start::
CreateRestorePoint:
CloseProcesses:
Hosts:
RemoveProxy:
HKU\S-1-5-18\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28]
BootExecute: autocheck autochk * sdnclean64.exe
Task: {2430FD2B-3425-41E4-BB02-45AEFB8A950E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: {550F3D14-2422-41F1-B6E5-1CE7BFF37EAF} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {68019A1D-C006-4679-85B0-922BAD6B4DD4} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
Task: {BA14A636-19B6-4317-AC3F-5B452FFAEDD6} - System32\Tasks\Safer-Networking\Spybot Identity Monitor\Run Identity Monitor Breach Tests => C:\Program Files (x86)\Safer-Networking Ltd\Spybot Identity Monitor\Spybot3IdentityMonitor.exe
OPR DefaultSuggestURL: Opera Stable -> hxxps://ff.search.yahoo.com/gossip?output=fxjson&command={searchTerms}
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24]
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [4088608 2016-09-21]
S3 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [235984 2016-11-24]
ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24]
ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24]
AlternateDataStreams: C:\ProgramData\TEMP:0FF263E8 [240]
HKLM\...\StartupApproved\Run32: => "CryptoTab Browser"
HKU\S-1-5-21-1375900704-2189307533-964791039-1001\...\StartupApproved\Run: => "Spybot-S&D Cleaning"
EmptyTemp:
cmd: ipconfig /flushdns
cmd: sfc /scannow
end::