CreateRestorePoint: Task: {5D631C9C-EBE6-4714-B4B1-15EDE585BCDC} - System32\Tasks\ProPCCleaner_Start => C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe <==== ATTENTION Task: {8779DD39-E14C-4D17-A59B-2B86EE35D58A} - System32\Tasks\EC => C:\Users\George\AppData\Roaming\EC.exe <==== ATTENTION Task: {C3F263FA-4DBB-4733-BEF0-D20B163DDA8B} - System32\Tasks\RHLISEA => C:\Users\George\AppData\Roaming\RHLISEA.exe <==== ATTENTION Task: {E0B2BA1D-5343-4191-92AE-6B3F825F1A54} - System32\Tasks\ProPCCleaner_Popup => C:\Program Files (x86)\Pro PC Cleaner\Splash.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\EC.job => C:\Users\George\AppData\Roaming\EC.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\RHLISEA.job => C:\Users\George\AppData\Roaming\RHLISEA.exe <==== ATTENTION Startup: C:\Users\George\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ScarletKnife Install Beta 10.0.5.lnk ShortcutTarget: ScarletKnife Install Beta 10.0.5.lnk -> C:\ProgramData\{23f92019-b8e9-eda7-23f9-92019b8e8066}\ScarletKnife Install Beta 10.0.5.exe (No File) CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR StartupUrls: Default -> "hxxp://websearch.goodforsearch.info/?pid=24390&r=2015/04/12&hid=6916836094339092537&lg=EN&cc=CA&unqvl=86" S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /svc [X] <==== ATTENTION S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /medsvc [X] <==== ATTENTION C:\Program Files (x86)\globalUpdate 2015-04-12 17:20 - 2015-04-12 17:23 - 00000000 ____D () C:\ProgramData\{23f92019-b8e9-eda7-23f9-92019b8e8066} 2015-04-12 17:19 - 2015-04-12 17:33 - 00000000 ____D () C:\ProgramData\{1738ca3d-5e34-df62-1738-8ca3d5e328f5} 2015-04-12 17:18 - 2015-04-12 17:33 - 00000000 ____D () C:\Program Files (x86)\SSalePluuss 2015-04-12 17:18 - 2015-04-12 17:33 - 00000000 ____D () C:\Program Files (x86)\Share on Tumblr 2015-04-12 17:18 - 2015-04-12 17:33 - 00000000 ____D () C:\Program Files (x86)\bestadblocker 2015-04-12 17:18 - 2015-04-12 17:26 - 00000000 ____D () C:\Program Files (x86)\SegmentAmplifier 2015-04-12 17:18 - 2015-04-12 17:18 - 00000000 ____D () C:\ProgramData\gpimanbojhelbdhedhdnebfdffbeckgj 2015-04-12 17:18 - 2015-04-12 17:18 - 00000000 ____D () C:\ProgramData\16265104164591406528 2015-04-12 17:17 - 2015-04-12 17:33 - 00000000 ____D () C:\ProgramData\{6d6cbec2-9659-dfae-6d6c-cbec2965fb0a} 2015-04-12 15:30 - 2015-04-12 15:30 - 00000004 _____ () C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 2015-04-12 15:30 - 2015-04-12 15:30 - 00000000 ____D () C:\ProgramData\ATI 2015-04-12 15:27 - 2015-04-12 17:39 - 00000000 ____D () C:\SUPERDelete 2015-04-12 15:26 - 2015-04-13 20:48 - 00001704 _____ () C:\WINDOWS\Tasks\RHLISEA.job 2015-04-12 15:26 - 2015-04-13 20:48 - 00001350 _____ () C:\WINDOWS\Tasks\EC.job 2015-04-12 15:26 - 2015-04-12 17:33 - 00000000 ____D () C:\Program Files (x86)\globalUpdate 2015-04-12 15:26 - 2015-04-12 17:33 - 00000000 ____D () C:\Program Files (x86)\c9c95e38-2290-42de-ba46-5eb832c1738c 2015-04-12 15:26 - 2015-04-12 15:39 - 00000000 ____D () C:\Users\George\AppData\Roaming\WTools 2015-04-12 15:26 - 2015-04-12 15:26 - 00004710 _____ () C:\WINDOWS\System32\Tasks\RHLISEA 2015-04-12 15:26 - 2015-04-12 15:26 - 00004356 _____ () C:\WINDOWS\System32\Tasks\EC 2015-04-12 15:26 - 2015-04-12 15:26 - 00000000 ____D () C:\Users\George\AppData\Local\globalUpdate 2015-04-12 15:25 - 2015-04-12 15:25 - 00003460 _____ () C:\WINDOWS\System32\Tasks\ProPCCleaner_Popup 2015-04-12 15:25 - 2015-04-12 15:25 - 00003196 _____ () C:\WINDOWS\System32\Tasks\ProPCCleaner_Start 2015-04-12 15:25 - 2015-04-12 15:25 - 00000078 _____ () C:\Users\George\AppData\Roaming\Bubble Suite.installation.log c:\program files (x86)\kmspico 10.0.6 Cmd: wevtutil cl application Cmd: wevtutil cl system Cmd: wevtutil cl security EmptyTemp: