start ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File GroupPolicy: Group Policy on Chrome detected <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearc...r=906266600&ir= SearchScopes: HKLM - {09971cee-01b8-42bc-9d91-456b1faad6be} URL = SearchScopes: HKCU - {09971cee-01b8-42bc-9d91-456b1faad6be} URL = SearchScopes: HKCU - {0C1C81D1-8189-4912-A3D9-D4BFDBDF98B2} URL = SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL = SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = SearchScopes: HKCU - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = Toolbar: HKLM-x32 - No Name - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - No File Toolbar: HKCU - No Name - {D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU - No Name - {4DA729A4-684A-4034-A45B-6D56CEAAE92B} - No File Toolbar: HKCU - No Name - {8F2767F8-338A-4258-BD1C-4DE5A3D8CDB2} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - No Name - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - No File FF Plugin HKCU: bebomedia.com/OfferMosquitoIEHelper -> C:\Users\Owner\AppData\Local\ext_offermosquito\npOfferMosquitoIEHelper.dll (Bebo Media Ltd) C:\Users\Owner\AppData\Local\ext_offermosquito CHR HKLM-x32\...\Chrome\Extension: [cekmkdkefndbeciggfanobcemjnppbbb] - C:\Program Files (x86)\LessTabs\Chrome\cekmkdkefndbeciggfanobcemjnppbbb.crx [2013-12-19] C:\Program Files (x86)\LessTabs CHR HKLM-x32\...\Chrome\Extension: [cnpkmcjgpcihgfnkcjapiaabbbplkcmf] - C:\Program Files (x86)\Coupons.com CouponBar\chrome\Coupons.com.crx [2013-12-19] C:\Program Files (x86)\Coupons.com CouponBar CHR HKLM-x32\...\Chrome\Extension: [eijoglodfkeicibboibphapnoahoaapi] - C:\Users\Owner\AppData\Local\Temp\ccex.crx [2013-12-19] S2 Update ClearThink; "C:\Program Files (x86)\ClearThink\updateClearThink.exe" [X] C:\Program Files (x86)\ClearThink S0 CoEYThOp; System32\drivers\CoEYThOp.sys [X] S1 hlnfd; system32\drivers\hlnfd.sys [X] S1 qknfd; system32\drivers\qknfd.sys [X] Task: {01ACB253-0795-48F6-B0D1-1135D5FF01C0} - System32\Tasks\PC Optimizer Pro64 startups => C:\Program Files\PC Optimizer Pro\StartApps.exe <==== ATTENTION Task: {174DA027-CEF1-4EFC-91F4-CB5B04086F5E} - System32\Tasks\MySearchDial => C:\Users\Owner\AppData\Roaming\MySearchDial\UpdateProc\UpdateTask.exe <==== ATTENTION Task: {5E32A351-0279-49DA-8BD8-7D5B778F1DC6} - System32\Tasks\GoforFilesUpdate => C:\Program Files (x86)\GoforFiles\GFFUpdater.exe <==== ATTENTION Task: C:\Windows\Tasks\MySearchDial.job => C:\Users\Owner\AppData\Roaming\MySearchDial\UpdateProc\UpdateTask.exe <==== ATTENTION Task: C:\Windows\Tasks\PC Optimizer Pro64 startups.job => C:\Program Files\PC Optimizer Pro\StartApps.exe <==== ATTENTION HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-21-4193904827-2178084348-2157540247-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION! Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services" /F Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services" /F Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder" /F Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder" /F Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F C:\Users\Owner\AppData\Roaming\DataMgr C:\Users\Owner\AppData\Local\omesuperv.exe C:\Users\Owner\AppData\Roaming\SCheck C:\Users\Owner\AppData\Roaming\ShopAtHome C:\Users\Owner\AppData\Roaming\SSync reboot: end