PROCESSUS MALWARE (Rootkit, trojan, ver, spyware, adware,...)G2 - EXT: C:\Users\chezmoi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma [Quick start] =>PUP.QuickStart M3 - MFPP: Plugins - [chezmoi] -- C:\Users\chezmoi\AppData\Roaming\Mozilla\Firefox\Profiles\u5njgjx0.default\searchplugins\buenosearch.xml =>PUP.BuenoSearch M3 - MFPP: Plugins - [chezmoi] -- C:\Users\chezmoi\AppData\Roaming\Mozilla\Firefox\Profiles\u5njgjx0.default\searchplugins\Mysearchdial.xml =>Adware.MyWebSearch R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://start.mysearchdial.com =>Adware.MyWebSearch R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://start.mysearchdial.com =>Adware.MyWebSearch R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
http://start.mysearchdial.com =>Adware.MyWebSearch R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.awesomehp.com =>PUP.Awesomehp R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.awesomehp.com =>PUP.Awesomehp R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.awesomehp.com =>PUP.Awesomehp R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.awesomehp.com =>PUP.Awesomehp R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs =
http://start.mysearchdial.com =>Adware.MyWebSearch R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
http://www.awesomehp.com =>PUP.Awesomehp R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.awesomehp.com =>PUP.Awesomehp R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.awesomehp.com =>PUP.Awesomehp O4 - HKLM\..\Wow6432Node\Run: [fst_fr_101] Clé orpheline =>Adware.FreeSoftToday O4 - HKLM\..\Wow6432Node\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe (.not file.) =>PUP.Mobogenie O39 - APT: - (..) -- C:\Windows\Tasks\bench-sys.job [348] =>PUP.GiganticSavings O39 - APT: - (..) -- C:\Windows\System32\Tasks\bench-sys [348] =>PUP.GiganticSavings O39 - APT: - (..) -- C:\Windows\Tasks\bench-Updater removing.job [288] =>PUP.CrossRider O39 - APT: - (..) -- C:\Windows\System32\Tasks\bench-Updater removing [288] =>PUP.CrossRider [HKCU\Software\8D0FD7F210A29BB5F716CCC86AE61150] =>PUP.CrossRider [HKCU\Software\AnyProtect] =>PUP.AnyProtect [HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider [HKCU\Software\AppDataLow\Software\Re_markit] =>PUP.ReMarkIt [HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}] => PUP.OptimizerPro [HKCU\Software\BabSolution] =>Hijacker.BabSolution [HKCU\Software\InstallCore] =>Adware.InstallCore [HKCU\Software\SweetIM] =>PUP.SweetIM [HKCU\Software\TutoTag] =>PUP.AgenceExclusive [HKCU\Software\mysearchdial.com] =>Adware.MyWebSearch [HKLM\Software\Wow6432Node\Bench] =>PUP.GiganticSavings [HKLM\Software\Wow6432Node\SweetIM] =>PUP.SweetIM [HKLM\Software\Wow6432Node\Tutorials] =>PUP.AgenceExclusive [HKLM\Software\Wow6432Node\Wpm] =>PUP.WpManager [HKLM\Software\Wow6432Node\awesomehpSoftware] =>PUP.Awesomehp [HKLM\Software\Wow6432Node\free_soft_to_day] =>Adware.FreeSoftToday [HKLM\Software\Wow6432Node\supTab] =>PUP.SupTab [HKLM\Software\Wow6432Node\supWPM] =>PUP.WpManager O43 - CFD: 22.02.2014 - 14:41:53 - [] ----D C:\Program Files (x86)\Bench =>PUP.GiganticSavings O43 - CFD: 22.02.2014 - 14:27:33 - [0] ----D C:\Program Files (x86)\Optimizer Pro =>PUP.OptimizerPro O43 - CFD: 22.02.2014 - 14:34:15 - [0] ----D C:\Program Files (x86)\predm =>Adware.Downware O43 - CFD: 22.02.2014 - 14:42:43 - [] ----D C:\Program Files (x86)\SupTab =>PUP.SupTab O43 - CFD: 22.02.2014 - 14:31:20 - [] ----D C:\ProgramData\IePluginService =>PUP.IePluginService O43 - CFD: 22.02.2014 - 14:31:27 - [] ----D C:\ProgramData\WPM =>PUP.WpManager O43 - CFD: 22.02.2014 - 14:27:05 - [] ----D C:\Users\chezmoi\AppData\Roaming\awesomehp =>PUP.Awesomehp O43 - CFD: 22.12.2013 - 20:19:50 - [] ----D C:\Users\chezmoi\AppData\Roaming\BabSolution =>Hijacker.BabSolution O43 - CFD: 09.03.2011 - 20:27:40 - [] ----D C:\Users\chezmoi\AppData\Roaming\Download Manager => PUP.DownloadManager O43 - CFD: 07.04.2015 - 00:15:04 - [] ----D C:\Users\chezmoi\AppData\Roamingewnext.me =>PUP.NextLive O43 - CFD: 22.02.2014 - 13:45:00 - [] ----D C:\Users\chezmoi\AppData\Roaming\SupTab =>PUP.SupTab O43 - CFD: 29.01.2010 - 21:56:40 - [] ----D C:\Users\chezmoi\AppData\Local\Apps => PUP.Mysoftpack O43 - CFD: 22.02.2014 - 13:45:02 - [] ----D C:\Users\chezmoi\AppData\Local\genienext =>PUP.NextLive O43 - CFD: 06.04.2015 - 14:00:50 - [] ----D C:\Users\chezmoi\AppData\Local\Mobogenie =>PUP.Mobogenie O43 - CFD: 22.02.2014 - 13:41:31 - [] ----D C:\Users\chezmoi\AppData\Local\SearchProtect =>PUP.SearchProtect O61 - LFC: 06.04.2015 - 12:54:19 ---A- . (...) -- C:\Users\chezmoi\AppData\Roamingewnext.me\cache\spark.bin [649] =>PUP.NextLive O61 - LFC: 06.04.2015 - 12:54:21 ---A- . (.Enigma Software Group USA, LLC..) -- C:\Users\chezmoi\Downloads\SpyHunter-Installer.exe [3109248] =>PUP.EnigmaSoftware O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (...) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
http://www.awesomehp.com =>PUP.Awesomehp O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("browser.search.order.1", "Mysearchdial"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.crossrider.bic", "144596a13db3afd01b7d1c30974ee330"); =>PUP.CrossRider O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.AL", 2); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.aflt", "irmsd0202ff"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzutDtDtByCzy0EyE0CtA0DtDtDyDtC0D0FtN0D0Tzu0SyBzztAtN1L2XzutBtFtBtFtCyDtFtCy[...] =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.cntry", "FR"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.cr", "1166648247"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.dfltLng", ""); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.dfltSrch", true); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.dnsErr", true); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497[...] =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.excTlbr", false); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.hdrMd5", "A95B650335507BC5565C59BDD155FED5"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.hmpg", true); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.hmpgUrl", "
http://start.mysearchdial.com/?f=1&a=ir ... yCzy0EyE0C[...] =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.id", "00269E4C3D0051DF"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.instlDay", "16123"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.instlRef", ""); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.lastB", "
http://start.mysearchdial.com/?f=1&a=ir ... zy0EyE0CtA[...] =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.lastVrsnTs", "1.8.21.012:58:47"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.newTabUrl", "
http://start.mysearchdial.com/?f=2&a=ir ... tByCzy0EyE[...] =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"90\",\"lastVrsn\":\"90\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"s[...] =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.prdct", "mysearchdial"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.prtnrId", "mysearchdial"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.sg", "none"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.tlbrId", "base"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.tlbrSrchUrl", "
http://start.mysearchdial.com/?f=3&a=ir ... tDtByCzy0E[...] =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.vrsn", "1.8.21.0"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial.vrsni", "1.8.21.0"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial_i.hmpg", true); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial_i.newTab", false); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial_i.smplGrp", "none"); =>Adware.MyWebSearch O69 - SBI: prefs.js [chezmoi - u5njgjx0.default] user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.012:58:47"); =>Adware.MyWebSearch O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} - (Bueno Search) -
http://www.buenosearch.com =>PUP.BuenoSearch O69 - SBI: SearchScopes [HKCU] {33BB0A4E-99AF-4226-BDF6-49120163DE86} - (Mysearchdial) -
http://start.mysearchdial.com =>Adware.MyWebSearch O69 - SBI: SearchScopes [HKCU] {77AA745B-F4F8-45DA-9B14-61D2D95054C8} - (awesomehp) -
http://www.awesomehp.com =>PUP.Awesomehp HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BabMaint_RASAPI32 =>Hijacker.BabSolution HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BabMaint_RASMANCS =>Hijacker.BabSolution HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Babylon_RASAPI32 =>PUP.Babylon HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Babylon_RASMANCS =>PUP.Babylon HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BringStarSetup_RASAPI32 =>PUP.BringStar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BringStarSetup_RASMANCS =>PUP.BringStar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BringStar_RASAPI32 =>PUP.BringStar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BringStar_RASMANCS =>PUP.BringStar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BringStar_Setup_RASAPI32 =>PUP.BringStar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BringStar_Setup_RASMANCS =>PUP.BringStar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FindRightSetup_RASAPI32 =>Hijacker.FindrToolbar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FindRightSetup_RASMANCS =>Hijacker.FindrToolbar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FindRight_RASAPI32 =>Hijacker.FindrToolbar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FindRight_RASMANCS =>Hijacker.FindrToolbar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FindRight_Setup_RASAPI32 =>Hijacker.FindrToolbar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\FindRight_Setup_RASMANCS =>Hijacker.FindrToolbar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\HQ-Video-Profession-1_RASAPI32 =>PUP.CrossRider HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\HQ-Video-Profession-1_RASMANCS =>PUP.CrossRider HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\InternetUpdaterService_RASAPI32 =>PUP.InternetUpdater HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\InternetUpdaterService_RASMANCS =>PUP.InternetUpdater HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MediaPlayerEnhance-chromeinstaller_RASAPI32 =>PUP.MediaPlayerEnhance HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MediaPlayerEnhance-chromeinstaller_RASMANCS =>PUP.MediaPlayerEnhance HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MediaPlayerEnhance-codedownloader_RASAPI32 =>PUP.MediaPlayerEnhance HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MediaPlayerEnhance-codedownloader_RASMANCS =>PUP.MediaPlayerEnhance HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MediaPlayerEnhance-enabler_RASAPI32 =>PUP.MediaPlayerEnhance HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MediaPlayerEnhance-enabler_RASMANCS =>PUP.MediaPlayerEnhance HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MediaPlayerEnhance-firefoxinstaller_RASAPI32 =>PUP.MediaPlayerEnhance HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MediaPlayerEnhance-firefoxinstaller_RASMANCS =>PUP.MediaPlayerEnhance HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MediaPlayerEnhance-updater_RASAPI32 =>PUP.MediaPlayerEnhance HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MediaPlayerEnhance-updater_RASMANCS =>PUP.MediaPlayerEnhance HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Mobogenie_RASAPI32 =>PUP.Mobogenie HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\Mobogenie_RASMANCS =>PUP.Mobogenie HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MySearchDial_RASAPI32 =>Adware.MyWebSearch HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MySearchDial_RASMANCS =>Adware.MyWebSearch HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MYSEAR~1_RASAPI32 =>Adware.MyWebSearch HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\MYSEAR~1_RASMANCS =>Adware.MyWebSearch HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\NewPlayer_RASAPI32 =>Adware.NewPlayer HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\NewPlayer_RASMANCS =>Adware.NewPlayer HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\OptimizerPro_RASAPI32 =>PUP.OptimizerPro HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\OptimizerPro_RASMANCS =>PUP.OptimizerPro HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\OptProStart_RASAPI32 =>PUP.OptimizerPro HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\OptProStart_RASMANCS =>PUP.OptimizerPro HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\predm_RASAPI32 =>Adware.Downware HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\predm_RASMANCS =>Adware.Downware HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SupTab_RASAPI32 =>PUP.SupTab HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\SupTab_RASMANCS =>PUP.SupTab HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateBringStar_RASAPI32 =>PUP.BringStar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateBringStar_RASMANCS =>PUP.BringStar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateFindRight_RASAPI32 =>Hijacker.FindrToolbar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\updateFindRight_RASMANCS =>Hijacker.FindrToolbar HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\upfst_fr_101_RASAPI32 =>Adware.FreeSoftToday HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\upfst_fr_101_RASMANCS =>Adware.FreeSoftToday HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\VOPackage_RASAPI32 =>Adware.Downware HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\VOPackage_RASMANCS =>Adware.Downware HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\wpm_RASAPI32 =>PUP.WpManager HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\wpm_RASMANCS =>PUP.WpManager [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}] =>PUP.Babylon [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software [HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] =>PUP.V9Software [HKLM\Software\Classes\Prod.cap] =>PUP.ClaroSearch [HKLM\Software\Wow6432Node\Microsoft\Tracing\optimizerpro_RASMANCS] =>PUP.OptimizerPro [HKLM\Software\Wow6432Node\Microsoft\Tracing\optimizerpro_RASAPI32] =>PUP.OptimizerPro [HKLM\Software\Wow6432Node\Microsoft\Tracing\Mobogenie_RASMANCS] =>PUP.Mobogenie [HKCU\Software\SweetIM] =>PUP.SweetIM [HKLM\Software\Wow6432Node\SweetIM] =>PUP.SweetIM [HKLM\Software\Wow6432Node\Tutorials] =>Spyware.AgenceExclusive [HKLM\Software\Wow6432Node\Microsoft\Tracing\Babylon_RASAPI32] =>PUP.Babylon [HKLM\Software\Wow6432Node\Microsoft\Tracing\Babylon_RASMANCS] =>PUP.Babylon [HKLM\Software\Wow6432Node\Microsoft\Tracing\optprostart_RASMANCS] =>PUP.OptimizerPro [HKLM\Software\Wow6432Node\Microsoft\Tracing\optprostart_RASAPI32] =>PUP.OptimizerPro [HKLM\Software\Wow6432Node\Microsoft\Tracing\Mobogenie_RASAPI32] =>PUP.Mobogenie [HKCU\Software\InstallCore] =>Adware.InstallCore [HKLM\Software\Classes\AppID\{6536801B-F50C-449B-9476-093DFD3789E3}] =>PUP.Babylon [HKLM\Software\Wow6432Node\Classes\AppID\{6536801B-F50C-449B-9476-093DFD3789E3}] =>PUP.Babylon [HKCU\Software\AppDataLow\Software\Crossrider] =>PUP.CrossRider [HKLM\Software\Classes\AppID\BabylonHelper.EXE] =>PUP.Babylon [HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro [HKLM\Software\Wow6432Node\{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:fst_fr_101 =>Adware.FreeSoftToday^ C:\Program Files (x86)\Bench =>PUP.GiganticSavings^ C:\Program Files (x86)\Optimizer Pro =>PUP.OptimizerPro^ C:\Program Files (x86)\predm =>Adware.Downware^ C:\Program Files (x86)\SupTab =>PUP.SupTab^ C:\ProgramData\IePluginService =>PUP.IePluginService^ C:\ProgramData\WPM =>PUP.WpManager^ C:\Users\chezmoi\AppData\Roaming\awesomehp =>PUP.Awesomehp^ C:\Users\chezmoi\AppData\Roaming\BabSolution =>Hijacker.BabSolution^ C:\Users\chezmoi\AppData\Roamingewnext.me =>PUP.NextLive^ C:\Users\chezmoi\AppData\Roaming\SupTab =>PUP.SupTab^ C:\Users\chezmoi\AppData\Local\genienext =>PUP.NextLive^ C:\Users\chezmoi\AppData\Local\Mobogenie =>PUP.Mobogenie^ C:\Users\chezmoi\AppData\Local\SearchProtect =>PUP.SearchProtect^ C:\Windows\Tasks\bench-sys.job =>PUP.GiganticSavings^ C:\Windows\System32\Tasks\bench-sys =>PUP.GiganticSavings^ C:\Windows\Tasks\bench-Updater removing.job =>PUP.CrossRider^ C:\Windows\System32\Tasks\bench-Updater removing =>PUP.CrossRider^ [HKCU\Software\8D0FD7F210A29BB5F716CCC86AE61150] =>PUP.CrossRider^ [HKCU\Software\AnyProtect] =>PUP.AnyProtect^ [HKCU\Software\AppDataLow\Software\Re_markit] =>PUP.ReMarkIt^ [HKCU\Software\BabSolution] =>Hijacker.BabSolution^ [HKCU\Software\TutoTag] =>PUP.AgenceExclusive^ [HKCU\Software\mysearchdial.com] =>Adware.MyWebSearch^ [HKLM\Software\Wow6432Node\Bench] =>PUP.GiganticSavings^ [HKLM\Software\Wow6432Node\Wpm] =>PUP.WpManager^ [HKLM\Software\Wow6432Node\awesomehpSoftware] =>PUP.Awesomehp^ [HKLM\Software\Wow6432Node\free_soft_to_day] =>Adware.FreeSoftToday^ [HKLM\Software\Wow6432Node\supTab] =>PUP.SupTab^ [HKLM\Software\Wow6432Node\supWPM] =>PUP.WpManager^ C:\Users\chezmoi\AppData\Local\Temp\uninst1.exe =>PUP.Babylon C:\Users\chezmoi\AppData\Local\Temp\GUninstaller.exe =>PUP.Babylon