CloseProcesses: HKU\S-1-5-21-1862850717-2673517611-151062465-1000\...\Run: [TTWeather] => "C:\Program Files (x86)\TTWeather\TTWeather.exe" /autorun HKU\S-1-5-21-1862850717-2673517611-151062465-1000\...\Run: [weatherTips] => "C:\Program Files (x86)\TTWeather\weatherTips.exe" /autorun C:\Program Files (x86)\TTWeather HKU\S-1-5-21-1862850717-2673517611-151062465-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [TTWeather] => "C:\Program Files (x86)\TTWeather\TTWeather.exe" /autorun HKU\S-1-5-21-1862850717-2673517611-151062465-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [weatherTips] => "C:\Program Files (x86)\TTWeather\weatherTips.exe" /autorun ShellIconOverlayIdentifiers: [DownloadIcon] -> {A8502600-B272-4F68-A67B-A0305D46D298} => C:\ProgramData\QvodPlayer\QvodExtend\5.0.100.0\QvodExtend_x64.dll (Shenzhen QVOD Technology Co.,Ltd) ShellIconOverlayIdentifiers: [FunOverlay] -> {A5662DF9-0C2E-4A56-9FE1-BACFF6966D88} => C:\Users\Public\Fundata\Sniper.dll (Funshion) C:\Users\Public\Fundata ShellIconOverlayIdentifiers-x32: [DownloadIcon] -> {A8502600-B272-4F68-A67B-A0305D46D297} => No File BHO: ѸÀ×ÏÂÔØÖ§³Ö -> {004B0726-A010-4ABF-8556-FCDB7F1FCA1E} -> G:\Program Files (x86)\Thunder Network\Thunder\BHO\XunleiBHO647.9.17.4698.dll (?????????????) BHO: QvodExtend -> {A8502600-B272-4F68-A67B-A0305D46D298} -> C:\ProgramData\QvodPlayer\QvodExtend\5.0.100.0\QvodExtend_x64.dll (Shenzhen QVOD Technology Co.,Ltd) BHO-x32: No Name -> {A8502600-B272-4F68-A67B-A0305D46D297} -> No File BHO-x32: ѸÀ×ÏÂÔØÖ§³Ö×é¼þ -> {DE05CF4A-7B0A-4775-B5E5-396244938679} -> G:\Program Files (x86)\Thunder Network\Thunder\Thunder BHO Platform\np_tdieplat.dll (?????????????) Task: {34D413E4-D766-4BDA-B745-27BBC45EF976} - System32\Tasks\Funshion\FSPlatform => C:\Users\zenny\funshion\funshiontools\FSPAP.exe Task: {8164D5A8-FC39-4E74-BDFF-02FF7923793B} - System32\Tasks\Trojan Killer => C:\Program Files\GridinSoft Trojan Killer\trojankiller.exe C:\ProgramData\QvodPlayer\ C:\Program Files (x86)\Elex-tech\ 2014-10-08 20:43 - 2014-10-08 20:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAC Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File FF Plugin: @qvod.com/QvodShare -> C:\Program Files (x86)\QvodPlayer\npShareModule_x64.dll No File FF Plugin-x32: @funshion.com/npFunshion -> C:\Users\zenny\funshion\funshiontools\npFunshion.dll No File R1 iSafeKrnl; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [248488 2014-10-08] (Elex do Brasil Participações Ltda) S3 iSafeKrnlBoot; C:\Windows\System32\DRIVERS\iSafeKrnlBoot.sys [45224 2014-10-08] (Elex do Brasil Participações Ltda) R1 iSafeKrnlKit; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [99496 2014-10-08] (Elex do Brasil Participações Ltda) R1 iSafeKrnlR3; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [65704 2014-10-08] (Elex do Brasil Participações Ltda) R1 iSafeNetFilter; C:\Windows\System32\DRIVERS\iSafeNetFilter.sys [49320 2014-09-22] (Elex do Brasil Participações Ltda) S3 gdrv; \??\C:\Windows\gdrv.sys [X] 2014-10-08 20:43 - 2014-10-08 20:43 - 00001902 _____ () C:\Users\Public\Desktop\YAC.lnk 2014-10-08 20:43 - 2014-10-08 20:43 - 00000000 ____D () C:\Users\zenny\AppData\Roaming\Elex-tech 2014-10-08 20:43 - 2014-10-08 18:15 - 00045224 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeKrnlBoot.sys 2014-10-08 20:43 - 2014-09-22 20:13 - 00049320 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeNetFilter.sys 2014-10-08 20:42 - 2014-10-08 20:43 - 15578360 _____ (Elex do Brasil Participações Ltda) C:\Users\zenny\Downloads\yet_another_cleaner_sk_42159.exe 2014-10-07 23:07 - 2014-10-07 23:07 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\zenny\Downloads\SpyHunter-Installer.exe 2014-10-07 22:07 - 2014-10-07 22:07 - 00003246 _____ () C:\Windows\System32\Tasks\Trojan Killer 2014-10-07 22:07 - 2014-10-07 22:07 - 00000000 ____D () C:\ProgramData\GridinSoft 2014-10-07 22:03 - 2014-10-07 22:03 - 03026176 _____ (GridinSoft) C:\Users\zenny\Downloads\TrojanKillerInstallerST.exe 2014-10-07 21:01 - 2014-07-15 21:10 - 00000000 ____D () C:\Users\zenny\AppData\Roaming\Funshion Task: {0BC733EC-2832-437B-A431-73A050CCB409} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {550674DA-B8B2-46EC-98DB-11B67D48B380} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {CBE63109-1989-476A-A426-9AB892308410} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe C:\Program Files (x86)\Spybot - Search & Destroy 2 HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] BootExecute: autocheck autochk * sdnclean64.exe 2014-10-07 23:38 - 2014-10-07 23:38 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-10-07 23:37 - 2014-10-07 23:37 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk 2014-10-07 23:37 - 2014-10-07 23:37 - 00001379 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2014-10-07 23:37 - 2014-10-07 23:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2 2014-10-07 23:36 - 2014-10-08 00:32 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-10-07 23:36 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe 2014-10-07 23:30 - 2014-10-07 23:32 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\zenny\Downloads\spybot-2.4.exe EmptyTemp: