|
Log-Analyse und Auswertung: Schädliche objekte gefundenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
27.12.2014, 14:57 | #1 |
| Schädliche objekte gefunden Guten tag ich habe folgendes Problem: ZUerst habe ich MBAM gedownloadet und gescant. Dann hat er mir über 200 Viren gemeldet, die ich in Quarantäne gesetzt hab. Mozilla ist ganz voll mit werbung und es öffnen sich mehrere Tabs beim surfen. Der Computer ist nur für private zwecke genutzt worden und wird auch nur so genutzt. Ich hoffe auf eure unterstützung, weil ich kein erfolg mit MBAM hab. FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 27-12-2014 Ran by Lene at 2014-12-27 14:21:27 Running from C:\Users\Lene\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.235 - Adobe Systems Incorporated) AMD USB Filter Driver (HKLM\...\{987B04C4-B5AC-4AD6-A7E9-8D681085B850}) (Version: 1.0.15.94 - Advanced Micro Devices, Inc.) AnySend (HKLM\...\ASPackage) (Version: 1.0.0.0 - CMI Limited) ATI Catalyst Install Manager (HKLM\...\{C7F73FB6-AC2B-A29A-334E-69C115E95E03}) (Version: 3.0.765.0 - ATI Technologies, Inc.) BurnAware Free 7.5 (HKLM\...\BurnAware Free_is1) (Version: - Burnaware) ccc-core-static (Version: 2010.0302.2233.40412 - Ihr Firmenname) Hidden CheckMeUp (HKLM\...\75E675FE-B240-F4A0-3D1C-C145C06FEA10) (Version: - CheckMeUp-software) ConvertAd (HKLM\...\ConvertAd) (Version: 1.0.0.0 - ConvertAd) <==== ATTENTION! coupcoup (HKLM\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version: - coupcoup) <==== ATTENTION Desktop Icon für Amazon (HKLM\...\DesktopIconAmazon) (Version: 1.0.1 (de) - CHIP.de) DivX-Setup (HKLM\...\DivX Setup) (Version: 2.7.0.31 - DivX, LLC) Free YouTube to MP3 Converter version 3.12.44.908 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.44.908 - DVDVideoSoft Ltd.) JFileManager (HKLM\...\JFileManager) (Version: v1.0.0.1 - ) Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation) Mozilla Firefox 34.0 (x86 de) (HKLM\...\Mozilla Firefox 34.0 (x86 de)) (Version: 34.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 32.0.1 - Mozilla) Optimizer Pro v3.2 (HKLM\...\Optimizer Pro_is1) (Version: 3.2.0.3 - PC Utilities Software Limited) <==== ATTENTION Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.) PriceLess (HKLM\...\{75F9BF4A-AF67-A478-A37B-31D73186D3F3}) (Version: 4.3.0.1958 - ) Realtek HDMI Audio Driver for ATI (HKLM\...\{5449FB4F-1802-4D5B-A6D8-087DB1142147}) (Version: 6.0.1.6034 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6069 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30116 - Realtek Semiconductor Corp.) Remote Desktop Access (VuuPC) (HKLM\...\VOPackage) (Version: 1.0.0.0 - CMI Limited) <==== ATTENTION Setting Utility Series (HKLM\...\{A7DA438C-2E43-4C20-BFDA-C1F4A6208558}) (Version: 5.2.0.15250 - Sony Corporation) Skype™ 6.21 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.) Spotify (HKU\S-1-5-21-1521733554-1607495114-2559871037-1000\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB) Super Optimizer v3.2 (HKLM\...\Super Optimizer_is1) (Version: 3.2.0.1 - Super PC Tools ltd) Support PL 1.1 (HKLM\...\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{40030ae4}) (Version: - PriceLess) <==== ATTENTION tricomfi (HKLM\...\{74f1e872-8d6f-4cc7-58d6-c60d8dfe43ed}) (Version: 1.0.0 - estdemin) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden Windows Driver Package - Sony Corporation (SFEP) HIDClass (11/27/2009 8.0.1.2) (HKLM\...\4E827A70BAA738C408DBDD024BCACE5085D946F1) (Version: 11/27/2009 8.0.1.2 - Sony Corporation) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1521733554-1607495114-2559871037-1000_Classes\CLSID\{33C53A50-F456-4884-B049-85FD643ECFED}\InprocServer32 -> No File CustomCLSID: HKU\S-1-5-21-1521733554-1607495114-2559871037-1000_Classes\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InprocServer32 -> C:\Users\Lene\AppData\Roaming\tricomfi\colers.dll () <==== ATTENTION ==================== Restore Points ========================= 27-11-2014 22:30:00 Scheduled Checkpoint 07-12-2014 12:04:39 Scheduled Checkpoint 11-12-2014 01:46:57 Windows Update 18-12-2014 20:05:07 Scheduled Checkpoint 18-12-2014 20:07:05 Windows Update 26-12-2014 03:21:27 Scheduled Checkpoint 27-12-2014 13:06:41 Removed TuneUp Utilities 2014 27-12-2014 13:07:28 TuneUp Utilities 2014 (de-DE) wird entfernt ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {09991328-C3F1-499F-AC4A-234999732BFE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-27] (Adobe Systems Incorporated) Task: {51BDA5DC-137D-4715-BD35-6642124C5688} - \upfs7235 No Task File <==== ATTENTION Task: {5FF1378A-0786-4C5F-8A86-2AE4BA34F316} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files\CHIP Updater\CHIPUpdater.exe Task: {9362B837-A631-488E-B0E3-579A5530C904} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files\Optimizer Pro 3.16\OptProLauncher.exe [2014-12-19] (PC Utilities Software Limited) <==== ATTENTION Task: {9FC557D4-9EBD-4372-B33E-497C8635492B} - System32\Tasks\amiupdaterExd => cmd.exe /c start /min bitsadmin /transfer amijob /download /priority high hxxp://d17xr4aw9ok0me.cloudfront.net/Updater.exe "C:\Users\Lene\AppData\Local\Temp\amiupdater1424.exe" Task: {D54E8DF1-F3E4-492A-8BDA-9A989E3CB471} - System32\Tasks\amiupdaterExi => C:\Users\Lene\AppData\Local\Temp\amiupdater1424.exe <==== ATTENTION Task: {D97AAC7A-F427-4C73-9614-CFA9B25C04F4} - System32\Tasks\{E769F3A2-F3AB-4747-87F0-2A574E49F372} => pcalua.exe -a C:\Users\Lene\AppData\Roaming\webssearches\UninstallManager.exe -c -ptid=brd (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2014-12-14 01:14 - 2014-12-14 01:14 - 04014184 _____ () c:\Program Files\Super Optimizer\SupOptCrash.dll 2014-01-10 06:26 - 2014-01-10 06:26 - 01861968 _____ () C:\Program Files\DivX\DivX Update\DivXUpdate.exe 2014-01-10 06:28 - 2014-01-10 06:28 - 00100688 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll 2008-08-26 10:41 - 2008-08-26 10:41 - 00016384 ____R () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll 2014-09-14 13:05 - 2014-09-14 13:05 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2014-06-13 10:37 - 2014-06-13 10:37 - 01354240 _____ () C:\Program Files\JFileManager\JFileManager.exe 2014-12-27 14:13 - 2014-12-27 14:13 - 00011264 _____ () C:\Users\Lene\AppData\Local\Temp\nst319C.tmp\System.dll 2014-12-27 14:13 - 2014-12-27 14:13 - 00117248 _____ () C:\Users\Lene\AppData\Local\Temp\nst319C.tmp\IpConfig.dll 2014-12-27 14:13 - 2014-12-27 14:13 - 05079632 _____ () c:\Program Files\Optimizer Pro 3.16\OptProMon.dll 2014-12-27 14:14 - 2014-12-27 14:14 - 00143872 _____ () C:\Users\Lene\AppData\Roaming\ASPackage\ASSrv.exe 2014-12-01 22:49 - 2014-12-01 22:49 - 03758192 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2014-12-09 15:26 - 2014-12-09 15:26 - 00133120 _____ () C:\Users\Lene\AppData\Roaming\tricomfi\colers.dll 2014-12-27 13:44 - 2014-12-27 13:44 - 16843952 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_235.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Users\Lene\Desktop\MOV00368.MPG:TOC.WMV ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-1521733554-1607495114-2559871037-500 - Administrator - Disabled) Guest (S-1-5-21-1521733554-1607495114-2559871037-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1521733554-1607495114-2559871037-1002 - Limited - Enabled) Lene (S-1-5-21-1521733554-1607495114-2559871037-1000 - Administrator - Enabled) => C:\Users\Lene ==================== Faulty Device Manager Devices ============= Name: Ethernet Controller Description: Ethernet Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (12/27/2014 02:13:51 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 34.0.0.5442, time stamp: 0x54754d35 Faulting module name: mozalloc.dll, version: 34.0.0.5442, time stamp: 0x54754649 Exception code: 0x80000003 Fault offset: 0x00001425 Faulting process id: 0x15a4 Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Error: (12/27/2014 02:12:58 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 34.0.0.5442, time stamp: 0x54754d35 Faulting module name: mozalloc.dll, version: 34.0.0.5442, time stamp: 0x54754649 Exception code: 0x80000003 Fault offset: 0x00001425 Faulting process id: 0x15c0 Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Error: (12/27/2014 02:08:24 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 34.0.0.5442, time stamp: 0x54754d35 Faulting module name: mozalloc.dll, version: 34.0.0.5442, time stamp: 0x54754649 Exception code: 0x80000003 Fault offset: 0x00001425 Faulting process id: 0x450 Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Error: (12/22/2014 06:29:34 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (12/22/2014 04:57:52 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 34.0.0.5442, time stamp: 0x54754d35 Faulting module name: mozalloc.dll, version: 34.0.0.5442, time stamp: 0x54754649 Exception code: 0x80000003 Fault offset: 0x00001425 Faulting process id: 0x61c Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Error: (12/20/2014 01:03:30 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: FlashPlayerPlugin_15_0_0_246.exe, version: 15.0.0.246, time stamp: 0x548108cd Faulting module name: FlashPlayerPlugin_15_0_0_246.exe, version: 15.0.0.246, time stamp: 0x548108cd Exception code: 0x40000015 Fault offset: 0x00017790 Faulting process id: 0x1370 Faulting application start time: 0xFlashPlayerPlugin_15_0_0_246.exe0 Faulting application path: FlashPlayerPlugin_15_0_0_246.exe1 Faulting module path: FlashPlayerPlugin_15_0_0_246.exe2 Report Id: FlashPlayerPlugin_15_0_0_246.exe3 Error: (12/18/2014 07:58:51 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (12/18/2014 07:58:48 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (12/17/2014 11:08:39 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 34.0.0.5442, time stamp: 0x54754d35 Faulting module name: mozalloc.dll, version: 34.0.0.5442, time stamp: 0x54754649 Exception code: 0x80000003 Fault offset: 0x00001425 Faulting process id: 0x14e8 Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Error: (12/14/2014 11:53:46 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 34.0.0.5442, time stamp: 0x54754d35 Faulting module name: mozalloc.dll, version: 34.0.0.5442, time stamp: 0x54754649 Exception code: 0x80000003 Fault offset: 0x00001425 Faulting process id: 0x61c Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 System errors: ============= Error: (12/27/2014 01:37:32 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (12/27/2014 01:37:32 PM) (Source: atikmdag) (EventID: 19468) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (12/27/2014 00:55:14 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (12/27/2014 01:53:46 AM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (12/26/2014 09:09:07 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (12/26/2014 07:53:47 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (12/26/2014 07:53:47 PM) (Source: atikmdag) (EventID: 19468) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (12/26/2014 06:21:56 PM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (12/26/2014 09:27:43 AM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Error: (12/26/2014 00:05:50 AM) (Source: atikmdag) (EventID: 10261) (User: ) Description: Display is not active Microsoft Office Sessions: ========================= Error: (12/27/2014 02:13:51 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe34.0.0.544254754d35mozalloc.dll34.0.0.544254754649800000030000142515a401d021d6edf8ff36C:\Program Files\Mozilla Firefox\plugin-container.exeC:\Program Files\Mozilla Firefox\mozalloc.dll33236f54-8dca-11e4-b0ed-9086907955f5 Error: (12/27/2014 02:12:58 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe34.0.0.544254754d35mozalloc.dll34.0.0.544254754649800000030000142515c001d021d64374abb1C:\Program Files\Mozilla Firefox\plugin-container.exeC:\Program Files\Mozilla Firefox\mozalloc.dll131fa2c6-8dca-11e4-b0ed-9086907955f5 Error: (12/27/2014 02:08:24 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe34.0.0.544254754d35mozalloc.dll34.0.0.544254754649800000030000142545001d021d6083620feC:\Program Files\Mozilla Firefox\plugin-container.exeC:\Program Files\Mozilla Firefox\mozalloc.dll7012f3f7-8dc9-11e4-b0ed-9086907955f5 Error: (12/22/2014 06:29:34 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"D:\Lene Backup\Lene\Downloads\iTunes64Setup.exe Error: (12/22/2014 04:57:52 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe34.0.0.544254754d35mozalloc.dll34.0.0.544254754649800000030000142561c01d01dfb84c2ae65C:\Program Files\Mozilla Firefox\plugin-container.exeC:\Program Files\Mozilla Firefox\mozalloc.dll48b95f37-89f3-11e4-81c4-fe6d86794de6 Error: (12/20/2014 01:03:30 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: FlashPlayerPlugin_15_0_0_246.exe15.0.0.246548108cdFlashPlayerPlugin_15_0_0_246.exe15.0.0.246548108cd4000001500017790137001d01bf458ea29adC:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exeC:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe360c7858-8840-11e4-9559-f2ea46d95de6 Error: (12/18/2014 07:58:51 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\Users\Lene\downloads\iTunes64Setup.exe Error: (12/18/2014 07:58:48 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\Users\Lene\downloads\iTunes64Setup.exe Error: (12/17/2014 11:08:39 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe34.0.0.544254754d35mozalloc.dll34.0.0.544254754649800000030000142514e801d01a457690c171C:\Program Files\Mozilla Firefox\plugin-container.exeC:\Program Files\Mozilla Firefox\mozalloc.dll40d559ef-8639-11e4-945f-f86328a95be6 Error: (12/14/2014 11:53:46 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe34.0.0.544254754d35mozalloc.dll34.0.0.544254754649800000030000142561c01d017dc04ae38d1C:\Program Files\Mozilla Firefox\plugin-container.exeC:\Program Files\Mozilla Firefox\mozalloc.dll0f005f68-83e4-11e4-bf90-bb28871511e6 ==================== Memory info =========================== Processor: AMD Athlon(tm) II P340 Dual-Core Processor Percentage of memory in use: 42% Total physical RAM: 3578.9 MB Available physical RAM: 2063.65 MB Total Pagefile: 7156.09 MB Available Pagefile: 5517.92 MB Total Virtual: 2047.88 MB Available Virtual: 1896.12 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:146.39 GB) (Free:105.36 GB) NTFS Drive d: () (Fixed) (Total:319.28 GB) (Free:286.42 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: F4B68721) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=146.4 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=319.3 GB) - (Type=07 NTFS) ==================== End Of Log ============================ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-12-2014 Ran by Lene (administrator) on LENE-PC on 27-12-2014 14:20:46 Running from C:\Users\Lene\Downloads Loaded Profile: Lene (Available profiles: Lene) Platform: Microsoft Windows 7 Enterprise Service Pack 1 (X86) OS Language: English (United States) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Spotify Ltd) C:\Users\Lene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe () C:\Program Files\JFileManager\JFileManager.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe ( ) C:\Users\Lene\AppData\Roaming\ASPackage\ASPackage.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe () C:\Users\Lene\AppData\Roaming\ASPackage\ASSrv.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_16_0_0_235.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_16_0_0_235.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-03-02] (Advanced Micro Devices, Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8546848 2010-07-01] (Realtek Semiconductor) HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM\...\RunOnce: [Update] => C:\Users\Lene\AppData\Roaming\ASPackage\ASPackage.exe [275125 2014-12-27] ( ) HKU\S-1-5-21-1521733554-1607495114-2559871037-1000\...\Run: [Spotify] => C:\Users\Lene\AppData\Roaming\Spotify\Spotify.exe [6737976 2014-12-13] (Spotify Ltd) HKU\S-1-5-21-1521733554-1607495114-2559871037-1000\...\Run: [Spotify Web Helper] => C:\Users\Lene\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-13] (Spotify Ltd) HKU\S-1-5-21-1521733554-1607495114-2559871037-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.) HKU\S-1-5-21-1521733554-1607495114-2559871037-1000\...\Run: [Super Optimizer] => C:\Program Files\Super Optimizer\SupOptLauncher.exe [676968 2014-11-19] (SUPER PC TOOLS LIMITED) HKU\S-1-5-21-1521733554-1607495114-2559871037-1000\...\Run: [Optimizer Pro] => C:\Program Files\Optimizer Pro 3.16\OptProLauncher.exe [148048 2014-12-19] (PC Utilities Software Limited) HKU\S-1-5-21-1521733554-1607495114-2559871037-1000\...\RunOnce: [Application Restart #0] => C:\Users\Lene\AppData\Local\Pokki\Engine\pokki.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-p (the data entry has 538 more characters). HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2014-09-16] (Microsoft Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\$McRebootA5E6DEAA56$.lnk ShortcutTarget: $McRebootA5E6DEAA56$.lnk -> (No File) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1521733554-1607495114-2559871037-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:49195;https=127.0.0.1:49195 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google HKU\S-1-5-21-1521733554-1607495114-2559871037-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-1521733554-1607495114-2559871037-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1521733554-1607495114-2559871037-1000 -> DefaultScope {9920011E-EF13-4B19-9587-C90506795729} URL = https://de.search.yahoo.com/search?fr=mcafee&type=B010DE80109D20140918&p={SearchTerms} SearchScopes: HKU\S-1-5-21-1521733554-1607495114-2559871037-1000 -> {9920011E-EF13-4B19-9587-C90506795729} URL = https://de.search.yahoo.com/search?fr=mcafee&type=B010DE80109D20140918&p={SearchTerms} BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default FF DefaultSearchEngine: Secure Search FF SearchEngineOrder.1: Secure Search FF SelectedSearchEngine: Secure Search FF Keyword.URL: https://de.search.yahoo.com/search?fr=mcafee&type=B110DE80109D20140918&p= FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_235.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml FF Extension: chineseperakungmailcom - C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\Extensions\chineseperakun@gmail.com [2014-12-17] FF Extension: offerapp - C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\Extensions\E00O3mnp@yry.com [2014-12-22] FF Extension: nitrodeal - C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\Extensions\jxbcN9@Qo5b.org [2014-12-22] FF Extension: PriceLess - C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\Extensions\OY2@A.net [2014-12-27] FF Extension: Cliqz Beta - C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\Extensions\cliqz@cliqz.com.xpi [2014-10-24] FF HKU\S-1-5-21-1521733554-1607495114-2559871037-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] FF HKU\S-1-5-21-1521733554-1607495114-2559871037-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\cliqz@cliqz.com Chrome: ======= CHR dev: Chrome dev build detected! <======= ATTENTION CHR Profile: C:\Users\Lene\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (PriceLess) - C:\Users\Lene\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpidcafopaofcojidolplknbfldoohbj [2014-12-27] CHR HKLM\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - No Path ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 0140311419685713mcinstcleanup; C:\Users\Lene\AppData\Local\Temp\014031~1.EXE [827456 2012-01-09] (McAfee, Inc.) R2 22134214; c:\Program Files\Super Optimizer\SupOptCrash.dll [4014184 2014-12-14] () R2 587ff355; c:\Program Files\Optimizer Pro 3.16\OptProMon.dll [5079632 2014-12-27] () R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.) R2 serveras; C:\Users\Lene\AppData\Roaming\ASPackage\ASSrv.exe [143872 2014-12-27] () [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2014-12-27] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation) R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [183584 2010-07-01] (Realtek Semiconductor Corp.) S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-27 14:20 - 2014-12-27 14:21 - 00011208 _____ () C:\Users\Lene\Downloads\FRST.txt 2014-12-27 14:20 - 2014-12-27 14:20 - 00000000 ____D () C:\FRST 2014-12-27 14:16 - 2014-12-27 14:16 - 01114624 _____ (Farbar) C:\Users\Lene\Downloads\FRST.exe 2014-12-27 14:16 - 2014-12-27 14:16 - 00000000 ____D () C:\Users\Lene\AppData\Local\ConvertAd 2014-12-27 14:14 - 2014-12-27 14:14 - 00000394 __RSH () C:\ProgramData\ntuser.pol 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\Lene\Documents\Optimizer Pro 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\Lene\AppData\Roaming\Optimizer Pro 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\Lene\AppData\Local\Torch 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\Lene\AppData\Local\Comodo 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\Lene\AppData\Local\Chromatic Browser 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\Guest\AppData\Local\Chromatic Browser 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\Guest 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\Administrator 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\ProgramData\PriceLess 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Program Files\Supporter 2014-12-27 14:14 - 2014-12-27 14:14 - 00000000 ____D () C:\Program Files\PriceLess 2014-12-27 14:13 - 2014-12-27 14:14 - 00000000 ____D () C:\Users\Lene\AppData\Roaming\ASPackage 2014-12-27 14:13 - 2014-12-27 14:13 - 00001061 _____ () C:\Users\Lene\Desktop\Optimizer Pro.lnk 2014-12-27 14:13 - 2014-12-27 14:13 - 00000000 ____D () C:\Users\Lene\AppData\Roaming\VOPackage 2014-12-27 14:13 - 2014-12-27 14:13 - 00000000 ____D () C:\Users\Lene\AppData\Roaming\tricomfi 2014-12-27 14:13 - 2014-12-27 14:13 - 00000000 ____D () C:\Users\Lene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASPackage 2014-12-27 14:13 - 2014-12-27 14:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 2014-12-27 14:13 - 2014-12-27 14:13 - 00000000 ____D () C:\Program Files\Optimizer Pro 3.16 2014-12-27 14:12 - 2014-12-27 14:13 - 00000000 ____D () C:\Program Files\ver9CheckMeUp 2014-12-27 14:12 - 2014-12-27 14:12 - 00001111 _____ () C:\Users\Public\Desktop\JFileManager.lnk 2014-12-27 14:12 - 2014-12-27 14:12 - 00000000 ____D () C:\Users\Lene\AppData\Local\JFileManager 2014-12-27 14:12 - 2014-12-27 14:12 - 00000000 ____D () C:\ProgramData\PicColor Utility 2014-12-27 14:12 - 2014-12-27 14:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JFileManager 2014-12-27 14:12 - 2014-12-27 14:12 - 00000000 ____D () C:\Program Files\JFileManager 2014-12-27 14:11 - 2014-12-27 14:11 - 00602488 _____ () C:\Users\Lene\Downloads\Setup.exe 2014-12-27 13:18 - 2014-12-27 13:38 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-12-27 13:17 - 2014-12-27 13:17 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-12-27 13:17 - 2014-12-27 13:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-12-27 13:17 - 2014-12-27 13:17 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-12-27 13:17 - 2014-12-27 13:17 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-12-27 13:17 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-12-27 13:17 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-12-27 13:17 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-12-27 13:16 - 2014-12-27 13:16 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Lene\Downloads\mbam-setup-2.0.4.1028.exe 2014-12-22 16:58 - 2014-12-27 13:35 - 00000000 ____D () C:\ProgramData\lowrate 2014-12-22 16:58 - 2014-12-27 13:35 - 00000000 ____D () C:\ProgramData\appsave 2014-12-22 16:58 - 2014-12-22 16:58 - 00000000 ____D () C:\ProgramData\coupcoup 2014-12-22 16:57 - 2014-12-27 14:14 - 00000000 ____D () C:\ProgramData\5ad395635c7a923c 2014-12-18 12:45 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-12-14 01:37 - 2014-12-14 01:37 - 00359656 _____ (Microsoft Corporation) C:\Users\Lene\Desktop\msicuu2.exe 2014-12-14 01:32 - 2014-12-14 01:33 - 00000000 ____D () C:\Program Files\Common Files\DivX Shared 2014-12-14 01:32 - 2014-12-14 01:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX 2014-12-14 01:31 - 2014-12-14 01:33 - 00000000 ____D () C:\Program Files\DivX 2014-12-14 01:29 - 2014-12-14 01:29 - 00957248 _____ (DivX, LLC) C:\Users\Lene\Downloads\DivXInstaller_913.exe 2014-12-14 01:14 - 2014-12-14 01:14 - 00001048 _____ () C:\Users\Lene\Desktop\Super Optimizer.lnk 2014-12-14 01:14 - 2014-12-14 01:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Super Optimizer 2014-12-14 01:14 - 2014-12-14 01:14 - 00000000 ____D () C:\Program Files\Super Optimizer 2014-12-14 01:14 - 2014-12-14 01:14 - 00000000 ____D () C:\Program Files\predm 2014-12-14 01:07 - 2014-12-14 01:33 - 00000000 ____D () C:\ProgramData\DivX 2014-12-14 01:06 - 2014-12-14 21:24 - 00000000 ____D () C:\Program Files\globalUpdate 2014-12-14 01:06 - 2014-12-14 01:06 - 00000000 ____D () C:\Users\Lene\AppData\Local\globalUpdate 2014-12-14 00:47 - 2014-12-14 00:47 - 00001087 _____ () C:\Users\Lene\Desktop\Continue Live Installation.lnk 2014-12-14 00:44 - 2014-12-14 00:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-12-14 00:44 - 2014-12-14 00:44 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-12-14 00:43 - 2014-12-14 00:43 - 00000000 __SHD () C:\Users\Lene\AppData\Local\EmieUserList 2014-12-14 00:43 - 2014-12-14 00:43 - 00000000 __SHD () C:\Users\Lene\AppData\Local\EmieSiteList 2014-12-14 00:43 - 2014-12-14 00:43 - 00000000 __SHD () C:\Users\Lene\AppData\Local\EmieBrowserModeList 2014-12-14 00:42 - 2014-12-27 14:13 - 00000000 ____D () C:\Users\Lene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage 2014-12-14 00:42 - 2014-12-17 23:11 - 00000000 ____D () C:\Users\Lene\AppData\Roaming\mystartsearch 2014-12-14 00:41 - 2014-12-14 01:24 - 00000002 _____ () C:\END 2014-12-14 00:40 - 2014-12-14 01:03 - 00001177 _____ () C:\Users\Lene\Desktop\Continue installation .lnk 2014-12-10 13:09 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-12-10 13:09 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-12-10 13:09 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-12-10 13:09 - 2014-11-22 03:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-12-10 13:09 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-12-10 13:09 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-12-10 13:09 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-12-10 13:09 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-12-10 13:09 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-12-10 13:09 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-12-10 13:09 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-12-10 13:09 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-12-10 13:09 - 2014-11-22 02:55 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-12-10 13:09 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-12-10 13:09 - 2014-11-22 02:48 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-12-10 13:09 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-12-10 13:09 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-12-10 13:09 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-12-10 13:09 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-12-10 13:09 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-12-10 13:09 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-12-10 13:09 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-12-10 13:09 - 2014-11-22 02:23 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-12-10 13:09 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-12-10 13:09 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-12-10 13:09 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-12-10 13:09 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-12-10 13:09 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-12-10 13:09 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-12-10 13:09 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-12-07 00:17 - 2014-12-07 02:43 - 00000000 ____D () C:\Users\Lene\Desktop\DESPERATE 2014-12-05 22:23 - 2014-12-05 22:24 - 00000000 ____D () C:\Users\Lene\Desktop\Straw Dogs 2014-12-05 22:20 - 2014-12-05 22:20 - 00000000 ____D () C:\Users\Lene\Desktop\Pulp Fiction 2014-12-05 22:18 - 2014-12-05 22:19 - 00000000 ____D () C:\Users\Lene\Desktop\catch me if you can 2014-12-05 22:06 - 2009-02-19 21:44 - 07523355 _____ () C:\Users\Lene\Desktop\MOV00368.MPG 2014-12-05 13:48 - 2014-12-05 13:49 - 00000000 _____ () C:\Users\Lene\Downloads\Free_Download_Jessica_Alba_Sex_Tape_zip.exe 2014-12-01 22:49 - 2014-12-14 01:33 - 00000000 ____D () C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-27 14:14 - 2014-10-11 18:45 - 00000000 ____D () C:\Users\Lene\AppData\Local\Google 2014-12-27 14:14 - 2014-09-13 16:21 - 01364889 _____ () C:\Windows\WindowsUpdate.log 2014-12-27 14:14 - 2009-07-14 03:37 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-12-27 14:11 - 2014-09-14 14:53 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-12-27 14:10 - 2014-09-18 20:58 - 00000000 ____D () C:\Users\Lene\AppData\Roaming\Skype 2014-12-27 14:08 - 2014-09-18 20:39 - 00000000 ____D () C:\Program Files\McAfee 2014-12-27 14:08 - 2014-09-14 14:53 - 00000000 ____D () C:\ProgramData\McAfee 2014-12-27 14:06 - 2009-07-14 05:39 - 00034404 _____ () C:\Windows\setupact.log 2014-12-27 13:58 - 2014-10-24 17:10 - 00000000 ____D () C:\Users\Lene\AppData\Local\Spotify 2014-12-27 13:58 - 2014-10-24 17:09 - 00000000 ____D () C:\Users\Lene\AppData\Roaming\Spotify 2014-12-27 13:44 - 2014-09-14 14:53 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-12-27 13:44 - 2014-09-14 14:53 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-12-27 13:44 - 2014-09-14 14:43 - 00000000 ____D () C:\Users\Lene\AppData\Local\Adobe 2014-12-27 13:37 - 2014-09-17 22:31 - 00144006 _____ () C:\Windows\PFRO.log 2014-12-27 13:37 - 2014-09-14 00:01 - 00000000 ____D () C:\Windows\Panther 2014-12-27 13:37 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-27 13:36 - 2009-07-14 05:34 - 00016000 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-12-27 13:36 - 2009-07-14 05:34 - 00016000 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-12-18 21:16 - 2014-10-11 18:49 - 00000821 ____H () C:\Users\Lene\Downloads\.picasa.ini 2014-12-17 23:11 - 2014-09-14 12:47 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-12-17 23:11 - 2014-09-14 12:47 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-12-17 23:11 - 2014-09-13 16:31 - 00001417 _____ () C:\Users\Lene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-12-17 13:12 - 2009-07-14 05:53 - 00032610 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-12-14 01:37 - 2014-09-13 16:30 - 00000000 ____D () C:\Users\Lene\AppData\Local\VirtualStore 2014-12-14 01:36 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public 2014-12-14 01:24 - 2014-10-24 17:08 - 00000000 ____D () C:\Program Files\CHIP Updater 2014-12-14 01:06 - 2014-10-11 18:45 - 00000000 ____D () C:\Program Files\Google 2014-12-12 03:47 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache 2014-12-05 20:39 - 2014-09-13 16:30 - 00781298 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-02 18:08 - 2014-09-14 12:47 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service Some content of TEMP: ==================== C:\Users\Lene\AppData\Local\Temp\0140311419685713mcinst.exe C:\Users\Lene\AppData\Local\Temp\18be6784_.exe C:\Users\Lene\AppData\Local\Temp\19F6CDA6-63CB-6C2E-3270-1C58A8782151.dll C:\Users\Lene\AppData\Local\Temp\19F6CDA6-63CB-6C2E-3270-1C58A8782151.exe C:\Users\Lene\AppData\Local\Temp\294823_.exe C:\Users\Lene\AppData\Local\Temp\32339A14-32B0-97B6-FED3-850BD13415A2.exe C:\Users\Lene\AppData\Local\Temp\DseShExt-x86.dll C:\Users\Lene\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Lene\AppData\Local\Temp\install_flashplayer15x32_mssa_aaa_aih.exe C:\Users\Lene\AppData\Local\Temp\mdimqd6s.dll C:\Users\Lene\AppData\Local\Temp\optprosetup.exe C:\Users\Lene\AppData\Local\Temp\SDShelEx-win32.dll C:\Users\Lene\AppData\Local\Temp\SpOrder.dll C:\Users\Lene\AppData\Local\Temp\supoptsetup.exe C:\Users\Lene\AppData\Local\Temp\System.Data.SQLite.dll C:\Users\Lene\AppData\Local\Temp\System.Data.SQLiteca38769c-9532-4af6-ba46-5d2afc10488d.dll C:\Users\Lene\AppData\Local\Temp\tmd_34016317.exe C:\Users\Lene\AppData\Local\Temp\tmd_34019819.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-26 03:14 ==================== End Of Log ============================ --- --- --- |
27.12.2014, 15:37 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Schädliche objekte gefunden Hi und
__________________bitte alle Logs mit Funden von Malwarebytes posten Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
27.12.2014, 15:47 | #3 |
| Schädliche objekte gefundenCode:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 27.12.2014 Scan Time: 13:51:07 Logfile: log 1.txt Administrator: Yes Version: 2.00.4.1028 Malware Database: v2014.12.27.04 Rootkit Database: v2014.12.23.02 License: Trial Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x86 File System: NTFS User: Lene Scan Type: Hyper Scan Result: Completed Objects Scanned: 259307 Time Elapsed: 8 min, 5 sec Memory: Enabled Startup: Enabled Filesystem: Disabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 0 (No malicious items detected) Files: 0 (No malicious items detected) Physical Sectors: 0 (No malicious items detected) (end) Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Protection, 27.12.2014 13:18:03, SYSTEM, LENE-PC, Protection, Malware Protection, Starting, Protection, 27.12.2014 13:18:03, SYSTEM, LENE-PC, Protection, Malware Protection, Started, Protection, 27.12.2014 13:18:03, SYSTEM, LENE-PC, Protection, Malicious Website Protection, Starting, Update, 27.12.2014 13:18:07, SYSTEM, LENE-PC, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1, Update, 27.12.2014 13:18:08, SYSTEM, LENE-PC, Manual, Rootkit Database, 2014.11.18.1, 2014.12.23.2, Update, 27.12.2014 13:18:32, SYSTEM, LENE-PC, Manual, Malware Database, 2014.11.20.6, 2014.12.27.4, Protection, 27.12.2014 13:18:32, SYSTEM, LENE-PC, Protection, Refresh, Starting, Protection, 27.12.2014 13:18:43, SYSTEM, LENE-PC, Protection, Malicious Website Protection, Started, Protection, 27.12.2014 13:18:43, SYSTEM, LENE-PC, Protection, Malicious Website Protection, Stopping, Protection, 27.12.2014 13:18:43, SYSTEM, LENE-PC, Protection, Malicious Website Protection, Stopped, Protection, 27.12.2014 13:18:51, SYSTEM, LENE-PC, Protection, Refresh, Success, Protection, 27.12.2014 13:18:51, SYSTEM, LENE-PC, Protection, Malicious Website Protection, Starting, Protection, 27.12.2014 13:18:51, SYSTEM, LENE-PC, Protection, Malicious Website Protection, Started, Scan, 27.12.2014 13:36:08, SYSTEM, LENE-PC, Manual, Start:27.12.2014 13:19:09, Duration:14 min 29 sec, Threat Scan, Completed, 2 Malware Detections, 292 Non-Malware Detections, Protection, 27.12.2014 13:37:59, SYSTEM, LENE-PC, Protection, Malware Protection, Starting, Protection, 27.12.2014 13:38:00, SYSTEM, LENE-PC, Protection, Malware Protection, Started, Protection, 27.12.2014 13:38:00, SYSTEM, LENE-PC, Protection, Malicious Website Protection, Starting, Protection, 27.12.2014 13:38:48, SYSTEM, LENE-PC, Protection, Malicious Website Protection, Started, Scan, 27.12.2014 13:59:12, SYSTEM, LENE-PC, Manual, Start:27.12.2014 13:51:07, Duration:8 min 5 sec, Hyper Scan, Completed, 0 Malware Detections, 0 Non-Malware Detections, Detection, 27.12.2014 14:00:22, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 91.202.63.160, www.movie4k.to, 50455, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:00:22, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 91.202.63.160, www.movie4k.to, 50455, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:00:22, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 91.202.63.160, www.movie4k.to, 50456, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:11:08, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 51794, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:11:08, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 51794, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:12:04, Lene, LENE-PC, Protection, Malware Protection, File, PUP.Optional.StormWatch.A, C:\Users\Lene\AppData\Local\Temp\f0c864d2-35ad-47e0-b8d0-161138ef1467\setup.exe, Quarantine Failed, 303, Queued for removal on reboot, [438dbaad38441e18882a4b0a2cd47090] Detection, 27.12.2014 14:12:41, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.Tuto4PC.A, C:\Users\Lene\AppData\Local\Temp\ea4baba4-55da-4534-85a8-16d5b690f8fb\games desktop.exe, Quarantine Failed, 303, Queued for removal on reboot, [7060fd6a83f92511ffe8e513bb46936d] Detection, 27.12.2014 14:12:53, Lene, LENE-PC, Protection, Malware Protection, File, PUP.Optional.CheckMeUp.A, C:\Program Files\ver9CheckMeUp\sqlite3.dll, Quarantine, [7b55bfa8b1cb61d516df91c5ef143dc3] Detection, 27.12.2014 14:12:59, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility\RfndNSIS.dll, Quarantine, [765ab1b689f3999de2f3d67881825aa6] Detection, 27.12.2014 14:13:01, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.CheckMeUp.A, C:\Program Files\ver9CheckMeUp\x86\TandemRunner.exe, Quarantine, [fad6e384b9c390a6c134c393b74c09f7] Detection, 27.12.2014 14:13:02, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.CheckMeUp.A, C:\Program Files\ver9CheckMeUp\CheckMeUp.exe, Quarantine, [646cf077aece3afc2ec765f1010244bc] Detection, 27.12.2014 14:13:03, Lene, LENE-PC, Protection, Malware Protection, File, PUP.Optional.CheckMeUp.A, C:\Program Files\ver9CheckMeUp\l7CheckMeUpB49.exe, Quarantine, [2da32d3adaa2072f35c08fc727dc57a9] Detection, 27.12.2014 14:13:03, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.StartPage.A, C:\Users\Lene\AppData\Local\Temp\Wtmp2093455\BaofengUpdate.exe, Quarantine, [60704d1ad5a78fa7396d777d8a77867a] Detection, 27.12.2014 14:14:03, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.Multiplug, C:\Program Files\PriceLess\xxaaEzTs6dlEyq.dll, Quarantine, [3799adba2d4fd4629896d302d42ea957] Detection, 27.12.2014 14:14:04, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.Multiplug, C:\Program Files\PriceLess\xxaaEzTs6dlEyq.x64.dll, Quarantine, [a62a4126d5a771c5e14c5d78c83aae52] Detection, 27.12.2014 14:14:24, Lene, LENE-PC, Protection, Malware Protection, File, PUP.Optional.Supporter.A, C:\Program Files\Supporter\Supporter.dll, Quarantine, [8d43f0770c70f93d01090f4ed2315ba5] Detection, 27.12.2014 14:16:06, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 52787, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:16:06, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 52788, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:16:06, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 52793, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:16:32, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.ConvertAd.A, C:\Users\Lene\AppData\Local\ConvertAd\CAWrapper.exe, Quarantine, [19b72a3d03798fa7923d232e4eb5e61a] Detection, 27.12.2014 14:16:35, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.ConvertAd.A, C:\Users\Lene\AppData\Local\ConvertAd\CASrv.exe, Quarantine, [efe14c1bdba147ef9837cd8421e26d93] Detection, 27.12.2014 14:17:50, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 5.150.195.167, 3c45d848d99.se, 52959, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:17:50, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 5.150.195.167, 3c45d848d99.se, 52959, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:17:52, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 52970, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:18:07, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 53029, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:18:10, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 53033, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:18:13, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 53045, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:18:24, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 53051, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:18:27, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 53053, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:18:31, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 53061, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:18:42, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 53070, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:18:52, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 53078, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:18:59, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 53088, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:19:15, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 53098, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:19:48, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 53160, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:20:00, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 53164, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:20:21, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 53179, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:20:38, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 53199, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:25:13, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.Linkury.A, C:\Program Files\PennyBee\PennyBee.exe, Quarantine, [c010590ecdafa690f16e94b408fba55b] Detection, 27.12.2014 14:25:15, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.Linkury.A, C:\Program Files\PennyBee\PennyBeeU.exe, Quarantine, [1eb25c0b522ad26466f975d3699af50b] Detection, 27.12.2014 14:25:23, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.Tuto4PC.A, C:\Users\Lene\AppData\Local\Temp\nsxD9D1.tmp, Quarantine, [517f88dfd8a4e55117d0ba3e629f4bb5] Detection, 27.12.2014 14:25:23, Lene, LENE-PC, Protection, Malware Protection, File, PUP.Optional.SmartBar, C:\Windows\Installer\MSI9C0.tmp, Quarantine Failed, 2, The system cannot find the file specified. , [ece46106d1ab88ae7ffe34fa45bb9070] Detection, 27.12.2014 14:25:24, Lene, LENE-PC, Protection, Malware Protection, File, PUP.Optional.SmartBar, C:\Windows\Installer\MSIB28.tmp, Quarantine, [a52bc2a53547e551a0dd2e00ff018b75] Detection, 27.12.2014 14:25:26, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.SmartWeb.A, C:\Users\Lene\AppData\Local\Temp\nsnA56.tmp, Quarantine, [616fd592bcc0c175d462c12fed1407f9] Detection, 27.12.2014 14:27:30, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.CheckMeUp.A, c:\program files\ver9checkmeup\l7checkmeupb49.exe, Quarantine Failed, 2, The system cannot find the file specified. , [2da32d3adaa2072f35c08fc727dc57a9] Detection, 27.12.2014 14:27:48, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.ConvertAd.A, C:\Users\Lene\AppData\Local\ConvertAd\CAWrapper.exe, Quarantine Failed, 2, The system cannot find the file specified. , [19b72a3d03798fa7923d232e4eb5e61a] Detection, 27.12.2014 14:27:51, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.ConvertAd.A, C:\Users\Lene\AppData\Local\ConvertAd\CASrv.exe, Quarantine, [efe14c1bdba147ef9837cd8421e26d93] Detection, 27.12.2014 14:27:57, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 93.103.86.92, 1000, Outbound, C:\Program Files\JFileManager\JFileManager.exe, Detection, 27.12.2014 14:27:57, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 93.103.86.92, 1000, Outbound, C:\Program Files\JFileManager\JFileManager.exe, Detection, 27.12.2014 14:28:32, SYSTEM, LENE-PC, Protection, Malware Protection, File, Riskware.Vmdetector, C:\Users\Lene\AppData\Local\Temp\nso8067.tmp\VMD.dll, Quarantine, [22ae1057d3a9c472a0b11c54d82d44bc] Detection, 27.12.2014 14:29:25, Lene, LENE-PC, Protection, Malware Protection, File, PUP.Optional.Bundle, C:\Users\Lene\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\adv_76.exe, Quarantine, [50802047b6c68aac84fe0ae152af926e] Detection, 27.12.2014 14:32:08, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.HealthAlert.A, C:\Users\Lene\AppData\Local\Temp\nso8067.tmp\Setup.exe, Quarantine, [6d6381e66c10cb6bfe133c275da37d83] Detection, 27.12.2014 14:34:09, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.InetStat.A, C:\Users\Lene\AppData\Roaming\InetStat\inetstat.exe, Quarantine, [4d83b0b73a4268cefca82440828155ab] Detection, 27.12.2014 14:35:02, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.Amonetize.A, C:\Users\Lene\AppData\Local\Temp\amiupdater1424.exe, Quarantine, [13bd85e2fc8070c6d53d1e4505fb17e9] Detection, 27.12.2014 14:45:26, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.228, 3c45d848d99.se, 57401, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:45:26, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.228, 3c45d848d99.se, 57401, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:45:43, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.228, d9ae99824.se, 57446, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:45:43, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.228, d9ae99824.se, 57446, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:49:32, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 5.150.195.167, d9ae99824.se, 57987, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:49:32, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 5.150.195.167, d9ae99824.se, 57987, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:54:17, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 5.150.195.167, 3c45d848d99.se, 58534, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:54:17, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 5.150.195.167, 3c45d848d99.se, 58534, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 14:56:44, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.228, d9ae99824.se, 58814, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 15:01:00, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.Amonetize.A, c:\users\lene\appdata\local\temp\amiupdater1424.exe, Quarantine Failed, 2, The system cannot find the file specified. , [13bd85e2fc8070c6d53d1e4505fb17e9] Detection, 27.12.2014 15:01:51, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 59203, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 15:01:52, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.229, 3c45d848d99.se, 59203, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 15:04:35, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 5.150.195.169, 3c45d848d99.se, 59475, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 15:04:35, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 5.150.195.169, 3c45d848d99.se, 59475, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 15:07:28, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.228, 3c45d848d99.se, 59692, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 15:09:48, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 80.252.188.228, 3c45d848d99.se, 60012, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 15:10:42, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 5.150.195.167, 3c45d848d99.se, 60107, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 15:11:00, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.Amonetize.A, c:\users\lene\appdata\local\temp\amiupdater1424.exe, Quarantine Failed, 2, The system cannot find the file specified. , [13bd85e2fc8070c6d53d1e4505fb17e9] Detection, 27.12.2014 15:11:00, SYSTEM, LENE-PC, Protection, Malware Protection, File, PUP.Optional.RegCleanPro.A, C:\Windows\System32\Tasks\RegClean Pro_DEFAULT, Quarantine, [1cb4bdaafd7f81b598b7a3da14efbb45] Detection, 27.12.2014 15:38:57, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 5.150.195.167, 3c45d848d99.se, 63300, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, Detection, 27.12.2014 15:42:48, SYSTEM, LENE-PC, Protection, Malicious Website Protection, IP, 5.150.195.167, 3c45d848d99.se, 63734, Outbound, C:\Program Files\Mozilla Firefox\firefox.exe, (end) |
27.12.2014, 15:47 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Schädliche objekte gefunden Wieo postest du ein Log ohne Funde?
__________________ Logfiles bitte immer in CODE-Tags posten |
27.12.2014, 15:48 | #5 |
| Schädliche objekte gefundenCode:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 27.12.2014 Scan Time: 13:19:09 Logfile: log 3.txt Administrator: Yes Version: 2.00.4.1028 Malware Database: v2014.12.27.04 Rootkit Database: v2014.12.23.02 License: Trial Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x86 File System: NTFS User: Lene Scan Type: Threat Scan Result: Completed Objects Scanned: 292437 Time Elapsed: 14 min, 29 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 2 PUP.Optional.Wajam, C:\Program Files\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe, 1872, Delete-on-Reboot, [f3ddbbac601c60d6cc53d6e703fedd23] PUP.Optional.Wajam, C:\Program Files\Wajam\Wajam Internet Enhancer\WajamInternetEnhancer.exe, 4896, Delete-on-Reboot, [d3fd2f383349211566b93786837e54ac] Modules: 2 PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\FiddlerCore.dll, Delete-on-Reboot, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\Newtonsoft.Json.dll, Delete-on-Reboot, [ffd163042359dc5a8b76ac7bd82b32ce], Registry Keys: 34 PUP.Optional.Wajam, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Wajam Internet Enhancer Service, Quarantined, [f3ddbbac601c60d6cc53d6e703fedd23], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{638de20a-7c0a-4edd-8c85-d361e49495cd}, Quarantined, [cb055d0a5d1f20165ed0864f2fd3659b], PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{638DE20A-7C0A-4EDD-8C85-D361E49495CD}, Quarantined, [cb055d0a5d1f20165ed0864f2fd3659b], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\., Quarantined, [cb055d0a5d1f20165ed0864f2fd3659b], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\..10, Quarantined, [cb055d0a5d1f20165ed0864f2fd3659b], PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{638DE20A-7C0A-4EDD-8C85-D361E49495CD}, Quarantined, [cb055d0a5d1f20165ed0864f2fd3659b], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{638DE20A-7C0A-4EDD-8C85-D361E49495CD}\INPROCSERVER32, Quarantined, [cb055d0a5d1f20165ed0864f2fd3659b], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{9d511ade-c1ee-4b51-978b-d1ac9af345be}, Quarantined, [f4dcec7b2a521323fc327e575aa8d12f], PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{9D511ADE-C1EE-4B51-978B-D1AC9AF345BE}, Quarantined, [f4dcec7b2a521323fc327e575aa8d12f], PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{9D511ADE-C1EE-4B51-978B-D1AC9AF345BE}, Quarantined, [f4dcec7b2a521323fc327e575aa8d12f], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{9D511ADE-C1EE-4B51-978B-D1AC9AF345BE}\INPROCSERVER32, Quarantined, [f4dcec7b2a521323fc327e575aa8d12f], PUP.Optional.Snapdo.T, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, Quarantined, [87490a5d2d4f5adcedda6ea88f744ab6], PUP.Optional.Snapdo.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, Quarantined, [87490a5d2d4f5adcedda6ea88f744ab6], PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1E38F0E0-5499-CDAF-F946-BA3D053AABC2}, Quarantined, [4987f275691391a5c26d9e37bc46b749], PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{5A1EDE4C-67FF-6CB4-C08E-A23CAB1557D4}, Quarantined, [2ea28bdc80fca5917cb3bb1a7d85f40c], PUP.Optional.Flowsurf.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Flwsrf, Quarantined, [3f91e186cab2bb7bb7d01de1e51cee12], PUP.Optional.FlowSurf.A, HKLM\SOFTWARE\Flowsurf, Quarantined, [ad23bdaad5a780b64e99d5094cb8c739], PUP.Optional.MBot.A, HKLM\SOFTWARE\MYBESTOFFERSTODAY, Quarantined, [745c0f58e19b270fe0ef1d544bb811ef], PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\mystartsearchSoftware, Quarantined, [a0302542790366d02b3a1151cf3446ba], PUP.Optional.WPM.A, HKLM\SOFTWARE\supWindowsMangerProtect, Quarantined, [854b94d39fdd52e433678550689cc23e], PUP.Optional.Wajam.A, HKLM\SOFTWARE\Wajam, Quarantined, [7858fb6c413b5ed82fe21ab6f80ce020], PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\webssearchesSoftware, Quarantined, [735d3e290b711b1bd37e444f17ecb947], PUP.Optional.VOPackage, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\VOPACKAGE, Quarantined, [26aa82e5bbc182b40cfd3345b25117e9], PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, Quarantined, [438db2b56418fa3c0d8090d5ff04ef11], PUP.Optional.DesktopDockApp.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DesktopDockApp, Quarantined, [daf6194ea6d62e081040045b7093cd33], PUP.Optional.Softonic.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic, Quarantined, [f7d978ef9ce084b2a261530c1ae9b14f], PUP.Optional.StormWatchApp.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\StormWatchApp, Quarantined, [e9e7085f6814c86e9640d78f659e07f9], PUP.Optional.Tuto4PC.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\TutoTag, Quarantined, [ffd1d790fe7eec4afbce24b4fc084fb1], PUP.Optional.CrossRider.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [4d83a1c6671578be22c053767a8adb25], PUP.Optional.FastStart.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS, Quarantined, [29a754139fdddf57ee8dd99451b2827e], PUP.Optional.SmartBar.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR, Quarantined, [e0f07dea87f5be78c58d510ebf44fd03], PUP.Optional.Wajam.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WAJAM, Quarantined, [cf0174f38eeed1659c612c8ca163a060], PUP.Optional.Wajam.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Wajam, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [5b75e0870676e94de0049ba50ff432ce], Registry Values: 8 Spyware.Password, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|xvtcuvvl.exe, "C:\Users\Lene\AppData\Roaming\Identities\xvtcuvvl.exe", Quarantined, [409081e6b5c70e28b4d203e600015aa6] PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, Quarantined, [09c75710b1cba29429e4135c7192669a] PUP.Optional.MBot.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|mbot_de_344, Quarantined, [438dca9d8eeeee48f4da6110c142926e], PUP.Optional.VOPackage, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\VOPACKAGE|UninstallString, "C:\Users\Lene\AppData\Roaming\VOPackage\uninstall.exe", Quarantined, [26aa82e5bbc182b40cfd3345b25117e9] PUP.Optional.FastStart.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|faststartff@gmail.com, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com, Quarantined, [904093d46a1277bf11a3389cf50f10f0] PUP.Optional.FastStart.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, Quarantined, [29a754139fdddf57ee8dd99451b2827e] PUP.Optional.SmartBar.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR|publisher, SoftPublisherYB, Quarantined, [e0f07dea87f5be78c58d510ebf44fd03] PUP.Optional.Wajam.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WAJAM|affiliate_id, 4630, Quarantined, [cf0174f38eeed1659c612c8ca163a060] Registry Data: 10 PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1418514129&from=amt&uid=ST9500325AS_5VEALD1AXXXX5VEALD1A, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1418514129&from=amt&uid=ST9500325AS_5VEALD1AXXXX5VEALD1A),Replaced,[1bb55b0ce3998ea88ac674fec34207f9] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1418516067&from=brd&uid=ST9500325AS_5VEALD1AXXXX5VEALD1A&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=ds&ts=1418516067&from=brd&uid=ST9500325AS_5VEALD1AXXXX5VEALD1A&q={searchTerms}),Replaced,[d3fddd8a9ede5fd7f36198dc45c0a25e] PUP.Optional.WebSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1418516067&from=brd&uid=ST9500325AS_5VEALD1AXXXX5VEALD1A&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=ds&ts=1418516067&from=brd&uid=ST9500325AS_5VEALD1AXXXX5VEALD1A&q={searchTerms}),Replaced,[04cc1156b2ca80b687ea9be5ce3749b7] PUP.Optional.SnapDo.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv6&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv6&q={searchTerms}),Replaced,[efe1580fa7d5e650e4d7fa78a85d2fd1] PUP.Optional.SnapDo.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}),Replaced,[7d530e59b6c603335569afc3768f58a8] PUP.Optional.SnapDo.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}),Replaced,[2ba51f4880fc87afa518d39ff114c33d] PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1418514129&from=amt&uid=ST9500325AS_5VEALD1AXXXX5VEALD1A&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1418514129&from=amt&uid=ST9500325AS_5VEALD1AXXXX5VEALD1A&q={searchTerms}),Replaced,[9a36aabd3547e2548a13e29032d3b14f] PUP.Optional.SnapDo.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}),Replaced,[d3fd2f38f88442f43c855919a0657b85] PUP.Optional.SnapDo.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}),Replaced,[814f67004636da5c04bc79f9a26332ce] PUP.Optional.SnapDo.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}),Replaced,[06ca83e413692f07a715056d44c16d93] Folders: 51 PUP.Optional.Wajam.A, C:\Program Files\Wajam, Delete-on-Reboot, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer, Delete-on-Reboot, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.OpenCandy, C:\Users\Lene\AppData\Roaming\OpenCandy, Quarantined, [15bb5c0b106c65d1022a96917093ce32], PUP.Optional.OpenCandy, C:\Users\Lene\AppData\Roaming\OpenCandy\A99DDCF77F224B55844057006FE161FA, Quarantined, [15bb5c0b106c65d1022a96917093ce32], PUP.Optional.OpenCandy, C:\Users\Lene\AppData\Roaming\OpenCandy\ACF1CAE869A1430EB0EA46AD7A507F2B, Quarantined, [15bb5c0b106c65d1022a96917093ce32], PUP.Optional.OpenCandy, C:\Users\Lene\AppData\Roaming\OpenCandy\C1C03F423A2F4F2ABB8A2C42E2EACD4B, Quarantined, [15bb5c0b106c65d1022a96917093ce32], PUP.Optional.OpenCandy, C:\Users\Lene\AppData\Roaming\OpenCandy\DB49D789067E4E30AE1286E8073A6DF6, Quarantined, [15bb5c0b106c65d1022a96917093ce32], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Uninstall Wajam, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.MindSpark.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\FilmFanatic, Quarantined, [a52b45226c1089adbdb4ee43f60dd030], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\include, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\include\tools, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\lib, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\module, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\pack, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\en, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\en-US, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\es, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\es-419, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr-BE, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr-CA, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr-CH, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr-LU, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\it, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\it-CH, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\pl, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\pt-BR, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\ru, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\ru-MO, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\tr, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\vi, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\zh-CN, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\zh-TW, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\defaults, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\defaults\preferences, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Quarantined, [1eb234339ede979ff6009ca28e7526da], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, Quarantined, [1eb234339ede979ff6009ca28e7526da], PUP.Optional.WebEnhance.A, C:\Program Files\WebEnhance, Quarantined, [755b5b0c592384b29ebf94ace0231ce4], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.Flowsurf.A, C:\Program Files\Flwsrf, Quarantined, [7e520a5d7606d165eca6e873c53e966a], Files: 187 PUP.Optional.Wajam, C:\Program Files\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe, Delete-on-Reboot, [f3ddbbac601c60d6cc53d6e703fedd23], PUP.Optional.Wajam, C:\Program Files\Wajam\Wajam Internet Enhancer\WajamInternetEnhancer.exe, Delete-on-Reboot, [d3fd2f383349211566b93786837e54ac], Spyware.Password, C:\Users\Lene\AppData\Roaming\Identities\xvtcuvvl.exe, Quarantined, [409081e6b5c70e28b4d203e600015aa6], PUP.Optional.Multiplug, C:\ProgramData\lowrate\uFIxFUCJQk38Ro.dll, Quarantined, [cb055d0a5d1f20165ed0864f2fd3659b], PUP.Optional.Multiplug, C:\ProgramData\appsave\4HV954zPncTjeT.dll, Quarantined, [f4dcec7b2a521323fc327e575aa8d12f], PUP.Optional.Multiplug, C:\ProgramData\appsave\4HV954zPncTjeT.exe, Quarantined, [4987f275691391a5c26d9e37bc46b749], PUP.Optional.Multiplug, C:\ProgramData\lowrate\uFIxFUCJQk38Ro.exe, Quarantined, [2ea28bdc80fca5917cb3bb1a7d85f40c], PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Quarantined, [646c9dca2656a1951a53883933ce9c64], PUP.Optional.CrossRider.A, C:\Users\Lene\AppData\Roaming\JVYJQ.exe, Quarantined, [c010c6a1e597e6505783743c50b551af], PUP.Optional.CrossRider.A, C:\Users\Lene\AppData\Roaming\YOYXRQCJ.exe, Quarantined, [488894d363196bcb13c71d938f76a25e], PUP.Optional.Flowsurf.A, C:\Program Files\Flwsrf\uninstall.exe, Quarantined, [3f91e186cab2bb7bb7d01de1e51cee12], PUP.Optional.Amonetize, C:\Users\Lene\AppData\Local\Temp\DivX.Web.Player.Installer__8420_il5733(1).exe, Quarantined, [b020214688f4a78f4d07f703be43c33d], PUP.Optional.Amonetize, C:\Users\Lene\AppData\Local\Temp\DivX.Web.Player.Installer__8420_il5733.exe, Quarantined, [814fec7b07752f07351fd129f60bef11], PUP.Optional.Tuto4PC.A, C:\Users\Lene\AppData\Local\Temp\is-NAGAM.tmp\package_stormpverti_installer_multilang.exe, Quarantined, [498778efe09cec4af85417d85fa2e719], PUP.Optional.Tuto4PC.A, C:\Users\Lene\AppData\Local\Temp\is-NAGAM.tmp\package_superpc_installer_multilang.exe, Quarantined, [22ae96d1df9d76c04606905fc140dd23], PUP.Optional.Tuto4PC.A, C:\Users\Lene\AppData\Local\Temp\is-NAGAM.tmp\package_websearches_pariente_installer_multilang.exe, Quarantined, [ac2417506c1045f1b99320cf2fd203fd], PUP.Optional.Amonetize, C:\Users\Lene\Downloads\DivX.Web.Player.Installer__8420_il5733(1).exe, Quarantined, [ffd1de89bebeb87e0a4a5d9dcd349b65], PUP.Optional.Amonetize, C:\Users\Lene\Downloads\DivX.Web.Player.Installer__8420_il5733.exe, Quarantined, [e6ea0d5a502c7bbb85cff60410f11de3], PUP.Optional.Softonic, C:\Users\Lene\Downloads\SoftonicDownloader_fuer_windows-installer-clean-up.exe, Quarantined, [fad65e09adcf999d7737e67401ffb54b], PUP.Optional.Flowsurf.A, C:\Windows\System32\abengineOff.ini, Quarantined, [a32ddd8a403cdb5b24bc4b1043c07b85], PUP.Optional.Flowsurf.A, C:\Windows\System32\abengine.ini, Quarantined, [28a8c0a7f18be15503def56630d3ed13], PUP.Optional.Flowsurf.A, C:\Windows\System32\Tasks\upfs7235, Quarantined, [7b555a0dbbc11620b033d586c0432fd1], PUP.Optional.Flowsurf.A, C:\Windows\Temp\abengine.log, Quarantined, [21af8cdb8fedc6702cba60fb7d86837d], PUP.Optional.MyStartSearch.A, C:\Program Files\Mozilla Firefox\browser\searchplugins\mystartsearch.xml, Quarantined, [e6eaa6c1f08c57dff172f46e9b6814ec], PUP.Optional.Wajam.A, C:\Program Files\Wajam\uninstall.exe, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\amazon.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\argos.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\ask.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\bestbuy.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\ebay.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\etsy.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\facebook.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\favicon.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\google.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\homedepot.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\ikea.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\imdb.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\lowes.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\mercado.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\mysearchweb.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\myshopping.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\searchresult.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\sears.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\setting.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\settings.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\shopping.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\target.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\tesco.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\tripadvisor.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\twitter.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\wajam.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\walmart.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\wiki.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\yahoo.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\zalando.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\2845734c09907de22309ed6090c7c5b9, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\41775c4c4b812fc8ed449048cbc01848, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\829d81e09f6974a1b6d2d7d21790bb4a, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\852cdcfe90ff11ba0bd4109a8f67d22b, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\8a8f52659c24ab15d20eee3779a8c44c, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\8ac3acfd3939085e1db6b946a4402fcf, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\8e018c6bd5197e2a6b79b5c27b040f1b, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\9d34e5b040ae920d8690d6698bc008b2, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\a12534f1688fe7d400f8d5ec8c062411, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\FiddlerCore.dll, Delete-on-Reboot, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\HtmlAgilityPack.dll, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\makecert.exe, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\Newtonsoft.Json.dll, Delete-on-Reboot, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\setup.exe, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\WajamHttpServer.exe, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\wie, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\WJManifest, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\a23c5912437d664303c8a1ad40e9ca03, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\a40dc56fe62e42a0aacfaa25f7c45ac2, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\ac98fc59c6e0aedbbb9622792385256f, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\aff952784d84706bf3382a8fd618f6ff, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\b3f4b05e3ab3a5e65883524e710a4e42, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\cac2bf29ed8244d2e982a160dc655780, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\d84aa6e25209ad335803a911d90669f0, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\f3be888373207c1153eccc9224d67f6b, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\fb0d18565c7d32aa3fb8a0c787765fd7, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.OpenCandy, C:\Users\Lene\AppData\Roaming\OpenCandy\DB49D789067E4E30AE1286E8073A6DF6\PokkiInstaller.exe, Quarantined, [15bb5c0b106c65d1022a96917093ce32], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Settings.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\SignIn with Facebook.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\SignIn with Twitter.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Wajam Website.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Ask.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Google.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\IMDb.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Shopping.com.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\TripAdvisor.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Wikipedia.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Yahoo!.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Amazon.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Argos.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Ebay.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Etsy.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\HomeDepot.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Ikea.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Lowe's.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Mercadolivre.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\MyShopping.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Sears.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Target.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Tesco.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Walmart.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Zalando.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Uninstall Wajam\uninstall.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome.manifest, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\install.rdf, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\index.html, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\quick_start.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\quick_start.xul, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\include\speed_dial.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\include\tools\about_blank_hook.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\include\tools\misc.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\include\tools\popup_image_helper.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\include\tools\urlrequestor.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\js.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\lib\doT.min.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\lib\jquery-2.1.0.min.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\lib\jquery.autocomplete.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\module\hotSearch.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\module\mostgrid.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\module\search.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\module\stat.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\pack\common.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\pack\ga.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\pack\xagainit.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\en\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\en-US\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\es\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\es-419\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr-BE\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr-CA\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr-CH\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr-LU\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\it\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\it-CH\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\pl\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\pt-BR\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\ru\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\ru-MO\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\tr\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\vi\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\zh-CN\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\zh-TW\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\default_logo.png, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\googlelogo.png, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\google_trends.png, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\icon.png, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\loading.gif, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\logo.png, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\newtab.ico, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\simple.css, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\style.css, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\defaults\preferences\fvd.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\defaults\preferences\preferences.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\addonmanager.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\aes.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\config.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\dialogs.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\last_tab.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\misc.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\properties.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\remoterequest.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\restoreprefs.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\settings.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, Quarantined, [1eb234339ede979ff6009ca28e7526da], PUP.Optional.WebEnhance.A, C:\Program Files\WebEnhance\webenhance.xpi, Quarantined, [755b5b0c592384b29ebf94ace0231ce4], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\GoogleCrashHandler.exe, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\GoogleUpdate.exe, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\GoogleUpdateBroker.exe, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\GoogleUpdateHelper.msi, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\GoogleUpdateOnDemand.exe, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\goopdate.dll, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\goopdateres_en.dll, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\npGoogleUpdate4.dll, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\psmachine.dll, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\psuser.dll, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.Flowsurf.A, C:\Program Files\Flwsrf\proc2.txt, Quarantined, [7e520a5d7606d165eca6e873c53e966a], PUP.Optional.Flowsurf.A, C:\Program Files\Flwsrf\upfs7235.exe, Quarantined, [7e520a5d7606d165eca6e873c53e966a], PUP.Optional.Flowsurf.A, C:\Program Files\Flwsrf\[SC] OpenService FAILED 1060, Quarantined, [7e520a5d7606d165eca6e873c53e966a], PUP.Optional.QuickStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\prefs.js, Good: (), Bad: (user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");), Replaced,[b61a66019fdd69cd166cbcfa30d5fa06] PUP.Optional.CrossRider.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossrider.bic", "14a46204747c2bedf40fb90148c19671");), Replaced,[f7d99fc8b9c3b284832debccf70ee719] PUP.Optional.ASK.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\prefs.js, Good: (), Bad: (user_pref("extensions.toolbar.mindspark._paMembers_.browser.startup.homepage.tb", "hxxp://home.tb.ask.com/index.jhtml?ptb=E890DAAC-EAAE-4BEC-85CE-63C42666D6AE&n=780d0dc4&p2=^Z1^xdm132^LADEDE^de&si=CIewoaSWxMICFWjItAodDQUAFw");), Replaced,[6e62b4b3413bbe782c5e7345699c34cc] Physical Sectors: 0 (No malicious items detected) (end) |
27.12.2014, 15:51 | #6 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Schädliche objekte gefundenZitat:
__________________ --> Schädliche objekte gefunden |
27.12.2014, 16:10 | #7 |
| Schädliche objekte gefundenCode:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 27.12.2014 Scan Time: 13:19:09 Logfile: log 3.txt Administrator: Yes Version: 2.00.4.1028 Malware Database: v2014.12.27.04 Rootkit Database: v2014.12.23.02 License: Trial Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x86 File System: NTFS User: Lene Scan Type: Threat Scan Result: Completed Objects Scanned: 292437 Time Elapsed: 14 min, 29 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 2 PUP.Optional.Wajam, C:\Program Files\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe, 1872, Delete-on-Reboot, [f3ddbbac601c60d6cc53d6e703fedd23] PUP.Optional.Wajam, C:\Program Files\Wajam\Wajam Internet Enhancer\WajamInternetEnhancer.exe, 4896, Delete-on-Reboot, [d3fd2f383349211566b93786837e54ac] Modules: 2 PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\FiddlerCore.dll, Delete-on-Reboot, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\Newtonsoft.Json.dll, Delete-on-Reboot, [ffd163042359dc5a8b76ac7bd82b32ce], Registry Keys: 34 PUP.Optional.Wajam, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Wajam Internet Enhancer Service, Quarantined, [f3ddbbac601c60d6cc53d6e703fedd23], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{638de20a-7c0a-4edd-8c85-d361e49495cd}, Quarantined, [cb055d0a5d1f20165ed0864f2fd3659b], PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{638DE20A-7C0A-4EDD-8C85-D361E49495CD}, Quarantined, [cb055d0a5d1f20165ed0864f2fd3659b], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\., Quarantined, [cb055d0a5d1f20165ed0864f2fd3659b], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\..10, Quarantined, [cb055d0a5d1f20165ed0864f2fd3659b], PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{638DE20A-7C0A-4EDD-8C85-D361E49495CD}, Quarantined, [cb055d0a5d1f20165ed0864f2fd3659b], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{638DE20A-7C0A-4EDD-8C85-D361E49495CD}\INPROCSERVER32, Quarantined, [cb055d0a5d1f20165ed0864f2fd3659b], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{9d511ade-c1ee-4b51-978b-d1ac9af345be}, Quarantined, [f4dcec7b2a521323fc327e575aa8d12f], PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{9D511ADE-C1EE-4B51-978B-D1AC9AF345BE}, Quarantined, [f4dcec7b2a521323fc327e575aa8d12f], PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{9D511ADE-C1EE-4B51-978B-D1AC9AF345BE}, Quarantined, [f4dcec7b2a521323fc327e575aa8d12f], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{9D511ADE-C1EE-4B51-978B-D1AC9AF345BE}\INPROCSERVER32, Quarantined, [f4dcec7b2a521323fc327e575aa8d12f], PUP.Optional.Snapdo.T, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, Quarantined, [87490a5d2d4f5adcedda6ea88f744ab6], PUP.Optional.Snapdo.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, Quarantined, [87490a5d2d4f5adcedda6ea88f744ab6], PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1E38F0E0-5499-CDAF-F946-BA3D053AABC2}, Quarantined, [4987f275691391a5c26d9e37bc46b749], PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{5A1EDE4C-67FF-6CB4-C08E-A23CAB1557D4}, Quarantined, [2ea28bdc80fca5917cb3bb1a7d85f40c], PUP.Optional.Flowsurf.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Flwsrf, Quarantined, [3f91e186cab2bb7bb7d01de1e51cee12], PUP.Optional.FlowSurf.A, HKLM\SOFTWARE\Flowsurf, Quarantined, [ad23bdaad5a780b64e99d5094cb8c739], PUP.Optional.MBot.A, HKLM\SOFTWARE\MYBESTOFFERSTODAY, Quarantined, [745c0f58e19b270fe0ef1d544bb811ef], PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\mystartsearchSoftware, Quarantined, [a0302542790366d02b3a1151cf3446ba], PUP.Optional.WPM.A, HKLM\SOFTWARE\supWindowsMangerProtect, Quarantined, [854b94d39fdd52e433678550689cc23e], PUP.Optional.Wajam.A, HKLM\SOFTWARE\Wajam, Quarantined, [7858fb6c413b5ed82fe21ab6f80ce020], PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\webssearchesSoftware, Quarantined, [735d3e290b711b1bd37e444f17ecb947], PUP.Optional.VOPackage, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\VOPACKAGE, Quarantined, [26aa82e5bbc182b40cfd3345b25117e9], PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, Quarantined, [438db2b56418fa3c0d8090d5ff04ef11], PUP.Optional.DesktopDockApp.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DesktopDockApp, Quarantined, [daf6194ea6d62e081040045b7093cd33], PUP.Optional.Softonic.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic, Quarantined, [f7d978ef9ce084b2a261530c1ae9b14f], PUP.Optional.StormWatchApp.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\StormWatchApp, Quarantined, [e9e7085f6814c86e9640d78f659e07f9], PUP.Optional.Tuto4PC.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\TutoTag, Quarantined, [ffd1d790fe7eec4afbce24b4fc084fb1], PUP.Optional.CrossRider.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [4d83a1c6671578be22c053767a8adb25], PUP.Optional.FastStart.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS, Quarantined, [29a754139fdddf57ee8dd99451b2827e], PUP.Optional.SmartBar.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR, Quarantined, [e0f07dea87f5be78c58d510ebf44fd03], PUP.Optional.Wajam.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WAJAM, Quarantined, [cf0174f38eeed1659c612c8ca163a060], PUP.Optional.Wajam.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Wajam, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [5b75e0870676e94de0049ba50ff432ce], Registry Values: 8 Spyware.Password, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|xvtcuvvl.exe, "C:\Users\Lene\AppData\Roaming\Identities\xvtcuvvl.exe", Quarantined, [409081e6b5c70e28b4d203e600015aa6] PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, Quarantined, [09c75710b1cba29429e4135c7192669a] PUP.Optional.MBot.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|mbot_de_344, Quarantined, [438dca9d8eeeee48f4da6110c142926e], PUP.Optional.VOPackage, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\VOPACKAGE|UninstallString, "C:\Users\Lene\AppData\Roaming\VOPackage\uninstall.exe", Quarantined, [26aa82e5bbc182b40cfd3345b25117e9] PUP.Optional.FastStart.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|faststartff@gmail.com, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com, Quarantined, [904093d46a1277bf11a3389cf50f10f0] PUP.Optional.FastStart.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, Quarantined, [29a754139fdddf57ee8dd99451b2827e] PUP.Optional.SmartBar.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR|publisher, SoftPublisherYB, Quarantined, [e0f07dea87f5be78c58d510ebf44fd03] PUP.Optional.Wajam.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WAJAM|affiliate_id, 4630, Quarantined, [cf0174f38eeed1659c612c8ca163a060] Registry Data: 10 PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1418514129&from=amt&uid=ST9500325AS_5VEALD1AXXXX5VEALD1A, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1418514129&from=amt&uid=ST9500325AS_5VEALD1AXXXX5VEALD1A),Replaced,[1bb55b0ce3998ea88ac674fec34207f9] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1418516067&from=brd&uid=ST9500325AS_5VEALD1AXXXX5VEALD1A&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=ds&ts=1418516067&from=brd&uid=ST9500325AS_5VEALD1AXXXX5VEALD1A&q={searchTerms}),Replaced,[d3fddd8a9ede5fd7f36198dc45c0a25e] PUP.Optional.WebSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1418516067&from=brd&uid=ST9500325AS_5VEALD1AXXXX5VEALD1A&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=ds&ts=1418516067&from=brd&uid=ST9500325AS_5VEALD1AXXXX5VEALD1A&q={searchTerms}),Replaced,[04cc1156b2ca80b687ea9be5ce3749b7] PUP.Optional.SnapDo.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv6&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv6&q={searchTerms}),Replaced,[efe1580fa7d5e650e4d7fa78a85d2fd1] PUP.Optional.SnapDo.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}),Replaced,[7d530e59b6c603335569afc3768f58a8] PUP.Optional.SnapDo.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}),Replaced,[2ba51f4880fc87afa518d39ff114c33d] PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1418514129&from=amt&uid=ST9500325AS_5VEALD1AXXXX5VEALD1A&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1418514129&from=amt&uid=ST9500325AS_5VEALD1AXXXX5VEALD1A&q={searchTerms}),Replaced,[9a36aabd3547e2548a13e29032d3b14f] PUP.Optional.SnapDo.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}),Replaced,[d3fd2f38f88442f43c855919a0657b85] PUP.Optional.SnapDo.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}),Replaced,[814f67004636da5c04bc79f9a26332ce] PUP.Optional.SnapDo.A, HKU\S-1-5-21-1521733554-1607495114-2559871037-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPBB49zLjAwor57FrVWaSTA8zLLXYtduKUwrirpBvk_czsRzbLyfx0g7GTSl-HuTwfzTFkX5Ydm3PNHPDeCZjb8NE2BrqEGiCncHG_4RTeopROywNFuPFC984oSeny76yB9yF48uD8txoM62WOc4PC_uGzQiKRMnIydbh2BI72NbUheAZe848Thy47_niZIpbv9&q={searchTerms}),Replaced,[06ca83e413692f07a715056d44c16d93] Folders: 51 PUP.Optional.Wajam.A, C:\Program Files\Wajam, Delete-on-Reboot, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer, Delete-on-Reboot, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.OpenCandy, C:\Users\Lene\AppData\Roaming\OpenCandy, Quarantined, [15bb5c0b106c65d1022a96917093ce32], PUP.Optional.OpenCandy, C:\Users\Lene\AppData\Roaming\OpenCandy\A99DDCF77F224B55844057006FE161FA, Quarantined, [15bb5c0b106c65d1022a96917093ce32], PUP.Optional.OpenCandy, C:\Users\Lene\AppData\Roaming\OpenCandy\ACF1CAE869A1430EB0EA46AD7A507F2B, Quarantined, [15bb5c0b106c65d1022a96917093ce32], PUP.Optional.OpenCandy, C:\Users\Lene\AppData\Roaming\OpenCandy\C1C03F423A2F4F2ABB8A2C42E2EACD4B, Quarantined, [15bb5c0b106c65d1022a96917093ce32], PUP.Optional.OpenCandy, C:\Users\Lene\AppData\Roaming\OpenCandy\DB49D789067E4E30AE1286E8073A6DF6, Quarantined, [15bb5c0b106c65d1022a96917093ce32], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Uninstall Wajam, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.MindSpark.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\FilmFanatic, Quarantined, [a52b45226c1089adbdb4ee43f60dd030], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\include, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\include\tools, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\lib, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\module, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\pack, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\en, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\en-US, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\es, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\es-419, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr-BE, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr-CA, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr-CH, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr-LU, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\it, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\it-CH, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\pl, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\pt-BR, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\ru, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\ru-MO, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\tr, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\vi, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\zh-CN, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\zh-TW, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\defaults, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\defaults\preferences, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Quarantined, [1eb234339ede979ff6009ca28e7526da], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, Quarantined, [1eb234339ede979ff6009ca28e7526da], PUP.Optional.WebEnhance.A, C:\Program Files\WebEnhance, Quarantined, [755b5b0c592384b29ebf94ace0231ce4], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.Flowsurf.A, C:\Program Files\Flwsrf, Quarantined, [7e520a5d7606d165eca6e873c53e966a], Files: 187 PUP.Optional.Wajam, C:\Program Files\Wajam\Wajam Internet Enhancer\WajamInternetEnhancerService.exe, Delete-on-Reboot, [f3ddbbac601c60d6cc53d6e703fedd23], PUP.Optional.Wajam, C:\Program Files\Wajam\Wajam Internet Enhancer\WajamInternetEnhancer.exe, Delete-on-Reboot, [d3fd2f383349211566b93786837e54ac], Spyware.Password, C:\Users\Lene\AppData\Roaming\Identities\xvtcuvvl.exe, Quarantined, [409081e6b5c70e28b4d203e600015aa6], PUP.Optional.Multiplug, C:\ProgramData\lowrate\uFIxFUCJQk38Ro.dll, Quarantined, [cb055d0a5d1f20165ed0864f2fd3659b], PUP.Optional.Multiplug, C:\ProgramData\appsave\4HV954zPncTjeT.dll, Quarantined, [f4dcec7b2a521323fc327e575aa8d12f], PUP.Optional.Multiplug, C:\ProgramData\appsave\4HV954zPncTjeT.exe, Quarantined, [4987f275691391a5c26d9e37bc46b749], PUP.Optional.Multiplug, C:\ProgramData\lowrate\uFIxFUCJQk38Ro.exe, Quarantined, [2ea28bdc80fca5917cb3bb1a7d85f40c], PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Quarantined, [646c9dca2656a1951a53883933ce9c64], PUP.Optional.CrossRider.A, C:\Users\Lene\AppData\Roaming\JVYJQ.exe, Quarantined, [c010c6a1e597e6505783743c50b551af], PUP.Optional.CrossRider.A, C:\Users\Lene\AppData\Roaming\YOYXRQCJ.exe, Quarantined, [488894d363196bcb13c71d938f76a25e], PUP.Optional.Flowsurf.A, C:\Program Files\Flwsrf\uninstall.exe, Quarantined, [3f91e186cab2bb7bb7d01de1e51cee12], PUP.Optional.Amonetize, C:\Users\Lene\AppData\Local\Temp\DivX.Web.Player.Installer__8420_il5733(1).exe, Quarantined, [b020214688f4a78f4d07f703be43c33d], PUP.Optional.Amonetize, C:\Users\Lene\AppData\Local\Temp\DivX.Web.Player.Installer__8420_il5733.exe, Quarantined, [814fec7b07752f07351fd129f60bef11], PUP.Optional.Tuto4PC.A, C:\Users\Lene\AppData\Local\Temp\is-NAGAM.tmp\package_stormpverti_installer_multilang.exe, Quarantined, [498778efe09cec4af85417d85fa2e719], PUP.Optional.Tuto4PC.A, C:\Users\Lene\AppData\Local\Temp\is-NAGAM.tmp\package_superpc_installer_multilang.exe, Quarantined, [22ae96d1df9d76c04606905fc140dd23], PUP.Optional.Tuto4PC.A, C:\Users\Lene\AppData\Local\Temp\is-NAGAM.tmp\package_websearches_pariente_installer_multilang.exe, Quarantined, [ac2417506c1045f1b99320cf2fd203fd], PUP.Optional.Amonetize, C:\Users\Lene\Downloads\DivX.Web.Player.Installer__8420_il5733(1).exe, Quarantined, [ffd1de89bebeb87e0a4a5d9dcd349b65], PUP.Optional.Amonetize, C:\Users\Lene\Downloads\DivX.Web.Player.Installer__8420_il5733.exe, Quarantined, [e6ea0d5a502c7bbb85cff60410f11de3], PUP.Optional.Softonic, C:\Users\Lene\Downloads\SoftonicDownloader_fuer_windows-installer-clean-up.exe, Quarantined, [fad65e09adcf999d7737e67401ffb54b], PUP.Optional.Flowsurf.A, C:\Windows\System32\abengineOff.ini, Quarantined, [a32ddd8a403cdb5b24bc4b1043c07b85], PUP.Optional.Flowsurf.A, C:\Windows\System32\abengine.ini, Quarantined, [28a8c0a7f18be15503def56630d3ed13], PUP.Optional.Flowsurf.A, C:\Windows\System32\Tasks\upfs7235, Quarantined, [7b555a0dbbc11620b033d586c0432fd1], PUP.Optional.Flowsurf.A, C:\Windows\Temp\abengine.log, Quarantined, [21af8cdb8fedc6702cba60fb7d86837d], PUP.Optional.MyStartSearch.A, C:\Program Files\Mozilla Firefox\browser\searchplugins\mystartsearch.xml, Quarantined, [e6eaa6c1f08c57dff172f46e9b6814ec], PUP.Optional.Wajam.A, C:\Program Files\Wajam\uninstall.exe, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\amazon.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\argos.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\ask.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\bestbuy.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\ebay.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\etsy.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\facebook.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\favicon.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\google.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\homedepot.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\ikea.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\imdb.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\lowes.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\mercado.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\mysearchweb.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\myshopping.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\searchresult.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\sears.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\setting.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\settings.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\shopping.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\target.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\tesco.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\tripadvisor.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\twitter.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\wajam.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\walmart.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\wiki.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\yahoo.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Logos\zalando.ico, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\2845734c09907de22309ed6090c7c5b9, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\41775c4c4b812fc8ed449048cbc01848, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\829d81e09f6974a1b6d2d7d21790bb4a, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\852cdcfe90ff11ba0bd4109a8f67d22b, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\8a8f52659c24ab15d20eee3779a8c44c, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\8ac3acfd3939085e1db6b946a4402fcf, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\8e018c6bd5197e2a6b79b5c27b040f1b, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\9d34e5b040ae920d8690d6698bc008b2, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\a12534f1688fe7d400f8d5ec8c062411, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\FiddlerCore.dll, Delete-on-Reboot, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\HtmlAgilityPack.dll, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\makecert.exe, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\Newtonsoft.Json.dll, Delete-on-Reboot, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\setup.exe, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\WajamHttpServer.exe, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\wie, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\WJManifest, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\a23c5912437d664303c8a1ad40e9ca03, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\a40dc56fe62e42a0aacfaa25f7c45ac2, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\ac98fc59c6e0aedbbb9622792385256f, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\aff952784d84706bf3382a8fd618f6ff, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\b3f4b05e3ab3a5e65883524e710a4e42, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\cac2bf29ed8244d2e982a160dc655780, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\d84aa6e25209ad335803a911d90669f0, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\f3be888373207c1153eccc9224d67f6b, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.Wajam.A, C:\Program Files\Wajam\Wajam Internet Enhancer\fb0d18565c7d32aa3fb8a0c787765fd7, Quarantined, [ffd163042359dc5a8b76ac7bd82b32ce], PUP.Optional.OpenCandy, C:\Users\Lene\AppData\Roaming\OpenCandy\DB49D789067E4E30AE1286E8073A6DF6\PokkiInstaller.exe, Quarantined, [15bb5c0b106c65d1022a96917093ce32], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Settings.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\SignIn with Facebook.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\SignIn with Twitter.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Wajam Website.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Ask.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Google.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\IMDb.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Shopping.com.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\TripAdvisor.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Wikipedia.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Yahoo!.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Amazon.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Argos.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Ebay.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Etsy.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\HomeDepot.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Ikea.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Lowe's.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Mercadolivre.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\MyShopping.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Sears.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Target.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Tesco.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Walmart.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Zalando.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.Wajam.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wajam\Uninstall Wajam\uninstall.lnk, Quarantined, [97397dea3547b97db3e3bf69e51ec63a], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome.manifest, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\install.rdf, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\index.html, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\quick_start.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\quick_start.xul, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\include\speed_dial.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\include\tools\about_blank_hook.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\include\tools\misc.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\include\tools\popup_image_helper.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\include\tools\urlrequestor.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\js.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\lib\doT.min.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\lib\jquery-2.1.0.min.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\lib\jquery.autocomplete.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\module\hotSearch.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\module\mostgrid.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\module\search.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\module\stat.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\pack\common.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\pack\ga.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\content\js\pack\xagainit.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\en\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\en-US\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\es\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\es-419\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr-BE\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr-CA\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr-CH\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\fr-LU\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\it\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\it-CH\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\pl\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\pt-BR\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\ru\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\ru-MO\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\tr\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\vi\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\zh-CN\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\locale\zh-TW\locale.properties, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\default_logo.png, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\googlelogo.png, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\google_trends.png, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\icon.png, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\loading.gif, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\logo.png, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\newtab.ico, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\simple.css, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\chrome\skin\style.css, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\defaults\preferences\fvd.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\defaults\preferences\preferences.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\addonmanager.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\aes.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\config.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\dialogs.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\last_tab.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\misc.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\properties.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\remoterequest.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\restoreprefs.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.FastStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\extensions\faststartff@gmail.com\modules\settings.js, Quarantined, [a42c6ff8e29a6fc7f7c51f1e6e9531cf], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, Quarantined, [1eb234339ede979ff6009ca28e7526da], PUP.Optional.WebEnhance.A, C:\Program Files\WebEnhance\webenhance.xpi, Quarantined, [755b5b0c592384b29ebf94ace0231ce4], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\GoogleCrashHandler.exe, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\GoogleUpdate.exe, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\GoogleUpdateBroker.exe, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\GoogleUpdateHelper.msi, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\GoogleUpdateOnDemand.exe, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\goopdate.dll, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\goopdateres_en.dll, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\npGoogleUpdate4.dll, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\psmachine.dll, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.GlobalUpdate.A, C:\Users\Lene\AppData\Local\Temp\comh.452453\psuser.dll, Quarantined, [5b75e0870676e94de0049ba50ff432ce], PUP.Optional.Flowsurf.A, C:\Program Files\Flwsrf\proc2.txt, Quarantined, [7e520a5d7606d165eca6e873c53e966a], PUP.Optional.Flowsurf.A, C:\Program Files\Flwsrf\upfs7235.exe, Quarantined, [7e520a5d7606d165eca6e873c53e966a], PUP.Optional.Flowsurf.A, C:\Program Files\Flwsrf\[SC] OpenService FAILED 1060, Quarantined, [7e520a5d7606d165eca6e873c53e966a], PUP.Optional.QuickStart.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\prefs.js, Good: (), Bad: (user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");), Replaced,[b61a66019fdd69cd166cbcfa30d5fa06] PUP.Optional.CrossRider.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossrider.bic", "14a46204747c2bedf40fb90148c19671");), Replaced,[f7d99fc8b9c3b284832debccf70ee719] PUP.Optional.ASK.A, C:\Users\Lene\AppData\Roaming\Mozilla\Firefox\Profiles\f98197xk.default\prefs.js, Good: (), Bad: (user_pref("extensions.toolbar.mindspark._paMembers_.browser.startup.homepage.tb", "hxxp://home.tb.ask.com/index.jhtml?ptb=E890DAAC-EAAE-4BEC-85CE-63C42666D6AE&n=780d0dc4&p2=^Z1^xdm132^LADEDE^de&si=CIewoaSWxMICFWjItAodDQUAFw");), Replaced,[6e62b4b3413bbe782c5e7345699c34cc] Physical Sectors: 0 (No malicious items detected) (end) hat ein bekannter heruntergeladen |
27.12.2014, 17:12 | #8 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Schädliche objekte gefundenZitat:
Enterprise Editionen von Windows bzw. Microsoftprodukten gibt es nur für Firmenkunden mit Volumenlizenz.
__________________ Logfiles bitte immer in CODE-Tags posten |
28.12.2014, 16:50 | #9 |
| Schädliche objekte gefunden Naja so genau kenne ich mich mit den Editionen nicht aus. Wie mein bekannter es geschafft hat diese version zu downloaden, weiß ich nicht. Heißt das, dass ich jetzt keine unterstützung von Trojaner Board bekomme? |
29.12.2014, 00:18 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Schädliche objekte gefunden Mit gecrackter Software ist nicht zu spaßen. V.a. wenn es auch noch um das Betriebssystem handelt. Die gefundene Werbung ist da dein kleinstes Problem. Besorg dir eine ordentliche Windows-Lizenz und installier alles neu. Und wenn ich du wäre würde ich dem Bekannten eins husten mit nem gecrackten Windows, kann ich ja gleich mein Geld und meine Daten draußen auf die Straße legen
__________________ Logfiles bitte immer in CODE-Tags posten |
01.01.2015, 22:20 | #11 |
| Schädliche objekte gefunden Alles Klar, cosinus und trotzdem danke Dieser Beitrag kann geschlossen werden. |