2016/04/19 11:10:12 +0100
mbam-log-2016-04-19 (11-09-33).xml
yes
2.2.1.1043
v2016.04.19.03
v2016.04.17.01
trial
enabled
enabled
disabled
USER-KOMPUTER
192.168.1.102
Windows 7
x64
User
NTFS
threat
completed
325461
0
0
5
3
0
2
7
0
enabled
enabled
enabled
enabled
disabled
disabled
enabled
enabled
enabled
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{3B420FCA-2F74-4FE7-9D3D-3EFFFB90C7C3}PUP.Optional.PriceFountaindelete-on-reboot7738e9c77f1a39fd8f87980924e0db25
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{8BADE460-FC94-48C2-B2A0-36C2997465EB}PUP.Optional.PriceFountaindelete-on-reboot6a455b55b2e794a232fabbe61fe59f61
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Price FountainPUP.Optional.PriceFountaindelete-on-reboot9c133c74fc9d4beb5252b4e74aba32ce
HKU\S-1-5-21-1652688680-2107975309-4158645315-1000\SOFTWARE\ICSW1.17PUP.Optional.InstallCoresuccess812ee2ceafea51e5172e1817b54f7c84
HKU\S-1-5-21-1652688680-2107975309-4158645315-1000\SOFTWARE\PRODUCTSETUPPUP.Optional.ProductSetupsuccesse1ce6b45ddbccf67168edc6228dc619f
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{3B420FCA-2F74-4FE7-9D3D-3EFFFB90C7C3}PathPUP.Optional.PriceFountaindelete-on-reboot\Price Fountain7738e9c77f1a39fd8f87980924e0db25
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{8BADE460-FC94-48C2-B2A0-36C2997465EB}PathPUP.Optional.PriceFountaindelete-on-reboot\UserPlunderageMaledictionV26a455b55b2e794a232fabbe61fe59f61
HKU\S-1-5-21-1652688680-2107975309-4158645315-1000\SOFTWARE\PRODUCTSETUPtbPUP.Optional.ProductSetupsuccess0Q1O1R1R0D1G1J1Se1ce6b45ddbccf67168edc6228dc619f
C:\Users\User\AppData\Roaming\PriceFountainPUP.Optional.PriceFountaindelete-on-reboot317e8e22e3b6191dc86daf833cc7db25
C:\Users\User\AppData\Roaming\PriceFountain\UpdateProcPUP.Optional.PriceFountainsuccess317e8e22e3b6191dc86daf833cc7db25
C:\$Recycle.Bin\S-1-5-21-1652688680-2107975309-4158645315-1000\$RNQW5EX.exePUP.Optional.ProductKeyFindersuccess159a525eadeca49293cb018e09f806fa
C:\$Recycle.Bin\S-1-5-21-1652688680-2107975309-4158645315-1000\$R4U5GTV.exePUP.Optional.ProductKeyFindersuccesscbe4a30d38614cea9ac4355ab05106fa
C:\Users\User\Downloads\d7II_SFX(1).exePUP.Optional.ProductKeyFindersuccessb2fde8c8dabf3402ea74d3bc5ea3ca36
C:\Windows\System32\Tasks\UserPlunderageMaledictionV2PUP.Optional.PriceFountainsuccessf3bc803029705fd7cf348014c14351af
C:\Windows\System32\Tasks\Price FountainPUP.Optional.PriceFountainsuccess19965e52c6d3ee485250edae2dd732ce
C:\Windows\Tasks\Price Fountain.jobPUP.Optional.PriceFountainsuccess802f10a05a3f66d08a19405b3dc7748c
C:\Users\User\AppData\Roaming\PriceFountain\UpdateProc\config.datPUP.Optional.PriceFountainsuccess317e8e22e3b6191dc86daf833cc7db25