start
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-1168640644-780688045-8547516-23350\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-1168640644-780688045-8547516-23350 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL =
SearchScopes: HKU\S-1-5-21-1168640644-780688045-8547516-23350 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL =
SearchScopes: HKU\S-1-5-21-1168640644-780688045-8547516-23350 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-1168640644-780688045-8547516-23350 -> {CC3F1F5D-0329-4C96-B873-045BB3F08D17} URL =
SearchScopes: HKU\S-1-5-21-1168640644-780688045-8547516-23350 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL =
BHO-x32: LuckyTab Class -> {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} -> C:\Program Files (x86)\MiuiTab\SupTab.dll [2015-06-16] (Thinknice Co. Limited)
FF user.js: detected! => C:\Users\perretj3\AppData\Roaming\Mozilla\Firefox\Profiles\b6lu9odz.default\user.js [2015-06-19]
FF Extension: QuickSearch - C:\Users\perretj3\AppData\Roaming\Mozilla\Firefox\Profiles\b6lu9odz.default\Extensions\
searchffv2@gmail.com [2015-06-19]
FF Extension: Search Enginer - C:\Users\perretj3\AppData\Roaming\Mozilla\Firefox\Profiles\b6lu9odz.default\Extensions\
sweetsearch@gmail.com [2015-06-19]
FF HKLM-x32\...\Firefox\Extensions: [
searchffv2@gmail.com] - C:\Users\perretj3\AppData\Roaming\Mozilla\Firefox\Profiles\b6lu9odz.default\extensions\
searchffv2@gmail.com
FF HKLM-x32\...\Firefox\Extensions: [
sweetsearch@gmail.com] - C:\Users\perretj3\AppData\Roaming\Mozilla\Firefox\Profiles\b6lu9odz.default\extensions\
sweetsearch@gmail.com
FF Extension: No Name - C:\Users\perretj3\AppData\Roaming\Mozilla\Firefox\Profiles\b6lu9odz.default\extensions\
ccf7276c-d388-480f-8835-5b680025e1ca@gmail.com [not found]
CHR Extension: (No Name) - C:\Users\perretj3\AppData\Local\Google\Chrome\User Data\Default\Extensions\acklnhgjphbhhomkneonohbjnbmkclfb [2015-06-19]
S2 WinFixRealTimeProtector; C:\Program Files\WinFix\WinFix Protector\WinFixGuard.exe [X]
2015-06-19 07:51 - 2015-06-19 08:17 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-06-19 07:48 - 2015-06-19 07:56 - 00000000 ____D C:\Users\perretj3\SupTab
2015-06-19 07:44 - 2015-06-19 07:44 - 00000000 ____D C:\ProgramData\8e069cc200004950
2015-06-19 07:43 - 2015-06-22 07:10 - 00001698 _____ C:\Windows\Tasks\BYAIAMUF.job
2015-06-19 07:43 - 2015-06-22 07:10 - 00001346 _____ C:\Windows\Tasks\GNOK.job
2015-06-19 07:43 - 2015-06-19 08:58 - 00000000 ____D C:\Program Files (x86)\69dc8177-a574-4dff-8461-b3267b078dcf
2015-06-19 07:43 - 2015-06-19 07:43 - 00004730 _____ C:\Windows\System32\Tasks\BYAIAMUF
2015-06-19 07:43 - 2015-06-19 07:43 - 00004378 _____ C:\Windows\System32\Tasks\GNOK
2015-06-19 07:42 - 2015-06-19 08:58 - 00000000 ____D C:\Program Files (x86)\globalUpdate
2015-06-19 07:42 - 2015-06-19 07:42 - 00000000 ____D C:\Users\perretj3\AppData\Local\globalUpdate
2015-06-19 07:40 - 2015-06-19 07:40 - 00004282 _____ C:\Windows\System32\Tasks\WinFixUpdater
2015-06-19 07:39 - 2015-06-19 09:03 - 00000000 ____D C:\Program Files (x86)\MiuiTab
2015-06-19 07:39 - 2015-06-19 07:41 - 00000144 _____ C:\Windows\Reimage.ini
2015-06-19 07:39 - 2015-06-19 07:40 - 00000072 _____ C:\Windows\winfix.ini
2015-06-19 07:39 - 2015-06-19 07:39 - 00000000 _____ C:\Windows\prleth.sys
2015-06-19 07:39 - 2015-06-19 07:39 - 00000000 _____ C:\Windows\hgfs.sys
2015-06-19 07:38 - 2015-06-19 07:50 - 00000346 _____ C:\Windows\Tasks\Bidaily Synchronize Task[3c32].job
2015-06-19 07:38 - 2015-06-19 07:38 - 00003264 _____ C:\Windows\System32\Tasks\Bidaily Synchronize Task[3c32]
2015-06-19 07:38 - 2015-06-19 07:38 - 00000000 ____D C:\ProgramData\{03f189dc-2eef-d4a5-03f1-189dc2ee2770}
2015-03-09 23:30 - 2015-03-09 23:30 - 0005487 _____ () C:\Users\perretj3\AppData\Roaming\BYAIAMUF
2015-01-25 18:12 - 2015-01-25 18:12 - 0002086 _____ () C:\Users\perretj3\AppData\Roaming\GNOK
C:\Program Files\WinFix
C:\Users\perretj3\AppData\Roaming\BYAIAMUF.exe
C:\Users\perretj3\AppData\Roaming\GNOK.exe
C:\Users\perretj3\AppData\Roaming\mystartsearch
Task: {187F72E5-8FB5-4342-B313-3D1E1F4C7F88} - System32\Tasks\BYAIAMUF => C:\Users\perretj3\AppData\Roaming\BYAIAMUF.exe
Task: {BC8D46B1-A4C4-42C1-AFD1-499E067592E7} - \WPD\SqmUpload_S-1-5-21-1880470417-4003164424-3182860430-500 No Task File
Task: {CD1EBFB8-35D9-46B4-8B14-3DB34BA2E290} - System32\Tasks\Bidaily Synchronize Task[3c32] => c:\programdata\{03f189dc-2eef-d4a5-03f1-189dc2ee2770}\hqghumeaylnlf.exe [2014-06-19] (PC Utilities Software Limited)
Task: {CFB2E67A-77FB-4AE0-8674-198792CEEA74} - System32\Tasks\{3F8B4945-3037-4438-A78A-6FFEB9521F9B} => pcalua.exe -a C:\Users\perretj3\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=ima
Task: {D96FC8EB-B758-4636-B358-CCA3E4CC2D01} - System32\Tasks\GNOK => C:\Users\perretj3\AppData\Roaming\GNOK.exe
Task: {EB8215EE-7BBE-4DF6-AE32-707853BCE053} - System32\Tasks\WinFixUpdater => C:\Program Files\WinFix\WinFix Protector\WinFixGuard.exe
Task: C:\Windows\Tasks\Bidaily Synchronize Task[3c32].job => c:\programdata\{03f189dc-2eef-d4a5-03f1-189dc2ee2770}\hqghumeaylnlf.exe
Task: C:\Windows\Tasks\BYAIAMUF.job => C:\Users\perretj3\AppData\Roaming\BYAIAMUF.exe
Task: C:\Windows\Tasks\GNOK.job => C:\Users\perretj3\AppData\Roaming\GNOK.exe
EmptyTemp:
end