start CloseProcesses: (Crawler Group) C:\Program Files (x86)\Spyware Clear\SC_svc64.exe (Crawler Group) C:\Program Files (x86)\Spyware Clear\SpywareClearShield.exe (Crawler Group) C:\Program Files (x86)\Spyware Clear\SpywareClearUpdate.exe HKLM\...\Run: [SpywareClearShield] => C:\Program Files (x86)\Spyware Clear\SpywareClearShield.exe [3742528 2015-01-27] (Crawler Group) HKLM\...\Run: [SpywareClearUpdater] => C:\Program Files (x86)\Spyware Clear\SpywareClearUpdate.exe [5412672 2015-01-27] (Crawler Group) AppInit_DLLs-x32: c:/progra~3/{d5963~1/171~1.0/rero.dll => c:/progra~3/{d5963~1/171~1.0/rero.dll [649216 2014-12-29] () c:/progra~3/{d5963~1/171~1.0/rero.dll CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = SearchScopes: HKLM-x32 -> {a5b9c0f5-5616-47cd-a95f-e43b488faccf} URL = http://search.tb.ask...or={searchTerms} SearchScopes: HKU\S-1-5-21-3365291103-1794807868-2818468661-1002 -> DefaultScope {7E9DCF03-E64E-4120-9F3C-E9D84FEA99B5} URL = http://Vosteran.com/...cr=997972564= SearchScopes: HKU\S-1-5-21-3365291103-1794807868-2818468661-1002 -> {7E9DCF03-E64E-4120-9F3C-E9D84FEA99B5} URL = http://Vosteran.com/...cr=997972564= SearchScopes: HKU\S-1-5-21-3365291103-1794807868-2818468661-1002 -> {992944B5-B08C-4A85-98D6-A23E761F2CB9} URL = http://search.xfinit...&q={searchTerms} SearchScopes: HKU\S-1-5-21-3365291103-1794807868-2818468661-1002 -> {a5b9c0f5-5616-47cd-a95f-e43b488faccf} URL = http://search.tb.ask...or={searchTerms} SearchScopes: HKU\S-1-5-21-3365291103-1794807868-2818468661-1002 -> {B3AF8F1B-394B-4EBC-98F7-D8E92907B5E9} URL = http://www.search.as...rms}&psv=&pt=tb S4 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166296 2014-11-24] () [File not signed] C:\Program Files (x86)\AskPartnerNetwork R2 SC_Svc; C:\Program Files (x86)\Spyware Clear\SC_svc64.exe [3006784 2015-01-27] (Crawler Group) 2015-01-22 19:17 - 2015-01-22 19:17 - 00000000 ____D () C:\b4dcf5a746554ecec026cd3ae5 2015-01-17 09:11 - 2015-01-17 09:11 - 00000000 ____D () C:\ProgramData\1078601655 2015-01-01 21:19 - 2015-01-01 21:25 - 00161717 _____ () C:\Users\consuella\Downloads\SkypeSetup.exe.coe3bjc.partial 2014-12-29 17:09 - 2014-12-29 17:09 - 00000000 ____D () C:\Users\consuella\Documents\Optimizer Pro 2014-12-29 17:04 - 2015-01-27 20:04 - 00000318 _____ () C:\Windows\Tasks\UpdaterEX.job 2014-12-29 17:04 - 2015-01-27 15:40 - 00000000 ____D () C:\ProgramData\Spyware Clear 2014-12-29 17:04 - 2015-01-15 13:27 - 00000000 ____D () C:\Users\consuella\AppData\Roaming\UpdaterEX 2014-12-29 17:04 - 2014-12-29 17:04 - 00002656 _____ () C:\Windows\System32\Tasks\UpdaterEX 2014-12-29 17:04 - 2014-12-29 17:04 - 00000000 ____D () C:\Users\consuella\AppData\Roaming\Spyware Clear 2014-12-29 17:04 - 2014-12-29 17:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Clear with PC Tech Hotline 2014-12-29 17:02 - 2015-01-27 16:22 - 00000000 ____D () C:\Program Files (x86)\Spyware Clear C:\Program Files (x86)\Spyware Clear Search App by Ask (HKLM-x32\...\{4F524A2D-5350-4500-76A7-A758B70C1500}) (Version: 12.21.0.114 - APN, LLC) <==== ATTENTION Spyware Clear with PC Tech Hotline (HKLM-x32\...\{5FB600FF-BC65-471F-A3F8-C2666863BA75}_is1) (Version: 1.3.0.27 - Crawler Group) Task: {06C72C2A-A6B3-4BDB-AD78-56C583D8CFC1} - System32\Tasks\UpdaterEX => C:\Users\CONSUE~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\UpdaterEX.job => C:\Users\CONSUE~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" EmptyTemp: CMD: bitsadmin /reset /allusers Reboot: end