Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Infected computer


  • This topic is locked This topic is locked

#1
jpatt

jpatt

    Member

  • Member
  • PipPip
  • 11 posts

I loaded Minecraft on my computer for my daughter, that worked fine. Then she wanted Mods. Being no stranger to the gaming community, I thought i had it under control....guess not.

 

Ran Super Anti Spyware, (CLEANED) 

Picked up: Trojan.Agent/Gen-VBinject

                  Trojan.Agent/Gen-Zbot

                  Trojan.Agent/Gen-Kasy

                  And various other STD's

 

Ran MS Essentials, (CLEANED)

 

Used Windows Unstaller to remover garbage that didn't belong, it all came back over night.

 

Install and ran MalwareBytes, (CLEANED).

    Logs are available

 

 

Pop ups are under control.I had issues with ERR_PROXY_CONNECTION_FAILED; under "LAN Setting" I unchecked "Use proxy server for you LAN". I back on the internet on the infected computer.

 

Thanks in advance,

jp

 

=================================================================

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:20-07-2015
Ran by jp (administrator) on JP-PC on 22-07-2015 18:40:24
Running from C:\Users\jp\Desktop
Loaded Profiles: jp (Available Profiles: jp & UpdatusUser)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(GoPro) C:\Program Files (x86)\GoPro\Tools\Importer\GoPro Importer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(winpcoptimizer) C:\Program Files (x86)\WinPCOptimizer\WinPCOptimizer.exe
(NEC Electronics Corporation) C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Razer USA Ltd) C:\Program Files (x86)\Razer\Mamba\RazerMambaSysTray.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\jp\Desktop\FRST64 (1).exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10806816 2010-04-30] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1796056 2014-08-19] (NVIDIA Corporation)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2010-01-22] (NEC Electronics Corporation)
HKLM-x32\...\Run: [Razer Mamba Elite Driver] => C:\Program Files (x86)\Razer\Mamba\RazerMambaSysTray.exe [973720 2011-11-25] (Razer USA Ltd)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-01-20] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-01-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKU\S-1-5-21-2309807771-1447711736-656462262-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1821888 2014-02-25] (Valve Corporation)
HKU\S-1-5-21-2309807771-1447711736-656462262-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7800088 2015-07-11] (SUPERAntiSpyware)
AppInit_DLLs-x32: c:\progra~3\flashb~1\flashb~1.dll => "c:\progra~3\flashb~1\flashb~1.dll" File not found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GoPro Importer.lnk [2015-03-06]
ShortcutTarget: GoPro Importer.lnk -> C:\Program Files (x86)\GoPro\Tools\Importer\GoPro Importer.exe (GoPro)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Win PC Optimizer.lnk [2015-07-21]
ShortcutTarget: Win PC Optimizer.lnk -> C:\Windows\Installer\{A12BC961-A17E-4400-89E3-7939E082D827}\NewShortcut1_C333EC4496E344CA9E30F596C2ED385D.exe (Flexera Software LLC)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:47574
ProxyServer: [S-1-5-21-2309807771-1447711736-656462262-1000] => http=127.0.0.1:47574
HKU\S-1-5-21-2309807771-1447711736-656462262-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre6\bin\ssv.dll [2012-04-18] (Sun Microsystems, Inc.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-04-18] (Sun Microsystems, Inc.)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}: [NameServer] 52.5.158.173,8.8.8.8
Tcpip\..\Interfaces\{8A2B8332-146E-4B1D-8493-7122587FFC7C}: [NameServer] 52.5.158.173,8.8.8.8
Tcpip\..\Interfaces\{8A2B8332-146E-4B1D-8493-7122587FFC7C}: [DhcpNameServer] 192.168.1.1 8.8.8.8 8.8.4.4
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll [2012-04-18] (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-12-18] ()
FF Plugin-x32: @esn/esnlaunch,version=1.122.0 -> C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll [2012-05-11] (ESN Social Software AB)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
 
Chrome: 
=======
CHR Profile: C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-10-28]
CHR Extension: (Google Search) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-10-28]
CHR Extension: (Star Stable Online) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnlmdkpemkkigkgelegknllpmfclakkk [2014-11-22]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (Google Wallet) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-26]
CHR Extension: (Gmail) - C:\Users\jp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-10-28]
StartMenuInternet: Google Chrome - chrome.exe
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2012-07-29] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-22] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-22 18:40 - 2015-07-22 18:40 - 00011235 _____ C:\Users\jp\Desktop\FRST.txt
2015-07-22 18:39 - 2015-07-22 18:40 - 00000000 ____D C:\FRST
2015-07-22 18:39 - 2015-07-22 18:39 - 02135552 _____ (Farbar) C:\Users\jp\Desktop\FRST64 (1).exe
2015-07-22 18:34 - 2015-07-22 18:34 - 02135552 _____ (Farbar) C:\Users\jp\Downloads\FRST64.exe
2015-07-22 05:35 - 2015-07-22 15:52 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-22 05:35 - 2015-07-22 05:35 - 00001102 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-07-22 05:35 - 2015-07-22 05:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-22 05:35 - 2015-07-22 05:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-07-22 05:35 - 2015-07-22 05:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-07-22 05:35 - 2015-07-22 05:33 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\jp\Desktop\mbam-setup-2.1.8.1057.exe
2015-07-22 05:35 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-07-22 05:35 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-07-22 05:35 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-07-22 05:22 - 2015-07-22 14:43 - 00000978 _____ C:\Windows\Tasks\wQmfRNclS.job
2015-07-22 05:22 - 2015-07-22 09:17 - 00003992 _____ C:\Windows\System32\Tasks\wQmfRNclS
2015-07-22 04:48 - 2015-07-22 04:48 - 00000135 _____ C:\Windows\version.ini
2015-07-22 04:06 - 2015-07-22 16:28 - 00000992 _____ C:\Windows\Tasks\29KouX8P5QCtjDVi.job
2015-07-22 04:06 - 2015-07-22 04:06 - 00004006 _____ C:\Windows\System32\Tasks\29KouX8P5QCtjDVi
2015-07-22 02:35 - 2015-07-22 05:18 - 00089365 _____ C:\ProgramData\8z41L16n.dat
2015-07-22 02:07 - 2015-07-22 15:26 - 00000988 _____ C:\Windows\Tasks\d7musQEpmoFigE.job
2015-07-22 02:07 - 2015-07-22 02:07 - 00004002 _____ C:\Windows\System32\Tasks\d7musQEpmoFigE
2015-07-22 01:38 - 2015-07-22 01:38 - 00000000 ____D C:\Users\jp\AppData\Local\HealthAlert
2015-07-22 01:38 - 2015-07-22 01:38 - 00000000 ____D C:\HealthAlert
2015-07-22 00:07 - 2015-07-22 18:01 - 00000986 _____ C:\Windows\Tasks\pSt8fpwyBUBMn.job
2015-07-22 00:07 - 2015-07-22 00:07 - 00004000 _____ C:\Windows\System32\Tasks\pSt8fpwyBUBMn
2015-07-21 22:54 - 2015-07-21 22:54 - 00003972 _____ C:\Windows\System32\Tasks\LaunchPreSignup
2015-07-21 22:52 - 2015-07-22 14:19 - 00000000 ____D C:\Program Files (x86)\YTDownloader
2015-07-21 22:52 - 2015-07-21 22:52 - 00003892 _____ C:\Windows\System32\Tasks\YTDownloaderUpd
2015-07-21 22:52 - 2015-07-21 22:52 - 00003838 _____ C:\Windows\System32\Tasks\Smp
2015-07-21 22:52 - 2015-07-21 22:52 - 00003570 _____ C:\Windows\System32\Tasks\YTDownloader
2015-07-21 22:43 - 2015-07-22 02:43 - 00003450 _____ C:\Windows\System32\Tasks\Onkavatiiihm
2015-07-21 22:38 - 2015-07-22 10:21 - 00000000 ____D C:\ProgramData\DataFile
2015-07-21 22:38 - 2015-07-21 22:38 - 00002615 _____ C:\Users\Public\Desktop\Win PC Optimizer.lnk
2015-07-21 22:38 - 2015-07-21 22:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Win PC Optimizer
2015-07-21 22:38 - 2015-07-21 22:38 - 00000000 ____D C:\Program Files (x86)\WinPCOptimizer
2015-07-21 22:35 - 2015-07-21 22:35 - 00000000 ____D C:\ProgramData\637633ac000009ce
2015-07-21 22:09 - 2015-07-22 14:19 - 00001000 _____ C:\Windows\Tasks\RXPrXnf6sA4m3yfQZl0W.job
2015-07-21 22:09 - 2015-07-21 22:09 - 00004014 _____ C:\Windows\System32\Tasks\RXPrXnf6sA4m3yfQZl0W
2015-07-21 22:07 - 2015-07-22 09:16 - 00000000 ____D C:\Program Files (x86)\globalUpdate
2015-07-21 22:07 - 2015-07-22 05:21 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-07-21 22:07 - 2015-07-21 22:07 - 00000000 ____D C:\Users\jp\AppData\Local\globalUpdate
2015-07-21 21:19 - 2015-07-22 09:16 - 00000000 ____D C:\Users\jp\AppData\Local\AA860BD4-5274-45AC-B02E-AA6F5A64B7F
2015-07-21 21:19 - 2015-07-21 21:19 - 00004162 _____ C:\Windows\System32\Tasks\AA860BD4-5274-45AC-B02E-AA6F5A64B7F
2015-07-21 21:19 - 2015-07-21 21:19 - 00000000 _____ C:\Windows\SysWOW64\Number of results
2015-07-21 21:18 - 2015-07-21 21:18 - 00000885 _____ C:\end
2015-07-21 20:07 - 2015-07-21 20:07 - 00000000 ____D C:\SUPERDelete
2015-07-21 20:02 - 2015-07-21 20:02 - 00000000 ____D C:\ProgramData\dbd6c89a0000265f
2015-07-21 19:47 - 2015-07-22 09:17 - 00000000 ____D C:\Windows\Provider32
2015-07-21 19:47 - 2015-07-09 23:17 - 00102912 _____ (drms media group) C:\Windows\Installer.exe
2015-07-21 19:46 - 2015-07-22 16:51 - 00000336 ____H C:\Windows\Tasks\DFOYLGNPBBOIGEUE.job
2015-07-21 19:46 - 2015-07-22 14:19 - 00000324 _____ C:\Windows\Tasks\DAHCX1.job
2015-07-21 19:46 - 2015-07-21 19:46 - 00003364 _____ C:\Windows\System32\Tasks\DFOYLGNPBBOIGEUE
2015-07-21 19:46 - 2015-07-21 19:46 - 00002846 _____ C:\Windows\System32\Tasks\DAHCX1
2015-07-21 19:46 - 2015-07-21 19:46 - 00000000 ____D C:\ProgramData\28341ff220e0446c9fff27c4493d622e
2015-07-21 19:37 - 2009-06-10 16:00 - 00000824 _____ C:\Windows\system32\Drivers\etc\hp.bak
2015-07-21 19:36 - 2015-07-22 09:16 - 00000000 ____D C:\Program Files (x86)\OSDownloader
2015-07-21 19:36 - 2015-07-21 19:36 - 00000000 ____D C:\Program Files (x86)\TestXp
2015-07-21 19:35 - 2015-07-21 19:35 - 00556488 _____ C:\Users\jp\Downloads\SetupNew.exe
2015-07-21 19:35 - 2015-07-21 19:35 - 00556488 _____ C:\Users\jp\Downloads\SetupNew (1).exe
2015-07-21 19:35 - 2015-07-21 19:35 - 00000003 _____ C:\Users\jp\Downloads\2.txt
2015-07-21 19:35 - 2015-07-21 19:35 - 00000003 _____ C:\Users\jp\Downloads\1.txt
2015-07-21 18:50 - 2015-07-21 19:42 - 00000000 ____D C:\Users\jp\AppData\Roaming\.minecraft
2015-07-21 18:50 - 2015-07-21 18:50 - 00000000 ____D C:\Users\jp\AppData\Roaming\java
2015-07-21 18:49 - 2015-07-21 18:50 - 00000000 ____D C:\Program Files (x86)\Minecraft
2015-07-21 18:49 - 2015-07-21 18:49 - 00000961 _____ C:\Users\Public\Desktop\Minecraft.lnk
2015-07-21 18:49 - 2015-07-21 18:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft
2015-07-21 18:48 - 2015-07-21 18:48 - 02314240 _____ C:\Users\jp\Downloads\MinecraftInstaller.msi
2015-07-20 19:26 - 2015-07-14 22:19 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-07-20 19:26 - 2015-07-14 22:19 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-07-20 19:26 - 2015-07-14 22:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-07-20 19:26 - 2015-07-14 22:19 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-07-20 19:26 - 2015-07-14 21:55 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-07-20 19:26 - 2015-07-14 21:55 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-07-20 19:26 - 2015-07-14 21:55 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-07-20 19:26 - 2015-07-14 21:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-07-20 19:26 - 2015-07-14 20:59 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-07-20 19:26 - 2015-07-14 20:52 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-07-14 22:51 - 2015-07-09 12:58 - 03154944 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-07-14 22:51 - 2015-07-09 12:58 - 02603008 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-07-14 22:51 - 2015-07-09 12:58 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-07-14 22:51 - 2015-07-09 12:58 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-07-14 22:51 - 2015-07-09 12:58 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-07-14 22:51 - 2015-07-09 12:58 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-07-14 22:51 - 2015-07-09 12:58 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-07-14 22:51 - 2015-07-09 12:58 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-07-14 22:51 - 2015-07-09 12:58 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-07-14 22:51 - 2015-07-09 12:58 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-07-14 22:51 - 2015-07-09 12:58 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-07-14 22:51 - 2015-07-09 12:43 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-07-14 22:51 - 2015-07-09 12:43 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-07-14 22:51 - 2015-07-09 12:43 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-07-14 22:51 - 2015-07-09 12:43 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-07-14 22:51 - 2015-07-09 12:42 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-07-14 22:51 - 2015-07-02 16:21 - 19877376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-07-14 22:51 - 2015-07-02 16:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-07-14 22:51 - 2015-07-02 15:50 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-07-14 22:51 - 2015-07-02 15:49 - 25193984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-07-14 22:51 - 2015-07-02 15:46 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-07-14 22:51 - 2015-07-02 15:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-07-14 22:51 - 2015-07-02 15:23 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-07-14 22:51 - 2015-07-02 15:19 - 12855296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-07-14 22:51 - 2015-07-02 15:12 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-07-14 22:51 - 2015-07-02 14:55 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-07-14 22:51 - 2015-07-02 14:20 - 14453248 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-07-14 22:51 - 2015-07-02 13:59 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-07-14 22:51 - 2015-06-26 21:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-07-14 22:51 - 2015-06-26 21:43 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-07-14 22:51 - 2015-06-26 20:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-07-14 22:51 - 2015-06-26 20:39 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-07-14 22:51 - 2015-06-25 03:57 - 03207168 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-07-14 22:51 - 2015-06-17 12:47 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-07-14 22:51 - 2015-06-17 12:37 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-07-14 22:51 - 2015-06-09 13:03 - 03180544 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-07-14 22:51 - 2015-06-09 13:03 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-07-14 22:51 - 2015-06-01 19:07 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll
2015-07-14 22:51 - 2015-06-01 18:47 - 00210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cewmdm.dll
2015-07-14 22:50 - 2015-06-25 13:09 - 00389832 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-07-14 22:50 - 2015-06-25 12:43 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-07-14 22:50 - 2015-06-20 15:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-07-14 22:50 - 2015-06-20 14:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-07-14 22:50 - 2015-06-20 14:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-07-14 22:50 - 2015-06-20 14:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-07-14 22:50 - 2015-06-20 14:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-07-14 22:50 - 2015-06-20 14:39 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-07-14 22:50 - 2015-06-20 14:34 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-07-14 22:50 - 2015-06-20 14:34 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-07-14 22:50 - 2015-06-20 14:34 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-07-14 22:50 - 2015-06-20 14:25 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-07-14 22:50 - 2015-06-20 14:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-07-14 22:50 - 2015-06-20 14:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-07-14 22:50 - 2015-06-20 14:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-07-14 22:50 - 2015-06-20 14:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-07-14 22:50 - 2015-06-20 13:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-07-14 22:50 - 2015-06-20 13:48 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-07-14 22:50 - 2015-06-20 13:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-07-14 22:50 - 2015-06-20 13:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-07-14 22:50 - 2015-06-20 13:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-07-14 22:50 - 2015-06-19 13:25 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-07-14 22:50 - 2015-06-19 13:25 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-07-14 22:50 - 2015-06-19 13:24 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-07-14 22:50 - 2015-06-19 13:24 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-07-14 22:50 - 2015-06-19 13:23 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-07-14 22:50 - 2015-06-19 13:17 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-07-14 22:50 - 2015-06-19 13:16 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-07-14 22:50 - 2015-06-19 13:13 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-07-14 22:50 - 2015-06-19 13:13 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-07-14 22:50 - 2015-06-19 13:03 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-07-14 22:50 - 2015-06-19 12:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-07-14 22:50 - 2015-06-19 12:53 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-07-14 22:50 - 2015-06-19 12:52 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-07-14 22:50 - 2015-06-19 12:51 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-07-14 22:50 - 2015-06-19 12:40 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-07-14 22:50 - 2015-06-19 12:40 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-07-14 22:50 - 2015-06-19 12:39 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-07-14 22:50 - 2015-06-19 12:15 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-07-14 22:50 - 2015-06-19 12:11 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-07-14 22:49 - 2015-06-20 14:49 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-07-14 22:49 - 2015-06-20 14:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-07-14 22:49 - 2015-06-20 14:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-07-14 22:49 - 2015-06-20 13:26 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-07-14 22:48 - 2015-07-04 13:07 - 02087424 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2015-07-14 22:48 - 2015-07-04 12:48 - 01414656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2015-07-14 22:48 - 2015-06-11 12:57 - 06131200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-07-14 22:48 - 2015-06-11 12:57 - 00856064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-07-14 22:48 - 2015-06-11 12:57 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-07-14 22:48 - 2015-06-11 12:56 - 07077376 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-07-14 22:48 - 2015-06-11 12:56 - 01057792 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-07-14 22:48 - 2015-06-11 12:56 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-07-14 22:48 - 2015-06-11 08:15 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-07-14 22:47 - 2015-07-09 12:59 - 00017856 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-07-14 22:47 - 2015-07-09 12:58 - 01085440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-07-14 22:47 - 2015-07-09 12:58 - 00765440 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-07-14 22:47 - 2015-07-09 12:58 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-07-14 22:47 - 2015-07-09 12:58 - 00433664 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-07-14 22:47 - 2015-07-09 12:58 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-07-14 22:47 - 2015-07-09 12:58 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-07-14 22:47 - 2015-07-09 12:50 - 01145856 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-07-14 22:47 - 2015-07-01 15:56 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-07-14 22:47 - 2015-07-01 15:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-07-14 22:47 - 2015-07-01 15:49 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-07-14 22:47 - 2015-07-01 15:49 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-07-14 22:47 - 2015-07-01 15:49 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-07-14 22:47 - 2015-07-01 15:49 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-07-14 22:47 - 2015-07-01 15:49 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-07-14 22:47 - 2015-07-01 15:49 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-07-14 22:47 - 2015-07-01 15:49 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-07-14 22:47 - 2015-07-01 15:49 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-07-14 22:47 - 2015-07-01 15:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-07-14 22:47 - 2015-07-01 15:49 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-07-14 22:47 - 2015-07-01 15:49 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-07-14 22:47 - 2015-07-01 15:48 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-07-14 22:47 - 2015-07-01 15:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-07-14 22:47 - 2015-07-01 15:47 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-07-14 22:47 - 2015-07-01 15:47 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-07-14 22:47 - 2015-07-01 15:43 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-07-14 22:47 - 2015-07-01 15:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-07-14 22:47 - 2015-07-01 15:39 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-07-14 22:47 - 2015-07-01 15:30 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-07-14 22:47 - 2015-07-01 15:30 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-07-14 22:47 - 2015-07-01 15:30 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-07-14 22:47 - 2015-07-01 15:30 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-07-14 22:47 - 2015-07-01 15:30 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-07-14 22:47 - 2015-07-01 15:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-07-14 22:47 - 2015-07-01 15:30 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-07-14 22:47 - 2015-07-01 15:30 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-07-14 22:47 - 2015-07-01 15:30 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-07-14 22:47 - 2015-07-01 15:29 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-07-14 22:47 - 2015-07-01 15:29 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-07-14 22:47 - 2015-07-01 15:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-07-14 22:47 - 2015-07-01 15:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-07-14 22:47 - 2015-07-01 15:26 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-07-14 22:47 - 2015-07-01 15:24 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-07-14 22:47 - 2015-07-01 14:27 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-07-14 22:47 - 2015-07-01 14:26 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-07-14 22:47 - 2015-07-01 14:26 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-07-14 22:47 - 2015-06-15 16:50 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-07-14 22:47 - 2015-06-15 16:45 - 03242496 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-07-14 22:47 - 2015-06-15 16:45 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-07-14 22:47 - 2015-06-15 16:45 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2015-07-14 22:47 - 2015-06-15 16:45 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-07-14 22:47 - 2015-06-15 16:44 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-07-14 22:47 - 2015-06-15 16:43 - 02364416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2015-07-14 22:47 - 2015-06-15 16:43 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-07-14 22:47 - 2015-06-15 16:43 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2015-07-14 22:47 - 2015-06-15 16:42 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2015-07-14 22:47 - 2015-06-15 16:42 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2015-07-14 22:47 - 2015-06-15 16:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2015-07-14 22:47 - 2015-04-27 14:23 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-07-14 22:47 - 2015-04-27 14:23 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-07-14 22:47 - 2015-04-27 14:23 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-07-14 22:47 - 2015-04-27 14:23 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-07-14 22:47 - 2015-04-27 14:05 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-07-14 22:47 - 2015-04-27 14:04 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-07-14 22:47 - 2015-04-27 14:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2015-07-14 22:47 - 2015-04-27 14:04 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2015-07-05 16:32 - 2015-07-06 17:34 - 121651128 _____ (GoPro, Inc.) C:\Users\jp\Downloads\GoProStudioPC-2.5.5.443.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-22 18:38 - 2009-07-13 23:45 - 00032416 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-22 18:38 - 2009-07-13 23:45 - 00032416 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-22 18:00 - 2012-03-31 06:55 - 01934832 _____ C:\Windows\WindowsUpdate.log
2015-07-22 17:50 - 2012-04-01 12:09 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-22 14:26 - 2009-07-14 00:13 - 00782470 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-22 14:20 - 2012-11-16 15:45 - 00000000 ____D C:\Program Files (x86)\Steam
2015-07-22 14:19 - 2012-10-28 09:30 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-22 14:19 - 2012-03-31 17:26 - 00000000 ____D C:\ProgramData\NVIDIA
2015-07-22 14:19 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-22 14:19 - 2009-07-13 23:51 - 00048030 _____ C:\Windows\setupact.log
2015-07-22 14:18 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\System
2015-07-22 09:19 - 2010-11-20 22:47 - 00239792 _____ C:\Windows\PFRO.log
2015-07-22 09:17 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\TAPI
2015-07-22 05:21 - 2012-03-31 06:56 - 00001605 _____ C:\Users\jp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-07-21 20:48 - 2009-07-14 00:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2015-07-21 20:05 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\system32\NDF
2015-07-21 20:04 - 2012-04-16 22:04 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2015-07-21 19:58 - 2012-10-28 09:30 - 00000000 ___HD C:\Users\jp\AppData\Local\Google
2015-07-21 19:58 - 2012-10-28 09:30 - 00000000 ____D C:\Program Files (x86)\Google
2015-07-21 19:38 - 2014-03-08 13:34 - 00000000 ___HD C:\Users\jp\AppData\Local\Battle.net
2015-07-21 18:53 - 2012-10-28 09:30 - 00000000 ___HD C:\Users\jp\AppData\Local\Deployment
2015-07-21 18:34 - 2009-07-13 23:45 - 00269128 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-21 14:42 - 2015-05-02 12:18 - 00000000 ____D C:\Users\Public\StarStableOnline
2015-07-16 18:00 - 2015-04-04 18:00 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-07-16 18:00 - 2015-04-04 18:00 - 00000000 ___SD C:\Windows\system32\GWX
2015-07-16 17:19 - 2015-03-08 21:35 - 00000000 ____D C:\Users\jp\Desktop\SS
2015-07-15 19:31 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache
2015-07-15 18:26 - 2015-03-08 16:35 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-07-15 18:25 - 2014-12-10 19:20 - 00000000 ____D C:\Windows\system32\appraiser
2015-07-15 18:25 - 2014-05-06 18:00 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-07-15 18:25 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-07-15 18:05 - 2013-08-14 18:01 - 00000000 ____D C:\Windows\system32\MRT
2015-07-15 17:36 - 2012-03-31 20:54 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2015-07-15 17:31 - 2014-03-08 13:34 - 00000000 ____D C:\Program Files (x86)\Battle.net
2015-07-15 14:01 - 2012-10-28 09:30 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-15 14:01 - 2012-10-28 09:30 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-15 14:01 - 2012-10-28 09:30 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-15 03:51 - 2012-04-01 12:09 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-07-15 03:50 - 2012-04-01 12:09 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-15 03:50 - 2012-04-01 12:09 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-05 05:08 - 2010-11-20 22:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-07-03 08:43 - 2012-04-02 16:55 - 130333168 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
 
==================== Files in the root of some directories =======
 
2015-04-19 07:20 - 2015-04-19 07:20 - 0005872 _____ () C:\Users\jp\AppData\Roaming\29KouX8P5QCtjDVi
2015-04-19 07:20 - 2015-04-19 07:20 - 0005872 _____ () C:\Users\jp\AppData\Roaming\d7musQEpmoFigE
2015-04-19 07:20 - 2015-04-19 07:20 - 0005872 _____ () C:\Users\jp\AppData\Roaming\pSt8fpwyBUBMn
2015-04-19 07:20 - 2015-04-19 07:20 - 0005872 _____ () C:\Users\jp\AppData\Roaming\RXPrXnf6sA4m3yfQZl0W
2015-04-19 07:20 - 2015-04-19 07:20 - 0005872 _____ () C:\Users\jp\AppData\Roaming\wQmfRNclS
2015-07-22 02:35 - 2015-07-22 05:18 - 0089365 _____ () C:\ProgramData\8z41L16n.dat
 
Files to move or delete:
====================
C:\ProgramData\8z41L16n.dat
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-07-13 00:22
 

==================== End of log ============================ 

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:20-07-2015
Ran by jp at 2015-07-22 18:40:56
Running from C:\Users\jp\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2309807771-1447711736-656462262-500 - Administrator - Disabled)
Guest (S-1-5-21-2309807771-1447711736-656462262-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2309807771-1447711736-656462262-1002 - Limited - Enabled)
jp (S-1-5-21-2309807771-1447711736-656462262-1000 - Administrator - Enabled) => C:\Users\jp
UpdatusUser (S-1-5-21-2309807771-1447711736-656462262-1003 - Limited - Enabled) => C:\Users\UpdatusUser
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 18 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\...\{A922C4B7-50E0-4787-A94C-59DBF3C65DBE}) (Version: 3.0 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{FE86CB0C-FCB3-4358-B4B0-B0A41E33B3DD}) (Version: 7.1.0.32 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.0.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 1.122.0 - EA Digital Illusions CE AB)
Blacklight Retribution (HKLM-x32\...\Blacklight Retribution) (Version:  - Perfect World Entertainment)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Call of Duty: Black Ops II - Zombies (HKLM-x32\...\Steam App 212910) (Version:  - )
Curse Client (HKU\S-1-5-21-2309807771-1447711736-656462262-1000\...\101a9f93b8f0bb6f) (Version: 5.1.1.844 - Curse)
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
FindingDiscount (HKLM-x32\...\FindingDiscount) (Version:  - )
globalupdate Helper (x32 Version: 1.3.25.0 - globalupdate Inc.) Hidden <==== ATTENTION
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.134 - Google Inc.)
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
GoPro Studio 2.5.4 (HKLM-x32\...\GoPro Studio) (Version: 2.5.4 - GoPro, Inc.)
Health Alert (HKLM-x32\...\HealthAlert) (Version: 2.7.68 - Rational Thought Solutions) <==== ATTENTION!
iTunes (HKLM\...\{0D924CB2-2EA4-4044-BAF7-770202D6BD0D}) (Version: 11.1.4.62 - Apple Inc.)
Java™ 6 Update 31 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416031FF}) (Version: 6.0.310 - Oracle)
Loadout (HKLM-x32\...\Steam App 208090) (Version:  - Edge of Reality)
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
marvell 91xx driver (HKLM-x32\...\MagniDriver) (Version: 1.0.0.1036 - Marvell)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
Mumble 1.2.4 (HKLM-x32\...\{E0955568-4353-4C85-8988-285A8C0F5E87}) (Version: 1.2.4 - Thorvald Natvig)
NEC Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}) (Version: 1.0.19.0 - NEC Electronics Corporation)
NEC Electronics USB 3.0 Host Controller Driver (x32 Version: 1.0.19.0 - NEC Electronics Corporation) Hidden
NVIDIA 3D Vision Controller Driver 314.07 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 314.07 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 340.52 - NVIDIA Corporation)
NVIDIA Graphics Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.12.1031 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.1031 - NVIDIA Corporation)
NVIDIA Update 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 8.5.2.23 - Electronic Arts, Inc.)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Razer Mamba (HKLM-x32\...\{BF60B320-3AA3-4DFB-B542-BDA6D4F1A60E}) (Version: 2.01.05 - Razer USA Ltd.)
Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.12.1218.2009 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6101 - Realtek Semiconductor Corp.)
RIFT (HKU\S-1-5-21-2309807771-1447711736-656462262-1000\...\RIFT) (Version:  - Trion Worlds, Inc.)
Setup (HKLM-x32\...\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}) (Version:  - )
Star Stable (HKLM-x32\...\{2B03B553-4983-4005-99C4-31DFC25B4BB9}) (Version: 1.00.0000 - Star Stable Entertainment AB)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1170 - SUPERAntiSpyware.com)
Ventrilo Client for Windows x64 (HKLM\...\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}) (Version: 3.0.8.0 - Flagship Industries, Inc.)
Windows Driver Package - GoPro (WinUSB) Universal Serial Bus devices  (03/07/2012 ) (HKLM\...\0B624A43DD66DBF5CF3EDFA9741A364E688062A4) (Version: 03/07/2012  - GoPro)
WinPCOptimizer (HKLM-x32\...\{A12BC961-A17E-4400-89E3-7939E082D827}) (Version: 1.03.1020 - Win PC Optimizer)
World of Logs Client (4.2) (HKU\S-1-5-21-2309807771-1447711736-656462262-1000\...\World of Logs Client (4.2)) (Version:  - Digibites Technology)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version:  - Blizzard Entertainment)
YTDownloader (HKLM-x32\...\YTDownloader) (Version:  - YTDownloader) <==== ATTENTION
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-2309807771-1447711736-656462262-1000_Classes\CLSID\{4df3e0ab-18b0-433d-b14c-aeeef26b1833}\InprocServer32 -> C:\Windows\system32\dfshim.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2309807771-1447711736-656462262-1000_Classes\CLSID\{5b55a44a-d008-49aa-9234-86fb7709bc0a}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
 
==================== Restore Points =========================
 
12-07-2015 02:27:55 Windows Update
12-07-2015 19:00:23 Windows Backup
15-07-2015 16:46:22 Windows Update
15-07-2015 18:00:15 Windows Update
16-07-2015 18:00:11 Windows Update
19-07-2015 18:40:22 Windows Update
19-07-2015 19:00:11 Windows Backup
21-07-2015 18:00:10 Windows Update
21-07-2015 18:49:04 Installed Minecraft
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {02E08FBC-6B8C-4125-90B9-3CC7461E8A3D} - System32\Tasks\29KouX8P5QCtjDVi => C:\Users\jp\AppData\Roaming\29KouX8P5QCtjDVi.exe <==== ATTENTION
Task: {11E0FEEB-D2E5-4AF2-ABF2-B68C757AB524} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-1-6 No Task File <==== ATTENTION
Task: {142EB9A5-FC64-43BC-9E6D-2F95CE6F5A9B} - System32\Tasks\EVGA CD Installer => D:\autorun.exe
Task: {1D4EDC70-1A53-413D-ACCC-A7215D284850} - \Super Optimizer Schedule No Task File <==== ATTENTION
Task: {23855FE6-2F13-4E21-ACDB-18C9E6C70B5D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-28] (Google Inc.)
Task: {2C4DC035-7C33-49A8-B439-CDBFD540056B} - \APSnotifierPP3 No Task File <==== ATTENTION
Task: {2EAF9767-53EB-47B0-B6BD-B7D4DB235DDE} - \SMupdate1 No Task File <==== ATTENTION
Task: {338B9654-7894-445B-B060-DB7F202DB5DC} - System32\Tasks\YTDownloader => C:\Program Files (x86)\YTDownloader\YTDownloader.exe <==== ATTENTION
Task: {3A8A6C3A-D169-4925-9DE2-041AF1CEE7EA} - System32\Tasks\{85A6FB23-2911-47F5-BD07-D7EBAEFACD52} => C:\Program Files (x86)\Star Stable Entertainment AB\Star Stable\StarStable.exe [2014-04-01] (Star Stable Entertainment AB)
Task: {3D2EA2AE-DF2B-49B6-8D84-3C27E6978B45} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3 <==== ATTENTION
Task: {3DFAB371-FFF5-42CF-896C-8B863A564E5B} - System32\Tasks\Onkavatiiihm => C:\ProgramData\Onkavatiiihm\1.0.4.1\jsixetek.exe
Task: {3E46DBD6-94DB-4E80-9BF2-45F29EE71E51} - \SMW_UpdateTask_Time_3338343934393333382d3437415a556c2a3223346c41 No Task File <==== ATTENTION
Task: {3ED523FA-4280-4A2C-955F-D6D3D022FCE3} - System32\Tasks\Smp => C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smp.exe <==== ATTENTION
Task: {3FF480CF-C08F-4062-BCC7-597EB9C41083} - \Bidaily Synchronize Task[8da6] No Task File <==== ATTENTION
Task: {48AF4823-CFB3-4F2A-8D21-9084B7AE5662} - System32\Tasks\DAHCX1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: {4B6183C7-5C6D-40F4-BF7C-5953D3BEF640} - System32\Tasks\AA860BD4-5274-45AC-B02E-AA6F5A64B7F => C:\Users\jp\AppData\Local\AA860BD4-5274-45AC-B02E-AA6F5A64B7F\AA860BD4-5274-45AC-B02E-AA6F5A64B7F.exe <==== ATTENTION
Task: {52A2C8C8-AB59-48FC-B3BE-8E9E5B045546} - System32\Tasks\wQmfRNclS => C:\Users\jp\AppData\Roaming\wQmfRNclS.exe <==== ATTENTION
Task: {5C7B2767-D4D7-4AAF-B0C4-9B32EBC87E65} - \APSnotifierPP1 No Task File <==== ATTENTION
Task: {5E6028ED-0CFB-492C-93B9-19C2D5BECDEB} - \SMWPUpd No Task File <==== ATTENTION
Task: {5FD4B11B-2278-4E91-B9D4-28E836883534} - System32\Tasks\d7musQEpmoFigE => C:\Users\jp\AppData\Roaming\d7musQEpmoFigE.exe <==== ATTENTION
Task: {69BBC392-B114-4060-9F5B-AC88047A89E1} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {732FB463-819B-4E65-8A53-35E4E17F077C} - \SmartWeb Upgrade Trigger Task No Task File <==== ATTENTION
Task: {75D681CF-B4E6-4824-BF78-E81B7D265B25} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {77A36547-0436-4D9E-B7E1-6E5ED009A452} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-28] (Google Inc.)
Task: {796CBCFE-BBF9-4EED-A351-E431FC04E196} - System32\Tasks\RXPrXnf6sA4m3yfQZl0W => C:\Users\jp\AppData\Roaming\RXPrXnf6sA4m3yfQZl0W.exe <==== ATTENTION
Task: {79B2E546-51C4-4E8E-93EF-D05F90783921} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-7 No Task File <==== ATTENTION
Task: {8684C6BD-FB1B-4C22-BCC5-BA576BBC7173} - System32\Tasks\YTDownloaderUpd => C:\Program Files (x86)\YTDownloader\updater.exe <==== ATTENTION
Task: {95C217F8-1C00-4C8F-B0EE-AB0CDBE53D87} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {95FD0D33-B414-446E-A1A0-93B0E856813F} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-10_user No Task File <==== ATTENTION
Task: {9907CA38-44BA-4C49-9350-81D11166D4F8} - \APSnotifierPP2 No Task File <==== ATTENTION
Task: {9DFA095B-C612-4BD9-8324-F431D04BE7D7} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update2 <==== ATTENTION
Task: {9ECE0643-1EA1-41E6-A43D-0D370AD66A18} - \Tny_Cassiopesa No Task File <==== ATTENTION
Task: {A7DCE32B-99F7-4EEF-B208-E0E9623889BD} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-3 No Task File <==== ATTENTION
Task: {BA192C50-A8B4-4A2C-B791-583B5BC410C5} - System32\Tasks\pSt8fpwyBUBMn => C:\Users\jp\AppData\Roaming\pSt8fpwyBUBMn.exe <==== ATTENTION
Task: {C294357E-2A44-43A8-AB6D-C76E6F8B17D6} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-6 No Task File <==== ATTENTION
Task: {C65B5A35-3B30-43A5-AFF0-2FB74D9E31A8} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-5_user No Task File <==== ATTENTION
Task: {D1ED8231-6334-487F-82C7-FB4FFE81699F} - System32\Tasks\DFOYLGNPBBOIGEUE => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: {D3812DC5-739D-4C15-9E3D-1DD24F50C12A} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-5 No Task File <==== ATTENTION
Task: {D91B1852-9DB5-46F0-A199-6AE63FDC776C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-15] (Adobe Systems Incorporated)
Task: {DA90A49E-CFA3-4832-B90A-A8AAF55232F1} - System32\Tasks\LaunchPreSignup => C:\Program Files (x86)\OLBPre\OLBPre.exe <==== ATTENTION
Task: {FC7E6B07-3FC9-4330-841E-18190BF690AE} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-1-7 No Task File <==== ATTENTION
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\29KouX8P5QCtjDVi.job => C:\Users\jp\AppData\Roaming\29KouX8P5QCtjDVi.exe <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\d7musQEpmoFigE.job => C:\Users\jp\AppData\Roaming\d7musQEpmoFigE.exe <==== ATTENTION
Task: C:\Windows\Tasks\DAHCX1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: C:\Windows\Tasks\DFOYLGNPBBOIGEUE.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\pSt8fpwyBUBMn.job => C:\Users\jp\AppData\Roaming\pSt8fpwyBUBMn.exe <==== ATTENTION
Task: C:\Windows\Tasks\RXPrXnf6sA4m3yfQZl0W.job => C:\Users\jp\AppData\Roaming\RXPrXnf6sA4m3yfQZl0W.exe <==== ATTENTION
Task: C:\Windows\Tasks\wQmfRNclS.job => C:\Users\jp\AppData\Roaming\wQmfRNclS.exe <==== ATTENTION
 
==================== Loaded Modules (Whitelisted) ==============
 
2012-03-31 17:26 - 2014-07-02 13:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2012-04-16 20:50 - 2012-07-29 09:25 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-12-16 17:37 - 2014-12-16 17:37 - 01800192 _____ () C:\Program Files (x86)\GoPro\Tools\Importer\GPSDKAnalyticsNet.dll
2015-07-14 12:01 - 2015-07-13 16:55 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libglesv2.dll
2015-07-14 12:01 - 2015-07-13 16:55 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:054203E4
 
==================== Safe Mode (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-2309807771-1447711736-656462262-1000\...\starstable.com -> starstable.com
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2309807771-1447711736-656462262-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\jp\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 52.5.158.173 - 8.8.8.8
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{A9D627D0-995F-4841-B9D4-6E40E23C4C9C}] => (Allow) C:\Program Files\Ventrilo\Ventrilo.exe
FirewallRules: [{302A982D-4A0C-4D84-ABCE-7C2E56F9128D}] => (Allow) C:\Program Files\Ventrilo\Ventrilo.exe
FirewallRules: [{48B7B65C-B0B3-4B90-93F0-40772DBEBF52}] => (Allow) C:\Program Files (x86)\World of Warcraft\Launcher.exe
FirewallRules: [{DC15E6EF-AFC7-41B7-B288-AE34FCAAC5D5}] => (Allow) C:\Program Files (x86)\World of Warcraft\Launcher.exe
FirewallRules: [{23101DD1-05FB-405A-9032-6DD28E9A7785}] => (Allow) C:\Program Files (x86)\World of Warcraft\Launcher.patch.exe
FirewallRules: [{424D164C-3EA7-467F-A2ED-161BDCB64AB6}] => (Allow) C:\Program Files (x86)\World of Warcraft\Launcher.patch.exe
FirewallRules: [TCP Query User{810E9FC2-4BF1-4E03-B111-E4B05603ECE5}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe] => (Allow) C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe
FirewallRules: [UDP Query User{5A1BB868-8AAD-460F-A3F0-2281EEFE7BB9}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe] => (Allow) C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe
FirewallRules: [TCP Query User{5C4667C1-F951-4F0D-BA7C-BACEF8EA3B09}C:\program files (x86)\world of warcraft\backgrounddownloader.exe] => (Allow) C:\program files (x86)\world of warcraft\backgrounddownloader.exe
FirewallRules: [UDP Query User{09F1F1E0-CE33-4192-8E91-D3997856C4C6}C:\program files (x86)\world of warcraft\backgrounddownloader.exe] => (Allow) C:\program files (x86)\world of warcraft\backgrounddownloader.exe
FirewallRules: [TCP Query User{894408AA-9503-4DAF-AE23-2C419BD6E5C6}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe] => (Allow) C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe
FirewallRules: [UDP Query User{67959C88-AF36-4D6B-9AAD-7A6132E424CA}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe] => (Allow) C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2730-enus-tools-downloader.exe
FirewallRules: [TCP Query User{50DCFF35-D384-4D8B-B7C0-58EC0EB264B9}C:\program files (x86)\world of warcraft\wow-4.2.1.2736-enus-tools-downloader.exe] => (Allow) C:\program files (x86)\world of warcraft\wow-4.2.1.2736-enus-tools-downloader.exe
FirewallRules: [UDP Query User{CBC7498A-722B-42D5-B8F9-82D87ECE92EA}C:\program files (x86)\world of warcraft\wow-4.2.1.2736-enus-tools-downloader.exe] => (Allow) C:\program files (x86)\world of warcraft\wow-4.2.1.2736-enus-tools-downloader.exe
FirewallRules: [{C1EB2F47-04B0-4F83-920B-6525E13E966F}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe
FirewallRules: [{59ECE83E-4D34-4F41-89A6-7D7FA0C0EF92}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe
FirewallRules: [{90A6D7A3-8F32-460B-A901-1872F944D0EA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.515\Agent.exe
FirewallRules: [{120DEE30-CA24-4557-970F-C5784AFE7A21}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.515\Agent.exe
FirewallRules: [{6851F6A0-DA14-4C92-92E9-E2ABDCBDEB21}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.868\Agent.exe
FirewallRules: [{232119DB-340A-4369-B04F-D8AFF0F8BF1D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.868\Agent.exe
FirewallRules: [{6B14D047-430D-405F-9663-6A01BDA3CDF2}] => (Allow) C:\Program Files (x86)\Diablo III Beta\Diablo III.exe
FirewallRules: [{B563E21D-5DB8-4830-83CB-041C23A92AC1}] => (Allow) C:\Program Files (x86)\Diablo III Beta\Diablo III.exe
FirewallRules: [{27EBBC0A-4F2C-428F-A4BF-164A759F70B2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{47BB46F1-E535-4ADF-8CFF-533C9452F95A}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{75E47A58-9704-4059-8D15-41F123E0ACC9}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{029D3BD2-E8A3-4223-AAC6-74CEC63837FE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{0FBD5E06-DF70-4621-8A45-FD8C876446AD}C:\program files (x86)\world of warcraft\launcher.exe] => (Allow) C:\program files (x86)\world of warcraft\launcher.exe
FirewallRules: [UDP Query User{400EC75B-FFDF-4208-ADEF-45905F18E50A}C:\program files (x86)\world of warcraft\launcher.exe] => (Allow) C:\program files (x86)\world of warcraft\launcher.exe
FirewallRules: [TCP Query User{825CD9ED-F93C-4230-9895-FA29005E12F3}C:\program files\java\jre6\bin\java.exe] => (Allow) C:\program files\java\jre6\bin\java.exe
FirewallRules: [UDP Query User{FEEB2C44-DCE3-4B9A-ABA6-27CE89710BD1}C:\program files\java\jre6\bin\java.exe] => (Allow) C:\program files\java\jre6\bin\java.exe
FirewallRules: [{0CF83BA7-8315-47AF-AC6C-6B175CD7DB42}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.976\Agent.exe
FirewallRules: [{F7C86BDA-B6E5-4C93-9312-500FAA66F516}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.976\Agent.exe
FirewallRules: [{E7A2BE7C-2279-4519-9306-CB179BA23269}] => (Allow) C:\Program Files (x86)\Diablo III\Diablo III.exe
FirewallRules: [{7E72FE13-7E28-4AF2-807C-F7A67A8A930B}] => (Allow) C:\Program Files (x86)\Diablo III\Diablo III.exe
FirewallRules: [TCP Query User{7F9914B3-6AC2-4FC3-A57B-9A5CF09F5093}C:\programdata\battle.net\agent\agent.998\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.998\agent.exe
FirewallRules: [UDP Query User{A56C4D02-0DDC-46EB-8FF2-34CC4E782553}C:\programdata\battle.net\agent\agent.998\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.998\agent.exe
FirewallRules: [TCP Query User{19659990-DD94-4775-B1EA-8AB1E49529D5}C:\programdata\battle.net\agent\agent.1040\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.1040\agent.exe
FirewallRules: [UDP Query User{7DC9FD1F-6675-4F4F-86E5-21DCE9BE6C95}C:\programdata\battle.net\agent\agent.1040\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.1040\agent.exe
FirewallRules: [{6303D421-50EA-4966-8A64-196105ACF621}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{8EED9741-A384-41FD-AB19-304293A1598C}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{F0E89DD9-D7A8-4643-A9DD-88617F79BE87}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{BD062255-A042-4772-BC33-16891B9DD55B}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [TCP Query User{4F5F191E-5F30-46EC-A24B-4AC0DA3D68DA}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe] => (Allow) C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe
FirewallRules: [UDP Query User{5ED60B89-F7A9-4693-AB13-50099199064B}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe] => (Allow) C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe
FirewallRules: [TCP Query User{9E2C7BD4-40FD-4FF5-87B5-C4F02E2E4C1E}C:\program files (x86)\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe] => (Allow) C:\program files (x86)\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe
FirewallRules: [UDP Query User{EFABECC8-8E12-44E0-B61B-0936D4EBD0E7}C:\program files (x86)\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe] => (Allow) C:\program files (x86)\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe
FirewallRules: [{CD5041F6-C03D-4AE8-BAC4-B3129FAB035F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe
FirewallRules: [{1F15D6F9-5D1F-4AD6-A4EE-694EFE036EFB}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe
FirewallRules: [{F10791C4-606F-4C4C-9C4E-E30342051B84}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1363\Agent.exe
FirewallRules: [{629926D1-D5A7-41DA-8DF9-B6A5645BADA3}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1363\Agent.exe
FirewallRules: [{F65C5BF3-7BFC-44AD-89E5-5A24862D672A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1363\Agent.exe
FirewallRules: [{AA957814-5F96-4FAC-ABFE-253B33FE784B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1363\Agent.exe
FirewallRules: [{2070E58C-F2EE-47D4-B979-6563A4721E91}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9015F7C1-03B1-49A9-975B-E10239FD84D9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{F3FD043A-0FDE-4910-B9B2-D163A0D31EF9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe
FirewallRules: [{39FBAB6E-5C06-4A16-B8FE-9424E5707CCC}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe
FirewallRules: [{EF6F16F5-CEA7-4FB2-9A55-7B8F36F90920}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1637\Agent.exe
FirewallRules: [{968EE181-C2B2-4976-8DF4-A0F42AA6C473}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1637\Agent.exe
FirewallRules: [{AE1E2C08-0071-4FBF-88DF-34ABF90631AE}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{82D68BD1-7E2B-4225-ADAB-C5F74FB99FA1}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{0214F5EF-4D01-45C9-892D-BEAC6566AEB5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1675\Agent.exe
FirewallRules: [{4AF19BE0-07C6-42D6-8E88-481C6E10534F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1675\Agent.exe
FirewallRules: [{14101907-AB5E-4B52-A360-8DBCED282B16}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1675\Agent.exe
FirewallRules: [{70FE2AC5-7E46-467B-9E51-6A6BD45DD526}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1675\Agent.exe
FirewallRules: [{47085C9C-090E-423F-B884-347B72E43876}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe
FirewallRules: [{55131776-5007-468E-9247-14CAC68EF364}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe
FirewallRules: [TCP Query User{3ED01829-92BE-47A8-A5F8-B07279A579B8}C:\programdata\battle.net\agent\agent.2000\agent.exe] => (Block) C:\programdata\battle.net\agent\agent.2000\agent.exe
FirewallRules: [UDP Query User{79EB8DDB-E09D-42BD-8C80-0D03D7A520A2}C:\programdata\battle.net\agent\agent.2000\agent.exe] => (Block) C:\programdata\battle.net\agent\agent.2000\agent.exe
FirewallRules: [{344B2303-8692-4341-911D-5D0CBDC65837}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2006\Agent.exe
FirewallRules: [{A0B251D6-38D0-4D1E-B00B-F68CC2396FE0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2006\Agent.exe
FirewallRules: [{0E65A494-DA6C-45D0-AF41-3BEA0D7396A1}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2045\Agent.exe
FirewallRules: [{30224012-4400-43AC-8C30-93BA876CEFBA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2045\Agent.exe
FirewallRules: [{045FDD7F-7527-4C7D-88CB-3EB2D88A35FD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe
FirewallRules: [{014338BD-EB83-4628-B12B-968BBAE20F69}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe
FirewallRules: [{9D815E6B-2D10-4055-A105-27802296BFD9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{8F364CDC-9704-4696-8B27-771812911EB6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{A0EB5B16-5833-4C41-AD9E-A9B994219886}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{BDFB8014-6028-43B7-A847-50485472895E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6zm.exe
FirewallRules: [{A770344B-AC07-45C4-944A-696774C0AE9D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty Black Ops II\t6zm.exe
FirewallRules: [{5E0A48AB-4644-4D30-B029-57CACC598F6B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Loadout\Loadout.exe
FirewallRules: [{B431A530-29E2-4C46-AAAB-49FA8A562D53}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Loadout\Loadout.exe
FirewallRules: [{6A27F057-44D1-41AC-A780-A4E3670ADB7E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2689\Agent.exe
FirewallRules: [{DF92701E-2E42-4F19-A201-727EB09023EB}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2689\Agent.exe
FirewallRules: [{CCC7D655-21F3-425B-BEE5-5548D4723649}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe
FirewallRules: [{62A7EDD9-99B3-40B2-A759-431E2E9318DF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe
FirewallRules: [{6425CE97-A82A-427C-A1FE-F0DD5FD88321}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{C2425020-2C53-441C-B46F-528B041B20E3}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [TCP Query User{0F899503-4F49-4B0E-9BE1-3837A5E5EAEB}C:\programdata\battle.net\agent\agent.beta.2737\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.beta.2737\agent.exe
FirewallRules: [UDP Query User{E37FF7CA-8E3B-40BD-8209-8AFC2A86DDF2}C:\programdata\battle.net\agent\agent.beta.2737\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.beta.2737\agent.exe
FirewallRules: [TCP Query User{B96AE211-44A8-4263-B9F6-A559A7A4CCDA}C:\programdata\battle.net\agent\agent.beta.2753\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.beta.2753\agent.exe
FirewallRules: [UDP Query User{0AB82E04-5B1D-480B-9F46-8874C6C2441B}C:\programdata\battle.net\agent\agent.beta.2753\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.beta.2753\agent.exe
FirewallRules: [{B1B1C28E-09B2-4AFB-ACD4-E8A8F08C0D1A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe
FirewallRules: [{C72C0ADD-3383-4727-819E-684F46926091}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe
FirewallRules: [{2BFC2550-A607-4CC9-A35B-04C5D1826E6C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe
FirewallRules: [{9586A481-2E6C-4D41-AD6A-F0344188C89F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe
FirewallRules: [TCP Query User{0D293ECD-6D28-4273-B35E-B52A53BD41CA}C:\programdata\battle.net\agent\agent.2880\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.2880\agent.exe
FirewallRules: [UDP Query User{A837366E-D575-4DC9-B40C-88C07F18F224}C:\programdata\battle.net\agent\agent.2880\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.2880\agent.exe
FirewallRules: [TCP Query User{1358A3CD-A33F-4762-AE84-5E1D74EBA1A9}C:\programdata\battle.net\agent\agent.3023\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3023\agent.exe
FirewallRules: [UDP Query User{44D01E67-13C3-4F25-BA5E-E95DE6E79EBA}C:\programdata\battle.net\agent\agent.3023\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3023\agent.exe
FirewallRules: [TCP Query User{8372E4DB-D843-441F-A7A0-D44D202A7A77}C:\programdata\battle.net\agent\agent.3109\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3109\agent.exe
FirewallRules: [UDP Query User{043C90F8-EF79-4B60-BCC9-87BC61DC3750}C:\programdata\battle.net\agent\agent.3109\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3109\agent.exe
FirewallRules: [TCP Query User{C9C61A27-20E3-408F-9ACD-DB5BB8732303}C:\programdata\battle.net\agent\agent.3147\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3147\agent.exe
FirewallRules: [UDP Query User{709FB9AC-729E-4C00-BEA0-C11BC9B5DA3E}C:\programdata\battle.net\agent\agent.3147\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3147\agent.exe
FirewallRules: [TCP Query User{ADA7ABAA-F0F1-4D56-8B40-21F3000A72CD}C:\programdata\battle.net\agent\agent.3182\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3182\agent.exe
FirewallRules: [UDP Query User{9D5B9A67-97A1-452A-B5DF-64DF1E7D3F1C}C:\programdata\battle.net\agent\agent.3182\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3182\agent.exe
FirewallRules: [TCP Query User{6EAC2EA2-6143-47CB-8B5A-E4CD35CCAA48}C:\programdata\battle.net\agent\agent.3235\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3235\agent.exe
FirewallRules: [UDP Query User{A42FA79F-1E48-4CA9-92ED-2297394723EE}C:\programdata\battle.net\agent\agent.3235\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3235\agent.exe
FirewallRules: [TCP Query User{805FE87C-9096-4EB0-9E8C-5F922BFA948B}C:\programdata\battle.net\agent\agent.3286\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3286\agent.exe
FirewallRules: [UDP Query User{9EC09586-D0FF-4B17-A0DB-873C5AB400C2}C:\programdata\battle.net\agent\agent.3286\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3286\agent.exe
FirewallRules: [TCP Query User{8CB627D0-F97A-4552-9520-632EC79AD349}C:\programdata\battle.net\agent\agent.3322\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3322\agent.exe
FirewallRules: [UDP Query User{E43FD89E-57B9-45F0-9C72-5BBEA4404B7B}C:\programdata\battle.net\agent\agent.3322\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3322\agent.exe
FirewallRules: [TCP Query User{3E1E70CC-1CA2-4948-B303-B0F1A1A993C1}C:\programdata\battle.net\agent\agent.3323\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3323\agent.exe
FirewallRules: [UDP Query User{14D0E658-D8D1-4CB0-91E8-987066AE5E5D}C:\programdata\battle.net\agent\agent.3323\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3323\agent.exe
FirewallRules: [TCP Query User{159DE811-A3F7-4EBA-A7C6-DBCBCA2721F6}C:\programdata\battle.net\agent\agent.3332\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3332\agent.exe
FirewallRules: [UDP Query User{5FDF4479-7CB4-4725-80A9-0D009DBFD5DE}C:\programdata\battle.net\agent\agent.3332\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3332\agent.exe
FirewallRules: [{13C41B3A-3D91-47EA-86FD-388E76B2D5C6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3334\Agent.exe
FirewallRules: [{4966796B-6018-464B-AF3D-483A086E68C4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3334\Agent.exe
FirewallRules: [TCP Query User{E5C3C24F-79A1-4F04-84B2-1EA05B3691D8}C:\programdata\battle.net\agent\agent.3346\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3346\agent.exe
FirewallRules: [UDP Query User{4F6099B2-5E85-475E-9B5E-DF5DE550865E}C:\programdata\battle.net\agent\agent.3346\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3346\agent.exe
FirewallRules: [TCP Query User{A15444EF-4449-4843-B76F-DC286D4D1896}C:\programdata\battle.net\agent\agent.3372\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3372\agent.exe
FirewallRules: [UDP Query User{C2ABC310-F41D-43BF-B02B-38585F05741C}C:\programdata\battle.net\agent\agent.3372\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3372\agent.exe
FirewallRules: [TCP Query User{0D097893-FF32-4B69-A428-4DF484F6BA85}C:\programdata\battle.net\agent\agent.3427\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3427\agent.exe
FirewallRules: [UDP Query User{97B12DC6-BEF5-456F-AA8C-5CEE7EA72CF6}C:\programdata\battle.net\agent\agent.3427\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3427\agent.exe
FirewallRules: [TCP Query User{15D2A26F-9419-46C3-B8E4-F28278D40B87}C:\programdata\battle.net\agent\agent.3454\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3454\agent.exe
FirewallRules: [UDP Query User{F39B6B33-45C7-401E-A7B8-8584E2BD4E9F}C:\programdata\battle.net\agent\agent.3454\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3454\agent.exe
FirewallRules: [{9534E308-E9A6-4511-A0F0-06A462F19C18}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3478\Agent.exe
FirewallRules: [{30DC7504-9649-4B9A-9AA3-01862BA288E3}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3478\Agent.exe
FirewallRules: [TCP Query User{B9BCE314-82A9-4907-B265-8E324FA55CF6}C:\programdata\battle.net\agent\agent.3507\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3507\agent.exe
FirewallRules: [UDP Query User{C5CD4A59-064C-47E8-997A-93B58F77AC34}C:\programdata\battle.net\agent\agent.3507\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3507\agent.exe
FirewallRules: [{51FA38F8-D8E1-481C-9514-B411A40278DE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe
FirewallRules: [{40682BDD-BF37-4EBF-94EC-47BE5D600DD9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe
FirewallRules: [TCP Query User{D545098B-7077-473A-874F-DBE9AAB5E07A}C:\programdata\battle.net\agent\agent.3632\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3632\agent.exe
FirewallRules: [UDP Query User{EC360A31-27D0-4159-9F5C-D10F2E98D8C2}C:\programdata\battle.net\agent\agent.3632\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.3632\agent.exe
FirewallRules: [{FC5BB6A7-3516-4282-9E81-9B347C084301}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{AF22A538-0721-44EB-BD28-DE4DED36636D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [TCP Query User{9C6837D8-68B5-4A4D-9B17-C215A418D187}C:\programdata\battle.net\agent\agent.3668\agent.exe] => (Block) C:\programdata\battle.net\agent\agent.3668\agent.exe
FirewallRules: [UDP Query User{5B0267E0-9763-44C4-8A8E-00E69C9B7970}C:\programdata\battle.net\agent\agent.3668\agent.exe] => (Block) C:\programdata\battle.net\agent\agent.3668\agent.exe
FirewallRules: [TCP Query User{60E9BC96-E131-4269-B5BE-441A34AA038C}C:\programdata\battle.net\agent\agent.3669\agent.exe] => (Block) C:\programdata\battle.net\agent\agent.3669\agent.exe
FirewallRules: [UDP Query User{13A184F3-1CBB-4A4C-9AC4-E63ECB573032}C:\programdata\battle.net\agent\agent.3669\agent.exe] => (Block) C:\programdata\battle.net\agent\agent.3669\agent.exe
FirewallRules: [{BE4F8501-A4DB-4C4A-8450-C2BE700112D6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3688\Agent.exe
FirewallRules: [{C833A007-8ECF-419B-A6F2-B3A9D14EE75A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3688\Agent.exe
FirewallRules: [TCP Query User{AE80F763-4C51-4228-9033-B5D168D58D75}C:\programdata\battle.net\agent\agent.3689\agent.exe] => (Block) C:\programdata\battle.net\agent\agent.3689\agent.exe
FirewallRules: [UDP Query User{AB73FFAE-8DC8-43E1-89BE-C43E5F38DDC0}C:\programdata\battle.net\agent\agent.3689\agent.exe] => (Block) C:\programdata\battle.net\agent\agent.3689\agent.exe
FirewallRules: [{3E8131AD-690C-4224-BD35-BEB03F0B1040}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe
FirewallRules: [{A22EC343-0E37-4B9A-BAA8-DB18CE5F6971}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe
FirewallRules: [{C24E650E-C9B8-4E13-9306-DEB8ADC761B0}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/22/2015 02:20:23 PM) (Source: Steam Client Service) (EventID: 1) (User: )
Description: Error: Failed to poke open firewall
 
Error: (07/22/2015 02:20:21 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/22/2015 09:21:08 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/22/2015 09:21:04 AM) (Source: Steam Client Service) (EventID: 1) (User: )
Description: Error: Failed to poke open firewall
 
Error: (07/22/2015 05:25:46 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/22/2015 05:21:29 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 428
 
Start Time: 01d0c467eacfd3ff
 
Termination Time: 0
 
Application Path: C:\Windows\Explorer.EXE
 
Report Id:
 
Error: (07/22/2015 05:21:22 AM) (Source: ESENT) (EventID: 215) (User: )
Description: WinMail (5080) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed.
 
Error: (07/22/2015 05:21:03 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program SuperOptimizer.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: a18
 
Start Time: 01d0c467ed2ed2e5
 
Termination Time: 0
 
Application Path: C:\Program Files (x86)\Super Optimizer\SuperOptimizer.exe
 
Report Id:
 
Error: (07/22/2015 05:20:55 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/22/2015 05:17:06 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17909, time stamp: 0x55844c24
Faulting module name: ntdll.dll, version: 6.1.7601.18869, time stamp: 0x55636317
Exception code: 0xc0000374
Fault offset: 0x000cea5f
Faulting process id: 0x5a74
Faulting application start time: 0xIEXPLORE.EXE0
Faulting application path: IEXPLORE.EXE1
Faulting module path: IEXPLORE.EXE2
Report Id: IEXPLORE.EXE3
 
 
System errors:
=============
Error: (07/22/2015 02:21:46 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error: 
%%1069
 
Error: (07/22/2015 02:21:46 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: 
%%1330
 
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
 
Error: (07/22/2015 09:22:17 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error: 
%%1069
 
Error: (07/22/2015 09:22:17 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: 
%%1330
 
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
 
Error: (07/22/2015 09:14:21 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (07/22/2015 09:14:21 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (07/22/2015 09:14:21 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (07/22/2015 09:12:13 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (07/22/2015 09:12:13 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (07/22/2015 09:12:13 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
 
Microsoft Office:
=========================
Error: (07/22/2015 02:20:23 PM) (Source: Steam Client Service) (EventID: 1) (User: )
Description: Failed to poke open firewall
 
Error: (07/22/2015 02:20:21 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/22/2015 09:21:08 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/22/2015 09:21:04 AM) (Source: Steam Client Service) (EventID: 1) (User: )
Description: Failed to poke open firewall
 
Error: (07/22/2015 05:25:46 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/22/2015 05:21:29 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Explorer.EXE6.1.7601.1756742801d0c467eacfd3ff0C:\Windows\Explorer.EXE
 
Error: (07/22/2015 05:21:22 AM) (Source: ESENT) (EventID: 215) (User: )
Description: WinMail5080WindowsMail0:
 
Error: (07/22/2015 05:21:03 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: SuperOptimizer.exe0.0.0.0a1801d0c467ed2ed2e50C:\Program Files (x86)\Super Optimizer\SuperOptimizer.exe
 
Error: (07/22/2015 05:20:55 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/22/2015 05:17:06 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: IEXPLORE.EXE11.0.9600.1790955844c24ntdll.dll6.1.7601.1886955636317c0000374000cea5f5a7401d0c4678c9e1e52C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SysWOW64\ntdll.dllcd53a16d-305a-11e5-9217-001fbc0dc707
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i7 CPU 930 @ 2.80GHz
Percentage of memory in use: 37%
Total physical RAM: 6135.14 MB
Available physical RAM: 3851.54 MB
Total Virtual: 12268.5 MB
Available Virtual: 9616.57 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:1397.17 GB) (Free:1236.47 GB) NTFS
Drive e: () (Fixed) (Total:931.5 GB) (Free:289.63 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1397.3 GB) (Disk ID: EE7E9EF6)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=1397.2 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: E14FE14F)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)
 
==================== End of log ============================
 
 
 
 

  • 0

Advertisements


#2
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,792 posts
Hi! My name is zep516 and Welcome to Geekstogo!
I'll do the best I can to resolve your computer issue
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, don't continue Stop and ask! Never be afraid to ask questions! :)

I need a bit of time to get started with a fix, you have got nailed pretty good.
  • 0

#3
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,792 posts
First
Please remove these programs from your programs an features list, Start > Control panel > Programs an features. In the list find the program listed below and uninstall it.
  • globalupdate Helper
  • Health Alert
  • YTDownloader
    If a program will not remove skip it and keep following instructions please.

    Next

    A few items to fix

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
    Open notepad (Start =>All Programs => Accessories => Notepad).
    Copy/Paste the contents of the code box below into Notepad.
    start
    CloseProcesses:
    CreateRestorePoint:
    AppInit_DLLs-x32: c:\progra~3\flashb~1\flashb~1.dll => "c:\progra~3\flashb~1\flashb~1.dll" File not found
    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
    ProxyServer: [.DEFAULT] => http=127.0.0.1:47574
    ProxyServer: [S-1-5-21-2309807771-1447711736-656462262-1000] => http=127.0.0.1:47574
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
    2015-07-22 05:22 - 2015-07-22 14:43 - 00000978 _____ C:\Windows\Tasks\wQmfRNclS.job
    2015-07-22 05:22 - 2015-07-22 09:17 - 00003992 _____ C:\Windows\System32\Tasks\wQmfRNclS
    2015-07-22 05:22 - 2015-07-22 14:43 - 00000978 _____ C:\Windows\Tasks\wQmfRNclS.job
    2015-07-22 05:22 - 2015-07-22 09:17 - 00003992 _____ C:\Windows\System32\Tasks\wQmfRNclS
    2015-07-22 04:06 - 2015-07-22 16:28 - 00000992 _____ C:\Windows\Tasks\29KouX8P5QCtjDVi.job
    2015-07-22 04:06 - 2015-07-22 04:06 - 00004006 _____ C:\Windows\System32\Tasks\29KouX8P5QCtjDVi
    2015-07-22 02:35 - 2015-07-22 05:18 - 00089365 _____ C:\ProgramData\8z41L16n.dat
    2015-07-22 02:07 - 2015-07-22 15:26 - 00000988 _____ C:\Windows\Tasks\d7musQEpmoFigE.job
    2015-07-22 02:07 - 2015-07-22 02:07 - 00004002 _____ C:\Windows\System32\Tasks\d7musQEpmoFigE
    2015-07-22 01:38 - 2015-07-22 01:38 - 00000000 ____D C:\Users\jp\AppData\Local\HealthAlert
    2015-07-22 01:38 - 2015-07-22 01:38 - 00000000 ____D C:\HealthAlert
    2015-07-22 00:07 - 2015-07-22 18:01 - 00000986 _____ C:\Windows\Tasks\pSt8fpwyBUBMn.job
    2015-07-22 00:07 - 2015-07-22 00:07 - 00004000 _____ C:\Windows\System32\Tasks\pSt8fpwyBUBMn
    2015-07-21 22:54 - 2015-07-21 22:54 - 00003972 _____ C:\Windows\System32\Tasks\LaunchPreSignup
    2015-07-21 22:52 - 2015-07-22 14:19 - 00000000 ____D C:\Program Files (x86)\YTDownloader
    2015-07-21 22:52 - 2015-07-21 22:52 - 00003892 _____ C:\Windows\System32\Tasks\YTDownloaderUpd
    2015-07-21 22:52 - 2015-07-21 22:52 - 00003838 _____ C:\Windows\System32\Tasks\Smp
    2015-07-21 22:52 - 2015-07-21 22:52 - 00003570 _____ C:\Windows\System32\Tasks\YTDownloader
    2015-07-21 22:43 - 2015-07-22 02:43 - 00003450 _____ C:\Windows\System32\Tasks\Onkavatiiihm
    2015-07-21 22:38 - 2015-07-22 10:21 - 00000000 ____D C:\ProgramData\DataFile
    2015-07-21 22:38 - 2015-07-21 22:38 - 00002615 _____ C:\Users\Public\Desktop\Win PC Optimizer.lnk
    2015-07-21 22:38 - 2015-07-21 22:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Win PC Optimizer
    2015-07-21 22:38 - 2015-07-21 22:38 - 00000000 ____D C:\Program Files (x86)\WinPCOptimizer
    2015-07-21 22:35 - 2015-07-21 22:35 - 00000000 ____D C:\ProgramData\637633ac000009ce
    2015-07-21 22:09 - 2015-07-22 14:19 - 00001000 _____ C:\Windows\Tasks\RXPrXnf6sA4m3yfQZl0W.job
    2015-07-21 22:09 - 2015-07-21 22:09 - 00004014 _____ C:\Windows\System32\Tasks\RXPrXnf6sA4m3yfQZl0W
    2015-07-21 22:07 - 2015-07-22 09:16 - 00000000 ____D C:\Program Files (x86)\globalUpdate
    2015-07-21 20:02 - 2015-07-21 20:02 - 00000000 ____D C:\ProgramData\dbd6c89a0000265f
    2015-07-21 19:46 - 2015-07-22 16:51 - 00000336 ____H C:\Windows\Tasks\DFOYLGNPBBOIGEUE.job
    2015-07-21 19:46 - 2015-07-22 14:19 - 00000324 _____ C:\Windows\Tasks\DAHCX1.job
    2015-07-21 19:46 - 2015-07-21 19:46 - 00003364 _____ C:\Windows\System32\Tasks\DFOYLGNPBBOIGEUE
    2015-07-21 19:46 - 2015-07-21 19:46 - 00002846 _____ C:\Windows\System32\Tasks\DAHCX1
    2015-07-21 19:46 - 2015-07-21 19:46 - 00000000 ____D C:\ProgramData\28341ff220e0446c9fff27c4493d622e
    C:\ProgramData\8z41L16n.dat
    Task: {02E08FBC-6B8C-4125-90B9-3CC7461E8A3D} - System32\Tasks\29KouX8P5QCtjDVi => C:\Users\jp\AppData\Roaming\29KouX8P5QCtjDVi.exe <==== ATTENTION
    Task: {11E0FEEB-D2E5-4AF2-ABF2-B68C757AB524} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-1-6 No Task File <==== ATTENTION
    C:\Users\jp\AppData\Roaming\29KouX8P5QCtjDVi.exe
    Task: {1D4EDC70-1A53-413D-ACCC-A7215D284850} - \Super Optimizer Schedule No Task File <==== ATTENTION
    Task: {2C4DC035-7C33-49A8-B439-CDBFD540056B} - \APSnotifierPP3 No Task File <==== ATTENTION
    Task: {2EAF9767-53EB-47B0-B6BD-B7D4DB235DDE} - \SMupdate1 No Task File <==== ATTENTION
    Task: {338B9654-7894-445B-B060-DB7F202DB5DC} - System32\Tasks\YTDownloader => C:\Program Files (x86)\YTDownloader\YTDownloader.exe <==== ATTENTION
    C:\Program Files (x86)\YTDownloader
    Task: {3D2EA2AE-DF2B-49B6-8D84-3C27E6978B45} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3 <==== ATTENTION
    Task: {3DFAB371-FFF5-42CF-896C-8B863A564E5B} - System32\Tasks\Onkavatiiihm => C:\ProgramData\Onkavatiiihm\1.0.4.1\jsixetek.exe
    Task: {3E46DBD6-94DB-4E80-9BF2-45F29EE71E51} - \SMW_UpdateTask_Time_3338343934393333382d3437415a556c2a3223346c41 No Task File <==== ATTENTION
    Task: {3ED523FA-4280-4A2C-955F-D6D3D022FCE3} - System32\Tasks\Smp => C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smp.exe <==== ATTENTION
    Task: {3FF480CF-C08F-4062-BCC7-597EB9C41083} - \Bidaily Synchronize Task[8da6] No Task File <==== ATTENTION
    Task: {48AF4823-CFB3-4F2A-8D21-9084B7AE5662} - System32\Tasks\DAHCX1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
    Task: {4B6183C7-5C6D-40F4-BF7C-5953D3BEF640} - System32\Tasks\AA860BD4-5274-45AC-B02E-AA6F5A64B7F => C:\Users\jp\AppData\Local\AA860BD4-5274-45AC-B02E-AA6F5A64B7F\AA860BD4-5274-45AC-B02E-AA6F5A64B7F.exe <==== ATTENTION
    Task: {52A2C8C8-AB59-48FC-B3BE-8E9E5B045546} - System32\Tasks\wQmfRNclS => C:\Users\jp\AppData\Roaming\wQmfRNclS.exe <==== ATTENTION
    Task: {5C7B2767-D4D7-4AAF-B0C4-9B32EBC87E65} - \APSnotifierPP1 No Task File <==== ATTENTION
    Task: {5E6028ED-0CFB-492C-93B9-19C2D5BECDEB} - \SMWPUpd No Task File <==== ATTENTION
    Task: {5FD4B11B-2278-4E91-B9D4-28E836883534} - System32\Tasks\d7musQEpmoFigE => C:\Users\jp\AppData\Roaming\d7musQEpmoFigE.exe <==== ATTENTION
    Task: {69BBC392-B114-4060-9F5B-AC88047A89E1} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
    Task: {732FB463-819B-4E65-8A53-35E4E17F077C} - \SmartWeb Upgrade Trigger Task No Task File <==== ATTENTION
    Task: {796CBCFE-BBF9-4EED-A351-E431FC04E196} - System32\Tasks\RXPrXnf6sA4m3yfQZl0W => C:\Users\jp\AppData\Roaming\RXPrXnf6sA4m3yfQZl0W.exe <==== ATTENTION
    Task: {79B2E546-51C4-4E8E-93EF-D05F90783921} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-7 No Task File <==== ATTENTION
    Task: {8684C6BD-FB1B-4C22-BCC5-BA576BBC7173} - System32\Tasks\YTDownloaderUpd => C:\Program Files (x86)\YTDownloader\updater.exe <==== ATTENTION
    Task: {95C217F8-1C00-4C8F-B0EE-AB0CDBE53D87} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
    Task: {95FD0D33-B414-446E-A1A0-93B0E856813F} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-10_user No Task File <==== ATTENTION
    Task: {9907CA38-44BA-4C49-9350-81D11166D4F8} - \APSnotifierPP2 No Task File <==== ATTENTION
    Task: {9DFA095B-C612-4BD9-8324-F431D04BE7D7} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update2 <==== ATTENTION
    Task: {9ECE0643-1EA1-41E6-A43D-0D370AD66A18} - \Tny_Cassiopesa No Task File <==== ATTENTION
    Task: {A7DCE32B-99F7-4EEF-B208-E0E9623889BD} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-3 No Task File <==== ATTENTION
    Task: {BA192C50-A8B4-4A2C-B791-583B5BC410C5} - System32\Tasks\pSt8fpwyBUBMn => C:\Users\jp\AppData\Roaming\pSt8fpwyBUBMn.exe <==== ATTENTION
    Task: {C294357E-2A44-43A8-AB6D-C76E6F8B17D6} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-6 No Task File <==== ATTENTION
    Task: {C65B5A35-3B30-43A5-AFF0-2FB74D9E31A8} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-5_user No Task File <==== ATTENTION
    Task: {D1ED8231-6334-487F-82C7-FB4FFE81699F} - System32\Tasks\DFOYLGNPBBOIGEUE => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
    Task: {D3812DC5-739D-4C15-9E3D-1DD24F50C12A} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-5 No Task File <==== ATTENTION
    Task: {DA90A49E-CFA3-4832-B90A-A8AAF55232F1} - System32\Tasks\LaunchPreSignup => C:\Program Files (x86)\OLBPre\OLBPre.exe <==== ATTENTION
    Task: {FC7E6B07-3FC9-4330-841E-18190BF690AE} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-1-7 No Task File <==== ATTENTION
    C:\ProgramData\Service1291 
    C:\Program Files (x86)\OLBPre
    Task: C:\Windows\Tasks\29KouX8P5QCtjDVi.job => C:\Users\jp\AppData\Roaming\29KouX8P5QCtjDVi.exe <==== ATTENTION
    Task: C:\Windows\Tasks\d7musQEpmoFigE.job => C:\Users\jp\AppData\Roaming\d7musQEpmoFigE.exe <==== ATTENTION
    Task: C:\Windows\Tasks\DAHCX1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
    Task: C:\Windows\Tasks\DFOYLGNPBBOIGEUE.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
    Task: C:\Windows\Tasks\pSt8fpwyBUBMn.job => C:\Users\jp\AppData\Roaming\pSt8fpwyBUBMn.exe <==== ATTENTION
    Task: C:\Windows\Tasks\RXPrXnf6sA4m3yfQZl0W.job => C:\Users\jp\AppData\Roaming\RXPrXnf6sA4m3yfQZl0W.exe <==== ATTENTION
    Task: C:\Windows\Tasks\wQmfRNclS.job => C:\Users\jp\AppData\Roaming\wQmfRNclS.exe <==== ATTENTION
    AlternateDataStreams: C:\ProgramData\TEMP:054203E4
    CMD: bitsadmin /reset /allusers
    CMD: netsh winsock reset catalog
    CMD: ipconfig /flushdns
    RemoveProxy:
    hosts:
    Emptytemp:
    
    Click Format and ensure Wordwrap is unchecked.
    Save as Fixlist.txt to your Desktop (Must be in this location)
    Run FRST/FRST64 and press the Fix button just once and wait.
    If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
    The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
    Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.

    Next

    Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the logfile button and the log will open in Notepad.
  • NOTE: If you get an error message, it means that nothing was found. Exit from AdwCleaner.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished and the PC has rebooted.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner

    Next

    thisisujrt.gif Please download Junkware Removal Tool to your Desktop.
    Please close your security software to avoid potential conflicts. See Here how to disable you security protection (Anti Virus)
    Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
    The tool will open and start scanning your system.
    Please be patient as this can take a while to complete, depending on your system's specifications.
    On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
    Please post the contents of JRT.txt into your reply.

    In your next reply post;

  • Fixlog.txt
  • The AdwCleaner [SO].txt Log
  • The JRT.txt Log
    Thanks
    Joe :)

  • 0

#4
jpatt

jpatt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts

thanks for your speedy response. attempted to remove processes no luck.

 

log requested.

 

==========================================================

 

Fix result of Farbar Recovery Scan Tool (x64) Version:20-07-2015
Ran by jp at 2015-07-22 21:05:15 Run:1
Running from C:\Users\jp\Desktop
Loaded Profiles: jp (Available Profiles: jp & UpdatusUser)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
start
CloseProcesses:
CreateRestorePoint:
AppInit_DLLs-x32: c:\progra~3\flashb~1\flashb~1.dll => "c:\progra~3\flashb~1\flashb~1.dll" File not found
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:47574
ProxyServer: [S-1-5-21-2309807771-1447711736-656462262-1000] => http=127.0.0.1:47574
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
2015-07-22 05:22 - 2015-07-22 14:43 - 00000978 _____ C:\Windows\Tasks\wQmfRNclS.job
2015-07-22 05:22 - 2015-07-22 09:17 - 00003992 _____ C:\Windows\System32\Tasks\wQmfRNclS
2015-07-22 05:22 - 2015-07-22 14:43 - 00000978 _____ C:\Windows\Tasks\wQmfRNclS.job
2015-07-22 05:22 - 2015-07-22 09:17 - 00003992 _____ C:\Windows\System32\Tasks\wQmfRNclS
2015-07-22 04:06 - 2015-07-22 16:28 - 00000992 _____ C:\Windows\Tasks\29KouX8P5QCtjDVi.job
2015-07-22 04:06 - 2015-07-22 04:06 - 00004006 _____ C:\Windows\System32\Tasks\29KouX8P5QCtjDVi
2015-07-22 02:35 - 2015-07-22 05:18 - 00089365 _____ C:\ProgramData\8z41L16n.dat
2015-07-22 02:07 - 2015-07-22 15:26 - 00000988 _____ C:\Windows\Tasks\d7musQEpmoFigE.job
2015-07-22 02:07 - 2015-07-22 02:07 - 00004002 _____ C:\Windows\System32\Tasks\d7musQEpmoFigE
2015-07-22 01:38 - 2015-07-22 01:38 - 00000000 ____D C:\Users\jp\AppData\Local\HealthAlert
2015-07-22 01:38 - 2015-07-22 01:38 - 00000000 ____D C:\HealthAlert
2015-07-22 00:07 - 2015-07-22 18:01 - 00000986 _____ C:\Windows\Tasks\pSt8fpwyBUBMn.job
2015-07-22 00:07 - 2015-07-22 00:07 - 00004000 _____ C:\Windows\System32\Tasks\pSt8fpwyBUBMn
2015-07-21 22:54 - 2015-07-21 22:54 - 00003972 _____ C:\Windows\System32\Tasks\LaunchPreSignup
2015-07-21 22:52 - 2015-07-22 14:19 - 00000000 ____D C:\Program Files (x86)\YTDownloader
2015-07-21 22:52 - 2015-07-21 22:52 - 00003892 _____ C:\Windows\System32\Tasks\YTDownloaderUpd
2015-07-21 22:52 - 2015-07-21 22:52 - 00003838 _____ C:\Windows\System32\Tasks\Smp
2015-07-21 22:52 - 2015-07-21 22:52 - 00003570 _____ C:\Windows\System32\Tasks\YTDownloader
2015-07-21 22:43 - 2015-07-22 02:43 - 00003450 _____ C:\Windows\System32\Tasks\Onkavatiiihm
2015-07-21 22:38 - 2015-07-22 10:21 - 00000000 ____D C:\ProgramData\DataFile
2015-07-21 22:38 - 2015-07-21 22:38 - 00002615 _____ C:\Users\Public\Desktop\Win PC Optimizer.lnk
2015-07-21 22:38 - 2015-07-21 22:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Win PC Optimizer
2015-07-21 22:38 - 2015-07-21 22:38 - 00000000 ____D C:\Program Files (x86)\WinPCOptimizer
2015-07-21 22:35 - 2015-07-21 22:35 - 00000000 ____D C:\ProgramData\637633ac000009ce
2015-07-21 22:09 - 2015-07-22 14:19 - 00001000 _____ C:\Windows\Tasks\RXPrXnf6sA4m3yfQZl0W.job
2015-07-21 22:09 - 2015-07-21 22:09 - 00004014 _____ C:\Windows\System32\Tasks\RXPrXnf6sA4m3yfQZl0W
2015-07-21 22:07 - 2015-07-22 09:16 - 00000000 ____D C:\Program Files (x86)\globalUpdate
2015-07-21 20:02 - 2015-07-21 20:02 - 00000000 ____D C:\ProgramData\dbd6c89a0000265f
2015-07-21 19:46 - 2015-07-22 16:51 - 00000336 ____H C:\Windows\Tasks\DFOYLGNPBBOIGEUE.job
2015-07-21 19:46 - 2015-07-22 14:19 - 00000324 _____ C:\Windows\Tasks\DAHCX1.job
2015-07-21 19:46 - 2015-07-21 19:46 - 00003364 _____ C:\Windows\System32\Tasks\DFOYLGNPBBOIGEUE
2015-07-21 19:46 - 2015-07-21 19:46 - 00002846 _____ C:\Windows\System32\Tasks\DAHCX1
2015-07-21 19:46 - 2015-07-21 19:46 - 00000000 ____D C:\ProgramData\28341ff220e0446c9fff27c4493d622e
C:\ProgramData\8z41L16n.dat
Task: {02E08FBC-6B8C-4125-90B9-3CC7461E8A3D} - System32\Tasks\29KouX8P5QCtjDVi => C:\Users\jp\AppData\Roaming\29KouX8P5QCtjDVi.exe <==== ATTENTION
Task: {11E0FEEB-D2E5-4AF2-ABF2-B68C757AB524} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-1-6 No Task File <==== ATTENTION
C:\Users\jp\AppData\Roaming\29KouX8P5QCtjDVi.exe
Task: {1D4EDC70-1A53-413D-ACCC-A7215D284850} - \Super Optimizer Schedule No Task File <==== ATTENTION
Task: {2C4DC035-7C33-49A8-B439-CDBFD540056B} - \APSnotifierPP3 No Task File <==== ATTENTION
Task: {2EAF9767-53EB-47B0-B6BD-B7D4DB235DDE} - \SMupdate1 No Task File <==== ATTENTION
Task: {338B9654-7894-445B-B060-DB7F202DB5DC} - System32\Tasks\YTDownloader => C:\Program Files (x86)\YTDownloader\YTDownloader.exe <==== ATTENTION
C:\Program Files (x86)\YTDownloader
Task: {3D2EA2AE-DF2B-49B6-8D84-3C27E6978B45} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3 <==== ATTENTION
Task: {3DFAB371-FFF5-42CF-896C-8B863A564E5B} - System32\Tasks\Onkavatiiihm => C:\ProgramData\Onkavatiiihm\1.0.4.1\jsixetek.exe
Task: {3E46DBD6-94DB-4E80-9BF2-45F29EE71E51} - \SMW_UpdateTask_Time_3338343934393333382d3437415a556c2a3223346c41 No Task File <==== ATTENTION
Task: {3ED523FA-4280-4A2C-955F-D6D3D022FCE3} - System32\Tasks\Smp => C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smp.exe <==== ATTENTION
Task: {3FF480CF-C08F-4062-BCC7-597EB9C41083} - \Bidaily Synchronize Task[8da6] No Task File <==== ATTENTION
Task: {48AF4823-CFB3-4F2A-8D21-9084B7AE5662} - System32\Tasks\DAHCX1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: {4B6183C7-5C6D-40F4-BF7C-5953D3BEF640} - System32\Tasks\AA860BD4-5274-45AC-B02E-AA6F5A64B7F => C:\Users\jp\AppData\Local\AA860BD4-5274-45AC-B02E-AA6F5A64B7F\AA860BD4-5274-45AC-B02E-AA6F5A64B7F.exe <==== ATTENTION
Task: {52A2C8C8-AB59-48FC-B3BE-8E9E5B045546} - System32\Tasks\wQmfRNclS => C:\Users\jp\AppData\Roaming\wQmfRNclS.exe <==== ATTENTION
Task: {5C7B2767-D4D7-4AAF-B0C4-9B32EBC87E65} - \APSnotifierPP1 No Task File <==== ATTENTION
Task: {5E6028ED-0CFB-492C-93B9-19C2D5BECDEB} - \SMWPUpd No Task File <==== ATTENTION
Task: {5FD4B11B-2278-4E91-B9D4-28E836883534} - System32\Tasks\d7musQEpmoFigE => C:\Users\jp\AppData\Roaming\d7musQEpmoFigE.exe <==== ATTENTION
Task: {69BBC392-B114-4060-9F5B-AC88047A89E1} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {732FB463-819B-4E65-8A53-35E4E17F077C} - \SmartWeb Upgrade Trigger Task No Task File <==== ATTENTION
Task: {796CBCFE-BBF9-4EED-A351-E431FC04E196} - System32\Tasks\RXPrXnf6sA4m3yfQZl0W => C:\Users\jp\AppData\Roaming\RXPrXnf6sA4m3yfQZl0W.exe <==== ATTENTION
Task: {79B2E546-51C4-4E8E-93EF-D05F90783921} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-7 No Task File <==== ATTENTION
Task: {8684C6BD-FB1B-4C22-BCC5-BA576BBC7173} - System32\Tasks\YTDownloaderUpd => C:\Program Files (x86)\YTDownloader\updater.exe <==== ATTENTION
Task: {95C217F8-1C00-4C8F-B0EE-AB0CDBE53D87} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {95FD0D33-B414-446E-A1A0-93B0E856813F} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-10_user No Task File <==== ATTENTION
Task: {9907CA38-44BA-4C49-9350-81D11166D4F8} - \APSnotifierPP2 No Task File <==== ATTENTION
Task: {9DFA095B-C612-4BD9-8324-F431D04BE7D7} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update2 <==== ATTENTION
Task: {9ECE0643-1EA1-41E6-A43D-0D370AD66A18} - \Tny_Cassiopesa No Task File <==== ATTENTION
Task: {A7DCE32B-99F7-4EEF-B208-E0E9623889BD} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-3 No Task File <==== ATTENTION
Task: {BA192C50-A8B4-4A2C-B791-583B5BC410C5} - System32\Tasks\pSt8fpwyBUBMn => C:\Users\jp\AppData\Roaming\pSt8fpwyBUBMn.exe <==== ATTENTION
Task: {C294357E-2A44-43A8-AB6D-C76E6F8B17D6} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-6 No Task File <==== ATTENTION
Task: {C65B5A35-3B30-43A5-AFF0-2FB74D9E31A8} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-5_user No Task File <==== ATTENTION
Task: {D1ED8231-6334-487F-82C7-FB4FFE81699F} - System32\Tasks\DFOYLGNPBBOIGEUE => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: {D3812DC5-739D-4C15-9E3D-1DD24F50C12A} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-5 No Task File <==== ATTENTION
Task: {DA90A49E-CFA3-4832-B90A-A8AAF55232F1} - System32\Tasks\LaunchPreSignup => C:\Program Files (x86)\OLBPre\OLBPre.exe <==== ATTENTION
Task: {FC7E6B07-3FC9-4330-841E-18190BF690AE} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-1-7 No Task File <==== ATTENTION
C:\ProgramData\Service1291 
C:\Program Files (x86)\OLBPre
Task: C:\Windows\Tasks\29KouX8P5QCtjDVi.job => C:\Users\jp\AppData\Roaming\29KouX8P5QCtjDVi.exe <==== ATTENTION
Task: C:\Windows\Tasks\d7musQEpmoFigE.job => C:\Users\jp\AppData\Roaming\d7musQEpmoFigE.exe <==== ATTENTION
Task: C:\Windows\Tasks\DAHCX1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: C:\Windows\Tasks\DFOYLGNPBBOIGEUE.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: C:\Windows\Tasks\pSt8fpwyBUBMn.job => C:\Users\jp\AppData\Roaming\pSt8fpwyBUBMn.exe <==== ATTENTION
Task: C:\Windows\Tasks\RXPrXnf6sA4m3yfQZl0W.job => C:\Users\jp\AppData\Roaming\RXPrXnf6sA4m3yfQZl0W.exe <==== ATTENTION
Task: C:\Windows\Tasks\wQmfRNclS.job => C:\Users\jp\AppData\Roaming\wQmfRNclS.exe <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:054203E4
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset catalog
CMD: ipconfig /flushdns
RemoveProxy:
hosts:
Emptytemp:
*****************
 
Processes closed successfully.
Restore point was successfully created.
"c:\progra~3\flashb~1\flashb~1.dll" => value data removed successfully.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value removed successfully
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully
HKU\S-1-5-21-2309807771-1447711736-656462262-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin" => key removed successfully
C:\Windows\Tasks\wQmfRNclS.job => moved successfully.
C:\Windows\System32\Tasks\wQmfRNclS => moved successfully.
"C:\Windows\Tasks\wQmfRNclS.job" => File/Folder not found.
"C:\Windows\System32\Tasks\wQmfRNclS" => File/Folder not found.
C:\Windows\Tasks\29KouX8P5QCtjDVi.job => moved successfully.
C:\Windows\System32\Tasks\29KouX8P5QCtjDVi => moved successfully.
C:\ProgramData\8z41L16n.dat => moved successfully.
C:\Windows\Tasks\d7musQEpmoFigE.job => moved successfully.
C:\Windows\System32\Tasks\d7musQEpmoFigE => moved successfully.
C:\Users\jp\AppData\Local\HealthAlert => moved successfully.
C:\HealthAlert => moved successfully.
C:\Windows\Tasks\pSt8fpwyBUBMn.job => moved successfully.
C:\Windows\System32\Tasks\pSt8fpwyBUBMn => moved successfully.
C:\Windows\System32\Tasks\LaunchPreSignup => moved successfully.
C:\Program Files (x86)\YTDownloader => moved successfully.
C:\Windows\System32\Tasks\YTDownloaderUpd => moved successfully.
C:\Windows\System32\Tasks\Smp => moved successfully.
C:\Windows\System32\Tasks\YTDownloader => moved successfully.
C:\Windows\System32\Tasks\Onkavatiiihm => moved successfully.
C:\ProgramData\DataFile => moved successfully.
C:\Users\Public\Desktop\Win PC Optimizer.lnk => moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Win PC Optimizer => moved successfully.
C:\Program Files (x86)\WinPCOptimizer => moved successfully.
C:\ProgramData\637633ac000009ce => moved successfully.
C:\Windows\Tasks\RXPrXnf6sA4m3yfQZl0W.job => moved successfully.
C:\Windows\System32\Tasks\RXPrXnf6sA4m3yfQZl0W => moved successfully.
C:\Program Files (x86)\globalUpdate => moved successfully.
C:\ProgramData\dbd6c89a0000265f => moved successfully.
C:\Windows\Tasks\DFOYLGNPBBOIGEUE.job => moved successfully.
C:\Windows\Tasks\DAHCX1.job => moved successfully.
C:\Windows\System32\Tasks\DFOYLGNPBBOIGEUE => moved successfully.
C:\Windows\System32\Tasks\DAHCX1 => moved successfully.
C:\ProgramData\28341ff220e0446c9fff27c4493d622e => moved successfully.
"C:\ProgramData\8z41L16n.dat" => File/Folder not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{02E08FBC-6B8C-4125-90B9-3CC7461E8A3D}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02E08FBC-6B8C-4125-90B9-3CC7461E8A3D}" => key removed successfully
C:\Windows\System32\Tasks\29KouX8P5QCtjDVi not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\29KouX8P5QCtjDVi" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{11E0FEEB-D2E5-4AF2-ABF2-B68C757AB524}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{11E0FEEB-D2E5-4AF2-ABF2-B68C757AB524}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-1-6" => key removed successfully
"C:\Users\jp\AppData\Roaming\29KouX8P5QCtjDVi.exe" => File/Folder not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1D4EDC70-1A53-413D-ACCC-A7215D284850}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D4EDC70-1A53-413D-ACCC-A7215D284850}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Super Optimizer Schedule" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2C4DC035-7C33-49A8-B439-CDBFD540056B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2C4DC035-7C33-49A8-B439-CDBFD540056B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP3" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2EAF9767-53EB-47B0-B6BD-B7D4DB235DDE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2EAF9767-53EB-47B0-B6BD-B7D4DB235DDE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMupdate1" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{338B9654-7894-445B-B060-DB7F202DB5DC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{338B9654-7894-445B-B060-DB7F202DB5DC}" => key removed successfully
C:\Windows\System32\Tasks\YTDownloader not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YTDownloader" => key removed successfully
"C:\Program Files (x86)\YTDownloader" => File/Folder not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3D2EA2AE-DF2B-49B6-8D84-3C27E6978B45}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3D2EA2AE-DF2B-49B6-8D84-3C27E6978B45}" => key removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Multimedia\SMupdate3" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{3DFAB371-FFF5-42CF-896C-8B863A564E5B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3DFAB371-FFF5-42CF-896C-8B863A564E5B}" => key removed successfully
C:\Windows\System32\Tasks\Onkavatiiihm not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Onkavatiiihm" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3E46DBD6-94DB-4E80-9BF2-45F29EE71E51}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E46DBD6-94DB-4E80-9BF2-45F29EE71E51}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMW_UpdateTask_Time_3338343934393333382d3437415a556c2a3223346c41" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3ED523FA-4280-4A2C-955F-D6D3D022FCE3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3ED523FA-4280-4A2C-955F-D6D3D022FCE3}" => key removed successfully
C:\Windows\System32\Tasks\Smp not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Smp" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3FF480CF-C08F-4062-BCC7-597EB9C41083}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3FF480CF-C08F-4062-BCC7-597EB9C41083}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Bidaily Synchronize Task[8da6]" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{48AF4823-CFB3-4F2A-8D21-9084B7AE5662}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{48AF4823-CFB3-4F2A-8D21-9084B7AE5662}" => key removed successfully
C:\Windows\System32\Tasks\DAHCX1 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DAHCX1" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4B6183C7-5C6D-40F4-BF7C-5953D3BEF640}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4B6183C7-5C6D-40F4-BF7C-5953D3BEF640}" => key removed successfully
C:\Windows\System32\Tasks\AA860BD4-5274-45AC-B02E-AA6F5A64B7F => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AA860BD4-5274-45AC-B02E-AA6F5A64B7F" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{52A2C8C8-AB59-48FC-B3BE-8E9E5B045546}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{52A2C8C8-AB59-48FC-B3BE-8E9E5B045546}" => key removed successfully
C:\Windows\System32\Tasks\wQmfRNclS not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\wQmfRNclS" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5C7B2767-D4D7-4AAF-B0C4-9B32EBC87E65}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5C7B2767-D4D7-4AAF-B0C4-9B32EBC87E65}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP1" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5E6028ED-0CFB-492C-93B9-19C2D5BECDEB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5E6028ED-0CFB-492C-93B9-19C2D5BECDEB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMWPUpd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5FD4B11B-2278-4E91-B9D4-28E836883534}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5FD4B11B-2278-4E91-B9D4-28E836883534}" => key removed successfully
C:\Windows\System32\Tasks\d7musQEpmoFigE not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\d7musQEpmoFigE" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{69BBC392-B114-4060-9F5B-AC88047A89E1}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{69BBC392-B114-4060-9F5B-AC88047A89E1}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{732FB463-819B-4E65-8A53-35E4E17F077C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{732FB463-819B-4E65-8A53-35E4E17F077C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SmartWeb Upgrade Trigger Task" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{796CBCFE-BBF9-4EED-A351-E431FC04E196}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{796CBCFE-BBF9-4EED-A351-E431FC04E196}" => key removed successfully
C:\Windows\System32\Tasks\RXPrXnf6sA4m3yfQZl0W not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RXPrXnf6sA4m3yfQZl0W" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{79B2E546-51C4-4E8E-93EF-D05F90783921}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79B2E546-51C4-4E8E-93EF-D05F90783921}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-7" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8684C6BD-FB1B-4C22-BCC5-BA576BBC7173}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8684C6BD-FB1B-4C22-BCC5-BA576BBC7173}" => key removed successfully
C:\Windows\System32\Tasks\YTDownloaderUpd not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YTDownloaderUpd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{95C217F8-1C00-4C8F-B0EE-AB0CDBE53D87}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95C217F8-1C00-4C8F-B0EE-AB0CDBE53D87}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{95FD0D33-B414-446E-A1A0-93B0E856813F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95FD0D33-B414-446E-A1A0-93B0E856813F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-10_user" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9907CA38-44BA-4C49-9350-81D11166D4F8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9907CA38-44BA-4C49-9350-81D11166D4F8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP2" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9DFA095B-C612-4BD9-8324-F431D04BE7D7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9DFA095B-C612-4BD9-8324-F431D04BE7D7}" => key removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Maintenance\SMupdate2" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9ECE0643-1EA1-41E6-A43D-0D370AD66A18}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9ECE0643-1EA1-41E6-A43D-0D370AD66A18}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Tny_Cassiopesa" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A7DCE32B-99F7-4EEF-B208-E0E9623889BD}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7DCE32B-99F7-4EEF-B208-E0E9623889BD}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-3" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BA192C50-A8B4-4A2C-B791-583B5BC410C5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BA192C50-A8B4-4A2C-B791-583B5BC410C5}" => key removed successfully
C:\Windows\System32\Tasks\pSt8fpwyBUBMn not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pSt8fpwyBUBMn" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C294357E-2A44-43A8-AB6D-C76E6F8B17D6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C294357E-2A44-43A8-AB6D-C76E6F8B17D6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-6" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C65B5A35-3B30-43A5-AFF0-2FB74D9E31A8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C65B5A35-3B30-43A5-AFF0-2FB74D9E31A8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-5_user" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D1ED8231-6334-487F-82C7-FB4FFE81699F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D1ED8231-6334-487F-82C7-FB4FFE81699F}" => key removed successfully
C:\Windows\System32\Tasks\DFOYLGNPBBOIGEUE not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DFOYLGNPBBOIGEUE" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D3812DC5-739D-4C15-9E3D-1DD24F50C12A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D3812DC5-739D-4C15-9E3D-1DD24F50C12A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-5" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DA90A49E-CFA3-4832-B90A-A8AAF55232F1}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA90A49E-CFA3-4832-B90A-A8AAF55232F1}" => key removed successfully
C:\Windows\System32\Tasks\LaunchPreSignup not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchPreSignup" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FC7E6B07-3FC9-4330-841E-18190BF690AE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC7E6B07-3FC9-4330-841E-18190BF690AE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-1-7" => key removed successfully
"C:\ProgramData\Service1291" => File/Folder not found.
"C:\Program Files (x86)\OLBPre" => File/Folder not found.
C:\Windows\Tasks\29KouX8P5QCtjDVi.job not found.
C:\Windows\Tasks\d7musQEpmoFigE.job not found.
C:\Windows\Tasks\DAHCX1.job not found.
C:\Windows\Tasks\DFOYLGNPBBOIGEUE.job not found.
C:\Windows\Tasks\pSt8fpwyBUBMn.job not found.
C:\Windows\Tasks\RXPrXnf6sA4m3yfQZl0W.job not found.
C:\Windows\Tasks\wQmfRNclS.job not found.
C:\ProgramData\TEMP => ":054203E4" ADS removed successfully.
 
=========  bitsadmin /reset /allusers =========
 
 
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
 
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
 
{636B83F7-2979-44B3-B4DA-472F93895B53} canceled.
{9D62877C-CE72-4E12-82C6-7609DCB3E74B} canceled.
2 out of 2 jobs canceled.
 
========= End of CMD: =========
 
 
=========  netsh winsock reset catalog =========
 
 
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
 
 
========= End of CMD: =========
 
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
========= RemoveProxy: =========
 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
 
 
========= End of RemoveProxy: =========
 
C:\Windows\System32\Drivers\etc\hosts => moved successfully.
Hosts restored successfully.
EmptyTemp: => 5.9 GB temporary data Removed.
 
 
The system needed a reboot.. 
 
==== End of Fixlog 21:06:17 ====Fix result of Farbar Recovery Scan Tool (x64) Version:20-07-2015
Ran by jp at 2015-07-22 21:05:15 Run:1
Running from C:\Users\jp\Desktop
Loaded Profiles: jp (Available Profiles: jp & UpdatusUser)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
start
CloseProcesses:
CreateRestorePoint:
AppInit_DLLs-x32: c:\progra~3\flashb~1\flashb~1.dll => "c:\progra~3\flashb~1\flashb~1.dll" File not found
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:47574
ProxyServer: [S-1-5-21-2309807771-1447711736-656462262-1000] => http=127.0.0.1:47574
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
2015-07-22 05:22 - 2015-07-22 14:43 - 00000978 _____ C:\Windows\Tasks\wQmfRNclS.job
2015-07-22 05:22 - 2015-07-22 09:17 - 00003992 _____ C:\Windows\System32\Tasks\wQmfRNclS
2015-07-22 05:22 - 2015-07-22 14:43 - 00000978 _____ C:\Windows\Tasks\wQmfRNclS.job
2015-07-22 05:22 - 2015-07-22 09:17 - 00003992 _____ C:\Windows\System32\Tasks\wQmfRNclS
2015-07-22 04:06 - 2015-07-22 16:28 - 00000992 _____ C:\Windows\Tasks\29KouX8P5QCtjDVi.job
2015-07-22 04:06 - 2015-07-22 04:06 - 00004006 _____ C:\Windows\System32\Tasks\29KouX8P5QCtjDVi
2015-07-22 02:35 - 2015-07-22 05:18 - 00089365 _____ C:\ProgramData\8z41L16n.dat
2015-07-22 02:07 - 2015-07-22 15:26 - 00000988 _____ C:\Windows\Tasks\d7musQEpmoFigE.job
2015-07-22 02:07 - 2015-07-22 02:07 - 00004002 _____ C:\Windows\System32\Tasks\d7musQEpmoFigE
2015-07-22 01:38 - 2015-07-22 01:38 - 00000000 ____D C:\Users\jp\AppData\Local\HealthAlert
2015-07-22 01:38 - 2015-07-22 01:38 - 00000000 ____D C:\HealthAlert
2015-07-22 00:07 - 2015-07-22 18:01 - 00000986 _____ C:\Windows\Tasks\pSt8fpwyBUBMn.job
2015-07-22 00:07 - 2015-07-22 00:07 - 00004000 _____ C:\Windows\System32\Tasks\pSt8fpwyBUBMn
2015-07-21 22:54 - 2015-07-21 22:54 - 00003972 _____ C:\Windows\System32\Tasks\LaunchPreSignup
2015-07-21 22:52 - 2015-07-22 14:19 - 00000000 ____D C:\Program Files (x86)\YTDownloader
2015-07-21 22:52 - 2015-07-21 22:52 - 00003892 _____ C:\Windows\System32\Tasks\YTDownloaderUpd
2015-07-21 22:52 - 2015-07-21 22:52 - 00003838 _____ C:\Windows\System32\Tasks\Smp
2015-07-21 22:52 - 2015-07-21 22:52 - 00003570 _____ C:\Windows\System32\Tasks\YTDownloader
2015-07-21 22:43 - 2015-07-22 02:43 - 00003450 _____ C:\Windows\System32\Tasks\Onkavatiiihm
2015-07-21 22:38 - 2015-07-22 10:21 - 00000000 ____D C:\ProgramData\DataFile
2015-07-21 22:38 - 2015-07-21 22:38 - 00002615 _____ C:\Users\Public\Desktop\Win PC Optimizer.lnk
2015-07-21 22:38 - 2015-07-21 22:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Win PC Optimizer
2015-07-21 22:38 - 2015-07-21 22:38 - 00000000 ____D C:\Program Files (x86)\WinPCOptimizer
2015-07-21 22:35 - 2015-07-21 22:35 - 00000000 ____D C:\ProgramData\637633ac000009ce
2015-07-21 22:09 - 2015-07-22 14:19 - 00001000 _____ C:\Windows\Tasks\RXPrXnf6sA4m3yfQZl0W.job
2015-07-21 22:09 - 2015-07-21 22:09 - 00004014 _____ C:\Windows\System32\Tasks\RXPrXnf6sA4m3yfQZl0W
2015-07-21 22:07 - 2015-07-22 09:16 - 00000000 ____D C:\Program Files (x86)\globalUpdate
2015-07-21 20:02 - 2015-07-21 20:02 - 00000000 ____D C:\ProgramData\dbd6c89a0000265f
2015-07-21 19:46 - 2015-07-22 16:51 - 00000336 ____H C:\Windows\Tasks\DFOYLGNPBBOIGEUE.job
2015-07-21 19:46 - 2015-07-22 14:19 - 00000324 _____ C:\Windows\Tasks\DAHCX1.job
2015-07-21 19:46 - 2015-07-21 19:46 - 00003364 _____ C:\Windows\System32\Tasks\DFOYLGNPBBOIGEUE
2015-07-21 19:46 - 2015-07-21 19:46 - 00002846 _____ C:\Windows\System32\Tasks\DAHCX1
2015-07-21 19:46 - 2015-07-21 19:46 - 00000000 ____D C:\ProgramData\28341ff220e0446c9fff27c4493d622e
C:\ProgramData\8z41L16n.dat
Task: {02E08FBC-6B8C-4125-90B9-3CC7461E8A3D} - System32\Tasks\29KouX8P5QCtjDVi => C:\Users\jp\AppData\Roaming\29KouX8P5QCtjDVi.exe <==== ATTENTION
Task: {11E0FEEB-D2E5-4AF2-ABF2-B68C757AB524} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-1-6 No Task File <==== ATTENTION
C:\Users\jp\AppData\Roaming\29KouX8P5QCtjDVi.exe
Task: {1D4EDC70-1A53-413D-ACCC-A7215D284850} - \Super Optimizer Schedule No Task File <==== ATTENTION
Task: {2C4DC035-7C33-49A8-B439-CDBFD540056B} - \APSnotifierPP3 No Task File <==== ATTENTION
Task: {2EAF9767-53EB-47B0-B6BD-B7D4DB235DDE} - \SMupdate1 No Task File <==== ATTENTION
Task: {338B9654-7894-445B-B060-DB7F202DB5DC} - System32\Tasks\YTDownloader => C:\Program Files (x86)\YTDownloader\YTDownloader.exe <==== ATTENTION
C:\Program Files (x86)\YTDownloader
Task: {3D2EA2AE-DF2B-49B6-8D84-3C27E6978B45} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3 <==== ATTENTION
Task: {3DFAB371-FFF5-42CF-896C-8B863A564E5B} - System32\Tasks\Onkavatiiihm => C:\ProgramData\Onkavatiiihm\1.0.4.1\jsixetek.exe
Task: {3E46DBD6-94DB-4E80-9BF2-45F29EE71E51} - \SMW_UpdateTask_Time_3338343934393333382d3437415a556c2a3223346c41 No Task File <==== ATTENTION
Task: {3ED523FA-4280-4A2C-955F-D6D3D022FCE3} - System32\Tasks\Smp => C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smp.exe <==== ATTENTION
Task: {3FF480CF-C08F-4062-BCC7-597EB9C41083} - \Bidaily Synchronize Task[8da6] No Task File <==== ATTENTION
Task: {48AF4823-CFB3-4F2A-8D21-9084B7AE5662} - System32\Tasks\DAHCX1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: {4B6183C7-5C6D-40F4-BF7C-5953D3BEF640} - System32\Tasks\AA860BD4-5274-45AC-B02E-AA6F5A64B7F => C:\Users\jp\AppData\Local\AA860BD4-5274-45AC-B02E-AA6F5A64B7F\AA860BD4-5274-45AC-B02E-AA6F5A64B7F.exe <==== ATTENTION
Task: {52A2C8C8-AB59-48FC-B3BE-8E9E5B045546} - System32\Tasks\wQmfRNclS => C:\Users\jp\AppData\Roaming\wQmfRNclS.exe <==== ATTENTION
Task: {5C7B2767-D4D7-4AAF-B0C4-9B32EBC87E65} - \APSnotifierPP1 No Task File <==== ATTENTION
Task: {5E6028ED-0CFB-492C-93B9-19C2D5BECDEB} - \SMWPUpd No Task File <==== ATTENTION
Task: {5FD4B11B-2278-4E91-B9D4-28E836883534} - System32\Tasks\d7musQEpmoFigE => C:\Users\jp\AppData\Roaming\d7musQEpmoFigE.exe <==== ATTENTION
Task: {69BBC392-B114-4060-9F5B-AC88047A89E1} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {732FB463-819B-4E65-8A53-35E4E17F077C} - \SmartWeb Upgrade Trigger Task No Task File <==== ATTENTION
Task: {796CBCFE-BBF9-4EED-A351-E431FC04E196} - System32\Tasks\RXPrXnf6sA4m3yfQZl0W => C:\Users\jp\AppData\Roaming\RXPrXnf6sA4m3yfQZl0W.exe <==== ATTENTION
Task: {79B2E546-51C4-4E8E-93EF-D05F90783921} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-7 No Task File <==== ATTENTION
Task: {8684C6BD-FB1B-4C22-BCC5-BA576BBC7173} - System32\Tasks\YTDownloaderUpd => C:\Program Files (x86)\YTDownloader\updater.exe <==== ATTENTION
Task: {95C217F8-1C00-4C8F-B0EE-AB0CDBE53D87} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {95FD0D33-B414-446E-A1A0-93B0E856813F} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-10_user No Task File <==== ATTENTION
Task: {9907CA38-44BA-4C49-9350-81D11166D4F8} - \APSnotifierPP2 No Task File <==== ATTENTION
Task: {9DFA095B-C612-4BD9-8324-F431D04BE7D7} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update2 <==== ATTENTION
Task: {9ECE0643-1EA1-41E6-A43D-0D370AD66A18} - \Tny_Cassiopesa No Task File <==== ATTENTION
Task: {A7DCE32B-99F7-4EEF-B208-E0E9623889BD} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-3 No Task File <==== ATTENTION
Task: {BA192C50-A8B4-4A2C-B791-583B5BC410C5} - System32\Tasks\pSt8fpwyBUBMn => C:\Users\jp\AppData\Roaming\pSt8fpwyBUBMn.exe <==== ATTENTION
Task: {C294357E-2A44-43A8-AB6D-C76E6F8B17D6} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-6 No Task File <==== ATTENTION
Task: {C65B5A35-3B30-43A5-AFF0-2FB74D9E31A8} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-5_user No Task File <==== ATTENTION
Task: {D1ED8231-6334-487F-82C7-FB4FFE81699F} - System32\Tasks\DFOYLGNPBBOIGEUE => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: {D3812DC5-739D-4C15-9E3D-1DD24F50C12A} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-5 No Task File <==== ATTENTION
Task: {DA90A49E-CFA3-4832-B90A-A8AAF55232F1} - System32\Tasks\LaunchPreSignup => C:\Program Files (x86)\OLBPre\OLBPre.exe <==== ATTENTION
Task: {FC7E6B07-3FC9-4330-841E-18190BF690AE} - \a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-1-7 No Task File <==== ATTENTION
C:\ProgramData\Service1291 
C:\Program Files (x86)\OLBPre
Task: C:\Windows\Tasks\29KouX8P5QCtjDVi.job => C:\Users\jp\AppData\Roaming\29KouX8P5QCtjDVi.exe <==== ATTENTION
Task: C:\Windows\Tasks\d7musQEpmoFigE.job => C:\Users\jp\AppData\Roaming\d7musQEpmoFigE.exe <==== ATTENTION
Task: C:\Windows\Tasks\DAHCX1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: C:\Windows\Tasks\DFOYLGNPBBOIGEUE.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: C:\Windows\Tasks\pSt8fpwyBUBMn.job => C:\Users\jp\AppData\Roaming\pSt8fpwyBUBMn.exe <==== ATTENTION
Task: C:\Windows\Tasks\RXPrXnf6sA4m3yfQZl0W.job => C:\Users\jp\AppData\Roaming\RXPrXnf6sA4m3yfQZl0W.exe <==== ATTENTION
Task: C:\Windows\Tasks\wQmfRNclS.job => C:\Users\jp\AppData\Roaming\wQmfRNclS.exe <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:054203E4
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset catalog
CMD: ipconfig /flushdns
RemoveProxy:
hosts:
Emptytemp:
*****************
 
Processes closed successfully.
Restore point was successfully created.
"c:\progra~3\flashb~1\flashb~1.dll" => value data removed successfully.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value removed successfully
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully
HKU\S-1-5-21-2309807771-1447711736-656462262-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin" => key removed successfully
C:\Windows\Tasks\wQmfRNclS.job => moved successfully.
C:\Windows\System32\Tasks\wQmfRNclS => moved successfully.
"C:\Windows\Tasks\wQmfRNclS.job" => File/Folder not found.
"C:\Windows\System32\Tasks\wQmfRNclS" => File/Folder not found.
C:\Windows\Tasks\29KouX8P5QCtjDVi.job => moved successfully.
C:\Windows\System32\Tasks\29KouX8P5QCtjDVi => moved successfully.
C:\ProgramData\8z41L16n.dat => moved successfully.
C:\Windows\Tasks\d7musQEpmoFigE.job => moved successfully.
C:\Windows\System32\Tasks\d7musQEpmoFigE => moved successfully.
C:\Users\jp\AppData\Local\HealthAlert => moved successfully.
C:\HealthAlert => moved successfully.
C:\Windows\Tasks\pSt8fpwyBUBMn.job => moved successfully.
C:\Windows\System32\Tasks\pSt8fpwyBUBMn => moved successfully.
C:\Windows\System32\Tasks\LaunchPreSignup => moved successfully.
C:\Program Files (x86)\YTDownloader => moved successfully.
C:\Windows\System32\Tasks\YTDownloaderUpd => moved successfully.
C:\Windows\System32\Tasks\Smp => moved successfully.
C:\Windows\System32\Tasks\YTDownloader => moved successfully.
C:\Windows\System32\Tasks\Onkavatiiihm => moved successfully.
C:\ProgramData\DataFile => moved successfully.
C:\Users\Public\Desktop\Win PC Optimizer.lnk => moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Win PC Optimizer => moved successfully.
C:\Program Files (x86)\WinPCOptimizer => moved successfully.
C:\ProgramData\637633ac000009ce => moved successfully.
C:\Windows\Tasks\RXPrXnf6sA4m3yfQZl0W.job => moved successfully.
C:\Windows\System32\Tasks\RXPrXnf6sA4m3yfQZl0W => moved successfully.
C:\Program Files (x86)\globalUpdate => moved successfully.
C:\ProgramData\dbd6c89a0000265f => moved successfully.
C:\Windows\Tasks\DFOYLGNPBBOIGEUE.job => moved successfully.
C:\Windows\Tasks\DAHCX1.job => moved successfully.
C:\Windows\System32\Tasks\DFOYLGNPBBOIGEUE => moved successfully.
C:\Windows\System32\Tasks\DAHCX1 => moved successfully.
C:\ProgramData\28341ff220e0446c9fff27c4493d622e => moved successfully.
"C:\ProgramData\8z41L16n.dat" => File/Folder not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{02E08FBC-6B8C-4125-90B9-3CC7461E8A3D}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02E08FBC-6B8C-4125-90B9-3CC7461E8A3D}" => key removed successfully
C:\Windows\System32\Tasks\29KouX8P5QCtjDVi not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\29KouX8P5QCtjDVi" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{11E0FEEB-D2E5-4AF2-ABF2-B68C757AB524}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{11E0FEEB-D2E5-4AF2-ABF2-B68C757AB524}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-1-6" => key removed successfully
"C:\Users\jp\AppData\Roaming\29KouX8P5QCtjDVi.exe" => File/Folder not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1D4EDC70-1A53-413D-ACCC-A7215D284850}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D4EDC70-1A53-413D-ACCC-A7215D284850}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Super Optimizer Schedule" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2C4DC035-7C33-49A8-B439-CDBFD540056B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2C4DC035-7C33-49A8-B439-CDBFD540056B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP3" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2EAF9767-53EB-47B0-B6BD-B7D4DB235DDE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2EAF9767-53EB-47B0-B6BD-B7D4DB235DDE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMupdate1" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{338B9654-7894-445B-B060-DB7F202DB5DC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{338B9654-7894-445B-B060-DB7F202DB5DC}" => key removed successfully
C:\Windows\System32\Tasks\YTDownloader not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YTDownloader" => key removed successfully
"C:\Program Files (x86)\YTDownloader" => File/Folder not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3D2EA2AE-DF2B-49B6-8D84-3C27E6978B45}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3D2EA2AE-DF2B-49B6-8D84-3C27E6978B45}" => key removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Multimedia\SMupdate3" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{3DFAB371-FFF5-42CF-896C-8B863A564E5B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3DFAB371-FFF5-42CF-896C-8B863A564E5B}" => key removed successfully
C:\Windows\System32\Tasks\Onkavatiiihm not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Onkavatiiihm" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3E46DBD6-94DB-4E80-9BF2-45F29EE71E51}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E46DBD6-94DB-4E80-9BF2-45F29EE71E51}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMW_UpdateTask_Time_3338343934393333382d3437415a556c2a3223346c41" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3ED523FA-4280-4A2C-955F-D6D3D022FCE3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3ED523FA-4280-4A2C-955F-D6D3D022FCE3}" => key removed successfully
C:\Windows\System32\Tasks\Smp not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Smp" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3FF480CF-C08F-4062-BCC7-597EB9C41083}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3FF480CF-C08F-4062-BCC7-597EB9C41083}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Bidaily Synchronize Task[8da6]" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{48AF4823-CFB3-4F2A-8D21-9084B7AE5662}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{48AF4823-CFB3-4F2A-8D21-9084B7AE5662}" => key removed successfully
C:\Windows\System32\Tasks\DAHCX1 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DAHCX1" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4B6183C7-5C6D-40F4-BF7C-5953D3BEF640}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4B6183C7-5C6D-40F4-BF7C-5953D3BEF640}" => key removed successfully
C:\Windows\System32\Tasks\AA860BD4-5274-45AC-B02E-AA6F5A64B7F => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AA860BD4-5274-45AC-B02E-AA6F5A64B7F" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{52A2C8C8-AB59-48FC-B3BE-8E9E5B045546}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{52A2C8C8-AB59-48FC-B3BE-8E9E5B045546}" => key removed successfully
C:\Windows\System32\Tasks\wQmfRNclS not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\wQmfRNclS" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5C7B2767-D4D7-4AAF-B0C4-9B32EBC87E65}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5C7B2767-D4D7-4AAF-B0C4-9B32EBC87E65}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP1" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5E6028ED-0CFB-492C-93B9-19C2D5BECDEB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5E6028ED-0CFB-492C-93B9-19C2D5BECDEB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMWPUpd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5FD4B11B-2278-4E91-B9D4-28E836883534}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5FD4B11B-2278-4E91-B9D4-28E836883534}" => key removed successfully
C:\Windows\System32\Tasks\d7musQEpmoFigE not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\d7musQEpmoFigE" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{69BBC392-B114-4060-9F5B-AC88047A89E1}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{69BBC392-B114-4060-9F5B-AC88047A89E1}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{732FB463-819B-4E65-8A53-35E4E17F077C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{732FB463-819B-4E65-8A53-35E4E17F077C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SmartWeb Upgrade Trigger Task" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{796CBCFE-BBF9-4EED-A351-E431FC04E196}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{796CBCFE-BBF9-4EED-A351-E431FC04E196}" => key removed successfully
C:\Windows\System32\Tasks\RXPrXnf6sA4m3yfQZl0W not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RXPrXnf6sA4m3yfQZl0W" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{79B2E546-51C4-4E8E-93EF-D05F90783921}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79B2E546-51C4-4E8E-93EF-D05F90783921}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-7" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8684C6BD-FB1B-4C22-BCC5-BA576BBC7173}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8684C6BD-FB1B-4C22-BCC5-BA576BBC7173}" => key removed successfully
C:\Windows\System32\Tasks\YTDownloaderUpd not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YTDownloaderUpd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{95C217F8-1C00-4C8F-B0EE-AB0CDBE53D87}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95C217F8-1C00-4C8F-B0EE-AB0CDBE53D87}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{95FD0D33-B414-446E-A1A0-93B0E856813F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95FD0D33-B414-446E-A1A0-93B0E856813F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-10_user" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9907CA38-44BA-4C49-9350-81D11166D4F8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9907CA38-44BA-4C49-9350-81D11166D4F8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP2" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9DFA095B-C612-4BD9-8324-F431D04BE7D7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9DFA095B-C612-4BD9-8324-F431D04BE7D7}" => key removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Maintenance\SMupdate2" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9ECE0643-1EA1-41E6-A43D-0D370AD66A18}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9ECE0643-1EA1-41E6-A43D-0D370AD66A18}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Tny_Cassiopesa" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A7DCE32B-99F7-4EEF-B208-E0E9623889BD}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7DCE32B-99F7-4EEF-B208-E0E9623889BD}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-3" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BA192C50-A8B4-4A2C-B791-583B5BC410C5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BA192C50-A8B4-4A2C-B791-583B5BC410C5}" => key removed successfully
C:\Windows\System32\Tasks\pSt8fpwyBUBMn not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pSt8fpwyBUBMn" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C294357E-2A44-43A8-AB6D-C76E6F8B17D6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C294357E-2A44-43A8-AB6D-C76E6F8B17D6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-6" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C65B5A35-3B30-43A5-AFF0-2FB74D9E31A8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C65B5A35-3B30-43A5-AFF0-2FB74D9E31A8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-5_user" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D1ED8231-6334-487F-82C7-FB4FFE81699F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D1ED8231-6334-487F-82C7-FB4FFE81699F}" => key removed successfully
C:\Windows\System32\Tasks\DFOYLGNPBBOIGEUE not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DFOYLGNPBBOIGEUE" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D3812DC5-739D-4C15-9E3D-1DD24F50C12A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D3812DC5-739D-4C15-9E3D-1DD24F50C12A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-5" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DA90A49E-CFA3-4832-B90A-A8AAF55232F1}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA90A49E-CFA3-4832-B90A-A8AAF55232F1}" => key removed successfully
C:\Windows\System32\Tasks\LaunchPreSignup not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchPreSignup" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FC7E6B07-3FC9-4330-841E-18190BF690AE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC7E6B07-3FC9-4330-841E-18190BF690AE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-1-7" => key removed successfully
"C:\ProgramData\Service1291" => File/Folder not found.
"C:\Program Files (x86)\OLBPre" => File/Folder not found.
C:\Windows\Tasks\29KouX8P5QCtjDVi.job not found.
C:\Windows\Tasks\d7musQEpmoFigE.job not found.
C:\Windows\Tasks\DAHCX1.job not found.
C:\Windows\Tasks\DFOYLGNPBBOIGEUE.job not found.
C:\Windows\Tasks\pSt8fpwyBUBMn.job not found.
C:\Windows\Tasks\RXPrXnf6sA4m3yfQZl0W.job not found.
C:\Windows\Tasks\wQmfRNclS.job not found.
C:\ProgramData\TEMP => ":054203E4" ADS removed successfully.
 
=========  bitsadmin /reset /allusers =========
 
 
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
 
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
 
{636B83F7-2979-44B3-B4DA-472F93895B53} canceled.
{9D62877C-CE72-4E12-82C6-7609DCB3E74B} canceled.
2 out of 2 jobs canceled.
 
========= End of CMD: =========
 
 
=========  netsh winsock reset catalog =========
 
 
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
 
 
========= End of CMD: =========
 
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
========= RemoveProxy: =========
 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
 
 
========= End of RemoveProxy: =========
 
C:\Windows\System32\Drivers\etc\hosts => moved successfully.
Hosts restored successfully.
EmptyTemp: => 5.9 GB temporary data Removed.
 
 
The system needed a reboot.. 
 
==== End of Fixlog 21:06:17 ====

 

 


  • 0

#5
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,792 posts
OK,

Run the other two scans and post the logs--> adwCleaner and JRT.
  • 0

#6
jpatt

jpatt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts

yep, sorry i was going step by-step, didn't read your full instructions

 

 

thanks

jp


  • 0

#7
jpatt

jpatt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts

AdwCleaner scan, hope I did this one right.

 

# AdwCleaner v4.208 - Logfile created 22/07/2015 at 21:21:05
# Updated 09/07/2015 by Xplode
# Database : 2015-07-15.1 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : jp - JP-PC
# Running from : C:\Users\jp\Desktop\AdwCleaner.exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
File Found : C:\END
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
Shortcut Infected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Shortcut Infected : C:\Users\jp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Infected : C:\Users\jp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Shortcut Infected : C:\Users\jp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
Shortcut Infected : C:\Users\jp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
Shortcut Infected : C:\Users\jp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Search.lnk
Shortcut Infected : C:\Users\jp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer (64-bit).lnk
 
***** [ Registry ] *****
 
Data Found : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>
Key Found : HKCU\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}
Key Found : HKCU\Software\AppDataLow\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\Tutorials
Key Found : HKCU\Software\YTDownloader
Key Found : [x64] HKCU\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}
Key Found : [x64] HKCU\Software\GlobalUpdate
Key Found : [x64] HKCU\Software\Tutorials
Key Found : [x64] HKCU\Software\YTDownloader
Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\SOFTWARE\3f8d67e5-e0b7-378b-6fea-12fbebad526e
Key Found : HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\SysMenuExt
Key Found : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}
Key Found : HKLM\SOFTWARE\Classes\AppID\SysMenu.DLL
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EDBF8C0-C94C-4A13-956F-E393BCA5BA4B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Found : HKLM\SOFTWARE\CompeteInc
Key Found : HKLM\SOFTWARE\GlobalUpdate
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}
Key Found : HKLM\SOFTWARE\YTDownloader
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{020B1D4B-5738-4C77-9E19-4F173DD9B486}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17909
 
 
-\\ Google Chrome v43.0.2357.134
 
 
*************************
 
AdwCleaner[R0].txt - [5122 bytes] - [22/07/2015 21:21:05]
 
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [5181 bytes] ##########
 
 
JRT Scan:
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.1 (07.16.2015:1)
OS: Windows 7 Professional x64
Ran by jp on Wed 07/22/2015 at 21:32:13.33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Tasks
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
Failed to delete: [File] C:\Windows\SysWOW64\number of results
Successfully deleted: [File] C:\Users\jp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\search.lnk
Successfully disinfected: [Shortcut] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Successfully disinfected: [Shortcut] C:\Users\jp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer (64-bit).lnk
Successfully disinfected: [Shortcut] C:\Users\jp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
Successfully disinfected: [Shortcut] C:\Users\jp\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
Successfully disinfected: [Shortcut] C:\Users\jp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Successfully disinfected: [Shortcut] C:\Users\jp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] C:\Program Files (x86)\osdownloader
Successfully deleted: [Folder] C:\Users\jp\Appdata\Local\globalupdate
Successfully deleted: [Folder] C:\Users\jp\Appdata\Local\installer
Successfully deleted: [Folder] C:\Windows\provider32
Successfully deleted: [Folder] C:\Users\jp\Appdata\Local\AA860BD4-5274-45AC-B02E-AA6F5A64B7F
 
 
 
~~~ Chrome
 
 
[C:\Users\jp\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Users\jp\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
 
[C:\Users\jp\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Users\jp\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
  booedmolknjekdopkepjjeckmjkdpfgl,
  flpcjncodpafbgdpnkljologafpionhb
]
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 07/22/2015 at 21:35:13.86
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 

  • 0

#8
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,792 posts
You said you ran Malwarebytes, can you post the log file from that.

To do that;
  • open MBAM once more.
  • Click on the History tab > Application Logs
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click Copy to Clipboard
  • Paste the contents of the clipboard into your reply.

  • 0

#9
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,792 posts
Hello,

Logging off for the nite;

RE: AdwCleaner

You ran Option : "Scan"

We need to run the option "Clean" now. This will actually remove the files that were discovered on the option scan.

To do that

Re-run AdwCleaner, click scan, let scan finish, now click on "Logfile" now click Clean

Thanks
Joe :)
  • 0

#10
jpatt

jpatt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts

MBAM log:

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 7/22/2015
Scan Time: 5:36 AM
Logfile: 
Administrator: Yes
 
Version: 2.1.8.1057
Malware Database: v2015.07.22.02
Rootkit Database: v2015.07.17.01
License: Trial
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: jp
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 382857
Time Elapsed: 12 min, 9 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 3
PUP.Optional.Winsock.HijackBoot, C:\Windows\Provider32\Provider.dll, Delete-on-Reboot, [c30711d35337ba7c5668a0227a87966a], 
PUP.Optional.Winsock.HijackBoot, C:\Windows\Provider32\Provider.dll, Delete-on-Reboot, [c30711d35337ba7c5668a0227a87966a], 
PUP.Optional.Winsock.HijackBoot, C:\Windows\Provider32\Provider.dll, Delete-on-Reboot, [c30711d35337ba7c5668a0227a87966a], 
 
Registry Keys: 143
PUP.Optional.Coupoon.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CoupoonService64, Quarantined, [69617e66f595a19513c193d7eb1a8b75], 
PUP.Optional.HealthAlert.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\cQhxFslxpe, Quarantined, [e3e705df008a181e501380d49f62b947], 
PUP.Optional.ModGoog, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdate, Quarantined, [aa2001e37b0f87afe126622eeb16ad53], 
PUP.Optional.ModGoog, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, Quarantined, [aa2001e37b0f87afe126622eeb16ad53], 
PUP.Optional.ModGoog, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GLOBALUPDATE.EXE, Quarantined, [aa2001e37b0f87afe126622eeb16ad53], 
PUP.Optional.ModGoog, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GLOBALUPDATE.EXE, Quarantined, [aa2001e37b0f87afe126622eeb16ad53], 
PUP.Optional.AdPeak.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\netfilter64, Quarantined, [aa20ba2a1d6d2d096fe1a1cae124a25e], 
PUP.Optional.Goobzo.SID.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SMUpdd, Quarantined, [ffcb01e3315954e26d5de882a26328d8], 
PUP.Optional.Coupoon.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\UpdateCheck, Quarantined, [9337e8fcf59558decd078edc2dd8f010], 
PUP.Optional.UpdateService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\UpdateSvc, Quarantined, [aa207c682e5c251108b5cff342bf7987], 
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, Quarantined, [e9e1bf25f1990432238b3953ca3829d7], 
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, Quarantined, [e9e1bf25f1990432238b3953ca3829d7], 
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, Quarantined, [e9e1bf25f1990432238b3953ca3829d7], 
PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, Quarantined, [a1294c98cdbd96a04789028acc3634cc], 
PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, Quarantined, [a1294c98cdbd96a04789028acc3634cc], 
PUP.Optional.ConsumerInput.A, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}, Quarantined, [2b9f01e36f1bf14555d5becf12f006fa], 
PUP.Optional.EORezo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\gmsd_us_005010037_is1, Quarantined, [a921954fe7a357dff8ea5b0f2adbdb25], 
PUP.Optional.SuperOptimizer.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Super Optimizer_is1, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\covygyxi, Quarantined, [e6e423c1f79374c28e3c3c60857f21df], 
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\vicoqudu, Quarantined, [e6e423c1f79374c28e3c3c60857f21df], 
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\hyverumu, Quarantined, [e6e423c1f79374c28e3c3c60857f21df], 
PUP.Optional.FriendlyError.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\FriendlyError, Quarantined, [ad1dd31199f16ec8cc4f1588c83c1ae6], 
PUP.Optional.Coupoon.A, HKLM\SOFTWARE\coupoon, Quarantined, [6268f5efcbbfeb4b96025637e71d6997], 
PUP.Optional.Flashbeat.A, HKLM\SOFTWARE\Flashbeat, Quarantined, [5575a73d74160333c1aa918562a19f61], 
PUP.Optional.HighDefAction.A, HKLM\SOFTWARE\HighDefAction, Quarantined, [6169b92bf29837ffa670b0e5e123d12f], 
PUP.Optional.SearchModule.A, HKLM\SOFTWARE\SearchModulePlus, Quarantined, [903aa341107a56e070513f5401038779], 
PUP.Optional.YorkNewCin.A, HKLM\SOFTWARE\YorkNewCin, Quarantined, [1eac6282dcaeac8a27fafa9ba361718f], 
PUP.Optional.CinemaPlus.C, HKLM\SOFTWARE\ARENAHD, Quarantined, [eae03fa5612900361ed96c24828243bd], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, Quarantined, [7555d4107416999d2b2e513dab596b95], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickProcessLauncherMachine, Quarantined, [cffb0ed6addd5ed8cf8ac2ccc53f6d93], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickProcessLauncherMachine.1.0, Quarantined, [7852cd17602a330387d2bfcfcd375ea2], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoCreateAsync, Quarantined, [7b4f7b694d3d45f101597e106b995ba5], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoCreateAsync.1.0, Quarantined, [7852499b5b2f092d11498fff857f47b9], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreClass, Quarantined, [4585b62e157566d062f8018d996b738d], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreClass.1, Quarantined, [478323c16921989eca90f89614f0bb45], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreMachineClass, Quarantined, [f5d533b13a50b97d64f60b8359ab5ca4], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreMachineClass.1, Quarantined, [26a4ac38aedc979fa0ba4d41798bb34d], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CredentialDialogMachine, Quarantined, [8c3e70740a80ff377fdbbfcf2fd5bf41], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CredentialDialogMachine.1.0, Quarantined, [2d9dca1a58325bdbb7a3f29cad572ad6], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine, Quarantined, [1ab070742f5be74f0654cbc3788c6a96], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [903a4a9a464493a386d491fd6d97a45c], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback, Quarantined, [deec20c4b1d9e55191c9d6b835cf23dd], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [6862ac38fc8e4de9baa0cac4e81c916f], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc, Quarantined, [14b6be260288be78f466602ed52fab55], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [9634b03423675ed8e971e6a8e71dd52b], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.ProcessLauncher, Quarantined, [7d4d9f45731796a096c4434bd92b619f], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.ProcessLauncher.1.0, Quarantined, [04c635afcfbb5cda0c4ee3abe42058a8], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3COMClassService, Quarantined, [ac1e9a4ad2b8152166f42b63a4607789], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3COMClassService.1.0, Quarantined, [b91127bd0585350199c1642a34d042be], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachine, Quarantined, [5377d50f4e3cac8aaeac8905b84c54ac], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachine.1.0, Quarantined, [efdb6a7a1b6f40f64d0d99f534d07987], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback, Quarantined, [5575459f4c3e999d104a6c228a7a8080], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback.1.0, Quarantined, [b713a3412664a78f5307583634d0da26], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebSvc, Quarantined, [b61412d28a001b1b9dbd414d9173cc34], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebSvc.1.0, Quarantined, [a129d4105d2dc17559014c4231d37e82], 
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\CLASSES\APPID\GLOBALUPDATE.EXE, Quarantined, [12b8da0a325854e2e39d454d0bf9b14f], 
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\GLOBALUPDATE.EXE, Quarantined, [bb0fcb19e9a182b4720e6929f70d4cb4], 
PUP.Optional.Cassiopesa.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, Quarantined, [d9f1eff53a50df57cc3843576c9817e9], 
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE, Quarantined, [3e8cb232fa90fc3a82bbd0c637cd6799], 
PUP.Optional.Coupoon.A, HKLM\SOFTWARE\WOW6432NODE\Coupoon, Quarantined, [f5d5d70db8d2bd793e5a5d3050b47789], 
PUP.Optional.Crossbrowse.A, HKLM\SOFTWARE\WOW6432NODE\Crossbrowse, Quarantined, [f6d402e2bfcbba7c4be1b15c2ed5df21], 
PUP.Optional.Flashbeat.A, HKLM\SOFTWARE\WOW6432NODE\Flashbeat, Quarantined, [97335d87a2e80f27d4977b9b0102e917], 
PUP.Optional.GamesDesktop.A, HKLM\SOFTWARE\WOW6432NODE\GAMESDESKTOP, Quarantined, [0fbbf2f2aedca195afd0d549ed164fb1], 
PUP.Optional.HighDefAction.A, HKLM\SOFTWARE\WOW6432NODE\HighDefAction, Quarantined, [95353ba91b6fcb6b75a1d6bf7a8a1de3], 
PUP.Optional.SearchModule.A, HKLM\SOFTWARE\WOW6432NODE\SearchModulePlus, Quarantined, [4f7b04e0fb8fdf57625f741f2ed6f709], 
PUP.Optional.WordSurfer.A, HKLM\SOFTWARE\WOW6432NODE\WordSurfer_1.10.0.19, Quarantined, [fbcf865e7d0da3931c5e38653bc910f0], 
PUP.Optional.YorkNewCin.A, HKLM\SOFTWARE\WOW6432NODE\YorkNewCin, Quarantined, [09c1d90b0f7b5bdbc45d385dde26ce32], 
PUP.Optional.SuperOptimizer.C, HKLM\SOFTWARE\WOW6432NODE\{1146AC44-2F03-4431-B4FD-889BC837521F}, Quarantined, [eddd43a1cfbbec4a9c959602996b06fa], 
PUP.Optional.SuperOptimizer.C, HKLM\SOFTWARE\WOW6432NODE\{6791A2F3-FC80-475C-A002-C014AF797E9C}, Quarantined, [ae1c1bc9543682b47fb3277162a26799], 
PUP.Optional.CrossRider.C, HKLM\SOFTWARE\WOW6432NODE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [01c922c28604ff374395be4c8083bc44], 
PUP.Optional.CinemaPlus.C, HKLM\SOFTWARE\WOW6432NODE\ARENAHD, Quarantined, [32986f751377b97da94e92fe6d97f20e], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickCtrl.10, Quarantined, [c00a3ca8b7d351e5fc5d77177d8724dc], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickProcessLauncherMachine, Quarantined, [3d8d34b0d6b483b3a1b8f6980afa9070], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickProcessLauncherMachine.1.0, Quarantined, [dfebfaea6c1efd394811404e3aca39c7], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoCreateAsync, Quarantined, [e1e9bf25eaa0989e4f0b513d986cd22e], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoCreateAsync.1.0, Quarantined, [36940ed6b0dafc3ac8921c726c98a35d], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreClass, Quarantined, [04c68f55701a89ad1248e1ad897bae52], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreClass.1, Quarantined, [527853910b7fc6705703cdc146bec13f], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreMachineClass, Quarantined, [6169fbe9e7a3979f3f1b3a548282b44c], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreMachineClass.1, Quarantined, [d3f7c61e2169b086ca90f19d09fbd12f], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CredentialDialogMachine, Quarantined, [c30744a01773a98dd288b5d905ff7789], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CredentialDialogMachine.1.0, Quarantined, [ab1fffe5f694023401596e205fa536ca], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine, Quarantined, [fecc29bb4b3f48ee92c85935f21243bd], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [f4d61ec6e1a985b1a0ba97f75aaae020], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback, Quarantined, [00cac91bd0ba49ed1f3be9a592727987], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [1cae53911278ce687bdf3d514eb68080], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc, Quarantined, [ab1fa14338527fb7560497f75ba97a86], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [3199d50f85052c0a51097a14c2423bc5], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.ProcessLauncher, Quarantined, [94366183e0aa96a0be9c028c57ad3ec2], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.ProcessLauncher.1.0, Quarantined, [76545a8a6723bb7bcc8ee0aeff052bd5], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3COMClassService, Quarantined, [8a408262cac062d4f169484645bf35cb], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3COMClassService.1.0, Quarantined, [49818d57860401352535880644c034cc], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachine, Quarantined, [9436a044a7e3fe3823374d411be9b947], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachine.1.0, Quarantined, [5d6d82621773979fb1a9a4ea9272aa56], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback, Quarantined, [7a50875dc8c21026ca909cf29d67c43c], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback.1.0, Quarantined, [e6e4e6fe533772c4a2b8d6b85ea6f60a], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebSvc, Quarantined, [02c805dfcfbb9d992931f797b64ed52b], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebSvc.1.0, Quarantined, [29a1994be1a93006d486513d91735ea2], 
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\GLOBALUPDATE.EXE, Quarantined, [25a537ad9eec4ceae39d9af824e08779], 
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE\Clients, Quarantined, [69618163fe8cf640d58ac6cef3116898], 
PUP.Optional.VoPackage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\VOPackage, Quarantined, [d7f33ea6d2b81026f7d98ffdb05448b8], 
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1146AC44-2F03-4431-B4FD-889BC837521F}{24a6f44f}, Quarantined, [0ac042a25238f541a6eddcb88e76916f], 
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1146AC44-2F03-4431-B4FD-889BC837521F}{cae99edb}, Quarantined, [6268a93bc2c845f1d1c2c2d2ae569a66], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, Quarantined, [a72341a372181e189c3de49da95b7090], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, Quarantined, [4d7db52f61299f971dbd2d548183867a], 
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE, Quarantined, [9a30885c2565fc3a2e0f6630e81c619f], 
PUP.Optional.Tuto4Pc.A, HKLM\SOFTWARE\WOW6432NODE\TUTORIALS, Quarantined, [e1e90ada3b4f0135fcffcfba659fdd23], 
PUP.Optional.SuperOptimizer.C, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\cae99edb, Quarantined, [a921c51f7d0d88ae5bd83b5dbf458a76], 
PUP.Optional.FindingDiscount.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\FindingDiscount, Delete-on-Reboot, [a42607dd9bef81b51cb42eeeef14e818], 
PUP.Optional.WordSurfer.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\wsafd_1_10_0_19, Quarantined, [8f3bf2f22e5cac8a7e18f5a7bd47ad53], 
PUP.Optional.RuntimeManager.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RuntimeManager, Quarantined, [834739ab18720630e0f25bc10ff4d62a], 
PUP.Optional.Goobzo.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SMUPDPLUS, Quarantined, [bd0d974dd8b2b1855fec8c09cf35a35d], 
PUP.Optional.CinemaPlus.A, HKU\S-1-5-18\SOFTWARE\CinemaPlus-3.2cV21.07-nv, Quarantined, [05c522c25d2dba7c7b6ba080f40fc23e], 
PUP.Optional.CinemaPlus.A, HKU\S-1-5-18\SOFTWARE\CinemaPlus-3.2cV21.07-nv-ie, Quarantined, [3a905e86c4c673c3ebfbbb658e75738d], 
PUP.Optional.DustApps.A, HKU\S-1-5-18\SOFTWARE\DustApps, Quarantined, [c20828bc8208ae889805db422ed5c739], 
PUP.Optional.SuperOptimizer.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, Quarantined, [01c9e1035a30ab8bdb552573e71d817f], 
PUP.Optional.Coupoon.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\coupoon, Quarantined, [7c4e657fb5d5e551e0b6d8b5788c21df], 
PUP.Optional.Crossrider.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\_CrossriderRegNamePlaceHolder_, Quarantined, [22a89e46a9e1c96d59a1058b13f11ae6], 
PUP.Optional.CinemaPlus.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\CinemaPlus-3.2cV21.07-nv-ie, Quarantined, [dded7d678cfe16201fc736ea2dd6738d], 
PUP.Optional.ConduitSearch.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\Conduit_Search_Protect, Quarantined, [1eac28bc2e5c152163aefd1ba2617888], 
PUP.Optional.Crossbrowse.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\Crossbrowse, Quarantined, [6c5e1acaccbee650a289a96435cee61a], 
PUP.Optional.Crossbrowse.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\CrossBrowser, Quarantined, [9337d311a7e344f2a388f11c14efb050], 
PUP.Optional.HighDefAction.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\HighDefAction, Quarantined, [d2f838ac0387bd799481722344c0d22e], 
PUP.Optional.Tuto4PC.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\TutoTag, Quarantined, [fbcf895b66240b2bd720dea338cc40c0], 
PUP.Optional.YorkNewCin.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\YorkNewCin, Quarantined, [b01a7d671476033318081382de26f50b], 
PUP.Optional.SuperOptimizer.C, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, Quarantined, [3b8f6e76692112242e024a4e54b08878], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [f2d8786c880247ef91dee6927292ed13], 
PUP.Optional.MultiIE.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\APPDATALOW\SOFTWARE\DynConIE, Quarantined, [3f8b786ce9a156e00700473717edf40c], 
PUP.Optional.CinemaPlus.C, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\ARENAHD, Quarantined, [01c94d97355571c5c036d8b85ba92fd1], 
PUP.Optional.GlobalUpdate.C, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY, Quarantined, [7555da0ad6b4ad89a0597399ef145aa6], 
PUP.Optional.Trovi.C, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, Quarantined, [8248f0f48a0069cd3a488111877d6e92], 
PUP.Optional.Searching.ShrtCln, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, Quarantined, [874332b2bad0a492250df7a647bd916f], 
PUP.Optional.Searching.ShrtCln, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{10FC182C-9075-4ACE-A21E-8C325D0C8811}, Quarantined, [b11921c3f892bd7941f1930a9d6732ce], 
PUP.Optional.Cassiopesa.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{86B9B426-BB48-4DC6-A56A-7695A15C19B7}, Quarantined, [3793e6fe1872d95da261980253b1ef11], 
PUP.Optional.Tuto4PC.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\TUTORIALS\updatetutorialeshp, Quarantined, [b01aba2a9ded6fc7c0228d88e61d56aa], 
PUP.Optional.Tuto4PC.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\TUTORIALS\updatetutorialshp, Quarantined, [6f5b885c9beff6406c7736dfd1320df3], 
PUP.Optional.Tuto4PC.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\TUTORIALS\updv, Quarantined, [19b18a5ab1d9de58b52fe035798afd03], 
PUP.Optional.OneSystemCare.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1003\SOFTWARE\ONE SYSTEM CARE, Quarantined, [69614e966426999deb40425430d4e61a], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.Goobzo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Search Module Plus, Quarantined, [3496974dafdbbd79b19614d9be44ed13], 
 
Registry Values: 51
PUP.Optional.EORezo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|gmsd_us_005010037, "C:\Program Files (x86)\gmsd_us_005010037\gmsd_us_005010037.exe", Quarantined, [26a49d47b5d523137969acbe54b1867a]
PUP.Optional.CinemaPlus.C, HKLM\SOFTWARE\ARENAHD|value, 1, Quarantined, [eae03fa5612900361ed96c24828243bd]
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\CLASSES\APPID\GLOBALUPDATE.EXE|AppID, {3278F5CF-48F3-4253-A6BB-004CE84AF492}, Quarantined, [12b8da0a325854e2e39d454d0bf9b14f]
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\GLOBALUPDATE.EXE|AppID, {3278F5CF-48F3-4253-A6BB-004CE84AF492}, Quarantined, [bb0fcb19e9a182b4720e6929f70d4cb4]
PUP.Optional.PCTuner.C, HKLM\SOFTWARE\HIGHDEFACTION|value, 1, Quarantined, [4f7bffe5d1b9ff374bb74a4754b09d63]
PUP.Optional.Cassiopesa.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, http://www.cassiopes...1084328375&ir=,Quarantined, [d9f1eff53a50df57cc3843576c9817e9]
PUP.Optional.Cassiopesa.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback, http://www.cassiopes...1084328375&ir=,Quarantined, [06c4ce168dfd7eb80ef6c2d8a55f629e]
PUP.Optional.Cassiopesa.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|FaviconPath, C:\Users\jp\AppData\LocalLow\Microsoft\Internet Explorer\Services\Tny_Cassiopesa.ico, Quarantined, [6c5e796bd1b9db5baf5509916a9aca36]
PUP.Optional.Cassiopesa.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}, Cassiopesa, Quarantined, [eedc6084becc1a1ce71d108ae222cd33]
PUP.Optional.Cassiopesa.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|DisplayName, Cassiopesa, Quarantined, [ae1cd0143d4dc17518ecddbd7f8547b9]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, Quarantined, [3e8cb232fa90fc3a82bbd0c637cd6799]
PUP.Optional.CinemaPlus.C, HKLM\SOFTWARE\WOW6432NODE\ARENAHD|value, 1, Quarantined, [32986f751377b97da94e92fe6d97f20e]
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\GLOBALUPDATE.EXE|AppID, {3278F5CF-48F3-4253-A6BB-004CE84AF492}, Quarantined, [25a537ad9eec4ceae39d9af824e08779]
PUP.Optional.PCTuner.C, HKLM\SOFTWARE\WOW6432NODE\HIGHDEFACTION|value, 1, Quarantined, [51793da796f46bcbda28246dc73def11]
PUP.Optional.Cassiopesa.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\Tny_Cassiopesa\\, Quarantined, [f2d8bf255337cd695b801680bb49649c]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, Quarantined, [9a30885c2565fc3a2e0f6630e81c619f]
PUP.Optional.Tuto4Pc.A, HKLM\SOFTWARE\WOW6432NODE\TUTORIALS|HostGUID, 7F70C1AB-24FA-4F11-814F-E9DB59B01ACB, Quarantined, [e1e90ada3b4f0135fcffcfba659fdd23]
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\covygyxi|ImagePath, C:\Program Files (x86)\00000000-1437525428-0000-0807-060504030201\knsn2B0.tmp, Quarantined, [21a95a8aeb9f96a0bb9d9eee4fb523dd]
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\hyverumu|ImagePath, C:\Program Files (x86)\00000000-1437525428-0000-0807-060504030201\jnst822A.tmp, Quarantined, [29a1f8ec7119270f6dec0a8237cdf808]
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\vicoqudu|ImagePath, C:\Program Files (x86)\00000000-1437525428-0000-0807-060504030201\hnst9906.tmp, Quarantined, [16b454900387d95d6fea315ba95b24dc]
PUP.Optional.RuntimeManager.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RUNTIMEMANAGER|ImagePath, C:\Program Files (x86)\Windows NT\Accessories\RuntimeManager\runtimemanager.exe -service, Quarantined, [834739ab18720630e0f25bc10ff4d62a]
PUP.Optional.Goobzo.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SMUpdd|ImagePath, \??\C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smw.sys, Quarantined, [2e9cbd276e1c0b2b0d3e8312f4103ec2]
PUP.Optional.Goobzo.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SMUpdPlus|ImagePath, C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smu.exe /service, Quarantined, [bd0d974dd8b2b1855fec8c09cf35a35d]
PUP.Optional.Coupoon.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\UPDATECHECK|ImagePath, C:\Program Files (x86)\Coupoon\UpdateCheck.exe run , Quarantined, [9c2e6480d0ba9d996720276b788c4eb2]
PUP.Optional.CinemaPlus.C, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\ARENAHD|value, 1, Quarantined, [01c94d97355571c5c036d8b85ba92fd1]
PUP.Optional.GlobalUpdate.C, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY|source, IE, Quarantined, [7555da0ad6b4ad89a0597399ef145aa6]
PUP.Optional.PCTuner.C, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\HIGHDEFACTION|value, 1, Quarantined, [9337bc28335714228f7199f813f1eb15]
PUP.Optional.Trovi.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|URL, http://www.trovi.com...chTerms}&SSPV=,Quarantined, [2aa0994b197159dda6dc5933af5502fe]
PUP.Optional.Conduit.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|SuggestionsURL_JSON, http://suggest.secci...={searchTerms},Quarantined, [bc0e0bd9b0da14224e357a9216eda65a]
PUP.Optional.Trovi.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|DisplayName, Trovi, Quarantined, [ad1de5ff404ab680e2a0fe8e31d355ab]
PUP.Optional.Searching.ShrtCln, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, http://www-searching...={searchTerms},Quarantined, [874332b2bad0a492250df7a647bd916f]
PUP.Optional.Searching.ShrtCln, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURL, http://www-searching...={searchTerms},Quarantined, [705a34b0d6b4b97de250a3faf410ef11]
PUP.Optional.Searching.ShrtCln, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback, http://www-searching...={searchTerms},Quarantined, [3f8bb3319af049eda2902a73d52fd927]
PUP.Optional.Searching.ShrtCln, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|FaviconURL, http://www-searching.com/favicon.ico, Quarantined, [45855d87127846f0a58d49543fc56f91]
PUP.Optional.Searching.ShrtCln, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|FaviconURLFallback, http://www-searching.com/favicon.ico, Quarantined, [ca00c0245c2ef83e40f2504dce36ac54]
PUP.Optional.SearchModule.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|SuggestionsURL, http://api.searchpre...={searchTerms},Quarantined, [e2e8b52f404ae94d7b44068df0147789]
PUP.Optional.SearchModule.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|SuggestionsURLFallback, http://api.searchpre...={searchTerms},Quarantined, [6c5e64802367d462f1ce43505ba9d12f]
PUP.Optional.Searching.ShrtCln, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{10FC182C-9075-4ACE-A21E-8C325D0C8811}|URL, http://www-searching...={searchTerms},Quarantined, [b11921c3f892bd7941f1930a9d6732ce]
PUP.Optional.Searching.ShrtCln, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{10FC182C-9075-4ACE-A21E-8C325D0C8811}|TopResultURL, http://www-searching...={searchTerms},Quarantined, [3f8b8e56850587afbf73a2fb956f3dc3]
PUP.Optional.Searching.ShrtCln, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{10FC182C-9075-4ACE-A21E-8C325D0C8811}|TopResultURLFallback, http://www-searching...={searchTerms},Quarantined, [72589f453654ab8b2b072479f70d9a66]
PUP.Optional.Searching.ShrtCln, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{10FC182C-9075-4ACE-A21E-8C325D0C8811}|FaviconURL, http://www-searching.com/favicon.ico, Quarantined, [3a90f2f25f2bfb3bca68efae11f3bb45]
PUP.Optional.Searching.ShrtCln, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{10FC182C-9075-4ACE-A21E-8C325D0C8811}|FaviconURLFallback, http://www-searching.com/favicon.ico, Quarantined, [9d2dcc18b4d6c373e34f227bce36629e]
PUP.Optional.SearchModule.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{10FC182C-9075-4ACE-A21E-8C325D0C8811}|SuggestionsURL, http://api.searchpre...={searchTerms},Quarantined, [e5e5e2020981c07601bef59ef311bd43]
PUP.Optional.SearchModule.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{10FC182C-9075-4ACE-A21E-8C325D0C8811}|SuggestionsURLFallback, http://api.searchpre...={searchTerms},Quarantined, [0cbe38ac8703d85e79466330e024a15f]
PUP.Optional.Cassiopesa.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{86B9B426-BB48-4DC6-A56A-7695A15C19B7}, Cassiopesa, Quarantined, [3793e6fe1872d95da261980253b1ef11]
PUP.Optional.Cassiopesa.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{86B9B426-BB48-4DC6-A56A-7695A15C19B7}|URL, http://www.cassiopes...1084328375&ir=,Quarantined, [8f3b26beee9cb3830003dfbb1de70000]
PUP.Optional.Cassiopesa.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{86B9B426-BB48-4DC6-A56A-7695A15C19B7}|TopResultURLFallback, http://www.cassiopes...1084328375&ir=,Quarantined, [54769c481f6b082e46bd6634a95b5fa1]
PUP.Optional.Cassiopesa.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{86B9B426-BB48-4DC6-A56A-7695A15C19B7}|FaviconPath, C:\Users\jp\AppData\LocalLow\Microsoft\Internet Explorer\Services\Tny_Cassiopesa.ico, Quarantined, [00ca7f658bff73c308fbecaec53fd12f]
PUP.Optional.Cassiopesa.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{86B9B426-BB48-4DC6-A56A-7695A15C19B7}|DisplayName, Cassiopesa, Quarantined, [b7135490e0aa36004db65941c83cb947]
PUP.Optional.OneSystemCare.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1003\SOFTWARE\ONE SYSTEM CARE|AdvertsLink1, http://dl.softserver...3/DriverPro.exe, Quarantined, [69614e966426999deb40425430d4e61a]
PUP.Optional.OneSystemCare.A, HKU\S-1-5-21-2309807771-1447711736-656462262-1003\SOFTWARE\ONE SYSTEM CARE|AdvertsLink2, http://dl.softserver...LiveSupport.exe, Quarantined, [1eacb52f206a78becc5fb1e5e81c9769]
 
Registry Data: 1
PUP.Optional.Searching.ShrtCln, HKU\S-1-5-21-2309807771-1447711736-656462262-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://www-searching...e&vp=ch&prd=set, Good: (www.google.com), Bad: (http://www-searching.com/?pid=s&s=F7Mzbuzdk00CN1,84f8f11d-3a92-4ead-b3ef-e5ccdf69d1de&vp=ch&prd=set),Replaced,[78525e86127892a4a1843affd23331cf]
 
Folders: 40
PUP.Optional.BrowserHelper.A, C:\Users\jp\AppData\Local\BrowserHelper, Quarantined, [5476bc28afdb67cf0b4c3dcf4ab9de22], 
PUP.Optional.HealthAlert.A, C:\ProgramData\HealthAlert, Quarantined, [ffcb7d67bbcf90a6799fe242e320e21e], 
PUP.Optional.MultiPlug.A, C:\Users\jp\AppData\Local\00000000-1437507476-0000-0807-060504030201, Quarantined, [8842ca1ae4a6d85e6165d7b641c3fe02], 
PUP.Optional.SuperOptimizer.A, C:\ProgramData\{016aaf46-a15a-b249-016a-aaf46a15bd1a}, Quarantined, [5377c71daedc25115f0c8d0609fbf10f], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.BundleInstaller.A, C:\ProgramData\abc, Quarantined, [795190546b1fd264e96d375e05ff28d8], 
PUP.Optional.PullUpdate.Gen, C:\ProgramData\Onkavatiiihm\1.0.4.1, Quarantined, [b911eafa335793a359bcd9c26a9a3ec2], 
PUP.Optional.PullUpdate.Gen, C:\ProgramData\Onkavatiiihm, Quarantined, [b911eafa335793a359bcd9c26a9a3ec2], 
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\00000000-1437525428-0000-0807-060504030201, Quarantined, [e6e423c1f79374c28e3c3c60857f21df], 
PUP.Optional.WombatService.A, C:\ProgramData\Service1291, Quarantined, [527821c3246640f6d8171f7d29db45bb], 
PUP.Optional.FriendlyError.A, C:\Program Files (x86)\FriendlyError, Quarantined, [ad1dd31199f16ec8cc4f1588c83c1ae6], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Download, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Install, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline\{B201CFC4-96A5-420B-977B-233DDACF5DB7}, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.Goobzo, C:\Program Files\Common Files\Goobzo, Quarantined, [3496974dafdbbd79b19614d9be44ed13], 
PUP.Optional.Goobzo, C:\Program Files\Common Files\Goobzo\GBUpdatePlus, Quarantined, [3496974dafdbbd79b19614d9be44ed13], 
PUP.Optional.GamesDesktop.A, C:\Users\jp\AppData\Local\gmsd_us_005010037, Quarantined, [e2e89351d5b5da5c78d2b74043bfb24e], 
PUP.Optional.GamesDesktop.A, C:\Users\jp\AppData\Local\gmsd_us_005010037\Download, Quarantined, [e2e89351d5b5da5c78d2b74043bfb24e], 
PUP.Optional.GamesDesktop.A, C:\Users\jp\AppData\Local\gmsd_us_005010037\gmsd_us_005010037, Quarantined, [e2e89351d5b5da5c78d2b74043bfb24e], 
PUP.Optional.GamesDesktop.A, C:\Users\jp\AppData\Local\gmsd_us_005010037\gmsd_us_005010037\1.20, Quarantined, [e2e89351d5b5da5c78d2b74043bfb24e], 
PUP.Optional.GamesDesktop.A, C:\Program Files (x86)\gmsd_us_005010037, Quarantined, [9e2c44a0563493a3b6957483669cd12f], 
PUP.Optional.FindingDiscount.A, C:\Program Files (x86)\Windows Discount, Quarantined, [d2f8875db7d355e16f7d70890bf724dc], 
PUP.Optional.FindingDiscount.A, C:\Program Files (x86)\Windows Discount\FindingDiscount, Quarantined, [d2f8875db7d355e16f7d70890bf724dc], 
PUP.Optional.FindingDiscount.A, C:\ProgramData\Windows Discount, Quarantined, [705a588ca1e9c86e6a83a15852b09e62], 
PUP.Optional.FindingDiscount.A, C:\ProgramData\Windows Discount\FindingDiscount, Quarantined, [705a588ca1e9c86e6a83a15852b09e62], 
PUP.Optional.RuntimeManager.A, C:\Program Files (x86)\Windows NT\Accessories\RuntimeManager, Quarantined, [5377df052d5d1e1871812fca25dd3dc3], 
PUP.Optional.VOPackage.A, C:\Users\jp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage, Quarantined, [deec0dd7b7d3a88e90d09e5df80a4bb5], 
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat, Quarantined, [94366381622871c5cb03a15da062bd43], 
PUP.Optional.Coupoon.A, C:\Program Files\Coupoon, Quarantined, [8b3f08dc79118bab90d8ae54778cc23e], 
PUP.Optional.Coupoon.A, C:\Program Files\Coupoon\SSL, Quarantined, [8b3f08dc79118bab90d8ae54778cc23e], 
PUP.Optional.Coupoon.A, C:\Program Files (x86)\Coupoon, Quarantined, [5b6f1ec60882d6608cdcfa0838cbcd33], 
PUP.Optional.Coupoon.A, C:\Program Files (x86)\Coupoon\locales, Quarantined, [5b6f1ec60882d6608cdcfa0838cbcd33], 
PUP.Optional.SearchModulePlus.A, C:\ProgramData\SearchModulePlus, Quarantined, [12b8d311ff8b1f17fa0dd92a0102629e], 
PUP.Optional.OneSystemCare.A, C:\Users\jp\AppData\Roaming\One System Care, Quarantined, [b515c123a9e19a9c23eb2adb53b0669a], 
PUP.Optional.OneSystemCare.A, C:\Users\jp\AppData\Roaming\One System Care\WL, Quarantined, [b515c123a9e19a9c23eb2adb53b0669a], 
PUP.Optional.PullUpdate.A, C:\ProgramData\uTWRpFF\dat, Quarantined, [c703b232c9c1043204a63d30d431f40c], 
PUP.Optional.PullUpdate.A, C:\ProgramData\uTWRpFF, Quarantined, [c703b232c9c1043204a63d30d431f40c], 
 
Files: 167
PUP.Optional.Winsock.HijackBoot, C:\Windows\Provider32\Provider.dll, Delete-on-Reboot, [c30711d35337ba7c5668a0227a87966a], 
PUP.Optional.EORezo, C:\Program Files (x86)\gmsd_us_005010037\gmsd_us_005010037.exe, Quarantined, [26a49d47b5d523137969acbe54b1867a], 
PUP.Optional.Coupoon.A, C:\Program Files (x86)\Coupoon\iiwjljrnpc64.exe, Quarantined, [69617e66f595a19513c193d7eb1a8b75], 
PUP.Optional.HealthAlert.A, C:\ProgramData\uTWRpFF\cQhxFslxpe.exe, Quarantined, [e3e705df008a181e501380d49f62b947], 
PUP.Optional.ModGoog, C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe, Quarantined, [aa2001e37b0f87afe126622eeb16ad53], 
PUP.Optional.AdPeak.A, C:\Windows\System32\drivers\netfilter64.sys, Quarantined, [aa20ba2a1d6d2d096fe1a1cae124a25e], 
PUP.Optional.Goobzo.SID.A, C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smw.sys, Quarantined, [ffcb01e3315954e26d5de882a26328d8], 
PUP.Optional.Coupoon.A, C:\Program Files (x86)\Coupoon\UpdateCheck.exe, Quarantined, [9337e8fcf59558decd078edc2dd8f010], 
PUP.Optional.UpdateService.A, C:\Windows\Updatesvc.exe, Quarantined, [aa207c682e5c251108b5cff342bf7987], 
PUP.Optional.FlashBeat, C:\ProgramData\FlashBeat\NSISHelper.dll, Quarantined, [5971ab391179f1455c97c201926ff20e], 
PUP.Optional.HealthAlert.A, C:\ProgramData\uTWRpFF\dat\IFXgokXXbT.exe, Quarantined, [7357eafadab0e5514320193b05fc9a66], 
PUP.Optional.HealthAlert.A, C:\ProgramData\uTWRpFF\dat\wkdrqHRjffq.exe, Quarantined, [705aeafa7317c4723d26153f22dfea16], 
Trojan.Downloader, C:\ProgramData\Windows Discount\FindingDiscount\FindingDiscount.exe, Quarantined, [8248ac3895f5053160234c3304feec14], 
PUP.Optional.CrossRider.A, C:\Users\jp\AppData\Roaming\29KouX8P5QCtjDVi.exe, Quarantined, [01c930b46c1ebe7816db6b280001738d], 
PUP.Optional.CrossRider.A, C:\Users\jp\AppData\Roaming\d7musQEpmoFigE.exe, Quarantined, [b218c71dfb8f082e4ba60b8832cfa35d], 
PUP.Optional.CrossRider.A, C:\Users\jp\AppData\Roaming\pSt8fpwyBUBMn.exe, Quarantined, [06c444a03c4ebb7b42af8b080001718f], 
PUP.Optional.CrossRider.A, C:\Users\jp\AppData\Roaming\wQmfRNclS.exe, Quarantined, [c505459f4149072fbb362172d8297f81], 
PUP.Optional.EORezo, C:\Program Files (x86)\gmsd_us_005010037\gamesdesktop_widget.exe, Quarantined, [b31724c06822ce687b67da90be47df21], 
PUP.Optional.EORezo, C:\Program Files (x86)\gmsd_us_005010037\unins000.exe, Quarantined, [a921954fe7a357dff8ea5b0f2adbdb25], 
PUP.Optional.OptimizerPro, C:\Program Files (x86)\Super Optimizer\SuperOptimizer.exe, Quarantined, [e3e7c81c7f0b3cfa436bc8e5f1100000], 
PUP.Optional.Compete, C:\Program Files (x86)\OSDownloader\cinput.exe, Quarantined, [3a9083618a005ed89bbef07b2bda53ad], 
Trojan.Downloader, C:\Program Files (x86)\OSDownloader\gpsetup.exe, Quarantined, [1dadbc28c8c2ed491a69b9c612f03ac6], 
PUP.Optional.OneSystemCare.A, C:\Program Files (x86)\OSDownloader\osc.exe, Quarantined, [894130b41e6c5ed83e5293d83bcaf10f], 
PUP.Optional.CrossRider.A, C:\Users\jp\AppData\Local\Temp\7330.exe, Quarantined, [13b71fc51c6ecc6aaf7b6202c441e41c], 
PUP.Optional.CrossRider.A, C:\Users\jp\AppData\Local\Temp\~nsu.tmp\Au_.exe, Quarantined, [7b4fb92b56346acc26040e56897c3ac6], 
PUP.Optional.AnyProtect, C:\Users\jp\AppData\Local\nsl3E9.tmp, Quarantined, [29a1eef67a10a393d1fa225a976b0af6], 
Trojan.Agent, C:\Users\jp\AppData\Local\00000000-1437507476-0000-0807-060504030201\pnsoF04D.exe, Quarantined, [8347578dd4b642f49eb0a9828d7856aa], 
PUP.Optional.Crossbrowse.C, C:\Users\jp\AppData\Local\AA860BD4-5274-45AC-B02E-AA6F5A64B7F\AA860BD4-5274-45AC-B02E-AA6F5A64B7F.exe, Quarantined, [27a3f7ed1e6cbd792699edaf08f96f91], 
PUP.Optional.SpeedBit, C:\Users\jp\AppData\Local\Installer\Install_23058\DCvau5BAA.tmp.exe, Quarantined, [894111d3d0ba5ed87d791183f50c31cf], 
PUP.Optional.SpeedBit, C:\Users\jp\AppData\Local\Installer\Install_29287\DCvau5BAA.tmp.exe, Quarantined, [656537ad0d7dca6c9c5a039135cc56aa], 
PUP.Optional.Winsock.HijackBoot, C:\Windows\Provider.dll, Delete-on-Reboot, [9f2b29bb7f0b0d29239b29997e830df3], 
PUP.Optional.Cassiopesa.C, C:\Windows\System32\Tasks\Tny_Cassiopesa, Quarantined, [7852b72d8505a78f31817d8b9d66f709], 
PUP.Optional.Cassiopesa.C, C:\Windows\Tasks\Tny_Cassiopesa.job, Quarantined, [4288c61e02886dc90aa99276659e2bd5], 
PUP.Optional.BrowserHelper.A, C:\Users\jp\AppData\Local\BrowserHelper\BrowserHelperBk.txt, Quarantined, [5476bc28afdb67cf0b4c3dcf4ab9de22], 
PUP.Optional.BrowserHelper.A, C:\Users\jp\AppData\Local\BrowserHelper\BrowserHelper.txt, Quarantined, [5476bc28afdb67cf0b4c3dcf4ab9de22], 
PUP.Optional.AnyProtect.A, C:\Windows\Tasks\APSnotifierPP1.job, Quarantined, [0ebc8361abdf88aeb5f9a766de2540c0], 
PUP.Optional.AnyProtect.A, C:\Windows\Tasks\APSnotifierPP2.job, Quarantined, [5a705c881b6fb18565497a93c83b4db3], 
PUP.Optional.AnyProtect.A, C:\Windows\Tasks\APSnotifierPP3.job, Quarantined, [7b4fe400d2b870c659558885d92a16ea], 
PUP.Optional.AnyProtect.A, C:\Windows\System32\Tasks\APSnotifierPP1, Quarantined, [4f7b8f55206a072f208f55b8659e28d8], 
PUP.Optional.AnyProtect.A, C:\Windows\System32\Tasks\APSnotifierPP2, Quarantined, [82483da75f2b52e4723d7994d82b5ea2], 
PUP.Optional.AnyProtect.A, C:\Windows\System32\Tasks\APSnotifierPP3, Quarantined, [a228c61eacde0c2aa906ad6051b2cc34], 
PUP.Optional.SearchModule.A, C:\Windows\System32\Tasks\SMWPUpd, Quarantined, [8d3d8f55583237ff65946faa986bf808], 
PUP.Optional.SmartWeb.A, C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task, Quarantined, [5476657fb1d90432a1c5819f29da9e62], 
PUP.Optional.HealthAlert.A, C:\ProgramData\HealthAlert\app.dat, Quarantined, [ffcb7d67bbcf90a6799fe242e320e21e], 
PUP.Optional.HealthAlert.A, C:\ProgramData\HealthAlert\data.dat, Quarantined, [ffcb7d67bbcf90a6799fe242e320e21e], 
PUP.Optional.HealthAlert.A, C:\ProgramData\HealthAlert\HealthAlert.ico, Quarantined, [ffcb7d67bbcf90a6799fe242e320e21e], 
PUP.Optional.Goobzo, C:\Windows\System32\Tasks\SMW_UpdateTask_Time_3338343934393333382d3437415a556c2a3223346c41, Quarantined, [7258b92bf59500361da3c26b0cf77789], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-1-6, Quarantined, [9d2d8f5519717bbb65b393a134cf58a8], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-1-7, Quarantined, [18b2667e36546dc9b95fe64eeb183dc3], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-10_user, Quarantined, [8842875d0c7ea88e3eda8aaa3ac916ea], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-3, Quarantined, [bd0dfbe9d1b9c670c94fb3818b786997], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-5, Quarantined, [dfeb3ea601893ff7c94f81b335ce4cb4], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-5_user, Quarantined, [e2e818cc92f8f0469d7bbb79689b7d83], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-6, Quarantined, [3199da0a513975c134e448eccc377987], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a96d2aeb-f5d4-4a48-9c46-a9e1fb40cb4d-7, Quarantined, [82481aca6723df574dcbe45051b2df21], 
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, Quarantined, [21a9f9eb5c2e2a0cbe5aea969d674cb4], 
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, Quarantined, [b911d311c4c6a3939782c6bab45023dd], 
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, Quarantined, [a228ba2ad0ba4beb7e9c631ded17847c], 
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, Quarantined, [0dbd3fa5cebc1f17f229d4ac23e1b14f], 
PUP.Optional.MultiPlug.A, C:\Users\jp\AppData\Local\00000000-1437507476-0000-0807-060504030201\onsoF04C.tmp, Quarantined, [8842ca1ae4a6d85e6165d7b641c3fe02], 
PUP.Optional.MultiPlug.A, C:\Users\jp\AppData\Local\00000000-1437507476-0000-0807-060504030201\DDF0.tmp, Quarantined, [8842ca1ae4a6d85e6165d7b641c3fe02], 
PUP.Optional.MultiPlug.A, C:\Users\jp\AppData\Local\00000000-1437507476-0000-0807-060504030201\pnsoF04D.exe, Quarantined, [8842ca1ae4a6d85e6165d7b641c3fe02], 
PUP.Optional.MultiPlug.A, C:\Users\jp\AppData\Local\00000000-1437507476-0000-0807-060504030201\rnsoF04B.exe, Quarantined, [8842ca1ae4a6d85e6165d7b641c3fe02], 
PUP.Optional.MultiPlug.A, C:\Users\jp\AppData\Local\00000000-1437507476-0000-0807-060504030201\snsoF04A.tmp, Quarantined, [8842ca1ae4a6d85e6165d7b641c3fe02], 
PUP.Optional.MultiPlug.A, C:\Users\jp\AppData\Local\00000000-1437507476-0000-0807-060504030201\Uninstall.exe, Quarantined, [8842ca1ae4a6d85e6165d7b641c3fe02], 
PUP.Optional.Goobzo.A, C:\Windows\System32\Tasks\SMupdate1, Quarantined, [408a5193305a48eee4bc058c887cb34d], 
PUP.Optional.SuperOptimizer.A, C:\ProgramData\{016aaf46-a15a-b249-016a-aaf46a15bd1a}\hqghumeaylnlf.dat, Quarantined, [5377c71daedc25115f0c8d0609fbf10f], 
PUP.Optional.SuperOptimizer.A, C:\ProgramData\{016aaf46-a15a-b249-016a-aaf46a15bd1a}\3059a9225aeee69c, Quarantined, [5377c71daedc25115f0c8d0609fbf10f], 
PUP.Optional.SuperOptimizer.A, C:\ProgramData\{016aaf46-a15a-b249-016a-aaf46a15bd1a}\fda40f777d3a0148, Quarantined, [5377c71daedc25115f0c8d0609fbf10f], 
PUP.Optional.SuperOptimizer.A, C:\ProgramData\{016aaf46-a15a-b249-016a-aaf46a15bd1a}\fda40f777d3a0148.lock, Quarantined, [5377c71daedc25115f0c8d0609fbf10f], 
PUP.Optional.SuperOptimizer.A, C:\ProgramData\{016aaf46-a15a-b249-016a-aaf46a15bd1a}\hqghumeaylnlf.exe, Quarantined, [5377c71daedc25115f0c8d0609fbf10f], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\unins000.msg, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\bg_new_en.bmp, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\bg_new_es.bmp, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\bg_new_fr.bmp, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\bg_new_it.bmp, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\cancel.bmp, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\CookiesException.txt, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\English.ini, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\file_id.diz, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\HomePage.url, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\idp.dll, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\itdownload.dll, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\scan.gif, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\sqlite3.dll, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\StartupList.txt, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\SuperOptimizer.chm, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\SupOptCashier.exe, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\SupOptGuard.exe, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\SupOptHelper.dll, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\SupOptLauncher.exe, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\SupOptReminder.exe, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\SupOptSchedule.exe, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\SupOptSmartScan.exe, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\SupOptStart.exe, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\SupOptStats.dll, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\SupOptUninstaller.exe, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\unins000.dat, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.SuperOptimizer.A, C:\Program Files (x86)\Super Optimizer\unins000.exe, Quarantined, [408a9351494160d6e983d5be38cc1ee2], 
PUP.Optional.Multiplug.A, C:\Windows\System32\Tasks\Bidaily Synchronize Task[8da6], Quarantined, [f4d674706228cf673cc499fb44c05aa6], 
PUP.Optional.Multiplug.A, C:\Windows\Tasks\Bidaily Synchronize Task[8da6].job, Quarantined, [3793f3f190faed49aa57712320e4c53b], 
PUP.Optional.BundleInstaller.A, C:\ProgramData\abc\debug.log, Quarantined, [795190546b1fd264e96d375e05ff28d8], 
PUP.Optional.BundleInstaller.A, C:\ProgramData\abc\17AF54B9, Quarantined, [795190546b1fd264e96d375e05ff28d8], 
PUP.Optional.BundleInstaller.A, C:\ProgramData\abc\4DEDA591, Quarantined, [795190546b1fd264e96d375e05ff28d8], 
PUP.Optional.BundleInstaller.A, C:\ProgramData\abc\6C8E155, Quarantined, [795190546b1fd264e96d375e05ff28d8], 
PUP.Optional.BundleInstaller.A, C:\ProgramData\abc\7F24D2EF, Quarantined, [795190546b1fd264e96d375e05ff28d8], 
PUP.Optional.BundleInstaller.A, C:\ProgramData\abc\9721B0CB, Quarantined, [795190546b1fd264e96d375e05ff28d8], 
PUP.Optional.BundleInstaller.A, C:\ProgramData\abc\99E1F920, Quarantined, [795190546b1fd264e96d375e05ff28d8], 
PUP.Optional.BundleInstaller.A, C:\ProgramData\abc\AA012CZ, Quarantined, [795190546b1fd264e96d375e05ff28d8], 
PUP.Optional.BundleInstaller.A, C:\ProgramData\abc\C78F0747, Quarantined, [795190546b1fd264e96d375e05ff28d8], 
PUP.Optional.SuperOptimizer, C:\Windows\System32\Tasks\Super Optimizer Schedule, Quarantined, [4b7f35afe2a89e988761801736ce7c84], 
PUP.Optional.PullUpdate.Gen, C:\ProgramData\Onkavatiiihm\1.0.4.1\jsixetek.exe.config, Quarantined, [b911eafa335793a359bcd9c26a9a3ec2], 
PUP.Optional.PullUpdate.Gen, C:\ProgramData\Onkavatiiihm\1.0.4.1\jsixetek.exe, Quarantined, [b911eafa335793a359bcd9c26a9a3ec2], 
PUP.Optional.PullUpdate.Gen, C:\ProgramData\Onkavatiiihm\1.0.4.1\sqlite3.dll, Quarantined, [b911eafa335793a359bcd9c26a9a3ec2], 
PUP.Optional.PullUpdate.Gen, C:\ProgramData\Onkavatiiihm\dat.dat, Quarantined, [b911eafa335793a359bcd9c26a9a3ec2], 
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\00000000-1437525428-0000-0807-060504030201\knsn2B0.tmp, Quarantined, [e6e423c1f79374c28e3c3c60857f21df], 
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\00000000-1437525428-0000-0807-060504030201\hnst9906.tmp, Quarantined, [e6e423c1f79374c28e3c3c60857f21df], 
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\00000000-1437525428-0000-0807-060504030201\jnst822A.tmp, Quarantined, [e6e423c1f79374c28e3c3c60857f21df], 
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\00000000-1437525428-0000-0807-060504030201\Number of results, Quarantined, [e6e423c1f79374c28e3c3c60857f21df], 
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\00000000-1437525428-0000-0807-060504030201\rnso59CF.exe, Quarantined, [e6e423c1f79374c28e3c3c60857f21df], 
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\00000000-1437525428-0000-0807-060504030201\Uninstall.exe, Quarantined, [e6e423c1f79374c28e3c3c60857f21df], 
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\00000000-1437525428-0000-0807-060504030201\vnst312D.tmp, Quarantined, [e6e423c1f79374c28e3c3c60857f21df], 
PUP.Optional.WombatService.A, C:\ProgramData\Service1291\Service1291.dll, Quarantined, [527821c3246640f6d8171f7d29db45bb], 
PUP.Optional.WombatService.A, C:\ProgramData\Service1291\Service1291.exe, Quarantined, [527821c3246640f6d8171f7d29db45bb], 
PUP.Optional.FriendlyError.A, C:\Program Files (x86)\FriendlyError\tmpBB4.bat, Quarantined, [ad1dd31199f16ec8cc4f1588c83c1ae6], 
PUP.Optional.RuntimeManager.A, C:\Program Files (x86)\Windows NT\Accessories\RuntimeManager\runtimemanager.exe, Quarantined, [834739ab18720630e0f25bc10ff4d62a], 
PUP.Optional.Goobzo.A, C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smu.exe, Quarantined, [bd0d974dd8b2b1855fec8c09cf35a35d], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\globalupdate.exe, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\globalupdateBroker.exe, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\globalupdateCrashHandler.exe, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\globalupdateHelper.msi, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\globalupdateOnDemand.exe, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdate.dll, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psmachine.dll, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psuser.dll, Quarantined, [af1beef67a1064d213785e8a54ae5fa1], 
PUP.Optional.Goobzo, C:\Program Files\Common Files\Goobzo\GBUpdatePlus\rlz_id.dll, Quarantined, [3496974dafdbbd79b19614d9be44ed13], 
PUP.Optional.Goobzo, C:\Program Files\Common Files\Goobzo\GBUpdatePlus\SBIEBrowserHelperObject.dll, Quarantined, [3496974dafdbbd79b19614d9be44ed13], 
PUP.Optional.Goobzo, C:\Program Files\Common Files\Goobzo\GBUpdatePlus\Search.lnk, Quarantined, [3496974dafdbbd79b19614d9be44ed13], 
PUP.Optional.Goobzo, C:\Program Files\Common Files\Goobzo\GBUpdatePlus\sma.exe, Quarantined, [3496974dafdbbd79b19614d9be44ed13], 
PUP.Optional.Goobzo, C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smci32.dll, Quarantined, [3496974dafdbbd79b19614d9be44ed13], 
PUP.Optional.Goobzo, C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smci64.dll, Quarantined, [3496974dafdbbd79b19614d9be44ed13], 
PUP.Optional.Goobzo, C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smi32.exe, Quarantined, [3496974dafdbbd79b19614d9be44ed13], 
PUP.Optional.Goobzo, C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smi64.exe, Quarantined, [3496974dafdbbd79b19614d9be44ed13], 
PUP.Optional.Goobzo, C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smp.exe, Quarantined, [3496974dafdbbd79b19614d9be44ed13], 
PUP.Optional.Goobzo, C:\Program Files\Common Files\Goobzo\GBUpdatePlus\SMUninstall.exe, Quarantined, [3496974dafdbbd79b19614d9be44ed13], 
PUP.Optional.Goobzo, C:\Program Files\Common Files\Goobzo\GBUpdatePlus\Updater.exe, Quarantined, [3496974dafdbbd79b19614d9be44ed13], 
PUP.Optional.GamesDesktop.A, C:\Users\jp\AppData\Local\gmsd_us_005010037\upgmsd_us_005010037.cyl, Quarantined, [e2e89351d5b5da5c78d2b74043bfb24e], 
PUP.Optional.GamesDesktop.A, C:\Users\jp\AppData\Local\gmsd_us_005010037\user_profil.cyp, Quarantined, [e2e89351d5b5da5c78d2b74043bfb24e], 
PUP.Optional.GamesDesktop.A, C:\Users\jp\AppData\Local\gmsd_us_005010037\gmsd_us_005010037\1.20\cnf.cyl, Quarantined, [e2e89351d5b5da5c78d2b74043bfb24e], 
PUP.Optional.GamesDesktop.A, C:\Program Files (x86)\gmsd_us_005010037\unins000.dat, Quarantined, [9e2c44a0563493a3b6957483669cd12f], 
PUP.Optional.GamesDesktop.A, C:\Program Files (x86)\gmsd_us_005010037\unins000.msg, Quarantined, [9e2c44a0563493a3b6957483669cd12f], 
PUP.Optional.FindingDiscount.A, C:\Program Files (x86)\Windows Discount\FindingDiscount\findingdiscount.exe, Quarantined, [d2f8875db7d355e16f7d70890bf724dc], 
PUP.Optional.FindingDiscount.A, C:\ProgramData\Windows Discount\FindingDiscount\config.dat, Quarantined, [705a588ca1e9c86e6a83a15852b09e62], 
PUP.Optional.FindingDiscount.A, C:\ProgramData\Windows Discount\FindingDiscount\FindingDiscount.exe, Quarantined, [705a588ca1e9c86e6a83a15852b09e62], 
PUP.Optional.VOPackage.A, C:\Users\jp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage\Configure.lnk, Quarantined, [deec0dd7b7d3a88e90d09e5df80a4bb5], 
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\install.log, Quarantined, [94366381622871c5cb03a15da062bd43], 
PUP.Optional.Coupoon.A, C:\Program Files (x86)\Coupoon\64.ico, Quarantined, [5b6f1ec60882d6608cdcfa0838cbcd33], 
PUP.Optional.Coupoon.A, C:\Program Files (x86)\Coupoon\libeay32.dll, Quarantined, [5b6f1ec60882d6608cdcfa0838cbcd33], 
PUP.Optional.Coupoon.A, C:\Program Files (x86)\Coupoon\nfregdrv.exe, Quarantined, [5b6f1ec60882d6608cdcfa0838cbcd33], 
PUP.Optional.Coupoon.A, C:\Program Files (x86)\Coupoon\ProtocolFilters.dll, Quarantined, [5b6f1ec60882d6608cdcfa0838cbcd33], 
PUP.Optional.Coupoon.A, C:\Program Files (x86)\Coupoon\ssleay32.dll, Quarantined, [5b6f1ec60882d6608cdcfa0838cbcd33], 
PUP.Optional.SearchModulePlus.A, C:\ProgramData\SearchModulePlus\smhe.js, Quarantined, [12b8d311ff8b1f17fa0dd92a0102629e], 
PUP.Optional.PullUpdate.A, C:\ProgramData\uTWRpFF\dat\IFXgokXXbT.exe.config, Quarantined, [c703b232c9c1043204a63d30d431f40c], 
PUP.Optional.PullUpdate.A, C:\ProgramData\uTWRpFF\dat\wkdrqHRjffq.exe.config, Quarantined, [c703b232c9c1043204a63d30d431f40c], 
PUP.Optional.PullUpdate.A, C:\ProgramData\uTWRpFF\cQhxFslxpe.dat, Quarantined, [c703b232c9c1043204a63d30d431f40c], 
PUP.Optional.PullUpdate.A, C:\ProgramData\uTWRpFF\cQhxFslxpe.exe.config, Quarantined, [c703b232c9c1043204a63d30d431f40c], 
PUP.Optional.PullUpdate.A, C:\ProgramData\uTWRpFF\info.dat, Quarantined, [c703b232c9c1043204a63d30d431f40c], 
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)

 


  • 0

Advertisements


#11
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,792 posts
Very good.

Do the adwCleaner "Clean" option now as instructed in post #9 :)
  • 0

#12
jpatt

jpatt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts

Joe, thanks for all your help. I'm running AdwCleaner again the scan runs and finishes...I guess. Above the progression bar it reads "Waiting for action. Please uncheck elements you want to keep".

 

Just an FYI....I will be away from my computer for the next few days.  I follow your next instructions when I get back.

 

thanks again,

jp

 

 


  • 0

#13
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,792 posts

"Waiting for action. Please uncheck elements you want to keep".


Now press the "Logfile" button, then press clean!

I'll leave the light on til your return :)


Thanks
Joe
  • 0

#14
jpatt

jpatt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts

I had my daughter do the clean before she log off last night. Didn't know about the Logfile, step. Does this program store older log files?

 


  • 0

#15
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,792 posts

Does this program store older log files


Yes it does store logs and they can be found here,
 
C:\AdwCleaner\AdwCleaner[SO].txt 
We want the [SO] LOG. that one shows the deletions, the [RO] is the scan log.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP