R1 scjrtf; C:\WINDOWS\system32\Drivers\scjrtf.sys [35744 2015-04-01] () [File not signed]
R1 scjrtr; C:\WINDOWS\system32\Drivers\scjrtr.sys [46496 2015-04-01] () [File not signed]
R2 scxy; C:\Program Files (x86)\System-Checker\Files\scxy.exe [1936280 2015-04-01] (scsp)
R2 syschkrm; C:\Program Files (x86)\System-Checker\syschkrm.exe [110080 2015-04-01] () [File not signed]
R2 syschkrs; C:\Program Files (x86)\System-Checker\syschkrs.exe [186880 2015-04-01] () [File not signed]
Task: {9E4D1FF7-BA79-4519-920D-BE4EB67A9249} - System32\Tasks\{4B16EC08-DBEE-4F0A-9F7F-7CAB87D80D7B} => pcalua.exe -a "C:\Program Files (x86)\Pricora 1.1\Uninstall.exe" -c /fcp=1
Task: {F5E316A8-53F1-427F-B38C-6E5D77B6A7B0} - System32\Tasks\{EF074DE4-AAFD-4278-83B4-66E4EB213DEC} => pcalua.exe -a "C:\Program Files (x86)\System-Checker\uninst.exe"
Task: {F6ACC430-78F7-48AA-822B-AFEAAB8EE20A} - System32\Tasks\Opera scheduled Autoupdate 1414347441 => C:\Program Files (x86)\Opera\launcher.exe [2015-03-16] (Opera Software)
Task: C:\WINDOWS\Tasks\23b8b003-2eb4-4efb-aa68-876b43abdaa9.job => C:\Program Files (x86)\Browsers Apps-\9a36731b-3c1d-478b-9966-5d844274f27c-4.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\82147e14-d145-4af5-97c6-86fe630c5d23-1.job => C:\Program Files (x86)\Pricora 1.1\Pricora 1.1-codedownloader.exeU/UhDrlG /gjWvTITqL=task /tmYzF='Pricora 1.1' /VcaOinD=35497 /iZKtjcC='000155' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=0D756398D797422782DACC2F66E0FE7EIE /jANlEtyt=bd708be9e517e65a903a0220056141f5 /jDoiK=1_34_06_10 /qCHxovSgb=1.34.6.10 /AZMKfmxC=1404233927 /bTnDNCp=http:/stats.democlientnet.com /maTWCr=http:/errors.democlientnet.com /wvFkWe=http:/js.democlientnet.com /CjQVh=ie /kftdvfCHI='Pricora 1.1' /jZIHa=http:/js.clientdemocloud.com /AZptvQBh /tjDinAv='{asw:[0, 5, 512]}' /bbHKcWc='http:/update.democlientnet.com/ie_code_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION
Task: C:\WINDOWS\Tasks\82147e14-d145-4af5-97c6-86fe630c5d23-11.job => C:\Program Files (x86)\Pricora 1.1\82147e14-d145-4af5-97c6-86fe630c5d23-11.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\82147e14-d145-4af5-97c6-86fe630c5d23-2.job => C:\Program Files (x86)\Pricora 1.1\82147e14-d145-4af5-97c6-86fe630c5d23-2.exeã/CqKHedRW /tmYzF='Pricora 1.1' /VcaOinD=35497 /iZKtjcC='000155' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=0D756398D797422782DACC2F66E0FE7EIE /jANlEtyt=bd708be9e517e65a903a0220056141f5 /jDoiK=1_34_06_10 /AZMKfmxC=1404233927 /bTnDNCp=http:/stats.democlientnet.com /maTWCr=http:/errors.democlientnet.com /BYdOfmzOk=11111111-1111-1111-1111-110311541197 /CjQVh=ie /AZptvQBh /bbHKcWc='http:/update.democlientnet.com/ie_enable_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION
Task: C:\WINDOWS\Tasks\82147e14-d145-4af5-97c6-86fe630c5d23-3.job => C:\Program Files (x86)\Pricora 1.1\82147e14-d145-4af5-97c6-86fe630c5d23-3.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\82147e14-d145-4af5-97c6-86fe630c5d23-4.job => C:\Program Files (x86)\Pricora 1.1\82147e14-d145-4af5-97c6-86fe630c5d23-4.exe{/afqlWsxT /tmYzF='Pricora 1.1' /bNoksL C:\Program Files (x86)\Pricora 1.1\35497.xpi' /VcaOinD=35497 /iZKtjcC='000155' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=0D756398D797422782DACC2F66E0FE7EIE /jANlEtyt=bd708be9e517e65a903a0220056141f5 /jDoiK=1_34_06_10 /qCHxovSgb=1.34.6.10 /AZMKfmxC=1404233927 /bTnDNCp=http:/stats.democlientnet.com /maTWCr=http:/errors.democlientnet.com /JcyMnkJE=300 /bedFK=
[email protected]d06855fa6.com /JqUZR=0.94 /mozpiHe=ab06fdef7671b4f24babf0377d4c408323dc509f25b3a49d68b546cad06855fa6com35497 /xKbJX=https:/w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/35497.rdf /dsHOwFaOL='Pricora 1.1' /bLKeQD='Services extension' /vXZtTvB='Corporate Inc' /CjQVh=ie /tjDinAv='{asw:[0, 5, 512]}' /AZptvQBh /PSuzmpV /kXxfiNB /bbHKcWc='http:/update.democlientnet.com/ff_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION
Task: C:\WINDOWS\Tasks\82147e14-d145-4af5-97c6-86fe630c5d23-5.job => C:\Program Files (x86)\Pricora 1.1\82147e14-d145-4af5-97c6-86fe630c5d23-5.exe/ARaItDTUx /tmYzF='Pricora 1.1' /VcaOinD=35497 /iZKtjcC='000155' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=0D756398D797422782DACC2F66E0FE7EIE /jANlEtyt=bd708be9e517e65a903a0220056141f5 /jDoiK=1_34_06_10 /AZMKfmxC=1404233927 /bTnDNCp=http:/stats.democlientnet.com /maTWCr=http:/errors.democlientnet.com /XxMXNLpLI=http:/ipgeoapi.com/ /fuwhFY=http:/update.democlientnet.com /VOaTqVU=2 /VFGQskT=http:/logs.democlientnet.com /bbHKcWc='http:/update.democlientnet.com/updater_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION
Task: C:\WINDOWS\Tasks\82147e14-d145-4af5-97c6-86fe630c5d23-6.job => C:\Program Files (x86)\Pricora 1.1\Pricora 1.1-novainstaller.exeY/yUfafiBNd /tmYzF='Pricora 1.1' /VcaOinD=35497 /iZKtjcC='000155' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=0D756398D797422782DACC2F66E0FE7EIE /jANlEtyt=bd708be9e517e65a903a0220056141f5 /jDoiK=1_34_06_10 /qCHxovSgb=1.34.6.10 /AZMKfmxC=1404233927 /bTnDNCp=http:/stats.democlientnet.com /maTWCr=http:/errors.democlientnet.com /wvFkWe=http:/js.democlientnet.com /CjQVh=ie /JKTpqGJSV /kftdvfCHI=Pricora 1.1 /hwvSBu='nova' /jZIHa=http:/js.clientdemocloud.com /tjDinAv='{asw:[0, 5, 512]}' /gjWvTITqL=task /bbHKcWc='http:/update.democlientnet.com/novacode/{CAMP_ID}/update.jso <==== ATTENTION
Task: C:\WINDOWS\Tasks\82147e14-d145-4af5-97c6-86fe630c5d23-7.job => C:\Program Files (x86)\Pricora 1.1\Pricora 1.1-nova.exe=/tmYzF='Pricora 1.1' /VcaOinD=35497 /iZKtjcC='000155' /DweBrm='0' /vZlOEbtTG='0' /uagnTWhw=0D756398D797422782DACC2F66E0FE7EIE /jANlEtyt=bd708be9e517e65a903a0220056141f5 /jDoiK=1_34_06_10 /qCHxovSgb=1.34.6.10 /AZMKfmxC=1404233927 /bTnDNCp=http:/stats.democlientnet.com /maTWCr=http:/errors.democlientnet.com /wvFkWe=http:/js.democlientnet.com /CjQVh=ie /JKTpqGJSV /kftdvfCHI=Pricora 1.1 /hwvSBu='nova' /jZIHa=http:/js.clientdemocloud.com /tjDinAv='{asw:[0, 5, 512]}' /bbHKcWc='http:/update.democlientnet.com/novarun/{CAMP_ID}/update.jso <==== ATTENTION
Task: C:\WINDOWS\Tasks\9a36731b-3c1d-478b-9966-5d844274f27c-4.job => C:\Program Files (x86)\Browsers Apps-\9a36731b-3c1d-478b-9966-5d844274f27c-4.exe4/installxpi /agentregpath='Browsers Apps-' /extensionfilepath C:\Program Files (x86)\Browsers Apps-\9a36731b-3c1d-478b-9966-5d844274f27c.xpi' /appid=61787 /srcid='001739' /subid='verticals-' /zdata='0' /bic=0D756398D797422782DACC2F66E0FE7EIE /verifier=bd708be9e517e65a903a0220056141f5 /installerversion=1_34_08_12 /installerfullversion=1.34.8.12 /installationtime=1409384286 /statsdomain=http:/stats.loadclientinputsrv.com /errorsdomain=http:/errors.loadclientinputsrv.com /waitforbrowser=300 /extensionid=
[email protected] /extensionversion=0.95 /prefsbranch=ahermanthorne45outlookcom61787 /updateurl=https:/w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/61787.rdf /extensionname='Browsers Apps-' /extensiondesc='Enhancing browsing experience' /publishername='app' /defbro=ie /sid=S-1-5-21-2669165515-361187302-876288576-1001 /addinfojson='{asw:[0, 8388613, 536872960],browser_name:__BROWSER_NAME__}' /allusers /allprofiles /checkfflist /autoupdateulr='http:/update.loadclientinputsrv.com/ff_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION
Task: C:\WINDOWS\Tasks\Er0Gve4Mv4qvSwk3sB.job => C:\Users\Sýÿb\AppData\Roaming\Er0Gve4Mv4qvSwk3sB.exe
C:\Users\Sýÿb\AppData\Roaming\Er0Gve4Mv4qvSwk3sB.exe
Task: C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
2015-04-01 13:27 - 2015-04-01 13:27 - 00110080 _____ () C:\Program Files (x86)\System-Checker\syschkrm.exe
2015-04-01 13:27 - 2015-04-01 13:27 - 00186880 _____ () C:\Program Files (x86)\System-Checker\syschkrs.exe
HKLM-x32\...\Run: [fst_fr_369] => [X]
HKU\S-1-5-21-2669165515-361187302-876288576-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.sweet-page.com/web/?type=ds& ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
http://www.sweet-page.com/web/?type=ds& ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.sweet-page.com/web/?type=ds& ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.sweet-page.com/web/?type=ds& ... earchTerms}
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\scjrtf.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\scjrtr.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\scjrtf.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\scjrtr.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\scxy => ""="service"
Winsock: Catalog9 01 C:\WINDOWS\SysWOW64\scxy.dll [349872] (scsp)
Winsock: Catalog9 02 C:\WINDOWS\SysWOW64\scxy.dll [349872] (scsp)
Winsock: Catalog9 03 C:\WINDOWS\SysWOW64\scxy.dll [349872] (scsp)
Winsock: Catalog9 04 C:\WINDOWS\SysWOW64\scxy.dll [349872] (scsp)
Winsock: Catalog9 16 C:\WINDOWS\SysWOW64\scxy.dll [349872] (scsp)
Winsock: Catalog9-x64 01 C:\WINDOWS\system32\scxy64.dll [416552] (scsp)
Winsock: Catalog9-x64 02 C:\WINDOWS\system32\scxy64.dll [416552] (scsp)
Winsock: Catalog9-x64 03 C:\WINDOWS\system32\scxy64.dll [416552] (scsp)
Winsock: Catalog9-x64 04 C:\WINDOWS\system32\scxy64.dll [416552] (scsp)
Winsock: Catalog9-x64 16 C:\WINDOWS\system32\scxy64.dll [416552] (scsp)
CHR Extension: (goicaghfpnaogbpejmaodednkiilckfo) - C:\Users\Séb\AppData\Local\Google\Chrome\User Data\Default\Extensions\goicaghfpnaogbpejmaodednkiilckfo [2015-04-01]
CHR StartupUrls: Default -> "hxxp://
www.sweet-page.com/?type=hp&ts=14042348 ... 2BKG7U2BKX"
CHR DefaultSearchKeyword: Default -> FE43C2DD8361C6C4C8F77899AEB52D4076D405DB7BB780C4BE73BF40BA6ED097
CHR DefaultSearchURL: Default -> 8AC316AABD95EDC0706CCD0C8F26C7B72C21E6B37A51D403C1772F504E492A56
C:\Program Files (x86)\System-Checker
EmptyTemp: