CloseProcesses: HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [SOSUAUI] => C:\Program Files (x86)\AVG Online Backup\sosuploadagent.exe [59440 2016-08-30] (AVG Online Backup) HKLM-x32\...\Run: [SMessaging] => C:\Program Files (x86)\AVG Online Backup\SMessaging.exe [63536 2016-08-30] (AVG Online Backup) HKLM-x32\...\Run: [AccountCreatorRunner] => C:\Program Files (x86)\AVG Online Backup\AccountCreatorRunner.exe [23088 2016-08-30] (AVG Online Backup) HKLM-x32\...\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File Toolbar: HKU\S-1-5-21-3526073170-1583772248-2959233235-1001 -> No Name - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File FF Plugin HKU\S-1-5-21-3526073170-1583772248-2959233235-1001: @hulu.com/Hulu Desktop -> C:\Users\Default.migrated\AppData\Local\HuluDesktop\instances\0.9.9.1\nphdplg.dll [No File] CHR Extension: (Ask Web Search) - C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllfmhclbkgdcbioppcjohckdmjmfmcj [2017-05-04] CHR Extension: (Ask Web Search) - C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkmodlfcmmnhhlofndkhdcembjaefbb [2017-05-04] CHR Extension: (InboxNow) - C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjhofhakdnfjgeobcioadclaekfbhndl [2017-05-04] CHR Extension: (EasyMailLogin) - C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgpcmjeckonpfoaacknfdaaehpjbflhl [2017-05-04] S4 sagentservice; C:\Program Files (x86)\AVG Online Backup\SAgent.Service.exe [44080 2016-08-30] (AVG Online Backup) R2 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 -ad -bt=0 [X] S4 AvgUpgrade; "C:\Program Files (x86)\AVG\CloudCare\AvgUpgrade.exe" [X] S4 ClientManager; "C:\Program Files (x86)\AVG\CloudCare\ClientManager.exe" [X] U3 idsvc; no ImagePath 2017-05-04 08:16 - 2016-12-05 13:32 - 00000000 ____D C:\ProgramData\Avg 2017-05-04 08:15 - 2016-12-05 13:30 - 00000000 ____D C:\Program Files (x86)\AVG 2017-05-04 08:09 - 2016-12-05 13:32 - 00000000 ____D C:\Users\William\AppData\Local\Avg 2017-05-03 22:58 - 2016-09-13 19:06 - 00000000 ____D C:\ProgramData\iolo 2017-05-02 11:31 - 2016-09-13 19:06 - 00000000 ____D C:\Program Files (x86)\iolo 2017-05-02 02:00 - 2016-12-05 13:30 - 00000000 ____D C:\ProgramData\AVG Online Backup Task: {60F567A5-1DE5-43F8-8452-525B5125375E} - System32\Tasks\AVG Online Backup - AVG78224 => C:\Program Files (x86)\AVG Online Backup\sosuploadagent.exe [2016-08-30] (AVG Online Backup) Task: {D5CB447C-7878-41BF-8E67-1D20D6C7DBF6} - \Microsoft\Windows\Setup\EOSNotify -> No File <==== ATTENTION HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AvgApiWrapper => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AvgUpgrade => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClientManager => ""="Service" MSCONFIG\Services: AvgApiWrapper => 2 MSCONFIG\Services: AvgUpgrade => 2 MSCONFIG\Services: ClientManager => 2 HKLM\...\StartupApproved\Run32: => "AVG_UI" HKLM\...\StartupApproved\Run32: => "AvgUi" FirewallRules: [{B053DAB0-BC1C-4972-A9B5-C0FAE72AEC9B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe FirewallRules: [{38157AB0-1413-4B5B-B110-0BB0B4CC5105}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe FirewallRules: [{D69F4EC7-13D5-420F-82D3-482CD6A2FC4B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe FirewallRules: [{3EEAD8DE-504C-44BC-B236-5847EC394699}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe C:\Program Files (x86)\AVG Online Backup CMD: ipconfig /flushdns Hosts: EmptyTemp: