Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Lots of Pop-ups and running slowly ... I believe this laptop is infect


  • This topic is locked This topic is locked

#1
moondog830

moondog830

    Member

  • Member
  • PipPipPip
  • 626 posts

A lady at my church asked me to look at her laptop because there were 'tons of pop-ups'. She had no idea how to look things over. She said her grandson had been using it the last time he visited and she wondered if it was something he had done. When  I  looked it over, I noticed a bunch of programs and toolbars that I wouldn't have put on it. 

 

I have run the first 2 scans as required

 

FRST

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:17-08-2015
Ran by Kathy (administrator) on KATHY-PC (19-08-2015 10:07:20)
Running from C:\Users\Kathy\Desktop
Loaded Profiles: Kathy (Available Profiles: Kathy)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files\shopperz12072015\Igivkorcb.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
() C:\Program Files\shopperz12072015\Bzvra.exe
() C:\Program Files\shopperz12072015\Bzvra64.exe
(Cinema PlusV13.07) C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.exe
() C:\Users\Kathy\AppData\Local\ospd_us_014010029\upospd_us_014010029.exe
(Cinema PlusV18.07) C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.exe
(Cinema PlusV13.07) C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.exe
(HQ-VideoV12.07) C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.exe
(HQ-VideoV12.07) C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-6.exe
(globalUpdate) C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe
() C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe
(ConsumerInput) C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe
(EpsanDrive) C:\ProgramData\EpsanDrive\EpsanDrive.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(EpsanDrive) C:\ProgramData\EpsanDrive\EpsanDrive.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(CLICK YES BELOW LP) C:\Program Files (x86)\Ninja Loader\Ninja Loader.exe
(PU-App) C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh\yxa2bzvwzf9jdth.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(SoftBrain Technologies Ltd.) C:\Users\Kathy\AppData\Local\SmartWeb\SmartWebHelper.exe
(Weather Protector LLC) C:\Program Files (x86)\StormWatch\StormWatch.exe
() C:\Program Files (x86)\StormWatch\StormWatchApp.exe
() C:\Program Files (x86)\msrtn32\msrtn32.exe
() C:\Program Files (x86)\gmsd_us_005010030\gmsd_us_005010030.exe
() C:\Program Files (x86)\Smwyyntm1ndi1zdz\ywi2mzv2zhnjbdh.exe
() C:\Program Files (x86)\gmsd_us_005010031\gmsd_us_005010031.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
() C:\Program Files\shopperz12072015\csrcc.exe
() C:\Program Files (x86)\dataup\dataup.exe
(FlashBeat) C:\ProgramData\FlashBeat\FlashBeat.exe
(SIEN S.A.) C:\Program Files (x86)\Common Files\IMGUpdater\IMGUpdater.exe
(FlashBeat) C:\ProgramData\FlashBeat\FlashBeat.exe
(Iminent) C:\Program Files (x86)\Common Files\Umbrella\Umbrella234.exe
(Iminent) C:\Program Files (x86)\Common Files\Umbrella\Umbrella234.exe
() C:\Program Files\shopperz12072015\ZazyjiKotn.exe
(Copyright © Microsoft 2015) C:\Program Files (x86)\Microsoft.NET\v2.0.507279\msnetcore.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(myradioplayer) C:\Program Files (x86)\RadPlayer\myradioplayer.exe
(Ninja Soft Inc.) C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe
() C:\Program Files (x86)\msrtn32\cdhtr.exe
() C:\Users\Kathy\AppData\Local\5670549A-1436745948-DE00-E918-1C7508113231\cnsh175B.tmp
() C:\Users\Kathy\AppData\Roaming\ASPackage\ASSrv.exe
() C:\Program Files\shopperz12072015\Xzeexmh.exe
(Ninja Soft Inc.) C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe
(Ninja Soft Inc.) C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe
() C:\Program Files (x86)\StormWatch\StormWatchSrv.exe
(Weather Protector LLC) C:\Program Files (x86)\StormWatch\SWUpdaterSvc.exe
() C:\ProgramData\1436760085\s9.exe
() C:\Program Files (x86)\Coupoon\UpdateCheck.exe
() C:\Program Files\WajIEn\wajam_64.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
() C:\Program Files\WajIEn\wajam.exe
() C:\Program Files\WajIEn\wajam_64.exe
(WS) C:\Program Files (x86)\WordShark_1.10.0.20\Service\wssvc.exe
(RadPlayer) C:\Program Files (x86)\RadPlayer\RadPlayerSvc.exe
(Valid Applications) C:\ProgramData\caGSSMRD\REhsGdKiASD.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
() C:\Program Files\shopperz12072015\Cofvopjy.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
() C:\Users\Kathy\AppData\Local\5670549A-1436745948-DE00-E918-1C7508113231\ansh1316.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Google Inc.) C:\Users\Kathy\AppData\Local\Temp\20150713\ct.exe
(Advanced Micro Devices, Inc.) C:\Windows\System32\atibtmon.exe
(SoftBrain Technologies Ltd.) C:\Users\Kathy\AppData\Local\SmartWeb\SmartWebApp.exe
(IObit) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
( ) C:\Users\Kathy\AppData\Roaming\ASPackage\ASPackage.exe
(The Chromium Authors) C:\Users\Kathy\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\Kathy\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\Kathy\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\Kathy\AppData\Local\Ninja Loader\Discover\Discover.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13774040 2015-01-06] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-07-12] (Adobe Systems Incorporated)
HKLM\...\Run: [RadPlayer Tray] => C:\Program Files (x86)\RadPlayer\TyV1.exe [294824 2015-05-29] (RadPlayer)
HKLM\...\Run: [shopperz12072015] => C:\Program Files\shopperz12072015\Bzvra.exe [433512 2015-07-13] ()
HKLM\...\Run: [shopperz1207201564] => C:\Program Files\shopperz12072015\Bzvra64.exe [464744 2015-07-13] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [896632 2015-07-22] (BlueStack Systems, Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2303152 2015-07-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StormWatch] => C:\Program Files (x86)\StormWatch\StormWatchApp.exe [1556504 2015-04-10] ()
HKLM-x32\...\Run: [cpx] => C:\Program Files (x86)\cpx\cpx.exe [1162240 2015-06-26] ()
HKLM-x32\...\Run: [msrtn32] => C:\Program Files (x86)\msrtn32\msrtn32.exe [1221120 2015-06-28] ()
HKLM-x32\...\Run: [WinCheck] => C:\Users\Kathy\AppData\Local\5670549A-1436745935-DE00-E918-1C7508113231\bnshDF4A.exe [350720 2015-06-24] ()
HKLM-x32\...\Run: [gmsd_us_005010030] => C:\Program Files (x86)\gmsd_us_005010030\gmsd_us_005010030.exe [3986064 2015-07-13] ()
HKLM-x32\...\Run: [mwyyntm1ndi1zdz] => C:\Program Files (x86)\Smwyyntm1ndi1zdz\ywi2mzv2zhnjbdh.exe [2422272 2015-07-13] ()
HKLM-x32\...\Run: [gmsd_us_005010031] => C:\Program Files (x86)\gmsd_us_005010031\gmsd_us_005010031.exe [3985552 2015-07-14] ()
HKLM-x32\...\Run: [MovieDea] => C:\Program Files (x86)\MovieDea\MovieDea.exe [3184640 2015-06-03] (MovieDea)
HKLM-x32\...\Run: [SmartWeb] => C:\Users\Kathy\AppData\Local\SmartWeb\SmartWebHelper.exe [270368 2015-02-17] (SoftBrain Technologies Ltd.)
HKLM-x32\...\RunOnce: [upospd_us_014010029.exe] => C:\Users\Kathy\AppData\Local\ospd_us_014010029\upospd_us_014010029.exe [3287696 2015-07-12] ()
HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2895552 2015-07-23] (Valve Corporation)
HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53282944 2015-06-29] (Skype Technologies S.A.)
HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Run: [NinjaLoader] => C:\Program Files (x86)\Ninja Loader\Ninja Loader.exe [1575016 2015-07-02] (CLICK YES BELOW LP)
HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro 3.99\OptProLauncher.exe [148112 2015-07-03] ()
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll [246544 2015-07-02] (Client Connect LTD)
AppInit_DLLs:  C:\ProgramData\FlashBeat\FlashBeat64.dll => C:\ProgramData\FlashBeat\FlashBeat64.dll File not found
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [213776 2015-07-02] (Client Connect LTD)
AppInit_DLLs-x32:  C:\ProgramData\FlashBeat\FlashBeat32.dll => C:\ProgramData\FlashBeat\FlashBeat32.dll [805376 2015-07-13] (FlashBeat)
AppInit_DLLs-x32:  C:\ProgramData\EpsanDrive\EpsanDrive32.dll => C:\ProgramData\EpsanDrive\EpsanDrive32.dll [805376 2015-07-08] (EpsanDrive)
AppInit_DLLs-x32:  C:\PROGRA~3\{63B88~1\1173~1.1\tiso.dll => "C:\PROGRA~3\{63B88~1\1173~1.1\tiso.dll" File not found
Startup: C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bm.lnk [2015-07-18]
ShortcutTarget: bm.lnk -> C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh\yxa2bzvwzf9jdth.exe (PU-App)
Startup: C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk [2015-07-13]
ShortcutTarget: crossbrowse.lnk -> C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe (No File)
Startup: C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk [2015-07-18]
ShortcutTarget: SmartWeb.lnk -> C:\Users\Kathy\AppData\Local\SmartWeb\SmartWebHelper.exe (SoftBrain Technologies Ltd.)
Startup: C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatch.lnk [2015-07-12]
ShortcutTarget: StormWatch.lnk -> C:\Program Files (x86)\StormWatch\StormWatch.exe (Weather Protector LLC)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-171533428-321824291-3300133993-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.yahoo.com/?fr=hp-ddc-bd&type=bl-bir-ob-rhb-29__alt__ddc_dsssyc_bd_com
HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
URLSearchHook: HKU\S-1-5-21-171533428-321824291-3300133993-1000 - (No Name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> OldSearch URL = hxxp://www.cassiopessa.com/results.php?f=4&q={searchTerms}&a=csp_installertech_15_26&cd=2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0EzztD0BzzyCtByDyDtAtN0D0Tzu0StCtByBtAtN1L2XzutAtFtCtCtFtAtFtCtN1L1Czu1R1B1E1V1L1G1B2Z1T1I1I1P1C2Z1P1R1MtN1L1G1B1V1N2Y1L1Qzu2StB0A0BtCtCyB0C0BtGyCyCtAtAtG0Azz0BtBtGyEzzyCzytGtBzz0C0ByE0DyB0BtA0D0F0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0E0DyC0E0DzytBtGtBtD0D0FtGyE0FtA0EtG0B0AtB0EtGyEzy0AtByByEzzyC0F0E0FtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzuzztBtB&cr=1202157401&ir=
SearchScopes: HKLM -> {460C3D19-B3D4-4964-A550-77D263B0CCCB} URL = hxxp://search.yahoo.com/yhs/search?hspart=ddc&hsimp=yhs-ddc_bd&type=bl-bir-ob-rhb-29__alt__ddc_dss_bd_com&p={searchTerms}
SearchScopes: HKLM-x32 -> {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://start.iminent.com/?appId=8437c40c-c891-4a5e-8eea-ca8568502d51&ref=toolbox&q={searchTerms}
SearchScopes: HKU\S-1-5-21-171533428-321824291-3300133993-1000 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3333887&octid=EB_ORIGINAL_CTID&ISID=M1890E6BC-BF65-41CA-B1ED-FCA8EC054D11&SearchSource=58&CUI=&UM=8&UP=SPA98636E4-750F-401C-BC08-F5A740811DAD&D=071415&q={searchTerms}&SSPV=SP30339T2B_sp_ie
SearchScopes: HKU\S-1-5-21-171533428-321824291-3300133993-1000 -> {BC4A5ADC-08EE-4734-9171-5A5035FF16D7} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-07-18] (IObit)
BHO: IMinent WebBooster (BHO) -> {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} -> C:\Program Files (x86)\Iminent\Minibar.InternetExplorer.BHOx64.dll [2015-06-10] (SIEN)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Consumer Input DCA BHO -> {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} -> C:\Program Files (x86)\Consumer Input\InternetExplorer\x64\dca-bho.dll [2015-06-25] (Compete, Inc.)
BHO: shopperz12072015 -> {c49ac435-5c4d-450f-aa56-cd31f96613b3} -> C:\Program Files\shopperz12072015\Eixrizl64.dll [2015-07-13] ()
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-27] (Oracle Corporation)
BHO-x32: No Name -> {84FF7BD6-B47F-46F8-9130-01B2696B36CB} ->  No File
BHO-x32: IMinent WebBooster (BHO) -> {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} -> C:\Program Files (x86)\Iminent\Minibar.InternetExplorer.BHOx86.dll [2015-06-10] (SIEN)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Consumer Input DCA BHO -> {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} -> C:\Program Files (x86)\Consumer Input\InternetExplorer\dca-bho.dll [2015-06-25] (Compete, Inc.)
BHO-x32: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2015-04-01] (IObit)
BHO-x32: shopperz12072015 -> {c49ac435-5c4d-450f-aa56-cd31f96613b3} -> C:\Program Files\shopperz12072015\Eixrizl.dll [2015-07-13] ()
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-27] (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Winsock: Catalog9 01 C:\Windows\SysWOW64\Cofvopjy.dll [279040 2015-07-14] ()
Winsock: Catalog9 02 C:\Windows\SysWOW64\Cofvopjy.dll [279040 2015-07-14] ()
Winsock: Catalog9 03 C:\Windows\SysWOW64\Cofvopjy.dll [279040 2015-07-14] ()
Winsock: Catalog9 04 C:\Windows\SysWOW64\Cofvopjy.dll [279040 2015-07-14] ()
Winsock: Catalog9 05 C:\Windows\SysWOW64\myradioplayer.dll [358824 2015-07-12] (myradioplayer)
Winsock: Catalog9 06 C:\Windows\SysWOW64\myradioplayer.dll [358824 2015-07-12] (myradioplayer)
Winsock: Catalog9 07 C:\Windows\SysWOW64\myradioplayer.dll [358824 2015-07-12] (myradioplayer)
Winsock: Catalog9 08 C:\Windows\SysWOW64\myradioplayer.dll [358824 2015-07-12] (myradioplayer)
Winsock: Catalog9 19 C:\Windows\SysWOW64\myradioplayer.dll [358824 2015-07-12] (myradioplayer)
Winsock: Catalog9 20 C:\Windows\SysWOW64\Cofvopjy.dll [279040 2015-07-14] ()
Winsock: Catalog9-x64 01 C:\Windows\system32\myradioplayer64.dll [465320 2015-07-12] (myradioplayer)
Winsock: Catalog9-x64 02 C:\Windows\system32\myradioplayer64.dll [465320 2015-07-12] (myradioplayer)
Winsock: Catalog9-x64 03 C:\Windows\system32\myradioplayer64.dll [465320 2015-07-12] (myradioplayer)
Winsock: Catalog9-x64 04 C:\Windows\system32\myradioplayer64.dll [465320 2015-07-12] (myradioplayer)
Winsock: Catalog9-x64 15 C:\Windows\system32\myradioplayer64.dll [465320 2015-07-12] (myradioplayer)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{13BA7357-F3CB-44DF-94FB-47B6BD1FF704}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{D464E0FB-F200-41A0-A115-BF3ED0CBE42C}: [DhcpNameServer] 192.168.1.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF Plugin: @iqiyi.com/npclient -> C:\IQIYI Video\LStyle\npclient.dll [2015-05-12] ()
FF Plugin: @iqiyi.com/npWebPlayer -> C:\IQIYI Video\LStyle\npWebPlayer.dll [2015-04-29] (爱奇艺公司)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2015-07-02] (Adobe Systems)
FF Plugin-x32: @iqiyi.com/npclient -> C:\IQIYI Video\LStyle\npclient.dll [2015-05-12] ()
FF Plugin-x32: @iqiyi.com/npWebPlayer -> C:\IQIYI Video\LStyle\npWebPlayer.dll [2015-04-29] (爱奇艺公司)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-27] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-07-19] (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-07-19] (globalUpdate)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-05] (Google Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2015-07-02] (Adobe Systems)
FF Plugin HKU\S-1-5-21-171533428-321824291-3300133993-1000: @iqiyi.com/npWebPlayer -> C:\IQIYI Video\LStyle\npWebPlayer.dll [2015-04-29] (爱奇艺公司)
FF Plugin HKU\S-1-5-21-171533428-321824291-3300133993-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Kathy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-12-05] (Unity Technologies ApS)
FF HKLM\...\Firefox\Extensions: [{c49ac435-5c4d-450f-aa56-cd31f96613b3}] - C:\Program Files\shopperz12072015\Firefox
FF Extension: shopperz12072015 - C:\Program Files\shopperz12072015\Firefox [2015-07-14]
FF HKLM-x32\...\Firefox\Extensions: [{c49ac435-5c4d-450f-aa56-cd31f96613b3}] - C:\Program Files\shopperz12072015\Firefox
FF HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12191.xpi
FF Extension: Consumer Input - C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12191.xpi [2015-06-25]
FF HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Ninja Loader\FireFox
FF Extension: NinjaLoader - C:\Program Files (x86)\Ninja Loader\FireFox [2015-07-13]
 
Chrome: 
=======
CHR Profile: C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (HQCinema Pro 2.1V12.07) - C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gegdfeiahlfolhcfioipjlkombmgbakh [2015-07-12]
CHR Extension: (CinemaPlus-3.2cV13.07) - C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\papbadoldddalgcjcicnikcfenodpghp [2015-07-13]
CHR HKLM-x32\...\Chrome\Extension: [adpeheiliennogfclcgmchdfdmafjegc] - https://clients2.goo...ice/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [cmlhbjpgeogifjnmlajdaealbdlfonah] - https://clients2.goo...ice/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ehhlaekjfiiojlddgndcnefflngfmhen] - https://clients2.goo...ice/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gihfmmedoddijgnhkgfgnkeohkpbipol] - https://clients2.goo...ice/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]
CHR HKLM-x32\...\Chrome\Extension: [nociobghckdhokecfeajdpimjeapnopn] - https://clients2.goo...ice/update2/crx
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 46784c7a-2afb-4c2f-b299-133de9a46a66; C:\Program Files\shopperz12072015\Igivkorcb.exe [285544 2015-07-13] ()
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [680112 2015-06-09] (Adobe Systems Incorporated)
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [433784 2015-06-16] (BlueStack Systems, Inc.)
S2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [413304 2015-06-16] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [831096 2015-07-21] (BlueStack Systems, Inc.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
S2 c31ed948; c:\Program Files (x86)\Optimizer Pro 3.99\OptProMon.dll [2570896 2015-07-13] () <==== ATTENTION
R3 Cofvopjy; C:\Program Files\shopperz12072015\Cofvopjy.exe [2020864 2015-07-13] () [File not signed]
S2 consumerinput_update; C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [105944 2015-07-12] (ConsumerInput)
S3 consumerinput_updatem; C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [105944 2015-07-12] (ConsumerInput)
S2 CoupoonService64; C:\Program Files (x86)\coupoon\iiwjljrnpc64.exe [172344 2015-04-02] ()
R2 csrcc; C:\Program Files\shopperz12072015\csrcc.exe [1448808 2015-07-13] ()
R2 Dataup; C:\Program Files (x86)\dataup\dataup.exe [77824 2015-06-29] () [File not signed] <==== ATTENTION
S2 FlashBeat; C:\ProgramData\FlashBeat\FlashBeat.exe [814080 2015-07-13] (FlashBeat) [File not signed]
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-07-19] (globalUpdate) [File not signed] <==== ATTENTION
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-07-19] (globalUpdate) [File not signed] <==== ATTENTION
R2 GlobalUpdater; C:\Program Files (x86)\Common Files\IMGUpdater\IMGUpdater.exe [378152 2015-07-02] (SIEN S.A.)
R2 IMService; C:\Program Files (x86)\Common Files\Umbrella\Umbrella234.exe [5315224 2015-07-02] (Iminent)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2904864 2015-06-02] (IObit)
R2 LosdyLijfeu; C:\Program Files\shopperz12072015\ZazyjiKotn.exe [171920 2015-07-13] () [File not signed]
R2 msdotnetserv_v2050729; C:\Program Files (x86)\Microsoft.NET\v2.0.507279\msnetcore.exe [3003880 2015-07-05] (Copyright © Microsoft 2015)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R2 myradioplayer; C:\Program Files (x86)\RadPlayer\myradioplayer.exe [3904936 2015-05-29] (myradioplayer)
R2 NinjaLoaderService; C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe [59496 2015-07-02] (Ninja Soft Inc.)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 RadPlayerV1; C:\Program Files (x86)\RadPlayer\RadPlayerSvc.exe [323496 2015-05-29] (RadPlayer)
S2 RadPlayerV2; C:\Program Files (x86)\RadPlayer\RadPlayer.Service.exe [78248 2015-05-29] (RadPlayer)
R2 REhsGdKiASD; C:\ProgramData\caGSSMRD\REhsGdKiASD.exe [2732288 2015-07-13] (Valid Applications)
R2 relibily; C:\Users\Kathy\AppData\Local\5670549A-1436745948-DE00-E918-1C7508113231\cnsh175B.tmp [219136 2015-07-13] () [File not signed]
R2 serveras; C:\Users\Kathy\AppData\Roaming\ASPackage\ASSrv.exe [183808 2015-07-13] () [File not signed]
R2 shopperz12072015 Updater; C:\Program Files\shopperz12072015\Xzeexmh.exe [174952 2015-07-13] ()
S3 Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [837312 2015-06-04] (Valve Corporation) [File not signed]
R2 StormWatch Update Service; C:\Program Files (x86)\StormWatch\StormWatchSrv.exe [586264 2015-04-10] ()
R2 SWUpdater; C:\Program Files (x86)\StormWatch\SWUpdaterSvc.exe [17584 2014-11-22] (Weather Protector LLC)
R2 UdvdPork; C:\ProgramData\1436760085\s9.exe [404480 2015-04-07] () [File not signed]
R2 UpdateCheck; C:\Program Files (x86)\Coupoon\UpdateCheck.exe [53040 2015-07-12] ()
R2 WajIEn Monitor; C:\Program Files\WajIEn\wajam_64.exe [1997824 2015-07-13] () [File not signed]
S2 wbsvc; C:\Program Files\WebBar\wbsvc.exe [37144 2015-02-18] (Web Bar Media)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-09-15] (Microsoft Corporation)
R2 windowsmanagementservice; C:\Users\Kathy\AppData\Local\Temp\20150713\ct.exe [848384 2015-06-29] (Google Inc.) [File not signed]
R2 wssvc_1.10.0.20; C:\Program Files (x86)\WordShark_1.10.0.20\Service\wssvc.exe [300120 2015-07-06] (WS)
S2 SMUpdPlus; no ImagePath
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation)
S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.)
R1 bsdriver; C:\Windows\system32\drivers\bsdriver.sys [34712 2015-07-14] ()
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [145528 2015-06-16] (BlueStack Systems)
S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation)
S3 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation)
R1 cherimoya; C:\Windows\System32\drivers\cherimoya.sys [61336 2015-06-18] (Cherimoya Ltd)
R3 CnxtHdmiAudService; C:\Windows\System32\drivers\CHDMI64.sys [722488 2014-12-29] (Conexant Systems Inc.)
S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [32512 2012-07-24] (Etron Technology Inc)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2014-12-29] (REALiX™)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-07-28] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2015-04-02] (NetFilterSDK.com)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit)
S3 SMUpdd; no ImagePath
S1 vfbhiosb; C:\Windows\system32\drivers\vfbhiosb.sys [55168 2015-08-16] (Microsoft Corporation)
R1 wsfd_vt_1_10_0_20; C:\Windows\System32\drivers\wsfd_vt_1_10_0_20.sys [61312 2015-07-06] (WS)
R1 ywi2mzv2zhnjbdh; C:\Windows\System32\drivers\ywi2mzv2zhnjbdh.sys [50520 2015-07-13] (Windows ® Win 7 DDK provider)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-19 10:07 - 2015-08-19 10:08 - 00030994 _____ C:\Users\Kathy\Desktop\FRST.txt
2015-08-19 09:46 - 2015-08-19 10:07 - 00000000 ____D C:\FRST
2015-08-19 09:46 - 2015-08-19 09:35 - 02173440 _____ (Farbar) C:\Users\Kathy\Desktop\FRST64.exe
2015-08-16 16:50 - 2015-08-16 16:50 - 00055168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vfbhiosb.sys
2015-08-16 16:39 - 2015-08-16 16:39 - 00000000 ____D C:\Users\Kathy\AppData\Local\CEF
2015-07-28 20:31 - 2015-08-19 09:37 - 00002904 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_Kathy
2015-07-28 20:15 - 2015-07-28 20:16 - 00000000 ____D C:\Program Files (x86)\GUMBFC5.tmp
2015-07-28 20:15 - 2015-07-28 20:15 - 06420480 _____ C:\Program Files (x86)\GUTC294.tmp
2015-07-28 20:15 - 2015-07-28 20:15 - 00000010 _____ C:\Windows\TEMPcoral.vbs
2015-07-28 20:15 - 2015-07-28 20:15 - 00000000 ____D C:\ProgramData\Ninja Loader
2015-07-28 20:10 - 2015-07-28 20:42 - 00118082 _____ C:\Windows\SysWOW64\debug.log
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-19 10:08 - 2015-07-12 23:59 - 00000360 _____ C:\Windows\Tasks\CIMT_S-1-5-21-171533428-321824291-3300133993-1000.job
2015-08-19 10:05 - 2015-07-19 00:04 - 00002112 _____ C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user.job
2015-08-19 10:05 - 2015-07-12 23:56 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-08-19 10:04 - 2015-07-13 12:59 - 00000342 ____H C:\Windows\Tasks\GLQHQICXMFBVKQCB.job
2015-08-19 10:01 - 2015-07-12 23:56 - 00000968 _____ C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job
2015-08-19 09:58 - 2015-07-12 23:58 - 00003140 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.job
2015-08-19 09:57 - 2015-07-12 23:57 - 00005520 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-6.job
2015-08-19 09:55 - 2015-07-12 23:55 - 00002114 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user.job
2015-08-19 09:51 - 2014-12-20 23:49 - 02021084 _____ C:\Windows\WindowsUpdate.log
2015-08-19 09:48 - 2009-07-14 01:13 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-19 09:46 - 2015-04-20 03:00 - 00006681 _____ C:\Windows\setupact.log
2015-08-19 09:44 - 2015-01-03 14:01 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-19 09:40 - 2009-07-14 00:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-19 09:40 - 2009-07-14 00:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-19 09:39 - 2014-12-29 14:58 - 00000000 ____D C:\Program Files (x86)\IObit
2015-08-19 09:37 - 2015-01-10 14:38 - 00002860 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (SYSTEM)
2015-08-19 09:33 - 2015-07-13 13:29 - 00003254 _____ C:\Windows\System32\Tasks\Optimizer Pro Schedule
2015-08-19 09:32 - 2015-07-13 13:09 - 00002112 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user.job
2015-08-16 22:53 - 2015-07-19 00:13 - 00005862 _____ C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job
2015-08-16 22:53 - 2015-07-13 13:13 - 00003138 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.job
2015-08-16 22:53 - 2015-07-13 13:12 - 00005518 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.job
2015-08-16 22:52 - 2015-07-09 23:44 - 00000000 ____D C:\Users\Kathy\AppData\Roaming\Skype
2015-08-16 16:50 - 2015-07-13 00:01 - 00000000 ____D C:\Program Files (x86)\baidu
2015-08-16 16:46 - 2015-04-14 12:14 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-08-16 16:45 - 2015-04-14 12:14 - 00000000 ___SD C:\Windows\system32\GWX
2015-08-16 16:40 - 2015-07-12 11:01 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-08-16 16:40 - 2015-06-30 18:46 - 00000000 ____D C:\Program Files (x86)\Steam
2015-08-16 16:40 - 2015-06-30 18:16 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2015-08-16 16:39 - 2015-07-19 00:04 - 00000000 ____D C:\Program Files (x86)\ORBTR
2015-08-16 16:39 - 2015-07-14 14:16 - 00004704 _____ C:\Windows\SysWOW64\Cofvopjy.ini
2015-08-16 16:39 - 2015-07-14 14:16 - 00002416 _____ C:\Windows\SysWOW64\CofvopjyOff.ini
2015-08-16 16:39 - 2015-07-14 14:16 - 00002416 _____ C:\Windows\system32\CofvopjyOff.ini
2015-08-16 16:37 - 2015-07-13 00:01 - 00000000 ____D C:\Users\Kathy\AppData\Local\ospd_us_014010029
2015-08-16 16:36 - 2015-07-13 12:15 - 00000000 ____D C:\Users\Kathy\AppData\Local\mstrn32
2015-08-16 16:34 - 2015-07-13 13:15 - 00000996 _____ C:\Windows\Tasks\WdEL9n2eiowr.job
2015-08-16 16:34 - 2015-07-12 23:59 - 00000986 _____ C:\Windows\Tasks\FYLVp79.job
2015-08-16 16:33 - 2015-07-19 00:13 - 00005518 _____ C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7.job
2015-08-16 16:33 - 2015-07-19 00:07 - 00004494 _____ C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3.job
2015-08-16 16:33 - 2015-07-13 13:15 - 00002446 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user.job
2015-08-16 16:33 - 2015-07-13 13:14 - 00002446 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.job
2015-08-16 16:33 - 2015-07-13 13:13 - 00003474 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7.job
2015-08-16 16:33 - 2015-07-13 13:12 - 00005518 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7.job
2015-08-16 16:33 - 2015-07-13 13:10 - 00004494 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3.job
2015-08-16 16:33 - 2015-07-13 13:07 - 00001056 _____ C:\Windows\Tasks\Crossbrowse.job
2015-08-16 16:33 - 2015-07-12 23:59 - 00002448 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user.job
2015-08-16 16:33 - 2015-07-12 23:59 - 00002448 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5.job
2015-08-16 16:33 - 2015-07-12 23:58 - 00003476 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7.job
2015-08-16 16:33 - 2015-07-12 23:57 - 00005184 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-7.job
2015-08-16 16:33 - 2015-07-12 23:56 - 00004496 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-3.job
2015-08-16 16:33 - 2015-07-12 23:56 - 00000970 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-08-16 16:33 - 2015-07-12 23:56 - 00000964 _____ C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job
2015-08-16 16:33 - 2015-07-12 23:55 - 00000342 ____H C:\Windows\Tasks\JWRTYVMXFBIVCPWL.job
2015-08-16 16:33 - 2015-07-12 23:55 - 00000336 _____ C:\Windows\Tasks\NLSAGZR1.job
2015-08-16 16:33 - 2014-12-29 14:56 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-16 16:32 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-16 16:30 - 2015-06-30 18:16 - 00000000 ____D C:\Program Files (x86)\BlueStacks
2015-07-28 20:42 - 2014-12-29 15:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
2015-07-28 20:22 - 2015-07-13 16:29 - 00003444 _____ C:\Windows\System32\Tasks\Epuifuuva
2015-07-28 20:15 - 2015-07-13 12:08 - 00000000 ____D C:\Users\Kathy\AppData\Local\Ninja Loader
2015-07-28 20:15 - 2015-01-18 22:58 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-28 20:15 - 2014-12-29 14:58 - 00000000 ____D C:\ProgramData\IObit
2015-07-28 20:12 - 2014-12-29 14:58 - 00000000 ____D C:\ProgramData\ProductData
2015-07-28 20:08 - 2015-07-19 00:16 - 00005086 _____ C:\Windows\Tasks\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job
2015-07-28 20:05 - 2015-04-20 03:00 - 00552878 _____ C:\Windows\PFRO.log
 
==================== Files in the root of some directories =======
 
2015-07-28 20:15 - 2015-07-28 20:15 - 6420480 _____ () C:\Program Files (x86)\GUTC294.tmp
2015-07-18 21:58 - 2015-07-18 21:58 - 6420480 _____ () C:\Program Files (x86)\GUTFD53.tmp
2015-04-19 08:20 - 2015-04-19 08:20 - 0005872 _____ () C:\Users\Kathy\AppData\Roaming\FYLVp79
2015-04-20 10:05 - 2015-04-20 10:05 - 1579520 _____ () C:\Users\Kathy\AppData\Roaming\FYLVp79.exe
2015-04-19 08:20 - 2015-04-19 08:20 - 0005872 _____ () C:\Users\Kathy\AppData\Roaming\WdEL9n2eiowr
2015-04-20 10:05 - 2015-04-20 10:05 - 1579520 _____ () C:\Users\Kathy\AppData\Roaming\WdEL9n2eiowr.exe
2015-07-13 13:52 - 2015-07-13 13:52 - 0613255 _____ (CMI Limited) C:\Users\Kathy\AppData\Local\nsiBAD8.tmp
2015-01-03 14:00 - 2015-01-03 14:00 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
Some files in TEMP:
====================
C:\Users\Kathy\AppData\Local\Temp\2147.exe
C:\Users\Kathy\AppData\Local\Temp\2707.exe
C:\Users\Kathy\AppData\Local\Temp\3087.exe
C:\Users\Kathy\AppData\Local\Temp\6380.exe
C:\Users\Kathy\AppData\Local\Temp\879.exe
C:\Users\Kathy\AppData\Local\Temp\9474.exe
C:\Users\Kathy\AppData\Local\Temp\9984.exe
C:\Users\Kathy\AppData\Local\Temp\avg3D5E.exe
C:\Users\Kathy\AppData\Local\Temp\bitool.dll
C:\Users\Kathy\AppData\Local\Temp\ConsumerInputSetup.exe
C:\Users\Kathy\AppData\Local\Temp\Cracked Steam__10924_i1556117268_il1622702.exe
C:\Users\Kathy\AppData\Local\Temp\Cracked Steam__10924_i1556117269_il1622702.exe
C:\Users\Kathy\AppData\Local\Temp\fsdD549.exe
C:\Users\Kathy\AppData\Local\Temp\[email protected]
C:\Users\Kathy\AppData\Local\Temp\Launcher__13202.exe
C:\Users\Kathy\AppData\Local\Temp\links.exe
C:\Users\Kathy\AppData\Local\Temp\mVO9C0.exe
C:\Users\Kathy\AppData\Local\Temp\mVOE791.exe
C:\Users\Kathy\AppData\Local\Temp\MYPCBU.exe
C:\Users\Kathy\AppData\Local\Temp\oprun23877.exe
C:\Users\Kathy\AppData\Local\Temp\qqpcmgr_v10.10.16434.218_72819_Silence.exe
C:\Users\Kathy\AppData\Local\Temp\Search_Protect_NonSearch_setup.exe
C:\Users\Kathy\AppData\Local\Temp\setup.exe
C:\Users\Kathy\AppData\Local\Temp\setup3.exe
C:\Users\Kathy\AppData\Local\Temp\setup_644.exe
C:\Users\Kathy\AppData\Local\Temp\SpOrder.dll
C:\Users\Kathy\AppData\Local\Temp\supoptsetup.exe
C:\Users\Kathy\AppData\Local\Temp\Uninstall.exe
C:\Users\Kathy\AppData\Local\Temp\uobnyv04ydl6.exe
C:\Users\Kathy\AppData\Local\Temp\updatetask.exe
C:\Users\Kathy\AppData\Local\Temp\vau3696.tmp.exe
C:\Users\Kathy\AppData\Local\Temp\ytb.exe
C:\Users\Kathy\AppData\Local\Temp\{F03E597C-5045-41C0-A02A-C5994E53D89F}-GoogleUpdateSetup.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-07-03 19:53
 
==================== End of log ============================
 
Addition

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:17-08-2015
Ran by Kathy (2015-08-19 10:09:11)
Running from C:\Users\Kathy\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-171533428-321824291-3300133993-500 - Administrator - Disabled)
Guest (S-1-5-21-171533428-321824291-3300133993-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-171533428-321824291-3300133993-1002 - Limited - Enabled)
Kathy (S-1-5-21-171533428-321824291-3300133993-1000 - Administrator - Enabled) => C:\Users\Kathy
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: IObit Malware Fighter (Disabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.1.3.121 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.134 - Adobe Systems Incorporated)
AdVenture Capitalist (HKLM-x32\...\Steam App 346900) (Version:  - Hyper Hippo Games)
AnySend (HKLM-x32\...\ASPackage) (Version: 1.0.0.0 - CMI Limited) <==== ATTENTION
Blender (HKLM-x32\...\{69FE4B50-CA11-498A-9E9F-830B32AFE32C}) (Version: 2.75.0 - Blender Foundation)
BlueStacks Notification Center (HKLM-x32\...\{3792811C-832F-4392-B44A-24092901EDDC}) (Version: 0.9.30.9239 - BlueStack Systems, Inc.)
Blur Megabyte (HKLM-x32\...\ConvertAd) (Version: 1.0.0.0 - Blur Megabyte) <==== ATTENTION
CinemaPlus-3.2cV13.07 (HKLM-x32\...\CinemaPlus-3.2cV13.07) (Version: 1.36.01.22 - Cinema PlusV13.07) <==== ATTENTION
CinemaPlus-3.2cV18.07 (HKLM-x32\...\CinemaPlus-3.2cV18.07) (Version: 1.36.01.22 - Cinema PlusV18.07) <==== ATTENTION
Conexant Audio Driver For AMD HDMI Codec (HKLM\...\CNXT_AUDIO_HDA_HDMI) (Version: 4.98.32.0 - Conexant)
Consumer Input (remove only) (HKLM-x32\...\Consumer Input Installer) (Version:  - Compete Inc.) <==== ATTENTION
Coupoon version 1.0 (HKLM-x32\...\{49F8B4F8-0CD4-4BE4-A9E8-B13A071F7C90}_is1) (Version: 1.0 - Coupoon) <==== ATTENTION
Driver Booster 2.1 (HKLM-x32\...\Driver Booster_is1) (Version: 2.1 - IObit)
EpsanDrive (HKLM-x32\...\EpsanDrive) (Version:  - )
Etherium (HKLM-x32\...\Steam App 245370) (Version:  - Tindalos Interactive)
FinanceAlert (HKLM-x32\...\FinanceAlert) (Version: 3.0.69 - Valid Applications)
FlashBeat (HKLM-x32\...\FlashBeat) (Version:  - ) <==== ATTENTION
Free Up Expand (HKLM-x32\...\wincheck) (Version: 1.0.0.0 - Free Up Expand) <==== ATTENTION
GamesDesktop 025.005010030 (HKLM-x32\...\gmsd_us_005010030_is1) (Version:  - GAMESDESKTOP) <==== ATTENTION
GamesDesktop 025.005010031 (HKLM-x32\...\gmsd_us_005010031_is1) (Version:  - GAMESDESKTOP) <==== ATTENTION
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.132 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Hades (HKLM-x32\...\Hades) (Version: 2.07.13.0 - Hades)
HQCinema Pro 2.1V12.07 (HKLM-x32\...\HQCinema Pro 2.1V12.07) (Version: 1.36.01.22 - HQ-VideoV12.07) <==== ATTENTION
Iminent (HKLM-x32\...\IMBoosterARP) (Version: 7.48.4.1 - Iminent) <==== ATTENTION
IminentToolbar (HKLM-x32\...\IminentToolbar) (Version: 7.48.4.1 - Iminent) <==== ATTENTION
IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 4.3.0.5 - IObit)
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
KNCTR (HKLM-x32\...\Itibiti_is1) (Version:  - Itibiti Inc.)
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft IntelliPoint 8.2 (HKLM\...\Microsoft IntelliPoint 8.2) (Version: 8.20.468.0 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Minecraft 1.8 1.00 (HKLM-x32\...\Minecraft 1.8 1.00) (Version:  - )
MovieDea 1.0 (HKLM-x32\...\MovieDea) (Version: 1.0 - MovieDea)
MyPCBU version 2.25 (HKLM-x32\...\{7D7D6742-5B49-4454-9E9B-748E731E741A}_is1) (Version: 2.25 - )
Ninja Loader (HKLM-x32\...\Ninja Loader) (Version: 187.0.0.605 - CLICK YES BELOW LP)
OneSoftPerDay 025.014010029 (HKLM-x32\...\ospd_us_014010029_is1) (Version:  - ONESOFTPERDAY)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version:  - )
Optimizer Pro v3.2 (HKLM-x32\...\Optimizer Pro_is1) (Version: 3.3.1.7 - PCUtilities Software Limited) <==== ATTENTION
Peggle Deluxe 1.0 (HKLM-x32\...\Peggle Deluxe 1.0) (Version:  - )
Pro PC Cleaner (HKLM-x32\...\Pro PC Cleaner) (Version: 2.9.6 - Pro PC Cleaner) <==== ATTENTION
RadPlayer (HKLM-x32\...\RadPlayer) (Version: 4.0.1 - RadPlayer)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7373 - Realtek Semiconductor Corp.)
s5mark (HKLM-x32\...\s5mark) (Version: 2.0.2 - s5mark)
Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.23.60.24 - Client Connect LTD) <==== ATTENTION
Setup (HKLM-x32\...\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}) (Version:  - )
shopperz12072015 2.0.0.471 (HKLM\...\{c49ac435-5c4d-450f-aa56-cd31f96613b3}_is1) (Version: 2.0.0.471 - shopperz) <==== ATTENTION
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
Skype™ 7.6 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.6.105 - Skype Technologies S.A.)
Smart Defrag 4 (HKLM-x32\...\Smart Defrag 4_is1) (Version: 4.1 - IObit)
SmartWeb (HKLM-x32\...\SmartWeb) (Version: 8.0.9 - SoftBrain Technologies Ltd.) <==== ATTENTION
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
StormWatch (HKLM-x32\...\StormWatch) (Version: 1.0.2.55 - StormWatch) <==== ATTENTION
Surfing Protection (HKLM-x32\...\IObit Surfing Protection_is1) (Version: 1.2 - IObit)
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version:  - Valve)
TeamSpeak 3 Client (HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Unity Web Player (HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\UnityWebPlayer) (Version: 4.6.1f1 - Unity Technologies ApS)
Wajam (HKLM-x32\...\WajIEn) (Version: 1.48.1.30 (i1.0) - Wajam) <==== ATTENTION
Web Bar 2.0.5527.25142 (HKLM\...\{0BCE8B0A-1E76-44E5-9909-3CF804D92E4D}_is1) (Version: 2.0.5527.25142 - Web Bar Media) <==== ATTENTION
WordShark 1.10.0.20 (HKLM-x32\...\WordShark_1.10.0.20) (Version: 1.10.0.20 - WordShark) <==== ATTENTION
Yahoo Search Set (HKLM-x32\...\Yahoo! SearchSet) (Version:  - Yahoo Inc.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-171533428-321824291-3300133993-1000_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
 
==================== Restore Points =========================
 
20-12-2014 20:58:59 Windows Update
29-12-2014 14:54:52 Windows Update
29-12-2014 15:18:35 Driver Booster : ATI I/O Communications Processor SMBus Controller
29-12-2014 15:30:41 Windows Update
29-12-2014 15:40:24 avast! antivirus system restore point
02-01-2015 14:11:56 Windows Update
03-01-2015 12:58:20 Windows Update
03-01-2015 13:55:40 Driver Booster : ATI Mobility Radeon HD 4200
03-01-2015 14:01:52 Installed DirectX
03-01-2015 14:04:54 Installed DirectX
03-01-2015 15:23:04 Windows Update
06-01-2015 19:11:47 Windows Update
06-01-2015 19:17:20 Driver Booster : Standard Enhanced PCI to USB Host Controller
06-01-2015 22:54:53 Windows Update
10-01-2015 13:28:22 Windows Update
10-01-2015 18:49:20 Windows Modules Installer
10-01-2015 18:50:25 Windows Modules Installer
13-01-2015 22:52:49 Windows Update
13-01-2015 22:59:53 Windows Update
17-01-2015 00:03:55 Windows Update
20-01-2015 12:56:59 Windows Update
29-01-2015 11:58:47 Windows Update
01-02-2015 23:43:04 Windows Update
14-02-2015 16:18:57 Windows Update
18-02-2015 11:44:39 Windows Update
04-03-2015 00:24:41 Windows Update
04-03-2015 02:19:43 Windows Update
26-03-2015 17:04:54 Windows Update
26-03-2015 18:18:31 Windows Update
26-03-2015 21:34:16 Driver Booster : Microsoft USB Wheel Mouse Optical
27-03-2015 08:46:30 Windows Update
10-04-2015 17:25:05 Windows Update
14-04-2015 11:25:39 Windows Update
19-04-2015 22:49:10 Windows Update
20-04-2015 01:38:58 avast! antivirus system restore point
20-04-2015 02:35:11 Windows Update
02-05-2015 14:41:02 Windows Update
07-05-2015 11:42:49 Windows Update
19-05-2015 16:18:36 Windows Update
05-06-2015 09:25:54 Windows Update
16-06-2015 08:59:39 Windows Update
25-06-2015 14:46:09 Windows Update
26-06-2015 21:54:42 Windows Update
02-07-2015 11:44:52 Windows Update
06-07-2015 12:33:56 Windows Update
07-07-2015 18:32:29 Installed Blender
10-07-2015 12:20:24 Windows Update
11-07-2015 21:29:57 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
11-07-2015 21:30:39 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
12-07-2015 10:55:13 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
12-07-2015 10:57:03 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
13-07-2015 00:11:07 Windows Update
16-08-2015 16:42:10 Windows Update
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2009-06-10 17:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {01A22A0D-37F6-4D85-A408-491ACA67BF31} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-6 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-6.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {02956738-DE99-47D8-A6C6-DCEE22EE7C4B} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {0473C0CA-9A3F-462C-9BB2-BB768544A91A} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-3 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-3.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {0C67CC53-4D97-46D6-A447-A0C70698D63C} - System32\Tasks\WebBarUpdateTask => C:\Program Files\WebBar\wbsvc.exe [2015-02-18] (Web Bar Media) <==== ATTENTION
Task: {12826CD3-979A-4778-9E55-62298738037F} - System32\Tasks\WdEL9n2eiowr => C:\Users\Kathy\AppData\Roaming\WdEL9n2eiowr.exe [2015-04-20] () <==== ATTENTION
Task: {13C77BBA-4D9D-4CC4-9783-0F09749EBC89} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {168DBC36-AAF6-4F39-8483-52C63048B4FE} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {1BEAFD01-BB2F-4D5D-A4CB-F3456C100409} - System32\Tasks\ConsumerInputUpdateTaskMachineUA => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [2015-07-12] (ConsumerInput) <==== ATTENTION
Task: {1D2B5213-0A0B-4933-8409-5B6CCA9D31C4} - System32\Tasks\SMW_UpdateTask_Time_333833393739363037312d235b783432415b45345a2d6c => Wscript.exe //B "C:\ProgramData\SearchModulePlus\smhe.js" smu.exe /invoke /f:check_services /l:0 <==== ATTENTION
Task: {1EC32D4B-9503-4E11-9581-F33F5490D6C8} - System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10.exe [2015-07-19] (Cinema PlusV18.07) <==== ATTENTION
Task: {25FCAB52-144F-4DF6-9ED8-A783CF9663E3} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {26C1D14B-D736-4340-AA04-29E5B0EE9912} - System32\Tasks\CIMT_S-1-5-21-171533428-321824291-3300133993-1000 => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe [2015-06-19] () <==== ATTENTION
Task: {2C86BA2E-43EA-43C1-9CC7-DC321BFFF485} - System32\Tasks\Snmix => C:\Program Files\shopperz12072015\Ubehsi.bat [2015-07-13] () <==== ATTENTION
Task: {325746AD-5A6F-430F-8E30-6CD44422ABDB} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {36F19701-E5F7-4483-856F-F95E73176541} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {3C325D05-59F7-4AA8-A14C-0D30C25CACC4} - System32\Tasks\Driver Booster SkipUAC (SYSTEM) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2015-07-06] (IObit)
Task: {41F7B16E-395A-4581-81BD-04F429088AC9} - System32\Tasks\Driver Booster SkipUAC (Kathy) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2015-07-06] (IObit)
Task: {423821BC-96E6-4D84-9341-34C7D6544576} - System32\Tasks\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6 => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.exe [2015-07-19] (Cinema PlusV18.07) <==== ATTENTION
Task: {4315E182-2227-4C77-880F-D8ED0781664D} - System32\Tasks\NLSAGZR1 => C:\ProgramData\EpsanDrive\EpsanDrive.exe [2015-07-08] (EpsanDrive) <==== ATTENTION
Task: {46EEB3FE-4979-4D71-B642-E6812F1A1B63} - System32\Tasks\SMWPUpd => C:\Program Files\Common Files\Goobzo\GBUpdatePlus\updater.exe <==== ATTENTION
Task: {4F7AA969-E2FB-46AC-A550-70B132457A08} - System32\Tasks\Smp => C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smp.exe <==== ATTENTION
Task: {519D5601-B701-4EF4-942D-023EB0776066} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files (x86)\Optimizer Pro 3.99\OptProLauncher.exe [2015-07-03] () <==== ATTENTION
Task: {536F625C-BFB1-4834-BC2B-BD6198974A9E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-29] (Google Inc.)
Task: {58BC472B-603B-41F5-A0F2-3D4FBD8E8B49} - System32\Tasks\WebBarLaunchTask => C:\Program Files\WebBar\wbsvc.exe [2015-02-18] (Web Bar Media) <==== ATTENTION
Task: {5AE88653-7D39-4018-A2D6-1B1865993C94} - System32\Tasks\BD634EFB-4435-4228-B1B1-B9F4709D5F79 => C:\Users\Kathy\AppData\Local\BD634EFB-4435-4228-B1B1-B9F4709D5F79\BD634EFB-4435-4228-B1B1-B9F4709D5F79.exe [2015-07-18] () <==== ATTENTION
Task: {5B84AF85-C877-4407-9B54-51E465C67CD3} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {5BAFB821-7E9C-44DA-8FF3-BA06AA1A580A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-26] (Adobe Systems Incorporated)
Task: {5D16852C-3009-4836-B678-96DD5F24BE7B} - System32\Tasks\ConsumerInputUpdateTaskMachineCore => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [2015-07-12] (ConsumerInput) <==== ATTENTION
Task: {610A4D52-9E85-4E0B-A680-BEA500D4EF11} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-29] (Google Inc.)
Task: {691E87A2-9D64-45C3-A667-ABE98310143F} - System32\Tasks\GLQHQICXMFBVKQCB => C:\ProgramData\Service1291\Service1291.exe [2015-06-28] () <==== ATTENTION
Task: {6F7B2104-C5A2-4870-8DAA-94359F4B295E} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {80ECF25B-E055-4C3B-B841-3F10B6413105} - System32\Tasks\Crossbrowse => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION
Task: {83886EC4-445C-4DB0-9EB6-83B465472564} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-5.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {88726888-5908-4FB8-A3FA-9043CB5B1478} - System32\Tasks\WordShark Auto Updater 1.10.0.20 Core => C:\Program Files (x86)\WordShark_1.10.0.20\Update\WordSharkAutoUpdateClient.exe [2015-07-06] (WS) <==== ATTENTION
Task: {8C648E3B-AA13-45C1-832C-77C99013C7F4} - System32\Tasks\ProPCCleaner_Start => C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe [2015-07-09] (Pro PC Cleaner) <==== ATTENTION
Task: {8D2D9211-2FB9-4C3E-AB7B-548D36C48621} - System32\Tasks\Epuifuuva => C:\ProgramData\Epuifuuva\1.0.4.1\allomlom.exe [2015-07-13] ()
Task: {8E797C65-1C95-4E33-BD35-2B67CFA422CC} - System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6 => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.exe [2015-07-19] (Cinema PlusV18.07) <==== ATTENTION
Task: {8F31C890-7EC5-49DE-B3B9-7476E1ADAD00} - System32\Tasks\CIMT_daily_S-1-5-21-171533428-321824291-3300133993-1000 => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe [2015-06-19] () <==== ATTENTION
Task: {8FCE26CD-8109-40D2-84C9-EC4D6052F068} - System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3 => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3.exe [2015-07-19] (Cinema PlusV18.07) <==== ATTENTION
Task: {9A4092C6-EB94-4323-A130-EEA16B56DCD3} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-07-19] (globalUpdate) <==== ATTENTION
Task: {9A6CF26F-A597-49B7-8D92-A65B8241C305} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-10.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {9C38A35C-5BD6-4388-BC91-FED16EF2B1F4} - System32\Tasks\Games\UpdateCheck_S-1-5-21-171533428-321824291-3300133993-1000
Task: {9DC79A38-C865-43F3-9280-76CE0AC74000} - System32\Tasks\Uninstaller_SkipUac_Kathy => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2015-05-20] (IObit)
Task: {ACC2C1A7-672C-479B-91FF-EB6428145187} - System32\Tasks\SushiLeads => C:\Program Files (x86)\sushileads\ScheduledTask.exe
Task: {B3E4C79F-31B0-4CEC-8855-3A125AFCA943} - System32\Tasks\FYLVp79 => C:\Users\Kathy\AppData\Roaming\FYLVp79.exe [2015-04-20] () <==== ATTENTION
Task: {B50E6BBF-9E5C-4375-A579-BA67BBBB3632} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {BEFA25DD-72D7-4DCD-A9B5-609E7D25109A} - System32\Tasks\WordShark Auto Updater 1.10.0.20 Pending Update => C:\Program Files (x86)\WordShark_1.10.0.20\Update\WordSharkAutoUpdateClient.exe [2015-07-06] (WS) <==== ATTENTION
Task: {BFD5E5F7-A581-4986-AA96-C25F1196ED50} - System32\Tasks\JWRTYVMXFBIVCPWL => C:\ProgramData\Service1198\Service1198.exe [2015-06-28] () <==== ATTENTION
Task: {CC0931E2-8841-4E30-A9AC-B3C127345ED4} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2014-12-17] (IObit)
Task: {CD043251-2487-4869-A33C-C07A835E7188} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {CF6E7CAA-8B5F-4C52-A529-903EEF71BD58} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {D0A3F695-CFF9-4D08-A2A2-A4FC09D36290} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-5.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {D17B14BD-B3E2-4FD2-AFBE-644A6A3B1782} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [2014-12-09] (IObit)
Task: {D67D6154-0544-43C0-A94B-02B9B1A17E7C} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {E95208D8-3FF8-4D59-AFCB-CDC5937532DF} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-7 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-7.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {E9AADAD9-F283-4AA1-9839-E55321CC24D3} - System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7 => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7.exe [2015-07-19] (Cinema PlusV18.07) <==== ATTENTION
Task: {F4309D18-BE10-4EE4-A49A-13DC9F49921B} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {F48924F7-2B13-4189-BEFC-7813745D4972} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-07-19] (globalUpdate) <==== ATTENTION
Task: {F60157AF-D870-485B-87FD-5F992DA7ACD1} - System32\Tasks\GlobalUpdate-ywy2yzvxzgtjbth => C:\Users\Kathy\AppData\Roaming\ywy2yzvxzgtjbth\ywy2yzvxzgtjbth.exe [2015-07-13] () <==== ATTENTION
Task: {F6838031-AB36-4284-9FC7-8677F4B77864} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => c:\Program Files\Microsoft IntelliPoint\IPoint.exe [2011-08-01] (Microsoft Corporation)
Task: {F93A1729-BC6D-42A0-888E-D2BEB8D08BA5} - System32\Tasks\avastBCLRestartS-1-5-21-171533428-321824291-3300133993-1000 => Chrome.exe 
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user.job => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10.exe <==== ATTENTION
Task: C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3.job => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7.job => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-10.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-3.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-6.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-7.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\CIMT_daily_S-1-5-21-171533428-321824291-3300133993-1000.job => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
Task: C:\Windows\Tasks\CIMT_S-1-5-21-171533428-321824291-3300133993-1000.job => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\Crossbrowse.job => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION
Task: C:\Windows\Tasks\FYLVp79.job => C:\Users\Kathy\AppData\Roaming\FYLVp79.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GLQHQICXMFBVKQCB.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\JWRTYVMXFBIVCPWL.job => C:\ProgramData\Service1198\Service1198.exe <==== ATTENTION
Task: C:\Windows\Tasks\NLSAGZR1.job => C:\ProgramData\EpsanDrive\EpsanDrive.exe <==== ATTENTION
Task: C:\Windows\Tasks\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\WdEL9n2eiowr.job => C:\Users\Kathy\AppData\Roaming\WdEL9n2eiowr.exe <==== ATTENTION
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-07-14 14:12 - 2015-07-13 14:24 - 00297832 _____ () C:\Program Files\shopperz12072015\Falhnzsy64.DLL
2015-06-13 14:17 - 2015-06-13 14:17 - 00803488 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
2015-07-14 14:12 - 2015-07-13 14:24 - 00285544 _____ () C:\Program Files\shopperz12072015\Igivkorcb.exe
2015-07-14 14:12 - 2015-07-13 14:24 - 00433512 _____ () C:\Program Files\shopperz12072015\Bzvra.exe
2015-07-14 14:12 - 2015-07-13 14:24 - 00464744 _____ () C:\Program Files\shopperz12072015\Bzvra64.exe
2015-07-14 14:12 - 2015-07-13 14:24 - 00631144 _____ () C:\Program Files\shopperz12072015\Ekehe64.DLL
2015-07-14 14:12 - 2015-07-13 14:25 - 00277864 _____ () C:\Program Files\shopperz12072015\Znjiay64.DLL
2015-07-14 14:12 - 2015-07-13 14:25 - 00337256 _____ () C:\Program Files\shopperz12072015\Moieoae64.DLL
2015-07-13 00:01 - 2015-07-12 15:48 - 03287696 _____ () C:\Users\Kathy\AppData\Local\ospd_us_014010029\upospd_us_014010029.exe
2015-06-19 12:41 - 2015-06-19 12:41 - 01250848 _____ () C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe
2015-04-10 09:49 - 2015-04-10 09:49 - 01556504 _____ () C:\Program Files (x86)\StormWatch\StormWatchApp.exe
2015-06-28 12:11 - 2015-06-28 12:11 - 01221120 _____ () C:\Program Files (x86)\msrtn32\msrtn32.exe
2015-07-13 13:10 - 2015-07-13 05:30 - 03986064 _____ () C:\Program Files (x86)\gmsd_us_005010030\gmsd_us_005010030.exe
2015-07-13 00:34 - 2015-07-13 00:34 - 02422272 _____ () C:\Program Files (x86)\Smwyyntm1ndi1zdz\ywi2mzv2zhnjbdh.exe
2015-07-14 14:22 - 2015-07-14 08:23 - 03985552 _____ () C:\Program Files (x86)\gmsd_us_005010031\gmsd_us_005010031.exe
2015-07-14 14:12 - 2015-07-13 14:24 - 01448808 _____ () C:\Program Files\shopperz12072015\csrcc.exe
2015-06-29 19:00 - 2015-06-29 19:00 - 00077824 _____ () C:\Program Files (x86)\dataup\dataup.exe
2015-07-13 07:13 - 2015-07-13 07:13 - 00171920 _____ () C:\Program Files\shopperz12072015\ZazyjiKotn.exe
2015-06-28 12:11 - 2015-06-28 12:11 - 00825856 _____ () C:\Program Files (x86)\msrtn32\cdhtr.exe
2015-07-13 00:06 - 2015-07-13 00:06 - 00219136 _____ () C:\Users\Kathy\AppData\Local\5670549A-1436745948-DE00-E918-1C7508113231\cnsh175B.tmp
2015-07-13 00:03 - 2015-07-13 00:03 - 00183808 _____ () C:\Users\Kathy\AppData\Roaming\ASPackage\ASSrv.exe
2015-07-14 14:12 - 2015-07-13 14:24 - 00174952 _____ () C:\Program Files\shopperz12072015\Xzeexmh.exe
2015-04-10 09:49 - 2015-04-10 09:49 - 00586264 _____ () C:\Program Files (x86)\StormWatch\StormWatchSrv.exe
2015-04-07 10:12 - 2015-04-07 10:12 - 00404480 _____ () C:\ProgramData\1436760085\s9.exe
2015-07-12 23:53 - 2015-07-12 23:54 - 00053040 _____ () C:\Program Files (x86)\Coupoon\UpdateCheck.exe
2015-07-13 06:18 - 2015-07-13 06:18 - 01997824 _____ () C:\Program Files\WajIEn\wajam_64.exe
2015-07-13 06:15 - 2015-07-13 06:15 - 01610240 _____ () C:\Program Files\WajIEn\wajam.exe
2015-08-16 16:38 - 2015-08-16 16:38 - 01422336 _____ () C:\Program Files\WajIEn\dlls\crusc.dll
2015-07-12 10:52 - 2015-07-12 10:52 - 31404192 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
2015-07-13 07:13 - 2015-07-13 07:13 - 02020864 _____ () C:\Program Files\shopperz12072015\Cofvopjy.exe
2015-06-25 08:50 - 2015-06-25 08:50 - 02248192 _____ () C:\Users\Kathy\AppData\Local\5670549A-1436745948-DE00-E918-1C7508113231\ansh1316.exe
2015-07-14 14:12 - 2015-07-13 14:24 - 00291688 _____ () C:\Program Files\shopperz12072015\Falhnzsy.DLL
2015-07-14 14:12 - 2015-07-13 14:24 - 00620392 _____ () C:\Program Files\shopperz12072015\Ekehe.DLL
2015-07-14 14:12 - 2015-07-13 14:25 - 00243560 _____ () C:\Program Files\shopperz12072015\Znjiay.DLL
2015-07-14 14:12 - 2015-07-13 14:24 - 00312168 _____ () C:\Program Files\shopperz12072015\Moieoae.DLL
2015-08-16 16:34 - 2015-08-16 16:34 - 00011264 _____ () C:\Users\Kathy\AppData\Local\Temp\nswCD10.tmp\System.dll
2015-08-16 16:34 - 2015-08-16 16:34 - 00091136 _____ () C:\Users\Kathy\AppData\Local\Temp\nswCD10.tmp\base64.dll
2015-08-16 16:34 - 2015-08-16 16:34 - 00004096 _____ () C:\Users\Kathy\AppData\Local\Temp\nswCD10.tmp\ThreadTimer.dll
2015-08-16 16:34 - 2015-08-16 16:34 - 00020992 _____ () C:\Users\Kathy\AppData\Local\Temp\nswCD10.tmp\inetc.dll
2015-06-09 22:36 - 2015-06-09 22:36 - 36732592 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\libcef.dll
2014-10-12 00:26 - 2014-10-12 00:26 - 02299904 _____ () C:\Program Files (x86)\msrtn32\QxOrm.dll
2013-09-24 12:38 - 2013-09-24 12:38 - 00243200 _____ () C:\Program Files (x86)\msrtn32\boost_serialization-vc100-mt-1_54.dll
2014-10-13 19:34 - 2014-10-13 19:34 - 00879104 _____ () C:\Program Files (x86)\msrtn32\platforms\qwindows.dll
2015-07-02 09:45 - 2015-07-02 09:45 - 00109160 _____ () C:\Program Files (x86)\Ninja Loader\Modules\Core.dll
2014-10-14 00:31 - 2014-10-14 00:31 - 00032256 _____ () C:\Program Files (x86)\msrtn32\imageformats\qdds.dll
2014-10-13 19:32 - 2014-10-13 19:32 - 00021504 _____ () C:\Program Files (x86)\msrtn32\imageformats\qgif.dll
2014-10-14 00:31 - 2014-10-14 00:31 - 00027648 _____ () C:\Program Files (x86)\msrtn32\imageformats\qicns.dll
2014-10-13 19:32 - 2014-10-13 19:32 - 00021504 _____ () C:\Program Files (x86)\msrtn32\imageformats\qico.dll
2014-10-14 00:31 - 2014-10-14 00:31 - 00381952 _____ () C:\Program Files (x86)\msrtn32\imageformats\qjp2.dll
2014-10-13 19:31 - 2014-10-13 19:31 - 00204800 _____ () C:\Program Files (x86)\msrtn32\imageformats\qjpeg.dll
2014-10-14 00:31 - 2014-10-14 00:31 - 00218112 _____ () C:\Program Files (x86)\msrtn32\imageformats\qmng.dll
2014-10-14 00:31 - 2014-10-14 00:31 - 00015360 _____ () C:\Program Files (x86)\msrtn32\imageformats\qtga.dll
2014-10-14 00:32 - 2014-10-14 00:32 - 00307712 _____ () C:\Program Files (x86)\msrtn32\imageformats\qtiff.dll
2014-10-14 00:32 - 2014-10-14 00:32 - 00014848 _____ () C:\Program Files (x86)\msrtn32\imageformats\qwbmp.dll
2014-10-14 00:32 - 2014-10-14 00:32 - 00252928 _____ () C:\Program Files (x86)\msrtn32\imageformats\qwebp.dll
2015-07-02 09:45 - 2015-07-02 09:45 - 00039528 _____ () C:\Program Files (x86)\Ninja Loader\Modules\ArSp.dll
2015-07-02 09:45 - 2015-07-02 09:45 - 00118376 _____ () C:\Program Files (x86)\Ninja Loader\Modules\BrSp.dll
2015-07-02 09:45 - 2015-07-02 09:45 - 00092776 _____ () C:\Program Files (x86)\Ninja Loader\Modules\CdPrc.dll
2015-07-02 09:44 - 2015-07-02 09:44 - 00041576 _____ () C:\Program Files (x86)\Ninja Loader\Modules\WInIn.dll
2015-07-02 09:44 - 2015-07-02 09:44 - 00096872 _____ () C:\Program Files (x86)\Ninja Loader\Modules\WbSt.dll
2015-07-02 09:44 - 2015-07-02 09:44 - 00056424 _____ () C:\Program Files (x86)\Ninja Loader\Modules\WdCtl.dll
2015-07-02 09:45 - 2015-07-02 09:45 - 00058984 _____ () C:\Program Files (x86)\Ninja Loader\Modules\BdUdr.dll
2015-07-18 21:58 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl
2015-07-18 21:58 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl
2015-07-18 21:58 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl
2015-08-16 16:38 - 2015-08-16 16:38 - 01220608 _____ () C:\Program Files\WajIEn\dlls\ulkty.dll
2015-06-30 18:47 - 2015-07-03 12:12 - 00778240 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2015-06-30 18:47 - 2015-07-03 12:12 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll
2015-06-30 18:47 - 2015-07-03 12:12 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2015-06-30 18:47 - 2015-07-03 12:12 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2015-06-30 18:47 - 2015-07-23 19:24 - 02410176 _____ () C:\Program Files (x86)\Steam\video.dll
2015-06-30 18:47 - 2014-12-01 17:31 - 02396672 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2015-06-30 18:47 - 2014-12-01 17:31 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2015-06-30 18:47 - 2014-12-01 17:31 - 00479744 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2015-06-30 18:47 - 2014-12-01 17:31 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2015-06-30 18:47 - 2014-12-01 17:31 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2015-06-30 18:47 - 2015-07-23 19:23 - 00703168 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2015-06-30 18:47 - 2015-07-03 12:12 - 39553928 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
2014-12-29 14:58 - 2014-10-08 16:51 - 00348992 _____ () C:\Program Files (x86)\IObit\Driver Booster\madExcept_.bpl
2014-12-29 14:58 - 2014-10-08 16:50 - 00183616 _____ () C:\Program Files (x86)\IObit\Driver Booster\madBasic_.bpl
2014-12-29 14:58 - 2014-10-08 16:50 - 00051008 _____ () C:\Program Files (x86)\IObit\Driver Booster\madDisAsm_.bpl
2014-12-29 14:58 - 2014-08-22 16:19 - 00893248 _____ () C:\Program Files (x86)\IObit\Driver Booster\webres.dll
2014-12-29 14:58 - 2012-02-16 11:16 - 00516440 _____ () C:\Program Files (x86)\IObit\Driver Booster\sqlite3.dll
2015-08-19 09:46 - 2015-08-19 09:46 - 00011264 _____ () C:\Users\Kathy\AppData\Local\Temp\nsn4709.tmp\System.dll
2015-08-19 09:46 - 2015-08-19 09:46 - 00117248 _____ () C:\Users\Kathy\AppData\Local\Temp\nsn4709.tmp\IpConfig.dll
2015-07-13 12:09 - 2015-03-26 10:13 - 01091584 _____ () C:\Users\Kathy\AppData\Local\Ninja Loader\Discover\libglesv2.dll
2015-07-13 12:09 - 2015-03-26 10:13 - 00167936 _____ () C:\Users\Kathy\AppData\Local\Ninja Loader\Discover\libEGL.dll
2015-07-13 12:09 - 2015-03-26 10:39 - 08569856 _____ () C:\Users\Kathy\AppData\Local\Ninja Loader\Discover\pdf.dll
2015-07-13 12:09 - 2015-03-26 10:18 - 00324608 _____ () C:\Users\Kathy\AppData\Local\Ninja Loader\Discover\ppGoogleNaClPluginChrome.dll
2015-07-13 12:09 - 2015-03-26 10:14 - 00880128 _____ () C:\Users\Kathy\AppData\Local\Ninja Loader\Discover\ffmpegsumo.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Windows\system32\Drivers\vfbhiosb.sys:changelist
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Cofvopjy => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\myradioplayer => ""="service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\100sexlinks.com -> 100sexlinks.com
 
There are 4788 more restricted sites.
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-171533428-321824291-3300133993-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{9ED28A31-FDD7-4583-8462-1071417A0BFD}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{C46D8DEB-70AE-441E-A3EA-5BC3B735FCD0}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [TCP Query User{06B3491D-090D-46B2-B1D0-77DEB7A9668D}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
FirewallRules: [UDP Query User{0E289524-7AF7-42E1-B79C-6CEFEA80A5A7}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
FirewallRules: [{0B5ADB51-8095-4367-9CE0-B9F8A08F5E8C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{F70B49AA-6FB6-45E3-A9C4-BA4B69A06567}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{B1830E8F-99BB-4647-871A-3E464AECC635}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{9D7B1C62-08F3-4201-892E-F1F204FB3B82}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{23707D09-9119-4D70-8065-8FDC631F5D12}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Team Fortress 2\hl2.exe
FirewallRules: [{182FD2AE-3BD2-44C9-81AE-AB0DB11B8F70}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Team Fortress 2\hl2.exe
FirewallRules: [{E89E610F-18AA-4855-8D2C-42BE8BCF386F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AdVenture Capitalist\adventure-capitalist.exe
FirewallRules: [{F6E90CEF-68C2-4075-9104-4BEC29442B30}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AdVenture Capitalist\adventure-capitalist.exe
FirewallRules: [{9EB6F522-4707-4F17-82F6-5566AF5DE129}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{264B9FAF-43DD-4343-A301-3DAD53EEC1A0}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{8D4815BF-C331-4AC1-8537-D6FEE45715D8}] => (Allow) C:\IQIYI Video\GeePlayer\GeePlayer.exe
FirewallRules: [{FD9121D0-CCD1-4339-8C12-545C16608EA1}] => (Allow) C:\Users\Kathy\AppData\Roaming\IQIYI Video\LStyle\QyUpdate.exe
FirewallRules: [{B1EDAE99-499C-4E97-B76E-5BABD06EB34B}] => (Allow) C:\IQIYI Video\LStyle\QyClient.exe
FirewallRules: [{57FAFCFF-2275-4BD7-ABA3-ED9FC909C651}] => (Allow) C:\IQIYI Video\LStyle\QyWebPlayer.exe
FirewallRules: [{7129562E-A0C2-410F-B5C6-233F4B07C18F}] => (Allow) C:\IQIYI Video\LStyle\QyPlayer.exe
FirewallRules: [{BD397738-D987-4F9C-9428-8ED28F2A3056}] => (Allow) C:\Program Files (x86)\Microsoft.NET\v2.0.507279\msnetcore.exe
FirewallRules: [{5B5678E7-8F8A-4971-B590-5273734B3839}] => (Allow) C:\Program Files (x86)\Microsoft.NET\v2.0.507279\msbuild.exe
FirewallRules: [{B73AFB0A-002E-4938-897D-9817CB63CB66}] => (Allow) C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe
FirewallRules: [{4B4AB129-F247-4FC0-99D9-96B00ED433F0}] => (Allow) C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe
 
==================== Faulty Device Manager Devices =============
 
Name: Microsoft ISATAP Adapter #2
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
Name: Microsoft ISATAP Adapter
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/19/2015 09:42:57 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IObitUninstaler.exe version 4.3.0.5 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 370c
 
Start Time: 01d0da841eaf97fc
 
Termination Time: 7
 
Application Path: C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
 
Report Id: 2a7b197c-4678-11e5-9888-70f1a1e80b86
 
Error: (08/16/2015 04:38:45 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/16/2015 04:35:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: cpx.exe, version: 1.1.0.1, time stamp: 0x558d0604
Faulting module name: cpx.exe, version: 1.1.0.1, time stamp: 0x558d0604
Exception code: 0xc0000409
Fault offset: 0x0003a8dc
Faulting process id: 0x13f4
Faulting application start time: 0xcpx.exe0
Faulting application path: cpx.exe1
Faulting module path: cpx.exe2
Report Id: cpx.exe3
 
Error: (08/16/2015 04:35:07 PM) (Source: CoupoonService64) (EventID: 1) (User: )
Description: CoupoonService64StartServiceCtrlDispatcher error 1063
 failed with 1063
 
Error: (07/28/2015 08:44:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
Error: (07/28/2015 08:44:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
Error: (07/28/2015 08:42:55 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Windows\system32\svchost.exe -k netsvcs; Description = Windows Update; Error = 0x81000101).
 
Error: (07/28/2015 08:33:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 43.0.2357.132, time stamp: 0x559b2699
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0xaabb1010
Faulting process id: 0x3ab4
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
 
Error: (07/28/2015 08:29:40 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.17840 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 2c3c
 
Start Time: 01d0c9958673ecdb
 
Termination Time: 7
 
Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Report Id:
 
Error: (07/28/2015 08:29:06 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.17840 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: c98
 
Start Time: 01d0c9955acf015c
 
Termination Time: 985
 
Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Report Id:
 
 
System errors:
=============
Error: (08/19/2015 09:51:46 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 115.5.0.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (08/19/2015 09:51:46 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.203.712.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (08/19/2015 09:51:46 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.203.712.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (08/19/2015 09:51:46 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.203.712.0
 
Update Source: %NT AUTHORITY59
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\SYSTEM
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (08/19/2015 09:43:30 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 115.5.0.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (08/19/2015 09:43:30 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.203.712.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (08/19/2015 09:43:30 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.203.712.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (08/19/2015 09:43:30 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.203.712.0
 
Update Source: %NT AUTHORITY59
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\SYSTEM
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (08/19/2015 09:41:40 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 115.5.0.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (08/19/2015 09:41:40 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.203.712.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
 
Microsoft Office:
=========================
Error: (08/19/2015 09:42:57 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IObitUninstaler.exe4.3.0.5370c01d0da841eaf97fc7C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe2a7b197c-4678-11e5-9888-70f1a1e80b86
 
Error: (08/16/2015 04:38:45 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/16/2015 04:35:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: cpx.exe1.1.0.1558d0604cpx.exe1.1.0.1558d0604c00004090003a8dc13f401d0d862f219501bC:\Program Files (x86)\cpx\cpx.exeC:\Program Files (x86)\cpx\cpx.exe50f87ae5-4456-11e5-9888-70f1a1e80b86
 
Error: (08/16/2015 04:35:07 PM) (Source: CoupoonService64) (EventID: 1) (User: )
Description: CoupoonService64StartServiceCtrlDispatcher error 1063
 failed with 1063
 
Error: (07/28/2015 08:44:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
Error: (07/28/2015 08:44:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
Error: (07/28/2015 08:42:55 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\Windows\system32\svchost.exe -k netsvcsWindows Update0x81000101
 
Error: (07/28/2015 08:33:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: chrome.exe43.0.2357.132559b2699unknown0.0.0.000000000c0000005aabb10103ab401d0c99602a2af19C:\Program Files (x86)\Google\Chrome\Application\chrome.exeunknown77323b50-3589-11e5-ab64-1c7508113231
 
Error: (07/28/2015 08:29:40 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.178402c3c01d0c9958673ecdb7C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Error: (07/28/2015 08:29:06 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.17840c9801d0c9955acf015c985C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
 
==================== Memory info =========================== 
 
Processor: AMD Phenom™ II N830 Triple-Core Processor
Percentage of memory in use: 64%
Total physical RAM: 3834.9 MB
Available physical RAM: 1347.59 MB
Total Virtual: 7668 MB
Available Virtual: 4560.26 MB
 
==================== Drives ================================
 
Drive c: (Gateway) (Fixed) (Total:452.66 GB) (Free:198.86 GB) NTFS
Drive e: (STORE N GO) (Removable) (Total:7.46 GB) (Free:7.45 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: F836E349)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=452.7 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 7.5 GB) (Disk ID: 1342406A)
Partition 1: (Not Active) - (Size=7.5 GB) - (Type=0C)
 
==================== End of log ============================
 
Thanks in Advance for the help

  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there I believe we may have the record for the number of malware files on any one system..... This first FRST fix may take a while to run as it has a lot to do

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Right click the attached fixlist.txt and select save target as.. Save to the desktop
Attached File  fixlist.txt   40.53KB   102 downloads
FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S0].txt as well.
NEXT

Please download Junkware Removal Tool to your desktop.
  • Right-mouse click JRT.exe and select "Run as Administrator" the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • post the contents of JRT.txt into your next message.

  • 0

#3
moondog830

moondog830

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 626 posts

I will make an extra effort to tell them to keep their grandson off of their computer ... we'll see how that works.

 

Fixlog

 

Fix result of Farbar Recovery Scan Tool (x64) Version:17-08-2015
Ran by Kathy (2015-08-19 19:03:31) Run:1
Running from C:\Users\Kathy\Desktop
Loaded Profiles: Kathy (Available Profiles: Kathy)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CreateRestorePoint: 
HKLM\...\Run: [RadPlayer Tray] => C:\Program Files (x86)\RadPlayer\TyV1.exe [294824 2015-05-29] (RadPlayer)
HKLM\...\Run: [shopperz12072015] => C:\Program Files\shopperz12072015\Bzvra.exe [433512 2015-07-13] ()
HKLM\...\Run: [shopperz1207201564] => C:\Program Files\shopperz12072015\Bzvra64.exe [464744 2015-07-13] ()
HKLM-x32\...\Run: [StormWatch] => C:\Program Files (x86)\StormWatch\StormWatchApp.exe [1556504 2015-04-10] ()
HKLM-x32\...\Run: [cpx] => C:\Program Files (x86)\cpx\cpx.exe [1162240 2015-06-26] ()
HKLM-x32\...\Run: [msrtn32] => C:\Program Files (x86)\msrtn32\msrtn32.exe [1221120 2015-06-28] ()
HKLM-x32\...\Run: [WinCheck] => C:\Users\Kathy\AppData\Local\5670549A-1436745935-DE00-E918-1C7508113231\bnshDF4A.exe [350720 2015-06-24] ()
HKLM-x32\...\Run: [gmsd_us_005010030] => C:\Program Files (x86)\gmsd_us_005010030\gmsd_us_005010030.exe [3986064 2015-07-13] ()
HKLM-x32\...\Run: [mwyyntm1ndi1zdz] => C:\Program Files (x86)\Smwyyntm1ndi1zdz\ywi2mzv2zhnjbdh.exe [2422272 2015-07-13] ()
HKLM-x32\...\Run: [gmsd_us_005010031] => C:\Program Files (x86)\gmsd_us_005010031\gmsd_us_005010031.exe [3985552 2015-07-14] ()
HKLM-x32\...\Run: [MovieDea] => C:\Program Files (x86)\MovieDea\MovieDea.exe [3184640 2015-06-03] (MovieDea)
HKLM-x32\...\Run: [SmartWeb] => C:\Users\Kathy\AppData\Local\SmartWeb\SmartWebHelper.exe [270368 2015-02-17] (SoftBrain Technologies Ltd.)
HKLM-x32\...\RunOnce: [upospd_us_014010029.exe] => C:\Users\Kathy\AppData\Local\ospd_us_014010029\upospd_us_014010029.exe [3287696 2015-07-12] ()
HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Run: [NinjaLoader] => C:\Program Files (x86)\Ninja Loader\Ninja Loader.exe [1575016 2015-07-02] (CLICK YES BELOW LP)
HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro 3.99\OptProLauncher.exe [148112 2015-07-03] ()
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll [246544 2015-07-02] (Client Connect LTD)
AppInit_DLLs:  C:\ProgramData\FlashBeat\FlashBeat64.dll => C:\ProgramData\FlashBeat\FlashBeat64.dll File not found
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [213776 2015-07-02] (Client Connect LTD)
AppInit_DLLs-x32:  C:\ProgramData\FlashBeat\FlashBeat32.dll => C:\ProgramData\FlashBeat\FlashBeat32.dll [805376 2015-07-13] (FlashBeat)
AppInit_DLLs-x32:  C:\ProgramData\EpsanDrive\EpsanDrive32.dll => C:\ProgramData\EpsanDrive\EpsanDrive32.dll [805376 2015-07-08] (EpsanDrive)
AppInit_DLLs-x32:  C:\PROGRA~3\{63B88~1\1173~1.1\tiso.dll => "C:\PROGRA~3\{63B88~1\1173~1.1\tiso.dll" File not found
Startup: C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bm.lnk [2015-07-18]
ShortcutTarget: bm.lnk -> C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh\yxa2bzvwzf9jdth.exe (PU-App)
Startup: C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk [2015-07-13]
ShortcutTarget: crossbrowse.lnk -> C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe (No File)
Startup: C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk [2015-07-18]
ShortcutTarget: SmartWeb.lnk -> C:\Users\Kathy\AppData\Local\SmartWeb\SmartWebHelper.exe (SoftBrain Technologies Ltd.)
Startup: C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatch.lnk [2015-07-12]
ShortcutTarget: StormWatch.lnk -> C:\Program Files (x86)\StormWatch\StormWatch.exe (Weather Protector LLC)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-171533428-321824291-3300133993-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
URLSearchHook: HKU\S-1-5-21-171533428-321824291-3300133993-1000 - (No Name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File
SearchScopes: HKLM -> OldSearch URL = hxxp://www.cassiopessa.com/results.php?f=4&q={searchTerms}&a=csp_installertech_15_26&cd=2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0EzztD0BzzyCtByDyDtAtN0D0Tzu0StCtByBtAtN1L2XzutAtFtCtCtFtAtFtCtN1L1Czu1R1B1E1V1L1G1B2Z1T1I1I1P1C2Z1P1R1MtN1L1G1B1V1N2Y1L1Qzu2StB0A0BtCtCyB0C0BtGyCyCtAtAtG0Azz0BtBtGyEzzyCzytGtBzz0C0ByE0DyB0BtA0D0F0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0E0DyC0E0DzytBtGtBtD0D0FtGyE0FtA0EtG0B0AtB0EtGyEzy0AtByByEzzyC0F0E0FtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzuzztBtB&cr=1202157401&ir=
SearchScopes: HKLM-x32 -> {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://start.iminent.com/?appId=8437c40c-c891-4a5e-8eea-ca8568502d51&ref=toolbox&q={searchTerms}
SearchScopes: HKU\S-1-5-21-171533428-321824291-3300133993-1000 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3333887&octid=EB_ORIGINAL_CTID&ISID=M1890E6BC-BF65-41CA-B1ED-FCA8EC054D11&SearchSource=58&CUI=&UM=8&UP=SPA98636E4-750F-401C-BC08-F5A740811DAD&D=071415&q={searchTerms}&SSPV=SP30339T2B_sp_ie
SearchScopes: HKU\S-1-5-21-171533428-321824291-3300133993-1000 -> {BC4A5ADC-08EE-4734-9171-5A5035FF16D7} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-07-18] (IObit)
BHO: IMinent WebBooster (BHO) -> {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} -> C:\Program Files (x86)\Iminent\Minibar.InternetExplorer.BHOx64.dll [2015-06-10] (SIEN)
BHO: Consumer Input DCA BHO -> {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} -> C:\Program Files (x86)\Consumer Input\InternetExplorer\x64\dca-bho.dll [2015-06-25] (Compete, Inc.)
BHO: shopperz12072015 -> {c49ac435-5c4d-450f-aa56-cd31f96613b3} -> C:\Program Files\shopperz12072015\Eixrizl64.dll [2015-07-13] ()
BHO-x32: No Name -> {84FF7BD6-B47F-46F8-9130-01B2696B36CB} ->  No File
BHO-x32: IMinent WebBooster (BHO) -> {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} -> C:\Program Files (x86)\Iminent\Minibar.InternetExplorer.BHOx86.dll [2015-06-10] (SIEN)
BHO-x32: Consumer Input DCA BHO -> {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} -> C:\Program Files (x86)\Consumer Input\InternetExplorer\dca-bho.dll [2015-06-25] (Compete, Inc.)
BHO-x32: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2015-04-01] (IObit)
BHO-x32: shopperz12072015 -> {c49ac435-5c4d-450f-aa56-cd31f96613b3} -> C:\Program Files\shopperz12072015\Eixrizl.dll [2015-07-13] ()
Winsock: Catalog9 01 C:\Windows\SysWOW64\Cofvopjy.dll [279040 2015-07-14] ()
Winsock: Catalog9 02 C:\Windows\SysWOW64\Cofvopjy.dll [279040 2015-07-14] ()
Winsock: Catalog9 03 C:\Windows\SysWOW64\Cofvopjy.dll [279040 2015-07-14] ()
Winsock: Catalog9 04 C:\Windows\SysWOW64\Cofvopjy.dll [279040 2015-07-14] ()
Winsock: Catalog9 05 C:\Windows\SysWOW64\myradioplayer.dll [358824 2015-07-12] (myradioplayer)
Winsock: Catalog9 06 C:\Windows\SysWOW64\myradioplayer.dll [358824 2015-07-12] (myradioplayer)
Winsock: Catalog9 07 C:\Windows\SysWOW64\myradioplayer.dll [358824 2015-07-12] (myradioplayer)
Winsock: Catalog9 08 C:\Windows\SysWOW64\myradioplayer.dll [358824 2015-07-12] (myradioplayer)
Winsock: Catalog9 19 C:\Windows\SysWOW64\myradioplayer.dll [358824 2015-07-12] (myradioplayer)
Winsock: Catalog9 20 C:\Windows\SysWOW64\Cofvopjy.dll [279040 2015-07-14] ()
Winsock: Catalog9-x64 01 C:\Windows\system32\myradioplayer64.dll [465320 2015-07-12] (myradioplayer)
Winsock: Catalog9-x64 02 C:\Windows\system32\myradioplayer64.dll [465320 2015-07-12] (myradioplayer)
Winsock: Catalog9-x64 03 C:\Windows\system32\myradioplayer64.dll [465320 2015-07-12] (myradioplayer)
Winsock: Catalog9-x64 04 C:\Windows\system32\myradioplayer64.dll [465320 2015-07-12] (myradioplayer)
Winsock: Catalog9-x64 15 C:\Windows\system32\myradioplayer64.dll [465320 2015-07-12] (myradioplayer)
FF Plugin: @iqiyi.com/npclient -> C:\IQIYI Video\LStyle\npclient.dll [2015-05-12] ()
FF Plugin: @iqiyi.com/npWebPlayer -> C:\IQIYI Video\LStyle\npWebPlayer.dll [2015-04-29] (?????)
FF Plugin-x32: @iqiyi.com/npclient -> C:\IQIYI Video\LStyle\npclient.dll [2015-05-12] ()
FF Plugin-x32: @iqiyi.com/npWebPlayer -> C:\IQIYI Video\LStyle\npWebPlayer.dll [2015-04-29] (?????)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-07-19] (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-07-19] (globalUpdate)
FF Plugin HKU\S-1-5-21-171533428-321824291-3300133993-1000: @iqiyi.com/npWebPlayer -> C:\IQIYI Video\LStyle\npWebPlayer.dll [2015-04-29] (?????)
FF Plugin HKU\S-1-5-21-171533428-321824291-3300133993-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Kathy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-12-05] (Unity Technologies ApS)
FF HKLM\...\Firefox\Extensions: [{c49ac435-5c4d-450f-aa56-cd31f96613b3}] - C:\Program Files\shopperz12072015\Firefox
FF Extension: shopperz12072015 - C:\Program Files\shopperz12072015\Firefox [2015-07-14]
FF HKLM-x32\...\Firefox\Extensions: [{c49ac435-5c4d-450f-aa56-cd31f96613b3}] - C:\Program Files\shopperz12072015\Firefox
FF HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12191.xpi
FF Extension: Consumer Input - C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12191.xpi [2015-06-25]
FF HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Ninja Loader\FireFox
FF Extension: NinjaLoader - C:\Program Files (x86)\Ninja Loader\FireFox [2015-07-13]
CHR Extension: (HQCinema Pro 2.1V12.07) - C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gegdfeiahlfolhcfioipjlkombmgbakh [2015-07-12]
CHR Extension: (CinemaPlus-3.2cV13.07) - C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\papbadoldddalgcjcicnikcfenodpghp [2015-07-13]
CHR HKLM-x32\...\Chrome\Extension: [adpeheiliennogfclcgmchdfdmafjegc] - https://clients2.goo...ice/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [cmlhbjpgeogifjnmlajdaealbdlfonah] - https://clients2.goo...ice/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ehhlaekjfiiojlddgndcnefflngfmhen] - https://clients2.goo...ice/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gihfmmedoddijgnhkgfgnkeohkpbipol] - https://clients2.goo...ice/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]
CHR HKLM-x32\...\Chrome\Extension: [nociobghckdhokecfeajdpimjeapnopn] - https://clients2.goo...ice/update2/crx
R2 46784c7a-2afb-4c2f-b299-133de9a46a66; C:\Program Files\shopperz12072015\Igivkorcb.exe [285544 2015-07-13] ()
S2 c31ed948; c:\Program Files (x86)\Optimizer Pro 3.99\OptProMon.dll [2570896 2015-07-13] () <==== ATTENTION
R3 Cofvopjy; C:\Program Files\shopperz12072015\Cofvopjy.exe [2020864 2015-07-13] () [File not signed]
S2 consumerinput_update; C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [105944 2015-07-12] (ConsumerInput)
S3 consumerinput_updatem; C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [105944 2015-07-12] (ConsumerInput)
S2 CoupoonService64; C:\Program Files (x86)\coupoon\iiwjljrnpc64.exe [172344 2015-04-02] ()
R2 csrcc; C:\Program Files\shopperz12072015\csrcc.exe [1448808 2015-07-13] ()
R2 Dataup; C:\Program Files (x86)\dataup\dataup.exe [77824 2015-06-29] () [File not signed] <==== ATTENTION
S2 FlashBeat; C:\ProgramData\FlashBeat\FlashBeat.exe [814080 2015-07-13] (FlashBeat) [File not signed]
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-07-19] (globalUpdate) [File not signed] <==== ATTENTION
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-07-19] (globalUpdate) [File not signed] <==== ATTENTION
R2 GlobalUpdater; C:\Program Files (x86)\Common Files\IMGUpdater\IMGUpdater.exe [378152 2015-07-02] (SIEN S.A.)
R2 IMService; C:\Program Files (x86)\Common Files\Umbrella\Umbrella234.exe [5315224 2015-07-02] (Iminent)
R2 LosdyLijfeu; C:\Program Files\shopperz12072015\ZazyjiKotn.exe [171920 2015-07-13] () [File not signed]
R2 myradioplayer; C:\Program Files (x86)\RadPlayer\myradioplayer.exe [3904936 2015-05-29] (myradioplayer)
R2 NinjaLoaderService; C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe [59496 2015-07-02] (Ninja Soft Inc.)
R2 RadPlayerV1; C:\Program Files (x86)\RadPlayer\RadPlayerSvc.exe [323496 2015-05-29] (RadPlayer)
S2 RadPlayerV2; C:\Program Files (x86)\RadPlayer\RadPlayer.Service.exe [78248 2015-05-29] (RadPlayer)
R2 REhsGdKiASD; C:\ProgramData\caGSSMRD\REhsGdKiASD.exe [2732288 2015-07-13] (Valid Applications)
R2 relibily; C:\Users\Kathy\AppData\Local\5670549A-1436745948-DE00-E918-1C7508113231\cnsh175B.tmp [219136 2015-07-13] () [File not signed]
R2 serveras; C:\Users\Kathy\AppData\Roaming\ASPackage\ASSrv.exe [183808 2015-07-13] () [File not signed]
R2 shopperz12072015 Updater; C:\Program Files\shopperz12072015\Xzeexmh.exe [174952 2015-07-13] ()
R2 StormWatch Update Service; C:\Program Files (x86)\StormWatch\StormWatchSrv.exe [586264 2015-04-10] ()
R2 SWUpdater; C:\Program Files (x86)\StormWatch\SWUpdaterSvc.exe [17584 2014-11-22] (Weather Protector LLC)
R2 UdvdPork; C:\ProgramData\1436760085\s9.exe [404480 2015-04-07] () [File not signed]
R2 UpdateCheck; C:\Program Files (x86)\Coupoon\UpdateCheck.exe [53040 2015-07-12] ()
R2 WajIEn Monitor; C:\Program Files\WajIEn\wajam_64.exe [1997824 2015-07-13] () [File not signed]
S2 wbsvc; C:\Program Files\WebBar\wbsvc.exe [37144 2015-02-18] (Web Bar Media)
R2 windowsmanagementservice; C:\Users\Kathy\AppData\Local\Temp\20150713\ct.exe [848384 2015-06-29] (Google Inc.) [File not signed]
R2 wssvc_1.10.0.20; C:\Program Files (x86)\WordShark_1.10.0.20\Service\wssvc.exe [300120 2015-07-06] (WS)
S2 SMUpdPlus; no ImagePath
R1 cherimoya; C:\Windows\System32\drivers\cherimoya.sys [61336 2015-06-18] (Cherimoya Ltd)
S3 SMUpdd; no ImagePath
S1 vfbhiosb; C:\Windows\system32\drivers\vfbhiosb.sys [55168 2015-08-16] (Microsoft Corporation)
R1 wsfd_vt_1_10_0_20; C:\Windows\System32\drivers\wsfd_vt_1_10_0_20.sys [61312 2015-07-06] (WS)
R1 ywi2mzv2zhnjbdh; C:\Windows\System32\drivers\ywi2mzv2zhnjbdh.sys [50520 2015-07-13] (Windows ® Win 7 DDK provider)
2015-08-16 16:50 - 2015-08-16 16:50 - 00055168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vfbhiosb.sys
2015-08-16 16:39 - 2015-08-16 16:39 - 00000000 ____D C:\Users\Kathy\AppData\Local\CEF
2015-07-28 20:15 - 2015-07-28 20:16 - 00000000 ____D C:\Program Files (x86)\GUMBFC5.tmp
2015-07-28 20:15 - 2015-07-28 20:15 - 06420480 _____ C:\Program Files (x86)\GUTC294.tmp
2015-07-28 20:15 - 2015-07-28 20:15 - 00000010 _____ C:\Windows\TEMPcoral.vbs
2015-07-28 20:15 - 2015-07-28 20:15 - 00000000 ____D C:\ProgramData\Ninja Loader
2015-07-28 20:10 - 2015-07-28 20:42 - 00118082 _____ C:\Windows\SysWOW64\debug.log
2015-08-19 10:08 - 2015-07-12 23:59 - 00000360 _____ C:\Windows\Tasks\CIMT_S-1-5-21-171533428-321824291-3300133993-1000.job
2015-08-19 10:05 - 2015-07-19 00:04 - 00002112 _____ C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user.job
2015-08-19 10:05 - 2015-07-12 23:56 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-08-19 10:04 - 2015-07-13 12:59 - 00000342 ____H C:\Windows\Tasks\GLQHQICXMFBVKQCB.job
2015-08-19 10:01 - 2015-07-12 23:56 - 00000968 _____ C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job
2015-08-19 09:58 - 2015-07-12 23:58 - 00003140 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.job
2015-08-19 09:57 - 2015-07-12 23:57 - 00005520 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-6.job
2015-08-19 09:55 - 2015-07-12 23:55 - 00002114 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user.job
2015-08-19 09:33 - 2015-07-13 13:29 - 00003254 _____ C:\Windows\System32\Tasks\Optimizer Pro Schedule
2015-08-19 09:32 - 2015-07-13 13:09 - 00002112 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user.job
2015-08-16 22:53 - 2015-07-19 00:13 - 00005862 _____ C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job
2015-08-16 22:53 - 2015-07-13 13:13 - 00003138 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.job
2015-08-16 22:53 - 2015-07-13 13:12 - 00005518 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.job
2015-08-16 16:40 - 2015-07-12 11:01 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-08-16 16:39 - 2015-07-14 14:16 - 00004704 _____ C:\Windows\SysWOW64\Cofvopjy.ini
2015-08-16 16:39 - 2015-07-14 14:16 - 00002416 _____ C:\Windows\SysWOW64\CofvopjyOff.ini
2015-08-16 16:39 - 2015-07-14 14:16 - 00002416 _____ C:\Windows\system32\CofvopjyOff.ini
2015-08-16 16:37 - 2015-07-13 00:01 - 00000000 ____D C:\Users\Kathy\AppData\Local\ospd_us_014010029
2015-08-16 16:36 - 2015-07-13 12:15 - 00000000 ____D C:\Users\Kathy\AppData\Local\mstrn32
2015-08-16 16:34 - 2015-07-13 13:15 - 00000996 _____ C:\Windows\Tasks\WdEL9n2eiowr.job
2015-08-16 16:34 - 2015-07-12 23:59 - 00000986 _____ C:\Windows\Tasks\FYLVp79.job
2015-08-16 16:33 - 2015-07-19 00:13 - 00005518 _____ C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7.job
2015-08-16 16:33 - 2015-07-19 00:07 - 00004494 _____ C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3.job
2015-08-16 16:33 - 2015-07-13 13:15 - 00002446 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user.job
2015-08-16 16:33 - 2015-07-13 13:14 - 00002446 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.job
2015-08-16 16:33 - 2015-07-13 13:13 - 00003474 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7.job
2015-08-16 16:33 - 2015-07-13 13:12 - 00005518 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7.job
2015-08-16 16:33 - 2015-07-13 13:10 - 00004494 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3.job
2015-08-16 16:33 - 2015-07-13 13:07 - 00001056 _____ C:\Windows\Tasks\Crossbrowse.job
2015-08-16 16:33 - 2015-07-12 23:59 - 00002448 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user.job
2015-08-16 16:33 - 2015-07-12 23:59 - 00002448 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5.job
2015-08-16 16:33 - 2015-07-12 23:58 - 00003476 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7.job
2015-08-16 16:33 - 2015-07-12 23:57 - 00005184 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-7.job
2015-08-16 16:33 - 2015-07-12 23:56 - 00004496 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-3.job
2015-08-16 16:33 - 2015-07-12 23:56 - 00000970 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-08-16 16:33 - 2015-07-12 23:56 - 00000964 _____ C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job
2015-08-16 16:33 - 2015-07-12 23:55 - 00000342 ____H C:\Windows\Tasks\JWRTYVMXFBIVCPWL.job
2015-08-16 16:33 - 2015-07-12 23:55 - 00000336 _____ C:\Windows\Tasks\NLSAGZR1.job
2015-07-28 20:22 - 2015-07-13 16:29 - 00003444 _____ C:\Windows\System32\Tasks\Epuifuuva
2015-07-28 20:15 - 2015-07-13 12:08 - 00000000 ____D C:\Users\Kathy\AppData\Local\Ninja Loader
2015-07-28 20:12 - 2014-12-29 14:58 - 00000000 ____D C:\ProgramData\ProductData
2015-07-28 20:15 - 2015-07-28 20:15 - 6420480 _____ () C:\Program Files (x86)\GUTC294.tmp
2015-07-18 21:58 - 2015-07-18 21:58 - 6420480 _____ () C:\Program Files (x86)\GUTFD53.tmp
2015-04-19 08:20 - 2015-04-19 08:20 - 0005872 _____ () C:\Users\Kathy\AppData\Roaming\FYLVp79
2015-04-20 10:05 - 2015-04-20 10:05 - 1579520 _____ () C:\Users\Kathy\AppData\Roaming\FYLVp79.exe
2015-04-19 08:20 - 2015-04-19 08:20 - 0005872 _____ () C:\Users\Kathy\AppData\Roaming\WdEL9n2eiowr
2015-04-20 10:05 - 2015-04-20 10:05 - 1579520 _____ () C:\Users\Kathy\AppData\Roaming\WdEL9n2eiowr.exe
2015-07-13 13:52 - 2015-07-13 13:52 - 0613255 _____ (CMI Limited) C:\Users\Kathy\AppData\Local\nsiBAD8.tmp
2015-07-28 20:08 - 2015-07-19 00:16 - 00005086 _____ C:\Windows\Tasks\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job
Task: {01A22A0D-37F6-4D85-A408-491ACA67BF31} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-6 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-6.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {02956738-DE99-47D8-A6C6-DCEE22EE7C4B} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {0473C0CA-9A3F-462C-9BB2-BB768544A91A} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-3 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-3.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {0C67CC53-4D97-46D6-A447-A0C70698D63C} - System32\Tasks\WebBarUpdateTask => C:\Program Files\WebBar\wbsvc.exe [2015-02-18] (Web Bar Media) <==== ATTENTION
Task: {12826CD3-979A-4778-9E55-62298738037F} - System32\Tasks\WdEL9n2eiowr => C:\Users\Kathy\AppData\Roaming\WdEL9n2eiowr.exe [2015-04-20] () <==== ATTENTION
Task: {13C77BBA-4D9D-4CC4-9783-0F09749EBC89} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {168DBC36-AAF6-4F39-8483-52C63048B4FE} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {1BEAFD01-BB2F-4D5D-A4CB-F3456C100409} - System32\Tasks\ConsumerInputUpdateTaskMachineUA => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [2015-07-12] (ConsumerInput) <==== ATTENTION
Task: {1D2B5213-0A0B-4933-8409-5B6CCA9D31C4} - System32\Tasks\SMW_UpdateTask_Time_333833393739363037312d235b783432415b45345a2d6c => Wscript.exe //B "C:\ProgramData\SearchModulePlus\smhe.js" smu.exe /invoke /f:check_services /l:0 <==== ATTENTION
Task: {1EC32D4B-9503-4E11-9581-F33F5490D6C8} - System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10.exe [2015-07-19] (Cinema PlusV18.07) <==== ATTENTION
Task: {25FCAB52-144F-4DF6-9ED8-A783CF9663E3} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {26C1D14B-D736-4340-AA04-29E5B0EE9912} - System32\Tasks\CIMT_S-1-5-21-171533428-321824291-3300133993-1000 => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe [2015-06-19] () <==== ATTENTION
Task: {2C86BA2E-43EA-43C1-9CC7-DC321BFFF485} - System32\Tasks\Snmix => C:\Program Files\shopperz12072015\Ubehsi.bat [2015-07-13] () <==== ATTENTION
Task: {325746AD-5A6F-430F-8E30-6CD44422ABDB} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {36F19701-E5F7-4483-856F-F95E73176541} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {3C325D05-59F7-4AA8-A14C-0D30C25CACC4} - System32\Tasks\Driver Booster SkipUAC (SYSTEM) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2015-07-06] (IObit)
Task: {41F7B16E-395A-4581-81BD-04F429088AC9} - System32\Tasks\Driver Booster SkipUAC (Kathy) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2015-07-06] (IObit)
Task: {423821BC-96E6-4D84-9341-34C7D6544576} - System32\Tasks\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6 => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.exe [2015-07-19] (Cinema PlusV18.07) <==== ATTENTION
Task: {4315E182-2227-4C77-880F-D8ED0781664D} - System32\Tasks\NLSAGZR1 => C:\ProgramData\EpsanDrive\EpsanDrive.exe [2015-07-08] (EpsanDrive) <==== ATTENTION
Task: {46EEB3FE-4979-4D71-B642-E6812F1A1B63} - System32\Tasks\SMWPUpd => C:\Program Files\Common Files\Goobzo\GBUpdatePlus\updater.exe <==== ATTENTION
Task: {4F7AA969-E2FB-46AC-A550-70B132457A08} - System32\Tasks\Smp => C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smp.exe <==== ATTENTION
Task: {519D5601-B701-4EF4-942D-023EB0776066} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files (x86)\Optimizer Pro 3.99\OptProLauncher.exe [2015-07-03] () <==== ATTENTION
Task: {536F625C-BFB1-4834-BC2B-BD6198974A9E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-29] (Google Inc.)
Task: {58BC472B-603B-41F5-A0F2-3D4FBD8E8B49} - System32\Tasks\WebBarLaunchTask => C:\Program Files\WebBar\wbsvc.exe [2015-02-18] (Web Bar Media) <==== ATTENTION
Task: {5AE88653-7D39-4018-A2D6-1B1865993C94} - System32\Tasks\BD634EFB-4435-4228-B1B1-B9F4709D5F79 => C:\Users\Kathy\AppData\Local\BD634EFB-4435-4228-B1B1-B9F4709D5F79\BD634EFB-4435-4228-B1B1-B9F4709D5F79.exe [2015-07-18] () <==== ATTENTION
Task: {5B84AF85-C877-4407-9B54-51E465C67CD3} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {5BAFB821-7E9C-44DA-8FF3-BA06AA1A580A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-26] (Adobe Systems Incorporated)
Task: {5D16852C-3009-4836-B678-96DD5F24BE7B} - System32\Tasks\ConsumerInputUpdateTaskMachineCore => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [2015-07-12] (ConsumerInput) <==== ATTENTION
Task: {610A4D52-9E85-4E0B-A680-BEA500D4EF11} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-29] (Google Inc.)
Task: {691E87A2-9D64-45C3-A667-ABE98310143F} - System32\Tasks\GLQHQICXMFBVKQCB => C:\ProgramData\Service1291\Service1291.exe [2015-06-28] () <==== ATTENTION
Task: {6F7B2104-C5A2-4870-8DAA-94359F4B295E} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {80ECF25B-E055-4C3B-B841-3F10B6413105} - System32\Tasks\Crossbrowse => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION
Task: {83886EC4-445C-4DB0-9EB6-83B465472564} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-5.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {88726888-5908-4FB8-A3FA-9043CB5B1478} - System32\Tasks\WordShark Auto Updater 1.10.0.20 Core => C:\Program Files (x86)\WordShark_1.10.0.20\Update\WordSharkAutoUpdateClient.exe [2015-07-06] (WS) <==== ATTENTION
Task: {8C648E3B-AA13-45C1-832C-77C99013C7F4} - System32\Tasks\ProPCCleaner_Start => C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe [2015-07-09] (Pro PC Cleaner) <==== ATTENTION
Task: {8D2D9211-2FB9-4C3E-AB7B-548D36C48621} - System32\Tasks\Epuifuuva => C:\ProgramData\Epuifuuva\1.0.4.1\allomlom.exe [2015-07-13] ()
Task: {8E797C65-1C95-4E33-BD35-2B67CFA422CC} - System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6 => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.exe [2015-07-19] (Cinema PlusV18.07) <==== ATTENTION
Task: {8F31C890-7EC5-49DE-B3B9-7476E1ADAD00} - System32\Tasks\CIMT_daily_S-1-5-21-171533428-321824291-3300133993-1000 => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe [2015-06-19] () <==== ATTENTION
Task: {8FCE26CD-8109-40D2-84C9-EC4D6052F068} - System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3 => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3.exe [2015-07-19] (Cinema PlusV18.07) <==== ATTENTION
Task: {9A4092C6-EB94-4323-A130-EEA16B56DCD3} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-07-19] (globalUpdate) <==== ATTENTION
Task: {9A6CF26F-A597-49B7-8D92-A65B8241C305} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-10.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {9C38A35C-5BD6-4388-BC91-FED16EF2B1F4} - System32\Tasks\Games\UpdateCheck_S-1-5-21-171533428-321824291-3300133993-1000
Task: {9DC79A38-C865-43F3-9280-76CE0AC74000} - System32\Tasks\Uninstaller_SkipUac_Kathy => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2015-05-20] (IObit)
Task: {ACC2C1A7-672C-479B-91FF-EB6428145187} - System32\Tasks\SushiLeads => C:\Program Files (x86)\sushileads\ScheduledTask.exe
Task: {B3E4C79F-31B0-4CEC-8855-3A125AFCA943} - System32\Tasks\FYLVp79 => C:\Users\Kathy\AppData\Roaming\FYLVp79.exe [2015-04-20] () <==== ATTENTION
Task: {B50E6BBF-9E5C-4375-A579-BA67BBBB3632} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {BEFA25DD-72D7-4DCD-A9B5-609E7D25109A} - System32\Tasks\WordShark Auto Updater 1.10.0.20 Pending Update => C:\Program Files (x86)\WordShark_1.10.0.20\Update\WordSharkAutoUpdateClient.exe [2015-07-06] (WS) <==== ATTENTION
Task: {BFD5E5F7-A581-4986-AA96-C25F1196ED50} - System32\Tasks\JWRTYVMXFBIVCPWL => C:\ProgramData\Service1198\Service1198.exe [2015-06-28] () <==== ATTENTION
Task: {CC0931E2-8841-4E30-A9AC-B3C127345ED4} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2014-12-17] (IObit)
Task: {CD043251-2487-4869-A33C-C07A835E7188} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {CF6E7CAA-8B5F-4C52-A529-903EEF71BD58} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {D0A3F695-CFF9-4D08-A2A2-A4FC09D36290} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-5.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {D17B14BD-B3E2-4FD2-AFBE-644A6A3B1782} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [2014-12-09] (IObit)
Task: {D67D6154-0544-43C0-A94B-02B9B1A17E7C} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {E95208D8-3FF8-4D59-AFCB-CDC5937532DF} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-7 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-7.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {E9AADAD9-F283-4AA1-9839-E55321CC24D3} - System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7 => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7.exe [2015-07-19] (Cinema PlusV18.07) <==== ATTENTION
Task: {F4309D18-BE10-4EE4-A49A-13DC9F49921B} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {F48924F7-2B13-4189-BEFC-7813745D4972} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-07-19] (globalUpdate) <==== ATTENTION
Task: {F60157AF-D870-485B-87FD-5F992DA7ACD1} - System32\Tasks\GlobalUpdate-ywy2yzvxzgtjbth => C:\Users\Kathy\AppData\Roaming\ywy2yzvxzgtjbth\ywy2yzvxzgtjbth.exe [2015-07-13] () <==== ATTENTION
Task: {F6838031-AB36-4284-9FC7-8677F4B77864} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => c:\Program Files\Microsoft IntelliPoint\IPoint.exe [2011-08-01] (Microsoft Corporation)
Task: {F93A1729-BC6D-42A0-888E-D2BEB8D08BA5} - System32\Tasks\avastBCLRestartS-1-5-21-171533428-321824291-3300133993-1000 => Chrome.exe 
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user.job => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10.exe <==== ATTENTION
Task: C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3.job => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7.job => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-10.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-3.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-6.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-7.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\CIMT_daily_S-1-5-21-171533428-321824291-3300133993-1000.job => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
Task: C:\Windows\Tasks\CIMT_S-1-5-21-171533428-321824291-3300133993-1000.job => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\Crossbrowse.job => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION
Task: C:\Windows\Tasks\FYLVp79.job => C:\Users\Kathy\AppData\Roaming\FYLVp79.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GLQHQICXMFBVKQCB.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\JWRTYVMXFBIVCPWL.job => C:\ProgramData\Service1198\Service1198.exe <==== ATTENTION
Task: C:\Windows\Tasks\NLSAGZR1.job => C:\ProgramData\EpsanDrive\EpsanDrive.exe <==== ATTENTION
Task: C:\Windows\Tasks\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\WdEL9n2eiowr.job => C:\Users\Kathy\AppData\Roaming\WdEL9n2eiowr.exe <==== ATTENTION
AlternateDataStreams: C:\Windows\system32\Drivers\vfbhiosb.sys:changelist
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Cofvopjy => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\myradioplayer => ""="service"
 C:\Program Files (x86)\cpx
C:\Program Files (x86)\Smwyyntm1ndi1zdz
 C:\Program Files (x86)\MovieDea
C:\Program Files (x86)\Optimizer Pro 3.99
C:\Program Files (x86)\SearchProtect\
C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh
C:\Program Files (x86)\Crossbrowse
C:\Program Files (x86)\Iminent
C:\Windows\system32\myradioplayer64.dll
C:\Windows\SysWOW64\Cofvopjy.dll 
C:\Windows\SysWOW64\myradioplayer.dll
C:\Users\Kathy\AppData\Local\Ninja Loader
C:\Users\Kathy\AppData\Roaming\ASPackage
C:\Users\Kathy\AppData\Local\Temp\20150713
C:\Users\Kathy\AppData\Local\5670549A-1436745948-DE00-E918-1C7508113231
C:\ProgramData\caGSSMRD
C:\Program Files (x86)\WordShark_1.10.0.20
C:\Program Files\WajIEn
C:\Program Files (x86)\Coupoon
C:\ProgramData\1436760085
C:\Users\Kathy\AppData\Roaming\ASPackage
C:\Users\Kathy\AppData\Local\5670549A-1436745948-DE00-E918-1C7508113231
C:\Program Files (x86)\msrtn32
C:\Program Files (x86)\RadPlayer
C:\Program Files (x86)\Common Files\Umbrella
C:\Program Files (x86)\Common Files\IMGUpdater
C:\ProgramData\FlashBeat
C:\Program Files (x86)\dataup
C:\Program Files (x86)\gmsd_us_005010030\gmsd_us_005010030.exe
C:\Program Files (x86)\Smwyyntm1ndi1zdz\ywi2mzv2zhnjbdh.exe
C:\Program Files (x86)\gmsd_us_005010031\gmsd_us_005010031.exe
C:\Program Files (x86)\msrtn32\msrtn32.exe
C:\Program Files (x86)\StormWatch
C:\Users\Kathy\AppData\Local\SmartWeb
C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh
C:\Program Files (x86)\Ninja Loader
C:\ProgramData\EpsanDrive
C:\Program Files (x86)\Consumer Input
C:\Program Files (x86)\globalUpdate
C:\Users\Kathy\AppData\Local\ospd_us_014010029\upospd_us_014010029.exe
C:\Program Files (x86)\CinemaPlus-3.2cV13.07
C:\Program Files\shopperz12072015
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON 
CMD: ipconfig /flushdns 
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt 
CMD: ipconfig /release
CMD: ipconfig /renew 
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp: 
CMD: bitsadmin /reset /allusers
 
*****************
 
Restore point was successfully created.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\RadPlayer Tray => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\shopperz12072015 => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\shopperz1207201564 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\StormWatch => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\cpx => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\msrtn32 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\WinCheck => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_us_005010030 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mwyyntm1ndi1zdz => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_us_005010031 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\MovieDea => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SmartWeb => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\upospd_us_014010029.exe => value removed successfully
HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\Microsoft\Windows\CurrentVersion\Run\\NinjaLoader => value removed successfully
HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Optimizer Pro => value removed successfully
"C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll" => Value data removed successfully.
" C:\ProgramData\FlashBeat\FlashBeat64.dll" => Value data removed successfully.
"C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll" => Value data removed successfully.
" C:\ProgramData\FlashBeat\FlashBeat32.dll" => Value data removed successfully.
" C:\ProgramData\EpsanDrive\EpsanDrive32.dll" => Value data removed successfully.
" C:\PROGRA~3\{63B88~1\1173~1.1\tiso.dll" => Value data removed successfully.
C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bm.lnk => moved successfully.
"C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh\yxa2bzvwzf9jdth.exe" => Could not move.
C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk => moved successfully.
C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe not found.
C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk => moved successfully.
C:\Users\Kathy\AppData\Local\SmartWeb\SmartWebHelper.exe => moved successfully.
C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatch.lnk => moved successfully.
C:\Program Files (x86)\StormWatch\StormWatch.exe => moved successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. 
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-171533428-321824291-3300133993-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{84FF7BD6-B47F-46F8-9130-01B2696B36CB} => value removed successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\OldSearch" => key removed successfully
HKCR\CLSID\OldSearch => key not found. 
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}" => key removed successfully
HKCR\Wow6432Node\CLSID\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} => key not found. 
"HKU\S-1-5-21-171533428-321824291-3300133993-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => key removed successfully
HKCR\CLSID\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => key not found. 
"HKU\S-1-5-21-171533428-321824291-3300133993-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BC4A5ADC-08EE-4734-9171-5A5035FF16D7}" => key removed successfully
HKCR\CLSID\{BC4A5ADC-08EE-4734-9171-5A5035FF16D7} => key not found. 
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}" => key removed successfully
"HKCR\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}" => key removed successfully
"HKCR\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}" => key removed successfully
"HKCR\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c49ac435-5c4d-450f-aa56-cd31f96613b3}" => key removed successfully
"HKCR\CLSID\{c49ac435-5c4d-450f-aa56-cd31f96613b3}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}" => key removed successfully
HKCR\Wow6432Node\CLSID\{84FF7BD6-B47F-46F8-9130-01B2696B36CB} => key not found. 
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c49ac435-5c4d-450f-aa56-cd31f96613b3}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{c49ac435-5c4d-450f-aa56-cd31f96613b3}" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000019" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000020" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000015" => key removed successfully
"HKLM\Software\MozillaPlugins\@iqiyi.com/npclient" => key removed successfully
C:\IQIYI Video\LStyle\npclient.dll => moved successfully.
"HKLM\Software\MozillaPlugins\@iqiyi.com/npWebPlayer" => key removed successfully
C:\IQIYI Video\LStyle\npWebPlayer.dll => moved successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@iqiyi.com/npclient" => key removed successfully
C:\IQIYI Video\LStyle\npclient.dll not found.
"HKLM\Software\Wow6432Node\MozillaPlugins\@iqiyi.com/npWebPlayer" => key removed successfully
C:\IQIYI Video\LStyle\npWebPlayer.dll not found.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10" => key removed successfully
C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll => moved successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4" => key removed successfully
C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll not found.
"HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\MozillaPlugins\@iqiyi.com/npWebPlayer" => key removed successfully
C:\IQIYI Video\LStyle\npWebPlayer.dll not found.
"HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0" => key removed successfully
C:\Users\Kathy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll => moved successfully.
HKLM\Software\Mozilla\Firefox\Extensions\\{c49ac435-5c4d-450f-aa56-cd31f96613b3} => value removed successfully
C:\Program Files\shopperz12072015\Firefox => moved successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{c49ac435-5c4d-450f-aa56-cd31f96613b3} => value removed successfully
HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\Mozilla\Firefox\Extensions\\[email protected] => value removed successfully
C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12191.xpi => moved successfully.
HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\Mozilla\Firefox\Extensions\\[email protected] => value removed successfully
C:\Program Files (x86)\Ninja Loader\FireFox => moved successfully.
C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gegdfeiahlfolhcfioipjlkombmgbakh => moved successfully.
C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\papbadoldddalgcjcicnikcfenodpghp => moved successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\adpeheiliennogfclcgmchdfdmafjegc" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\cmlhbjpgeogifjnmlajdaealbdlfonah" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ehhlaekjfiiojlddgndcnefflngfmhen" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gihfmmedoddijgnhkgfgnkeohkpbipol" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl" => key removed successfully
C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx => moved successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nociobghckdhokecfeajdpimjeapnopn" => key removed successfully
46784c7a-2afb-4c2f-b299-133de9a46a66 => Service stopped successfully.
46784c7a-2afb-4c2f-b299-133de9a46a66 => service removed successfully
c31ed948 => service removed successfully
Cofvopjy => Service stopped successfully.
Cofvopjy => service removed successfully
consumerinput_update => service removed successfully
consumerinput_updatem => service removed successfully
CoupoonService64 => service removed successfully
csrcc => Service stopped successfully.
csrcc => service removed successfully
Dataup => Service stopped successfully.
Dataup => service removed successfully
FlashBeat => service removed successfully
globalUpdate => service removed successfully
globalUpdatem => service removed successfully
GlobalUpdater => Service stopped successfully.
GlobalUpdater => service removed successfully
IMService => Service stopped successfully.
IMService => service removed successfully
LosdyLijfeu => Unable to stop service.
LosdyLijfeu => service removed successfully
myradioplayer => Service stopped successfully.
myradioplayer => service removed successfully
NinjaLoaderService => Service stopped successfully.
NinjaLoaderService => service removed successfully
RadPlayerV1 => Service stopped successfully.
RadPlayerV1 => service removed successfully
RadPlayerV2 => service removed successfully
REhsGdKiASD => Unable to stop service.
REhsGdKiASD => service removed successfully
relibily => Service stopped successfully.
relibily => service removed successfully
serveras => Service stopped successfully.
serveras => service removed successfully
shopperz12072015 Updater => Service stopped successfully.
shopperz12072015 Updater => service removed successfully
StormWatch Update Service => Service stopped successfully.
StormWatch Update Service => service removed successfully
SWUpdater => Service stopped successfully.
SWUpdater => service removed successfully
UdvdPork => Service stopped successfully.
UdvdPork => service removed successfully
UpdateCheck => Service stopped successfully.
UpdateCheck => service removed successfully
WajIEn Monitor => Service stopped successfully.
WajIEn Monitor => service removed successfully
wbsvc => service removed successfully
windowsmanagementservice => Service stopped successfully.
windowsmanagementservice => service removed successfully
wssvc_1.10.0.20 => Service stopped successfully.
wssvc_1.10.0.20 => service removed successfully
SMUpdPlus => service removed successfully
cherimoya => Unable to stop service.
cherimoya => service removed successfully
SMUpdd => service removed successfully
vfbhiosb => service removed successfully
wsfd_vt_1_10_0_20 => Unable to stop service.
wsfd_vt_1_10_0_20 => service removed successfully
ywi2mzv2zhnjbdh => Unable to stop service.
ywi2mzv2zhnjbdh => service removed successfully
C:\Windows\system32\Drivers\vfbhiosb.sys => moved successfully.
C:\Users\Kathy\AppData\Local\CEF => moved successfully.
C:\Program Files (x86)\GUMBFC5.tmp => moved successfully.
C:\Program Files (x86)\GUTC294.tmp => moved successfully.
C:\Windows\TEMPcoral.vbs => moved successfully.
C:\ProgramData\Ninja Loader => moved successfully.
C:\Windows\SysWOW64\debug.log => moved successfully.
C:\Windows\Tasks\CIMT_S-1-5-21-171533428-321824291-3300133993-1000.job => moved successfully.
C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user.job => moved successfully.
C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 => moved successfully.
C:\Windows\Tasks\GLQHQICXMFBVKQCB.job => moved successfully.
C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job => moved successfully.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.job => moved successfully.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-6.job => moved successfully.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user.job => moved successfully.
C:\Windows\System32\Tasks\Optimizer Pro Schedule => moved successfully.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user.job => moved successfully.
C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job => moved successfully.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.job => moved successfully.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.job => moved successfully.
C:\ProgramData\boost_interprocess => moved successfully.
C:\Windows\SysWOW64\Cofvopjy.ini => moved successfully.
C:\Windows\SysWOW64\CofvopjyOff.ini => moved successfully.
C:\Windows\system32\CofvopjyOff.ini => moved successfully.
C:\Users\Kathy\AppData\Local\ospd_us_014010029 => moved successfully.
 
"C:\Users\Kathy\AppData\Local\mstrn32" folder move:
 
Could not move "C:\Users\Kathy\AppData\Local\mstrn32" => Scheduled to move on reboot.
 
C:\Windows\Tasks\WdEL9n2eiowr.job => moved successfully.
C:\Windows\Tasks\FYLVp79.job => moved successfully.
C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7.job => moved successfully.
C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3.job => moved successfully.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user.job => moved successfully.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.job => moved successfully.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7.job => moved successfully.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7.job => moved successfully.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3.job => moved successfully.
C:\Windows\Tasks\Crossbrowse.job => moved successfully.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user.job => moved successfully.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5.job => moved successfully.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7.job => moved successfully.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-7.job => moved successfully.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-3.job => moved successfully.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => moved successfully.
C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job => moved successfully.
C:\Windows\Tasks\JWRTYVMXFBIVCPWL.job => moved successfully.
C:\Windows\Tasks\NLSAGZR1.job => moved successfully.
C:\Windows\System32\Tasks\Epuifuuva => moved successfully.
C:\Users\Kathy\AppData\Local\Ninja Loader => moved successfully.
C:\ProgramData\ProductData => moved successfully.
"C:\Program Files (x86)\GUTC294.tmp" => File/Folder not found.
C:\Program Files (x86)\GUTFD53.tmp => moved successfully.
C:\Users\Kathy\AppData\Roaming\FYLVp79 => moved successfully.
C:\Users\Kathy\AppData\Roaming\FYLVp79.exe => moved successfully.
C:\Users\Kathy\AppData\Roaming\WdEL9n2eiowr => moved successfully.
C:\Users\Kathy\AppData\Roaming\WdEL9n2eiowr.exe => moved successfully.
C:\Users\Kathy\AppData\Local\nsiBAD8.tmp => moved successfully.
C:\Windows\Tasks\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{01A22A0D-37F6-4D85-A408-491ACA67BF31}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{01A22A0D-37F6-4D85-A408-491ACA67BF31}" => key removed successfully
C:\Windows\System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-6 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a1e5f7dc-19c6-44a2-882d-e75547499632-6" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{02956738-DE99-47D8-A6C6-DCEE22EE7C4B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02956738-DE99-47D8-A6C6-DCEE22EE7C4B}" => key removed successfully
C:\Windows\System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0473C0CA-9A3F-462C-9BB2-BB768544A91A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0473C0CA-9A3F-462C-9BB2-BB768544A91A}" => key removed successfully
C:\Windows\System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-3 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a1e5f7dc-19c6-44a2-882d-e75547499632-3" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0C67CC53-4D97-46D6-A447-A0C70698D63C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0C67CC53-4D97-46D6-A447-A0C70698D63C}" => key removed successfully
C:\Windows\System32\Tasks\WebBarUpdateTask => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WebBarUpdateTask" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{12826CD3-979A-4778-9E55-62298738037F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{12826CD3-979A-4778-9E55-62298738037F}" => key removed successfully
C:\Windows\System32\Tasks\WdEL9n2eiowr => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WdEL9n2eiowr" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{13C77BBA-4D9D-4CC4-9783-0F09749EBC89}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{13C77BBA-4D9D-4CC4-9783-0F09749EBC89}" => key removed successfully
C:\Windows\System32\Tasks\APSnotifierPP2 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP2" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{168DBC36-AAF6-4F39-8483-52C63048B4FE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{168DBC36-AAF6-4F39-8483-52C63048B4FE}" => key removed successfully
C:\Windows\System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1BEAFD01-BB2F-4D5D-A4CB-F3456C100409}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1BEAFD01-BB2F-4D5D-A4CB-F3456C100409}" => key removed successfully
C:\Windows\System32\Tasks\ConsumerInputUpdateTaskMachineUA => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ConsumerInputUpdateTaskMachineUA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1D2B5213-0A0B-4933-8409-5B6CCA9D31C4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D2B5213-0A0B-4933-8409-5B6CCA9D31C4}" => key removed successfully
C:\Windows\System32\Tasks\SMW_UpdateTask_Time_333833393739363037312d235b783432415b45345a2d6c => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMW_UpdateTask_Time_333833393739363037312d235b783432415b45345a2d6c" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1EC32D4B-9503-4E11-9581-F33F5490D6C8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EC32D4B-9503-4E11-9581-F33F5490D6C8}" => key removed successfully
C:\Windows\System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{25FCAB52-144F-4DF6-9ED8-A783CF9663E3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25FCAB52-144F-4DF6-9ED8-A783CF9663E3}" => key removed successfully
C:\Windows\System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{26C1D14B-D736-4340-AA04-29E5B0EE9912}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{26C1D14B-D736-4340-AA04-29E5B0EE9912}" => key removed successfully
C:\Windows\System32\Tasks\CIMT_S-1-5-21-171533428-321824291-3300133993-1000 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CIMT_S-1-5-21-171533428-321824291-3300133993-1000" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2C86BA2E-43EA-43C1-9CC7-DC321BFFF485}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2C86BA2E-43EA-43C1-9CC7-DC321BFFF485}" => key removed successfully
C:\Windows\System32\Tasks\Snmix => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Snmix" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{325746AD-5A6F-430F-8E30-6CD44422ABDB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{325746AD-5A6F-430F-8E30-6CD44422ABDB}" => key removed successfully
C:\Windows\System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{36F19701-E5F7-4483-856F-F95E73176541}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{36F19701-E5F7-4483-856F-F95E73176541}" => key removed successfully
C:\Windows\System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3C325D05-59F7-4AA8-A14C-0D30C25CACC4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C325D05-59F7-4AA8-A14C-0D30C25CACC4}" => key removed successfully
C:\Windows\System32\Tasks\Driver Booster SkipUAC (SYSTEM) => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (SYSTEM)" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{41F7B16E-395A-4581-81BD-04F429088AC9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41F7B16E-395A-4581-81BD-04F429088AC9}" => key removed successfully
C:\Windows\System32\Tasks\Driver Booster SkipUAC (Kathy) => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (Kathy)" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{423821BC-96E6-4D84-9341-34C7D6544576}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{423821BC-96E6-4D84-9341-34C7D6544576}" => key removed successfully
C:\Windows\System32\Tasks\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4315E182-2227-4C77-880F-D8ED0781664D}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4315E182-2227-4C77-880F-D8ED0781664D}" => key removed successfully
C:\Windows\System32\Tasks\NLSAGZR1 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NLSAGZR1" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{46EEB3FE-4979-4D71-B642-E6812F1A1B63}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{46EEB3FE-4979-4D71-B642-E6812F1A1B63}" => key removed successfully
C:\Windows\System32\Tasks\SMWPUpd => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMWPUpd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4F7AA969-E2FB-46AC-A550-70B132457A08}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4F7AA969-E2FB-46AC-A550-70B132457A08}" => key removed successfully
C:\Windows\System32\Tasks\Smp => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Smp" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{519D5601-B701-4EF4-942D-023EB0776066}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{519D5601-B701-4EF4-942D-023EB0776066}" => key removed successfully
C:\Windows\System32\Tasks\Optimizer Pro Schedule not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimizer Pro Schedule" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{536F625C-BFB1-4834-BC2B-BD6198974A9E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{536F625C-BFB1-4834-BC2B-BD6198974A9E}" => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{58BC472B-603B-41F5-A0F2-3D4FBD8E8B49}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{58BC472B-603B-41F5-A0F2-3D4FBD8E8B49}" => key removed successfully
C:\Windows\System32\Tasks\WebBarLaunchTask => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WebBarLaunchTask" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5AE88653-7D39-4018-A2D6-1B1865993C94}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5AE88653-7D39-4018-A2D6-1B1865993C94}" => key removed successfully
C:\Windows\System32\Tasks\BD634EFB-4435-4228-B1B1-B9F4709D5F79 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BD634EFB-4435-4228-B1B1-B9F4709D5F79" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5B84AF85-C877-4407-9B54-51E465C67CD3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B84AF85-C877-4407-9B54-51E465C67CD3}" => key removed successfully
C:\Windows\System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5BAFB821-7E9C-44DA-8FF3-BA06AA1A580A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5BAFB821-7E9C-44DA-8FF3-BA06AA1A580A}" => key removed successfully
C:\Windows\System32\Tasks\Adobe Flash Player Updater => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5D16852C-3009-4836-B678-96DD5F24BE7B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D16852C-3009-4836-B678-96DD5F24BE7B}" => key removed successfully
C:\Windows\System32\Tasks\ConsumerInputUpdateTaskMachineCore => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ConsumerInputUpdateTaskMachineCore" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{610A4D52-9E85-4E0B-A680-BEA500D4EF11}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{610A4D52-9E85-4E0B-A680-BEA500D4EF11}" => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{691E87A2-9D64-45C3-A667-ABE98310143F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{691E87A2-9D64-45C3-A667-ABE98310143F}" => key removed successfully
C:\Windows\System32\Tasks\GLQHQICXMFBVKQCB => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GLQHQICXMFBVKQCB" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6F7B2104-C5A2-4870-8DAA-94359F4B295E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F7B2104-C5A2-4870-8DAA-94359F4B295E}" => key removed successfully
C:\Windows\System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{80ECF25B-E055-4C3B-B841-3F10B6413105}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{80ECF25B-E055-4C3B-B841-3F10B6413105}" => key removed successfully
C:\Windows\System32\Tasks\Crossbrowse => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Crossbrowse" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{83886EC4-445C-4DB0-9EB6-83B465472564}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83886EC4-445C-4DB0-9EB6-83B465472564}" => key removed successfully
C:\Windows\System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{88726888-5908-4FB8-A3FA-9043CB5B1478}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{88726888-5908-4FB8-A3FA-9043CB5B1478}" => key removed successfully
C:\Windows\System32\Tasks\WordShark Auto Updater 1.10.0.20 Core => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WordShark Auto Updater 1.10.0.20 Core" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8C648E3B-AA13-45C1-832C-77C99013C7F4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8C648E3B-AA13-45C1-832C-77C99013C7F4}" => key removed successfully
C:\Windows\System32\Tasks\ProPCCleaner_Start => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProPCCleaner_Start" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{8D2D9211-2FB9-4C3E-AB7B-548D36C48621}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D2D9211-2FB9-4C3E-AB7B-548D36C48621}" => key removed successfully
C:\Windows\System32\Tasks\Epuifuuva not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Epuifuuva" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8E797C65-1C95-4E33-BD35-2B67CFA422CC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8E797C65-1C95-4E33-BD35-2B67CFA422CC}" => key removed successfully
C:\Windows\System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8F31C890-7EC5-49DE-B3B9-7476E1ADAD00}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8F31C890-7EC5-49DE-B3B9-7476E1ADAD00}" => key removed successfully
C:\Windows\System32\Tasks\CIMT_daily_S-1-5-21-171533428-321824291-3300133993-1000 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CIMT_daily_S-1-5-21-171533428-321824291-3300133993-1000" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8FCE26CD-8109-40D2-84C9-EC4D6052F068}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8FCE26CD-8109-40D2-84C9-EC4D6052F068}" => key removed successfully
C:\Windows\System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9A4092C6-EB94-4323-A130-EEA16B56DCD3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9A4092C6-EB94-4323-A130-EEA16B56DCD3}" => key removed successfully
C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9A6CF26F-A597-49B7-8D92-A65B8241C305}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9A6CF26F-A597-49B7-8D92-A65B8241C305}" => key removed successfully
C:\Windows\System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9C38A35C-5BD6-4388-BC91-FED16EF2B1F4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9C38A35C-5BD6-4388-BC91-FED16EF2B1F4}" => key removed successfully
C:\Windows\System32\Tasks\Games\UpdateCheck_S-1-5-21-171533428-321824291-3300133993-1000 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Games\UpdateCheck_S-1-5-21-171533428-321824291-3300133993-1000" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9DC79A38-C865-43F3-9280-76CE0AC74000}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9DC79A38-C865-43F3-9280-76CE0AC74000}" => key removed successfully
C:\Windows\System32\Tasks\Uninstaller_SkipUac_Kathy => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_Kathy" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ACC2C1A7-672C-479B-91FF-EB6428145187}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ACC2C1A7-672C-479B-91FF-EB6428145187}" => key removed successfully
C:\Windows\System32\Tasks\SushiLeads => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SushiLeads" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B3E4C79F-31B0-4CEC-8855-3A125AFCA943}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B3E4C79F-31B0-4CEC-8855-3A125AFCA943}" => key removed successfully
C:\Windows\System32\Tasks\FYLVp79 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FYLVp79" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B50E6BBF-9E5C-4375-A579-BA67BBBB3632}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B50E6BBF-9E5C-4375-A579-BA67BBBB3632}" => key removed successfully
C:\Windows\System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BEFA25DD-72D7-4DCD-A9B5-609E7D25109A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BEFA25DD-72D7-4DCD-A9B5-609E7D25109A}" => key removed successfully
C:\Windows\System32\Tasks\WordShark Auto Updater 1.10.0.20 Pending Update => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WordShark Auto Updater 1.10.0.20 Pending Update" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BFD5E5F7-A581-4986-AA96-C25F1196ED50}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFD5E5F7-A581-4986-AA96-C25F1196ED50}" => key removed successfully
C:\Windows\System32\Tasks\JWRTYVMXFBIVCPWL => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\JWRTYVMXFBIVCPWL" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CC0931E2-8841-4E30-A9AC-B3C127345ED4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CC0931E2-8841-4E30-A9AC-B3C127345ED4}" => key removed successfully
C:\Windows\System32\Tasks\Driver Booster Scan => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scan" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CD043251-2487-4869-A33C-C07A835E7188}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CD043251-2487-4869-A33C-C07A835E7188}" => key removed successfully
C:\Windows\System32\Tasks\APSnotifierPP1 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP1" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CF6E7CAA-8B5F-4C52-A529-903EEF71BD58}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CF6E7CAA-8B5F-4C52-A529-903EEF71BD58}" => key removed successfully
C:\Windows\System32\Tasks\APSnotifierPP3 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP3" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D0A3F695-CFF9-4D08-A2A2-A4FC09D36290}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D0A3F695-CFF9-4D08-A2A2-A4FC09D36290}" => key removed successfully
C:\Windows\System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a1e5f7dc-19c6-44a2-882d-e75547499632-5" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D17B14BD-B3E2-4FD2-AFBE-644A6A3B1782}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D17B14BD-B3E2-4FD2-AFBE-644A6A3B1782}" => key removed successfully
C:\Windows\System32\Tasks\Driver Booster Update => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Update" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D67D6154-0544-43C0-A94B-02B9B1A17E7C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D67D6154-0544-43C0-A94B-02B9B1A17E7C}" => key removed successfully
C:\Windows\System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E95208D8-3FF8-4D59-AFCB-CDC5937532DF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E95208D8-3FF8-4D59-AFCB-CDC5937532DF}" => key removed successfully
C:\Windows\System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-7 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a1e5f7dc-19c6-44a2-882d-e75547499632-7" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E9AADAD9-F283-4AA1-9839-E55321CC24D3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E9AADAD9-F283-4AA1-9839-E55321CC24D3}" => key removed successfully
C:\Windows\System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F4309D18-BE10-4EE4-A49A-13DC9F49921B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4309D18-BE10-4EE4-A49A-13DC9F49921B}" => key removed successfully
C:\Windows\System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F48924F7-2B13-4189-BEFC-7813745D4972}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F48924F7-2B13-4189-BEFC-7813745D4972}" => key removed successfully
C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F60157AF-D870-485B-87FD-5F992DA7ACD1}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F60157AF-D870-485B-87FD-5F992DA7ACD1}" => key removed successfully
C:\Windows\System32\Tasks\GlobalUpdate-ywy2yzvxzgtjbth => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GlobalUpdate-ywy2yzvxzgtjbth" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F6838031-AB36-4284-9FC7-8677F4B77864}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F6838031-AB36-4284-9FC7-8677F4B77864}" => key removed successfully
C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft_Hardware_Launch_IPoint_exe" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F93A1729-BC6D-42A0-888E-D2BEB8D08BA5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F93A1729-BC6D-42A0-888E-D2BEB8D08BA5}" => key removed successfully
C:\Windows\System32\Tasks\avastBCLRestartS-1-5-21-171533428-321824291-3300133993-1000 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avastBCLRestartS-1-5-21-171533428-321824291-3300133993-1000" => key removed successfully
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.job not found.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7.job not found.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user.job not found.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3.job not found.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.job not found.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user.job not found.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.job not found.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7.job not found.
C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user.job not found.
C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3.job not found.
C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job not found.
C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7.job not found.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.job not found.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7.job not found.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user.job not found.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-3.job not found.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5.job not found.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user.job not found.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-6.job not found.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-7.job not found.
C:\Windows\Tasks\Adobe Flash Player Updater.job => moved successfully.
C:\Windows\Tasks\APSnotifierPP1.job => moved successfully.
C:\Windows\Tasks\APSnotifierPP2.job => moved successfully.
C:\Windows\Tasks\APSnotifierPP3.job => moved successfully.
C:\Windows\Tasks\CIMT_daily_S-1-5-21-171533428-321824291-3300133993-1000.job => moved successfully.
C:\Windows\Tasks\CIMT_S-1-5-21-171533428-321824291-3300133993-1000.job not found.
C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job not found.
C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job not found.
C:\Windows\Tasks\Crossbrowse.job not found.
C:\Windows\Tasks\FYLVp79.job not found.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job not found.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => moved successfully.
C:\Windows\Tasks\GLQHQICXMFBVKQCB.job not found.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully.
C:\Windows\Tasks\JWRTYVMXFBIVCPWL.job not found.
C:\Windows\Tasks\NLSAGZR1.job not found.
C:\Windows\Tasks\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job not found.
C:\Windows\Tasks\WdEL9n2eiowr.job not found.
"C:\Windows\system32\Drivers\vfbhiosb.sys" => ":changelist" ADS not found.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\Cofvopjy" => key removed successfully
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\myradioplayer" => key removed successfully
C:\Program Files (x86)\cpx => moved successfully.
 
"C:\Program Files (x86)\Smwyyntm1ndi1zdz" folder move:
 
Could not move "C:\Program Files (x86)\Smwyyntm1ndi1zdz" => Scheduled to move on reboot.
 
C:\Program Files (x86)\MovieDea => moved successfully.
C:\Program Files (x86)\Optimizer Pro 3.99 => moved successfully.
C:\Program Files (x86)\SearchProtect => moved successfully.
 
"C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh" folder move:
 
Could not move "C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh" => Scheduled to move on reboot.
 
"C:\Program Files (x86)\Crossbrowse" => File/Folder not found.
C:\Program Files (x86)\Iminent => moved successfully.
C:\Windows\system32\myradioplayer64.dll => moved successfully.
C:\Windows\SysWOW64\Cofvopjy.dll => moved successfully.
C:\Windows\SysWOW64\myradioplayer.dll => moved successfully.
"C:\Users\Kathy\AppData\Local\Ninja Loader" => File/Folder not found.
 
"C:\Users\Kathy\AppData\Roaming\ASPackage" folder move:
 
Could not move "C:\Users\Kathy\AppData\Roaming\ASPackage" => Scheduled to move on reboot.
 
C:\Users\Kathy\AppData\Local\Temp\20150713 => moved successfully.
C:\Users\Kathy\AppData\Local\5670549A-1436745948-DE00-E918-1C7508113231 => moved successfully.
 
"C:\ProgramData\caGSSMRD" folder move:
 
Could not move "C:\ProgramData\caGSSMRD" => Scheduled to move on reboot.
 
C:\Program Files (x86)\WordShark_1.10.0.20 => moved successfully.
C:\Program Files\WajIEn => moved successfully.
C:\Program Files (x86)\Coupoon => moved successfully.
C:\ProgramData\1436760085 => moved successfully.
 
"C:\Users\Kathy\AppData\Roaming\ASPackage" folder move:
 
Could not move "C:\Users\Kathy\AppData\Roaming\ASPackage" => Scheduled to move on reboot.
 
"C:\Users\Kathy\AppData\Local\5670549A-1436745948-DE00-E918-1C7508113231" => File/Folder not found.
 
"C:\Program Files (x86)\msrtn32" folder move:
 
Could not move "C:\Program Files (x86)\msrtn32" => Scheduled to move on reboot.
 
C:\Program Files (x86)\RadPlayer => moved successfully.
C:\Program Files (x86)\Common Files\Umbrella => moved successfully.
C:\Program Files (x86)\Common Files\IMGUpdater => moved successfully.
C:\ProgramData\FlashBeat => moved successfully.
C:\Program Files (x86)\dataup => moved successfully.
C:\Program Files (x86)\gmsd_us_005010030\gmsd_us_005010030.exe => moved successfully.
C:\Program Files (x86)\Smwyyntm1ndi1zdz\ywi2mzv2zhnjbdh.exe => moved successfully.
C:\Program Files (x86)\gmsd_us_005010031\gmsd_us_005010031.exe => moved successfully.
C:\Program Files (x86)\msrtn32\msrtn32.exe => moved successfully.
 
"C:\Program Files (x86)\StormWatch" folder move:
 
Could not move "C:\Program Files (x86)\StormWatch" => Scheduled to move on reboot.
 
 
"C:\Users\Kathy\AppData\Local\SmartWeb" folder move:
 
Could not move "C:\Users\Kathy\AppData\Local\SmartWeb" => Scheduled to move on reboot.
 
 
"C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh" folder move:
 
Could not move "C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh" => Scheduled to move on reboot.
 
C:\Program Files (x86)\Ninja Loader => moved successfully.
 
"C:\ProgramData\EpsanDrive" folder move:
 
Could not move "C:\ProgramData\EpsanDrive" => Scheduled to move on reboot.
 
 
"C:\Program Files (x86)\Consumer Input" folder move:
 
Could not move "C:\Program Files (x86)\Consumer Input" => Scheduled to move on reboot.
 
 
"C:\Program Files (x86)\globalUpdate" folder move:
 
Could not move "C:\Program Files (x86)\globalUpdate" => Scheduled to move on reboot.
 
"C:\Users\Kathy\AppData\Local\ospd_us_014010029\upospd_us_014010029.exe" => File/Folder not found.
C:\Program Files (x86)\CinemaPlus-3.2cV13.07 => moved successfully.
 
"C:\Program Files\shopperz12072015" folder move:
 
Could not move "C:\Program Files\shopperz12072015" => Scheduled to move on reboot.
 
 
========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 
 
========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 
 
========= Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
 
========= Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 
 
========= RemoveProxy: =========
 
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-171533428-321824291-3300133993-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-171533428-321824291-3300133993-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
 
 
========= End of RemoveProxy: =========
 
 
=========  netsh advfirewall reset =========
 
Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 10107
Ok.
 
 
========= End of CMD: =========
 
 
=========  netsh advfirewall set allprofiles state ON =========
 
Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 10107
Ok.
 
 
========= End of CMD: =========
 
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
=========  netsh winsock reset catalog =========
 
Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 10107
 
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
 
 
========= End of CMD: =========
 
 
=========  netsh int ip reset c:\resetlog.txt =========
 
Reseting Global, OK!
Reseting Interface, OK!
Restart the computer to complete this action.
 
 
========= End of CMD: =========
 
 
=========  ipconfig /release =========
 
 
Windows IP Configuration
 
No operation can be performed on Local Area Connection while it has its media disconnected.
No operation can be performed on Wireless Network Connection while it has its media disconnected.
 
========= End of CMD: =========
 
 
=========  ipconfig /renew =========
 
 
Windows IP Configuration
 
No operation can be performed on Local Area Connection while it has its media disconnected.
No operation can be performed on Wireless Network Connection while it has its media disconnected.
 
========= End of CMD: =========
 
 
=========  netsh int ipv4 reset =========
 
There's no user specified settings to be reset.
 
 
========= End of CMD: =========
 
 
=========  netsh int ipv6 reset =========
 
Reseting Interface, OK!
Restart the computer to complete this action.
 
 
========= End of CMD: =========
 
 
=========  bitsadmin /reset /allusers =========
 
 
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
 
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
 
{95015F66-BB19-4D80-A73F-8412445E640E} canceled.
{2B49767F-0AD2-41C5-8953-48D8F9FF8FBE} canceled.
{CADDA9DA-2871-4398-BFF0-D6234D326DE2} canceled.
{DEC7F8C7-BE08-49B0-A655-AA179558BBF8} canceled.
{7ABD69DD-E802-44DC-9AA7-1217BFBA7470} canceled.
{32219307-FDAE-45E3-9E6E-774E99B4A811} canceled.
{E346774C-6D44-4F44-8885-49174D0BE938} canceled.
{0891396F-EC29-40D2-B61F-59A058112390} canceled.
{B114875B-35CD-45FF-9F3F-35F8F041C808} canceled.
{A68AAF1E-7273-4F54-840F-81699556946B} canceled.
{49766B9F-739A-46FF-8EFB-43D601B165A2} canceled.
{75CDE805-74D1-46F1-8E36-30DFEA1EFB6B} canceled.
{4F9C66D6-52C0-448E-8A04-EFE974846456} canceled.
{F85CDF05-2640-4787-A775-71F8487DD5AE} canceled.
{5C6E4274-82F9-4CFA-A8DE-BD470D94CEB6} canceled.
{87B4A5C7-A277-4E03-82DE-B1D1210A06A4} canceled.
{6B3B6659-486F-4F35-88F3-06FA918D2EE0} canceled.
{4ECEB7CF-AF5D-4DF9-B5FB-5C22AD9BD1EB} canceled.
{6A490EFA-7249-43EC-A040-4DD960A4AF18} canceled.
{8D65F036-4457-4426-92C7-13F15AD02259} canceled.
{B9ACED6E-2F67-4957-8329-079DB5D2FA96} canceled.
{6F64B517-63F3-4610-9190-8BA5ADD5AAD7} canceled.
{FE1B6B44-188F-47B3-8F9F-41071A7D2173} canceled.
{195534A1-2B13-4BF1-802E-C5BBFF636714} canceled.
{2D5EC538-77DF-4857-9ED1-A8904CC4E187} canceled.
{51951F1D-94C6-446D-9DC1-37650D5C0238} canceled.
{FCB02259-3B98-4135-9E32-9667B8089759} canceled.
{9E5D8FC3-44CF-439E-9FC4-EC2CB5A1AD61} canceled.
{5897511A-6464-4500-9B85-9B18168437E9} canceled.
{4DEB0EE5-F7B1-4E39-9DA0-02F180D89AD9} canceled.
{633F5717-9A04-4356-BE02-4EB2CFEB4B1E} canceled.
{DAD19FF0-7EAE-4022-9BEE-5E8E8DC51722} canceled.
{9E2093C5-DAE9-4160-BB53-693BDA8A4B2F} canceled.
{74D24FEF-5C68-48BB-9CD8-0DE56BD985F9} canceled.
{7D5BCCF6-0A50-4253-9026-95723C4FF948} canceled.
{D1B647F0-4274-4793-B9E9-66785EA28E8A} canceled.
{2A3EB26A-4730-4A0B-849B-A6784956A600} canceled.
{33F51C3A-5D19-4C37-A546-3990BFB2DF3C} canceled.
{ED35E099-03DD-4EAD-9C31-DE8027D3AE2E} canceled.
{F0D30050-00CC-4118-9CE0-2ECF4A9E1F59} canceled.
{0254B0EE-A274-482D-9E7F-A88CF6F4D148} canceled.
{65F13A23-E8BD-4EC6-81CD-F703085521B3} canceled.
{9684FB73-C288-47C4-A608-61AF94A8056D} canceled.
{CB02DF5F-2219-4906-A342-C7EB6183BB30} canceled.
{34846892-CDB1-4DA2-AB4F-DF9BFA5DE74F} canceled.
{4E31D2DE-E889-4D46-AD18-714D9A191E48} canceled.
{025661F3-5B3B-446D-81B6-319C483CEEC9} canceled.
{C994BFA4-AAEE-47F3-8AFD-4E88DEC95397} canceled.
{EC5A092A-6EFD-4D88-B8BB-D9C4C4061E60} canceled.
{D7CD537A-4D08-49E7-9014-E3D8D701E716} canceled.
{60FEEA54-B256-4935-83CD-2A198E401300} canceled.
{7603AAFD-CC58-42A8-8BA8-3DF606F56963} canceled.
{D1B9A369-3A1B-4635-A656-3D3D3D69F1DE} canceled.
{528DB515-8618-45F4-A9E0-DDAE7312B54E} canceled.
{AAC1AB3D-A665-4EF7-8DD7-E6D046D6E974} canceled.
55 out of 55 jobs canceled.
 
========= End of CMD: =========
 
 
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-08-19 20:04:09)<=
 
==> ATTENTION: System is not rebooted.
"C:\Users\Kathy\AppData\Local\mstrn32" => Could not move
"C:\Program Files (x86)\Smwyyntm1ndi1zdz" => Could not move
"C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh" => Could not move
"C:\Users\Kathy\AppData\Roaming\ASPackage" => Could not move
"C:\ProgramData\caGSSMRD" => Could not move
"C:\Users\Kathy\AppData\Roaming\ASPackage" => Could not move
"C:\Program Files (x86)\msrtn32" => Could not move
"C:\Program Files (x86)\StormWatch" => Could not move
"C:\Users\Kathy\AppData\Local\SmartWeb" => Could not move
"C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh" => Could not move
"C:\ProgramData\EpsanDrive" => Could not move
"C:\Program Files (x86)\Consumer Input" => Could not move
"C:\Program Files (x86)\globalUpdate" => Could not move
"C:\Program Files\shopperz12072015" => Could not move
 
==== End of Fixlog 20:04:38 ====
 
AdwCleanerS1
 

# AdwCleaner v5.002 - Logfile created 19/08/2015 at 22:41:30
# Updated 18/08/2015 by Xplode
# Database : 2015-08-14.3 [Local]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Kathy - KATHY-PC
# Running from : C:\Users\Kathy\Desktop\AdwCleaner.exe
# Option : Scan
 
***** [ Services ] *****
 
Service Found : bsdriver
Service Found : cherimoya
Service Found : consumerinput_update
Service Found : consumerinput_updatem
Service Found : csrcc
Service Found : globalUpdate
Service Found : globalUpdatem
Service Found : GlobalUpdater
Service Found : netfilter64
Service Found : SMUpdd
Service Found : StormWatch Update Service
Service Found : SWUpdater
Service Found : wbsvc
Service Found : FlashBeat
Service Found : CoupoonService64
Service Found : SMUpdPlus
Service Found : IMService
Service Found : UpdateCheck
Service Found : Cofvopjy
Service Found : WajIEn Monitor
 
***** [ Folders ] *****
 
Folder Found : C:\FinanceAlert
Folder Found : C:\IQIYI Video
Folder Found : C:\Program Files\WebBar
Folder Found : C:\Program Files\coupoon
Folder Found : C:\Program Files (x86)\globalUpdate
Folder Found : C:\Program Files (x86)\StormWatch
Folder Found : C:\Program Files (x86)\ORBTR
Folder Found : C:\Program Files (x86)\Consumer Input
Folder Found : C:\Program Files (x86)\MyPCBU
Folder Found : C:\Program Files (x86)\app_setup
Folder Found : C:\Program Files (x86)\Hades
Folder Found : C:\Program Files (x86)\Itibiti Soft Phone
Folder Found : C:\Program Files (x86)\CinemaPlus-3.2cV18.07
Folder Found : C:\Program Files\Common Files\Goobzo
Folder Found : C:\ProgramData\Browser
Folder Found : C:\ProgramData\FinanceAlert
Folder Found : C:\ProgramData\IQIYI Video
Folder Found : C:\ProgramData\InstallSightSDK
Folder Found : C:\ProgramData\SearchModulePlus
Folder Found : C:\ProgramData\radio
Folder Found : C:\ProgramData\EpsanDrive
Folder Found : C:\ProgramData\MovieDeaConfig
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StormWatch
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UpdateAdmin
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajIEn
Folder Found : C:\Users\Kathy\AppData\Local\globalUpdate
Folder Found : C:\Users\Kathy\AppData\Local\SearchProtect
Folder Found : C:\Users\Kathy\AppData\Local\StormWatch
Folder Found : C:\Users\Kathy\AppData\Local\Weather_Protector_LLC
Folder Found : C:\Users\Kathy\AppData\Local\SmartWeb
Folder Found : C:\Users\Kathy\AppData\Local\Consumer Input
Folder Found : C:\Users\Kathy\AppData\Local\FinanceAlert
Folder Found : C:\Users\Kathy\AppData\Local\WebBar
Folder Found : C:\Users\Kathy\AppData\Local\Crossbrowse
Folder Found : C:\Users\Kathy\AppData\Local\avabvexvac
Folder Found : C:\Users\Kathy\AppData\Local\YSearchUtil
Folder Found : C:\Users\Kathy\AppData\Local\SysassistByHotWheel
Folder Found : C:\Users\Kathy\AppData\Local\5670549A-1436745935-DE00-E918-1C7508113231
Folder Found : C:\Users\Kathy\AppData\Local\Temp\Iminent
Folder Found : C:\Users\Kathy\AppData\LocalLow\SmartWeb
Folder Found : C:\Users\Kathy\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
Folder Found : C:\Users\Kathy\AppData\Roaming\AnyProtectEx
Folder Found : C:\Users\Kathy\AppData\Roaming\ASPackage
Folder Found : C:\Users\Kathy\AppData\Roaming\IQIYI Video
Folder Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormWatch
Folder Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASPackage
Folder Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MovieDea
Folder Found : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\StormWatch
Folder Found : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\YSearchUtil
 
***** [ Files ] *****
 
File Found : C:\END
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ehhlaekjfiiojlddgndcnefflngfmhen_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_papbadoldddalgcjcicnikcfenodpghp_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_papbadoldddalgcjcicnikcfenodpghp_0.localstorage-journal
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_papbadoldddalgcjcicnikcfenodpghp_0
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\papbadoldddalgcjcicnikcfenodpghp
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jdkokpcldhneihjdhigfjmoeojkdcbmg_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nociobghckdhokecfeajdpimjeapnopn_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_adpeheiliennogfclcgmchdfdmafjegc_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gegdfeiahlfolhcfioipjlkombmgbakh_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gegdfeiahlfolhcfioipjlkombmgbakh_0.localstorage-journal
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_gegdfeiahlfolhcfioipjlkombmgbakh_0
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gegdfeiahlfolhcfioipjlkombmgbakh
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_home.tb.ask.com_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_myscrapnook.dl.tb.ask.com_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_premierdownloadmanager.dl.tb.ask.com_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.cassiopessa.com_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Temp\UPDATETASK.EXE
File Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\crossbrowse.lnk
File Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Knctr.lnk
File Found : C:\Users\Public\Desktop\Knctr.lnk
File Found : C:\Windows\apppatch\apppatch64\vcldr64.dll
File Found : C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
File Found : C:\Windows\AppPatch\nbin\VC32Loader.dll
File Found : C:\Windows\Sysnative\drivers\bsdriver.sys
File Found : C:\Windows\Sysnative\drivers\cherimoya.sys
File Found : C:\Windows\Sysnative\drivers\netfilter64.sys
 
***** [ Shortcuts ] *****
 
Shortcut Infected : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk ( hxxp://www-searching.com/?s=F7Dzbuzdk00CN1,bebc7f3d-aee9-4b42-a9e1-f02206ddae60,&pi=3 )
Shortcut Infected : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk ( hxxp://www-searching.com/?s=F7Dzbuzdk00CN1,bebc7f3d-aee9-4b42-a9e1-f02206ddae60,&pi=3 )
Shortcut Infected : C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ( hxxp://www-searching.com/?s=F7Dzbuzdk00CN1,bebc7f3d-aee9-4b42-a9e1-f02206ddae60,&pi=3 )
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
Key Found : HKLM\SOFTWARE\Classes\AppID\CptUrlPassthru.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\dca-bho.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\Iminent.WebBooster.InternetExplorer.DLL
Key Found : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor
Key Found : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor.1
Key Found : HKLM\SOFTWARE\Classes\dcabho.Dca
Key Found : HKLM\SOFTWARE\Classes\dcabho.Dca.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\Iminent
Key Found : HKLM\SOFTWARE\Classes\IminentWebBooster.BrowserHelperObject
Key Found : HKLM\SOFTWARE\Classes\IminentWebBooster.BrowserHelperObject.1
Key Found : HKLM\SOFTWARE\Classes\IminentWebBooster.ScriptExtender
Key Found : HKLM\SOFTWARE\Classes\IminentWebBooster.ScriptExtender.1
Key Found : HKLM\SOFTWARE\Classes\PCProxy.DataContainer
Key Found : HKLM\SOFTWARE\Classes\AppID\globalupdate.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\smu.exe
Key Found : HKLM\SOFTWARE\Classes\HCDNProxy
Key Found : HKLM\SOFTWARE\276f7b6a-57ac-4835-a899-bb16f1998207
Key Found : HKLM\SOFTWARE\76fbede2-4201-4105-b699-b6e1cfa0842d
Key Found : HKLM\SOFTWARE\77265a05-c503-42c6-9008-ccb4c776410f
Key Found : HKLM\SOFTWARE\8b7efd01-8cc0-4a74-83c0-195ca4a69f62
Key Found : HKLM\SOFTWARE\cc176909-f20b-4492-db14-910bce233454
Key Found : HKLM\SOFTWARE\cf36c35d-fd9e-40ab-bee6-4a2f89864f9d
Key Found : HKLM\SOFTWARE\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11}
Key Found : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\AppID\{9DC8FA51-B596-4F77-802C-5B295919C205}
Key Found : HKLM\SOFTWARE\Classes\AppID\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
Key Found : HKLM\SOFTWARE\Classes\AppID\{DD7C44CC-0F60-4FD9-A38F-5CF30D698AC2}
Key Found : HKLM\SOFTWARE\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}
Key Found : HKLM\SOFTWARE\Classes\AppID\{4D6A5312-AB4D-41AA-8BED-0E019B87CA11}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3E28F712-0D6C-4EE3-AC8C-8F060F5D7C33}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6CE321DA-DC11-45C6-A0FC-4E8A7D978ABC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EEBC7FF-67DA-4B90-9251-C2C5696E4B48}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{74137531-80F7-406F-9543-7D11385FA8C8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{832599B2-55BF-4437-8F3E-030CF5AEB262}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B1A429DB-FB06-4645-B7C0-0CC405EAD3CD}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DD67706E-819E-4EBD-BF8D-6D6147CC7A49}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F62A4AF9-58B4-4FEC-89CC-D717A547D8E8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{085CB97F-6D0B-487D-B94C-E11A736C38CE}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CF3CDEFB-31BE-43AE-B064-B9C62C883259}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D96C1D26-5CDF-4506-9244-57233C3984DF}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7D8DAE88-BC05-4578-8C29-E541FFBA5757}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A2970C7C-8392-4E6F-8B51-B763CF38E13C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EDBF8C0-C94C-4A13-956F-E393BCA5BA4B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Found : HKLM\SOFTWARE\Classes\Interface\{22511E2E-7970-414E-BC7C-28D16C4AF54D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{23C5311E-016D-4999-BCB1-499898429D6C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2C4B6DB8-6413-403B-A038-16A352CFE8B9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{46803190-228D-470E-90FE-F5E0CEA9C4F2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Found : HKLM\SOFTWARE\Classes\Interface\{5180FE16-2E09-497B-9C8B-5A6F029ECECB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A4F6E1B3-469E-46EF-A936-FBA9D5EFD2B9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C97AF157-6A27-4F57-9D47-E2D3E4761B77}
Key Found : HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{ED0D2C81-7DB5-4599-B7C0-1033418B5672}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E4C3E50F-5761-4BF8-95A0-939A819DF1C3}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D96C1D26-5CDF-4506-9244-57233C3984DF}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{7BAB653D-88FB-4F60-AFC2-8E6FD59FAFF3}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A9CAF365-EA35-45DA-BD8B-2EFA09D374AC}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{ED721A76-8160-4DA0-A18E-7FD7C4574774}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9AE7A6AE-162E-44C4-9A2B-A6B4EF19909D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B6360BD3-5CD0-40D3-BD87-DAFF37889F50}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E6F928E4-B672-4F3A-8CA2-53C4259235DE}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{14EF423E-3EE8-44AE-9337-07AC3F27B744}
Key Found : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C49AC435-5C4D-450F-AA56-CD31F96613B3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C49AC435-5C4D-450F-AA56-CD31F96613B3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}]
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E6A8DA1-2731-465B-B036-B9E16EF26CAC}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAC94FEE-45B4-4FD4-9EEA-D8978EC96C6E}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{085CB97F-6D0B-487D-B94C-E11A736C38CE}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{A2970C7C-8392-4E6F-8B51-B763CF38E13C}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5CD76C57-6893-478A-B776-47E7C82504BE}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{22511E2E-7970-414E-BC7C-28D16C4AF54D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{23C5311E-016D-4999-BCB1-499898429D6C}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{2C4B6DB8-6413-403B-A038-16A352CFE8B9}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{46803190-228D-470E-90FE-F5E0CEA9C4F2}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{5180FE16-2E09-497B-9C8B-5A6F029ECECB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{A4F6E1B3-469E-46EF-A936-FBA9D5EFD2B9}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C97AF157-6A27-4F57-9D47-E2D3E4761B77}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{ED0D2C81-7DB5-4599-B7C0-1033418B5672}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{E4C3E50F-5761-4BF8-95A0-939A819DF1C3}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{D96C1D26-5CDF-4506-9244-57233C3984DF}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1E6A8DA1-1731-465B-B036-B9E16EF26CAC}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E6A8DA1-2731-465B-B036-B9E16EF26CAC}
Key Found : HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\Compete
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\coupoon
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
Key Found : HKCU\Software\AnyProtect
Key Found : HKCU\Software\Compete
Key Found : HKCU\Software\Conduit_Search_Protect
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\Iminent
Key Found : HKCU\Software\InstalledBrowserExtensions
Key Found : HKCU\Software\Microsoft\KanarCore
Key Found : HKCU\Software\NpApp
Key Found : HKCU\Software\Optimizer Pro
Key Found : HKCU\Software\Tutorials
Key Found : HKCU\Software\TutoTag
Key Found : HKCU\Software\StormWatchApp
Key Found : HKCU\Software\WajIEnhance
Key Found : HKCU\Software\Super Optimizer
Key Found : HKCU\Software\CrossBrowser
Key Found : HKCU\Software\Crossbrowse
Key Found : HKCU\Software\YorkNewCin
Key Found : HKCU\Software\HighDefAction
Key Found : HKCU\Software\ArenaHD
Key Found : HKCU\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}
Key Found : HKCU\Software\QyGameClient
Key Found : HKCU\Software\CinemaPlus-3.2cV18.07
Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKCU\Software\AppDataLow\Software\Compete
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\AppDataLow\Software\SmartWeb
Key Found : HKLM\SOFTWARE\AppDataLow\SOFTWARE\Crossrider
Key Found : HKLM\SOFTWARE\AppDataLow\SOFTWARE\_CrossriderRegNamePlaceHolder_
Key Found : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Found : HKLM\SOFTWARE\CompeteInc
Key Found : HKLM\SOFTWARE\GlobalUpdate
Key Found : HKLM\SOFTWARE\IMGUPDATER
Key Found : HKLM\SOFTWARE\Iminent
Key Found : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : HKLM\SOFTWARE\NpApp
Key Found : HKLM\SOFTWARE\SearchProtect
Key Found : HKLM\SOFTWARE\Tutorials
Key Found : HKLM\SOFTWARE\Umbrella
Key Found : HKLM\SOFTWARE\StormWatchApp
Key Found : HKLM\SOFTWARE\StormWatch
Key Found : HKLM\SOFTWARE\GAMESDESKTOP
Key Found : HKLM\SOFTWARE\FlashBeat
Key Found : HKLM\SOFTWARE\Crossbrowse
Key Found : HKLM\SOFTWARE\SearchModulePlus
Key Found : HKLM\SOFTWARE\coupoon
Key Found : HKLM\SOFTWARE\YorkNewCin
Key Found : HKLM\SOFTWARE\HighDefAction
Key Found : HKLM\SOFTWARE\Universal
Key Found : HKLM\SOFTWARE\Hades
Key Found : HKLM\SOFTWARE\ArenaHD
Key Found : HKLM\SOFTWARE\MovieDea
Key Found : HKLM\SOFTWARE\{AA2C4D29-36C3-48AB-8A25-181CF7483597}
Key Found : HKLM\SOFTWARE\Br MediaPlayer
Key Found : HKLM\SOFTWARE\WajIEn
Key Found : HKLM\SOFTWARE\CinemaPlus-3.2cV18.07
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ConvertAd
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StormWatch
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SmartWeb
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FinanceAlert
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wincheck
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Consumer Input Installer
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBeat
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ASPackage
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hades
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7D7D6742-5B49-4454-9E9B-748E731E741A}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EpsanDrive
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MovieDea
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{49F8B4F8-0CD4-4BE4-A9E8-B13A071F7C90}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WajIEn
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{49F8B4F8-0CD4-4BE4-A9E8-B13A071F7C90}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaPlus-3.2cV18.07
Key Found : [x64] HKCU\Software\AnyProtect
Key Found : [x64] HKCU\Software\Compete
Key Found : [x64] HKCU\Software\Conduit_Search_Protect
Key Found : [x64] HKCU\Software\GlobalUpdate
Key Found : [x64] HKCU\Software\Iminent
Key Found : [x64] HKCU\Software\InstalledBrowserExtensions
Key Found : [x64] HKCU\Software\Microsoft\KanarCore
Key Found : [x64] HKCU\Software\NpApp
Key Found : [x64] HKCU\Software\Optimizer Pro
Key Found : [x64] HKCU\Software\Tutorials
Key Found : [x64] HKCU\Software\TutoTag
Key Found : [x64] HKCU\Software\StormWatchApp
Key Found : [x64] HKCU\Software\WajIEnhance
Key Found : [x64] HKCU\Software\Super Optimizer
Key Found : [x64] HKCU\Software\CrossBrowser
Key Found : [x64] HKCU\Software\Crossbrowse
Key Found : [x64] HKCU\Software\YorkNewCin
Key Found : [x64] HKCU\Software\HighDefAction
Key Found : [x64] HKCU\Software\ArenaHD
Key Found : [x64] HKCU\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}
Key Found : [x64] HKCU\Software\QyGameClient
Key Found : [x64] HKCU\Software\CinemaPlus-3.2cV18.07
Key Found : [x64] HKLM\SOFTWARE\Iminent
Key Found : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : [x64] HKLM\SOFTWARE\FlashBeat
Key Found : [x64] HKLM\SOFTWARE\WebBar
Key Found : [x64] HKLM\SOFTWARE\SearchModulePlus
Key Found : [x64] HKLM\SOFTWARE\coupoon
Key Found : [x64] HKLM\SOFTWARE\YorkNewCin
Key Found : [x64] HKLM\SOFTWARE\HighDefAction
Key Found : [x64] HKLM\SOFTWARE\ArenaHD
Key Found : [x64] HKLM\SOFTWARE\{AA2C4D29-36C3-48AB-8A25-181CF7483597}
Key Found : [x64] HKLM\SOFTWARE\WajIEn
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0BCE8B0A-1E76-44E5-9909-3CF804D92E4D}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GLOBALUPDATE.EXE
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9}
 
***** [ Web browsers ] *****
 
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : trovi.search
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : www-searching.com_
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : www-searching.com
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider] Found : hxxp://www.iminent.com/Content/Images/favicon.ico?2fdde4
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider_Data] Found : hxxp://start.iminent.com/?appId=8437c40c-c891-4a5e-8eea-ca8568502d51&ref=toolbox&q={searchTerms}
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Homepage] Found : hxxp://start.iminent.com/?appId=8437c40c-c891-4a5e-8eea-ca8568502d51
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://start.iminent.com/?appId=8437c40c-c891-4a5e-8eea-ca8568502d51",
      "hxxp://www.trovi.com/?gd=&ctid=CT3333887&octid=EB_ORIGINAL_CTID&ISID=M1890E6BC-BF65-41CA-B1ED-FCA8EC054D11&SearchSource=55&CUI=&UM=8&UP=SPA98636E4-750F-401C-BC08-F5A740811DAD&D=071415&SSPV=SP30339T2B_sp_ch
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [32483 bytes] ##########
 
 
AdwCleanerC1
 

# AdwCleaner v5.002 - Logfile created 19/08/2015 at 22:41:30
# Updated 18/08/2015 by Xplode
# Database : 2015-08-14.3 [Local]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Kathy - KATHY-PC
# Running from : C:\Users\Kathy\Desktop\AdwCleaner.exe
# Option : Scan
 
***** [ Services ] *****
 
Service Found : bsdriver
Service Found : cherimoya
Service Found : consumerinput_update
Service Found : consumerinput_updatem
Service Found : csrcc
Service Found : globalUpdate
Service Found : globalUpdatem
Service Found : GlobalUpdater
Service Found : netfilter64
Service Found : SMUpdd
Service Found : StormWatch Update Service
Service Found : SWUpdater
Service Found : wbsvc
Service Found : FlashBeat
Service Found : CoupoonService64
Service Found : SMUpdPlus
Service Found : IMService
Service Found : UpdateCheck
Service Found : Cofvopjy
Service Found : WajIEn Monitor
 
***** [ Folders ] *****
 
Folder Found : C:\FinanceAlert
Folder Found : C:\IQIYI Video
Folder Found : C:\Program Files\WebBar
Folder Found : C:\Program Files\coupoon
Folder Found : C:\Program Files (x86)\globalUpdate
Folder Found : C:\Program Files (x86)\StormWatch
Folder Found : C:\Program Files (x86)\ORBTR
Folder Found : C:\Program Files (x86)\Consumer Input
Folder Found : C:\Program Files (x86)\MyPCBU
Folder Found : C:\Program Files (x86)\app_setup
Folder Found : C:\Program Files (x86)\Hades
Folder Found : C:\Program Files (x86)\Itibiti Soft Phone
Folder Found : C:\Program Files (x86)\CinemaPlus-3.2cV18.07
Folder Found : C:\Program Files\Common Files\Goobzo
Folder Found : C:\ProgramData\Browser
Folder Found : C:\ProgramData\FinanceAlert
Folder Found : C:\ProgramData\IQIYI Video
Folder Found : C:\ProgramData\InstallSightSDK
Folder Found : C:\ProgramData\SearchModulePlus
Folder Found : C:\ProgramData\radio
Folder Found : C:\ProgramData\EpsanDrive
Folder Found : C:\ProgramData\MovieDeaConfig
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StormWatch
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UpdateAdmin
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajIEn
Folder Found : C:\Users\Kathy\AppData\Local\globalUpdate
Folder Found : C:\Users\Kathy\AppData\Local\SearchProtect
Folder Found : C:\Users\Kathy\AppData\Local\StormWatch
Folder Found : C:\Users\Kathy\AppData\Local\Weather_Protector_LLC
Folder Found : C:\Users\Kathy\AppData\Local\SmartWeb
Folder Found : C:\Users\Kathy\AppData\Local\Consumer Input
Folder Found : C:\Users\Kathy\AppData\Local\FinanceAlert
Folder Found : C:\Users\Kathy\AppData\Local\WebBar
Folder Found : C:\Users\Kathy\AppData\Local\Crossbrowse
Folder Found : C:\Users\Kathy\AppData\Local\avabvexvac
Folder Found : C:\Users\Kathy\AppData\Local\YSearchUtil
Folder Found : C:\Users\Kathy\AppData\Local\SysassistByHotWheel
Folder Found : C:\Users\Kathy\AppData\Local\5670549A-1436745935-DE00-E918-1C7508113231
Folder Found : C:\Users\Kathy\AppData\Local\Temp\Iminent
Folder Found : C:\Users\Kathy\AppData\LocalLow\SmartWeb
Folder Found : C:\Users\Kathy\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
Folder Found : C:\Users\Kathy\AppData\Roaming\AnyProtectEx
Folder Found : C:\Users\Kathy\AppData\Roaming\ASPackage
Folder Found : C:\Users\Kathy\AppData\Roaming\IQIYI Video
Folder Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormWatch
Folder Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASPackage
Folder Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MovieDea
Folder Found : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\StormWatch
Folder Found : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\YSearchUtil
 
***** [ Files ] *****
 
File Found : C:\END
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ehhlaekjfiiojlddgndcnefflngfmhen_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_papbadoldddalgcjcicnikcfenodpghp_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_papbadoldddalgcjcicnikcfenodpghp_0.localstorage-journal
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_papbadoldddalgcjcicnikcfenodpghp_0
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\papbadoldddalgcjcicnikcfenodpghp
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jdkokpcldhneihjdhigfjmoeojkdcbmg_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nociobghckdhokecfeajdpimjeapnopn_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_adpeheiliennogfclcgmchdfdmafjegc_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gegdfeiahlfolhcfioipjlkombmgbakh_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gegdfeiahlfolhcfioipjlkombmgbakh_0.localstorage-journal
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_gegdfeiahlfolhcfioipjlkombmgbakh_0
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gegdfeiahlfolhcfioipjlkombmgbakh
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_home.tb.ask.com_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_myscrapnook.dl.tb.ask.com_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_premierdownloadmanager.dl.tb.ask.com_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.cassiopessa.com_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Temp\UPDATETASK.EXE
File Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\crossbrowse.lnk
File Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Knctr.lnk
File Found : C:\Users\Public\Desktop\Knctr.lnk
File Found : C:\Windows\apppatch\apppatch64\vcldr64.dll
File Found : C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
File Found : C:\Windows\AppPatch\nbin\VC32Loader.dll
File Found : C:\Windows\Sysnative\drivers\bsdriver.sys
File Found : C:\Windows\Sysnative\drivers\cherimoya.sys
File Found : C:\Windows\Sysnative\drivers\netfilter64.sys
 
***** [ Shortcuts ] *****
 
Shortcut Infected : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk ( hxxp://www-searching.com/?s=F7Dzbuzdk00CN1,bebc7f3d-aee9-4b42-a9e1-f02206ddae60,&pi=3 )
Shortcut Infected : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk ( hxxp://www-searching.com/?s=F7Dzbuzdk00CN1,bebc7f3d-aee9-4b42-a9e1-f02206ddae60,&pi=3 )
Shortcut Infected : C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ( hxxp://www-searching.com/?s=F7Dzbuzdk00CN1,bebc7f3d-aee9-4b42-a9e1-f02206ddae60,&pi=3 )
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
Key Found : HKLM\SOFTWARE\Classes\AppID\CptUrlPassthru.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\dca-bho.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\Iminent.WebBooster.InternetExplorer.DLL
Key Found : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor
Key Found : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor.1
Key Found : HKLM\SOFTWARE\Classes\dcabho.Dca
Key Found : HKLM\SOFTWARE\Classes\dcabho.Dca.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\Iminent
Key Found : HKLM\SOFTWARE\Classes\IminentWebBooster.BrowserHelperObject
Key Found : HKLM\SOFTWARE\Classes\IminentWebBooster.BrowserHelperObject.1
Key Found : HKLM\SOFTWARE\Classes\IminentWebBooster.ScriptExtender
Key Found : HKLM\SOFTWARE\Classes\IminentWebBooster.ScriptExtender.1
Key Found : HKLM\SOFTWARE\Classes\PCProxy.DataContainer
Key Found : HKLM\SOFTWARE\Classes\AppID\globalupdate.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\smu.exe
Key Found : HKLM\SOFTWARE\Classes\HCDNProxy
Key Found : HKLM\SOFTWARE\276f7b6a-57ac-4835-a899-bb16f1998207
Key Found : HKLM\SOFTWARE\76fbede2-4201-4105-b699-b6e1cfa0842d
Key Found : HKLM\SOFTWARE\77265a05-c503-42c6-9008-ccb4c776410f
Key Found : HKLM\SOFTWARE\8b7efd01-8cc0-4a74-83c0-195ca4a69f62
Key Found : HKLM\SOFTWARE\cc176909-f20b-4492-db14-910bce233454
Key Found : HKLM\SOFTWARE\cf36c35d-fd9e-40ab-bee6-4a2f89864f9d
Key Found : HKLM\SOFTWARE\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11}
Key Found : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\AppID\{9DC8FA51-B596-4F77-802C-5B295919C205}
Key Found : HKLM\SOFTWARE\Classes\AppID\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
Key Found : HKLM\SOFTWARE\Classes\AppID\{DD7C44CC-0F60-4FD9-A38F-5CF30D698AC2}
Key Found : HKLM\SOFTWARE\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}
Key Found : HKLM\SOFTWARE\Classes\AppID\{4D6A5312-AB4D-41AA-8BED-0E019B87CA11}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3E28F712-0D6C-4EE3-AC8C-8F060F5D7C33}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6CE321DA-DC11-45C6-A0FC-4E8A7D978ABC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EEBC7FF-67DA-4B90-9251-C2C5696E4B48}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{74137531-80F7-406F-9543-7D11385FA8C8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{832599B2-55BF-4437-8F3E-030CF5AEB262}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B1A429DB-FB06-4645-B7C0-0CC405EAD3CD}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DD67706E-819E-4EBD-BF8D-6D6147CC7A49}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F62A4AF9-58B4-4FEC-89CC-D717A547D8E8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{085CB97F-6D0B-487D-B94C-E11A736C38CE}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CF3CDEFB-31BE-43AE-B064-B9C62C883259}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D96C1D26-5CDF-4506-9244-57233C3984DF}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7D8DAE88-BC05-4578-8C29-E541FFBA5757}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A2970C7C-8392-4E6F-8B51-B763CF38E13C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EDBF8C0-C94C-4A13-956F-E393BCA5BA4B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Found : HKLM\SOFTWARE\Classes\Interface\{22511E2E-7970-414E-BC7C-28D16C4AF54D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{23C5311E-016D-4999-BCB1-499898429D6C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2C4B6DB8-6413-403B-A038-16A352CFE8B9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{46803190-228D-470E-90FE-F5E0CEA9C4F2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Found : HKLM\SOFTWARE\Classes\Interface\{5180FE16-2E09-497B-9C8B-5A6F029ECECB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A4F6E1B3-469E-46EF-A936-FBA9D5EFD2B9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C97AF157-6A27-4F57-9D47-E2D3E4761B77}
Key Found : HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{ED0D2C81-7DB5-4599-B7C0-1033418B5672}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E4C3E50F-5761-4BF8-95A0-939A819DF1C3}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D96C1D26-5CDF-4506-9244-57233C3984DF}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{7BAB653D-88FB-4F60-AFC2-8E6FD59FAFF3}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A9CAF365-EA35-45DA-BD8B-2EFA09D374AC}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{ED721A76-8160-4DA0-A18E-7FD7C4574774}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9AE7A6AE-162E-44C4-9A2B-A6B4EF19909D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B6360BD3-5CD0-40D3-BD87-DAFF37889F50}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E6F928E4-B672-4F3A-8CA2-53C4259235DE}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{14EF423E-3EE8-44AE-9337-07AC3F27B744}
Key Found : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C49AC435-5C4D-450F-AA56-CD31F96613B3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C49AC435-5C4D-450F-AA56-CD31F96613B3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}]
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E6A8DA1-2731-465B-B036-B9E16EF26CAC}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAC94FEE-45B4-4FD4-9EEA-D8978EC96C6E}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{085CB97F-6D0B-487D-B94C-E11A736C38CE}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{A2970C7C-8392-4E6F-8B51-B763CF38E13C}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5CD76C57-6893-478A-B776-47E7C82504BE}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{22511E2E-7970-414E-BC7C-28D16C4AF54D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{23C5311E-016D-4999-BCB1-499898429D6C}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{2C4B6DB8-6413-403B-A038-16A352CFE8B9}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{46803190-228D-470E-90FE-F5E0CEA9C4F2}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{5180FE16-2E09-497B-9C8B-5A6F029ECECB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{A4F6E1B3-469E-46EF-A936-FBA9D5EFD2B9}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C97AF157-6A27-4F57-9D47-E2D3E4761B77}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{ED0D2C81-7DB5-4599-B7C0-1033418B5672}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{E4C3E50F-5761-4BF8-95A0-939A819DF1C3}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{D96C1D26-5CDF-4506-9244-57233C3984DF}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1E6A8DA1-1731-465B-B036-B9E16EF26CAC}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E6A8DA1-2731-465B-B036-B9E16EF26CAC}
Key Found : HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\Compete
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\coupoon
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
Key Found : HKCU\Software\AnyProtect
Key Found : HKCU\Software\Compete
Key Found : HKCU\Software\Conduit_Search_Protect
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\Iminent
Key Found : HKCU\Software\InstalledBrowserExtensions
Key Found : HKCU\Software\Microsoft\KanarCore
Key Found : HKCU\Software\NpApp
Key Found : HKCU\Software\Optimizer Pro
Key Found : HKCU\Software\Tutorials
Key Found : HKCU\Software\TutoTag
Key Found : HKCU\Software\StormWatchApp
Key Found : HKCU\Software\WajIEnhance
Key Found : HKCU\Software\Super Optimizer
Key Found : HKCU\Software\CrossBrowser
Key Found : HKCU\Software\Crossbrowse
Key Found : HKCU\Software\YorkNewCin
Key Found : HKCU\Software\HighDefAction
Key Found : HKCU\Software\ArenaHD
Key Found : HKCU\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}
Key Found : HKCU\Software\QyGameClient
Key Found : HKCU\Software\CinemaPlus-3.2cV18.07
Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKCU\Software\AppDataLow\Software\Compete
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\AppDataLow\Software\SmartWeb
Key Found : HKLM\SOFTWARE\AppDataLow\SOFTWARE\Crossrider
Key Found : HKLM\SOFTWARE\AppDataLow\SOFTWARE\_CrossriderRegNamePlaceHolder_
Key Found : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Found : HKLM\SOFTWARE\CompeteInc
Key Found : HKLM\SOFTWARE\GlobalUpdate
Key Found : HKLM\SOFTWARE\IMGUPDATER
Key Found : HKLM\SOFTWARE\Iminent
Key Found : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : HKLM\SOFTWARE\NpApp
Key Found : HKLM\SOFTWARE\SearchProtect
Key Found : HKLM\SOFTWARE\Tutorials
Key Found : HKLM\SOFTWARE\Umbrella
Key Found : HKLM\SOFTWARE\StormWatchApp
Key Found : HKLM\SOFTWARE\StormWatch
Key Found : HKLM\SOFTWARE\GAMESDESKTOP
Key Found : HKLM\SOFTWARE\FlashBeat
Key Found : HKLM\SOFTWARE\Crossbrowse
Key Found : HKLM\SOFTWARE\SearchModulePlus
Key Found : HKLM\SOFTWARE\coupoon
Key Found : HKLM\SOFTWARE\YorkNewCin
Key Found : HKLM\SOFTWARE\HighDefAction
Key Found : HKLM\SOFTWARE\Universal
Key Found : HKLM\SOFTWARE\Hades
Key Found : HKLM\SOFTWARE\ArenaHD
Key Found : HKLM\SOFTWARE\MovieDea
Key Found : HKLM\SOFTWARE\{AA2C4D29-36C3-48AB-8A25-181CF7483597}
Key Found : HKLM\SOFTWARE\Br MediaPlayer
Key Found : HKLM\SOFTWARE\WajIEn
Key Found : HKLM\SOFTWARE\CinemaPlus-3.2cV18.07
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ConvertAd
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StormWatch
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SmartWeb
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FinanceAlert
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wincheck
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Consumer Input Installer
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBeat
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ASPackage
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hades
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7D7D6742-5B49-4454-9E9B-748E731E741A}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EpsanDrive
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MovieDea
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{49F8B4F8-0CD4-4BE4-A9E8-B13A071F7C90}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WajIEn
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{49F8B4F8-0CD4-4BE4-A9E8-B13A071F7C90}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaPlus-3.2cV18.07
Key Found : [x64] HKCU\Software\AnyProtect
Key Found : [x64] HKCU\Software\Compete
Key Found : [x64] HKCU\Software\Conduit_Search_Protect
Key Found : [x64] HKCU\Software\GlobalUpdate
Key Found : [x64] HKCU\Software\Iminent
Key Found : [x64] HKCU\Software\InstalledBrowserExtensions
Key Found : [x64] HKCU\Software\Microsoft\KanarCore
Key Found : [x64] HKCU\Software\NpApp
Key Found : [x64] HKCU\Software\Optimizer Pro
Key Found : [x64] HKCU\Software\Tutorials
Key Found : [x64] HKCU\Software\TutoTag
Key Found : [x64] HKCU\Software\StormWatchApp
Key Found : [x64] HKCU\Software\WajIEnhance
Key Found : [x64] HKCU\Software\Super Optimizer
Key Found : [x64] HKCU\Software\CrossBrowser
Key Found : [x64] HKCU\Software\Crossbrowse
Key Found : [x64] HKCU\Software\YorkNewCin
Key Found : [x64] HKCU\Software\HighDefAction
Key Found : [x64] HKCU\Software\ArenaHD
Key Found : [x64] HKCU\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}
Key Found : [x64] HKCU\Software\QyGameClient
Key Found : [x64] HKCU\Software\CinemaPlus-3.2cV18.07
Key Found : [x64] HKLM\SOFTWARE\Iminent
Key Found : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : [x64] HKLM\SOFTWARE\FlashBeat
Key Found : [x64] HKLM\SOFTWARE\WebBar
Key Found : [x64] HKLM\SOFTWARE\SearchModulePlus
Key Found : [x64] HKLM\SOFTWARE\coupoon
Key Found : [x64] HKLM\SOFTWARE\YorkNewCin
Key Found : [x64] HKLM\SOFTWARE\HighDefAction
Key Found : [x64] HKLM\SOFTWARE\ArenaHD
Key Found : [x64] HKLM\SOFTWARE\{AA2C4D29-36C3-48AB-8A25-181CF7483597}
Key Found : [x64] HKLM\SOFTWARE\WajIEn
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0BCE8B0A-1E76-44E5-9909-3CF804D92E4D}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GLOBALUPDATE.EXE
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9}
 
***** [ Web browsers ] *****
 
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : trovi.search
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : www-searching.com_
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : www-searching.com
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider] Found : hxxp://www.iminent.com/Content/Images/favicon.ico?2fdde4
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider_Data] Found : hxxp://start.iminent.com/?appId=8437c40c-c891-4a5e-8eea-ca8568502d51&ref=toolbox&q={searchTerms}
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Homepage] Found : hxxp://start.iminent.com/?appId=8437c40c-c891-4a5e-8eea-ca8568502d51
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://start.iminent.com/?appId=8437c40c-c891-4a5e-8eea-ca8568502d51",
      "hxxp://www.trovi.com/?gd=&ctid=CT3333887&octid=EB_ORIGINAL_CTID&ISID=M1890E6BC-BF65-41CA-B1ED-FCA8EC054D11&SearchSource=55&CUI=&UM=8&UP=SPA98636E4-750F-401C-BC08-F5A740811DAD&D=071415&SSPV=SP30339T2B_sp_ch
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [32483 bytes] ##########
 
 
JRT
 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.7 (08.18.2015:1)
OS: Windows 7 Ultimate x64
Ran by Kathy on Thu 08/20/2015 at  9:16:57.73
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Tasks
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B9D25D14-5326-4B87-B96E-A55E33600D20}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\wbsvc
 
 
 
~~~ Files
 
Failed to delete: [File] C:\Windows\system32\drivers\bsdriver.sys
Failed to delete: [File] C:\Windows\system32\drivers\cherimoya.sys
Failed to delete: [File] C:\Windows\SysWOW64\number of results
Successfully deleted: [File] C:\Users\Kathy\Appdata\Local\google\chrome\user data\default\local storage\hxxp_www.superfish.com_0.localstorage
Successfully deleted: [File] C:\Users\Kathy\desktop\pro pc cleaner.lnk
Successfully deleted: [File] C:\Users\Public\Desktop\play more great games!.url
Successfully deleted: [File] C:\Windows\system32\drivers\wsfd_vt_1_10_0_20.sys
Successfully deleted: [File] C:\Windows\system32\drivers\wsfd_vw_1_10_0_20.sys
Successfully deleted: [File] C:\Windows\system32\drivers\ywi2mzv2zhnjbdh.sys
Successfully disinfected: [Shortcut] C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
Successfully disinfected: [Shortcut] C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
Successfully disinfected: [Shortcut] C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
Successfully disinfected: [Shortcut] C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
 
 
 
~~~ Folders
 
Failed to delete: [Folder] C:\Program Files\shopperz12072015
Successfully deleted: [Folder] C:\Program Files (x86)\gmsd_us_005010030 [Adware.EoRezo]
Successfully deleted: [Folder] C:\Program Files (x86)\gmsd_us_005010031 [Adware.EoRezo]
Successfully deleted: [Folder] C:\Program Files (x86)\HQCinema Pro 2.1V12.07
Successfully deleted: [Folder] C:\Program Files (x86)\iobit\driver booster
Successfully deleted: [Folder] C:\Program Files (x86)\osdownloader
Successfully deleted: [Folder] C:\Program Files (x86)\ospd_us_014010029 [Adware.EoRezo]
Successfully deleted: [Folder] C:\Program Files (x86)\pro pc cleaner
Successfully deleted: [Folder] C:\Program Files (x86)\smwyyntm1ndi1zdz
Successfully deleted: [Folder] C:\ProgramData\abc
Successfully deleted: [Folder] C:\ProgramData\iobit\driver booster
Successfully deleted: [Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\driver booster 2
Successfully deleted: [Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\knctr
Successfully deleted: [Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\onesoftperday
Successfully deleted: [Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro v3.2
Successfully deleted: [Folder] C:\Users\Kathy\Appdata\Local\installer
Successfully deleted: [Folder] C:\Users\Kathy\Appdata\Local\pro_pc_cleaner
Successfully deleted: [Folder] C:\Users\Kathy\Appdata\LocalLow\company
Successfully deleted: [Folder] C:\Users\Kathy\AppData\Roaming\compete
Successfully deleted: [Folder] C:\Users\Kathy\AppData\Roaming\iobit\driver booster
Successfully deleted: [Folder] C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\pro pc cleaner
Successfully deleted: [Folder] C:\Users\Kathy\AppData\Roaming\optimizer pro
Successfully deleted: [Folder] C:\Users\Kathy\AppData\Roaming\productdata
Successfully deleted: [Folder] C:\Users\Kathy\Documents\optimizer pro
Successfully deleted: [Folder] C:\Users\Kathy\Documents\propccleaner
Successfully deleted: [Folder] C:\Users\Public\qiyi
Successfully deleted: [Folder] C:\ProgramData\28341ff220e0446c9fff27c4493d622e
Successfully deleted: [Folder] C:\ProgramData\7c0535b143fc4671b6ebd202fbffe066
Successfully deleted: [Folder] C:\ProgramData\Service1198
Successfully deleted: [Folder] C:\ProgramData\Service1291
Successfully deleted: [Folder] C:\Users\Kathy\Appdata\Local\BD634EFB-4435-4228-B1B1-B9F4709D5F79
Successfully deleted: [Folder] C:\Users\Kathy\Appdata\Local\gmsd_us_005010030 [Adware.EoRezo]
Successfully deleted: [Folder] C:\Users\Kathy\Appdata\Local\gmsd_us_005010031 [Adware.EoRezo]
 
 
 
~~~ Chrome
 
 
[C:\Users\Kathy\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Users\Kathy\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
gegdfeiahlfolhcfioipjlkombmgbakh
papbadoldddalgcjcicnikcfenodpghp
 
[C:\Users\Kathy\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Users\Kathy\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
  gegdfeiahlfolhcfioipjlkombmgbakh,
  papbadoldddalgcjcicnikcfenodpghp
]
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 08/20/2015 at  9:22:07.25
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
did not find a file called AdwCleaner[SO]
 
 

  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK that is phase one, there were several that did not want to go so I will increase the strength of the hammer :)

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here NSIS_extraction.png
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.
  • Notes:
    1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

    3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


    Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

  • 0

#5
moondog830

moondog830

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 626 posts

ComboFix

 

ComboFix 15-08-18.01 - Kathy 08/20/2015  13:00:02.1.3 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.1.1033.18.3835.988 [GMT -4:00]
Running from: c:\users\Kathy\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Outdated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Microsoft Security Essentials *Disabled/Outdated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\4a1fe953-c74b-463a-ad75-85a9096112df\2c58d024-f978-4d5c-9c87-81ac5611fb11.dll
c:\program files (x86)\4a1fe953-c74b-463a-ad75-85a9096112df\96d55ba1-5d5c-473a-9953-e96dd9948b3f.dll
c:\program files (x86)\a1009f48-01fb-4840-a15c-84d1f8624b11\0835ef3d-9195-426b-8d81-163a3e57ecdd.dll
c:\program files (x86)\a1009f48-01fb-4840-a15c-84d1f8624b11\3a799cf5-4e0d-483a-973d-8716b643d65c.dll
c:\program files (x86)\a1009f48-01fb-4840-a15c-84d1f8624b11\77d6d386-3d9c-468f-87a4-42e8219c261c.dll
c:\program files (x86)\a1009f48-01fb-4840-a15c-84d1f8624b11\a1009f48-01fb-4840-a15c-84d1f8624b11.dll
c:\program files (x86)\Adobe\81e7f42e-60af-4d8b-99d1-425a50e8bd35.dll
c:\program files (x86)\Adobe\fe94cf4e-c008-4f1a-9cb7-236dfdf7c989.dll
c:\program files (x86)\fe94cf4e-c008-4f1a-9cb7-236dfdf7c989\00b51828-13fa-4bf1-aa48-c6ad6101fe68.dll
c:\program files (x86)\fe94cf4e-c008-4f1a-9cb7-236dfdf7c989\da149b17-601e-47a2-8ccf-1fe9ceeeff24.dll
c:\program files (x86)\RegTool
c:\program files (x86)\RegTool\regtool.exe
c:\windows\security\Database\tmp.edb
.
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_AdobeUpdateService
.
.
(((((((((((((((((((((((((   Files Created from 2015-07-20 to 2015-08-20  )))))))))))))))))))))))))))))))
.
.
2015-08-20 17:07 . 2015-08-20 17:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-08-20 13:16 . 2015-08-20 13:16 -------- d-----w- c:\programdata\boost_interprocess
2015-08-20 02:41 . 2015-08-20 13:27 -------- d-----w- C:\AdwCleaner
2015-08-19 13:46 . 2015-08-20 00:04 -------- d-----w- C:\FRST
2015-08-16 20:32 . 2015-07-15 01:12 12222168 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A9B414CC-73D0-4568-B986-295224F262E5}\mpengine.dll
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-07-29 00:15 . 2015-01-19 02:58 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-07-14 18:17 . 2015-07-14 18:17 34712 ----a-w- c:\windows\system32\drivers\bsdriver.sys
2015-07-13 11:13 . 2015-07-14 18:15 349184 ----a-w- c:\windows\system32\Cofvopjy64.dll
2015-07-05 10:08 . 2010-11-21 03:27 300704 ------w- c:\windows\system32\MpSigStub.exe
2015-07-02 15:45 . 2015-07-11 18:11 1190000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7A7B7288-F676-4D32-8D71-93656A92ACF5}\gapaengine.dll
2015-07-02 15:45 . 2015-06-25 19:37 1190000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2015-06-27 18:15 . 2015-06-27 18:16 97888 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2015-06-25 18:51 . 2015-01-03 16:58 140135120 ----a-w- c:\windows\system32\MRT.exe
2015-06-18 16:08 . 2015-07-14 18:12 61336 ----a-w- c:\windows\system32\drivers\cherimoya.sys
2015-06-12 07:50 . 2015-07-13 17:23 12221144 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2015-06-01 19:16 . 2015-06-16 13:53 389840 ----a-w- c:\windows\system32\iedkcs32.dll
2015-05-27 14:35 . 2015-06-16 13:53 24917504 ----a-w- c:\windows\system32\mshtml.dll
2015-05-25 18:24 . 2015-06-16 13:55 5569984 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-05-25 18:23 . 2015-06-16 13:54 95680 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2015-05-25 18:23 . 2015-06-16 13:54 155584 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2015-05-25 18:21 . 2015-06-16 13:55 1728960 ----a-w- c:\windows\system32\ntdll.dll
2015-05-25 18:19 . 2015-06-16 13:54 243712 ----a-w- c:\windows\system32\wow64.dll
2015-05-25 18:19 . 2015-06-16 13:54 362496 ----a-w- c:\windows\system32\wow64win.dll
2015-05-25 18:19 . 2015-06-16 13:54 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2015-05-25 18:19 . 2015-06-16 13:54 215040 ----a-w- c:\windows\system32\winsrv.dll
2015-05-25 18:19 . 2015-06-16 13:55 1255424 ----a-w- c:\windows\system32\diagtrack.dll
2015-05-25 18:19 . 2015-06-16 13:54 210944 ----a-w- c:\windows\system32\wdigest.dll
2015-05-25 18:19 . 2015-06-16 13:55 879104 ----a-w- c:\windows\system32\tdh.dll
2015-05-25 18:19 . 2015-06-16 13:54 86528 ----a-w- c:\windows\system32\TSpkg.dll
2015-05-25 18:19 . 2015-06-16 13:54 136192 ----a-w- c:\windows\system32\sspicli.dll
2015-05-25 18:19 . 2015-06-16 13:54 29184 ----a-w- c:\windows\system32\sspisrv.dll
2015-05-25 18:19 . 2015-06-16 13:54 113664 ----a-w- c:\windows\system32\sechost.dll
2015-05-25 18:19 . 2015-06-16 13:54 503808 ----a-w- c:\windows\system32\srcore.dll
2015-05-25 18:19 . 2015-06-16 13:54 50176 ----a-w- c:\windows\system32\srclient.dll
2015-05-25 18:19 . 2015-06-16 13:54 28160 ----a-w- c:\windows\system32\secur32.dll
2015-05-25 18:19 . 2015-06-16 13:54 342016 ----a-w- c:\windows\system32\schannel.dll
2015-05-25 18:19 . 2015-06-16 13:54 314880 ----a-w- c:\windows\system32\msv1_0.dll
2015-05-25 18:19 . 2015-06-16 13:54 309760 ----a-w- c:\windows\system32\ncrypt.dll
2015-05-25 18:19 . 2015-06-16 13:54 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2015-05-25 18:19 . 2015-06-16 13:55 728576 ----a-w- c:\windows\system32\kerberos.dll
2015-05-25 18:19 . 2015-06-16 13:54 424960 ----a-w- c:\windows\system32\KernelBase.dll
2015-05-25 18:19 . 2015-06-16 13:54 1162752 ----a-w- c:\windows\system32\kernel32.dll
2015-05-25 18:19 . 2015-06-16 13:54 1461760 ----a-w- c:\windows\system32\lsasrv.dll
2015-05-25 18:18 . 2015-06-16 13:54 43520 ----a-w- c:\windows\system32\csrsrv.dll
2015-05-25 18:18 . 2015-06-16 13:54 22016 ----a-w- c:\windows\system32\credssp.dll
2015-05-25 18:18 . 2015-06-16 13:55 879104 ----a-w- c:\windows\system32\advapi32.dll
2015-05-25 18:18 . 2015-06-16 13:54 404992 ----a-w- c:\windows\system32\tracerpt.exe
2015-05-25 18:18 . 2015-06-16 13:54 47104 ----a-w- c:\windows\system32\typeperf.exe
2015-05-25 18:18 . 2015-06-16 13:54 112640 ----a-w- c:\windows\system32\smss.exe
2015-05-25 18:18 . 2015-06-16 13:54 296960 ----a-w- c:\windows\system32\rstrui.exe
2015-05-25 18:18 . 2015-06-16 13:54 43008 ----a-w- c:\windows\system32\relog.exe
2015-05-25 18:18 . 2015-06-16 13:54 104448 ----a-w- c:\windows\system32\logman.exe
2015-05-25 18:18 . 2015-06-16 13:54 31232 ----a-w- c:\windows\system32\lsass.exe
2015-05-25 18:18 . 2015-06-16 13:54 19456 ----a-w- c:\windows\system32\diskperf.exe
2015-05-25 18:18 . 2015-06-16 13:54 338432 ----a-w- c:\windows\system32\conhost.exe
2015-05-25 18:18 . 2015-06-16 13:54 64000 ----a-w- c:\windows\system32\auditpol.exe
2015-05-25 18:14 . 2015-06-16 13:54 60416 ----a-w- c:\windows\system32\msobjs.dll
2015-05-25 18:14 . 2015-06-16 13:54 146432 ----a-w- c:\windows\system32\msaudite.dll
2015-05-25 18:11 . 2015-06-16 13:54 6656 ----a-w- c:\windows\system32\apisetschema.dll
2015-05-25 18:11 . 2015-06-16 13:54 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 686080 ----a-w- c:\windows\system32\adtschema.dll
2015-05-25 18:07 . 2015-06-16 13:55 3989440 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2015-05-25 18:07 . 2015-06-16 13:55 3934144 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2015-05-25 18:04 . 2015-06-16 13:54 1310744 ----a-w- c:\windows\SysWow64\ntdll.dll
2015-05-25 18:01 . 2015-06-16 13:54 172032 ----a-w- c:\windows\SysWow64\wdigest.dll
2015-05-25 18:01 . 2015-06-16 13:55 635392 ----a-w- c:\windows\SysWow64\tdh.dll
2015-05-25 18:01 . 2015-06-16 13:54 65536 ----a-w- c:\windows\SysWow64\TSpkg.dll
2015-05-25 18:01 . 2015-06-16 13:54 43008 ----a-w- c:\windows\SysWow64\srclient.dll
2015-05-25 18:01 . 2015-06-16 13:54 92160 ----a-w- c:\windows\SysWow64\sechost.dll
2015-05-25 18:01 . 2015-06-16 13:54 248832 ----a-w- c:\windows\SysWow64\schannel.dll
2015-05-25 18:01 . 2015-06-16 13:54 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2015-05-25 18:01 . 2015-06-16 13:54 221184 ----a-w- c:\windows\SysWow64\ncrypt.dll
2015-05-25 18:01 . 2015-06-16 13:54 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2015-05-25 18:01 . 2015-06-16 13:54 259584 ----a-w- c:\windows\SysWow64\msv1_0.dll
2015-05-25 18:01 . 2015-06-16 13:55 551424 ----a-w- c:\windows\SysWow64\kerberos.dll
2015-05-25 18:01 . 2015-06-16 13:54 17408 ----a-w- c:\windows\SysWow64\credssp.dll
2015-05-25 18:01 . 2015-06-16 13:54 641536 ----a-w- c:\windows\SysWow64\advapi32.dll
2015-05-25 18:01 . 2015-06-16 13:54 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2015-07-23 2895552]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2015-06-29 53282944]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2015-04-30 334896]
"BlueStacks Agent"="c:\program files (x86)\BlueStacks\HD-Agent.exe" [2015-07-22 896632]
"Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2015-07-02 2303152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"RequireSignedAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\drivers\asmthub3.sys;c:\windows\SYSNATIVE\drivers\asmthub3.sys [x]
R3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\drivers\asmtxhci.sys;c:\windows\SYSNATIVE\drivers\asmtxhci.sys [x]
R3 b06diag;Broadcom NetXtreme II Diag Driver;c:\windows\system32\drivers\bxdiaga.sys;c:\windows\SYSNATIVE\drivers\bxdiaga.sys [x]
R3 BFN7x64;Bigfoot Networks Killer Gaming Service;c:\windows\system32\drivers\Xeno7x64.sys;c:\windows\SYSNATIVE\drivers\Xeno7x64.sys [x]
R3 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
R3 bxfcoe;bxfcoe;c:\windows\system32\drivers\bxfcoe.sys;c:\windows\SYSNATIVE\drivers\bxfcoe.sys [x]
R3 bxois;bxois;c:\windows\system32\drivers\bxois.sys;c:\windows\SYSNATIVE\drivers\bxois.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\System32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
R3 EtronSTOR;Etron Enhance USB BOT/UASP Mass Storage Driver;c:\windows\System32\Drivers\EtronSTOR.sys;c:\windows\SYSNATIVE\Drivers\EtronSTOR.sys [x]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\System32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 ioatdma1;ioatdma1;c:\windows\System32\Drivers\qd162x64.sys;c:\windows\SYSNATIVE\Drivers\qd162x64.sys [x]
R3 ioatdma2;Intel® QuickData Technology device ver.2;c:\windows\System32\Drivers\qd262x64.sys;c:\windows\SYSNATIVE\Drivers\qd262x64.sys [x]
R3 iusb3hub;Intel® USB 3.0 Hub Driver;c:\windows\system32\drivers\iusb3hub.sys;c:\windows\SYSNATIVE\drivers\iusb3hub.sys [x]
R3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\drivers\iusb3xhc.sys;c:\windows\SYSNATIVE\drivers\iusb3xhc.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x]
R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S1 bsdriver;bsdriver;c:\windows\system32\drivers\bsdriver.sys;c:\windows\SYSNATIVE\drivers\bsdriver.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]
S2 BstHdUpdaterSvc;BlueStacks Updater Service;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe [x]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 msdotnetserv_v2050729;Microsoft .Net Framework v2.0.50729 ALP (X86);c:\program files (x86)\Microsoft.NET\v2.0.507279\msnetcore.exe;c:\program files (x86)\Microsoft.NET\v2.0.507279\msnetcore.exe [x]
S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
S3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDMI64.sys;c:\windows\SYSNATIVE\drivers\CHDMI64.sys [x]
S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys;c:\windows\SYSNATIVE\DRIVERS\rtl8192se.sys [x]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2015-06-13 18:17 803488 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2015-06-13 18:17 803488 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2015-06-13 18:17 803488 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2015-01-06 13774040]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2015-04-30 1337000]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2015-07-12 500936]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Driver Booster_is1 - c:\program files (x86)\IObit\Driver Booster\unins000.exe
AddRemove-gmsd_us_005010030_is1 - c:\program files (x86)\gmsd_us_005010030\unins000.exe
AddRemove-gmsd_us_005010031_is1 - c:\program files (x86)\gmsd_us_005010031\unins000.exe
AddRemove-Itibiti_is1 - c:\program files (x86)\Itibiti Soft Phone\unins000.exe
AddRemove-Ninja Loader - c:\program files (x86)\Ninja Loader\uninstall.exe
AddRemove-ospd_us_014010029_is1 - c:\program files (x86)\ospd_us_014010029\unins000.exe
AddRemove-PPStream - c:\iqiyi video\LStyle\QyUninst.exe
AddRemove-Pro PC Cleaner - c:\program files (x86)\Pro PC Cleaner\uninst.exe
AddRemove-RadPlayer - c:\program files (x86)\RadPlayer\Uninstall.exe
AddRemove-WordShark_1.10.0.20 - c:\program files (x86)\WordShark_1.10.0.20\Uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_134_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_134_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_134_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_134_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_134.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.17"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_134.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_134.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_134.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
.
**************************************************************************
.
Completion time: 2015-08-20  13:18:15 - machine was rebooted
ComboFix-quarantined-files.txt  2015-08-20 17:18
.
Pre-Run: 204,659,408,896 bytes free
Post-Run: 204,746,702,848 bytes free
.
- - End Of File - - E1B0D04281E1728D640D5E5664C67AB0
A36C5E4F47E84449FF07ED3517B43A31

  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
This should remove the recalcitrant ones :)

Once this has completed can you let me know how the computer is behaving

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:
 

File::
c:\windows\system32\Cofvopjy64.dll
c:\windows\system32\drivers\bsdriver.sys
c:\programdata\boost_interprocess
c:\windows\system32\drivers\cherimoya.sys

Driver::
bsdriver
cherimoya


Save this as CFScript.txt, in the same location as ComboFix.exe


CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
  • 0

#7
moondog830

moondog830

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 626 posts

ComboFix again

 

ComboFix 15-08-18.01 - Kathy 08/20/2015  14:04:33.2.3 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.1.1033.18.3835.2723 [GMT -4:00]
Running from: c:\users\Kathy\Desktop\ComboFix.exe
Command switches used :: c:\users\Kathy\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Microsoft Security Essentials *Disabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\programdata\boost_interprocess"
"c:\windows\system32\Cofvopjy64.dll"
"c:\windows\system32\drivers\bsdriver.sys"
"c:\windows\system32\drivers\cherimoya.sys"
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_BSDRIVER
-------\Legacy_CHERIMOYA
-------\Service_bsdriver
.
.
(((((((((((((((((((((((((   Files Created from 2015-07-20 to 2015-08-20  )))))))))))))))))))))))))))))))
.
.
2015-08-20 18:10 . 2015-08-20 18:10 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-08-20 17:59 . 2015-08-20 17:59 -------- d-----w- c:\programdata\ProductData
2015-08-20 13:16 . 2015-08-20 13:16 -------- d-----w- c:\programdata\boost_interprocess
2015-08-20 02:41 . 2015-08-20 13:27 -------- d-----w- C:\AdwCleaner
2015-08-19 13:46 . 2015-08-20 00:04 -------- d-----w- C:\FRST
2015-08-16 20:32 . 2015-07-15 01:12 12222168 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A9B414CC-73D0-4568-B986-295224F262E5}\mpengine.dll
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-07-14 18:17 . 2015-07-14 18:17 34712 ----a-w- c:\windows\system32\drivers\bsdriver.sys
2015-07-13 11:13 . 2015-07-14 18:15 349184 ----a-w- c:\windows\system32\Cofvopjy64.dll
2015-07-05 10:08 . 2010-11-21 03:27 300704 ------w- c:\windows\system32\MpSigStub.exe
2015-07-02 15:45 . 2015-07-11 18:11 1190000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7A7B7288-F676-4D32-8D71-93656A92ACF5}\gapaengine.dll
2015-07-02 15:45 . 2015-06-25 19:37 1190000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2015-06-27 18:15 . 2015-06-27 18:16 97888 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2015-06-25 18:51 . 2015-01-03 16:58 140135120 ----a-w- c:\windows\system32\MRT.exe
2015-06-18 16:08 . 2015-07-14 18:12 61336 ----a-w- c:\windows\system32\drivers\cherimoya.sys
2015-06-12 07:50 . 2015-07-13 17:23 12221144 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2015-06-01 19:16 . 2015-06-16 13:53 389840 ----a-w- c:\windows\system32\iedkcs32.dll
2015-05-27 14:35 . 2015-06-16 13:53 24917504 ----a-w- c:\windows\system32\mshtml.dll
2015-05-25 18:24 . 2015-06-16 13:55 5569984 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-05-25 18:23 . 2015-06-16 13:54 95680 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2015-05-25 18:23 . 2015-06-16 13:54 155584 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2015-05-25 18:21 . 2015-06-16 13:55 1728960 ----a-w- c:\windows\system32\ntdll.dll
2015-05-25 18:19 . 2015-06-16 13:54 243712 ----a-w- c:\windows\system32\wow64.dll
2015-05-25 18:19 . 2015-06-16 13:54 362496 ----a-w- c:\windows\system32\wow64win.dll
2015-05-25 18:19 . 2015-06-16 13:54 13312 ----a-w- c:\windows\system32\wow64cpu.dll
2015-05-25 18:19 . 2015-06-16 13:54 215040 ----a-w- c:\windows\system32\winsrv.dll
2015-05-25 18:19 . 2015-06-16 13:55 1255424 ----a-w- c:\windows\system32\diagtrack.dll
2015-05-25 18:19 . 2015-06-16 13:54 210944 ----a-w- c:\windows\system32\wdigest.dll
2015-05-25 18:19 . 2015-06-16 13:55 879104 ----a-w- c:\windows\system32\tdh.dll
2015-05-25 18:19 . 2015-06-16 13:54 86528 ----a-w- c:\windows\system32\TSpkg.dll
2015-05-25 18:19 . 2015-06-16 13:54 136192 ----a-w- c:\windows\system32\sspicli.dll
2015-05-25 18:19 . 2015-06-16 13:54 29184 ----a-w- c:\windows\system32\sspisrv.dll
2015-05-25 18:19 . 2015-06-16 13:54 113664 ----a-w- c:\windows\system32\sechost.dll
2015-05-25 18:19 . 2015-06-16 13:54 503808 ----a-w- c:\windows\system32\srcore.dll
2015-05-25 18:19 . 2015-06-16 13:54 50176 ----a-w- c:\windows\system32\srclient.dll
2015-05-25 18:19 . 2015-06-16 13:54 28160 ----a-w- c:\windows\system32\secur32.dll
2015-05-25 18:19 . 2015-06-16 13:54 342016 ----a-w- c:\windows\system32\schannel.dll
2015-05-25 18:19 . 2015-06-16 13:54 314880 ----a-w- c:\windows\system32\msv1_0.dll
2015-05-25 18:19 . 2015-06-16 13:54 309760 ----a-w- c:\windows\system32\ncrypt.dll
2015-05-25 18:19 . 2015-06-16 13:54 16384 ----a-w- c:\windows\system32\ntvdm64.dll
2015-05-25 18:19 . 2015-06-16 13:55 728576 ----a-w- c:\windows\system32\kerberos.dll
2015-05-25 18:19 . 2015-06-16 13:54 424960 ----a-w- c:\windows\system32\KernelBase.dll
2015-05-25 18:19 . 2015-06-16 13:54 1162752 ----a-w- c:\windows\system32\kernel32.dll
2015-05-25 18:19 . 2015-06-16 13:54 1461760 ----a-w- c:\windows\system32\lsasrv.dll
2015-05-25 18:18 . 2015-06-16 13:54 43520 ----a-w- c:\windows\system32\csrsrv.dll
2015-05-25 18:18 . 2015-06-16 13:54 22016 ----a-w- c:\windows\system32\credssp.dll
2015-05-25 18:18 . 2015-06-16 13:55 879104 ----a-w- c:\windows\system32\advapi32.dll
2015-05-25 18:18 . 2015-06-16 13:54 404992 ----a-w- c:\windows\system32\tracerpt.exe
2015-05-25 18:18 . 2015-06-16 13:54 47104 ----a-w- c:\windows\system32\typeperf.exe
2015-05-25 18:18 . 2015-06-16 13:54 112640 ----a-w- c:\windows\system32\smss.exe
2015-05-25 18:18 . 2015-06-16 13:54 296960 ----a-w- c:\windows\system32\rstrui.exe
2015-05-25 18:18 . 2015-06-16 13:54 43008 ----a-w- c:\windows\system32\relog.exe
2015-05-25 18:18 . 2015-06-16 13:54 104448 ----a-w- c:\windows\system32\logman.exe
2015-05-25 18:18 . 2015-06-16 13:54 31232 ----a-w- c:\windows\system32\lsass.exe
2015-05-25 18:18 . 2015-06-16 13:54 19456 ----a-w- c:\windows\system32\diskperf.exe
2015-05-25 18:18 . 2015-06-16 13:54 338432 ----a-w- c:\windows\system32\conhost.exe
2015-05-25 18:18 . 2015-06-16 13:54 64000 ----a-w- c:\windows\system32\auditpol.exe
2015-05-25 18:14 . 2015-06-16 13:54 60416 ----a-w- c:\windows\system32\msobjs.dll
2015-05-25 18:14 . 2015-06-16 13:54 146432 ----a-w- c:\windows\system32\msaudite.dll
2015-05-25 18:11 . 2015-06-16 13:54 6656 ----a-w- c:\windows\system32\apisetschema.dll
2015-05-25 18:11 . 2015-06-16 13:54 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-25 18:11 . 2015-06-16 13:54 686080 ----a-w- c:\windows\system32\adtschema.dll
2015-05-25 18:07 . 2015-06-16 13:55 3989440 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2015-05-25 18:07 . 2015-06-16 13:55 3934144 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2015-05-25 18:04 . 2015-06-16 13:54 1310744 ----a-w- c:\windows\SysWow64\ntdll.dll
2015-05-25 18:01 . 2015-06-16 13:54 172032 ----a-w- c:\windows\SysWow64\wdigest.dll
2015-05-25 18:01 . 2015-06-16 13:55 635392 ----a-w- c:\windows\SysWow64\tdh.dll
2015-05-25 18:01 . 2015-06-16 13:54 65536 ----a-w- c:\windows\SysWow64\TSpkg.dll
2015-05-25 18:01 . 2015-06-16 13:54 43008 ----a-w- c:\windows\SysWow64\srclient.dll
2015-05-25 18:01 . 2015-06-16 13:54 92160 ----a-w- c:\windows\SysWow64\sechost.dll
2015-05-25 18:01 . 2015-06-16 13:54 248832 ----a-w- c:\windows\SysWow64\schannel.dll
2015-05-25 18:01 . 2015-06-16 13:54 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2015-05-25 18:01 . 2015-06-16 13:54 221184 ----a-w- c:\windows\SysWow64\ncrypt.dll
2015-05-25 18:01 . 2015-06-16 13:54 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2015-05-25 18:01 . 2015-06-16 13:54 259584 ----a-w- c:\windows\SysWow64\msv1_0.dll
2015-05-25 18:01 . 2015-06-16 13:55 551424 ----a-w- c:\windows\SysWow64\kerberos.dll
2015-05-25 18:01 . 2015-06-16 13:54 17408 ----a-w- c:\windows\SysWow64\credssp.dll
2015-05-25 18:01 . 2015-06-16 13:54 641536 ----a-w- c:\windows\SysWow64\advapi32.dll
2015-05-25 18:01 . 2015-06-16 13:54 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2015-05-25 18:00 . 2015-06-16 13:54 40448 ----a-w- c:\windows\SysWow64\typeperf.exe
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2015-07-23 2895552]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2015-06-29 53282944]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2015-04-30 334896]
"BlueStacks Agent"="c:\program files (x86)\BlueStacks\HD-Agent.exe" [2015-07-22 896632]
"Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2015-07-02 2303152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"RequireSignedAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\drivers\asmthub3.sys;c:\windows\SYSNATIVE\drivers\asmthub3.sys [x]
R3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\drivers\asmtxhci.sys;c:\windows\SYSNATIVE\drivers\asmtxhci.sys [x]
R3 b06diag;Broadcom NetXtreme II Diag Driver;c:\windows\system32\drivers\bxdiaga.sys;c:\windows\SYSNATIVE\drivers\bxdiaga.sys [x]
R3 BFN7x64;Bigfoot Networks Killer Gaming Service;c:\windows\system32\drivers\Xeno7x64.sys;c:\windows\SYSNATIVE\drivers\Xeno7x64.sys [x]
R3 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
R3 bxfcoe;bxfcoe;c:\windows\system32\drivers\bxfcoe.sys;c:\windows\SYSNATIVE\drivers\bxfcoe.sys [x]
R3 bxois;bxois;c:\windows\system32\drivers\bxois.sys;c:\windows\SYSNATIVE\drivers\bxois.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\System32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
R3 EtronSTOR;Etron Enhance USB BOT/UASP Mass Storage Driver;c:\windows\System32\Drivers\EtronSTOR.sys;c:\windows\SYSNATIVE\Drivers\EtronSTOR.sys [x]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\System32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 ioatdma1;ioatdma1;c:\windows\System32\Drivers\qd162x64.sys;c:\windows\SYSNATIVE\Drivers\qd162x64.sys [x]
R3 ioatdma2;Intel® QuickData Technology device ver.2;c:\windows\System32\Drivers\qd262x64.sys;c:\windows\SYSNATIVE\Drivers\qd262x64.sys [x]
R3 iusb3hub;Intel® USB 3.0 Hub Driver;c:\windows\system32\drivers\iusb3hub.sys;c:\windows\SYSNATIVE\drivers\iusb3hub.sys [x]
R3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\drivers\iusb3xhc.sys;c:\windows\SYSNATIVE\drivers\iusb3xhc.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x]
R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]
S2 BstHdUpdaterSvc;BlueStacks Updater Service;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe [x]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
S2 msdotnetserv_v2050729;Microsoft .Net Framework v2.0.50729 ALP (X86);c:\program files (x86)\Microsoft.NET\v2.0.507279\msnetcore.exe;c:\program files (x86)\Microsoft.NET\v2.0.507279\msnetcore.exe [x]
S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
S3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDMI64.sys;c:\windows\SYSNATIVE\drivers\CHDMI64.sys [x]
S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys;c:\windows\SYSNATIVE\DRIVERS\rtl8192se.sys [x]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2015-06-13 18:17 803488 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2015-06-13 18:17 803488 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2015-06-13 18:17 803488 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2015-01-06 13774040]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2015-04-30 1337000]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2015-07-12 500936]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Driver Booster_is1 - c:\program files (x86)\IObit\Driver Booster\unins000.exe
AddRemove-gmsd_us_005010030_is1 - c:\program files (x86)\gmsd_us_005010030\unins000.exe
AddRemove-gmsd_us_005010031_is1 - c:\program files (x86)\gmsd_us_005010031\unins000.exe
AddRemove-Itibiti_is1 - c:\program files (x86)\Itibiti Soft Phone\unins000.exe
AddRemove-Ninja Loader - c:\program files (x86)\Ninja Loader\uninstall.exe
AddRemove-ospd_us_014010029_is1 - c:\program files (x86)\ospd_us_014010029\unins000.exe
AddRemove-PPStream - c:\iqiyi video\LStyle\QyUninst.exe
AddRemove-Pro PC Cleaner - c:\program files (x86)\Pro PC Cleaner\uninst.exe
AddRemove-RadPlayer - c:\program files (x86)\RadPlayer\Uninstall.exe
AddRemove-WordShark_1.10.0.20 - c:\program files (x86)\WordShark_1.10.0.20\Uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\BlueStacks]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_134_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_134_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_134_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_134_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_134.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.17"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_134.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_134.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_134.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Google\Update\GoogleUpdate.exe
.
**************************************************************************
.
Completion time: 2015-08-20  15:01:25 - machine was rebooted
ComboFix-quarantined-files.txt  2015-08-20 19:01
ComboFix2.txt  2015-08-20 17:18
.
Pre-Run: 204,926,459,904 bytes free
Post-Run: 204,916,875,264 bytes free
.
- - End Of File - - F0679BE4B9BE7227F9183BDA65214453
A36C5E4F47E84449FF07ED3517B43A31

  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
How is the computer now, any evident problems ?

If I could have another FRST scan please to ensure that all is good
  • 0

#9
moondog830

moondog830

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 626 posts

won't be able to get on the other laptop until  sometime on Sunday ... will get you the necessary report.

 

It seems to be working okay ... no pop-ups or anything else ... thanks


  • 0

#10
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
For sure :)
  • 0

Advertisements


#11
moondog830

moondog830

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 626 posts

FRST

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:17-08-2015
Ran by Kathy (administrator) on KATHY-PC (23-08-2015 13:55:07)
Running from C:\Users\Kathy\Desktop
Loaded Profiles: Kathy (Available Profiles: Kathy)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Copyright © Microsoft 2015) C:\Program Files (x86)\Microsoft.NET\v2.0.507279\msnetcore.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Advanced Micro Devices, Inc.) C:\Windows\System32\atibtmon.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13774040 2015-01-06] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-07-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [896632 2015-07-22] (BlueStack Systems, Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2303152 2015-07-02] (Adobe Systems Incorporated)
HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2895552 2015-07-23] (Valve Corporation)
HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53282944 2015-06-29] (Skype Technologies S.A.)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-171533428-321824291-3300133993-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.yahoo.com/?fr=hp-ddc-bd&type=bl-bir-ob-rhb-29__alt__ddc_dsssyc_bd_com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-27] (Oracle Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-27] (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{13BA7357-F3CB-44DF-94FB-47B6BD1FF704}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{D464E0FB-F200-41A0-A115-BF3ED0CBE42C}: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2015-07-02] (Adobe Systems)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-27] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-05] (Google Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2015-07-02] (Adobe Systems)
 
Chrome: 
=======
CHR Profile: C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [433784 2015-06-16] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [413304 2015-06-16] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [831096 2015-07-21] (BlueStack Systems, Inc.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2904864 2015-06-02] (IObit)
R2 msdotnetserv_v2050729; C:\Program Files (x86)\Microsoft.NET\v2.0.507279\msnetcore.exe [3003880 2015-07-05] (Copyright © Microsoft 2015)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
S3 Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [838336 2015-07-23] (Valve Corporation) [File not signed]
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-09-15] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation)
S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [145528 2015-06-16] (BlueStack Systems)
S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation)
S3 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation)
R3 CnxtHdmiAudService; C:\Windows\System32\drivers\CHDMI64.sys [722488 2014-12-29] (Conexant Systems Inc.)
S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [32512 2012-07-24] (Etron Technology Inc)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2014-12-29] (REALiX™)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-23 13:53 - 2015-08-23 13:53 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_dc3d_01009.Wdf
2015-08-23 13:50 - 2015-08-23 13:50 - 00000000 ___SD C:\ComboFix
2015-08-23 13:41 - 2015-08-23 13:41 - 00000000 ____D C:\Users\Kathy\AppData\Local\CEF
2015-08-20 15:01 - 2015-08-20 15:01 - 00027245 _____ C:\ComboFix.txt
2015-08-20 13:59 - 2015-08-20 13:59 - 00000000 ____D C:\ProgramData\ProductData
2015-08-20 12:57 - 2011-06-26 02:45 - 00256000 _____ C:\Windows\PEV.exe
2015-08-20 12:57 - 2010-11-07 13:20 - 00208896 _____ C:\Windows\MBR.exe
2015-08-20 12:57 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-08-20 12:57 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-08-20 12:57 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-08-20 12:57 - 2000-08-30 20:00 - 00098816 _____ C:\Windows\sed.exe
2015-08-20 12:57 - 2000-08-30 20:00 - 00080412 _____ C:\Windows\grep.exe
2015-08-20 12:57 - 2000-08-30 20:00 - 00068096 _____ C:\Windows\zip.exe
2015-08-20 12:41 - 2015-08-23 13:50 - 00000000 ____D C:\Qoobox
2015-08-20 12:41 - 2015-08-20 14:10 - 00000000 ____D C:\Windows\erdnt
2015-08-20 12:40 - 2015-08-20 12:38 - 05635271 ____R (Swearware) C:\Users\Kathy\Desktop\ComboFix.exe
2015-08-20 09:16 - 2015-08-23 13:41 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-08-19 22:41 - 2015-08-20 09:27 - 00000000 ____D C:\AdwCleaner
2015-08-19 19:01 - 2015-08-19 17:56 - 01585664 _____ C:\Users\Kathy\Desktop\AdwCleaner.exe
2015-08-19 19:01 - 2015-08-19 17:55 - 01798576 _____ (Malwarebytes Corporation) C:\Users\Kathy\Desktop\JRT.exe
2015-08-19 19:01 - 2015-08-19 17:54 - 00041501 _____ C:\Users\Kathy\Desktop\fixlist.txt
2015-08-19 10:09 - 2015-08-19 10:10 - 00061118 _____ C:\Users\Kathy\Desktop\Addition.txt
2015-08-19 10:07 - 2015-08-23 13:55 - 00011312 _____ C:\Users\Kathy\Desktop\FRST.txt
2015-08-19 09:46 - 2015-08-23 13:55 - 00000000 ____D C:\FRST
2015-08-19 09:46 - 2015-08-19 09:35 - 02173440 _____ (Farbar) C:\Users\Kathy\Desktop\FRST64.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-23 13:53 - 2015-04-20 03:00 - 00007538 _____ C:\Windows\setupact.log
2015-08-23 13:48 - 2015-06-30 18:46 - 00000000 ____D C:\Program Files (x86)\Steam
2015-08-23 13:47 - 2014-12-20 23:49 - 01579640 _____ C:\Windows\WindowsUpdate.log
2015-08-23 13:44 - 2009-07-14 00:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-23 13:44 - 2009-07-14 00:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-23 13:36 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-20 14:57 - 2009-07-13 22:34 - 00000215 _____ C:\Windows\system.ini
2015-08-20 14:11 - 2015-04-20 03:00 - 00560254 _____ C:\Windows\PFRO.log
2015-08-20 14:10 - 2009-07-13 22:34 - 69492736 _____ C:\Windows\system32\config\SOFTWARE.bak
2015-08-20 14:10 - 2009-07-13 22:34 - 16252928 _____ C:\Windows\system32\config\SYSTEM.bak
2015-08-20 14:10 - 2009-07-13 22:34 - 00266240 _____ C:\Windows\system32\config\DEFAULT.bak
2015-08-20 14:10 - 2009-07-13 22:34 - 00065536 _____ C:\Windows\system32\config\SAM.bak
2015-08-20 14:10 - 2009-07-13 22:34 - 00024576 _____ C:\Windows\system32\config\SECURITY.bak
2015-08-20 13:18 - 2009-07-13 23:20 - 00000000 __RHD C:\Users\Default
2015-08-20 13:08 - 2009-07-13 22:34 - 38273024 _____ C:\Windows\system32\config\COMPONENTS.bak
2015-08-20 13:07 - 2015-07-19 00:12 - 00000000 ____D C:\Program Files (x86)\a1009f48-01fb-4840-a15c-84d1f8624b11
2015-08-20 13:07 - 2015-07-13 13:12 - 00000000 ____D C:\Program Files (x86)\fe94cf4e-c008-4f1a-9cb7-236dfdf7c989
2015-08-20 13:07 - 2015-07-12 23:57 - 00000000 ____D C:\Program Files (x86)\4a1fe953-c74b-463a-ad75-85a9096112df
2015-08-20 13:07 - 2015-07-12 10:50 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-08-20 12:41 - 2015-07-09 23:44 - 00000000 ____D C:\Users\Kathy\AppData\Roaming\Skype
2015-08-20 09:19 - 2015-07-14 14:11 - 00000000 ____D C:\Program Files\shopperz12072015
2015-08-20 09:19 - 2014-12-29 14:58 - 00000000 ____D C:\Users\Kathy\AppData\Roaming\IObit
2015-08-20 09:19 - 2014-12-29 14:58 - 00000000 ____D C:\ProgramData\IObit
2015-08-20 09:19 - 2014-12-29 14:58 - 00000000 ____D C:\Program Files (x86)\IObit
2015-08-19 22:43 - 2014-12-20 21:05 - 00000996 _____ C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-19 19:06 - 2015-07-13 12:14 - 00000000 ____D C:\Program Files (x86)\msrtn32
2015-08-19 19:05 - 2015-01-03 13:31 - 00000000 ____D C:\Windows\System32\Tasks\Games
2015-08-19 09:48 - 2009-07-14 01:13 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-16 16:50 - 2015-07-13 00:01 - 00000000 ____D C:\Program Files (x86)\baidu
2015-08-16 16:46 - 2015-04-14 12:14 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-08-16 16:45 - 2015-04-14 12:14 - 00000000 ___SD C:\Windows\system32\GWX
2015-08-16 16:40 - 2015-06-30 18:16 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2015-08-16 16:30 - 2015-06-30 18:16 - 00000000 ____D C:\Program Files (x86)\BlueStacks
2015-07-28 20:42 - 2014-12-29 15:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
 
==================== Files in the root of some directories =======
 
2015-01-03 14:00 - 2015-01-03 14:00 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-08-19 19:33
 
==================== End of log ============================
 
Addition
 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:17-08-2015
Ran by Kathy (2015-08-23 13:56:13)
Running from C:\Users\Kathy\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-171533428-321824291-3300133993-500 - Administrator - Disabled)
Guest (S-1-5-21-171533428-321824291-3300133993-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-171533428-321824291-3300133993-1002 - Limited - Enabled)
Kathy (S-1-5-21-171533428-321824291-3300133993-1000 - Administrator - Enabled) => C:\Users\Kathy
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Disabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Disabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: IObit Malware Fighter (Disabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.1.3.121 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.134 - Adobe Systems Incorporated)
AdVenture Capitalist (HKLM-x32\...\Steam App 346900) (Version:  - Hyper Hippo Games)
Blender (HKLM-x32\...\{69FE4B50-CA11-498A-9E9F-830B32AFE32C}) (Version: 2.75.0 - Blender Foundation)
BlueStacks Notification Center (HKLM-x32\...\{3792811C-832F-4392-B44A-24092901EDDC}) (Version: 0.9.30.9239 - BlueStack Systems, Inc.)
CinemaPlus-3.2cV13.07 (HKLM-x32\...\CinemaPlus-3.2cV13.07) (Version: 1.36.01.22 - Cinema PlusV13.07) <==== ATTENTION
Conexant Audio Driver For AMD HDMI Codec (HKLM\...\CNXT_AUDIO_HDA_HDMI) (Version: 4.98.32.0 - Conexant)
Driver Booster 2.1 (HKLM-x32\...\Driver Booster_is1) (Version: 2.1 - IObit)
Etherium (HKLM-x32\...\Steam App 245370) (Version:  - Tindalos Interactive)
GamesDesktop 025.005010030 (HKLM-x32\...\gmsd_us_005010030_is1) (Version:  - GAMESDESKTOP) <==== ATTENTION
GamesDesktop 025.005010031 (HKLM-x32\...\gmsd_us_005010031_is1) (Version:  - GAMESDESKTOP) <==== ATTENTION
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.132 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
HQCinema Pro 2.1V12.07 (HKLM-x32\...\HQCinema Pro 2.1V12.07) (Version: 1.36.01.22 - HQ-VideoV12.07) <==== ATTENTION
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
KNCTR (HKLM-x32\...\Itibiti_is1) (Version:  - Itibiti Inc.)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft IntelliPoint 8.2 (HKLM\...\Microsoft IntelliPoint 8.2) (Version: 8.20.468.0 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Minecraft 1.8 1.00 (HKLM-x32\...\Minecraft 1.8 1.00) (Version:  - )
Ninja Loader (HKLM-x32\...\Ninja Loader) (Version: 187.0.0.605 - CLICK YES BELOW LP)
OneSoftPerDay 025.014010029 (HKLM-x32\...\ospd_us_014010029_is1) (Version:  - ONESOFTPERDAY)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version:  - )
Peggle Deluxe 1.0 (HKLM-x32\...\Peggle Deluxe 1.0) (Version:  - )
Pro PC Cleaner (HKLM-x32\...\Pro PC Cleaner) (Version: 2.9.6 - Pro PC Cleaner) <==== ATTENTION
RadPlayer (HKLM-x32\...\RadPlayer) (Version: 4.0.1 - RadPlayer)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7373 - Realtek Semiconductor Corp.)
s5mark (HKLM-x32\...\s5mark) (Version: 2.0.2 - s5mark)
shopperz12072015 2.0.0.471 (HKLM\...\{c49ac435-5c4d-450f-aa56-cd31f96613b3}_is1) (Version: 2.0.0.471 - shopperz) <==== ATTENTION
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
Skype™ 7.6 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.6.105 - Skype Technologies S.A.)
Smart Defrag 4 (HKLM-x32\...\Smart Defrag 4_is1) (Version: 4.1 - IObit)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Surfing Protection (HKLM-x32\...\IObit Surfing Protection_is1) (Version: 1.2 - IObit)
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version:  - Valve)
TeamSpeak 3 Client (HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Unity Web Player (HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\UnityWebPlayer) (Version: 4.6.1f1 - Unity Technologies ApS)
WordShark 1.10.0.20 (HKLM-x32\...\WordShark_1.10.0.20) (Version: 1.10.0.20 - WordShark) <==== ATTENTION
Yahoo Search Set (HKLM-x32\...\Yahoo! SearchSet) (Version:  - Yahoo Inc.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-171533428-321824291-3300133993-1000_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
 
==================== Restore Points =========================
 
20-12-2014 20:58:59 Windows Update
29-12-2014 14:54:52 Windows Update
29-12-2014 15:18:35 Driver Booster : ATI I/O Communications Processor SMBus Controller
29-12-2014 15:30:41 Windows Update
29-12-2014 15:40:24 avast! antivirus system restore point
02-01-2015 14:11:56 Windows Update
03-01-2015 12:58:20 Windows Update
03-01-2015 13:55:40 Driver Booster : ATI Mobility Radeon HD 4200
03-01-2015 14:01:52 Installed DirectX
03-01-2015 14:04:54 Installed DirectX
03-01-2015 15:23:04 Windows Update
06-01-2015 19:11:47 Windows Update
06-01-2015 19:17:20 Driver Booster : Standard Enhanced PCI to USB Host Controller
06-01-2015 22:54:53 Windows Update
10-01-2015 13:28:22 Windows Update
10-01-2015 18:49:20 Windows Modules Installer
10-01-2015 18:50:25 Windows Modules Installer
13-01-2015 22:52:49 Windows Update
13-01-2015 22:59:53 Windows Update
17-01-2015 00:03:55 Windows Update
20-01-2015 12:56:59 Windows Update
29-01-2015 11:58:47 Windows Update
01-02-2015 23:43:04 Windows Update
14-02-2015 16:18:57 Windows Update
18-02-2015 11:44:39 Windows Update
04-03-2015 00:24:41 Windows Update
04-03-2015 02:19:43 Windows Update
26-03-2015 17:04:54 Windows Update
26-03-2015 18:18:31 Windows Update
26-03-2015 21:34:16 Driver Booster : Microsoft USB Wheel Mouse Optical
27-03-2015 08:46:30 Windows Update
10-04-2015 17:25:05 Windows Update
14-04-2015 11:25:39 Windows Update
19-04-2015 22:49:10 Windows Update
20-04-2015 01:38:58 avast! antivirus system restore point
20-04-2015 02:35:11 Windows Update
02-05-2015 14:41:02 Windows Update
07-05-2015 11:42:49 Windows Update
19-05-2015 16:18:36 Windows Update
05-06-2015 09:25:54 Windows Update
16-06-2015 08:59:39 Windows Update
25-06-2015 14:46:09 Windows Update
26-06-2015 21:54:42 Windows Update
02-07-2015 11:44:52 Windows Update
06-07-2015 12:33:56 Windows Update
07-07-2015 18:32:29 Installed Blender
10-07-2015 12:20:24 Windows Update
11-07-2015 21:29:57 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
11-07-2015 21:30:39 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
12-07-2015 10:55:13 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
12-07-2015 10:57:03 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
13-07-2015 00:11:07 Windows Update
16-08-2015 16:42:10 Windows Update
19-08-2015 19:03:33 Restore Point Created by FRST
20-08-2015 09:17:28 JRT Pre-Junkware Removal
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2015-08-20 14:57 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-06-13 14:17 - 2015-06-13 14:17 - 00803488 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
2015-07-12 10:52 - 2015-07-12 10:52 - 31404192 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
2015-06-09 22:36 - 2015-06-09 22:36 - 36732592 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\libcef.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\100sexlinks.com -> 100sexlinks.com
 
There are 4788 more restricted sites.
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-171533428-321824291-3300133993-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [TCP Query User{D2634ED2-C857-49F9-9D70-6EEDE30F93AA}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{BCD1E63B-7B19-4611-B08F-1D6056B28592}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{679A6BE7-E2CF-4A66-BB69-908E7F793C03}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{7EBC7126-9722-41CF-BB09-99D8172579E3}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
 
==================== Faulty Device Manager Devices =============
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/23/2015 01:37:53 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/20/2015 02:14:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/20/2015 01:12:25 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/19/2015 10:50:55 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/19/2015 08:04:05 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program FRST64.exe version 17.8.2015.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 828
 
Start Time: 01d0dad32d9e2bfe
 
Termination Time: 4
 
Application Path: C:\Users\Kathy\Desktop\FRST64.exe
 
Report Id: f4409f86-46ce-11e5-9888-1c7508113231
 
Error: (08/19/2015 09:42:57 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IObitUninstaler.exe version 4.3.0.5 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 370c
 
Start Time: 01d0da841eaf97fc
 
Termination Time: 7
 
Application Path: C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
 
Report Id: 2a7b197c-4678-11e5-9888-70f1a1e80b86
 
Error: (08/16/2015 04:38:45 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/16/2015 04:35:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: cpx.exe, version: 1.1.0.1, time stamp: 0x558d0604
Faulting module name: cpx.exe, version: 1.1.0.1, time stamp: 0x558d0604
Exception code: 0xc0000409
Fault offset: 0x0003a8dc
Faulting process id: 0x13f4
Faulting application start time: 0xcpx.exe0
Faulting application path: cpx.exe1
Faulting module path: cpx.exe2
Report Id: cpx.exe3
 
Error: (08/16/2015 04:35:07 PM) (Source: CoupoonService64) (EventID: 1) (User: )
Description: CoupoonService64StartServiceCtrlDispatcher error 1063
 failed with 1063
 
Error: (07/28/2015 08:44:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
 
System errors:
=============
Error: (08/23/2015 01:47:21 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.203.712.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (08/23/2015 01:47:21 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.203.712.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (08/23/2015 01:47:21 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.203.712.0
 
Update Source: %NT AUTHORITY59
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\SYSTEM
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (08/23/2015 01:41:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Steam Client Service service failed to start due to the following error: 
%%1053
 
Error: (08/23/2015 01:41:27 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
 
Error: (08/23/2015 01:38:26 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.203.712.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (08/23/2015 01:38:26 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.203.712.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (08/23/2015 01:38:25 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.203.712.0
 
Update Source: %NT AUTHORITY59
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\SYSTEM
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (08/20/2015 03:03:18 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
 
Error: (08/20/2015 02:43:45 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.203.712.0
 
Update Source: %NT AUTHORITY51
 
Update Stage: 4.8.0204.00
 
Source Path: 4.8.0204.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
 
Microsoft Office:
=========================
Error: (08/23/2015 01:37:53 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/20/2015 02:14:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/20/2015 01:12:25 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/19/2015 10:50:55 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/19/2015 08:04:05 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: FRST64.exe17.8.2015.082801d0dad32d9e2bfe4C:\Users\Kathy\Desktop\FRST64.exef4409f86-46ce-11e5-9888-1c7508113231
 
Error: (08/19/2015 09:42:57 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IObitUninstaler.exe4.3.0.5370c01d0da841eaf97fc7C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe2a7b197c-4678-11e5-9888-70f1a1e80b86
 
Error: (08/16/2015 04:38:45 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (08/16/2015 04:35:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: cpx.exe1.1.0.1558d0604cpx.exe1.1.0.1558d0604c00004090003a8dc13f401d0d862f219501bC:\Program Files (x86)\cpx\cpx.exeC:\Program Files (x86)\cpx\cpx.exe50f87ae5-4456-11e5-9888-70f1a1e80b86
 
Error: (08/16/2015 04:35:07 PM) (Source: CoupoonService64) (EventID: 1) (User: )
Description: CoupoonService64StartServiceCtrlDispatcher error 1063
 failed with 1063
 
Error: (07/28/2015 08:44:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
 
CodeIntegrity:
===================================
  Date: 2015-08-20 13:07:14.877
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2015-08-20 13:07:14.807
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
==================== Memory info =========================== 
 
Processor: AMD Phenom™ II N830 Triple-Core Processor
Percentage of memory in use: 40%
Total physical RAM: 3834.9 MB
Available physical RAM: 2275.61 MB
Total Virtual: 7668 MB
Available Virtual: 5757.04 MB
 
==================== Drives ================================
 
Drive c: (Gateway) (Fixed) (Total:452.66 GB) (Free:190.91 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: F836E349)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=452.7 GB) - (Type=07 NTFS)
 
==================== End of log ============================

  • 0

#12
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Just the final orphans to kill before I tidy up :)
 
 
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 

CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-171533428-321824291-3300133993-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
2015-08-20 13:07 - 2015-07-19 00:12 - 00000000 ____D C:\Program Files (x86)\a1009f48-01fb-4840-a15c-84d1f8624b11
2015-08-20 13:07 - 2015-07-13 13:12 - 00000000 ____D C:\Program Files (x86)\fe94cf4e-c008-4f1a-9cb7-236dfdf7c989
2015-08-20 13:07 - 2015-07-12 23:57 - 00000000 ____D C:\Program Files (x86)\4a1fe953-c74b-463a-ad75-85a9096112df
2015-08-20 09:19 - 2015-07-14 14:11 - 00000000 ____D C:\Program Files\shopperz12072015
2015-08-20 09:16 - 2015-08-23 13:41 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-08-19 19:06 - 2015-07-13 12:14 - 00000000 ____D C:\Program Files (x86)\msrtn32
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers


Save this as fixlist.txt, in the same location as FRST.exe
FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
 
THEN 
 
 
Could you go to control panel > programs and features
Then uninstall the following, windows may say they are not found and offer to remove them accept that :

CinemaPlus-3.2cV13.07
GamesDesktop 025.005010030
GamesDesktop 025.005010031
HQCinema Pro 2.1V12.07
Pro PC Cleaner
shopperz12072015 2.0.0.471
WordShark 1.10.0.20


ANy further problem noticeable before I tidy up and remove my tools
  • 0

#13
moondog830

moondog830

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 626 posts
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:17-08-2015
Ran by Kathy (administrator) on KATHY-PC (24-08-2015 08:00:04)
Running from C:\Users\Kathy\Desktop
Loaded Profiles: Kathy (Available Profiles: Kathy)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Copyright © Microsoft 2015) C:\Program Files (x86)\Microsoft.NET\v2.0.507279\msnetcore.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13774040 2015-01-06] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-07-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [896632 2015-07-22] (BlueStack Systems, Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2303152 2015-07-02] (Adobe Systems Incorporated)
HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2895552 2015-07-23] (Valve Corporation)
HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53282944 2015-06-29] (Skype Technologies S.A.)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.yahoo.com/?fr=hp-ddc-bd&type=bl-bir-ob-rhb-29__alt__ddc_dsssyc_bd_com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-27] (Oracle Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-27] (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{13BA7357-F3CB-44DF-94FB-47B6BD1FF704}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{D464E0FB-F200-41A0-A115-BF3ED0CBE42C}: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2015-07-02] (Adobe Systems)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-27] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-05] (Google Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2015-07-02] (Adobe Systems)
 
Chrome: 
=======
CHR Profile: C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [433784 2015-06-16] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [413304 2015-06-16] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [831096 2015-07-21] (BlueStack Systems, Inc.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2904864 2015-06-02] (IObit)
R2 msdotnetserv_v2050729; C:\Program Files (x86)\Microsoft.NET\v2.0.507279\msnetcore.exe [3003880 2015-07-05] (Copyright © Microsoft 2015)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
S3 Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [838336 2015-07-23] (Valve Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-09-15] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation)
S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [145528 2015-06-16] (BlueStack Systems)
S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation)
S3 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation)
R3 CnxtHdmiAudService; C:\Windows\System32\drivers\CHDMI64.sys [722488 2014-12-29] (Conexant Systems Inc.)
S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [32512 2012-07-24] (Etron Technology Inc)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2014-12-29] (REALiX™)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-23 17:16 - 2015-08-24 07:59 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-08-23 13:53 - 2015-08-23 13:53 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_dc3d_01009.Wdf
2015-08-23 13:50 - 2015-08-23 13:50 - 00000000 ___SD C:\ComboFix
2015-08-23 13:41 - 2015-08-23 13:41 - 00000000 ____D C:\Users\Kathy\AppData\Local\CEF
2015-08-20 15:01 - 2015-08-20 15:01 - 00027245 _____ C:\ComboFix.txt
2015-08-20 13:59 - 2015-08-20 13:59 - 00000000 ____D C:\ProgramData\ProductData
2015-08-20 12:57 - 2011-06-26 02:45 - 00256000 _____ C:\Windows\PEV.exe
2015-08-20 12:57 - 2010-11-07 13:20 - 00208896 _____ C:\Windows\MBR.exe
2015-08-20 12:57 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-08-20 12:57 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-08-20 12:57 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-08-20 12:57 - 2000-08-30 20:00 - 00098816 _____ C:\Windows\sed.exe
2015-08-20 12:57 - 2000-08-30 20:00 - 00080412 _____ C:\Windows\grep.exe
2015-08-20 12:57 - 2000-08-30 20:00 - 00068096 _____ C:\Windows\zip.exe
2015-08-20 12:41 - 2015-08-23 13:50 - 00000000 ____D C:\Qoobox
2015-08-20 12:41 - 2015-08-20 14:10 - 00000000 ____D C:\Windows\erdnt
2015-08-20 12:40 - 2015-08-20 12:38 - 05635271 ____R (Swearware) C:\Users\Kathy\Desktop\ComboFix.exe
2015-08-19 22:41 - 2015-08-20 09:27 - 00000000 ____D C:\AdwCleaner
2015-08-19 19:01 - 2015-08-19 17:56 - 01585664 _____ C:\Users\Kathy\Desktop\AdwCleaner.exe
2015-08-19 19:01 - 2015-08-19 17:55 - 01798576 _____ (Malwarebytes Corporation) C:\Users\Kathy\Desktop\JRT.exe
2015-08-19 10:09 - 2015-08-23 13:57 - 00027412 _____ C:\Users\Kathy\Desktop\Addition.txt
2015-08-19 10:07 - 2015-08-24 08:00 - 00011480 _____ C:\Users\Kathy\Desktop\FRST.txt
2015-08-19 09:46 - 2015-08-24 08:00 - 00000000 ____D C:\FRST
2015-08-19 09:46 - 2015-08-19 09:35 - 02173440 _____ (Farbar) C:\Users\Kathy\Desktop\FRST64.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-24 08:02 - 2009-07-14 00:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-24 08:02 - 2009-07-14 00:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-24 08:01 - 2015-06-30 18:46 - 00000000 ____D C:\Program Files (x86)\Steam
2015-08-24 07:58 - 2014-12-20 23:49 - 01757385 _____ C:\Windows\WindowsUpdate.log
2015-08-24 07:56 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-24 07:55 - 2015-04-20 03:00 - 00007706 _____ C:\Windows\setupact.log
2015-08-20 14:57 - 2009-07-13 22:34 - 00000215 _____ C:\Windows\system.ini
2015-08-20 14:11 - 2015-04-20 03:00 - 00560254 _____ C:\Windows\PFRO.log
2015-08-20 14:10 - 2009-07-13 22:34 - 69492736 _____ C:\Windows\system32\config\SOFTWARE.bak
2015-08-20 14:10 - 2009-07-13 22:34 - 16252928 _____ C:\Windows\system32\config\SYSTEM.bak
2015-08-20 14:10 - 2009-07-13 22:34 - 00266240 _____ C:\Windows\system32\config\DEFAULT.bak
2015-08-20 14:10 - 2009-07-13 22:34 - 00065536 _____ C:\Windows\system32\config\SAM.bak
2015-08-20 14:10 - 2009-07-13 22:34 - 00024576 _____ C:\Windows\system32\config\SECURITY.bak
2015-08-20 13:18 - 2009-07-13 23:20 - 00000000 __RHD C:\Users\Default
2015-08-20 13:08 - 2009-07-13 22:34 - 38273024 _____ C:\Windows\system32\config\COMPONENTS.bak
2015-08-20 13:07 - 2015-07-12 10:50 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-08-20 12:41 - 2015-07-09 23:44 - 00000000 ____D C:\Users\Kathy\AppData\Roaming\Skype
2015-08-20 09:19 - 2014-12-29 14:58 - 00000000 ____D C:\Users\Kathy\AppData\Roaming\IObit
2015-08-20 09:19 - 2014-12-29 14:58 - 00000000 ____D C:\ProgramData\IObit
2015-08-20 09:19 - 2014-12-29 14:58 - 00000000 ____D C:\Program Files (x86)\IObit
2015-08-19 22:43 - 2014-12-20 21:05 - 00000996 _____ C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-19 19:05 - 2015-01-03 13:31 - 00000000 ____D C:\Windows\System32\Tasks\Games
2015-08-19 09:48 - 2009-07-14 01:13 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-16 16:50 - 2015-07-13 00:01 - 00000000 ____D C:\Program Files (x86)\baidu
2015-08-16 16:46 - 2015-04-14 12:14 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-08-16 16:45 - 2015-04-14 12:14 - 00000000 ___SD C:\Windows\system32\GWX
2015-08-16 16:40 - 2015-06-30 18:16 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2015-08-16 16:30 - 2015-06-30 18:16 - 00000000 ____D C:\Program Files (x86)\BlueStacks
2015-07-28 20:42 - 2014-12-29 15:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
 
==================== Files in the root of some directories =======
 
2015-01-03 14:00 - 2015-01-03 14:00 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-08-19 19:33
 
==================== End of log ============================
 
 
On each of the ones you wanted me to delete ... i get the same message .. "an error occurred while trying to uninstall xxxxxx. It may have already been uninstalled. would you like to remove xxxxxx from the Programs and Features list. I clicked yes ...

  • 0

#14
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Grand :)   Time to send you on your merry way I feel

Subject to no further problems :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset System Restore points:

Remove Combofix

Click Start then Run.
On Windows7 or Vista you may use Start Search field if Run is not available.
In the box copy/paste the following command:

ComboFix /Uninstall

Note that there is a space between " ComboFix " and " /Uninstall " .

Then click OK (or press Enter ).
Wait for the uninstall process to complete.

Remove tools

Download and run Delfix
Select the options as shown
delfix.JPG


: Keep Java Updated :

WARNING: Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
See this article

I would recommend that you completely uninstall Java unless you need it to run an important software.
In that instance I would recommend that you disable Java in your browsers until you need it for that software and then enable it. (See How to diasble Java in your web browser and How to unplug Java from the browser)

If you do need to keep Java then download JavaRa
Run the programme and select Remove Java Runtime. Uninstall all versions of Java present
Once done then run it again and select Update Java runtime > Download and install Latest version
javara.JPG


Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

Malwarebytes

Update and run weekly to keep your system clean

Unchecky

Click on the link above to be taken to Unchecky.com
click the very large Download button.
click Save
Click Open folder
Right click on the Unchecky_setup and choose to Run as Administrator
Once open click the Install button.
Then click on Finish
Unchecky is now installed and will help you keep unwanted check boxes unchecked, this is a fire and forget programme ;)

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To learn more about how to protect yourself while on the internet read this little guide Best security practices Keep safe :wave:
  • 0

#15
moondog830

moondog830

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 626 posts

All complete now ... thanks a lot for the help ... I'm sure she will be very greatful ... but I will continue to warn her about her grandson :o)

 

dog


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP