1} - C:\Program Files\Video_Clip_Grab\prxtbVide.dll (Conduit Ltd.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) => Ask.com Toolbar
O3 - HKU\ilyes_ON_C\..\Toolbar\WebBrowser: (no name) - {05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E} - No CLSID value found. => Toolbar.Agent
O3 - HKU\ilyes_ON_C\..\Toolbar\WebBrowser: (BMFTV bar Toolbar) - {53903846-3FB3-467B-A1BB-F3049E1A89A9} - C:\Program Files\BMFTV_bar\prxtbBMFT.dll (Conduit Ltd.)
O3 - HKU\ilyes_ON_C\..\Toolbar\WebBrowser: (IMinent Toolbar) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - C:\Program Files\IMinent Toolbar\tbcore3.dll () => Infection PUP (Adware.IMBooster)
O3 - HKU\ilyes_ON_C\..\Toolbar\WebBrowser: (Video Clip Grab Toolbar) - {9B53772A-8259-495D-A6B2-FA5966FE52E1} - C:\Program Files\Video_Clip_Grab\prxtbVide.dll (Conduit Ltd.)
O3 - HKU\ilyes_ON_C\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [QJa8hs7QNbxt4uL] C:\Windows\System32\config\systemprofile\AppData\Roaming\ram_reserver64.exe ()
O4 - HKU\.DEFAULT..\Run: [PC Health Status] C:\Windows\System32\config\systemprofile\AppData\Roaming\sqskqdpq.exe (Eugene Roshal & FAR Group)
O4 - HKU\.DEFAULT..\Run: [QJa8hs7QNbxt4uL] C:\Windows\System32\config\systemprofile\AppData\Roaming\ram_reserver64.exe ()
O4 - HKU\ilyes_ON_C..\Run: [QJa8hs7QNbxt4uL] C:\Users\ilyes\AppData\Roaming\ram_reserver64.exe ()
O4 - HKU\ilyes_ON_C..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = C:\Windows\system32\System32\sv_chosts.exe (Microsoft Corporation)
O7 - HKU\ilyes_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: Policies = C:\Windows\system32\System32\sv_chosts.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (C:\Windows\system32\config\systemprofile\AppData\Roaming\ram_reserver64.exe) - C:\Windows\System32\config\systemprofile\AppData\Roaming\ram_reserver64.exe (
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\config\systemprofile\AppData\Roaming\ram_reserver64.exe) - C:\Windows\System32\config\systemprofile\AppData\Roaming\ram_reserver64.exe ()
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKU\.DEFAULT Winlogon: Shell - (C:\Windows\system32\config\systemprofile\AppData\Roaming\ram_reserver64.exe) - C:\Windows\System32\config\systemprofile\AppData\Roaming\ram_reserver64.exe ()
O20 - HKU\.DEFAULT Winlogon: UserInit - (C:\Windows\system32\config\systemprofile\AppData\Roaming\ram_reserver64.exe) - C:\Windows\System32\config\systemprofile\AppData\Roaming\ram_reserver64.exe ()
O20 - HKU\ilyes_ON_C Winlogon: Shell - (C:\Users\ilyes\AppData\Roaming\ram_reserver64.exe) - C:\Users\ilyes\AppData\Roaming\ram_reserver64.exe ()
O20 - HKU\ilyes_ON_C Winlogon: UserInit - (C:\Users\ilyes\AppData\Roaming\ram_reserver64.exe) - C:\Users\ilyes\AppData\Roaming\ram_reserver64.exe ()
O20 - Winlogon\Notify\primkhi: DllName - C:\Windows\system32\config\systemprofile\AppData\Local\primkhi.dll - C:\Windows\System32\config\systemprofile\AppData\Local\primkhi.dll ()
MsConfig - StartUpReg:
Iminent - hkey= - key= - C:\Program Files\Iminent\Iminent.exe (Iminent)
MsConfig - StartUpReg:
IminentMessenger - hkey= - key= - C:\Program Files\Iminent\Iminent.Messengers.exe (Iminent)
MsConfig - StartUpReg:
Kujytuo - hkey= - key= - C:\Users\ilyes\AppData\Roaming\kujytuo.exe ()
MsConfig - StartUpReg:
offerbox - hkey= - key= - C:\Program Files\OfferBox\OfferBox.exe (Aedge Performance BCN SL)
MsConfig - StartUpReg:
Sweetpacks Communicator - hkey= - key= - C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe (SweetIM Technologies Ltd.)
ActiveX: {4406WM8P-BQ7J-2315-U415-HRIETL255EUF} - C:\Windows\system32\System32\sv_chosts.exe Restart
ActiveX: {tlMe4VA9-8LXI-r4nq-LmM7-2PRL0gJFErMy} -
ActiveX: {2E5368F6-B73A-A4AF-73BB-E9F5E242CA1A} - Internet Explorer
ActiveX: {FB3D0904-49D1-8C68-764E-36F8B250E822} - Internet Explorer
[2012/04/09 06:22:39 | 000,000,000 | ---D | C] -- C:\Users\ilyes\AppData\Local\freetvradio Air
[2012/04/09 06:22:31 | 000,000,000 | ---D | C] -- C:\Users\ilyes\AppData\Roaming\freeTVRadio
[2012/04/09 06:22:19 | 000,000,000 | ---D | C] -- C:\Program Files\freeTVRadio
[2012/04/09 06:22:01 | 000,000,000 | ---D | C] -- C:\Users\ilyes\AppData\Roaming\OfferBox
[2012/04/09 06:21:55 | 000,000,000 | ---D | C] -- C:\Program Files\OfferBox
[2012/04/09 06:17:40 | 000,000,000 | ---D | C] -- C:\Users\ilyes\AppData\Roaming\WebPlayerBdd
[2012/04/09 06:15:00 | 000,000,000 | ---D | C] -- C:\Users\ilyes\AppData\Local\Babylon
[2012/04/09 06:14:59 | 000,000,000 | ---D | C] -- C:\Users\ilyes\AppData\Roaming\Babylon
[2012/04/09 06:14:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2012/04/06 15:25:56 | 000,000,000 | ---D | C] -- C:\Users\ilyes\Documents\GlobalStar
[2011/10/19 19:32:02 | 000,094,208 | ---- | C] (ujgaspNiHN) -- C:\Users\ilyes\AppData\Roaming\Svchost.exe
[2012/04/25 08:49:32 | 000,182,784 | ---- | M] () -- C:\Users\ilyes\AppData\Roaming\ram_reserver64.exe
[2012/04/09 06:14:59 | 000,391,520 | ---- | C] () -- C:\Users\ilyes\AppData\Roaming\kujytuo.exe
[2011/12/27 02:41:12 | 000,155,648 | ---- | C] () -- C:\Users\ilyes\AppData\Roaming\chrtmp
[2011/12/27 02:41:09 | 000,020,480 | ---- | C] () -- C:\Users\ilyes\AppData\Roaming\trilu.exe
[2011/10/11 09:16:29 | 000,005,028 | ---- | C] () -- C:\ProgramData\cgatmfqq.mbd
[2012/03/06 12:14:31 | 000,094,208 | ---- | M] (ujgaspNiHN) MD5=04EC5BE676AF3B7787D60E77B99B9709 -- C:\Documents and Settings\ilyes\AppData\Roaming\Svchost.exe
[2012/03/06 12:14:31 | 000,094,208 | ---- | M] (ujgaspNiHN) MD5=04EC5BE676AF3B7787D60E77B99B9709 -- C:\Documents and Settings\ilyes\Application Data\Svchost.exe
[2012/03/06 12:14:31 | 000,094,208 | ---- | M] (ujgaspNiHN) MD5=04EC5BE676AF3B7787D60E77B99B9709 -- C:\Users\ilyes\AppData\Roaming\Svchost.exe
:Files
C:\Windows\tasks\At*
[2012/04/05 13:44:31 | 000,119,808 | ---- | C] () -- C:\ProgramData\mx18y1i1.exe
[2012/03/17 16:44:59 | 000,075,562 | ---- | C] () -- C:\Windows\System32\e056c9c4.exe
[2012/03/17 16:44:56 | 002,551,808 | ---- | C] () -- C:\Windows\System32\4d60b17c.dll
:Commands
[resethosts]
[emptytemp]
[purity]
[createrestorepoint]
[reboot]