Hi,
please find the logs below as requested.
I have also removed all the programs as requested, without problems.
Fix result of Farbar Recovery Scan Tool (x86) Version:30-08-2015
Ran by Riaan Nel (2015-08-31 16:40:22) Run:1
Running from C:\Users\Riaan Nel\Desktop
Loaded Profiles: Riaan Nel (Available Profiles: Riaan Nel)
Boot Mode: Normal
==============================================
fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
Task: {68166B4E-9B27-4599-8A18-9EF5FD53C52D} - System32\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-5 => C:\Program Files\SavePass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-5.exe [2015-08-28] (OB) <==== ATTENTION
Task: {5E9D0A76-8D7D-4C31-A17E-77829F21F33E} - System32\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-5_user => C:\Program Files\SavePass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-5.exe [2015-08-28] (OB) <==== ATTENTION
C:\Program Files\SFK\SSFK.exe
C:\Program Files\SFK\SFKEX.exe
C:\Program Files\SFK
C:\Program Files\NixSrv\packages\c3cd72eb-e609-45a2-97c2-d2479f8fa73d\NixHost.exe
C:\ProgramData\ExtTag\Zaamstock.exe
HKU\S-1-5-21-444297693-2264169564-2716400923-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B1C30ZKEa5UhX2PRCO-5Poa2pHn7-A--VWt7oSCt15QDP0ZhwKBihrFsvTseo-t9xuG9XogegjVFqnVsZNZtlgs-elcBjZsc_0Pby_8fl5Y4Jpp7M3rXctaOAzDWttjKRU59bM_1EwPGB45WgRtZSs-DtH1Kv&q={searchTerms}
HKU\S-1-5-21-444297693-2264169564-2716400923-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B1C30ZKEa5UhX2PRCO-5Poa2pHn7-A--VWt7oSCt15QDP0ZhwKBihrFsvTseo-t9xuG9XogegjVFqnVc10LodNmSHz1i0FugpAW8314UUtUUEKG8yhwFXiWN5wJYIj83EPv_dkI8HuZie3LzPna7ty6lh1tD0
HKU\S-1-5-21-444297693-2264169564-2716400923-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B1C30ZKEa5UhX2PRCO-5Poa2pHn7-A--VWt7oSCt15QDP0ZhwKBihrFsvTseo-t9xuG9XogegjVFqnVsZNZtlgs-elcBjZsc_0Pby_8fl5Y4Jpp7M3rXctaOAzDWttjKRU59bM_1EwPGB45WgRtZSs-DtH1Kv&q={searchTerms}
HKU\S-1-5-21-444297693-2264169564-2716400923-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B1C30ZKEa5UhX2PRCO-5Poa2pHn7-A--VWt7oSCt15QDP0ZhwKBihrFsvTseo-t9xuG9XogegjVFqnVsZNZtlgs-elcBjZsc_0Pby_8fl5Y4Jpp7M3rXctaOAzDWttjKRU59bM_1EwPGB45WgRtZSs-DtH1Kv&q={searchTerms}
SearchScopes: HKLM -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B1C30ZKEa5UhX2PRCO-5Poa2pHn7-A--VWt7oSCt15QDP0ZhwKBihrFsvTseo-t9xuG9XogegjVFqnVsZNZtlgs-elcBjZsc_0Pby_8fl5Y4Jpp7M3rXctaOAzDWttjKRU59bM_1EwPGB45WgRtZSs-DtH1Kv&q={searchTerms}
SearchScopes: HKU\S-1-5-21-444297693-2264169564-2716400923-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B1C30ZKEa5UhX2PRCO-5Poa2pHn7-A--VWt7oSCt15QDP0ZhwKBihrFsvTseo-t9xuG9XogegjVFqnVsZNZtlgs-elcBjZsc_0Pby_8fl5Y4Jpp7M3rXctaOAzDWttjKRU59bM_1EwPGB45WgRtZSs-DtH1Kv&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1440760054&z=54f83e43e617994f95f37d7g3zaz0e9meqaefgecee&from=obw&uid=ST3250823AS_5ND3BHZBXXXX5ND3BHZB
FF Homepage: hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B1C30ZKEa5UhX2PRCO-5Poa2pHn7-A--VWt7oSCt15QDP0ZhwKBihrFsvTseo-t9xuG9XogegjVFqnVc10LodNmSHz1i0FugpAW8314UUtUUEKG8yhwFXiWN5wJYIj83EPv_dkI8HuZie3LzPna7ty6lh1tD0
FF NewTab: hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B1C30ZKEa5UhX2PRCO-5Poa2pHn7-A--VWt7oSCt15QDP0ZhwKBihrFsvTseo-t9xuG9XogegjVFqnVc10LodNmSHz1i0FugpAW8314UUtUUEKG8yhwFXiWN5wJYIj83EPv_dkI8HuZie3LzPna7ty6lh1tD0
R2 ExtTag; C:\ProgramData\ExtTag\ExtTag.exe [33792 2015-08-27] () [File not signed]
C:\ProgramData\ExtTag\ExtTag.exe
R2 NixSrv; C:\Program Files\NixSrv\NixSrv.exe [379904 2015-08-27] () [File not signed] <==== ATTENTION
R2 SSFK; C:\Program Files\SFK\SSFK.exe [448000 2015-08-28]
S2 updvte; C:\Users\Riaan Nel\AppData\Local\Lot-media.exe [52736 2015-08-28] () [File not signed]
2015-08-28 13:12 - 2015-08-28 13:13 - 00000000 ____D C:\Users\Riaan Nel\AppData\Roaming\istartsurf
2015-08-28 13:07 - 2015-08-28 14:07 - 00000000 ____D C:\Program Files\NixSrv
C:\Users\Riaan Nel\AppData\Local\Temp\ose00000.exe
Task: {965AF130-2446-4959-9471-25DD739B5415} - System32\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-1-6 => C:\Program Files\SavePass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-1-6.exe [2015-08-28] (OB) <==== ATTENTION
Task: {A7A7F30F-C622-4D72-8F2F-CBCABBE1FB69} - \ProgramRefresh-ATFST -> No File <==== ATTENTION
Task: {A9269E43-DBB5-41B2-ABC1-81059AE9E90B} - System32\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-7 => C:\Program Files\SavePass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-7.exe <==== ATTENTION
Task: {C129B3D8-8A12-45CB-8A78-484EBAE55753} - System32\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-6 => C:\Program Files\SavePass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-6.exe [2015-08-28] (OB) <==== ATTENTION
Task: {D2220DE8-2932-46CF-A071-15E2C77BB12F} - System32\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-1-7 => C:\Program Files\SavePass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-1-7.exe [2015-08-28] (OB) <==== ATTENTION
Task: {FDDFBAD9-E558-45FF-87F0-5F2E3E1DE836} - \ProgramUpdateCheck -> No File <==== ATTENTION
Task: {FF3C717F-E3D9-4903-ABB6-E944098C0BD0} - System32\Tasks\atSFQS1rBZ3lbTAqGUWmZlNN => C:\Users\Riaan Nel\AppData\Roaming\atSFQS1rBZ3lbTAqGUWmZlNN.exe [2015-04-20] () <==== ATTENTION
Task: C:\Windows\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-1-6.job => C:\Program Files\SavePass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-1-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-1-7.job => C:\Program Files\SavePass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-1-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-5.job => C:\Program Files\SavePass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-5_user.job => C:\Program Files\SavePass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-6.job => C:\Program Files\SavePass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-7.job => C:\Program Files\SavePass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\atSFQS1rBZ3lbTAqGUWmZlNN.job => C:\Users\Riaan Nel\AppData\Roaming\atSFQS1rBZ3lbTAqGUWmZlNN.exe <==== ATTENTION
EmptyTemp:
Hosts:
End
*****************
Restore point was successfully created.
Processes closed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{68166B4E-9B27-4599-8A18-9EF5FD53C52D} => key not found.
C:\Windows\System32\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-5 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\aab96cd1-6eaa-4846-92fd-660511195439-5 => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5E9D0A76-8D7D-4C31-A17E-77829F21F33E} => key not found.
C:\Windows\System32\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-5_user => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\aab96cd1-6eaa-4846-92fd-660511195439-5_user => key not found.
"C:\Program Files\SFK\SSFK.exe" => File/Folder not found.
"C:\Program Files\SFK\SFKEX.exe" => File/Folder not found.
"C:\Program Files\SFK" => File/Folder not found.
"C:\Program Files\NixSrv\packages\c3cd72eb-e609-45a2-97c2-d2479f8fa73d\NixHost.exe" => File/Folder not found.
C:\ProgramData\ExtTag\Zaamstock.exe => moved successfully
HKU\S-1-5-21-444297693-2264169564-2716400923-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKU\S-1-5-21-444297693-2264169564-2716400923-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-444297693-2264169564-2716400923-1000\Software\Microsoft\Internet Explorer\Main\\Search Bar => value removed successfully.
HKU\S-1-5-21-444297693-2264169564-2716400923-1000\Software\Microsoft\Internet Explorer\Main\\SearchAssistant => value removed successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\ielnksrch" => key removed successfully.
HKCR\CLSID\ielnksrch => key not found.
"HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}" => key removed successfully.
HKCR\CLSID\{ielnksrch} => key not found.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => value restored successfully
Firefox "homepage" removed successfully.
Firefox "newtab" removed successfully.
ExtTag => service not found.
"C:\ProgramData\ExtTag\ExtTag.exe" => File/Folder not found.
NixSrv => service removed successfully.
SSFK => service removed successfully.
updvte => service removed successfully.
C:\Users\Riaan Nel\AppData\Roaming\istartsurf => moved successfully
"C:\Program Files\NixSrv" => File/Folder not found.
C:\Users\Riaan Nel\AppData\Local\Temp\ose00000.exe => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{965AF130-2446-4959-9471-25DD739B5415} => key not found.
C:\Windows\System32\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-1-6 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\aab96cd1-6eaa-4846-92fd-660511195439-1-6 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A7A7F30F-C622-4D72-8F2F-CBCABBE1FB69}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A7A7F30F-C622-4D72-8F2F-CBCABBE1FB69}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProgramRefresh-ATFST" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A9269E43-DBB5-41B2-ABC1-81059AE9E90B}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9269E43-DBB5-41B2-ABC1-81059AE9E90B}" => key removed successfully.
C:\Windows\System32\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-7 => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\aab96cd1-6eaa-4846-92fd-660511195439-7" => key removed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C129B3D8-8A12-45CB-8A78-484EBAE55753} => key not found.
C:\Windows\System32\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-6 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\aab96cd1-6eaa-4846-92fd-660511195439-6 => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D2220DE8-2932-46CF-A071-15E2C77BB12F} => key not found.
C:\Windows\System32\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-1-7 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\aab96cd1-6eaa-4846-92fd-660511195439-1-7 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FDDFBAD9-E558-45FF-87F0-5F2E3E1DE836}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FDDFBAD9-E558-45FF-87F0-5F2E3E1DE836}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProgramUpdateCheck" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FF3C717F-E3D9-4903-ABB6-E944098C0BD0}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FF3C717F-E3D9-4903-ABB6-E944098C0BD0}" => key removed successfully.
C:\Windows\System32\Tasks\atSFQS1rBZ3lbTAqGUWmZlNN => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\atSFQS1rBZ3lbTAqGUWmZlNN" => key removed successfully.
C:\Windows\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-1-6.job => not found.
C:\Windows\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-1-7.job => not found.
C:\Windows\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-5.job => not found.
C:\Windows\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-5_user.job => not found.
C:\Windows\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-6.job => not found.
C:\Windows\Tasks\aab96cd1-6eaa-4846-92fd-660511195439-7.job => moved successfully
C:\Windows\Tasks\atSFQS1rBZ3lbTAqGUWmZlNN.job => moved successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
EmptyTemp: => 686.7 MB temporary data Removed.
The system needed a reboot.
==== End of Fixlog 16:44:23 ====
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 2015/08/31
Scan Time: 05:03 PM
Logfile: MalwareLog.txt
Administrator: Yes
Version: 2.1.8.1057
Malware Database: v2015.08.31.02
Rootkit Database: v2015.08.16.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Riaan Nel
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 472647
Time Elapsed: 39 min, 13 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 24
PUP.Optional.HighDefAction, HKLM\SOFTWARE\HighDefAction, Quarantined, [055936d998f37fb702cce4afe32137c9],
PUP.Optional.IStartSurf.ShrtCln, HKLM\SOFTWARE\istartsurfSoftware, Quarantined, [bf9f25ea7417aa8ccc8ca28d1ee58f71],
PUP.Optional.SavePass, HKLM\SOFTWARE\SavePass 1.1, Quarantined, [cf8fed223556092de9799a111ce845bb],
PUP.Optional.SavePass, HKLM\SOFTWARE\SavePass 1.1-nv, Quarantined, [6bf3ac630d7e71c597cbd2d957ad8d73],
PUP.Optional.SavePass, HKLM\SOFTWARE\SavePass 1.1-nv-ie, Quarantined, [afaff916ec9ff640144e931819eb2ed2],
PUP.Optional.YorkNewCin, HKLM\SOFTWARE\YorkNewCin, Quarantined, [06582ce3a0ebff37d805605db15320e0],
PUP.Optional.CrossRider, HKLM\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [243a070874171620eea7becacd37ea16],
PUP.Optional.CinemaPlus, HKLM\SOFTWARE\ARENAHD, Quarantined, [a7b7c24d0b809c9acff4394884800df3],
PUP.Optional.CrossRider, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\29777, Quarantined, [b8a66ea1dab14cea86180c7c64a0e61a],
PUP.Optional.SavePass, HKU\S-1-5-18\SOFTWARE\SavePass 1.1-nv-ie, Quarantined, [7ce24cc38efd2016a1bd74376f954eb2],
PUP.Optional.CrossRider, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\_CrossriderRegNamePlaceHolder_, Quarantined, [81dddd32543790a6133deb9c46bea55b],
PUP.Optional.CrossRider, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\Cinem Plus 2.4cV28.08-nv-ie, Quarantined, [a6b88689216ab581c0793a4d39cb619f],
PUP.Optional.HighDefAction, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\HighDefAction, Quarantined, [0d5112fde0ab171fe6e7dfb4df25827e],
PUP.Optional.SavePass, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\SavePass 1.1-nv-ie, Quarantined, [70eede31f992fc3afc62fbb037cd926e],
PUP.Optional.YorkNewCin, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\YorkNewCin, Quarantined, [9dc1ad62d9b2b4823ca04a73c53fc838],
PUP.Optional.Conduit, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\APPDATALOW\SOFTWARE\ConduitSearchScopes, Quarantined, [e975a36c0b80c3738f4c6b18c341c040],
PUP.Optional.CrossRider, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [57078e81d7b4181ea6aafa8d6b99956b],
PUP.Optional.CinemaPlus, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\ARENAHD, Quarantined, [243ae52ad1ba1a1c386cff822ada649c],
PUP.Optional.GlobalUpdate, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY, Quarantined, [134bb15e28633ef8ad259bf66c98cf31],
PUP.Optional.CrossRider, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\29777, Quarantined, [e876d53af299f04668fd04833aca0df3],
PUP.Optional.CrossRider, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\OB, Quarantined, [76e83fd0f893df57ad662e5a29dbc838],
PUP.Optional.Spigot, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{268C499D-539E-4660-9550-610C05F59C45}, Quarantined, [b7a748c793f84beb8e908b27ec18d32d],
PUP.Optional.YahooVNM, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C0C3A6C6-03BC-4195-8FCB-AEA091301353}, Quarantined, [134bbc53e1aa1521d5e804b99e6617e9],
PUP.Optional.OutBrowse, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\OB, Quarantined, [64facb444a4155e135f4faaac341e719],
Registry Values: 17
PUP.Optional.CinemaPlus, HKLM\SOFTWARE\ARENAHD|value, 1, Quarantined, [a7b7c24d0b809c9acff4394884800df3]
PUP.Optional.PCTuner, HKLM\SOFTWARE\HIGHDEFACTION|value, 1, Quarantined, [1846e02fcac1a39369cad2d37292eb15]
PUP.Optional.Linkury.ShrtCln, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B1C30ZKEa5UhX2PRCO-5Poa2pHn7-A--VWt7oSCt15QDP0ZhwKBihrFsvTseo-t9xuG9XogegjVFqnVsZNZtlgs-elcBjZsc_0Pby_8fl5Y4Jpp7M3rXctaOAzDWttjKRU59bM_1EwPGB45WgRtZSs-DtH1Kv&q={searchTerms}, Quarantined, [590540cf494292a4e54a8ee406fed32d]
PUP.Optional.Linkury, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\ENVIRONMENT|SNP, http://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D?publisher=APSFRec&co=ZA&userid=3d62a4c8-374c-f85f-15c2-6fc95844d8e2&searchtype=sc&installDate=30/08/2015&barcodeid=50045888&channelid=888, Quarantined, [2935d03fd7b40b2b1e9c5742659f8e72]
PUP.Optional.Linkury, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\ENVIRONMENT|SNF, C:\ProgramData\ExtTags\snp.sc, Quarantined, [82dcf81777144aecf9c0c4d507fd6d93]
PUP.Optional.CinemaPlus, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\ARENAHD|value, 1, Quarantined, [243ae52ad1ba1a1c386cff822ada649c]
PUP.Optional.GlobalUpdate, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY|source, IE, Quarantined, [134bb15e28633ef8ad259bf66c98cf31]
PUP.Optional.PCTuner, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\HIGHDEFACTION|value, 1, Quarantined, [154937d8147769cda689c9dcb84c966a]
PUP.Optional.Spigot, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{268C499D-539E-4660-9550-610C05F59C45}|URL, http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}, Quarantined, [b7a748c793f84beb8e908b27ec18d32d]
PUP.Optional.Spigot, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{268C499D-539E-4660-9550-610C05F59C45}|OSDFileURL, file:///C:/Program%20Files/Common%20Files/Spigot/Search%20Settings/yahoo_ie.xml, Quarantined, [3727bc53c7c4a2944dd2ecc6986c52ae]
PUP.Optional.YahooVNM, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C0C3A6C6-03BC-4195-8FCB-AEA091301353}|URL, https://za.search.yahoo.com/search?fr=vmn&type=vmn__webcompa__1_0__ya__ch_WCYID10099_swoc_campaign_150830__yaie&p={searchTerms}, Quarantined, [134bbc53e1aa1521d5e804b99e6617e9]
PUP.Optional.Linkury.ShrtCln, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B1C30ZKEa5UhX2PRCO-5Poa2pHn7-A--VWt7oSCt15QDP0ZhwKBihrFsvTseo-t9xuG9XogegjVFqnVsZNZtlgs-elcBjZsc_0Pby_8fl5Y4Jpp7M3rXctaOAzDWttjKRU59bM_1EwPGB45WgRtZSs-DtH1Kv&q={searchTerms}, Quarantined, [aab45bb474170c2ae4487df5b3513bc5]
PUP.Optional.OutBrowse, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\OB|monitype20, 8/28/15 13:8:20, Quarantined, [64facb444a4155e135f4faaac341e719]
PUP.Optional.OutBrowse, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\OB|monitype14, 8/28/15 13:12:52, Quarantined, [26380d02bad1f0462801d9cb01034eb2]
PUP.Optional.OutBrowse, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\OB|monitype15, 8/28/15 13:14:3, Quarantined, [fb6357b892f9ee4849e05d47a06440c0]
PUP.Optional.OutBrowse, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\OB|monitype25, 8/28/15 13:17:18, Quarantined, [510d66a98dfece681415842012f233cd]
PUP.Optional.OutBrowse, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\OB|monitype21, 8/28/15 13:18:47, Quarantined, [b1addc33f09be2540c1ddaca25dff709]
Registry Data: 1
PUP.Optional.Linkury.ShrtCln, HKU\S-1-5-21-444297693-2264169564-2716400923-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B1C30ZKEa5UhX2PRCO-5Poa2pHn7-A--VWt7oSCt15QDP0ZhwKBihrFsvTseo-t9xuG9XogegjVFqnVsZNZtlgs-elcBjZsc_0Pby_8fl5Y4Jpp7M3rXctaOAzDWttjKRU59bM_1EwPGB45WgRtZSs-DtH1Kv&q={searchTerms}, Good: (www.google.com), Bad: (http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B1C30ZKEa5UhX2PRCO-5Poa2pHn7-A--VWt7oSCt15QDP0ZhwKBihrFsvTseo-t9xuG9XogegjVFqnVsZNZtlgs-elcBjZsc_0Pby_8fl5Y4Jpp7M3rXctaOAzDWttjKRU59bM_1EwPGB45WgRtZSs-DtH1Kv&q={searchTerms}),Replaced,[f36bcc43e1aa7cbabc678dd04cb9768a]
Folders: 7
PUP.Optional.OpenCandy, C:\Users\Riaan Nel\AppData\Roaming\OpenCandy, Quarantined, [4f0f30df3b5078be21e8915b5ca62ad6],
PUP.Optional.OpenCandy, C:\Users\Riaan Nel\AppData\Roaming\OpenCandy\C22279883C3F4E17A6E3C3F3665FB43F, Quarantined, [4f0f30df3b5078be21e8915b5ca62ad6],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\ondemand, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTags, Quarantined, [4e109c73c3c850e647b709fdac5747b9],
PUP.Optional.MiniLite, C:\Program Files\MiniLite, Quarantined, [85d9fe11acdf9d990aab2ce4778c5fa1],
PUP.Optional.SavePass, C:\Program Files\SavePass 1.1, Quarantined, [f36b6ea1e9a205313404888ea95adb25],
Files: 30
PUP.Optional.Nova, C:\Program Files\Acro Software\97a9ac5d-d6ff-4631-a774-216668061390.dll, Quarantined, [7ae47e9196f5f244c4f1557e45bc5ba5],
PUP.Optional.MiniLite, C:\Program Files\MiniLite\Uninstall.exe, Quarantined, [dd81858adeadc17559e4efe4f30ed030],
Trojan.Agent.MSIL, C:\Users\Riaan Nel\AppData\Local\Lot-media.exe, Quarantined, [134bd9365c2fd561ee7d8c3eb05105fb],
PUP.Optional.Linkury.Gen, C:\Windows\System32\findit.xml, Quarantined, [76e897788209270fc22a4257b94b35cb],
PUP.Optional.OpenCandy, C:\Users\Riaan Nel\AppData\Roaming\OpenCandy\C22279883C3F4E17A6E3C3F3665FB43F\WcInstaller.exe, Quarantined, [4f0f30df3b5078be21e8915b5ca62ad6],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\AlphaJob.exe, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\AlphaJob.exe.config, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\CanIt.dll, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\conf.config, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\Config.xml, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\ExtTag.dll, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\ExtTag.exe.config, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\Isjob.dll, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\Latit.exe, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\Latit.exe.config, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\PrxCfg.xml, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\Ranstock.dll, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\Stimla.bin, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\StrongTex.exe, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\StrongTex.exe.config, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\Tampfan.bin, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\uninstall.exe, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\Villa-Phase.bin, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\VoyaApflex.bin, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTag\Zaamstock.exe.config, Quarantined, [8fcf8887c4c764d2db229c6a976ca15f],
PUP.Optional.ExtTag, C:\ProgramData\ExtTags\ff.HP, Quarantined, [4e109c73c3c850e647b709fdac5747b9],
PUP.Optional.ExtTag, C:\ProgramData\ExtTags\ff.NT, Quarantined, [4e109c73c3c850e647b709fdac5747b9],
PUP.Optional.ExtTag, C:\ProgramData\ExtTags\snp.sc, Quarantined, [4e109c73c3c850e647b709fdac5747b9],
PUP.Optional.MiniLite, C:\Program Files\MiniLite\msvcp110.dll, Quarantined, [85d9fe11acdf9d990aab2ce4778c5fa1],
PUP.Optional.MiniLite, C:\Program Files\MiniLite\msvcr110.dll, Quarantined, [85d9fe11acdf9d990aab2ce4778c5fa1],
Physical Sectors: 0
(No malicious items detected)
(end)
# AdwCleaner v5.004 - Logfile created 31/08/2015 at 18:00:54
# Updated 26/08/2015 by Xplode
# Database : 2015-08-30.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x86)
# Username : Riaan Nel - RIAANNEL-PC
# Running from : C:\Users\Riaan Nel\Desktop\AdwCleaner.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
[-] Folder Deleted : C:\Program Files\globalUpdate
[-] Folder Deleted : C:\ProgramData\Premium
[-] Folder Deleted : C:\ProgramData\RightClick
[-] Folder Deleted : C:\Users\Riaan Nel\AppData\Local\FileTypeAssistant
[-] Folder Deleted : C:\Users\Riaan Nel\AppData\Local\globalUpdate
[-] Folder Deleted : C:\Users\Riaan Nel\AppData\Local\OpenCandy
[-] Folder Deleted : C:\Users\Riaan Nel\AppData\LocalLow\Conduit
[-] Folder Deleted : C:\Users\Riaan Nel\AppData\Roaming\cpuminer
[-] Folder Deleted : C:\Users\Riaan Nel\Documents\Updater
[-] Folder Deleted : C:\Windows\system32\config\systemprofile\AppData\Local\FileTypeAssistant
***** [ Files ] *****
[-] File Deleted : C:\Users\Riaan Nel\AppData\Roaming\Mozilla\Firefox\Profiles\ubs63plf.default\searchplugins\yahoo.xml
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [gpuminer]
[-] Key Deleted : HKLM\SOFTWARE\97a9ac5d-d6ff-4631-a774-216668061390
[-] Key Deleted : HKLM\SOFTWARE\c6980348-9af8-445a-8ff9-f44fe6dc4f41
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
[-] Key Deleted : HKCU\Software\Bitberry
[-] Key Deleted : HKCU\Software\Conduit
[-] Key Deleted : HKCU\Software\FileTypeAssistant
[-] Key Deleted : HKCU\Software\GlobalUpdate
[-] Key Deleted : HKCU\Software\InstalledBrowserExtensions
[-] Key Deleted : HKCU\Software\YahooPartnerToolbar
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
[-] Key Deleted : HKLM\SOFTWARE\AppDataLow\SOFTWARE\_CrossriderRegNamePlaceHolder_
[-] Key Deleted : HKLM\SOFTWARE\Conduit
[-] Key Deleted : HKLM\SOFTWARE\GlobalUpdate
[-] Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
[-] Key Deleted : HKLM\SOFTWARE\downchecker
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gpuminer
[!] Key Not Deleted : HKU\S-1-5-21-444297693-2264169564-2716400923-1000\Software\AppDataLow\Software\Conduit
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GLOBALUPDATE.EXE
***** [ Web browsers ] *****
[-] [C:\Users\Riaan Nel\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider_Data] Deleted :
*************************
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4126 bytes] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.0 (08.31.2015:1)
OS: Windows 7 Home Premium x86
Ran by Riaan Nel on 2015/09/01 at 11:40:28.08
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] C:\Program Files\convert audio free
Successfully deleted: [Folder] C:\Program Files\myfree codec
Successfully deleted: [Folder] C:\Users\Riaan Nel\Appdata\Local\cre
Successfully deleted: [Folder] C:\Users\Riaan Nel\Appdata\Local\28050
~~~ Chrome
[C:\Users\Riaan Nel\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Riaan Nel\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\Riaan Nel\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Riaan Nel\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 2015/09/01 at 11:44:40.32
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
I have also re-activated my Norton IS, as I noted it expired a few days ago. Here is the history log created by the Full System Scan:
Category: Resolved Security Risks
Date & Time,Risk,Activity,Status,Recommended Action,Path - Filename
2015/08/31 09:52:36 PM,Medium,frst.exe (WS.Reputation.1) detected by Download Insight,Quarantined,Resolved - No Action Required,c:\users\riaan nel\desktop\frst.exe
2015/08/31 08:33:20 PM,High,Suspicious.Cloud.9 detected by Virus scanner,Quarantined,Resolved - No Action Required,c:\users\riaan nel\downloads\vector magic 1.15.rar
2015/08/31 08:25:39 PM,Low,Adware.Gen detected by Virus scanner,Quarantined,Resolved - No Action Required,c:\users\riaan nel\appdata\roaming\atsfqs1rbz3lbtaqguwmzlnn
2015/08/31 05:54:38 PM,High,lot-media.exe (Trojan.Gen.2) detected by Auto-Protect,Quarantined,Resolved - No Action Required,c:\users\riaan nel\appdata\local\lot-media.exe
2015/08/31 04:02:13 PM,Low,protectservice.exe (PUA.SearchProtect) detected by Virus scanner,Quarantined,Resolved - No Action Required,c:\program files\minilite\protectservice.exe
2015/08/31 04:01:48 PM,High,aab96cd1-6eaa-4846-92fd-660511195439-1-7.exe (WS.Malware.2) detected by Virus scanner,Removed,Resolved - No Action Required,c:\program files\savepass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-1-7.exe
2015/08/31 04:01:47 PM,High,{4c2490b8-3135-4953-8c3d-6c03c4721091}gw.sys (WS.Malware.2) detected by Virus scanner,Quarantined,Resolved - No Action Required,c:\windows\system32\drivers\{4c2490b8-3135-4953-8c3d-6c03c4721091}gw.sys
2015/08/31 03:59:43 PM,High,aab96cd1-6eaa-4846-92fd-660511195439-5.exe (Suspicious.Epi) detected by Virus scanner,Removed,Resolved - No Action Required,c:\program files\savepass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-5.exe
2015/08/31 03:59:42 PM,High,aab96cd1-6eaa-4846-92fd-660511195439-6.exe (Trojan.Gen.2) detected by Virus scanner,Removed,Resolved - No Action Required,c:\program files\savepass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-6.exe
2015/08/31 03:59:41 PM,High,exttag.exe (Trojan.Gen) detected by Virus scanner,Quarantined,Resolved - No Action Required,c:\programdata\exttag\exttag.exe
2015/08/31 03:59:38 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2015/08/31 03:59:16 PM,Medium,frst.exe (WS.Reputation.1) detected by Download Insight,Quarantined,Resolved - No Action Required,c:\users\riaan nel\desktop\frst.exe
2015/08/31 03:53:19 PM,High,exttag.exe (SONAR.Heuristic.120) detected by SONAR,Quarantined,Resolved - No Action Required,c:\programdata\exttag\exttag.exe
2015/08/31 03:52:52 PM,High,aab96cd1-6eaa-4846-92fd-660511195439-1-6.exe (Trojan.Gen.2) detected by Auto-Protect,Quarantined,Resolved - No Action Required,c:\program files\savepass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-1-6.exe
2015/08/31 03:52:15 PM,High,ozerzumtax.dll (Suspicious.Cloud.7.EP) detected by Auto-Protect,Quarantined,Resolved - No Action Required,c:\programdata\exttag\ozerzumtax.dll
2015/08/31 03:50:49 PM,Low,protectservice.exe (PUA.SearchProtect) detected by Auto-Protect,Quarantined,Resolved - No Action Required,c:\program files\minilite\protectservice.exe
2015/08/31 03:50:10 PM,High,aab96cd1-6eaa-4846-92fd-660511195439-1-7.exe (Suspicious.Epi) detected by Auto-Protect,Quarantined,Resolved - No Action Required,c:\program files\savepass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-1-7.exe
2015/08/31 03:50:05 PM,High,aab96cd1-6eaa-4846-92fd-660511195439-5.exe (Suspicious.Epi) detected by Auto-Protect,Quarantined,Resolved - No Action Required,c:\program files\savepass 1.1\aab96cd1-6eaa-4846-92fd-660511195439-5.exe
2015/08/31 03:50:01 PM,High,finlex.dll (Suspicious.Epi) detected by Virus scanner and Auto-Protect,Quarantined,Resolved - No Action Required,c:\programdata\exttag\finlex.dll
2015/04/17 04:34:32 PM,High,kontrolepunt_bl10_p.exe (SAPE.Downloader.373e) detected by Virus scanner,Quarantined,Resolved - No Action Required,d:\afrikaanse hoër seunskool\rw\programme\riaan\kontrolepunt_bl10_p.exe
2015/03/16 05:57:01 PM,High,"Risks in compressed file "teknomw2_1.0.rar" detected by Virus scanner",Quarantined,Resolved - No Action Required,u:\michael\games\call of duty 6 - modern warfare 2\cod 6 stuff\teknomw2_1.0.rar
2015/02/10 04:48:53 PM,Low,CommunityToolbar detected by Virus scanner,Quarantined,Resolved - No Action Required,
2014/11/30 08:56:16 AM,High,dimensies_bl13_p.exe (SAPE.Heur.5158) detected by Virus scanner,Quarantined,Resolved - No Action Required,d:\afrikaanse hoër seunskool\rw\programme\riaan\dimensies_bl13_p.exe
2014/11/30 08:55:58 AM,High,datum_u.exe (SAPE.Heur.1f7b) detected by Virus scanner,Quarantined,Resolved - No Action Required,d:\afrikaanse hoër seunskool\rw\programme\riaan\datum_u.exe
2014/11/30 08:55:39 AM,High,balbeweeg_p.exe (SAPE.Heur.d6a) detected by Virus scanner,Quarantined,Resolved - No Action Required,d:\afrikaanse hoër seunskool\rw\programme\riaan\balbeweeg_p.exe
2014/11/28 03:21:31 PM,High,gupd.exe (Suspicious.Cloud.9) detected by Auto-Protect,Quarantined,Resolved - No Action Required,c:\users\riaan nel\gupd.exe
2014/10/26 07:29:33 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2014/10/26 07:29:33 PM,Medium,SecurityRisk.OrphanInf detected by Virus scanner,Removed,Resolved - No Action Required,
2014/10/26 07:28:08 PM,Medium,SecurityRisk.OrphanInf detected by Virus scanner,Quarantined,Resolved - No Action Required,
2014/09/21 04:44:01 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2014/08/21 05:27:44 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2014/07/20 11:41:15 AM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2014/06/09 01:49:53 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2014/05/25 09:18:40 PM,High,baha+men+-+who+let+the+dogs+out%20-%20[mp3juices.com][1].exe (W32.SAPE.Cloud9.5) detected by Download Insight,Quarantined,Resolved - No Action Required,c:\users\riaan nel\appdata\local\microsoft\windows\temporary internet files\low\content.ie5\hw9kxx4e\baha+men+-+who+let+the+dogs+out%20-%20[mp3juices.com][1].exe
2014/05/08 06:05:50 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2014/05/07 04:42:40 PM,High,download%20mixpad%20audio%20mixer%203.52%20%20%20serial%20key[1].exe (W32.SAPE.Cloud9.1) detected by Download Insight,Quarantined,Resolved - No Action Required,c:\users\riaan nel\appdata\local\microsoft\windows\temporary internet files\low\content.ie5\vhhiozc6\download%20mixpad%20audio%20mixer%203.52%20%20%20serial%20key[1].exe
2014/05/07 04:41:00 PM,High,mixpad%20audio%20mixer%203.54%20with%20register%20key%20code[1].exe (W32.SAPE.Cloud9.1) detected by Download Insight,Quarantined,Resolved - No Action Required,c:\users\riaan nel\appdata\local\microsoft\windows\temporary internet files\low\content.ie5\2j2i3s9x\mixpad%20audio%20mixer%203.54%20with%20register%20key%20code[1].exe
2014/04/14 05:22:08 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2014/02/27 04:07:02 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2014/01/27 12:29:24 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2013/12/28 12:03:35 AM,High,"Risks in compressed file "adobe.photoshop.lightroom.v4.0.multilingual.incl.keymaker-core.rar" detected by Virus scanner",Removed,Resolved - No Action Required,u:\michael\programs\adobe.photoshop.lightroom.v4.0.multilingual.incl.keymaker-core.rar
2013/12/28 12:03:32 AM,High,"Risks in compressed file "realflight.g4.5.emu33.rar" detected by Virus scanner",Quarantined,Resolved - No Action Required,u:\michael\programs\realflight\realflight.g4.5.emu33.rar
2013/12/27 07:21:01 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2013/11/27 12:08:40 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2013/10/05 12:39:38 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2013/09/14 06:19:09 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2013/07/10 06:36:26 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2013/06/06 05:57:47 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2013/06/05 07:07:46 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2013/06/03 09:16:46 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2013/05/17 04:02:46 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2013/05/02 04:42:57 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2013/02/10 04:15:45 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/12/29 01:36:40 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/12/07 02:29:59 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/12/01 12:53:38 PM,Medium,setup.exe (WS.Reputation.1) detected by Download Insight,Quarantined,Resolved - No Action Required,c:\users\riaan nel\desktop\setup.exe
2012/11/28 05:32:01 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/11/12 06:11:07 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/10/18 08:55:57 PM,High,bnetgatewayeditor.exe (Infostealer) detected by Auto-Protect,Quarantined,Resolved - No Action Required,\\meiztr\games\wc3\bnetgatewayeditor.exe
2012/10/16 06:24:25 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/09/24 03:47:26 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/09/08 04:24:14 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/08/08 11:20:37 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/05/13 05:56:46 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/05/02 09:45:39 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/04/24 05:10:12 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/04/23 06:32:30 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/04/23 03:40:33 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/04/16 06:16:55 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/04/08 06:41:20 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/04/06 11:16:59 AM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/04/02 05:54:21 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/03/28 08:06:37 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/03/18 03:12:14 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/02/23 04:54:18 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/02/11 12:31:08 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/02/01 09:24:35 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/01/23 06:40:54 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/01/11 06:40:34 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2012/01/08 01:22:01 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/12/26 09:31:25 AM,Medium,adobe cs4 web premium keygen.exe (WS.Reputation.1) detected by Download Insight,Quarantined,Resolved - No Action Required,c:\users\riaan nel\appdata\local\microsoft\windows\temporary internet files\content.ie5\s8zo0n7h\adobe cs4 web premium keygen.exe
2011/12/19 12:55:35 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/12/04 08:11:29 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/10/24 07:07:09 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/10/12 06:58:16 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/09/24 01:30:09 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/09/20 07:01:26 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/09/08 05:05:36 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/09/08 03:46:00 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/09/06 02:00:28 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/08/25 06:21:12 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/08/18 03:33:00 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/08/10 11:32:07 AM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/08/04 05:43:40 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/08/04 05:36:03 PM,Medium,SecurityRisk.OrphanInf detected by Virus scanner,Quarantined,Resolved - No Action Required,
2011/07/26 06:22:53 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/07/18 01:36:54 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/07/14 06:02:06 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/07/07 04:29:49 PM,High,keygen.exe (Suspicious.MH690.A) detected by Virus scanner,Quarantined,Resolved - No Action Required,d:\sibelius 4 install files\sibelius.v4.0.incl.keygen-h2o\keygen.exe
2011/07/04 06:54:30 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/07/03 10:06:38 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/06/30 11:49:16 AM,High,vguimatsurface.dll (WS.Viral.1) detected by Virus scanner,Quarantined,Resolved - No Action Required,d:\programme\cs source\bin\vguimatsurface.dll
2011/06/24 08:13:31 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/06/11 05:33:18 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/05/22 01:27:56 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/05/16 05:43:29 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/04/19 01:46:30 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/04/06 12:06:53 AM,Low,kojikuki.exe (Packed.Generic.307) detected by Virus scanner,Removed,Resolved - No Action Required,i:\tata\govori\kojikuki.exe
2011/04/06 12:02:46 AM,High,kojikuki.exe (Trojan.Usuge!gen3) detected by Virus scanner,Quarantined,Resolved - No Action Required,i:\tata\govori\kojikuki.exe
2011/03/29 03:17:23 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/03/19 12:38:40 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/03/12 06:27:14 PM,High,info.exe (W32.SillyDC) detected by Virus scanner,Quarantined,Resolved - No Action Required,i:\recycler\info.exe
2011/03/12 06:26:56 PM,High,xtnvbd.exe (W32.Harakit) detected by Virus scanner,Quarantined,Resolved - No Action Required,i:\xtnvbd.exe
2011/03/11 05:07:59 PM,High,order.exe (Trojan Horse) detected by Virus scanner,Quarantined,Resolved - No Action Required,i:\new\world\order.exe
2011/03/11 05:07:41 PM,High,syn.exe (W32.IRCbot) detected by Virus scanner,Quarantined,Resolved - No Action Required,i:\usb vault\syn.exe
2011/03/08 02:55:28 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/02/28 07:12:33 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/02/16 01:06:53 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,
2011/02/03 03:36:58 PM,Low,Tracking Cookies detected by Virus scanner,Removed,Resolved - No Action Required,