Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-02-2014 Ran by ella at 2014-02-08 21:27:11 Run:1 Running from C:\Users\ella\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** Start Task: {3AB09144-5E7A-4679-AAE6-E96D75C7D757} - \RunAsStdUser Task No Task File AlternateDataStreams: C:\ProgramData\TEMP:029E021F AlternateDataStreams: C:\ProgramData\TEMP:049C87B7 AlternateDataStreams: C:\ProgramData\TEMP:06253D7D AlternateDataStreams: C:\ProgramData\TEMP:0807AFBC AlternateDataStreams: C:\ProgramData\TEMP:087D1C56 AlternateDataStreams: C:\ProgramData\TEMP:094B2B4C AlternateDataStreams: C:\ProgramData\TEMP:0D3FF2E1 AlternateDataStreams: C:\ProgramData\TEMP:0E341035 AlternateDataStreams: C:\ProgramData\TEMP:14A7EC62 AlternateDataStreams: C:\ProgramData\TEMP:15FA1ECB AlternateDataStreams: C:\ProgramData\TEMP:171AE0BC AlternateDataStreams: C:\ProgramData\TEMP:17DA7CD5 AlternateDataStreams: C:\ProgramData\TEMP:18295838 AlternateDataStreams: C:\ProgramData\TEMP:1A15C498 AlternateDataStreams: C:\ProgramData\TEMP:1BFEE019 AlternateDataStreams: C:\ProgramData\TEMP:1F812AFD AlternateDataStreams: C:\ProgramData\TEMP:1FDDA142 AlternateDataStreams: C:\ProgramData\TEMP:26140299 AlternateDataStreams: C:\ProgramData\TEMP:26C3D553 AlternateDataStreams: C:\ProgramData\TEMP:293E91EE AlternateDataStreams: C:\ProgramData\TEMP:299EEE45 AlternateDataStreams: C:\ProgramData\TEMP:29E2AFFE AlternateDataStreams: C:\ProgramData\TEMP:2A0E0B9F AlternateDataStreams: C:\ProgramData\TEMP:2B353054 AlternateDataStreams: C:\ProgramData\TEMP:2B9724CF AlternateDataStreams: C:\ProgramData\TEMP:2C16E576 AlternateDataStreams: C:\ProgramData\TEMP:2C515259 AlternateDataStreams: C:\ProgramData\TEMP:2D1BE4C6 AlternateDataStreams: C:\ProgramData\TEMP:2E0BE9CA AlternateDataStreams: C:\ProgramData\TEMP:2E0F1A0A AlternateDataStreams: C:\ProgramData\TEMP:3031D8E8 AlternateDataStreams: C:\ProgramData\TEMP:30997E0F AlternateDataStreams: C:\ProgramData\TEMP:318F58ED AlternateDataStreams: C:\ProgramData\TEMP:32ED0002 AlternateDataStreams: C:\ProgramData\TEMP:373C6DC2 AlternateDataStreams: C:\ProgramData\TEMP:37F44C44 AlternateDataStreams: C:\ProgramData\TEMP:38583C87 AlternateDataStreams: C:\ProgramData\TEMP:389D51A1 AlternateDataStreams: C:\ProgramData\TEMP:3D11302A AlternateDataStreams: C:\ProgramData\TEMP:3E7393FC AlternateDataStreams: C:\ProgramData\TEMP:3E7C402E AlternateDataStreams: C:\ProgramData\TEMP:41326804 AlternateDataStreams: C:\ProgramData\TEMP:4220A65C AlternateDataStreams: C:\ProgramData\TEMP:42275BC2 AlternateDataStreams: C:\ProgramData\TEMP:42821DCD AlternateDataStreams: C:\ProgramData\TEMP:42B9B72F AlternateDataStreams: C:\ProgramData\TEMP:42F7036E AlternateDataStreams: C:\ProgramData\TEMP:45CAACFA AlternateDataStreams: C:\ProgramData\TEMP:45E33ED2 AlternateDataStreams: C:\ProgramData\TEMP:47317C33 AlternateDataStreams: C:\ProgramData\TEMP:48071099 AlternateDataStreams: C:\ProgramData\TEMP:4B1807BE AlternateDataStreams: C:\ProgramData\TEMP:4BB6A9E7 AlternateDataStreams: C:\ProgramData\TEMP:4C33F119 AlternateDataStreams: C:\ProgramData\TEMP:52598916 AlternateDataStreams: C:\ProgramData\TEMP:52FE3CCD AlternateDataStreams: C:\ProgramData\TEMP:54997B77 AlternateDataStreams: C:\ProgramData\TEMP:54F7A151 AlternateDataStreams: C:\ProgramData\TEMP:55662D3E AlternateDataStreams: C:\ProgramData\TEMP:55781AF7 AlternateDataStreams: C:\ProgramData\TEMP:5690D76E AlternateDataStreams: C:\ProgramData\TEMP:57737F50 AlternateDataStreams: C:\ProgramData\TEMP:589A2088 AlternateDataStreams: C:\ProgramData\TEMP:5D458568 AlternateDataStreams: C:\ProgramData\TEMP:5E4A7758 AlternateDataStreams: C:\ProgramData\TEMP:64170090 AlternateDataStreams: C:\ProgramData\TEMP:6C1C8691 AlternateDataStreams: C:\ProgramData\TEMP:6C3B96F0 AlternateDataStreams: C:\ProgramData\TEMP:6F16D671 AlternateDataStreams: C:\ProgramData\TEMP:706CFC8E AlternateDataStreams: C:\ProgramData\TEMP:735575D8 AlternateDataStreams: C:\ProgramData\TEMP:73CCE32D AlternateDataStreams: C:\ProgramData\TEMP:7890F666 AlternateDataStreams: C:\ProgramData\TEMP:792C1D5C AlternateDataStreams: C:\ProgramData\TEMP:798A3728 AlternateDataStreams: C:\ProgramData\TEMP:7991541F AlternateDataStreams: C:\ProgramData\TEMP:799B8AA7 AlternateDataStreams: C:\ProgramData\TEMP:7A0A894A AlternateDataStreams: C:\ProgramData\TEMP:7AFC6F91 AlternateDataStreams: C:\ProgramData\TEMP:7C3E753C AlternateDataStreams: C:\ProgramData\TEMP:831B2461 AlternateDataStreams: C:\ProgramData\TEMP:883774F9 AlternateDataStreams: C:\ProgramData\TEMP:891A7A73 AlternateDataStreams: C:\ProgramData\TEMP:8AD1F2E0 AlternateDataStreams: C:\ProgramData\TEMP:8BE98D9F AlternateDataStreams: C:\ProgramData\TEMP:8C443193 AlternateDataStreams: C:\ProgramData\TEMP:8C885EDD AlternateDataStreams: C:\ProgramData\TEMP:8F76671E AlternateDataStreams: C:\ProgramData\TEMP:8FC027DE AlternateDataStreams: C:\ProgramData\TEMP:901256DA AlternateDataStreams: C:\ProgramData\TEMP:9023976A AlternateDataStreams: C:\ProgramData\TEMP:92298B59 AlternateDataStreams: C:\ProgramData\TEMP:9373B271 AlternateDataStreams: C:\ProgramData\TEMP:948CDB3D AlternateDataStreams: C:\ProgramData\TEMP:98A71B94 AlternateDataStreams: C:\ProgramData\TEMP:9F9D57FD AlternateDataStreams: C:\ProgramData\TEMP:A2A602F0 AlternateDataStreams: C:\ProgramData\TEMP:A362A045 AlternateDataStreams: C:\ProgramData\TEMP:A3642ED6 AlternateDataStreams: C:\ProgramData\TEMP:A477A19D AlternateDataStreams: C:\ProgramData\TEMP:A757EEE2 AlternateDataStreams: C:\ProgramData\TEMP:A98B0BB8 AlternateDataStreams: C:\ProgramData\TEMP:ABCD2B94 AlternateDataStreams: C:\ProgramData\TEMP:AC1DA023 AlternateDataStreams: C:\ProgramData\TEMP:ADE91125 AlternateDataStreams: C:\ProgramData\TEMP:AE9DFC85 AlternateDataStreams: C:\ProgramData\TEMP:B51B92ED AlternateDataStreams: C:\ProgramData\TEMP:B6AE8DE6 AlternateDataStreams: C:\ProgramData\TEMP:BA660D25 AlternateDataStreams: C:\ProgramData\TEMP:BB24555F AlternateDataStreams: C:\ProgramData\TEMP:BB9D3F60 AlternateDataStreams: C:\ProgramData\TEMP:BE1DA945 AlternateDataStreams: C:\ProgramData\TEMP:C104B0EF AlternateDataStreams: C:\ProgramData\TEMP:C7F76735 AlternateDataStreams: C:\ProgramData\TEMP:C953979F AlternateDataStreams: C:\ProgramData\TEMP:CEE9940F AlternateDataStreams: C:\ProgramData\TEMP:CEED62ED AlternateDataStreams: C:\ProgramData\TEMP:CF2C26D2 AlternateDataStreams: C:\ProgramData\TEMP:D20FFA63 AlternateDataStreams: C:\ProgramData\TEMP:D3F5157D AlternateDataStreams: C:\ProgramData\TEMP:D6C2C750 AlternateDataStreams: C:\ProgramData\TEMP:D7CCB616 AlternateDataStreams: C:\ProgramData\TEMP:DAFAF1BF AlternateDataStreams: C:\ProgramData\TEMP:DD3F5AF4 AlternateDataStreams: C:\ProgramData\TEMP:DE22D45C AlternateDataStreams: C:\ProgramData\TEMP:E0CDAF60 AlternateDataStreams: C:\ProgramData\TEMP:E1069F99 AlternateDataStreams: C:\ProgramData\TEMP:E10DCAF3 AlternateDataStreams: C:\ProgramData\TEMP:E3C19E60 AlternateDataStreams: C:\ProgramData\TEMP:E95683AD AlternateDataStreams: C:\ProgramData\TEMP:ECB488E5 AlternateDataStreams: C:\ProgramData\TEMP:EE198B1F AlternateDataStreams: C:\ProgramData\TEMP:EFC8E0D1 AlternateDataStreams: C:\ProgramData\TEMP:F131B2B8 AlternateDataStreams: C:\ProgramData\TEMP:F2F115B4 AlternateDataStreams: C:\ProgramData\TEMP:F46BE53E AlternateDataStreams: C:\ProgramData\TEMP:F5955908 AlternateDataStreams: C:\ProgramData\TEMP:F79CBFC4 AlternateDataStreams: C:\ProgramData\TEMP:F854B030 AlternateDataStreams: C:\ProgramData\TEMP:F854E9B8 AlternateDataStreams: C:\ProgramData\TEMP:F880DE59 AlternateDataStreams: C:\ProgramData\TEMP:F8CC1DFD AlternateDataStreams: C:\ProgramData\TEMP:F9B7A59C AlternateDataStreams: C:\ProgramData\TEMP:FACC16FC AlternateDataStreams: C:\ProgramData\TEMP:FD20BDA6 C:\ProgramData\WinWeb protection\WinWebprotection.dll C:\ProgramData\WinWeb protection C:\ProgramData\Speed Streamer\SpeedStreamer.dll C:\ProgramData\Speed Streamer C:\ProgramData\System Booster\SystemBooster.dll C:\ProgramData\System Booster HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] ATTENTION! ====> ZeroAccess? HKU\.DEFAULT\...\Run: [systray] - C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe HKU\S-1-5-19\...\Run: [systray] - C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe HKU\S-1-5-20\...\Run: [systray] - C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe HKU\S-1-5-21-3157340471-375526885-1420865249-1000\...\Run: [TheAeroClock] - "C:\Users\ella\AppData\Local\Temp\Temp10_TheAeroClock.zip\TheAeroClock.exe" -bg <===== ATTENTION HKU\S-1-5-21-3157340471-375526885-1420865249-1000\...\Run: [Rainlendar2] - C:\Program Files\Rainlendar2\Rainlendar2.exe [3931136 2012-07-02] () HKU\S-1-5-21-3157340471-375526885-1420865249-1000\...\Run: [xwidget] - C:\Program Files (x86)\XWidget\xwidget.exe C:\Program Files (x86)\XWidget HKU\S-1-5-21-3157340471-375526885-1420865249-1000\...\MountPoints2: {37000b85-73fe-11e0-b7df-78843c2f7300} - E:\USBAutoRun.exe AppInit_DLLs: C:\PROGRA~3\WINWEB~1\WINWEB~2.DLL => C:\ProgramData\WinWeb protection\WinWebprotection_x64.dll [4392448 2013-12-28] () AppInit_DLLs: C:\PROGRA~3\SPEEDS~1\SPEEDS~2.DLL => C:\ProgramData\Speed Streamer\SpeedStreamer_x64.dll [4416000 2013-12-30] () AppInit_DLLs: C:\PROGRA~3\SYSTEM~1\SYSTEM~2.DLL => C:\ProgramData\System Booster\SystemBooster_x64.dll [4443136 2014-01-01] () AppInit_DLLs-x32: c:\progra~3\winweb~1\winweb~1.dll => C:\ProgramData\WinWeb protection\WinWebprotection.dll [4121088 2013-12-28] () AppInit_DLLs-x32: c:\progra~3\speeds~1\speeds~1.dll => C:\ProgramData\Speed Streamer\SpeedStreamer.dll [4130816 2013-12-30] () AppInit_DLLs-x32: c:\progra~3\system~1\system~1.dll => C:\ProgramData\System Booster\SystemBooster.dll [4242944 2014-01-01] () AppInit_DLLs: C:\PROGRA~3\WINWEB~1\WINWEB~2.DLL => C:\ProgramData\WinWeb protection\WinWebprotection_x64.dll [4392448 2013-12-28] () AppInit_DLLs: C:\PROGRA~3\SPEEDS~1\SPEEDS~2.DLL => C:\ProgramData\Speed Streamer\SpeedStreamer_x64.dll [4416000 2013-12-30] () AppInit_DLLs: C:\PROGRA~3\SYSTEM~1\SYSTEM~2.DLL => C:\ProgramData\System Booster\SystemBooster_x64.dll [4443136 2014-01-01] () AppInit_DLLs-x32: c:\progra~3\winweb~1\winweb~1.dll => C:\ProgramData\WinWeb protection\WinWebprotection.dll [4121088 2013-12-28] () AppInit_DLLs-x32: c:\progra~3\speeds~1\speeds~1.dll => C:\ProgramData\Speed Streamer\SpeedStreamer.dll [4130816 2013-12-30] () AppInit_DLLs-x32: c:\progra~3\system~1\system~1.dll => C:\ProgramData\System Booster\SystemBooster.dll [4242944 2014-01-01] () HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1391640965&from=air&uid=TOSHIBAXMK3265GSXN_X095D00TBXXX095D00TB&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://le%20pogona/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1391640965&from=air&uid=TOSHIBAXMK3265GSXN_X095D00TBXXX095D00TB HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/web/?type=ds&ts=1391640965&from=air&uid=TOSHIBAXMK3265GSXN_X095D00TBXXX095D00TB&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/web/?type=ds&ts=1391640965&from=air&uid=TOSHIBAXMK3265GSXN_X095D00TBXXX095D00TB&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1391640965&from=air&uid=TOSHIBAXMK3265GSXN_X095D00TBXXX095D00TB HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com/?type=hp&ts=1391640965&from=air&uid=TOSHIBAXMK3265GSXN_X095D00TBXXX095D00TB HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1391640965&from=air&uid=TOSHIBAXMK3265GSXN_X095D00TBXXX095D00TB&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/web/?type=ds&ts=1391640965&from=air&uid=TOSHIBAXMK3265GSXN_X095D00TBXXX095D00TB&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1391640965&from=air&uid=TOSHIBAXMK3265GSXN_X095D00TBXXX095D00TB HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com/?type=hp&ts=1391640965&from=air&uid=TOSHIBAXMK3265GSXN_X095D00TBXXX095D00TB HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1391640965&from=air&uid=TOSHIBAXMK3265GSXN_X095D00TBXXX095D00TB&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.awesomehp.com/?type=sc&ts=1391640965&from=air&uid=TOSHIBAXMK3265GSXN_X095D00TBXXX095D00TB SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd1103&cd=2XzuyEtN2Y1L1QzuyBzzzzyEtA0CtB0FyBtAtDtD0C0ByC0BtN0D0Tzu0SyBtDzztN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1678006637&ir= BHO: TubeIttADBllocKFr - {0A894228-DA43-B2DD-B015-9C3A7C2AFCE2} - C:\ProgramData\TubeIttADBllocKFr\Xcd9gR.x64.dll () BHO: FunDueals - {5A2574AB-FE05-50FA-B256-50BA363AF431} - C:\ProgramData\FunDueals\DB4P1.x64.dll () BHO: RoBoSavveoR - {D20EE9E7-9D58-DF96-0B43-88F81F4781BD} - C:\ProgramData\RoBoSavveoR\_twGc.x64.dll () BHO-x32: crimsolite - {45fecc6b-dd67-41ff-984b-d43ba5d53574} - C:\Program Files (x86)\crimsolite\crimsolitebho.dll (crimsolite) C:\Program Files (x86)\crimsolite CHR HomePage: hxxp://www.awesomehp.com/?type=hp&ts=1391640965&from=air&uid=TOSHIBAXMK3265GSXN_X095D00TBXXX095D00TB CHR Plugin: (Wajam) - C:\Users\ella\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\plugins/PriamNPAPI.dll No File CHR Extension: (FunDueals) - C:\ProgramData\eppinbnjlaamcoilceemnefbbfhgaagj [2013-12-29] CHR Extension: (Lightning speedDial) - C:\Users\ella\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkndmigholgfjlniaohblojbhgjbkakn [2014-02-05] CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.awesomehp.com/?type=sc&ts=1391640965&from=air&uid=TOSHIBAXMK3265GSXN_X095D00TBXXX095D00TB CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION CHR HKLM-x32\...\Chrome\Extension: [pkndmigholgfjlniaohblojbhgjbkakn] - C:\Users\ella\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv2.crx [2014-02-05] R2 89f7ebe4; C:\ProgramData\WinWeb protection\WinWebprotectionSvc.dll [182608 2013-12-28] () R2 a1851772; C:\ProgramData\System Booster\SystemBoosterSvc.dll [179536 2014-01-01] () S3 Boonty Games; C:\Program Files (x86)\Common Files\BOONTY Shared\Service\Boonty.exe [69120 2011-11-20] (BOONTY) R2 d458591c; C:\ProgramData\Speed Streamer\SpeedStreamerSvc.dll [180048 2013-12-30] () 2014-02-05 23:52 - 2014-02-05 23:52 - 00321104 _____ () C:\Users\ella\Downloads\Player Setup (2).exe 2014-02-05 23:45 - 2014-02-05 23:45 - 00321104 _____ () C:\Users\ella\Downloads\Player Setup (1).exe 2014-02-05 23:43 - 2014-02-05 23:43 - 00321104 _____ () C:\Users\ella\Downloads\Player Setup.exe 2014-02-01 22:14 - 2014-02-01 22:14 - 00002760 _____ () C:\Users\ella\Downloads\2A5F.tmp 2014-01-31 23:56 - 2014-01-31 23:56 - 06889432 _____ (ObviousIdea.com ) C:\Users\ella\Downloads\EasyPhotoUploader_for_Facebook_setup.exe 2014-01-31 21:42 - 2014-01-31 21:42 - 00000000 ____D () C:\ProgramData\TubeIttADBllocKFr 2014-01-31 21:42 - 2014-01-31 21:42 - 00000000 ____D () C:\ProgramData\mbmjloiboonmbpmlkmhncacbfdgomafm 2014-01-14 21:10 - 2014-01-14 21:11 - 04741136 _____ () C:\Users\ella\Downloads\adblockplusie-1.1.exe 2014-02-05 23:56 - 2013-11-12 21:43 - 00002668 _____ () C:\Users\ella\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Le Pogona - Vos sites préférés accessibles en un clic ! (1).lnk C:\$Recycle.Bin\S-1-5-21-3157340471-375526885-1420865249-1000\$b8f82b15438c4a231bb9d36115f83576 C:\$Recycle.Bin\S-1-5-18\$b8f82b15438c4a231bb9d36115f83576 C:\Users\ella\Captvty.exe C:\Users\ella\Setup.exe C:\Users\ella\AppData\Local\Temp\76373uninstall.exe C:\Users\ella\AppData\Local\Temp\air1371.exe C:\Users\ella\AppData\Local\Temp\air605A.exe C:\Users\ella\AppData\Local\Temp\airACC5.exe C:\Users\ella\AppData\Local\Temp\airBF67.exe C:\Users\ella\AppData\Local\Temp\BackupSetup.exe C:\Users\ella\AppData\Local\Temp\BF68_HiDefMedia-1.1.12-win32.exe C:\Users\ella\AppData\Local\Temp\cleanuninstall.exe C:\Users\ella\AppData\Local\Temp\FreemakeVideoDownloader_3.5.1.0.exe C:\Users\ella\AppData\Local\Temp\FreemakeVideoDownloader_3.5.2.4.exe C:\Users\ella\AppData\Local\Temp\FreemakeYoutubeMp3Converter_3.5.2.5.exe C:\Users\ella\AppData\Local\Temp\ICReinstall_nsqFF7B.tmp.exe C:\Users\ella\AppData\Local\Temp\ICReinstall_xwidget_setup188.exe C:\Users\ella\AppData\Local\Temp\InstallFlashPlayer.exe C:\Users\ella\AppData\Local\Temp\jna1811382523787491330.dll C:\Users\ella\AppData\Local\Temp\jna7181485984464790288.dll C:\Users\ella\AppData\Local\Temp\nsqD912.tmp.exe C:\Users\ella\AppData\Local\Temp\Quarantine.exe C:\Users\ella\AppData\Local\Temp\SkypeSetup.exe C:\Users\ella\AppData\Local\Temp\Sqlite3.dll C:\Users\ella\AppData\Local\Temp\sSetup-se.exe C:\Users\ella\AppData\Local\Temp\vlc-2.0.8-win32.exe Task: {12357BCA-E986-4E68-B40E-CAD5FE86BFDD} - System32\Tasks\{12FB1A96-B3B3-46AF-A1BC-535F2ABAE566} => C:\Program Files (x86)\VSO\VSO Downloader\2\VsoDownloader.exe Task: {4BF7F3B5-CCA8-4DE3-9548-FD30A6CD7D51} - System32\Tasks\{2059A96F-77CB-464A-B817-7D04568B7B78} => C:\Program Files (x86)\VSO\VSO Downloader\2\VsoDownloader.exe Task: {528C5215-59A3-49FD-A492-09FC3EE2D97C} - System32\Tasks\{CE7C6EEF-1961-449A-9324-D2CFB4596113} => C:\Program Files (x86)\VSO\VSO Downloader\2\VsoDownloader.exe Task: {597701C9-FB52-469D-B9EB-B985866D0F33} - System32\Tasks\{EB5D50E7-E161-46E4-8FE0-633482A90C84} => C:\Program Files (x86)\VSO\VSO Downloader\2\VsoDownloader.exe Task: {72C4985A-25B5-43B9-AFA3-567F299B0C8A} - System32\Tasks\{D677FE84-09F6-4C11-A942-4B81A99DEEA8} => C:\Program Files (x86)\JEUX ANNE\Deadtime Stories\DeadtimeStories.exe end ***************** HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3AB09144-5E7A-4679-AAE6-E96D75C7D757} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3AB09144-5E7A-4679-AAE6-E96D75C7D757} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RunAsStdUser Task => Key deleted successfully. C:\ProgramData\TEMP => ":029E021F" ADS removed successfully. C:\ProgramData\TEMP => ":049C87B7" ADS removed successfully. C:\ProgramData\TEMP => ":06253D7D" ADS removed successfully. C:\ProgramData\TEMP => ":0807AFBC" ADS removed successfully. C:\ProgramData\TEMP => ":087D1C56" ADS removed successfully. C:\ProgramData\TEMP => ":094B2B4C" ADS removed successfully. C:\ProgramData\TEMP => ":0D3FF2E1" ADS removed successfully. C:\ProgramData\TEMP => ":0E341035" ADS removed successfully. C:\ProgramData\TEMP => ":14A7EC62" ADS removed successfully. C:\ProgramData\TEMP => ":15FA1ECB" ADS removed successfully. C:\ProgramData\TEMP => ":171AE0BC" ADS removed successfully. C:\ProgramData\TEMP => ":17DA7CD5" ADS removed successfully. C:\ProgramData\TEMP => ":18295838" ADS removed successfully. C:\ProgramData\TEMP => ":1A15C498" ADS removed successfully. C:\ProgramData\TEMP => ":1BFEE019" ADS removed successfully. C:\ProgramData\TEMP => ":1F812AFD" ADS removed successfully. C:\ProgramData\TEMP => ":1FDDA142" ADS removed successfully. C:\ProgramData\TEMP => ":26140299" ADS removed successfully. C:\ProgramData\TEMP => ":26C3D553" ADS removed successfully. C:\ProgramData\TEMP => ":293E91EE" ADS removed successfully. C:\ProgramData\TEMP => ":299EEE45" ADS removed successfully. C:\ProgramData\TEMP => ":29E2AFFE" ADS removed successfully. C:\ProgramData\TEMP => ":2A0E0B9F" ADS removed successfully. C:\ProgramData\TEMP => ":2B353054" ADS removed successfully. C:\ProgramData\TEMP => ":2B9724CF" ADS removed successfully. C:\ProgramData\TEMP => ":2C16E576" ADS removed successfully. C:\ProgramData\TEMP => ":2C515259" ADS removed successfully. C:\ProgramData\TEMP => ":2D1BE4C6" ADS removed successfully. C:\ProgramData\TEMP => ":2E0BE9CA" ADS removed successfully. C:\ProgramData\TEMP => ":2E0F1A0A" ADS removed successfully. C:\ProgramData\TEMP => ":3031D8E8" ADS removed successfully. C:\ProgramData\TEMP => ":30997E0F" ADS removed successfully. C:\ProgramData\TEMP => ":318F58ED" ADS removed successfully. C:\ProgramData\TEMP => ":32ED0002" ADS removed successfully. C:\ProgramData\TEMP => ":373C6DC2" ADS removed successfully. C:\ProgramData\TEMP => ":37F44C44" ADS removed successfully. C:\ProgramData\TEMP => ":38583C87" ADS removed successfully. C:\ProgramData\TEMP => ":389D51A1" ADS removed successfully. C:\ProgramData\TEMP => ":3D11302A" ADS removed successfully. C:\ProgramData\TEMP => ":3E7393FC" ADS removed successfully. C:\ProgramData\TEMP => ":3E7C402E" ADS removed successfully. C:\ProgramData\TEMP => ":41326804" ADS removed successfully. C:\ProgramData\TEMP => ":4220A65C" ADS removed successfully. C:\ProgramData\TEMP => ":42275BC2" ADS removed successfully. C:\ProgramData\TEMP => ":42821DCD" ADS removed successfully. C:\ProgramData\TEMP => ":42B9B72F" ADS removed successfully. C:\ProgramData\TEMP => ":42F7036E" ADS removed successfully. C:\ProgramData\TEMP => ":45CAACFA" ADS removed successfully. C:\ProgramData\TEMP => ":45E33ED2" ADS removed successfully. C:\ProgramData\TEMP => ":47317C33" ADS removed successfully. C:\ProgramData\TEMP => ":48071099" ADS removed successfully. C:\ProgramData\TEMP => ":4B1807BE" ADS removed successfully. C:\ProgramData\TEMP => ":4BB6A9E7" ADS removed successfully. C:\ProgramData\TEMP => ":4C33F119" ADS removed successfully. C:\ProgramData\TEMP => ":52598916" ADS removed successfully. C:\ProgramData\TEMP => ":52FE3CCD" ADS removed successfully. C:\ProgramData\TEMP => ":54997B77" ADS removed successfully. C:\ProgramData\TEMP => ":54F7A151" ADS removed successfully. C:\ProgramData\TEMP => ":55662D3E" ADS removed successfully. C:\ProgramData\TEMP => ":55781AF7" ADS removed successfully. C:\ProgramData\TEMP => ":5690D76E" ADS removed successfully. C:\ProgramData\TEMP => ":57737F50" ADS removed successfully. C:\ProgramData\TEMP => ":589A2088" ADS removed successfully. C:\ProgramData\TEMP => ":5D458568" ADS removed successfully. C:\ProgramData\TEMP => ":5E4A7758" ADS removed successfully. C:\ProgramData\TEMP => ":64170090" ADS removed successfully. C:\ProgramData\TEMP => ":6C1C8691" ADS removed successfully. C:\ProgramData\TEMP => ":6C3B96F0" ADS removed successfully. C:\ProgramData\TEMP => ":6F16D671" ADS removed successfully. C:\ProgramData\TEMP => ":706CFC8E" ADS removed successfully. C:\ProgramData\TEMP => ":735575D8" ADS removed successfully. C:\ProgramData\TEMP => ":73CCE32D" ADS removed successfully. C:\ProgramData\TEMP => ":7890F666" ADS removed successfully. C:\ProgramData\TEMP => ":792C1D5C" ADS removed successfully. C:\ProgramData\TEMP => ":798A3728" ADS removed successfully. C:\ProgramData\TEMP => ":7991541F" ADS removed successfully. C:\ProgramData\TEMP => ":799B8AA7" ADS removed successfully. C:\ProgramData\TEMP => ":7A0A894A" ADS removed successfully. C:\ProgramData\TEMP => ":7AFC6F91" ADS removed successfully. C:\ProgramData\TEMP => ":7C3E753C" ADS removed successfully. C:\ProgramData\TEMP => ":831B2461" ADS removed successfully. C:\ProgramData\TEMP => ":883774F9" ADS removed successfully. C:\ProgramData\TEMP => ":891A7A73" ADS removed successfully. C:\ProgramData\TEMP => ":8AD1F2E0" ADS removed successfully. C:\ProgramData\TEMP => ":8BE98D9F" ADS removed successfully. C:\ProgramData\TEMP => ":8C443193" ADS removed successfully. C:\ProgramData\TEMP => ":8C885EDD" ADS removed successfully. C:\ProgramData\TEMP => ":8F76671E" ADS removed successfully. C:\ProgramData\TEMP => ":8FC027DE" ADS removed successfully. C:\ProgramData\TEMP => ":901256DA" ADS removed successfully. C:\ProgramData\TEMP => ":9023976A" ADS removed successfully. C:\ProgramData\TEMP => ":92298B59" ADS removed successfully. C:\ProgramData\TEMP => ":9373B271" ADS removed successfully. C:\ProgramData\TEMP => ":948CDB3D" ADS removed successfully. C:\ProgramData\TEMP => ":98A71B94" ADS removed successfully. C:\ProgramData\TEMP => ":9F9D57FD" ADS removed successfully. C:\ProgramData\TEMP => ":A2A602F0" ADS removed successfully. C:\ProgramData\TEMP => ":A362A045" ADS removed successfully. C:\ProgramData\TEMP => ":A3642ED6" ADS removed successfully. C:\ProgramData\TEMP => ":A477A19D" ADS removed successfully. C:\ProgramData\TEMP => ":A757EEE2" ADS removed successfully. C:\ProgramData\TEMP => ":A98B0BB8" ADS removed successfully. C:\ProgramData\TEMP => ":ABCD2B94" ADS removed successfully. C:\ProgramData\TEMP => ":AC1DA023" ADS removed successfully. C:\ProgramData\TEMP => ":ADE91125" ADS removed successfully. C:\ProgramData\TEMP => ":AE9DFC85" ADS removed successfully. C:\ProgramData\TEMP => ":B51B92ED" ADS removed successfully. C:\ProgramData\TEMP => ":B6AE8DE6" ADS removed successfully. C:\ProgramData\TEMP => ":BA660D25" ADS removed successfully. C:\ProgramData\TEMP => ":BB24555F" ADS removed successfully. C:\ProgramData\TEMP => ":BB9D3F60" ADS removed successfully. C:\ProgramData\TEMP => ":BE1DA945" ADS removed successfully. C:\ProgramData\TEMP => ":C104B0EF" ADS removed successfully. C:\ProgramData\TEMP => ":C7F76735" ADS removed successfully. C:\ProgramData\TEMP => ":C953979F" ADS removed successfully. C:\ProgramData\TEMP => ":CEE9940F" ADS removed successfully. C:\ProgramData\TEMP => ":CEED62ED" ADS removed successfully. C:\ProgramData\TEMP => ":CF2C26D2" ADS removed successfully. C:\ProgramData\TEMP => ":D20FFA63" ADS removed successfully. C:\ProgramData\TEMP => ":D3F5157D" ADS removed successfully. C:\ProgramData\TEMP => ":D6C2C750" ADS removed successfully. C:\ProgramData\TEMP => ":D7CCB616" ADS removed successfully. C:\ProgramData\TEMP => ":DAFAF1BF" ADS removed successfully. C:\ProgramData\TEMP => ":DD3F5AF4" ADS removed successfully. C:\ProgramData\TEMP => ":DE22D45C" ADS removed successfully. C:\ProgramData\TEMP => ":E0CDAF60" ADS removed successfully. C:\ProgramData\TEMP => ":E1069F99" ADS removed successfully. C:\ProgramData\TEMP => ":E10DCAF3" ADS removed successfully. C:\ProgramData\TEMP => ":E3C19E60" ADS removed successfully. C:\ProgramData\TEMP => ":E95683AD" ADS removed successfully. C:\ProgramData\TEMP => ":ECB488E5" ADS removed successfully. C:\ProgramData\TEMP => ":EE198B1F" ADS removed successfully. C:\ProgramData\TEMP => ":EFC8E0D1" ADS removed successfully. C:\ProgramData\TEMP => ":F131B2B8" ADS removed successfully. C:\ProgramData\TEMP => ":F2F115B4" ADS removed successfully. C:\ProgramData\TEMP => ":F46BE53E" ADS removed successfully. C:\ProgramData\TEMP => ":F5955908" ADS removed successfully. C:\ProgramData\TEMP => ":F79CBFC4" ADS removed successfully. C:\ProgramData\TEMP => ":F854B030" ADS removed successfully. C:\ProgramData\TEMP => ":F854E9B8" ADS removed successfully. C:\ProgramData\TEMP => ":F880DE59" ADS removed successfully. C:\ProgramData\TEMP => ":F8CC1DFD" ADS removed successfully. C:\ProgramData\TEMP => ":F9B7A59C" ADS removed successfully. C:\ProgramData\TEMP => ":FACC16FC" ADS removed successfully. C:\ProgramData\TEMP => ":FD20BDA6" ADS removed successfully. C:\ProgramData\WinWeb protection\WinWebprotection.dll => Moved successfully. "C:\ProgramData\WinWeb protection" directory move: Could not move "C:\ProgramData\WinWeb protection\WinWebprotectionSvc.dll" => Scheduled to move on reboot. C:\ProgramData\WinWeb protection\WinWebprotection_x64.dll => Moved successfully. Could not move "C:\ProgramData\WinWeb protection" directory. => Scheduled to move on reboot. C:\ProgramData\Speed Streamer\SpeedStreamer.dll => Moved successfully. "C:\ProgramData\Speed Streamer" directory move: Could not move "C:\ProgramData\Speed Streamer\SpeedStreamerSvc.dll" => Scheduled to move on reboot. C:\ProgramData\Speed Streamer\SpeedStreamer_x64.dll => Moved successfully. Could not move "C:\ProgramData\Speed Streamer" directory. => Scheduled to move on reboot. C:\ProgramData\System Booster\SystemBooster.dll => Moved successfully. "C:\ProgramData\System Booster" directory move: Could not move "C:\ProgramData\System Booster\SystemBoosterSvc.dll" => Scheduled to move on reboot. C:\ProgramData\System Booster\SystemBooster_x64.dll => Moved successfully. Could not move "C:\ProgramData\System Booster" directory. => Scheduled to move on reboot. HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\\Default => Value was restored successfully. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\\systray => Value deleted successfully. HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\\systray => Value deleted successfully. HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\\systray => Value deleted successfully. "C:\Program Files (x86)\TheBestMatch\Homepage\DWCSysTray.exe" => File/Directory not found. HKU\S-1-5-21-3157340471-375526885-1420865249-1000\Software\Microsoft\Windows\CurrentVersion\Run\\TheAeroClock => Value deleted successfully. HKU\S-1-5-21-3157340471-375526885-1420865249-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Rainlendar2 => Value deleted successfully. HKU\S-1-5-21-3157340471-375526885-1420865249-1000\Software\Microsoft\Windows\CurrentVersion\Run\\xwidget => Value deleted successfully. "C:\Program Files (x86)\XWidget" => File/Directory not found. HKU\1\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{37000b85-73fe-11e0-b7df-78843c2f7300} => Key not found. HKCR\CLSID\{37000b85-73fe-11e0-b7df-78843c2f7300} => Key not found. "C:\\PROGRA~3\\WINWEB~1\\WINWEB~2.DLL" => Value Data removed successfully. "C:\\PROGRA~3\\SPEEDS~1\\SPEEDS~2.DLL" => Value Data removed successfully. "C:\\PROGRA~3\\SYSTEM~1\\SYSTEM~2.DLL" => Value Data removed successfully. "c:\\progra~3\\winweb~1\\winweb~1.dll" => Value Data removed successfully. "c:\\progra~3\\speeds~1\\speeds~1.dll" => Value Data removed successfully. "c:\\progra~3\\system~1\\system~1.dll" => Value Data removed successfully. "C:\\PROGRA~3\\WINWEB~1\\WINWEB~2.DLL" => Value Data not found. "C:\\PROGRA~3\\SPEEDS~1\\SPEEDS~2.DLL" => Value Data not found. "C:\\PROGRA~3\\SYSTEM~1\\SYSTEM~2.DLL" => Value Data not found. "c:\\progra~3\\winweb~1\\winweb~1.dll" => Value Data not found. "c:\\progra~3\\speeds~1\\speeds~1.dll" => Value Data not found. "c:\\progra~3\\system~1\\system~1.dll" => Value Data not found. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully. HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0A894228-DA43-B2DD-B015-9C3A7C2AFCE2} => Key deleted successfully. HKCR\CLSID\{0A894228-DA43-B2DD-B015-9C3A7C2AFCE2} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5A2574AB-FE05-50FA-B256-50BA363AF431} => Key deleted successfully. HKCR\CLSID\{5A2574AB-FE05-50FA-B256-50BA363AF431} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D20EE9E7-9D58-DF96-0B43-88F81F4781BD} => Key deleted successfully. HKCR\CLSID\{D20EE9E7-9D58-DF96-0B43-88F81F4781BD} => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45fecc6b-dd67-41ff-984b-d43ba5d53574} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{45fecc6b-dd67-41ff-984b-d43ba5d53574} => Key deleted successfully. C:\Program Files (x86)\crimsolite => Moved successfully. CHR HomePage: hxxp://www.awesomehp.com/?type=hp&ts=1391640965&from=air&uid=TOSHIBAXMK3265GSXN_X095D00TBXXX095D00TB ==> The Chrome "Settings" can be used to fix the entry. C:\Users\ella\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\plugins/PriamNPAPI.dll not found. CHR Extension: (FunDueals) - C:\ProgramData\eppinbnjlaamcoilceemnefbbfhgaagj [2013-12-29] directory not found. C:\Users\ella\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkndmigholgfjlniaohblojbhgjbkakn => Moved successfully. HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command\\Default => Value was restored successfully. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pkndmigholgfjlniaohblojbhgjbkakn => Key deleted successfully. C:\Users\ella\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv2.crx => Moved successfully. 89f7ebe4 => Service deleted successfully. a1851772 => Service deleted successfully. Boonty Games => Service deleted successfully. d458591c => Service deleted successfully. C:\Users\ella\Downloads\Player Setup (2).exe => Moved successfully. C:\Users\ella\Downloads\Player Setup (1).exe => Moved successfully. C:\Users\ella\Downloads\Player Setup.exe => Moved successfully. C:\Users\ella\Downloads\2A5F.tmp => Moved successfully. C:\Users\ella\Downloads\EasyPhotoUploader_for_Facebook_setup.exe => Moved successfully. C:\ProgramData\TubeIttADBllocKFr => Moved successfully. C:\ProgramData\mbmjloiboonmbpmlkmhncacbfdgomafm => Moved successfully. C:\Users\ella\Downloads\adblockplusie-1.1.exe => Moved successfully. C:\Users\ella\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Le Pogona - Vos sites préférés accessibles en un clic ! (1).lnk => Moved successfully. C:\$Recycle.Bin\S-1-5-21-3157340471-375526885-1420865249-1000\$b8f82b15438c4a231bb9d36115f83576 => Moved successfully. C:\$Recycle.Bin\S-1-5-18\$b8f82b15438c4a231bb9d36115f83576 => Moved successfully. C:\Users\ella\Captvty.exe => Moved successfully. C:\Users\ella\Setup.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\76373uninstall.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\air1371.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\air605A.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\airACC5.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\airBF67.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\BackupSetup.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\BF68_HiDefMedia-1.1.12-win32.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\cleanuninstall.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\FreemakeVideoDownloader_3.5.1.0.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\FreemakeVideoDownloader_3.5.2.4.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\FreemakeYoutubeMp3Converter_3.5.2.5.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\ICReinstall_nsqFF7B.tmp.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\ICReinstall_xwidget_setup188.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\InstallFlashPlayer.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\jna1811382523787491330.dll => Moved successfully. C:\Users\ella\AppData\Local\Temp\jna7181485984464790288.dll => Moved successfully. C:\Users\ella\AppData\Local\Temp\nsqD912.tmp.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\Quarantine.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\SkypeSetup.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\Sqlite3.dll => Moved successfully. C:\Users\ella\AppData\Local\Temp\sSetup-se.exe => Moved successfully. C:\Users\ella\AppData\Local\Temp\vlc-2.0.8-win32.exe => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{12357BCA-E986-4E68-B40E-CAD5FE86BFDD} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{12357BCA-E986-4E68-B40E-CAD5FE86BFDD} => Key deleted successfully. C:\Windows\System32\Tasks\{12FB1A96-B3B3-46AF-A1BC-535F2ABAE566} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{12FB1A96-B3B3-46AF-A1BC-535F2ABAE566} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4BF7F3B5-CCA8-4DE3-9548-FD30A6CD7D51} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4BF7F3B5-CCA8-4DE3-9548-FD30A6CD7D51} => Key deleted successfully. C:\Windows\System32\Tasks\{2059A96F-77CB-464A-B817-7D04568B7B78} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2059A96F-77CB-464A-B817-7D04568B7B78} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{528C5215-59A3-49FD-A492-09FC3EE2D97C} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{528C5215-59A3-49FD-A492-09FC3EE2D97C} => Key deleted successfully. C:\Windows\System32\Tasks\{CE7C6EEF-1961-449A-9324-D2CFB4596113} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CE7C6EEF-1961-449A-9324-D2CFB4596113} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{597701C9-FB52-469D-B9EB-B985866D0F33} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{597701C9-FB52-469D-B9EB-B985866D0F33} => Key deleted successfully. C:\Windows\System32\Tasks\{EB5D50E7-E161-46E4-8FE0-633482A90C84} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{EB5D50E7-E161-46E4-8FE0-633482A90C84} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{72C4985A-25B5-43B9-AFA3-567F299B0C8A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72C4985A-25B5-43B9-AFA3-567F299B0C8A} => Key deleted successfully. C:\Windows\System32\Tasks\{D677FE84-09F6-4C11-A942-4B81A99DEEA8} => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D677FE84-09F6-4C11-A942-4B81A99DEEA8} => Key deleted successfully. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-02-08 21:29:54)<= C:\ProgramData\WinWeb protection\WinWebprotectionSvc.dll => Is moved successfully. C:\ProgramData\WinWeb protection => Is moved successfully. C:\ProgramData\Speed Streamer\SpeedStreamerSvc.dll => Is moved successfully. C:\ProgramData\Speed Streamer => Is moved successfully. C:\ProgramData\System Booster\SystemBoosterSvc.dll => Is moved successfully. C:\ProgramData\System Booster => Is moved successfully. ==== End of Fixlog ====