CloseProcesses: CreateRestorePoint: HKLM\...\Run: [] => [X] HKU\S-1-5-21-1494171341-1486453739-2533022584-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize C:\Program Files (x86)\Lavasoft\Web Companion HKLM\...\Policies\Explorer: [HideSCAHealth] 1 HKU\S-1-5-21-1494171341-1486453739-2533022584-1001\...\Policies\Explorer: [HideSCAHealth] 1 HKU\S-1-5-21-1494171341-1486453739-2533022584-1001\...\MountPoints2: {38078d4b-a1e0-11dd-a8e4-88ae1d490acc} - E:\Autorun.exe HKU\S-1-5-21-1494171341-1486453739-2533022584-1001\...\MountPoints2: {40721f25-9dcd-11dd-8a6f-88ae1d490acc} - E:\MotorolaDeviceManagerSetup.exe -a AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found C:\PROGRA~2\SupTab AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => "C:\PROGRA~2\SupTab\SEARCH~1.DLL" File Not Found ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = SearchScopes: HKLM -> DefaultScope {D19EE6DA-2378-4E89-A48A-509CB5EB910D} URL = http://Vosteran.com/...r=541885164&ir= SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-s...p={searchTerms} SearchScopes: HKLM -> {D19EE6DA-2378-4E89-A48A-509CB5EB910D} URL = http://Vosteran.com/...r=541885164&ir= SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = http://Vosteran.com/...=1003046661&ir= SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-s...p={searchTerms} SearchScopes: HKU\.DEFAULT -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = SearchScopes: HKU\S-1-5-21-1494171341-1486453739-2533022584-1001 -> C21C9A5F607F44EF983234E68BA51160 URL = SearchScopes: HKU\S-1-5-21-1494171341-1486453739-2533022584-1001 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-s...p={searchTerms} SearchScopes: HKU\S-1-5-21-1494171341-1486453739-2533022584-1001 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = BHO-x32: No Name -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> No File BHO-x32: No Name -> {BFE4B5CB-63F7-4A51-9266-6167655D5B4F} -> No File BHO-x32: No Name -> {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} -> No File Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM-x32 - No Name - {b278d9f8-0fa9-465e-9938-0c392605d8e3} - No File Toolbar: HKU\S-1-5-21-1494171341-1486453739-2533022584-1001 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKU\S-1-5-21-1494171341-1486453739-2533022584-1001 -> No Name - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File Toolbar: HKU\S-1-5-21-1494171341-1486453739-2533022584-1001 -> No Name - {30F9B915-B755-4826-820B-08FBA6BD249D} - No File FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safesearch.xml FF Extension: Perfect Redirector - C:\Users\Bridget\AppData\Roaming\Mozilla\Firefox\Profiles\avb5pwdi.default\Extensions\{4B797F68-9C25-4926-8959-728E54D7B699}.xpi [2015-02-13] FF HKLM-x32\...\Firefox\Extensions: [{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}] - C:\Program Files (x86)\RelevantKnowledge\firefox C:\Program Files (x86)\RelevantKnowledge CHR HKLM\...\Chrome\Extension: [iagcajndpnfncplednpbnkahadegklfa] - C:\Users\Bridget\AppData\Local\speedial.crx [2008-05-22] CHR HKU\S-1-5-21-1494171341-1486453739-2533022584-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [iagcajndpnfncplednpbnkahadegklfa] - C:\Users\Bridget\AppData\Local\speedial.crx [2008-05-22] CHR HKLM-x32\...\Chrome\Extension: [kdidombaedgpfiiedeimiebkmbilgmlc] - C:\Program Files (x86)\DefaultTab\DefaultTab.crx [Not Found] C:\Program Files (x86)\DefaultTab CHR HKLM-x32\...\Chrome\Extension: [niapdbllcanepiiimjjndipklodoedlc] - C:\Program Files (x86)\Yontoo\YontooLayers.crx [2013-02-13] C:\Program Files (x86)\Yontoo S4 70e6ca8c; "C:\windows\system32\rundll32.exe" "c:\progra~2\optimi~1\OptProCrashSvc.dll",ServiceMain c:\progra~2\optimi~1 S4 IePluginServices; No ImagePath 2015-02-21 03:07 - 2015-02-21 03:07 - 00804985 ____C () C:\Users\Bridget\Downloads\RegpairSetup.exe 2015-02-20 15:51 - 2015-02-20 15:51 - 02925856 ____C (BoostSoftware Inc. ) C:\Users\Bridget\Downloads\PCHealthBoost-Setup.exe 2015-02-18 05:45 - 2008-06-13 04:45 - 00000288 ____C () C:\windows\Tasks\RegClean Pro_UPDATES.job 2015-02-12 18:29 - 2008-05-22 19:50 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 2015-02-05 20:18 - 2014-12-31 22:57 - 00000000 ___DC () C:\Program Files (x86)\AVG 2015-02-05 21:58 - 2011-03-21 11:16 - 00000000 ___DC () C:\ProgramData\AVAST Software Task: {03AABE41-F279-4120-8147-CC5FBD23EF8F} - \BrowserSafeguard Update Task No Task File <==== ATTENTION Task: {1B2BAE5D-34F5-4040-BD75-3313A4E04D4D} - System32\Tasks\Optimum_Daily => C:\Program Files (x86)\Optimum PC Boost\OptimumPCBoost.exe <==== ATTENTION C:\Program Files (x86)\Optimum PC Boost Task: {37AEAB9D-62A4-421E-AB22-F79285654A19} - System32\Tasks\BuzzSocialPoints_DNS_Checker => C:\Windows\BuzzSocialPointsChecker\BSP_li.exe <==== ATTENTION C:\Windows\BuzzSocialPointsChecker Task: {4CE75FC7-E81C-4822-9EDF-4C724A5B20AF} - System32\Tasks\ProPCCleaner_Start => C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe C:\Program Files (x86)\Pro PC Cleaner Task: {54656568-EAA1-4440-A7CB-1FD5AB38AF2D} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION C:\Program Files (x86)\RegClean Pro Task: {86A76A15-CCE4-4BCB-BB4D-525AC17BAD75} - System32\Tasks\{3644A2E3-C346-4E05-938C-576B626DE708} => pcalua.exe -a "C:\Users\Bridget\Downloads\oPryzeLP_setup (1).exe" -d C:\Users\Bridget\Downloads Task: {92216D2F-9C5C-4776-B581-FF9C1152D18F} - System32\Tasks\{D68EBFB4-1F88-45BE-8BD7-74E03705D8DE} => pcalua.exe -a C:\Users\Bridget\Downloads\dxwebsetup(2).exe -d C:\Users\Bridget\Downloads Task: {95F9ABFD-ED30-4566-97BE-98FD9C1E4C78} - System32\Tasks\Advanced System Protector_startup => C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe <==== ATTENTION C:\Program Files (x86)\Advanced System Protector Task: {C91DF1F1-7DD7-463B-9006-3684E0FB9BE3} - System32\Tasks\{61493062-FC9F-47FD-B49C-029F4BCA6B18} => pcalua.exe -a C:\Users\Bridget\Downloads\dxwebsetup(1).exe -d C:\Users\Bridget\Downloads Task: C:\windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION C:\Program Files (x86)\RegClean Pro AlternateDataStreams: C:\ProgramData\TEMP:373E1720 AlternateDataStreams: C:\ProgramData\TEMP:770B11C9 AlternateDataStreams: C:\ProgramData\TEMP:ABE30DDB Hosts: EmptyTemp: CMD: bitsadmin /reset /allusers cmd: netsh advfirewall reset cmd: netsh advfirewall set allprofiles state off Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartupApproved" /F Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\StartupApproved" /F Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F