mbam Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 01.01.2015 12:19:43, SYSTEM, MMM-PC, Protection, Malware Protection, Starting,
Protection, 01.01.2015 12:19:46, SYSTEM, MMM-PC, Protection, Malware Protection, Started,
Protection, 01.01.2015 12:19:46, SYSTEM, MMM-PC, Protection, Malicious Website Protection, Starting,
Protection, 01.01.2015 12:19:54, SYSTEM, MMM-PC, Protection, Malicious Website Protection, Started,
Update, 01.01.2015 12:20:03, SYSTEM, MMM-PC, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1,
Update, 01.01.2015 12:20:03, SYSTEM, MMM-PC, Manual, Rootkit Database, 2014.11.18.1, 2014.12.30.1,
Update, 01.01.2015 12:20:12, SYSTEM, MMM-PC, Manual, Malware Database, 2014.11.20.6, 2015.1.1.2,
Protection, 01.01.2015 12:20:12, SYSTEM, MMM-PC, Protection, Refresh, Starting,
Protection, 01.01.2015 12:20:12, SYSTEM, MMM-PC, Protection, Malicious Website Protection, Stopping,
Protection, 01.01.2015 12:20:13, SYSTEM, MMM-PC, Protection, Malicious Website Protection, Stopped,
Protection, 01.01.2015 12:20:21, SYSTEM, MMM-PC, Protection, Refresh, Success,
Protection, 01.01.2015 12:20:21, SYSTEM, MMM-PC, Protection, Malicious Website Protection, Starting,
Protection, 01.01.2015 12:20:22, SYSTEM, MMM-PC, Protection, Malicious Website Protection, Started,
Protection, 01.01.2015 13:19:43, SYSTEM, MMM-PC, Protection, Malware Protection, Starting,
Protection, 01.01.2015 13:19:43, SYSTEM, MMM-PC, Protection, Malware Protection, Started,
Protection, 01.01.2015 13:19:43, SYSTEM, MMM-PC, Protection, Malicious Website Protection, Starting,
Protection, 01.01.2015 13:22:31, SYSTEM, MMM-PC, Protection, Malicious Website Protection, Started,
(end) adwcleaner [R2] Code:
# AdwCleaner v4.106 - Bericht erstellt am 01/01/2015 um 13:32:26
# Aktualisiert 21/12/2014 von Xplode
# Database : 2014-12-21.4 [Local]
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 1 (32 bits)
# Benutzername : azita21 - MMM-PC
# Gestartet von : C:\Users\azita21.mmm-PC\Desktop\AdwCleaner_4.106.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gefunden : C:\ProgramData\48f81aa1bb9c31ec
Ordner Gefunden : C:\ProgramData\Wideblue installer
***** [ Tasks ] *****
Task Gefunden : APSnotifierPP1
Task Gefunden : APSnotifierPP2
Task Gefunden : APSnotifierPP3
Task Gefunden : globalUpdateUpdateTaskMachineCore
Task Gefunden : globalUpdateUpdateTaskMachineUA
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
***** [ Browser ] *****
-\\ Internet Explorer v7.0.6001.18527
-\\ Google Chrome v35.0.1916.153
*************************
AdwCleaner[R0].txt - [23136 octets] - [12/07/2014 15:55:31]
AdwCleaner[R1].txt - [13846 octets] - [04/09/2014 11:11:09]
AdwCleaner[R2].txt - [1166 octets] - [01/01/2015 13:32:26]
AdwCleaner[S0].txt - [21120 octets] - [12/07/2014 16:21:06]
AdwCleaner[S1].txt - [12167 octets] - [04/09/2014 11:14:15]
########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [1348 octets] ########## adwcleaner [S2] Code:
# AdwCleaner v4.106 - Bericht erstellt am 01/01/2015 um 13:38:37
# Aktualisiert 21/12/2014 von Xplode
# Database : 2014-12-21.4 [Local]
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 1 (32 bits)
# Benutzername : azita21 - MMM-PC
# Gestartet von : C:\Users\azita21.mmm-PC\Desktop\AdwCleaner_4.106.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Wideblue installer
Ordner Gelöscht : C:\ProgramData\48f81aa1bb9c31ec
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
***** [ Browser ] *****
-\\ Internet Explorer v7.0.6001.18527
-\\ Google Chrome v35.0.1916.153
*************************
AdwCleaner[R0].txt - [23136 octets] - [12/07/2014 15:55:31]
AdwCleaner[R1].txt - [13846 octets] - [04/09/2014 11:11:09]
AdwCleaner[R2].txt - [1428 octets] - [01/01/2015 13:32:26]
AdwCleaner[S0].txt - [21120 octets] - [12/07/2014 16:21:06]
AdwCleaner[S1].txt - [12167 octets] - [04/09/2014 11:14:15]
AdwCleaner[S2].txt - [1153 octets] - [01/01/2015 13:38:37]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1213 octets] ########## JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows Vista (TM) Home Premium x86
Ran by azita21 on 01.01.2015 at 13:51:42,85
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\azita21.mmm-PC\AppData\Roaming\systweak"
Successfully deleted: [Folder] "C:\Users\azita21.mmm-PC\AppData\Roaming\vopackage"
Successfully deleted: [Folder] "C:\Users\azita21.mmm-PC\AppData\Roaming\microsoft\windows\start menu\programs\mypc backup"
Successfully deleted: [Folder] "C:\Users\azita21.mmm-PC\AppData\Roaming\microsoft\windows\start menu\programs\vopackage"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01.01.2015 at 13:57:47,22
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-12-2014
Ran by azita21 (administrator) on MMM-PC on 01-01-2015 14:02:46
Running from c:\Users\azita21.mmm-PC\Downloads
Loaded Profile: azita21 (Available profiles: azita & azita21 & mmm)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 7 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Sony Corporation) C:\Program Files\sony\VAIO Update 5\VAIOUpdt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jusched.exe
(Sony Corporation) C:\Program Files\sony\ISB Utility\ISBMgr.exe
(Sony Corporation) C:\Program Files\sony\Marketing Tools\MarketingTools.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(McAfee, Inc.) C:\Program Files\McAfee.com\Agent\mcagent.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(Sony Corporation) C:\Program Files\sony\Network Utility\LANUtil.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
(McAfee, Inc.) C:\Program Files\McAfee\VirusScan\Mcshield.exe
(McAfee, Inc.) C:\Program Files\McAfee\MPF\MpfSrv.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSK\msksrver.exe
(Sony Corporation) C:\Program Files\sony\Network Utility\NSUService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ArcSoft, Inc.) C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files\sony\VAIO Event Service\VESMgr.exe
(Panda Security) C:\Program Files\Panda USB Vaccine\USBVaccine.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Sony Corporation) C:\Program Files\sony\VAIO Event Service\VESMgrSub.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSC\mcmscsvc.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe
(ALPS) C:\Program Files\Apoint\Apvfb.exe
(McAfee, Inc.) C:\Program Files\McAfee\VirusScan\mcsysmon.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6703648 2009-01-06] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint\Apoint.exe [155648 2009-04-13] (Alps Electric Co., Ltd.)
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35184 2008-12-03] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Java\jre6\bin\jusched.exe [136600 2009-05-15] (Sun Microsystems, Inc.)
HKLM\...\Run: [ISBMgr.exe] => C:\Program Files\Sony\ISB Utility\ISBMgr.exe [317288 2008-12-18] (Sony Corporation)
HKLM\...\Run: [StartCCC] => c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [61440 2009-02-10] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [McENUI] => C:\Program Files\McAfee\MHN\McENUI.exe [1176808 2008-09-12] (McAfee, Inc.)
HKLM\...\Run: [MarketingTools] => C:\Program Files\Sony\Marketing Tools\MarketingTools.exe [26624 2014-06-19] (Sony Corporation)
HKLM\...\Run: [mcagent_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [645328 2008-12-16] (McAfee, Inc.)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-04] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
Winlogon\Notify\VESWinlogon: C:\Windows\system32\VESWinlogon.dll (Sony Corporation)
HKU\S-1-5-21-3996859763-3761385545-3165565353-1001\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3996859763-3761385545-3165565353-1001\...\Run: [NSUFloatingUI] => C:\Program Files\Sony\Network Utility\LANUtil.exe [274432 2008-12-21] (Sony Corporation)
HKU\S-1-5-21-3996859763-3761385545-3165565353-1001\...\Run: [GoogleChromeAutoLaunch_058E7E9EBC9AFAD151F8EE0ED50FBC3A] => C:\Program Files\Google\Chrome\Application\chrome.exe [860488 2014-06-05] (Google Inc.)
HKU\S-1-5-21-3996859763-3761385545-3165565353-1001\...\Run: [genesis_08201850] => /r
HKU\S-1-5-21-3996859763-3761385545-3165565353-1001\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\azita21.mmm-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\azita21.mmm-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3996859763-3761385545-3165565353-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3996859763-3761385545-3165565353-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SNYT
SearchScopes: HKLM -> {EA6E82DD-9489-4B32-8E7B-5A97F7EF3395} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta=
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3996859763-3761385545-3165565353-1001 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SNYT
SearchScopes: HKU\S-1-5-21-3996859763-3761385545-3165565353-1001 -> {EA6E82DD-9489-4B32-8E7B-5A97F7EF3395} URL = hxxp://www.google.de/search?hl=de&q={searchTerms}&meta=
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> C:\Program Files\McAfee\MSK\MskAPBho.dll ()
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
BHO: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2014-06-20]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files\McAfee\SiteAdvisor [2014-06-19]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\azita21.mmm-PC\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Docs) - C:\Users\azita21.mmm-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-21]
CHR Extension: (Google Drive) - C:\Users\azita21.mmm-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-21]
CHR Extension: (YouTube) - C:\Users\azita21.mmm-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-21]
CHR Extension: (Google Search) - C:\Users\azita21.mmm-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-21]
CHR Extension: (SiteAdvisor) - C:\Users\azita21.mmm-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2014-07-21]
CHR Extension: (Avira Browserschutz) - C:\Users\azita21.mmm-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-28]
CHR Extension: (Gmail) - C:\Users\azita21.mmm-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-21]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - No Path
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2008-08-01] (ArcSoft Inc.)
S3 Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-07-01] (Adobe Systems) [File not signed]
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-12-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-04] (Avira Operations GmbH & Co. KG)
S2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG)
R2 EvtEng; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [860160 2008-08-20] (Intel(R) Corporation) [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [131136 2014-12-03] (McAfee, Inc.)
R2 mcmscsvc; C:\Program Files\McAfee\MSC\mcmscsvc.exe [797864 2008-12-16] (McAfee, Inc.)
R2 McNASvc; c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe [2482848 2008-10-24] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [365072 2008-12-13] (McAfee, Inc.)
R2 McProxy; c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe [359952 2008-10-23] (McAfee, Inc.)
R2 McShield; C:\Program Files\McAfee\VirusScan\Mcshield.exe [144704 2008-12-19] (McAfee, Inc.)
R3 McSysmon; C:\Program Files\McAfee\VirusScan\mcsysmon.exe [606736 2008-12-16] (McAfee, Inc.)
R2 MpfService; C:\Program Files\McAfee\MPF\MPFSrv.exe [884360 2008-12-05] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\McAfee\MSK\MskSrver.exe [26640 2008-11-25] (McAfee, Inc.)
R2 NSUService; C:\Program Files\sony\Network Utility\NSUService.exe [303104 2008-12-21] (Sony Corporation) [File not signed]
S3 PACSPTISVR; C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [114688 2009-01-07] (Sony Corporation) [File not signed]
S2 RegSrvc; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [466944 2008-08-20] (Intel(R) Corporation) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe [109088 2009-01-06] (Realtek Semiconductor)
S3 SOHDBSvr; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-02-05] (Sony Corporation)
S3 SOHPlMgr; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-02-05] (Sony Corporation)
R2 uCamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [104960 2008-09-18] (ArcSoft, Inc.)
S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [69632 2009-01-21] (Sony Corporation) [File not signed]
R2 VAIO Event Service; C:\Program Files\sony\VAIO Event Service\VESMgr.exe [203624 2009-01-19] (Sony Corporation)
S2 VAIO Power Management; C:\Program Files\Sony\VAIO Power Management\SPMService.exe [415592 2008-12-19] (Sony Corporation)
S3 VcmIAlzMgr; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [394536 2009-01-19] (Sony Corporation)
R3 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [313264 2009-01-21] (Sony Corporation)
S3 VUAgent; C:\Program Files\sony\VAIO Update 5\VUAgent.exe [722288 2010-04-09] (Sony Corporation)
R2 VzCdbSvc; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2009-01-21] (Sony Corporation) [File not signed]
R2 yksvc; C:\Windows\System32\ykx32mpcoinst.dll [282624 2009-02-10] (Marvell)
S2 3f17c95f; "C:\Windows\system32\rundll32.exe" "c:\progra~1\so_boo~1\AssistantSvc.dll",service
S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17920 2008-04-24] (ArcSoft, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-07] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-07] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2014-08-15] (Avira Operations GmbH & Co. KG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-01-01] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [79304 2008-12-19] (McAfee, Inc.)
R3 mfebopk; C:\Windows\System32\drivers\mfebopk.sys [35272 2008-12-19] (McAfee, Inc.)
R1 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [213640 2008-12-19] (McAfee, Inc.)
S3 mferkdk; C:\Windows\System32\drivers\mferkdk.sys [34216 2008-12-19] (McAfee, Inc.)
R3 mfesmfk; C:\Windows\System32\drivers\mfesmfk.sys [40552 2008-12-19] (McAfee, Inc.)
R1 MPFP; C:\Windows\System32\Drivers\Mpfp.sys [130424 2008-10-23] (McAfee, Inc.)
R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [155808 2009-02-23] (Realtek Semiconductor Corp.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2014-08-15] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 igfx; system32\DRIVERS\igdkmd32.sys [X]
S3 IntcHdmiAddService; system32\drivers\IntcHdmi.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S4 UIUSys; system32\DRIVERS\UIUSYS.SYS [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-01 13:57 - 2015-01-01 13:57 - 00001342 _____ () C:\Users\azita21.mmm-PC\Desktop\JRT.txt
2015-01-01 13:50 - 2015-01-01 13:50 - 00001295 _____ () C:\Users\azita21.mmm-PC\Desktop\AdwCleaner[S2].txt
2015-01-01 13:49 - 2015-01-01 13:49 - 00000000 ____D () C:\Windows\ERUNT
2015-01-01 13:48 - 2015-01-01 13:48 - 01707939 _____ (Thisisu) C:\Users\azita21.mmm-PC\Downloads\JRT.exe
2015-01-01 13:30 - 2015-01-01 13:30 - 02173952 _____ () C:\Users\azita21.mmm-PC\Desktop\AdwCleaner_4.106.exe
2015-01-01 13:30 - 2015-01-01 13:30 - 00001717 _____ () C:\Users\azita21.mmm-PC\Desktop\mbam.txt
2015-01-01 13:28 - 2015-01-01 13:28 - 00001002 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-01-01 12:19 - 2015-01-01 13:47 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-01 12:19 - 2015-01-01 12:19 - 00000899 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-01-01 12:19 - 2015-01-01 12:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-01 12:18 - 2015-01-01 12:19 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-01-01 12:18 - 2015-01-01 12:18 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-01 12:18 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-01 12:18 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-01 12:18 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-01-01 12:12 - 2015-01-01 12:12 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\azita21.mmm-PC\Downloads\mbam-setup-2.0.4.1028.exe
2015-01-01 00:08 - 2015-01-01 00:08 - 00031317 _____ () C:\ComboFix.txt
2014-12-31 23:38 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-12-31 23:38 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-12-31 23:38 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-12-31 23:38 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-12-31 23:38 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-12-31 23:38 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-12-31 23:38 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-12-31 23:38 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-12-31 23:18 - 2015-01-01 00:08 - 00000000 ____D () C:\Qoobox
2014-12-31 23:17 - 2015-01-01 00:06 - 00000000 ____D () C:\Windows\erdnt
2014-12-31 23:16 - 2014-12-31 23:17 - 00848856 _____ (Panda Security ) C:\Users\azita21.mmm-PC\Downloads\USBVaccineSetup (1).exe
2014-12-31 23:14 - 2014-12-31 23:14 - 05604036 ____R (Swearware) C:\Users\azita21.mmm-PC\Downloads\ComboFix.exe
2014-12-31 23:13 - 2014-12-31 23:13 - 00000000 ____D () C:\ProgramData\Panda Security
2014-12-31 23:13 - 2014-12-31 23:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security
2014-12-31 23:13 - 2014-12-31 23:13 - 00000000 ____D () C:\Program Files\Panda USB Vaccine
2014-12-31 23:12 - 2014-12-31 23:12 - 00848856 _____ (Panda Security ) C:\Users\azita21.mmm-PC\Downloads\USBVaccineSetup.exe
2014-12-31 23:03 - 2014-12-31 23:03 - 00001057 _____ () C:\Users\azita21.mmm-PC\Desktop\Revo Uninstaller.lnk
2014-12-31 23:03 - 2014-12-31 23:03 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-12-31 23:02 - 2014-12-31 23:02 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\azita21.mmm-PC\Downloads\revosetup95.exe
2014-12-31 23:02 - 2014-12-31 23:02 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\azita21.mmm-PC\Downloads\revosetup95 (1).exe
2014-12-31 11:29 - 2014-12-31 11:36 - 00033090 _____ () C:\Users\azita21.mmm-PC\Downloads\Addition.txt
2014-12-31 11:27 - 2015-01-01 14:02 - 00022474 _____ () C:\Users\azita21.mmm-PC\Downloads\FRST.txt
2014-12-31 11:26 - 2015-01-01 14:02 - 00000000 ____D () C:\FRST
2014-12-31 11:25 - 2014-12-31 11:26 - 01114624 _____ (Farbar) C:\Users\azita21.mmm-PC\Downloads\FRST.exe
2014-12-31 11:02 - 2014-11-24 14:04 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-12-30 23:50 - 2014-12-31 23:38 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-12-30 23:38 - 2014-12-30 23:39 - 11473216 _____ (Microsoft Corporation) C:\Users\azita21.mmm-PC\Downloads\MSEInstall (1).exe
2014-12-30 23:38 - 2014-12-30 23:38 - 14107296 _____ (Microsoft Corporation) C:\Users\azita21.mmm-PC\Downloads\MSEInstall.exe
2014-12-30 21:17 - 2014-12-30 21:20 - 13947406 _____ () C:\Users\azita21.mmm-PC\Downloads\Install_FD10DXZ_Trial.zip
2014-12-23 00:50 - 2014-12-23 00:51 - 00088641 _____ () C:\Users\azita21.mmm-PC\Downloads\hamburg_alstertanne_weihnacht_tanne_alster_jungfernstieg_michel_3666386309_600x450xcr.jpeg
2014-12-16 01:36 - 2014-12-16 01:36 - 05948992 _____ () C:\Users\azita21.mmm-PC\Downloads\Fragile lyrics - Tech N9ne (Kendall Morgan, Kendrick Lamar & ¡Mayday!).mp4
2014-12-15 21:55 - 2014-12-15 22:03 - 167650716 _____ () C:\Users\azita21.mmm-PC\Downloads\In Fashion- Sir Paul Smith interview.mp4
2014-12-12 02:26 - 2014-12-12 02:28 - 152333158 _____ () C:\Users\azita21.mmm-PC\Downloads\Sensational S'more Cones!! - Camp Food Pt.2.mp4
2014-12-12 02:25 - 2014-12-12 02:28 - 190470924 _____ () C:\Users\azita21.mmm-PC\Downloads\Boys Gone Wild - Camp Food Pt.1.mp4
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-01 13:46 - 2014-06-19 23:35 - 00034391 _____ () C:\Windows\system32\Config.MPF
2015-01-01 13:40 - 2008-01-21 03:47 - 00591582 _____ () C:\Windows\PFRO.log
2015-01-01 13:40 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-01 13:40 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-01 13:40 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-01 13:39 - 2014-06-19 23:16 - 01759123 _____ () C:\Windows\WindowsUpdate.log
2015-01-01 13:39 - 2009-05-15 09:57 - 00000012 _____ () C:\Windows\bthservsdp.dat
2015-01-01 13:39 - 2006-11-02 14:01 - 00026150 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-01-01 13:38 - 2014-07-12 15:55 - 00000000 ____D () C:\AdwCleaner
2015-01-01 13:28 - 2014-08-28 17:32 - 00000000 ____D () C:\ProgramData\Package Cache
2015-01-01 13:28 - 2014-08-28 16:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-01-01 13:28 - 2014-08-28 16:36 - 00000000 ____D () C:\Program Files\Avira
2015-01-01 13:13 - 2014-07-07 00:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-01 00:59 - 2014-06-19 23:31 - 00000348 _____ () C:\Windows\Tasks\McQcTask.job
2015-01-01 00:08 - 2006-11-02 12:18 - 00000000 __RHD () C:\Users\Default
2015-01-01 00:08 - 2006-11-02 12:18 - 00000000 ___RD () C:\Users\Public
2014-12-31 23:59 - 2006-11-02 11:23 - 00000215 _____ () C:\Windows\system.ini
2014-12-31 00:23 - 2014-08-21 23:00 - 00000000 ____D () C:\Users\azita21.mmm-PC\Desktop\tomo
2014-12-31 00:05 - 2014-06-19 23:30 - 00000000 ____D () C:\Program Files\McAfee
2014-12-30 20:57 - 2008-01-21 08:16 - 01565124 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-23 00:51 - 2014-09-03 00:58 - 155762616 _____ () C:\Users\azita21.mmm-PC\Downloads\How to Talk to Your Crush.mp4
2014-12-16 02:22 - 2006-11-02 13:52 - 00107520 _____ () C:\Windows\setupact.log
2014-12-15 01:00 - 2014-06-19 23:31 - 00000372 _____ () C:\Windows\Tasks\McDefragTask.job
2014-12-12 11:33 - 2014-06-19 23:37 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-11 01:13 - 2014-07-07 00:54 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-12-11 01:13 - 2014-07-07 00:54 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-12-06 18:36 - 2014-09-16 00:39 - 180013387 _____ () C:\Users\azita21.mmm-PC\Downloads\The What If- Game Ft. Daniel Radcliffe (1).mp4
2014-12-06 18:35 - 2014-09-16 00:43 - 46816571 _____ () C:\Users\azita21.mmm-PC\Downloads\Epic Rap Battle- Nerd vs. Geek (1).mp4
2014-12-06 18:35 - 2014-09-16 00:42 - 103218786 _____ () C:\Users\azita21.mmm-PC\Downloads\Daniel Radcliffe Talks About The Friend Zone.mp4
Some content of TEMP:
====================
C:\Users\azita21.mmm-PC\AppData\Local\Temp\avgnt.exe
C:\Users\azita21.mmm-PC\AppData\Local\Temp\Quarantine.exe
C:\Users\azita21.mmm-PC\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-01 13:51
==================== End Of Log ============================ --- --- ---
--- --- --- |