start
CreateRestorePoint:
CloseProcesses:
HKLM-x32\...\Run: [mbot_fr_429] => [X]
HKLM-x32\...\Run: [gmsd_fr_104] => [X]
HKU\S-1-5-21-287015425-813974205-1193642550-1002\...\Run: [WindApp] => "C:\Users\gilles\AppData\Roaming\Store\WindApp\WindApp.exe" /winstartup
HKU\S-1-5-21-287015425-813974205-1193642550-1002\...\Run: [Selection Tools] => "C:\Users\gilles\AppData\Roaming\WTools\Selection Tools\Selection Tools.exe" /winstartup
HKU\S-1-5-21-287015425-813974205-1193642550-1002\...\Run: [BoBrowser] => C:\Users\gilles\AppData\Local\BoBrowser\Application\bobrowser.exe [7353992 2014-11-19] (The BoBrowser Authors)
GroupPolicy: Group Policy on Chrome detected
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www. version="1.0" encoding="UTF-8"?>?type=hppppp
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
http://www. version="1.0" encoding="UTF-8"?>?type=hppppp
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www. version="1.0" encoding="UTF-8"?>web/?type=dspp&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
http://www. version="1.0" encoding="UTF-8"?>web/?type=dspp&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www. version="1.0" encoding="UTF-8"?>?type=hppppp
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www. version="1.0" encoding="UTF-8"?>?type=hppppp
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www. version="1.0" encoding="UTF-8"?>web/?type=dspp&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www. version="1.0" encoding="UTF-8"?>web/?type=dspp&q={searchTerms}
HKU\S-1-5-21-287015425-813974205-1193642550-1002\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www. version="1.0" encoding="UTF-8"?>
HKU\S-1-5-21-287015425-813974205-1193642550-1002\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www. version="1.0" encoding="UTF-8"?>?type=hppppp
HKU\S-1-5-21-287015425-813974205-1193642550-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www. version="1.0" encoding="UTF-8"?>?type=hppppp
HKU\S-1-5-21-287015425-813974205-1193642550-1002\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www. version="1.0" encoding="UTF-8"?>
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe
http://www.mystartsearch.com/?type=sc&t ... J9FD708649
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
http://www. version="1.0" encoding="UTF-8"?>web/?type=dspp&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
http://www. version="1.0" encoding="UTF-8"?>web/?type=dspp&q={searchTerms}
SearchScopes: HKLM -> {938135F9-DE58-49C8-8B89-E0FB499632E4} URL =
http://start.mysearchdial.com/results.p ... 357793&ir=
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
http://www. version="1.0" encoding="UTF-8"?>web/?type=dspp&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
http://www. version="1.0" encoding="UTF-8"?>web/?type=dspp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-287015425-813974205-1193642550-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
http://www. version="1.0" encoding="UTF-8"?>web/?type=dspp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-287015425-813974205-1193642550-1002 -> {70BA81A7-2C4F-4D0E-B68F-799C03040360} URL =
http://www.search.ask.com/web?tpid=ORJ- ... erms}&psv=
SearchScopes: HKU\S-1-5-21-287015425-813974205-1193642550-1002 -> {938135F9-DE58-49C8-8B89-E0FB499632E4} URL =
http://start.mysearchdial.com/results.p ... 357793&ir=
BHO: No Name -> {11111111-1111-1111-1111-110611131165} -> No File
BHO: No Name -> {11111111-1111-1111-1111-110611181106} -> No File
BHO-x32: No Name -> {0F6E720A-1A6B-40E1-A294-1D4D19F156C8} -> No File
BHO-x32: No Name -> {11111111-1111-1111-1111-110611131165} -> No File
BHO-x32: No Name -> {11111111-1111-1111-1111-110611181106} -> No File
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mystartsearch.xml
FF Extension: AccelerateTab - C:\Users\gilles\AppData\Roaming\Mozilla\Firefox\Profiles\o9zyiqs0.default\Extensions\
speeddial@instair.net [2015-01-16]
FF HKLM-x32\...\Firefox\Extensions: [
faststartff@gmail.com] - C:\Users\gilles\AppData\Roaming\Mozilla\Firefox\Profiles\o9zyiqs0.default\extensions\
faststartff@gmail.com
CHR HomePage: Default -> hxxp://www.\u003C?xml version=\
CHR StartupUrls: Default -> "hxxp://www.\u003C?xml version=\"1.0\" encoding=\"UTF-8\"?>?type=hppppp"
CHR DefaultSearchURL: Default -> http://www.\u003C?xml version=\
CHR Extension: (SmartSaver+ 3) - C:\Users\gilles\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekpibplnnkfdcafdpoekhoffegcajene [2015-01-17]
CHR Extension: (iGraal) - C:\Users\gilles\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmhkepipobnjllejbafajoemahjejdcm [2014-12-07]
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - No Path
R2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [158864 2014-12-29] (XTab system)
R2 RUMFRJW; C:\ProgramData\MiRjYowhEm\RUMFRJW.exe [2726256 2015-01-17] (Time Lapse Solutions)
S2 Update Techgile; C:\Program Files (x86)\Techgile\updateTechgile.exe [529648 2015-01-17] ()
S2 Util Techgile; C:\Program Files (x86)\Techgile\bin\utilTechgile.exe [529648 2015-01-17] ()
S2 SecureUpdateSvc; C:\Program Files (x86)\Secure Speed Dial\IE\SecureUpdate.exe [X]
R1 {8d3b604a-9bd5-4112-8d4a-58ce2f912071}Gw64; C:\Windows\System32\drivers\{8d3b604a-9bd5-4112-8d4a-58ce2f912071}Gw64.sys [48784 2015-01-16] (StdLib)
S1 ccnfd_1_10_0_6; system32\drivers\ccnfd_1_10_0_6.sys [X]
2015-01-17 13:57 - 2015-01-23 09:53 - 00000000 ____D () C:\Program Files (x86)\Software
2015-01-17 13:57 - 2015-01-17 13:57 - 00000000 ____D () C:\Users\gilles\AppData\Local\Software
2015-01-17 13:57 - 2015-01-17 13:57 - 00000000 ____D () C:\Users\gilles\AppData\Local\Boxore
2015-01-17 13:57 - 2015-01-17 13:57 - 00000000 ____D () C:\Program Files (x86)\predm
2015-01-17 10:04 - 2015-01-23 17:10 - 00000000 ____D () C:\Users\gilles\AppData\Local\ZombieNews
2015-01-17 00:50 - 2015-01-23 12:50 - 00002794 _____ () C:\WINDOWS\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-5_user.job
2015-01-17 00:50 - 2015-01-23 12:50 - 00002794 _____ () C:\WINDOWS\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-5.job
2015-01-17 00:50 - 2015-01-23 12:50 - 00002450 _____ () C:\WINDOWS\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-2.job
2015-01-17 00:50 - 2015-01-17 00:50 - 00005798 _____ () C:\WINDOWS\System32\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-5
2015-01-17 00:50 - 2015-01-17 00:50 - 00005454 _____ () C:\WINDOWS\System32\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-2
2015-01-17 00:49 - 2015-01-23 12:49 - 00004498 _____ () C:\WINDOWS\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-4.job
2015-01-17 00:49 - 2015-01-23 12:49 - 00003448 _____ () C:\WINDOWS\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-1.job
2015-01-17 00:49 - 2015-01-17 00:49 - 00007502 _____ () C:\WINDOWS\System32\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-4
2015-01-17 00:49 - 2015-01-17 00:49 - 00006452 _____ () C:\WINDOWS\System32\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-1
2015-01-17 00:48 - 2015-01-23 16:48 - 00001772 _____ () C:\WINDOWS\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-10_user.job
2015-01-17 00:48 - 2015-01-23 12:48 - 00005522 _____ () C:\WINDOWS\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-7.job
2015-01-17 00:48 - 2015-01-23 12:48 - 00005188 _____ () C:\WINDOWS\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-11.job
2015-01-17 00:48 - 2015-01-23 10:48 - 00000000 ____D () C:\Program Files (x86)\I - Cinema
2015-01-17 00:48 - 2015-01-17 00:48 - 00008526 _____ () C:\WINDOWS\System32\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-7
2015-01-17 00:48 - 2015-01-17 00:48 - 00008192 _____ () C:\WINDOWS\System32\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-11
2015-01-17 00:46 - 2015-01-23 12:46 - 00002456 _____ () C:\WINDOWS\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-5_user.job
2015-01-17 00:46 - 2015-01-23 12:46 - 00002456 _____ () C:\WINDOWS\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-5.job
2015-01-17 00:46 - 2015-01-17 10:03 - 00000000 ____D () C:\ProgramData\MiRjYowhEm
2015-01-17 00:46 - 2015-01-17 00:47 - 00000000 ____D () C:\ProgramData\ZombieNews
2015-01-17 00:46 - 2015-01-17 00:46 - 00005460 _____ () C:\WINDOWS\System32\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-5
2015-01-17 00:45 - 2015-01-23 12:45 - 00003124 _____ () C:\WINDOWS\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-1.job
2015-01-17 00:45 - 2015-01-23 12:45 - 00002120 _____ () C:\WINDOWS\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-2.job
2015-01-17 00:45 - 2015-01-17 00:45 - 00006128 _____ () C:\WINDOWS\System32\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-1
2015-01-17 00:45 - 2015-01-17 00:45 - 00005124 _____ () C:\WINDOWS\System32\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-2
2015-01-17 00:43 - 2015-01-23 12:43 - 00005192 _____ () C:\WINDOWS\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-7.job
2015-01-17 00:43 - 2015-01-23 12:43 - 00004168 _____ () C:\WINDOWS\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-4.job
2015-01-17 00:43 - 2015-01-17 00:43 - 00008196 _____ () C:\WINDOWS\System32\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-7
2015-01-17 00:43 - 2015-01-17 00:43 - 00007172 _____ () C:\WINDOWS\System32\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-4
2015-01-17 00:42 - 2015-01-17 00:42 - 00000000 ____D () C:\Users\gilles\AppData\Local\globalUpdate
2015-01-17 00:41 - 2015-01-23 16:42 - 00001778 _____ () C:\WINDOWS\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-10_user.job
2015-01-17 00:41 - 2015-01-23 12:43 - 00000000 ____D () C:\Program Files (x86)\SmartSaver+ 3
2015-01-17 00:34 - 2015-01-17 00:34 - 00003824 _____ () C:\WINDOWS\System32\Tasks\PostPoneInstall
2015-01-17 00:34 - 2015-01-17 00:34 - 00003162 _____ () C:\WINDOWS\System32\Tasks\Run_Bobby_Browser
2015-01-17 00:33 - 2015-01-17 00:36 - 00000000 ____D () C:\Users\gilles\AppData\Local\BoBrowser
2015-01-16 23:11 - 2015-01-17 13:47 - 00000000 ____D () C:\Users\gilles\AppData\Roaming\Store
2015-01-16 23:11 - 2015-01-17 00:47 - 00000000 ____D () C:\Users\gilles\AppData\Roaming\WTools
2015-01-16 23:11 - 2015-01-16 23:11 - 00000078 _____ () C:\Users\gilles\AppData\Roaming\WindApp.installation.log
2015-01-16 23:11 - 2015-01-16 23:11 - 00000078 _____ () C:\Users\gilles\AppData\Roaming\Selection Tools.installation.log
2015-01-16 23:10 - 2015-01-16 23:11 - 00005777 _____ () C:\Users\gilles\AppData\Roaming\Bubble Dock.installation.log
2015-01-16 23:10 - 2015-01-16 23:10 - 00000097 _____ () C:\Users\gilles\AppData\Roaming\WindApp.boostrap.log
2015-01-16 23:10 - 2015-01-16 23:10 - 00000000 ____D () C:\Users\gilles\AppData\Roaming\Nosibay
2015-01-16 23:10 - 2015-01-16 23:10 - 00000000 ____D () C:\Users\gilles\AppData\Roaming\Lavasoft
2015-01-16 23:10 - 2015-01-16 23:10 - 00000000 ____D () C:\ProgramData\Lavasoft
2015-01-16 23:09 - 2015-01-16 23:11 - 00001275 _____ () C:\Users\gilles\AppData\Roaming\Bubble Dock.boostrap.log
2015-01-16 19:03 - 2015-01-16 05:28 - 00048784 _____ (StdLib) C:\WINDOWS\system32\Drivers\{8d3b604a-9bd5-4112-8d4a-58ce2f912071}Gw64.sys
2015-01-16 18:56 - 2015-01-16 18:56 - 00000000 ____D () C:\ProgramData\IHProtectUpDate
2015-01-16 18:56 - 2015-01-16 18:56 - 00000000 ____D () C:\Program Files (x86)\XTab
2015-01-16 18:55 - 2015-01-16 18:55 - 00000000 ____D () C:\WINDOWS\Download
2015-01-16 18:54 - 2015-01-16 18:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainishare
2015-01-16 18:53 - 2015-01-17 13:50 - 00000000 ____D () C:\Program Files (x86)\Techgile
2015-01-16 18:48 - 2015-01-16 18:48 - 00000000 ____D () C:\ProgramData\IObit
2015-01-16 18:46 - 2015-01-16 18:46 - 00000000 ____D () C:\Users\gilles\AppData\Roaming\Vtools
C:\Program Files (x86)\MyPC Backup
C:\Program Files (x86)\globalUpdate
C:\Program Files (x86)\Secure Speed Dial
C:\Users\gilles\AppData\Roaming\mystartsearch
C:\Users\gilles\AppData\Roaming\Nosibay
C:\Users\gilles\AppData\Roaming\WTools
Task: {1A9A0C31-13EE-4BB9-A86D-ED7EF9B62484} - System32\Tasks\{35B6734A-B95C-42D7-B99F-5C82AADF440C} => pcalua.exe -a C:\Users\gilles\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=ima
Task: {21B600BD-3BEB-4303-BB6F-248E15A35839} - System32\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-2 => C:\Program Files (x86)\SmartSaver+ 3\3aff9db0-203f-461e-bd90-8791b23d2e14-2.exe [2015-01-17] (smart-saverplus)
Task: {2990B287-65F5-4AD6-BC81-807749BF6771} - System32\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-10_user => C:\Program Files (x86)\SmartSaver+ 3\3aff9db0-203f-461e-bd90-8791b23d2e14-10.exe [2015-01-17] (smart-saverplus)
Task: {428C7DB7-E68B-46FA-B761-E1EE31E68FB9} - System32\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-4 => C:\Program Files (x86)\I - Cinema\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-4.exe
Task: {4C405D4F-6548-4394-867A-050D5DEF5F76} - System32\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-2 => C:\Program Files (x86)\I - Cinema\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-2.exe [2015-01-17] (DiscountFrenzy)
Task: {53334B25-0287-4B9D-85AF-A2FB0366C21E} - System32\Tasks\{CB184CC5-AB48-48A6-96E8-4D50B969E123} => pcalua.exe -a C:\ProgramData\ZombieNews\uninstall.exe -c /kb=y /ic=1
Task: {57BF940E-E2B8-49DA-BDC2-53325F29C58A} - System32\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-1 => C:\Program Files (x86)\I - Cinema\I - Cinema-codedownloader.exe [2015-01-17] (DiscountFrenzy)
Task: {62078B24-8596-4A45-A1B0-A401C146A451} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe
Task: {6E2BF352-EC91-44EA-8C2A-05E856D3A040} - System32\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-5_user => C:\Program Files (x86)\SmartSaver+ 3\3aff9db0-203f-461e-bd90-8791b23d2e14-5.exe [2015-01-17] (smart-saverplus)
Task: {772AC2DC-7493-4883-93ED-E51E03F70732} - System32\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-7 => C:\Program Files (x86)\I - Cinema\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-7.exe [2015-01-17] (DiscountFrenzy)
Task: {8327EDA0-CE54-4E5E-9A5E-03B9762370F4} - System32\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-1 => C:\Program Files (x86)\SmartSaver+ 3\SmartSaver+ 3-codedownloader.exe [2015-01-17] (smart-saverplus)
Task: {8B7488C6-2706-4596-8874-E5899B6C3949} - System32\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-5 => C:\Program Files (x86)\I - Cinema\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-5.exe [2015-01-17] (DiscountFrenzy)
Task: {8BB04457-AFE6-4996-B7E4-63F3C6E0F932} - System32\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-5 => C:\Program Files (x86)\SmartSaver+ 3\3aff9db0-203f-461e-bd90-8791b23d2e14-5.exe [2015-01-17] (smart-saverplus)
Task: {8D90D356-78BA-4B48-A1F8-0B57B96E630E} - System32\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-10_user => C:\Program Files (x86)\I - Cinema\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-10.exe [2015-01-17] (DiscountFrenzy)
Task: {9A52DAC1-E7F4-4810-A1D6-30493D5D3BCE} - System32\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-5_user => C:\Program Files (x86)\I - Cinema\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-5.exe [2015-01-17] (DiscountFrenzy)
Task: {B083A0B6-A42F-47D9-8809-34B7CF42E433} - System32\Tasks\Run_Bobby_Browser => C:\Users\gilles\AppData\Local\BoBrowser\Application\bobrowser.exe [2014-11-19] (The BoBrowser Authors)
Task: {B6AD9784-2C4B-41C4-A89C-E5ADC8329185} - System32\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-4 => C:\Program Files (x86)\SmartSaver+ 3\3aff9db0-203f-461e-bd90-8791b23d2e14-4.exe
Task: {C0AEEECF-C888-4A18-A7A6-C9B02E5327E3} - System32\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-7 => C:\Program Files (x86)\SmartSaver+ 3\3aff9db0-203f-461e-bd90-8791b23d2e14-7.exe [2015-01-17] (smart-saverplus)
Task: {C1FED732-3CE0-4E90-AD79-F60AA9977045} - System32\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-11 => C:\Program Files (x86)\I - Cinema\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-11.exe [2015-01-17] (DiscountFrenzy)
Task: {CC49D7D5-8DFF-4208-9131-0366CAC22642} - System32\Tasks\{FAB7C7C1-69A7-470C-8FDC-1FF8402E1890} => pcalua.exe -a "C:\Users\gilles\AppData\Roaming\Nosibay\Bubble Dock\Uninstall Bubble Dock.exe"
Task: {CD1DD70D-0526-4C8F-B7AB-2F43C4B94F3E} - System32\Tasks\PostPoneInstall => C:\Users\gilles\AppData\Local\Temp\ce98ac2e-20c0-4a93-86f6-bdb3e61caf55.exe
Task: C:\WINDOWS\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-1.job => C:\Program Files (x86)\SmartSaver+ 3\SmartSaver+ 3-codedownloader.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-10_user.job => C:\Program Files (x86)\SmartSaver+ 3\3aff9db0-203f-461e-bd90-8791b23d2e14-10.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-2.job => C:\Program Files (x86)\SmartSaver+ 3\3aff9db0-203f-461e-bd90-8791b23d2e14-2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-4.job => C:\Program Files (x86)\SmartSaver+ 3\3aff9db0-203f-461e-bd90-8791b23d2e14-4.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-5.job => C:\Program Files (x86)\SmartSaver+ 3\3aff9db0-203f-461e-bd90-8791b23d2e14-5.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-5_user.job => C:\Program Files (x86)\SmartSaver+ 3\3aff9db0-203f-461e-bd90-8791b23d2e14-5.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\3aff9db0-203f-461e-bd90-8791b23d2e14-7.job => C:\Program Files (x86)\SmartSaver+ 3\3aff9db0-203f-461e-bd90-8791b23d2e14-7.exe
Task: C:\WINDOWS\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-1.job => C:\Program Files (x86)\I - Cinema\I - Cinema-codedownloader.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-10_user.job => C:\Program Files (x86)\I - Cinema\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-10.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-11.job => C:\Program Files (x86)\I - Cinema\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-11.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-2.job => C:\Program Files (x86)\I - Cinema\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-2.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-4.job => C:\Program Files (x86)\I - Cinema\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-4.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-5.job => C:\Program Files (x86)\I - Cinema\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-5.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-5_user.job => C:\Program Files (x86)\I - Cinema\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-5.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-7.job => C:\Program Files (x86)\I - Cinema\fb8d8c6c-aa74-43de-9f46-c7f9944d9bd2-7.exe
AlternateDataStreams: C:\ProgramData\Temp:AD022376
EmptyTemp:
end