:OTL
PRC - C:\Documents and Settings\All Users\Application Data\Browser Manager\2.3.811.154\{61d8b74e-8d89-46ff-afa6-33382c54ac73}\browsermngr.exe () => Infection BT (Toolbar.Babylon)
PRC - C:\Program Files\TUTO4PC\tuto4pc_fr_5.exe () => Infection BT (Spyware.AgenceExclusive)
MOD - C:\Documents and Settings\All Users\Application Data\Browser Manager\2.3.811.154\{61d8b74e-8d89-46ff-afa6-33382c54ac73}\browsermngr.exe () => Infection BT (Toolbar.Babylon)
MOD - C:\Documents and Settings\All Users\Application Data\Browser Manager\2.3.811.154\{61d8b74e-8d89-46ff-afa6-33382c54ac73}\browsermngr.dll () => Infection BT (Toolbar.Babylon)
MOD - C:\Program Files\TUTO4PC\tuto4pc_fr_5.exe () => Infection BT (Spyware.AgenceExclusive)
SRV - (Browser Manager) -- C:\Documents and Settings\All Users\Application Data\Browser Manager\2.3.811.154\{61d8b74e-8d89-46ff-afa6-33382c54ac73}\browsermngr.exe () => Infection BT (Toolbar.Babylon)
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} => Infection BT (Adware.IMBooster)
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" =
http://search.sweetim.com/search.asp?src=6&q={searchTerms}&st=6&barid={3DB08C29-1ABE-11E2-8804-801F023AF90B} => Infection BT (Adware.IMBooster)
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} => Infection BT (Toolbar.Babylon)
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" =
http://search.sweetim.com/search.asp?src=6&q={searchTerms}&st=6&barid={3DB08C29-1ABE-11E2-8804-801F023AF90B} => Infection BT (Adware.IMBooster)
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\Documents and Settings\All Users\Application Data\Browser Manager\2.3.811.154\{61d8b74e-8d89-46ff-afa6-33382c54ac73}\FirefoxExtension [2012/10/20 15:43: => Infection BT (Toolbar.Babylon)
[2012/10/20 15:43:50 | 000,000,000 | ---D | M] (Browser Manager) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\BROWSER MANAGER\2.3.811.154\{61D8B74E-8D89-46FF-AFA6-33382C54AC73}\FIREFOXEXTENSION => Infection BT (Toolbar.Babylon)
[2012/10/21 19:15:42 | 000,006,520 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml => Infection BT (Toolbar.Babylon)
O2 - BHO: (Browser Companion Helper) - {00cbb66b-1d3b-46d3-9577-323a336acb50} - C:\Program Files\BrowserCompanion\jsloader.dll ( ) => Infection PUP (PUP.Blabbers)
O2 - BHO: (Browser Companion Helper Verifier) - {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Program Files\BrowserCompanion\updatebhoWin32.dll ( ) => Infection PUP (PUP.Blabbers)
O4 - HKLM\..\Run: [Tutorials] C:\Program Files\TUTO4PC\tuto4pc_fr_5.exe () => Infection BT (Spyware.AgenceExclusive)
O4 - HKLM\..\Run: [upt4pc_fr_5.exe] C:\Documents and Settings\evelyne\Local Settings\Application Data\tuto4pc_fr_5\upt4pc_fr_5.exe () => Infection BT (Spyware.AgenceExclusive)
O18 - Protocol\Handler\base64 {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd) => Infection PUP (PUP.Blabbers)
O18 - Protocol\Handler\chrome {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd) => Infection PUP (PUP.Blabbers)
O18 - Protocol\Handler\prox {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd) => Infection PUP (PUP.Blabbers)
[2012/10/21 19:15:43 | 000,000,000 | ---D | C] -- C:\Program Files\BrowserCompanion => Infection PUP (PUP.Blabbers)
[2012/10/21 19:15:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\evelyne\Application Data\BrowserCompanion => Infection PUP (PUP.Blabbers)
[2012/10/20 15:59:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\evelyne\Application Data\OfferBox => Infection PUP (PUP.OfferBox)
[2012/10/20 15:45:21 | 000,000,000 | ---D | C] -- C:\Program Files\TUTO4PC => Infection BT (Spyware.AgenceExclusive)
[2012/10/20 15:43:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\evelyne\Application Data\Babylon => Infection BT (Toolbar.Babylon)
[2012/10/20 15:43:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Babylon => Infection BT (Toolbar.Babylon)
[2012/10/20 15:43:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Browser Manager => Infection BT (Toolbar.Babylon)
[2012/10/21 16:04:52 | 000,000,232 | ---- | M] () -- C:\Documents and Settings\evelyne\Bureau\Search the Web.url => Infection BT (Adware.IMBooster)
[2012/10/21 16:04:50 | 000,000,232 | ---- | C] () -- C:\Documents and Settings\evelyne\Bureau\Search the Web.url => Infection BT (Adware.IMBooster)
PRC - C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://searchfunmoods.com/?f=1&a=aed&ch ... 1482018643 IE - HKLM\..\SearchScopes\{2493729B-65B2-0FBD-3C7C-1DA3BB295408}: "URL" =
http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10019&barid={3DB08C29-1ABE-11E2-8804-801F023AF90B}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page =
http://www.claro-search.com/?affID=1145 ... 1f023af90b IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.claro-search.com/?affID=1152 ... 1f023af90b IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
http://www.claro-search.com/?q={searchTerms}&affID=115299&tt=4212_8&babsrc=SP_ss&mntrId=320d180e000000000000801f023af90b
IE - HKCU\..\SearchScopes\{2493729B-65B2-0FBD-3C7C-1DA3BB295408}: "URL" =
http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10019&barid={3DB08C29-1ABE-11E2-8804-801F023AF90B}
IE - HKCU\..\SearchScopes\{9D5BD211-422C-4164-9298-BB4186A30F31}: "URL" =
http://www.bing.com/search?q={searchTerms}&mkt=fr-FR&form=MKIE8P
FF - prefs.js..browser.search.selectedEngine: "Claro Search"
FF - prefs.js..browser.startup.homepage: "http://www.claro-search.com/?affID=115299&tt=4212_8&babsrc=HP_ss&mntrId=320d180e000000000000801f023af90b"
FF - prefs.js..browser.startup.homepage: "http://www.claro-search.com/?affID=114508&tt=4212_4&babsrc=HP_clro&mntrId=320d180e000000000000801f023af90b"
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "Claro Search"
FF - prefs.js..browser.search.defaulturl: ""
[2012/10/21 17:26:22 | 000,000,000 | ---D | M] (SweetPacks Toolbar for Firefox) -- C:\Documents and Settings\evelyne\Application Data\Mozilla\Firefox\Profiles\wttlw9mb.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2012/10/21 16:05:36 | 000,169,792 | ---- | M] () (No name found) -- C:\Documents and Settings\evelyne\Application Data\Mozilla\Firefox\Profiles\wttlw9mb.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
[2012/10/21 17:35:54 | 000,003,983 | ---- | M] () -- C:\Documents and Settings\evelyne\Application Data\Mozilla\Firefox\Profiles\wttlw9mb.default\searchplugins\sweetim.xml
CHR - default_search_provider: Claro Search (Enabled)
CHR - default_search_provider: search_url =
http://www.claro-search.com/?q={searchTerms}&affID=110824&tt=4212_4&babsrc=SP_ss&mntrId=320d180e000000000000801f023af90b
O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {D0F4A166-B8D4-48b8-9D63-80849FE137CB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM\..\Run: [] File not found
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKLM\..\Run: [Sweetpacks Communicator] C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe (SweetIM Technologies Ltd.)
[2012/10/20 15:58:35 | 000,000,000 | ---D | C] -- C:\Program Files\SweetIM
[2012/10/20 15:58:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SweetIM
[2012/10/20 15:45:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\evelyne\Local Settings\Application Data\tuto4pc_fr_5
:Commands
[emptytemp]
[createrestorepoint]