start
CreateRestorePoint:
CloseProcesses:
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {87FD958C-6DCD-4030-9C86-8645A8EE7F7C} - System32\Tasks\SMW_UpdateTask_Time_333630323336353531342d4a785b455a2a783445323757 => Wscript.exe //B "C:\ProgramData\SearchModule\smhe.js" smu.exe /invoke /f:check_services /l:0 <==== ATTENTION
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {AE16BD67-1375-4F04-89BF-4BDC320E17BB} - System32\Tasks\SMW_P => C:\ProgramData\smp2.exe [2016-04-25] () <==== ATTENTION
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {DFAB8729-7FA3-4445-9B86-C972183E8732} - System32\Tasks\Funmoods => C:\Users\brian\AppData\Roaming\Funmoods\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
ShortcutWithArgument: C:\Users\brian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www%2dsearching.com/?prd=set_epf&s=g4pzftpbl0cshmoam,7520fe93-9ec8-4c3d-a2a3-985c1e4ab80c,
ShortcutWithArgument: C:\Users\brian\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www%2dsearching.com/?prd=set_epf&s=g4pzftpbl0cshmoam,7520fe93-9ec8-4c3d-a2a3-985c1e4ab80c,
ShortcutWithArgument: C:\Users\brian\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet-Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www%2dsearching.com/?prd=set_epf&s=g4pzftpbl0cshmoam,7520fe93-9ec8-4c3d-a2a3-985c1e4ab80c,
ShortcutWithArgument: C:\Users\brian\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www%2dsearching.com/?prd=set_epf&s=g4pzftpbl0cshmoam,7520fe93-9ec8-4c3d-a2a3-985c1e4ab80c,
ShortcutWithArgument: C:\Users\brian\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www%2dsearching.com/?prd=set_epf&s=g4pzftpbl0cshmoam,7520fe93-9ec8-4c3d-a2a3-985c1e4ab80c,
ShortcutWithArgument: C:\Users\brian\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www%2dsearching.com/?prd=set_epf&s=g4pzftpbl0cshmoam,7520fe93-9ec8-4c3d-a2a3-985c1e4ab80c,
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www%2dsearching.com/?prd=set_epf&s=g4pzftpbl0cshmoam,7520fe93-9ec8-4c3d-a2a3-985c1e4ab80c,
ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www%2dsearching.com/?prd=set_epf&s=g4pzftpbl0cshmoam,7520fe93-9ec8-4c3d-a2a3-985c1e4ab80c,
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-4192471749-589627928-3305957805-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about
:blank
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {7ABB8264-F25C-44C9-AD4E-4F4CE9D0F08B} URL = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
SearchScopes: HKLM -> {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} URL = hxxp://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=as1212y&ir=as1212y&cd=2XzuyEtN2Y1L1Qzu0Ezzzy0Azz0FyBtDyDzytDtBtA0AyB0EtN0D0Tzu0CtAyDtBtN1L2XzutBtFtBtFtCtFyEtDyB&cr=1029339382
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {7ABB8264-F25C-44C9-AD4E-4F4CE9D0F08B} URL = hxxp://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-4192471749-589627928-3305957805-1001 -> {1A585308-226F-46B3-8179-FA5A060522AB} URL = hxxp://www-searching.com/s.ashx?prd=opensearch&q={searchTerms}&s=G4Pzftpbl0cshmoAM,7520fe93-9ec8-4c3d-a2a3-985c1e4ab80c,
SearchScopes: HKU\S-1-5-21-4192471749-589627928-3305957805-1001 -> {7ABB8264-F25C-44C9-AD4E-4F4CE9D0F08B} URL =
SearchScopes: HKU\S-1-5-21-4192471749-589627928-3305957805-1001 -> {C0CBAC0F-963B-4EC0-BC3D-6370F16E24AB} URL = hxxp://www.google.co.uk/search?hl=en&q={searchTerms}&meta=
SearchScopes: HKU\S-1-5-21-4192471749-589627928-3305957805-1001 -> {CE7004D9-9DAF-4F31-AFCA-1FA36CAC2535} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: No Name -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> No File
BHO-x32: No Name -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
CHR HomePage: Default -> hxxp://www-searching.com/?pid=s&s=G4Pzftpbl0cshmoAM,7520fe93-9ec8-4c3d-a2a3-985c1e4ab80c,&vp=ch&prd=set_ch
S3 SMUpdd; C:\Program Files\Common Files\Doobzo\GSUpdate\smw.sys [43264 2016-04-23] ()
C:\Program Files\Common Files\Doobzo\GSUpdate\smw.sys
C:\Program Files\Common Files\Doobzo
C:\ProgramData\SearchModule
C:\ProgramData\smp2.exe
C:\ProgramData\vlwlirjf.odd
C:\ProgramData\vzj9dqt.bxx
C:\ProgramData\vzj9dqt.fvv
C:\ProgramData\vzj9dqt.reg
CMD: ipconfig /flushdns
CMD: netsh winsock reset all
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
EmptyTemp:
Hosts:
End