Code:
# AdwCleaner v3.018 - Bericht erstellt am 11/02/2014 um 22:15:05
# Updated 28/01/2014 von Xplode
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : Farah - REZAI
# Gestartet von : C:\Users\Farah\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\apn
Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\WINDOWS\SysWOW64\Searchprotect
Ordner Gelöscht : C:\Users\Farah\AppData\Local\Searchprotect
Ordner Gelöscht : C:\Users\Farah\AppData\Local\Wajam
Ordner Gelöscht : C:\Users\Farah\AppData\LocalLow\IminentToolbar
Ordner Gelöscht : C:\Users\Farah\AppData\Roaming\Systweak
Datei Gelöscht : C:\WINDOWS\System32\roboot64.exe
Datei Gelöscht : C:\Users\Farah\AppData\Roaming\Mozilla\Firefox\Profiles\cbc6qd7g.default\searchplugins\iminent.xml
Datei Gelöscht : C:\Users\Farah\AppData\Roaming\Mozilla\Firefox\Profiles\cbc6qd7g.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [lollipop_01032129]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366966680}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1631550F-191D-4826-B069-D9439253D926}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1631550F-191D-4826-B069-D9439253D926}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{06E50566-0AB7-431C-841D-62794727DAF9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366966680}
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\lollipop
Schlüssel Gelöscht : HKCU\Software\powerpack
Schlüssel Gelöscht : HKCU\Software\Somoto
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DynConIE
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong
Schlüssel Gelöscht : HKLM\Software\SearchProtect
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16384
-\\ Mozilla Firefox v25.0.1 (en-US)
[ Datei : C:\Users\Farah\AppData\Roaming\Mozilla\Firefox\Profiles\cbc6qd7g.default\prefs.js ]
Zeile gelöscht : user_pref("CT3309350.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"false\"}");
Zeile gelöscht : user_pref("extensions.G0329kgkhluB.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"onduit\")>-1||url.[...]
Zeile gelöscht : user_pref("extensions.aFo5TrMz7.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"onduit\")>-1||url.mat[...]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "1438c09c789fe1bb3e5bf0e90bad8ebe");
-\\ Google Chrome v31.0.1650.63
[ Datei : C:\Users\Farah\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [13716 octets] - [11/02/2014 22:13:54]
AdwCleaner[S0].txt - [13059 octets] - [11/02/2014 22:15:05]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [13120 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.1 (02.04.2014:1)
OS: Windows 8.1 x64
Ran by Farah on 11.02.2014 at 22:21:08,60
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-731532133-2375222265-127545158-1002\Software\wajam
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220322962280}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220322962280}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Farah\appdata\local\appshat mobile apps"
Successfully deleted: [Folder] "C:\Users\Farah\appdata\local\webplayer"
Successfully deleted: [Folder] "C:\WINDOWS\syswow64\ai_recyclebin"
~~~ FireFox
Successfully deleted the following from C:\Users\Farah\AppData\Roaming\mozilla\firefox\profiles\cbc6qd7g.default\prefs.js
user_pref("extensions.G0329kgkhluB.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.ind
user_pref("extensions.aFo5TrMz7.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexO
user_pref("extensions.iminent.admin", false);
user_pref("extensions.iminent.aflt", "orgnl");
user_pref("extensions.iminent.appId", "{0E4B2CAB-B859-4C57-B96E-63DDEC692BC4}");
user_pref("extensions.iminent.autoRvrt", "false");
user_pref("extensions.iminent.dfltLng", "");
user_pref("extensions.iminent.excTlbr", false);
user_pref("extensions.iminent.ffxUnstlRst", false);
user_pref("extensions.iminent.id", "400f6ecc00000000000016db301e6bb0");
user_pref("extensions.iminent.instlDay", "16078");
user_pref("extensions.iminent.instlRef", "");
user_pref("extensions.iminent.newTab", false);
user_pref("extensions.iminent.prdct", "iminent");
user_pref("extensions.iminent.prtnrId", "iminent");
user_pref("extensions.iminent.rvrt", "false");
user_pref("extensions.iminent.smplGrp", "none");
user_pref("extensions.iminent.tlbrId", "GCPCTSAD");
user_pref("extensions.iminent.tlbrSrchUrl", "hxxp://start.iminent.com/?ref=toolbarm#q=");
user_pref("extensions.iminent.vrsn", "1.8.28.3");
user_pref("extensions.iminent.vrsnTs", "1.8.28.317:03:20");
user_pref("extensions.iminent.vrsni", "1.8.28.3");
Emptied folder: C:\Users\Farah\AppData\Roaming\mozilla\firefox\profiles\cbc6qd7g.default\minidumps [3 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 11.02.2014 at 22:25:41,66
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-02-2014 01
Ran by Farah (administrator) on REZAI on 11-02-2014 22:26:49
Running from C:\Users\Farah\Downloads
Windows 8.1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
() C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
() C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler.exe
(Intel Corporation) C:\WINDOWS\system32\DptfParticipantProcessorService.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Intel Corporation) C:\WINDOWS\system32\DptfPolicyConfigTDPService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler64.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Microsoft Corporation) C:\Windows\System32\skydrive.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Akamai Technologies, Inc.) C:\Users\Farah\AppData\Local\Akamai\netsession_win.exe
(Dropbox, Inc.) C:\Users\Farah\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Akamai Technologies, Inc.) C:\Users\Farah\AppData\Local\Akamai\netsession_win.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
(Adobe Systems, Inc.) C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13267016 2013-01-23] (Realtek Semiconductor)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-09-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSPRP] - C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-04-26] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [3576784 2012-12-19] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [ATLauncher] - C:\Program Files\McAfeeEx\McAfeeAntiTheft\ATLauncher.exe [511232 2013-07-23] (McAfee, Inc.)
HKLM-x32\...\Run: [ATUninstallIcon] - C:\Program Files\McAfeeEx\McAfeeAntiTheft\ATLauncher.exe [511232 2013-07-23] (McAfee, Inc.)
HKLM-x32\...\Run: [mcpltui_exe] - C:\Program Files\Common Files\mcafee\platform\McUICnt.exe [644656 2013-08-17] (McAfee, Inc.)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [X]
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-01-20] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-01-20] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-731532133-2375222265-127545158-1002\...\Run: [Akamai NetSession Interface] - C:\Users\Farah\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [168616 2013-12-10] (NVIDIA Corporation)
Startup: C:\Users\Farah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Farah\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Plus-HD-4.6 - {11111111-1111-1111-1111-110311961180} - C:\Program Files (x86)\Plus-HD-4.6\Plus-HD-4.6-bho64.dll No File
BHO: FineDEaalSoft - {6D440B7B-BEEF-369B-6610-4AB29FEB59DD} - C:\ProgramData\FineDEaalSoft\hTMJYEwSz_.x64.dll No File
BHO: websaVear - {AD4095D1-59A8-FD85-F22D-EE9B48A66FBE} - C:\ProgramData\websaVear\TLPGX3K.x64.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Farah\AppData\Roaming\Mozilla\Firefox\Profiles\cbc6qd7g.default
FF Homepage: google.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Extension: Widget context - C:\Users\Farah\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{140A2D0E-85CC-4ed3-9BA5-8FA35DA7FABA}.xpi [2013-12-12]
FF Extension: Plus-HD-4.6 - C:\Users\Farah\AppData\Roaming\Mozilla\Firefox\Profiles\cbc6qd7g.default\Extensions\5fdca21f-37d5-4e88-90b5-9d2f3ac7528e@842a12bf-3d32-40de-9ffb-8543bfad2483.com [2014-01-28]
FF Extension: FineDEaalSoft - C:\Users\Farah\AppData\Roaming\Mozilla\Firefox\Profiles\cbc6qd7g.default\Extensions\ccvau5@cnwfeoumwz.org [2014-01-13]
FF Extension: websaVear - C:\Users\Farah\AppData\Roaming\Mozilla\Firefox\Profiles\cbc6qd7g.default\Extensions\ge9ao18a54@bctdsveelblj.co.uk [2014-01-13]
FF Extension: Tube Dimmer - C:\Users\Farah\AppData\Roaming\Mozilla\Firefox\Profiles\cbc6qd7g.default\Extensions\support@tubedimmerapp.com [2013-12-05]
FF Extension: Adblock Plus - C:\Users\Farah\AppData\Roaming\Mozilla\Firefox\Profiles\cbc6qd7g.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-27]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\Farah\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-13]
CHR Extension: (Adblock Plus) - C:\Users\Farah\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-01-13]
CHR Extension: (Plus-HD-4.6) - C:\Users\Farah\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffalemnbenephhkjhhemdmihjmdeafbk [2014-01-14]
CHR Extension: (Google Wallet) - C:\Users\Farah\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-13]
CHR Extension: (FineDEaalSoft) - C:\ProgramData\hanekhofjkmainffkcokafddekmphphk [2014-01-05]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [72192 2012-12-19] ()
R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [31632 2013-01-18] (Intel Corporation)
R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [33168 2013-01-18] (Intel Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 McAWFwk; C:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe [334608 2013-07-24] (McAfee, Inc.)
R2 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McSchedulerSvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
S3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-01-16] (ASUS Corporation)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [107920 2013-01-18] (Intel Corporation)
R3 DptfDevFan; C:\Windows\system32\DRIVERS\DptfDevFan.sys [43408 2013-01-18] (Intel Corporation)
R3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [65424 2013-01-18] (Intel Corporation)
R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [229776 2013-01-18] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [363920 2013-01-18] (Intel Corporation)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-12-11] (Microsoft Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-12-11] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-12-11] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-11 22:26 - 2014-02-11 22:26 - 00000000 ____D () C:\Users\Farah\Downloads\FRST-OlderVersion
2014-02-11 22:25 - 2014-02-11 22:25 - 00002957 _____ () C:\Users\Farah\Desktop\JRT.txt
2014-02-11 22:21 - 2014-02-11 22:21 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-02-11 22:20 - 2014-02-11 22:20 - 00013397 _____ () C:\Users\Farah\Desktop\ADW.txt
2014-02-11 22:18 - 2014-02-11 22:18 - 01037530 _____ (Thisisu) C:\Users\Farah\Downloads\JRT.exe
2014-02-11 22:13 - 2014-02-11 22:15 - 00000000 ____D () C:\AdwCleaner
2014-02-11 22:13 - 2014-02-11 22:13 - 01166132 _____ () C:\Users\Farah\Downloads\adwcleaner.exe
2014-02-06 20:16 - 2014-02-11 22:19 - 01455395 _____ () C:\WINDOWS\WindowsUpdate.log
2014-02-02 23:30 - 2014-02-02 23:30 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2014-01-31 16:35 - 2014-01-31 16:35 - 00001123 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-31 16:35 - 2014-01-31 16:35 - 00000000 ____D () C:\Users\Farah\AppData\Roaming\Malwarebytes
2014-01-31 16:34 - 2014-01-31 16:35 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-31 16:34 - 2014-01-31 16:34 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-01-31 16:34 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-01-31 16:32 - 2014-01-31 16:34 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Farah\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-30 21:39 - 2014-01-30 21:39 - 00021477 _____ () C:\Users\Farah\Downloads\Addition.txt
2014-01-30 21:38 - 2014-02-11 22:26 - 00015975 _____ () C:\Users\Farah\Downloads\FRST.txt
2014-01-30 21:38 - 2014-02-11 22:26 - 00000000 ____D () C:\FRST
2014-01-30 21:35 - 2014-02-11 22:26 - 02151424 _____ (Farbar) C:\Users\Farah\Downloads\FRST64.exe
2014-01-29 00:15 - 2014-01-29 00:15 - 00003266 _____ () C:\WINDOWS\System32\Tasks\{7119D284-535A-47C1-8F61-A114DA4032A6}
2014-01-28 23:35 - 2014-01-31 17:12 - 00000000 ____D () C:\Program Files\office.tmp
2014-01-28 23:34 - 2014-01-28 23:34 - 00003204 _____ () C:\WINDOWS\System32\Tasks\{B146A838-D39D-4443-8449-502B0B8E98A3}
2014-01-28 13:18 - 2014-01-28 13:27 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-01-27 22:15 - 2014-01-27 22:15 - 00000000 ____D () C:\Users\Farah\AppData\Local\Intel_Corporation
2014-01-26 19:28 - 2014-01-26 19:28 - 00001797 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-01-26 19:27 - 2014-01-26 19:28 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-26 19:27 - 2014-01-26 19:28 - 00000000 ____D () C:\Program Files\iTunes
2014-01-26 19:27 - 2014-01-26 19:28 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-01-26 19:27 - 2014-01-26 19:27 - 00000000 ____D () C:\Program Files\iPod
2014-01-22 00:00 - 2014-01-22 00:00 - 00000000 ____D () C:\Users\Farah\AppData\Roaming\LolClient
2014-01-21 20:44 - 2014-01-21 20:44 - 00001625 _____ () C:\Users\Public\Desktop\Play League of Legends.lnk
2014-01-21 20:44 - 2014-01-21 20:44 - 00000000 ____D () C:\Riot Games
2014-01-21 20:44 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
2014-01-21 20:44 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
2014-01-21 20:44 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
2014-01-21 20:44 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
2014-01-21 20:44 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
2014-01-20 23:38 - 2014-02-11 22:14 - 00000000 ____D () C:\Users\Farah\AppData\Local\PMB Files
2014-01-20 23:38 - 2014-02-11 22:00 - 00000000 ____D () C:\ProgramData\PMB Files
2014-01-20 23:38 - 2014-01-20 23:38 - 00000000 ____D () C:\Program Files (x86)\Pando Networks
2014-01-20 23:37 - 2014-01-21 20:45 - 00000000 ____D () C:\Users\Farah\AppData\Roaming\Riot Games
2014-01-20 23:37 - 2014-01-20 23:37 - 34888568 _____ (Riot Games) C:\Users\Farah\Downloads\LeagueofLegends_EUW_Installer_06_12_13.exe
2014-01-15 12:32 - 2013-11-27 16:36 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2014-01-15 12:32 - 2013-11-27 12:41 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe
2014-01-15 12:32 - 2013-11-27 11:34 - 00138240 _____ () C:\WINDOWS\system32\OEMLicense.dll
2014-01-15 12:32 - 2013-11-27 10:54 - 00103936 _____ () C:\WINDOWS\SysWOW64\OEMLicense.dll
2014-01-15 12:32 - 2013-11-27 09:48 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 12:32 - 2013-11-27 09:45 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll
2014-01-15 12:32 - 2013-11-27 09:40 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 12:32 - 2013-11-27 09:38 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll
2014-01-15 12:32 - 2013-11-27 09:17 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-01-15 12:32 - 2013-11-27 09:12 - 00848384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-01-15 12:31 - 2013-12-09 01:15 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2014-01-14 16:36 - 2014-01-14 16:36 - 00003293 _____ () C:\Users\Farah\AppData\Local\recently-used.xbel
2014-01-14 16:25 - 2014-01-14 16:25 - 00002041 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-01-13 18:06 - 2014-01-15 19:10 - 00000000 ____D () C:\Users\Farah\Desktop\Primera
2014-01-13 18:05 - 2014-02-11 22:17 - 00000000 ___RD () C:\Users\Farah\Dropbox
2014-01-13 18:05 - 2014-01-13 18:05 - 00001090 _____ () C:\Users\Farah\Desktop\Dropbox.lnk
2014-01-13 18:04 - 2014-01-13 18:05 - 00000000 ____D () C:\Users\Farah\AppData\Roaming\DropboxMaster
2014-01-13 18:04 - 2014-01-13 18:04 - 00000000 ____D () C:\Users\Farah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-13 18:03 - 2014-02-11 22:20 - 00000000 ____D () C:\Users\Farah\AppData\Roaming\Dropbox
2014-01-13 18:03 - 2014-01-13 18:03 - 37660568 _____ (Dropbox, Inc.) C:\Users\Farah\Downloads\Dropbox 2.6.2.exe
2014-01-13 17:50 - 2014-01-14 16:36 - 00000000 ____D () C:\Users\Farah\AppData\Local\gtk-2.0
2014-01-13 17:50 - 2014-01-13 17:50 - 00000000 ____D () C:\Users\Farah\.thumbnails
2014-01-13 17:49 - 2014-01-14 17:40 - 00000000 ____D () C:\Users\Farah\.gimp-2.8
2014-01-13 17:49 - 2014-01-13 17:49 - 00000000 ____D () C:\Users\Farah\AppData\Local\gegl-0.2
2014-01-13 17:47 - 2014-01-13 17:48 - 00000000 ____D () C:\Program Files\GIMP 2
2014-01-13 17:45 - 2014-01-13 17:46 - 90396104 _____ (The GIMP Team ) C:\Users\Farah\Downloads\gimp-2.8.10-setup.exe
2014-01-13 17:44 - 2014-02-06 20:19 - 00064512 ___SH () C:\Users\Farah\Desktop\Thumbs.db
2014-01-13 15:41 - 2014-02-11 22:17 - 00002197 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-13 15:41 - 2014-02-11 22:16 - 00000904 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-13 15:41 - 2014-02-11 21:46 - 00000908 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-13 15:41 - 2014-01-13 15:41 - 00003880 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-01-13 15:41 - 2014-01-13 15:41 - 00003644 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-01-13 15:40 - 2014-01-13 15:40 - 00819144 _____ (Google Inc.) C:\Users\Farah\Downloads\chrome_installer_31.0.1650.63.exe
==================== One Month Modified Files and Folders =======
2014-02-11 22:27 - 2014-02-06 20:16 - 01455395 _____ () C:\WINDOWS\WindowsUpdate.log
2014-02-11 22:27 - 2014-01-30 21:38 - 00015975 _____ () C:\Users\Farah\Downloads\FRST.txt
2014-02-11 22:26 - 2014-02-11 22:26 - 00000000 ____D () C:\Users\Farah\Downloads\FRST-OlderVersion
2014-02-11 22:26 - 2014-01-30 21:38 - 00000000 ____D () C:\FRST
2014-02-11 22:26 - 2014-01-30 21:35 - 02151424 _____ (Farbar) C:\Users\Farah\Downloads\FRST64.exe
2014-02-11 22:25 - 2014-02-11 22:25 - 00002957 _____ () C:\Users\Farah\Desktop\JRT.txt
2014-02-11 22:21 - 2014-02-11 22:21 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-02-11 22:21 - 2013-12-17 09:29 - 00003918 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{4D0B327E-F2D5-4143-9E49-B13FE0750E13}
2014-02-11 22:20 - 2014-02-11 22:20 - 00013397 _____ () C:\Users\Farah\Desktop\ADW.txt
2014-02-11 22:20 - 2014-01-13 18:03 - 00000000 ____D () C:\Users\Farah\AppData\Roaming\Dropbox
2014-02-11 22:19 - 2013-12-04 23:36 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-02-11 22:18 - 2014-02-11 22:18 - 01037530 _____ (Thisisu) C:\Users\Farah\Downloads\JRT.exe
2014-02-11 22:18 - 2013-12-18 21:31 - 00000000 __RDO () C:\Users\Farah\SkyDrive
2014-02-11 22:18 - 2013-11-29 17:31 - 00000062 _____ () C:\Users\Farah\AppData\Roaming\sp_data.sys
2014-02-11 22:17 - 2014-01-13 18:05 - 00000000 ___RD () C:\Users\Farah\Dropbox
2014-02-11 22:17 - 2014-01-13 15:41 - 00002197 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-11 22:16 - 2014-01-13 15:41 - 00000904 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-11 22:16 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-02-11 22:15 - 2014-02-11 22:13 - 00000000 ____D () C:\AdwCleaner
2014-02-11 22:15 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-02-11 22:14 - 2014-01-20 23:38 - 00000000 ____D () C:\Users\Farah\AppData\Local\PMB Files
2014-02-11 22:13 - 2014-02-11 22:13 - 01166132 _____ () C:\Users\Farah\Downloads\adwcleaner.exe
2014-02-11 22:02 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-02-11 22:00 - 2014-01-20 23:38 - 00000000 ____D () C:\ProgramData\PMB Files
2014-02-11 21:46 - 2014-01-13 15:41 - 00000908 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-10 22:34 - 2013-11-29 17:40 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-731532133-2375222265-127545158-1002
2014-02-06 20:23 - 2013-12-01 19:50 - 00000000 ____D () C:\Users\Farah\Desktop\Rezai
2014-02-06 20:19 - 2014-01-13 17:44 - 00064512 ___SH () C:\Users\Farah\Desktop\Thumbs.db
2014-02-04 23:19 - 2013-12-04 23:36 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-02-04 22:22 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-02-02 23:32 - 2013-09-30 05:14 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-02-02 23:32 - 2013-09-30 04:56 - 00771640 _____ () C:\WINDOWS\system32\perfh007.dat
2014-02-02 23:32 - 2013-09-30 04:56 - 00161916 _____ () C:\WINDOWS\system32\perfc007.dat
2014-02-02 23:30 - 2014-02-02 23:30 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2014-01-31 17:12 - 2014-01-28 23:35 - 00000000 ____D () C:\Program Files\office.tmp
2014-01-31 17:12 - 2013-11-29 17:49 - 00000000 ____D () C:\ProgramData\Updater
2014-01-31 17:08 - 2014-01-05 18:11 - 00000000 ____D () C:\ProgramData\FineDEaalSoft
2014-01-31 17:08 - 2014-01-05 18:10 - 00000000 ____D () C:\ProgramData\websaVear
2014-01-31 16:35 - 2014-01-31 16:35 - 00001123 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-31 16:35 - 2014-01-31 16:35 - 00000000 ____D () C:\Users\Farah\AppData\Roaming\Malwarebytes
2014-01-31 16:35 - 2014-01-31 16:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-31 16:34 - 2014-01-31 16:34 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-01-31 16:34 - 2014-01-31 16:32 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Farah\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-30 21:47 - 2013-08-22 16:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-01-30 21:47 - 2013-08-22 16:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-30 21:39 - 2014-01-30 21:39 - 00021477 _____ () C:\Users\Farah\Downloads\Addition.txt
2014-01-29 00:15 - 2014-01-29 00:15 - 00003266 _____ () C:\WINDOWS\System32\Tasks\{7119D284-535A-47C1-8F61-A114DA4032A6}
2014-01-28 23:36 - 2013-04-26 00:13 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-01-28 23:34 - 2014-01-28 23:34 - 00003204 _____ () C:\WINDOWS\System32\Tasks\{B146A838-D39D-4443-8449-502B0B8E98A3}
2014-01-28 23:33 - 2013-04-26 00:16 - 00000000 ____D () C:\Program Files (x86)\ASUS
2014-01-28 19:54 - 2013-12-11 21:11 - 00000000 ____D () C:\Users\Farah
2014-01-28 13:27 - 2014-01-28 13:18 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-01-28 13:18 - 2013-04-26 00:18 - 00000000 ____D () C:\Program Files\mcafee
2014-01-27 22:15 - 2014-01-27 22:15 - 00000000 ____D () C:\Users\Farah\AppData\Local\Intel_Corporation
2014-01-26 19:28 - 2014-01-26 19:28 - 00001797 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-01-26 19:28 - 2014-01-26 19:27 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-26 19:28 - 2014-01-26 19:27 - 00000000 ____D () C:\Program Files\iTunes
2014-01-26 19:28 - 2014-01-26 19:27 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-01-26 19:27 - 2014-01-26 19:27 - 00000000 ____D () C:\Program Files\iPod
2014-01-26 19:24 - 2013-12-24 13:41 - 00000000 ____D () C:\ProgramData\Apple
2014-01-22 00:00 - 2014-01-22 00:00 - 00000000 ____D () C:\Users\Farah\AppData\Roaming\LolClient
2014-01-21 20:45 - 2014-01-20 23:37 - 00000000 ____D () C:\Users\Farah\AppData\Roaming\Riot Games
2014-01-21 20:44 - 2014-01-21 20:44 - 00001625 _____ () C:\Users\Public\Desktop\Play League of Legends.lnk
2014-01-21 20:44 - 2014-01-21 20:44 - 00000000 ____D () C:\Riot Games
2014-01-21 00:12 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\LiveKernelReports
2014-01-20 23:38 - 2014-01-20 23:38 - 00000000 ____D () C:\Program Files (x86)\Pando Networks
2014-01-20 23:37 - 2014-01-20 23:37 - 34888568 _____ (Riot Games) C:\Users\Farah\Downloads\LeagueofLegends_EUW_Installer_06_12_13.exe
2014-01-19 13:36 - 2013-11-30 20:08 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-01-19 13:34 - 2013-11-30 20:08 - 86054176 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-01-19 08:38 - 2013-11-30 19:52 - 00270496 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2014-01-16 00:15 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\WinStore
2014-01-15 19:10 - 2014-01-13 18:06 - 00000000 ____D () C:\Users\Farah\Desktop\Primera
2014-01-15 12:45 - 2014-01-08 18:03 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-01-14 17:40 - 2014-01-13 17:49 - 00000000 ____D () C:\Users\Farah\.gimp-2.8
2014-01-14 16:36 - 2014-01-14 16:36 - 00003293 _____ () C:\Users\Farah\AppData\Local\recently-used.xbel
2014-01-14 16:36 - 2014-01-13 17:50 - 00000000 ____D () C:\Users\Farah\AppData\Local\gtk-2.0
2014-01-14 16:25 - 2014-01-14 16:25 - 00002041 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-01-13 23:54 - 2013-04-26 00:15 - 00000000 ____D () C:\ProgramData\Adobe
2014-01-13 18:05 - 2014-01-13 18:05 - 00001090 _____ () C:\Users\Farah\Desktop\Dropbox.lnk
2014-01-13 18:05 - 2014-01-13 18:04 - 00000000 ____D () C:\Users\Farah\AppData\Roaming\DropboxMaster
2014-01-13 18:05 - 2013-11-29 17:33 - 00000000 ___RD () C:\Users\Farah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-13 18:04 - 2014-01-13 18:04 - 00000000 ____D () C:\Users\Farah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-13 18:03 - 2014-01-13 18:03 - 37660568 _____ (Dropbox, Inc.) C:\Users\Farah\Downloads\Dropbox 2.6.2.exe
2014-01-13 17:50 - 2014-01-13 17:50 - 00000000 ____D () C:\Users\Farah\.thumbnails
2014-01-13 17:49 - 2014-01-13 17:49 - 00000000 ____D () C:\Users\Farah\AppData\Local\gegl-0.2
2014-01-13 17:48 - 2014-01-13 17:47 - 00000000 ____D () C:\Program Files\GIMP 2
2014-01-13 17:46 - 2014-01-13 17:45 - 90396104 _____ (The GIMP Team ) C:\Users\Farah\Downloads\gimp-2.8.10-setup.exe
2014-01-13 17:44 - 2013-11-29 17:33 - 00000854 _____ () C:\Users\Farah\Desktop\Downloads.lnk
2014-01-13 17:36 - 2013-12-06 14:46 - 00000000 ____D () C:\Users\Farah\AppData\Local\HP
2014-01-13 15:41 - 2014-01-13 15:41 - 00003880 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-01-13 15:41 - 2014-01-13 15:41 - 00003644 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-01-13 15:41 - 2013-11-29 17:38 - 00000000 ____D () C:\Program Files (x86)\Google
2014-01-13 15:40 - 2014-01-13 15:40 - 00819144 _____ (Google Inc.) C:\Users\Farah\Downloads\chrome_installer_31.0.1650.63.exe
2014-01-13 15:37 - 2014-01-08 17:04 - 00000000 ____D () C:\Users\Farah\AppData\Local\Mobogenie
2014-01-13 15:26 - 2014-01-08 17:02 - 00000898 _____ () C:\WINDOWS\SysWOW64\InstallUtil.InstallLog
2014-01-12 00:17 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
C:\ProgramData\SetStretch.VBS
Some content of TEMP:
====================
C:\Users\Farah\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpfy_1ci.dll
C:\Users\Farah\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpuxkhjb.dll
C:\Users\Farah\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-01 16:27
==================== End Of Log ============================ --- --- --- |