start CreateRestorePoint: CloseProcesses: HKU\S-1-5-18\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe CHR StartupUrls: Default -> "hxxp://www.jigsawplanet.com/","hxxp://www.mylucky123.com/?type=hp&ts=1476777238&z=b1292b6b19f427a99b6aeaagbz3m2q2m0m7m0obz2g&from=amule1017&uid=SAMSUNGXMZ7LN256HCHP-000H1_S1ZPNX0H716508" R2 ed2kidle; C:\Program Files (x86)\walalala co\aMuleCustom\ed2k.exe [236544 2016-09-12] (hxxp://www.amule.org/) [File not signed] R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X] S3 dbx; system32\DRIVERS\dbx.sys [X] C:\Program Files (x86)\walalala co C:\Users\louisa-jeaninne\AppData\Local\Temp\INST01.dll C:\Users\louisa-jeaninne\AppData\Local\Temp\INST011.dll FirewallRules: [{681F0A43-BD3A-454C-9095-81D5C2BCABA7}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe FirewallRules: [{3E788BE3-8AE7-487E-87B7-065D8956A2FA}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe EmptyTemp: Reboot: end