CloseProcesses: CreateRestorePoint: Iminent (x32 Version: 6.20.11.0 - Iminent) Hidden <==== ATTENTION Task: {0014022F-A75E-4641-95C3-D0014EC22FBA} - System32\Tasks\HDNINSTSCHD => C:\windows\PCBHDNW\hdnInstaller.exe <==== ATTENTION Task: {031F3FC8-583F-47C4-997C-716E9AA861E2} - System32\Tasks\3595562324 => \\.\globalroot\Device\HarddiskVolume2\Users\erica\AppData\Local\Temp\thpm7082909883505452935.tmp <==== ATTENTION Task: {05FEEDD6-1046-4249-B36F-E505F92BEBF1} - System32\Tasks\4697 => Wscript.exe C:\Users\erica\AppData\Local\Temp\launchie.vbs //B <==== ATTENTION Task: {0A6F337E-0F06-4605-A576-186E598CEAA7} - System32\Tasks\PC Optimizer Pro64 startups => C:\Program Files\PC Optimizer Pro\StartApps.exe <==== ATTENTION Task: {0EA5825B-5C2E-40D8-9D8C-0C793D61C4FB} - System32\Tasks\Crossbrowse => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION Task: {0F18558A-66F4-4CB2-88D6-9E1DB2D4BC78} - System32\Tasks\IFADZJC => C:\ProgramData\8d38ca20717a458aaa815e7a54207c0b\8d38ca20717a458aaa815e7a54207c0b.exe <==== ATTENTION C:\windows\PCBHDNW C:\Program Files\PC Optimizer Pro C:\Program Files (x86)\Crossbrowse C:\ProgramData\8d38ca20717a458aaa815e7a54207c0b Task: {216A975D-7233-4AC2-8C89-F0AA6CA5D133} - \bde78538 -> No File <==== ATTENTION Task: {26F95923-069D-4F15-BEF0-4D9C2CE02D47} - \808183000 -> No File <==== ATTENTION Task: {2B5F6ADC-7D05-424B-ABF8-6D6F1F144D0D} - System32\Tasks\1A35 => \\?\globalroot\Device\HarddiskVolume2\Users\erica\AppData\Local\Temp\1A35.tmp <==== ATTENTION Task: {34B313AF-3F11-4077-8DB5-D4D316021710} - System32\Tasks\IE_ERR4WDR => C:\Program Files (x86)\Portable WeatherApp\IEError.exe <==== ATTENTION Task: {37599387-2623-4453-9556-11A029036665} - System32\Tasks\WebBarLaunchTask => C:\Program Files\WebBar\wbsvc.exe [2015-06-30] (Web Bar Media) <==== ATTENTION Task: {3A4AFBEA-C7AF-41C0-ADBA-2C069391FEC6} - \f1740384 -> No File <==== ATTENTION Task: {3BD09BC3-B543-4F05-A64A-09215CC186BA} - \364ebf48 -> No File <==== ATTENTION C:\Program Files (x86)\Portable WeatherApp C:\Program Files\WebBar Task: {48E4F107-BA57-46A0-8462-3FF099077F83} - \73191588 -> No File <==== ATTENTION Task: {48E626BE-1C4E-42C2-82BB-5804017FDD87} - \7bcbe4c8 -> No File <==== ATTENTION Task: {61A185F3-7F08-421C-BC38-B0E1E5D1A0A2} - System32\Tasks\ANHIX1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION Task: {64B961F6-0061-413C-BC9F-9B2C4C250976} - System32\Tasks\SmartWeb Upgrade Trigger Task => C:\Users\erica\AppData\Local\SmartWeb\SmartWebHelper.exe <==== ATTENTION C:\ProgramData\FlashBeat C:\Users\erica\AppData\Local\SmartWeb Task: {6A001706-AA54-4ACE-9574-C7B96FC0882E} - System32\Tasks\BitGuard => Sc.exe start BitGuard <==== ATTENTION Task: {6FF2BBDC-9C70-41DC-9F73-9A9670938BF5} - System32\Tasks\UPDTEXE4_WDR => C:\Program Files (x86)\Portable WeatherApp\updater.exe <==== ATTENTION Task: {75E8414B-897F-44CE-982B-01738E6E7D82} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {7CEEBCD3-9EE4-4BF0-AB49-6DA0F3E40D93} - \770b9c8 -> No File <==== ATTENTION Task: {7E4C9C59-33DF-4D6C-9A39-853032F7C502} - \328f4e74 -> No File <==== ATTENTION C:\Program Files (x86)\AnyProtectEx Task: {8C94E84D-6256-4A65-BEFE-998D953E2CC3} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {A0756112-7FC3-4A0E-A647-C8BD64756221} - \a63eee94 -> No File <==== ATTENTION Task: {AA29354C-8CC5-41FC-BE26-C051B8AB6D10} - \5b3d5ba8 -> No File <==== ATTENTION Task: {ABA66E2E-37CE-487B-B643-BA75A646244B} - \7723d110 -> No File <==== ATTENTION Task: {B87A8943-C2A5-42C0-9DF1-CBDF6A29B90C} - \7ee62fd0 -> No File <==== ATTENTION Task: {BC6DDAF4-D556-427C-BE29-B998E004EB63} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {C0F6F4F9-8C1D-4693-BABC-7920B97D61C6} - System32\Tasks\Default2Check => c:\Users\All Users\dtdata\R003.exe <==== ATTENTION c:\Users\All Users\dtdata Task: {D0A13D63-F405-4841-A63B-28374E69E56C} - System32\Tasks\winupd => C:\Users\erica\AppData\Local\Temp:winupd.exe <==== ATTENTION Task: {D16E6C4C-7409-4789-9F91-18152B976EB9} - System32\Tasks\Maintenance Service-y0ritzvtzei5ltd => C:\Users\erica\AppData\Local\y0ritzvtzei5ltd\y2jiczvvzgq5ljd.exe Task: {DDB4DAA1-A2C6-4DF7-8A8E-B6075C5A8103} - System32\Tasks\LaunchPreSignup => C:\Program Files (x86)\OLBPre\OLBPre.exe <==== ATTENTION C:\Program Files (x86)\OLBPre Task: {E6A686B6-4D08-4929-824A-9597DF40E68A} - System32\Tasks\WebBarUpdateTask => C:\Program Files\WebBar\wbsvc.exe [2015-06-30] (Web Bar Media) <==== ATTENTION Task: C:\windows\Tasks\ANHIX1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION Task: C:\windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: C:\windows\Tasks\Crossbrowse.job => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION Task: C:\windows\Tasks\PC Optimizer Pro64 startups.job => C:\Program Files\PC Optimizer Pro\StartApps.exe <==== ATTENTION C:\Program Files\PC Optimizer Pro AlternateDataStreams: C:\windows\system32\Drivers\omtccgwk.sys:changelist AlternateDataStreams: C:\ProgramData\TEMP:373E1720 AlternateDataStreams: C:\ProgramData\TEMP:AD022376 HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Peakoar => ""="service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2" HKU\S-1-5-21-1343300749-3102139153-451857411-1001\Software\Classes\.exe: exefile => <===== ATTENTION C:\Program Files (x86)\Iminent HKLM\...\Run: [] => [X] HKLM-x32\...\Run: [SuddenlyMusic AppIntegrator 32-bit] => C:\PROGRA~2\SUDDEN~2\bar\1.bin\AppIntegrator.exe HKLM-x32\...\Run: [SuddenlyMusic AppIntegrator 64-bit] => C:\PROGRA~2\SUDDEN~2\bar\1.bin\AppIntegrator64.exe HKLM-x32\...\Run: [gmsd_us_648] => [X] HKLM-x32\...\Run: [gmsd_us_657] => [X] HKLM-x32\...\Run: [gmsd_us_005010020] => [X] HKLM-x32\...\Run: [gmsd_us_005010022] => [X] HKLM-x32\...\Run: [gmsd_us_005010054] => [X] HKU\S-1-5-21-1343300749-3102139153-451857411-1001\...\Run: [DW6] => [X] HKU\S-1-5-21-1343300749-3102139153-451857411-1001\...\Run: [Itibiti.exe] => C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe ShortcutTarget: bm.lnk -> C:\Users\erica\AppData\Local\y1bivtutzek5bjd\y3bibzvwzf85dtd.exe (No File) GroupPolicy: Restriction - Chrome <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1343300749-3102139153-451857411-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1343300749-3102139153-451857411-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIPc7-luTLJrDFH_OAl5xepwp6FPqPUuo4tdFUJSSqrQ6fncTnwfA7w32X6eBMOU_IxyzZaQuX5QH3FL4DALGIz8gAQUNVeboKxkBMa8mf81QSAxu35Dk0r7cfEngvQPxM6_ymasYMRKPPUIrSUtLCx5qDv6O5azSdShP&q={searchTerms} HKU\S-1-5-21-1343300749-3102139153-451857411-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://amazon.smart-search.com/websearch/ref=bit_bds-y46_serp_ie_us_display?ie=utf8&tagbase=bds-y46&tbrid=v1_bds-y46_2b9d9be0d598407f955b4944e2593db8_1012_1005_20130508_us_ie_sp_todownload HKU\S-1-5-21-1343300749-3102139153-451857411-1001\Software\Microsoft\Internet Explorer\Main,Start Page Restore = hxxp://www.yahoo.com/?ilc=1 HKU\S-1-5-21-1343300749-3102139153-451857411-1001\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.mysearchresults.com/?c=2629&t=01 HKU\S-1-5-21-1343300749-3102139153-451857411-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIPc7-luTLJrDFH_OAl5xepwp6FPqPUuo4tdFUJSSqrQ6fncTnwfA7w32X6eBMOU_IxyzZaQuX5QH3FL4DALGIz8gAQUNVeboKxkBMa8mf81QSAxu35Dk0r7cfEngvQPxM6_ymasYMRKPPUIrSUtLCx5qDv6O5azSdShP&q={searchTerms} URLSearchHook: HKLM-x32 - (No Name) - {b2ed7faf-72a0-46d1-9d9d-602226f5cb9f} - No File URLSearchHook: HKLM-x32 - (No Name) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - No File SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL = SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIPc7-luTLJrDFH_OAl5xepwp6FPqPUuo4tdFUJSSqrQ6fncTnwfA7w32X6eBMOU_IxyzZaQuX5QH3FL4DALGIz8gAQUNVeboKxkBMa8mf81QSAxu35Dk0r7cfEngvQPxM6_ymasYMRKPPUIrSUtLCx5qDv6O5azSdShP&q={searchTerms} SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3074349 SearchScopes: HKLM-x32 -> {f74a1771-905e-4046-a27c-62f72ece7452} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^B2N^xdm002^YYA^us&si=CKzcq5SUrsMCFQ6NaQodlYYA1A&ptb=8B009548-2CCB-4BBB-B2CC-B9C210CB6B5E&ind=2015012422&n=781aa646&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> {093CD3E6-8ABE-4069-AEB2-EC819F8585E7} URL = SearchScopes: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&affID=119747&tt=gc_&babsrc=SP_ss&mntrId=F04FE89A8F44BF77 SearchScopes: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> {1095B326-F630-4676-ADE9-B3F95690159A} URL = hxxps://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> {36377DD7-B3EB-42f5-986F-680BAF59BA9D} URL = hxxp://start.iplay.com/searchresults.aspx?o=chrome&q={searchTerms} SearchScopes: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> {68ECF76E-C86B-4661-9DFB-6CEF3AACA7A1} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3333887&octid=EB_ORIGINAL_CTID&ISID=M52DAC855-7460-40DD-9E27-E3F62DC50186&SearchSource=58&CUI=&UM=8&UP=SPC7E7CBE0-6D53-4D06-AD61-DD540E2F7F29&D=070515&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> {8AD019FB-9BB1-45B8-91AC-D1C41CEED233} URL = hxxp://www.mysearchresults.com/search?&c=2630&t=03&q={searchTerms} SearchScopes: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> {8C32BE9E-6B2E-41AD-A2D1-425B8155276D} URL = hxxp://search.yahoo.com/search?p={searchterms}&ei=UTF-8&fr=w3i&type=W3i_DS,136,0_0,Search,20120626,0,0,0,0 SearchScopes: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> {91BE8E39-ACA0-4913-9414-8E8BED82F8A7} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=OVO2&o=2159&src=kw&q={searchTerms}&locale=en_US&apn_ptnrs=^A2E&apn_dtid=^YYYYYY^YY^US&apn_uid=066ea872-7586-40c0-98f4-588b500604d4&apn_sauid=11F14A1A-82D6-4575-96E0-7238A15D5AE6 SearchScopes: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://mysearch.avg.com/search?cid={459FE109-8C4E-44D0-B278-ECACC5A1D871}&mid=bf9d6c71a6e447d2bf6e39d3c9a05684-6f1c593974f63dda1a12a0b1327fc25d24e95e7a&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=pr&d=2013-12-29 17:12:41&v=17.2.0.38&pid=safeguard&sg=&sap=dsp&q={searchTerms SearchScopes: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = hxxp://amazon.smart-search.com/websearch/ref=bit_bds-y46_serp_ie_us_display?ie=UTF8&tagbase=bds-y46&tbrId=v1_bds-y46_2b9d9be0d598407f955b4944e2593db8_1012_1005_20130508_US_ie_ds_todownload&query={searchTerms} SearchScopes: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = hxxp://toolbar.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=80303&lng=en SearchScopes: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> {f74a1771-905e-4046-a27c-62f72ece7452} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^B2N^xdm002^YYA^us&si=CKzcq5SUrsMCFQ6NaQodlYYA1A&ptb=8B009548-2CCB-4BBB-B2CC-B9C210CB6B5E&ind=2015012422&n=781aa646&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIPc7-luTLJrDFH_OAl5xepwp6FPqPUuo4tdFUJSSqrQ6fncTnwfA7w32X6eBMOU_IxyzZaQuX5QH3FL4DALGIz8gAQUNVeboKxkBMa8mf81QSAxu35Dk0r7cfEngvQPxM6_ymasYMRKPPUIrSUtLCx5qDv6O5azSdShP&q={searchTerms} Toolbar: HKLM-x32 - No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File Toolbar: HKLM-x32 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll [2011-06-08] (Yahoo! Inc.) Toolbar: HKLM-x32 - No Name - {b2ed7faf-72a0-46d1-9d9d-602226f5cb9f} - No File Toolbar: HKLM-x32 - No Name - {ba14329e-9550-4989-b3f2-9732e92d17cc} - No File Toolbar: HKLM-x32 - Amazon Browser Bar - {EA582743-9076-4178-9AA6-7393FDF4D5CE} - C:\Program Files (x86)\Amazon Browser Bar\AmazonBrowserBar.3.0.dll [2012-08-15] (Amazon.com) Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.8.0.179\AVG SafeGuard toolbar_toolbar.dll [2015-08-30] (AVG Secure Search) Toolbar: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> No Name - {9565115D-C7D6-46D3-BD63-B67B481A4368} - No File Toolbar: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File Toolbar: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> No Name - {30F9B915-B755-4826-820B-08FBA6BD249D} - No File Toolbar: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> No Name - {B2ED7FAF-72A0-46D1-9D9D-602226F5CB9F} - No File Toolbar: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> No Name - {F2C43291-151E-499C-98A7-923C120B88FA} - No File Toolbar: HKU\S-1-5-21-1343300749-3102139153-451857411-1001 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File FF HKLM\...\Firefox\Extensions: [{cc89419d-fcd5-4a6b-aca2-09043448db22}] - C:\Program Files\shopperz\Firefox FF HKLM\...\Firefox\Extensions: [{0a0e29f6-0ab0-44e1-a98e-bd050ee692ec}] - C:\Program Files\shopperz04082015\Firefox FF Extension: shopperz04082015 - C:\Program Files\shopperz04082015\Firefox [2015-08-07] FF HKLM-x32\...\Firefox\Extensions: [webbooster@iminent.com] - FF HKLM-x32\...\Firefox\Extensions: [{cc89419d-fcd5-4a6b-aca2-09043448db22}] - C:\Program Files\shopperz\Firefox FF HKLM-x32\...\Firefox\Extensions: [{0a0e29f6-0ab0-44e1-a98e-bd050ee692ec}] - C:\Program Files\shopperz04082015\Firefox S2 Updater Service for AMZN; C:\Program Files (x86)\Amazon Browser Bar\ToolbarUpdaterService.exe [222368 2012-05-22] () S2 vToolbarUpdater18.8.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.8.0\ToolbarUpdater.exe [1861520 2015-08-30] (AVG Secure Search) S2 wbsvc; C:\Program Files\WebBar\wbsvc.exe [37144 2015-06-30] (Web Bar Media) S1 innfd_1_10_0_14; system32\drivers\innfd_1_10_0_14.sys [X] S1 nvfzxhyo; \??\C:\windows\system32\drivers\nvfzxhyo.sys [X] S3 usbbus; system32\DRIVERS\lgx64bus.sys [X] S3 UsbDiag; system32\DRIVERS\lgx64diag.sys [X] S3 USBModem; system32\DRIVERS\lgx64modem.sys [X] S1 y2jimzv2zhm5bdd; system32\drivers\y2jimzv2zhm5bdd.sys [X] S3 Andbus; system32\DRIVERS\lgandbus64.sys [X] S3 AndDiag; system32\DRIVERS\lganddiag64.sys [X] S3 AndGps; system32\DRIVERS\lgandgps64.sys [X] S3 ANDModem; system32\DRIVERS\lgandmodem64.sys [X] S1 AntiLog32; \??\C:\windows\system32\drivers\AntiLog64.sys [X] C:\Program Files (x86)\SystemUphold 2015-09-11 12:18 - 2015-06-03 20:34 - 00000330 _____ C:\windows\Tasks\ANHIX1.job 2015-09-11 12:18 - 2015-06-03 20:10 - 00001056 _____ C:\windows\Tasks\Crossbrowse.job 2015-09-11 12:18 - 2011-09-02 20:08 - 00000410 _____ C:\windows\Tasks\PC Optimizer Pro64 startups.job 2015-09-03 07:40 - 2015-08-07 12:25 - 00000000 ____D C:\Program Files\shopperz04082015 2015-08-30 18:22 - 2013-05-07 20:11 - 00000000 ____D C:\Program Files (x86)\Amazon Browser Bar 2015-08-30 16:29 - 2013-12-29 18:12 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar 2015-08-28 13:28 - 2015-07-04 20:21 - 00000000 ____D C:\Program Files (x86)\SaveRPro 2015-08-28 13:27 - 2015-07-02 17:06 - 00000000 ____D C:\Program Files (x86)\browseandshoPP 2015-08-28 13:27 - 2015-07-02 17:06 - 00000000 ____D C:\Program Files (x86)\browseandshhopo 2015-08-28 13:27 - 2015-07-02 17:06 - 00000000 ____D C:\Program Files (x86)\browseaNddShoep 2015-08-28 13:27 - 2015-06-11 16:07 - 00000000 ____D C:\Program Files (x86)\gmsd_us_005010001 2015-08-21 23:37 - 2015-08-07 13:18 - 00000000 ____D C:\ProgramData\772b297800001f88 2015-08-21 23:37 - 2015-08-07 12:56 - 00000000 ____D C:\ProgramData\15721aa800005ce0 2015-08-21 23:36 - 2015-08-07 13:36 - 00000000 ____D C:\ProgramData\4b08948000003fda 2015-08-21 23:30 - 2015-08-07 11:20 - 00000000 ____D C:\Users\erica\AppData\Local\WebBar 2015-08-21 23:30 - 2009-07-13 22:20 - 00000000 ____D C:\windows\system32\NDF 2015-08-13 10:37 - 2015-06-03 20:35 - 00000000 ____D C:\Users\erica\AppData\Roaming\y2ziyzvxzgs5btd C:\Users\Public\AlexaNSISPlugin.6132.dll CMD: bitsadmin /reset /allusers CMD: netsh winsock reset catalog CMD: ipconfig /flushdns RemoveProxy: hosts: Emptytemp: