thats the second one,
Zemana AntiMalware 2.50.2.133 (Installed)
-------------------------------------------------------
Scan Result : Completed
Scan Date : 2016/10/8
Operating System : Windows 10 64-bit
Processor : 8X Intel(R) Core(TM) i7-4700HQ CPU @ 2.40GHz
BIOS Mode : UEFI
CUID : 129AC19F677BB27145BE3C
Scan Type : Smart Scan
Duration : 3m 46s
Scanned Objects : 39773
Detected Objects : 13
Excluded Objects : 0
Read Level : Normal
Auto Upload : Enabled
Detect All Extensions : Disabled
Scan Documents : Disabled
Domain Info : WORKGROUP,0,2
Detected Objects
-------------------------------------------------------
NlaSvc Manual Proxies
Status : Scanned
Object : HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\@
MD5 : -
Publisher : -
Size : -
Version : -
Detection : Suspicious Setting
Cleaning Action : Delete
Related Objects :
Registry Entry - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\@ = 1http=127.0.0.1:8877;https=127.0.0.1:8877
Proxy Settings (Policy)
Status : Scanned
Object : HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel\Proxy
MD5 : -
Publisher : -
Size : -
Version : -
Detection : Suspicious Setting
Cleaning Action : Delete
Related Objects :
Registry Entry - HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel\Proxy = enabled
Proxy Settings (Policy)
Status : Scanned
Object : HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel\Proxy
MD5 : -
Publisher : -
Size : -
Version : -
Detection : Suspicious Setting
Cleaning Action : Delete
Related Objects :
Registry Entry - HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel\Proxy = enabled
Proxy Enabled (System)
Status : Scanned
Object : HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
MD5 : -
Publisher : -
Size : -
Version : -
Detection : Suspicious Setting
Cleaning Action : Repair
Related Objects :
Registry Entry - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable = enabled
Proxy Enabled (User)
Status : Scanned
Object : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
MD5 : -
Publisher : -
Size : -
Version : -
Detection : Suspicious Setting
Cleaning Action : Repair
Related Objects :
Registry Entry - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable = enabled
Proxy Server (System)
Status : Scanned
Object : HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
MD5 : -
Publisher : -
Size : -
Version : -
Detection : Suspicious Setting
Cleaning Action : Delete
Related Objects :
Registry Entry - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer = http=127.0.0.1:8877;https=127.0.0.1:8877
Proxy Server (User)
Status : Scanned
Object : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
MD5 : -
Publisher : -
Size : -
Version : -
Detection : Suspicious Setting
Cleaning Action : Delete
Related Objects :
Registry Entry - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer = http=127.0.0.1:8877;https=127.0.0.1:8877
kana.exe
Status : Scanned
Object : %programfiles%\darned\kana.exe
MD5 : AF2FDBB38288E12956CFE2551CDB0B7E
Publisher : -
Size : 516096
Version : 1.0.0.0
Detection : Adware:Win32/Fitzia.A!Ltal
Cleaning Action : Quarantine
Related Objects :
File - %programfiles%\darned\kana.exe
Process - 4112 - C:\Program Files (x86)\Darned\kana.exe
Scheduled Task - C:\Windows\System32\Tasks\Da3975449239754492
Scheduled Task - C:\Windows\System32\Tasks\39754492
Registry Entry - HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup = C:\Users\Laptop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Registry Entry - HKCU\Software\Microsoft\Windows\CurrentVersion\Run\overfished = "C:\Program Files (x86)\Darned\kana.exe"
pinpricks.exe
Status : Scanned
Object : %systemroot%\pinpricks.exe
MD5 : AB98F594A71E7F9EFB4DCC4B9B7B3A56
Publisher : -
Size : 7680
Version : 7.2.6.18
Detection : Adware:Win32/Tyron.A!Aaea
Cleaning Action : Quarantine
Related Objects :
File - %systemroot%\pinpricks.exe
Process - 2260 - C:\Windows\pinpricks.exe
Registry Entry - HKLM\System\CurrentControlSet\Services\indentured\ImagePath = C:\Windows\pinpricks.exe
interstatnogui.exe
Status : Scanned
Object : %appdata%\interstatnogui\interstatnogui.exe
MD5 : E2D02E48943BD9D255661BB892656CBC
Publisher : OOO "FENIKS"
Size : 3220416
Version : 3.5.7.0
Detection : Adware:Win32/BandwidthStat-DJ!Ep
Cleaning Action : Quarantine
Related Objects :
File - %appdata%\interstatnogui\interstatnogui.exe
Process - 5864 - C:\Users\Laptop\AppData\Roaming\Interstatnogui\interstatnogui.exe
Registry Entry - HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Interstatnogui = C:\Users\Laptop\AppData\Roaming\Interstatnogui\interstatnogui.exe
recalibrated.exe
Status : Scanned
Object : %systemroot%\recalibrated.exe
MD5 : 56D652CED8BF2843D66F775888940351
Publisher : -
Size : 7680
Version : 5.6.8.140
Detection : Adware:Win32/Gavin.A!Aaea
Cleaning Action : Quarantine
Related Objects :
File - %systemroot%\recalibrated.exe
Process - 2500 - C:\Windows\recalibrated.exe
Registry Entry - HKLM\System\CurrentControlSet\Services\murthy\ImagePath = C:\Windows\recalibrated.exe
sampras.exe
Status : Scanned
Object : %programfiles%\stahl\sampras.exe
MD5 : 03634CAD29542E643C38C0D7CEE0F0BA
Publisher : -
Size : 523264
Version : 7.7.5.136
Detection : Adware:Win32/Bander.A!Taec
Cleaning Action : Quarantine
Related Objects :
File - %programfiles%\stahl\sampras.exe
Scheduled Task - C:\Windows\System32\Tasks\b404112
Scheduled Task - C:\Windows\System32\Tasks\217173660
Registry Entry - HKCU\Software\Microsoft\Windows\CurrentVersion\Run\pollack = "C:\Program Files (x86)\stahl\sampras.exe"
research soft
Status : Scanned
Object : NE->c:\windows\marketing research association\research soft
MD5 : -
Publisher : -
Size : -
Version : -
Detection : PUA:Win32/Research Soft.B!Neng
Cleaning Action : Quarantine
Related Objects :
(null) - (null)
Cleaning Result
-------------------------------------------------------
Cleaned : 13
this is the first one. it said its quarantined everything.