Task: {A91A2E75-6234-4799-A548-03352F29AF97} - System32\Tasks\SK.Enhancer-S-161304646 => c:\programdata\quickset\sk.enhancer\SK.Enhancer.exe <==== ATTENTION
c:\programdata\quickset
Task: C:\Windows\Tasks\SK.Enhancer-S-161304646.job => c:\programdata\quickset\sk.enhancer\SK.Enhancer.exe <==== ATTENTION
AppInit_DLLs: C:\PROGRA~3\WinSpeed\WINSPE~1.DLL => C:\ProgramData\WinSpeed\WinSpeed_x64.dll [4197376 2013-12-28] ()
AppInit_DLLs: C:\PROGRA~3\WINCLE~1\WINCLE~2.DLL => C:\ProgramData\Winclean performap\Wincleanperformap_x64.dll [4391424 2013-12-29] ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
C:\PROGRA~3\WinSpeed
C:\PROGRA~3\WINCLE~1
BHO: RemoveTheAdApP - {347D16B4-5F50-4F5B-AC27-A815925BE36E} - C:\ProgramData\RemoveTheAdApP\7.x64.dll ()
BHO: UUteubeADReMeovualu - {8A62C290-A416-2675-4B1B-400AA935681F} - C:\ProgramData\UUteubeADReMeovualu\Rt0NUZfl.x64.dll ()
BHO-x32: RemoveTheAdApP - {347D16B4-5F50-4F5B-AC27-A815925BE36E} - C:\ProgramData\RemoveTheAdApP\7.dll ()
BHO-x32: UUteubeADReMeovualu - {8A62C290-A416-2675-4B1B-400AA935681F} - C:\ProgramData\UUteubeADReMeovualu\Rt0NUZfl.dll ()
C:\ProgramData\RemoveTheAdApP
C:\ProgramData\UUteubeADReMeovualu
FF DefaultSearchEngine: Wowhead
FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", "");
FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", "");
FF SelectedSearchEngine: Wowhead
FF SearchPlugin: C:\Users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\ynqg34zf.default\searchplugins\wowhead.xml
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR Extension: (RemoveTheAdApP) - C:\Users\Zach\AppData\Local\Google\Chrome\User Data\Default\Extensions\lppmokjogjfjfbhmmeehhhdcnmkpladh [2014-01-30]
CHR Extension: (BitSaver) - C:\ProgramData\mahbdlkfdnmfnndocdpbbfpkkfdodaan [2013-12-31]
R2 def8540c; C:\ProgramData\Winclean performap\WincleanperformapSvc.dll [177488 2013-12-29] ()
R2 f1f78e38; C:\ProgramData\WinSpeed\WinSpeedSvc.dll [180560 2013-12-28] ()
2014-01-30 19:52 - 2014-01-30 19:51 - 00000000 ____D () C:\ProgramData\UUteubeADReMeovualu
2014-01-30 19:52 - 2014-01-30 19:51 - 00000000 ____D () C:\ProgramData\RemoveTheAdApP
2014-01-30 19:52 - 2013-12-06 23:51 - 00000000 ____D () C:\ProgramData\965a642fcbaad410
2014-01-30 19:51 - 2014-01-30 19:51 - 00000000 ____D () C:\ProgramData\lppmokjogjfjfbhmmeehhhdcnmkpladh
2014-01-30 19:51 - 2014-01-30 19:51 - 00000000 ____D () C:\ProgramData\fnenkjcmnokljgpichcommfeghihhoae
C:\ProgramData\hash.dat
C:\Users\Zach\jagex_cl_runescape_LIVE.dat
C:\Users\Zach\jagex_runescape_preferences.dat
C:\Users\Zach\jagex_runescape_preferences2.dat
C:\Users\Zach\random.dat
C:\Users\Zach\AppData\Local\Temp\AskMrRobot-Setup-1.3.10.0.exe
C:\Users\Zach\AppData\Local\Temp\askToolbarInstaller.exe
C:\Users\Zach\AppData\Local\Temp\CmdLineExt02.dll
C:\Users\Zach\AppData\Local\Temp\devcon.exe
C:\Users\Zach\AppData\Local\Temp\drm_dyndata_7370014.dll
C:\Users\Zach\AppData\Local\Temp\drm_dyndata_7380014.dll
C:\Users\Zach\AppData\Local\Temp\dxwebsetup.exe
C:\Users\Zach\AppData\Local\Temp\GLFAC8C.tmp.ConduitEngineSetup.exe
C:\Users\Zach\AppData\Local\Temp\GomEncDnInstaller.exe
C:\Users\Zach\AppData\Local\Temp\ietA7F5.tmp.exe
C:\Users\Zach\AppData\Local\Temp\iTunesPluginWinSetup_3.0.4.0.exe
C:\Users\Zach\AppData\Local\Temp\iv_uninstall.exe
C:\Users\Zach\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe
C:\Users\Zach\AppData\Local\Temp\jre-6u33-windows-i586-iftw.exe
C:\Users\Zach\AppData\Local\Temp\mirc719.exe
C:\Users\Zach\AppData\Local\Temp\mirc722.exe
C:\Users\Zach\AppData\Local\Temp\Quarantine.exe
C:\Users\Zach\AppData\Local\Temp\SIntf16.dll
C:\Users\Zach\AppData\Local\Temp\SIntf32.dll
C:\Users\Zach\AppData\Local\Temp\SIntfNT.dll
C:\Users\Zach\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Zach\AppData\Local\Temp\tmchth.exe
C:\Users\Zach\AppData\Local\Temp\war3_Install.exe
C:\Users\Zach\AppData\Local\Temp\WmpPluginSetup_2.1.0.6.exe
cmd: ipconfig /flushdns
Folder: C:\Windows\system32\GroupPolicy
Folder: C:\Windows\SysWOW64\GroupPolicy