start
CloseProcesses:
GroupPolicy: Group Policy on Chrome detected
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction
SearchScopes: HKLM -> {A25AC313-DD19-4238-ACA2-401D6BEE4321} URL =
http://Lasaoren.com/results.php?f=4&q={ ... 849537&ir=
SearchScopes: HKU\S-1-5-21-4092278269-1464089807-1071999903-1000 -> {A25AC313-DD19-4238-ACA2-401D6BEE4321} URL =
BHO: BrowseStudio -> {1e9e0e98-4ab7-40b0-a0ce-69105c1b7c92} -> C:\Program Files\BrowseStudio\BrowseStudiobho.dll (BrowseStudio)
FF user.js: detected! => C:\Users\fabsyl\AppData\Roaming\Mozilla\Firefox\Profiles\vrr9wiqw.default\user.js
FF Extension: BrowseStudio - C:\Users\fabsyl\AppData\Roaming\Mozilla\Firefox\Profiles\vrr9wiqw.default\Extensions\{b6f164a0-5e01-4c08-b4af-72276812d17d}.xpi [2014-11-21]
CHR Extension: (BrowseStudio) - C:\Users\fabsyl\AppData\Local\Google\Chrome\User Data\Default\Extensions\gficojlapckepbplflckmpniplodckmc [2014-11-24]
R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [714208 2014-11-21] (Cherished Technololgy LIMITED)
R2 Update BrowseStudio; C:\Program Files\BrowseStudio\updateBrowseStudio.exe [423152 2014-11-25] ()
R2 Util BrowseStudio; C:\Program Files\BrowseStudio\bin\utilBrowseStudio.exe [423152 2014-11-25] ()
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [490640 2014-11-21] (Fuyu LIMITED)
R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15384 2014-01-07] ()
R2 webinstrT; C:\Windows\system32\Drivers\webinstrT.sys [56992 2014-11-15] (Corsica)
R1 {b6f164a0-5e01-4c08-b4af-72276812d17d}Gw; C:\Windows\System32\drivers\{b6f164a0-5e01-4c08-b4af-72276812d17d}Gw.sys [43152 2014-11-21] (StdLib)
R1 {fa03420d-05ef-4826-9373-bf3c8734921f}Gw; C:\Windows\System32\drivers\{fa03420d-05ef-4826-9373-bf3c8734921f}Gw.sys [43152 2014-11-24] (StdLib)
2014-11-24 18:55 - 2014-11-24 18:55 - 00000000 ____D () C:\Users\fabsyl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-11-24 18:55 - 2014-11-24 18:55 - 00000000 ____D () C:\sh4ldr
2014-11-24 18:55 - 2014-11-24 18:55 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-11-24 18:54 - 2014-11-25 18:46 - 00000000 ____D () C:\Windows\AF54923662584AC6A0435B5B89C6EB61.TMP
2014-11-24 18:54 - 2014-11-24 18:54 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2014-11-24 18:53 - 2014-11-24 18:53 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\fabsyl\Downloads\SpyHunter-installer.exe
2014-11-24 18:20 - 2014-11-24 08:30 - 00043152 _____ (StdLib) C:\Windows\system32\Drivers\{fa03420d-05ef-4826-9373-bf3c8734921f}Gw.sys
2014-11-21 20:41 - 2014-11-21 01:29 - 00043152 _____ (StdLib) C:\Windows\system32\Drivers\{b6f164a0-5e01-4c08-b4af-72276812d17d}Gw.sys
2014-11-21 20:36 - 2014-11-21 20:36 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-11-21 20:35 - 2014-11-25 20:41 - 00000000 ____D () C:\Program Files\BrowseStudio
2014-11-21 20:35 - 2014-11-21 20:35 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-11-21 20:34 - 2014-11-22 09:03 - 00000000 ____D () C:\Users\fabsyl\AppData\Roaming\{3D2B3714-F20B-486C-81A2-1949BAE31CF2}_AZ
2014-11-15 19:07 - 2014-11-15 19:07 - 00613012 _____ (CMI Limited) C:\Users\fabsyl\AppData\Local\nso665E.tmp
2014-11-15 19:06 - 2014-11-15 19:06 - 00000000 ____D () C:\Users\fabsyl\AppData\Local\Software
2014-11-15 19:06 - 2014-11-15 19:06 - 00000000 ____D () C:\Program Files\Software
2014-11-15 19:04 - 2014-11-15 19:04 - 00056992 _____ (Corsica) C:\Windows\system32\Drivers\webinstrT.sys
2014-11-15 19:04 - 2014-11-15 19:04 - 00002065 _____ () C:\Windows\patsearch.bin
C:\ProgramData\KMSAutoS
C:\Windows\AutoKMS
C:\Users\fabsyl\AppData\Local\Microsoft\WinU\~jseakvu.exe
C:\Users\fabsyl\AppData\Local\Microsoft\WinU\~xyqlqop.exe
C:\Users\fabsyl\AppData\Roaming\~bwvaglw.exe
C:\Users\fabsyl\AppData\Roaming\~opcuirp.exe
CustomCLSID: HKU\S-1-5-21-4092278269-1464089807-1071999903-1000_Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InprocServer32 -> No File Path
Task: {2E98A60E-E60A-474B-98AE-EDA1458175E7} - System32\Tasks\WIN-statsSystem => C:\Users\fabsyl\AppData\Local\Microsoft\WinU\~jseakvu.exe
Task: {30050D22-8E45-4A7D-947A-01B78763046C} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe
Task: {5BF33139-BA09-4EB7-8169-E8E513C79B8C} - System32\Tasks\WIN-statsAdmin => C:\Users\fabsyl\AppData\Local\Microsoft\WinU\~xyqlqop.exe [2014-08-06] ()
Task: {67537110-6C71-474E-8233-C986324E9A89} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe [2014-10-03] (MSfree Inc.)
Task: {8B5445D6-CEA6-4F89-A5B6-B809D405BBF2} - System32\Tasks\WIN-GGfIfEGCfEGbGffIfCfEGC => C:\Users\fabsyl\AppData\Roaming\~bwvaglw.exe
Task: {B225AEA1-4E32-45DE-A773-07691D0AB651} - System32\Tasks\WIN-fIGbfFfEGCfFGEGbfCfE => C:\Users\fabsyl\AppData\Roaming\~opcuirp.exe
Task: {C30393C0-EE6B-4623-9FE4-7243FAC34018} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2014-01-09] (Enigma Software Group USA, LLC.)
Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS\AutoKMS.exe
EmptyTemp:
end