I will make an extra effort to tell them to keep their grandson off of their computer ... we'll see how that works.
Fixlog
Fix result of Farbar Recovery Scan Tool (x64) Version:17-08-2015
Ran by Kathy (2015-08-19 19:03:31) Run:1
Running from C:\Users\Kathy\Desktop
Loaded Profiles: Kathy (Available Profiles: Kathy)
Boot Mode: Normal
==============================================
fixlist content:
*****************
CreateRestorePoint:
HKLM\...\Run: [RadPlayer Tray] => C:\Program Files (x86)\RadPlayer\TyV1.exe [294824 2015-05-29] (RadPlayer)
HKLM\...\Run: [shopperz12072015] => C:\Program Files\shopperz12072015\Bzvra.exe [433512 2015-07-13] ()
HKLM\...\Run: [shopperz1207201564] => C:\Program Files\shopperz12072015\Bzvra64.exe [464744 2015-07-13] ()
HKLM-x32\...\Run: [StormWatch] => C:\Program Files (x86)\StormWatch\StormWatchApp.exe [1556504 2015-04-10] ()
HKLM-x32\...\Run: [cpx] => C:\Program Files (x86)\cpx\cpx.exe [1162240 2015-06-26] ()
HKLM-x32\...\Run: [msrtn32] => C:\Program Files (x86)\msrtn32\msrtn32.exe [1221120 2015-06-28] ()
HKLM-x32\...\Run: [WinCheck] => C:\Users\Kathy\AppData\Local\5670549A-1436745935-DE00-E918-1C7508113231\bnshDF4A.exe [350720 2015-06-24] ()
HKLM-x32\...\Run: [gmsd_us_005010030] => C:\Program Files (x86)\gmsd_us_005010030\gmsd_us_005010030.exe [3986064 2015-07-13] ()
HKLM-x32\...\Run: [mwyyntm1ndi1zdz] => C:\Program Files (x86)\Smwyyntm1ndi1zdz\ywi2mzv2zhnjbdh.exe [2422272 2015-07-13] ()
HKLM-x32\...\Run: [gmsd_us_005010031] => C:\Program Files (x86)\gmsd_us_005010031\gmsd_us_005010031.exe [3985552 2015-07-14] ()
HKLM-x32\...\Run: [MovieDea] => C:\Program Files (x86)\MovieDea\MovieDea.exe [3184640 2015-06-03] (MovieDea)
HKLM-x32\...\Run: [SmartWeb] => C:\Users\Kathy\AppData\Local\SmartWeb\SmartWebHelper.exe [270368 2015-02-17] (SoftBrain Technologies Ltd.)
HKLM-x32\...\RunOnce: [upospd_us_014010029.exe] => C:\Users\Kathy\AppData\Local\ospd_us_014010029\upospd_us_014010029.exe [3287696 2015-07-12] ()
HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Run: [NinjaLoader] => C:\Program Files (x86)\Ninja Loader\Ninja Loader.exe [1575016 2015-07-02] (CLICK YES BELOW LP)
HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro 3.99\OptProLauncher.exe [148112 2015-07-03] ()
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll [246544 2015-07-02] (Client Connect LTD)
AppInit_DLLs: C:\ProgramData\FlashBeat\FlashBeat64.dll => C:\ProgramData\FlashBeat\FlashBeat64.dll File not found
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [213776 2015-07-02] (Client Connect LTD)
AppInit_DLLs-x32: C:\ProgramData\FlashBeat\FlashBeat32.dll => C:\ProgramData\FlashBeat\FlashBeat32.dll [805376 2015-07-13] (FlashBeat)
AppInit_DLLs-x32: C:\ProgramData\EpsanDrive\EpsanDrive32.dll => C:\ProgramData\EpsanDrive\EpsanDrive32.dll [805376 2015-07-08] (EpsanDrive)
AppInit_DLLs-x32: C:\PROGRA~3\{63B88~1\1173~1.1\tiso.dll => "C:\PROGRA~3\{63B88~1\1173~1.1\tiso.dll" File not found
Startup: C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bm.lnk [2015-07-18]
ShortcutTarget: bm.lnk -> C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh\yxa2bzvwzf9jdth.exe (PU-App)
Startup: C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk [2015-07-13]
ShortcutTarget: crossbrowse.lnk -> C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe (No File)
Startup: C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk [2015-07-18]
ShortcutTarget: SmartWeb.lnk -> C:\Users\Kathy\AppData\Local\SmartWeb\SmartWebHelper.exe (SoftBrain Technologies Ltd.)
Startup: C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatch.lnk [2015-07-12]
ShortcutTarget: StormWatch.lnk -> C:\Program Files (x86)\StormWatch\StormWatch.exe (Weather Protector LLC)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-171533428-321824291-3300133993-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
URLSearchHook: HKU\S-1-5-21-171533428-321824291-3300133993-1000 - (No Name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - No File
SearchScopes: HKLM -> OldSearch URL = hxxp://www.cassiopessa.com/results.php?f=4&q={searchTerms}&a=csp_installertech_15_26&cd=2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0EzztD0BzzyCtByDyDtAtN0D0Tzu0StCtByBtAtN1L2XzutAtFtCtCtFtAtFtCtN1L1Czu1R1B1E1V1L1G1B2Z1T1I1I1P1C2Z1P1R1MtN1L1G1B1V1N2Y1L1Qzu2StB0A0BtCtCyB0C0BtGyCyCtAtAtG0Azz0BtBtGyEzzyCzytGtBzz0C0ByE0DyB0BtA0D0F0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0E0DyC0E0DzytBtGtBtD0D0FtGyE0FtA0EtG0B0AtB0EtGyEzy0AtByByEzzyC0F0E0FtD2QtN0A0LzuyEtN1B2Z1V1T1S1NzuzztBtB&cr=1202157401&ir=
SearchScopes: HKLM-x32 -> {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://start.iminent.com/?appId=8437c40c-c891-4a5e-8eea-ca8568502d51&ref=toolbox&q={searchTerms}
SearchScopes: HKU\S-1-5-21-171533428-321824291-3300133993-1000 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3333887&octid=EB_ORIGINAL_CTID&ISID=M1890E6BC-BF65-41CA-B1ED-FCA8EC054D11&SearchSource=58&CUI=&UM=8&UP=SPA98636E4-750F-401C-BC08-F5A740811DAD&D=071415&q={searchTerms}&SSPV=SP30339T2B_sp_ie
SearchScopes: HKU\S-1-5-21-171533428-321824291-3300133993-1000 -> {BC4A5ADC-08EE-4734-9171-5A5035FF16D7} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-07-18] (IObit)
BHO: IMinent WebBooster (BHO) -> {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} -> C:\Program Files (x86)\Iminent\Minibar.InternetExplorer.BHOx64.dll [2015-06-10] (SIEN)
BHO: Consumer Input DCA BHO -> {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} -> C:\Program Files (x86)\Consumer Input\InternetExplorer\x64\dca-bho.dll [2015-06-25] (Compete, Inc.)
BHO: shopperz12072015 -> {c49ac435-5c4d-450f-aa56-cd31f96613b3} -> C:\Program Files\shopperz12072015\Eixrizl64.dll [2015-07-13] ()
BHO-x32: No Name -> {84FF7BD6-B47F-46F8-9130-01B2696B36CB} -> No File
BHO-x32: IMinent WebBooster (BHO) -> {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} -> C:\Program Files (x86)\Iminent\Minibar.InternetExplorer.BHOx86.dll [2015-06-10] (SIEN)
BHO-x32: Consumer Input DCA BHO -> {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} -> C:\Program Files (x86)\Consumer Input\InternetExplorer\dca-bho.dll [2015-06-25] (Compete, Inc.)
BHO-x32: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2015-04-01] (IObit)
BHO-x32: shopperz12072015 -> {c49ac435-5c4d-450f-aa56-cd31f96613b3} -> C:\Program Files\shopperz12072015\Eixrizl.dll [2015-07-13] ()
Winsock: Catalog9 01 C:\Windows\SysWOW64\Cofvopjy.dll [279040 2015-07-14] ()
Winsock: Catalog9 02 C:\Windows\SysWOW64\Cofvopjy.dll [279040 2015-07-14] ()
Winsock: Catalog9 03 C:\Windows\SysWOW64\Cofvopjy.dll [279040 2015-07-14] ()
Winsock: Catalog9 04 C:\Windows\SysWOW64\Cofvopjy.dll [279040 2015-07-14] ()
Winsock: Catalog9 05 C:\Windows\SysWOW64\myradioplayer.dll [358824 2015-07-12] (myradioplayer)
Winsock: Catalog9 06 C:\Windows\SysWOW64\myradioplayer.dll [358824 2015-07-12] (myradioplayer)
Winsock: Catalog9 07 C:\Windows\SysWOW64\myradioplayer.dll [358824 2015-07-12] (myradioplayer)
Winsock: Catalog9 08 C:\Windows\SysWOW64\myradioplayer.dll [358824 2015-07-12] (myradioplayer)
Winsock: Catalog9 19 C:\Windows\SysWOW64\myradioplayer.dll [358824 2015-07-12] (myradioplayer)
Winsock: Catalog9 20 C:\Windows\SysWOW64\Cofvopjy.dll [279040 2015-07-14] ()
Winsock: Catalog9-x64 01 C:\Windows\system32\myradioplayer64.dll [465320 2015-07-12] (myradioplayer)
Winsock: Catalog9-x64 02 C:\Windows\system32\myradioplayer64.dll [465320 2015-07-12] (myradioplayer)
Winsock: Catalog9-x64 03 C:\Windows\system32\myradioplayer64.dll [465320 2015-07-12] (myradioplayer)
Winsock: Catalog9-x64 04 C:\Windows\system32\myradioplayer64.dll [465320 2015-07-12] (myradioplayer)
Winsock: Catalog9-x64 15 C:\Windows\system32\myradioplayer64.dll [465320 2015-07-12] (myradioplayer)
FF Plugin: @iqiyi.com/npclient -> C:\IQIYI Video\LStyle\npclient.dll [2015-05-12] ()
FF Plugin: @iqiyi.com/npWebPlayer -> C:\IQIYI Video\LStyle\npWebPlayer.dll [2015-04-29] (?????)
FF Plugin-x32: @iqiyi.com/npclient -> C:\IQIYI Video\LStyle\npclient.dll [2015-05-12] ()
FF Plugin-x32: @iqiyi.com/npWebPlayer -> C:\IQIYI Video\LStyle\npWebPlayer.dll [2015-04-29] (?????)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-07-19] (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-07-19] (globalUpdate)
FF Plugin HKU\S-1-5-21-171533428-321824291-3300133993-1000: @iqiyi.com/npWebPlayer -> C:\IQIYI Video\LStyle\npWebPlayer.dll [2015-04-29] (?????)
FF Plugin HKU\S-1-5-21-171533428-321824291-3300133993-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Kathy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-12-05] (Unity Technologies ApS)
FF HKLM\...\Firefox\Extensions: [{c49ac435-5c4d-450f-aa56-cd31f96613b3}] - C:\Program Files\shopperz12072015\Firefox
FF Extension: shopperz12072015 - C:\Program Files\shopperz12072015\Firefox [2015-07-14]
FF HKLM-x32\...\Firefox\Extensions: [{c49ac435-5c4d-450f-aa56-cd31f96613b3}] - C:\Program Files\shopperz12072015\Firefox
FF HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Firefox\Extensions: [ConsumerInput@Compete] - C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12191.xpi
FF Extension: Consumer Input - C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12191.xpi [2015-06-25]
FF HKU\S-1-5-21-171533428-321824291-3300133993-1000\...\Firefox\Extensions: [
[email protected]] - C:\Program Files (x86)\Ninja Loader\FireFox
FF Extension: NinjaLoader - C:\Program Files (x86)\Ninja Loader\FireFox [2015-07-13]
CHR Extension: (HQCinema Pro 2.1V12.07) - C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gegdfeiahlfolhcfioipjlkombmgbakh [2015-07-12]
CHR Extension: (CinemaPlus-3.2cV13.07) - C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\papbadoldddalgcjcicnikcfenodpghp [2015-07-13]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]
R2 46784c7a-2afb-4c2f-b299-133de9a46a66; C:\Program Files\shopperz12072015\Igivkorcb.exe [285544 2015-07-13] ()
S2 c31ed948; c:\Program Files (x86)\Optimizer Pro 3.99\OptProMon.dll [2570896 2015-07-13] () <==== ATTENTION
R3 Cofvopjy; C:\Program Files\shopperz12072015\Cofvopjy.exe [2020864 2015-07-13] () [File not signed]
S2 consumerinput_update; C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [105944 2015-07-12] (ConsumerInput)
S3 consumerinput_updatem; C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [105944 2015-07-12] (ConsumerInput)
S2 CoupoonService64; C:\Program Files (x86)\coupoon\iiwjljrnpc64.exe [172344 2015-04-02] ()
R2 csrcc; C:\Program Files\shopperz12072015\csrcc.exe [1448808 2015-07-13] ()
R2 Dataup; C:\Program Files (x86)\dataup\dataup.exe [77824 2015-06-29] () [File not signed] <==== ATTENTION
S2 FlashBeat; C:\ProgramData\FlashBeat\FlashBeat.exe [814080 2015-07-13] (FlashBeat) [File not signed]
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-07-19] (globalUpdate) [File not signed] <==== ATTENTION
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-07-19] (globalUpdate) [File not signed] <==== ATTENTION
R2 GlobalUpdater; C:\Program Files (x86)\Common Files\IMGUpdater\IMGUpdater.exe [378152 2015-07-02] (SIEN S.A.)
R2 IMService; C:\Program Files (x86)\Common Files\Umbrella\Umbrella234.exe [5315224 2015-07-02] (Iminent)
R2 LosdyLijfeu; C:\Program Files\shopperz12072015\ZazyjiKotn.exe [171920 2015-07-13] () [File not signed]
R2 myradioplayer; C:\Program Files (x86)\RadPlayer\myradioplayer.exe [3904936 2015-05-29] (myradioplayer)
R2 NinjaLoaderService; C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe [59496 2015-07-02] (Ninja Soft Inc.)
R2 RadPlayerV1; C:\Program Files (x86)\RadPlayer\RadPlayerSvc.exe [323496 2015-05-29] (RadPlayer)
S2 RadPlayerV2; C:\Program Files (x86)\RadPlayer\RadPlayer.Service.exe [78248 2015-05-29] (RadPlayer)
R2 REhsGdKiASD; C:\ProgramData\caGSSMRD\REhsGdKiASD.exe [2732288 2015-07-13] (Valid Applications)
R2 relibily; C:\Users\Kathy\AppData\Local\5670549A-1436745948-DE00-E918-1C7508113231\cnsh175B.tmp [219136 2015-07-13] () [File not signed]
R2 serveras; C:\Users\Kathy\AppData\Roaming\ASPackage\ASSrv.exe [183808 2015-07-13] () [File not signed]
R2 shopperz12072015 Updater; C:\Program Files\shopperz12072015\Xzeexmh.exe [174952 2015-07-13] ()
R2 StormWatch Update Service; C:\Program Files (x86)\StormWatch\StormWatchSrv.exe [586264 2015-04-10] ()
R2 SWUpdater; C:\Program Files (x86)\StormWatch\SWUpdaterSvc.exe [17584 2014-11-22] (Weather Protector LLC)
R2 UdvdPork; C:\ProgramData\1436760085\s9.exe [404480 2015-04-07] () [File not signed]
R2 UpdateCheck; C:\Program Files (x86)\Coupoon\UpdateCheck.exe [53040 2015-07-12] ()
R2 WajIEn Monitor; C:\Program Files\WajIEn\wajam_64.exe [1997824 2015-07-13] () [File not signed]
S2 wbsvc; C:\Program Files\WebBar\wbsvc.exe [37144 2015-02-18] (Web Bar Media)
R2 windowsmanagementservice; C:\Users\Kathy\AppData\Local\Temp\20150713\ct.exe [848384 2015-06-29] (Google Inc.) [File not signed]
R2 wssvc_1.10.0.20; C:\Program Files (x86)\WordShark_1.10.0.20\Service\wssvc.exe [300120 2015-07-06] (WS)
S2 SMUpdPlus; no ImagePath
R1 cherimoya; C:\Windows\System32\drivers\cherimoya.sys [61336 2015-06-18] (Cherimoya Ltd)
S3 SMUpdd; no ImagePath
S1 vfbhiosb; C:\Windows\system32\drivers\vfbhiosb.sys [55168 2015-08-16] (Microsoft Corporation)
R1 wsfd_vt_1_10_0_20; C:\Windows\System32\drivers\wsfd_vt_1_10_0_20.sys [61312 2015-07-06] (WS)
R1 ywi2mzv2zhnjbdh; C:\Windows\System32\drivers\ywi2mzv2zhnjbdh.sys [50520 2015-07-13] (Windows ® Win 7 DDK provider)
2015-08-16 16:50 - 2015-08-16 16:50 - 00055168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vfbhiosb.sys
2015-08-16 16:39 - 2015-08-16 16:39 - 00000000 ____D C:\Users\Kathy\AppData\Local\CEF
2015-07-28 20:15 - 2015-07-28 20:16 - 00000000 ____D C:\Program Files (x86)\GUMBFC5.tmp
2015-07-28 20:15 - 2015-07-28 20:15 - 06420480 _____ C:\Program Files (x86)\GUTC294.tmp
2015-07-28 20:15 - 2015-07-28 20:15 - 00000010 _____ C:\Windows\TEMPcoral.vbs
2015-07-28 20:15 - 2015-07-28 20:15 - 00000000 ____D C:\ProgramData\Ninja Loader
2015-07-28 20:10 - 2015-07-28 20:42 - 00118082 _____ C:\Windows\SysWOW64\debug.log
2015-08-19 10:08 - 2015-07-12 23:59 - 00000360 _____ C:\Windows\Tasks\CIMT_S-1-5-21-171533428-321824291-3300133993-1000.job
2015-08-19 10:05 - 2015-07-19 00:04 - 00002112 _____ C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user.job
2015-08-19 10:05 - 2015-07-12 23:56 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-08-19 10:04 - 2015-07-13 12:59 - 00000342 ____H C:\Windows\Tasks\GLQHQICXMFBVKQCB.job
2015-08-19 10:01 - 2015-07-12 23:56 - 00000968 _____ C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job
2015-08-19 09:58 - 2015-07-12 23:58 - 00003140 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.job
2015-08-19 09:57 - 2015-07-12 23:57 - 00005520 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-6.job
2015-08-19 09:55 - 2015-07-12 23:55 - 00002114 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user.job
2015-08-19 09:33 - 2015-07-13 13:29 - 00003254 _____ C:\Windows\System32\Tasks\Optimizer Pro Schedule
2015-08-19 09:32 - 2015-07-13 13:09 - 00002112 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user.job
2015-08-16 22:53 - 2015-07-19 00:13 - 00005862 _____ C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job
2015-08-16 22:53 - 2015-07-13 13:13 - 00003138 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.job
2015-08-16 22:53 - 2015-07-13 13:12 - 00005518 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.job
2015-08-16 16:40 - 2015-07-12 11:01 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-08-16 16:39 - 2015-07-14 14:16 - 00004704 _____ C:\Windows\SysWOW64\Cofvopjy.ini
2015-08-16 16:39 - 2015-07-14 14:16 - 00002416 _____ C:\Windows\SysWOW64\CofvopjyOff.ini
2015-08-16 16:39 - 2015-07-14 14:16 - 00002416 _____ C:\Windows\system32\CofvopjyOff.ini
2015-08-16 16:37 - 2015-07-13 00:01 - 00000000 ____D C:\Users\Kathy\AppData\Local\ospd_us_014010029
2015-08-16 16:36 - 2015-07-13 12:15 - 00000000 ____D C:\Users\Kathy\AppData\Local\mstrn32
2015-08-16 16:34 - 2015-07-13 13:15 - 00000996 _____ C:\Windows\Tasks\WdEL9n2eiowr.job
2015-08-16 16:34 - 2015-07-12 23:59 - 00000986 _____ C:\Windows\Tasks\FYLVp79.job
2015-08-16 16:33 - 2015-07-19 00:13 - 00005518 _____ C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7.job
2015-08-16 16:33 - 2015-07-19 00:07 - 00004494 _____ C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3.job
2015-08-16 16:33 - 2015-07-13 13:15 - 00002446 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user.job
2015-08-16 16:33 - 2015-07-13 13:14 - 00002446 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.job
2015-08-16 16:33 - 2015-07-13 13:13 - 00003474 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7.job
2015-08-16 16:33 - 2015-07-13 13:12 - 00005518 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7.job
2015-08-16 16:33 - 2015-07-13 13:10 - 00004494 _____ C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3.job
2015-08-16 16:33 - 2015-07-13 13:07 - 00001056 _____ C:\Windows\Tasks\Crossbrowse.job
2015-08-16 16:33 - 2015-07-12 23:59 - 00002448 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user.job
2015-08-16 16:33 - 2015-07-12 23:59 - 00002448 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5.job
2015-08-16 16:33 - 2015-07-12 23:58 - 00003476 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7.job
2015-08-16 16:33 - 2015-07-12 23:57 - 00005184 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-7.job
2015-08-16 16:33 - 2015-07-12 23:56 - 00004496 _____ C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-3.job
2015-08-16 16:33 - 2015-07-12 23:56 - 00000970 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-08-16 16:33 - 2015-07-12 23:56 - 00000964 _____ C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job
2015-08-16 16:33 - 2015-07-12 23:55 - 00000342 ____H C:\Windows\Tasks\JWRTYVMXFBIVCPWL.job
2015-08-16 16:33 - 2015-07-12 23:55 - 00000336 _____ C:\Windows\Tasks\NLSAGZR1.job
2015-07-28 20:22 - 2015-07-13 16:29 - 00003444 _____ C:\Windows\System32\Tasks\Epuifuuva
2015-07-28 20:15 - 2015-07-13 12:08 - 00000000 ____D C:\Users\Kathy\AppData\Local\Ninja Loader
2015-07-28 20:12 - 2014-12-29 14:58 - 00000000 ____D C:\ProgramData\ProductData
2015-07-28 20:15 - 2015-07-28 20:15 - 6420480 _____ () C:\Program Files (x86)\GUTC294.tmp
2015-07-18 21:58 - 2015-07-18 21:58 - 6420480 _____ () C:\Program Files (x86)\GUTFD53.tmp
2015-04-19 08:20 - 2015-04-19 08:20 - 0005872 _____ () C:\Users\Kathy\AppData\Roaming\FYLVp79
2015-04-20 10:05 - 2015-04-20 10:05 - 1579520 _____ () C:\Users\Kathy\AppData\Roaming\FYLVp79.exe
2015-04-19 08:20 - 2015-04-19 08:20 - 0005872 _____ () C:\Users\Kathy\AppData\Roaming\WdEL9n2eiowr
2015-04-20 10:05 - 2015-04-20 10:05 - 1579520 _____ () C:\Users\Kathy\AppData\Roaming\WdEL9n2eiowr.exe
2015-07-13 13:52 - 2015-07-13 13:52 - 0613255 _____ (CMI Limited) C:\Users\Kathy\AppData\Local\nsiBAD8.tmp
2015-07-28 20:08 - 2015-07-19 00:16 - 00005086 _____ C:\Windows\Tasks\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job
Task: {01A22A0D-37F6-4D85-A408-491ACA67BF31} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-6 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-6.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {02956738-DE99-47D8-A6C6-DCEE22EE7C4B} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {0473C0CA-9A3F-462C-9BB2-BB768544A91A} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-3 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-3.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {0C67CC53-4D97-46D6-A447-A0C70698D63C} - System32\Tasks\WebBarUpdateTask => C:\Program Files\WebBar\wbsvc.exe [2015-02-18] (Web Bar Media) <==== ATTENTION
Task: {12826CD3-979A-4778-9E55-62298738037F} - System32\Tasks\WdEL9n2eiowr => C:\Users\Kathy\AppData\Roaming\WdEL9n2eiowr.exe [2015-04-20] () <==== ATTENTION
Task: {13C77BBA-4D9D-4CC4-9783-0F09749EBC89} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {168DBC36-AAF6-4F39-8483-52C63048B4FE} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {1BEAFD01-BB2F-4D5D-A4CB-F3456C100409} - System32\Tasks\ConsumerInputUpdateTaskMachineUA => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [2015-07-12] (ConsumerInput) <==== ATTENTION
Task: {1D2B5213-0A0B-4933-8409-5B6CCA9D31C4} - System32\Tasks\SMW_UpdateTask_Time_333833393739363037312d235b783432415b45345a2d6c => Wscript.exe //B "C:\ProgramData\SearchModulePlus\smhe.js" smu.exe /invoke /f:check_services /l:0 <==== ATTENTION
Task: {1EC32D4B-9503-4E11-9581-F33F5490D6C8} - System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10.exe [2015-07-19] (Cinema PlusV18.07) <==== ATTENTION
Task: {25FCAB52-144F-4DF6-9ED8-A783CF9663E3} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {26C1D14B-D736-4340-AA04-29E5B0EE9912} - System32\Tasks\CIMT_S-1-5-21-171533428-321824291-3300133993-1000 => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe [2015-06-19] () <==== ATTENTION
Task: {2C86BA2E-43EA-43C1-9CC7-DC321BFFF485} - System32\Tasks\Snmix => C:\Program Files\shopperz12072015\Ubehsi.bat [2015-07-13] () <==== ATTENTION
Task: {325746AD-5A6F-430F-8E30-6CD44422ABDB} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {36F19701-E5F7-4483-856F-F95E73176541} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {3C325D05-59F7-4AA8-A14C-0D30C25CACC4} - System32\Tasks\Driver Booster SkipUAC (SYSTEM) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2015-07-06] (IObit)
Task: {41F7B16E-395A-4581-81BD-04F429088AC9} - System32\Tasks\Driver Booster SkipUAC (Kathy) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2015-07-06] (IObit)
Task: {423821BC-96E6-4D84-9341-34C7D6544576} - System32\Tasks\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6 => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.exe [2015-07-19] (Cinema PlusV18.07) <==== ATTENTION
Task: {4315E182-2227-4C77-880F-D8ED0781664D} - System32\Tasks\NLSAGZR1 => C:\ProgramData\EpsanDrive\EpsanDrive.exe [2015-07-08] (EpsanDrive) <==== ATTENTION
Task: {46EEB3FE-4979-4D71-B642-E6812F1A1B63} - System32\Tasks\SMWPUpd => C:\Program Files\Common Files\Goobzo\GBUpdatePlus\updater.exe <==== ATTENTION
Task: {4F7AA969-E2FB-46AC-A550-70B132457A08} - System32\Tasks\Smp => C:\Program Files\Common Files\Goobzo\GBUpdatePlus\smp.exe <==== ATTENTION
Task: {519D5601-B701-4EF4-942D-023EB0776066} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files (x86)\Optimizer Pro 3.99\OptProLauncher.exe [2015-07-03] () <==== ATTENTION
Task: {536F625C-BFB1-4834-BC2B-BD6198974A9E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-29] (Google Inc.)
Task: {58BC472B-603B-41F5-A0F2-3D4FBD8E8B49} - System32\Tasks\WebBarLaunchTask => C:\Program Files\WebBar\wbsvc.exe [2015-02-18] (Web Bar Media) <==== ATTENTION
Task: {5AE88653-7D39-4018-A2D6-1B1865993C94} - System32\Tasks\BD634EFB-4435-4228-B1B1-B9F4709D5F79 => C:\Users\Kathy\AppData\Local\BD634EFB-4435-4228-B1B1-B9F4709D5F79\BD634EFB-4435-4228-B1B1-B9F4709D5F79.exe [2015-07-18] () <==== ATTENTION
Task: {5B84AF85-C877-4407-9B54-51E465C67CD3} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {5BAFB821-7E9C-44DA-8FF3-BA06AA1A580A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-26] (Adobe Systems Incorporated)
Task: {5D16852C-3009-4836-B678-96DD5F24BE7B} - System32\Tasks\ConsumerInputUpdateTaskMachineCore => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe [2015-07-12] (ConsumerInput) <==== ATTENTION
Task: {610A4D52-9E85-4E0B-A680-BEA500D4EF11} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-29] (Google Inc.)
Task: {691E87A2-9D64-45C3-A667-ABE98310143F} - System32\Tasks\GLQHQICXMFBVKQCB => C:\ProgramData\Service1291\Service1291.exe [2015-06-28] () <==== ATTENTION
Task: {6F7B2104-C5A2-4870-8DAA-94359F4B295E} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {80ECF25B-E055-4C3B-B841-3F10B6413105} - System32\Tasks\Crossbrowse => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION
Task: {83886EC4-445C-4DB0-9EB6-83B465472564} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-5.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {88726888-5908-4FB8-A3FA-9043CB5B1478} - System32\Tasks\WordShark Auto Updater 1.10.0.20 Core => C:\Program Files (x86)\WordShark_1.10.0.20\Update\WordSharkAutoUpdateClient.exe [2015-07-06] (WS) <==== ATTENTION
Task: {8C648E3B-AA13-45C1-832C-77C99013C7F4} - System32\Tasks\ProPCCleaner_Start => C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe [2015-07-09] (Pro PC Cleaner) <==== ATTENTION
Task: {8D2D9211-2FB9-4C3E-AB7B-548D36C48621} - System32\Tasks\Epuifuuva => C:\ProgramData\Epuifuuva\1.0.4.1\allomlom.exe [2015-07-13] ()
Task: {8E797C65-1C95-4E33-BD35-2B67CFA422CC} - System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6 => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.exe [2015-07-19] (Cinema PlusV18.07) <==== ATTENTION
Task: {8F31C890-7EC5-49DE-B3B9-7476E1ADAD00} - System32\Tasks\CIMT_daily_S-1-5-21-171533428-321824291-3300133993-1000 => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe [2015-06-19] () <==== ATTENTION
Task: {8FCE26CD-8109-40D2-84C9-EC4D6052F068} - System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3 => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3.exe [2015-07-19] (Cinema PlusV18.07) <==== ATTENTION
Task: {9A4092C6-EB94-4323-A130-EEA16B56DCD3} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-07-19] (globalUpdate) <==== ATTENTION
Task: {9A6CF26F-A597-49B7-8D92-A65B8241C305} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-10.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {9C38A35C-5BD6-4388-BC91-FED16EF2B1F4} - System32\Tasks\Games\UpdateCheck_S-1-5-21-171533428-321824291-3300133993-1000
Task: {9DC79A38-C865-43F3-9280-76CE0AC74000} - System32\Tasks\Uninstaller_SkipUac_Kathy => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2015-05-20] (IObit)
Task: {ACC2C1A7-672C-479B-91FF-EB6428145187} - System32\Tasks\SushiLeads => C:\Program Files (x86)\sushileads\ScheduledTask.exe
Task: {B3E4C79F-31B0-4CEC-8855-3A125AFCA943} - System32\Tasks\FYLVp79 => C:\Users\Kathy\AppData\Roaming\FYLVp79.exe [2015-04-20] () <==== ATTENTION
Task: {B50E6BBF-9E5C-4375-A579-BA67BBBB3632} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {BEFA25DD-72D7-4DCD-A9B5-609E7D25109A} - System32\Tasks\WordShark Auto Updater 1.10.0.20 Pending Update => C:\Program Files (x86)\WordShark_1.10.0.20\Update\WordSharkAutoUpdateClient.exe [2015-07-06] (WS) <==== ATTENTION
Task: {BFD5E5F7-A581-4986-AA96-C25F1196ED50} - System32\Tasks\JWRTYVMXFBIVCPWL => C:\ProgramData\Service1198\Service1198.exe [2015-06-28] () <==== ATTENTION
Task: {CC0931E2-8841-4E30-A9AC-B3C127345ED4} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2014-12-17] (IObit)
Task: {CD043251-2487-4869-A33C-C07A835E7188} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {CF6E7CAA-8B5F-4C52-A529-903EEF71BD58} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {D0A3F695-CFF9-4D08-A2A2-A4FC09D36290} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-5.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {D17B14BD-B3E2-4FD2-AFBE-644A6A3B1782} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [2014-12-09] (IObit)
Task: {D67D6154-0544-43C0-A94B-02B9B1A17E7C} - System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7 => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7.exe [2015-07-13] (Cinema PlusV13.07) <==== ATTENTION
Task: {E95208D8-3FF8-4D59-AFCB-CDC5937532DF} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-7 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-7.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {E9AADAD9-F283-4AA1-9839-E55321CC24D3} - System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7 => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7.exe [2015-07-19] (Cinema PlusV18.07) <==== ATTENTION
Task: {F4309D18-BE10-4EE4-A49A-13DC9F49921B} - System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7 => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7.exe [2015-07-12] (HQ-VideoV12.07) <==== ATTENTION
Task: {F48924F7-2B13-4189-BEFC-7813745D4972} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-07-19] (globalUpdate) <==== ATTENTION
Task: {F60157AF-D870-485B-87FD-5F992DA7ACD1} - System32\Tasks\GlobalUpdate-ywy2yzvxzgtjbth => C:\Users\Kathy\AppData\Roaming\ywy2yzvxzgtjbth\ywy2yzvxzgtjbth.exe [2015-07-13] () <==== ATTENTION
Task: {F6838031-AB36-4284-9FC7-8677F4B77864} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => c:\Program Files\Microsoft IntelliPoint\IPoint.exe [2011-08-01] (Microsoft Corporation)
Task: {F93A1729-BC6D-42A0-888E-D2BEB8D08BA5} - System32\Tasks\avastBCLRestartS-1-5-21-171533428-321824291-3300133993-1000 => Chrome.exe
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7.job => C:\Program Files (x86)\CinemaPlus-3.2cV13.07\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user.job => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10.exe <==== ATTENTION
Task: C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3.job => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7.job => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-10.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-3.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-6.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-7.job => C:\Program Files (x86)\HQCinema Pro 2.1V12.07\a1e5f7dc-19c6-44a2-882d-e75547499632-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\CIMT_daily_S-1-5-21-171533428-321824291-3300133993-1000.job => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
Task: C:\Windows\Tasks\CIMT_S-1-5-21-171533428-321824291-3300133993-1000.job => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job => C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\Crossbrowse.job => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION
Task: C:\Windows\Tasks\FYLVp79.job => C:\Users\Kathy\AppData\Roaming\FYLVp79.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GLQHQICXMFBVKQCB.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\JWRTYVMXFBIVCPWL.job => C:\ProgramData\Service1198\Service1198.exe <==== ATTENTION
Task: C:\Windows\Tasks\NLSAGZR1.job => C:\ProgramData\EpsanDrive\EpsanDrive.exe <==== ATTENTION
Task: C:\Windows\Tasks\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job => C:\Program Files (x86)\CinemaPlus-3.2cV18.07\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\WdEL9n2eiowr.job => C:\Users\Kathy\AppData\Roaming\WdEL9n2eiowr.exe <==== ATTENTION
AlternateDataStreams: C:\Windows\system32\Drivers\vfbhiosb.sys:changelist
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Cofvopjy => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\myradioplayer => ""="service"
C:\Program Files (x86)\cpx
C:\Program Files (x86)\Smwyyntm1ndi1zdz
C:\Program Files (x86)\MovieDea
C:\Program Files (x86)\Optimizer Pro 3.99
C:\Program Files (x86)\SearchProtect\
C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh
C:\Program Files (x86)\Crossbrowse
C:\Program Files (x86)\Iminent
C:\Windows\system32\myradioplayer64.dll
C:\Windows\SysWOW64\Cofvopjy.dll
C:\Windows\SysWOW64\myradioplayer.dll
C:\Users\Kathy\AppData\Local\Ninja Loader
C:\Users\Kathy\AppData\Roaming\ASPackage
C:\Users\Kathy\AppData\Local\Temp\20150713
C:\Users\Kathy\AppData\Local\5670549A-1436745948-DE00-E918-1C7508113231
C:\ProgramData\caGSSMRD
C:\Program Files (x86)\WordShark_1.10.0.20
C:\Program Files\WajIEn
C:\Program Files (x86)\Coupoon
C:\ProgramData\1436760085
C:\Users\Kathy\AppData\Roaming\ASPackage
C:\Users\Kathy\AppData\Local\5670549A-1436745948-DE00-E918-1C7508113231
C:\Program Files (x86)\msrtn32
C:\Program Files (x86)\RadPlayer
C:\Program Files (x86)\Common Files\Umbrella
C:\Program Files (x86)\Common Files\IMGUpdater
C:\ProgramData\FlashBeat
C:\Program Files (x86)\dataup
C:\Program Files (x86)\gmsd_us_005010030\gmsd_us_005010030.exe
C:\Program Files (x86)\Smwyyntm1ndi1zdz\ywi2mzv2zhnjbdh.exe
C:\Program Files (x86)\gmsd_us_005010031\gmsd_us_005010031.exe
C:\Program Files (x86)\msrtn32\msrtn32.exe
C:\Program Files (x86)\StormWatch
C:\Users\Kathy\AppData\Local\SmartWeb
C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh
C:\Program Files (x86)\Ninja Loader
C:\ProgramData\EpsanDrive
C:\Program Files (x86)\Consumer Input
C:\Program Files (x86)\globalUpdate
C:\Users\Kathy\AppData\Local\ospd_us_014010029\upospd_us_014010029.exe
C:\Program Files (x86)\CinemaPlus-3.2cV13.07
C:\Program Files\shopperz12072015
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
CMD: bitsadmin /reset /allusers
*****************
Restore point was successfully created.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\RadPlayer Tray => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\shopperz12072015 => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\shopperz1207201564 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\StormWatch => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\cpx => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\msrtn32 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\WinCheck => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_us_005010030 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mwyyntm1ndi1zdz => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_us_005010031 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\MovieDea => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SmartWeb => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\upospd_us_014010029.exe => value removed successfully
HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\Microsoft\Windows\CurrentVersion\Run\\NinjaLoader => value removed successfully
HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Optimizer Pro => value removed successfully
"C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll" => Value data removed successfully.
" C:\ProgramData\FlashBeat\FlashBeat64.dll" => Value data removed successfully.
"C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll" => Value data removed successfully.
" C:\ProgramData\FlashBeat\FlashBeat32.dll" => Value data removed successfully.
" C:\ProgramData\EpsanDrive\EpsanDrive32.dll" => Value data removed successfully.
" C:\PROGRA~3\{63B88~1\1173~1.1\tiso.dll" => Value data removed successfully.
C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bm.lnk => moved successfully.
"C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh\yxa2bzvwzf9jdth.exe" => Could not move.
C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk => moved successfully.
C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe not found.
C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk => moved successfully.
C:\Users\Kathy\AppData\Local\SmartWeb\SmartWebHelper.exe => moved successfully.
C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatch.lnk => moved successfully.
C:\Program Files (x86)\StormWatch\StormWatch.exe => moved successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-171533428-321824291-3300133993-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{84FF7BD6-B47F-46F8-9130-01B2696B36CB} => value removed successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\OldSearch" => key removed successfully
HKCR\CLSID\OldSearch => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}" => key removed successfully
HKCR\Wow6432Node\CLSID\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} => key not found.
"HKU\S-1-5-21-171533428-321824291-3300133993-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => key removed successfully
HKCR\CLSID\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => key not found.
"HKU\S-1-5-21-171533428-321824291-3300133993-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BC4A5ADC-08EE-4734-9171-5A5035FF16D7}" => key removed successfully
HKCR\CLSID\{BC4A5ADC-08EE-4734-9171-5A5035FF16D7} => key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}" => key removed successfully
"HKCR\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}" => key removed successfully
"HKCR\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}" => key removed successfully
"HKCR\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c49ac435-5c4d-450f-aa56-cd31f96613b3}" => key removed successfully
"HKCR\CLSID\{c49ac435-5c4d-450f-aa56-cd31f96613b3}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}" => key removed successfully
HKCR\Wow6432Node\CLSID\{84FF7BD6-B47F-46F8-9130-01B2696B36CB} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c49ac435-5c4d-450f-aa56-cd31f96613b3}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{c49ac435-5c4d-450f-aa56-cd31f96613b3}" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000019" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000020" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000015" => key removed successfully
"HKLM\Software\MozillaPlugins\@iqiyi.com/npclient" => key removed successfully
C:\IQIYI Video\LStyle\npclient.dll => moved successfully.
"HKLM\Software\MozillaPlugins\@iqiyi.com/npWebPlayer" => key removed successfully
C:\IQIYI Video\LStyle\npWebPlayer.dll => moved successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@iqiyi.com/npclient" => key removed successfully
C:\IQIYI Video\LStyle\npclient.dll not found.
"HKLM\Software\Wow6432Node\MozillaPlugins\@iqiyi.com/npWebPlayer" => key removed successfully
C:\IQIYI Video\LStyle\npWebPlayer.dll not found.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10" => key removed successfully
C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll => moved successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4" => key removed successfully
C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll not found.
"HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\MozillaPlugins\@iqiyi.com/npWebPlayer" => key removed successfully
C:\IQIYI Video\LStyle\npWebPlayer.dll not found.
"HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0" => key removed successfully
C:\Users\Kathy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll => moved successfully.
HKLM\Software\Mozilla\Firefox\Extensions\\{c49ac435-5c4d-450f-aa56-cd31f96613b3} => value removed successfully
C:\Program Files\shopperz12072015\Firefox => moved successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{c49ac435-5c4d-450f-aa56-cd31f96613b3} => value removed successfully
HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\Mozilla\Firefox\Extensions\\ConsumerInput@Compete => value removed successfully
C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12191.xpi => moved successfully.
HKU\S-1-5-21-171533428-321824291-3300133993-1000\Software\Mozilla\Firefox\Extensions\\
[email protected] => value removed successfully
C:\Program Files (x86)\Ninja Loader\FireFox => moved successfully.
C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gegdfeiahlfolhcfioipjlkombmgbakh => moved successfully.
C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Extensions\papbadoldddalgcjcicnikcfenodpghp => moved successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\adpeheiliennogfclcgmchdfdmafjegc" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\cmlhbjpgeogifjnmlajdaealbdlfonah" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ehhlaekjfiiojlddgndcnefflngfmhen" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gihfmmedoddijgnhkgfgnkeohkpbipol" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl" => key removed successfully
C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx => moved successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nociobghckdhokecfeajdpimjeapnopn" => key removed successfully
46784c7a-2afb-4c2f-b299-133de9a46a66 => Service stopped successfully.
46784c7a-2afb-4c2f-b299-133de9a46a66 => service removed successfully
c31ed948 => service removed successfully
Cofvopjy => Service stopped successfully.
Cofvopjy => service removed successfully
consumerinput_update => service removed successfully
consumerinput_updatem => service removed successfully
CoupoonService64 => service removed successfully
csrcc => Service stopped successfully.
csrcc => service removed successfully
Dataup => Service stopped successfully.
Dataup => service removed successfully
FlashBeat => service removed successfully
globalUpdate => service removed successfully
globalUpdatem => service removed successfully
GlobalUpdater => Service stopped successfully.
GlobalUpdater => service removed successfully
IMService => Service stopped successfully.
IMService => service removed successfully
LosdyLijfeu => Unable to stop service.
LosdyLijfeu => service removed successfully
myradioplayer => Service stopped successfully.
myradioplayer => service removed successfully
NinjaLoaderService => Service stopped successfully.
NinjaLoaderService => service removed successfully
RadPlayerV1 => Service stopped successfully.
RadPlayerV1 => service removed successfully
RadPlayerV2 => service removed successfully
REhsGdKiASD => Unable to stop service.
REhsGdKiASD => service removed successfully
relibily => Service stopped successfully.
relibily => service removed successfully
serveras => Service stopped successfully.
serveras => service removed successfully
shopperz12072015 Updater => Service stopped successfully.
shopperz12072015 Updater => service removed successfully
StormWatch Update Service => Service stopped successfully.
StormWatch Update Service => service removed successfully
SWUpdater => Service stopped successfully.
SWUpdater => service removed successfully
UdvdPork => Service stopped successfully.
UdvdPork => service removed successfully
UpdateCheck => Service stopped successfully.
UpdateCheck => service removed successfully
WajIEn Monitor => Service stopped successfully.
WajIEn Monitor => service removed successfully
wbsvc => service removed successfully
windowsmanagementservice => Service stopped successfully.
windowsmanagementservice => service removed successfully
wssvc_1.10.0.20 => Service stopped successfully.
wssvc_1.10.0.20 => service removed successfully
SMUpdPlus => service removed successfully
cherimoya => Unable to stop service.
cherimoya => service removed successfully
SMUpdd => service removed successfully
vfbhiosb => service removed successfully
wsfd_vt_1_10_0_20 => Unable to stop service.
wsfd_vt_1_10_0_20 => service removed successfully
ywi2mzv2zhnjbdh => Unable to stop service.
ywi2mzv2zhnjbdh => service removed successfully
C:\Windows\system32\Drivers\vfbhiosb.sys => moved successfully.
C:\Users\Kathy\AppData\Local\CEF => moved successfully.
C:\Program Files (x86)\GUMBFC5.tmp => moved successfully.
C:\Program Files (x86)\GUTC294.tmp => moved successfully.
C:\Windows\TEMPcoral.vbs => moved successfully.
C:\ProgramData\Ninja Loader => moved successfully.
C:\Windows\SysWOW64\debug.log => moved successfully.
C:\Windows\Tasks\CIMT_S-1-5-21-171533428-321824291-3300133993-1000.job => moved successfully.
C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user.job => moved successfully.
C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 => moved successfully.
C:\Windows\Tasks\GLQHQICXMFBVKQCB.job => moved successfully.
C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job => moved successfully.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.job => moved successfully.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-6.job => moved successfully.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user.job => moved successfully.
C:\Windows\System32\Tasks\Optimizer Pro Schedule => moved successfully.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user.job => moved successfully.
C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job => moved successfully.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.job => moved successfully.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.job => moved successfully.
C:\ProgramData\boost_interprocess => moved successfully.
C:\Windows\SysWOW64\Cofvopjy.ini => moved successfully.
C:\Windows\SysWOW64\CofvopjyOff.ini => moved successfully.
C:\Windows\system32\CofvopjyOff.ini => moved successfully.
C:\Users\Kathy\AppData\Local\ospd_us_014010029 => moved successfully.
"C:\Users\Kathy\AppData\Local\mstrn32" folder move:
Could not move "C:\Users\Kathy\AppData\Local\mstrn32" => Scheduled to move on reboot.
C:\Windows\Tasks\WdEL9n2eiowr.job => moved successfully.
C:\Windows\Tasks\FYLVp79.job => moved successfully.
C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7.job => moved successfully.
C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3.job => moved successfully.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user.job => moved successfully.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.job => moved successfully.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7.job => moved successfully.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7.job => moved successfully.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3.job => moved successfully.
C:\Windows\Tasks\Crossbrowse.job => moved successfully.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user.job => moved successfully.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5.job => moved successfully.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7.job => moved successfully.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-7.job => moved successfully.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-3.job => moved successfully.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => moved successfully.
C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job => moved successfully.
C:\Windows\Tasks\JWRTYVMXFBIVCPWL.job => moved successfully.
C:\Windows\Tasks\NLSAGZR1.job => moved successfully.
C:\Windows\System32\Tasks\Epuifuuva => moved successfully.
C:\Users\Kathy\AppData\Local\Ninja Loader => moved successfully.
C:\ProgramData\ProductData => moved successfully.
"C:\Program Files (x86)\GUTC294.tmp" => File/Folder not found.
C:\Program Files (x86)\GUTFD53.tmp => moved successfully.
C:\Users\Kathy\AppData\Roaming\FYLVp79 => moved successfully.
C:\Users\Kathy\AppData\Roaming\FYLVp79.exe => moved successfully.
C:\Users\Kathy\AppData\Roaming\WdEL9n2eiowr => moved successfully.
C:\Users\Kathy\AppData\Roaming\WdEL9n2eiowr.exe => moved successfully.
C:\Users\Kathy\AppData\Local\nsiBAD8.tmp => moved successfully.
C:\Windows\Tasks\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{01A22A0D-37F6-4D85-A408-491ACA67BF31}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{01A22A0D-37F6-4D85-A408-491ACA67BF31}" => key removed successfully
C:\Windows\System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-6 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a1e5f7dc-19c6-44a2-882d-e75547499632-6" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{02956738-DE99-47D8-A6C6-DCEE22EE7C4B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02956738-DE99-47D8-A6C6-DCEE22EE7C4B}" => key removed successfully
C:\Windows\System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0473C0CA-9A3F-462C-9BB2-BB768544A91A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0473C0CA-9A3F-462C-9BB2-BB768544A91A}" => key removed successfully
C:\Windows\System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-3 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a1e5f7dc-19c6-44a2-882d-e75547499632-3" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0C67CC53-4D97-46D6-A447-A0C70698D63C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0C67CC53-4D97-46D6-A447-A0C70698D63C}" => key removed successfully
C:\Windows\System32\Tasks\WebBarUpdateTask => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WebBarUpdateTask" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{12826CD3-979A-4778-9E55-62298738037F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{12826CD3-979A-4778-9E55-62298738037F}" => key removed successfully
C:\Windows\System32\Tasks\WdEL9n2eiowr => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WdEL9n2eiowr" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{13C77BBA-4D9D-4CC4-9783-0F09749EBC89}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{13C77BBA-4D9D-4CC4-9783-0F09749EBC89}" => key removed successfully
C:\Windows\System32\Tasks\APSnotifierPP2 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP2" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{168DBC36-AAF6-4F39-8483-52C63048B4FE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{168DBC36-AAF6-4F39-8483-52C63048B4FE}" => key removed successfully
C:\Windows\System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1BEAFD01-BB2F-4D5D-A4CB-F3456C100409}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1BEAFD01-BB2F-4D5D-A4CB-F3456C100409}" => key removed successfully
C:\Windows\System32\Tasks\ConsumerInputUpdateTaskMachineUA => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ConsumerInputUpdateTaskMachineUA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1D2B5213-0A0B-4933-8409-5B6CCA9D31C4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D2B5213-0A0B-4933-8409-5B6CCA9D31C4}" => key removed successfully
C:\Windows\System32\Tasks\SMW_UpdateTask_Time_333833393739363037312d235b783432415b45345a2d6c => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMW_UpdateTask_Time_333833393739363037312d235b783432415b45345a2d6c" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1EC32D4B-9503-4E11-9581-F33F5490D6C8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EC32D4B-9503-4E11-9581-F33F5490D6C8}" => key removed successfully
C:\Windows\System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{25FCAB52-144F-4DF6-9ED8-A783CF9663E3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25FCAB52-144F-4DF6-9ED8-A783CF9663E3}" => key removed successfully
C:\Windows\System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{26C1D14B-D736-4340-AA04-29E5B0EE9912}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{26C1D14B-D736-4340-AA04-29E5B0EE9912}" => key removed successfully
C:\Windows\System32\Tasks\CIMT_S-1-5-21-171533428-321824291-3300133993-1000 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CIMT_S-1-5-21-171533428-321824291-3300133993-1000" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2C86BA2E-43EA-43C1-9CC7-DC321BFFF485}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2C86BA2E-43EA-43C1-9CC7-DC321BFFF485}" => key removed successfully
C:\Windows\System32\Tasks\Snmix => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Snmix" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{325746AD-5A6F-430F-8E30-6CD44422ABDB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{325746AD-5A6F-430F-8E30-6CD44422ABDB}" => key removed successfully
C:\Windows\System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{36F19701-E5F7-4483-856F-F95E73176541}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{36F19701-E5F7-4483-856F-F95E73176541}" => key removed successfully
C:\Windows\System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3C325D05-59F7-4AA8-A14C-0D30C25CACC4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C325D05-59F7-4AA8-A14C-0D30C25CACC4}" => key removed successfully
C:\Windows\System32\Tasks\Driver Booster SkipUAC (SYSTEM) => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (SYSTEM)" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{41F7B16E-395A-4581-81BD-04F429088AC9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41F7B16E-395A-4581-81BD-04F429088AC9}" => key removed successfully
C:\Windows\System32\Tasks\Driver Booster SkipUAC (Kathy) => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (Kathy)" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{423821BC-96E6-4D84-9341-34C7D6544576}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{423821BC-96E6-4D84-9341-34C7D6544576}" => key removed successfully
C:\Windows\System32\Tasks\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4315E182-2227-4C77-880F-D8ED0781664D}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4315E182-2227-4C77-880F-D8ED0781664D}" => key removed successfully
C:\Windows\System32\Tasks\NLSAGZR1 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NLSAGZR1" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{46EEB3FE-4979-4D71-B642-E6812F1A1B63}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{46EEB3FE-4979-4D71-B642-E6812F1A1B63}" => key removed successfully
C:\Windows\System32\Tasks\SMWPUpd => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMWPUpd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4F7AA969-E2FB-46AC-A550-70B132457A08}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4F7AA969-E2FB-46AC-A550-70B132457A08}" => key removed successfully
C:\Windows\System32\Tasks\Smp => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Smp" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{519D5601-B701-4EF4-942D-023EB0776066}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{519D5601-B701-4EF4-942D-023EB0776066}" => key removed successfully
C:\Windows\System32\Tasks\Optimizer Pro Schedule not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimizer Pro Schedule" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{536F625C-BFB1-4834-BC2B-BD6198974A9E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{536F625C-BFB1-4834-BC2B-BD6198974A9E}" => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{58BC472B-603B-41F5-A0F2-3D4FBD8E8B49}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{58BC472B-603B-41F5-A0F2-3D4FBD8E8B49}" => key removed successfully
C:\Windows\System32\Tasks\WebBarLaunchTask => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WebBarLaunchTask" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5AE88653-7D39-4018-A2D6-1B1865993C94}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5AE88653-7D39-4018-A2D6-1B1865993C94}" => key removed successfully
C:\Windows\System32\Tasks\BD634EFB-4435-4228-B1B1-B9F4709D5F79 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BD634EFB-4435-4228-B1B1-B9F4709D5F79" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5B84AF85-C877-4407-9B54-51E465C67CD3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B84AF85-C877-4407-9B54-51E465C67CD3}" => key removed successfully
C:\Windows\System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5BAFB821-7E9C-44DA-8FF3-BA06AA1A580A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5BAFB821-7E9C-44DA-8FF3-BA06AA1A580A}" => key removed successfully
C:\Windows\System32\Tasks\Adobe Flash Player Updater => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5D16852C-3009-4836-B678-96DD5F24BE7B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D16852C-3009-4836-B678-96DD5F24BE7B}" => key removed successfully
C:\Windows\System32\Tasks\ConsumerInputUpdateTaskMachineCore => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ConsumerInputUpdateTaskMachineCore" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{610A4D52-9E85-4E0B-A680-BEA500D4EF11}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{610A4D52-9E85-4E0B-A680-BEA500D4EF11}" => key removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{691E87A2-9D64-45C3-A667-ABE98310143F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{691E87A2-9D64-45C3-A667-ABE98310143F}" => key removed successfully
C:\Windows\System32\Tasks\GLQHQICXMFBVKQCB => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GLQHQICXMFBVKQCB" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6F7B2104-C5A2-4870-8DAA-94359F4B295E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F7B2104-C5A2-4870-8DAA-94359F4B295E}" => key removed successfully
C:\Windows\System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{80ECF25B-E055-4C3B-B841-3F10B6413105}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{80ECF25B-E055-4C3B-B841-3F10B6413105}" => key removed successfully
C:\Windows\System32\Tasks\Crossbrowse => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Crossbrowse" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{83886EC4-445C-4DB0-9EB6-83B465472564}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{83886EC4-445C-4DB0-9EB6-83B465472564}" => key removed successfully
C:\Windows\System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{88726888-5908-4FB8-A3FA-9043CB5B1478}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{88726888-5908-4FB8-A3FA-9043CB5B1478}" => key removed successfully
C:\Windows\System32\Tasks\WordShark Auto Updater 1.10.0.20 Core => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WordShark Auto Updater 1.10.0.20 Core" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8C648E3B-AA13-45C1-832C-77C99013C7F4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8C648E3B-AA13-45C1-832C-77C99013C7F4}" => key removed successfully
C:\Windows\System32\Tasks\ProPCCleaner_Start => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProPCCleaner_Start" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{8D2D9211-2FB9-4C3E-AB7B-548D36C48621}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D2D9211-2FB9-4C3E-AB7B-548D36C48621}" => key removed successfully
C:\Windows\System32\Tasks\Epuifuuva not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Epuifuuva" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8E797C65-1C95-4E33-BD35-2B67CFA422CC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8E797C65-1C95-4E33-BD35-2B67CFA422CC}" => key removed successfully
C:\Windows\System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8F31C890-7EC5-49DE-B3B9-7476E1ADAD00}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8F31C890-7EC5-49DE-B3B9-7476E1ADAD00}" => key removed successfully
C:\Windows\System32\Tasks\CIMT_daily_S-1-5-21-171533428-321824291-3300133993-1000 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CIMT_daily_S-1-5-21-171533428-321824291-3300133993-1000" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8FCE26CD-8109-40D2-84C9-EC4D6052F068}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8FCE26CD-8109-40D2-84C9-EC4D6052F068}" => key removed successfully
C:\Windows\System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9A4092C6-EB94-4323-A130-EEA16B56DCD3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9A4092C6-EB94-4323-A130-EEA16B56DCD3}" => key removed successfully
C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9A6CF26F-A597-49B7-8D92-A65B8241C305}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9A6CF26F-A597-49B7-8D92-A65B8241C305}" => key removed successfully
C:\Windows\System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9C38A35C-5BD6-4388-BC91-FED16EF2B1F4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9C38A35C-5BD6-4388-BC91-FED16EF2B1F4}" => key removed successfully
C:\Windows\System32\Tasks\Games\UpdateCheck_S-1-5-21-171533428-321824291-3300133993-1000 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Games\UpdateCheck_S-1-5-21-171533428-321824291-3300133993-1000" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9DC79A38-C865-43F3-9280-76CE0AC74000}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9DC79A38-C865-43F3-9280-76CE0AC74000}" => key removed successfully
C:\Windows\System32\Tasks\Uninstaller_SkipUac_Kathy => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_Kathy" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ACC2C1A7-672C-479B-91FF-EB6428145187}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ACC2C1A7-672C-479B-91FF-EB6428145187}" => key removed successfully
C:\Windows\System32\Tasks\SushiLeads => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SushiLeads" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B3E4C79F-31B0-4CEC-8855-3A125AFCA943}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B3E4C79F-31B0-4CEC-8855-3A125AFCA943}" => key removed successfully
C:\Windows\System32\Tasks\FYLVp79 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FYLVp79" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B50E6BBF-9E5C-4375-A579-BA67BBBB3632}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B50E6BBF-9E5C-4375-A579-BA67BBBB3632}" => key removed successfully
C:\Windows\System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BEFA25DD-72D7-4DCD-A9B5-609E7D25109A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BEFA25DD-72D7-4DCD-A9B5-609E7D25109A}" => key removed successfully
C:\Windows\System32\Tasks\WordShark Auto Updater 1.10.0.20 Pending Update => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WordShark Auto Updater 1.10.0.20 Pending Update" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BFD5E5F7-A581-4986-AA96-C25F1196ED50}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFD5E5F7-A581-4986-AA96-C25F1196ED50}" => key removed successfully
C:\Windows\System32\Tasks\JWRTYVMXFBIVCPWL => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\JWRTYVMXFBIVCPWL" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CC0931E2-8841-4E30-A9AC-B3C127345ED4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CC0931E2-8841-4E30-A9AC-B3C127345ED4}" => key removed successfully
C:\Windows\System32\Tasks\Driver Booster Scan => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scan" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CD043251-2487-4869-A33C-C07A835E7188}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CD043251-2487-4869-A33C-C07A835E7188}" => key removed successfully
C:\Windows\System32\Tasks\APSnotifierPP1 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP1" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CF6E7CAA-8B5F-4C52-A529-903EEF71BD58}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CF6E7CAA-8B5F-4C52-A529-903EEF71BD58}" => key removed successfully
C:\Windows\System32\Tasks\APSnotifierPP3 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP3" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D0A3F695-CFF9-4D08-A2A2-A4FC09D36290}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D0A3F695-CFF9-4D08-A2A2-A4FC09D36290}" => key removed successfully
C:\Windows\System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a1e5f7dc-19c6-44a2-882d-e75547499632-5" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D17B14BD-B3E2-4FD2-AFBE-644A6A3B1782}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D17B14BD-B3E2-4FD2-AFBE-644A6A3B1782}" => key removed successfully
C:\Windows\System32\Tasks\Driver Booster Update => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Update" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D67D6154-0544-43C0-A94B-02B9B1A17E7C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D67D6154-0544-43C0-A94B-02B9B1A17E7C}" => key removed successfully
C:\Windows\System32\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E95208D8-3FF8-4D59-AFCB-CDC5937532DF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E95208D8-3FF8-4D59-AFCB-CDC5937532DF}" => key removed successfully
C:\Windows\System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-7 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a1e5f7dc-19c6-44a2-882d-e75547499632-7" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E9AADAD9-F283-4AA1-9839-E55321CC24D3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E9AADAD9-F283-4AA1-9839-E55321CC24D3}" => key removed successfully
C:\Windows\System32\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F4309D18-BE10-4EE4-A49A-13DC9F49921B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4309D18-BE10-4EE4-A49A-13DC9F49921B}" => key removed successfully
C:\Windows\System32\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F48924F7-2B13-4189-BEFC-7813745D4972}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F48924F7-2B13-4189-BEFC-7813745D4972}" => key removed successfully
C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F60157AF-D870-485B-87FD-5F992DA7ACD1}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F60157AF-D870-485B-87FD-5F992DA7ACD1}" => key removed successfully
C:\Windows\System32\Tasks\GlobalUpdate-ywy2yzvxzgtjbth => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GlobalUpdate-ywy2yzvxzgtjbth" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F6838031-AB36-4284-9FC7-8677F4B77864}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F6838031-AB36-4284-9FC7-8677F4B77864}" => key removed successfully
C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft_Hardware_Launch_IPoint_exe" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F93A1729-BC6D-42A0-888E-D2BEB8D08BA5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F93A1729-BC6D-42A0-888E-D2BEB8D08BA5}" => key removed successfully
C:\Windows\System32\Tasks\avastBCLRestartS-1-5-21-171533428-321824291-3300133993-1000 => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avastBCLRestartS-1-5-21-171533428-321824291-3300133993-1000" => key removed successfully
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-6.job not found.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-1-7.job not found.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-10_user.job not found.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-3.job not found.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5.job not found.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-5_user.job not found.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-6.job not found.
C:\Windows\Tasks\24590c5b-2a5f-42b8-91a2-fa4788a2a0d9-7.job not found.
C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-10_user.job not found.
C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-3.job not found.
C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job not found.
C:\Windows\Tasks\5375a8f1-d04e-4014-8417-fe3a4f558ce7-7.job not found.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-6.job not found.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-1-7.job not found.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-10_user.job not found.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-3.job not found.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5.job not found.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-5_user.job not found.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-6.job not found.
C:\Windows\Tasks\a1e5f7dc-19c6-44a2-882d-e75547499632-7.job not found.
C:\Windows\Tasks\Adobe Flash Player Updater.job => moved successfully.
C:\Windows\Tasks\APSnotifierPP1.job => moved successfully.
C:\Windows\Tasks\APSnotifierPP2.job => moved successfully.
C:\Windows\Tasks\APSnotifierPP3.job => moved successfully.
C:\Windows\Tasks\CIMT_daily_S-1-5-21-171533428-321824291-3300133993-1000.job => moved successfully.
C:\Windows\Tasks\CIMT_S-1-5-21-171533428-321824291-3300133993-1000.job not found.
C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job not found.
C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job not found.
C:\Windows\Tasks\Crossbrowse.job not found.
C:\Windows\Tasks\FYLVp79.job not found.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job not found.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => moved successfully.
C:\Windows\Tasks\GLQHQICXMFBVKQCB.job not found.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully.
C:\Windows\Tasks\JWRTYVMXFBIVCPWL.job not found.
C:\Windows\Tasks\NLSAGZR1.job not found.
C:\Windows\Tasks\temp_5375a8f1-d04e-4014-8417-fe3a4f558ce7-6.job not found.
C:\Windows\Tasks\WdEL9n2eiowr.job not found.
"C:\Windows\system32\Drivers\vfbhiosb.sys" => ":changelist" ADS not found.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\Cofvopjy" => key removed successfully
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\myradioplayer" => key removed successfully
C:\Program Files (x86)\cpx => moved successfully.
"C:\Program Files (x86)\Smwyyntm1ndi1zdz" folder move:
Could not move "C:\Program Files (x86)\Smwyyntm1ndi1zdz" => Scheduled to move on reboot.
C:\Program Files (x86)\MovieDea => moved successfully.
C:\Program Files (x86)\Optimizer Pro 3.99 => moved successfully.
C:\Program Files (x86)\SearchProtect => moved successfully.
"C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh" folder move:
Could not move "C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh" => Scheduled to move on reboot.
"C:\Program Files (x86)\Crossbrowse" => File/Folder not found.
C:\Program Files (x86)\Iminent => moved successfully.
C:\Windows\system32\myradioplayer64.dll => moved successfully.
C:\Windows\SysWOW64\Cofvopjy.dll => moved successfully.
C:\Windows\SysWOW64\myradioplayer.dll => moved successfully.
"C:\Users\Kathy\AppData\Local\Ninja Loader" => File/Folder not found.
"C:\Users\Kathy\AppData\Roaming\ASPackage" folder move:
Could not move "C:\Users\Kathy\AppData\Roaming\ASPackage" => Scheduled to move on reboot.
C:\Users\Kathy\AppData\Local\Temp\20150713 => moved successfully.
C:\Users\Kathy\AppData\Local\5670549A-1436745948-DE00-E918-1C7508113231 => moved successfully.
"C:\ProgramData\caGSSMRD" folder move:
Could not move "C:\ProgramData\caGSSMRD" => Scheduled to move on reboot.
C:\Program Files (x86)\WordShark_1.10.0.20 => moved successfully.
C:\Program Files\WajIEn => moved successfully.
C:\Program Files (x86)\Coupoon => moved successfully.
C:\ProgramData\1436760085 => moved successfully.
"C:\Users\Kathy\AppData\Roaming\ASPackage" folder move:
Could not move "C:\Users\Kathy\AppData\Roaming\ASPackage" => Scheduled to move on reboot.
"C:\Users\Kathy\AppData\Local\5670549A-1436745948-DE00-E918-1C7508113231" => File/Folder not found.
"C:\Program Files (x86)\msrtn32" folder move:
Could not move "C:\Program Files (x86)\msrtn32" => Scheduled to move on reboot.
C:\Program Files (x86)\RadPlayer => moved successfully.
C:\Program Files (x86)\Common Files\Umbrella => moved successfully.
C:\Program Files (x86)\Common Files\IMGUpdater => moved successfully.
C:\ProgramData\FlashBeat => moved successfully.
C:\Program Files (x86)\dataup => moved successfully.
C:\Program Files (x86)\gmsd_us_005010030\gmsd_us_005010030.exe => moved successfully.
C:\Program Files (x86)\Smwyyntm1ndi1zdz\ywi2mzv2zhnjbdh.exe => moved successfully.
C:\Program Files (x86)\gmsd_us_005010031\gmsd_us_005010031.exe => moved successfully.
C:\Program Files (x86)\msrtn32\msrtn32.exe => moved successfully.
"C:\Program Files (x86)\StormWatch" folder move:
Could not move "C:\Program Files (x86)\StormWatch" => Scheduled to move on reboot.
"C:\Users\Kathy\AppData\Local\SmartWeb" folder move:
Could not move "C:\Users\Kathy\AppData\Local\SmartWeb" => Scheduled to move on reboot.
"C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh" folder move:
Could not move "C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh" => Scheduled to move on reboot.
C:\Program Files (x86)\Ninja Loader => moved successfully.
"C:\ProgramData\EpsanDrive" folder move:
Could not move "C:\ProgramData\EpsanDrive" => Scheduled to move on reboot.
"C:\Program Files (x86)\Consumer Input" folder move:
Could not move "C:\Program Files (x86)\Consumer Input" => Scheduled to move on reboot.
"C:\Program Files (x86)\globalUpdate" folder move:
Could not move "C:\Program Files (x86)\globalUpdate" => Scheduled to move on reboot.
"C:\Users\Kathy\AppData\Local\ospd_us_014010029\upospd_us_014010029.exe" => File/Folder not found.
C:\Program Files (x86)\CinemaPlus-3.2cV13.07 => moved successfully.
"C:\Program Files\shopperz12072015" folder move:
Could not move "C:\Program Files\shopperz12072015" => Scheduled to move on reboot.
========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
The operation completed successfully.
========= End of Reg: =========
========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
The operation completed successfully.
========= End of Reg: =========
========= Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F =========
ERROR: The system was unable to find the specified registry key or value.
========= End of Reg: =========
========= Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F =========
The operation completed successfully.
========= End of Reg: =========
========= RemoveProxy: =========
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-171533428-321824291-3300133993-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-171533428-321824291-3300133993-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
========= End of RemoveProxy: =========
========= netsh advfirewall reset =========
Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 10107
Ok.
========= End of CMD: =========
========= netsh advfirewall set allprofiles state ON =========
Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 10107
Ok.
========= End of CMD: =========
========= ipconfig /flushdns =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
========= netsh winsock reset catalog =========
Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 10107
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
========= End of CMD: =========
========= netsh int ip reset c:\resetlog.txt =========
Reseting Global, OK!
Reseting Interface, OK!
Restart the computer to complete this action.
========= End of CMD: =========
========= ipconfig /release =========
Windows IP Configuration
No operation can be performed on Local Area Connection while it has its media disconnected.
No operation can be performed on Wireless Network Connection while it has its media disconnected.
========= End of CMD: =========
========= ipconfig /renew =========
Windows IP Configuration
No operation can be performed on Local Area Connection while it has its media disconnected.
No operation can be performed on Wireless Network Connection while it has its media disconnected.
========= End of CMD: =========
========= netsh int ipv4 reset =========
There's no user specified settings to be reset.
========= End of CMD: =========
========= netsh int ipv6 reset =========
Reseting Interface, OK!
Restart the computer to complete this action.
========= End of CMD: =========
========= bitsadmin /reset /allusers =========
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
{95015F66-BB19-4D80-A73F-8412445E640E} canceled.
{2B49767F-0AD2-41C5-8953-48D8F9FF8FBE} canceled.
{CADDA9DA-2871-4398-BFF0-D6234D326DE2} canceled.
{DEC7F8C7-BE08-49B0-A655-AA179558BBF8} canceled.
{7ABD69DD-E802-44DC-9AA7-1217BFBA7470} canceled.
{32219307-FDAE-45E3-9E6E-774E99B4A811} canceled.
{E346774C-6D44-4F44-8885-49174D0BE938} canceled.
{0891396F-EC29-40D2-B61F-59A058112390} canceled.
{B114875B-35CD-45FF-9F3F-35F8F041C808} canceled.
{A68AAF1E-7273-4F54-840F-81699556946B} canceled.
{49766B9F-739A-46FF-8EFB-43D601B165A2} canceled.
{75CDE805-74D1-46F1-8E36-30DFEA1EFB6B} canceled.
{4F9C66D6-52C0-448E-8A04-EFE974846456} canceled.
{F85CDF05-2640-4787-A775-71F8487DD5AE} canceled.
{5C6E4274-82F9-4CFA-A8DE-BD470D94CEB6} canceled.
{87B4A5C7-A277-4E03-82DE-B1D1210A06A4} canceled.
{6B3B6659-486F-4F35-88F3-06FA918D2EE0} canceled.
{4ECEB7CF-AF5D-4DF9-B5FB-5C22AD9BD1EB} canceled.
{6A490EFA-7249-43EC-A040-4DD960A4AF18} canceled.
{8D65F036-4457-4426-92C7-13F15AD02259} canceled.
{B9ACED6E-2F67-4957-8329-079DB5D2FA96} canceled.
{6F64B517-63F3-4610-9190-8BA5ADD5AAD7} canceled.
{FE1B6B44-188F-47B3-8F9F-41071A7D2173} canceled.
{195534A1-2B13-4BF1-802E-C5BBFF636714} canceled.
{2D5EC538-77DF-4857-9ED1-A8904CC4E187} canceled.
{51951F1D-94C6-446D-9DC1-37650D5C0238} canceled.
{FCB02259-3B98-4135-9E32-9667B8089759} canceled.
{9E5D8FC3-44CF-439E-9FC4-EC2CB5A1AD61} canceled.
{5897511A-6464-4500-9B85-9B18168437E9} canceled.
{4DEB0EE5-F7B1-4E39-9DA0-02F180D89AD9} canceled.
{633F5717-9A04-4356-BE02-4EB2CFEB4B1E} canceled.
{DAD19FF0-7EAE-4022-9BEE-5E8E8DC51722} canceled.
{9E2093C5-DAE9-4160-BB53-693BDA8A4B2F} canceled.
{74D24FEF-5C68-48BB-9CD8-0DE56BD985F9} canceled.
{7D5BCCF6-0A50-4253-9026-95723C4FF948} canceled.
{D1B647F0-4274-4793-B9E9-66785EA28E8A} canceled.
{2A3EB26A-4730-4A0B-849B-A6784956A600} canceled.
{33F51C3A-5D19-4C37-A546-3990BFB2DF3C} canceled.
{ED35E099-03DD-4EAD-9C31-DE8027D3AE2E} canceled.
{F0D30050-00CC-4118-9CE0-2ECF4A9E1F59} canceled.
{0254B0EE-A274-482D-9E7F-A88CF6F4D148} canceled.
{65F13A23-E8BD-4EC6-81CD-F703085521B3} canceled.
{9684FB73-C288-47C4-A608-61AF94A8056D} canceled.
{CB02DF5F-2219-4906-A342-C7EB6183BB30} canceled.
{34846892-CDB1-4DA2-AB4F-DF9BFA5DE74F} canceled.
{4E31D2DE-E889-4D46-AD18-714D9A191E48} canceled.
{025661F3-5B3B-446D-81B6-319C483CEEC9} canceled.
{C994BFA4-AAEE-47F3-8AFD-4E88DEC95397} canceled.
{EC5A092A-6EFD-4D88-B8BB-D9C4C4061E60} canceled.
{D7CD537A-4D08-49E7-9014-E3D8D701E716} canceled.
{60FEEA54-B256-4935-83CD-2A198E401300} canceled.
{7603AAFD-CC58-42A8-8BA8-3DF606F56963} canceled.
{D1B9A369-3A1B-4635-A656-3D3D3D69F1DE} canceled.
{528DB515-8618-45F4-A9E0-DDAE7312B54E} canceled.
{AAC1AB3D-A665-4EF7-8DD7-E6D046D6E974} canceled.
55 out of 55 jobs canceled.
========= End of CMD: =========
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-08-19 20:04:09)<=
==> ATTENTION: System is not rebooted.
"C:\Users\Kathy\AppData\Local\mstrn32" => Could not move
"C:\Program Files (x86)\Smwyyntm1ndi1zdz" => Could not move
"C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh" => Could not move
"C:\Users\Kathy\AppData\Roaming\ASPackage" => Could not move
"C:\ProgramData\caGSSMRD" => Could not move
"C:\Users\Kathy\AppData\Roaming\ASPackage" => Could not move
"C:\Program Files (x86)\msrtn32" => Could not move
"C:\Program Files (x86)\StormWatch" => Could not move
"C:\Users\Kathy\AppData\Local\SmartWeb" => Could not move
"C:\Users\Kathy\AppData\Local\yva2vtutzeljbjh" => Could not move
"C:\ProgramData\EpsanDrive" => Could not move
"C:\Program Files (x86)\Consumer Input" => Could not move
"C:\Program Files (x86)\globalUpdate" => Could not move
"C:\Program Files\shopperz12072015" => Could not move
==== End of Fixlog 20:04:38 ====
AdwCleanerS1
# AdwCleaner v5.002 - Logfile created 19/08/2015 at 22:41:30
# Updated 18/08/2015 by Xplode
# Database : 2015-08-14.3 [Local]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Kathy - KATHY-PC
# Running from : C:\Users\Kathy\Desktop\AdwCleaner.exe
# Option : Scan
***** [ Services ] *****
Service Found : bsdriver
Service Found : cherimoya
Service Found : consumerinput_update
Service Found : consumerinput_updatem
Service Found : csrcc
Service Found : globalUpdate
Service Found : globalUpdatem
Service Found : GlobalUpdater
Service Found : netfilter64
Service Found : SMUpdd
Service Found : StormWatch Update Service
Service Found : SWUpdater
Service Found : wbsvc
Service Found : FlashBeat
Service Found : CoupoonService64
Service Found : SMUpdPlus
Service Found : IMService
Service Found : UpdateCheck
Service Found : Cofvopjy
Service Found : WajIEn Monitor
***** [ Folders ] *****
Folder Found : C:\FinanceAlert
Folder Found : C:\IQIYI Video
Folder Found : C:\Program Files\WebBar
Folder Found : C:\Program Files\coupoon
Folder Found : C:\Program Files (x86)\globalUpdate
Folder Found : C:\Program Files (x86)\StormWatch
Folder Found : C:\Program Files (x86)\ORBTR
Folder Found : C:\Program Files (x86)\Consumer Input
Folder Found : C:\Program Files (x86)\MyPCBU
Folder Found : C:\Program Files (x86)\app_setup
Folder Found : C:\Program Files (x86)\Hades
Folder Found : C:\Program Files (x86)\Itibiti Soft Phone
Folder Found : C:\Program Files (x86)\CinemaPlus-3.2cV18.07
Folder Found : C:\Program Files\Common Files\Goobzo
Folder Found : C:\ProgramData\Browser
Folder Found : C:\ProgramData\FinanceAlert
Folder Found : C:\ProgramData\IQIYI Video
Folder Found : C:\ProgramData\InstallSightSDK
Folder Found : C:\ProgramData\SearchModulePlus
Folder Found : C:\ProgramData\radio
Folder Found : C:\ProgramData\EpsanDrive
Folder Found : C:\ProgramData\MovieDeaConfig
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StormWatch
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UpdateAdmin
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajIEn
Folder Found : C:\Users\Kathy\AppData\Local\globalUpdate
Folder Found : C:\Users\Kathy\AppData\Local\SearchProtect
Folder Found : C:\Users\Kathy\AppData\Local\StormWatch
Folder Found : C:\Users\Kathy\AppData\Local\Weather_Protector_LLC
Folder Found : C:\Users\Kathy\AppData\Local\SmartWeb
Folder Found : C:\Users\Kathy\AppData\Local\Consumer Input
Folder Found : C:\Users\Kathy\AppData\Local\FinanceAlert
Folder Found : C:\Users\Kathy\AppData\Local\WebBar
Folder Found : C:\Users\Kathy\AppData\Local\Crossbrowse
Folder Found : C:\Users\Kathy\AppData\Local\avabvexvac
Folder Found : C:\Users\Kathy\AppData\Local\YSearchUtil
Folder Found : C:\Users\Kathy\AppData\Local\SysassistByHotWheel
Folder Found : C:\Users\Kathy\AppData\Local\5670549A-1436745935-DE00-E918-1C7508113231
Folder Found : C:\Users\Kathy\AppData\Local\Temp\Iminent
Folder Found : C:\Users\Kathy\AppData\LocalLow\SmartWeb
Folder Found : C:\Users\Kathy\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
Folder Found : C:\Users\Kathy\AppData\Roaming\AnyProtectEx
Folder Found : C:\Users\Kathy\AppData\Roaming\ASPackage
Folder Found : C:\Users\Kathy\AppData\Roaming\IQIYI Video
Folder Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormWatch
Folder Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASPackage
Folder Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MovieDea
Folder Found : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\StormWatch
Folder Found : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\YSearchUtil
***** [ Files ] *****
File Found : C:\END
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ehhlaekjfiiojlddgndcnefflngfmhen_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_papbadoldddalgcjcicnikcfenodpghp_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_papbadoldddalgcjcicnikcfenodpghp_0.localstorage-journal
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_papbadoldddalgcjcicnikcfenodpghp_0
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\papbadoldddalgcjcicnikcfenodpghp
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jdkokpcldhneihjdhigfjmoeojkdcbmg_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nociobghckdhokecfeajdpimjeapnopn_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_adpeheiliennogfclcgmchdfdmafjegc_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gegdfeiahlfolhcfioipjlkombmgbakh_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gegdfeiahlfolhcfioipjlkombmgbakh_0.localstorage-journal
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_gegdfeiahlfolhcfioipjlkombmgbakh_0
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gegdfeiahlfolhcfioipjlkombmgbakh
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_home.tb.ask.com_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_myscrapnook.dl.tb.ask.com_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_premierdownloadmanager.dl.tb.ask.com_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.cassiopessa.com_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Temp\UPDATETASK.EXE
File Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\crossbrowse.lnk
File Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Knctr.lnk
File Found : C:\Users\Public\Desktop\Knctr.lnk
File Found : C:\Windows\apppatch\apppatch64\vcldr64.dll
File Found : C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
File Found : C:\Windows\AppPatch\nbin\VC32Loader.dll
File Found : C:\Windows\Sysnative\drivers\bsdriver.sys
File Found : C:\Windows\Sysnative\drivers\cherimoya.sys
File Found : C:\Windows\Sysnative\drivers\netfilter64.sys
***** [ Shortcuts ] *****
Shortcut Infected : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk ( hxxp://www-searching.com/?s=F7Dzbuzdk00CN1,bebc7f3d-aee9-4b42-a9e1-f02206ddae60,&pi=3 )
Shortcut Infected : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk ( hxxp://www-searching.com/?s=F7Dzbuzdk00CN1,bebc7f3d-aee9-4b42-a9e1-f02206ddae60,&pi=3 )
Shortcut Infected : C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ( hxxp://www-searching.com/?s=F7Dzbuzdk00CN1,bebc7f3d-aee9-4b42-a9e1-f02206ddae60,&pi=3 )
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
Key Found : HKLM\SOFTWARE\Classes\AppID\CptUrlPassthru.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\dca-bho.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\Iminent.WebBooster.InternetExplorer.DLL
Key Found : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor
Key Found : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor.1
Key Found : HKLM\SOFTWARE\Classes\dcabho.Dca
Key Found : HKLM\SOFTWARE\Classes\dcabho.Dca.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\Iminent
Key Found : HKLM\SOFTWARE\Classes\IminentWebBooster.BrowserHelperObject
Key Found : HKLM\SOFTWARE\Classes\IminentWebBooster.BrowserHelperObject.1
Key Found : HKLM\SOFTWARE\Classes\IminentWebBooster.ScriptExtender
Key Found : HKLM\SOFTWARE\Classes\IminentWebBooster.ScriptExtender.1
Key Found : HKLM\SOFTWARE\Classes\PCProxy.DataContainer
Key Found : HKLM\SOFTWARE\Classes\AppID\globalupdate.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\smu.exe
Key Found : HKLM\SOFTWARE\Classes\HCDNProxy
Key Found : HKLM\SOFTWARE\276f7b6a-57ac-4835-a899-bb16f1998207
Key Found : HKLM\SOFTWARE\76fbede2-4201-4105-b699-b6e1cfa0842d
Key Found : HKLM\SOFTWARE\77265a05-c503-42c6-9008-ccb4c776410f
Key Found : HKLM\SOFTWARE\8b7efd01-8cc0-4a74-83c0-195ca4a69f62
Key Found : HKLM\SOFTWARE\cc176909-f20b-4492-db14-910bce233454
Key Found : HKLM\SOFTWARE\cf36c35d-fd9e-40ab-bee6-4a2f89864f9d
Key Found : HKLM\SOFTWARE\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11}
Key Found : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\AppID\{9DC8FA51-B596-4F77-802C-5B295919C205}
Key Found : HKLM\SOFTWARE\Classes\AppID\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
Key Found : HKLM\SOFTWARE\Classes\AppID\{DD7C44CC-0F60-4FD9-A38F-5CF30D698AC2}
Key Found : HKLM\SOFTWARE\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}
Key Found : HKLM\SOFTWARE\Classes\AppID\{4D6A5312-AB4D-41AA-8BED-0E019B87CA11}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3E28F712-0D6C-4EE3-AC8C-8F060F5D7C33}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6CE321DA-DC11-45C6-A0FC-4E8A7D978ABC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EEBC7FF-67DA-4B90-9251-C2C5696E4B48}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{74137531-80F7-406F-9543-7D11385FA8C8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{832599B2-55BF-4437-8F3E-030CF5AEB262}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B1A429DB-FB06-4645-B7C0-0CC405EAD3CD}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DD67706E-819E-4EBD-BF8D-6D6147CC7A49}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F62A4AF9-58B4-4FEC-89CC-D717A547D8E8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{085CB97F-6D0B-487D-B94C-E11A736C38CE}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CF3CDEFB-31BE-43AE-B064-B9C62C883259}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D96C1D26-5CDF-4506-9244-57233C3984DF}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7D8DAE88-BC05-4578-8C29-E541FFBA5757}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A2970C7C-8392-4E6F-8B51-B763CF38E13C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EDBF8C0-C94C-4A13-956F-E393BCA5BA4B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Found : HKLM\SOFTWARE\Classes\Interface\{22511E2E-7970-414E-BC7C-28D16C4AF54D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{23C5311E-016D-4999-BCB1-499898429D6C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2C4B6DB8-6413-403B-A038-16A352CFE8B9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{46803190-228D-470E-90FE-F5E0CEA9C4F2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Found : HKLM\SOFTWARE\Classes\Interface\{5180FE16-2E09-497B-9C8B-5A6F029ECECB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A4F6E1B3-469E-46EF-A936-FBA9D5EFD2B9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C97AF157-6A27-4F57-9D47-E2D3E4761B77}
Key Found : HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{ED0D2C81-7DB5-4599-B7C0-1033418B5672}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E4C3E50F-5761-4BF8-95A0-939A819DF1C3}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D96C1D26-5CDF-4506-9244-57233C3984DF}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{7BAB653D-88FB-4F60-AFC2-8E6FD59FAFF3}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A9CAF365-EA35-45DA-BD8B-2EFA09D374AC}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{ED721A76-8160-4DA0-A18E-7FD7C4574774}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9AE7A6AE-162E-44C4-9A2B-A6B4EF19909D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B6360BD3-5CD0-40D3-BD87-DAFF37889F50}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E6F928E4-B672-4F3A-8CA2-53C4259235DE}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{14EF423E-3EE8-44AE-9337-07AC3F27B744}
Key Found : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C49AC435-5C4D-450F-AA56-CD31F96613B3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C49AC435-5C4D-450F-AA56-CD31F96613B3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}]
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E6A8DA1-2731-465B-B036-B9E16EF26CAC}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAC94FEE-45B4-4FD4-9EEA-D8978EC96C6E}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{085CB97F-6D0B-487D-B94C-E11A736C38CE}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{A2970C7C-8392-4E6F-8B51-B763CF38E13C}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5CD76C57-6893-478A-B776-47E7C82504BE}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{22511E2E-7970-414E-BC7C-28D16C4AF54D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{23C5311E-016D-4999-BCB1-499898429D6C}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{2C4B6DB8-6413-403B-A038-16A352CFE8B9}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{46803190-228D-470E-90FE-F5E0CEA9C4F2}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{5180FE16-2E09-497B-9C8B-5A6F029ECECB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{A4F6E1B3-469E-46EF-A936-FBA9D5EFD2B9}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C97AF157-6A27-4F57-9D47-E2D3E4761B77}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{ED0D2C81-7DB5-4599-B7C0-1033418B5672}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{E4C3E50F-5761-4BF8-95A0-939A819DF1C3}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{D96C1D26-5CDF-4506-9244-57233C3984DF}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1E6A8DA1-1731-465B-B036-B9E16EF26CAC}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E6A8DA1-2731-465B-B036-B9E16EF26CAC}
Key Found : HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\Compete
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\coupoon
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
Key Found : HKCU\Software\AnyProtect
Key Found : HKCU\Software\Compete
Key Found : HKCU\Software\Conduit_Search_Protect
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\Iminent
Key Found : HKCU\Software\InstalledBrowserExtensions
Key Found : HKCU\Software\Microsoft\KanarCore
Key Found : HKCU\Software\NpApp
Key Found : HKCU\Software\Optimizer Pro
Key Found : HKCU\Software\Tutorials
Key Found : HKCU\Software\TutoTag
Key Found : HKCU\Software\StormWatchApp
Key Found : HKCU\Software\WajIEnhance
Key Found : HKCU\Software\Super Optimizer
Key Found : HKCU\Software\CrossBrowser
Key Found : HKCU\Software\Crossbrowse
Key Found : HKCU\Software\YorkNewCin
Key Found : HKCU\Software\HighDefAction
Key Found : HKCU\Software\ArenaHD
Key Found : HKCU\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}
Key Found : HKCU\Software\QyGameClient
Key Found : HKCU\Software\CinemaPlus-3.2cV18.07
Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKCU\Software\AppDataLow\Software\Compete
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\AppDataLow\Software\SmartWeb
Key Found : HKLM\SOFTWARE\AppDataLow\SOFTWARE\Crossrider
Key Found : HKLM\SOFTWARE\AppDataLow\SOFTWARE\_CrossriderRegNamePlaceHolder_
Key Found : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Found : HKLM\SOFTWARE\CompeteInc
Key Found : HKLM\SOFTWARE\GlobalUpdate
Key Found : HKLM\SOFTWARE\IMGUPDATER
Key Found : HKLM\SOFTWARE\Iminent
Key Found : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : HKLM\SOFTWARE\NpApp
Key Found : HKLM\SOFTWARE\SearchProtect
Key Found : HKLM\SOFTWARE\Tutorials
Key Found : HKLM\SOFTWARE\Umbrella
Key Found : HKLM\SOFTWARE\StormWatchApp
Key Found : HKLM\SOFTWARE\StormWatch
Key Found : HKLM\SOFTWARE\GAMESDESKTOP
Key Found : HKLM\SOFTWARE\FlashBeat
Key Found : HKLM\SOFTWARE\Crossbrowse
Key Found : HKLM\SOFTWARE\SearchModulePlus
Key Found : HKLM\SOFTWARE\coupoon
Key Found : HKLM\SOFTWARE\YorkNewCin
Key Found : HKLM\SOFTWARE\HighDefAction
Key Found : HKLM\SOFTWARE\Universal
Key Found : HKLM\SOFTWARE\Hades
Key Found : HKLM\SOFTWARE\ArenaHD
Key Found : HKLM\SOFTWARE\MovieDea
Key Found : HKLM\SOFTWARE\{AA2C4D29-36C3-48AB-8A25-181CF7483597}
Key Found : HKLM\SOFTWARE\Br MediaPlayer
Key Found : HKLM\SOFTWARE\WajIEn
Key Found : HKLM\SOFTWARE\CinemaPlus-3.2cV18.07
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ConvertAd
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StormWatch
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SmartWeb
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FinanceAlert
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wincheck
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Consumer Input Installer
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBeat
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ASPackage
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hades
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7D7D6742-5B49-4454-9E9B-748E731E741A}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EpsanDrive
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MovieDea
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{49F8B4F8-0CD4-4BE4-A9E8-B13A071F7C90}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WajIEn
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{49F8B4F8-0CD4-4BE4-A9E8-B13A071F7C90}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaPlus-3.2cV18.07
Key Found : [x64] HKCU\Software\AnyProtect
Key Found : [x64] HKCU\Software\Compete
Key Found : [x64] HKCU\Software\Conduit_Search_Protect
Key Found : [x64] HKCU\Software\GlobalUpdate
Key Found : [x64] HKCU\Software\Iminent
Key Found : [x64] HKCU\Software\InstalledBrowserExtensions
Key Found : [x64] HKCU\Software\Microsoft\KanarCore
Key Found : [x64] HKCU\Software\NpApp
Key Found : [x64] HKCU\Software\Optimizer Pro
Key Found : [x64] HKCU\Software\Tutorials
Key Found : [x64] HKCU\Software\TutoTag
Key Found : [x64] HKCU\Software\StormWatchApp
Key Found : [x64] HKCU\Software\WajIEnhance
Key Found : [x64] HKCU\Software\Super Optimizer
Key Found : [x64] HKCU\Software\CrossBrowser
Key Found : [x64] HKCU\Software\Crossbrowse
Key Found : [x64] HKCU\Software\YorkNewCin
Key Found : [x64] HKCU\Software\HighDefAction
Key Found : [x64] HKCU\Software\ArenaHD
Key Found : [x64] HKCU\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}
Key Found : [x64] HKCU\Software\QyGameClient
Key Found : [x64] HKCU\Software\CinemaPlus-3.2cV18.07
Key Found : [x64] HKLM\SOFTWARE\Iminent
Key Found : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : [x64] HKLM\SOFTWARE\FlashBeat
Key Found : [x64] HKLM\SOFTWARE\WebBar
Key Found : [x64] HKLM\SOFTWARE\SearchModulePlus
Key Found : [x64] HKLM\SOFTWARE\coupoon
Key Found : [x64] HKLM\SOFTWARE\YorkNewCin
Key Found : [x64] HKLM\SOFTWARE\HighDefAction
Key Found : [x64] HKLM\SOFTWARE\ArenaHD
Key Found : [x64] HKLM\SOFTWARE\{AA2C4D29-36C3-48AB-8A25-181CF7483597}
Key Found : [x64] HKLM\SOFTWARE\WajIEn
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0BCE8B0A-1E76-44E5-9909-3CF804D92E4D}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GLOBALUPDATE.EXE
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9}
***** [ Web browsers ] *****
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : trovi.search
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : www-searching.com_
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : www-searching.com
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider] Found : hxxp://www.iminent.com/Content/Images/favicon.ico?2fdde4
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider_Data] Found : hxxp://start.iminent.com/?appId=8437c40c-c891-4a5e-8eea-ca8568502d51&ref=toolbox&q={searchTerms}
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Homepage] Found : hxxp://start.iminent.com/?appId=8437c40c-c891-4a5e-8eea-ca8568502d51
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://start.iminent.com/?appId=8437c40c-c891-4a5e-8eea-ca8568502d51",
"hxxp://www.trovi.com/?gd=&ctid=CT3333887&octid=EB_ORIGINAL_CTID&ISID=M1890E6BC-BF65-41CA-B1ED-FCA8EC054D11&SearchSource=55&CUI=&UM=8&UP=SPA98636E4-750F-401C-BC08-F5A740811DAD&D=071415&SSPV=SP30339T2B_sp_ch
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [32483 bytes] ##########
AdwCleanerC1
# AdwCleaner v5.002 - Logfile created 19/08/2015 at 22:41:30
# Updated 18/08/2015 by Xplode
# Database : 2015-08-14.3 [Local]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Kathy - KATHY-PC
# Running from : C:\Users\Kathy\Desktop\AdwCleaner.exe
# Option : Scan
***** [ Services ] *****
Service Found : bsdriver
Service Found : cherimoya
Service Found : consumerinput_update
Service Found : consumerinput_updatem
Service Found : csrcc
Service Found : globalUpdate
Service Found : globalUpdatem
Service Found : GlobalUpdater
Service Found : netfilter64
Service Found : SMUpdd
Service Found : StormWatch Update Service
Service Found : SWUpdater
Service Found : wbsvc
Service Found : FlashBeat
Service Found : CoupoonService64
Service Found : SMUpdPlus
Service Found : IMService
Service Found : UpdateCheck
Service Found : Cofvopjy
Service Found : WajIEn Monitor
***** [ Folders ] *****
Folder Found : C:\FinanceAlert
Folder Found : C:\IQIYI Video
Folder Found : C:\Program Files\WebBar
Folder Found : C:\Program Files\coupoon
Folder Found : C:\Program Files (x86)\globalUpdate
Folder Found : C:\Program Files (x86)\StormWatch
Folder Found : C:\Program Files (x86)\ORBTR
Folder Found : C:\Program Files (x86)\Consumer Input
Folder Found : C:\Program Files (x86)\MyPCBU
Folder Found : C:\Program Files (x86)\app_setup
Folder Found : C:\Program Files (x86)\Hades
Folder Found : C:\Program Files (x86)\Itibiti Soft Phone
Folder Found : C:\Program Files (x86)\CinemaPlus-3.2cV18.07
Folder Found : C:\Program Files\Common Files\Goobzo
Folder Found : C:\ProgramData\Browser
Folder Found : C:\ProgramData\FinanceAlert
Folder Found : C:\ProgramData\IQIYI Video
Folder Found : C:\ProgramData\InstallSightSDK
Folder Found : C:\ProgramData\SearchModulePlus
Folder Found : C:\ProgramData\radio
Folder Found : C:\ProgramData\EpsanDrive
Folder Found : C:\ProgramData\MovieDeaConfig
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StormWatch
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UpdateAdmin
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajIEn
Folder Found : C:\Users\Kathy\AppData\Local\globalUpdate
Folder Found : C:\Users\Kathy\AppData\Local\SearchProtect
Folder Found : C:\Users\Kathy\AppData\Local\StormWatch
Folder Found : C:\Users\Kathy\AppData\Local\Weather_Protector_LLC
Folder Found : C:\Users\Kathy\AppData\Local\SmartWeb
Folder Found : C:\Users\Kathy\AppData\Local\Consumer Input
Folder Found : C:\Users\Kathy\AppData\Local\FinanceAlert
Folder Found : C:\Users\Kathy\AppData\Local\WebBar
Folder Found : C:\Users\Kathy\AppData\Local\Crossbrowse
Folder Found : C:\Users\Kathy\AppData\Local\avabvexvac
Folder Found : C:\Users\Kathy\AppData\Local\YSearchUtil
Folder Found : C:\Users\Kathy\AppData\Local\SysassistByHotWheel
Folder Found : C:\Users\Kathy\AppData\Local\5670549A-1436745935-DE00-E918-1C7508113231
Folder Found : C:\Users\Kathy\AppData\Local\Temp\Iminent
Folder Found : C:\Users\Kathy\AppData\LocalLow\SmartWeb
Folder Found : C:\Users\Kathy\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
Folder Found : C:\Users\Kathy\AppData\Roaming\AnyProtectEx
Folder Found : C:\Users\Kathy\AppData\Roaming\ASPackage
Folder Found : C:\Users\Kathy\AppData\Roaming\IQIYI Video
Folder Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormWatch
Folder Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASPackage
Folder Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MovieDea
Folder Found : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\StormWatch
Folder Found : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\YSearchUtil
***** [ Files ] *****
File Found : C:\END
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ehhlaekjfiiojlddgndcnefflngfmhen_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_papbadoldddalgcjcicnikcfenodpghp_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_papbadoldddalgcjcicnikcfenodpghp_0.localstorage-journal
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_papbadoldddalgcjcicnikcfenodpghp_0
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\papbadoldddalgcjcicnikcfenodpghp
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jdkokpcldhneihjdhigfjmoeojkdcbmg_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nociobghckdhokecfeajdpimjeapnopn_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_adpeheiliennogfclcgmchdfdmafjegc_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gegdfeiahlfolhcfioipjlkombmgbakh_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gegdfeiahlfolhcfioipjlkombmgbakh_0.localstorage-journal
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_gegdfeiahlfolhcfioipjlkombmgbakh_0
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gegdfeiahlfolhcfioipjlkombmgbakh
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_home.tb.ask.com_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_myscrapnook.dl.tb.ask.com_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_premierdownloadmanager.dl.tb.ask.com_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.cassiopessa.com_0.localstorage
File Found : C:\Users\Kathy\AppData\Local\Temp\UPDATETASK.EXE
File Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\crossbrowse.lnk
File Found : C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Knctr.lnk
File Found : C:\Users\Public\Desktop\Knctr.lnk
File Found : C:\Windows\apppatch\apppatch64\vcldr64.dll
File Found : C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
File Found : C:\Windows\AppPatch\nbin\VC32Loader.dll
File Found : C:\Windows\Sysnative\drivers\bsdriver.sys
File Found : C:\Windows\Sysnative\drivers\cherimoya.sys
File Found : C:\Windows\Sysnative\drivers\netfilter64.sys
***** [ Shortcuts ] *****
Shortcut Infected : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk ( hxxp://www-searching.com/?s=F7Dzbuzdk00CN1,bebc7f3d-aee9-4b42-a9e1-f02206ddae60,&pi=3 )
Shortcut Infected : C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk ( hxxp://www-searching.com/?s=F7Dzbuzdk00CN1,bebc7f3d-aee9-4b42-a9e1-f02206ddae60,&pi=3 )
Shortcut Infected : C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ( hxxp://www-searching.com/?s=F7Dzbuzdk00CN1,bebc7f3d-aee9-4b42-a9e1-f02206ddae60,&pi=3 )
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
Key Found : HKLM\SOFTWARE\Classes\AppID\CptUrlPassthru.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\dca-bho.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\Iminent.WebBooster.InternetExplorer.DLL
Key Found : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor
Key Found : HKLM\SOFTWARE\Classes\CptUrlPassthru.hxxpMonitor.1
Key Found : HKLM\SOFTWARE\Classes\dcabho.Dca
Key Found : HKLM\SOFTWARE\Classes\dcabho.Dca.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Found : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Found : HKLM\SOFTWARE\Classes\Iminent
Key Found : HKLM\SOFTWARE\Classes\IminentWebBooster.BrowserHelperObject
Key Found : HKLM\SOFTWARE\Classes\IminentWebBooster.BrowserHelperObject.1
Key Found : HKLM\SOFTWARE\Classes\IminentWebBooster.ScriptExtender
Key Found : HKLM\SOFTWARE\Classes\IminentWebBooster.ScriptExtender.1
Key Found : HKLM\SOFTWARE\Classes\PCProxy.DataContainer
Key Found : HKLM\SOFTWARE\Classes\AppID\globalupdate.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\smu.exe
Key Found : HKLM\SOFTWARE\Classes\HCDNProxy
Key Found : HKLM\SOFTWARE\276f7b6a-57ac-4835-a899-bb16f1998207
Key Found : HKLM\SOFTWARE\76fbede2-4201-4105-b699-b6e1cfa0842d
Key Found : HKLM\SOFTWARE\77265a05-c503-42c6-9008-ccb4c776410f
Key Found : HKLM\SOFTWARE\8b7efd01-8cc0-4a74-83c0-195ca4a69f62
Key Found : HKLM\SOFTWARE\cc176909-f20b-4492-db14-910bce233454
Key Found : HKLM\SOFTWARE\cf36c35d-fd9e-40ab-bee6-4a2f89864f9d
Key Found : HKLM\SOFTWARE\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11}
Key Found : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\AppID\{9DC8FA51-B596-4F77-802C-5B295919C205}
Key Found : HKLM\SOFTWARE\Classes\AppID\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
Key Found : HKLM\SOFTWARE\Classes\AppID\{DD7C44CC-0F60-4FD9-A38F-5CF30D698AC2}
Key Found : HKLM\SOFTWARE\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}
Key Found : HKLM\SOFTWARE\Classes\AppID\{4D6A5312-AB4D-41AA-8BED-0E019B87CA11}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3E28F712-0D6C-4EE3-AC8C-8F060F5D7C33}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6CE321DA-DC11-45C6-A0FC-4E8A7D978ABC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EEBC7FF-67DA-4B90-9251-C2C5696E4B48}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{74137531-80F7-406F-9543-7D11385FA8C8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{832599B2-55BF-4437-8F3E-030CF5AEB262}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B1A429DB-FB06-4645-B7C0-0CC405EAD3CD}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DD67706E-819E-4EBD-BF8D-6D6147CC7A49}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F62A4AF9-58B4-4FEC-89CC-D717A547D8E8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{085CB97F-6D0B-487D-B94C-E11A736C38CE}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CF3CDEFB-31BE-43AE-B064-B9C62C883259}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{D96C1D26-5CDF-4506-9244-57233C3984DF}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7D8DAE88-BC05-4578-8C29-E541FFBA5757}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A2970C7C-8392-4E6F-8B51-B763CF38E13C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EDBF8C0-C94C-4A13-956F-E393BCA5BA4B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Found : HKLM\SOFTWARE\Classes\Interface\{22511E2E-7970-414E-BC7C-28D16C4AF54D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{23C5311E-016D-4999-BCB1-499898429D6C}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2C4B6DB8-6413-403B-A038-16A352CFE8B9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Found : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{46803190-228D-470E-90FE-F5E0CEA9C4F2}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Found : HKLM\SOFTWARE\Classes\Interface\{5180FE16-2E09-497B-9C8B-5A6F029ECECB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A4F6E1B3-469E-46EF-A936-FBA9D5EFD2B9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C97AF157-6A27-4F57-9D47-E2D3E4761B77}
Key Found : HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{ED0D2C81-7DB5-4599-B7C0-1033418B5672}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E4C3E50F-5761-4BF8-95A0-939A819DF1C3}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D96C1D26-5CDF-4506-9244-57233C3984DF}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{7BAB653D-88FB-4F60-AFC2-8E6FD59FAFF3}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A9CAF365-EA35-45DA-BD8B-2EFA09D374AC}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{ED721A76-8160-4DA0-A18E-7FD7C4574774}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9AE7A6AE-162E-44C4-9A2B-A6B4EF19909D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B6360BD3-5CD0-40D3-BD87-DAFF37889F50}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E6F928E4-B672-4F3A-8CA2-53C4259235DE}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{14EF423E-3EE8-44AE-9337-07AC3F27B744}
Key Found : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C49AC435-5C4D-450F-AA56-CD31F96613B3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C49AC435-5C4D-450F-AA56-CD31F96613B3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}]
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E6A8DA1-2731-465B-B036-B9E16EF26CAC}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAC94FEE-45B4-4FD4-9EEA-D8978EC96C6E}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{085CB97F-6D0B-487D-B94C-E11A736C38CE}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5E6A8DA1-5731-465B-B036-B9E16EF26CAC}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5EC7C511-CD0F-42E6-830C-1BD9882F3458}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{A2970C7C-8392-4E6F-8B51-B763CF38E13C}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5CD76C57-6893-478A-B776-47E7C82504BE}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{15527BF5-9729-49DC-889C-9F956983154C}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{22511E2E-7970-414E-BC7C-28D16C4AF54D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{23C5311E-016D-4999-BCB1-499898429D6C}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{2C4B6DB8-6413-403B-A038-16A352CFE8B9}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{46803190-228D-470E-90FE-F5E0CEA9C4F2}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{5180FE16-2E09-497B-9C8B-5A6F029ECECB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{A4F6E1B3-469E-46EF-A936-FBA9D5EFD2B9}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C97AF157-6A27-4F57-9D47-E2D3E4761B77}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{ED0D2C81-7DB5-4599-B7C0-1033418B5672}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{E4C3E50F-5761-4BF8-95A0-939A819DF1C3}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{D96C1D26-5CDF-4506-9244-57233C3984DF}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1E6A8DA1-1731-465B-B036-B9E16EF26CAC}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E6A8DA1-2731-465B-B036-B9E16EF26CAC}
Key Found : HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\Compete
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\coupoon
Key Found : HKU\.DEFAULT\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
Key Found : HKCU\Software\AnyProtect
Key Found : HKCU\Software\Compete
Key Found : HKCU\Software\Conduit_Search_Protect
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\Iminent
Key Found : HKCU\Software\InstalledBrowserExtensions
Key Found : HKCU\Software\Microsoft\KanarCore
Key Found : HKCU\Software\NpApp
Key Found : HKCU\Software\Optimizer Pro
Key Found : HKCU\Software\Tutorials
Key Found : HKCU\Software\TutoTag
Key Found : HKCU\Software\StormWatchApp
Key Found : HKCU\Software\WajIEnhance
Key Found : HKCU\Software\Super Optimizer
Key Found : HKCU\Software\CrossBrowser
Key Found : HKCU\Software\Crossbrowse
Key Found : HKCU\Software\YorkNewCin
Key Found : HKCU\Software\HighDefAction
Key Found : HKCU\Software\ArenaHD
Key Found : HKCU\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}
Key Found : HKCU\Software\QyGameClient
Key Found : HKCU\Software\CinemaPlus-3.2cV18.07
Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKCU\Software\AppDataLow\Software\Compete
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\AppDataLow\Software\SmartWeb
Key Found : HKLM\SOFTWARE\AppDataLow\SOFTWARE\Crossrider
Key Found : HKLM\SOFTWARE\AppDataLow\SOFTWARE\_CrossriderRegNamePlaceHolder_
Key Found : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Found : HKLM\SOFTWARE\CompeteInc
Key Found : HKLM\SOFTWARE\GlobalUpdate
Key Found : HKLM\SOFTWARE\IMGUPDATER
Key Found : HKLM\SOFTWARE\Iminent
Key Found : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : HKLM\SOFTWARE\NpApp
Key Found : HKLM\SOFTWARE\SearchProtect
Key Found : HKLM\SOFTWARE\Tutorials
Key Found : HKLM\SOFTWARE\Umbrella
Key Found : HKLM\SOFTWARE\StormWatchApp
Key Found : HKLM\SOFTWARE\StormWatch
Key Found : HKLM\SOFTWARE\GAMESDESKTOP
Key Found : HKLM\SOFTWARE\FlashBeat
Key Found : HKLM\SOFTWARE\Crossbrowse
Key Found : HKLM\SOFTWARE\SearchModulePlus
Key Found : HKLM\SOFTWARE\coupoon
Key Found : HKLM\SOFTWARE\YorkNewCin
Key Found : HKLM\SOFTWARE\HighDefAction
Key Found : HKLM\SOFTWARE\Universal
Key Found : HKLM\SOFTWARE\Hades
Key Found : HKLM\SOFTWARE\ArenaHD
Key Found : HKLM\SOFTWARE\MovieDea
Key Found : HKLM\SOFTWARE\{AA2C4D29-36C3-48AB-8A25-181CF7483597}
Key Found : HKLM\SOFTWARE\Br MediaPlayer
Key Found : HKLM\SOFTWARE\WajIEn
Key Found : HKLM\SOFTWARE\CinemaPlus-3.2cV18.07
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ConvertAd
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\StormWatch
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SmartWeb
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FinanceAlert
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wincheck
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Consumer Input Installer
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBeat
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ASPackage
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hades
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7D7D6742-5B49-4454-9E9B-748E731E741A}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EpsanDrive
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MovieDea
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{49F8B4F8-0CD4-4BE4-A9E8-B13A071F7C90}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WajIEn
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{49F8B4F8-0CD4-4BE4-A9E8-B13A071F7C90}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaPlus-3.2cV18.07
Key Found : [x64] HKCU\Software\AnyProtect
Key Found : [x64] HKCU\Software\Compete
Key Found : [x64] HKCU\Software\Conduit_Search_Protect
Key Found : [x64] HKCU\Software\GlobalUpdate
Key Found : [x64] HKCU\Software\Iminent
Key Found : [x64] HKCU\Software\InstalledBrowserExtensions
Key Found : [x64] HKCU\Software\Microsoft\KanarCore
Key Found : [x64] HKCU\Software\NpApp
Key Found : [x64] HKCU\Software\Optimizer Pro
Key Found : [x64] HKCU\Software\Tutorials
Key Found : [x64] HKCU\Software\TutoTag
Key Found : [x64] HKCU\Software\StormWatchApp
Key Found : [x64] HKCU\Software\WajIEnhance
Key Found : [x64] HKCU\Software\Super Optimizer
Key Found : [x64] HKCU\Software\CrossBrowser
Key Found : [x64] HKCU\Software\Crossbrowse
Key Found : [x64] HKCU\Software\YorkNewCin
Key Found : [x64] HKCU\Software\HighDefAction
Key Found : [x64] HKCU\Software\ArenaHD
Key Found : [x64] HKCU\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}
Key Found : [x64] HKCU\Software\QyGameClient
Key Found : [x64] HKCU\Software\CinemaPlus-3.2cV18.07
Key Found : [x64] HKLM\SOFTWARE\Iminent
Key Found : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Found : [x64] HKLM\SOFTWARE\FlashBeat
Key Found : [x64] HKLM\SOFTWARE\WebBar
Key Found : [x64] HKLM\SOFTWARE\SearchModulePlus
Key Found : [x64] HKLM\SOFTWARE\coupoon
Key Found : [x64] HKLM\SOFTWARE\YorkNewCin
Key Found : [x64] HKLM\SOFTWARE\HighDefAction
Key Found : [x64] HKLM\SOFTWARE\ArenaHD
Key Found : [x64] HKLM\SOFTWARE\{AA2C4D29-36C3-48AB-8A25-181CF7483597}
Key Found : [x64] HKLM\SOFTWARE\WajIEn
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0BCE8B0A-1E76-44E5-9909-3CF804D92E4D}_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GLOBALUPDATE.EXE
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A33DB9FD-7A8A-496E-92D3-9CFCF9D9E1C9}
***** [ Web browsers ] *****
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : trovi.search
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : www-searching.com_
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : www-searching.com
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider] Found : hxxp://www.iminent.com/Content/Images/favicon.ico?2fdde4
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider_Data] Found : hxxp://start.iminent.com/?appId=8437c40c-c891-4a5e-8eea-ca8568502d51&ref=toolbox&q={searchTerms}
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Homepage] Found : hxxp://start.iminent.com/?appId=8437c40c-c891-4a5e-8eea-ca8568502d51
[C:\Users\Kathy\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://start.iminent.com/?appId=8437c40c-c891-4a5e-8eea-ca8568502d51",
"hxxp://www.trovi.com/?gd=&ctid=CT3333887&octid=EB_ORIGINAL_CTID&ISID=M1890E6BC-BF65-41CA-B1ED-FCA8EC054D11&SearchSource=55&CUI=&UM=8&UP=SPA98636E4-750F-401C-BC08-F5A740811DAD&D=071415&SSPV=SP30339T2B_sp_ch
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [32483 bytes] ##########
JRT
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.7 (08.18.2015:1)
OS: Windows 7 Ultimate x64
Ran by Kathy on Thu 08/20/2015 at 9:16:57.73
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B9D25D14-5326-4B87-B96E-A55E33600D20}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\wbsvc
~~~ Files
Failed to delete: [File] C:\Windows\system32\drivers\bsdriver.sys
Failed to delete: [File] C:\Windows\system32\drivers\cherimoya.sys
Failed to delete: [File] C:\Windows\SysWOW64\number of results
Successfully deleted: [File] C:\Users\Kathy\Appdata\Local\google\chrome\user data\default\local storage\hxxp_www.superfish.com_0.localstorage
Successfully deleted: [File] C:\Users\Kathy\desktop\pro pc cleaner.lnk
Successfully deleted: [File] C:\Users\Public\Desktop\play more great games!.url
Successfully deleted: [File] C:\Windows\system32\drivers\wsfd_vt_1_10_0_20.sys
Successfully deleted: [File] C:\Windows\system32\drivers\wsfd_vw_1_10_0_20.sys
Successfully deleted: [File] C:\Windows\system32\drivers\ywi2mzv2zhnjbdh.sys
Successfully disinfected: [Shortcut] C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
Successfully disinfected: [Shortcut] C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
Successfully disinfected: [Shortcut] C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
Successfully disinfected: [Shortcut] C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
~~~ Folders
Failed to delete: [Folder] C:\Program Files\shopperz12072015
Successfully deleted: [Folder] C:\Program Files (x86)\gmsd_us_005010030 [Adware.EoRezo]
Successfully deleted: [Folder] C:\Program Files (x86)\gmsd_us_005010031 [Adware.EoRezo]
Successfully deleted: [Folder] C:\Program Files (x86)\HQCinema Pro 2.1V12.07
Successfully deleted: [Folder] C:\Program Files (x86)\iobit\driver booster
Successfully deleted: [Folder] C:\Program Files (x86)\osdownloader
Successfully deleted: [Folder] C:\Program Files (x86)\ospd_us_014010029 [Adware.EoRezo]
Successfully deleted: [Folder] C:\Program Files (x86)\pro pc cleaner
Successfully deleted: [Folder] C:\Program Files (x86)\smwyyntm1ndi1zdz
Successfully deleted: [Folder] C:\ProgramData\abc
Successfully deleted: [Folder] C:\ProgramData\iobit\driver booster
Successfully deleted: [Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\driver booster 2
Successfully deleted: [Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\knctr
Successfully deleted: [Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\onesoftperday
Successfully deleted: [Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro v3.2
Successfully deleted: [Folder] C:\Users\Kathy\Appdata\Local\installer
Successfully deleted: [Folder] C:\Users\Kathy\Appdata\Local\pro_pc_cleaner
Successfully deleted: [Folder] C:\Users\Kathy\Appdata\LocalLow\company
Successfully deleted: [Folder] C:\Users\Kathy\AppData\Roaming\compete
Successfully deleted: [Folder] C:\Users\Kathy\AppData\Roaming\iobit\driver booster
Successfully deleted: [Folder] C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\pro pc cleaner
Successfully deleted: [Folder] C:\Users\Kathy\AppData\Roaming\optimizer pro
Successfully deleted: [Folder] C:\Users\Kathy\AppData\Roaming\productdata
Successfully deleted: [Folder] C:\Users\Kathy\Documents\optimizer pro
Successfully deleted: [Folder] C:\Users\Kathy\Documents\propccleaner
Successfully deleted: [Folder] C:\Users\Public\qiyi
Successfully deleted: [Folder] C:\ProgramData\28341ff220e0446c9fff27c4493d622e
Successfully deleted: [Folder] C:\ProgramData\7c0535b143fc4671b6ebd202fbffe066
Successfully deleted: [Folder] C:\ProgramData\Service1198
Successfully deleted: [Folder] C:\ProgramData\Service1291
Successfully deleted: [Folder] C:\Users\Kathy\Appdata\Local\BD634EFB-4435-4228-B1B1-B9F4709D5F79
Successfully deleted: [Folder] C:\Users\Kathy\Appdata\Local\gmsd_us_005010030 [Adware.EoRezo]
Successfully deleted: [Folder] C:\Users\Kathy\Appdata\Local\gmsd_us_005010031 [Adware.EoRezo]
~~~ Chrome
[C:\Users\Kathy\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Kathy\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
gegdfeiahlfolhcfioipjlkombmgbakh
papbadoldddalgcjcicnikcfenodpghp
[C:\Users\Kathy\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Kathy\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
gegdfeiahlfolhcfioipjlkombmgbakh,
papbadoldddalgcjcicnikcfenodpghp
]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 08/20/2015 at 9:22:07.25
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
did not find a file called AdwCleaner[SO]