CloseProcesses: CreateRestorePoint: Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-600410608-1858306824-1911990453-1001\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-600410608-1858306824-1911990453-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-600410608-1858306824-1911990453-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 GroupPolicyUsers\S-1-5-21-600410608-1858306824-1911990453-1007\User: Restriction <======= ATTENTION SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = Toolbar: HKU\S-1-5-21-600410608-1858306824-1911990453-1001 -> No Name - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - No File Handler: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll No File U3 idsvc; no ImagePath 2016-08-21 20:06 - 2016-08-21 20:43 - 00000486 _____ C:\WINDOWS\Tasks\SparkTrust Registration3.job 2016-08-21 20:06 - 2016-08-21 20:43 - 00000444 _____ C:\WINDOWS\Tasks\SparkTrust Update Version3_triggeronce.job 2016-08-21 20:06 - 2016-08-21 20:43 - 00000444 _____ C:\WINDOWS\Tasks\SparkTrust Update Version3.job 2016-08-21 20:06 - 2016-08-21 20:06 - 00004254 _____ C:\WINDOWS\System32\Tasks\SparkTrust PC Cleaner Plus_sch_9F2687C4-6797-11E6-9CBA-7824AFC129AE 2016-08-21 20:06 - 2016-08-21 20:06 - 00003406 _____ C:\WINDOWS\System32\Tasks\SparkTrust Update Version3 2016-08-21 20:06 - 2016-08-21 20:06 - 00003294 _____ C:\WINDOWS\System32\Tasks\SparkTrust Registration3 2016-08-21 20:06 - 2016-08-21 20:06 - 00003094 _____ C:\WINDOWS\System32\Tasks\SparkTrust Update Version3_triggeronce 2016-08-21 20:06 - 2016-08-21 20:06 - 00001426 _____ C:\Users\Stepan\Desktop\SparkTrust PC Cleaner Plus.lnk 2016-08-21 20:06 - 2016-08-21 20:06 - 00000000 ____D C:\Users\Stepan\AppData\Roaming\SparkTrust 2016-08-21 20:05 - 2016-08-21 20:43 - 00000667 _____ C:\WINDOWS\Tasks\SparkTrust PC Cleaner Plus_sch_9F2687C4-6797-11E6-9CBA-7824AFC129AE.job 2016-08-21 20:05 - 2016-08-21 20:06 - 00000000 ____D C:\Program Files\BDServices 2016-08-21 20:05 - 2016-08-21 20:05 - 00000000 ____D C:\Users\Stepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SparkTrust 2016-08-21 20:05 - 2016-08-21 20:05 - 00000000 ____D C:\ProgramData\SparkTrust 2016-08-21 20:05 - 2016-08-21 20:05 - 00000000 ____D C:\Program Files (x86)\SparkTrust 2016-08-21 20:03 - 2016-08-21 20:04 - 11088144 _____ (SparkTrust) C:\Users\Stepan\Downloads\SparkTrust PC Cleaner Plus Setup_1F211128-B6AC-40FA-BE7A-C91E70D03CC7_.exe 2016-08-21 19:33 - 2016-08-21 19:33 - 03516080 _____ (Enigma Software Group USA, LLC.) C:\Users\Stepan\Downloads\SpyHunter-Installer.exe 2016-08-21 16:08 - 2016-08-21 17:59 - 00000000 ____D C:\Users\Stepan\AppData\Roaming\Lavasoft Task: {0FD865E9-13E1-4D13-B7B0-F8279830C371} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {265E76CD-C262-4E19-8781-7E9316A505F0} - System32\Tasks\SparkTrust Update Version3_triggeronce => c:\program files (x86)\common files\sparktrust\uus3\Update3.exe [2016-07-27] (SparkTrust Systems) <==== ATTENTION Task: {38329735-9504-44AE-BB5E-C63402669E49} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {406C3957-E1AD-4F75-AADF-C7236DFD490A} - System32\Tasks\SparkTrust PC Cleaner Plus_sch_9F2687C4-6797-11E6-9CBA-7824AFC129AE => C:\Program Files (x86)\SparkTrust\SparkTrust PC Cleaner Plus\SparkTrustPCCleanerPlus.exe [2016-07-27] (SparkTrust) <==== ATTENTION Task: {4A75A742-B6E7-4E25-A977-B9AD971C7A45} - System32\Tasks\{79D1CF0C-9F02-5AB2-8460-E7159068251E} => Regsvr32.exe /s /n /i:"/rt" "C:\PROGRA~3\eff4e719\f83d0aa8.dll" <==== ATTENTION Task: {5E4A78C5-7A35-46B5-B7F1-D952E005E80F} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION Task: {64760BA2-B14F-4EDA-9829-9AF1E1256EB9} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION C:\Program Files (x86)\SparkTrust\ "C:\PROGRA~3\eff4e719\ Task: {6BB1DE5D-0059-4897-9073-82A66A9550B2} - System32\Tasks\SparkTrust Registration3 => Rundll32.exe "C:\Program Files (x86)\Common Files\SparkTrust\UUS3\UUS3.dll" RunUns <==== ATTENTION Task: {6DD497D5-8A0B-48C2-A1EB-22939F61FBB7} - System32\Tasks\SparkTrust Update Version3 => c:\program files (x86)\common files\sparktrust\uus3\Update3.exe [2016-07-27] (SparkTrust Systems) <==== ATTENTION "C:\Program Files (x86)\Common Files\SparkTrust Task: {7FB6A892-0DA9-4B60-A9F1-66B399DA5302} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {9DF7118D-75B8-49D9-9EB3-E48F3279A1B6} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {AC23D927-41EF-4122-BD7F-549943AD8639} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {BF7E63CC-73B2-42B5-8CB3-336E12CCA355} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {D9420185-3A37-4973-B2F6-85C5489AA2F9} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {E61F3361-C27B-4AA2-897E-A89429B6ED4E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {F8EDA1A2-E2A0-44CB-A753-C7E5392A300E} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: C:\WINDOWS\Tasks\SparkTrust PC Cleaner Plus_sch_9F2687C4-6797-11E6-9CBA-7824AFC129AE.job => C:\Program Files (x86)\SparkTrust\SparkTrust PC Cleaner Plus\SparkTrustPCCleanerPlus.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\SparkTrust Registration3.job => rundll32.exe C:\Program Files (x86)\Common Files\SparkTrust\UUS3\UUS3.dll <==== ATTENTION Task: C:\WINDOWS\Tasks\SparkTrust Update Version3.job => c:\program files (x86)\common files\sparktrust\uus3\Update3.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\SparkTrust Update Version3_triggeronce.job => c:\program files (x86)\common files\sparktrust\uus3\Update3.exe <==== ATTENTION CMD: netsh advfirewall reset CMD: netsh advfirewall set allprofiles state Off CMD: bitsadmin /reset /allusers CMD: netsh winsock reset catalog CMD: ipconfig /flushdns RemoveProxy: hosts: Emptytemp: