kaborska | 18.06.2014 13:32 | Addition Log Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version:16-06-2014
Ran by Sina at 2014-06-18 12:47:23
Running from C:\Users\Sina\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
Adobe Acrobat X Pro - English, Français, Deutsch (HKLM\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.10 - Adobe Systems)
Adobe Flash Player 14 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 14.0.0.125 - Adobe Systems Incorporated)
Apple Application Support (HKLM\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
avast! Free Antivirus (HKLM\...\Avast) (Version: 9.0.2018 - Avast Software)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{CA75CBF9-B078-47CB-ABA3-74EFD4FC9A43}) (Version: - Microsoft)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{CA75CBF9-B078-47CB-ABA3-74EFD4FC9A43}) (Version: - Microsoft)
Enhanced Multimedia Keyboard Solution (HKLM\...\KBD) (Version: - )
Google Chrome (HKLM\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.)
Google Earth Plug-in (HKLM\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (Version: 1.3.24.7 - Google Inc.) Hidden
HWiNFO32 Version 4.40 (HKLM\...\HWiNFO32_is1) (Version: 4.40 - Martin Malík - REALiX)
Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 16.3 - Intel)
iTunes (HKLM\...\{0718A90E-93AA-49AF-A4FE-0165ACD91DF0}) (Version: 11.2.2.3 - Apple Inc.)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Project MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Project Professional 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Project Professional 2010 (HKLM\...\Office14.PRJPROR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Mozilla Firefox 27.0 (x86 de) (HKLM\...\Mozilla Firefox 27.0 (x86 de)) (Version: 27.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 27.0 - Mozilla)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{58FA40EF-ABA9-4FED-AD3D-318A6073934D}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (Version: - Microsoft) Hidden
SpywareBlaster 5.0 (HKLM\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.24.0 - Synaptics Incorporated)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817396) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{39767ECA-1731-45DB-AB5B-6BF40E151D66}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{BA610006-2C39-4419-9834-CF61AB24810A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.PRJPROR_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PRJPROR_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version: - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version: - Microsoft)
Update for Microsoft Word 2010 (KB2880529) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{B9B89E01-5B6B-4F73-BC34-B2C0D8ACB4CD}) (Version: - Microsoft)
Validity Sensors DDK (HKLM\...\{62A20ECA-920E-4052-BF77-88C78DD20FAA}) (Version: 3.1.374 - Validity Sensors, Inc.)
==================== Restore Points =========================
13-06-2014 10:41:45 Windows Update
14-06-2014 05:00:47 Windows Update
14-06-2014 19:44:15 Windows Update
16-06-2014 09:19:49 Windows Update
16-06-2014 20:06:01 Wiederherstellungsvorgang
16-06-2014 20:12:24 avast! antivirus system restore point
16-06-2014 20:17:04 Wiederherstellungsvorgang
16-06-2014 20:17:11 Windows Update
16-06-2014 20:30:25 Windows Update
16-06-2014 20:44:34 Windows Update
17-06-2014 08:39:24 Wiederherstellungsvorgang
17-06-2014 08:44:53 avast! antivirus system restore point
17-06-2014 08:51:42 Windows Update
17-06-2014 10:37:18 Windows Update
17-06-2014 11:21:23 Windows Update
17-06-2014 13:30:07 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:04 - 2013-12-01 23:03 - 00000875 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 activate.adobe.com
==================== Scheduled Tasks (whitelisted) =============
Task: {356C1FA7-B0AE-4AE2-B100-CF7AA114F747} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd)
Task: {35BFECF4-F387-4211-827D-03F5B1923106} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-02-06] (Google Inc.)
Task: {3D27857A-BF17-468C-9B4D-5799D989436F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-13] (Adobe Systems Incorporated)
Task: {615AC445-6D1D-4CAC-A0AD-931AAF3E5FAE} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files\Desk 365\desk365.exe <==== ATTENTION
Task: {67ED2531-8310-42A1-BB5F-8462298D8017} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-02-06] (Google Inc.)
Task: {94A0C6FE-A7C1-48D3-9D8C-F4D418BBAAB7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {C53F1409-FFFC-481E-8F03-414C7DAB84E1} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-05-27] (AVAST Software)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-06-18 11:56 - 2014-06-18 11:56 - 02776064 _____ () C:\Program Files\AVAST Software\Avast\defs\14061800\algo.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2014-02-12 21:58 - 2014-02-12 21:58 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 21:58 - 2014-02-12 21:58 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-10-17 23:28 - 2013-10-17 23:28 - 00024064 _____ () C:\Windows\system32\valWBFPolicyService.exe
2014-01-30 22:57 - 2014-01-30 22:57 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-05-08 13:22 - 2014-05-08 13:22 - 00019968 _____ () C:\Program Files\Adobe\Acrobat 10.0\Acrobat\locale\de_de\acrotray.deu
2014-06-12 21:14 - 2014-06-05 15:58 - 00716616 _____ () C:\Program Files\Google\Chrome\Application\35.0.1916.153\libglesv2.dll
2014-06-12 21:14 - 2014-06-05 15:58 - 00126280 _____ () C:\Program Files\Google\Chrome\Application\35.0.1916.153\libegl.dll
2014-06-12 21:14 - 2014-06-05 15:58 - 04217672 _____ () C:\Program Files\Google\Chrome\Application\35.0.1916.153\pdf.dll
2014-06-12 21:14 - 2014-06-05 15:58 - 00414536 _____ () C:\Program Files\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll
2014-06-12 21:14 - 2014-06-05 15:58 - 01732424 _____ () C:\Program Files\Google\Chrome\Application\35.0.1916.153\ffmpegsumo.dll
2014-06-12 21:14 - 2014-06-05 15:58 - 14612296 _____ () C:\Program Files\Google\Chrome\Application\35.0.1916.153\PepperFlash\pepflashplayer.dll
2014-06-18 12:40 - 2014-06-18 12:40 - 00050477 _____ () C:\Users\Sina\Downloads\Defogger.exe
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== MSCONFIG/TASK MANAGER disabled items =========
==================== Faulty Device Manager Devices =============
Name: Basissystemgerät
Description: Basissystemgerät
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Basissystemgerät
Description: Basissystemgerät
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: iSafeNetFilter
Description: iSafeNetFilter
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: iSafeNetFilter
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (06/17/2014 05:56:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 640931
Error: (06/17/2014 05:56:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 640931
Error: (06/17/2014 05:56:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (06/17/2014 05:56:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 639932
Error: (06/17/2014 05:56:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 639932
Error: (06/17/2014 05:56:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (06/17/2014 05:56:33 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 638934
Error: (06/17/2014 05:56:33 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 638934
Error: (06/17/2014 05:56:33 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (06/17/2014 05:56:32 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 637889
System errors:
=============
Error: (06/18/2014 00:05:33 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (06/18/2014 00:04:33 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
iSafeNetFilter
Error: (06/18/2014 00:04:07 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active
Error: (06/18/2014 00:04:07 PM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (06/18/2014 00:02:42 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (06/18/2014 00:01:42 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
iSafeNetFilter
Error: (06/18/2014 00:01:17 PM) (Source: atikmdag) (EventID: 10261) (User: )
Description: Display is not active
Error: (06/18/2014 00:01:17 PM) (Source: atikmdag) (EventID: 19468) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (06/18/2014 11:56:44 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (06/18/2014 11:55:44 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
iSafeNetFilter
Microsoft Office Sessions:
=========================
Error: (06/17/2014 05:56:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 640931
Error: (06/17/2014 05:56:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 640931
Error: (06/17/2014 05:56:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (06/17/2014 05:56:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 639932
Error: (06/17/2014 05:56:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 639932
Error: (06/17/2014 05:56:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (06/17/2014 05:56:33 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 638934
Error: (06/17/2014 05:56:33 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 638934
Error: (06/17/2014 05:56:33 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (06/17/2014 05:56:32 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 637889
==================== Memory info ===========================
Percentage of memory in use: 42%
Total physical RAM: 3055.43 MB
Available physical RAM: 1745.16 MB
Total Pagefile: 6109.15 MB
Available Pagefile: 4607.66 MB
Total Virtual: 2047.88 MB
Available Virtual: 1895.02 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:232.88 GB) (Free:141.84 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 00000080)
Partition 1: (Active) - (Size=233 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Gmer Log Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-06-18 13:08:53
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD2500BEVS-75UST0 rev.01.01A01 232,89GB
Running: Gmer-19357.exe; Driver: C:\Users\Sina\AppData\Local\Temp\kxldypow.sys
---- System - GMER 2.1 ----
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAddBootEntry [0x8BAB4AA0]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0x8BAB557E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEvent [0x8BAC15C8]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEventPair [0x8BAC1614]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0x8BAC17AE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateMutant [0x8BAC1536]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwCreateSection [0x8BB6B6D2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSemaphore [0x8BAC157E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThread [0x8BAB5AB4]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThreadEx [0x8BAB5CD0]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateTimer [0x8BAC1768]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0x8BAB636C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0x8BAB4B06]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDuplicateObject [0x8BAB9B40]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwLoadDriver [0x8BAB46F2]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwMapViewOfSection [0x8BB6B7B2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwModifyBootEntry [0x8BAB4B6C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0x8BAB9F36]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0x8BAB6E54]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEvent [0x8BAC15F2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEventPair [0x8BAC1636]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0x8BAC17D2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenMutant [0x8BAC155C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenProcess [0x8BAB943A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSection [0x8BAC16E6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSemaphore [0x8BAC15A6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenThread [0x8BAB9822]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenTimer [0x8BAC178C]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0x8BB6B556]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryObject [0x8BAB6CC8]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueueApcThreadEx [0x8BAB69D6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0x8BAB4BD2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootOptions [0x8BAB4C38]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwSetContextThread [0x8BB6B8AE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemInformation [0x8BAB478C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0x8BAB495E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwShutdownSystem [0x8BAB48EC]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendProcess [0x8BAB6536]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendThread [0x8BAB6698]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSystemDebugControl [0x8BAB49E6]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwTerminateProcess [0x8BB6B624]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateThread [0x8BAB61C6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwVdmControl [0x8BAB4C9E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0x8BAB55DA]
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 142D 82C4FA15 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82C89212 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10CB 82C90460 4 Bytes [A0, 4A, AB, 8B]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1153 82C904E8 4 Bytes [7E, 55, AB, 8B]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11A7 82C9053C 8 Bytes [C8, 15, AC, 8B, 14, 16, AC, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11B3 82C90548 4 Bytes [AE, 17, AC, 8B]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 82C90564 4 Bytes [36, 15, AC, 8B]
.text ...
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 108 82E4B4EF 4 Bytes CALL 8BAB7517 \SystemRoot\system32\drivers\aswSnx.sys
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 122 82E65357 4 Bytes CALL 8BAB752D \SystemRoot\system32\drivers\aswSnx.sys
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x91A05000, 0x2D5378, 0xE8000020]
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE[220] kernel32.dll!GetBinaryTypeW + 70 76096AAC 1 Byte [62]
.text C:\Windows\system32\csrss.exe[436] kernel32.dll!GetBinaryTypeW + 70 76096AAC 1 Byte [62]
.text C:\Windows\system32\wininit.exe[500] kernel32.dll!GetBinaryTypeW + 70 76096AAC 1 Byte [62]
.text C:\Windows\system32\csrss.exe[508] kernel32.dll!GetBinaryTypeW + 70 76096AAC 1 Byte [62]
.text C:\Windows\system32\services.exe[548] kernel32.dll!GetBinaryTypeW + 70 76096AAC 1 Byte [62]
.text ...
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1536] kernel32.dll!SetUnhandledExceptionFilter 7607F5AB 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1536] kernel32.dll!GetBinaryTypeW + 70 76096AAC 1 Byte [62]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1576] kernel32.dll!GetBinaryTypeW + 70 76096AAC 1 Byte [62]
.text C:\Windows\system32\Dwm.exe[1632] kernel32.dll!GetBinaryTypeW + 70 76096AAC 1 Byte [62]
.text C:\Windows\Explorer.EXE[1656] kernel32.dll!GetBinaryTypeW + 70 76096AAC 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1712] kernel32.dll!GetBinaryTypeW + 70 76096AAC 1 Byte [62]
.text ...
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2624] kernel32.dll!SetUnhandledExceptionFilter 7607F5AB 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2624] kernel32.dll!GetBinaryTypeW + 70 76096AAC 1 Byte [62]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2724] kernel32.dll!GetBinaryTypeW + 70 76096AAC 1 Byte [62]
.text C:\Program Files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2756] kernel32.dll!GetBinaryTypeW + 70 76096AAC 1 Byte [62]
.text C:\HP\KBD\kbd.exe[2808] kernel32.dll!GetBinaryTypeW + 70 76096AAC 1 Byte [62]
.text C:\Program Files\iTunes\iTunesHelper.exe[2816] kernel32.dll!GetBinaryTypeW + 70 76096AAC 1 Byte [62]
.text ...
---- Devices - GMER 2.1 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys
Device \Driver\BTHUSB \Device\00000086 bthport.sys
Device \Driver\BTHUSB \Device\00000088 bthport.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\70f39599b199
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\70f39599b199 (not active ControlSet)
Reg HKLM\SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Catalogs\SystemIndex@{D0990EB0-89E3-11E3-A28B-806E6F6E6963} 1423531888
---- EOF - GMER 2.1 ---- Malwarebytes Log Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 18.06.2014
Scan Time: 11:45:49
Logfile: malware.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.06.18.03
Rootkit Database: v2014.06.02.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Sina
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 248784
Time Elapsed: 7 min, 13 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 7
PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\awesomehpSoftware, Quarantined, [78730772dc9ff5413f652c9512f03ac6],
PUP.Optional.NewTab.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pkndmigholgfjlniaohblojbhgjbkakn, Quarantined, [7d6ef3868feca98deaa79031857d09f7],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Quarantined, [4f9cd8a12a51270fcdb945a1b350847c],
PUP.Optional.AlexaTB.A, HKU\S-1-5-21-200124554-1064517884-196756452-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DISTROMATIC\Toolbars, Quarantined, [87649edbbcbff1452e2a875a50b3e818],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-200124554-1064517884-196756452-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, [03e8f188601bf145813b08bc55ad857b],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-200124554-1064517884-196756452-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Quarantined, [6388e891fb80e6504780d2087291b050],
PUP.Optional.Qone8, HKU\S-1-5-21-200124554-1064517884-196756452-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Quarantined, [b93297e297e41e18c0c55f8749bace32],
Registry Values: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-200124554-1064517884-196756452-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0O1J1G2R, Quarantined, [6388e891fb80e6504780d2087291b050]
Registry Data: 4
PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.awesomehp.com/web/?type=ds&ts=1391115701&from=adks&uid=WDCXWD2500BEVS-75UST0_WD-WXC10844415844158&q={searchTerms}, Good: (hxxp://www.google.com), Bad: (hxxp://www.awesomehp.com/web/?type=ds&ts=1391115701&from=adks&uid=WDCXWD2500BEVS-75UST0_WD-WXC10844415844158&q={searchTerms}),Replaced,[7e6d7aff2754f73f7b936909a75d8c74]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Replaced,[b536f9807efd1e18fecb49321aea21df]
PUP.Optional.Awesomehp.A, HKU\S-1-5-21-200124554-1064517884-196756452-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.awesomehp.com/?type=hp&ts=1391115701&from=adks&uid=WDCXWD2500BEVS-75UST0_WD-WXC10844415844158, Good: (hxxp://www.google.com), Bad: (hxxp://www.awesomehp.com/?type=hp&ts=1391115701&from=adks&uid=WDCXWD2500BEVS-75UST0_WD-WXC10844415844158),Replaced,[aa414d2c93e8b581838e680af0146f91]
PUP.Optional.Awesomehp.A, HKU\S-1-5-21-200124554-1064517884-196756452-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.awesomehp.com/?type=hp&ts=1391115701&from=adks&uid=WDCXWD2500BEVS-75UST0_WD-WXC10844415844158, Good: (hxxp://www.google.com), Bad: (hxxp://www.awesomehp.com/?type=hp&ts=1391115701&from=adks&uid=WDCXWD2500BEVS-75UST0_WD-WXC10844415844158),Replaced,[36b532471d5e57df61a9076b27ddcf31]
Folders: 36
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\1, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\3, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\35, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\36, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\39, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\4, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\41, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\42, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\62, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\components, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\desk_bkg, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\sysicons, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\wp, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Program Files\Desk 365, Quarantined, [7f6cc8b10b70bb7ba1f6ac2c44bf12ee],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\Install, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\language, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\language\en_us, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\language\es_es, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\language\pt_br, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\language\tr_tr, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\language\zh_cn, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\language\zh_tw, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\layout, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\layout\default, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\style, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService, Quarantined, [4c9f2e4b1269cd69e8312569f70b5da3],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update, Quarantined, [4c9f2e4b1269cd69e8312569f70b5da3],
PUP.Optional.AmazonBrowserBar.A, C:\Users\Sina\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pbjikboenpfhbbejgkoklgkhjpfogcam, Quarantined, [ce1de198601ba88e452af7aa03ff36ca],
Files: 150
PUP.Optional.Installcore, C:\Users\Sina\AppData\Local\Temp\ICReinstall_FlashPlayer.exe, Quarantined, [36b5f386106bfc3a1ab69ab1e61e44bc],
PUP.Optional.InstallCore.A, C:\Users\Sina\AppData\Local\Temp\ICReinstall_install_flashplayer.exe, Quarantined, [a14ae594aecdfa3cd3f6d25eba468977],
PUP.Optional.NationZoom.A, C:\Users\Sina\AppData\Local\Temp\fullpackage_temp1391115680\Baofeng.exe, Quarantined, [f5f6e297b7c48da9c6b7a68704fc1fe1],
PUP.Optional.NationZoom.A, C:\Users\Sina\AppData\Local\Temp\fullpackage_temp1391115680\package1.zip, Quarantined, [668561187efd9e9814691716748c0af6],
PUP.Optional.SkyTech.A, C:\Users\Sina\AppData\Local\Temp\fullpackage_temp1391115680\UpDate.dll, Quarantined, [5893f881c0bbdc5ad94e66ccba46629e],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\fullpackage_temp1391115680\tmp\desk365.exe, Quarantined, [f2f98beef68560d66aeac94fee13837d],
PUP.Optional.SupTab.A, C:\Users\Sina\AppData\Local\Temp\fullpackage_temp1391115680\tmp\SupTab.exe, Quarantined, [3facc8b1e299fa3c72eb1421738dea16],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\eInstall.exe, Quarantined, [e2099bde2f4c61d5292b9e7a5fa26f91],
PUP.Optional.NewTab.A, C:\Users\Sina\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv2.crx, Quarantined, [37b437420c6ff640404dc2ff7b87e818],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote.xml, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\accelerate, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\desk_bkg_list.xml, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\desk_list.xml, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\desk_settings.ini, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\firstrun, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\process_mgr.xml, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\1\angrybirds.db, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\1\angrybirds.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\3\BigFarm.db, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\3\BigFarm.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\35\Gmail.db, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\35\Gmail.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\36\Outlook.db, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\36\Outlook.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\39\ESPN.db, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\39\ESPN.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\4\Empire.db, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\4\Empire.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\41\gcalendar.db, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\41\gcalendar.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\42\pulse.db, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\42\pulse.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\62\ddtank2.db, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\app\config\62\ddtank2.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\components\component_libcef_1.1364.1123.exe.tmp, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_1.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_2.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_3.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_4.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_5.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\desk_bkg\desk_bkg_default.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\337_7c9140b13c049fd26989f7fa25b77cb1_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\angrybirds_00ff92c12703baaf0130d6aec427d047_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\Barbie_00a67ff4ef657679a6c88553135d62ad_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\BigFarm_de933b0e5218a4db24bebe3d55ed3558_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\chrome_f004de26f9f97b93028f3f04aaa62cc9.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\chrome_f004de26f9f97b93028f3f04aaa62cc9_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\ddtank2_5d02d177c73d12e7ceb1811a8c30f9c5_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\Empire_22b42f57d1c467841280810e218d5510_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\ESPN_a7b078f5f5f5b87efcef66ab5783cf9d_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\Facebook_aab07bc79cf599b25c0110f32d46a3ef_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\gcalendar_50b3e3c5fc202f0cfcae8032b2465c1b_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\Gmail_731b6d011bd9f67463a916a496775935_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\Google_1eed88936b91d2b6bc341da82c727a8f_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\iexplore_10b5070763457bf93b9c3a073ef606ff.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\iexplore_10b5070763457bf93b9c3a073ef606ff_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\Mario_52934d81761dc31187a93a3a0be7fecc_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\Outlook_6f817b67fa6af1a9c8abfa3813a8595c_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\pulse_b5a242da04cc06eacd02b1ca41e3583c_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\sys_computer_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\sys_control_panel_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\sys_my_documents_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\Twitter_ebddd85ec04b7b94a2b2e97b73a90a4a_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\icons\Youtube_bf18fdfc4aefd6417a8bacae4be5b415_48_48.png, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote\337.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote\337_7c9140b13c049fd26989f7fa25b77cb1.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote\barbie.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote\Barbie_00a67ff4ef657679a6c88553135d62ad.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote\facebook.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote\Facebook_aab07bc79cf599b25c0110f32d46a3ef.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote\GameCenter.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote\google.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote\Google_1eed88936b91d2b6bc341da82c727a8f.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote\mario.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote\Mario_52934d81761dc31187a93a3a0be7fecc.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote\twitter.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote\Twitter_ebddd85ec04b7b94a2b2e97b73a90a4a.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote\v9.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote\youtube.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\promote\Youtube_bf18fdfc4aefd6417a8bacae4be5b415.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\sysicons\07584c03a5dd11a6104e45e8ad03b3fe_104.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\sysicons\07584c03a5dd11a6104e45e8ad03b3fe_107.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\sysicons\1f2396c6693b847e47fc39346e3dfa36_21.ico, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\wp\r0.jpg, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\wp\r1.jpg, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\wp\r2.jpg, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\wp\r3.jpg, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\wp\r4.jpg, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\wp\r5.jpg, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\wp\r6.jpg, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\wp\r7.jpg, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\wp\r8.jpg, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Roaming\Desk 365\wp\r9.jpg, Quarantined, [47a40376bdbed660c0d63b9d2fd47f81],
PUP.Optional.Desk365.A, C:\Program Files\Desk 365\promote.xml, Quarantined, [7f6cc8b10b70bb7ba1f6ac2c44bf12ee],
PUP.Optional.Desk365.A, C:\Program Files\Desk 365\desk_bkg_list.xml, Quarantined, [7f6cc8b10b70bb7ba1f6ac2c44bf12ee],
PUP.Optional.Desk365.A, C:\Program Files\Desk 365\desk_list.xml, Quarantined, [7f6cc8b10b70bb7ba1f6ac2c44bf12ee],
PUP.Optional.Desk365.A, C:\Program Files\Desk 365\desk_settings.ini, Quarantined, [7f6cc8b10b70bb7ba1f6ac2c44bf12ee],
PUP.Optional.Desk365.A, C:\Program Files\Desk 365\process_mgr.xml, Quarantined, [7f6cc8b10b70bb7ba1f6ac2c44bf12ee],
PUP.Optional.Desk365.A, C:\Program Files\Desk 365\recent.xml, Quarantined, [7f6cc8b10b70bb7ba1f6ac2c44bf12ee],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\main, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\msvcp100.dll, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\msvcr100.dll, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\segoeui.ttf, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\segoeuib.ttf, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\app_icon.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\change_skin.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\combo_skin.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\edit_skin.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\install_back.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\install_button_skin.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\install_check_checked.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\install_check_intermediate.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\install_check_uncheck.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\install_logo.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\install_resource.xml, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\patch_file_icon.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\pic-error.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\pic-info.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\pic-question.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\pic-warning.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\popup_dialog_bk.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\progressbar_bk.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\progressbar_image.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\radio_normal.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\radio_selected.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\image\default\sys_close.png, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\Install\4zip.inst, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\Install\AirZip.inst, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\Install\edesk.inst, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\Install\gamelogin.inst, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\language\protocol.txt, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\language\en_us\install_lang.ini, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\language\es_es\install_lang.ini, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\language\pt_br\install_lang.ini, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\language\tr_tr\install_lang.ini, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\layout\default\eDeskInstall.xml, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\layout\default\gamelogin.xml, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\layout\default\install_msgbox.xml, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\layout\default\languageSelect.xml, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\layout\default\uninstgl.xml, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.Desk365.A, C:\Users\Sina\AppData\Local\Temp\Desk365\eInstall\style\install_style.xml, Quarantined, [0ae11f5a84f7f640c4bd345732d08f71],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update\conf, Quarantined, [4c9f2e4b1269cd69e8312569f70b5da3],
PUP.Optional.AmazonBrowserBar.A, C:\Users\Sina\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pbjikboenpfhbbejgkoklgkhjpfogcam\000005.ldb, Quarantined, [ce1de198601ba88e452af7aa03ff36ca],
PUP.Optional.AmazonBrowserBar.A, C:\Users\Sina\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pbjikboenpfhbbejgkoklgkhjpfogcam\000008.ldb, Quarantined, [ce1de198601ba88e452af7aa03ff36ca],
PUP.Optional.AmazonBrowserBar.A, C:\Users\Sina\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pbjikboenpfhbbejgkoklgkhjpfogcam\000017.log, Quarantined, [ce1de198601ba88e452af7aa03ff36ca],
PUP.Optional.AmazonBrowserBar.A, C:\Users\Sina\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pbjikboenpfhbbejgkoklgkhjpfogcam\CURRENT, Quarantined, [ce1de198601ba88e452af7aa03ff36ca],
PUP.Optional.AmazonBrowserBar.A, C:\Users\Sina\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pbjikboenpfhbbejgkoklgkhjpfogcam\LOCK, Quarantined, [ce1de198601ba88e452af7aa03ff36ca],
PUP.Optional.AmazonBrowserBar.A, C:\Users\Sina\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pbjikboenpfhbbejgkoklgkhjpfogcam\LOG, Quarantined, [ce1de198601ba88e452af7aa03ff36ca],
PUP.Optional.AmazonBrowserBar.A, C:\Users\Sina\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pbjikboenpfhbbejgkoklgkhjpfogcam\LOG.old, Quarantined, [ce1de198601ba88e452af7aa03ff36ca],
PUP.Optional.AmazonBrowserBar.A, C:\Users\Sina\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pbjikboenpfhbbejgkoklgkhjpfogcam\MANIFEST-000015, Quarantined, [ce1de198601ba88e452af7aa03ff36ca],
Physical Sectors: 0
(No malicious items detected)
(end) |