[removed]
Boot Mode: Normal
==============================================
fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
HKLM-x32\…\Run: [] => [X]
Winlogon\Notify\GoToAssist Express Customer: C:\Program Files (x86)\GoToAssist Remote Support Customer\1599\g2ax_winlogonx64.dll [X]
SearchScopes: HKU\S-1-5-21-3809103438-860770262-2800771106-1001 -> DefaultScope {1A95DC8F-4A6D-4938-B715-50B59B516306} URL =
SearchScopes: HKU\S-1-5-21-3809103438-860770262-2800771106-1001 -> {1A95DC8F-4A6D-4938-B715-50B59B516306} URL =
CustomCLSID: HKU\S-1-5-21-3809103438-860770262-2800771106-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-0B0B4C4A01D9}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Task: {01FF5D6C-A373-4856-B75B-878EFBFF8378} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {04253631-9F14-49F2-8692-0FA137261C3B} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
Task: {08D00E6A-F600-4ACE-8222-4FB5616B329C} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {1143399F-A52A-41E6-8B62-423DAC8C04CD} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {248C48EB-3639-4C61-89AF-0881F6CDAE89} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {67669D81-5EEE-4095-9E9D-F3290CD0B934} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {87A26711-9EBF-4F0E-9126-627F50FB0853} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {9B43ED85-0CC2-49E5-AFFB-13A10CDDE75C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {BB7F95C6-D4FF-44C4-A254-4839059B6E6F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {D4466704-0431-4CFD-B03F-12A85459F83C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {D7E8C2D7-593B-4CEA-9C7A-C6AF17031EA1} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {E248B8A5-7EE8-4E9D-8B42-721BE869C556} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {EA07EEAD-B6B5-4802-9D66-D7CE1E075C64} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: C:\WINDOWS\Tasks\AVGPCTuneUp_Task_BkGndMaintenance.job => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
ShortcutWithArgument: C:\Users\EFSS-1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Login - Paymode-X.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory=Default –app-id=edjpncpljacfnfmmpdknlpmjknpjmdgl
Emptytemp:
*****************
Processes closed successfully.
Restore point was successfully created.
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\GoToAssist Express Customer" => removed successfully
"HKU\S-1-5-21-3809103438-860770262-2800771106-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
"HKU\S-1-5-21-3809103438-860770262-2800771106-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1A95DC8F-4A6D-4938-B715-50B59B516306}" => removed successfully
HKLM\Software\Classes\CLSID\{1A95DC8F-4A6D-4938-B715-50B59B516306} => not found
"HKU\S-1-5-21-3809103438-860770262-2800771106-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-0B0B4C4A01D9}" => removed successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avg" => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
"HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui" => removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{01FF5D6C-A373-4856-B75B-878EFBFF8378}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{01FF5D6C-A373-4856-B75B-878EFBFF8378}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{04253631-9F14-49F2-8692-0FA137261C3B}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{04253631-9F14-49F2-8692-0FA137261C3B}" => removed successfully
C:\WINDOWS\System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVGPCTuneUp_Task_BkGndMaintenance" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{08D00E6A-F600-4ACE-8222-4FB5616B329C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{08D00E6A-F600-4ACE-8222-4FB5616B329C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1143399F-A52A-41E6-8B62-423DAC8C04CD}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1143399F-A52A-41E6-8B62-423DAC8C04CD}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{248C48EB-3639-4C61-89AF-0881F6CDAE89}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{248C48EB-3639-4C61-89AF-0881F6CDAE89}" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{67669D81-5EEE-4095-9E9D-F3290CD0B934}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{67669D81-5EEE-4095-9E9D-F3290CD0B934}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{87A26711-9EBF-4F0E-9126-627F50FB0853}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87A26711-9EBF-4F0E-9126-627F50FB0853}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9B43ED85-0CC2-49E5-AFFB-13A10CDDE75C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9B43ED85-0CC2-49E5-AFFB-13A10CDDE75C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BB7F95C6-D4FF-44C4-A254-4839059B6E6F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BB7F95C6-D4FF-44C4-A254-4839059B6E6F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D4466704-0431-4CFD-B03F-12A85459F83C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D4466704-0431-4CFD-B03F-12A85459F83C}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D7E8C2D7-593B-4CEA-9C7A-C6AF17031EA1}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D7E8C2D7-593B-4CEA-9C7A-C6AF17031EA1}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E248B8A5-7EE8-4E9D-8B42-721BE869C556}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E248B8A5-7EE8-4E9D-8B42-721BE869C556}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EA07EEAD-B6B5-4802-9D66-D7CE1E075C64}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA07EEAD-B6B5-4802-9D66-D7CE1E075C64}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => removed successfully
C:\WINDOWS\Tasks\AVGPCTuneUp_Task_BkGndMaintenance.job => moved successfully
C:\Users\EFSS-1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Login - Paymode-X.lnk => Shortcut argument removed successfully
=========== EmptyTemp: ==========
BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 145631301 B
Java, Flash, Steam htmlcache => 1133 B
Windows/system/drivers => 126179724 B
# ——————————-
# Malwarebytes AdwCleaner 7.2.2.0
# ——————————-
# Build: 07-17-2018
# Database: 2018-07-25.1
# Support: https://www.malwarebytes.com/support
#
# ——————————-
# Mode: Clean
# ——————————-
# Start: 08-06-2018
# Duration: 00:00:01
# OS: Windows 10 Home
# Cleaned: 5
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\Users\EFSS-1\AppData\Roaming\download Manager
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKLM\Software\Wow6432Node\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{B9D64D3B-BE75-4FA2-B94A-C4AE772A0146}
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
Deleted Ask
Deleted AOL
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [1524 octets] - [06/08/2018 08:41:58]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
RogueKiller V12.12.30.0 (x64) [Aug 6 2018] (Free) by Adlice Software
Operating System : Windows 10 (10.0.17134) 64 bits version
Started in : Normal mode
User : EFSS-1 [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Delete – Date : 08/06/2018 08:53:54 (Duration : 01:43:52)
¤¤¤ Processes : 2 ¤¤¤
[Proc.RunPE] RuntimeBroker.exe(13192) – C:\Windows\System32\RuntimeBroker.exe[7] -> Killed [TermThr]
[Proc.RunPE] RuntimeBroker.exe(12548) – C:\Windows\System32\RuntimeBroker.exe[7] -> Killed [TermProc]
¤¤¤ Registry : 4 ¤¤¤
[VT.Unknown] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | FUFAXRCV : "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe" [7] -> Deleted
[VT.Unknown] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | FUFAXSTM : "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe" [7] -> Deleted
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ WMI : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤