start CreateRestorePoint: HKLM-x32\...\Run: [] => [X] HKLM\...\Policies\Explorer: [HideSCAHealth] 1 HKU\S-1-5-21-3282976517-464489140-710967569-1001\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-3282976517-464489140-710967569-1001\...\Policies\Explorer: [HideSCAHealth] 1 HKU\S-1-5-21-3282976517-464489140-710967569-1001\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml.dll,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf> (the data entry has 243 more characters). <==== Poweliks! CustomCLSID: HKU\S-1-5-21-3282976517-464489140-710967569-1001_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml.dll,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf> (the data entry has 251 more characters). <==== Poweliks? ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File SearchScopes: HKLM -> DefaultScope {3024780C-8805-4BB6-8A35-5EF877BCE473} URL = http://start.mysearc...r=286216617&ir= SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {3024780C-8805-4BB6-8A35-5EF877BCE473} URL = http://start.mysearc...r=286216617&ir= SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3282976517-464489140-710967569-1001 -> {3024780C-8805-4BB6-8A35-5EF877BCE473} URL = http://start.mysearc...r=286216617&ir= FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - No Path CustomCLSID: HKU\S-1-5-21-3282976517-464489140-710967569-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Monika\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-3282976517-464489140-710967569-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Monika\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-3282976517-464489140-710967569-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Monika\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-3282976517-464489140-710967569-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Monika\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-3282976517-464489140-710967569-1001_Classes\CLSID\{F6BF8414-962C-40FE-90F1-B80A7E72DB9A}\InprocServer32 -> C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}\neth.dll No File CustomCLSID: HKU\S-1-5-21-3282976517-464489140-710967569-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Monika\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File AlternateDataStreams: C:\ProgramData\Microsoft:axxJcGPNpO9GcWXB06pzh46M AlternateDataStreams: C:\ProgramData\Microsoft:dKytVRlomlUudnGuHgtDzNO AlternateDataStreams: C:\ProgramData\TEMP:CB0AACC9 AlternateDataStreams: C:\Users\Monika\Cookies:RF0LeKXUVBXR30UyYx2MzWt AlternateDataStreams: C:\Users\Monika\Local Settings:lKCBBrFWPsF0hJDNmoeaZlZ AlternateDataStreams: C:\Users\Monika\AppData\Local:lKCBBrFWPsF0hJDNmoeaZlZ AlternateDataStreams: C:\Users\Monika\AppData\Local\Application Data:lKCBBrFWPsF0hJDNmoeaZlZ 2015-02-05 09:09 - 2014-07-20 16:34 - 00000000 _RSHD () C:\Users\Monika\t19zkij File: C:\Users\Monika\gosetup.exe CMD: bitsadmin /reset /allusers EmptyTemp: end