O2 - BHO: BHO - {47B614AF-B4CC-485B-B331-BE26F02ED4CC} . (.APC - Browser Helper Object.) -- C:\Program Files\Internet Explorer\IEAddon.dll => Infection PUP (Toolbar.Babylon)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} ((no name)) -
http://ak.exe.imgfarm.com/images/nocach ... .0.1.1.cab =Adware.MyWebSearch
[MD5.F498F9A6044DE57744BD465662E6AD77] [APT] [BHO updater] (...) -- C:\Program Files\Internet Explorer\Updater.exe [117760] = Infection PUP (Toolbar.Babylon)
O42 - Logiciel: Browser Helper Object - (.APC Soft.) [HKLM] -- Browser Helper Object1.4 = Toolbar.Babylon
O43 - CFD: 15/02/2013 - 15:01:32 - [2,258] ----D C:\Program Files\Browser Helper Object = Toolbar.Babylon
O87 - FAEL: "{8005EA5A-D26C-42D6-A77B-03FE8E88471C}" |In - Public - P6 - TRUE | .(...) -- C:\Program Files\Moovida\moovida.exe (.not file.) =Adware.SPointer
O87 - FAEL: "{F1E5EE96-F11F-4B55-A436-180024E2B3AE}" |In - Public - P17 - TRUE | .(...) -- C:\Program Files\Moovida\moovida.exe (.not file.) =Adware.SPointer
O90 - PUC: "9FEB8FB96CD4CF54A95AB4311193C2DA" . (.Boxore Client.) -- C:\windows\Installer\{9BF8BEF9-4DC6-45FC-9AA5-4B1311392CAD}\boxore.ico =Adware.Boxore
[MD5.B37035B11B94C6D1865C09834976143F] [WIS][11/04/2010] (.Secure Digital Services - Moovida, your choice for faster, easier downloading!.) -- C:\Windows\Installer\182e9f.msi [2192384] =Adware.SPointer
[HKLM\Software\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}] =Adware.MyWebSearch
[HKLM\SOFTWARE\SOFTWARE\UPDATE\CLIENTS\{5B54E9B6-D6C4-11E0-8E9D-92FB4824019B}] =Adware.Boxore
[HKLM\Software\Classes\Installer\Features\9FEB8FB96CD4CF54A95AB4311193C2DA] =Adware.Boxore
[HKLM\Software\Classes\Installer\Products\9FEB8FB96CD4CF54A95AB4311193C2DA] =Adware.Boxore
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9FEB8FB96CD4CF54A95AB4311193C2DA] =Adware.Boxore
[HKLM\Software\Google\Chrome\Extensions\kkkeikdkpjenmoiicggnnodbkebafgpc] =Toolbar.Babylon
[HKCU\Software\Microsoft\Installer\Features\112C48061A10E464790A9077E221B205] =Adware.SPointer
[HKCU\Software\Microsoft\Installer\Products\112C48061A10E464790A9077E221B205] =Adware.SPointer
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{47B614AF-B4CC-485B-B331-BE26F02ED4CC}] =Toolbar.Babylon
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{47B614AF-B4CC-485B-B331-BE26F02ED4CC}] =Toolbar.Babylon
[HKLM\Software\Classes\CLSID\{47B614AF-B4CC-485B-B331-BE26F02ED4CC}] =Toolbar.Babylon
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{47B614AF-B4CC-485B-B331-BE26F02ED4CC}] =Toolbar.Babylon
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Browser Helper Object1.4] =Toolbar.Babylon
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\464AA55239C100F32AF2D438EDDC0F47] =Adware.IMBooster
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5652BA3D5FB98AE31B337BF0AF939856] =Adware.IMBooster
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EB95E1AFCBABE3DB9ECCC669B99494] =Adware.IMBooster
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\38D5CDD0A851B3940A43CC50ABBA251C] =Adware.Boxore^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BA71D41F6CC0B6247B05D473850A8AEA] =Adware.Boxore^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] =Adware.Boxore^
C:\Program Files\Browser Helper Object =Toolbar.Babylon
C:\windows\Installer\{9BF8BEF9-4DC6-45FC-9AA5-4B1311392CAD}\boxore.ico =Adware.Boxore^
C:\Windows\Installer\182e9f.msi =Adware.SPointer^
C:\Program Files\Internet Explorer\cr_addon.crx =Toolbar.Babylon
[MD5.3F1E3E140B8B313C17DE7DF6AE6931C2] - (.Yahoo! Inc. - Yahoo! Messenger Tray.) -- C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe [79160] [PID.4240] =Toolbar.Yahoo
P2 - FPN: [HKLM] [@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6] - (.Yahoo! Inc. - Yahoo Application State Plugin version 1.0.0.7.) -- C:\Program Files\Yahoo!\Shared\npYState.dll =Toolbar.Yahoo
R3 - URLSearchHook: (no name) - {90b49673-5506-483e-b92b-ca0265bd9ca8} . (.Pas de propriétaire - Provides additional functionality on Facebook. See Toolbar.Yahoo
O87 - FAEL: "{7982640F-0C8B-4066-9E1E-4887D4552AC8}" | In - Public - P17 - TRUE | .(.Yahoo! Inc. - Yahoo! Messenger.) -- C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe =Toolbar.Yahoo
SR - | Auto 09/11/2008 602392 | (YahooAUService) . (.Yahoo! Inc..) - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe =Toolbar.Yahoo
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Messenger] =Toolbar.Yahoo^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Software Update] =Toolbar.Yahoo^
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:Messenger (Yahoo!) =Toolbar.Yahoo^
C:\Program Files\Yahoo! =Toolbar.Yahoo^
C:\ProgramData\Yahoo! =Toolbar.Yahoo^
C:\Users\utilisateur\AppData\Roaming\Yahoo! =Toolbar.Yahoo^
C:\Users\utilisateur\AppData\Local\Yahoo =Toolbar.Yahoo^
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe =Toolbar.Yahoo^
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe =Toolbar.Google^
C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll =Toolbar.Google^
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe =Toolbar.Yahoo^
[HKCU\Software\AppDataLow\Software\Yahoo] =Toolbar.Yahoo^
[HKCU\Software\Yahoo] =Toolbar.Yahoo^
[HKLM\Software\Yahoo] =Toolbar.Yahoo^
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe =Toolbar.Yahoo^
[MD5.00000000000000000000000000000000] [APT] [{7B13AF33-2A99-480A-A6C8-03D43C4B888C}] (...) -- C:\Program Files\Gallimard\Pays des nombres\PAYSNOMB.exe (.not file.) [0] = Fichier absent
[MD5.00000000000000000000000000000000] [APT] [{93B06E83-6269-4787-BAEB-D31035C03B55}] (...) -- C:\Program Files\Gallimard\Pays des nombres\PAYSNOMB.exe (.not file.) [0] = Fichier absent
[MD5.00000000000000000000000000000000] [APT] [{9837EBDC-B69D-4AC4-8866-C2EAC3F9C36C}] (...) -- C:\Program Files\Gallimard\Pays des nombres\PAYSNOMB.exe (.not file.) [0] = Fichier absent
[MD5.00000000000000000000000000000000] [APT] [{9862A7D6-FB15-4251-9B0F-F503B2648337}] (...) -- C:\Program Files\Gallimard\Pays des nombres\PAYSNOMB.exe (.not file.) [0] = Fichier absent
[MD5.00000000000000000000000000000000] [APT] [{B366FE57-8FD3-482B-B215-76E145358132}] (...) -- E:\DEMOPL.exe (.not file.) [0] = Fichier absent
[MD5.00000000000000000000000000000000] [APT] [{D8205036-92A0-4271-8B25-2E74A4BCD887}] (...) -- C:\Program Files\Gallimard\Pays des nombres\PAYSNOMB.exe (.not file.) [0] = Fichier absent
[MD5.00000000000000000000000000000000] [APT] [{FE191C7E-81F9-41D8-9211-96EEB9795F93}] (...) -- D:\Desktop\OOo_3.2.0_Win32Intel_install_wJRE_fr.exe (.not file.) [0] = Fichier absent
O43 - CFD: 19/10/2012 - 09:12:25 - [0] ----D C:\Users\utilisateur\AppData\Local\VHS to DVD = Empty Folder not necessary
O61 - LFC: 05/09/2013 - 11:03:40 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\wmplog04.sqm [1184] = Temporary file not necessary
O61 - LFC: 05/09/2013 - 11:04:14 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\wmplog05.sqm [1184] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 03:49:11 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\jrt\STATS_clsid.dat [1518] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 03:49:12 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\jrt\SETTINGS_clsid.dat [1478] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 03:49:14 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\jrt\INTERFACE_clsid.dat [5038] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 03:49:43 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\jrt\BHO_name.dat [1032] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 03:50:05 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\jrt\CHR_extensions.cfg [5812] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 03:58:47 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\jrt\REGhkcu_and_hklm_software.cfg [3189] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 03:59:05 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\jrt\REGhkcu_software_appdatalow.cfg [2910] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 03:59:27 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\jrt\badFOLDERS.cfg [16522] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 04:01:06 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\jrt\get.bat [16063] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 04:01:23 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\jrt\JRT.bat [10261] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 04:01:28 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\jrt\currentmd5.txt [13] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 04:02:12 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\jrt\misc.bat [144210] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 04:03:03 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\jrt\services.dat [2596] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 04:33:00 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\jrt\newmd5.txt [13] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 13:32:05 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\~DF582745489200FD9A.TMP [409600] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 14:21:13 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\chart_data.dat [20762] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 19:07:26 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\Skype\DbTemp\temp-SR52CpBlprHDQDBUFy8X3Vbg [0] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 19:07:42 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\Skype\DbTemp\temp-kGtKVsMXPwsVr2V4kIfcuc6a [0] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 20:25:04 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\JRT.txt [41928] = Temporary file not necessary
O61 - LFC: 06/09/2013 - 20:25:04 ---A- . (...) -- C:\Users\utilisateur\AppData\Local\Temp\jrt\temp\null.txt [0] = Temporary file not necessary
[MD5.CF57E8B0CBE301EE29A41C92C44D5BF4] [SPRF][06/09/2013] (...) -- C:\Users\utilisateur\AppData\Local\Temp\chart_data.dat [20762] = Temporary file not necessary
[MD5.2A00675C8B0105BF938F22DAA5FC9B79] [SPRF][01/09/2013] (...) -- C:\Users\utilisateur\AppData\Local\Temp\Quarantine.exe [344507] = Temporary file not necessary
[MD5.46E2D72A986DCEF5B2827311E3B5C2EC] [SPRF][15/01/2009] (.Kiwee - Installer Control.) -- C:\Windows\Downloaded Program Files\InstallerControl.dll [204800]
O87 - FAEL: "{32793C61-E5A9-48DB-8195-9B3A338FC21D}" |In - Public - P6 - TRUE | .(...) -- C:\Users\utilisateur\AppData\Local\Temp\7zSA87E.tmp\SymNRT.exe (.not file.) = Fichier absent
O87 - FAEL: "{030EA286-0556-476A-A8FC-B2B0A1AF2780}" |In - Public - P17 - TRUE | .(...) -- C:\Users\utilisateur\AppData\Local\Temp\7zSA87E.tmp\SymNRT.exe (.not file.) = Fichier absent
O87 - FAEL: "{5064F6F2-F9CD-4DFB-951A-664AE1E72F0F}" |In - Public - P6 - TRUE | .(...) -- E:\fscommand\CKSocketServer.exe (.not file.) = Fichier absent
O87 - FAEL: "{D385E69B-94A7-4B55-879B-AD00F3C5158A}" |In - Public - P17 - TRUE | .(...) -- E:\fscommand\CKSocketServer.exe (.not file.) = Fichier absent
EmptyTemp
EmptyFlash
EmptyCLSID
SysRestore