Task: {C786F912-7A7D-4159-AFC2-E3D5AF7A45C1} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2015-05-10] (Enigma Software Group USA, LLC.)
HKLM-x32\...\Run: [mbot_pl_87] => [X]
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
ShellIconOverlayIdentifiers: [00avast]
{472083B0-C522-11CF-8763-00608CC02F24} => No File
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1415004025&from=cor&uid=ST9320423AS_5VH0X775&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1415004025&from=cor&uid=ST9320423AS_5VH0X775&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1415004025&from=cor&uid=ST9320423AS_5VH0X775&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1415004025&from=cor&uid=ST9320423AS_5VH0X775&q={searchTerms}
HKU\S-1-5-21-2661704577-2204847276-1519159744-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.yahoo.com/?fr=hp-ddc-bd&type=pr__alt__ddc_dsssyc_bd_com
SearchScopes: HKU\S-1-5-21-2661704577-2204847276-1519159744-1000
DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=pr_f7f8f299-3100-43c9-842b-9def180c5e5d&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2661704577-2204847276-1519159744-1000
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://q.search-simple.com/?affID=pr_f7f8f299-3100-43c9-842b-9def180c5e5d&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2661704577-2204847276-1519159744-1000
{C459DAB0-BCE3-4A77-936C-9B93B85D5717} URL = http://rts.dsrlte.com/?affID=na&q={searchTerms}&r=750
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1415004025&from=cor&uid=ST9320423AS_5VH0X775
FF Homepage: hxxp://rts.dsrlte.com?affID=na
FF SelectedSearchEngine: Yahoo! Search
FF DefaultSearchEngine: Yahoo! Search
FF SearchPlugin: C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\xtiwkl9n.default\searchplugins\dsrlte.xml [2015-01-18]
FF Extension: No Name - C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\xtiwkl9n.default\extensions\
[email protected] [not found]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [not found]
FF Extension: GoHD - C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\xtiwkl9n.default\Extensions\
[email protected] [2014-11-03]
\fcfenmboojpjinhpgggodefccipikbpd [2014-12-27]
CHR Extension: (SunriseBrowse) - C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcmihjjhagjnbphnmihchianoncccnmj [2015-04-01]
S3 massfilter; system32\drivers\massfilter.sys [X]
S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X]
S3 ZTEusbnet; system32\DRIVERS\ZTEusbnet.sys [X]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X]
S1 {3f7fa6e7-633b-4753-a8aa-90403860bfc7}Gw64; system32\drivers\{3f7fa6e7-633b-4753-a8aa-90403860bfc7}Gw64.sys [X]
S1 {8431bbbd-4243-4758-beab-348411cd1e12}Gw64; system32\drivers\{8431bbbd-4243-4758-beab-348411cd1e12}Gw64.sys [X]
S1 {8ec359df-296d-4b42-a63e-bf65b4956546}Gw64; system32\drivers\{8ec359df-296d-4b42-a63e-bf65b4956546}Gw64.sys [X]
S1 {ac2b164b-7189-4743-b803-06981a00f9d8}Gw64; system32\drivers\{ac2b164b-7189-4743-b803-06981a00f9d8}Gw64.sys [X]
S1 {ce82773f-55f0-485d-83dd-5b67bdaf13ea}Gw64; system32\drivers\{ce82773f-55f0-485d-83dd-5b67bdaf13ea}Gw64.sys [X]
S1 {e9ab7dfa-9d2f-4c48-8fd4-5314a020a2b5}Gw64; system32\drivers\{e9ab7dfa-9d2f-4c48-8fd4-5314a020a2b5}Gw64.sys [X]
S1 {f65802d2-0721-4106-8bec-2e7deda41572}Gw64; system32\drivers\{f65802d2-0721-4106-8bec-2e7deda41572}Gw64.sys [X]
2015-05-10 12:59 - 2014-11-03 15:07 - 00000000 ____D C:\Program Files (x86)\SunriseBrowse
2015-05-10 12:59 - 2014-11-03 10:41 - 00000000 ____D C:\ProgramData\IePluginServices
EmptyTemp: