start CloseProcesses: Hosts: CreateRestorePoint: Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X] BootExecute: autocheck autochk * sdnclean.exe HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKU\S-1-5-21-1729050527-3723923849-1480690319-1276-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-1729050527-3723923849-1480690319-1276-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-3715540173-261750164-1524581544-500-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-3715540173-261750164-1524581544-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-731575003-407927641-2806599476-3611-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-731575003-407927641-2806599476-3611-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-731575003-407927641-2806599476-3623-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-731575003-407927641-2806599476-3623-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-731575003-407927641-2806599476-5590-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-731575003-407927641-2806599476-5590-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1729050527-3723923849-1480690319-3140 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1729050527-3723923849-1480690319-3140-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = FF Keyword.URL: hxxp://go.mail.ru/distib/ep/?product_id=%7BDAF50C9D-B048-4E56-B748-ABC4B0F5D482%7D&gp=811014 S3 dgderdrv; System32\drivers\dgderdrv.sys [X] S1 Teefer3; system32\DRIVERS\Teefer3.sys [X] 2016-08-10 17:47 - 2014-03-26 20:22 - 00000378 _____ C:\windows\Tasks\update-sys.job Task: {ADF8AB99-25B7-4BFE-9D06-56FBA157FFF6} - System32\Tasks\ComDev => C:\Users\jherce.PREMAMANBXL\AppData\Local\ComDev\ComDev.exe <==== ATTENTION Task: C:\windows\Tasks\update-S-1-5-21-1729050527-3723923849-1480690319-3140.job => C:\Program Files\Skillbrains\Updater\Updater.exe Task: C:\windows\Tasks\update-sys.job => C:\Program Files\Skillbrains\Updater\Updater.exe EmptyTemp: end