Start
CloseProcesses:
C:\Users\store0355\AppData\LocalLow\EmieSiteList\wrndvuqxqyzo
HKLM\...\Run: [] => [X]
HKU\S-1-5-21-598306107-975790763-3788616320-1000\...\Run: [Google Update**.d<*>] => "C:\Users\store0355\AppData\Local\Google\Desktop\Install\{fe701b6b-144c-d079-585b-9e196f361888}\d'x"Ù"\", &h#\. ùû[\{fe701b6b-144c-d079-585b-9e196f361888}\GoogleUpdate.exe" > <===== ATTENTION (Value Name with invalid
C:\Users\store0355\AppData\Local\Google\Desktop\Install\{fe701b6b-144c-d079-585b-9e196f361888}
HKU\S-1-5-21-598306107-975790763-3788616320-1000\...\Run: [hqzbnzmtmhfm] => regsvr32.exe /s "C:\Users\store0355\AppData\Local\NETGEARGenie\hqzbnzmtmhfm.dll" <===== ATTENTION
C:\Users\store0355\AppData\Local\NETGEARGenie
HKU\S-1-5-21-598306107-975790763-3788616320-1000\...\Policies\system: [DisableRegistryTools] 1
HKU\S-1-5-21-598306107-975790763-3788616320-1000\...\Policies\system: [1] lsnibwfea.exe
HKU\S-1-5-21-598306107-975790763-3788616320-1000\...\MountPoints2: E - E:\LaunchU3.exe -a
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
C:\windows\SysWOW64\u
C:\windows\System32\Tasks\{C96D72BC-6CAE-668B-5BB4-8BEAD1C6B529}
C:\windows\system32\ylcmtic.dll
C:\Users\store0355\AppData\Local\Google\Desktop\Install
C:\$Recycle.Bin\S-1-5-21-598306107-975790763-3788616320-1000\$fe701b6b144cd079585b9e196f361888
C:\ProgramData\ftoupowoxifvdjsmrbp.reg
EmptyTemp:
End