BlueAzure | 13.05.2015 07:55 | So, obwohl der Benachrichtigungsdienst nun nach jedem Neustart nach den Scans wieder von selbst gestartet ist und Aero funktioniert, hängt sich trotzdem alles dauernd auf. Ich kann einen normalen Doppelklick im Explorer machen und er hängt sich so schlimm auf, dass ich den ganzen PC ausmachen muss. Fast genauso schlimm bei Firefox. (obwohl ich heut morgen einen Moment lang das Gefühl hatte, dass es jetzt wieder okay ist; da hab ich mich wohl geirrt) Es hat schon Ewigkeiten und Neustarts gedauert, bis ich den Log vom AdwCleaner aus dem Explorer öffnen konnte....PDFs werden entweder garnicht geöffnet oder nur nach langer Zeit oder alles hängt sich auf...
Ich verstehs echt nicht, was ist denn los? :( Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 12.05.2015
Suchlauf-Zeit: 22:31:42
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.05.12.07
Rootkit Datenbank: v2015.04.21.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Flavia
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 386143
Verstrichene Zeit: 31 Min, 52 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 7
PUP.Optional.SpeedTest.A, HKLM\SOFTWARE\CLASSES\Speed Test (4354).BackgroundHostObject, In Quarantäne, [6f58464cfb8fe74fa9d48f9250b418e8],
PUP.Optional.SpeedTest.A, HKLM\SOFTWARE\CLASSES\Speed Test (4354).BackgroundHostObject.1, In Quarantäne, [a91eb6dcdcae0d29a0dd7aa77c8858a8],
PUP.Optional.PlusHD.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-2.5, In Quarantäne, [9e292e64afdb58dece0630e4af5527d9],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-4132011797-2711336362-2655832662-1000\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-2.5, In Quarantäne, [b611f0a2c5c553e3c01427ed18ec1ee2],
PUP.Optional.SearchElf.C, HKU\S-1-5-21-4132011797-2711336362-2655832662-1000\SOFTWARE\APPDATALOW\SOFTWARE\SearchElf_1.2, In Quarantäne, [f1d6632f42483df9eb9f706aa3601ce4],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-4132011797-2711336362-2655832662-1000\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [e3e4533fa4e63afc2badb070758f857b],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-4132011797-2711336362-2655832662-1000\SOFTWARE\INSTALLCORE, In Quarantäne, [4780e1b1fe8c9b9b218187af02037987],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-4132011797-2711336362-2655832662-1000\SOFTWARE\INSTALLCORE|tb, 0H1L1J1L1S1R1N, In Quarantäne, [4780e1b1fe8c9b9b218187af02037987]
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 17
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\userCode, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\icons, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\icons\actions, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\api, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\popupResource, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.OpenCandy, C:\Users\Flavia\AppData\Roaming\OpenCandy, In Quarantäne, [1ea92e6490fa2c0ada352c744eb5ff01],
PUP.Optional.OpenCandy, C:\Users\Flavia\AppData\Roaming\OpenCandy\DFBD94179E1749C080B69A455ED8CE58, In Quarantäne, [1ea92e6490fa2c0ada352c744eb5ff01],
PUP.Optional.NextLive.A, C:\Users\Flavia\AppData\Roaming\newnext.me, In Quarantäne, [3a8df89a3555e25494fbfca553b0a858],
PUP.Optional.NextLive.A, C:\Users\Flavia\AppData\Roaming\newnext.me\cache, In Quarantäne, [3a8df89a3555e25494fbfca553b0a858],
PUP.Optional.SpeedTest.A, C:\Users\Flavia\AppData\Roaming\speedtest4354, In Quarantäne, [1fa82171d7b371c5e0d1356c1de6dc24],
PUP.Optional.Updater.A, C:\Users\Flavia\AppData\Roaming\FoxTab\UpdateProc, In Quarantäne, [9433197948420f27315b8a2c44bf53ad],
Dateien: 93
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\crossriderManifest.json, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\background.html, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\manifest.json, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\popup.html, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\manifest.xml, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins.json, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\102_dealply_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\103_intext_5_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\104_jollywallet_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\105_corticas_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\108_icm_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\117_coupons_intext_ads_5_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\119_similar_web_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\120_luck_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\123_intext_adv_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\124_superfish_no_search_no_coupons_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\155_ibario_pops_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\158_50onred_ads_only_no_fb_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\159_cortica_rollover_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\171_arcadi2_sourceID_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\174_arcadi_serp_dynamic_id_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\175_coolmirage_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\178_revizer_ws_dynamic_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\179_revizer_p_dynamic_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\17_jQuery.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\19_CHAppAPIWrapper.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\1_base.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\21_debug.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\22_resources.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\28_initializer.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\47_resources_background.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\125_arcadi2_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\126_revizer_ws_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\127_revizer_p_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\128_superfish_pricora_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\135_arcadi3_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\138_getdeal_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\13_CrossriderAppUtils.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\141_corticas_ru_m.js.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\142_intext_fa_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\14_CrossriderUtils.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\4_jquery_1_7_1.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\64_appApiMessage.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\72_appApiValidation.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\78_CrossriderInfo.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\7_hooks.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\80_CHPopupAppAPI.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\87_ginyas_wrapper.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\91_monetizationLoader.js.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\93_superfish_no_coupons_m.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\97_resourceApiWrapper.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\plugins\9_search_engine_hook.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\userCode\background.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\extensionData\userCode\extension.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\icons\icon128.png, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\icons\icon16.png, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\icons\icon48.png, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\icons\actions\1.png, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\background.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\main.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\api\chrome.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\api\cookie.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\api\message.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\api\pageAction.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\api\pageActionBG.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\app_api.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\bg_app_api.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\consts.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\cookie_store.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\crossriderAPI.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\delegate.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\events.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\extensionDataStore.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\installer.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\logFile.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\logging.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\onBGDocumentLoad.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\reports.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\storageWrapper.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\updateManager.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\util.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\xhr.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\popupResource\newPopup.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.CrossRider.A, C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.25.80_0\js\lib\popupResource\popup.js, In Quarantäne, [c9fedeb46e1c8baba69dabba34d1b54b],
PUP.Optional.OpenCandy, C:\Users\Flavia\AppData\Roaming\OpenCandy\DFBD94179E1749C080B69A455ED8CE58\PokkiInstaller.exe, In Quarantäne, [1ea92e6490fa2c0ada352c744eb5ff01],
PUP.Optional.NextLive.A, C:\Users\Flavia\AppData\Roaming\newnext.me\nengine.cookie, In Quarantäne, [3a8df89a3555e25494fbfca553b0a858],
PUP.Optional.NextLive.A, C:\Users\Flavia\AppData\Roaming\newnext.me\cache\spark.bin, In Quarantäne, [3a8df89a3555e25494fbfca553b0a858],
PUP.Optional.SpeedTest.A, C:\Users\Flavia\AppData\Roaming\speedtest4354\install_helper.exe, In Quarantäne, [1fa82171d7b371c5e0d1356c1de6dc24],
PUP.Optional.SpeedTest.A, C:\Users\Flavia\AppData\Roaming\speedtest4354\speedtest4354.crx, In Quarantäne, [1fa82171d7b371c5e0d1356c1de6dc24],
PUP.Optional.SpeedTest.A, C:\Users\Flavia\AppData\Roaming\speedtest4354\speedtest4354DeskTopIcon.ico, In Quarantäne, [1fa82171d7b371c5e0d1356c1de6dc24],
PUP.Optional.Updater.A, C:\Users\Flavia\AppData\Roaming\FoxTab\UpdateProc\config.dat, In Quarantäne, [9433197948420f27315b8a2c44bf53ad],
PUP.Optional.Updater.A, C:\Users\Flavia\AppData\Roaming\FoxTab\UpdateProc\STTL.DAT, In Quarantäne, [9433197948420f27315b8a2c44bf53ad],
PUP.Optional.Updater.A, C:\Users\Flavia\AppData\Roaming\FoxTab\UpdateProc\TTL.DAT, In Quarantäne, [9433197948420f27315b8a2c44bf53ad],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Code:
# AdwCleaner v4.204 - Bericht erstellt 12/05/2015 um 23:33:07
# Aktualisiert 12/05/2015 von Xplode
# Datenbank : 2015-05-12.2 [Server]
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (x86)
# Benutzername : Flavia - FLAVIA-PC
# Gestarted von : C:\Users\Flavia\Desktop\AdwCleaner_4.204.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : TS888
[#] Dienst Gelöscht : QMUdisk
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Flavia\Favorites\StumbleUpon
Ordner Gelöscht : C:\Program Files\Uniblue
Ordner Gelöscht : C:\Program Files\Common Files\tencent
Ordner Gelöscht : C:\Windows\system32\tencent
Ordner Gelöscht : C:\Windows\system32\config\systemprofile\AppData\Roaming\tencent
Ordner Gelöscht : C:\Users\Flavia\AppData\Local\emaze
Ordner Gelöscht : C:\Users\Flavia\AppData\Local\genienext
Ordner Gelöscht : C:\Users\Flavia\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Flavia\AppData\LocalLow\HPAppData
Ordner Gelöscht : C:\Users\Flavia\AppData\Roaming\FoxTab
Ordner Gelöscht : C:\Users\Flavia\AppData\Roaming\KingSoft
Ordner Gelöscht : C:\Users\Flavia\AppData\Roaming\tencent
Ordner Gelöscht : C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooebklgpfnbcnpokahmdidgbmlcdepkm
Datei Gelöscht : C:\Users\Flavia\AppData\Roaming\Mozilla\Firefox\Profiles\ppf858wc.default\user.js
Datei Gelöscht : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js
***** [ Geplante Tasks ] *****
Task Gelöscht : RunAsStdUser Task for VeohWebPlayer
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp
Schlüssel Gelöscht : HKCU\Software\Classes\pokki
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon]
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@qq.com/TXSSO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{70DE12EA-79F4-46BC-9812-86DB50A2FD64}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{75CC1BBE-D96F-45DF-A622-D60BFA8AF49E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A75BE48D-BF58-4A8B-B96C-F9A09DFB9844}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{B69509B5-4A90-4433-A2DE-BE439F6581F2}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Driver-Soft
Schlüssel Gelöscht : HKLM\SOFTWARE\VBMZ
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\VisualBee for Microsoft PowerPoint
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - hxxp=localhost:8118;hxxps=localhost:8118;ftp=localhost:8118;socks=localhost:9050
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - localhost;127.0.01;<local>
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17728
-\\ Mozilla Firefox v37.0.2 (x86 de)
-\\ Google Chrome v
[C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://de.ask.com/web?q={searchTerms}
[C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.babylon.com/?q={searchTerms}&affID=109958&tt=3212_2&babsrc=SP_ss&mntrId=2a21be6200000000000000ff9e5a681c
-\\ Chromium v
*************************
AdwCleaner[R0].txt - [4594 Bytes] - [12/05/2015 23:32:14]
AdwCleaner[S0].txt - [4251 Bytes] - [12/05/2015 23:33:07]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4310 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.7.0 (05.09.2015:1)
OS: Windows 7 Ultimate x86
Ran by Flavia on 13.05.2015 at 7:59:04.00
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{71576546-354D-41C9-AAE8-31F2EC22BF0D}
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{71576546-354D-41C9-AAE8-31F2EC22BF0D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{C920E44A-7F78-4E64-BDD7-A57026E7FEB7}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C920E44A-7F78-4E64-BDD7-A57026E7FEB7}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] C:\ProgramData\drivergenius
Successfully deleted: [Folder] C:\Users\Flavia\AppData\Roaming\getrighttogo
Successfully deleted: [Folder] C:\Windows\System32\ai_recyclebin
~~~ FireFox
Emptied folder: C:\Users\Flavia\AppData\Roaming\mozilla\firefox\profiles\ppf858wc.default\minidumps [84 files]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 13.05.2015 at 8:01:52.62
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-05-2015
Ran by Flavia (administrator) on FLAVIA-PC on 13-05-2015 08:04:53
Running from C:\Users\Flavia\Desktop
Loaded Profiles: Flavia (Available profiles: Flavia)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Englisch (USA)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(SurfRight B.V.) C:\Program Files\HitmanPro.Alert\hmpalert.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [DT LGE] => C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe [81920 2007-10-11] ()
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10082920 2011-06-09] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-03-20] (Apple Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-11] (Avast Software s.r.o.)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKU\S-1-5-21-4132011797-2711336362-2655832662-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Flavia\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-30] (Akamai Technologies, Inc.)
HKU\S-1-5-21-4132011797-2711336362-2655832662-1000\...\Run: [Pando Media Booster] => C:\Program Files\Pando Networks\Media Booster\PMB.exe [3093624 2013-02-22] ()
AppInit_DLLs: ´ê6 => ´ê6 File Not Found
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-05-03] (Avast Software s.r.o.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-4132011797-2711336362-2655832662-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-4132011797-2711336362-2655832662-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22] (Hewlett-Packard Co.)
BHO: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-10] (Avast Software s.r.o.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22] (Hewlett-Packard Co.)
Toolbar: HKLM - No Name - {52836EB0-631A-47B1-94A6-61F9D9112DAE} - No File
Toolbar: HKLM - No Name - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - No File
Toolbar: HKU\S-1-5-21-4132011797-2711336362-2655832662-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab
DPF: {60F33B36-3E89-48EF-BE77-ACC23A366C2A} https://wstatic.plaync.co.kr/common/UniUpdate/NCLoader.8.cab
DPF: {640044E9-92A3-4B89-A615-1F65354D3A65} hxxp://rfonline-full.gscdn.com/gscdn/ccr_downloader.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} hxxp://www.navigram.com/engine/v911/Navigram.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} hxxp://panda-plugin.disney.go.com/plugin/win32/p3dactivex.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll [2011-11-03] ()
Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Flavia\AppData\Roaming\Mozilla\Firefox\Profiles\ppf858wc.default
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-19] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-09-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2014-09-11] (Foxit Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @nexon.net/NxGame -> C:\ProgramData\NexonUS\NGM\npNxGameUS.dll No File
FF Plugin: @ngm.nexoneu.com/NxGame -> C:\ProgramData\NexonEU\NGM\npNxGameEU.dll No File
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-05] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-05] (NVIDIA Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll [2013-02-22] (Pando Networks)
FF Plugin: @real.com/nppl3260;version=6.0.11.2852 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll [2008-06-03] (RealNetworks, Inc.)
FF Plugin: @real.com/nppl3260;version=6.0.12.46 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll [2008-06-03] (RealNetworks, Inc.)
FF Plugin: @real.com/nppl3260;version=6.0.12.732 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll No File
FF Plugin: @real.com/nprjplug;version=1.0.3.732 -> c:\program files\real\realplayer\Netscape6\nprjplug.dll No File
FF Plugin: @real.com/nprphtml5videoshim;version=1.0.0.0 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll No File
FF Plugin: @real.com/nprpjplug;version=6.0.12.1662 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll [2008-06-03] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.46 -> C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll [2008-06-03] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.732 -> c:\program files\real\realplayer\Netscape6\nprpjplug.dll No File
FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1 -> C:\Program Files\Yahoo!\Common\npyaxmpb.dll No File
FF Plugin HKU\S-1-5-21-4132011797-2711336362-2655832662-1000: @soe.sony.com/installer,version=1.0.3 -> C:\Users\Flavia\AppData\Local\Microsoft\Internet Explorer\Downloaded Program Files\npsoe.dll [2009-10-19] ()
FF Plugin HKU\S-1-5-21-4132011797-2711336362-2655832662-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Flavia\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2009-11-30] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-4132011797-2711336362-2655832662-1000: pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll [2013-02-22] (Pando Networks)
FF Plugin ProgramFiles/Appdata: C:\Users\Flavia\AppData\Roaming\mozilla\plugins\npDXStudioPlugin.DLL [2010-01-26] (Worldweaver Ltd.)
FF SearchPlugin: C:\Users\Flavia\AppData\Roaming\Mozilla\Firefox\Profiles\ppf858wc.default\searchplugins\google-images.xml [2014-12-21]
FF SearchPlugin: C:\Users\Flavia\AppData\Roaming\Mozilla\Firefox\Profiles\ppf858wc.default\searchplugins\google-maps.xml [2014-12-21]
FF Extension: WOT - C:\Users\Flavia\AppData\Roaming\Mozilla\Firefox\Profiles\ppf858wc.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-26]
FF Extension: Adblock Plus - C:\Users\Flavia\AppData\Roaming\Mozilla\Firefox\Profiles\ppf858wc.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-31]
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-03-21]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-09-25]
FF HKU\S-1-5-21-4132011797-2711336362-2655832662-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKU\S-1-5-21-4132011797-2711336362-2655832662-1000\...\Firefox\Extensions: [{282BBB71-6301-4E39-9F74-00210BB4E0B3}] - C:\Users\Flavia\AppData\Local\{282BBB71-6301-4E39-9F74-00210BB4E0B3}
FF Extension: XULRunner - C:\Users\Flavia\AppData\Local\{282BBB71-6301-4E39-9F74-00210BB4E0B3} [2011-04-30]
Chrome:
=======
CHR Profile: C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-02-24]
CHR Extension: (Google Search) - C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-02-24]
CHR Extension: (avast! WebRep) - C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda [2012-03-08]
CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk [2012-02-24]
CHR Extension: (Gmail) - C:\Users\Flavia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-02-24]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-19]
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [Not Found]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-05-03] (Avast Software s.r.o.)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3207800 2015-05-03] (Avast Software)
S2 DTSRVC; C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe [65536 2007-10-11] () [File not signed]
S2 FoxitCloudUpdateService; C:\Program Files\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [244392 2015-05-11] (Foxit Software Inc.)
R2 hmpalertsvc; C:\Program Files\HitmanPro.Alert\hmpalert.exe [1876816 2014-12-20] (SurfRight B.V.)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [116224 2012-02-09] ()
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
S2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) [File not signed]
S3 npggsvc; C:\Windows\system32\GameMon.des [4573608 2013-05-13] (INCA Internet Co., Ltd.)
S2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15904544 2014-02-05] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1931632 2015-05-03] (Electronic Arts)
S3 OverwolfUpdaterService; C:\Program Files\Overwolf\OverwolfUpdater.exe [18360 2012-06-21] (Overwolf Ltd)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S3 xsherlock; C:\Windows\system32\xsherlock.xem [670816 2012-07-01] (Wellbia.com Co., Ltd.) [File not signed]
S3 NMIndexingService; "C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 1394hub; C:\Windows\System32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 acedrv11; C:\Windows\system32\drivers\acedrv11.sys [185472 2010-02-24] (Protect Software GmbH)
S3 apf003; C:\Windows\system32\apf003.sys [13232 2012-03-16] () [File not signed]
S3 apf004; C:\Windows\system32\apf004.sys [15112 2014-01-08] ()
R1 AsrAppCharger; C:\Windows\System32\DRIVERS\AsrAppCharger.sys [15656 2011-05-10] (Windows (R) Win 7 DDK provider)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24144 2015-05-03] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [74976 2015-05-03] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81728 2015-05-03] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49904 2015-05-03] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [787760 2015-05-03] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427992 2015-05-03] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [106912 2015-05-03] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [209048 2015-05-03] ()
R2 hmpalert; C:\Windows\System32\drivers\hmpalert.sys [75640 2014-12-20] ()
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [21952 2012-02-09] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [21952 2012-02-09] ()
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD.sys [40936 2013-01-19] ()
R3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [28944 2008-02-29] (Logitech, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [46080 2011-11-10] (Intel Corporation)
R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [734208 2009-05-25] (Ralink Technology Corp.)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2013-12-27] (NVIDIA Corporation)
R3 PdiPorts; C:\Windows\System32\Drivers\PdiPorts.sys [15920 2006-11-16] (Portrait Displays, Inc.)
S3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1311232 2009-07-14] (NXP Semiconductors)
S3 S6000KNT; C:\Windows\System32\Drivers\S6000KNT.sys [3328472 2011-07-28] (Windows (R) Win 7 DDK provider)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [466008 2013-06-17] (Duplex Secure Ltd.)
S3 TelekomNM3; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM3.sys [35040 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
S3 TesSafe; C:\Windows\system32\TesSafe.sys [834832 2015-03-06] (TENCENT)
S3 usbUDisc; C:\Windows\System32\DRIVERS\USBDrv.sys [13824 2012-07-28] (Scott)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220752 2015-05-03] (Avast Software)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [31680 2015-05-13] ()
R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.)
S2 adfs; No ImagePath
S3 catchme; \??\C:\Users\Flavia\AppData\Local\Temp\catchme.sys [X]
S3 EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [X]
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfd.sys [X]
S3 StarOpen; No ImagePath
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 taphss; system32\DRIVERS\taphss.sys [X]
S3 taphss6; system32\DRIVERS\taphss6.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 vtany; \??\C:\Windows\vtany.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-13 08:04 - 2015-05-13 08:05 - 00023017 _____ () C:\Users\Flavia\Desktop\FRST.txt
2015-05-13 08:04 - 2015-05-13 08:04 - 01141248 _____ (Farbar) C:\Users\Flavia\Desktop\FRST.exe
2015-05-13 08:01 - 2015-05-13 08:01 - 00001465 _____ () C:\Users\Flavia\Desktop\JRT.txt
2015-05-13 07:59 - 2015-05-13 07:59 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-FLAVIA-PC-Windows-7-Ultimate-(32-bit).dat
2015-05-13 07:59 - 2015-05-13 07:59 - 00000000 ____D () C:\RegBackup
2015-05-13 07:43 - 2015-05-13 07:59 - 00086976 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2015-05-12 23:32 - 2015-05-12 23:33 - 00000000 ____D () C:\AdwCleaner
2015-05-12 23:29 - 2015-05-12 23:27 - 02720307 _____ (Thisisu) C:\Users\Flavia\Desktop\JRT.exe
2015-05-12 23:29 - 2015-05-12 23:26 - 02209792 _____ () C:\Users\Flavia\Desktop\AdwCleaner_4.204.exe
2015-05-12 23:21 - 2015-05-12 23:21 - 00026009 _____ () C:\Users\Flavia\Desktop\mbam.txt
2015-05-12 22:31 - 2015-05-12 23:19 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-12 22:30 - 2015-05-12 22:30 - 00001028 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-12 22:30 - 2015-05-12 22:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-12 22:30 - 2015-05-12 22:30 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-12 22:30 - 2015-05-12 22:30 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-05-12 22:30 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-05-12 22:30 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-05-12 22:30 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-05-12 22:29 - 2015-05-12 22:29 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Flavia\Downloads\mbam-setup-2.1.6.1022.exe
2015-05-12 21:48 - 2015-05-12 21:50 - 00079509 _____ () C:\Users\Flavia\Downloads\Addition.txt
2015-05-12 21:47 - 2015-05-13 08:04 - 00000000 ____D () C:\FRST
2015-05-12 21:47 - 2015-05-12 21:50 - 00064531 _____ () C:\Users\Flavia\Downloads\FRST.txt
2015-05-12 21:45 - 2015-05-12 21:45 - 01141248 _____ (Farbar) C:\Users\Flavia\Downloads\FRST.exe
2015-05-12 18:47 - 2015-05-12 18:47 - 00002059 _____ () C:\Users\Public\Desktop\Foxit Reader.lnk
2015-05-12 18:47 - 2015-05-12 18:47 - 00000000 ____D () C:\Users\Public\Foxit Software
2015-05-12 18:46 - 2015-05-12 18:46 - 00000000 ____D () C:\Program Files\Foxit Software
2015-05-12 00:47 - 2015-05-12 00:47 - 00000000 ____D () C:\Users\Flavia\AppData\Roaming\Real
2015-05-11 19:45 - 2015-05-11 19:45 - 00000000 __SHD () C:\found.000
2015-05-11 18:20 - 2015-04-18 11:03 - 00272296 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2015-05-11 18:20 - 2015-04-18 11:03 - 00191400 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2015-05-11 18:20 - 2015-04-18 11:03 - 00190888 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2015-05-11 18:20 - 2015-04-18 11:03 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-05-08 14:49 - 2015-05-08 14:49 - 00108513 _____ () C:\Users\Flavia\Downloads\Swim Suit v2.package
2015-05-08 14:40 - 2015-05-08 14:40 - 00009928 ____N () C:\bootsqm.dat
2015-05-08 14:25 - 2015-05-08 14:25 - 00412306 _____ () C:\Users\Flavia\Downloads\Sims4Krampus_RandomBathingsuits.package
2015-05-08 14:25 - 2015-05-08 14:25 - 00412243 _____ () C:\Users\Flavia\Downloads\1271248.zip
2015-05-08 14:20 - 2015-05-08 14:20 - 11148041 _____ () C:\Users\Flavia\Downloads\1274607.zip
2015-05-08 14:19 - 2015-05-08 14:19 - 00247066 _____ () C:\Users\Flavia\Downloads\1294924.zip
2015-05-08 14:08 - 2015-05-08 14:18 - 00466431 _____ () C:\Users\Flavia\Downloads\Birba32_fy_BulletSwimsuit.package
2015-05-08 14:05 - 2015-05-08 14:07 - 00530134 _____ () C:\Users\Flavia\Downloads\Birba32_fy_AlphaStringSwimsuit.package
2015-05-08 13:51 - 2015-05-08 13:51 - 00559198 _____ () C:\Users\Flavia\Downloads\Leather vest with tube top [CB].package
2015-05-08 13:51 - 2015-05-08 13:51 - 00326145 _____ () C:\Users\Flavia\Downloads\1Z_outfit_fem_sunny_Otshorts_neu3F.package
2015-05-07 21:35 - 2015-05-07 21:35 - 01135032 _____ () C:\Users\Flavia\Downloads\uktrash_SundaySweaterDress.package
2015-05-07 21:35 - 2015-05-07 21:35 - 00143756 _____ () C:\Users\Flavia\Downloads\Wolfcry_LaceJeansShort.package
2015-05-07 21:31 - 2015-05-07 21:31 - 01485427 _____ () C:\Users\Flavia\Downloads\S4_DelicateLace_Mh75.package
2015-05-07 21:30 - 2015-05-07 21:30 - 00638215 _____ () C:\Users\Flavia\Downloads\Simsimay_2DyBlazer.package
2015-05-07 21:29 - 2015-05-07 21:29 - 00460843 _____ () C:\Users\Flavia\Downloads\uktrash_CropTankTop.package
2015-05-07 21:29 - 2015-05-07 21:29 - 00411079 _____ () C:\Users\Flavia\Downloads\1285044.zip
2015-05-07 21:28 - 2015-05-07 21:28 - 00292353 _____ () C:\Users\Flavia\Downloads\simsoertchen_white top sexy - kawaii -.package
2015-05-07 21:27 - 2015-05-07 21:27 - 00252514 _____ () C:\Users\Flavia\Downloads\Printed Crop tops.package
2015-05-07 21:27 - 2015-05-07 21:27 - 00151527 _____ () C:\Users\Flavia\Downloads\longlivetherecklessandthesims_yfTop_SweaterOffShoulder_AWG.package
2015-05-07 21:24 - 2015-05-07 21:24 - 00646329 _____ () C:\Users\Flavia\Downloads\LollaLeeloo_F_LaceBodycon (1).package
2015-05-07 21:24 - 2015-05-07 21:24 - 00587743 _____ () C:\Users\Flavia\Downloads\LollaLeeloo_F_Longsleeve.package
2015-05-07 21:23 - 2015-05-07 21:23 - 01913334 _____ () C:\Users\Flavia\Downloads\uktrash_BasicsLongSleeve.package
2015-05-07 21:23 - 2015-05-07 21:23 - 00923513 _____ () C:\Users\Flavia\Downloads\~Zodapop~ (S4) Stripe Print Knitted Dress.package
2015-05-07 21:22 - 2015-05-07 21:22 - 00493988 _____ () C:\Users\Flavia\Downloads\~Zodapop~ (S4) Tartan Check Crop Top.package
2015-05-07 21:18 - 2015-05-07 21:18 - 02086542 _____ () C:\Users\Flavia\Downloads\Metens_Serenity.package
2015-05-07 21:17 - 2015-05-07 21:17 - 00210168 _____ () C:\Users\Flavia\Downloads\2.package
2015-05-07 21:07 - 2015-05-07 21:07 - 01212670 _____ () C:\Users\Flavia\Downloads\Birba32_fy_winterbootpastel.package
2015-05-07 21:06 - 2015-05-07 21:06 - 00971151 _____ () C:\Users\Flavia\Downloads\S-Club LL thesims4 eyecolors 09.package
2015-05-07 21:05 - 2015-05-07 21:05 - 01860807 _____ () C:\Users\Flavia\Downloads\SL_yf_ZuhairMurad_Gown1.package
2015-05-07 21:03 - 2015-05-07 21:03 - 00805049 _____ () C:\Users\Flavia\Downloads\BL_Sequin Blazer.package
2015-05-07 11:44 - 2015-05-07 11:44 - 00321678 _____ () C:\Users\Flavia\Downloads\S4FD_MissLicious_Tanks.package
2015-05-07 11:44 - 2015-05-07 11:44 - 00132781 _____ () C:\Users\Flavia\Downloads\Jeans.package
2015-05-07 11:42 - 2015-05-07 11:42 - 00291721 _____ () C:\Users\Flavia\Downloads\top renda dani's.package
2015-05-07 11:41 - 2015-05-07 11:41 - 00169125 _____ () C:\Users\Flavia\Downloads\cutesims4_gtw top india.package
2015-05-07 11:40 - 2015-05-07 11:40 - 01976727 _____ () C:\Users\Flavia\Downloads\1294014.zip
2015-05-07 11:39 - 2015-05-07 11:39 - 01373730 _____ () C:\Users\Flavia\Downloads\Birba32_fy_LaceCipriaDress.package
2015-05-07 11:39 - 2015-05-07 11:39 - 00345945 _____ () C:\Users\Flavia\Downloads\Cleotopia-MiniShortsRippedColorful.package
2015-05-07 11:38 - 2015-05-07 11:38 - 00504146 _____ () C:\Users\Flavia\Downloads\Spring Dress set.package
2015-05-07 11:37 - 2015-05-07 11:37 - 00668569 _____ () C:\Users\Flavia\Downloads\Milk Lace Dress.package
2015-05-07 11:37 - 2015-05-07 11:37 - 00074451 _____ () C:\Users\Flavia\Downloads\cutesims4_romantic_White_Tube.package
2015-05-07 11:36 - 2015-05-07 11:36 - 00500120 _____ () C:\Users\Flavia\Downloads\Aztec Top by Pinkzombiecupcake.package
2015-05-07 11:36 - 2015-05-07 11:36 - 00451796 _____ () C:\Users\Flavia\Downloads\Blusa Renda Branca.package
2015-05-07 11:33 - 2015-05-07 11:33 - 00090648 _____ () C:\Users\Flavia\Downloads\Leeah_yfShoes_CalfCowboy_SuedeChocolate.package
2015-05-07 11:30 - 2015-05-07 11:30 - 00607019 _____ () C:\Users\Flavia\Downloads\Madlen Scafati Boots.package
2015-05-07 11:30 - 2015-05-07 11:30 - 00403762 _____ () C:\Users\Flavia\Downloads\Madlen Cirino Shoes.package
2015-05-07 11:29 - 2015-05-07 11:29 - 00710251 _____ () C:\Users\Flavia\Downloads\Madlen Tiziano Shoes.package
2015-05-07 11:29 - 2015-05-07 11:29 - 00511975 _____ () C:\Users\Flavia\Downloads\Madlen Umbria Shoes.package
2015-05-07 11:28 - 2015-05-07 11:28 - 00387493 _____ () C:\Users\Flavia\Downloads\Madlen Livia Shoes.package
2015-05-07 11:27 - 2015-05-07 11:28 - 00417972 _____ () C:\Users\Flavia\Downloads\Madlen Eris Boots.package
2015-05-07 11:27 - 2015-05-07 11:27 - 00603820 _____ () C:\Users\Flavia\Downloads\Madlen Ambrogio Shoes.package
2015-05-07 11:26 - 2015-05-07 11:26 - 01278415 _____ () C:\Users\Flavia\Downloads\1294236.zip
2015-05-07 11:26 - 2015-05-07 11:26 - 00704730 _____ () C:\Users\Flavia\Downloads\Madlen Nineveh Shoes.package
2015-05-07 11:25 - 2015-05-07 11:25 - 00497960 _____ () C:\Users\Flavia\Downloads\Madlen Novara Sandals.package
2015-05-07 11:22 - 2015-05-07 11:22 - 00287377 _____ () C:\Users\Flavia\Downloads\Toska.zip
2015-05-07 11:22 - 2015-05-07 11:22 - 00134871 _____ () C:\Users\Flavia\Downloads\ZIP UP BOOTS.package
2015-05-07 11:21 - 2015-05-07 11:21 - 00756084 _____ () C:\Users\Flavia\Downloads\Madlen Neroni Sneakers (Male).package
2015-05-07 11:21 - 2015-05-07 11:21 - 00161515 _____ () C:\Users\Flavia\Downloads\Vans Classic Slip-On Core (male) by Pinzombiecupcake.package
2015-05-07 11:20 - 2015-05-07 11:20 - 00451295 _____ () C:\Users\Flavia\Downloads\Madlen Orlando Shoes (Male).package
2015-05-07 11:20 - 2015-05-07 11:20 - 00187334 _____ () C:\Users\Flavia\Downloads\THL_NikeShoesSB_M.package
2015-05-07 11:18 - 2015-05-07 11:19 - 00095991 _____ () C:\Users\Flavia\Downloads\Jazminerev.zip
2015-05-07 11:18 - 2015-05-07 11:18 - 00101879 _____ () C:\Users\Flavia\Downloads\TugmeL-S4_Daphne-FYA.zip
2015-05-07 11:17 - 2015-05-07 11:17 - 00102633 _____ () C:\Users\Flavia\Downloads\AlyssaDíazPérezbySimFabulous.zip
2015-05-07 11:17 - 2015-05-07 11:17 - 00091261 _____ () C:\Users\Flavia\Downloads\MsBlue_JasminBlue.zip
2015-05-07 11:16 - 2015-05-07 11:16 - 00089561 _____ () C:\Users\Flavia\Downloads\MK_KendallEdwards.zip
2015-05-07 11:15 - 2015-05-07 11:15 - 00095291 _____ () C:\Users\Flavia\Downloads\Bryant Caliente.zip
2015-05-07 11:14 - 2015-05-07 11:15 - 00090187 _____ () C:\Users\Flavia\Downloads\MaseoUehara-Munter_Bacon2.zip
2015-05-07 11:12 - 2015-05-07 11:12 - 04833426 _____ () C:\Users\Flavia\Downloads\1291079.zip
2015-05-07 11:12 - 2015-05-07 11:12 - 00385291 _____ () C:\Users\Flavia\Downloads\MsBlue_LauraSkin.package
2015-05-07 11:10 - 2015-05-07 11:10 - 00448444 _____ () C:\Users\Flavia\Downloads\curbs_hat4_rosa.package
2015-05-07 11:10 - 2015-05-07 11:10 - 00278001 _____ () C:\Users\Flavia\Downloads\altea127 Visor Hat .package
2015-05-07 11:09 - 2015-05-07 11:09 - 00648473 _____ () C:\Users\Flavia\Downloads\[SrslyBrownie] (S4) Sheer Leggings .package
2015-05-07 11:09 - 2015-05-07 11:09 - 00119657 _____ () C:\Users\Flavia\Downloads\Vault101Hat.package
2015-05-07 11:08 - 2015-05-07 11:08 - 00686972 _____ () C:\Users\Flavia\Downloads\Birba32_fy_SideBandLeggings.package
2015-05-07 11:07 - 2015-05-07 11:07 - 00338585 _____ () C:\Users\Flavia\Downloads\cutesims4_replay skinny jeans - set.package
2015-05-07 11:07 - 2015-05-07 11:07 - 00056175 _____ () C:\Users\Flavia\Downloads\PDsims_SpikedBobbySocks.package
2015-05-07 11:06 - 2015-05-07 11:06 - 02335029 _____ () C:\Users\Flavia\Downloads\[SrslySims] (S4) High Waist PVC Leggings.package
2015-05-07 11:06 - 2015-05-07 11:06 - 00156997 _____ () C:\Users\Flavia\Downloads\TS4 Stockings Cat by Irink@a.package
2015-05-07 11:05 - 2015-05-07 11:05 - 01379143 _____ () C:\Users\Flavia\Downloads\altea127 Sonia Tights.package
2015-05-07 11:05 - 2015-05-07 11:05 - 00049164 _____ () C:\Users\Flavia\Downloads\Metens_Seduction.package
2015-05-07 11:03 - 2015-05-07 11:03 - 00395555 _____ () C:\Users\Flavia\Downloads\[Sintiklia]Eyeshadow 7.package
2015-05-07 11:02 - 2015-05-07 11:02 - 00338242 _____ () C:\Users\Flavia\Downloads\Alin22_NecklaceShapes.package
2015-05-07 11:01 - 2015-05-07 11:02 - 00718560 _____ () C:\Users\Flavia\Downloads\LLSIMS_LayeredNecklace_001.package
2015-05-07 11:01 - 2015-05-07 11:01 - 00810278 _____ () C:\Users\Flavia\Downloads\1269610.zip
2015-05-07 11:00 - 2015-05-07 11:00 - 00252918 _____ () C:\Users\Flavia\Downloads\Mallard Close.zip
2015-05-07 11:00 - 2015-05-07 11:00 - 00032549 _____ () C:\Users\Flavia\Downloads\Wood_Style.package
2015-05-07 10:59 - 2015-05-07 10:59 - 00427598 _____ () C:\Users\Flavia\Downloads\1Z_dress_marine_neu2D.package
2015-05-07 10:58 - 2015-05-07 10:58 - 00166194 _____ () C:\Users\Flavia\Downloads\SV Earrings with round jewel.package
2015-05-07 10:58 - 2015-05-07 10:58 - 00079101 _____ () C:\Users\Flavia\Downloads\NataliS_Spring and crystal earings FT-FA.package
2015-05-07 10:57 - 2015-05-07 10:57 - 00144082 _____ () C:\Users\Flavia\Downloads\NataliS_Crystal drop earrings FT-FA.package
2015-05-07 10:56 - 2015-05-07 10:56 - 00054561 _____ () C:\Users\Flavia\Downloads\MYOBI-zest-eyes.package
2015-05-07 10:55 - 2015-05-07 10:55 - 00089604 _____ () C:\Users\Flavia\Downloads\MYOBI-jelly-eyemask.package
2015-05-07 10:54 - 2015-05-07 10:54 - 00041317 _____ () C:\Users\Flavia\Downloads\EnticingSims_Feather Tattoo.package
2015-05-07 10:53 - 2015-05-07 10:53 - 01851664 _____ () C:\Users\Flavia\Downloads\MILK Jasmine Skintone.zip
2015-05-07 10:53 - 2015-05-07 10:53 - 00003782 _____ () C:\Users\Flavia\Downloads\cateye.package
2015-05-07 10:51 - 2015-05-07 10:51 - 04378955 _____ () C:\Users\Flavia\Downloads\MILK Divine.package
2015-05-07 10:51 - 2015-05-07 10:51 - 00269171 _____ () C:\Users\Flavia\Downloads\Love Frekles by Pinkzombiecupcake.package
2015-05-07 10:50 - 2015-05-07 10:50 - 00042966 _____ () C:\Users\Flavia\Downloads\MYOBI-samantha-facedetail.package
2015-05-07 10:49 - 2015-05-07 10:49 - 00265490 _____ () C:\Users\Flavia\Downloads\MorganeParis_For_Natalis_Nails_02.package
2015-05-07 10:49 - 2015-05-07 10:49 - 00044856 _____ () C:\Users\Flavia\Downloads\Syrup Lipstick by Baarbiie-GiirL(1).package
2015-05-07 10:48 - 2015-05-07 10:48 - 00209148 _____ () C:\Users\Flavia\Downloads\PS Lip 01.package
2015-05-07 10:47 - 2015-05-07 10:47 - 00217924 _____ () C:\Users\Flavia\Downloads\Aveira_LipglossN3.package
2015-05-07 09:48 - 2015-05-07 09:48 - 00000000 ____D () C:\ProgramData\Aeria Games
2015-05-06 10:32 - 2015-05-06 10:32 - 00001608 _____ () C:\Users\Flavia\Desktop\Echo of Soul.lnk
2015-05-06 10:17 - 2015-05-06 10:17 - 00001950 _____ () C:\Users\Public\Desktop\Aeria Ignite.lnk
2015-05-06 10:17 - 2015-05-06 10:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AeriaGames
2015-05-06 10:17 - 2015-05-06 10:17 - 00000000 ____D () C:\Program Files\Aeria Games
2015-05-06 09:46 - 2015-05-06 10:17 - 00000000 ____D () C:\AeriaGames
2015-05-05 13:00 - 2015-05-05 13:00 - 00268383 _____ () C:\Users\Flavia\Downloads\Cenothera Biennis - by Onyxium.zip
2015-05-05 12:59 - 2015-05-05 12:59 - 00164311 _____ () C:\Users\Flavia\Downloads\MYOBI-opulent-lipcolour.package
2015-05-05 12:58 - 2015-05-05 12:58 - 00772625 _____ () C:\Users\Flavia\Downloads\[EVE62]lipstick1.package
2015-05-05 12:58 - 2015-05-05 12:58 - 00042707 _____ () C:\Users\Flavia\Downloads\Doll Lipstick Nr1. by Baarbiie-GiirL .package
2015-05-05 12:57 - 2015-05-05 12:57 - 00203248 _____ () C:\Users\Flavia\Downloads\S-Club LL thesims4 Lipstick 09.package
2015-05-05 12:57 - 2015-05-05 12:57 - 00062311 _____ () C:\Users\Flavia\Downloads\Autumn dream lipstick by Pinzombiecupcake.package
2015-05-05 12:56 - 2015-05-05 12:56 - 00252650 _____ () C:\Users\Flavia\Downloads\MYOBI-lilt-lipcolour.package
2015-05-05 12:55 - 2015-05-05 12:55 - 00044856 _____ () C:\Users\Flavia\Downloads\Syrup Lipstick by Baarbiie-GiirL.package
2015-05-05 12:54 - 2015-05-05 12:54 - 00003717 _____ () C:\Users\Flavia\Downloads\Doll Eyeliner.package
2015-05-05 12:53 - 2015-05-05 12:53 - 00135801 _____ () C:\Users\Flavia\Downloads\[GrizzlySimr] Sohlein Classy Eyeshadow.package
2015-05-05 12:52 - 2015-05-05 12:52 - 00122500 _____ () C:\Users\Flavia\Downloads\[simbastic] smokey_glitter_eyeshadow.package
2015-05-05 12:52 - 2015-05-05 12:52 - 00043249 _____ () C:\Users\Flavia\Downloads\mormo_eyeshadow1_AF.package
2015-05-05 12:51 - 2015-05-05 12:51 - 01685607 _____ () C:\Users\Flavia\Downloads\MYOBI-fiona-eyeshadow.package
2015-05-05 12:42 - 2015-05-05 12:42 - 00132889 _____ () C:\Users\Flavia\Downloads\S-Club WM thesims4 Eyebrows16 M .package
2015-05-05 12:41 - 2015-05-05 12:41 - 00192771 _____ () C:\Users\Flavia\Downloads\MYOBI-nemo-brows.package
2015-05-05 12:40 - 2015-05-05 12:40 - 19387267 _____ () C:\Users\Flavia\Downloads\1265549.zip
2015-05-05 12:40 - 2015-05-05 12:40 - 01063041 _____ () C:\Users\Flavia\Downloads\SV Summer floral dress.package
2015-05-05 12:39 - 2015-05-05 12:39 - 00109478 _____ () C:\Users\Flavia\Downloads\S-Club WM thesims4 Eyebrows12 F.package
2015-05-05 12:38 - 2015-05-05 12:38 - 04103232 _____ () C:\Users\Flavia\Downloads\Realistic beard By Pinkzombiecupcake.package
2015-05-05 12:38 - 2015-05-05 12:38 - 00025198 _____ () C:\Users\Flavia\Downloads\Eyebrow with 8 colours.package
2015-05-05 12:36 - 2015-05-05 12:37 - 07179080 _____ () C:\Users\Flavia\Downloads\beard nr 2.package
2015-05-05 12:35 - 2015-05-05 12:35 - 08296793 _____ () C:\Users\Flavia\Downloads\Cazy_c119-Nicholas_r.package
2015-05-05 11:18 - 2015-05-05 11:18 - 00494281 _____ () C:\Users\Flavia\Downloads\1268783.zip
2015-05-05 11:17 - 2015-05-05 11:17 - 20023938 _____ () C:\Users\Flavia\Downloads\Stealthic Like Lust (Hair).package
2015-05-05 11:17 - 2015-05-05 11:17 - 00468442 _____ () C:\Users\Flavia\Downloads\1266813.zip
2015-05-05 11:16 - 2015-05-05 11:16 - 23228914 _____ () C:\Users\Flavia\Downloads\Stealthic Haunting (Hair).package
2015-05-05 11:15 - 2015-05-05 11:16 - 19367239 _____ () C:\Users\Flavia\Downloads\Stealthic Hysteria (Hair)(1).package
2015-05-05 11:14 - 2015-05-05 11:14 - 06313851 _____ () C:\Users\Flavia\Downloads\skysims-hair-229(1).package
2015-05-05 11:10 - 2015-05-05 11:11 - 24898232 _____ () C:\Users\Flavia\Downloads\Stealthic Sleepwalking (Hair).package
2015-05-05 11:10 - 2015-05-05 11:10 - 05337936 _____ () C:\Users\Flavia\Downloads\Skysims-hair257g.package
2015-05-05 11:09 - 2015-05-05 11:09 - 17935799 _____ () C:\Users\Flavia\Downloads\Stealthic Captivated (Hair).package
2015-05-05 11:08 - 2015-05-05 11:08 - 06313851 _____ () C:\Users\Flavia\Downloads\skysims-hair-229.package
2015-05-05 11:06 - 2015-05-05 11:06 - 21139442 _____ () C:\Users\Flavia\Downloads\Stealthic Runaway (Hair).package
2015-05-05 11:04 - 2015-05-05 11:04 - 04326482 _____ () C:\Users\Flavia\Downloads\Skysims Hair 208-lok sims4.package
2015-05-05 11:03 - 2015-05-05 11:03 - 21509106 _____ () C:\Users\Flavia\Downloads\Stealthic Vapor (Hair)(1).package
2015-05-05 11:02 - 2015-05-05 11:02 - 11803982 _____ () C:\Users\Flavia\Downloads\Cazy_c172-Izzy_t-e_type2_re.package
2015-05-05 11:01 - 2015-05-05 11:01 - 00208048 _____ () C:\Users\Flavia\Downloads\Tantars Estate.zip
2015-05-05 11:00 - 2015-05-05 11:00 - 23136216 _____ () C:\Users\Flavia\Downloads\Stealthic Midsummer Night (Hair and Acc).package
2015-05-05 11:00 - 2015-05-05 11:00 - 05331542 _____ () C:\Users\Flavia\Downloads\Skysims-hair149.package
2015-05-05 10:59 - 2015-05-05 10:59 - 08029586 _____ () C:\Users\Flavia\Downloads\Nightcrawler AF Hair Turn It Up.package
2015-05-05 10:57 - 2015-05-05 10:57 - 21011847 _____ () C:\Users\Flavia\Downloads\Stealthic Amber Lights (Hair).package
2015-05-05 10:56 - 2015-05-05 10:56 - 07481536 _____ () C:\Users\Flavia\Downloads\Alesso_Circus.zip
2015-05-05 10:55 - 2015-05-05 10:55 - 06149100 _____ () C:\Users\Flavia\Downloads\Skysims-Hair-113.package
2015-05-05 10:53 - 2015-05-05 10:53 - 31996596 _____ () C:\Users\Flavia\Downloads\Stealthic Daughter (Hair).package
2015-05-05 10:52 - 2015-05-05 10:53 - 21697048 _____ () C:\Users\Flavia\Downloads\Stealthic Sanctuary (Hair).package
2015-05-05 10:51 - 2015-05-05 10:51 - 19367239 _____ () C:\Users\Flavia\Downloads\Stealthic Hysteria (Hair).package
2015-05-04 17:59 - 2015-05-04 17:59 - 03451698 _____ () C:\Users\Flavia\Downloads\1427212032d4244028654db8b5795c78.zip
2015-05-04 17:57 - 2015-05-04 17:57 - 02772812 _____ () C:\Users\Flavia\Downloads\141571469380eb3fb6e18314cd5679e3.zip
2015-05-04 17:53 - 2015-05-04 17:53 - 21497179 _____ () C:\Users\Flavia\Downloads\Stealthic Vapor (Hair).package
2015-05-03 21:04 - 2015-05-03 21:04 - 00000000 ____D () C:\Program Files\Origin Games
2015-05-03 20:50 - 2015-05-03 20:50 - 00000000 ____D () C:\Users\Flavia\Documents\Electronic Arts
2015-05-03 20:48 - 2015-05-03 21:04 - 00000000 ____D () C:\Users\Flavia\AppData\Local\Origin
2015-05-03 20:45 - 2015-05-03 20:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2015-05-03 20:45 - 2015-05-03 20:47 - 00000000 ____D () C:\Program Files\Origin
2015-05-03 20:45 - 2015-05-03 20:45 - 00000905 _____ () C:\Users\Public\Desktop\Origin.lnk
2015-05-03 20:43 - 2015-05-03 20:43 - 00000000 ____D () C:\ProgramData\Package Cache
2015-05-03 20:41 - 2015-05-03 20:41 - 00002051 _____ () C:\Users\Public\Desktop\The Sims 4.lnk
2015-05-03 20:41 - 2015-05-03 20:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Sims 4
2015-05-03 20:34 - 2015-05-03 20:34 - 00000000 ____D () C:\Program Files\The Sims 4
2015-05-03 19:57 - 2015-05-03 21:11 - 00000000 ____D () C:\ProgramData\Origin
2015-05-03 19:51 - 2015-05-03 20:45 - 00000000 ____D () C:\ProgramData\Electronic Arts
2015-05-03 12:23 - 2015-05-03 12:23 - 00291312 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-05-03 12:23 - 2015-05-03 12:23 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-04-28 10:53 - 2015-04-28 10:53 - 00000000 ____D () C:\Users\Flavia\Downloads\[FS]Day04
2015-04-23 15:32 - 2015-04-23 15:32 - 00000000 __SHD () C:\Users\Flavia\AppData\Local\EmieBrowserModeList
2015-04-23 15:05 - 2015-04-23 15:05 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-22 11:15 - 2015-05-06 10:31 - 00000000 ____D () C:\Users\Flavia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AeriaGames
2015-04-19 14:10 - 2015-04-19 14:10 - 00000000 ____D () C:\ProgramData\Ahead
2015-04-19 13:58 - 2015-05-12 23:14 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-19 13:58 - 2015-04-19 13:58 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-19 13:58 - 2015-04-19 13:58 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-18 11:04 - 2015-04-18 11:04 - 00000000 ____D () C:\Program Files\Common Files\Java
2015-04-18 11:03 - 2015-04-18 11:03 - 00000000 ____D () C:\ProgramData\Oracle
2015-04-16 10:50 - 2015-04-18 11:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-04-15 09:39 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-15 09:39 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-15 09:39 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-15 09:39 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-15 09:39 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-15 09:39 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-15 09:39 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-15 09:39 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-15 09:39 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-15 09:39 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-15 09:39 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-15 09:38 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-15 09:38 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-15 09:38 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-15 09:38 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-15 09:38 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-15 09:38 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-15 09:38 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-15 09:38 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-15 09:38 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-15 09:38 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-15 09:38 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 09:38 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-15 09:38 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-15 09:38 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-15 09:38 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-15 09:38 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-15 09:38 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-15 09:38 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-15 09:38 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-15 09:38 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-15 09:38 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-15 09:38 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-15 09:38 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-15 09:38 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-15 09:38 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-15 09:38 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-15 09:38 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-15 09:38 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-15 09:38 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-15 09:38 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-15 09:38 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-15 09:38 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-15 09:38 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-15 09:38 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-15 09:38 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-15 09:38 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-15 09:38 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 09:38 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-15 09:38 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-04-15 09:38 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 09:38 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-15 09:38 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-15 09:38 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-04-15 09:38 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-04-15 09:38 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 09:38 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-15 09:38 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-15 09:38 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-15 09:38 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-15 09:38 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-04-15 09:38 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-04-15 09:38 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-15 09:38 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-15 09:38 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-15 09:38 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-15 09:38 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-15 09:38 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-15 09:38 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-15 09:38 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 09:38 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-15 09:38 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-15 09:38 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-15 09:38 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 09:38 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 09:38 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 09:38 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-15 09:38 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-15 09:38 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-15 09:38 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 09:38 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-15 09:37 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-15 09:37 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-13 08:02 - 2012-11-09 19:40 - 00000000 ____D () C:\Users\Flavia\AppData\Local\CrashDumps
2015-05-13 07:59 - 2012-11-09 19:08 - 00031680 _____ () C:\Windows\system32\Drivers\WPRO_41_2001.sys
2015-05-13 07:59 - 2011-07-09 18:33 - 00000000 ____D () C:\Users\Flavia\AppData\Local\PMB Files
2015-05-13 07:52 - 2009-07-14 06:34 - 00024368 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-13 07:52 - 2009-07-14 06:34 - 00024368 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-13 07:49 - 2009-12-28 01:26 - 01756880 _____ () C:\Windows\WindowsUpdate.log
2015-05-13 07:45 - 2014-12-20 14:36 - 00000000 ____D () C:\Windows\CryptoGuard
2015-05-13 07:44 - 2011-09-25 14:34 - 00145542 _____ () C:\Windows\setupact.log
2015-05-13 07:43 - 2010-01-20 16:10 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-05-13 07:43 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-13 07:42 - 2011-09-25 16:31 - 00623506 _____ () C:\Windows\PFRO.log
2015-05-12 23:32 - 2014-08-14 11:55 - 00651504 _____ () C:\Windows\system32\perfh01F.dat
2015-05-12 23:32 - 2014-08-14 11:55 - 00140826 _____ () C:\Windows\system32\perfc01F.dat
2015-05-12 23:32 - 2011-05-21 00:31 - 00423246 _____ () C:\Windows\system32\perfh012.dat
2015-05-12 23:32 - 2011-05-21 00:31 - 00121210 _____ () C:\Windows\system32\perfc012.dat
2015-05-12 23:32 - 2010-01-20 16:25 - 00411600 _____ () C:\Windows\system32\perfh011.dat
2015-05-12 23:32 - 2010-01-20 16:25 - 00122926 _____ () C:\Windows\system32\perfc011.dat
2015-05-12 23:32 - 2009-12-27 16:41 - 04400078 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-12 23:11 - 2011-03-30 17:25 - 00000000 ____D () C:\Windows\Minidump
2015-05-12 18:48 - 2013-01-31 14:12 - 00000000 ____D () C:\Users\Flavia\AppData\Roaming\Foxit Software
2015-05-12 18:47 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2015-05-12 16:07 - 2009-12-27 16:44 - 00000000 ____D () C:\Users\Flavia
2015-05-12 00:45 - 2011-09-15 17:48 - 00000000 ____D () C:\Download
2015-05-12 00:43 - 2014-05-27 12:07 - 00000000 ____D () C:\Users\Flavia\AppData\Local\Samsung
2015-05-12 00:43 - 2009-12-27 18:54 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-05-11 20:55 - 2011-09-25 15:14 - 00000000 ____D () C:\Windows\pss
2015-05-11 20:38 - 2012-12-05 21:15 - 00000000 ____D () C:\Users\Flavia\AppData\Local\Spotify
2015-05-11 20:37 - 2012-12-05 21:14 - 00000000 ____D () C:\Users\Flavia\AppData\Roaming\Spotify
2015-05-11 18:39 - 2013-08-02 10:35 - 00000992 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2015-05-11 18:21 - 2015-01-23 17:12 - 00000000 ____D () C:\Program Files\Common Files\Adobe AIR
2015-05-03 20:05 - 2013-03-16 15:21 - 00000000 ____D () C:\Users\Flavia\AppData\Roaming\Origin
2015-05-03 12:23 - 2014-05-16 17:00 - 00024144 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2015-05-03 12:23 - 2014-01-07 17:20 - 00106912 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-05-03 12:23 - 2013-03-17 18:59 - 00209048 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2015-05-03 12:23 - 2013-03-17 18:59 - 00049904 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2015-05-03 12:23 - 2012-02-24 15:33 - 00081728 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-05-03 12:23 - 2011-09-25 16:52 - 00427992 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys
2015-05-03 12:23 - 2011-09-25 16:51 - 00787760 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-05-03 12:23 - 2011-09-25 16:51 - 00074976 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-04-30 16:29 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-26 19:18 - 2012-04-18 19:53 - 00000000 ____D () C:\Users\Flavia\AppData\Roaming\Audacity
2015-04-26 19:03 - 2012-07-28 11:45 - 00000000 ____D () C:\Users\Flavia\Downloads\eBooks
2015-04-26 18:49 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-04-25 16:03 - 2013-11-01 15:29 - 00000000 ____D () C:\Users\Flavia\Downloads\Dokumente
2015-04-25 09:54 - 2013-01-19 15:17 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-22 11:15 - 2013-03-15 12:46 - 00000000 ___HD () C:\Windows\msdownld.tmp
2015-04-22 11:15 - 2010-08-06 13:49 - 00000000 ____D () C:\Windows\system32\directx
2015-04-19 14:00 - 2015-01-16 12:23 - 00000000 ____D () C:\Users\Flavia\AppData\Local\Adobe
2015-04-19 13:57 - 2009-12-28 16:55 - 00000000 ____D () C:\Program Files\Adobe
2015-04-19 13:56 - 2009-12-28 16:55 - 00000000 ____D () C:\ProgramData\Adobe
2015-04-18 11:03 - 2013-02-21 13:11 - 00000000 ____D () C:\Program Files\Java
2015-04-16 09:53 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-15 10:44 - 2014-12-10 19:18 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-15 10:44 - 2014-05-01 19:52 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-15 10:44 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\tr-TR
2015-04-15 10:44 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\ko-KR
2015-04-15 10:44 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\ja-JP
2015-04-15 10:44 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-04-15 10:18 - 2013-07-11 10:02 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-15 10:10 - 2009-12-27 17:09 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-15 10:09 - 2009-12-27 18:01 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-13 18:07 - 2015-03-09 17:41 - 00000000 ____D () C:\Users\Flavia\Top Body
==================== Files in the root of some directories =======
2014-01-20 15:12 - 2014-01-27 16:12 - 0000085 _____ () C:\Users\Flavia\AppData\Roaming\WB.CFG
2011-04-29 13:55 - 2011-04-29 13:55 - 0009216 _____ () C:\Users\Flavia\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2011-03-30 19:59 - 2011-07-22 13:50 - 0000000 _____ () C:\Users\Flavia\AppData\Local\Itiqeyabeguyoya.bin
2011-03-30 19:59 - 2011-07-21 10:02 - 0000120 _____ () C:\Users\Flavia\AppData\Local\Kholohiyesupa.dat
2015-04-10 16:47 - 2015-04-10 16:47 - 0005197 _____ () C:\Users\Flavia\AppData\Local\recently-used.xbel
2012-04-25 22:36 - 2012-07-11 23:50 - 0007597 _____ () C:\Users\Flavia\AppData\Local\resmon.resmoncfg
2011-09-25 10:24 - 2011-09-25 10:24 - 0000000 _____ () C:\Users\Flavia\AppData\Local\{07929EE3-DAD7-4105-8DF8-2CE403B4C7E2}
2015-02-27 18:27 - 2015-03-06 13:11 - 0000040 _____ () C:\ProgramData\DT0001.dat
2015-02-25 22:32 - 2015-03-06 13:11 - 0000040 _____ () C:\ProgramData\DT0006.dat
2010-02-22 15:38 - 2010-02-22 15:38 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
Files to move or delete:
====================
C:\ProgramData\DT0001.dat
C:\ProgramData\DT0006.dat
Some content of TEMP:
====================
C:\Users\Flavia\AppData\Local\temp\dxwebsetup.exe
C:\Users\Flavia\AppData\Local\temp\FoxitUpdater.exe
C:\Users\Flavia\AppData\Local\temp\jre-8u45-windows-au.exe
C:\Users\Flavia\AppData\Local\temp\Quarantine.exe
C:\Users\Flavia\AppData\Local\temp\sqlite3.dll
C:\Users\Flavia\AppData\Local\temp\uninst.exe
C:\Users\Flavia\AppData\Local\temp\uninstall_complete.exe
C:\Users\Flavia\AppData\Local\temp\vcredist_x86.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-05 10:31
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- --- |